安全分析报告: 云移资讯 v5.0.5.0

安全分数


安全分数 25/100

风险评级


等级

  1. A
  2. B
  3. C
  4. F

严重性分布 (%)


隐私风险

1

用户/设备跟踪器


调研结果

高危 27
中危 20
信息 4
安全 2
关注 31

高危 Activity (ynyd.mobile.moa.Web3Activity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (ynyd.mobile.moa.wxapi.WXPayEntryActivity) is vulnerable to StrandHogg 2.0

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (26) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (ynyd.mobile.moa.wxapi.WXEntryActivity) is vulnerable to StrandHogg 2.0

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (26) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (com.cmcc.miguhelpersdk.activity.SettingActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.cmcc.miguhelpersdk.activity.SettingFeedBackActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.cmcc.miguhelpersdk.activity.TtsVoicerActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.cmcc.miguhelpersdk.webview.WebViewActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.cmcc.miguhelpersdk.webview.TrainWebViewActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.richinfo.asrsdk.ui.AstMainActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.richinfo.asrsdk.ui.AstMainActivity) is vulnerable to StrandHogg 2.0

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (26) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.cloudscanner.homepage.CloudScannerMainActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.cloudscanner.homepage.ScannerDocumentActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.cloudscanner.homepage.ScannerPreviewActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.cloudscanner.homepage.IdentityPreviewActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.cloudscanner.homepage.ScannerReplaceActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.cloudscanner.homepage.ScannerSortOperationActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.imageselector.ImageSelectorActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (cn.richinfo.imageselector.ImageSelectorActivity2) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (26) 更新到 28 或更高版本以在平台级别修复此问题。

高危 SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击

SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#android-network-apis

Files:
com/intsig/scanner/c.java, line(s) 131,14,15,16
com/juphoon/as/cmcc/asavatar/ZpandHttp.java, line(s) 55,70,16,17,18,19,20
com/nostra13/universalimageloader/core/download/HttpUtil.java, line(s) 582,520,39,40,41,42,43,44,45

高危 默认情况下,调用Cipher.getInstance("AES")将返回AES ECB模式。众所周知,ECB模式很弱,因为它导致相同明文块的密文相同

默认情况下,调用Cipher.getInstance("AES")将返回AES ECB模式。众所周知,ECB模式很弱,因为它导致相同明文块的密文相同
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-block-cipher-mode

Files:
com/zj/mobile/message/utils/AESUtils.java, line(s) 45,66
com/zj/mobile/util/AESUtil.java, line(s) 76,123

高危 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击

如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-7

Files:
com/cmcc/miguhelpersdk/i5.java, line(s) 32,41,4
com/just/agentweb/UrlLoaderImpl.java, line(s) 99,103,5
com/msec/net/WebKit/WebView.java, line(s) 246,263,266,25,72,288

高危 WebView域控制不严格漏洞

WebView域控制不严格漏洞


Files:
asr_sdk/dy.java, line(s) 165,155
cls/mc.java, line(s) 138,128
com/cmcc/miguhelpersdk/webview/TrainWebViewActivity.java, line(s) 545,535
com/cmcc/miguhelpersdk/webview/WebViewActivity.java, line(s) 177,167
com/just/agentweb/AbsAgentWebSettings.java, line(s) 62,37
ynyd/mobile/moa/Web3Activity.java, line(s) 92,90,106,107

高危 应用程序在加密算法中使用ECB模式。ECB模式是已知的弱模式,因为它对相同的明文块[UNK]产生相同的密文

应用程序在加密算法中使用ECB模式。ECB模式是已知的弱模式,因为它对相同的明文块[UNK]产生相同的密文
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-block-cipher-mode

Files:
com/lzy/okgo/utils/AES.java, line(s) 19,28

高危 已启用远程WebView调试

已启用远程WebView调试
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
com/just/agentweb/AgentWebConfig.java, line(s) 47,10

高危 启用了调试配置。生产版本不能是可调试的

启用了调试配置。生产版本不能是可调试的
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
com/marswin89/marsdaemon/BuildConfig.java, line(s) 3,6
com/nostra13/universalimageloader/BuildConfig.java, line(s) 3,4
com/richinfo/scanqrcode/BuildConfig.java, line(s) 3,8

高危 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
cls/aj.java, line(s) 36
com/EIP/plugins/YNFingerprintLock/CryptoObjectCreator.java, line(s) 114
com/cmic/tyrz_android_common/utils/AESUtils.java, line(s) 15

中危 应用程序已启用明文网络流量

[android:usesCleartextTraffic=true]
应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。

中危 Activity (ynyd.mobile.moa.wxapi.WXPayEntryActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (ynyd.mobile.moa.wxapi.WXEntryActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity设置了TaskAffinity属性

(com.richinfo.asrsdk.ui.TranscriptionActivity)
如果设置了 taskAffinity,其他应用程序可能会读取发送到属于另一个任务的 Activity 的 Intent。为了防止其他应用程序读取发送或接收的 Intent 中的敏感信息,请始终使用默认设置,将 affinity 保持为包名

中危 Activity (com.richinfo.asrsdk.ui.AstMainActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (com.huawei.hms.support.api.push.service.HmsMsgService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Content Provider (com.huawei.hms.support.api.push.PushProvider) 未被保护。

[android:exported=true]
发现 Content Provider与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
cn/hutool/core/util/RandomUtil.java, line(s) 46
cn/richinfo/cloudscanner/utils/CommonUtil.java, line(s) 296
cn/richinfo/cloudscanner/utils/SdkAppUtils.java, line(s) 110,85
com/cmcc/miguhelpersdk/r1.java, line(s) 122
com/cmcc/miguhelpersdk/t2.java, line(s) 478
com/sdp/etrust/sdk/logic/HardwareInfoCollector.java, line(s) 121
com/zj/mobile/util/SHA1Util.java, line(s) 11,22
org/java_websocket/drafts/Draft_6455.java, line(s) 566

中危 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
cn/hutool/cache/impl/CacheObj.java, line(s) 30
cn/hutool/core/lang/Pair.java, line(s) 31
cn/hutool/core/lang/tree/TreeNodeConfig.java, line(s) 13,9,12,10,11
cn/richinfo/cloudscanner/entities/addressbook/ContactUserEntity.java, line(s) 252
cn/richinfo/cloudscanner/entities/ast/ShareWithEmail.java, line(s) 60
cn/richinfo/cloudscanner/utils/CommonUtil.java, line(s) 83,86
cn/richinfo/cloudscanner/utils/ConstantsApp.java, line(s) 125,99,20,19,128
com/cmcc/miguhelpersdk/v1.java, line(s) 24
com/cxp/imsdk/data/IMThirdCardMessage.java, line(s) 84
com/intsig/scanner/ScannerSDK.java, line(s) 13,14
com/lzy/okgo/cache/CacheEntity.java, line(s) 14,86
com/lzy/okgo/exception/CacheException.java, line(s) 7,11
com/lzy/okgo/utils/AES.java, line(s) 10
com/lzy/okgo/utils/RSAUtils.java, line(s) 22,23
com/lzy/okgo/utils/sm4/SM4EncDecUtils.java, line(s) 21
com/marswin89/marsdaemon/DaemonClient.java, line(s) 14
com/moa/quicknotify/utils/Constants.java, line(s) 9
com/nordnetab/chcp/main/config/FetchUpdateOptions.java, line(s) 9,10
com/nordnetab/chcp/main/events/WorkerEvent.java, line(s) 8
com/nordnetab/chcp/main/storage/PluginInternalPreferencesStorage.java, line(s) 9
com/richinfo/asrsdk/bean/ContactUserEntity.java, line(s) 259
com/richinfo/asrsdk/bean/ast/DispatchTaskBean.java, line(s) 195
com/richinfo/asrsdk/bean/ast/ReceivePeople.java, line(s) 155
com/richinfo/asrsdk/bean/ast/ShareWithEmail.java, line(s) 60
com/richinfo/asrsdk/bean/ast/SplitSectionBean.java, line(s) 183
com/sdp/etrust/sdk/LVSDPService.java, line(s) 105,106,111,112,113,73,99,97,101,123,124,125,132,129,133,136
com/yhao/floatwindow/FloatLifecycle.java, line(s) 13,14
com/zj/mobile/base/BaseGaussianBlurActivity.java, line(s) 134,133,131
com/zj/mobile/bingo/bean/CPNoticeInfo.java, line(s) 115
com/zj/mobile/bingo/bean/ServiceIdInfo.java, line(s) 194
com/zj/mobile/bingo/bean/SysMsg.java, line(s) 210
com/zj/mobile/bingo/impl/TempInjectionImpl.java, line(s) 91,92
com/zj/mobile/bingo/network/IMApi.java, line(s) 338,339,340
com/zj/mobile/init/IMInitialize.java, line(s) 85,119,117,79,80,125
com/zj/mobile/message/BuildConfig.java, line(s) 5,8,15
com/zj/mobile/message/activity/SelectForwardActivity.java, line(s) 94
com/zj/mobile/message/bean/UserInfoBean.java, line(s) 595
com/zj/mobile/message/database/entity/MessageDetail.java, line(s) 160
com/zj/mobile/message/quantum/EncryptFileBean.java, line(s) 70
com/zj/mobile/message/quantum/FileEncryptor$decryptFileSM4$2$1.java, line(s) 78,75
com/zj/mobile/message/quantum/alg/SM2Util.java, line(s) 25
com/zj/mobile/message/quantum/alg/SM4Tool.java, line(s) 27
com/zj/mobile/message/quantum/alg/SM4Util.java, line(s) 30
com/zj/mobile/message/utils/AESUtils.java, line(s) 15
com/zj/mobile/message/utils/DataConstants.java, line(s) 52,62,93,67,65,68,63,66
com/zj/mobile/message/utils/MiguUtils.java, line(s) 13
com/zj/mobile/message/utils/audio2text/ist/WebISTWS.java, line(s) 21
com/zj/mobile/util/AESUtil.java, line(s) 21
com/zj/mobile/util/CloudDocUtil.java, line(s) 24,26
org/java_websocket/drafts/Draft_6455.java, line(s) 57
org/jsoup/helper/W3CDom.java, line(s) 45
org/jsoup/nodes/Comment.java, line(s) 7
org/jsoup/nodes/DataNode.java, line(s) 7
org/jsoup/nodes/TextNode.java, line(s) 9
rx/internal/schedulers/NewThreadWorker.java, line(s) 26,35
wechat/Wechat.java, line(s) 83
xu/li/cordova/wechat/Wechat.java, line(s) 85,356

中危 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
asr_sdk/b.java, line(s) 17
asr_sdk/ch.java, line(s) 217,225
asr_sdk/ef.java, line(s) 70
asr_sdk/ek.java, line(s) 180,47,168,209
asr_sdk/ft.java, line(s) 7
cls/m1.java, line(s) 16,17,18,19,20
cls/oc.java, line(s) 10
cls/p.java, line(s) 194,1505,194,1507
cn/richinfo/cloudscanner/utils/AppPathHelp.java, line(s) 11,21,43
cn/richinfo/cloudscanner/utils/FileUtil.java, line(s) 992,1036
cn/richinfo/cloudscanner/utils/PicUtil.java, line(s) 116,127
cn/richinfo/cloudscanner/utils/cache/disk/DiskLruCacheHelper.java, line(s) 70
cn/richinfo/imageselector/ImageSelectorActivity.java, line(s) 226,265,284
cn/richinfo/imageselector/ImageSelectorActivity2.java, line(s) 170,209,228
com/cmcc/miguhelpersdk/j0.java, line(s) 26
com/cmcc/miguhelpersdk/player/SessionPlayer.java, line(s) 30
com/cmcc/miguhelpersdk/webview/TrainWebViewActivity.java, line(s) 60
com/cmic/promopush/a.java, line(s) 265
com/cmic/rzsdk/push_sdk/b.java, line(s) 87
com/example/miaow/picture/utils/AlbumUtils.java, line(s) 60,59
com/just/agentweb/AgentWebUtils.java, line(s) 166,443
com/lxj/xpopup/util/XPopupUtils.java, line(s) 378
com/lzy/okgo/convert/FileConvert.java, line(s) 26,43
com/moa/quicknotify/utils/ToolsUtils.java, line(s) 300
com/nostra13/universalimageloader/utils/StorageUtils.java, line(s) 23,56,57,67,68,77
com/orhanobut/logger/CsvFormatStrategy.java, line(s) 101
com/richinfo/image/FileUtils.java, line(s) 31,33,346,367
com/richinfo/util/NetworkLogUtil.java, line(s) 47
com/sdp/etrust/sdk/evaluationrules/EvaluationRule.java, line(s) 220
com/sdp/etrust/sdk/logic/InternalService.java, line(s) 114,115
com/yalantis/ucrop/util/FileUtils.java, line(s) 88
com/yanzhenjie/permission/FileProvider.java, line(s) 315,172
com/yanzhenjie/permission/checker/StorageReadTest.java, line(s) 10,13
com/yanzhenjie/permission/checker/StorageWriteTest.java, line(s) 10,13
com/zego/zegoavkit2/utils/ZegoLogUtil.java, line(s) 24,19,64
com/zj/mobile/bingo/dp/DatabaseContext.java, line(s) 19,23
com/zj/mobile/bingo/network/IMApi.java, line(s) 181
com/zj/mobile/bingo/util/CleanCacheUtil.java, line(s) 52
com/zj/mobile/bingo/util/FunctionUtils.java, line(s) 302
com/zj/mobile/message/activity/CameraMessageActivity.java, line(s) 84
com/zj/mobile/message/activity/DocReadActivity.java, line(s) 138
com/zj/mobile/message/activity/FileDownloadManagerActivity.java, line(s) 601,629
com/zj/mobile/message/activity/GroupChatSettingActivity.java, line(s) 1278
com/zj/mobile/message/activity/GroupSettingQrCodeActivity.java, line(s) 158
com/zj/mobile/message/activity/PlayVideoActivity.java, line(s) 67
com/zj/mobile/message/activity/SearchChatPhotoAndVideoActivity.java, line(s) 70
com/zj/mobile/message/activity/msgpourin/socket/utils/FileUtils.java, line(s) 41
com/zj/mobile/message/activity/readzip/ReadFileDetailActivity.java, line(s) 140
com/zj/mobile/message/record/RecordFileUtils.java, line(s) 10
com/zj/mobile/message/utils/FileUtils.java, line(s) 1444,63,72,207,983,1293,1294,1296,1432,1467,1577,1835,1854,1855
com/zj/mobile/message/utils/PhotoUtils.java, line(s) 44,45,46,47,48,49,50,51,490
com/zj/mobile/message/utils/ToolsUtils.java, line(s) 229,183,228
com/zj/mobile/message/utils/img/GetImgUtils.java, line(s) 33,82,86
com/zj/mobile/message/utils/pcm/ConvertMP3Utils.java, line(s) 23,24
com/zj/mobile/message/view/preview/MessageChatMediaPreviewActivity.java, line(s) 509,510
com/zj/mobile/util/AndroidFileSelector.java, line(s) 45
com/zj/mobile/util/ImageUtils.java, line(s) 126
com/zj/mobile/util/Log4jConfigure.java, line(s) 11,43
com/zj/mobile/util/LogcatHelper.java, line(s) 40,41
com/zlw/main/recorderlib/recorder/RecordConfig.java, line(s) 35,43,52
com/zlw/main/recorderlib/recorder/RecordHelper.java, line(s) 244
cordova/file/DirectoryManager.java, line(s) 14,18,19,34
cordova/file/FileUtils.java, line(s) 110,707,708,108,111,705,710
cordova/file/LocalFilesystem.java, line(s) 339
im/zego/zegoexpress/utils/ZegoLogUtil.java, line(s) 25,25,69
wechat/Util.java, line(s) 32,33
wechat/Wechat.java, line(s) 410
xu/li/cordova/wechat/Util.java, line(s) 32,33
xu/li/cordova/wechat/Wechat.java, line(s) 419
ynyd/mobile/moa/util/ContentUtil.java, line(s) 24
ynyd/mobile/moa/util/CrashManager.java, line(s) 79
ynyd/mobile/moa/util/FileUtil.java, line(s) 15,24

中危 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
cls/sg.java, line(s) 163
cn/hutool/core/io/FileUtil.java, line(s) 427
cn/hutool/core/net/multipart/UploadFile.java, line(s) 132
com/cmcc/miguhelpersdk/activity/AssistantActivity.java, line(s) 1093
com/journeyapps/barcodescanner/CaptureManager.java, line(s) 237
com/nanchen/compresshelper/FileUtil.java, line(s) 89
com/zj/mobile/message/database/SQLCipherUtils.java, line(s) 76,103
com/zj/mobile/message/utils/FileUtils.java, line(s) 1298,1301
com/zj/mobile/message/utils/pcm/SSRC.java, line(s) 2477

中危 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
cn/richinfo/cloudscanner/db/AsrErrorInfoDao.java, line(s) 4,32
cn/richinfo/cloudscanner/db/BitmapBeanCacheDao.java, line(s) 4,98
cn/richinfo/cloudscanner/db/BitmapBeanDao.java, line(s) 4,94
cn/richinfo/cloudscanner/db/CameraSettingEntityDao.java, line(s) 4,41
cn/richinfo/cloudscanner/db/ContactUserEntityDao.java, line(s) 4,50
cn/richinfo/cloudscanner/db/ExcelRecordEntityDao.java, line(s) 4,67
cn/richinfo/cloudscanner/db/PdfRecordEntityDao.java, line(s) 4,62
cn/richinfo/cloudscanner/db/ScannerResultEntityDao.java, line(s) 4,88
cn/richinfo/cloudscanner/db/TagEntityDao.java, line(s) 4,44
cn/richinfo/cloudscanner/db/TextRecordEntityDao.java, line(s) 4,47
cn/richinfo/cloudscanner/db/WordRecordEntityDao.java, line(s) 4,69
com/github/yuweiguocn/library/greendao/MigrationHelper.java, line(s) 5,101
com/lzy/okgo/db/DBHelper.java, line(s) 4,5,41
com/lzy/okgo/db/DBUtils.java, line(s) 4,12
com/raizlabs/android/dbflow/sql/language/BaseQueriable.java, line(s) 3,72
com/raizlabs/android/dbflow/structure/database/AndroidDatabase.java, line(s) 4,53
com/raizlabs/android/dbflow/structure/database/AndroidDatabaseStatement.java, line(s) 5,6,35
com/raizlabs/android/dbflow/structure/database/BaseDatabaseHelper.java, line(s) 3,58
com/richinfo/asrsdk/db/AsrErrorInfoDao.java, line(s) 4,32
com/richinfo/asrsdk/db/AstAudioUploadTaskDao.java, line(s) 4,31
com/richinfo/asrsdk/db/AudioRecordCacheDao.java, line(s) 4,47
com/richinfo/asrsdk/db/ContactUserEntityDao.java, line(s) 4,49
com/richinfo/asrsdk/db/ConvertRecordEntityDao.java, line(s) 4,76
com/richinfo/asrsdk/db/LinkNativeRecordEntityDao.java, line(s) 4,26
com/richinfo/asrsdk/db/RecordDetailDao.java, line(s) 4,58
com/richinfo/asrsdk/db/ResultVoiceDao.java, line(s) 4,55
io/sqlc/SQLiteAndroidDatabase.java, line(s) 4,5,6,7,515
net/sqlcipher/database/SQLiteDatabase.java, line(s) 1663,1683,940
org/greenrobot/greendao/AbstractDao.java, line(s) 6,7,119
org/greenrobot/greendao/DbUtils.java, line(s) 6,15
org/greenrobot/greendao/database/StandardDatabase.java, line(s) 5,15
sqlc/SQLiteAndroidDatabase.java, line(s) 5,6,7,8,9,548

中危 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
asr_sdk/fw.java, line(s) 643
cls/fh.java, line(s) 403
cls/p.java, line(s) 233,981,997
cn/hutool/core/lang/UUID.java, line(s) 64
cn/richinfo/cloudscanner/utils/CommonUtil.java, line(s) 1004
cn/richinfo/cloudscanner/utils/cache/disk/Utils.java, line(s) 73
com/cmcc/miguhelpersdk/x4.java, line(s) 115
com/cmic/data/sdk/log/i.java, line(s) 17,27
com/cmic/tyrz_android_common/utils/EncUtil.java, line(s) 52,67
com/cmic/tyrz_android_common/utils/MD5STo16Byte.java, line(s) 72
com/cmic/tyrz_android_common/utils/MD5Util.java, line(s) 14,39
com/intsig/scanner/CommonUtil.java, line(s) 116
com/intsig/scanner/ScannerSDK.java, line(s) 84
com/intsig/scanner/c.java, line(s) 61
com/just/agentweb/AgentWebUtils.java, line(s) 728
com/lzy/okgo/utils/MD5.java, line(s) 22
com/lzy/okgo/utils/RSAUtils.java, line(s) 38,46
com/moa/quicknotify/utils/ToolsUtils.java, line(s) 245
com/nordnetab/chcp/main/utils/MD5.java, line(s) 13
com/nostra13/universalimageloader/cache/disc/naming/Md5FileNameGenerator.java, line(s) 22
com/richinfo/image/FileUtils.java, line(s) 52
com/sdp/etrust/sdk/logic/HardwareInfoCollector.java, line(s) 123
com/zj/mobile/bingo/util/MD5Utils.java, line(s) 33,43,83,104
com/zj/mobile/message/activity/FileDownloadManagerActivity.java, line(s) 315
com/zj/mobile/message/activity/msgpourin/MsgPourinClientActivity.java, line(s) 472
com/zj/mobile/message/activity/msgpourin/SelectConversationActivity.java, line(s) 454
com/zj/mobile/message/database/MessageRepository.java, line(s) 263
com/zj/mobile/message/quantum/alg/AESUtil.java, line(s) 17,29,41,55
com/zj/mobile/message/utils/AESUtils.java, line(s) 41,62
com/zj/mobile/message/utils/FileUtils.java, line(s) 882
com/zj/mobile/util/AESUtil.java, line(s) 72,119
ynyd/mobile/moa/util/FileUtil.java, line(s) 30

中危 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
cls/c6.java, line(s) 36
cls/e7.java, line(s) 11
cls/p.java, line(s) 83
cls/u5.java, line(s) 35
cn/hutool/core/img/ImgUtil.java, line(s) 45
cn/hutool/core/util/ArrayUtil.java, line(s) 29
cn/hutool/core/util/NumberUtil.java, line(s) 14
cn/hutool/core/util/PrimitiveArrayUtil.java, line(s) 5
cn/hutool/core/util/RandomUtil.java, line(s) 19
cn/richinfo/cloudscanner/homepage/ExcelPreviewActivity.java, line(s) 49
cn/richinfo/cloudscanner/homepage/ScannerDocumentActivity.java, line(s) 86
cn/richinfo/cloudscanner/homepage/ScannerIdentityActivity.java, line(s) 53
cn/richinfo/cloudscanner/homepage/ScannerReplaceActivity.java, line(s) 76
cn/richinfo/cloudscanner/homepage/WordPreviewActivity.java, line(s) 57
com/cmcc/miguhelpersdk/u4.java, line(s) 3
com/cmcc/miguhelpersdk/webview/TrainWebViewActivity.java, line(s) 40
com/example/miaow/picture/utils/ActivityResultFragment.java, line(s) 12
com/zj/mobile/message/quantum/QuantumKeyManager.java, line(s) 10
com/zj/mobile/message/quantum/alg/AESUtil.java, line(s) 7
com/zj/mobile/message/quantum/alg/RSAUtil.java, line(s) 15
com/zj/mobile/message/quantum/alg/SM4Util.java, line(s) 14
com/zj/mobile/message/utils/ToolsUtils.java, line(s) 50
com/zj/mobile/message/utils/pcm/SSRC.java, line(s) 17
com/zj/mobile/util/AESUtil.java, line(s) 10
in/srain/cube/views/ptr/header/StoreHouseBarItem.java, line(s) 8
org/greenrobot/greendao/test/DbTest.java, line(s) 7
org/jsoup/helper/DataUtil.java, line(s) 15

中危 IP地址泄露

IP地址泄露


Files:
cls/jb.java, line(s) 570
cls/mc.java, line(s) 79
cls/qb.java, line(s) 17
cls/vb.java, line(s) 93
cn/hutool/core/net/MaskBit.java, line(s) 12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43
cn/hutool/core/net/NetUtil.java, line(s) 147,147,42,147,147,147,147
cn/hutool/crypto/asymmetric/Sign.java, line(s) 175
cn/richinfo/cloudscanner/CloudScannerInit.java, line(s) 152
cn/richinfo/cloudscanner/mine/WebViewWithOneTitleActivity.java, line(s) 252
com/moa/sdp/SDPUtil.java, line(s) 166
com/nostra13/universalimageloader/core/download/HttpUtil.java, line(s) 77
com/sdp/etrust/sdk/evaluationrules/SimulatorCheck.java, line(s) 139
com/sdp/etrust/sdk/logic/CharonVpnService.java, line(s) 611
ynyd/mobile/moa/BuildConfig.java, line(s) 8

中危 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
asr_sdk/dy.java, line(s) 230,156
asr_sdk/eb.java, line(s) 151,152,159
cls/mc.java, line(s) 152,129
cn/richinfo/cloudscanner/mine/WebViewWithOneTitleActivity.java, line(s) 603,604,611
com/cmcc/miguhelpersdk/webview/TrainWebViewActivity.java, line(s) 547,536
com/cmcc/miguhelpersdk/webview/WebViewActivity.java, line(s) 179,168
com/msec/MSecClient.java, line(s) 256,255
com/msec/net/WebKit/WebView.java, line(s) 75,76,74
ynyd/mobile/moa/Web3Activity.java, line(s) 277,296,91

中危 此应用程序可能会请求root(超级用户)权限

此应用程序可能会请求root(超级用户)权限
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md#testing-root-detection-mstg-resilience-1

Files:
com/scottyab/rootbeer/Const.java, line(s) 9,9,9,11,9,11,9,9

中危 应用程序包含隐私跟踪程序

此应用程序有多个1隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
华为HMS Core 应用ID的=> "com.huawei.hms.client.appid" : "appid=107769181"
"privatekey100" : "MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDLnm8M+5p4+NF+cvDm2XgS5VLGGgEE87h1dyzXiXSbOiLL0IWWUTHA8jES7qaeq9AGtArnqMPcX7VSbVyM0IzjF9eg7MBy4NKmUYbRN09q9xG87ENKPZTjdhzmmT8IyPBPX9Po7CnHHjWLz0zHkjmR6d+BosTBDC8rkA56uWIp+G/q3v36tbOsUIQJSxwaE9IGfUstGH5AMTghgPDkGiYQqydssJUEnpUGJcM+SQXLtuqTfBD6JP38P7d5ZbhZ3qBcojLuLfJyfSnk2TzQQUo/ru/vcwTAxHL5BRAwFu1c7OaOcMWXwCJ0wpuFxB/kxDXmtXMpIaVw8G1h8Rae1fB5AgMBAAECggEAUidIUwqo1qo9jDE/9URE6ArSjM8tHhxfjjVZSFVTUNXx+B3X6EA2PMz689KKM3bK5gl6ZOF4tM+AzxMExmPWlEGoZGthcng3RZebN4qDZnrtEzaYJ7oU+nlLS9cE0byRCNV3IIE4kfgkTpaDOfpLdA3SefF8RQ9vcLocvXNSoe+7eA08wiFN0RscW6hpHWqmx1vrA4kMXs+eU1Sj+4PZxLTfYibViTz3Zue7sKVaGY/ZEdrC9AlBGdPoVb2s+X+kbFLjZoyLPrHlNSzKUmcXtSkrlukZfgPpC/ptaBGK2um15x8BvQZGj27utFi2f1GoqQGXWlL19Ccv/uJyw76hIQKBgQD/7Vtj7GR6CYxOoiTINqc+ixGPLpU4V+hE4348R5bd3/YpjzstPw26TG1PgbvlSR6bdkb1rklm/BHoBeUpCuSowK3EYtVh8RTFAuoNjEJNc4Ya3CpZh4O8ZUKZGTHtZib09if8Fj3vzDPWFi8z5g3pXZb+hbrZpYKtJfRR71Bg3QKBgQDLrUQy9A9uAlV53RBS3SIkbzcfAND/Y2BjTo6DlRktz/F2PFrwYMGppCOVIl81tDQtGI/ak7Zc5pwe3OBSq9ESstRPoHi/fOKYg4AVdl1/dR0cQOCbgmSkES4DlWJ7v4Fe+BqKJj//1UCynzOJVujgLE8cmE2t7Qg1jgtGUegmTQKBgQCC/fIxCuXCsPBnrwY0lAS2NmgeaTFnTVdNK0OJhvrpRaCxVOZtGkDkggnREA4kJXDNEZTwWuynEY34vEu23iR7W2OViSC+qK6AyCUUGh41llOlm9rxSDNdUlbsFcFASXDXIMcGeDvraRF/Gou+fJnSQFzwmXIxxE1GYo7TATKa4QKBgE/eIsckQ0StL5143WTRCAlnfyLuLAZpjquCa4oXlmcLirEFm9d06Zw/HCDn+JPTlT41yns4vyMQ3xmPHXvtmi+N5olO8OqN60FJF5nS73kCkKa6nhj8+cAIaJXJJ3RFNVLrUWTo+OG2WwdwPEJXzTvSxDb/Vj6kmzp899jcV39lAoGAHp777h0wY9+/O0OxcihkqJNrLbWDlwG/qCKOAFMKo1T1PYooFCckvpAId+0BtcQjY+Efv2gsTMxp4RvOGBccA18BxslQhB+YRXwalV8wqsz/HqDgfFK2cdt2zJYQoqHhEiOtzxBDz5S4msvyT6a/4eGoB0HwKQ3+r0YLC33o8VU="
"library_android_database_sqlcipher_authorWebsite" : "https://www.zetetic.net/sqlcipher/"
97bd0b06bdb0722c965ce1cfcc920f
97b6b97bd19801ec9210c965cc920e
97bcf97c3598082c95f8c965cc920f
7f0e37f1487f595b0b0bb0b6fb0722
97b6b7f0e47f531b0723b0b6fb0722
0123456789ABCDEFGHJKLMNPQRSTUVWXYZ
e24b52a50a428f87039bFHCRElPNZRENcPFlPEBClRAUNAPRcCQS59f272
aXhjZ2lkMEhndktwM0RMTmZOWUZYUFVVNmZXbjh4U1IyZXIvYWYyYXlDWjc0TEZmTWdjRm9hOVFGeFFQQkppUytTMURtUmIyUlVlYW5YMElrdmtyY0RRUUNrZkdvc1JCMHpkVENZQlBCZU5Gd1Q1bVFaNzg4c0ZpU0xib2tUOER4K0NqY1U4bnRXKzc3WVRiUEl5RHYvT1dNN1hTUERPOEtzMUs2dXFUZjVmT2dlSUFCSnd4S0ROR2lUa1pkTlI2dmtCUGlpektTa09RTUk2UE4zUGVmYVkxL2xzUEhwaSt3WTVyRUxqTm1ZNXJ5NFpRU2RhY21GVjQ0M3ZBcENseFMxdzcrSkVwQUVrQTVDVVpVb0VCcnZmT3pMamJVcjlVbkdBWmp1dlJTMFF4VXVLbnVETWdIZU9jWUxJRnVFd1NCVDVuUjdXRG5JbXErdEdDb0s2WVdZOXZKUGNTQjN5U0dEUVFDODJPbFZJZGxpSEFVUVV6UU1PVS9xRE9mbE9FYTJNZ3RJVnhOdnlrbGNhMjg2aG9HWklYZVludUhPZXg0OUtWNWlGUkFKRXRaQkJYdkxhS3U3Qk9zZE9BQkpRczJwa3NxQXF5SVlKWFFYSENidys5amZpclpWK2t1Q25nUVVhM2pkY05SUmw1bXhCZG0zaXN6YlFPcHhsbDZBQStyT0VQNW16ek0vazVFWHAvLw
0b76fc1c95f399caa9f6F
258EAFA5-E914-47DA-95CA-C5AB0DC85B11
ngZlTTem7Pjdm1V9bJgQ6iQvFHsvT+vNgJ3wAIRd+iCMXm8y96yZhD2+SH5odBYS2
0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF
0418f27f51e63511fba650e94ba3da390fb3f4d9bd0c790d80e71098ae9fb548eeba334a4b6ee5d27b455eeb1faf6d59c89fb9e5e629deac61932096dccdfa6d61
97bcf97c3598082c95f8e1cfcc920f
fcfde86366c440e0aa7b0fdb95d215
ecd0221b322947c51236F
53f03e5df0af4e3363acF
nCOtV4S6o3r4VefeXdG1zglePu+WZoAMLzlgHBiCK3VDg2kyabIDi6X4MW2aeeRRv
97bd097bd097c35b0b6fc920fb0722
7f07e7f0e37f14998082b0787b0721
4037881ec3cc4efcb83b572247b72c25
MIICXAIBAAKBgQDPUajJJ4T9I9diQwYHzLfEN1wk7QlBPU2V1MDH7z10n8K2/X6q
b8bb0c071bbf460d82c33825b393b335
7800beddaa804106a91eb93df93ae313
97bcf97c359801ec95f8c965cc920f
7f0e37f0e37f14898082b0723b02d5
nKtz2gyN8fKaRfcrti/NeoTgAdw540WUq6Xtr8FnaInTN2kBCy9yuA1pvYQJANJSr
3D7D49C766D944FDE7DB9384DF846E0530DB5AEE
97bd097bd097c36b0b6fc9210c8dc2
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIejd8mN9ht7qkFOhj26wZvdCafMpfzquEd0io2X8ehDlWI+PUOmeldhdoq5NNK2vs9YKGAb74dOJqhxdTiQvbFe1Ve+8uUMepXFFfBSKXd5OVTGHCO7+WgbzzKt8rek8Kh/Ng6Ka9jYzgULZBhbfCyk0lJqvm2h0R0CDYUGLABQIDAQAB
ecd3f653b95511ab9431FHCRElPNZRENcPFlPEBClRAUNAPRcCQS550412
97bd07f1487f595b0b0bc920fb0722
7f07e7f0e47f531b0723b0b6fb0722
b027097bd097c36b0b6fc9274c91aa
nHM/X069dEXqI1sPItgtmu6bvLMsKu2XQ8wJAauUgo49YIzFGW5jAYTJx4a6OxcKr
7f0e397bd07f595b0b6fc920fb0722
97b6b97bd19801ec9210c9274c920e
9778397bd19801ec9210c9274c920e
vIDMwkjOt92YuUGbpJ2btFmbph2YuQXau02bkNXa39yL6MHc0RHa
97bcf7f0e47f531b0b0bb0b6fb0722
nGbDLUL1XdDl/Xz2ZwwJBALZ8g6Ksvn5HRB5EMhnI4lOC7NfPEZJzUMqGv7KEV0wY
CFUUBRUS3VjRI10Q1JmYXRjb0RWVFZncuZGRSV0NV90TtZVVBtGbtJEaHJ0MmZDahplVHJTcqd0U5UVaQFVTux2bp5GOrVXRNN0bNNVd4oEZrMzTUtUOs50N1c3d5MkYkBzd3MzSz92U45mWiNlYaRmQ5kzMyQjbB9UbyNFSvEFW1olM6hHV2YmSGFGUkFkSL9GNRVWUzF1YygzLysCe0gTUkVTevkGZZJXZvtybPJjcDF1ZCtUUpJ0QEFkTHRTQBVVUBJURRR0Mil0UHF3UDdEMB1kZHlUT
97bcf7f1487f595b0b0bb0b6fb0722
665f67f0e37f1489801eb072297c35
97b6b7f0e47f149b0723b0787b0721
ZGF0ajBFdzk0YUo3d1N3WDJnbzVQSVR3UTBVeGxkZlUveXBoNkd6SElCMExQUEFoWGNMZldDaXVDd1RJUCsxRVlpaHA5b05rM2p2cEVPOHdDRmhCcHcwQkFZZ0NFQUFCTWdBM01yelRqakpIbzJ4Q0hDSW5ZVkIzNU56SEEycmNhUThWRjVrVEJQc0l1U1hyTEZMRGE1Y1JTK0FnNXZuRE9YbDZsVzAyKzRnelhKTXpTVjlDdjZoajd5OWc4Mk5wb1ZKQk05Q0JXaHFSYjlzOXBpR3hvMjJBSDhwN0VjcDRMbVptNVBrUDJUeUJhYWRScWNHblJsaFhyUEdOeTBWdHlTczNNcFpla1hxQk5MQUJHb0FBRWdBZUpnZ3dJbUFDU0FBRkVRQUIwdzlHaWtocWtnQk5BREFCSUFlQ0lJTQ
6e0edc650f63d98ce700c16e292436b3
977837f0e37f14998082b0787b0721
97bd07f5307f595b0b0bc920fb0722
7f0e397bd097c36b0b6fc9210c8dc2
2f45ea58b78ff2e62dae2cb28a0be92e
87E9F32842FED280DC4FE8047D034BC4
aHR0cHM6Ly9iY3JzLmludHNpZy5uZXQvYmNyL0JDUlNES19VcGRhdGVfVXNhZ2VfMg==
7f0e27f1487f531b0b0bb0b6fb0722
AD42F6697B035B7580E4FEF93BE20BAD
cfa167fa7e9f24259b61b8e770fc3d6f
977837f0e37f149b0723b0787b0721
9778397bd097c36b0b6fc9210c91aa
96325C1CB3D9665D82AD3902A8DF8D14
1fe0e099c008441f9d27e2d1f2f6f67d
34388075-ef93-30f2-93fa-86d2a005f2f8
6fe006cbe30445928cc446ea589b49e0
neGnbOZS76UCTkz12XKS9pQxxPMe8v4SqatHKS+6ty38=
97b6b7f0e47f531b0723b0787b0721
9778397bd197c36c9210c9274c91aa
2c0230ccf6a14083b406748e605d4523
7f0e27f0e47f531b0723b0b6fb0722
977837f0e37f14998082b0723b06bd
97bcf7f1487f531b0b0bb0b6fb0722
7f0e37f5307f595b0b0bc920fb0722
977837f0e37f14898082b0723b02d5
1b53cfb7c459d48cb0ff12f423498a4470a3aaac09808e1d173ffb6a0eb3fb0a
e24b52a50a428f87039bF
53f03e5df0af4e3363acFHCRElPNZRENcPFlPEBClRAUNAPRcCQS59f272
7f0e397bd07f595b0b0bc920fb0722
665f67f0e37f14898082b0723b02d5
0123456789ABCDEFGHJKLMNPQRTUWXY
ef722153784341929b37f7cf68bac88f
nwofdMQZe9LULSnXMKS+NfkridZl+yIFlWo2BtojCEs9gjT0CQQDzHT3o1JurXcHb
7f0e397bd097c35b0b6fc920fb0722
ecd3f653b95511ab9431F
aHR0cHM6Ly9hcGkudGV4dGluLmNvbS9ib3NzL3Nkay9hdXRob3JpemF0aW9uL2FwcGx5
97bd09801d98082c95f8e1cfcc920f
97b6b97bd19801ec95f8c965cc920f
B3AB6394FA70419E9BA69CF8C9BDBF46
vMDMwkjOt92YuUGbpJ2btFmbph2YuQXau02bkNXa39yL6MHc0RHa
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCWuAuSCrzUXC1l4ixXBeBfotUtkALrAjLM5UHiVfOFHrRJHM41HSeHVm56UZHgJlwk80R8juu1ykuhkgrilTv7H+3MpZdIunvndDElgdgk8aI2Ip4GUlemUDvCtWd3ychWEh4kYQ8CeInQvNM08imoLFldvbjWt/IkGK+BcGzamQIDAQAB
9778397bd097c36b0b70c9274c91aa
70dbdd5ab614a6526198019fb5fc7ff2
vc0ASV5exmYjb2MoaHkmNHOIMgGNgFwN7AIu
7f0e37f0e366aa89801eb072297c35
9778397bd097c36b0b6fc9210c8dc2
7f0e37f0e37f14898082b072297c35
44656C69766572792D646174653A
1A45DFA3934282886D6174726F736B61
nYXZlKrTKMDLpCqAXBx0i5h6ZDgY8LtddoenYlhU2ZU2TYYppa/hmBRmcVK0Fci6D
97b6b97bd19801ec95f8c965cc920e
0aad91a8293b530cdb65bd73dfb426e2
9778397bd097c36c9210c9274c920e
977837f0e37f14998082b0787b06bd
7f0e26665b66a449801e9808297c35
7f0e37f1487f531b0b0bb0b6fb0722
833378ccbdc0e545938af4b12f567349
7f07e7f0e47f531b0723b0b6fb0721
7f0e27f0e47f531b0b0bb0b6fb0722
7ec967f0e37f14898082b0723b02d5
7f07e7f0e47f149b0723b0787b0721
04de25c1fb00f6199f8f1dcc4416ad74c83ee3384829031fd0c726454a7b0fbfd50ee7cac7509959fda0bb6a2f333a0cf7da84a340a81fd5aa8d8d3fea23a0c150
9778397bd19801ec9210c965cc920e
7f0e36665b66aa89801e9808297c35
9778397bd097c36b0b6fc9274c91aa
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC/YHP9utFGOhGk7Xf5L7jOgQz5
nVfBB1TwczWQXgzAfst6Qok30Y852Zjz0vVu3wc9hCTRJGVNaXnQtLr5ZM0GJPfkw
c9231594f6aa4e03971a227870500280
97bd097bd07f595b0b6fc920fb0722
nAoGAZHWwcVDqG3QbsWzC5lKoFbexud72phtbligTBo8CW5ny05NAprU1ls477uGu
7f0e36665b66a449801e9808297c35
97b6b7f0e47f531b0723b0b6fb0721
97b6b97bd197c36c9210c9274c920e
7f07e7f0e37f14998083b0787b0721
9778397bd097c36c9210c9274c91aa
7ec967f0e37f14998082b0787b06bd
H3UM16TDFPSBZJ90CW28QYRE45AXKNGV7L
vh9wGkfK8YmqbsoENP3764SeCX0dVzrgy1HRtpnTaLjJW2xQiZAcBMUFDu5
3df23883cc8f6a5aeaaff332b96a2bbb
7f0e397bd097c35b0b6fc9210c8dc2
65B0D69C422848E1B3857C4FA6342F7B
0b76fc1c95f399caa9f6FHCRElPNZRENcPFlPEBClRAUNAPRcCQS5c9482
70057A37ACBA6E7CF33D8240FB8891C350CA1D9C3F9382669E14AFAFBB45BE4678067A6DFD29D8E9EDE554AAB9A01A88
665f67f0e37f14898082b072297c35
5df0b57533a4c1cd1b1e87f0
7f07e7f0e37f149b0723b0787b0721
04e9668233582140b89b1bac8b603556
nJsAtj5bHAkEA2k64cKzxvHe4ql4cbz/EXddZjaQF7pA2kYd79W7uuGJDDeuSAPKu
7ec967f0e37f14998082b0787b0721
7f0e27f1487f595b0b0bb0b6fb0722
7ec967f0e37f14998082b0723b06bd

信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
ar/com/hjg/pngj/PngHelperInternal.java, line(s) 202,250
ar/com/hjg/pngj/ProgressiveOutputStream.java, line(s) 78
asr_sdk/ae.java, line(s) 48
asr_sdk/aq.java, line(s) 30
asr_sdk/ch.java, line(s) 427
asr_sdk/cx.java, line(s) 38,44
asr_sdk/dp.java, line(s) 484
asr_sdk/dq.java, line(s) 423,428,440,597,691,706,745,120,132,139,147,308,313,320,328,701,719,725,729,734
asr_sdk/dr.java, line(s) 740,761,957
asr_sdk/dw.java, line(s) 471
asr_sdk/eb.java, line(s) 173
asr_sdk/ek.java, line(s) 58,62,69,72,159,170,187,195,241,303,309
asr_sdk/f.java, line(s) 60
asr_sdk/fn.java, line(s) 77,86,154,160,172,188,200,204,205,226,227,247,253,259,276,279,295,305,371,408,416,428,429,499,500,520,524,543,571,617,637,663,673,713,719
asr_sdk/fr.java, line(s) 169,187,452,519,537,561,589,604,800,819,827,829,870,882,891,894,895,935,946,957,972,1021
asr_sdk/gf.java, line(s) 107
asr_sdk/gk.java, line(s) 19
asr_sdk/gt.java, line(s) 63,70
asr_sdk/gw.java, line(s) 42,49,56,63,69,75,76,83,88,96,100,104,107
asr_sdk/hb.java, line(s) 131,207,217,227,237,263
asr_sdk/it.java, line(s) 49
asr_sdk/jf.java, line(s) 11,17,27
cls/a2.java, line(s) 21
cls/ha.java, line(s) 304,306,308,310
cls/s1.java, line(s) 21
cls/t7.java, line(s) 15
cls/x5.java, line(s) 441,447,458,461,467
cls/y7.java, line(s) 297
cn/hutool/core/lang/Console.java, line(s) 89,118,11,40,85
cn/hutool/cron/Scheduler.java, line(s) 92
cn/hutool/cron/listener/TaskListenerManager.java, line(s) 55
cn/hutool/cron/timingwheel/TimingWheel.java, line(s) 39
cn/hutool/db/Db.java, line(s) 123,133
cn/hutool/db/dialect/DialectFactory.java, line(s) 28
cn/hutool/db/ds/GlobalDSFactory.java, line(s) 15,41
cn/hutool/extra/expression/engine/ExpressionFactory.java, line(s) 17
cn/hutool/extra/pinyin/engine/PinyinFactory.java, line(s) 17
cn/hutool/extra/template/engine/TemplateFactory.java, line(s) 23
cn/hutool/extra/tokenizer/engine/TokenizerFactory.java, line(s) 17
cn/hutool/log/dialect/jdk/JdkLogFactory.java, line(s) 31
cn/hutool/setting/Setting.java, line(s) 131
cn/hutool/setting/dialect/Props.java, line(s) 379
cn/hutool/socket/aio/AcceptHandler.java, line(s) 20
cn/hutool/socket/aio/SimpleIoAction.java, line(s) 13
cn/hutool/socket/nio/AcceptHandler.java, line(s) 15,24
cn/hutool/socket/nio/NioServer.java, line(s) 85
cn/richinfo/cloudscanner/CloudScannerInit.java, line(s) 187
cn/richinfo/cloudscanner/homepage/IdentityPreviewActivity.java, line(s) 1362,1365,1377,1388,1391,1397
cn/richinfo/cloudscanner/homepage/SinglePagePreViewActivity.java, line(s) 313,319,330,333,339
cn/richinfo/cloudscanner/utils/Base64Utils.java, line(s) 178,189,226,248,275,284
cn/richinfo/cloudscanner/utils/ScreenUtils.java, line(s) 176,177
cn/richinfo/cloudscanner/utils/cache/disk/DiskLruCache.java, line(s) 433
com/EIP/plugins/YNFingerprintLock/FingerprintCore.java, line(s) 153,82,150
com/EIP/plugins/YNFingerprintLock/YNFingerprintLock.java, line(s) 21,29,43,59,145
com/app/hubert/library/ScreenUtils.java, line(s) 33,56
com/appmanager/AppManager.java, line(s) 95
com/arthenica/mobileffmpeg/CameraSupport.java, line(s) 25,32
com/arthenica/mobileffmpeg/Config.java, line(s) 184,287,291,324,326,175,199,264,331,376,61,78,113,116,127,191,188,202,194
com/arthenica/mobileffmpeg/FFprobe.java, line(s) 37
com/arthenica/mobileffmpeg/MediaInformationParser.java, line(s) 14
com/cmcc/miguhelpersdk/activity/AssistantActivity.java, line(s) 284,1393,316,318,351,382,388,395,411,428,437,455,637,770,824,829,833,838,851,853,855,860,875,1058,1061,1154,1429,1579,1601,1630,1658,1668,1671,1687,1690,1695,1698,1709,1712,1715,1727,1730,1737,1742,653
com/cmcc/miguhelpersdk/b5.java, line(s) 111,116,202,210,232,264,463,468,471,482,485,488,500,507
com/cmcc/miguhelpersdk/d2.java, line(s) 40,28,30,32,45,48,70,71,73,78,80,83
com/cmcc/miguhelpersdk/e5.java, line(s) 52
com/cmcc/miguhelpersdk/g.java, line(s) 237,241,327
com/cmcc/miguhelpersdk/g2.java, line(s) 72
com/cmcc/miguhelpersdk/h.java, line(s) 192,199,210,217,228,235,246,253,264,309,317,325,333
com/cmcc/miguhelpersdk/h0.java, line(s) 25,89
com/cmcc/miguhelpersdk/i4.java, line(s) 25
com/cmcc/miguhelpersdk/m1.java, line(s) 23,29,51,71,91,111,133,154
com/cmcc/miguhelpersdk/m4.java, line(s) 37,50,58,66,69,75,89,91,100,106,111,141,211,215,217,227
com/cmcc/miguhelpersdk/n4.java, line(s) 61,120
com/cmcc/miguhelpersdk/o4.java, line(s) 95,177,185,218,226,243,382,384,265,242
com/cmcc/miguhelpersdk/player/SessionPlayer.java, line(s) 67,100,195,220,57,59,60,77,203,210,185,187,198
com/cmcc/miguhelpersdk/utils/RecordToFileUtil.java, line(s) 87
com/cmcc/miguhelpersdk/w4.java, line(s) 20,46
com/cmcc/miguhelpersdk/webview/TrainWebViewActivity.java, line(s) 113,162,215,223,393,399,405,411,417,433,449,459,465,470,711
com/cmcc/miguhelpersdk/y4.java, line(s) 12,18,24
com/cmic/data/sdk/log/g.java, line(s) 8,14,22,25,31
com/cmic/promopush/a/a.java, line(s) 105
com/cmic/promopush/c.java, line(s) 74,90
com/cmic/rzsdk/push_sdk/b.java, line(s) 537,304,529
com/cmic/tyrz_android_common/utils/RzLogUtils.java, line(s) 13,21,27,35,45
com/cmic/tyrz_android_common/utils/UrlUtils.java, line(s) 21,22,23,24
com/cxp/imsdk/IMInterface.java, line(s) 431,169,171,218
com/cxp/imsdk/IMSDKManage.java, line(s) 155,146,149
com/cxp/imsdk/callback/MtcImCallback.java, line(s) 285,292,299,306,313,320,326,333,339,346,352,359,365,372,378,385,391,398,404,411,432,513,519,600,606,242,256,272,277,577,583,588,594
com/dianping/logan/LoganThread.java, line(s) 137,173,195,202,241
com/dianping/logan/SendLogDefaultRunnable.java, line(s) 458
com/disusered/Open.java, line(s) 35
com/example/miaow/picture/dialog/PictureClipDialog.java, line(s) 182
com/example/miaow/picture/dialog/PictureEditorDialog.java, line(s) 471,496
com/example/miaow/picture/editor/PictureEditorView.java, line(s) 261
com/github/barteksc/pdfviewer/PDFView.java, line(s) 290,553,791
com/github/barteksc/pdfviewer/RenderingHandler.java, line(s) 74
com/github/barteksc/pdfviewer/link/DefaultLinkHandler.java, line(s) 36
com/github/yuweiguocn/library/greendao/MigrationHelper.java, line(s) 253,85,202
com/hp/hpl/sparta/ParseByteStream.java, line(s) 117
com/hp/hpl/sparta/ParseCharStream.java, line(s) 136,394,498,589,706,842
com/hp/hpl/sparta/ParseException.java, line(s) 56
com/hutchind/cordova/plugins/launcher/Launcher.java, line(s) 71,76,80,102,131,149,153,161,313,314,210,218,226,246,254,286,301,306,308,310,338,360,387,406,164,348
com/initialxy/cordova/themeablebrowser/ThemeableBrowser.java, line(s) 245,860,871,896,905,917
com/journeyapps/barcodescanner/CameraPreview.java, line(s) 610,629,126,225,324,707,481,687
com/journeyapps/barcodescanner/CaptureManager.java, line(s) 90,243
com/journeyapps/barcodescanner/DecoderThread.java, line(s) 108
com/journeyapps/barcodescanner/camera/AutoFocusManager.java, line(s) 60,84,101
com/journeyapps/barcodescanner/camera/CameraInstance.java, line(s) 24,36,51,64,28,43,56,68
com/journeyapps/barcodescanner/camera/CameraManager.java, line(s) 54,163,193,231,159,165,245,253
com/journeyapps/barcodescanner/camera/CenterCropStrategy.java, line(s) 27
com/journeyapps/barcodescanner/camera/FitCenterStrategy.java, line(s) 27
com/journeyapps/barcodescanner/camera/LegacyPreviewScalingStrategy.java, line(s) 42,43,73
com/journeyapps/barcodescanner/camera/PreviewScalingStrategy.java, line(s) 22,23
com/juphoon/as/cmcc/asavatar/ZpandTimer.java, line(s) 71,76,80
com/juphoon/cmcc/app/lemon/MtcCliHelper.java, line(s) 50
com/just/agentweb/AgentWebUtils.java, line(s) 362,342,355,374,375
com/just/agentweb/AgentWebView.java, line(s) 70,195,210,233,58,62,245
com/just/agentweb/DefaultChromeClient.java, line(s) 231,238
com/just/agentweb/JsCallJava.java, line(s) 187,68,44,81
com/just/agentweb/JsCallback.java, line(s) 46
com/just/agentweb/LogUtils.java, line(s) 28,32,37,14,20
com/lxj/xpopup/util/XPermission.java, line(s) 346
com/lxj/xpopup/widget/SmartDivider.java, line(s) 27
com/lzy/okgo/RichNet.java, line(s) 233,242
com/lzy/okgo/utils/AES.java, line(s) 33,37
com/lzy/okgo/utils/LogUtil.java, line(s) 65,71,73
com/lzy/okgo/utils/OkLogger.java, line(s) 34,64,44,24,54
com/lzy/okgo/utils/RSAUtils2.java, line(s) 153,154,155,156,157,162,163,164,165,166
com/lzy/okgo/utils/sm4/SM4EncDecUtils.java, line(s) 60
com/manna/audio/AudioCapture.java, line(s) 34,43,49,60,89
com/manna/audio/AudioPlayService.java, line(s) 59
com/manna/audio/AudioPlayer.java, line(s) 71,74
com/manna/audio/utils/FFT.java, line(s) 102,103,105,107,132
com/manna/audio/utils/FftFactory.java, line(s) 22
com/marswin89/marsdaemon/strategy/DaemonStrategy22.java, line(s) 125
com/marswin89/marsdaemon/strategy/DaemonStrategy23.java, line(s) 142
com/marswin89/marsdaemon/strategy/DaemonStrategyXiaomi.java, line(s) 117
com/moa/asrsdk/Asrsdk.java, line(s) 66,18,57,61,71
com/moa/cloudscanner/CloudScanner.java, line(s) 18,82,112,73,77,87,93,99,109
com/moa/commonplugin/CommonPlugin.java, line(s) 34,175
com/moa/commonplugin/im/IMPlugin.java, line(s) 50,53,67,79,107,74
com/moa/quicknotify/widget/SectionDecoration.java, line(s) 97
com/moa/sdp/MoaSDP.java, line(s) 14
com/moa/sdp/SDPUtil.java, line(s) 163
com/msec/C0156b.java, line(s) 136
com/msec/C0159e.java, line(s) 12,26
com/nanchen/compresshelper/FileUtil.java, line(s) 75,78
com/nineoldandroids/animation/PropertyValuesHolder.java, line(s) 148,176,222,240,242,259,261,297,299,425,427,515,517
com/nordnetab/chcp/main/HotCodePushPlugin.java, line(s) 83,259,273,390,395,411,430,437,454,466,472,475,490,516,529,549,552
com/nordnetab/chcp/main/config/ApplicationConfig.java, line(s) 45,68,80,94
com/nordnetab/chcp/main/network/FileDownloader.java, line(s) 24
com/nordnetab/chcp/main/updater/UpdateLoaderWorker.java, line(s) 46,87,114,123
com/nordnetab/chcp/main/utils/CleanUpHelper.java, line(s) 51
com/nordnetab/chcp/main/utils/URLUtility.java, line(s) 25
com/nordnetab/chcp/main/utils/VersionHelper.java, line(s) 15,24
com/nostra13/universalimageloader/cache/disc/impl/ext/DiskLruCache.java, line(s) 139
com/nostra13/universalimageloader/core/assist/ViewScaleType.java, line(s) 63
com/nostra13/universalimageloader/core/download/HttpUtil.java, line(s) 829,846
com/petterp/floatingx/impl/control/FxBasisControlImpl.java, line(s) 268,411,440,497
com/petterp/floatingx/impl/lifecycle/FxLifecycleCallbackImpl.java, line(s) 127,197,224,239,255,287
com/petterp/floatingx/util/FxLog.java, line(s) 42,52,47
com/petterp/floatingx/view/FxMagnetView.java, line(s) 101,366,428,472,486,500,513,553,242,616,148,201,298
com/raizlabs/android/dbflow/config/FlowLog.java, line(s) 20,38,48,26,14,32,45
com/richinfo/asrsdk/ui/AudioTranslateDetailActivity.java, line(s) 951
com/richinfo/asrsdk/ui/ImportAudioDetailActivity.java, line(s) 1426,1436,1770
com/richinfo/asrsdk/ui/dialog/VoiceQuickInputDialog.java, line(s) 228,230,381,1431,1474,1530,1535,1104,1114,171,184,394,398,399,447,614,629,688,699,899,924,927,929,961,1025,1126,1325,1337,1348,1359,1379,1419
com/richinfo/asrsdk/ui/voicequickinput/VoiceQuickInputActivity.java, line(s) 201,204,807,1052,427,430,674,702,714,716,719,806,1051,1091,1125
com/richinfo/scanqrcode/ScanActivity.java, line(s) 77,100,103
com/richinfo/scanqrcode/customView/ViewAdapt.java, line(s) 51,134
com/richinfo/scanqrcode/zxing/BGAQRCodeUtil.java, line(s) 43,49
com/richinfo/share/TestActivity.java, line(s) 50,62,74
com/scottyab/rootbeer/RootBeer.java, line(s) 119,132,143,183,242,99,165,197
com/scottyab/rootbeer/RootBeerNative.java, line(s) 17
com/scottyab/rootbeer/util/QLog.java, line(s) 64,20,21,22,23,29,30,58,70,42,43,44,45,51,52
com/sdp/etrust/sdk/LVSDPService.java, line(s) 260,176
com/sdp/etrust/sdk/evaluationrules/EvaluationRule.java, line(s) 150
com/sdp/etrust/sdk/evaluationrules/LocationInfoManager.java, line(s) 97,103,108,113,118
com/sdp/etrust/sdk/evaluationrules/NetworkOperatorCheck.java, line(s) 148
com/sdp/etrust/sdk/logic/AuthService.java, line(s) 428
com/sdp/etrust/sdk/logic/AuthStateManager.java, line(s) 265,283
com/sdp/etrust/sdk/logic/CharonVpnService.java, line(s) 321,273,294,466,644
com/sdp/etrust/sdk/logic/HardwareInfoCollector.java, line(s) 32,125,140
com/sdp/etrust/sdk/logic/InternalService.java, line(s) 269,277,287,293,301,307,313,321,335,341,348,354,360,366,374,386,397,405,411,419,425,431,439,447,455,463,471,477,485,493,501,645,654,721,750,775,794,827,868,641,661,669,678,689,704,714,726,831,834,843,863
com/sdp/etrust/sdk/logic/NetworkManager.java, line(s) 64,80,107
com/sdp/etrust/sdk/tools/LogManager.java, line(s) 96
com/sdp/etrust/sdk/tools/xmlParser.java, line(s) 67,70,74,78,1081,1083,1086,1089
com/shockwave/pdfium/PdfiumCore.java, line(s) 111,86,231,235,265,269
com/xuhao/didi/core/iocore/ReaderImpl.java, line(s) 38,39,42,43,130,131,132
com/xuhao/didi/core/iocore/WriterImpl.java, line(s) 58,59,60
com/xuhao/didi/core/utils/SLog.java, line(s) 16,22
com/xuhao/didi/socket/client/impl/client/ConnectionManagerImpl.java, line(s) 121,131,149,256,54,56,62,76,81,84,89,157,160,165,200,225,229,240,295
com/xuhao/didi/socket/client/impl/client/ManagerHolder.java, line(s) 45
com/xuhao/didi/socket/client/impl/client/action/ActionDispatcher.java, line(s) 210
com/xuhao/didi/socket/client/impl/client/iothreads/DuplexReadThread.java, line(s) 42
com/xuhao/didi/socket/client/impl/client/iothreads/DuplexWriteThread.java, line(s) 42
com/xuhao/didi/socket/client/impl/client/iothreads/IOThreadManager.java, line(s) 55,58
com/xuhao/didi/socket/client/impl/client/iothreads/SimplexIOThread.java, line(s) 54
com/xuhao/didi/socket/client/sdk/client/connection/DefaultReconnectManager.java, line(s) 43,115,119,122,136
com/xuhao/didi/socket/common/interfaces/basic/AbsLoopThread.java, line(s) 40,70,75
com/xuhao/didi/socket/common/interfaces/utils/SPIUtils.java, line(s) 10,19
com/xuhao/didi/socket/server/impl/ServerManagerImpl.java, line(s) 38,35
com/xuhao/didi/socket/server/impl/iocore/ClientReadThread.java, line(s) 42
com/xuhao/didi/socket/server/impl/iocore/ClientWriteThread.java, line(s) 42
com/yalantis/ucrop/UCropActivity.java, line(s) 155
com/yalantis/ucrop/task/BitmapCropTask.java, line(s) 150,117
com/yalantis/ucrop/task/BitmapLoadTask.java, line(s) 126,154,197,87,90,132,141,148
com/yalantis/ucrop/util/BitmapLoadUtils.java, line(s) 103,51,82
com/yalantis/ucrop/util/EglUtils.java, line(s) 28
com/yalantis/ucrop/util/FileUtils.java, line(s) 60,96
com/yalantis/ucrop/util/ImageHeaderParser.java, line(s) 54,61,72,80,112,122,134,148,162,168,172,177,183,187,290,53,60,71,79,111,121,133,147,161,167,171,176,182,186
com/yalantis/ucrop/view/TransformImageView.java, line(s) 218,235,125,79
com/yanzhenjie/permission/runtime/LRequest.java, line(s) 73
com/yanzhenjie/permission/runtime/MRequest.java, line(s) 119
com/yhao/floatwindow/LogUtil.java, line(s) 16,12
com/zego/ve/AudioDevice.java, line(s) 237,245,292,520,531,535,417,431
com/zego/ve/AudioDeviceHelper.java, line(s) 262,270,274,277,290,295
com/zego/ve/AudioEventMonitor.java, line(s) 231,272,290,312,421,443,73,270,285,310,352,358,375,391,221,366,381
com/zego/ve/FileMediaDataSource.java, line(s) 14,21,24,28
com/zego/ve/HwAudioKit.java, line(s) 131,164,81
com/zego/ve/KaraokeHelper.java, line(s) 122
com/zego/ve/Log.java, line(s) 71
com/zego/ve/MediaCodecVideoDecoder.java, line(s) 78,148,150,171,200,236,241,253,291,313,328,344,346,358,365,375,391,395,397,516,532,570,580,591,317,334,338,361,381,384,404,413,427,441,455,608,83,88,93,98,174,178
com/zego/ve/MediaCodecVideoEncoder.java, line(s) 198,306,353,366,370,426,428,459,469,481,503,530,545,554,563,583,587,622,624,696,709,713,731,808,863,879,287,393,535,569,572,577,601,653,664,715,721,724,766,776,840,897,749,752,758,203,208,213,218,274,278,319,323
com/zego/ve/VCam.java, line(s) 194,209,269,345,689,695,708,712,844,890,899,926,934,1021,1032,1052,1063,1101,1107,1138,1151,1195,1210,1226,1236,1244,1260,1273,1282,1290,1309,1353,1507,1670,1697,1709,1756,1893,1984,2018,2034,2054,2093,2123,2139,2161,2170,2178,2196,181,187,256,262,296,357,358,547,582,668,731,802,825,886,897,963,965,967,973,1026,1057,1136,1149,1162,1184,1192,1270,1298,1306,1441,1447,1453,1472,1480,1546,1628,1642,1695,1707,1720,1771,1778,1787,1848,1899,2009,2015,2039,2059,2115,2158,2187,2193,698
com/zego/ve/VImageReader.java, line(s) 125,67,70,99,102
com/zego/ve/VSurTex.java, line(s) 42
com/zego/zegoavkit2/receiver/Background.java, line(s) 84
com/zj/mobile/base/BaseActivity.java, line(s) 147,168,432,457,490,531
com/zj/mobile/base/IMLoginCallbackAction.java, line(s) 63,97,139,239
com/zj/mobile/bingo/dp/DatabaseContext.java, line(s) 20
com/zj/mobile/bingo/dp/DbDao.java, line(s) 116,154
com/zj/mobile/bingo/ui/MultiImageSelectorActivity.java, line(s) 71,74,234,346,360,377,383
com/zj/mobile/bingo/util/ContactUtils.java, line(s) 344,311
com/zj/mobile/bingo/util/DateUtil.java, line(s) 58
com/zj/mobile/bingo/util/FunctionUtils.java, line(s) 258,401
com/zj/mobile/bingo/util/LogUtil.java, line(s) 47,64,81
com/zj/mobile/bingo/util/MD5Utils.java, line(s) 54
com/zj/mobile/bingo/util/location/LocationUtil.java, line(s) 92,109
com/zj/mobile/bingo/view/ViewAdapt.java, line(s) 137
com/zj/mobile/bingo/view/preview/editor/PreviewEditorAllFragmentActivity.java, line(s) 293
com/zj/mobile/bingo/view/preview/editor/PreviewEditorFragmentActivity.java, line(s) 264
com/zj/mobile/bingo/view/preview/editor/callback/GridAdapter.java, line(s) 120
com/zj/mobile/bingo/view/preview/editor/callback/ItemTouchCallBack.java, line(s) 25,34,41,47,53
com/zj/mobile/init/InitMMKV.java, line(s) 56,62,65
com/zj/mobile/init/utils/IMFileUtils.java, line(s) 196
com/zj/mobile/init/utils/IMInitUtils.java, line(s) 121
com/zj/mobile/init/utils/IMNetWorkUtils.java, line(s) 13,14
com/zj/mobile/message/activity/AddGroupByQrCodeActivity.java, line(s) 198
com/zj/mobile/message/activity/DocReadActivity.java, line(s) 140,143,170,178
com/zj/mobile/message/activity/ForwardOrgContactActivity.java, line(s) 331,420
com/zj/mobile/message/activity/MessageChatActivity.java, line(s) 10874,10879,10914,14036,14041,14074,1366,1446,1662,7860,8909,9197,7000,7015,10908,13909,14068
com/zj/mobile/message/activity/MessageDetailListActivity.java, line(s) 385
com/zj/mobile/message/activity/MessageSelectContactsActivity.java, line(s) 885,910
com/zj/mobile/message/activity/PCLoginLogoutActivity.java, line(s) 116
com/zj/mobile/message/activity/PhotoPreviewActivity.java, line(s) 200
com/zj/mobile/message/activity/PhotoViewPagerActivity.java, line(s) 184,648
com/zj/mobile/message/activity/PlayVideoActivity.java, line(s) 327
com/zj/mobile/message/activity/SearchContactsActivity.java, line(s) 635
com/zj/mobile/message/activity/SearchContactsAllActivity.java, line(s) 525
com/zj/mobile/message/activity/SelectForwardActivity.java, line(s) 901,1356,1602,1659,1868,1903
com/zj/mobile/message/activity/choose/ChooseCommonGroupActivity.java, line(s) 572
com/zj/mobile/message/activity/choose/ChooseOrgContactsActivity.java, line(s) 430,551
com/zj/mobile/message/activity/choose/common/ForwardUtils.java, line(s) 708,1244,1455,1512
com/zj/mobile/message/activity/commongroup/CommonGroupDetailActivity.java, line(s) 373
com/zj/mobile/message/activity/msgconvenient/adapter/TreatMsgConvenientListAdapter.java, line(s) 282,286
com/zj/mobile/message/activity/msgpourin/socket/ClientPeer.java, line(s) 95,104,156,220,254,272,283
com/zj/mobile/message/activity/msgpourin/socket/ServerPeer.java, line(s) 69,117,230,241
com/zj/mobile/message/activity/msgpourin/socket/io/SocketConnection.java, line(s) 122
com/zj/mobile/message/activity/msgpourin/socket/utils/SHAUtil.java, line(s) 74
com/zj/mobile/message/activity/readzip/ReadFileDetailActivity.java, line(s) 142,145,160,168
com/zj/mobile/message/adapter/ChatMediaMsgAdapter.java, line(s) 209
com/zj/mobile/message/adapter/MessageChatTypesAdapter.java, line(s) 201,246
com/zj/mobile/message/adapter/SearchChatMsgPhotoItemAdapter.java, line(s) 154
com/zj/mobile/message/adapter/TopicMessageChatTypesAdapter.java, line(s) 203,248
com/zj/mobile/message/bean/ImThirdAppPushData.java, line(s) 26
com/zj/mobile/message/database/MessageRepository.java, line(s) 768,773,1378,1418,1427,1447,1457,1463,1498,1504,1514,1520,1530,1535,1540,1545,1571,1577,1608,1613,1624,1629,1640,1646,1651,1987,1993,459,853,1025,1145,2408,1878
com/zj/mobile/message/fragment/MessageFragment.java, line(s) 1588,1676,1735,1771,1823,1895,1947,2568
com/zj/mobile/message/processor/MessageProcessCentral.java, line(s) 211,226,243,248,268,283,293,302,383,398,415,420,439,449,459,495,191
com/zj/mobile/message/processor/ProcessorResult.java, line(s) 201
com/zj/mobile/message/processor/template/ReplyTransparentProcessor.java, line(s) 118,125
com/zj/mobile/message/processor/template/TemplateNoticeProcessor.java, line(s) 43
com/zj/mobile/message/quantum/alg/AESUtil.java, line(s) 80,83,87
com/zj/mobile/message/quantum/alg/RSAUtil.java, line(s) 148,151,155,156,157,158,159
com/zj/mobile/message/quantum/alg/SM2Util.java, line(s) 36,50,64,76,78,80,82,88,90
com/zj/mobile/message/quantum/alg/SM4Util.java, line(s) 158,159,160,168
com/zj/mobile/message/utils/AESUtils.java, line(s) 48,70
com/zj/mobile/message/utils/AndroidBarUtils.java, line(s) 69,71,73
com/zj/mobile/message/utils/AppTrackUtil.java, line(s) 47,60,63,105,114,123
com/zj/mobile/message/utils/AriaTaskModule.java, line(s) 114
com/zj/mobile/message/utils/BurnMessageManager.java, line(s) 52
com/zj/mobile/message/utils/CompressUtil.java, line(s) 172,217,246,366,371,384
com/zj/mobile/message/utils/DateUtils.java, line(s) 93,149,156,220
com/zj/mobile/message/utils/FileUtils.java, line(s) 1326,1337,1339,1346,1348,1391,1393,1423,1434,1451,1459,1502,1504,1530,1545,1555,1561,1588,1592,1599,1602,401,1258,1262,1266,1803,73,74
com/zj/mobile/message/utils/LocalThreadPools.java, line(s) 50,51,52
com/zj/mobile/message/utils/MediaManager.java, line(s) 147
com/zj/mobile/message/utils/NetworkReceiver.java, line(s) 35,41,45
com/zj/mobile/message/utils/SerialTasks.java, line(s) 45,47,64,68
com/zj/mobile/message/utils/ThreadExecutorUtils.java, line(s) 47
com/zj/mobile/message/utils/ToolsUtils.java, line(s) 923,945,937
com/zj/mobile/message/utils/audio2text/ist/RealWebISTWS.java, line(s) 37,84,90,95,109,114,121,127,136,137,146,154
com/zj/mobile/message/utils/audio2text/ist/WebISTWS.java, line(s) 36,66,67,77,81,92,99,104,113,114,123
com/zj/mobile/message/utils/audio2text/service/WsGatewayService.java, line(s) 30,31,49,50
com/zj/mobile/message/utils/helper/ViewHolderHelperOfVideo.java, line(s) 51
com/zj/mobile/message/utils/pcm/ConvertMP3Utils.java, line(s) 106,177,188,207,209,219,145,190,221
com/zj/mobile/message/utils/pcm/SSRC.java, line(s) 3015,3041,63,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,290,294,297,2268,2282,2361,2393,2394,2395,2396,2401,2404,2407,2409,2471,2562,2700,2840,2913,2932,2933,2934,2935,2937,2940,2943,2946,3004
com/zj/mobile/message/utils/texthighlight/PinYinUtils.java, line(s) 54,62
com/zj/mobile/message/view/preview/MessageChatMediaPreviewActivity.java, line(s) 237
com/zj/mobile/message/view/preview/MessageChatVideoPreviewFragment.java, line(s) 156,164
com/zj/mobile/message/viewholder/CustomTipViewHolder.java, line(s) 44
com/zj/mobile/message/viewholder/SubContentAudio.java, line(s) 289
com/zj/mobile/message/widget/CustomPopWindow.java, line(s) 175,176,182
com/zj/mobile/message/widget/RecordButton.java, line(s) 218,281,295,349,352,388,446,456,499,514,337,340,344
com/zj/mobile/message/widget/RecordOldButton.java, line(s) 246,290,309,317,319,376,459,462,469,429,437
com/zj/mobile/message/widget/StickyItemDecoration.java, line(s) 218,265,278,288
com/zj/mobile/message/widget/SwipeRecyclerView.java, line(s) 152,162,167
com/zj/mobile/message/widget/datetime/DateTimePicker.java, line(s) 84,130
com/zj/mobile/message/widget/emoji/newEmoji/EmojiRecyclerLayout.java, line(s) 107,132
com/zj/mobile/push/pushutil/HWPushUtil.java, line(s) 64,79,102,123,36,49,55,57,77,86,97,120,140
com/zj/mobile/push/receiver/HWPushReceiver.java, line(s) 59,63,25,29,23,35,38
com/zj/mobile/util/AESUtil.java, line(s) 79
com/zj/mobile/util/GZipUtil.java, line(s) 24,56
com/zj/mobile/util/ImCloudDocMapping.java, line(s) 194
com/zj/mobile/util/Log4jConfigure.java, line(s) 31,34
com/zj/mobile/util/LogUtil.java, line(s) 93,29,46,63,80
com/zj/mobile/util/MoaApiGetWay.java, line(s) 78
com/zj/mobile/util/NetworkReceiver.java, line(s) 35,41,45
com/zj/mobile/util/SHA1Util.java, line(s) 33
com/zj/mobile/util/SPUtils.java, line(s) 271
com/zj/mobile/util/TimeUtils.java, line(s) 82,83
com/zlw/main/recorderlib/utils/Logger.java, line(s) 91,100,109,118,148,157,193,202,211,220
de/mindpipe/android/logging/log4j/LogCatAppender.java, line(s) 48,51,75,78,57,60,39,42,66,69,86,88
de/mindpipe/android/logging/log4j/LogConfigurator.java, line(s) 76
filechooser/FileChooser.java, line(s) 56
im/zego/zegoexpress/internal/ZegoExpressEngineInternalImpl.java, line(s) 159
im/zego/zegoexpress/utils/ZegoLibraryLoadUtil.java, line(s) 84,102
in/srain/cube/views/ptr/PtrFrameLayout.java, line(s) 195,210,211,239,252,302,416,486,495,516,522,531,542,755,766,859,325,334,353,458,475,507,549,579,287,371,807,820
in/srain/cube/views/ptr/util/PtrCLog.java, line(s) 46,56,63,118,128,135,70,80,87,22,29,39,94,104,111,142,152,159
io/sqlc/SQLiteAndroidDatabase.java, line(s) 472,483,47,61,124,167,184,197,224,249,266,294,311,336,355,362,389,405,433,528,532,549
io/sqlc/SQLiteConnectorDatabase.java, line(s) 36,80,91,69,156,161
io/sqlc/SQLitePlugin.java, line(s) 34,38,115,135,194,217,232,284,302,313,319,160,254,258
me/rahul/plugins/sqlDB/DatabaseHelper.java, line(s) 37,38,77
me/rahul/plugins/sqlDB/sqlDB.java, line(s) 81,107
me/shouheng/icamera/CameraView.java, line(s) 273,389,394,398,495,525
me/shouheng/icamera/config/ConfigurationProvider.java, line(s) 342,378,401,300,267
me/shouheng/icamera/config/calculator/impl/CameraSizeCalculatorImpl.java, line(s) 47,58,68,84,96,108,120
me/shouheng/icamera/config/size/AspectRatio.java, line(s) 99
me/shouheng/icamera/manager/impl/BaseCameraManager.java, line(s) 639,647,650,653,912
me/shouheng/icamera/manager/impl/Camera1Manager.java, line(s) 57,82,135,151,351,595,664,669,674,677,697,120,165,444,597,756,955,960,965,1023,1056,441,256
me/shouheng/icamera/manager/impl/Camera2Manager.java, line(s) 217,269,703,725,754,760,786,831,930,1027,158,223,232,240,283,326,372,411,662,666,701,720,921,935,988,1034,1113,1124,1138,1200,1252,1325,1353,1488,1493,1498,1519,337,340,364,381,384,422,425,428,583,1132,1249
me/shouheng/icamera/util/CameraHelper.java, line(s) 265,329,68,279
me/shouheng/icamera/util/ImageHelper.java, line(s) 73,115
me/shouheng/icamera/util/XLog.java, line(s) 28,52,36,20,44
me/shouheng/icamera/widget/FocusMarkerLayout.java, line(s) 169
me/zhanghai/android/materialprogressbar/BaseProgressLayerDrawable.java, line(s) 72
me/zhanghai/android/materialprogressbar/MaterialProgressBar.java, line(s) 120,297,469
moa/leolin/shortcutbadger/ShortcutBadger.java, line(s) 69,129,66,100,107,128,113
net/sqlcipher/AbstractCursor.java, line(s) 237
net/sqlcipher/BulkCursorToCursorAdaptor.java, line(s) 50,98,139,165,176,186,204,109,120,224
net/sqlcipher/DatabaseUtils.java, line(s) 65,74,596,663
net/sqlcipher/DefaultDatabaseErrorHandler.java, line(s) 12,14,18,28,32
net/sqlcipher/database/SQLiteCompiledSql.java, line(s) 46,64,71,82
net/sqlcipher/database/SQLiteContentHelper.java, line(s) 25
net/sqlcipher/database/SQLiteDatabase.java, line(s) 367,981,989,1009,1020
net/sqlcipher/database/SQLiteDebug.java, line(s) 7,8,9,10,11,12
net/sqlcipher/database/SQLiteOpenHelper.java, line(s) 168,189
net/sqlcipher/database/SQLiteProgram.java, line(s) 68,74
net/sqlcipher/database/SQLiteQuery.java, line(s) 43
net/sqlcipher/database/SQLiteQueryBuilder.java, line(s) 133,132
net/sqlcipher/database/SqliteWrapper.java, line(s) 34,44,54,64,74
org/greenrobot/eventbus/Logger.java, line(s) 34,39
org/greenrobot/eventbus/util/ErrorDialogConfig.java, line(s) 34
org/greenrobot/eventbus/util/ErrorDialogManager.java, line(s) 188
org/greenrobot/greendao/AbstractDao.java, line(s) 383,283,731
org/greenrobot/greendao/DaoException.java, line(s) 28,29
org/greenrobot/greendao/DaoLog.java, line(s) 35,39,67,15,43,47,27,31,51,55,59,63
org/greenrobot/greendao/DbUtils.java, line(s) 88,30
org/greenrobot/greendao/async/AsyncOperationExecutor.java, line(s) 173,183,195,129
org/greenrobot/greendao/internal/LongHashMap.java, line(s) 132
org/greenrobot/greendao/query/QueryBuilder.java, line(s) 243,246
org/greenrobot/greendao/test/AbstractDaoTest.java, line(s) 55,57,47
org/greenrobot/greendao/test/AbstractDaoTestLongPk.java, line(s) 32,35
org/greenrobot/greendao/test/AbstractDaoTestSinglePk.java, line(s) 306
org/greenrobot/greendao/test/DbTest.java, line(s) 85
org/joda/time/tz/DateTimeZoneBuilder.java, line(s) 931,932,957
org/joda/time/tz/ZoneInfoCompiler.java, line(s) 104,105,106,107,108,226,237,273,292,305,317,320,325,344,360,416,647
org/jsoup/examples/HtmlToPlainText.java, line(s) 29,33
org/jsoup/examples/ListLinks.java, line(s) 46
pub/devrel/easypermissions/EasyPermissions.java, line(s) 139,141,35
pub/devrel/easypermissions/helper/ActivityPermissionHelper.java, line(s) 36
pub/devrel/easypermissions/helper/BaseSupportPermissionsHelper.java, line(s) 20
razerdp/basepopup/BasePopupWindow.java, line(s) 299,315,158,167,176
rx/internal/util/IndexedRingBuffer.java, line(s) 29
rx/internal/util/RxRingBuffer.java, line(s) 26
rx/plugins/RxJavaHooks.java, line(s) 207
sqlDB/DatabaseHelper.java, line(s) 37,38,77
sqlDB/sqlDB.java, line(s) 81,107
sqlc/SQLiteAndroidDatabase.java, line(s) 505,516,114,153,172,185,214,238,271,289,310,334,340,370,385,392,401,412,429,443,580
sqlc/SQLiteConnectorDatabase.java, line(s) 36,80,91,69,156,161
sqlc/SQLitePlugin.java, line(s) 34,38,115,135,197,220,235,287,305,316,322,163,257,261
top/zibin/luban/Checker.java, line(s) 71,91,97,122,130
top/zibin/luban/Luban.java, line(s) 85,84
uk/co/senab/photoview/PhotoViewAttacher.java, line(s) 59
uk/co/senab/photoview/log/LoggerDefault.java, line(s) 18,23,48,53,28,33,8,13,38,43
wechat/Util.java, line(s) 46,63,50
wechat/Wechat.java, line(s) 93,115,282,379,406,412,417,421,426,431,164,192,228,260,169,172,197,200,220,223,252,255
xu/li/cordova/wechat/Util.java, line(s) 46,63,50
xu/li/cordova/wechat/Wechat.java, line(s) 95,117,284,388,415,421,426,430,435,440,166,194,230,262,171,174,199,202,222,225,254,257
ynyd/mobile/moa/MainActivity.java, line(s) 81,91,97,100,136,143,150,163,173,282,454,481,535,250,260,288,317,336,440,529
ynyd/mobile/moa/Web3Activity.java, line(s) 107,133,159,160,170,177,184,205,219,224,237,256,262,280,292,299,311,320,251,270
ynyd/mobile/moa/util/CrashManager.java, line(s) 51,102
ynyd/mobile/moa/util/Des.java, line(s) 53,54
ynyd/mobile/moa/util/Downloader.java, line(s) 37
ynyd/mobile/moa/util/LogSaver.java, line(s) 33
ynyd/mobile/moa/util/SmsObserver.java, line(s) 28,29,41,48
ynyd/mobile/moa/wxapi/EntryActivity.java, line(s) 45,91,103,115

信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
com/zj/mobile/bingo/view/selectabletext/SelectableTextHelper.java, line(s) 4,493
com/zj/mobile/message/activity/MessageChatActivity.java, line(s) 10,8798
com/zj/mobile/message/activity/MessageDetailListActivity.java, line(s) 5,488
com/zj/mobile/message/activity/RingListActivity.java, line(s) 5,2011,2012
com/zj/mobile/message/utils/CopyLinkTextHelper.java, line(s) 4,57,66,73,80
com/zj/mobile/message/utils/helper/SystemHelper.java, line(s) 4,13

信息 此应用程序使用SQL Cipher。SQLCipher为sqlite数据库文件提供256位AES加密

此应用程序使用SQL Cipher。SQLCipher为sqlite数据库文件提供256位AES加密


Files:
com/raizlabs/android/dbflow/sqlcipher/SQLCipherOpenHelper.java, line(s) 22,11,12
com/zj/mobile/bingo/dp/CommonDBOpenHelper.java, line(s) 19,5,6
com/zj/mobile/bingo/dp/DBOpenHelper.java, line(s) 39,7,8,9
com/zj/mobile/message/database/SQLCipherUtils.java, line(s) 22,74,101,8,9,10,11
com/zj/mobile/message/emoticon/EmoticonDb.java, line(s) 46,7,8
net/sqlcipher/database/SupportHelper.java, line(s) 12,1
org/greenrobot/greendao/database/SqlCipherEncryptedHelper.java, line(s) 15,4,5

安全 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
asr_sdk/cu.java, line(s) 47,59
asr_sdk/dc.java, line(s) 45,45
asr_sdk/fu.java, line(s) 63,63
cls/rb.java, line(s) 36,36,38
cn/richinfo/cloudscanner/utils/CommonUtil.java, line(s) 267,331,382,263,264,264,329,329,380,380
com/github/kevinsawicki/http/HttpRequest.java, line(s) 275,182,1699,272,272
com/lzy/okgo/https/HttpsUtils.java, line(s) 60,162,59,58,160,160
com/msec/CertHelper.java, line(s) 61,48,59,59
com/nostra13/universalimageloader/core/download/HttpUtil.java, line(s) 428,520
com/xuhao/didi/socket/client/impl/client/ConnectionManagerImpl.java, line(s) 109,115
org/jsoup/helper/HttpConnection.java, line(s) 934,892

安全 此应用程序可能具有Root检测功能

此应用程序可能具有Root检测功能
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md#testing-root-detection-mstg-resilience-1

Files:
com/scottyab/rootbeer/RootBeer.java, line(s) 42
com/sdp/etrust/sdk/evaluationrules/EvaluationRule.java, line(s) 74,78,78,78,78,78,78
com/zj/mobile/message/utils/DeviceUtils.java, line(s) 64,22

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (ah.moazq.chinamobile.com) 通信。

{'ip': '112.33.111.253', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (hl.moazq.chinamobile.com) 通信。

{'ip': '117.132.188.195', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (hb.moazq.chinamobile.com) 通信。

{'ip': '112.33.111.253', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (www.weixin.com) 通信。

{'ip': '112.33.111.253', 'country_short': 'CN', 'country_long': '中国', 'region': '广东', 'city': '惠州', 'latitude': '39.509766', 'longitude': '116.693001'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (wisdom.it.chinamobile.com) 通信。

{'ip': '112.33.111.253', 'country_short': 'CN', 'country_long': '中国', 'region': '海南', 'city': '海口', 'latitude': '20.045830', 'longitude': '110.341667'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (log1.cmpassport.com) 通信。

{'ip': '8.219.211.108', 'country_short': 'CN', 'country_long': '中国', 'region': '甘肃', 'city': '兰州', 'latitude': '36.056690', 'longitude': '103.792221'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (api.125339.com.cn) 通信。

{'ip': '120.232.188.83', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (jzts.cmpassport.com) 通信。

{'ip': '112.33.111.253', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '合肥', 'latitude': '31.863815', 'longitude': '117.280830'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (yyzx.netvan.cn) 通信。

{'ip': '218.202.0.192', 'country_short': 'CN', 'country_long': '中国', 'region': '云南', 'city': '昆明', 'latitude': '25.038891', 'longitude': '102.718330'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (dnks.cmpassport.com) 通信。

{'ip': '120.232.188.83', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '合肥', 'latitude': '31.863815', 'longitude': '117.280830'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (da.mmarket.com) 通信。

{'ip': '120.232.188.83', 'country_short': 'CN', 'country_long': '中国', 'region': '广东', 'city': '广州', 'latitude': '23.127361', 'longitude': '113.264572'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (o.andfx.cn) 通信。

{'ip': '117.161.4.177', 'country_short': 'CN', 'country_long': '中国', 'region': '内蒙古自治区', 'city': '呼和浩特', 'latitude': '40.810650', 'longitude': '111.650665'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (cn.register.xmpush.xiaomi.com) 通信。

{'ip': '220.181.106.176', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (hippo.migu.cn) 通信。

{'ip': '117.132.188.195', 'country_short': 'CN', 'country_long': '中国', 'region': '重庆', 'city': '重庆', 'latitude': '29.562780', 'longitude': '106.553101'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (www.cz88.net) 通信。

{'ip': '117.132.188.195', 'country_short': 'CN', 'country_long': '中国', 'region': '湖南', 'city': '衡阳', 'latitude': '26.888060', 'longitude': '112.614998'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (mirrors.aliyun.com) 通信。

{'ip': '117.132.188.195', 'country_short': 'CN', 'country_long': '中国', 'region': '湖南', 'city': '衡阳', 'latitude': '26.888060', 'longitude': '112.614998'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (token.cmpassport.com) 通信。

{'ip': '118.26.252.230', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '合肥', 'latitude': '31.863815', 'longitude': '117.280830'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (cq.moazq.chinamobile.com) 通信。

{'ip': '117.132.188.24', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (ha.moazq.chinamobile.com) 通信。

{'ip': '117.136.179.66', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (test.andfx.cn) 通信。

{'ip': '117.136.240.10', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (aics.iflysec.com) 通信。

{'ip': '36.7.109.47', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '合肥', 'latitude': '31.863815', 'longitude': '117.280830'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (mirrors.163.com) 通信。

{'ip': '13.225.114.63', 'country_short': 'CN', 'country_long': '中国', 'region': '广东', 'city': '广州', 'latitude': '23.127361', 'longitude': '113.264572'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (api.xmpush.xiaomi.com) 通信。

{'ip': '117.132.188.24', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (resolver.msg.xiaomi.net) 通信。

{'ip': '220.181.106.150', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (gz.moazq.chinamobile.com) 通信。

{'ip': '117.132.188.24', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (o.andfx.net) 通信。

{'ip': '117.161.4.177', 'country_short': 'CN', 'country_long': '中国', 'region': '内蒙古自治区', 'city': '呼和浩特', 'latitude': '40.810650', 'longitude': '111.650665'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (moazq.chinamobile.com) 通信。

{'ip': '221.176.67.239', 'country_short': 'CN', 'country_long': '中国', 'region': '海南', 'city': '海口', 'latitude': '20.045830', 'longitude': '110.341667'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (docs.zegocloud.com) 通信。

{'ip': '47.242.198.129', 'country_short': 'HK', 'country_long': '中国', 'region': '香港', 'city': '香港', 'latitude': '22.285521', 'longitude': '114.157692'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (log2.cmpassport.com) 通信。

{'ip': '36.138.255.61', 'country_short': 'CN', 'country_long': '中国', 'region': '甘肃', 'city': '兰州', 'latitude': '36.056690', 'longitude': '103.792221'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (mail.yn.chinamobile.com) 通信。

{'ip': '111.22.67.128', 'country_short': 'CN', 'country_long': '中国', 'region': '湖南', 'city': '株洲市', 'latitude': '27.833330', 'longitude': '113.150002'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (hi.moazq.chinamobile.com) 通信。

{'ip': '117.136.179.67', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

安全评分: ( 云移资讯 5.0.5.0)