移动应用安全检测报告: LEDMobile v10.2.74

安全基线评分


安全基线评分 48/100

综合风险等级


风险等级评定

  1. A
  2. B
  3. C
  4. F

漏洞与安全项分布(%)


隐私风险

1

检测到的第三方跟踪器数量


检测结果分布

高危安全漏洞 2
中危安全漏洞 13
安全提示信息 1
已通过安全项 1
重点安全关注 3

高危安全漏洞 SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击

SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#android-network-apis

Files:
org/xutils/x$Ext.java, line(s) 50,4,5

高危安全漏洞 启用了调试配置。生产版本不能是可调试的

启用了调试配置。生产版本不能是可调试的
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
org/xutils/BuildConfig.java, line(s) 3,6

中危安全漏洞 应用程序已启用明文网络流量

[android:usesCleartextTraffic=true]
应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。

中危安全漏洞 应用程序数据可以被备份

[android:allowBackup=true]
这个标志允许任何人通过adb备份你的应用程序数据。它允许已经启用了USB调试的用户从设备上复制应用程序数据。

中危安全漏洞 Activity (com.zoehoo.lowrgb.wxapi.WXEntryActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危安全漏洞 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
com/soundcloud/android/crop/Constants.java, line(s) 53
com/zoehoo/cardOfD/PartsDStruct.java, line(s) 555
com/zoehoo/lowrgb/common/TypeCommon.java, line(s) 54,74
com/zoehoo/lowrgb/fullcolor/struct/PartsStruct.java, line(s) 434
com/zoehoo/lowrgb/ui/activity/DoorHeadLowActivity.java, line(s) 131
com/zoehoo/lowrgb/ui/widget/dialog/PasswordValidationDialog.java, line(s) 30
org/xutils/common/util/KeyValue.java, line(s) 41

中危安全漏洞 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
com/yzq/zxinglibrary/android/RichScanActivity.java, line(s) 253
com/yzq/zxinglibrary/decode/ImageUtil.java, line(s) 26
com/zoehoo/landscape/LandScapeBorderView.java, line(s) 278
com/zoehoo/landscape/LandScapeItemNatureDialog.java, line(s) 113
com/zoehoo/landscape/LandScapeProgramBorder.java, line(s) 263
com/zoehoo/lowrgb/beans/DoorLowPackage/DoorLowParseXmlUtil.java, line(s) 44
com/zoehoo/lowrgb/common/TypeCommon.java, line(s) 140,142
com/zoehoo/lowrgb/helper/DCardReadBackHelper.java, line(s) 252,272,296
com/zoehoo/lowrgb/helper/DoorBorder.java, line(s) 279
com/zoehoo/lowrgb/helper/DoorHeadSearch.java, line(s) 975,979,1025,1029
com/zoehoo/lowrgb/helper/ProgramBorder.java, line(s) 286
com/zoehoo/lowrgb/model/BorderBean.java, line(s) 32,171
com/zoehoo/lowrgb/myview/ChoiceMatrixView.java, line(s) 574
com/zoehoo/lowrgb/network/HttpServer.java, line(s) 81,95
com/zoehoo/lowrgb/ui/activity/CancellationActivity.java, line(s) 53
com/zoehoo/lowrgb/ui/activity/DoorHeadLowActivity$22.java, line(s) 19,23,25,30,32,40,41,44,45,46
com/zoehoo/lowrgb/ui/activity/DoorHeadLowActivity$24.java, line(s) 24
com/zoehoo/lowrgb/ui/activity/DoorHeadLowActivity.java, line(s) 802,805
com/zoehoo/lowrgb/ui/activity/FastLoginActivity.java, line(s) 195
com/zoehoo/lowrgb/ui/activity/PhotoSelectActivity.java, line(s) 239
com/zoehoo/lowrgb/ui/activity/SelectFirmwareActivity.java, line(s) 104
com/zoehoo/lowrgb/ui/activity/VideoSelectActivity.java, line(s) 228
com/zoehoo/lowrgb/ui/fragment/ControllerFragment.java, line(s) 234
com/zoehoo/lowrgb/utils/BitmapUtils.java, line(s) 335,354
com/zoehoo/lowrgb/utils/DeviceUtil.java, line(s) 200,215,223,237
com/zoehoo/lowrgb/utils/FileUtil.java, line(s) 48,847,1170,55,852
com/zoehoo/lowrgb/utils/FontUtils.java, line(s) 163
com/zoehoo/lowrgb/utils/MyCrashHandler.java, line(s) 33,32
com/zoehoo/lowrgb/utils/Utils.java, line(s) 834,844
com/zoehoo/lowrgb/utils/XmlParseUtils.java, line(s) 2163,2174,4334,4341,5177,5188
com/zoehoo/lowrgb/widget/luban/Luban.java, line(s) 191
com/zoehoo/single_color/LedUtils/LedProject.java, line(s) 33,37,41
com/zoehoo/single_color/LedUtils/ShereDefine.java, line(s) 14
com/zoehoo/single_color/LedUtils/UpdateHardUtil.java, line(s) 166,167,168,169,170,171
com/zoehoo/single_color/SundriesUtils/ProgramReadbackUtils.java, line(s) 30,31
com/zoehoo/single_color/ui/SingleColorOpenFileActivity.java, line(s) 28
org/xutils/common/util/FileUtil.java, line(s) 19,40,45

中危安全漏洞 IP地址泄露

IP地址泄露


Files:
com/zoehoo/lowrgb/beans/led/LedBean.java, line(s) 8
com/zoehoo/lowrgb/network/DeviceSearcher.java, line(s) 90
com/zoehoo/single_color/Constant/LedcommandType.java, line(s) 39
com/zoehoo/single_color/LedUtils/LedCommWifi.java, line(s) 17
com/zoehoo/single_color/LedUtils/LedNewSingleCmd.java, line(s) 17
com/zoehoo/single_color/LedUtils/LedPanel.java, line(s) 26,27,28,29,30,31
com/zoehoo/single_color/LedUtils/LedProtocol.java, line(s) 49
com/zoehoo/single_color/LedUtils/LedSingleCmd.java, line(s) 19
com/zoehoo/single_color/LedUtils/LedSingleLTCmd.java, line(s) 14
fi/iki/elonen/NanoHTTPD.java, line(s) 424

中危安全漏洞 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
com/soundcloud/android/crop/CropUtil.java, line(s) 72
fi/iki/elonen/NanoHTTPD.java, line(s) 295,774,889

中危安全漏洞 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/zoehoo/lowrgb/utils/FileUtil.java, line(s) 724,898
org/xutils/common/util/MD5.java, line(s) 36,76

中危安全漏洞 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/zoehoo/lowrgb/utils/FileUtil.java, line(s) 803

中危安全漏洞 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
com/esotericsoftware/kryo/util/ObjectMap.java, line(s) 6
com/zoehoo/lowrgb/utils/Utils.java, line(s) 95
com/zoehoo/lowrgb/widget/ZoeSVImageView.java, line(s) 24
com/zoehoo/lowrgb/widget/ZoeSVTableView.java, line(s) 22

中危安全漏洞 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
org/xutils/db/DbManagerImpl.java, line(s) 4,5,540

中危安全漏洞 应用程序包含隐私跟踪程序

此应用程序有多个1隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危安全漏洞 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
百度地图的=> "com.baidu.lbsapi.API_KEY" : "GTZBdyHrxbNyfhEm6eoRwsWkpRv1kGRo"
"authorized" : "Authorized"
"authorize_success" : "Authorized"
c9a01892174c948bbbbe59bf6825a854
8ad1406b369731411a475f98c57609b8
79387275080c5f4549647e7e23b41cfb

安全提示信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
com/esotericsoftware/kryo/Kryo.java, line(s) 262,586,887
com/esotericsoftware/kryo/util/Util.java, line(s) 100
com/esotericsoftware/minlog/Log.java, line(s) 226
com/github/mjdev/libaums/ErrNo.java, line(s) 18
com/github/mjdev/libaums/UsbMassStorageDevice.java, line(s) 98,130,77,136,50,55,57,67,110,61
com/github/mjdev/libaums/driver/scsi/ScsiBlockDevice.java, line(s) 41,55,56,46
com/github/mjdev/libaums/driver/scsi/commands/CommandStatusWrapper.java, line(s) 24
com/github/mjdev/libaums/fs/AbstractUsbFile.java, line(s) 12,15,20,23,26
com/github/mjdev/libaums/fs/UsbFileInputStream.java, line(s) 22
com/github/mjdev/libaums/fs/fat32/ClusterChain.java, line(s) 18,24,79,82
com/github/mjdev/libaums/fs/fat32/FAT.java, line(s) 26,33,156,210
com/github/mjdev/libaums/fs/fat32/Fat32FileSystem.java, line(s) 26
com/github/mjdev/libaums/fs/fat32/FatDirectory.java, line(s) 84,163,180,81
com/github/mjdev/libaums/fs/fat32/FsInfoStructure.java, line(s) 65
com/github/mjdev/libaums/partition/Partition.java, line(s) 32
com/github/mjdev/libaums/partition/mbr/MasterBootRecord.java, line(s) 49,57
com/github/mjdev/libaums/usb/UsbCommunicationFactory.java, line(s) 22
com/nineoldandroids/animation/PropertyValuesHolder.java, line(s) 148,176,222,240,242,259,261,297,299,425,427,515,517
com/snappydb/internal/KeyIteratorImpl.java, line(s) 36
com/soundcloud/android/crop/CropImageActivity.java, line(s) 139,145,385,393,425
com/soundcloud/android/crop/CropUtil.java, line(s) 47,61
com/soundcloud/android/crop/Log.java, line(s) 10,14
com/yzq/zxinglibrary/android/BeepManager.java, line(s) 70
com/yzq/zxinglibrary/android/CaptureActivity.java, line(s) 85,218,199,202
com/yzq/zxinglibrary/android/InactivityTimer.java, line(s) 87,37,43
com/yzq/zxinglibrary/android/RichScanActivity.java, line(s) 172,197
com/yzq/zxinglibrary/camera/AutoFocusManager.java, line(s) 28,36,42,55,71,82,100,49,63,89
com/yzq/zxinglibrary/camera/CameraConfigurationManager.java, line(s) 31,45,70,22,27,43,53,58,63,77,120,121,136,141,142,91,108,154,165
com/yzq/zxinglibrary/camera/CameraManager.java, line(s) 171,211,34,44,76,91,96,107,122,132,147,156,177,199,220,75,84
com/yzq/zxinglibrary/camera/OpenCameraInterface.java, line(s) 13,32,39,44,16,36
com/yzq/zxinglibrary/camera/PreviewCallback.java, line(s) 34,15,20,27
com/yzq/zxinglibrary/decode/BitmapLuminanceSource.java, line(s) 12,24,30
com/yzq/zxinglibrary/decode/DecodeHandler.java, line(s) 19,29
com/yzq/zxinglibrary/decode/DecodeImgThread.java, line(s) 22,30,46,58,68
com/yzq/zxinglibrary/decode/DecodeThread.java, line(s) 21,38,48
com/yzq/zxinglibrary/decode/ImageUtil.java, line(s) 19,61,93,98,103,108
com/zoehoo/cardOfD/EditDCardPresenterImpl.java, line(s) 742,389,591
com/zoehoo/cardOfD/EditDCardProgramModelImpl.java, line(s) 511,735,304,316,778
com/zoehoo/cardOfD/FFmpeg/FFmpegUtil.java, line(s) 38
com/zoehoo/landscape/LandScapeDCardScreenSetupView.java, line(s) 119
com/zoehoo/landscape/LandScapeHeadSearch.java, line(s) 154
com/zoehoo/landscape/LandScapeScreenSetupActivity.java, line(s) 392,403,406,466
com/zoehoo/landscape/LandScapeSetDialog.java, line(s) 116,121,123,157
com/zoehoo/landscape/LandScapeSetProgramPopupWindow.java, line(s) 197
com/zoehoo/landscape/LandScapeUpgradeFirmwareActivity.java, line(s) 239,228,51,53,157
com/zoehoo/lowrgb/adapter/AddFontAdapter.java, line(s) 162,171,173,177,179,180,51,55
com/zoehoo/lowrgb/adapter/EffectAdapter.java, line(s) 76
com/zoehoo/lowrgb/adapter/ZoeBaseAdapter.java, line(s) 122
com/zoehoo/lowrgb/common/CmdCommon.java, line(s) 93,521,178,211,312
com/zoehoo/lowrgb/common/config/ActivityManagerStack.java, line(s) 41,55
com/zoehoo/lowrgb/common/config/CityConfig.java, line(s) 16
com/zoehoo/lowrgb/helper/DCardReadBackHelper.java, line(s) 70,165,182,195,316,353
com/zoehoo/lowrgb/helper/DCardSendProgramHelper.java, line(s) 251,314,323,796,848,792
com/zoehoo/lowrgb/helper/DoorHeadSearch.java, line(s) 1001,1051,254,262,267,1093,1100
com/zoehoo/lowrgb/helper/SingleColorScreenSetupView.java, line(s) 520
com/zoehoo/lowrgb/model/DeviceBean.java, line(s) 200
com/zoehoo/lowrgb/model/impl/EditProgramModelImpl.java, line(s) 512,537,800,274,286,911,915,923
com/zoehoo/lowrgb/myview/ChoiceMatrixView.java, line(s) 313,202,205,80,89,97,98,191,195,228
com/zoehoo/lowrgb/myview/ControlView.java, line(s) 204,311,336,349,352,174
com/zoehoo/lowrgb/myview/DeviceInfoDialog.java, line(s) 37,76,46
com/zoehoo/lowrgb/myview/PowerFullLayout.java, line(s) 170,243,253
com/zoehoo/lowrgb/myview/RegionView.java, line(s) 350,362,366,370,374,380
com/zoehoo/lowrgb/myview/SetDialog.java, line(s) 129,134,136,169
com/zoehoo/lowrgb/network/DeviceSearcher.java, line(s) 96,270,116,142,168
com/zoehoo/lowrgb/network/HttpServer.java, line(s) 81,54,33,62,111,28,47,130,188,205,220,237,252,262,272
com/zoehoo/lowrgb/network/HttpService.java, line(s) 20,40,74,84,90
com/zoehoo/lowrgb/network/MinaTcpClient.java, line(s) 32,36,40,44,48,52
com/zoehoo/lowrgb/network/NetworkUtil.java, line(s) 110,112,114
com/zoehoo/lowrgb/network/TCPHandler.java, line(s) 73,35,40,47,52,57,67,99,105
com/zoehoo/lowrgb/network/TcpConnectionManager.java, line(s) 25,29,40,59
com/zoehoo/lowrgb/network/WifiChangedReceiver.java, line(s) 26,60
com/zoehoo/lowrgb/network/udp/MinaUdpHandler.java, line(s) 31,39,54,60,65,71
com/zoehoo/lowrgb/presenter/impl/EditPresenterImpl.java, line(s) 177,137
com/zoehoo/lowrgb/ui/activity/AddFontActivity.java, line(s) 33
com/zoehoo/lowrgb/ui/activity/AdvancedFunctionsActivity.java, line(s) 106,110
com/zoehoo/lowrgb/ui/activity/BaseActivity$2.java, line(s) 27
com/zoehoo/lowrgb/ui/activity/BaseActivity$9.java, line(s) 26
com/zoehoo/lowrgb/ui/activity/BaseActivity.java, line(s) 88,377
com/zoehoo/lowrgb/ui/activity/ChangeDoorUsePasswordActivity.java, line(s) 76,93
com/zoehoo/lowrgb/ui/activity/ControllerActivity.java, line(s) 54
com/zoehoo/lowrgb/ui/activity/DCardAutoCloseActivity.java, line(s) 92,110,114,118,122,127,131,156,162,509,510,512,513,516,518,521,523,526,528,531,533,536,538,541,543,546,548,551,553,556,558,561,562,571,136
com/zoehoo/lowrgb/ui/activity/DoorHeadLowActivity.java, line(s) 1287,225,767,1929
com/zoehoo/lowrgb/ui/activity/FastLoginActivity.java, line(s) 153,155,287,293,302,308,348,197,230,241,249,258,273,281,295,331,341,344,356,365,370,389,395,398
com/zoehoo/lowrgb/ui/activity/FirstLoginActivity.java, line(s) 227,293,344,208,212,232,237,242,304,349,354,359,373,386,392,407,413
com/zoehoo/lowrgb/ui/activity/LauncherActivity.java, line(s) 75,59,60,54,55
com/zoehoo/lowrgb/ui/activity/ScreenSetupActivity.java, line(s) 477,541
com/zoehoo/lowrgb/ui/activity/SelectFirmwareActivity.java, line(s) 150,155
com/zoehoo/lowrgb/ui/activity/UnitBoardSettingActivity.java, line(s) 488
com/zoehoo/lowrgb/ui/activity/UpgradeFirmwareActivity.java, line(s) 215,222,232,208,50,52,144
com/zoehoo/lowrgb/ui/activity/WifiApOnOff.java, line(s) 83,89,155
com/zoehoo/lowrgb/ui/activity/WifiSettingsActivity.java, line(s) 235,252,278,86,227,282
com/zoehoo/lowrgb/ui/fragment/ControllerFragment.java, line(s) 76,241,251,256,261,266,271
com/zoehoo/lowrgb/ui/fragment/DoorLowBackGroundColorFragment.java, line(s) 51
com/zoehoo/lowrgb/ui/fragment/DoorLowSetProgramFragment.java, line(s) 171,671
com/zoehoo/lowrgb/ui/fragment/ScreenShotFragment.java, line(s) 42
com/zoehoo/lowrgb/ui/fragment/SetIpFragment.java, line(s) 186
com/zoehoo/lowrgb/ui/widget/dialog/PickerViewDialog.java, line(s) 54
com/zoehoo/lowrgb/ui/widget/pickerview/WheelView.java, line(s) 278
com/zoehoo/lowrgb/utils/ByteUtils.java, line(s) 91,100,227
com/zoehoo/lowrgb/utils/DBUtil.java, line(s) 28,31,47,168,481,485
com/zoehoo/lowrgb/utils/DeviceUtil.java, line(s) 434
com/zoehoo/lowrgb/utils/DownLoadAPKUtils.java, line(s) 62,82,89
com/zoehoo/lowrgb/utils/FileUtil.java, line(s) 1074,772,776,870
com/zoehoo/lowrgb/utils/FontUtils.java, line(s) 95
com/zoehoo/lowrgb/utils/GifUtil.java, line(s) 27
com/zoehoo/lowrgb/utils/MyCrashHandler.java, line(s) 60,34
com/zoehoo/lowrgb/utils/ProgramXmlUtil.java, line(s) 471,473
com/zoehoo/lowrgb/utils/RsaUtil.java, line(s) 49,50,52,53
com/zoehoo/lowrgb/utils/SoftKeyBoardListener.java, line(s) 28
com/zoehoo/lowrgb/utils/Utils.java, line(s) 903,189,893,905,908,1436
com/zoehoo/lowrgb/utils/XLog.java, line(s) 45,31,38,52,59,66
com/zoehoo/lowrgb/utils/XmlParseLedUtils.java, line(s) 66,271,623,641,655,1049,1398
com/zoehoo/lowrgb/utils/XmlParseUtils.java, line(s) 62,65,341,469,3485,4117
com/zoehoo/lowrgb/utils/XmlUnitBoardUtils.java, line(s) 31,164
com/zoehoo/lowrgb/utils/ZipUtil.java, line(s) 135
com/zoehoo/lowrgb/widget/BorderSurfaceView.java, line(s) 56,83
com/zoehoo/lowrgb/widget/ScreenShotDialog.java, line(s) 110,196,231,256,257,258
com/zoehoo/lowrgb/widget/WheelView.java, line(s) 106,178,235,268
com/zoehoo/lowrgb/widget/ZoeBgTextureView.java, line(s) 85,133,225
com/zoehoo/lowrgb/widget/ZoeNumClockView.java, line(s) 414,422,427
com/zoehoo/lowrgb/widget/ZoeSVImageView.java, line(s) 142
com/zoehoo/lowrgb/widget/ZoeSVTableView.java, line(s) 571
com/zoehoo/lowrgb/widget/ZoeTextureView.java, line(s) 248,252,143,167,234,99,116,131,162,333,342
com/zoehoo/lowrgb/widget/ZoeTimeView.java, line(s) 265,273,278
com/zoehoo/lowrgb/widget/luban/Luban.java, line(s) 61,60,339
com/zoehoo/lowrgb/wxapi/WXEntryActivity.java, line(s) 69
com/zoehoo/single_color/LedUtils/LedControl.java, line(s) 768,796,801,815,821,842,864,1941,1950,1957,1966,2067,2119
com/zoehoo/single_color/LedUtils/LedNewSingleCmd.java, line(s) 54
com/zoehoo/single_color/LedUtils/LedProtocol.java, line(s) 370
com/zoehoo/single_color/LedUtils/LedUtil.java, line(s) 321
com/zoehoo/single_color/SundriesUtils/ProgramReadbackUtils.java, line(s) 253
com/zoehoo/single_color/drawBmpUtils/DrawDate.java, line(s) 875,1243
com/zoehoo/single_color/ui/BrightnessSetDialog.java, line(s) 58,65
de/innosystec/unrar/Volume.java, line(s) 19
de/innosystec/unrar/unpack/ppm/AnalyzeHeapDump.java, line(s) 14,18,24,25,26,81,83,106
de/innosystec/unrar/unsigned/UnsignedByte.java, line(s) 25,26,27,28,29,30,31,32
fi/iki/elonen/util/ServerRunner.java, line(s) 15,18,24
github/chenupt/multiplemodel/BaseModelManager.java, line(s) 32
github/chenupt/multiplemodel/ModelFactory.java, line(s) 18,35
org/greenrobot/eventbus/BackgroundPoster.java, line(s) 40
org/greenrobot/eventbus/EventBus.java, line(s) 290,429,431,440,172
org/greenrobot/eventbus/util/AsyncExecutor.java, line(s) 98
org/greenrobot/eventbus/util/ErrorDialogConfig.java, line(s) 34
org/greenrobot/eventbus/util/ErrorDialogManager.java, line(s) 185
org/greenrobot/eventbus/util/ExceptionToResourceMapping.java, line(s) 26
org/xutils/common/util/LogUtil.java, line(s) 26,32,38,44,50,56,62,68,74,80,86,92,98,104

已通过安全项 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
fi/iki/elonen/NanoHTTPD.java, line(s) 1317,1315,1314,1314

重点安全关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (zca.zoecloud.cn) 通信。

{'ip': '58.220.52.237', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

重点安全关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (www.zhonghangled.com) 通信。

{'ip': '140.249.61.219', 'country_short': 'CN', 'country_long': '中国', 'region': '山东', 'city': '临沂', 'latitude': '35.063061', 'longitude': '118.342781'}

重点安全关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (download.zhonghangled.com) 通信。

{'ip': '58.220.52.237', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '扬州', 'latitude': '32.397221', 'longitude': '119.435600'}

综合安全基线评分: ( LEDMobile 10.2.74)