安全分析报告: v1.8.0

安全分数


安全分数 41/100

风险评级


等级

  1. A
  2. B
  3. C
  4. F

严重性分布 (%)


隐私风险

2

用户/设备跟踪器


调研结果

高危 13
中危 36
信息 4
安全 3
关注 2

高危 程序可被任意调试

[android:debuggable=true]
应用可调试标签被开启,这使得逆向工程师更容易将调试器挂接到应用程序上。这允许导出堆栈跟踪和访问调试助手类。

高危 App 链接 assetlinks.json 文件未找到

[android:name=im.cyrwjqklpq.ui.LaunchActivity][android:host=http://lovechat323.com]
App Link 资产验证 URL (http://lovechat323.com/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:None)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。

高危 App 链接 assetlinks.json 文件未找到

[android:name=im.cyrwjqklpq.ui.LaunchActivity][android:host=https://lovechat323.com]
App Link 资产验证 URL (https://lovechat323.com/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:None)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。

高危 Activity (im.cyrwjqklpq.ui.IntroActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (im.cyrwjqklpq.messenger.OpenChatReceiver) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (im.cyrwjqklpq.ui.hui.visualcall.VisualCallActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (im.cyrwjqklpq.ui.hui.visualcall.VisualCallReceiveActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (im.cyrwjqklpq.ui.PopupNotificationActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.bjz.comm.net.premission.PermissionActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/alivc/rtc/device/utils/AESUtils.java, line(s) 39,46
im/cyrwjqklpq/ui/hui/friendscircle/okhttphelper/AESHelper.java, line(s) 50
im/cyrwjqklpq/ui/utils/AesUtils.java, line(s) 27,49,58
im/cyrwjqklpq/ui/utils/ChiperUtils.java, line(s) 52,74,83

高危 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击

如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-7

Files:
im/cyrwjqklpq/ui/ArticleViewer.java, line(s) 7320,61,62
im/cyrwjqklpq/ui/components/EmbedBottomSheet.java, line(s) 687,33,34

高危 启用了调试配置。生产版本不能是可调试的

启用了调试配置。生产版本不能是可调试的
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
com/litesuits/orm/BuildConfig.java, line(s) 3,4
com/serenegiant/uvccamera/BuildConfig.java, line(s) 3,6
im/cyrwjqklpq/messenger/BuildConfig.java, line(s) 3,6

中危 应用程序已启用明文网络流量

[android:usesCleartextTraffic=true]
应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。

中危 Service (im.cyrwjqklpq.messenger.GcmPushListenerService) 未被保护。

存在一个intent-filter。
发现 Service与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Service是显式导出的。

中危 Broadcast Receiver (com.google.android.gms.measurement.AppMeasurementReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Activity (im.cyrwjqklpq.ui.ShareActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (im.cyrwjqklpq.ui.ExternalActionActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (im.cyrwjqklpq.messenger.OpenChatReceiver) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (im.cyrwjqklpq.ui.hui.visualcall.VisualCallActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (im.cyrwjqklpq.ui.hui.visualcall.VisualCallReceiveActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (im.cyrwjqklpq.messenger.AuthenticatorService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (im.cyrwjqklpq.messenger.ContactsSyncAdapterService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (im.cyrwjqklpq.messenger.AppChooserTargetService) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.BIND_CHOOSER_TARGET_SERVICE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Service (im.cyrwjqklpq.messenger.MusicPlayerService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (im.cyrwjqklpq.messenger.MusicBrowserService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (im.cyrwjqklpq.messenger.WearDataLayerListenerService) 未被保护。

存在一个intent-filter。
发现 Service与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Service是显式导出的。

中危 Service (im.cyrwjqklpq.messenger.voip.AppConnectionService) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.BIND_TELECOM_CONNECTION_SERVICE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Broadcast Receiver (im.cyrwjqklpq.messenger.MusicPlayerReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (im.cyrwjqklpq.messenger.voip.VoIPMediaButtonReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (im.cyrwjqklpq.messenger.AppStartReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (im.cyrwjqklpq.messenger.RefererReceiver) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.INSTALL_PACKAGES [android:exported=true]
发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Content Provider (im.cyrwjqklpq.messenger.voip.CallNotificationSoundProvider) 未被保护。

[android:exported=true]
发现 Content Provider与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (com.blankj.utilcode.util.MessengerUtils$ServerService) 未被保护。

存在一个intent-filter。
发现 Service与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Service是显式导出的。

中危 Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.google.android.c2dm.permission.SEND [android:exported=true]
发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Service (com.google.android.gms.auth.api.signin.RevocationBoundService) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.google.android.gms.auth.api.signin.permission.REVOCATION_NOTIFICATION [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Broadcast Receiver (com.qiniu.android.dns.NetworkReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/bjz/comm/net/utils/MD5Utils.java, line(s) 19
com/danikula/videocache/ProxyCacheUtils.java, line(s) 74
com/litesuits/orm/db/assit/Encrypt.java, line(s) 35
im/cyrwjqklpq/messenger/AndroidUtilities.java, line(s) 2168
im/cyrwjqklpq/messenger/FileUploadOperation.java, line(s) 418
im/cyrwjqklpq/messenger/Utilities.java, line(s) 371
im/cyrwjqklpq/translate/MD5.java, line(s) 20,51
im/cyrwjqklpq/ui/hui/friendscircle/okhttphelper/MD5Utils.java, line(s) 19
im/cyrwjqklpq/ui/utils/ChiperUtils.java, line(s) 18

中危 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/alivc/rtc/device/UTUtdid.java, line(s) 344
im/cyrwjqklpq/messenger/Utilities.java, line(s) 226,240
im/cyrwjqklpq/ui/PassportActivity.java, line(s) 2820
im/cyrwjqklpq/utils/DeviceUtils.java, line(s) 97
im/cyrwjqklpq/utils/FingerprintUtil.java, line(s) 157

中危 可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息

可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-6

Files:
im/cyrwjqklpq/ui/fragments/TabWebFragment.java, line(s) 87,80
im/cyrwjqklpq/ui/hui/discoveryweb/DiscoveryJumpToPage.java, line(s) 258,251

中危 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
com/alivc/rtc/device/UTUtdid.java, line(s) 23,24,43
com/bjz/comm/net/bean/AtUserBean.java, line(s) 60
com/bjz/comm/net/bean/FCEntitysRequest.java, line(s) 49
com/bjz/comm/net/bean/FCEntitysResponse.java, line(s) 121
com/bjz/comm/net/bean/FcUserInfoBean.java, line(s) 116
com/bjz/comm/net/bean/MiniGameBean.java, line(s) 113
com/bjz/comm/net/bean/ResponseAccessTokenBean.java, line(s) 60
com/litesuits/orm/db/assit/SQLBuilder.java, line(s) 61
com/litesuits/orm/db/model/EntityTable.java, line(s) 32
com/litesuits/orm/db/model/MapProperty.java, line(s) 7
com/zhy/http/okhttp/builder/PostFormBuilder.java, line(s) 48
im/cyrwjqklpq/javaBean/ShareInstallConfigBean.java, line(s) 46
im/cyrwjqklpq/messenger/ContactsController.java, line(s) 1191,1532
im/cyrwjqklpq/messenger/FileRefController.java, line(s) 129,161,178,193,198,203,210,228,225,231
im/cyrwjqklpq/messenger/ImageLoader.java, line(s) 775
im/cyrwjqklpq/messenger/LocaleController.java, line(s) 538
im/cyrwjqklpq/messenger/NotificationsController.java, line(s) 2186,2231
im/cyrwjqklpq/messenger/SendMessagesHelper.java, line(s) 2278,1465,1473,3114
im/cyrwjqklpq/ui/ArticleViewer.java, line(s) 1813,4730,3982
im/cyrwjqklpq/ui/ChannelCreateActivity.java, line(s) 134
im/cyrwjqklpq/ui/ChatEditTypeActivity.java, line(s) 123
im/cyrwjqklpq/ui/DataAutoDownloadActivity.java, line(s) 302,453,317,463,310,458
im/cyrwjqklpq/ui/DataSettingsActivity.java, line(s) 218,382,230,390,224,386
im/cyrwjqklpq/ui/LaunchActivity.java, line(s) 1981
im/cyrwjqklpq/ui/NotificationsCustomSettingsActivity.java, line(s) 340,338,336
im/cyrwjqklpq/ui/NotificationsSettingsActivity.java, line(s) 381
im/cyrwjqklpq/ui/PassportActivity.java, line(s) 4342,3927,4380,3933,4348,4384,4354,4357,910,5003,4333,4364,905,4995,4345,4339,4368,4336,4366,3941,4378,4351,908,4999,901,4983,3937,4382,3920,4374,3923,4376,913,4987
im/cyrwjqklpq/ui/QuickRepliesSettingsActivity.java, line(s) 170,166,162,158
im/cyrwjqklpq/ui/actionbar/Theme.java, line(s) 2806,3238,3306
im/cyrwjqklpq/ui/adapters/MentionsAdapter.java, line(s) 399
im/cyrwjqklpq/ui/components/AlertsCreator.java, line(s) 533,535
im/cyrwjqklpq/ui/components/CheckBoxBase.java, line(s) 63,61,62
im/cyrwjqklpq/ui/components/ContextProgressView.java, line(s) 33,36,39,42,34,37,40,43
im/cyrwjqklpq/ui/components/EmojiView.java, line(s) 3995,3999
im/cyrwjqklpq/ui/components/EmojiViewV2.java, line(s) 3979,3983
im/cyrwjqklpq/ui/components/GroupCreateCheckBox.java, line(s) 40,38,39
im/cyrwjqklpq/ui/components/ScrollSlidingTextTabStrip.java, line(s) 72,131,191,70,129,189,73,132,192,71,130,190
im/cyrwjqklpq/ui/components/Switch.java, line(s) 68,69,70,71
im/cyrwjqklpq/ui/hui/contacts/CreateGroupingActivity.java, line(s) 555
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/CommFCArcView.java, line(s) 18,24,30
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/edittext/span/User.java, line(s) 152
im/cyrwjqklpq/ui/hui/login/LoginContronllerActivity.java, line(s) 65
im/cyrwjqklpq/ui/hui/packet/SelecteContactsActivity.java, line(s) 164,168
im/cyrwjqklpq/ui/hviews/MrySwitch.java, line(s) 70,88,71,89,72,73,90,91
im/cyrwjqklpq/ui/settings/AutoDownloadSettingActivity.java, line(s) 78,470,88,485,83,478
im/cyrwjqklpq/ui/settings/DataAndStoreSettingActivity.java, line(s) 286,294,290
im/cyrwjqklpq/ui/settings/ProxySettingActivity.java, line(s) 510,520,525,532,535

中危 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
im/cyrwjqklpq/messenger/utils/PlayerUtils.java, line(s) 1244,1251
im/cyrwjqklpq/ui/ArticleViewer.java, line(s) 7190,7185
im/cyrwjqklpq/ui/WebviewActivity.java, line(s) 280,267
im/cyrwjqklpq/ui/components/EmbedBottomSheet.java, line(s) 663,221
im/cyrwjqklpq/ui/components/WebPlayerView.java, line(s) 1234,1241

中危 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
com/alivc/rtc/device/UTUtdid.java, line(s) 16
com/alivc/rtc/device/utils/PhoneInfoUtils.java, line(s) 7
com/socks/library/klog/FileLog.java, line(s) 12
im/cyrwjqklpq/ui/hui/visualcall/VisualCallReceiveService.java, line(s) 27
im/cyrwjqklpq/ui/utils/number/StringUtils.java, line(s) 4
im/cyrwjqklpq/ui/utils/translate/ssrc/SSRC.java, line(s) 15

中危 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
com/alivc/rtc/device/core/persistent/PersistentConfiguration.java, line(s) 52,151,326,376
com/danikula/videocache/StorageUtils.java, line(s) 25,44
im/cyrwjqklpq/messenger/AndroidUtilities.java, line(s) 1222,613,1216,1217
im/cyrwjqklpq/messenger/FileLog.java, line(s) 49,82,331
im/cyrwjqklpq/messenger/ImageLoader.java, line(s) 1422,1423
im/cyrwjqklpq/messenger/SharedConfig.java, line(s) 656
im/cyrwjqklpq/messenger/voip/VoIPController.java, line(s) 300
im/cyrwjqklpq/ui/DocumentSelectActivity.java, line(s) 478,579,579,579,582
im/cyrwjqklpq/ui/SettingsActivity.java, line(s) 1215
im/cyrwjqklpq/ui/components/voip/VoIPHelper.java, line(s) 488
im/cyrwjqklpq/ui/dialogs/McShareDialog.java, line(s) 168
im/cyrwjqklpq/ui/fragments/MeFragmentV2.java, line(s) 857
im/cyrwjqklpq/ui/hui/chats/GroupShareActivity.java, line(s) 264
im/cyrwjqklpq/ui/hui/mine/AboutAppActivity.java, line(s) 380
im/cyrwjqklpq/ui/hui/mine/QrCodeActivity.java, line(s) 287
im/cyrwjqklpq/ui/hviews/helper/MryDisplayHelper.java, line(s) 279
im/cyrwjqklpq/ui/utils/DownloadUtils.java, line(s) 152
np/log/NPCrashHandler.java, line(s) 126

中危 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
im/cyrwjqklpq/ui/components/paint/Slice.java, line(s) 20
im/cyrwjqklpq/ui/utils/translate/ssrc/SSRC.java, line(s) 826

中危 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
com/danikula/videocache/sourcestorage/DatabaseSourceInfoStorage.java, line(s) 6,7,28
com/litesuits/orm/db/assit/Querier.java, line(s) 4,14

中危 IP地址泄露

IP地址泄露


Files:
com/danikula/videocache/HttpProxyCacheServer.java, line(s) 31
im/cyrwjqklpq/tgnet/NetworkConfig.java, line(s) 41,183,175,185,173

中危 应用程序包含隐私跟踪程序

此应用程序有多个2隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
openinstall统计的=> "com.openinstall.APP_KEY" : "ihwxqr"
百度地图的=> "com.baidu.lbsapi.API_KEY" : "kdjUejIjejr98r5lAPl34kPK4M45T7Y4"
谷歌地图的=> "com.google.android.maps.v2.API_KEY" : "AIzaSyA-t0jLPjUt2FxrA8VPK2EiYHcYcboIR6k"
"UseProxySecret" : "Secret"
"key_walletDefaultBackground" : "walletDefaultBackground"
"baidu_map_key" : "kdjUejIjejr98r5lAPl34kPK4M45T7Y4"
"RestorePasswordNoEmailTitle" : "Sorry"
"PayPasswordReset" : "PayPasswordReset"
"PasswordCode" : "Code"
"TypePrivateGroup" : "Private"
"TypePrivate" : "Private"
"TypePrivate2" : "Private"
"PayPasswordSetting" : "PayPasswordSetting"
"UserNameOrPhoneNumberSearch" : "Username"
"pref_speakerphone_key" : "speakerphone_preference"
"PasscodePassword" : "Password"
"firebase_database_url" : "https://cyrwjqklpq-48b0d.firebaseio.com"
"UseProxyUsername" : "Username"
"key_windowBackgroundGray" : "windowBackgroundGray"
"LoginPassword" : "Password"
"PaymentPasswordTitle" : "Password"
"Username" : "Username"
"LoginPasswordReset" : "LoginPasswordReset"
"Sessions" : "Sessions"
"google_api_key" : "AIzaSyC6uk1nvjb5BYzqEzgaWy_iTryf5373Nyw"
"google_app_id" : "1:194512522065:android:a3b6ee229cc1efe012e170"
"yuncheng_app_key" : "hf4gX21KF4+d3MBQdtbQCgRUv4JmXdcd366tMJ_2Nkpr4qFQ+JpjJLgILcjeglAiPhawp_SkhJg-btxAXxfMy6eoVE1Z5fLbHa9ML84-gJ9CQ2t-p5A1wGw-liBiglGLE35hA5yAWgdxLwxRJflwNFFm2i29YghMzFxjgNtgLqtrtwmcG66YUL1m-O7wxuAyW8yaJiCVl5igvChLSTlvQPwxfiKp1Sw1+iG1UAx4j69AT3tPeWludJlhbEQzVkcRPSkvtrz5ZtvTAFTFGw_ZtiXBOWXRg5i-lvaTd++Zp9pr85E8lZCy2roG4BKf2Mc9ZTtRVClTm+l6Ht2Hs8ipggo3uTxwXTMXDiNYfvoAyegblngR-OM26+E4MCAKI_QSqRI25NOKS8O5EV+1J+VKP2nx89cKwxQErwhdZUnDDnvDuxRffIrfRP7PZhbkcjaUvQiv-ZTE6J91V3ZQnzu7a8jOf5IsaiXnwUDNBuOWP6c4xjOQHalyUGA9b8fGpdefZXz"
"UseProxyPassword" : "Password"
"YourPasswordSuccess" : "Success!"
"PayPasswordSetReminder" : "Tips"
"FindBackPassword" : "FindBack"
"key_windowBackgroundWhite" : "windowBackgroundWhite"
"google_crash_reporting_api_key" : "AIzaSyC6uk1nvjb5BYzqEzgaWy_iTryf5373Nyw"
"FindBackPassword" : "FindBackPassword"
e283aac0-7c0f-4f2e-bcf7-90acc19903ed
QrMgt8GGYI6T52ZY5AnhtxkLzb8egpFn3j5JELI8H6wtACbUnZ5cc3aYTsTRbmkAkRJeYbtx92LPBWm7nBO9UIl7y5i5MQNmUZNf5QENurR5tGyo7yJ2G0MBjWvy6iAtlAbacKP0SwOUeUWx5dsBdyhxa7Id1APtybSdDgicBDuNjI0mlZFUzZSS9dmN8lBD0WTVOMz0pRZbR3cysomRXOO1ghqjJdTcyDIxzpNAEszN8RMGjrzyU7Hjbmwi6YNK
C71CAEB9C6B1C9048E6C522F70F13F73980D40238E3E21C14934D037563D930F48198A0AA7C14058229493D22530F4DBFA336F6E0AC925139543AED44CCE7C3720FD51F69458705AC68CD4FE6B6B13ABDC9746512969328454F18FAF8C595F642477FE96BB2A941D5BCD1D4AC8CC49880708FA9B378E3C4F3A9060BEE67CF9A4A4A695811051907E162753B56B0F6B410DBA74D8A84B2A14B3144E0EF1284754FD17ED950D5965B4B9DD46582DB1178D169C6BC465B0D6FF9CA3928FEF5B9AE4E418FC15E83EBEA0F87FA9FF5EED70050DED2849F47BF959D956850CE929851F0D8115F635B105EE2E4E15D04B2454BF6F4FADF034B10403119CD8E3B92FCC5B
9A04F079-9840-4286-AB92-E65BE0885F95
fb9f0bb7fdd0760c354cc3d80cecb1d9
A2B55680-6F43-11E0-9A3F-0002A5D5C51B
f180c508-f49a-40bd-b8ac-50577ce9aff6
pE5eNoBQIFVcd9IEuyIhvopfgS1RSj5C
ABVGDE2JZIQKLMNOPRSTUFHC34WXY9678
c06c8400-8e06-11e0-9cb6-0002a5d5c51b
bb392ec0-8d4d-11e0-a896-0002a5d5c51b

信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
cn/dreamtobe/kpswitch/handler/KPSwitchRootLayoutHandler.java, line(s) 35,46,50,56,60
cn/dreamtobe/kpswitch/util/KeyboardUtil.java, line(s) 44,186,193,233,164,202,219
cn/dreamtobe/kpswitch/util/StatusBarHeightUtil.java, line(s) 21
cn/dreamtobe/kpswitch/util/ViewUtil.java, line(s) 17
com/alivc/component/capture/VideoPusher.java, line(s) 158,306,310,329,334,339,397,412,423,428,451,457,467,583,615,635,640,667,728,758,762,764,771,965,999,1052,369,388,392,649,815,878,925,983,1016,659
com/alivc/component/capture/VideoPusherJNI.java, line(s) 40,51,59,74,82,97,105,115,127,139,150,158,167,176,185,194,196,203,212,221,229,238,246,255,68,91,121,133
com/alivc/rtc/AliRtcEngine.java, line(s) 271,284,301,308
com/alivc/rtc/AliRtcEngineImpl.java, line(s) 1548,1620,1966,2004,2179,3289,318,343,627,898,923,1207,1350,1366,1385,1399,1439,1452,1473,1529,1536,1538,1542,1550,1566,1570,1574,1578,1597,1601,1622,1626,1638,1642,1650,1676,1690,1694,1755,1759,1763,1768,1793,1812,1819,1822,1826,1841,1845,1850,1854,1879,1885,1887,1893,1899,1901,1906,1908,1914,1916,1922,1930,1941,1953,1973,2016,2160,2202,2217,2232,2247,2631,2636,2681,2686,2691,2698,2713,2732,2738,2740,2891,2904,2981,73,75,82,84,97,99,106,108,114,120,148,150,160,163,189,191,213,215,227,229,252,254,276,278,288,290,298,326,328,341,361,365,367,375,377,384,386,392,394,400,407,413,434,436,442,468,470,476,481,488,490,492,494,496,498,504,506,508,514,517,519,521,523,525,527,573,575,625,639,641,647,649,655,657,663,665,671,673,692,728,730,740,743,769,771,793,795,807,809,832,834,856,858,868,870,878,906,908,921,941,945,947,955,957,964,966,972,974,980,987,993,1014,1016,1022,1048,1050,1056,1061,1068,1070,1072,1074,1076,1078,1084,1086,1088,1094,1097,1099,1101,1103,1105,1107,1153,1155,1205,1219,1221,1227,1229,1235,1237,1243,1245,1251,1253,1290,1292,1318,1326,1373,1377,1383,1386,1391,1397,1403,1409,1411,1417,1424,1431,1437,1455,1460,1462,1516,1530,1558,1564,1582,1588,1591,1614,1636,1660,1667,1673,1682,1688,1699,1706,1710,1715,1720,1728,1733,1738,1747,1753,1804,1810,1833,1839,1867,1872,1876,1928,1934,1947,1961,2010,2027,2039,2045,2072,2082,2090,2092,2098,2104,2106,2113,2126,2133,2135,2143,2145,2150,2152,2158,2171,2177,2185,2187,2193,2195,2208,2210,2223,2225,2236,2238,2253,2258,2267,2277,2285,2287,2293,2297,2307,2309,2319,2321,2333,2341,2352,2368,2378,2383,2389,2391,2407,2439,2456,2488,2505,2520,2522,2530,2532,2539,2541,2553,2561,2570,2618,2706,2717,2743,2805,2807,2813,2836,2842,2848,2854,2860,2866,2872,2878,2884,2986,2995,2997,3006,3008,3017,3019,3028,3030,3039,3041,3050,3052,3061,3063,3072,3074,3083,3088,3097,3099,3108,3113,3122,3124,3133,3138,3147,3149,3158,3163,3172,3174,3183,3185,3194,3196,3205,3207,3216,3218,3227,3229,3240,3252,3256,3266,3270,3285,3339,3344,3353,3355,1453
com/alivc/rtc/device/DeviceInfo.java, line(s) 30,57,61
com/alivc/rtc/device/UTUtdid.java, line(s) 132,134,139,141,152,154,159,161,207,212,238,241,246,249
com/bjz/comm/net/factory/ApiFactory.java, line(s) 59,66
com/bjz/comm/net/factory/ApiGameFactory.java, line(s) 57,64
com/bjz/comm/net/mvp/presenter/FcCommonPresenter.java, line(s) 111
com/bjz/comm/net/premission/PermissionActivity.java, line(s) 52,331,343,358
com/bjz/comm/net/premission/PermissionManager.java, line(s) 34
com/bjz/comm/net/receiver/NetworkConnectChangedReceiver.java, line(s) 23,29,39
com/bjz/comm/net/utils/MD5Utils.java, line(s) 21,88,92,93
com/bjz/comm/net/utils/RxHelper.java, line(s) 95,100,121,125,136,182
com/bjz/comm/net/utils/TokenLoader.java, line(s) 47,79,83
com/contrarywind/view/WheelView.java, line(s) 341
com/coremedia/iso/boxes/sampleentry/AudioSampleEntry.java, line(s) 195
com/litesuits/orm/LiteOrm.java, line(s) 79,81,85,115,310
com/litesuits/orm/db/TableManager.java, line(s) 91,132,123,171,249,90,95,96,101,102,119,121,131,138,139,159,160,180,181,182,187,188
com/litesuits/orm/db/assit/Querier.java, line(s) 12,18,21,11,17,20
com/litesuits/orm/db/assit/SQLStatement.java, line(s) 250,280,519,170,285,101,102,126,127,169,183,184,187,188,233,234,249,275,276,279,284,323,359,375,380,422,423,496,506,518,324,360,497,507
com/litesuits/orm/db/assit/Transaction.java, line(s) 15,21,22
com/litesuits/orm/db/utils/DataUtil.java, line(s) 109,110
com/litesuits/orm/log/OrmLog.java, line(s) 41,74,124,157,62,95,145,178,20,27,48,81,131,164,34,67,117,150,55,88,138,171
com/preview/PreviewDialogFragment.java, line(s) 162
com/serenegiant/usb/DeviceFilter.java, line(s) 73,75
com/serenegiant/usb/USBMonitor.java, line(s) 240,247,826,845,423,427,430,842,280,465
com/serenegiant/usb/UVCCamera.java, line(s) 1050,1056,1061,1067,484,1084
com/socks/library/Util.java, line(s) 13,15
com/socks/library/klog/BaseLog.java, line(s) 29,38,32,26,35,41
com/socks/library/klog/FileLog.java, line(s) 18,21
com/socks/library/klog/JsonLog.java, line(s) 29
com/socks/library/klog/XmlLog.java, line(s) 22
com/tablayout/SlidingScaleTabLayout.java, line(s) 674
com/tablayout/transformer/TabScaleTransformer.java, line(s) 29
com/zhy/http/okhttp/cookie/store/PersistentCookieStore.java, line(s) 142,155,158
com/zhy/http/okhttp/log/LoggerInterceptor.java, line(s) 41,44,45,46,48,51,54,57,59,70,71,72,74,78,80,82,85
com/zhy/http/okhttp/utils/L.java, line(s) 10
ezy/assist/compat/RomUtil.java, line(s) 148
ezy/assist/compat/SettingsCompat.java, line(s) 94,114,125
im/cyrwjqklpq/javaBean/wallet/BankCardListResBean.java, line(s) 83
im/cyrwjqklpq/javaBean/wallet/BillRecordDetailBean.java, line(s) 90
im/cyrwjqklpq/javaBean/wallet/BillRecordResBillListBean.java, line(s) 212
im/cyrwjqklpq/javaBean/wallet/WalletPaymentBankCardBean.java, line(s) 77,89
im/cyrwjqklpq/javaBean/wallet/WalletWithdrawTemplateBean.java, line(s) 69
im/cyrwjqklpq/messenger/AndroidUtilities$LinkMovementMethodMy.java, line(s) 19
im/cyrwjqklpq/messenger/AndroidUtilities.java, line(s) 536,1220,1230,159,216,353,445,459,496,528,573,586,606,615,624,633,730,733,853,868,883,928,946,950,1017,1038,1136,1185,1207,1267,1330,1371,1383,1424,1585,2369
im/cyrwjqklpq/messenger/AnimatedFileDrawableStream.java, line(s) 56
im/cyrwjqklpq/messenger/AppChooserTargetService.java, line(s) 55,97,179
im/cyrwjqklpq/messenger/ApplicationLoader.java, line(s) 77,126,161,185,196,210,220,257,260,271,274,309,70,129,296,324,338,358,375,423
im/cyrwjqklpq/messenger/ContactsController.java, line(s) 372,389,405,655,709,823,833,857,1008,1013,1043,1120,1137,1699,1856,511,537,779,1344,1353,1590,1599,1605,1623,1935,2416
im/cyrwjqklpq/messenger/ContactsSyncAdapterService.java, line(s) 49,30
im/cyrwjqklpq/messenger/DispatchQueue.java, line(s) 26,35,47,61,80
im/cyrwjqklpq/messenger/DownloadController.java, line(s) 859
im/cyrwjqklpq/messenger/Emoji.java, line(s) 192,104,117,128,356,402,422,491,503,729,741
im/cyrwjqklpq/messenger/FileLoadOperation.java, line(s) 597,793,864,1121,1228,1260,425,438,455,710,716,723,729,736,742,749,755,763,823,825,834,842
im/cyrwjqklpq/messenger/FileLoader.java, line(s) 937,1394,1402,1410,1419
im/cyrwjqklpq/messenger/FileLog.java, line(s) 234,259,101,127,152,177,284,309
im/cyrwjqklpq/messenger/FileRefController.java, line(s) 123,636,974
im/cyrwjqklpq/messenger/FileStreamLoadOperation.java, line(s) 132
im/cyrwjqklpq/messenger/FileUploadOperation.java, line(s) 117,141,207,427,549,690
im/cyrwjqklpq/messenger/GcmPushListenerService.java, line(s) 22,35,82,137
im/cyrwjqklpq/messenger/ImageLoader.java, line(s) 1349,1419,1433,1445,1458,1471,1479,194,202,211,234,238,247,253,303,332,351,371,394,405,424,581,590,599,622,626,636,648,822,840,1188,1194,1409,1415,1437,1449,1462,1475,1483,1528,1533,1541,1549,2069,2081,2108,2273,2279,2389
im/cyrwjqklpq/messenger/ImageReceiver.java, line(s) 514,603,650,682
im/cyrwjqklpq/messenger/KeepAliveJob.java, line(s) 28,44,50,72,84
im/cyrwjqklpq/messenger/LocaleController.java, line(s) 800,1951,2060,2097,265,271,560,693,740,748,754,760,878,907,962,1379,1455,1480,1502,1524,1558,1606,1646,1741,1758,1782,2028,2848
im/cyrwjqklpq/messenger/LocationController.java, line(s) 554,637,701
im/cyrwjqklpq/messenger/MediaController$4.java, line(s) 68
im/cyrwjqklpq/messenger/MediaController$5.java, line(s) 26
im/cyrwjqklpq/messenger/MediaController$6.java, line(s) 26
im/cyrwjqklpq/messenger/MediaController$StopMediaObserverRunnable.java, line(s) 25,33
im/cyrwjqklpq/messenger/MediaController$VideoConvertRunnable.java, line(s) 31
im/cyrwjqklpq/messenger/MediaController.java, line(s) 336,727,765,808,813,833,852,864,874,290,295,300,305,322,346,355,413,424,441,475,486,1083,1113,1228,1355,1370,1680,1686,1808,1830,1946,1955,2059,2139,2203,2231,2239,2262,2268,2276,2299,2305,2313,2331,2364,2371,2391,2397,2401,2406,2413,2554
im/cyrwjqklpq/messenger/MediaDataController.java, line(s) 268,407,463,526,670,726,934,1003,1041,1055,1266,1349,1590,1729,1916,1936,2046,2442,2701,2739,2821,2889,2923,2944,2975,3060,3179,3264,3295,3476,3551,3568,3643,3773,3849,3871,3997,4029,4107,4109,4343,4591,4676,4817,4859,4898,4937,4973,5045
im/cyrwjqklpq/messenger/MessageObject.java, line(s) 257,1822,1867,1962,1968
im/cyrwjqklpq/messenger/MessagesController.java, line(s) 2386,2391,2436,2447,2472,2479,2496,2508,3844,3853,5485,5792,5799,5805,5856,5889,5927,7998,8012,8061,8172,8181,8194,8256,8265,8277,8667,8685,8900,10110,1342,3280,3389,3416,3445,5204,5498,5908,6277,6698,7263,7288,8314,8442,8964,9085,9160,9642,10480,10789,10882,10885
im/cyrwjqklpq/messenger/MessagesStorage.java, line(s) 3776,243,279,834,896,932,1038,1075,1118,1191,1285,1344,1356,1440,1479,1535,1575,1609,1611,1657,1715,1744,1842,1918,1963,1997,2079,2216,2292,2361,2421,2465,2467,2549,2629,2669,2699,2866,2921,2952,2975,3002,3031,3092,3179,3248,3387,3441,3518,3577,3641,3656,3703,3746,3787,3838,3900,3921,3957,3998,4064,4093,4165,4224,4270,4310,4416,4472,4493,4529,4650,4753,4794,4874,4908,4946,4968,4995,5012,5074,5085,5101,5110,5164,5204,5269,5357,5390,5524,5564,5593,5667,5706,5746,5804,5817,5894,5956,6028,6057,6089,6204,6257,6322,6362,6402,6635,6689,6766,6822,6865,6886,6907,6929,6949,6960,6975,6990,7018,7041,7075,7110,7144,7178,7215,7249
im/cyrwjqklpq/messenger/MusicBrowserService.java, line(s) 210,302,339,388,517
im/cyrwjqklpq/messenger/MusicPlayerService.java, line(s) 190,391
im/cyrwjqklpq/messenger/NativeLoader.java, line(s) 46,76,82,88,94,99,106
im/cyrwjqklpq/messenger/NotificationBadge.java, line(s) 181,458
im/cyrwjqklpq/messenger/NotificationCenter.java, line(s) 959
im/cyrwjqklpq/messenger/NotificationImageProvider.java, line(s) 107
im/cyrwjqklpq/messenger/NotificationsController.java, line(s) 205,341,2129,180,185,193,216,253,287,308,1357,1371,1976,2053,2066,2081,2108,2112,2121,2135,2193,2225,2333,2367,2371,2380
im/cyrwjqklpq/messenger/ScreenReceiver.java, line(s) 13,27
im/cyrwjqklpq/messenger/SecretChatHelper.java, line(s) 582,1142,659,685,771,1074,1288,1466,1768,1782,1894,1923,1964,1980
im/cyrwjqklpq/messenger/SendMessagesHelper$LocationProvider.java, line(s) 37,95,100,109
im/cyrwjqklpq/messenger/SendMessagesHelper.java, line(s) 612,629,1089,1778,3382,3388,3817,3866,3893,4201,4204,4219,4227
im/cyrwjqklpq/messenger/SharedConfig.java, line(s) 705,119,251,272,286,356,678
im/cyrwjqklpq/messenger/SmsReceiver.java, line(s) 48
im/cyrwjqklpq/messenger/UserConfig.java, line(s) 195
im/cyrwjqklpq/messenger/Utilities.java, line(s) 70,230,246,275,288,299,311,330,347,379
im/cyrwjqklpq/messenger/VideoEncodingService.java, line(s) 36,86,53
im/cyrwjqklpq/messenger/WearDataLayerListenerService.java, line(s) 41,49,65,234,241,58,228,245,341
im/cyrwjqklpq/messenger/XiaomiUtilities.java, line(s) 45
im/cyrwjqklpq/messenger/browser/Browser.java, line(s) 84,99
im/cyrwjqklpq/messenger/camera/CameraController.java, line(s) 163,190,510,527,546,304,320,325,376,398,424,436,468,500,553,582,631,659,662,679,685,706,729,743,795,800,806,811,819,842
im/cyrwjqklpq/messenger/camera/CameraSession.java, line(s) 213,217,174,255,270,346,359,375,380,467
im/cyrwjqklpq/messenger/secretmedia/ExtendedDefaultDataSource.java, line(s) 195
im/cyrwjqklpq/messenger/support/JobIntentService.java, line(s) 128
im/cyrwjqklpq/messenger/support/customtabs/CustomTabsSessionToken.java, line(s) 19,28,37,46
im/cyrwjqklpq/messenger/support/customtabsclient/shared/CustomTabsHelper.java, line(s) 89
im/cyrwjqklpq/messenger/support/fingerprint/FingerprintManagerCompatApi23.java, line(s) 21,30,39
im/cyrwjqklpq/messenger/utils/PlayerUtils.java, line(s) 473,394,453,529,588,643,706,773,1193,1454,1524,1922,1934,1947,1961,1975,1989,2003
im/cyrwjqklpq/messenger/utils/SelectorUtils.java, line(s) 91
im/cyrwjqklpq/messenger/voip/AppConnectionService.java, line(s) 31,68,48,58,16,24
im/cyrwjqklpq/messenger/voip/AudioRecordJNI.java, line(s) 248,66,79,95,114,137,180,203,239,109,211,63,76,92
im/cyrwjqklpq/messenger/voip/AudioTrackJNI.java, line(s) 38,65,111,121,119,32
im/cyrwjqklpq/messenger/voip/JNIUtilities.java, line(s) 80
im/cyrwjqklpq/messenger/voip/VoIPBaseService.java, line(s) 592,685,742,844,886,893,899,1065,1263,1424,1436,1464,1476,1483,174,182,273,526,564,640,733,825,854,1000,1016,1174,1341,1352
im/cyrwjqklpq/messenger/voip/VoIPServerConfig.java, line(s) 19
im/cyrwjqklpq/messenger/voip/VoIPService.java, line(s) 363,448,454,461,702,721,750,757,786,802,969,1086,1106,1262,93,282,339,361,395,418,467,519,576,586,694,726,886,1043,1100,1147,107,388,414,566,741,830,837,847,873,901
im/cyrwjqklpq/phoneformat/PhoneFormat.java, line(s) 101,107,128,137,200,239
im/cyrwjqklpq/sqlite/SQLiteCursor.java, line(s) 98,103
im/cyrwjqklpq/sqlite/SQLiteDatabase.java, line(s) 60,77
im/cyrwjqklpq/sqlite/SQLitePreparedStatement.java, line(s) 107,108
im/cyrwjqklpq/tgnet/ConnectionsManager$DnsTxtLoadTask.java, line(s) 40,20
im/cyrwjqklpq/tgnet/ConnectionsManager$FirebaseTask.java, line(s) 41,21
im/cyrwjqklpq/tgnet/ConnectionsManager$ResolveHostByNameTask.java, line(s) 64,69,90,104,117
im/cyrwjqklpq/tgnet/ConnectionsManager.java, line(s) 198,316,461,469,485,500,512,562,595,603,611,761,768,771,309,327,329,515,579,649,661,685,777,805
im/cyrwjqklpq/tgnet/FCTokenRequestCallback.java, line(s) 44,64,65,118,124,130,138,142
im/cyrwjqklpq/tgnet/NativeByteBuffer.java, line(s) 37,130,145,174,189,209,220,256,292,303,340,392,412,426,442,455,488,515,545,561
im/cyrwjqklpq/tgnet/NetworkConfig.java, line(s) 248,82,105,216
im/cyrwjqklpq/tgnet/SerializedData.java, line(s) 64,72,80,88,119,142,174,189,204,219,255,266,302,313,348,375,390,426,457,473,492,513
im/cyrwjqklpq/tgnet/TLClassStore.java, line(s) 54
im/cyrwjqklpq/tgnet/TLJsonResolve.java, line(s) 86,141,169
im/cyrwjqklpq/translate/MD5.java, line(s) 33
im/cyrwjqklpq/ui/ArticleViewer.java, line(s) 3731,4348,4426,4613,4787,4836,4857,4998,5008,5035,5048,7158,7168,7279,7300,7326,9695,10132,10534,10725,10796,10802,10829,10882
im/cyrwjqklpq/ui/AudioSelectActivity.java, line(s) 281
im/cyrwjqklpq/ui/CacheControlActivity.java, line(s) 229,405,427
im/cyrwjqklpq/ui/CancelAccountDeletionActivity.java, line(s) 137,267,399,957,1075
im/cyrwjqklpq/ui/ChangeBioActivity.java, line(s) 236,247
im/cyrwjqklpq/ui/ChangePhoneActivity.java, line(s) 133,289,681,691,857,1472,1590
im/cyrwjqklpq/ui/ChangePhoneNumberActivity.java, line(s) 186,196
im/cyrwjqklpq/ui/ChangeSignActivity.java, line(s) 152,163
im/cyrwjqklpq/ui/ChangeUsernameActivity.java, line(s) 88,106,497,512
im/cyrwjqklpq/ui/ChannelAdminLogActivity.java, line(s) 960,1410,2483,2492,2501,2510,2519,2528,2537,2546
im/cyrwjqklpq/ui/ChannelCreateActivity.java, line(s) 772,879,1004,1016
im/cyrwjqklpq/ui/ChatActivity.java, line(s) 9912,9948,839,865,894,914,1213,3603,3747,5072,5283,6918,7244,7365,8238,8605,10025,10808,10843,11300,11650,11824,11829,12798,12850,12865,14414,14478,14695,14704,14713,14722,14731,14740,14749,14758
im/cyrwjqklpq/ui/ChatEditActivity.java, line(s) 940
im/cyrwjqklpq/ui/ChatEditTypeActivity.java, line(s) 452,466,498
im/cyrwjqklpq/ui/ChatRightsEditActivity.java, line(s) 606,633
im/cyrwjqklpq/ui/ChatUsersActivity.java, line(s) 2163
im/cyrwjqklpq/ui/ContactAddActivity.java, line(s) 182
im/cyrwjqklpq/ui/ContactsActivity.java, line(s) 518,625,707
im/cyrwjqklpq/ui/ContentPreviewViewer.java, line(s) 776,823,858,879,891,986
im/cyrwjqklpq/ui/CountrySelectActivity.java, line(s) 408,419
im/cyrwjqklpq/ui/DialogsActivity.java, line(s) 1839,2718
im/cyrwjqklpq/ui/DocumentSelectActivity.java, line(s) 145,167,502,692
im/cyrwjqklpq/ui/ExternalActionActivity.java, line(s) 591,595,70,388,436
im/cyrwjqklpq/ui/GroupCreateFinalActivity.java, line(s) 148
im/cyrwjqklpq/ui/GroupEditActivity.java, line(s) 409
im/cyrwjqklpq/ui/GroupInviteActivity.java, line(s) 142,157
im/cyrwjqklpq/ui/GroupStickersActivity.java, line(s) 722
im/cyrwjqklpq/ui/IdenticonActivity.java, line(s) 67
im/cyrwjqklpq/ui/IndexActivity.java, line(s) 301,306,777,806,297,567,583,759,763,768,809
im/cyrwjqklpq/ui/InviteContactsActivity.java, line(s) 570,614,785,811
im/cyrwjqklpq/ui/LanguageSelectActivity.java, line(s) 271,282
im/cyrwjqklpq/ui/LaunchActivity.java, line(s) 178,511,560,567,597,639,685,2127,2342,2400,2695,2925,2959,3057,3061,227,476,527,1032,1185,1193,1244,1371,1468,1486,1503,1524,1552,1608,1646,1753,1779,1789,2004,2120,2222,2230,2504,2513,2788,2991,3181,3249
im/cyrwjqklpq/ui/LaunchAgDialogActivity.java, line(s) 40
im/cyrwjqklpq/ui/LocationActivity.java, line(s) 214,270,795,974,1085,1135,1180,1193,1395,1478,1535,1552,1561
im/cyrwjqklpq/ui/LoginActivity.java, line(s) 374,431,726,1132,1142,1340,2031,2153,3990
im/cyrwjqklpq/ui/Media1Activity.java, line(s) 2200
im/cyrwjqklpq/ui/MediaActivity.java, line(s) 2098
im/cyrwjqklpq/ui/NewContactActivity.java, line(s) 458,472,585
im/cyrwjqklpq/ui/NotificationsCustomSettingsActivity.java, line(s) 430
im/cyrwjqklpq/ui/NotificationsSettingsActivity.java, line(s) 358
im/cyrwjqklpq/ui/PasscodeActivity.java, line(s) 496,606
im/cyrwjqklpq/ui/PassportActivity.java, line(s) 1079,2824,3302,3589,3695,4624,6820,6886,7064,7135,7294,8022,8140
im/cyrwjqklpq/ui/PeopleNearbyActivity.java, line(s) 437,364,573
im/cyrwjqklpq/ui/PhoneBookSelectActivity.java, line(s) 226
im/cyrwjqklpq/ui/PhonebookShareActivity.java, line(s) 520,576,624
im/cyrwjqklpq/ui/PhotoCropActivity.java, line(s) 349,413,336,341,355
im/cyrwjqklpq/ui/PhotoViewer.java, line(s) 1372,4871,9534,9541,9549,9555,456,654,1925,2541,2553,2863,3079,3720,3778,3807,3865,3893,4300,4307,4527,4549,4639,4698,4711,4957,4964,6608,7360,7825,7862,7942,8172,8264,9561
im/cyrwjqklpq/ui/PopupNotificationActivity.java, line(s) 505,1267
im/cyrwjqklpq/ui/PrivacyControlActivity.java, line(s) 119,719
im/cyrwjqklpq/ui/PrivacySettingsActivity.java, line(s) 443,522
im/cyrwjqklpq/ui/ProfileActivity.java, line(s) 271,605,623,1373,1387,1399,1427,2139
im/cyrwjqklpq/ui/ProfileNotificationsActivity.java, line(s) 508,533
im/cyrwjqklpq/ui/SecretMediaViewer.java, line(s) 513,519,560,604,884,1014,1247
im/cyrwjqklpq/ui/SessionsActivity.java, line(s) 368,394
im/cyrwjqklpq/ui/SettingsActivity.java, line(s) 2784
im/cyrwjqklpq/ui/ShareActivity.java, line(s) 77,98
im/cyrwjqklpq/ui/StickersActivity.java, line(s) 408,419,509
im/cyrwjqklpq/ui/TestActivity.java, line(s) 35
im/cyrwjqklpq/ui/ThemeActivity.java, line(s) 1032,1044,1130,1135,1176,1512,1518,1524,1550
im/cyrwjqklpq/ui/ThemeSetUrlActivity.java, line(s) 103,121,454,469,697,708
im/cyrwjqklpq/ui/TwoStepVerificationActivity.java, line(s) 170,1023
im/cyrwjqklpq/ui/VoIPActivity.java, line(s) 227
im/cyrwjqklpq/ui/WallpaperActivity.java, line(s) 460,469,490,514,533,550
im/cyrwjqklpq/ui/WebviewActivity.java, line(s) 92,190,296,307,498,515
im/cyrwjqklpq/ui/actionbar/ActionBarLayout.java, line(s) 187,1476,1667,2274
im/cyrwjqklpq/ui/actionbar/ActionBarPopupWindow.java, line(s) 104,323,385
im/cyrwjqklpq/ui/actionbar/AlertDialog.java, line(s) 911
im/cyrwjqklpq/ui/actionbar/BaseFragment.java, line(s) 136,148,176,191,291,326,417,436,490,504
im/cyrwjqklpq/ui/actionbar/BottomSheet.java, line(s) 613,1037,1100,1117
im/cyrwjqklpq/ui/actionbar/DrawerLayoutContainer.java, line(s) 321
im/cyrwjqklpq/ui/actionbar/Theme.java, line(s) 3021,3063,1178,1234,1242,2137,2201,2776,2783,2835,3324,3345,3358,3480,3489,4706,4713,4722,4729
im/cyrwjqklpq/ui/actionbar/ThemeDescription.java, line(s) 711
im/cyrwjqklpq/ui/actionbar/XAlertDialog.java, line(s) 944,997
im/cyrwjqklpq/ui/activities/LoginActivity.java, line(s) 143,315,70,317
im/cyrwjqklpq/ui/activities/WalletRechargeH5Activity.java, line(s) 133,213
im/cyrwjqklpq/ui/activities/WalletWithdrawActivity.java, line(s) 306,358,373
im/cyrwjqklpq/ui/activities/WalletWithdrawAddNewAccountActivity.java, line(s) 427,434,611,637,693
im/cyrwjqklpq/ui/activities/WqDialogsActivity.java, line(s) 1266,2106
im/cyrwjqklpq/ui/activities/WqDialogsAdapter.java, line(s) 252
im/cyrwjqklpq/ui/adapters/BaseLocationAdapter.java, line(s) 61,83
im/cyrwjqklpq/ui/adapters/ContactsAdapter.java, line(s) 101
im/cyrwjqklpq/ui/adapters/DialogsAdapter.java, line(s) 233
im/cyrwjqklpq/ui/adapters/DialogsSearchAdapter.java, line(s) 355,399,419
im/cyrwjqklpq/ui/adapters/PhonebookSearchAdapter.java, line(s) 38,54
im/cyrwjqklpq/ui/adapters/SearchAdapter.java, line(s) 86,106
im/cyrwjqklpq/ui/adapters/SearchAdapterHelper.java, line(s) 360,484,486,507,570
im/cyrwjqklpq/ui/bottom/BottomBarLayout.java, line(s) 166
im/cyrwjqklpq/ui/cell/FmtDialogCell.java, line(s) 366
im/cyrwjqklpq/ui/cells/AboutLinkCell.java, line(s) 121,131,148,196
im/cyrwjqklpq/ui/cells/ArchiveHintCell.java, line(s) 50,54
im/cyrwjqklpq/ui/cells/AudioPlayerCell.java, line(s) 70,78
im/cyrwjqklpq/ui/cells/BotHelpCell.java, line(s) 102,135,145,162
im/cyrwjqklpq/ui/cells/ChatActionCell.java, line(s) 335,340
im/cyrwjqklpq/ui/cells/ChatMessageCell.java, line(s) 2376,2475,2510,3329,3994,4004,6117,2958,5518,5621
im/cyrwjqklpq/ui/cells/DialogCell.java, line(s) 361
im/cyrwjqklpq/ui/cells/DialogMeUrlCell.java, line(s) 120
im/cyrwjqklpq/ui/cells/DrawerActionCell.java, line(s) 54
im/cyrwjqklpq/ui/cells/DrawerProfileCell.java, line(s) 112,158
im/cyrwjqklpq/ui/cells/PopMenuCell.java, line(s) 48
im/cyrwjqklpq/ui/cells/SharedAudioCell.java, line(s) 79,84
im/cyrwjqklpq/ui/cells/SharedLinkCell.java, line(s) 233,245
im/cyrwjqklpq/ui/cells/ThemesHorizontalListCell.java, line(s) 621,630,636,723
im/cyrwjqklpq/ui/components/AlertsCreator.java, line(s) 1023,1075,1090
im/cyrwjqklpq/ui/components/AnimatedFileDrawable.java, line(s) 193,224
im/cyrwjqklpq/ui/components/AudioPlayerAlert.java, line(s) 855,1290,1305
im/cyrwjqklpq/ui/components/AvatarDrawable.java, line(s) 220,248
im/cyrwjqklpq/ui/components/BlockingUpdateView.java, line(s) 252,274,278
im/cyrwjqklpq/ui/components/ChatActivityEnterView.java, line(s) 1611,1649,2608,3711,3757,3939,4086,4101,4115,4129,4152,4162,4216,4703
im/cyrwjqklpq/ui/components/ChatAttachAlert.java, line(s) 1880
im/cyrwjqklpq/ui/components/ChatAvatarContainer.java, line(s) 280
im/cyrwjqklpq/ui/components/ClippingImageView.java, line(s) 75,151
im/cyrwjqklpq/ui/components/EditTextBoldCursor.java, line(s) 178,314,571,579
im/cyrwjqklpq/ui/components/EditTextCaption.java, line(s) 323,345,405
im/cyrwjqklpq/ui/components/EditTextEmoji.java, line(s) 88,489
im/cyrwjqklpq/ui/components/EmbedBottomSheet.java, line(s) 199,303,318,344,372,418,496,503,684,693,711,821,840,916
im/cyrwjqklpq/ui/components/EmojiView.java, line(s) 589,1459,3441
im/cyrwjqklpq/ui/components/EmojiViewV2.java, line(s) 589,1458,3425
im/cyrwjqklpq/ui/components/ForegroundDetector.java, line(s) 53,86,61,94
im/cyrwjqklpq/ui/components/ImageUpdater.java, line(s) 269,297,320,342
im/cyrwjqklpq/ui/components/InstantCameraView.java, line(s) 489,497,503,879,898,920,1054,1299,1322,1569,1618,1625,1629,1638,1650,1690,1770,2016,449,938,953,984,996,1062,1070,1080,1093,1104,1141,1163,1169,1175,1184,1236,1392,1397,1405,1666,1723,1735,1852,1861,1871,1879,1953,2089
im/cyrwjqklpq/ui/components/LetterDrawable.java, line(s) 60
im/cyrwjqklpq/ui/components/PasscodeView.java, line(s) 140,255,929,938,952,1003,1031,1050
im/cyrwjqklpq/ui/components/PhotoFilterView.java, line(s) 402,419,434,442,452,465,730,736,745,946
im/cyrwjqklpq/ui/components/PhotoPaintView.java, line(s) 438,1263,1270,1297
im/cyrwjqklpq/ui/components/PhotoViewerCaptionEnterView.java, line(s) 112,326,360,426,540,570,584,613,694,707
im/cyrwjqklpq/ui/components/PipRoundVideoView.java, line(s) 255
im/cyrwjqklpq/ui/components/PipVideoView.java, line(s) 406
im/cyrwjqklpq/ui/components/RLottieDrawable.java, line(s) 216,340,416
im/cyrwjqklpq/ui/components/RadioButton.java, line(s) 60,159
im/cyrwjqklpq/ui/components/RecyclerListView.java, line(s) 595,807,820,1498,1506
im/cyrwjqklpq/ui/components/ShareAlert.java, line(s) 941
im/cyrwjqklpq/ui/components/SpannableStringLight.java, line(s) 24,41,58
im/cyrwjqklpq/ui/components/StaticLayoutEx.java, line(s) 58,122,155,161,172,177,182,216,249,257
im/cyrwjqklpq/ui/components/StickersAlert.java, line(s) 118,797,833,911
im/cyrwjqklpq/ui/components/TermsOfServiceView.java, line(s) 165
im/cyrwjqklpq/ui/components/ThemeEditorView.java, line(s) 99,107,1160,1406,1611
im/cyrwjqklpq/ui/components/TimerDrawable.java, line(s) 78
im/cyrwjqklpq/ui/components/VideoTimelinePlayView.java, line(s) 299,356,384
im/cyrwjqklpq/ui/components/VideoTimelineView.java, line(s) 229,286,314
im/cyrwjqklpq/ui/components/WallpaperUpdater.java, line(s) 85,101,124,150,181,184,196,212
im/cyrwjqklpq/ui/components/WebPlayerView.java, line(s) 463,384,443,519,578,633,696,763,1183,1444,1492,1852,1864,1877,1891,1905,1919,1933
im/cyrwjqklpq/ui/components/compress/Luban.java, line(s) 86,85
im/cyrwjqklpq/ui/components/paint/RenderView.java, line(s) 307,315,325,338,349,359,378,498
im/cyrwjqklpq/ui/components/paint/Shader.java, line(s) 20,28,82,92
im/cyrwjqklpq/ui/components/paint/Slice.java, line(s) 22,53
im/cyrwjqklpq/ui/components/paint/Utils.java, line(s) 12
im/cyrwjqklpq/ui/components/toast/ToastUtils.java, line(s) 77
im/cyrwjqklpq/ui/components/voip/CallSwipeView.java, line(s) 95
im/cyrwjqklpq/ui/components/voip/DarkTheme.java, line(s) 2381
im/cyrwjqklpq/ui/components/voip/VoIPHelper.java, line(s) 154,570
im/cyrwjqklpq/ui/dialogs/McShareDialog.java, line(s) 198
im/cyrwjqklpq/ui/fragments/BaseFmts.java, line(s) 213,268,282,304
im/cyrwjqklpq/ui/fragments/CallRecordsFragment.java, line(s) 593,195
im/cyrwjqklpq/ui/fragments/ContactsFragment.java, line(s) 627
im/cyrwjqklpq/ui/fragments/DialogsFragment.java, line(s) 490,505,1671
im/cyrwjqklpq/ui/fragments/DiscoveryFragment.java, line(s) 207,256
im/cyrwjqklpq/ui/fragments/MeFragmentV2.java, line(s) 480,971,1029,1044
im/cyrwjqklpq/ui/fragments/TabWebFragment.java, line(s) 182,287,324,347,511
im/cyrwjqklpq/ui/fragments/adapter/FmtContactsAdapter.java, line(s) 142
im/cyrwjqklpq/ui/hui/CameraViewActivity.java, line(s) 1754
im/cyrwjqklpq/ui/hui/CharacterParser.java, line(s) 30
im/cyrwjqklpq/ui/hui/WebViewAppCompatActivity.java, line(s) 101,212
im/cyrwjqklpq/ui/hui/adapter/AddNewCallAdapter.java, line(s) 78
im/cyrwjqklpq/ui/hui/adapter/CreateGroupAdapter.java, line(s) 95
im/cyrwjqklpq/ui/hui/adapter/CreateSecureAdapter.java, line(s) 81
im/cyrwjqklpq/ui/hui/adapter/MyDialogsAdapter.java, line(s) 240
im/cyrwjqklpq/ui/hui/adapter/NewChatAdapter.java, line(s) 86
im/cyrwjqklpq/ui/hui/adapter/SelectContactsAdapter.java, line(s) 85
im/cyrwjqklpq/ui/hui/adapter/StartChatAdapter.java, line(s) 85
im/cyrwjqklpq/ui/hui/adapter/grouping/AddGroupingUserAdapter.java, line(s) 84
im/cyrwjqklpq/ui/hui/adapter/pageAdapter/PageSelectionAdapter.java, line(s) 78
im/cyrwjqklpq/ui/hui/adapter/pageAdapter/PageStickerAdapter.java, line(s) 110
im/cyrwjqklpq/ui/hui/chats/CreateGroupFinalActivity.java, line(s) 156
im/cyrwjqklpq/ui/hui/chats/GroupShareActivity.java, line(s) 211
im/cyrwjqklpq/ui/hui/chats/MryDialogsActivity.java, line(s) 1743,2576
im/cyrwjqklpq/ui/hui/chats/NewChatActivity.java, line(s) 397
im/cyrwjqklpq/ui/hui/chats/ProfileGroupActivity.java, line(s) 360,836,854,1049,1599,1613,1625,1653,2776
im/cyrwjqklpq/ui/hui/chats/StartChatActivity.java, line(s) 352
im/cyrwjqklpq/ui/hui/contacts/AddContactsActivity.java, line(s) 261
im/cyrwjqklpq/ui/hui/discovery/ActionIntroActivity.java, line(s) 381,427,462,507
im/cyrwjqklpq/ui/hui/discovery/NearPersonAndGroupActivity.java, line(s) 480,484,489,492,499,552,416,639
im/cyrwjqklpq/ui/hui/discovery/QrScanActivity.java, line(s) 308,334
im/cyrwjqklpq/ui/hui/discoveryweb/DiscoveryJumpPausedFloatingView.java, line(s) 254,526
im/cyrwjqklpq/ui/hui/discoveryweb/DiscoveryJumpToPage.java, line(s) 110,137,541,554,588,758
im/cyrwjqklpq/ui/hui/friendscircle/fcHelper/OKHttpStreamFetcher.java, line(s) 44,43
im/cyrwjqklpq/ui/hui/friendscircle/okhttphelper/AESHelper.java, line(s) 62,75
im/cyrwjqklpq/ui/hui/friendscircle/okhttphelper/MD5Utils.java, line(s) 21,88,92,93
im/cyrwjqklpq/ui/hui/friendscircle/okhttphelper/OkHttpStringCallBack.java, line(s) 69,61,70
im/cyrwjqklpq/ui/hui/friendscircle_v1/adapter/FcDetailAdapter.java, line(s) 187
im/cyrwjqklpq/ui/hui/friendscircle_v1/adapter/FcHomeAdapter.java, line(s) 179,690
im/cyrwjqklpq/ui/hui/friendscircle_v1/adapter/UserFcListAdapter.java, line(s) 165
im/cyrwjqklpq/ui/hui/friendscircle_v1/base/BaseFcActivity.java, line(s) 286,354,459,203,217,239,320,340,482
im/cyrwjqklpq/ui/hui/friendscircle_v1/base/BaseFcFragment.java, line(s) 378,446,551,251,265,287,412,432,574
im/cyrwjqklpq/ui/hui/friendscircle_v1/base/CommFcListActivity.java, line(s) 159
im/cyrwjqklpq/ui/hui/friendscircle_v1/base/CommFcListFragment.java, line(s) 165,169,180
im/cyrwjqklpq/ui/hui/friendscircle_v1/fragments/FcFollowFragment.java, line(s) 323,909
im/cyrwjqklpq/ui/hui/friendscircle_v1/fragments/FcHomeFragment.java, line(s) 238,790,842
im/cyrwjqklpq/ui/hui/friendscircle_v1/fragments/FcRecommendFragment.java, line(s) 233,764,816
im/cyrwjqklpq/ui/hui/friendscircle_v1/helper/FcDBHelper.java, line(s) 150,156,165,167
im/cyrwjqklpq/ui/hui/friendscircle_v1/player/logger/ExoPlayerLogger.java, line(s) 89,93,111,114,127,134,151,156,173,176,182,190,198,216,221,225,227,231,233,237,241,245,249,253,257,261,265,269,273,287,291,295,311,314,317,320,323,326,329,332,103,303
im/cyrwjqklpq/ui/hui/friendscircle_v1/player/player/AbsBaseVideoPlayer.java, line(s) 36,47,54,63,70,78,90
im/cyrwjqklpq/ui/hui/friendscircle_v1/player/player/VideoPlayerManager.java, line(s) 385
im/cyrwjqklpq/ui/hui/friendscircle_v1/player/utils/Utils.java, line(s) 112,116
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/FcPageDetailActivity.java, line(s) 148,192,324,343,847
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/FcPageMineActivity.java, line(s) 962,1011
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/FcPageOthersActivity.java, line(s) 1028
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/FcPublishActivity.java, line(s) 744,998,1440,894,1443,1453
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/FcTopicMainActivity.java, line(s) 835,884
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/ImagePreSelectorActivity.java, line(s) 1608
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/ImagePreviewActivity.java, line(s) 1326,9017,9024,9032,9038,544,742,1872,2516,2529,2825,3032,3740,3796,3825,3883,3911,4323,4330,4535,4557,4651,4707,4720,6302,7002,7375,7412,7670,7757,9044
im/cyrwjqklpq/ui/hui/friendscircle_v1/ui/ImageSelectorActivity.java, line(s) 2087
im/cyrwjqklpq/ui/hui/friendscircle_v1/utils/KeyboardUtils.java, line(s) 47,190,197,237,168,206,223
im/cyrwjqklpq/ui/hui/friendscircle_v1/utils/StatusBarHeightUtil.java, line(s) 21
im/cyrwjqklpq/ui/hui/friendscircle_v1/utils/ViewUtil.java, line(s) 17
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/FCIndexBar.java, line(s) 117
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/FcChildReplyListDialog.java, line(s) 204
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/FcDoReplyDialog.java, line(s) 185,392
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/flowLayout/TagAdapter.java, line(s) 84,88
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/flowLayout/TagFlowLayout.java, line(s) 121
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/panel/KPSwitchRootLayoutHandler.java, line(s) 35,46,50,56,60
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/richtext/TextCommonUtils.java, line(s) 246,274,280
im/cyrwjqklpq/ui/hui/friendscircle_v1/view/toast/FcToastUtils.java, line(s) 82
im/cyrwjqklpq/ui/hui/login/ChangePersonalInformationActivity.java, line(s) 478
im/cyrwjqklpq/ui/hui/login/LoginPasswordContronllerActivity.java, line(s) 180
im/cyrwjqklpq/ui/hui/login/PcScanCodeLoginActivity.java, line(s) 108,145
im/cyrwjqklpq/ui/hui/mine/AboutAppActivity.java, line(s) 208,293,344,359
im/cyrwjqklpq/ui/hui/mine/DataUsageActivity.java, line(s) 348
im/cyrwjqklpq/ui/hui/mine/MrySessionsActivity.java, line(s) 684,709
im/cyrwjqklpq/ui/hui/mine/MryThemeActivity.java, line(s) 1009,1042,1054,1140,1145,1186,1524,1530,1536,1562
im/cyrwjqklpq/ui/hui/mine/PrivacyAndSafeActivity.java, line(s) 279
im/cyrwjqklpq/ui/hui/mine/PrivacySecurityActivity.java, line(s) 228
im/cyrwjqklpq/ui/hui/mine/QrCodeActivity.java, line(s) 269
im/cyrwjqklpq/ui/hui/packet/RedpktGroupSendActivity.java, line(s) 774,1011,1167,1218,1233
im/cyrwjqklpq/ui/hui/packet/RedpktSendActivity.java, line(s) 416,610,799,850,865
im/cyrwjqklpq/ui/hui/packet/RedpktSendActivity_back.java, line(s) 413,614,803,854,869
im/cyrwjqklpq/ui/hui/packet/fragments/PacketLuckyFragment.java, line(s) 428
im/cyrwjqklpq/ui/hui/packet/fragments/PacketNormalFragment.java, line(s) 445
im/cyrwjqklpq/ui/hui/packet/fragments/PacketSpecialFragment.java, line(s) 389
im/cyrwjqklpq/ui/hui/packet/pop/RedPacketViewHolder.java, line(s) 213,218,223
im/cyrwjqklpq/ui/hui/transfer/TransferSendActivity.java, line(s) 423,649,854,905,920
im/cyrwjqklpq/ui/hui/transfer/TransferSendActivity_back.java, line(s) 423,657,861,912,927
im/cyrwjqklpq/ui/hui/transfer/TransferStatusActivity.java, line(s) 309,488
im/cyrwjqklpq/ui/hui/transfer/TransferStatusActivity_back.java, line(s) 348,527
im/cyrwjqklpq/ui/hui/views/SilderRelativeLayout.java, line(s) 93,103
im/cyrwjqklpq/ui/hui/visualcall/AVideoCallInterface.java, line(s) 74,92,107,117,161,179,184,202
im/cyrwjqklpq/ui/hui/visualcall/BaseCallActivity.java, line(s) 228,262,358,420,422,156,217,330
im/cyrwjqklpq/ui/hui/visualcall/FlowService.java, line(s) 260,208
im/cyrwjqklpq/ui/hui/visualcall/PermissionUtils.java, line(s) 66,71,89,93,113,116,136,155,166,203,217,225,77,230,52,60,62,176,178,181,215,82,172
im/cyrwjqklpq/ui/hui/visualcall/RingUtils.java, line(s) 169,65
im/cyrwjqklpq/ui/hui/visualcall/ThreadUtils.java, line(s) 54
im/cyrwjqklpq/ui/hui/visualcall/VisualCallActivity.java, line(s) 311,315,379,410,467,712,816,907,929,956,961,1075,1101,1259,1291,1335,1337,1364,1399,1403,1429,1433,1442,1466,1470,1515,1746,654,1066,1489,792,796
im/cyrwjqklpq/ui/hui/visualcall/VisualCallReceiveActivity.java, line(s) 466,506,588,627,755,861,1001,1029,1078,1082,1180
im/cyrwjqklpq/ui/hui/visualcall/VisualCallReceiveService.java, line(s) 51
im/cyrwjqklpq/ui/hviews/MryCheckBox.java, line(s) 96
im/cyrwjqklpq/ui/hviews/MyScrollView.java, line(s) 481,547
im/cyrwjqklpq/ui/hviews/PasswordEditText.java, line(s) 138,291
im/cyrwjqklpq/ui/hviews/dialogs/XDialog.java, line(s) 672
im/cyrwjqklpq/ui/hviews/dragView/DragCallBack.java, line(s) 235
im/cyrwjqklpq/ui/hviews/dragView/DragHelperFrameLayout.java, line(s) 169
im/cyrwjqklpq/ui/hviews/helper/MryDeviceHelper.java, line(s) 44,53
im/cyrwjqklpq/ui/hviews/helper/MryDrawableHelper.java, line(s) 159
im/cyrwjqklpq/ui/hviews/helper/MryNotchHelper.java, line(s) 48,64,67,368,370,372,45,61
im/cyrwjqklpq/ui/hviews/page/PagerConfig.java, line(s) 43,37
im/cyrwjqklpq/ui/hviews/page/PagerGridLayoutManager.java, line(s) 475,479,513,517
im/cyrwjqklpq/ui/hviews/pop/BasePopup.java, line(s) 150,154
im/cyrwjqklpq/ui/hviews/slidemenu/SwipeLayout.java, line(s) 800,805
im/cyrwjqklpq/ui/hviews/swipelist/reservation/TopWrappedDividerItemDecoration.java, line(s) 28
im/cyrwjqklpq/ui/load/animation/SpriteAnimatorBuilder.java, line(s) 145
im/cyrwjqklpq/ui/newcall/NewCallActivity.java, line(s) 317
im/cyrwjqklpq/ui/settings/CacheControlSettingActivity.java, line(s) 193
im/cyrwjqklpq/ui/settings/NoticeAndSoundSettingActivity.java, line(s) 351,412,473
im/cyrwjqklpq/ui/utils/AppUpdater.java, line(s) 85,147,160
im/cyrwjqklpq/ui/utils/ChatActionBarHelper.java, line(s) 295
im/cyrwjqklpq/ui/utils/DownloadUtils.java, line(s) 186,219
im/cyrwjqklpq/ui/utils/QrCodeParseUtil.java, line(s) 138,153,198,235
im/cyrwjqklpq/ui/utils/ThirdPartSdkInitUtil.java, line(s) 42,70,101,98
im/cyrwjqklpq/ui/utils/number/MoneyUtil.java, line(s) 147
im/cyrwjqklpq/ui/utils/picture/PictureUtil.java, line(s) 72
im/cyrwjqklpq/ui/utils/translate/DecodeEngine.java, line(s) 116,120,136,143,171,175,269,291,299,317,325,380,384,419,447
im/cyrwjqklpq/ui/utils/translate/ssrc/SSRC.java, line(s) 58,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,325,329,332,553,567,650,715,716,717,718,735,737,739,811,953,1142,1146,1190,1284,1285,1286,1287,1301,1303,1305,1354,1360
im/cyrwjqklpq/ui/utils/translate/utils/AudioFileUtils.java, line(s) 32,35,56,111,113,134,150
np/log/NPCrashHandler.java, line(s) 96,53,87,98,137
org/webrtc/ali/AliHardwareAudioEncoder.java, line(s) 114,127,176,68
org/webrtc/ali/USBAudioDevice.java, line(s) 67
org/webrtc/alirtcInterface/ALI_RTC_INTERFACE_IMPL.java, line(s) 400,691,711,717,732,738,1268,288,293,303,342,347,352,357,362,367,372,377,382,387,335
org/webrtc/alirtcInterface/SophonEngine.java, line(s) 275
org/webrtc/alirtcInterface/SophonEngineImpl.java, line(s) 82,222,247,256,266,321,333,430,439,449,509,671,99,102,104,197,299,83,122,300,410,414,1211
org/webrtc/audio/AppRTCAudioManager.java, line(s) 257,271,304,346,389,398,94,99,109,112,178,190,201,213,242,254,260,269,292,296,318,328,332,349,391,500,501,531,551,557
org/webrtc/audio/AppRTCBluetoothManager.java, line(s) 61,64,72,78,94,109,113,121,123,127,132,137,142,159,190,191,193,199,214,219,228,234,240,248,255,260,264,266,298,301,303,310,316,322,331,341,344,355,178,183,221,225,118,161,165,174,348
org/webrtc/audio/AppRTCProximitySensor.java, line(s) 26,33,43,71,74,81,126,61
org/webrtc/sdk/SophonSurfaceView.java, line(s) 58,68,77,34
org/webrtc/utils/AppRTCUtils.java, line(s) 21
org/webrtc/utils/CpuMonitor.java, line(s) 103,114,121,128,167,240,181,186,188,303,338,365,371,374,377
org/webrtc/utils/MemoryMonitor.java, line(s) 33,40,63,69
org/webrtc/utils/NetworkMonitor.java, line(s) 49,55
pub/devrel/easypermissions/EasyPermissions.java, line(s) 138,140,34
pub/devrel/easypermissions/helper/ActivityPermissionHelper.java, line(s) 38
pub/devrel/easypermissions/helper/BaseSupportPermissionsHelper.java, line(s) 22

信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
im/cyrwjqklpq/messenger/AndroidUtilities.java, line(s) 8,1183
im/cyrwjqklpq/ui/ChangeUsernameActivity.java, line(s) 4,85
im/cyrwjqklpq/ui/ChannelCreateActivity.java, line(s) 8,769
im/cyrwjqklpq/ui/ChatActivity.java, line(s) 10,11643
im/cyrwjqklpq/ui/ChatEditTypeActivity.java, line(s) 4,449,463
im/cyrwjqklpq/ui/GroupInviteActivity.java, line(s) 4,138
im/cyrwjqklpq/ui/PhonebookShareActivity.java, line(s) 4,573,613
im/cyrwjqklpq/ui/ProfileActivity.java, line(s) 5,1370,1395
im/cyrwjqklpq/ui/StickersActivity.java, line(s) 4,416
im/cyrwjqklpq/ui/ThemeSetUrlActivity.java, line(s) 4,100
im/cyrwjqklpq/ui/components/EmbedBottomSheet.java, line(s) 9,819
im/cyrwjqklpq/ui/components/ShareAlert.java, line(s) 8,934
im/cyrwjqklpq/ui/dialogs/McShareDialog.java, line(s) 5,234
im/cyrwjqklpq/ui/hui/chats/ProfileGroupActivity.java, line(s) 11,1596,1621
im/cyrwjqklpq/ui/hui/discovery/QrScanResultActivity.java, line(s) 4,65
im/cyrwjqklpq/ui/hui/packet/BillDetailsActivity.java, line(s) 4,311

信息 应用程序可以写入应用程序目录。敏感信息应加密

应用程序可以写入应用程序目录。敏感信息应加密


Files:
com/alivc/rtc/device/core/persistent/TransactionXMLFile.java, line(s) 17

信息 应用与Firebase数据库通信

该应用与位于 https://cyrwjqklpq-48b0d.firebaseio.com 的 Firebase 数据库进行通信

安全 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/bjz/comm/net/factory/ApiFactory.java, line(s) 50,50
com/bjz/comm/net/factory/ApiGameFactory.java, line(s) 48,48
com/bjz/comm/net/factory/ApiHuanHuiFactory.java, line(s) 41,41
com/bjz/comm/net/factory/ApiMPFactory.java, line(s) 46,46
com/bjz/comm/net/factory/ApiTranslateAudioFactory.java, line(s) 40,40
com/zhy/http/okhttp/https/HttpsUtils.java, line(s) 110,174,42,109,135,173,98,108,108,172,172

安全 此应用程序可能具有Root检测功能

此应用程序可能具有Root检测功能
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md#testing-root-detection-mstg-resilience-1

Files:
im/cyrwjqklpq/ui/utils/SimulatorUtil.java, line(s) 19

安全 Firebase远程配置已禁用

Firebase远程配置URL ( https://firebaseremoteconfig.googleapis.com/v1/projects/194512522065/namespaces/firebase:fetch?key=AIzaSyC6uk1nvjb5BYzqEzgaWy_iTryf5373Nyw ) 已禁用。响应内容如下所示:

{
    "state": "NO_TEMPLATE"
}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (www.ntsc.ac.cn) 通信。

{'ip': '159.226.242.43', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (impyq.gz.bcebos.com) 通信。

{'ip': '121.228.183.252', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '苏州', 'latitude': '31.311365', 'longitude': '120.617691'}

安全评分: ( ⚘ 1.8.0)