安全分析报告: CloudStream Remix v2.5

安全分数


安全分数 31/100

风险评级


等级

  1. A
  2. B
  3. C
  4. F

严重性分布 (%)


隐私风险

1

用户/设备跟踪器


调研结果

高危 17
中危 25
信息 3
安全 1
关注 3

高危 应用程序容易受到 Janus 漏洞的影响

应用程序使用 v1 签名方案进行签名,如果仅使用 v1 签名方案进行签名,则在 Android 5.0-8.0 上容易受到 Janus 漏洞的影响。在使用 v1 和 v2/v3 方案签名的 Android 5.0-7.0 上运行的应用程序也容易受到攻击。

高危 Activity (com.lagradost.cloudstream3.ui.player.DownloadedPlayerActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (27) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.lagradost.cloudstream3.ui.player.DownloadedPlayerActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (com.lagradost.cloudstream3.MainActivity) 容易受到 Android Task Hijacking/StrandHogg 的攻击。

活动不应将启动模式属性设置为“singleTask”。 然后,其他应用程序可以将恶意活动放置在活动栈顶部,从而导致任务劫持/StrandHogg 1.0 漏洞。 这使应用程序成为网络钓鱼攻击的易受攻击目标。 可以通过将启动模式属性设置为“singleInstance”或设置空 taskAffinity (taskAffinity="") 属性来修复此漏洞。 您还可以将应用的目标 SDK 版本 (27) 更新到 28 或更高版本以在平台级别修复此问题。

高危 Activity (com.lagradost.cloudstream3.MainActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (com.lagradost.cloudstream3.ui.account.AccountSelectActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (androidx.test.core.app.InstrumentationActivityInvoker$BootstrapActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (androidx.test.core.app.InstrumentationActivityInvoker$EmptyActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (androidx.test.core.app.InstrumentationActivityInvoker$EmptyFloatingActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 Activity (com.applisto.appcloner.classes.DefaultProvider$MyActivity) 容易受到StrandHogg 2.0的攻击

已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (27) 更新到 29 或更高版本以在平台级别修复此问题。

高危 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/lagradost/cloudstream3/extractors/Rabbitstream.java, line(s) 122
com/lagradost/cloudstream3/extractors/helper/GogoHelper.java, line(s) 70
com/lagradost/cloudstream3/utils/M3u8Helper2.java, line(s) 81

高危 默认情况下,调用Cipher.getInstance("AES")将返回AES ECB模式。众所周知,ECB模式很弱,因为它导致相同明文块的密文相同

默认情况下,调用Cipher.getInstance("AES")将返回AES ECB模式。众所周知,ECB模式很弱,因为它导致相同明文块的密文相同
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-block-cipher-mode

Files:
com/applisto/appcloner/classes/util/SimpleCrypt.java, line(s) 55

高危 启用了调试配置。生产版本不能是可调试的

启用了调试配置。生产版本不能是可调试的
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
andhook/lib/BuildConfig.java, line(s) 3,6
com/applisto/appcloner/classes/BuildConfig.java, line(s) 3,6

高危 已启用远程WebView调试

已启用远程WebView调试
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
com/lagradost/cloudstream3/network/WebViewResolver$resolveUsingWebView$6.java, line(s) 74,8,9

高危 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击

不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#webview-server-certificate-verification

Files:
com/lagradost/cloudstream3/network/WebViewResolver$resolveUsingWebView$6.java, line(s) 133,131

高危 使用弱加密算法

使用弱加密算法
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/lagradost/cloudstream3/extractors/VidSrcTo.java, line(s) 159,178
com/lagradost/cloudstream3/extractors/Vidplay.java, line(s) 164,183

高危 Malicious domain found - yip.su

{'ip': '172.67.169.89', 'country_short': 'US', 'country_long': '美国', 'region': '加利福尼亚', 'city': '旧金山', 'latitude': '37.775700', 'longitude': '-122.395203'}

中危 应用程序已启用明文网络流量

[android:usesCleartextTraffic=true]
应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。

中危 应用程序数据可以被备份

[android:allowBackup=true]
这个标志允许任何人通过adb备份你的应用程序数据。它允许已经启用了USB调试的用户从设备上复制应用程序数据。

中危 Activity设置了TaskAffinity属性

(com.lagradost.cloudstream3.ui.player.DownloadedPlayerActivity)
如果设置了 taskAffinity,其他应用程序可能会读取发送到属于另一个任务的 Activity 的 Intent。为了防止其他应用程序读取发送或接收的 Intent 中的敏感信息,请始终使用默认设置,将 affinity 保持为包名

中危 Activity (com.lagradost.cloudstream3.ui.player.DownloadedPlayerActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (com.lagradost.cloudstream3.MainActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (androidx.work.impl.background.systemjob.SystemJobService) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Broadcast Receiver (androidx.work.impl.diagnostics.DiagnosticsReceiver) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.DUMP [android:exported=true]
发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Activity (androidx.test.core.app.InstrumentationActivityInvoker$BootstrapActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (androidx.test.core.app.InstrumentationActivityInvoker$EmptyActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (androidx.test.core.app.InstrumentationActivityInvoker$EmptyFloatingActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Broadcast Receiver (androidx.profileinstaller.ProfileInstallReceiver) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.DUMP [android:exported=true]
发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Content Provider (com.applisto.appcloner.classes.DefaultProvider) 未被保护。

[android:exported=true]
发现 Content Provider与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Service (com.applisto.appcloner.service.RemoteService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Broadcast Receiver (com.applisto.appcloner.classes.DefaultProvider$DefaultReceiver) 未被保护。

[android:exported=true]
发现 Broadcast Receiver与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 Activity (com.applisto.appcloner.classes.DefaultProvider$MyActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

中危 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
coil3/intercept/EngineInterceptor.java, line(s) 109
coil3/memory/MemoryCache.java, line(s) 93
coil3/memory/MemoryCacheService.java, line(s) 31
coil3/request/ImageRequest.java, line(s) 138,138
coil3/request/Options.java, line(s) 46
coil3/request/SuccessResult.java, line(s) 41
coil3/transform/Transformation.java, line(s) 29
com/lagradost/api/BuildConfig.java, line(s) 9
com/lagradost/cloudstream3/BuildConfig.java, line(s) 11
com/lagradost/cloudstream3/MainAPIKt.java, line(s) 48
com/lagradost/cloudstream3/MainActivity.java, line(s) 127,128
com/lagradost/cloudstream3/extractors/MailRu.java, line(s) 154
com/lagradost/cloudstream3/extractors/Rabbitstream.java, line(s) 37
com/lagradost/cloudstream3/extractors/WcoStream.java, line(s) 136
com/lagradost/cloudstream3/extractors/helper/NineAnimeHelper.java, line(s) 21,20
com/lagradost/cloudstream3/extractors/helper/WcoHelper.java, line(s) 156,75
com/lagradost/cloudstream3/plugins/PluginManagerKt.java, line(s) 10
com/lagradost/cloudstream3/plugins/VotingApi.java, line(s) 23
com/lagradost/cloudstream3/syncproviders/InAppAuthAPI.java, line(s) 94
com/lagradost/cloudstream3/syncproviders/providers/AniListApi.java, line(s) 66,35,36,37
com/lagradost/cloudstream3/syncproviders/providers/Dropbox.java, line(s) 18
com/lagradost/cloudstream3/syncproviders/providers/MALApi.java, line(s) 81,45,46,47,48
com/lagradost/cloudstream3/syncproviders/providers/OpenSubtitlesApi.java, line(s) 40,35,326
com/lagradost/cloudstream3/syncproviders/providers/SimklApi.java, line(s) 96,206,69,70,65,544
com/lagradost/cloudstream3/syncproviders/providers/SubDlApi.java, line(s) 35,653,286,542
com/lagradost/cloudstream3/ui/library/LibraryFragment.java, line(s) 81
com/lagradost/cloudstream3/ui/library/LibraryViewModelKt.java, line(s) 7
com/lagradost/cloudstream3/ui/player/CS3IPlayer.java, line(s) 471
com/lagradost/cloudstream3/ui/player/CS3IPlayerKt.java, line(s) 7
com/lagradost/cloudstream3/ui/player/FullScreenPlayerKt.java, line(s) 14
com/lagradost/cloudstream3/ui/quicksearch/QuickSearchFragment.java, line(s) 56,59
com/lagradost/cloudstream3/ui/search/SearchHistoryItem.java, line(s) 75
com/lagradost/cloudstream3/ui/search/SearchViewModelKt.java, line(s) 7
com/lagradost/cloudstream3/ui/settings/extensions/ExtensionsViewModelKt.java, line(s) 7
com/lagradost/cloudstream3/ui/setup/SetupFragmentLanguageKt.java, line(s) 7
com/lagradost/cloudstream3/ui/subtitles/ChromecastSubtitlesFragmentKt.java, line(s) 7
com/lagradost/cloudstream3/ui/subtitles/SubtitlesFragmentKt.java, line(s) 9,8,10
com/uwetrottmann/tmdb2/Tmdb.java, line(s) 47
org/jsoup/helper/W3CDom.java, line(s) 211
org/jsoup/internal/SharedConstants.java, line(s) 8,4,6,7
org/jsoup/nodes/DocumentType.java, line(s) 13,14,16
org/schabi/newpipe/extractor/services/peertube/PeertubeParsingHelper.java, line(s) 39,41
org/schabi/newpipe/extractor/services/soundcloud/extractors/SoundcloudPlaylistInfoItemExtractor.java, line(s) 16,17,18
org/schabi/newpipe/extractor/services/youtube/extractors/YoutubeCommentsExtractor.java, line(s) 39,40

中危 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
com/applisto/appcloner/classes/BundleObb.java, line(s) 106
com/hippo/unifile/DocumentsContractApi19.java, line(s) 84
com/lagradost/cloudstream3/plugins/PluginManager.java, line(s) 338,81
com/lagradost/cloudstream3/ui/download/DownloadViewModel.java, line(s) 431
com/lagradost/cloudstream3/ui/subtitles/SubtitlesFragment.java, line(s) 223,496
com/lagradost/safefile/MediaFileKt.java, line(s) 71
com/lagradost/safefile/SafeFile.java, line(s) 553
io/github/anilbeesetti/nextlib/mediainfo/PathUtil.java, line(s) 50
org/acra/file/Directory.java, line(s) 53,103

中危 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
coil3/decode/SourceImageSource.java, line(s) 74
com/applisto/appcloner/classes/Utils.java, line(s) 427
com/lagradost/cloudstream3/actions/OpenInAppActionKt.java, line(s) 61
com/lagradost/cloudstream3/subtitles/SubtitleResource.java, line(s) 35,53
j$/nio/file/Files.java, line(s) 167,171
org/junit/rules/TemporaryFolder.java, line(s) 79,164

中危 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
j$/util/concurrent/ThreadLocalRandom.java, line(s) 14
org/jsoup/helper/DataUtil.java, line(s) 17
org/junit/runner/manipulation/Ordering.java, line(s) 7
org/schabi/newpipe/extractor/services/youtube/YoutubeParsingHelper.java, line(s) 28
org/schabi/newpipe/extractor/utils/RandomStringFromAlphabetGenerator.java, line(s) 3

中危 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/lagradost/cloudstream3/extractors/Chillx.java, line(s) 62

中危 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
com/lagradost/cloudstream3/ui/WebviewFragment.java, line(s) 68,69

中危 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
andhook/lib/xposed/XposedHelpers.java, line(s) 1087
com/lagradost/cloudstream3/extractors/Rabbitstream.java, line(s) 113

中危 IP地址泄露

IP地址泄露


Files:
com/applisto/appcloner/classes/HostsBlocker.java, line(s) 147
com/lagradost/cloudstream3/network/DohProvidersKt.java, line(s) 38,38,53,63,63,58,58,33,33,48,48,53,43,43

中危 应用程序包含隐私跟踪程序

此应用程序有多个1隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
"biometric_key" : "biometric_key"
"extension_authors" : "Lahaanshaha"
"player_resize_enabled_key" : "player_resize_enabled_key"
"simkl_key" : "simkl_key"
"download_path_key_visual" : "download_path_key_visual"
"rotate_video_key" : "rotate_video_key"
"example_password" : "wachtwoord123"
"redo_setup_key" : "redo_setup_key"
"extension_authors" : "Pembuat"
"player_default_key" : "player_default_key"
"poster_ui_key" : "poster_ui_key"
"double_tap_enabled_key" : "double_tap_enabled_key"
"nginx_key" : "nginx_key"
"example_username" : "MijnCoolGebruikersnaam"
"extension_authors" : "Auteurs"
"test_providers_key" : "test_providers_key"
"example_password" : "motdepasse123"
"playback_speed_enabled_key" : "playback_speed_enabled_key"
"battery_optimisation_key" : "battery_optimisation"
"pref_category_android_tv_key" : "pref_category_android_tv_key"
"enable_nsfw_on_providers_key" : "enable_nsfw_on_providers_key"
"double_tap_seek_time_key" : "double_tap_seek_time_key2"
"quality_pref_mobile_data_key" : "quality_pref_mobile_data_key"
"show_kitsu_posters_key" : "show_kitsu_posters_key"
"extension_authors" : "Autorzy"
"android_tv_interface_off_seek_key" : "android_tv_interface_off_seek_key"
"preview_seekbar_key" : "preview_seekbar_key"
"video_buffer_length_key" : "video_buffer_length_key"
"subdl_key" : "subdl_key"
"legal_notice_key" : "legal_notice_key"
"auto_rotate_video_key" : "auto_rotate_video_key"
"pref_category_gestures_key" : "pref_category_gestures_key"
"dns_key" : "dns_key"
"app_layout_key" : "app_layout_key"
"video_buffer_disk_key" : "video_buffer_disk_key"
"auto_rotate_video_key" : "automatski_rotiraj_video_tipka"
"example_password" : "pasvorto123"
"mal_key" : "mal_key"
"swipe_enabled_key" : "swipe_enabled_key"
"extension_authors" : "Autoriai"
"example_username" : "MiaSalutNomo"
"example_username" : "MagacKaYaabAh"
"extension_authors" : "Autoren"
"pref_category_bypass" : "ISP-Umgehungen"
"show_fillers_key" : "show_fillers_key"
"override_site_key" : "override_site_key"
"skip_startup_account_select_key" : "skip_startup_account_select_key"
"opensubtitles_key" : "opensubtitles_key"
"android_tv_interface_on_seek_key" : "android_tv_interface_on_seek_key"
"show_sub_key" : "show_sub_key"
"rotate_video_key" : "rotera_video_nyckel"
"example_username" : "Benutzername"
"example_password" : "passord123"
"app_theme_key" : "app_theme_key"
"rotate_video_key" : "rotiraj_video_tipka"
"restore_key" : "restore_key"
"apk_installer_key" : "apk_installer_key"
"show_dub_key" : "show_dub_key"
"search_types_list_key" : "search_type_list"
"show_trailers_key" : "show_trailers_key"
"example_username" : "aaaagggk"
"backup_dir_key" : "backup_dir_key"
"display_sub_key" : "display_sub_key"
"quality_pref_key" : "quality_pref_key"
"pref_category_security_key" : "pref_category_security_key"
"extension_authors" : "Autors"
"log_enabled_key" : "log_enabled_key"
"extension_authors" : "Autori"
"subtitles_encoding_key" : "subtitles_encoding_key"
"video_buffer_size_key" : "video_buffer_size_key"
"jsdelivr_proxy_key" : "jsdelivr_proxy_key"
"provider_lang_key" : "provider_lang_key"
"locale_key" : "app_locale"
"example_password" : "passwort123"
"example_username" : "MojeSuperMeno"
"automatic_backup_key" : "automatic_backup_key"
"double_tap_pause_enabled_key" : "double_tap_pause_enabled_key"
"example_password" : "parola123"
"example_password" : "heslo123"
"autoplay_next_key" : "autoplay_next_key"
"auto_rotate_video_key" : "auto_rotera_video_nyckel"
"prefer_media_type_key" : "prefer_media_type_key_2"
"extension_authors" : "Pengarang"
"extension_authors" : "Autores"
"search_providers_list_key" : "search_providers_list"
"anilist_key" : "anilist_key"
"swipe_vertical_enabled_key" : "swipe_vertical_enabled_key"
"example_password" : "Lambarkasirta123"
"backup_key" : "backup_key"
"extension_authors" : "Authors"
"video_buffer_clear_key" : "video_buffer_clear_key"
"auto_download_plugins_key" : "auto_download_plugins_key2"
"episode_sync_enabled_key" : "episode_sync_enabled_key"
"example_password" : "parol123"
"use_system_brightness_key" : "use_system_brightness_key"
"example_username" : "Username"
"example_password" : "lozinka123"
"example_password" : "Parole123"
"extension_authors" : "Utviklere"
"example_username" : "MittKuleBrukernavn"
"download_path_key" : "download_path_key"
"extension_authors" : "ooooggg"
"show_logcat_key" : "show_logcat_key"
"backup_path_key" : "backup_path_key"
"primary_color_key" : "primary_color_key"
"example_password" : "password123"
"software_decoding_key" : "software_decoding_key2"
"pip_enabled_key" : "pip_enabled_key"
"filter_sub_lang_key" : "filter_sub_lang_key"
"show_hd_key" : "show_hd_key"
"example_password" : "senha123"
"example_password" : "Slaptazodis123"
"pref_filter_search_quality_key" : "pref_filter_search_quality_key"
bac0925df628dce7841a1d4e8d474c2e63fb818b
nZWtL6D4gxleEjTgRsiZreZ8nNC9qRwx6BC0WIWuyNpCzY/YJalfUgLEw4LPgFs0T+snumNuJ4BOD
nbmhoaGhoaMig8M5S0hTgENxxYMk8kg9v+nAPg34ys79CB6GnkDt8Q5KGon97Er8nPxu1LWU8UsbB
n5cgy1k4ASf3A5cAFuJXKKaF9KpBPgDvM7KP4g1oIIGkCMADcBJwb2p8KOMvMPoUaCCBpALgfmBba
nd7qkHRn2vssMU5VdE3xYVka86jITBsDMNuBGM2mjDa9lhqhj7ifnqmsbvLfG5CH0PGDUkNXMvqV4
n+ZGkpzrId6ak3RlpLm1xz5kePn0QOrZ5A3H9GIMf80wHeZ+l7OZo6Qh7HwFWh45t3iCsKEiATkXo
n2olwU2SXZdN1AtzmEfwtI+49oSQRspqj1yT9EUqAMoahx3rYvpW8MLONwFzglxT7WyQ97eOMmX0M
nnEP6ewBXAAflTa7oYJUhwJEetmtGlXCvCL+m3LNYblk7NznmCXnpivcDfARoGWQz+wH3PlZaTRjs
nJ2k5MBi65DXhQ6iwE5b0BHBP6FLXhB3AUWa2u5ImSNKdNMFPcp2Z7YYKaoCkmcDa0CWuCVuBu8zs
e6333b32409e02a4a6eba6fb7ff866bb
nzHYAd4WORoWsA241sxkhgw8jJi6SHgPuC+lQifwMvAu8ZGavhnYmptVM+CLc4RUzgEm42eiehP2E
n4EPbNtXMNgNzgO0pJjfLc54Q9QnnUoOaUIYAPh3VtjxGkQhzM+wXdSDCxzgR/iipbLkIXQNuy2sY
nxtAB6Dkkzc+55W9DaF97Fkkv5BBgPHxbUjgkvZgS+F2SbgztX10o9cGJpAXA1cB03BOr94DlZvZT
N2YzODYwYWQzNGI4ZTZmOTdmN2I5MTA0ZWQzMzEwOGI0MmQ3MTdlMTM0MmM2NGMxMTg5NGE1MjUyYTQ3NjE3Zg==
n78C8qoIPewXwOcK9V1kHzIi2qlRGLEB3LDSVx3KgP3rEWSlxHzAZt8OgljPjEvkcWGJmr4dyoA/A
noCasBeYxdhEKpQwBfJ50pb7yY2abgNmki7C4F0QoQ4DC2slIhFm4VchWLJb0nGeaa3F9QicidEUf
Y29tLmFwcGxpc3RvLmFwcGNsb25lci5jbGFzc2VzLnNlY29uZGFyeQ==
nAP7xsB0qOvNGAL+5kIrOvBGghKD60AgQmEYAONDD9oSiM98ndOlrwNdAPL4fjn7G/UKyedoX+C60
n+AxcP7sT90e4wsx2lRLoVkh6KOeOs1Z8IekeSce3yWOWpL9T0tglaWGb+w/x8OmdyoJXQPCPkDTc
nbz2PpFXK5obQPvYskh5WPqaG9rXnkDRR0q6cAjxZdP59oQNQA84ADshpO6vozBsB4DAP2/2KzrwR
njY7OJr0mLOpwiHpt4BgUi6Q3PCZi8h1SSjpR0vaM9LxEkHSMh69dMRHz7agGfUSIhqhzKG50dHiJ
nCXBIWXMAAC4jAAAuIwF4pT92AAAHk0lEQVR42u2dW6wdUxjHf98pirqURElc6tIihKZOL0rqLiEl
1714d6f2f4f7cc19644384f8c4629910
nJBUhcameExFCkEhow4NEJCIST32oW4TEg3ogbg+NklAaSl1KFG2lNGlJimqU0/P3sGZ0nLNn9qx9
39f470a9f2ec1aa2383269ca831bc7be0e47da48d6d708ccad9bed4e1a60993e
nlwr5ETjezBRsKULS6ZJWAU8xvoIPcBxwGQRaC5I0iNvycX7oSARkPgQQQNKjwHJgQugIBGYiVLwY
uyBLgFD17MgrYmA0gSXoKllMJBelOYj2
nsw0NDQ0NDQ0FUesnYpIOBE4BTsKt2ewLTEyYDCfK0MfeUYzYO8ROjmQsca3o2lrYFJm2AXuAL81s
n6ILXhSq+P2Ae7qsIh4HV0REDDQ314F/QQmVQhaYmuwAAAABJRU5ErkJggg==
nEWYD347Bz/VmtmYM96cSWoCWRCLMJVsE38naNXQ+k30gdExyI+kVj3Z1fpu0Jssdnp1GWxEkHSTp
1e8f8cd198588a544e2063c8d50c29ea6b5a4c7b7d8ee65e96fe4aaf001872e0
nYfAXeebVnyGCJC3JuHeGh1/vFx2nMjvh++m8iTvax9jMPgHOBv5OMXlE0tICyhR86SYXchted46h

信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
andhook/lib/AndHook.java, line(s) 56,104
andhook/lib/HookHelper.java, line(s) 34,67,87,139,150,163,184,205,226,261,266,79
andhook/lib/xposed/XposedBridge.java, line(s) 30,26
andhook/lib/xposed/XposedHelpers.java, line(s) 468,479,490,501,512,523,534,545,556,567,582,593,604,615,626,637,648,659,670,681,692,703,714,725,736,747,758,769,780,791,802,813,824,835,846,857,868,881,894,907,928,943
com/applisto/appcloner/classes/AbstractActivityContentProvider.java, line(s) 25,31
com/applisto/appcloner/classes/AppClonerNative.java, line(s) 16
com/applisto/appcloner/classes/ApplicationWrapper.java, line(s) 31,189,196,203,210,217,58,70,86,98,110,122,134,146,158,175
com/applisto/appcloner/classes/AutoPressButtons.java, line(s) 31,44,62,67,72,91,106,120,100,122,126,130,153
com/applisto/appcloner/classes/AutoRotateControls.java, line(s) 18,19,38,45,36,50
com/applisto/appcloner/classes/BackKeyHandler.java, line(s) 33,35,43,52,64,72,85,54,94
com/applisto/appcloner/classes/BluetoothControls.java, line(s) 18,19,37,40,45,52,58,61,43,64
com/applisto/appcloner/classes/BootReceiver.java, line(s) 14,24
com/applisto/appcloner/classes/BundleFilesDirectories.java, line(s) 18,30,38,46,61,41,66
com/applisto/appcloner/classes/BundleObb.java, line(s) 20,30,33,44,53,84,87
com/applisto/appcloner/classes/CalculatorActivity.java, line(s) 52,62,125,251
com/applisto/appcloner/classes/ClearCacheOnExitProvider.java, line(s) 16,43,47,21,39,52
com/applisto/appcloner/classes/ClearCacheOnExitService.java, line(s) 18,24
com/applisto/appcloner/classes/ClearCacheReceiver.java, line(s) 15
com/applisto/appcloner/classes/CloneSettings.java, line(s) 63,200,211,49,72,77,208
com/applisto/appcloner/classes/Configuration.java, line(s) 22,44,63,67,70,77,87,97,36,58,81,91,101
com/applisto/appcloner/classes/ConfirmExit.java, line(s) 14
com/applisto/appcloner/classes/CrashHandler.java, line(s) 71,80,94,26,60,82,98
com/applisto/appcloner/classes/DefaultFontProvider.java, line(s) 32
com/applisto/appcloner/classes/DefaultProvider.java, line(s) 42,78,83,91,95,111,57,70,102,117,175,182
com/applisto/appcloner/classes/DisableCameras.java, line(s) 24,45,62,80,100,106,126,140,28,57,75,93,121,133
com/applisto/appcloner/classes/DisableClipboardAccess.java, line(s) 58,94,98,102,109,116,122,128,145,149,153,157,161,165,174,186,191,202,206,210,217,224,230,236,253,257,261,265,269,273,282,294,299,308,338,347,353,358,362,379,396,72,136,244,301,340,365,382,398
com/applisto/appcloner/classes/FacebookLoginBehavior.java, line(s) 14,34
com/applisto/appcloner/classes/FacebookMessengerProvider.java, line(s) 36,38
com/applisto/appcloner/classes/FakeCalculator.java, line(s) 14,22,29,32
com/applisto/appcloner/classes/GmailSupport.java, line(s) 35,38,50,100,113,125,130,149,167,183,185,195,197,213,220,227,40,104,108,135,143,160,222
com/applisto/appcloner/classes/HeadphonesEventReceiver.java, line(s) 12,24,31,18,44
com/applisto/appcloner/classes/HostsBlocker.java, line(s) 83,111,119,133,155,158,169,222,249,257,265,270,305,316,325,334,345,358,426,103,121,281,297,348,441
com/applisto/appcloner/classes/InterruptionFilterControls.java, line(s) 21,22,37,47,48,57,62,64
com/applisto/appcloner/classes/LaunchTileService.java, line(s) 16,21,28
com/applisto/appcloner/classes/LogcatViewer.java, line(s) 49,308,63,147
com/applisto/appcloner/classes/NotificationOptions.java, line(s) 142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,188,193,198,200,250,302,319,326,93,233,241,252,256,285,355
com/applisto/appcloner/classes/OnAppExitListener.java, line(s) 19,26
com/applisto/appcloner/classes/OpenLinksWith.java, line(s) 26,42,50
com/applisto/appcloner/classes/PasswordActivity.java, line(s) 61,86,96,101,69,90,156,162,177,188
com/applisto/appcloner/classes/PasswordProvider.java, line(s) 12,14,21,24
com/applisto/appcloner/classes/PenEventReceiver.java, line(s) 12,17,35
com/applisto/appcloner/classes/PersistentApp.java, line(s) 13,21
com/applisto/appcloner/classes/PersistentAppService.java, line(s) 18
com/applisto/appcloner/classes/PictureInPicture.java, line(s) 28,34,40,52,63,73,83,65,88
com/applisto/appcloner/classes/PowerEventReceiver.java, line(s) 12,16,19,23,27,30,40
com/applisto/appcloner/classes/PreferenceEditor.java, line(s) 24,26,29,39,56,64
com/applisto/appcloner/classes/PressBackAgainToExit.java, line(s) 17,32,54
com/applisto/appcloner/classes/SecretDialerCodeReceiver.java, line(s) 15,25
com/applisto/appcloner/classes/SetBrightnessOnStart.java, line(s) 22,23,38,46,88,58,67,82,98,104
com/applisto/appcloner/classes/ShowOnLockScreen.java, line(s) 14,25
com/applisto/appcloner/classes/Signatures.java, line(s) 36,55,58,94,98,109,113,145,82,88,140,149,152,169,179,202,215
com/applisto/appcloner/classes/StartExitAppEventReceiver.java, line(s) 19,39,48,61,34,56,66
com/applisto/appcloner/classes/ToastFilter.java, line(s) 25,29,55,61,89,81,91
com/applisto/appcloner/classes/TrustAllCertificatesProvider.java, line(s) 37,39
com/applisto/appcloner/classes/Utils.java, line(s) 68,75,87,90,519,105,109,124,164,174,184,195,216,226,240,322,441,482,524,537,574,609
com/applisto/appcloner/classes/WhatsAppSupport.java, line(s) 30,59,72,45,62,66,85
com/applisto/appcloner/classes/WifiControls.java, line(s) 18,19,37,40,45,52,58,61,43,64
com/applisto/appcloner/classes/freeform/FreeFormWindow.java, line(s) 35,39,44,59
com/applisto/appcloner/classes/freeform/FreeFormWindowActivity.java, line(s) 37,53,56,76,96,59,89
com/applisto/appcloner/classes/service/RemoteService.java, line(s) 20
com/applisto/appcloner/classes/util/IActivityManagerHook.java, line(s) 19
com/applisto/appcloner/classes/util/IPackageManagerHook.java, line(s) 20
com/discord/panels/PanelsChildGestureRegionObserver.java, line(s) 46
com/hippo/unifile/DocumentsContractApi19.java, line(s) 113,166
com/hippo/unifile/DocumentsContractApi21.java, line(s) 35,104
com/hippo/unifile/RawFile.java, line(s) 50,230
com/hippo/unifile/TreeDocumentFile.java, line(s) 42
com/hippo/unifile/TrickRandomAccessFile.java, line(s) 28,35,37,123,127
com/jaredrummler/android/colorpicker/ColorPickerDialog.java, line(s) 486,500
com/lagradost/api/Log.java, line(s) 16,34,22,28
com/lagradost/cloudstream3/CommonActivity.java, line(s) 388,300,297
com/lagradost/cloudstream3/MainActivity$Companion$handleAppIntentUrl$1$1.java, line(s) 45,59,61
com/lagradost/cloudstream3/MainActivity$onCreate$17.java, line(s) 150
com/lagradost/cloudstream3/MainActivity.java, line(s) 632,634,693,1201,287
com/lagradost/cloudstream3/actions/temp/fcast/FcastManager$DefaultDiscoveryListener$onServiceFound$2.java, line(s) 48,97,33
com/lagradost/cloudstream3/actions/temp/fcast/FcastManager.java, line(s) 62,67,72,77,117,138,171,183,177,189
com/lagradost/cloudstream3/extractors/Chillx.java, line(s) 76
com/lagradost/cloudstream3/extractors/Pelisplus$getUrl$3.java, line(s) 73
com/lagradost/cloudstream3/extractors/Vidstream$getUrl$3.java, line(s) 72
com/lagradost/cloudstream3/extractors/Voe.java, line(s) 60
com/lagradost/cloudstream3/network/WebViewResolver$resolveUsingWebView$6$2$shouldInterceptRequest$1.java, line(s) 86,109
com/lagradost/cloudstream3/network/WebViewResolver$resolveUsingWebView$destroyWebView$1.java, line(s) 54
com/lagradost/cloudstream3/plugins/Plugin.java, line(s) 26
com/lagradost/cloudstream3/plugins/PluginManager$_DO_NOT_CALL_FROM_A_PLUGIN_loadAllLocalPlugins$2.java, line(s) 71
com/lagradost/cloudstream3/plugins/PluginManager$_DO_NOT_CALL_FROM_A_PLUGIN_manuallyReloadAndUpdatePlugins$1.java, line(s) 52
com/lagradost/cloudstream3/plugins/PluginManager.java, line(s) 313,337,408,128,210,399,329,402
com/lagradost/cloudstream3/receivers/VideoDownloadRestartReceiver.java, line(s) 13
com/lagradost/cloudstream3/services/PackageInstallerService.java, line(s) 173
com/lagradost/cloudstream3/ui/SelectSourceController$onMediaStatusUpdated$1.java, line(s) 119
com/lagradost/cloudstream3/ui/SelectSourceController.java, line(s) 253
com/lagradost/cloudstream3/ui/account/AccountSelectActivity.java, line(s) 298
com/lagradost/cloudstream3/ui/download/button/PieFetchButton.java, line(s) 122
com/lagradost/cloudstream3/ui/player/AbstractPlayerFragment.java, line(s) 514
com/lagradost/cloudstream3/ui/player/CS3IPlayer.java, line(s) 1268,1518,1574,1581,1666,613,657,898,909,911,923,1020,1038,1062,1072,1432,1440,1448,1539,1623,1656,1751
com/lagradost/cloudstream3/ui/player/CustomDecoder.java, line(s) 310,317,327
com/lagradost/cloudstream3/ui/player/DownloadedPlayerActivity.java, line(s) 48
com/lagradost/cloudstream3/ui/player/GeneratorPlayer.java, line(s) 207,1459,1623,1809,2100,2102,1071
com/lagradost/cloudstream3/ui/player/M3u8PreviewGenerator$load$1.java, line(s) 96,117,178
com/lagradost/cloudstream3/ui/player/Mp4PreviewGenerator$load$1.java, line(s) 48
com/lagradost/cloudstream3/ui/player/Mp4PreviewGenerator$load$2.java, line(s) 51
com/lagradost/cloudstream3/ui/player/Mp4PreviewGenerator.java, line(s) 78,81,110,168,186
com/lagradost/cloudstream3/ui/player/PlayerGeneratorViewModel.java, line(s) 116,129,154,273
com/lagradost/cloudstream3/ui/player/PlayerSubtitleHelper.java, line(s) 77
com/lagradost/cloudstream3/ui/player/PreviewGenerator.java, line(s) 133
com/lagradost/cloudstream3/ui/player/RepoLinkGenerator.java, line(s) 150,86,94,102
com/lagradost/cloudstream3/ui/result/ResultViewModel2.java, line(s) 1520,1522
com/lagradost/cloudstream3/ui/result/SyncViewModel$addFromUrl$1.java, line(s) 41,70
com/lagradost/cloudstream3/ui/result/SyncViewModel$modifyData$1.java, line(s) 145,134
com/lagradost/cloudstream3/ui/result/SyncViewModel.java, line(s) 79,87,123,134,152,162,179,262
com/lagradost/cloudstream3/ui/settings/SettingsFragment.java, line(s) 367
com/lagradost/cloudstream3/ui/settings/extensions/PluginAdapter.java, line(s) 342
com/lagradost/cloudstream3/ui/settings/extensions/PluginDetailsFragment.java, line(s) 253
com/lagradost/cloudstream3/ui/settings/extensions/PluginsViewModel$handlePluginAction$1.java, line(s) 59
com/lagradost/cloudstream3/ui/settings/extensions/PluginsViewModel$updatePluginList$1.java, line(s) 50
com/lagradost/cloudstream3/ui/settings/extensions/PluginsViewModel$updatePluginListLocal$1.java, line(s) 58
com/lagradost/cloudstream3/ui/settings/utils/DirectoryPickerKt.java, line(s) 42
com/lagradost/cloudstream3/utils/ApkInstaller.java, line(s) 236,246
com/lagradost/cloudstream3/utils/AppContextUtils.java, line(s) 1023,1076
com/lagradost/cloudstream3/utils/BatteryOptimizationChecker.java, line(s) 61,84
com/lagradost/cloudstream3/utils/BiometricAuthenticator.java, line(s) 75
com/lagradost/cloudstream3/utils/CastHelper$awaitLinks$1.java, line(s) 62
com/lagradost/cloudstream3/utils/ImageLoader.java, line(s) 89,96,82
com/lagradost/cloudstream3/utils/UIHelper$popCurrentPage$1.java, line(s) 43,58
com/lagradost/cloudstream3/utils/UIHelper.java, line(s) 149,266,288
com/lagradost/cloudstream3/utils/UiText.java, line(s) 126
com/lagradost/cloudstream3/utils/VideoDownloadManager$deleteFilesAndUpdateSettings$2.java, line(s) 104,100
com/lagradost/nicehttp/ContinuationCallback.java, line(s) 45
com/lagradost/nicehttp/NiceResponse.java, line(s) 171
com/lagradost/safefile/SafeFileKt.java, line(s) 22,23,24,26
io/github/anilbeesetti/nextlib/media3ext/ffdecoder/FfmpegLibrary.java, line(s) 68
io/github/anilbeesetti/nextlib/media3ext/ffdecoder/FfmpegVideoDecoder.java, line(s) 116
io/github/anilbeesetti/nextlib/media3ext/ffdecoder/NextRenderersFactory.java, line(s) 42,64
io/github/anilbeesetti/nextlib/mediainfo/MediaInfoBuilder.java, line(s) 72
java/io/ByteArrayOutputStrean.java, line(s) 13,17,18,35,20
junit/runner/BaseTestRunner.java, line(s) 149
junit/runner/Version.java, line(s) 12
junit/textui/TestRunner.java, line(s) 88,112,137
org/acra/ACRA.java, line(s) 115
org/acra/collector/LogCatCollector.java, line(s) 82
org/acra/log/AndroidLogDelegate.java, line(s) 28,36,80,88,43,51,13,21,58,66,73
org/acra/reporter/ErrorReporterImpl.java, line(s) 112
org/mozilla/classfile/TypeInfo.java, line(s) 174,175,176,177,178

信息 此应用侦听剪贴板更改。一些恶意软件也会监听剪贴板更改

此应用侦听剪贴板更改。一些恶意软件也会监听剪贴板更改
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
com/applisto/appcloner/classes/DisableClipboardAccess.java, line(s) 45,117,117,123,123,132,225,225,231,231,240,9

信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
com/applisto/appcloner/classes/DisableClipboardAccess.java, line(s) 9,70,359
com/lagradost/cloudstream3/utils/UIHelper.java, line(s) 7,143

安全 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/uwetrottmann/tmdb2/Tmdb.java, line(s) 145,145

关注 应用程序可能与位于OFAC制裁国家 (塞浦路斯) 的服务器 (dns.adguard.com) 通信。

{'ip': '94.140.15.15', 'country_short': 'CY', 'country_long': '塞浦路斯', 'region': 'Lemesos', 'city': '利马索尔', 'latitude': '34.674976', 'longitude': '33.033245'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (asnwish.com) 通信。

{'ip': '221.228.32.13', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '无锡', 'latitude': '31.569349', 'longitude': '120.288788'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (tracker1.bt.moack.co.kr) 通信。

{'ip': '156.234.201.18', 'country_short': 'HK', 'country_long': '中国', 'region': '香港', 'city': '香港', 'latitude': '22.285521', 'longitude': '114.157692'}

安全评分: ( CloudStream Remix 2.5)