安全分析报告: Azan Time Pro v8.1.9

安全分数


安全分数 33/100

风险评级


等级

  1. A
  2. B
  3. C
  4. F

严重性分布 (%)


隐私风险

8

用户/设备跟踪器


调研结果

高危 32
中危 53
信息 3
安全 2
关注 6

高危 域配置不安全地配置为允许明文流量到达范围内的这些域。

Scope:
www.mobilexsoft.com
svc.mobilexsoft.com
multimedia.mobilexsoft.com
ezanvaktipro.com
ezanvakti.pro
maviay.co
mobilexsoft.com
download.mobilexsoft.com
127.0.0.1
localhost
::ffff:127.0.0.1
::/::
::1
138.201.250.157
stream.ezanvaktipro.com

高危 App 链接 assetlinks.json 文件未找到

[android:name=com.mobilexsoft.ezanvakti.HolderActivity][android:host=http://www.ezanvaktipro.com]
App Link 资产验证 URL (http://www.ezanvaktipro.com/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:301)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。

高危 App 链接 assetlinks.json 文件未找到

[android:name=com.mobilexsoft.ezanvakti.HolderActivity][android:host=http://ezanvaktipro.com]
App Link 资产验证 URL (http://ezanvaktipro.com/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:301)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。

高危 Activity (com.mobilexsoft.ezanvakti.HolderActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.HolderActivityTv) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.EzanOkuyanActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.UyariVerenActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.DiyanetSecActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.DilSecActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.ConsentActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.GPSSehirBulActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.GPSSehirBulActivityTV) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.SehirOnayActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.UyariAyarlariActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.VakitleriYukleActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.wizard.TemaWizardActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.kuran.radio.RadioFragment) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.kuran.EzberActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 App 链接 assetlinks.json 文件未找到

[android:name=com.mobilexsoft.ezanvakti.kuran.CepMainActivity][android:host=http://www.ezanvaktipro.com]
App Link 资产验证 URL (http://www.ezanvaktipro.com/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:301)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。

高危 Activity (com.mobilexsoft.ezanvakti.kuran.CepMainActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.util.geofence.ProfilEkleActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.mobilexsoft.ezanvakti.util.geofence.ProfilDetayAyarActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.google.firebase.auth.internal.FederatedSignInActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 Activity (com.google.android.play.core.missingsplits.PlayCoreMissingSplitsActivity) 的启动模式不是standard模式

Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

高危 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/blesh/sdk/core/zz/b08.java, line(s) 105
com/blesh/sdk/core/zz/bz7.java, line(s) 156
com/blesh/sdk/core/zz/eo4.java, line(s) 24
com/blesh/sdk/core/zz/fz6.java, line(s) 21,24
com/blesh/sdk/core/zz/m0.java, line(s) 23,26,29
com/blesh/sdk/core/zz/w31.java, line(s) 39
com/blesh/sdk/core/zz/x2.java, line(s) 162,263

高危 WebView域控制不严格漏洞

WebView域控制不严格漏洞


Files:
com/blesh/sdk/core/zz/op0.java, line(s) 646,636,644,676

高危 该文件是World Writable。任何应用程序都可以写入文件

该文件是World Writable。任何应用程序都可以写入文件
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-local-storage-for-sensitive-data-mstg-storage-1-and-mstg-storage-2

Files:
com/blesh/sdk/core/zz/f39.java, line(s) 483
com/blesh/sdk/core/zz/r69.java, line(s) 2058

高危 该文件是World Readable。任何应用程序都可以读取文件

该文件是World Readable。任何应用程序都可以读取文件
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-local-storage-for-sensitive-data-mstg-storage-1-and-mstg-storage-2

Files:
com/blesh/sdk/core/zz/dn8.java, line(s) 723

高危 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击

如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-7

Files:
com/blesh/sdk/core/zz/cj2.java, line(s) 339,11,12
com/blesh/sdk/core/zz/dj2.java, line(s) 354,753,21,22
com/blesh/sdk/core/zz/g23.java, line(s) 25,4
com/blesh/sdk/core/zz/kk2.java, line(s) 325,19,20
com/blesh/sdk/core/zz/qk2.java, line(s) 97,8
com/blesh/sdk/core/zz/zsa.java, line(s) 62,7

高危 已启用远程WebView调试

已启用远程WebView调试
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
com/amazon/device/ads/DTBAdView.java, line(s) 168,17

高危 应用程序包含隐私跟踪程序

此应用程序有多个8隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危 应用程序可以安装在有漏洞的已更新 Android 版本上

Android 4.4-4.4.4, [minSdk=19]
该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。

中危 Activity (com.mobilexsoft.ezanvakti.HolderActivityTv) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (com.mobilexsoft.ezanvakti.EzanOkuyanActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Activity (com.mobilexsoft.ezanvakti.UyariVerenActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Activity (com.mobilexsoft.ezanvakti.multimedia.GreetingsActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (com.mobilexsoft.ezanvakti.kuran.CepMainActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Service (com.mobilexsoft.ezanvakti.servisler.OnlyVoiceService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.mobilexsoft.ezanvakti.servisler.EzanProfileService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.mobilexsoft.ezanvakti.util.geofence.MasjeedGeofenceTransitionsIntentService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Activity (com.mobilexsoft.ezanvakti.WidgetMTConfigActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (com.mobilexsoft.ezanvakti.WidgetConfigActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (com.mobilexsoft.ezanvakti.WidgetConfigActivity2) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Activity (com.mobilexsoft.ezanvakti.WidgetPieConfigActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.EzanVaktiBootupReceiver) 未被保护。

[android:exported=true]
发现 Broadcast Receiver与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.mobilexsoft.ezanvakti.DataSyncListenerService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updatepiewidget) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updateMTwidget) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updatewidget) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updateyeniwidget) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updateyeniwidgetorta) 未被保护。

[android:exported=true]
发现 Broadcast Receiver与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updateyeniwidgetmini) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Broadcast Receiver (com.mobilexsoft.ezanvakti.updatewidget2) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Service (com.mobilexsoft.ezanvakti.EzanVaktiPushMessagingService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (coelib.c.couluslibrary.plugin.SurveyService) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Service (com.mobilexsoft.ezanvakti.servisler.AlarmReceiverIntentService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.mobilexsoft.ezanvakti.servisler.BootupReceiverIntentService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Broadcast Receiver (coelib.c.couluslibrary.plugin.SurveyReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Activity (com.huawei.openalliance.ad.activity.PPSLauncherActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Activity (com.folioreader.ui.activity.SearchActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Service (com.google.android.gms.auth.api.signin.RevocationBoundService) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.google.android.gms.auth.api.signin.permission.REVOCATION_NOTIFICATION [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Activity (com.google.firebase.auth.internal.FederatedSignInActivity) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.google.firebase.auth.api.gms.permission.LAUNCH_FEDERATED_SIGN_IN [android:exported=true]
发现一个 Activity被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.google.android.c2dm.permission.SEND [android:exported=true]
发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Service (com.google.android.play.core.assetpacks.AssetPackExtractionService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 高优先级的Intent (999)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (999)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 高优先级的Intent (900)

[android:priority]
通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

中危 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
com/blesh/sdk/core/zz/ak7.java, line(s) 15
com/blesh/sdk/core/zz/d29.java, line(s) 13
com/blesh/sdk/core/zz/dc5.java, line(s) 3
com/blesh/sdk/core/zz/dt7.java, line(s) 38
com/blesh/sdk/core/zz/e4.java, line(s) 60
com/blesh/sdk/core/zz/fs.java, line(s) 15
com/blesh/sdk/core/zz/ft7.java, line(s) 5
com/blesh/sdk/core/zz/ic6.java, line(s) 31
com/blesh/sdk/core/zz/in0.java, line(s) 6
com/blesh/sdk/core/zz/it7.java, line(s) 4
com/blesh/sdk/core/zz/kx7.java, line(s) 28
com/blesh/sdk/core/zz/mk7.java, line(s) 14
com/blesh/sdk/core/zz/n85.java, line(s) 3
com/blesh/sdk/core/zz/nda.java, line(s) 3
com/blesh/sdk/core/zz/ni5.java, line(s) 19
com/blesh/sdk/core/zz/q69.java, line(s) 14
com/blesh/sdk/core/zz/r69.java, line(s) 82
com/blesh/sdk/core/zz/s69.java, line(s) 7
com/blesh/sdk/core/zz/ts7.java, line(s) 9
com/blesh/sdk/core/zz/uda.java, line(s) 3
com/blesh/sdk/core/zz/vca.java, line(s) 5
com/blesh/sdk/core/zz/wa4.java, line(s) 9
j$/util/concurrent/ThreadLocalRandom.java, line(s) 14

中危 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/blesh/sdk/core/zz/bz7.java, line(s) 166
com/blesh/sdk/core/zz/gp.java, line(s) 908
com/blesh/sdk/core/zz/iz6.java, line(s) 47
com/blesh/sdk/core/zz/zh7.java, line(s) 54

中危 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
com/blesh/sdk/core/zz/a49.java, line(s) 5,6,20
com/blesh/sdk/core/zz/ac6.java, line(s) 12,13,1647
com/blesh/sdk/core/zz/b3.java, line(s) 6,72
com/blesh/sdk/core/zz/b4.java, line(s) 9,79
com/blesh/sdk/core/zz/bj3.java, line(s) 5,6,15
com/blesh/sdk/core/zz/bq8.java, line(s) 3,22
com/blesh/sdk/core/zz/c3.java, line(s) 6,36
com/blesh/sdk/core/zz/cp8.java, line(s) 15,272
com/blesh/sdk/core/zz/f66.java, line(s) 5,6,7,8,89
com/blesh/sdk/core/zz/fo0.java, line(s) 4,5,31
com/blesh/sdk/core/zz/go8.java, line(s) 5,203
com/blesh/sdk/core/zz/gp.java, line(s) 18,414
com/blesh/sdk/core/zz/gw0.java, line(s) 5,6,225
com/blesh/sdk/core/zz/gz7.java, line(s) 5,47
com/blesh/sdk/core/zz/k50.java, line(s) 6,7,77
com/blesh/sdk/core/zz/kq.java, line(s) 5,6,28
com/blesh/sdk/core/zz/mq8.java, line(s) 4,33
com/blesh/sdk/core/zz/mw0.java, line(s) 4,5,92
com/blesh/sdk/core/zz/mw8.java, line(s) 6,60
com/blesh/sdk/core/zz/n16.java, line(s) 5,6,678
com/blesh/sdk/core/zz/nc6.java, line(s) 5,6,270
com/blesh/sdk/core/zz/nw8.java, line(s) 7,8,641
com/blesh/sdk/core/zz/oo8.java, line(s) 5,288
com/blesh/sdk/core/zz/ov8.java, line(s) 6,187
com/blesh/sdk/core/zz/p29.java, line(s) 7,8,62
com/blesh/sdk/core/zz/pj3.java, line(s) 4,177
com/blesh/sdk/core/zz/q29.java, line(s) 5,6,15
com/blesh/sdk/core/zz/r69.java, line(s) 15,16,1452
com/blesh/sdk/core/zz/rn1.java, line(s) 21,22,4044
com/blesh/sdk/core/zz/sc6.java, line(s) 4,45
com/blesh/sdk/core/zz/sp8.java, line(s) 5,106
com/blesh/sdk/core/zz/tv8.java, line(s) 14,1987
com/blesh/sdk/core/zz/u19.java, line(s) 5,6,34
com/blesh/sdk/core/zz/uq8.java, line(s) 4,5,21
com/blesh/sdk/core/zz/v3.java, line(s) 6,7,204
com/blesh/sdk/core/zz/vp8.java, line(s) 12,2114
com/blesh/sdk/core/zz/xv8.java, line(s) 17,1700
com/blesh/sdk/core/zz/yn8.java, line(s) 9,75

中危 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
com/amazon/device/ads/DTBMetricsConfiguration.java, line(s) 78
com/amazon/device/ads/WebResourceService.java, line(s) 94
com/blesh/sdk/core/zz/ai7.java, line(s) 45
com/blesh/sdk/core/zz/xm.java, line(s) 89

中危 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
com/amazon/device/ads/DTBAdView.java, line(s) 177,161
com/blesh/sdk/core/zz/dj2.java, line(s) 134,120
com/blesh/sdk/core/zz/lk2.java, line(s) 31,32,24
com/blesh/sdk/core/zz/o18.java, line(s) 869,858
com/blesh/sdk/core/zz/op0.java, line(s) 652,655,658,661,664,638

中危 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
com/blesh/sdk/core/zz/a50.java, line(s) 15,21
com/blesh/sdk/core/zz/b49.java, line(s) 9
com/blesh/sdk/core/zz/cz8.java, line(s) 56,57
com/blesh/sdk/core/zz/do8.java, line(s) 733,734,578,580,732
com/blesh/sdk/core/zz/g39.java, line(s) 1156,3282
com/blesh/sdk/core/zz/h55.java, line(s) 89
com/blesh/sdk/core/zz/hq0.java, line(s) 21
com/blesh/sdk/core/zz/j3.java, line(s) 113
com/blesh/sdk/core/zz/lq1.java, line(s) 25
com/blesh/sdk/core/zz/mm8.java, line(s) 1084,1085,1083
com/blesh/sdk/core/zz/n39.java, line(s) 448
com/blesh/sdk/core/zz/pu6.java, line(s) 31,31
com/blesh/sdk/core/zz/qp1.java, line(s) 9
com/blesh/sdk/core/zz/r69.java, line(s) 318,319
com/blesh/sdk/core/zz/tv8.java, line(s) 1821,1822,1820
com/blesh/sdk/core/zz/v07.java, line(s) 341

中危 IP地址泄露

IP地址泄露


Files:
com/blesh/sdk/core/zz/e4.java, line(s) 1048
com/blesh/sdk/core/zz/p40.java, line(s) 136,140,146,182
com/blesh/sdk/core/zz/wpa.java, line(s) 44
com/blesh/sdk/core/zz/xr0.java, line(s) 43
com/folioreader/Constants.java, line(s) 18

中危 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
com/amazon/device/ads/DTBAdLoader.java, line(s) 6,7,9,8
com/blesh/sdk/core/zz/m0.java, line(s) 35
com/blesh/sdk/core/zz/zw.java, line(s) 85

中危 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/blesh/sdk/core/zz/ic6.java, line(s) 273
com/blesh/sdk/core/zz/qd2.java, line(s) 187,220
com/blesh/sdk/core/zz/qr3.java, line(s) 13
com/blesh/sdk/core/zz/s35.java, line(s) 19
com/blesh/sdk/core/zz/x40.java, line(s) 47

中危 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
凭证信息=> "com.google.android.geo.API_KEY" : "AIzaSyD7Qpt11UdIr9kBW_Pxa963iimYpl-Y_tk"
AdMob广告平台的=> "com.google.android.gms.ads.APPLICATION_ID" : "ca-app-pub-9655763725113422~3767622198"
凭证信息=> "com.blesh.sdk.secretKey" : "@string/blesh_sdk_app_key"
凭证信息=> "com.google.android.backup.api_key" : "AEdPqrEAAAAIyC7-cBtTKdIyd2SZgDDB4MKoOmi5wwDAKdHRzA"
"authorsMeta" : "<tr><td>Authors:</td>"
"blesh_sdk_app_key" : "xViP/M0dvfUBB8LuRT+WXzD2UPCcub0dFLhKMb7+Rm3xoSLZ0FxpJmEhiHt9/ZB7"
"firebase_database_url" : "https://ezan-vakti-bbe0f.firebaseio.com"
"fsq_secret" : "PFLCWTEFIP3K3VNQDV0W0IKOXRU4SZM5TALILEND2ZMQ51VE"
"google_api_key" : "AIzaSyD7Qpt11UdIr9kBW_Pxa963iimYpl-Y_tk"
"google_crash_reporting_api_key" : "AIzaSyD7Qpt11UdIr9kBW_Pxa963iimYpl-Y_tk"
"hava_durumu_key" : "Weather"
"yandex_api_key" : "a8a39630-8439-4662-b196-4e37f18d85be"
"hava_durumu_key" : "Wetter"
"hava_durumu_key" : "Weer"
"hava_durumu_key" : "Cuaca"
"hava_durumu_key" : "Mot"
"hava_durumu_key" : "Temps"
"hava_durumu_key" : "Tiempo"
"hava_durumu_key" : "Cuaca"
"hava_durumu_key" : "Tempo"
"hava_durumu_key" : "Hava"
"authorsMeta" : "<tr><td>Autori:</td>"
noAm+x9W1I6GUlzvs/lOlhV3JeTIGhsWKI9Lap9sAAfaDpQxnYJrrSbhG+PGcN1qYxshptd272GP1
rSYhJJHF5kuUSeVTNPNw2nZQeRBUWQY9GRiatfzsnBI=
nI6e7iyrVEBc2GGXl6XwVpKL8WLKC/L3rRzD23lx5PJaGgjlaJ+Y+FLHvoXZVKzvzI7bivAZ4UE5s
52e81612bcbc57f1066b79ff
1bR3VLwyKPqduFBz9kXnGy9UPty9HeyYL7t+HjE4ync=
6305326e-12d0-4258-87f7-c35bbe6a3ef1
JvvFzwwo66S0VRYmvytx5jLGWNK4QTG9DsWMC8EHPsa+dy60MhFDXxhSCFeMdBUA
nanQEzjFOLFclQhijpY+EOK5UrEv+1Lh4m7B8QdsExItW77sh13NN3wPO0uWJ8ybvlDuS0XniR6/i
11839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650
nhFoIyk0tkEj4dJ5TbrOE8Ql1e3QKoKt4wtgFDdPp04yJD875P9j+GvNOO69HSak=
nT4sLXMVKlzN32oYaFhUNi36ife+xZQcFmsSR6/J6k0J2bgp0En+66Wug4DyziaMD+ouS6xgEOnA3
mI4AvGY+nQt22tJsUNFln/OBC0y4peiX+clO3RuuvHbZxKoMDV9bJ0uZQRoWlvUW
E72409364B865B757E1D6B8DB73011BBB1D20C1A9F931ADD3C4C09E2794CE102F8AA7F2D50EB88F9880A576E6C7B0E95712CAE9416F7BACB798564627846E93B
0000016742C00BDA259000000168CE0F13200000016588840DCE7118A0002FBF1C31C3275D78
5OYWxvL0YyQkZBINW5Sa0hxY3jRpVGVkelkvQWkYxqwt8vd6+XgGHuJJ1gb6db9WkBGA
nEcli9p67Wm6ZciztUCOfhfszkQ+vPGQoyj0Eh5UfchA+4JBC7xyhxM7QqMR39Tum9O0/TdzFrBcX
xbfft456rqtoEjzflxINvm3jB0UueLr4QkvjRWQER1VwL7sPWXVbi0ERv76eXFyQ
nB8xyKoIhEfopH3lp6KAWvIbYvRvM836bPVl+ApzwSRkaGV2kELuGWc9SrWFkTAZR4KdbdGLLB4Xy
8f1d08a2d6496191a5ebae8f0590f513e2619489
cv0918hk0Ixh6mgTuWFBI8gZKMv9+x0a7WQIRPI0CIjokxPl8BUdSu4fOjx+GgSIk+cr5ufUTEpL
ngDJBj4ASonZpKg/BYv9C7JtH1EDyHadUtJpBMMjSo7sKXf2AYEjj2SBZlNIFrUFzUsCSSHLbvCdc
naiHrs5VYbptM68kvHgaBwjeGZNXWtmbSV5Lslp3na0IEUrkRSiG6948r/Lx0q1N+fAWdp24H3qbn
nrWNe9mPwbP6pz4ny/hIt7PncQirTOfJJDBXTH+3p6gWOjCesHGIpRj7aaHZ14wz9LvXKnRrLoh2x
nNryHAMVFBDvURi4zUSG13WshoIJSaThgGfM5DWQaabzw3kqiNsdwuBT+Mqw8a7qJgw495m2RGehV
DL06yVystRGRjM8EyvmOgS0+0UCTDIf3AO1BdC6S2Xc=
nugTw1wmwgDjZd3mu6CiDJEluPrKCqv52WXRfE3qXdOqQRUYKVh1IUhP/R72cZuF5ie5Bj4YagXwl
D8c6NAmywhfnShC87wKLOPWI667JyTy6/R+sj2OrkcE=
nh+G9t3EpYdTPquQ53C4Pzb20RidmxuhopLFwGw6iBWE6zjjXZj0JZmj9KmmaNgLctiLeaR2Dasas
ndr1B/z1PGa8GwBvZhbBZcKMQyfT+qrI7Sk21jh+fxiXB7sNXUyAQgARzvQ9NL74WY70Ws7025onb
ne19OtLLoAgDE9hhvI1O4k5h0HCRu4RooVSH4wlhaw/lb1i15B3IhZqI7jAsVem5GnFPX78kqTRp8
39402006196394479212279040100143613805079739270465446667948293404245721771496870329047266088258938001861606973112319
nicZrnwYLUEzFyP2NyC/UxDd0CMoJOJGEkljihqrkjaTksEvq2fk223SiGobVYFE74Bnks9VqZ2rr
c334ae83accfebb8da23104450c896463c9cfab7
ceQUDMmIspNePIQJbm5sD+0WYMcJxKiy+KS8DogRZko=
nYozhZuv0HUyB5YhcDgaUZeRJttY7tOjknDLhnc1e2GXRNwv8z73PfIK7RSSeDC6D2jjaq4iQF037
VmyCEaBbgXUge3crX5DhhnNRVJcJLKw2o+4M6cwIJJA=
4fe342e2fe1a7f9b8ee7eb4a7c0f9e162bce33576b315ececbb6406837bf51f5
zX3km1qPLrYiG9n7dUoZFQC+zmTqD3abHbpkWV6m20n4Hps2FMxcbSPgd5Hww3wz
n0git2Dso0iz3kkpe+Dli4UR3eGqHsRSQRPtFPmr8gqbgp1nGTihhBWbtXqqs04Z6MOEmhGw+K9h8
nJKyFGd195ZcXyFTAG3GEbVnCW4fZl5ZvGBpfcIpcE4618aK/AgMMsRnN0Os7+u3xeVQfRDuFcc3l
Gi2YikSW4mz4yLeV51PuRFzLB4uKpJt5dlUqD2L9JzjHJ007dtZdVfKWEzHFdZMW
aHR0cDovL2Rvd25sb2FkLm1vYmlsZXhzb2Z0LmNvbS9rdXJhbi9wb3NpdGlvbnMuemlw
ZYG1jdm5AM7mUcEoXCq3rK65rJCTC1sw09mQRjZNz08G/w3QyVfe+O2dWBpXFfYE
nGjY0hJE8SSPr0X/wCEWSfmCDUG4eVzZ+kcT7u8Tkf13ZPgK7aHSRCVm+6srIq3RDhLRdHJVdXPVc
nY8A8EMEvBsjIwAM6dsSDpW0HbDwo95eWLQeCEVFOxqgrzntn53n9txZjwLfKwotHt43/Gf4aK2YM
qQVKAx02rHnn2UaKtetDqipolXas2IxKzVl7aqiMUUcMdXS6i8xgDAUQQupXjNmlXxeXC2vyZvot
nB+TboatjchnCD47i7GQsTxYcJu3LXMxBCBanS93A3x5wMIDm/fDdAQLJlCBYD6ihaGA1zOcDAsol
b3312fa7e23ee7e4988e056be3f82d19181d9c6efe8141120314088f5013875ac656398d8a2ed19d2a85c8edd3ec2aef
bbeorT8HnDjhgCmLxJSaG49vZOZDmEBAromJsmLLaJDgD4XnOWZTd1fCJxVf9tP03MvJMKZtJpI9
nTgnjEWQB9/eEuNPmQBT0j4HPbx2gBmMRklvYUdWEYmbMV47jEMVhvXBXeY0wzKgnDZyLA9Y01IKD
nlOo8ZzH2A3WF8WxD0mbY9uv+OJB7j7IjdFYzPboMY3HtMfxzWvL0N7KAu7ogvm3H1rok5D6rrfJI
na+mEHdiQ2FByqWgzZPbK8w93vzOghjkDQLNvamWPXKh/24mMB5vuU+U1IIy1MnQWHuJMBHRENDdv
5ac635d8aa3a93e7b3ebbd55769886bc651d06b0cc53b0f63bce3c3e27d2604b
nZnP0eDXGcEoy0J0xo0yyWbBvyCDqt2D7zuPcBW3WofvKitFgjLL/9Xtkniuioy70EEm+jBN59hTL
nb62vwW0/2VNxIzJs2gsNlfcqwsM2CCTKeVHCvKRqtDooEoOOvElQ1qSI1BfDJVdZlvgMu1WHI0Ub
n1QcC9VdtqO9QoE6D4r3k+AJDhyPRdSfcRoTwLzDmpZfo9KyF++PMFvH2+UcWIcHbZuBTr9ROYgD6
6b17d1f2e12c4247f8bce6e563a440f277037d812deb33a0f4a13945d898c296
mLW4WfBtN0b1ZboDT/Xcg0iQ140V7G6lHXVBVeBNgLy2jqsT86h2d5npN9bwHugA
n0mQ7rmPiIyUNaoA3EybsGsM8WRVy6/Thd1aW5YJCykkwB2h8zrqa00o+RkCnVntOGx7wmnswC3GM
AC2788F9C7F3FC3E246D81BBE79C1B26
cv0918hk0Ixh6mgTuWFBI8gZKMv9+x0a7WQIRPI0CIjhh76ve4XeBnGLaQPbtc15Gt1SgOzZShEG
3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f
cv0918hk0Ixh6mgTuWFBI8gZKMv9+x0a7WQIRPI0CIhUCza8ohTzFqTa3mQgb2gfIbdTfJxnQ/mJ
nh/0asHCCyF7SmQ796VQ9WT6n5PZgefmYPPmchQPUg7oD6daZC+clBCbb7V9DMK2CYLLcXcucnhFe
nrAG5zfw0pA/so4M+YkhZ+O2VyhXpa6fb8PNB2tQeFnvXIPKKCd7cfrCl032D8zlgFDy+dMHJPiMk
6864797660130609714981900799081393217269435300143305409394463459185543183397655394245057746333217197532963996371363321113864768612440380340372808892707005449
n4SZkHQ5p9FE1bHKA9EJOc4uV4XBhf9pGb4TzjQ0mBUVCCc4TV95fwOCcumU6k9X1YkYc+5ajHs3H
nSNwbhtQASzQrnf08D0Du/DOBUgTzqKvRN9611tLW7t7R8xYicBvBuLYbTt2DZwZoAUdFb2b8wgrJ
na8yH6bOXzqS4lt3ThuO4pHAJ8CImy0NjqEmNWBJYLfqtQrUPMCUeoGm+muCjiCEBLHEWbsv3bERq
470fa2b4ae81cd56ecbcda9735803434cec591fa
nM94XE8NH9PH+UCsrQbIlPXAk5k5gjZEPAcdtSZMHweSvIgBIKh8gRJhhSlD68OghgCquOBSESL9B
n1SQa2CVL92jzO8Bkk95PePKt5u13+pExWQoexOas0NmXMW9MkdO7E/olw+OantniKa4LRWfmr3s7
nQcXMm8BsbylHK23ufK9BSagPOjmw5Y9mNMi1bImwUOLtpzmbib/7MZyYoQwQWDUVMAIl+m20CTcH
ngZrUJY47D96ViQmrjT6CtyoBcCM0C5qvT165kTrSm0R1RdhXn+cJ3UFkwwM+oH0SkiYjJkv2pj2N
964229C8BCB2A7BEC0EB07BE697E49A6
nrevkAaglnp09WkwFpScxc6bHMHSdppeFKyGJt24+qNExHROnMz9Fl7UzdNNJqMW+qUlt0IFEeUeq
fJGzXKpU2C8iDl+Y7ANdP7v6dQ4TyTGpRfe+tJE9nXBQ6AkONmMJiKZGUd7krHwa
nX7ngh9iGO2UseiRJSfXGGvlFMTQMdNm08Un8UaIfBfgHiEP37C78XAY19rWroogn3wmr7Xo5b5k7
yc8yVBGvbM+lDFTeqeGtXc4ZNvehxfgG+5lUS0qb9Du8+QB2SPf9wsrUE/z4yk8S
n7we2OWzvSJyF4mtrVUsuxBv1yy1PRPe2KNfzlphOgnwei6aPEQW7Y8qgOwBngUur/aiTSjJbBSJh
zr0B6w2ARZzNLj2nzDGif7orJvzwcPV/ZAvZIkxUu58=
3iWeLGlh18NsDExlN2QIzTmA4vWzzS1+BPse+PPBjp4=
na5JNu5+ykkKu7EQ6rSfy/eZukkLisi9o2S+oNqvG2bgcGcRrn5weZmK5iRPZK9o2OXVKNVaxKUme
nEhHWnVzbFsj8tPFb41Z9ggtl54mBp7ElI8XxnY2oScGjRQJ3E5vzOwTI+AEbVP/VIxKbjsdSMDRR
nmcted7+Rmtc/S4WGss8XMeSYhdR61j73Fke99bEgaJOhUyKHUESSrFGDxakqJzvEN4PQK+r6uRTY
JRUkDJhW1HFHNphIghrQ/GpgsHAYhKZrP+QjqJGAwmK1uoDv5DksWYPGE3CIg8Wl
TkuK+8ZKbIcxeUe4msY7eeifKf/tICuqqRvwzwQUhsKM0HemvJhBrPQYp0qpvgcE
KPLQ0fePjwRZEMYpyhf3z9wME5WAXo6nyi3l+jJDepzY4MR9ieVKu+2i7JuNsveg
Y29tLmFuZHJvaWQudmVuZGluZy5saWNlbnNpbmcuSUxpY2Vuc2luZ1NlcnZpY2U=
n2wVRvLyW07VRsma0aX0ty4fYfMX2Hn0V1j9JpG6Ax0kA8x7lWlk8UssyD7WoaQGHbgcNnMIR87Qz
n+2mEp3tnOyAcVTYncBd2I8OTVgYVfjaR4LkPPz9Hji34+nyynaCeg20z2wz1nG5GZUamob8CYKt8
nLIjKVW24Oq86lvMVLF6bF0fgsZaLzAQALIid0i7OBKB4/KINQsrjfzs0Q2KvOdW7ei6EHlc0G2Gy
nYv/PCbD4mgep8YBCgmdSjeIMTjO3ZornziSMMsoumq0ZcR4L4oDmxCweZYdE5W1oe4kSYwr+b7oA
nmP3dJxFfiyhJHHwxzx4TFgDpx6m2QpAxjwNrCJehBAbWpNt9Cw8qviAfGlGsUklaCROfIQaxedTq
nTqTjzVdPPGfP1dlnU7+nlwVswNCDlUGd7d3ynGp7cv6iYasphd/cwnGauGQVwL0EZLyiwSVrkYRE
nfbzhQx7/FDlfgRiyWJLszGNdEHlKw7wzcYQAo85m0b6jiImpQj5NZvDdKvjWYFi82EAuILnj+QVW
nNfCdutb6gjSM/pnRhqSgO8oBlu2UXMrtKBBAFH20FjGedCFuzhadNHpMrSRxMhoeiXqwfzje3E4D
nQ94QFwZ1IVKDsep9gnpZ0cvmep2P7hfTr5Bp9FPz/bXMJuNlJvZDQp7hcKuSjwGdTvx92ZahByqv
n6hMf6DPL5m1PeuK9gDu++Ktn2XkMCed3b8hBhrqSMqaf1Fic+OVMZUoHfdg4UzZ9u/tecdT9d+Oa
nNpvMQPCi3bkQlFSnR0ndrhANfqzAEhHBhPDqyJSLtOntNMvNxa2VaSWnebKjE0LE4KJ03UOwaOOm
nrFDmHcgfvMwAzTk2tHn2R19V7Dv0b5QWq7udi0+MpriOGK6PCRvg6ENpxHPdCCFQzz4U4zZJPsam
nsdXerCGFwGEZFaEM9racR9bx3vBj/ERzMRu9TqAlgWISGC10o79jMhu757NtvCZMkU5hYGiwGyxx
YNaCscR40XE3jUfiuSQHOi4SzYzHuKIdiPgG8VTOtns=
nSHOyRX1P0l5VLAMV6ZA7jW5FHRbUPs/B0VMIStM45uMwcHYYbZVZv9ETMy+DBiGk8t0rRd+MUqjW
eNJuSXkridnHpFkTgNBQFH0ivDH801goaJfT5bONEac=
PodJLO62QvFjTRyT1s1j7Q9gO2vYuekX/f9fSujDgK0lEz9+ovbaOYnK8KkglxI5
n7mXQZVAbxZtfYpEXTla1/QwgTBJX5NPiv9Vds5gvSRLbUjocf3bejM1yZAYz9QfuwJquN2s9nQu9
cmVsaWIuY29tL3N1cnZleS8=
ndWtB5zBcP4XtRfPrnrwFCZ8sIUdp62Dbo3at5ixIhCnQTmeaQn46hZDlvMiRCNzKkcygwEYtB6yJ
nwf7+M1/ej7DNAKxkxIAAyMofoEQlB0li1rbyNKMXg45aoC86eUqeDDUnBeLKFPDqnZOi3qQ6d31f
n/fmp67FGfmVyHFalVmlAobdBTFuxnpXUXchrD9oYARFw3lo5Jgtc2SKH9NO3dUIbLXACXyg81hkk
nptmMSAhApKZeJWINZcNjALhfwh23oF42ANQCiaTRZnzxOIQ8KzbMhh3MV6Ob5dE6rIYNInBWNOtI
n7eUWFTVvamdk0f8sb65bdczh+E2u0uthejU2hKsI9MmM+tCFZtet2TgdUdeQUvnQQrziJmxjPpbx
115792089210356248762697446949407573530086143415290314195533631308867097853951
nVxs+lF1BBPN55EOVz423J9a1Ci/B3CynAwke22X3pd3AxsnY9sUElaq7hg56ZwhrZybKKEN4TJAM
nbBwjOdAfj1N5FKjmdHIYCQmdjqbvUX34YbZbOLifd+GENqj5ngiGqAkzu900mt1xZQueJu4vKXs5
ReoS3B5WMCMFdJKmPyF5hDrYSI+H3suOGmd1TWj29uY=
1436a3a8-d6a8-407c-8fb6-1ea27570083a
BgRtXwp/TdPjOMTtxgPOZvXLI0QBLAqNFbcCQtGyZIw=
ECBqiWBAFfHVW9c0fNISGmIVHjwqX6w+ErcYZElUmEc=
n6T6xbAbUYMrlJcOTRVhDm6tCQLBwN3Op956lORVGPl5dr2EEJrIA69skDKqxI2y9V0Nx/eON0g8f
nd7MpIxGdLirb/z7pEgbTDWPYDbP94rMwuwTLzMmHtFQxw2gV6gQKuQBjhR0+MGoRLhvjcuT0GD0B
nsnsxJMqi1jN0XlgBvti0WsdIugpjV7KSAHzEuHy4/blisMfWvEGX+nm0t6aw25ZE2nO33PheOVn5
051953eb9618e1c9a1f929a21a0b68540eea2da725b99b315f3b8b489918ef109e156193951ec7e937b1652c0bd3bb1bf073573df883d2c34f1ef451fd46b503f00
0LbfErERsnzVecZdFdN1r+gkwDj0UWKblMs3MLLnL2Xbg6jOw+rQN6l6e1wPHG33
n6Lc7t2Vze+jWqIwvtB2xghRvON1eNxIq2v4n3JpyS76U0rgBkslFbzj/VhFtMiVFiIV6s72xheE6
6tksJC1oiOeEiy2PbP6Xt59/bZLk2jiIwJLpwcxJtmo=
nEEMZpJRJT6BRLflSqRL2T4r8c1a7dOTTB34r49zgkh4GKOiXAQ7TIG9Yp0BBQTvI/215xiMSMMHl
ne/HeDsTYzPRM+MYyiI6Wgiu9WsjsofT2YA8s+ca7u2dQJcGHoNYunONghp5CZLXycEg+APPXfMo0
6MSHSlSyck9tPP3AhA1TvP6GMucaxnzE6fuqtUKNFpo3t/1gZkhYdWZ3T7TqgVQ+
nEosmmxPnDBUDy64g1jjhZVDD/up+HbcIdga99eHRtromeD7lmp32C0Fo6Z58f86zMbCwSMq0DbSW
39402006196394479212279040100143613805079739270465446667946905279627659399113263569398956308152294913554433653942643
nhXzRqYq2bggsiUjsb2K5NTVreBQBGZcEA8JkaXtwdf6ry4N3hBKNFLXycqzeN30m1c9S1M0n
XLHOfrBefh/XuKTLTjyhlPIaCxluS3pTQi+gEZfTBluRJuWX3xNYXE2jLxpQRzgB
F/EU4ZcvKrJZHhJGs54afTSYBM9roD2BTsVzFmIfQmM=
Cr3Y6+GncptpU6DnnTxAUgghcXzA5hROF2y+XKP1eRU=
nnOLN4TNEXQKQMN3nvpoUMqPb9r6dKjo1ptpJnkSL+cNScCAdq9++u30jAeH6V8NdTflMHTNZ/DVQ
nr+bhK6lq1hs2br01si0VnQVC8QiMVVBZapQ5S1g681I1lXQ0hrB5YZ/1jAZngtmTow0AfjrTiWfj
nZCS1VhXhqqNNeEy+E5akwaiCCKUvp42SEmx7g0sqK9sJ6Ka/QqAdIxZ4gVMcxSiB7pcgUl4FrECP
jgvEncvxob+pdE8d4JYFj2otUJMxUVgOSjZFi7SPhb8=
Mg7hpNILFKkI7hAkw7A/iVut8RIgxPSTSSiW9E7s4cWD5OqGx03LJQgW7i+QM0lp
aa87ca22be8b05378eb1c71ef320ad746e1d3b628ba79b9859f741e082542a385502f25dbf55296c3a545e3872760ab7
115792089210356248762697446949407573529996955224135760342422259061068512044369
Q2/dQoYza3Uuw12qqlI5Okt59+FCPCwuUEpf8JYT3zQ=
nf002p4eX1mDFOz4mma1LNco3i21TVYDqmvK2VITsogYw0l90YpORo4557Qxwn9day1BnrsovLWx8
rLEoSrMv+m9P4c0XgvGDAT4PtrEu5QedT29DowrEKUw=
n+r9W7ctYCXjKS6h1Pjta8tDkjUDWKdZ3ZvAO2YKlEJyHDsXBSvMjGJZCvALv7/ObIzg07VC5nuR4
Z7KH49fR2DjGspeuHX8BcHTD0uvOOHknJOx30FGv58BpyVtvGyvjuMhyW8cRn2RI
nTs97FBGg5b4RjHR5z7dH0ip8Jk1USKOsJLhAPDwJ+jIZOK2EKsnLTExCXoPXdByV782muYXGVoYi
n6WjNgjw6xTdeR2YCQBT1+rdTnjtBe6o8w+XcldnctzsgotgTSrAbsRqY/1uOCiH2CtLDRcujs5fl
UQKiPRoyS+CnmUD46E4EQsdx5KAVcG8QUHzjpjKV7eOLJZ8IiejnQxha3R+ewm0b
nGUFQdx05LvFQjbpNpccUiFbLfirhqZ8VnbAs2UhlhZMTjMnbv2l13ydr2xZyzB4KicgiPiqxkxxn
X0m24tw9RfpfSH/8tn2SLvPJTtxlpwlibbKYTkjQXto=
M3Jm9tdc6mKg5JLPg/PZJ4ab+k2uhToiN0ZHz1C6DK2VSVMAtNJqoxuAgqUAnDUW
26Ohttc1YMDS/slW8vGpdK8iFLV040F3RgiqDCo8vCY=
4bf58dd8d48988d138941735
nU7thIbwoaaeTpLYe4HffNtNx6CxDnd0malFxA6caBjz3Dm8Hv9cTEWEcAGFfk5li/m6NHn2irhd2
oGPxyK0MwPjhYamik95TRAfpfH6vWsbKtfhXi+EQnuc=
6864797660130609714981900799081393217269435300143305409394463459185543183397656052122559640661454554977296311391480858037121987999716643812574028291115057151
aHR0cDovL2Rvd25sb2FkLm1vYmlsZXhzb2Z0LmNvbS8=
c6858e06b70404e9cd9e3ecb662395b4429c648139053fb521f828af606b4d3dbaa14b5e77efe75928fe1dc127a2ffa8de3348b3c1856a429bf97e7e31c2e5bd66
nLEjFlqWcP7BmxFuuKko9OBWMo1RvOFJTZnC0P4BfbMRSstjTuG7WW7QRAr0t8fHzBug9Hqtmvcas
7PTXHfesCwrygeE6a5SpFPYapA+6N5AjzCxH/Yeev9s=
nuF1i9B9G4KEPT59KF12BsPc0mfOkFFX+E8FnHCStqcg+hj1qL3tltFPr8jxmzMfqbpjzvX39VN2c
ni0DeL5aVPn1ZIlhygnI62wXn2LtcvvoZR65VdjmhpzuZ2xO7YEWJ7pq9RjcomqAqlXbaKxNW1FMS
783DB57E2490F78FB75A26C3136C7343
nevixOhyKz2uvxXifwKENaZbmvbnTIHZr4mTVvUgCyuHz0BaJloMvZ1ZIPqoAw333F6WgggmnFOpw
17DwGTsvrSwrOOIos7QWdg74ixLWLGA2Yzsqu+WYLrw=
nU2SKiTxbmbHsKxOaBRoqVjI4LNteq0ihKHXsc5zCKDOcF8FjvubCkYfRNqqPM+rikl5QooE6rw24
nSviouY7bPW8qmeAeUWf7MI/ViQykk42AM+QZ+Vojj81geQlgasYdoh9C6fyIVeTfk0SD1lquYDXv
n38J6JRqUpo8PqFlIAlFdCivk7aVE14bkhBEUZ24NmXJWIIbMV1QYpkxawgo1swyhaauhIKsRV1oE
nXwbOlZ3AamjiDUjAdJaykkAnB8Oo+/QyHuawk9Kg91lYse2sQjEWY5yNxeQEKGfMs1ad8bfS9ihj
edef8ba9-79d6-4ace-a3c8-27dcd51d21ed
nbNnBk1Z5cBrrBfjNCLfX97Oa07ACUFd741mqeoS6IAQKpRyyppNpG24jb67OMsOAK9s1dgGnQD3z
ny9l+1bWCj8yMttrcDs88wgISMQMJAtooBl55x7T3wWhItjXc5WTHXK4L0cmrAqEgEqerc6nUF/CU
nOZ9GGF9RRSLVEQXdf7ePtfqbnUFmOSEMousYhfE6G/wFh9XAO7d5lfZ0hy8CX8pssXD21ivogLdM
nktFrXmJ0SDFG8GQoxCou6ovoQ68lbzbY6O1xFy+8kGWsQ8DpVmM1ON+r7q0PzF/WUKlCisDaEoMp
NGRjZGMwOTYtMDQ4ZS00YjBmLWJiNGMtOWVkZGQ3ZDU0YzVjCg==
nGXrNehDPGF7nqX9easaMg7UHsQCuN1SHyUzNkQpAVd71cz9nf3PdPHfWSvxEdpRuLtG1EK6HdRkd
nRhwJMc2cJytncozClQ0920Z1UGWsLD0OsJsD104ke27muIzm2YGhc9Kbs7UdGAK0vo22pXiYdUhN
2pYopzTvTKz5lKmw9xOg8KoJpRi+qonTMAPEuw8ei1o=
n5TLLOUkU9wUYrVnlbsnbpvsLL8RYRArj5DyafgA3R9DnXcJ7Tlqc2s8wN8rP3c0l2Hrs53Vt28Ug
S7j7LD+X97hW9j19WIw8PL4uee7GXfPlwR/necYXNzsTAuZoEKTwM2kjDqHm05Xn
nSNoc+nL9NoNjBgt+o1giS705Wlf1U+XkLc7ASXLrtLD7opFUDECmLwBTBmo6VkDdKxxe9LLwQcIV
f6b99820-a361-4282-b8d5-bc11a6a7222a

信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
com/amazon/device/ads/AdRegistration.java, line(s) 177,242,425,443,487,190,415,464,228,230,505,507
com/amazon/device/ads/DTBActivity.java, line(s) 19,36,63,71,103,106,110
com/amazon/device/ads/DTBAdMRAIDBannerController.java, line(s) 524
com/amazon/device/ads/DTBAdMRAIDController.java, line(s) 176,291,420,443,446,467,597,611,495
com/amazon/device/ads/DTBAdMRAIDExpandedController.java, line(s) 86
com/amazon/device/ads/DTBAdMRAIDInterstitialController.java, line(s) 134,159
com/amazon/device/ads/DTBAdRequest.java, line(s) 165,172,226,230,236,243,267,286,288,294,297,303,308,313,333,439,500,502,520,530,532,559,561,688,362,441,489,524,726,744,327,383,436,475,478,667,106,195,365,696,753
com/amazon/device/ads/DTBAdResponse.java, line(s) 166,177
com/amazon/device/ads/DTBAdUtil.java, line(s) 52,115,120,124,220,228,234,238,240,242,244,247,252,261,271,274,276,279,281
com/amazon/device/ads/DTBAdView.java, line(s) 68,85,105,113,142,322,336,343,98,140,259,274
com/amazon/device/ads/DTBAdViewSupportClient.java, line(s) 115,120,142,35,44,108
com/amazon/device/ads/DTBFetchFactory.java, line(s) 28,35,53
com/amazon/device/ads/DTBFetchManager.java, line(s) 82
com/amazon/device/ads/DTBMetricReport.java, line(s) 67,147
com/amazon/device/ads/DTBMetricsConfiguration.java, line(s) 61,87,96,108,123,48
com/amazon/device/ads/DTBMetricsProcessor.java, line(s) 64,69,74,77,86,81,85,90
com/amazon/device/ads/DTBTimeTrace.java, line(s) 48
com/amazon/device/ads/DtbAdRequestParamsBuilder.java, line(s) 108
com/amazon/device/ads/DtbAdvertisingInfo.java, line(s) 12,18,25,28,41,40
com/amazon/device/ads/DtbCommonUtils.java, line(s) 96,99,104,109,112,115,173,176,181,186,189,192,204,258,293,84,64,281,283
com/amazon/device/ads/DtbDebugProperties.java, line(s) 65,73,109,114,117,120,126,132,138,154
com/amazon/device/ads/DtbDeviceData.java, line(s) 112,118,149,151,264,280,180,186
com/amazon/device/ads/DtbDeviceRegistration.java, line(s) 21,96,101,115,154,231,243,283,301,303,307,107,175,182,288,321,70,73,123,150,189,200,207,218,223,263,266,280,292,326,337
com/amazon/device/ads/DtbFireOSServiceAdapter.java, line(s) 21,23,36,42
com/amazon/device/ads/DtbGeoLocation.java, line(s) 15,40,46,51,53,57,59,23,26
com/amazon/device/ads/DtbGooglePlayServices.java, line(s) 61,77
com/amazon/device/ads/DtbGooglePlayServicesAdapter.java, line(s) 39,42,49,21,26,33
com/amazon/device/ads/DtbHttpClient.java, line(s) 44,81,87,99,108,163,164,174,177
com/amazon/device/ads/DtbLog.java, line(s) 30,37,132,140,48,55,148,172,179,186,16,97,156,125,164
com/amazon/device/ads/DtbMetrics.java, line(s) 98,121,123,130,137,147,150,153,159,162,168
com/amazon/device/ads/DtbPackageNativeData.java, line(s) 21,37
com/amazon/device/ads/DtbThreadService.java, line(s) 22,30
com/amazon/device/ads/SDKUtilities.java, line(s) 132,154
com/amazon/device/ads/WebResourceService.java, line(s) 88
com/blesh/sdk/core/Blesh.java, line(s) 391,323,354,310,225
com/blesh/sdk/core/services/GeofenceIntentService.java, line(s) 91,102
com/blesh/sdk/core/ui/activities/NotificationActivity.java, line(s) 86
com/blesh/sdk/core/ui/activities/ViewCollectionActivity.java, line(s) 225
com/blesh/sdk/core/zz/a20.java, line(s) 178,179,187
com/blesh/sdk/core/zz/a30.java, line(s) 470,15,346,356
com/blesh/sdk/core/zz/ad6.java, line(s) 64,76,93,97
com/blesh/sdk/core/zz/ae.java, line(s) 27
com/blesh/sdk/core/zz/ae7.java, line(s) 47
com/blesh/sdk/core/zz/ag.java, line(s) 17
com/blesh/sdk/core/zz/ag5.java, line(s) 21
com/blesh/sdk/core/zz/ag7.java, line(s) 103,59,100
com/blesh/sdk/core/zz/ah5.java, line(s) 41
com/blesh/sdk/core/zz/ah7.java, line(s) 33,43,69,101,97,167,67,100,118,123
com/blesh/sdk/core/zz/aj7.java, line(s) 49,65,93,143,160,174
com/blesh/sdk/core/zz/ak7.java, line(s) 87,92,95,100,124
com/blesh/sdk/core/zz/al1.java, line(s) 348,515,544,233,249,364,613,617,622,628
com/blesh/sdk/core/zz/al5.java, line(s) 120
com/blesh/sdk/core/zz/am.java, line(s) 45
com/blesh/sdk/core/zz/ap1.java, line(s) 23
com/blesh/sdk/core/zz/aq.java, line(s) 177,180,690
com/blesh/sdk/core/zz/av.java, line(s) 85,101,118,84,100,117
com/blesh/sdk/core/zz/aw.java, line(s) 91,139,88,138,142,148,155,152,158
com/blesh/sdk/core/zz/ax.java, line(s) 82
com/blesh/sdk/core/zz/ax4.java, line(s) 671,1028,1048,1105
com/blesh/sdk/core/zz/b00.java, line(s) 96,475,762,95,441,474,497,535,644,661,704,741,761,782,793,461,507,560
com/blesh/sdk/core/zz/b10.java, line(s) 14,15
com/blesh/sdk/core/zz/b39.java, line(s) 50
com/blesh/sdk/core/zz/b81.java, line(s) 108,158,164,176
com/blesh/sdk/core/zz/bg6.java, line(s) 69
com/blesh/sdk/core/zz/bh6.java, line(s) 27
com/blesh/sdk/core/zz/bo0.java, line(s) 85,97
com/blesh/sdk/core/zz/bp0.java, line(s) 175,190
com/blesh/sdk/core/zz/by.java, line(s) 45,78,90,100,123,46,91,79,103,124
com/blesh/sdk/core/zz/bz.java, line(s) 100,101
com/blesh/sdk/core/zz/c00.java, line(s) 28,32,29,33
com/blesh/sdk/core/zz/c1.java, line(s) 255,551,207,233,240
com/blesh/sdk/core/zz/c15.java, line(s) 178,184,196
com/blesh/sdk/core/zz/c61.java, line(s) 62
com/blesh/sdk/core/zz/c8.java, line(s) 532
com/blesh/sdk/core/zz/c97.java, line(s) 148,231
com/blesh/sdk/core/zz/ca7.java, line(s) 54,98,116,121,126
com/blesh/sdk/core/zz/cb7.java, line(s) 59,105
com/blesh/sdk/core/zz/cf.java, line(s) 55,60
com/blesh/sdk/core/zz/cg1.java, line(s) 47,87,164,171
com/blesh/sdk/core/zz/ch5.java, line(s) 17,32,37
com/blesh/sdk/core/zz/ci.java, line(s) 32
com/blesh/sdk/core/zz/ci1.java, line(s) 28
com/blesh/sdk/core/zz/cla.java, line(s) 10,15
com/blesh/sdk/core/zz/cm.java, line(s) 31
com/blesh/sdk/core/zz/co1.java, line(s) 73,77,30
com/blesh/sdk/core/zz/cp8.java, line(s) 208
com/blesh/sdk/core/zz/cv.java, line(s) 69,68
com/blesh/sdk/core/zz/cw.java, line(s) 52,51
com/blesh/sdk/core/zz/cy4.java, line(s) 97,114
com/blesh/sdk/core/zz/cz.java, line(s) 38,37
com/blesh/sdk/core/zz/d11.java, line(s) 38,44
com/blesh/sdk/core/zz/d20.java, line(s) 118,125,119,126
com/blesh/sdk/core/zz/d39.java, line(s) 77
com/blesh/sdk/core/zz/d61.java, line(s) 217,261,266,340
com/blesh/sdk/core/zz/d67.java, line(s) 42,60
com/blesh/sdk/core/zz/d7.java, line(s) 31
com/blesh/sdk/core/zz/da.java, line(s) 501,506
com/blesh/sdk/core/zz/df.java, line(s) 27
com/blesh/sdk/core/zz/dg6.java, line(s) 132,293,314,92,144,80,102,131,288,309,87,107
com/blesh/sdk/core/zz/dg7.java, line(s) 33,31
com/blesh/sdk/core/zz/dh1.java, line(s) 318,393,723,850
com/blesh/sdk/core/zz/dh5.java, line(s) 16,31
com/blesh/sdk/core/zz/dh7.java, line(s) 22,21
com/blesh/sdk/core/zz/dj.java, line(s) 60
com/blesh/sdk/core/zz/dk1.java, line(s) 76,210
com/blesh/sdk/core/zz/dm.java, line(s) 29,65
com/blesh/sdk/core/zz/do1.java, line(s) 48
com/blesh/sdk/core/zz/do8.java, line(s) 685,960
com/blesh/sdk/core/zz/dq0.java, line(s) 27,44
com/blesh/sdk/core/zz/dsa.java, line(s) 253,330
com/blesh/sdk/core/zz/e42.java, line(s) 51,55,10,60
com/blesh/sdk/core/zz/e51.java, line(s) 279,329,343
com/blesh/sdk/core/zz/e91.java, line(s) 161,167
com/blesh/sdk/core/zz/e99.java, line(s) 87,105,107
com/blesh/sdk/core/zz/ea.java, line(s) 86,152
com/blesh/sdk/core/zz/ef.java, line(s) 53
com/blesh/sdk/core/zz/eh.java, line(s) 187
com/blesh/sdk/core/zz/ei7.java, line(s) 140,147,73,78
com/blesh/sdk/core/zz/em.java, line(s) 24
com/blesh/sdk/core/zz/es0.java, line(s) 153,83,90,105,107,143
com/blesh/sdk/core/zz/f30.java, line(s) 37,83,84,38
com/blesh/sdk/core/zz/f40.java, line(s) 44,47
com/blesh/sdk/core/zz/f59.java, line(s) 40
com/blesh/sdk/core/zz/f7.java, line(s) 66
com/blesh/sdk/core/zz/f9.java, line(s) 90,99,187,231
com/blesh/sdk/core/zz/fd.java, line(s) 67
com/blesh/sdk/core/zz/ff.java, line(s) 40
com/blesh/sdk/core/zz/fj.java, line(s) 703,1007,1104,1226,1272,1992,1993,2001,2009,188,631,695,1180,1376,1442,1448,1454,1487,1500,1510,1525,1553,1601,1629,1642,1685,1691,1706,1719,1805,1814,1945,1955,1963
com/blesh/sdk/core/zz/fj7.java, line(s) 32
com/blesh/sdk/core/zz/fm.java, line(s) 35
com/blesh/sdk/core/zz/fn1.java, line(s) 24
com/blesh/sdk/core/zz/fo0.java, line(s) 30
com/blesh/sdk/core/zz/fp6.java, line(s) 239
com/blesh/sdk/core/zz/fq0.java, line(s) 42
com/blesh/sdk/core/zz/fz0.java, line(s) 720,1049,1121
com/blesh/sdk/core/zz/g00.java, line(s) 108,109
com/blesh/sdk/core/zz/g1.java, line(s) 261,390
com/blesh/sdk/core/zz/g91.java, line(s) 1004,327,405,927
com/blesh/sdk/core/zz/g99.java, line(s) 97,129,144,146,246,248
com/blesh/sdk/core/zz/gd.java, line(s) 177,88,149
com/blesh/sdk/core/zz/gd7.java, line(s) 63
com/blesh/sdk/core/zz/gf.java, line(s) 50,208
com/blesh/sdk/core/zz/gf5.java, line(s) 32,47
com/blesh/sdk/core/zz/gg7.java, line(s) 50,122,306,315,384,46,120,129,153,184,194,232,303,312,379,130,154,185,195,233,58,264
com/blesh/sdk/core/zz/gh7.java, line(s) 52,56,60,76,101,124,84,89,109,51,55,59,71,96,119
com/blesh/sdk/core/zz/gi1.java, line(s) 81
com/blesh/sdk/core/zz/gj7.java, line(s) 19
com/blesh/sdk/core/zz/gk7.java, line(s) 155
com/blesh/sdk/core/zz/go0.java, line(s) 36
com/blesh/sdk/core/zz/gp.java, line(s) 1144,1162,2270,2294,912,914,916,918,923,926,931,938,2277,2358,2381,2388,2409,991
com/blesh/sdk/core/zz/gp0.java, line(s) 47,22
com/blesh/sdk/core/zz/gq0.java, line(s) 37,75,190
com/blesh/sdk/core/zz/gw.java, line(s) 117,155,214,116,154,213
com/blesh/sdk/core/zz/gy.java, line(s) 96,81
com/blesh/sdk/core/zz/h10.java, line(s) 44,45
com/blesh/sdk/core/zz/h21.java, line(s) 186,285,290,299,505,517,555
com/blesh/sdk/core/zz/h41.java, line(s) 102,463,467
com/blesh/sdk/core/zz/h51.java, line(s) 15
com/blesh/sdk/core/zz/h87.java, line(s) 20,26,32,38,15,44
com/blesh/sdk/core/zz/h89.java, line(s) 119,253,256,297,308,341,346,396
com/blesh/sdk/core/zz/ha.java, line(s) 21,31,48,50,52
com/blesh/sdk/core/zz/ha7.java, line(s) 38
com/blesh/sdk/core/zz/hd.java, line(s) 594,1005,1012,1013,1018,1026,1733,1080,613,623,924,1778,1785
com/blesh/sdk/core/zz/hg1.java, line(s) 82,34,66,111,117,122,135,143,158
com/blesh/sdk/core/zz/hj1.java, line(s) 29,48
com/blesh/sdk/core/zz/hk.java, line(s) 26
com/blesh/sdk/core/zz/hl1.java, line(s) 23
com/blesh/sdk/core/zz/hm.java, line(s) 27
com/blesh/sdk/core/zz/hp0.java, line(s) 37
com/blesh/sdk/core/zz/hq0.java, line(s) 28
com/blesh/sdk/core/zz/hs0.java, line(s) 34,44,53,63,73,84,89,96,132,170,119,151,160,178,201
com/blesh/sdk/core/zz/hsa.java, line(s) 13
com/blesh/sdk/core/zz/ht.java, line(s) 93,97,10,102
com/blesh/sdk/core/zz/hz6.java, line(s) 75,83,88,107,48,59,129,133,147
com/blesh/sdk/core/zz/i1.java, line(s) 119,355,166
com/blesh/sdk/core/zz/i29.java, line(s) 156,248
com/blesh/sdk/core/zz/i6.java, line(s) 218
com/blesh/sdk/core/zz/i89.java, line(s) 63,65,101,104,248,252,268,270,333,493,499,506,510,512,520
com/blesh/sdk/core/zz/i9.java, line(s) 124
com/blesh/sdk/core/zz/ia7.java, line(s) 52
com/blesh/sdk/core/zz/ig1.java, line(s) 131,133,129,39
com/blesh/sdk/core/zz/ig6.java, line(s) 39
com/blesh/sdk/core/zz/ih.java, line(s) 21,32
com/blesh/sdk/core/zz/ij5.java, line(s) 22
com/blesh/sdk/core/zz/il5.java, line(s) 61
com/blesh/sdk/core/zz/im.java, line(s) 29
com/blesh/sdk/core/zz/in1.java, line(s) 40,45,32,57,62
com/blesh/sdk/core/zz/is.java, line(s) 57,63,58,64
com/blesh/sdk/core/zz/is0.java, line(s) 22,32,41,50,59
com/blesh/sdk/core/zz/iu4.java, line(s) 44,83,94
com/blesh/sdk/core/zz/iy.java, line(s) 69,68
com/blesh/sdk/core/zz/iz6.java, line(s) 51,57,60,63,66,69,73,78,112,28,33,97,102,117
com/blesh/sdk/core/zz/j39.java, line(s) 14,23,32,42,52,62,71,87
com/blesh/sdk/core/zz/j66.java, line(s) 210,233
com/blesh/sdk/core/zz/j85.java, line(s) 58
com/blesh/sdk/core/zz/jf.java, line(s) 63,66
com/blesh/sdk/core/zz/ji.java, line(s) 338
com/blesh/sdk/core/zz/jj.java, line(s) 56
com/blesh/sdk/core/zz/jj7.java, line(s) 211,220,230,236,246,103,106
com/blesh/sdk/core/zz/jo1.java, line(s) 26,29,43
com/blesh/sdk/core/zz/js.java, line(s) 448,229,243,344,413
com/blesh/sdk/core/zz/js0.java, line(s) 19,29,38,47,57,62
com/blesh/sdk/core/zz/ju4.java, line(s) 56
com/blesh/sdk/core/zz/jx.java, line(s) 35,36
com/blesh/sdk/core/zz/jy4.java, line(s) 171,186,211,237,261,357,362,370,376,385,396,413,435
com/blesh/sdk/core/zz/k01.java, line(s) 300
com/blesh/sdk/core/zz/k15.java, line(s) 123
com/blesh/sdk/core/zz/k47.java, line(s) 138,106,168,172,76,86
com/blesh/sdk/core/zz/k87.java, line(s) 27
com/blesh/sdk/core/zz/kg.java, line(s) 17
com/blesh/sdk/core/zz/kg7.java, line(s) 70,65,54
com/blesh/sdk/core/zz/kh7.java, line(s) 32,48,71
com/blesh/sdk/core/zz/ki1.java, line(s) 34
com/blesh/sdk/core/zz/ki7.java, line(s) 942,949,144,320,565,654
com/blesh/sdk/core/zz/kj7.java, line(s) 35,47,95,175,66,66,90,142,155,170,181,190
com/blesh/sdk/core/zz/kl1.java, line(s) 30
com/blesh/sdk/core/zz/kn.java, line(s) 24
com/blesh/sdk/core/zz/ku.java, line(s) 192,199,209,214,231,241,191,198,202,208,213,230,237,322,203,323
com/blesh/sdk/core/zz/ku4.java, line(s) 806,817,822,1083
com/blesh/sdk/core/zz/l11.java, line(s) 40
com/blesh/sdk/core/zz/l29.java, line(s) 143,64
com/blesh/sdk/core/zz/ld7.java, line(s) 34
com/blesh/sdk/core/zz/li.java, line(s) 916,1312,1540,263,271,304,316,328,340,352,364,376,388,400,407,418,430,413,610,619,860,1092,1161,1188,1191,1198,1293,1297,1375,1386
com/blesh/sdk/core/zz/lj.java, line(s) 114
com/blesh/sdk/core/zz/lm8.java, line(s) 116
com/blesh/sdk/core/zz/ln1.java, line(s) 66,72
com/blesh/sdk/core/zz/lv4.java, line(s) 477
com/blesh/sdk/core/zz/lx6.java, line(s) 15
com/blesh/sdk/core/zz/ly.java, line(s) 16,15
com/blesh/sdk/core/zz/m00.java, line(s) 103,108,155,164,171,104,109,156,165,172,173,174,178
com/blesh/sdk/core/zz/m27.java, line(s) 44
com/blesh/sdk/core/zz/m57.java, line(s) 15
com/blesh/sdk/core/zz/m87.java, line(s) 19
com/blesh/sdk/core/zz/ma1.java, line(s) 39,54,64,75
com/blesh/sdk/core/zz/mi6.java, line(s) 39,31,49
com/blesh/sdk/core/zz/mi7.java, line(s) 171,93,170,183,75,159,166
com/blesh/sdk/core/zz/ml5.java, line(s) 22
com/blesh/sdk/core/zz/mm8.java, line(s) 3143,468
com/blesh/sdk/core/zz/mo8.java, line(s) 321
com/blesh/sdk/core/zz/mp0.java, line(s) 36,52,56,24
com/blesh/sdk/core/zz/mq0.java, line(s) 90,127,138
com/blesh/sdk/core/zz/mx0.java, line(s) 636,212,228,244,673
com/blesh/sdk/core/zz/my.java, line(s) 43,42
com/blesh/sdk/core/zz/mz.java, line(s) 67,104,78,114
com/blesh/sdk/core/zz/mz0.java, line(s) 132,185
com/blesh/sdk/core/zz/n07.java, line(s) 237,160
com/blesh/sdk/core/zz/n30.java, line(s) 38,84,85,39
com/blesh/sdk/core/zz/n87.java, line(s) 43
com/blesh/sdk/core/zz/na1.java, line(s) 15,27
com/blesh/sdk/core/zz/na7.java, line(s) 52
com/blesh/sdk/core/zz/ne.java, line(s) 142,170,178,215,296,308,330,338,136,169,175,214,295,305,329,337,157,183,209,285
com/blesh/sdk/core/zz/ng7.java, line(s) 64,83
com/blesh/sdk/core/zz/nh.java, line(s) 401,411,422,431
com/blesh/sdk/core/zz/ni1.java, line(s) 23
com/blesh/sdk/core/zz/ni5.java, line(s) 224,178,168,175,186,299,305
com/blesh/sdk/core/zz/nk7.java, line(s) 50
com/blesh/sdk/core/zz/nl5.java, line(s) 157,155
com/blesh/sdk/core/zz/nm8.java, line(s) 1905
com/blesh/sdk/core/zz/np0.java, line(s) 78,132
com/blesh/sdk/core/zz/nq0.java, line(s) 48,152,32,70,168,214,223
com/blesh/sdk/core/zz/nt0.java, line(s) 134
com/blesh/sdk/core/zz/nta.java, line(s) 18,22,23
com/blesh/sdk/core/zz/nw8.java, line(s) 176,215,519,581,922,941,961
com/blesh/sdk/core/zz/o00.java, line(s) 100,99
com/blesh/sdk/core/zz/o11.java, line(s) 98,115
com/blesh/sdk/core/zz/o29.java, line(s) 75
com/blesh/sdk/core/zz/o57.java, line(s) 95,61
com/blesh/sdk/core/zz/o76.java, line(s) 122,138,153
com/blesh/sdk/core/zz/o9.java, line(s) 407,155,160,167,314,390
com/blesh/sdk/core/zz/od7.java, line(s) 52,73,177,187
com/blesh/sdk/core/zz/of.java, line(s) 39,62
com/blesh/sdk/core/zz/of7.java, line(s) 32,42,129,165,174,158,160,177,187,190,31,41,128,164,61
com/blesh/sdk/core/zz/og1.java, line(s) 123
com/blesh/sdk/core/zz/oh7.java, line(s) 241,410
com/blesh/sdk/core/zz/ol.java, line(s) 153
com/blesh/sdk/core/zz/om6.java, line(s) 53
com/blesh/sdk/core/zz/on1.java, line(s) 15
com/blesh/sdk/core/zz/oo0.java, line(s) 27,34,87
com/blesh/sdk/core/zz/oo8.java, line(s) 273
com/blesh/sdk/core/zz/op0.java, line(s) 133,141,343,906,1642,1699,129,330,367,927,949,1061,1082,1211,1538,1546,1565,137
com/blesh/sdk/core/zz/osa.java, line(s) 678
com/blesh/sdk/core/zz/ota.java, line(s) 15,89,93
com/blesh/sdk/core/zz/ou0.java, line(s) 37,40,44,48,80,83,86,89,92
com/blesh/sdk/core/zz/oy.java, line(s) 100,99
com/blesh/sdk/core/zz/p0.java, line(s) 64
com/blesh/sdk/core/zz/p51.java, line(s) 40
com/blesh/sdk/core/zz/p6.java, line(s) 393,223,231
com/blesh/sdk/core/zz/p97.java, line(s) 670,710,794,1099
com/blesh/sdk/core/zz/pe4.java, line(s) 60
com/blesh/sdk/core/zz/pg.java, line(s) 230
com/blesh/sdk/core/zz/pi.java, line(s) 32,115,128,138
com/blesh/sdk/core/zz/pm.java, line(s) 45
com/blesh/sdk/core/zz/pp.java, line(s) 35,61
com/blesh/sdk/core/zz/pw6.java, line(s) 25,47,39,40,46
com/blesh/sdk/core/zz/pz6.java, line(s) 62,89,102,115
com/blesh/sdk/core/zz/q5.java, line(s) 168,210,453,471,479,607,622,1383,1417,1987,2314,2328,2340,2362,2371,136,145,1747,1757,1826,1835,2391,2400
com/blesh/sdk/core/zz/q71.java, line(s) 66
com/blesh/sdk/core/zz/q9.java, line(s) 106
com/blesh/sdk/core/zz/qg.java, line(s) 35
com/blesh/sdk/core/zz/qi5.java, line(s) 68
com/blesh/sdk/core/zz/qi7.java, line(s) 76,90,135,69,75,89,134,87
com/blesh/sdk/core/zz/qj6.java, line(s) 66,70,95
com/blesh/sdk/core/zz/qk7.java, line(s) 71,78,85,112
com/blesh/sdk/core/zz/ql.java, line(s) 91
com/blesh/sdk/core/zz/qn8.java, line(s) 198
com/blesh/sdk/core/zz/qo5.java, line(s) 26,35,59,67,25,34,58
com/blesh/sdk/core/zz/qt.java, line(s) 46
com/blesh/sdk/core/zz/qx0.java, line(s) 482
com/blesh/sdk/core/zz/qz.java, line(s) 56,55,72,73
com/blesh/sdk/core/zz/r01.java, line(s) 100
com/blesh/sdk/core/zz/r11.java, line(s) 387,410,418,430,445,266,286,291,296,318
com/blesh/sdk/core/zz/r51.java, line(s) 213,69,224,377,386
com/blesh/sdk/core/zz/r69.java, line(s) 922,952,1883
com/blesh/sdk/core/zz/r9.java, line(s) 129,41,56,81,322
com/blesh/sdk/core/zz/re.java, line(s) 181
com/blesh/sdk/core/zz/rf7.java, line(s) 40
com/blesh/sdk/core/zz/ri6.java, line(s) 30,41,35,46
com/blesh/sdk/core/zz/rj1.java, line(s) 24,42
com/blesh/sdk/core/zz/rj6.java, line(s) 24,36,45,59,78,19,31,40,54,73,71
com/blesh/sdk/core/zz/rl.java, line(s) 149,154,161,165,181,191
com/blesh/sdk/core/zz/rl5.java, line(s) 26
com/blesh/sdk/core/zz/rm8.java, line(s) 1353
com/blesh/sdk/core/zz/rn1.java, line(s) 300,538,2162,1331,2097,4067,4166,299,543,1370,579,1577,293,1540,4718
com/blesh/sdk/core/zz/ro6.java, line(s) 115
com/blesh/sdk/core/zz/ru.java, line(s) 361,318,360,319
com/blesh/sdk/core/zz/rw.java, line(s) 465,253,309,464,512
com/blesh/sdk/core/zz/s30.java, line(s) 27
com/blesh/sdk/core/zz/s6.java, line(s) 1929,1957,1966,1976,1985,2000,2009,2022,2031,454,1311,1407,1410,1493,1522,2314
com/blesh/sdk/core/zz/s71.java, line(s) 154,169,224,165
com/blesh/sdk/core/zz/sg7.java, line(s) 20,15
com/blesh/sdk/core/zz/si.java, line(s) 173,218,337
com/blesh/sdk/core/zz/si6.java, line(s) 70,45,54,65,50,59
com/blesh/sdk/core/zz/sl5.java, line(s) 23
com/blesh/sdk/core/zz/sn5.java, line(s) 21
com/blesh/sdk/core/zz/sp0.java, line(s) 119,122
com/blesh/sdk/core/zz/sq4.java, line(s) 19
com/blesh/sdk/core/zz/ssa.java, line(s) 35,21
com/blesh/sdk/core/zz/sv.java, line(s) 51,50
com/blesh/sdk/core/zz/sw.java, line(s) 131,132
com/blesh/sdk/core/zz/sx.java, line(s) 95,213,99,218
com/blesh/sdk/core/zz/sx4.java, line(s) 94,108,286,433
com/blesh/sdk/core/zz/sz0.java, line(s) 162,342
com/blesh/sdk/core/zz/t10.java, line(s) 36,33,79,100,80,101
com/blesh/sdk/core/zz/t57.java, line(s) 64
com/blesh/sdk/core/zz/t7.java, line(s) 116,150,164,172,332
com/blesh/sdk/core/zz/t89.java, line(s) 21,26,29
com/blesh/sdk/core/zz/ta7.java, line(s) 97
com/blesh/sdk/core/zz/td6.java, line(s) 62,65,155,183,74,82,97
com/blesh/sdk/core/zz/te1.java, line(s) 46
com/blesh/sdk/core/zz/tg6.java, line(s) 73,65
com/blesh/sdk/core/zz/tj7.java, line(s) 97,157,192,199,95,171
com/blesh/sdk/core/zz/tm3.java, line(s) 21
com/blesh/sdk/core/zz/to6.java, line(s) 3148,3159
com/blesh/sdk/core/zz/tsa.java, line(s) 61,24
com/blesh/sdk/core/zz/tu.java, line(s) 288
com/blesh/sdk/core/zz/tx.java, line(s) 95,99,110,159,194,55,64,94,98,109,128,158,172,183,193,56,65,148,173,184
com/blesh/sdk/core/zz/ty8.java, line(s) 409
com/blesh/sdk/core/zz/tz0.java, line(s) 180,48,68,89,203,248,265,275
com/blesh/sdk/core/zz/tz8.java, line(s) 76
com/blesh/sdk/core/zz/u19.java, line(s) 32
com/blesh/sdk/core/zz/u27.java, line(s) 30
com/blesh/sdk/core/zz/u39.java, line(s) 70,77
com/blesh/sdk/core/zz/u89.java, line(s) 28
com/blesh/sdk/core/zz/uh1.java, line(s) 180,164,171,198,199
com/blesh/sdk/core/zz/uk4.java, line(s) 27
com/blesh/sdk/core/zz/ul1.java, line(s) 16
com/blesh/sdk/core/zz/ul5.java, line(s) 26
com/blesh/sdk/core/zz/um.java, line(s) 352,396,444,458,217,254,268,276,286,377,379,390,393,260,272,282,299,305,314,331,386,415
com/blesh/sdk/core/zz/un1.java, line(s) 56,63,80,91
com/blesh/sdk/core/zz/us.java, line(s) 63
com/blesh/sdk/core/zz/usa.java, line(s) 35,21
com/blesh/sdk/core/zz/ut.java, line(s) 134,197,256,242
com/blesh/sdk/core/zz/uw.java, line(s) 15,144
com/blesh/sdk/core/zz/uz0.java, line(s) 674,908
com/blesh/sdk/core/zz/uz7.java, line(s) 20,30,33,36,12
com/blesh/sdk/core/zz/v0.java, line(s) 83,482,647,742,218,198,205
com/blesh/sdk/core/zz/v3.java, line(s) 45,99
com/blesh/sdk/core/zz/v89.java, line(s) 124,130,147,148,149,152,153,161,162,163,23,55,59
com/blesh/sdk/core/zz/v9.java, line(s) 94,247,359,173,180,229,340,380,394
com/blesh/sdk/core/zz/v97.java, line(s) 263
com/blesh/sdk/core/zz/vg.java, line(s) 154,176,203
com/blesh/sdk/core/zz/vl.java, line(s) 36,73
com/blesh/sdk/core/zz/vl1.java, line(s) 35,38,41,44,47,50,61,64,67,70,94,100
com/blesh/sdk/core/zz/vm1.java, line(s) 48
com/blesh/sdk/core/zz/vr7.java, line(s) 64,121,239,260,282
com/blesh/sdk/core/zz/vsa.java, line(s) 29
com/blesh/sdk/core/zz/vx4.java, line(s) 600
com/blesh/sdk/core/zz/vy8.java, line(s) 38,53
com/blesh/sdk/core/zz/vz7.java, line(s) 160
com/blesh/sdk/core/zz/w0.java, line(s) 21
com/blesh/sdk/core/zz/w05.java, line(s) 186,211,307,203
com/blesh/sdk/core/zz/w38.java, line(s) 31
com/blesh/sdk/core/zz/w39.java, line(s) 83,104
com/blesh/sdk/core/zz/w89.java, line(s) 127,46,54,109,86,87
com/blesh/sdk/core/zz/w9.java, line(s) 26
com/blesh/sdk/core/zz/wm1.java, line(s) 54
com/blesh/sdk/core/zz/wn6.java, line(s) 252
com/blesh/sdk/core/zz/wo6.java, line(s) 47
com/blesh/sdk/core/zz/wp0.java, line(s) 59,79,134,452,462,474,501
com/blesh/sdk/core/zz/wt.java, line(s) 48
com/blesh/sdk/core/zz/wv4.java, line(s) 167,181,195
com/blesh/sdk/core/zz/wx4.java, line(s) 246,51,62,88,105,130,140,213,259
com/blesh/sdk/core/zz/x15.java, line(s) 50,82,89
com/blesh/sdk/core/zz/x47.java, line(s) 16
com/blesh/sdk/core/zz/xg7.java, line(s) 64,81,107,168,182,62,80,106,163,181,94,121,195,244,284
com/blesh/sdk/core/zz/xi1.java, line(s) 38
com/blesh/sdk/core/zz/xj6.java, line(s) 47,60,87
com/blesh/sdk/core/zz/xk6.java, line(s) 45
com/blesh/sdk/core/zz/xm.java, line(s) 47,57,59,92,106,187,207,217,219,227,234,281,289,301,323,83,200,274,285,311,327,342
com/blesh/sdk/core/zz/xsa.java, line(s) 56,31
com/blesh/sdk/core/zz/xw5.java, line(s) 19
com/blesh/sdk/core/zz/y0.java, line(s) 28
com/blesh/sdk/core/zz/y00.java, line(s) 49,142,151,158,57,145,154,161
com/blesh/sdk/core/zz/y79.java, line(s) 157,145,150
com/blesh/sdk/core/zz/yf2.java, line(s) 131,132,145,267,268
com/blesh/sdk/core/zz/yg7.java, line(s) 32,42,31,41
com/blesh/sdk/core/zz/yi7.java, line(s) 23
com/blesh/sdk/core/zz/yr4.java, line(s) 138,305,199,200,201
com/blesh/sdk/core/zz/ysa.java, line(s) 60,28,84
com/blesh/sdk/core/zz/yy7.java, line(s) 60
com/blesh/sdk/core/zz/yz0.java, line(s) 53
com/blesh/sdk/core/zz/yz5.java, line(s) 78,26
com/blesh/sdk/core/zz/z0.java, line(s) 22
com/blesh/sdk/core/zz/z01.java, line(s) 29
com/blesh/sdk/core/zz/z10.java, line(s) 112,113
com/blesh/sdk/core/zz/z15.java, line(s) 860,205,283,684
com/blesh/sdk/core/zz/z4.java, line(s) 50
com/blesh/sdk/core/zz/z7.java, line(s) 524
com/blesh/sdk/core/zz/zc7.java, line(s) 45,128
com/blesh/sdk/core/zz/zd.java, line(s) 92
com/blesh/sdk/core/zz/zg6.java, line(s) 35
com/blesh/sdk/core/zz/zg7.java, line(s) 87,80,85
com/blesh/sdk/core/zz/zh7.java, line(s) 47,58
com/blesh/sdk/core/zz/zi7.java, line(s) 36,85,83,68,76,91
com/blesh/sdk/core/zz/zk1.java, line(s) 19
com/blesh/sdk/core/zz/zl.java, line(s) 32,271,334,569
com/blesh/sdk/core/zz/zl1.java, line(s) 44,63
com/blesh/sdk/core/zz/zr0.java, line(s) 23
com/blesh/sdk/core/zz/zsa.java, line(s) 141,112,95,44
com/blesh/sdk/core/zz/zu.java, line(s) 159,187,156,186
com/blesh/sdk/core/zz/zz.java, line(s) 163,171,180,193,202,256,282,300,308,313,322,325,330,337,162,170,179,190,201,255,281,299,303,312,321,324,329,336
com/folioreader/AppContext.java, line(s) 37
com/folioreader/Config.java, line(s) 99,125,138,185,192,200,217,220,223,259,263
com/folioreader/ui/activity/FolioActivity.java, line(s) 596,919,991,1011,1019,213,355,511,556,565,587,632,636,696,700,787,1601,1920,204,306,313,332,368,452,495,1175,1293,1349,1362,1508,1583,1596,1663,1777,1805,1836,1852,1859,1864,1888,1914,1931,1954,1968,1974,1978,2001,2132,1810,1813
com/folioreader/ui/activity/SearchActivity.java, line(s) 400,681,338,511,545,96,133,164,182,203,245,304,312,322,445,466,471,480,652,669,718,728,740
com/folioreader/ui/view/DirectionalViewpager.java, line(s) 1311,2698,2704,2720
com/folioreader/ui/view/FolioAppBarLayout.java, line(s) 29,57
com/folioreader/ui/view/FolioWebView.java, line(s) 250,265,276,292,325,340,352,372,388,609,639,671,685,1051,1056,1164,1196,1058,1066,1068,1070,1090,1100,1103,104,109,114,119,124,129,605,718,901,907,912,976,1052
com/folioreader/ui/view/WebViewPager.java, line(s) 194
org/lucasr/twowayview/TwoWayView.java, line(s) 3369,3814,4486,4490,4498,4502,4510,4514
org/readium/r2/streamer/ClientAppContext.java, line(s) 33

信息 应用程序可以写入应用程序目录。敏感信息应加密

应用程序可以写入应用程序目录。敏感信息应加密


Files:
com/blesh/sdk/core/zz/j0.java, line(s) 18,18,21

信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
com/blesh/sdk/core/zz/g39.java, line(s) 6,3265
com/blesh/sdk/core/zz/mq0.java, line(s) 6,36

安全 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/blesh/sdk/core/zz/bv7.java, line(s) 67,70
com/blesh/sdk/core/zz/e4.java, line(s) 155,182,151,260,304,152,152,179,179
com/blesh/sdk/core/zz/n.java, line(s) 52,71
com/blesh/sdk/core/zz/r3.java, line(s) 66,59,161,63,63
com/blesh/sdk/core/zz/u3.java, line(s) 332,93
com/blesh/sdk/core/zz/zga.java, line(s) 137,136,135,135

安全 此应用程序可能具有Root检测功能

此应用程序可能具有Root检测功能
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md#testing-root-detection-mstg-resilience-1

Files:
com/blesh/sdk/core/zz/bx6.java, line(s) 37
com/blesh/sdk/core/zz/c97.java, line(s) 363,363,364
com/blesh/sdk/core/zz/o76.java, line(s) 106

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (app-measurement.com) 通信。

{'ip': '180.163.150.161', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (update.crashlytics.com) 通信。

{'ip': '180.163.151.162', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (pagead2.googlesyndication.com) 通信。

{'ip': '180.163.151.38', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (firebase-settings.crashlytics.com) 通信。

{'ip': '180.163.150.162', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (googleads.g.doubleclick.net) 通信。

{'ip': '180.163.151.166', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (i.l.inmobicdn.net) 通信。

{'ip': '152.199.39.108', 'country_short': 'HK', 'country_long': '中国', 'region': '香港', 'city': '香港', 'latitude': '22.285521', 'longitude': '114.157692'}

安全评分: ( Azan Time Pro 8.1.9)