#tracking #surveillance #appsec #Virucy
Tracking with @Facebook Analytics, @Google @Firebase, @Microsoft @VSAppCenter Analytics.
play.google.com/store/apps/det…
"Once the outbreak is over [...] users will be updated on how to delete the data from their phones"
play.google.com/store/apps/det…
tracetogether.zendesk.com/hc/en-sg/artic…
Tracking with @Google @Firebase, @GoogleAds, @crashlytics, #Doubleclick, @Pushwoosh.
play.google.com/store/apps/det…
❗️User login and account management over cleartext HTTP❗️
Tracking with @Facebook Analytics, #Login, #Share, @Google @Firebase, @googleanalytics, @crashlytics, #TagManager
play.google.com/store/apps/det…
Still broadcast receivers exported and logging (CWE-532).
Tracking with @googleanalytics and #TagManager though.
play.google.com/store/apps/det…
Tracking with @Google @Firebase.
play.google.com/store/apps/det…
Tracking with @Google @Firebase and @onesignal.
Broadcast receivers and activity exported. Possible SQL injections (CWE-89).
play.google.com/store/apps/det…
Tracking with @Mapbox.
Broadcast receivers exported. Writes to external storage (CWE-276). Logging sensitive information (CWE-532). Using Java Hash algorithm (CWE-327).
play.google.com/store/apps/det…
Tracking with @Google @Firebase, @crashlytics, @Facebook Analytics, Login, @uxcam.
aot-app.kdlab.ai
See also, thailand-business-news.com/health/78399-t…
Tracking with @Google @Firebase, @Facebook Analytics, Login.
play.google.com/store/apps/det…
Some flaws though: Possible SQL injections (CWE-89). Logging (CWE-532). App copies data to clipboard. Using Java Hash algorithm (CWE-327).
play.google.com/store/apps/det…
Not much to flag, except an insecure WebView implementation (CWE-749).
sld.cu/noticia/2020/0…
play.google.com/store/apps/det…
Tracking: @Google @Firebase, [...]
Broadcast receivers exported. Storing sensitive information (CWE-312), temp files (-276), logging (-532). Possible SQL injections (-89). Java Hash algorithm (-327). Random values (-330).
Tracking with @Google @Firebase Analytics, @crashlytics.
play.google.com/store/apps/det…
Tracking with @Facebook Analytics, Login, @Google @Firebase. Developed by @get_intelligent.
play.google.com/store/apps/det…
Storage of sensitive information (CWE-312), logging (CWE-532). Insuff. random values (-330). Using Java Hash algorithm (CWE-327). SSL pinning(?).
previenecovid19.puebla.gob.mx
Built with @getcapacitor.
Tracking with @Google @Firebase Analytics, @crashlytics, @branchmetrics.
play.google.com/store/apps/det…
Broadcast receivers exported. Cleartext traffic, storage of sensitive information (CWE-312), temp files (CWE-276), logging (CWE-532). Using MD5, Java Hash algorithm (CWE-327).
No common trackers 😇 though server connection/auth looks somewhat bizarre ...
play.google.com/store/apps/det…
No common trackers, but ... user auth over cleartext❗️
play.google.com/store/apps/det…