My Authors
Read all threads
<Thread> 2 days ago, India launched a mobile app "to fight against the #COVID19"

I installed the app and I have 1 hour in front of me, let's see what I can find.
The app is available on the Playstore. First step is to install and use the app as a normal user play.google.com/store/apps/det… 2/
They detected that my device was rooted. Let's bypass that! 3/
I decompiled the apk and search the string the error message "due to security restrictions". This string appears only 1 time in the SplashActivity. Make sense 4/
Side note: I have no idea what I'm doing at the moment 😁 5/
The pop up is shown if the v1.a(v0_1) returns 0. Time to fire Frida. 6/
Sorry I made a break to analyse a French thing ^^ I'm back 7/
My Frida code is not working and it's too late to debug it. I'll go for the easy route, I'll remove the root detection code from the apk 😁 8/
I bypassed the SplashActivity and recompiled the app. No more root detection 9/
Now, they want my phone number and I always have a problem when I try to login. Let's see if I can bypass that 10/
Somehow they detected that I monitored the network requests made by the app and throw me this error. Searching how 11/
I'll check that later tomorrow 12/
Lol
The WebviewActivity of the app can be used to open any url. There is no validation... Not the end of the world but it can be useful 😏 14/
Time to sleep 😴, I'll continue this thread later
I wanted to check something before going to bed. I can use this "issue" to access my authToken. I will record a small video
It can be considered as a security issue 😁
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Elliot Alderson

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!