1/ Yesterday night, I analysed "COVID-19 Gov PK", the official #Covid19 mobile app made by the Pakistani government. Hardcoded passwords, insecure connections, privacy issues, ... nothing is ok with this app.
Want to see this horror? Follow me ⬇️
2/ This app, made by the Ministry of IT and Telecom with National Information Technology Board, is available on the PlayStore and has been downloaded more than 500,000 times.
3/ It's NOT a contact tracing app. It gives access to dashboards for each province and state, you can do a self-assessment, get radius alert, get a popup notification reminding the user of their personal hygiene (wut?).
4/ When you open the app, it asks a token to the pak gov server with hardcoded credentials: CovidAppUser / CovidApi!@#890#
5/ Because hardcoded credentials seems to be a thing in Pakistan, when the app requests the position of infected people on the map, they used another hardcoded creds: ApiUser / ApiUser@1234#
6/ The 1st request made by the app is, ofc, an insecure request
7/ In the "Radius Alert" tab you can get a map of infected people. Ofc, the exact coordinates of infected people are downloaded by the app 🤦♂️
Sick people deserve privacy
8/8 To sum-up, in "COVID-19 Gov PK" we found:
- hardcoded passwords
- insecure requests
- privacy issue
Thanks for the good laugh, you are the worst #Covid19 app I analysed
What can we see?
- We can recognise the road signs, we are in the US.
- The building looks like NYC but it just a wild guess
- The store is in a corner
- We can read the store sign: "Hardware *umber store"
- The store sign is also in Chinese. Maybe chinatown?
Just type "Hardware *umber store" in Google. Ok, the missing letter is an l.
1) After a quick image reverse search on Google Image, we can find the original publication. Yesterday, Louis de Luxembourg announced his engagement with Scarlett-Lauren Sirgue. instagram.com/p/CNUQgmaC7rm/
2) Time to check their last moves. We are in a pandemic and they are public figures, so everything should be documented. After scrolling about the last news on the Royal Family of Luxembourg, I can see they spent the last holidays in Biarritz, France parismatch.com/Royal-Blog/fam…
3) Time to open Google Maps. I can see water behind them and the building in the background is pretty far from them which suggest the beach is probably long.
Vous avez juste une infrastructure qui ne tient pas la charge. Encore une fois. Tous les parents de France font travailler leurs enfants en ce retour de week-end prolongé, ce qui a probablement provoqué la surcharge des serveurs...
On va commencer par un cours de sport. Commence à courir je te rattrape
You asked so I did it. I spent 30 min on this new Koo app. The app is leaking of the personal data of his users: email, dob, name, marital status, gender, ...