A̴N̴D̴R̴O̴I̴D̴ ̴R̴E̴V̴E̴R̴S̴E̴
Open in Telegram
No data
Subscribers
+224 hours
+77 days
+2330 days
Posts Archive
I did before report many issues related to android apps to different companies and developers.
X companies where fast and very professionals, they understood exactly what happening and they where updated.
LIAPP made me feel stupid ..
Because i did contact them
Never Ever Send Reports To LIAPP
its an advice
< LIAPP TWO MONTHS WASTE OF TIME >
1. I conducted an analysis on the LIAPP protection product for Android apps.
2. Report 1: I found a way to breach app security temporarily using Xposed (I created an Xposed module as a proof of concept for protected apps to demonstrate the issue).
3. I reported this to LIAPP.
4. I received a response, "Thank you for the good information." In their next email, they claimed they already knew about it, which is amusing since the issue was still exploitable.
5. Report 2: I created another proof of concept video about repackaging the same app and sent it to them. They replied that the app uses cheap subscriptions on their platform, which are not eligible for their bounty program. This was also quite amusing.
6. I wasted two months explaining these issues to them, which made me upset.
7. Finally, they offered a $100 bounty, which I didn't accept. They requested a copy of my passport for payment, which is impossible for me to provide.
8. I asked them to review my reports professionally. They didn't like this and each time, I had to send a follow-up email after waiting for six days, only to receive a disappointing response.
9. Report 3: I mentioned that I could bypass full protection on multiple apps with different subscriptions (both cheap and expensive) tested on six apps. However, I didn't send this report.
10. Report 4: I was able to repack all protected apps by LIAPP from different subscriptions. I didn't send this report either.
I have never had to explain so much to get a bounty. Most teams are professionals and didn't ask any stupid questions. This company neither cares about its clients' privacy nor their security, and they have the worst team I've ever dealt with.
I don't advise anyone to report anything to them as all they want is to take the information for free and waste your time with apologies.
I will be sharing all my findings soon.
Maybe they think I'm stupid.
Or maybe they are stupid ..
interested -> @syn74x_3rr
@Android_Reverse Simo
Repost from JsHook
v1.2.5:
与旧版mod菜单共存,由用户在设置中切换
frida-gadget可修改全局配置文件
frida-mod和frida-inject可关闭扩展api
新增日志行数设置
脚本存储位置可修改
修正mod菜单id自动生成规则
修复imgui实例销毁失败
修复hook子进程多实例异常
恢复canvas接口
修复软重启导致的假激活
---
Coexist with the old version of mod menu, switched by the user in settings
frida-gadget can modify the global configuration file
frida-mod and frida-inject can close the extension API
Added log line number setting
Script storage location can be modified
Fixed the rules for automatic generation of mod menu id
Fixed imgui instance destruction failure
Fixed hook subprocess multi-instance exception
Restore canvas interface
Fixed false activation caused by soft restart
Simplehook config for Inure app 99999 trial days
{"packageName":"app.simple.inure.play","appName":"Inure","versionName":"Build100.6.3","description":"@Android_Reverse","configs":"[{\"className\":\"app.simple.inure.preferences.TrialPreferences\",\"methodName\":\"getDaysLeft\",\"resultValues\":\"99999\",\"hookPoint\":\"after\"}]","id":35}
@Android_ReverseRepost from Th3-R3p4ck3r Mods
https://github.com/Hamza417/Inure
An elegant and beautiful premium Android app manager for rooted and non-rooted devices with a built-in terminal, analytics, debloat, stats and various other panels with an independent custom theme engine, developed with purely custom APIs created for this app.
Repost from N/a
🔹Repo to assist with decrypting strings of Promon Shield protected apps.🔹
https://github.com/RevealedSoulEven/promon-string-deobfuscator
+1
- The new Algorithm Assistant Pro version has added a feature to select hooked method directly using built-in dex decompiler.
- Also they added support for frida scripts, u can enable a script within the module options.
Few more adjustment it will be the perfect Xposed module .. Loved the idea.
Amazing and inspiring work 👏
The new simplehook competitor 😁
@Android_Reverse
Algorithm Assistant Pro: xposed Module latest version.
- Now adapted to latest xposed api.
- Support running frida scripts.
- I will translate it completely soon.
@Android_Reverse
HBCTool: A command-line interface for disassembling and assembling the Hermes Bytecode.
Supported Hermes Bytecode versions:
Hermes Bytecode version 59
Hermes Bytecode version 62
Hermes Bytecode version 74
Hermes Bytecode version 76
Hermes Bytecode version 83 [New]
Hermes Bytecode version 84 [Fixed]
Hermes Bytecode version 85 [Fixed]
Hermes Bytecode version 86 [New]
Hermes Bytecode version 87 [New]
Hermes Bytecode version 88 [New]
Hermes Bytecode version 89 [New]
Hermes Bytecode version 90 [New]
Hermes Bytecode version 91 [New]
Hermes Bytecode version 92 [New]
Hermes Bytecode version 93 [New]
Hermes Bytecode version 94 [New]
Hermes Bytecode version 95 [New]
Hermes Bytecode version 96 [New]
https://github.com/Kirlif/HBC-Tool
@Android_Reverse
Repost from AbhiTheModder
Unveiling Dex2C Compiled Android APKs || Reverse Engineering Dex2C
- Recovering smali from native code and retrieve the original SMALI codes.
https://youtu.be/DcArD4SPBAU
Full Mobile Hacking Course:
-> Update: 4/2023
-> Publisher: @apk_modding
