[Info]whatsapp security loophole!!! - Sony Ericsson Xperia Neo, Pro

Hello guys
I started this thread to warn u about loopholes in whatsapp messenger!!!
With about 10000000+ downloads(from play store) it is one of the best cross-platform messenger.
But back MAY 2011 (about a year back) it was found that whatsapp actually sends all the details in PLAIN TEXT.
Whatsapp developed said they are working on this issue but it hasn't been solved!!!
Earlier it wasn't easy to sniff ur whatsapp conversation as it required knowledge of packet sniffing.
But now there is an app in play store to do it!!!
Yes u read it right !!!
The only reason i posted this thing here is because it's very easy to sniff conversation using that app.
DON'T BELIEVE ME???
Try this app from play store.

UPDATE
Sniffer app is taken down by the play store
hopefully whatsapp developers will now update the app!!!

Tested it worked O.O
I read my sisters Convo :O
Needs to be fixed~

tested with my bro's droid, it works -.-
suggesting an uninstall, or just dont use it for now

free version for three talks only and dont delete it

Damn we don't have wifi here :/ otherwise useful app

good job!!!!!!

Guys dats d reason i posted it here
WHATSAPP GUYS KNOW THIS FROM A YEAR!!!
I WONDER WHY THEY AIN'T FIXING IT.
I use packed sniffing methods on my coll WiFi since months
But this app is damm userfriendly and even a noob can use it.
If possible don't use whatsapp on public WiFi n/w.

i search this aplication and i search donate version, really function, whatsapp sniffer is the app

does it only work with WIFI network,, wont it work on Cellular network

Will work on shared n/w i.e. WiFi only

Application has been removed from play store.. Can any one who had tested upload here
Sent from my MT11i using XDA

Glad to hear it only works on WIFI as I don't use WIFI anywhere but at home. But I can't believe they've just been sitting on this for a year. And apparently they have or had other security issues that were handled in questionable ways. Hope all this coverage gains traction and they are forced to address this.

Plain Text?
Hi,
I've tried it between my two android devices and sniffed the network traffic with Wireshark (sent a text message in WA). Here is a screenshot where you can see that the whole network traffic was in ssl packets (except the ACK's). I haven't tried the WA sniffer yet but my suggest is that it uses man in the middle attack and if the Whatsapp doesn't verify the SSL certificate the sniffer device can scam with it.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}

would like the apk too ....

Still working now?
Hai guys, recently i try out the application which i download somewhere, it can start spoofing. But does not Catch any conversation. although in same network. So now is not working dy?
see the link for image
wwwdotfacebookdotcom/ajax/messaging/attachment.php?attach_id=16aed27f638191557f7ad738a30884ce&mid=id.366744480064899&ext=1342473340&hash=AQBwQotNj-CBuI8V
Thanks

Related

[App] PlayOn Mobile v1.13

Great App..but unfortunately for me..not working unless I'm on Wifi..Anybody else have this problem? I haven't really had time to mess with it..but reminds me of At&t mobile video..streams tv..but most of them only clips. With a netflix account..start your instant queue, browse genres, or browse new arrivals..going through genres and new arrivals seemed a lil difficult..for me anyway..wish there was a search feature within the app..quality of the streaming is based on your internet connection which is great..would be greater if it worked with my mobile internet instead of only my home internet. I'm continuing to test this app as I write this........well..this sucks..netflix doesn't want to stream for me..94%...98%..displays poster..&asks me to push play. This app working for anyone?..Is there something I didn't read about..Gonna try this on my cappy.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
I have it working intranet and internet. Did you open the port on your router to forward to your server.
Seems like a cool idea, but I set it up on the Wii for my hoodlums and it lagged some. Not bad program, but not knocking me dead to have it either.
Sent from my MB860 using XDA App
briansaul said:
I have it working intranet and internet. Did you open the port on your router to forward to your server.
Seems like a cool idea, but I set it up on the Wii for my hoodlums and it lagged some. Not bad program, but not knocking me dead to have it either.
Sent from my MB860 using XDA App
Click to expand...
Click to collapse
will i was trying and well..didn't seem to work..how did you manage to get it?
Works fine for me just fine. This is probably something you should take up with PlayOn support and not in the Atrix forums.
knigitz said:
Works fine for me just fine. This is probably something you should take up with PlayOn support and not in the Atrix forums.
Click to expand...
Click to collapse
I would tend to agree. Also configuring your router correctly and testing over wifi at a friend's house would take ATT out of the mix.
Sent from my MB860 using Tapatalk

content removed

content removed
Or maybe it thinks the TP is running FB from the legit webOS app
Sent from my MB860 using XDA App
You don't believe me?
Ever think its because every other platforms FB app has been recently updated..and WebOS has not?
Facebook now requires a GPS connection, hence why almost all mobile FB apps give a rough location now when you post
OK.. Next question.
About that SIM Card slot...
Antenna? SIM Card? SD? Identifier? What IS that?
What exactly is that? Can you take it out? Can you insert something into it? Can you use it in some way?
If not...why would they include it...? It must be useful in some way...
That's odd...
its the sim card slot for the 4g models. on all other models its a dummy with the serial number
and there is NO sim card hardware if you have a dummy slug, teardown confirmed
but it DOES have the pins and chipset to wire one in but that would require a meta-doctor of the 4G doctor for drivers (webOS), but then CM7 would not work
Would have loved to have had an SD slot.
that would have been nice for the 16GB users, but im sure there will be a much easier method for OTG with a flash drive/sd card reader in the near future
DreamOWD said:
Apps / Facebook
1. Lets you view messages you thought you deleted
2. Lets you get messages from people you've blocked
3. Won't let you delete statuses or messages
4. When you update your status on Facebook from the TouchPad app, it will do this:
>>>
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
<<<
Facebook no longer does that for iPhones, Androids or anything else. It'll simple say via mobile, if anything.
Maybe Facebook is buying WebOS?
Click to expand...
Click to collapse
Read this http://www.precentral.net/how-webos-facebook-app-made-jobs-yell-zuckerberg to understand why facebook for webos isn't as consistant as official facebook app interfaces.
Regarding the via mobile message, like others said, it was updated for ios and android devices. It still says Blackberry, Windows Phone, etc for other platforms.
You can put your conspiracy theory to rest.
Okay.
Is anyone getting that Wifi and Sound problem from time to time?
Every now and then, the sound will become rattly. It just happens.
And every now and then, the WiFi will just stop working. And you have to reset it.
It's happening increasingly often..is it just me?
Noticing the WiFi issue for sure. Never happened before 3.4.
Um, in Android. What's with Facebook not working?
I see people with the icon on their homescreens. But... Why if it doesn't work.
It shuts down repeatedly.
I never really looked into this issue since I browse the facebook website rather than using the app but I did skim over this issue. I believe it crashes because it's trying to pull your location and the touchpad has no GPS. Solution is to fake it. I think there's a fake gps app on the market to fix this.
As to why people have the facebook app. 2 functions. Contact syncing and ability to share photos via facebook app.
comment just disappeared
What is the cause of the HP TouchPad's bulkiness? If you tap the back of your TouchPad with your fingernails, it sounds hallow- do you think they'd be able to issue out new backings that would make the TouchPad half as thick?
Another thing is, you can scroll through card view left and right, but why not up and down?
Ever notice in webOS, when you're interacting with card view and you tap to bring the card up and it's blurry for a moment- why does that happen?
Odd...

[Q] Methods for streaming video from my PC remotely?

Many of the suggestions I've ran across so far were for local wifi streaming. Im looking to be able to watch something stored on my pc with my N4 away from home via mobile network. I have an unthrottled data plan, so nothing is overkill.
Thanks for any suggestions.
Any ideas?
MikeChops said:
Any ideas?
Click to expand...
Click to collapse
I might have something working, I'm making sure it works first before i pass it to you though, so stay tuned!
Sent from an Xposed LG-G2/LS-980
Ok I figured it out, and feel silly that it was under my nose this whole time. I hate when people figure out a problem without sharing the solution so I'll share for anybody with the same question in the future.
1. Download the Plex server (Plex for connected TVs and streaming devices): https://www.plex.tv/downloads
2. Invest $4.99 (well worth it) into the Plex app: https://play.google.com/store/apps/details?id=com.plexapp.android
3. Setup the Plex server on your computer and enable the myPlex server. (see attachment)
Your app should discover your computer as if you're connected on the same network.
MikeChops said:
Ok I figured it out, and feel silly that it was under my nose this whole time. I hate when people figure out a problem without sharing the solution so I'll share for anybody with the same question in the future.
1. Download the Plex server (Plex for connected TVs and streaming devices): https://www.plex.tv/downloads
2. Invest $4.99 (well worth it) into the Plex app: https://play.google.com/store/apps/details?id=com.plexapp.android
3. Setup the Plex server on your computer and enable the myPlex server:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Your app should discover your computer as if you're connected on the same network.
Click to expand...
Click to collapse
I never said i wasn't going to share it, i was making sure it will work outside wifi, but whatever, you invested money on something you could of done for free.
Sent from an Xposed LG-G2/LS-980
Please share I'd like to know
Emit also a good alternative.
Sent from my Desire HD using xda premium
Critical Detox said:
I never said i wasn't going to share it, i was making sure it will work outside wifi, but whatever, you invested money on something you could of done for free.
Sent from an Xposed LG-G2/LS-980
Click to expand...
Click to collapse
I never implied that you weren't going to share it, so my apologies if my wording seemed directed at you. My "not sharing" comment was directed to people that fix a problem they have without sharing a solution after the fact. By all means, I'd love to hear your method!
Other methods I ran across were a bit wonky. Plex offers the ability to change the bitrate of the videos I'm streaming, which was a major plus for me. The five bucks was well worth it. (having a gift card balance left over didn't hurt either.)

[APP] My Webcam - Turn your windows phone into a Remote Webcam

Hello guys, here I present you My Webcam an app to transform your Windows Phone into a remote webcam which can be accessed using a simple web interface, VLC & any program to access IP Camera feeds.
you can also remotely take pictures and record videos it has support for IP Webcam adapters to use your phone like an pc webcam for Skype , google Hangouts & some web video chatting.
i am inspired to bring even more features with future updates.
app price is $3,99 with free trial.
Mod edit: Removed paid app link
First, the app isn't working for me: probably, your host is blocked by my firewall. Second, I should be a complete idiot to stream my (private) camera via your host with insecure (however it's doesn't matter - even if you'' implement https - who knows, maybe you are owner of the some sort of "live porno" site, who knows?!) http connection. No way, sir!
Actually, the app only create one local port people cant just accesss it over the internet ( someone correct me if i am wrong), and the other there is NO HOST thing LOL. Everything is done within your local network only.
What happened when you tried? What is your phone model?
myrcello said:
Actually, the app only create one local port people cant just accesss it over the internet ( someone correct me if i am wrong), and the other there is NO HOST thing LOL. Everything is done within your local network only.
What happened when you tried? What is your phone model?
Click to expand...
Click to collapse
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
That means your app is buggy and can't detect real (internal or external) IP address of the handset connected to the router. It shows 172.20.20.20 (I just googled it: yes, it's not your IP but rarely used private adresses range - I have NO idea why you used it as a text template instead of common 127.0.0.1, for example).
Having bugs like this in the paid (and expensive for it's kind) app (JFYI, paid app promotion is against the xda rules) is also "NO WAY".
P.S. It doesn't really matter what handset model is used (it's your implementation bug!) but I used L-640 for test.
sensboston said:
View attachment 3550706
That means your app is buggy and can't detect real (internal or external) IP address of the handset connected to the router. It shows 172.20.20.20 (I just googled it: yes, it's not your IP but rarely used private adresses range - I have NO idea why you used it as a text template instead of common 127.0.0.1, for example).
Having bugs like this in the paid (and expensive for it's kind) app (JFYI, paid app promotion is against the xda rules) is also "NO WAY".
P.S. It doesn't really matter what handset model is used (it's your implementation bug!) but I used L-640 for test.
Click to expand...
Click to collapse
Hello dear sensboston, the app gets all the IPs that the phone is connected to ( this is not a text template the defaut xaml incode template is 0.0.0.0 haha) then show it in the links menu, but Windows Phone attaches the port to only one ip, my implementation is not buggy - this is Lumia 640 issue ( I can say that because I have a lot of email sent by user using this phone and bad reviews also).
sorry man maybe you will not be able to use the app not by my fault but by the way you are speeching you don't really need to, best regards.
Maybe you are right about L-640-specific bug but just tried (just in case!) on my L-920: it detects IP correctly but still doesn't work in Chrome
And, @myrcello, if you are writing something on the public forum, you should be ready not for the "thanks" only but for criticism too. Your app has too many issues for the paid app; you've posted paid app promotion on the enthusiasts forum - I believe it's a good reason to criticize your app.
Please read the article posted in the link below before posting any more paid apps on this site.
http://www.xda-developers.com/a-guide-to-paid-work-on-xda-developers/
Thread closed

General Those wonderful inventions (Call recording)

I still remember the first bitter feeling when I learned that I could not record the calls, I felt helpless: The companies could, and can, record me but I could not record them to avoid an injustice in the future.
I had a Huawei then, now a S23 Ultra, and discovered the following marvel:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
This app only took a few kbbs and added the record button in the phone menu, it recorded in very good quality and solved my life.
Now searching for the Samsung I haven't found anything similar, but I'm sure we might find something similar in some Chinese file or from some random person.
I know what you are going to tell me, there is Cube ACR (but I refuse to give permission to the connector and have access to do whatever I want with my phone) and the change of CSC region to INS but I refuse to believe that something as simple as the file I left in the photo does not exist.
Skvalex call recorder
It's free, and you download it from his website and everything just works. If you want pro features you buy the unlocker app from the play store. But basic recording features are free. And no root needed. I've used it for years and works completely offline if you want if you wanted to make sure it doesn't data.
Change csc. You can find it here on xda. No apps needed
inthedark22 said:
Change csc. You can find it here on xda. No apps needed
Click to expand...
Click to collapse
Unfortunately that didn't work for me on my old zfold3 or my s23 ultra being a NA models.... So I have to use the app
spart0n said:
Skvalex call recorder
It's free, and you download it from his website and everything just works. If you want pro features you buy the unlocker app from the play store. But basic recording features are free. And no root needed. I've used it for years and works completely offline if you want if you wanted to make sure it doesn't data.
Click to expand...
Click to collapse
Although the app is not available on PlayStore, I downloaded it from their official website and it also asks for full access (connector) just like Cube ACR, which is too invasive.
While it requires that for the recording I have used it while blocking all internet connectivity to the app and it works just fine without internet therefore it's not collecting anything if it can't connect to the internet
spart0n said:
While it requires that for the recording I have used it while blocking all internet connectivity to the app and it works just fine without internet therefore it's not collecting anything if it can't connect to the internet
Click to expand...
Click to collapse
It's an interesting option, although I'm not entirely convinced, as with access to the whole phone, any command could intermittently activate internet access.
Still, out of curiosity, how do you block an app from accessing the internet?
Change csc to get it integred at sam call
Gor3zno said:
It's an interesting option, although I'm not entirely convinced, as with access to the whole phone, any command could intermittently activate internet access.
Still, out of curiosity, how do you block an app from accessing the internet?
Click to expand...
Click to collapse
I use a combination of things. I have NextDNS on all of my devices including home wifi and set as private DNS on any device with that setting. I also use tracker control to block internet access to specific apps on device.

Categories

Resources