APK is not security !!! Google should re-design it!!! - Android

Dear Developers:
I've found someone publish cracked android apps on Google Play easily.
They didn't design or code anything, just crack some famous apps of the famous companies, then remove the Ads, change the package to the others, also could add their own Ads ID.
Please See:
https://play.google.com/store/apps/developer?id=milner#?t=W251bGwsbnVsbCxudWxsLDEsImNvbS5taW5pY2xpcC5hbmdlcm9mc3RpY2syLnp6Il0."]https://play.google.com/store/apps/developer?id=milner#?t=W251bGwsbnVsbCxudWxsLDEsImNvbS5taW5pY2xpcC5hbmdlcm9mc3RpY2syLnp6Il0.
Almost all his published apps are the same as other famous apps.
Google allow this? Actually it's easy to add a shell and re-package apk.
APK, Not security!!! Someone tell me .so files also can be cracked.

Google design a non-security apk format
Google design a non-security apk format!!!
qidaozhilong said:
Dear Developers:
I've found someone publish cracked android apps on Google Play easily.
They didn't design or code anything, just crack some famous apps of the famous companies, then remove the Ads, change the package to the others, also could add their own Ads ID.
Please See:
https://play.google.com/store/apps/developer?id=milner#?t=W251bGwsbnVsbCxudWxsLDEsImNvbS5taW5pY2xpcC5hbmdlcm9mc3RpY2syLnp6Il0."]https://play.google.com/store/apps/developer?id=milner#?t=W251bGwsbnVsbCxudWxsLDEsImNvbS5taW5pY2xpcC5hbmdlcm9mc3RpY2syLnp6Il0.
Almost all his published apps are the same as other famous apps.
Google allow this? Actually it's easy to add a shell and re-package apk.
APK, Not security!!! Someone tell me .so files also can be cracked.
Click to expand...
Click to collapse

qidaozhilong said:
Dear Developers:
I've found someone publish cracked android apps on Google Play easily.
They didn't design or code anything, just crack some famous apps of the famous companies, then remove the Ads, change the package to the others, also could add their own Ads ID.
Please See:
https://play.google.com/store/apps/developer?id=milner#?t=W251bGwsbnVsbCxudWxsLDEsImNvbS5taW5pY2xpcC5hbmdlcm9mc3RpY2syLnp6Il0."]https://play.google.com/store/apps/developer?id=milner#?t=W251bGwsbnVsbCxudWxsLDEsImNvbS5taW5pY2xpcC5hbmdlcm9mc3RpY2syLnp6Il0.
Almost all his published apps are the same as other famous apps.
Google allow this? Actually it's easy to add a shell and re-package apk.
APK, Not security!!! Someone tell me .so files also can be cracked.
Click to expand...
Click to collapse
An APK is an Android PacKage, an installer package. Even windows installer packages can be edited. An *.so file, is a library file, a file containing api method and properties for use by other applications or even as modules for the kernel. Nothing is uncrackable really, implementing application security is the developers responsibility, not google's. For that purpose many licencing options are available
There will always be those who crack applications. The problem here is the screening process for android market, as a user and member of the greater android community you should report this kind of thing to google via play store.

Related

[Tips]What is ads(must read all users)

What is Ads???
-(pronounced as separate letters) Short for alternate data stream, a function of Microsoft��s NTFS file system in which files can be embedded in other files and are invisible to the user through Windows Explorer (i.e., the ADS does not affect the size, function or display of the main file the ADS is attached to). While ADS files (which are well known throughout the hacker community) can be used maliciously by an attacker wishing to plant an executable file into another file without it being detected, ADS also is used legitimately by programmers. For example, an antivirus program can include a checksum value in an ADS attached to each file.
Effect of ads...
1.ads can slow your phone
ex.Script manager(Not Paid) has a ads if you are data enable
2.some ads has a virus Called ADWARE from not Known apps downloaded in others not in gp(google play), Virus means a software can destroy your files, hardware of your phone
How to prevent adware???
You need a adblocker app Here
adaway is a app that can block all ads especially ads in script manager
so download it and install on your phone
note:this is not a antivirus! if u want antivirus go Here
FAQS...
Q. why i need to download it here instead on google play
A. google removed all adblocker app in google play so you need to download it here
If u have bugs go here
dont forget to click thanks to me...:good:
Note: this app is not mine im sharing it for u
thank you
nulda said:
thank you
Click to expand...
Click to collapse
your welcome but click thanks bro...
There is no NTFS file-system on our phones, so there is no Alternative Data Stream.
ADS is shorthand for ADvertisementS, which are a legitimate way of making money of your applications if you don't want to charge the end-user money (like the unpaid script-manager, which displays ads)
It is rarely malware, and the reason Google has removed ad-blockers (or advertisement-blockers) from it's store is because ie negatively impacts on the revenue-stream of App-developers.
So, no alternative data stream, only some code that gets advertisements of google's servers so the developers can get a little bit of money for their efforts.
Thank you.

[Q] How do Mobile Ad Networks put ads in our apps?

I make apps with tasker and I want to put them up on Play store in order to earn bucks, but they are not good/useful enough to sell directly. So I need to put ads and as far as I have read, I have to contact an ad network or two. But the problem is that I don't have programming knowledge at all! All I know is to make series of tasks and scenes in tasker and export them with tasker app factory so I have an apk file in the end.
I can make almost all apps which are usually seen in the top free apps' trends in Play Store.
So, how will I put their ads? Do they give something which involves the use of Android SDK? Or can I give them my apk file so they will incorporate their ads for me? (this doesn't seem safe though).
One solution for this may be that they give me HTML for the ad so I can put it in tasker's HTML box, but then the ad networks won't be sure if their ads are showed properly or I am showing something else over the HTML box.
Also, do I have to pay the ad networks in advance or do they only take the share from the advertisements' earnings?
____________________
UPDATE: I have learned how to develop real android apps using java and I have been uploading my apps with the name "Apps By Usman".
I thank everyone for the replies and I want to let everyone know that although I personally do not require an answer to this thread now, anyone who can share information about tasker apps and their monetization should write a reply for those visitors who would be needing such answer.
the post is like 4 months old, so i don't know if you still need the answers, but since nobody answered yet, i guess i'll just try, who knows if it helps you or anybody else.
i never used tasker before, but as far as i know, ads network company is providing sdk we have to include in our development project, some company like millenial media (i don't know about other company though) even providing step by step instruction of how to put their ads into our application on their website.
from your question, i assume tasker is something like game maker or app maker, sorry if i'm wrong, well, since i've some experience in using game maker also, just in case i'm right, in game maker, if they support putting ads into application, usually they include some option to do so, and the sdk from the ads network company is already included, i don't know if tasker have something like this.
hope this helps.
Thanks for the reply, tasker is not a development environment, it is just an app which lets us invoke different functions of phone on a step by step manner, and even lets us export these sets of actions as apk files.
I have, however, found that there is a very little possibility for banner ads in it. So I have now learnt coding in java and I am now making apps in java.
The answer to this question, if someone else is interested is that tasker can invoke html banner ads with the help of webview object if your preferred ad network supports this format, but to make real and native apps, we need to learn java.
if anyone needs to integrate ads in your tasker aps contact us.we have developed a plugin to help you.
noorudheen km said:
if anyone needs to integrate ads in your tasker aps contact us.we have developed a plugin to help you.
Click to expand...
Click to collapse
admob?
You can get benefits by advertising.
Each advertising platform, there will be a detailed access way and their own SDK,
My Skype is: s40319882
Welcome exchange
noorudheen km said:
if anyone needs to integrate ads in your tasker aps contact us.we have developed a plugin to help you.
Click to expand...
Click to collapse
I am willing to monetize my app made with Tasker, is there any easy easy way to insert or inject ads into the apk without codes?
As for paying the ad networks- are you looking to advertise your product or publish advertisements on your app? I guess it depends how many users you have! If you want to both promote your app and monetize your audience base, you should consider choosing a cross-promotional advertising company. I can give suggestions, but for now I suggest you google App cross promotion companies and pick the one that is best for you.
As for the tool kit, it again depends on the company, but a good company will have the option of SDK, API S2S, open RTB, JS tag, etc
ad mediation !!
hey , if still need answer , ther is some mediation website where you upload your apk and they put their sdk in it with some banner or interstitel ads but still limited as tyou can't control where ads will show up, only at the begining or the exit .
So being this thread has been revived, Ad networks do not put ads in your apps, you have to put the ad networks into your app. This is normally done by taking hours and hours of your precious time coding a SDK into your project. Boring.....
Using Enhance, you can now integrate all of the services that providers offer without ever having to touch an SDK again. With little to NO coding at all and without touching source code, Enhance® is the easiest way to integrate 3rd party services into your project or to keep them up to date. (Ads, Mediation, Analytics, Attribution, Crash Reporting and more) No more SDK integration!!!
We even have a "ZERO CODE" option for certain features!!!
For more information on Enhance, just follow this link : https://goo.gl/kufiQQ
ismaelbb said:
hey , if still need answer , ther is some mediation website where you upload your apk and they put their sdk in it with some banner or interstitel ads but still limited as tyou can't control where ads will show up, only at the begining or the exit .
Click to expand...
Click to collapse
The point is being able to choose the placement and format for in-app ads easily. That's why mediation works so well.

Lowrance GoFreeLink app and chartplotter rooting

The application that Navico has released for its line of chartplotters encompassing the following brands; Lowrance, Simrad and B&G line of chartplotters has all the auto pilot functionality coded into the application and is very hard to remove.
You can't just simply remove a function. The code has to be rebuilt from the application side or found complete on the chartplotter. A typical Lowrance HDS7 Gen3 if one could get root on it may very well contain the same code with which to redesign the android .apk file.
Does anyone know how to jailbreak a chartplotter?
PacificGreen said:
The application that Navico has released for its line of chartplotters encompassing the following brands; Lowrance, Simrad and B&G line of chartplotters has all the auto pilot functionality coded into the application and is very hard to remove.
You can't just simply remove a function. The code has to be rebuilt from the application side or found complete on the chartplotter. A typical Lowrance HDS7 Gen3 if one could get root on it may very well contain the same code with which to redesign the android .apk file.
Does anyone know how to jailbreak a chartplotter?
Click to expand...
Click to collapse
What you are asking sounds illegal (I apologise if its not) so can't be discussed on xda
Thanks for understanding
Sawdoctor

how to protect my privacy on android

my question is as above in the title
btw i saw about replucant on gnu's website
thoughts about it?
how would it protect my privacy
and i have been told that even if i start using repulcant google service will be another privacy threat
i want to know also how google services can be privacy threat do they have malicious code made by like other trackers (like windows trackers ...websites... etc..)
The most basic thing you should do:
do not grant various apps on your phone the permission to access your album, contact, sms or email, location and so on, unless you really need to use their functions that require such permission.
finalvagas said:
The most basic thing you should do:
do not grant various apps on your phone the permission to access your album, contact, sms or email, location and so on, unless you really need to use their functions that require such permission.
Click to expand...
Click to collapse
ik ! but i want to protect myself from the tracking or spying of google
Root your device, preferably a 'clean' way (without questionable root software that can do more harm than good). Make a TWRP backup or similar, just in case you stuff your device.
Allow installation of apps from unknown sources in "Security > Unknown Sources". Then install AdAway (ad-blocker) from f-droid.org. https://f-droid.org/packages/org.adaway/. F-droid is officially linked from the AdAway website https://adaway.org/ since it was banned on the Google Play Store, which is testament to how much of a threat it is to Google.
The key (to me) is to kill Google's main revenue first: ads. Along with the revenue of all the other adware/tracking/spyware creators who wish to do business on the Spyware Store. The second way to kill them is to use ad-free apps as much as possible (f-droid.org can probably cater to most needs).
Installing a keyboard that doesn't spy on you is fairly important to me. You might consider AnySoftKeyboard or others from f-droid.org. After switching to the new keyboard, uninstall your default Google keyboard using your preferred root uninstaller. You can use Play Store apps like Titanium Backup to uninstall & backup if you wish. You can download Play Store apps without using Play Store by just getting their APK files on sites like https://apps.evozi.com/apk-downloader/ though some apps and games will require Google Play Store and related spyware to run. To me, those that do require Google Play Store and related spyware components aren't even worth considering.
Uninstall every single Google app on your device. Including Voice components. Plus the Play Store and related Services Framework and heaps of other Google Spyware. I have finally started to compile a list of those I have found to be safe to remove, so if you need more details, I might be able to help a bit.
There are usually better apps for Mail, Contacts, Maps, Gallery, Calculator, SMS, messaging, Calendar, Camera, etc. They are freely available without tracking/analytics, adware & spyware. An extremely good place to start inorder to get the basics are the Simple Mobile Tools apps from Tibor Kaputa https://simplemobiletools.github.io/
If you want to spend your money, consider giving it to guys like this.
Some root uninstallers I have tried have been extremely unreliable, leaving your device essentially bricked after they fail to start after removing a component, or by giving you dumb error messages after removing a safe component that other root uninstallers have no trouble with. Regrettably, I have yet to find a decent open source root uninstaller. At the moment I am using Titanium Backup to uninstall unwanted apps and components from Google, unwanted spyware from the chipset manufacturer & unwanted spyware from the device manufacturer. Personally I don't use any of the stock apps, including the stock launcher. All of these companies have a long history of customer privacy violations. All profit from profiling you and selling you out to their partners.
There are useful (adware/tracking-infested) Play Store apps like MyAndroidTools that allow you to disable certain components from certain apps which might also be useful to you. This was available on Google's Play Store but now does not appear. I use it for apps like Firefox, to disable the Crap Components I do not want running.
You might also consider XPrivacy or XPrivacyLua which gives you more control over what apps can do. You might also consider changing your DNS settings from Google's to another with apps like DNS man.
Google is the Spyware King at the moment with literally billions of devices in use, eclipsing Microsoft and Apple soyware in terms of numbers of devices in use.
You have many different ways to protect your Android phone. You should use a strong password and backup your phone. Here is good article about it: imei.info/news/android-privacy-protect
You can just check it.

General Download Any Apk Off The Playstore Without installing Google, AMAZON, or Any other APP Store

EDIT-- This post is super old (but still works).
Another method (maybe better for your use case?) is the Aurora store. Please see the COMMENTS SECTION.
How To Download any app on the playstore, Without installing GMS, GAPPS, AMAZON, Or any other App Store
EVOZI:
https://apps.evozi.com/apk-downloader/
GOOGLE PLAY STORE:
Android Apps on Google Play
Enjoy millions of the latest Android apps, games, music, movies, TV, books, magazines & more. Anytime, anywhere, across your devices.
play.google.com
Simply paste the playstore link to evozi, of the app you want to download!
This is not warez, you Can Not Download Paid apps.
This site just caches and backs up all our favorite apps.
Rarely, if you're looking for something too obscure, it will not be able to locate it.
Have Fun
Google Play Store lets you download and install Android apps on an Android-powered phone or tablet or emulator if GMS Core already are installed thereon.
Sometimes evozi will say something about "you're being rate limited" and it won't work. I think this is bc they are getting too much traffic. I use Evozi in this example, as it is the cleanest (adless) experience, but do bare in mind you can always use other Mirrors~! sites like APKpure.com are mostly safe
any idea how does https://apps.evozi.com/apk-downloader/ work as am trying to automate some work and i dont want to depend on apk-downloader or any other mirror
@synackers sorry I just now had the time to research what I wanted to share. There's a "store" that has access to the playstore repositories, that is open source, and gives the user the freedom to choose to enable google features or not. This works on windows phones too and I would guess WSA too?
It is called the "aurora store" it's website is here:
auroraoss.com
This is still new to me so I can not explain it personally but the knowledge is available
This article explains a little about it and shows pictures
Maybe they have a github repo somewhere you can obtain the code you need to dl things
Hope it helps!
Hi Jeneh , to be honest am not interested in any open source apk mirroring available in internet
am seeking to understand how auroraoss or evozi actually works behind the screen ... how do they give you apk to be downloadable is also fetched from other mirror or do they have google developer and google offer any api to play store ..etc
more deep technical details is of my interest . i do appreciate your feedback
@synackers The Aurora Store is different from evozi or other sites like evozi, in that it actually accesses the repositories, ie the link to the android app in question.
For instance: to download the app "Termux" a call is made to get the app from com.termux and it goes on to install and build from there, the latest software.
When using evozi or apk mirror, they save actual hard copies of the apps to their servers to share to users, which could be any older version of the app.
Evozi regularly redownloads the more popular apps from the play store and they take requests. However there is No version choice available. The downloaded apks hash signatures will match the playstore app sigs for that app version.
Sites like apk mirror and others tend to keep all the older app versions and provide a choice which version to download. This is my only use case for these as they are more risky and you should vet the sigs on them.
Here is aurora's gitlab https://gitlab.com/AuroraOSS/AuroraStore
This link has all the code to be able to go through and find exactly what you need.
Some info on the code
"Aurora Store was originally based on Sergei Yeriomin's Yalp store. Aurora Store v4.0 is a rewrite of version 3 in Kotlin"
The developer of the store has made a page here on xda that maybe they would be willing to give better insight to a specific question you have in the installation process to provide the technicals.
Outside of Aurora, it may be beneficial to learn about PackageInstaller to be able to manually install and or uninstall apps with code. Or Package Manager, if you open that spoiler and select the "PM" option you can see all the code for using it.
Hi Jenneh ,
much appreciate your response and cooperation |
https://www.codevoila.com/post/77/how-to-install-or-uninstall-an-android-apk-file-programmatically this is definitely valuable and its crystal clear for me on how aurora works.. i had a glance at the code in github .
now my challenge or use case which i want to achieve is as following ;
1. need to take APK directly from play store ( i dont mind if google offer paid API which am not aware or seen )
this should be automated off android physical phone / or emulator
working in other project ^^ and stuck in this point
what i have noticed indeed evozi take package from playstore cause i checked an APK which recently was published and not available in any other mirror site
Aruroa still need mobile phone or emulator to work
Thanks again and appreciate your cooperation
With regards to thread's title "Download Any Apk Off The Playstore Without installing Google, AMAZON, or Any other APP Store" take note that you of course need an app store to get APKs from.​
Never make use of Aptoide: it's Large, Decentralized, Dangerous.
Aptoide is one of the most sophisticated app sources. The store works with a distributed network of different store providers and combines them on a unified platform. However, this poses significant security risks.
Truely not what am seeking , any mirror is not an enterprise grade options cause security risk is high so if there is any way to download directly apk from play store without the need for emulator or device would be much appreciated
The app store with least security risks is Google Play Store.
Apps from outside of the Google Play Store are also scan using Google Play protect on the device, it is a security risk to install apps outside of the Play Store but as long as you trust the app developer you should be fine.
well, what is the case if i need to automate a way for MDM solutions
IDK.
Probably MDM isn't not applicable if the managed devices differ in Android version and ARM architecture.

Categories

Resources