how to detect spy software like flexispy, mspy, phonesheriff, ikeymonitor, ... ? - Android Q&A, Help & Troubleshooting

I don't want to factory reset my phone nor do I want to reflash lineage os.
I just want to detect if there is some spy software on my phone. Software like flexispy, mspy, phonesheriff, ikeymonitor, thetruthspy, ....
I found one app that claim to find them but I doubt its effectivness (https://play.google.com/store/apps/details?id=com.antispycell.free&hl=fr)
One blog from some years ago claims that the anti-virus made a poor job to detect such softwares. (I can't find that page again)
Some site suggested to use an access point to sniff traffic. That's what I did with my raspberry pi but I got only a bunch of encrypted traffic from my phone (https). So it was not helpfull beside getting a list of IP or at best domain name. You can tell much with that. The next step would be to MITM with ssldump or sslsplit but that's more technically challenging for me
Is there other tool available ? an app ? a site of a good soul that maintain a list of file installed that such spy app and that you could find manually by using an (root) explorer of /system or /data ?
Thanks

Related

[Q] Android Phoenix LG help.

So call me paranoid, but I have a number of questions on security and log/ user monitoring. A while back I was using my neighbor's network via wifi and long story short I felt almost like my androids apparently were acting funny and since resetting it and using my own 3g network don't seem to have the same issues. I use a LG Phoenix I got new in late 2011. What are some foreign hacking files to look for? I found a file with es file explorer named monkey... long story short what are some log and user monitoring apks that let me see foreign controllers changes and information logs and if my data is going anywhere I can see where its going, and lets me fully secure my phone. Please even if I have to delete factory files my phone is rooted and I use es file explorer not much of a hacker for now. Please understand. Also is there a way to save directly to my Google Drive? Maybe even run apps with data via gdrive? What are some things to check if a hacker added programs to my phone what are some files apks etc to look for thanks. What I meant about downloads is changing my android download directory path to directly automatically by default download to my gdrive cloud, if there's a way please share. Thank You.

[Q] Installing multiple devices at once

Hi, I have about 200 android tablets and I would like to know if there is any solution how to install them whit filled Google account, installed apps from GP, settings by some easy way rather than doing it with every single tablet...
Something like image file ofr Windows, or *.exe app (in self execution rar) which contains specific informations, ex. specific company ports etc.
Do you guys know about anything like that? It could be even bussines solution, paid, there is no problem with that, only I could not find anything
ยจ
Thank you very much!!!

Finding app pretending to connect to internet as other

Hi,
I am trying to remove malware from my smartphone. I know I should probably flash a custom ROM, but it's a generic Chinese device based on MTK6753 and I don't know enough to port ROM's.
So far I found I had some strange monitoring thing in /system/bin. It was called "smsdamon" and "smsservice". It used UID1001, hiding its existence. Took me 2 weeks to find it. After I deleted it there is no connection shown in NetGuard logs from UID1001 to "dominoppo".
However there was another entry in the logs, for apps using UID1000. I tried searching the device for any "dominoppo" entry, but was unsuccessful so far. Can anyone help find a way to locate it? I'm at a loss here.

[TOOL] HuaweiUpdater - Update to EMUI 9 without changing DNS

Copying from my previous post:
I made a tool to "force update" my phone (Honor View 10, European/C432 model), and I thought I'd share it in case anybody wants to give it a try.
Notes
It is Windows-only (Specifically Windows 10 (64-bit), build 1809, although it probably works fine for most/all other versions of Windows)
It requires .NET Framework to be installed on your computer. It can be downloaded from here
It might cause some anti-virus programs to flag it due to the nature of the tool (although nothing on VirusTotal detects it as malware)
Currently, a lot of stuff is hard-coded (source code available below), including the path to HiSuite.exe. If the path to your HiSuite installation isn't "C:\Program Files (x86)\HiSuite\HiSuite.exe" (or "C:\Program Files\HiSuite\HiSuite.exe" in the case of 32-bit Windows), the tool won't work
It's currently only supposed to work with the BKL-L09 (C432) model. Do not use this tool if you do not have the BKL-L09 (C432) model
If you are on 32-bit Windows (your HiSuite installation path is "C:\Program Files\HiSuite" instead of "C:\Program Files (x86)\HiSuite"), download the HuaweiUpdaterWin32.7z file. Otherwise, download the regular HuaweiUpdater.7z file
And, of course, please use the tool at your own risk. I'm not responsible if the update somehow ends up breaking your phone.
Usage
Connect your phone to your computer through USB
Before proceeding, make sure HiSuite isn't running. Open Task Manager (Ctrl+Alt+Del -> Task Manager or Ctrl+Shift+Escape) and make sure "Huawei PC Suite" (hisuite.exe) isn't running. If it's running, right-click and select "End Task" to kill the process
Run "Launcher.exe" and HiSuite should open
Click on the "Update" button. There should be a red dot on it
Wait for HiSuite to finish installing the update on your phone
Source code can be found here: https://github.com/Smaehtin/HuaweiUpdater
Here's a version that should work for the Indian (C675) variant.
Reserved
can not download the indian version link
ram161287 said:
can not download the indian version link
Click to expand...
Click to collapse
Strange, maybe it works with TinyUpload:
HuaweiUpdater(C675).7z
HuaweiUpdater(C675)Win32.7z
It worked! I updated to Android 9.0 with EMUI 9. Thanks, mate!
Does it revert your phone to factory setting?
The procedure worked like a charm! I'm on Pie now
All apps and settings stayed untouched, no factory reset.
Works great for the Indian variant:good:
You sir are amazing..tyvm
Thanks for the method mate.
Smaehtin said:
Here's a version that should work for the Indian (C675) variant.
Click to expand...
Click to collapse
I will try this today. Btw, can you just elaborate what is your approach for this solution? I mean the other Firmware finder solution masks your DNS and then updates the firmware and ROM. 2hat does your solution do? I am not a developer but just wanted to know how does it actually work. If it's too technical or difficult to explain, let it be. Just being curious. Thanks and happy new year dude
Will try tonight and feedback
kavee.gauravjoshi said:
I will try this today. Btw, can you just elaborate what is your approach for this solution? I mean the other Firmware finder solution masks your DNS and then updates the firmware and ROM. 2hat does your solution do? I am not a developer but just wanted to know how does it actually work. If it's too technical or difficult to explain, let it be. Just being curious. Thanks and happy new year dude
Click to expand...
Click to collapse
The way the FunkyHuawei and Firmware Finder method works is by you configuring your network to use their DNS server. A DNS server is what is used on the internet for "resolving" a domain name (like google.com, .xda-developers.com, hicloud.com, etc.) into an IP address. So, when a "client" (either your computer when using HiSuite to check for updates or your phone) asks for the IP address of query.hicloud.com (used for update checking), instead of giving you the IP address of Huawei's update server like a normal DNS server would, it gives you the IP address of FunkyHuawei/Firmware Finder's update server.
So now, whenever you do an update check, you're not talking with Huawei's update server but a "fake" server, but your phone/computer isn't aware of this (well ...), and when your phone/computer asks this server if updates are available and if your phone is allowed to install the update, the server will just say "Yeah, here's the update, go ahead and install it".
My method is similar in some ways. What it does is "hooking" the HiSuite process. This allows my tool to intercept and alter communication between HiSuite and Huawei's update server, and by spoofing some requests/responses, it acts somewhat in the same way a "fake" server would. So, when HiSuite asks the update server if there are any updates available for your phone, the update server will say "Nope, no new updates at the moment" - but my tool will intercept that and overwrite the response with a "Yep, here's the update" instead.
Hopefully that explains things
Not to shabby
Launcher.exe not working for me on Windows 7 Please help
Smaehtin said:
The way the FunkyHuawei and Firmware Finder method works is by you configuring your network to use their DNS server. A DNS server is what is used on the internet for "resolving" a domain name (like google.com, .xda-developers.com, hicloud.com, etc.) into an IP address. So, when a "client" (either your computer when using HiSuite to check for updates or your phone) asks for the IP address of query.hicloud.com (used for update checking), instead of giving you the IP address of Huawei's update server like a normal DNS server would, it gives you the IP address of FunkyHuawei/Firmware Finder's update server.
So now, whenever you do an update check, you're not talking with Huawei's update server but a "fake" server, but your phone/computer isn't aware of this (well ...), and when your phone/computer asks this server if updates are available and if your phone is allowed to install the update, the server will just say "Yeah, here's the update, go ahead and install it".
My method is similar in some ways. What it does is "hooking" the HiSuite process. This allows my tool to intercept and alter communication between HiSuite and Huawei's update server, and by spoofing some requests/responses, it acts somewhat in the same way a "fake" server would. So, when HiSuite asks the update server if there are any updates available for your phone, the update server will say "Nope, no new updates at the moment" - but my tool will intercept that and overwrite the response with a "Yep, here's the update" instead.
Hopefully that explains things
Click to expand...
Click to collapse
Thanks for this great explaination. I think i understood now. Why don't you include this in your initial posts? Its a nice learning for noobs like me. Just a suggestion. I feel there is very little *educating* material for Honor devices like the one you told about, or about rooting, or downgrading etc., at least for view 10. Unlike OnePlus devices. So I feel this might educate people who are just enthusiast, non technical and want to know few things.
Btw, the tool didn't work for my Indian model. Guess, because I am on EMUI 9.0 beta already. But thanks for the information
Shivang003 said:
Launcher.exe not working for me on Windows 7 Please help
Click to expand...
Click to collapse
Same for me, any solution for that please reply if any.
No luck. Tried 2-3 times, even made the changes to FF DNS so that firmware is approved but nothing on hisuite.
May be I am on EMUI 9.0 beta thats the reason its not showing anything but will eork for EMUI 8 users.
works great mate! thanks for your work and sharing!

HUAWEI MediaPad T3 10 and locked bootloader. Struggle in 2021.

Main objective: Find any way to enabling application transfer from internal storage to external storage.
The device has 16 GB of internal memory, which is definitely not enough to use additional applications. It looks like the option to transfer apps from internal storage to external storage for this particular model is forbidden. This situation makes it practically impossible to use this device any longer. I have tried many ways to resolve the problem. Unfortunately i failed. Therefore, I am asking for help from specialists from this forum if there is any way to make it possible way to do this taking into consider the inability to obtain the code from the site, which I am writing about below.
What i have tried already:
Enabling programmer mode and therefore changing the option that is blocking transfer to external storage. Unfortunately switching is not possible in this case. Enabling this option automatically forces return to the previous state.
Installing applications that are supposed to enable such transfer. Most of them are crap and scam.
Attempting to upgrade system with a built-in option and with Hi Suite. There is no option to upgrade firmware or downgrade by using this options.
Attempting to upgrade system with Firmware Finder for Huawei. I don't think I can get anything more than just downloading the firmware using this app. The idea was to force the installation of a newer version of the operating system by forcing some changes in the built-in updater.
Root and open firmware attempts:
At first, I was looking for a way to gain root access with the app available (kingRoot, KingoRoot etc.). Neither of them worked
I tried to install custom recovery. I turned on usb debugging, disabled the OEM lock and I was able to set the connection to the device.
When I tried to upload a custom recovery I got a message saying that this method is forbidden.
I was looking for information about the problem and so I found out that the botlooader is locked and that I need a special key to unlock him.
Next I found information that it is possible to obtain this key using paid applications and I'm skeptical about them.
Another option was to try to get this code from the manufacturer. It turned out that it was actually possible, but for some time Huawei as a manufacturer no longer provides these codes, which was confirmed to me by a person employed on the HelpDesk hotline.
Device information
Device nameHUAWEI MediaPad T3 10ModelAGS-L09S/NHEKNU19103105947Product ID89046711External SD card:64 GB
System information
Android System Version7.0EMUI version5.1.3Compilation:AGS-L09C100B279
Have you tried this steps - https://www.droidguides.com/unlock-bootloader-install-twrp-recovery-huawei-mediapad-t3-10/
Also trying this, Tempted to just throw the device out the window, think next time I will stick with Samsung.
Viro251 said:
Main objective: Find any way to enabling application transfer from internal storage to external storage.
The device has 16 GB of internal memory, which is definitely not enough to use additional applications. It looks like the option to transfer apps from internal storage to external storage for this particular model is forbidden. This situation makes it practically impossible to use this device any longer. I have tried many ways to resolve the problem. Unfortunately i failed. Therefore, I am asking for help from specialists from this forum if there is any way to make it possible way to do this taking into consider the inability to obtain the code from the site, which I am writing about below.
What i have tried already:
Enabling programmer mode and therefore changing the option that is blocking transfer to external storage. Unfortunately switching is not possible in this case. Enabling this option automatically forces return to the previous state.
Installing applications that are supposed to enable such transfer. Most of them are crap and scam.
Attempting to upgrade system with a built-in option and with Hi Suite. There is no option to upgrade firmware or downgrade by using this options.
Attempting to upgrade system with Firmware Finder for Huawei. I don't think I can get anything more than just downloading the firmware using this app. The idea was to force the installation of a newer version of the operating system by forcing some changes in the built-in updater.
Root and open firmware attempts:
At first, I was looking for a way to gain root access with the app available (kingRoot, KingoRoot etc.). Neither of them worked
I tried to install custom recovery. I turned on usb debugging, disabled the OEM lock and I was able to set the connection to the device.
When I tried to upload a custom recovery I got a message saying that this method is forbidden.
I was looking for information about the problem and so I found out that the botlooader is locked and that I need a special key to unlock him.
Next I found information that it is possible to obtain this key using paid applications and I'm skeptical about them.
Another option was to try to get this code from the manufacturer. It turned out that it was actually possible, but for some time Huawei as a manufacturer no longer provides these codes, which was confirmed to me by a person employed on the HelpDesk hotline.
Device information
Device nameHUAWEI MediaPad T3 10ModelAGS-L09S/NHEKNU19103105947Product ID89046711External SD card:64 GB
System information
Android System Version7.0EMUI version5.1.3Compilation:AGS-L09C100B279
Click to expand...
Click to collapse
Have you had any look so far?
Not possible without unlock the bootloader.
Im very angry with Huawei.
----Edit----
Unlock bootloader but pay 49$ with octoplus huawei tool, now tried install lineageOs
I unlocked for 4 Euro with HCU Client. I buy the credit on DC-Unlocker.
krisy0243 said:
I unlocked for 4 Euro with HCU Client. I buy the credit on DC-Unlocker.
Click to expand...
Click to collapse
Thanks for the tips I was able to unlock my AGS-W09 for 4 euro too (I would not have paid 40 euros for this device!).
I just lost several hours to understand and find the way to the "manufacter mode" on a tablet !
For those looking how to: launch the calc app and enter ()()2846579()()
an hidden menu will popup and you will be able to setup USB ports.
tuxfamily said:
Thanks for the tips I was able to unlock my AGS-W09 for 4 euro too (I would not have paid 40 euros for this device!).
I just lost several hours to understand and find the way to the "manufacter mode" on a tablet !
For those looking how to: launch the calc app and enter ()()2846579()()
an hidden menu will popup and you will be able to setup USB ports.
Click to expand...
Click to collapse
I launch the Calc app as you advised but nothing happened..! Pls help a brother..! How can I buy this 4euro bootloader tool..?
aobaro said:
I launch the Calc app as you advised but nothing happened..! Pls help a brother..! How can I buy this 4euro bootloader tool..?
Click to expand...
Click to collapse
Sorry, it wasn't mine, I don't have it anymore.
As I remember, It was the stock calc app, in landscape mode in order to have the "()" but that's all.
But the firmware is very important: it should be Android 7, and not the 8 (I don't remember the exact firmware version).
This said, I wasted my time rooting this tablet, it's pretty useless. Apart removing two stock apps and installing AdAway, I was not able to do much more. Unfortunately, there are no custom rom to give a new youth to device.
I got all the prerequisites, try to flash twrp in recovery but get the error: the partition table doesn't exist. Is there any solutions for this?

Categories

Resources