Device fingerprint modifyable? - HD2 Android Q&A, Help & Troubleshooting and Genera

In my quest to understand why a few games that auto-identify your phone don't work, I've run across a couple potential options. Can games read imei numbers? If so, does every hd2 android build report the same imei?
Another likely culprit is the "device fingerprint." You can view it in the system panel application. Mine shows up as a directory on my phone... is there a way to modify one's device fingerprint? Surely it coould be added into the startup options in startup.txt...
Sent from my Htcclay's SuperHD2 using XDA App

Related

Close the Security issue of wiping Data through the Browser with NoTelURL

As some of you might have heard, there is a security issue on some Android phones (including the SII) that enables someone to create a link which will wipe the data of your device when you click on that link from an Android device like the SII.
I have discovered a very cool App that prevents that from happening. All this App does is to recognize everytime you click on a link which wants to execute some code on your device through the dialer.
It then automatically tells you if it`s a dangerous code and if it`s harmful for your device. If it`s a normal phone number then you can dial it straight from the App.
Simple but very effective App that closes the security issue until Google/Samsung etc. decide to do something about it.
Here`s the link for the App:
https://play.google.com/store/apps/details?id=com.voss.notelurl
I haven`t developed this App so all credit goes to the Developer: Joerg Voss
Thank you so much for this info. Even though I'm using Firefox as my basic android browser. I have to use android's native one from time to time. Now can do that we less worries :good:

Writing an app that interacts with another app

I want to write an app that will run in the background while I run another app. Mine would look at the screen of the other app, do some computations, and either highlight certain elements, or automatically click certain elements based on those computations.
I realize this would probably require root, correct?
I am a developer, but don't have as much Android dev experience. The parts I'm wondering about are:
- How to write an app that runs in the background of another app, but can detect its screen output and overlay on top of it.
- How to generate screen touch events for the other app.
Thanks for any tips to point me in the right direction!
Sent from my SGH-T999 using xda app-developers app

[Q] Possible to lock phone in case of theft?

My Galaxy 1 was stolen from me in Feb, after that i went through a lent s3 and now proud owner of an s4 (i9500).
So i have two questions on this:
1) is there an equivalent for what a bios password is in a PC?
(have to go short something in hardware to bypass, only is asked upon powerup/hard reboot).
2) Is is technically possible for an app to lock on custom sim? (possibly modifying efs folder)
Thanks!
Abrojo said:
My Galaxy 1 was stolen from me in Feb, after that i went through a lent s3 and now proud owner of an s4 (i9500).
So i have two questions on this:
1) is there an equivalent for what a bios password is in a PC?
(have to go short something in hardware to bypass, only is asked upon powerup/hard reboot).
2) Is is technically possible for an app to lock on custom sim? (possibly modifying efs folder)
Thanks!
Click to expand...
Click to collapse
http://bit.ly/174zPh6
LeJolly said:
http://bit.ly/174zPh6
Click to expand...
Click to collapse
Thank you for patronizing me but that didnt answer my question, already been through pages of results when i previous galaxy was stolen (even tried locking from google play). None of the apps listed on a google search for locking and tracking do what i ask.
Centralized cloud based locking doesnt work (a blacklisted imei can get reinstated fairly easy), neither does the standard password Operating System level password.
Thats why i am asking for specific alternative ways of locking the phone that should be (if possible) more tampering resistant.
1) bios equivalent password.(requiering hardware shorting to bypass)
2) custom simlock
I use avast! free mobile security (https://play.google.com/store/apps/details?id=com.avast.android.mobilesecurity&hl=en),
the anti-theft module has option to block the phone if the sim card is changed
LeJolly said:
http://bit.ly/174zPh6
Click to expand...
Click to collapse
What a woeful answer. Try reading before you be a ****.
In answer, no there is nothing similar to a BIOS lock on Android phones, however like mist813 said, Avast is quite good. If you have root access you can install it as a system apk then even if the thief wipes your phone, it's still there.
You could also try lookout its free. Can do tracking, remote wipe and also takes a photo of anyone trying to unlock your phone.
I don't think there is anything that can prevent someone from just flashing a new firmware and wiping the phone completely.
Sent from my Nexus 10 using Tapatalk 2
I don't think there is an equivalent to BIOS lock in Android. I'm not sure if you tried Lookout or the native Samsung remote control under security settings. Both gives you the options to locate, lock, scream or wipe your data. I tried the locate and scream options and they work. Never tried lock or wipe, but they should also work! Now going to the fact of wether someone can bypass or overcome these security measures, then I personally think it's possible and whatever we do he can find a way to go around it depending on how smart and resourceful he is! If my phone is stolen, frankly speaking I won't waste my time trying to find it or just lock it. All what I'll care about is to wipe the data off, and hopefully these softwares will work if needed!
Sent from my SGS IV using Tapatalk 2
Abrojo said:
Thank you for patronizing me but that didnt answer my question, already been through pages of results when i previous galaxy was stolen (even tried locking from google play). None of the apps listed on a google search for locking and tracking do what i ask.
Centralized cloud based locking doesnt work (a blacklisted imei can get reinstated fairly easy), neither does the standard password Operating System level password.
Thats why i am asking for specific alternative ways of locking the phone that should be (if possible) more tampering resistant.
1) bios equivalent password.(requiering hardware shorting to bypass)
2) custom simlock
Click to expand...
Click to collapse
Okay lets not be a **** this time.
1) There's nothing equivalent to that bios thing
2) http://stackoverflow.com/questions/...-the-device-on-removal-of-sim-card-or-sd-card
There are also apps that just notify you if sim card is changed for example this https://play.google.com/store/apps/details?id=instigate.simCardChangeNotifier&hl=fi
And of course there are some apps that let you remotely control your phone for example http://forum.xda-developers.com/showthread.php?p=7567932
Abrojo,
You don't really need a third-party app for this.
Please check out the Samsung Dive service. (www.samsungdive.com)
You can track your phone, lock it with a custom password, sound an alarm, etc...
The problem is, the phone needs to have Internet access.
I am using the Cerberus app (https://play.google.com/store/apps/details?id=com.lsdroid.cerberus&hl=en)
This is the best rated Anti-theft app you can find for your Android.
a license costs 3USD if I remember correctly. With one license you can secure up to five Android phones.
Featuers:
Track your phone
Remote lock
Remote wipe
And a lot more options...
A couple of things that I think are extremely useful:
When a wrong password or pattern is drawn to unlock your phone, a picture is taken with the front camera and emailed to you together with the location of the phone.
When the SIM is swapped, you can configure up to three phone numbers that will receive an SMS with the new SIM card number and the location of the phone.
You can hide the app from the App Drawer.
Check it out... very useful
i use also cerberusapp 4 years now. everything is perfect. when u install as system app u can do everything.
Sent from my ThL W8 using xda premium
Apparently there is also rumors of LoJack already being built into these phones, with the possibility to activate it some time in the near future. Don't remember all the details, but I just read an article about that. Not being patronizing when I say it, but Google Galaxy S4 LoJack and look into it.
Also, I am on Verizon, and am testing out their mobile security app that is preinstalled. It's $1 a month, but they allow you to remotely lock your phone, wipe it, and track it should you lose it. I don't believe it embedded at the hardware level, but it is something that gives me a little piece of mind.
Edit: I went to switch to the Norton Mobile Security app, since I use it for all of my other devices, and discovered that the Verizon Mobile Security App - once activated - cannot be uninstalled, force stopped, you cannot clear the data, and you cannot disable it. In order to do so, I first have to go into my Verizon account online, sign in, and unsubscribe from the service. After realizing that, I have chosen to keep the Verizon security app, because it has that extra layer of security. Are there ways of bypassing that, I'm sure there are. But assuming that my phone is stolen by some low level thief and not some crazy high level criminal circuit, I should have no problem retrieving it.
Samsung Dive down?
I cant seem to have this page load up www.samsungdive.com
Is it down for you too?
Sm007hCriminal said:
I cant seem to have this page load up www.samsungdive.com
Is it down for you too?
Click to expand...
Click to collapse
It's working with me.
Sent from my SGS IV using Tapatalk 2

[Q] Popup Ads in Lock Screen

Recently I've been getting ads popping up on my lock screen. Sometimes the popup may be up when I swipe out of lock and onto the home screen. I have downloaded some security programs, AD push apps, but none of them are able to detect which app is doing this.
Has anyone else had this issue?
Paperinik68 said:
Recently I've been getting ads popping up on my lock screen. Sometimes the popup may be up when I swipe out of lock and onto the home screen. I have downloaded some security programs, AD push apps, but none of them are able to detect which app is doing this.
Has anyone else had this issue?
Click to expand...
Click to collapse
Are you using a replacement lock screen or the default one? If you can't narrow it down to be from a user based app you installed, I would full wipe immediately. You seemed to have done good troubleshooting with scanning with an antivirus(i prefer Eset) and using an ad push detector.
Do the security scanners get root rights?
ICS (and beyond) needed "tagged socket" support from the kernel so that the Android UI can tell you how much data had been used on an app-by-app basis (and probably also increase the granularity of Google spy-ware), so I have to imagine that it is possible to somehow figure that out. But this is sort of low-level stuff - not sure if there is a root app that will do this for you.
You sort of need some combination of "lsof" and "tcpdump". Maybe a tcpdump that is socket-tag aware. (I recently built an ARM version of tcpdump, but I haven't spent much time with it - don't know if that capability is in there.). In this scenario you would run a command-line tool via adb with the screen locked. Or maybe there is a way to dump android's "per-app data usage monitor" rapidly - review of time-stamped data might show you who the villain app is.
Are you sure it's not just the browser? (e.g. if you kill all tabs in you browser, does it still happen?)
Use "Norton Spot". Great app that tells you who is doing what.
Sent from my Galaxy Note III; Previous owner/hacker of Galaxy S III, Galaxy Nexus, Droid X, HTC HD2, HTC Touch Pro 2, HTC Tilt, HTC 8525, O2 XDA II, O2 XDA.

Apk copy/extracting/backing up protection

I hope that this is not the wrong place for my post.
I am trying to protect an apk from being copied/extracted/backed up off the phone and installed later, on another phone.
I have to mention that the app is not (and will not be) for sale on PlayStore or on any web store, being sold along with the phone. This is why I can not use apk protection offered by GooglePlay, which is anyway cracked at his time.
But I want to take advantages on this situation: every single phone will pass trough my hands (I will install myself the app) before hitting users. How can I use this advantage in order to protect my app?
At this time my app is not visible in Running Apps drawer, is having a default Android icon and the name is disguised in something pretty innocent. GUI access by dialing a code. No worries, is not malware but only a security app regarding GSM connection security.
Also, is running as a system app, which make it invisible for apps like Astro file manager, thus impossible to copy/back up by such file manager apps. Unfortunately there are a bunch of system app managers, that can convert a system app on user app, and then copying the apk file is easy.
I know that security sucks big time when it comes about Android OS, but I am determined to find a way to protect my app.
I know also that even a licensing scheme based on IMEI, WiFi MAC or Bluetooth MAC addresses can be bypassed by some skilled crackers. This values can be spoofed or even null.
I have tried apk encryption. Doesn't work: some apps supposed to encrypt other Android apps are actually encrypting only app libraries, not the apk file itself. By encrypting apk file, the app obviously will not work.
Code obfuscation is not an option as long the app can be duplicated off the phone and installed later on another phone.
The last idea that I had: pulling some app resources (like drawables) from a server. What do you think?
At this time I'm in a dead end. I have no more ideas how to protect my app. That's why I need your help. Can you give me please some feasible ideas, based on your huge experience?
Thank you very much for your time.
theres a thread
http://forum.xda-developers.com/showthread.php?t=2279813
where we're discussing about methods to protect apps from piracy u can post it there
Sent from my GT-S5302 using Tapatalk 2
Thanks
Thx a lot sak-venom1997.

Categories

Resources