[VULNERABILITY] Remote wipe via iframe USSD trigger - Galaxy Tab 7.7 General

Something to acquaint one with..
link

Related

[Q] Flash Global Security Settings

Hello,
I'm trying to make an application that uses a webview to load a page containing a swf which should be populate with data loaded from a localfile.
The main idea, is that if I want to open that html from my computer directly, I should go to :
http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager04.html
... and add the swf as a trusted file. If I copy the files inside tomcat, and start the tomcat, I can view thee swf with all data loaded
Now, in android I can't open that page to change the Global Security Settings, so I can't load the data. Do you have any idea how to do this? Or a workaround to this?
Ok, I see that no one has any idea.. But what about creating a tiny web server that returns that page? I think it should do the trick, but I can't find any tutorial about creating web servers in Android.. basically I need to open a port and return the html from @assets relative to what's after localhost : port. Do you know, or have a sample that I could use it as an example?

Vocera Application on CM10 or AOSP ROMs

I am required to use an application for hospital communication - it is a messaging app that takes the place of pagers. It is called Vocera -- it is available on the Playstore.
The problem that I'm having is that the app installs fine on both Sammy based and CM10 or AOSP ROMs but then you have to enter a server ip address and a registration key. The keys are one time use apparently so every time I try a new install our Sys Admin gets frustrated (they don;t care for rooted devices anyway).
On the CM10 or AOSP based ROMs the IP address for the server and Registration key seem to be accepted but don't "take" in that after they are entered and I press OK then the screen flashes and goes right back to the Registration page.
I have attached the log that was recorded during install of Vocera or VMP app and then the subsequent entry of the Registration.
Can anyone help with troubleshooting this app for use on AOSP based ROM's (or point me in the right direction)??
Also the other interesting thing is that if I do a Titanium Backup of the app then restore to a different ROM it doesn't maintain the Registration information -- I have to get a new key from the Sys Admin and re register the device. Does anyone know how to copy that registration information? Is there a hidden registry for Android OS's?
I have attached log and the files that are in the Titanium Backup folder for this app

N910C - broken fingerprint sensor, backup password not working, don't want wipe...

Hello,
N910C, COJ5, noroot. Suddenly my phone stopped to use fingerprint sensor and backup password I am providing is not being acceptable.
Short list:
- notifications, network, sms and incoming calls are working, BUT nothing else
- after restarts, removing battery, tries to use ODIN(3.07 & 3.10) or TWRP or kernel with permissive - not working (blocked by R/L) - I wanted to use root privileges to remove files in /data/system responsible for fingerprints and backup password.
- ADB is working
- I want to recover data before wipe - some free soft like Android Recovery Tool or sthg like this ?
Any ideas?
Thanks in advance!
--
Szymon
I see three ways:
-Try to unlock with the fingerprint, it will give you the option to enter a secondary password. Put a random pass 5 times until the device blocks you to keep entering wrong passwords. After that, a new button saying "Unlock with your google account" should appear. Touch it, put your email and password and wait for a couple of seconds. The device will unlock and will set the lockscreen to "Swipe".
-If that doesn't work (rare), try this, it shoud work: http://forum.xda-developers.com/not...ass-lock-screen-pattern-password-pin-t2948336 (since your device is locked you can't access to the MTP functions. You have to put the zip file in a external sd card and flash it with TWRP.
-If that doesn't work either (dafuq?), make a data backup in TWRP ("Backup" option, then select data only), wipe your device, flash a rom and then flash the backup again.
Also remember: "Wipe data" option in TWRP erases all ylur apps and configs, but your pesonal info like photos, documents, downloads, etc will still be at there.
galaxynote2 said:
I see three ways:
[...]
Click to expand...
Click to collapse
I see that you did not read my post
All of these 3 options you mentioned are not possible.
Any other ideas?
I just copied via adb in shell all important files from internal memory and now after I wiped it out I got strange info that "This device is locked because of an abnormal factory reset"
I am not using Find My Mobile Samsung service so WTF ?! Why is it asking me for something that I am not using and it will be not working ???
Regards,
add-on: there was a Find My Mobile by Samsung block, but I used some mystery account I forgot about Now everything is up and running

How to enter the ServiceMode in T585C?

Hi,
I have a T585C with Android 6.0.1 (version=T585CZCU2AQH2). It seems the well known secret code (e.g. *#...) doesn't work anymore on it. I can enter the Service Mode using Shortcut Master. But I prefer to not using any third-party tools. Anyone who can help me?
Another question is: is there a way to reset all settings in Service Mode? The "NV Rebuild" function seems to have no effect... I did some changes previously. But I'm not sure if they have been all set back to their original values...
Thanks!
regarding the reset settings. I found a simple way that just use the nv_data backup file to replace the current used one in /efs partition.
but still have no idea how to enter the service mode via a graceful way...

Xtrons Android 8.1 HU - Remote Access Via AnyDesk?

Hello - I have a very specific remote access requirement, however I’m a total novice with regards to Android. I wanted to provide the instructions I have been given to see if anyone in the know could simply summarise or advice how I can achieve this please?
I need remote access of my Android 8.1 Xtrons HU however am finding that all Android Apps fail to allow ‘clicking’ when accessing the device remotely (ie. TeamViewer/ VNC install and allow a connection, however ‘clicking’ can not be done remotely). I believe this could be a security and/or accessibility issue/function, however the closest solution I have found has been advised by both the App publisher and the Xtrons support team below.
Although technical, I don’t know what the exact steps are, or if this approach will even work, however I wanted to post it here to see if anyone could make sense of it please?
Advise from Xtrons (HU Manufactuer):
"After entering "adbon "in the factory set and opening ADB ,you can apply on the machine by yourself directly."
Advice from AnyDesk Development Team:
"For the manufacturer of the Android's ROM there is a process to get the APK signed, so that remote control for that ROM is possible.
This is our Control Plugin Creation Process:
1. Run AnyDesk on the destination device and send the trace file to [email protected]<mailto:[email protected]> or as reply to this mail.
- Open Anydesk on Android
- Open the menu
- Open about panel
- Click on: Send Support Information
2. Please tell us the name you would like for your plugin and whether you want it to be available in the app store.
3. We can extract the system signature hash from the trace files and will build a plugin for this system.
4. We will send you this plugin APK file.
5. You have to sign the plugin with the platform key of your ROM.
apksigner sign --ks YOUR_PLATFORM_KEY_STORE --out YOUR_ANYDESK_PLUGIN-signed.apk YOUR_ANYDESK_PLUGIN-unsigned.apk
6. Send us the signed plugin back.
7. If possible provide us with one of your devices for testing.
8. We will send you the updated anydesk.apk for testing, you will have to install the updated anydesk.apk as well as the signed plugin manually on the test device.
9. After your ok we will publish it with our next android release.
10. Once the plugin and the updated AnyDesk app are released, your devices can be remote-controlled by AnyDesk."

Categories

Resources