
Mobile Hacker
@androidmalware2 • 59,946 subscribers
Mobile Offensive Security 🔴 #redteam Android Reverse Engineering | malware analysis
Shorts
Videos

Public WiFi: Quick demo for 2 devices on the same network 1. SSLstrip + DNS change leads to user input interception for HTTPS with HSTS bypass 2. DNS spoofing redirects user to attacker controlled website More in upcoming "NetHunter Hacker XIII: Overall guide to MITM framework"
Mobile Hacker534,341 次观看 • 2 年前
1:02
Sensitive content
This media may contain sensitive content.

Bruteforcing PIN protection of popular app using $3 ATTINY85 #Arduino Testing all possible PIN combinations (10,000) would take less than 1,5 hours without getting account locked. It is possible coz, PIN is limited only to 4 digits, without biometrics authentication #rubberducky
Mobile Hacker355,982 次观看 • 2 年前

Guessing app's PIN using Flipper Zero as #BadUSB This "App Locker" app protects access to user selected apps - in this case, Instagram - using PIN code. It is possible to guess it with unlimited attempts, because the app developers haven't implemented brute-force protection and even timeout after few incorrect entered passwords. The app only allows to set 4 digit PIN. This allows us to try 10,000 PINs with unlimited attempts. After every try is 0.5 second delay. Because of that, it would take us 84 minutes to rotate through all the PIN combinations. ✅If you decide to use such an app lock protector, make sure not to use easy to guess and common passwords. If you are a developer, I advise you to implement a brute-force protection that includes timeout. #FlipperZero #Android #bruteforce
Mobile Hacker220,922 次观看 • 2 年前

New Pixnapping Attack: allows any Android app without permissions to leak info displayed by other apps exploiting Android APIs and a hardware side channel (CVE-2025-48561) Pixnapping is not fixed and probably affects all Androids. PoC: Not available yet. Steal 2FA codes 👇
Mobile Hacker54,963 次观看 • 7 个月前