Video wird geladen...
Video konnte nicht geladen werden
Exfiltrate #WhatsApp chat, or internal data of any Android app, running on Android 12 or 13 by exploiting CVE-2024-0044 vulnerability
143,647 Aufrufe • vor 2 Jahren •via X (Twitter)
10 Kommentare

PoC for CVE-2024-0044 #Android

So basically run-as victim and the data is decrypted? I thought WhatsApp chats are encrypted on the device?

It's are not encrypted. Many apps doesn't encrypt data in internal storage. One time I have seen even credentials in clear text for popular cryptocurrency exchange - intended behavior. I understand that, since each app is sandboxed, but with similar exploits this can be an issue.

What cryptography used to encrypted data on WhatsApp apps ?

Using adb to open an package then copy it's internal storage as shell is a very old concept but I didn't think it was still not patched 😳

Why not just open the internal storage on the PC and copy the whatapp directory that exists Andriod directory ?

This is possible only if the targeted device is already rooted. If the device is not rooted, then you can't access internal data of any app.

@TweetHelperBot Please download this

How we enable usb debugging if we have to do forensic on a stolen device ?

To approve usb debug tool we need to "accept" access via touch;) If the the screen is blocked...
Ähnliche Videos
Sensitive content
Here’s a very bad video of it running on Android 😅 I think it should be playable without any major problems.
Vyns 🍑
222,583 Aufrufe • vor 3 Monaten

