The core idea of permission string attacks is that A program A has A specific execution permission, and A program B does not have this permission. However, B can use the permissions of A to execute this permission. To put it bluntly, it is to use A knife to kill people.
There is A program here. There is A program here. A can receive all broadcasts.
A permission:
A core code:
Use the tool MercuryMercuryMercuryMercury MercuryMercury. First, install the tool on your mobile phone. First, install the tool on your mobile phone, first install agent.apk on your mobile phone:
Run the agent.apk tool and open it.
Connect in linux:
Because it is to find unfiltered Broadcast, execute broadcast and enter info to view all Broadcast
You can also see that the required permission is null. We can see from the source code that two parameters need to be passed
Therefore, two parameters are passed here:
At this time, the program will accept this parameter
Genius.png is displayed in the SDK root directory.
For any harm, please enjoy YY.