This app is the love of countless otaku, also known as the "gun artifact", its registered users have reached 80 million, but heard that they are very strict protection of the app, to prevent users from packaging two times. Now let's analyze How secure this app is .
First, we analyze the next two packaging protection, we first go online to find the app's installation package, unpacking-- > Pack-and-run. found that when we log in, we will be prompted that the signature information is inconsistent, resulting in the inability to log in. After analysis, he uploaded the apk signature information to the server and verified it, and then we needed to find him. Get a sign
Name information, such as:
ok, the way to get the signature information has been obtained, Now all we have to do is change his signature message to the signature string we got from the original package, such as:
In this step we can bypass his two-time package protection, can log in.
Second, for this social app, the user's account password is also very important, Let's analyze how to get the user's account password, such as:
You can get the user's account password easily and randomly. Speaking of the heart is a little excited, may wish to try. For reference only do not like to spray!
A small share of the security analysis report on social apps!