跳到主要內容

Pinduoduo拼多多

 Removed from Google Play



Nov 22 Project Zero:

researchers at Google’s Project Zero warned about active attacks on Samsung mobile phones which chained together three security vulnerabilities that Samsung patched in March 2021, and which would have allowed an app to add or read any files on the device.

Google said it believes the exploit chain for Samsung devices belonged to a “commercial surveillance vendor,” without elaborating further. The highly technical writeup also did not name the malicious app in question.

Feb 23 DarkNavy 深藍洞察

researchers at the Chinese security firm DarkNavy published a blog post purporting to show evidence that a major Chinese ecommerce company’s app was using this same three-exploit chain to read user data stored by other apps on the affected device, and to make its app nearly impossible to remove.

DarkNavy likewise did not name the app they said was responsible for the attacks. In fact, the researchers took care to redact the name of the app from multiple code screenshots published in their writeup. DarkNavy did not respond to requests for clarification.

“At present, a large number of end users have complained on multiple social platforms,” reads a translated version of the DarkNavy blog post. “The app has problems such as inexplicable installation, privacy leakage, and inability to uninstall.

最终,该互联网厂商通过上述一系列隐蔽的黑客技术手段,在其合法 App 的背后,达到了:

- 隐蔽安装,提升装机量

- 伪造提升 DAU/MAU

- 用户无法卸载

- 攻击竞争对手 App

- 窃取用户隐私数据

- 逃避隐私合规监管

等各种涉嫌违规违法目的。

Reference:

Krebsonsecurity

DarkNavy 微信 

Davincifans101

V2ex 

Landiannews 

VPNoverview

留言

這個網誌中的熱門文章

劣質洗衣機入水喉

上面白色是最易找到,$2x. 但漏水. 灰色, $4x, 是假冒 "MADE IN ITALY"  假冒 "MADE IN ITALY"  的標緻  左面是白色膠喉的喉頭, 右面是灰色膠喉的喉頭, 上圖左面是真正 好貨 ( MADE IN ITALY )灰色膠蓋.右面是冒牌 白色膠蓋. 膠蓋在安裝扭緊時爆開  上圖左面是真正 好貨 , 標了其他規格.右面是冒牌, 單單印了 MADE IN ITALY  好貨的膠蓋是可以下移, 露出喉頭及黑色軟膠墊 黑色軟膠墊是有坑紋. 質感較柔軟. 緊後可以"迫實"水龍頭 及喉蓋, 沒有滲漏 正板 MADE IN ITALY 賣 $4x, 價錢絕對合理. 冒牌貨在旺角新填地街買的, 也是$4x. 真是要小心!!! NB: MADE IN ITALY 是否真正 意大利制造實在無從考 証

ES8311 and ES8388 codec IC

ES8388 audio codec module is one of the audio codec modules available that is supported by ESP32 and official ESP-ADF releases. The ES8388 module lets you have: Stereo microphone and line input Stereo headphone and line out Up to 96 kHz 24 bpp high quality audio This module is compatible with all MCUs that have I2C and I2S ports (like ESP32, ESP8266, STM32, i.MX6, Raspberry Pi, etc) ES8311 Maxgerhardt github PCBartist twblogs ESP32-A1S  (limited stock)Audio codec AC101 or ES8388 built-in. NB the pinouts and firmware are different! Arduino - ESP31-A1S instructable Phil Schatzmann and his github   Simple A2DP thaaraak github on ESP32-A1S github of Yveaux and  Marcel-licence ESP ADF   example:  Logitech PiCorePlayer squeeze lite squeezebox forum   ESP32-Audio-kit  (from AI thinker) based on ESP32-A1S, is simple and small. But upgrade-ability seems limited  Alex John Talbert mixer equalizer: can this be used as simple equalizer? how about proces...

sharpstar 150mm f/2.8 hyperbolic astrograph

to be launched in summer, 2019. spot diagram is now available, and connections diagram to camera is shown . list price RMB 13,000 ( USD 1900 approx) comparing this with Takahashi epsilon-180ED: spot diagram: connections: the focuser is 2.5 inch, and threads are M48 x 0.75mm   cloudynights first impression threads   some nice photo review from skypoint   Astrofotoblog review  c