Soroush Messenger Information Leak Exploit

2018.04.12
ir GIST (IR) ir
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

############################################### # Title : Soroush Messenger Information Leak Exploit # Date : 10 April 2018 # Vendor : https://soroush-app.ir/ # Software : https://android.sapp.ir/ # Author : GIST # Tested on : Android 4.4.2 # Exploit Type : Local # Version : All Versions # Youtube : https://youtu.be/Sl2v4Dh_9r0 ########################################### Description : Soroush Is a Most popular Messanger in iran With 3 mil User In Iran. There Is a problem in this messenger and that is The Sources not encrypted. Also When we send an messsege to the other contacts his phone numbers will save in Local database. We Can View The Sources Just With Installing The CheatDroid and allow the premission. You Can See The Details of the Exploit in youtube Youtube : https://youtu.be/Sl2v4Dh_9r0 Informations : File name : ott.db Database Name : members Strings Leaked : member_nick_name , member_avatar_url , members_avatar_thumbnail_url , members_user_id , members_soroush_id ,members_standars_phone_numb , members_standars_phone_number , members_last_online and ...

References:

https://youtu.be/Sl2v4Dh_9r0


Vote for this issue:
42%
58%

Comment it here.
Unknwon | Date: 2018-04-13 04:55 CET+1
Zhmat Kshede😂 pub hast
Mr.Yavar | Date: 2018-04-13 07:29 CET+1
eshgham! in bug rafe shode
Submiter | Date: 2018-04-13 22:15 CET+1
video ro bebin.bug hast.hodude 12 13 roz pish find shode alan submit shode.

Copyright 2025, cxsecurity.com

 

Back to Top