Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Android Static Analysis test request #468

Closed
MrVaughan opened this issue Aug 14, 2017 · 2 comments
Closed

Android Static Analysis test request #468

MrVaughan opened this issue Aug 14, 2017 · 2 comments
Assignees
Labels
android sca Android Static Code Analysis related enhancement MobSF enhancements and feature requests

Comments

@MrVaughan
Copy link

Internal username and path disclosure:
I believe this also applies to iOS but apple strips this data out before it goes to iTunes.

If you run strings *|grep "/Users/" on any of the compiled library .so files you get the username of the developer who compiled the binary. You also get the folder structure/layout of the developers local machine. That is if they are running on a mac. Similar strings could be searched for windows/nix based.

Love the tool, thanks!

@ajinabraham ajinabraham self-assigned this Aug 17, 2017
@ajinabraham ajinabraham added the enhancement MobSF enhancements and feature requests label Aug 17, 2017
@ajinabraham
Copy link
Member

Good suggestion. Would be great if you can sent a PR, else we will track it as an enhancement.

@ajinabraham ajinabraham added the android sca Android Static Code Analysis related label Jan 16, 2018
@ajinabraham
Copy link
Member

tracked separately

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
android sca Android Static Code Analysis related enhancement MobSF enhancements and feature requests
Projects
None yet
Development

No branches or pull requests

2 participants