Other nomination
Android Exploit to RCE: $5000 Bounty
Frida hooks on Conscrypt's checkTrustedRecursive and on Java's Cipher strip TLS pinning and a second app-layer AES whose key exchange rides in an X-Cookie header (seed, key length, two IVs, HMAC). The decrypted body reads wgt:[FILE_PATH]:FUNC(ARGS), which a server-side headless browser opens and executes, so appended JavaScript runs on the server. With no outbound HTTP, the payload builds a hostname from location.pathname and exfiltrates over DNS.
Record
- Researcher
- Yashar Shahinzadeh
- Published by
- Voorivex Team
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Yashar Shahinzadeh, first published at the original source. Preserved copies are kept so the citation survives its host.