"spy"-app without encryption - General Questions and Answers

Hi guys,
i'm currently preparing a presentation for university (about mobile device security).
I would like to demonstrate how an app sends collected data (contacts, browser history, ...) to an remote server.
Like the Barcode Scanner.
Seeing the transmitted data (man in the middle) just works.
But my main problem is to find an app which sends the data not encrypted.
Do you know any?
I am not able to and do not want to spend a lot of time on decrypting the encryption.
Hope you can help.
thx! :good:
edit:
i am not talking about apps like mspy.
the app should seem to be usefull.
the mobile os should be android.

leAndroid91 said:
Hi guys,
i'm currently preparing a presentation for university (about mobile device security).
I would like to demonstrate how an app sends collected data (contacts, browser history, ...) to an remote server.
Like the Barcode Scanner.
Seeing the transmitted data (man in the middle) just works.
But my main problem is to find an app which sends the data not encrypted.
Do you know any?
I am not able to and do not want to spend a lot of time on decrypting the encryption.
Hope you can help.
thx! :good:
Click to expand...
Click to collapse
Good luck. No real Developer would send any info un-encrypted.

zelendel said:
Good luck. No real Developer would send any info un-encrypted.
Click to expand...
Click to collapse
yeah. i know that.
but i also guess that there are "crap-apps" in the market, probably with no or very weak enrcryption

leAndroid91 said:
yeah. i know that.
but i also guess that there are "crap-apps" in the market, probably with no or very weak enrcryption
Click to expand...
Click to collapse
Maybe but you will be hard pressed to find one that passes Googles requirments. If I remember right when I looked into building an app for sending data the SDK sets up the encryption for you so it is done for you to prevent info hi-jacking.

yep. looks like i have to write my own one

Related

intercept text messages? or sniff packets sent by phones?

Is there a app that sniff packets sent by cell phones, my whole goal would be to intercept text messages or the data thats sent by cell phones. I came up with this idea when I was messing around with packet sniffer and thought about the idea but on cell phones. Is there something already out like this?
Wireshark at a "router"
While not an on-device solution, I use this setup when I want to watch the traffic between my phone and the network:
"sorry, apparently I can't post a link to this forum, it's at my site droidhacks.com, click on the wireshark tag in the sidebar and you'll find the post"
Having a full Wireshark install running on the desktop is great for poking through the data. I think some folks do the capture on the device and then just move the capture file across. Also helps sometimes to pull the SIM to make sure all the traffic goes through the laptop and not through the network. Sharing on OS X with an handset can be a bit fidgety when first starting up.
Find shark for android and sharkreader. Both of which can be found in this forum.
Sent from my Nexus One using XDA App
can this be countermanded? stoped, disabled somehow? encrypted packets? someone's safety could be at risk.
Are you looking to capture the communications of other phones, rather than your own? If so, good luck, it's encrypted traffic.
Sounds pretty stupid and no, it is not possible. I would rather want a network sniffer for android. Connect to your local coffee shop network and start sniffing.
rTiGd2 said:
Are you looking to capture the communications of other phones, rather than your own? If so, good luck, it's encrypted traffic.
Click to expand...
Click to collapse
no, i'm just curious how this can be done.
if its encrypted how can you read the packets with your program then ?
some kind of id or serial number?
tmpmailone said:
no, i'm just curious how this can be done.
if its encrypted how can you read the packets with your program then ?
some kind of id or serial number?
Click to expand...
Click to collapse
Ok, I think we need a rather large dose of reality here. You'll not manage it, simple as that, certainly not from a consumer device. I suspect you are thinking along the line of WiFi wireless, where you can monitor what other devices are sending. If you really wish to know more then google 'usrp' and you'll soon see you'll need far more hardware and software to start capturing GSM traffic.
ok so you're saying with my router i can't capture my text messages, like those sent and received with the YMesenger app ?
so its possible to sniff datalines?
tmpmailone said:
ok so you're saying with my router i can't capture my text messages, like those sent and received with the YMesenger app ?
so its possible to sniff datalines?
Click to expand...
Click to collapse
Yes, it's possibly to sniff datalines, as well as WiFi.
I think you should break out with you gf
this thread is too funny ( lol )
encryption - lol
cant sniff - lmao!!
link1
I am a network security specialist and you people are just too funny saying "cant" "impossible" "illegal" .. .. ..
morning_wood said:
link1
Click to expand...
Click to collapse
Nice info.
Packet sniffing over public wifi is well known, but I learnt something new today
Chris Paget hapens to be a personal friend of mine
I'm pretty sure intercepting phone calls would still be "illegal", regardless of the fact that you're a network security specialist.
But yes, nothing is impossible, that's pretty much a given. Give someone enough expertise and resources, anything can be hacked. Encryption is actually important, so the general, uninformed riff-raff can't access anything they want. Like my previous statement, it can still be hacked, but it's better that not being encrypted at all.
morning_wood said:
this thread is too funny ( lol )
encryption - lol
cant sniff - lmao!!
link1
I am a network security specialist and you people are just too funny saying "cant" "impossible" "illegal" .. .. ..
Click to expand...
Click to collapse
So, my ex husband is using a packet sniffer to read all of my info that I txt over my phone. He is living with me until he closes on his new house (30 days out). I have installed a VPN on my phone. What else do I need to do? He says he can see all messages that I send, both txt and messenger as well as my calls?? He is a programmer, so I know he knows what he’s doing, how can I get my privacy back? I’m afraid that he will always be spying on me and it’s very frustrating.
Sunshine08 said:
So, my ex husband is using a packet sniffer to read all of my info that I txt over my phone. He is living with me until he closes on his new house (30 days out). I have installed a VPN on my phone. What else do I need to do? He says he can see all messages that I send, both txt and messenger as well as my calls?? He is a programmer, so I know he knows what he’s doing, how can I get my privacy back? I’m afraid that he will always be spying on me and it’s very frustrating.
Click to expand...
Click to collapse
Do you use Google Messages app for text messages? If so check if it is connected to Messages for web. Also if you use Whatsapp check if it is connected to Whatsapp web. I recommend to change password for all the services, Google, Facebook and so on and reset the phone to factory defaults. I don't think this has anything to do with packet sniffing.

[App] RemotifyMyDroid (my 3rd FREE app)

Hello Everyone,
i've finish working on my application RemotifyMyDroid, and uploaded it to the market place toy can download:
https://market.android.com/details?id=com.yazan.remotifyMyDroid&feature=more_from_developer
it sends notifications to your PC, when you got event on your mobile,
best case when you are charging your mobile in a room, and setting in another..
however you can use it in different purposes ...
the phone and the PC should be on the same LAN,
in future i may upgrade it to work over the internet ...
it notifies for those events:
1- Incoming Call (shows the caller number to)
2- Outgoing Call (someone using your mobile to call a number)
3- Your mobile is fully charged (in case you were charging it)
4- Someone unplugged the power of the charger.
5- New Incoming SMS.
to download the PC server
http://www.yazandroid.com/
and go to RemotifyMyDroid (1st link) and it contains some screen shots to.
also have a look at my other FREE 2 applications there
your feedback is appreciated
Yazan.
Sounds great, but I think setting this up might be a tad harsh for general use (firewalls etc). I would suggest building an intermediary platform (web service) to communicate to. That way you can have a very easy setup. For instance, you can use the Google login service to identify yourself from the phone and the notification program and that's it then. No IP's or port numbers as most users don't know what that is anyway.
But for the techies, good start.
Cheers
bra1nDeaD said:
Sounds great, but I think setting this up might be a tad harsh for general use (firewalls etc). I would suggest building an intermediary platform (web service) to communicate to. That way you can have a very easy setup. For instance, you can use the Google login service to identify yourself from the phone and the notification program and that's it then. No IP's or port numbers as most users don't know what that is anyway.
But for the techies, good start.
Cheers
Click to expand...
Click to collapse
good point, and that what i was afraid about in the first place
i am planning to take this to the internet as a next step, i will be doing that soon
thanks bra1nDeaD
stinger1 said:
good point, and that what i was afraid about in the first place
i am planning to take this to the internet as a next step, i will be doing that soon
thanks bra1nDeaD
Click to expand...
Click to collapse
No problem
Portal pending. Nice app
I will use this when it's possible to use it via the web. Maybe a Chrome/FireFox/IE plugin would be cool?
Really nice idea!
Another suggestion : an honeycomb client
let us be notified about our phone when it's away and we're using our favorite tablet
I'm sorry to have to say this, but I think you may have wasted your time:
http://code.google.com/p/android-notifier/
Timmmmmm said:
I'm sorry to have to say this, but I think you may have wasted your time:
[Link]
Click to expand...
Click to collapse
What a great find... The integration with Growl will be excellent on my HTPC. Also, this allows easy integration with EventGhost through Scripty.
just installed. works fine.
Any chance on a open source version, i would like to see how you did this. an maybe use some of the code in a Domotica project of mine.
Hey another MightyText. At least I can use this one lol.\
Timmmmmm said:
I'm sorry to have to say this, but I think you may have wasted your time:
http://code.google.com/p/android-notifier/
Click to expand...
Click to collapse
Have you ever heard of...dare I say it...variation of ideas? Just because there is something similar out there, does not mean it is identical. Please do not spam dev's threads with others work.
he's right though, there is google voice add on for chrome that does this, mighty text, and that last one he mentioned.
Timmmmmm I'm sorry to have to say this, but I think you may have wasted your time:
http://code.google.com/p/android-notifier/
Click to expand...
Click to collapse
its not a waste of time, and for sure i have learned couple of things while developing this app, its not a waste at all.
otherwise you will see a single app for each purpose ... on pc\mobile ...
one more thing .. why do you think there is Windows , Linux and Mac??
could not other parties just SAVE there time and NOT develop another OS!!!!
Any chance on a open source version, i would like to see how you did this. an maybe use some of the code in a Domotica project of mine.
Click to expand...
Click to collapse
for now i am not planning to open source any of my work,
sorry
Really nice idea!
Another suggestion : an honeycomb client
let us be notified about our phone when it's away and we're using our favorite tablet
Click to expand...
Click to collapse
this was on the list next
with this to
I will use this when it's possible to use it via the web. Maybe a Chrome/FireFox/IE plugin would be cool?
Click to expand...
Click to collapse
still thinking which one will go first,
thanks all
Hey, didn't try it yet but I have some suggestions, in addition to a web service:
reply to sms / transfer calls to PC
low battery event
as an option, deliver every notification from notification bar (alarms, songs played, ebay auctions ending, FB msgs, etc.)
cheers
Mac version would be awesome .
Hey, didn't try it yet but I have some suggestions, in addition to a web service:
reply to sms / transfer calls to PC
low battery event
as an option, deliver every notification from notification bar (alarms, songs played, ebay auctions ending, FB msgs, etc.)
cheers
Click to expand...
Click to collapse
hey lastnikita, thx for suggestions,
i will be working on such updates,
but regarding the call forwarding to PC as far as i know you can't do it as the call is protected by the OS. it has limitations...
Mac version would be awesome .
Click to expand...
Click to collapse
hey Bomster,
there is a MAC version...
not tested yet, i don't have a MAC, please if you try and send us a feed back, that will be great
cheers
thanks,
stinger1 said:
but regarding the call forwarding to PC as far as i know you can't do it as the call is protected by the OS. it has limitations...
Click to expand...
Click to collapse
Using bluetooth maybe ? PC as a handset (would have to be paired before)
I understand then distance range would come as a limit for many use cases, but could still be enjoyable instead of standing up to pick up the phone !
lastnikita said:
Using bluetooth maybe ? PC as a handset (would have to be paired before)
I understand then distance range would come as a limit for many use cases, but could still be enjoyable instead of standing up to pick up the phone !
Click to expand...
Click to collapse
that looks fine
now we have along list to start with lol
cheers

[App request] systemwide data corruption app (security)

Hi guys,
I'm only asking for this app due to a massive security breach of my emails and Facebook account after my phone got stolen at a cinema. The app requested is a security app which the person can set the app to have 3 people's handphone numbers which they would receive a specific code and instruction (e.g. 123456destroy) which would corrupt all data inside the phone and trigger a hard brick. The app should be factory reset proof
Sorry if I sound a bit too demanding but I'm still very worked up.........yep.
there r anti-theft apps with data wipe option, isn't that enough?
Sent from my GT-I9000 using XDA
Look man
They stole my phone
I'm gonna give them sh*t
The system corruption prevents them from selling it.
I'm sorry for your loss.
And what would happen if someone you sent the code to activated it for a really **** joke? Personally, I think it'd be better if you could activate the app when you download/install it then brick the device via a website yourself to save complications.
Sorry to hear you lost your phone though
Sent from my GT-I9100
no the whole point is that you don't tell anyone except yourself the code until you lose your phone
here are programs/ apps (e.g. airdroid) which can access your device as long as it is connected to a cellular or broadband network or internet portal. With airdroid, for instance, you can install apps, screw with files, and do whatever you could from the device remotely. Just a thought.
WEM97 said:
here are programs/ apps
Click to expand...
Click to collapse
Sorry to trouble you, but could you tell me an app that allows remote screwing of root files like /system by SMS remote commands?

[Tool] Network Monitor

Hi All,
Would you like to know what app is using network in your phone? Would you like to know what address is the application connecting?
My friend wrote a tool named Network Monitor. The link is https://play.google.com/store/apps/details?id=com.jmm.networkmonitor Would you like to try?
The tool could help you below:
1. Monitor current data activity and uplink/downlink throughput.
2. Monitor external IP address.
3. List all package which using internet currently.
4. List all socket link including destination IP address and source IP address of per package.
5. Query where is the destination address of the link connection and show it in map.
It is a fun tool if you want to know what application using your internet connection background.
My friend welcome any comments and he could add function if it would helpful.
Thanks.
Would this be helpful in analyzing what kind of intranet traffic is causing high wlan_rx_wakelocks?
Useful tool.
Works good on my N7100.
Thank you.
much needed as many are taking up lots of data without knowingly.
thanks
Nice app. Keep up the good work :good:
I almost installed this as it looks to be very helpful, but.....then I reread the thread and the fact that you say "My friend" made this app and not you makes me very nervous....why isn't your friend posting this up?
The way I see it if this app was found to be stealing data or compromising networks who would we have to turn to? You? All you are going to say is "my friend did it not me".
No insult intended but have him\her post this themselves would be my request.
I mean dude....you have less than 20 posts. Not like you have been on here for years....or even a year.
As an IT professional with 46 companies relying on my judgement....I simply can't risk their security
The tool will let you know which application is using your network, even for intranet.
tylerdurden83 said:
Would this be helpful in analyzing what kind of intranet traffic is causing high wlan_rx_wakelocks?
Click to expand...
Click to collapse
I think your concern was reasonable.
I am the author and using my friend's account. Let me explain what was going on. I wrote the tool part time and shown to my friend. My friend said you should publish in google play. But as you know, it is hard to let more person know there is software named "network monitor". My friend said he has a xda account and could help me to post. I will apply a account or just use this account.
One thing I could guarantee, there isn't back door in the application. Thanks for everybody's reply, it encourages me to add more functions.
One function I am considering to add is WIFI control/diag function.
Thanks
nerdslogic said:
I almost installed this as it looks to be very helpful, but.....then I reread the thread and the fact that you say "My friend" made this app and not you makes me very nervous....why isn't your friend posting this up?
The way I see it if this app was found to be stealing data or compromising networks who would we have to turn to? You? All you are going to say is "my friend did it not me".
No insult intended but have him\her post this themselves would be my request.
I mean dude....you have less than 20 posts. Not like you have been on here for years....or even a year.
As an IT professional with 46 companies relying on my judgement....I simply can't risk their security
Click to expand...
Click to collapse
he_arslan said:
The tool will let you know which application is using your network, even for intranet.
Click to expand...
Click to collapse
So it won't I guess, I need to know analyze the broadcast packets originating from somewhere else on the intranet and waking up my device from deep sleep (wlan_rx_wakelocks).
You are correct. Currently the tool doesn't support packet analyze. It needs root right to capture the packet from network.
tylerdurden83 said:
So it won't I guess, I need to know analyze the broadcast packets originating from somewhere else on the intranet and waking up my device from deep sleep (wlan_rx_wakelocks).
Click to expand...
Click to collapse
One way to alleviate fears is to open source your code.
Sent from my Nexus 4 using Tapatalk
:good::good::good:
ph37rd said:
One way to alleviate fears is to open source your code.
Sent from my Nexus 4 using Tapatalk
Click to expand...
Click to collapse
nice app... would be nice if it also shows wi-fi TX/RX along with the total and mobile... I take it total is the combo of wi-fi and mobile?
Yes. Total TX/RX combines Wifi information.
The reason I didn't list wifi TX/RX is most person only care about mobile data and there is limited space to show information.
Maybe need to provide a way to configure the display items.
BTW, I have upgraded the software and added floating window and process view. Please enjoy it.

[APP] [BETA] Phone Usage Monitor

Hello,
I want present my new app. that is in beta stage but fully functional: Phone usage monitor.
With this app you will be able to know when and how much you use your device and the apps that you have in it.
Please, report issues, if any, and suggest more events to monitorize.
Thanks
Play Store Description
Are you obsessed with your phone?
Up to what point?
Do you want to be aware of which apps are the most used?
Do you want to know what WiFi networks you connect to and at what time?
When are your applications updated?
Do you want to know if your phone suffers a expontaneous reboot or when you turn on or off the screen?
You need this app and you know it!
Play store link
https://play.google.com/store/apps/details?id=com.ryosoftware.phoneusagemonitor
Looking good! An option to exclude certain apps like Nova Launcher would be nice.
WDawn said:
Looking good! An option to exclude certain apps like Nova Launcher would be nice.
Click to expand...
Click to collapse
Thanks for the suggestion. Great idea!
It would also be nice to be able to monitor a remote phone (opening up the app to for parental monitoring for example).
This could be achieved by either allowing to :
- send a daily report by mail
- having a client app with data synced whenever a connection is avaialable
- sending data to a central server
...
anyway to export the data as .csv ?
Hello, thanks for app!
Any chance to remove "full network access" from permissions in future ?
Heya! Congrats on making the portal. Good stuff you got there.
Here's some suggestions for the intro texts:
Part 1 - Current
"Do you want to know how do you use your smartphone?
You have installed this app, so the answer will surely be affirmative.
With this app you can know with what apps you lose your time; time which you could lose living your real life..."
Part 1 - Suggested
"Would you like to know how you use your smartphone?
Well, as you've already installed this app, that'll be an affirmative!
By gathering statistics about your apps with Phone Usage Monitor, you'll know where your precious time is creeping off to. Time you might want to spend on living your real life..."
Part 1 - Motivation
The second "do" doesn't really have a function in the first sentence and I made it a bit softer to make a more friendly first impression. I mentioned the app's name to remind the user what's going to help them (branding, be proud of your creation). I stayed true to your intention, the reference to 'real life', but made that a bit softer as well by using "might" and not mentioning a negative word like "lose". We're all winners here!
Part 2 - Current
"To let us know this information we will run a service in the background to monitor the use you make of your smartphone.
Quiet!, it will not consume more than a little bit of the precious battery of your mobile..."
Part 2 - Suggested
"You're probably wondering how much battery this app will consume. Don't worry, just a tiny bit.
Think about the time you will save after gaining all this usage intel. You won't even need as much battery anymore."
Part 2 - Motivation
Shouting "Quiet!" doesn't come across very friendly. There's also never a comma after an exclamation mark. I wrote the text to match the battery icon better. I'm also pushing the major goal of the app forward.
Part 3 - Current
"We will give you more information if you let us see how do you use the apps in your device..."
Part 3 - Suggested
"Sorry to bother you but I will need some usage access in order to provide you with all these awesome statistics. Is that okay with you?"
Part 3 - Motivation
"let us see" gives the impression multiple people or a company will be watching along, which totally isn't the case. I wrote it a bit more personal, fun and friendly.
Part 4 - Current
"Do not worry!
The data we collect is NOT sent anywhere."
Part 4 - Suggested
"Do not worry!
The data I collect is NOT sent anywhere."
Part 4 - Motivation
As in part 3, It's better to speak from a first person point of view, "I" instead of "we". It's just the app and the user, "you and me", which is a more comforting thought.
Instead of "START APP" I'd use something more vivid like "Lets go!" or "Show me some numbers!" or "Start saving time!"
The UDPA looks good, people are used to not reading these disclaimers and accepting them anyway. It's also a nice reminder that even if there is a "we", it's literally stating no personal data will be collected on any server. Kudos! :highfive:
I personally don't like the last paragraph but ah well, one has to make a living, right?
Looking forward to those stats...
Timmmmaaahh said:
Heya! Congrats on making the portal. Good stuff you got there.
Here's some suggestions for the intro texts:
.
Click to expand...
Click to collapse
Thanks, thanks, thanks!
I have updated the app with your suggestions.
English isn't my matter language
MaXX99 said:
It would also be nice to be able to monitor a remote phone (opening up the app to for parental monitoring for example).
This could be achieved by either allowing to :
- send a daily report by mail
- having a client app with data synced whenever a connection is avaialable
- sending data to a central server
...
Click to expand...
Click to collapse
I need to think on it.
I would not like it to be used without consent to spy on anyone :/
legendnexus said:
anyway to export the data as .csv ?
Click to expand...
Click to collapse
Sounds pretty good.
I have added to the ToDo
panfiluta said:
Hello, thanks for app!
Any chance to remove "full network access" from permissions in future ?
Click to expand...
Click to collapse
Sorry, but Internet permission is needed to display Ads.
I understand that you do not believe in my word when I say that I am not sending data anywhere, but I need to access the Internet to load the Ads
Please add export data functionality! Csv format for example. Great app otherwise, thanks!
Crashing
Hi,. Unfortunately the app crashes every time I open it on my OnePlus 6 that runs Android 9. The first time run screens work fine and permissions are assigned ok but then I can't open the app. I have tried clearing the storage/cache and that hasn't helped. Any ideas what to try next please?
Hi
Assuming you're rooted, please, post a logcat or send by email.
Thanks
Peteba said:
Hi,. Unfortunately the app crashes every time I open it on my OnePlus 6 that runs Android 9. The first time run screens work fine and permissions are assigned ok but then I can't open the app. I have tried clearing the storage/cache and that hasn't helped. Any ideas what to try next please?
Click to expand...
Click to collapse
bartito said:
Hi
Assuming you're rooted, please, post a logcat or send by email.
Thanks
Click to expand...
Click to collapse
Sorry no not rooted..
Peteba said:
Sorry no not rooted..
Click to expand...
Click to collapse
OK, I will try it by my self
Hello
I've tried but no luck reproducing the issue.
If possible, enter app settings then enable debug mode then reproduce the issue then sent the log file.
If not possible, please, contact by email or PM to receive a debug version of the app to track the issue.
Thanks in advance
Peteba said:
Sorry no not rooted..
Click to expand...
Click to collapse
Peteba said:
Hi,. Unfortunately the app crashes every time I open it on my OnePlus 6 that runs Android 9. The first time run screens work fine and permissions are assigned ok but then I can't open the app. I have tried clearing the storage/cache and that hasn't helped. Any ideas what to try next please?
Click to expand...
Click to collapse
I have the same Problem on my OnePlus 6 (A6003) running Android 9 (OxygenOS: 9.0.4)
max_m42 said:
I have the same Problem on my OnePlus 6 (A6003) running Android 9 (OxygenOS: 9.0.4)
Click to expand...
Click to collapse
I have answered your PM
hi, in my view for PRO version i would like to keep data live for 365days and to export them in csv in order to analize with spreadsheet or other stuff.
thanks

Categories

Resources