Web Hack List

Collected research

Android Exploit to RCE: $5000 Bounty

From an Android Hook to RCE: $5000 Bounty

Frida hooks on Conscrypt's checkTrustedRecursive and on Java's Cipher strip TLS pinning and a second app-layer AES whose key exchange rides in an X-Cookie header (seed, key length, two IVs, HMAC). The decrypted body reads wgt:[FILE_PATH]:FUNC(ARGS), which a server-side headless browser opens and executes, so appended JavaScript runs on the server. With no outbound HTTP, the payload builds a hostname from location.pathname and exfiltrates over DNS.

Record

Document
From an Android Hook to RCE: $5000 Bounty
Researcher
Yashar Shahinzadeh
Published by
Voorivex Team
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Yashar Shahinzadeh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .