Collected research
Android Exploit to RCE: $5000 Bounty
From an Android Hook to RCE: $5000 Bounty
Frida hooks on Conscrypt's checkTrustedRecursive and on Java's Cipher strip TLS pinning and a second app-layer AES whose key exchange rides in an X-Cookie header (seed, key length, two IVs, HMAC). The decrypted body reads wgt:[FILE_PATH]:FUNC(ARGS), which a server-side headless browser opens and executes, so appended JavaScript runs on the server. With no outbound HTTP, the payload builds a hostname from location.pathname and exfiltrates over DNS.
Record
- Document
- From an Android Hook to RCE: $5000 Bounty
- Researcher
- Yashar Shahinzadeh
- Published by
- Voorivex Team
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Yashar Shahinzadeh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .