Razer2015 / NordeaRootBypasser

Xposed Module for bypassing root detection in Nordeas banking apps.
14 stars 7 forks source link

Codes 1.5.0 #4

Closed kyrasantae closed 7 years ago

kyrasantae commented 7 years ago

Doesn't work anymore with latest codes app. Just shows screen saying root was detected.

Enskan commented 7 years ago

Hey,

Same thing here, since about 14th of june Nordea codes recognises root. I had been using the similar module " XposedCodeApp". I the process i also tried this module which does not work either.

Nordeas FAQ says that "the new version of the code app reconises root better than the previous"

Please help us soon :)

Razer2015 commented 7 years ago

@kyrasantae @Enskan

I think I might have found the new root detection but I can't test it thoroughly since I only have access to rooted VM android (not a real device).

There was apparently a hook detection as well as root detection :D I first bypassed the root detection and it seemed to work but then crashed. I guess I got that fixed but not entirely sure. I've committed the changes to repository and compiled a new version, please give me a feedback on how it works.

Download: https://github.com/Razer2015/NordeaRootBypasser/releases/tag/v1.1

kyrasantae commented 7 years ago

Not working yet.

Razer2015 commented 7 years ago

@kyrasantae

What is the problem? It still says root detected or is it crashing or something?

My virtual android device works great so I don't know what could be the problem and so I can't even debug it further :(.

Or do you maybe have another version of the APK since they do say that it can vary depending on device? I've tested it on this APK (if you could check the MD5 or SHA1 from yours?): image

MD5: 30169142EA1D8E3FFFBFDCFD434E6FD5 SHA1: FE79C2DECA0132946A34CE63AB54ACC23F0FCCF8

And possibly a logcat from the point where you open the Nordea Codes app?

villelappi commented 7 years ago

Hi,

I tested latest version 1.1 and it works. Thanks!

Razer2015 commented 7 years ago

@villelappi Cool, thanks for feedback.

kyrasantae commented 7 years ago

I still get the root detected screen. The hashes for my package are the same as yours. I'll try to upload some logcat material tonight, but in the meantime I can tell you that my device is using Android 4.4.2.

Razer2015 commented 7 years ago

@kyrasantae

Have you double checked that the installed version of my module is 1.1 and that you have it activated + rebooted your device after that?

Also, take the logcat from the first startup of the app after reboot. I don't know if it's just a bug in the virtual android or not but it doesn't log everything if I take the logcat from the second startup IF I haven't force closed the nordea codes app before.

kyrasantae commented 7 years ago

Yes, it shows that I have 1.1. I have switched the module off and on and rebooted the device multiple times over the weekend, with the same result.

Razer2015 commented 7 years ago

That's weird that it works for some and not for you :/ Well, lets hope the logcat can shed some light on this issue.

Enskan commented 7 years ago

I'm using a Meizu pro 5 phone and it seems to be working! I can start the code app but not use the actual codes until a get a new account again (reinstalled the code app in the troubleshooting process). I am using Xposed framework version 87.

Thank you very much Razer2015!

kyrasantae commented 7 years ago

Hey, I got it working again. First I tried disabling the module, rebooting, then enabling it, and rebooting again. At this point, instead of going to the root detected error, it popped the error that the version of the codes app was no longer in use.

Enskan's post gave me the idea to try reinstalling. So I deleted the device from my netbank, reinstalled the code app, and then added it again in netbank. Now it works :) Thanks to both of you!

kyrasantae commented 7 years ago

Update to 1.5.1 has broken it again. Same root detected screen. Anyone else?

Razer2015 commented 7 years ago

@kyrasantae Added support for 1.5.1 in the newest release.

kyrasantae commented 7 years ago

Working again. Thanks!