aarony / asef

Automatically exported from code.google.com/p/asef
0 stars 0 forks source link

specific case scenario. CAPTCHAS and passwords #2

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1. Run ASEF on an APK which uses a CAPTCHA to allow access

What is the expected output? What do you see instead?
If the application is sending user data to a malicious user (on the google 
unsafe list lets say) unknown to the user one would like to know of it. But 
since there is a CAPTCHA step before the malicious activity begins ASEF would 
not even get into the functionality of the application leave alone the stealth 
malicious activity.

What version of the product are you using? On what operating system?
ASEF running on Ubuntu 12.04.1 LTS 32 bit.  

Please provide any additional information below.
Try it with the prankdial apk available at http://www.prankdial.com/mob/

Original issue reported on code.google.com by khanimt...@gmail.com on 20 Sep 2012 at 7:02