infobyte / evilgrade

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.
https://www.faradaysec.com/
1.28k stars 279 forks source link

Enhancement request #6

Closed ortholinux closed 8 years ago

ortholinux commented 8 years ago

Evilgrade can do several malicious upgrades for several applications even cross platform like itunes and others, but there is nothing for Android devices, and there are two really popular applications in android world i.e playstore and whatsapp, if evilgrade could have something for such popular apps it would be really good. I also tried the skype upgrade on android skype version, even sniffed the urls it was sending requests to and redirected those to evilgrade, but still didn't work.

mattaereal commented 8 years ago

Hi @ortholinux, we'll be glad to add any module you like. Feel free to set a description for an HTTP/Plaintext update of an unsigned (or a possible bad signed) application and well work it out for you.