• Please take a moment to look over the Suggestions & Feedback rules before making a post: READ RULES HERE

Warning: do not use any not authorized BHW apps from Google Play

Status
Not open for further replies.

Lukmat

Elite Member
Executive VIP
Jr. VIP
Joined
Jan 22, 2008
Messages
5,797
Reaction score
8,171
Topic is here, but there is no warning from moderation:
https://www.blackhatworld.com/seo/is-this-bhw-app-authorized.1200360/

I decompiled this app, not run it:
https://play.google.com/store/apps/details?id=black.hat.worlds


Screenshot looks like Android WebView component, but there is so much other code here and a lot is obfuscated (ProGuarded, that we don't know what this developer is doing). He uses some own command servers, crashlytics and many other weird libraries.

The biggest question, if this is a webview, why he is reading login and password? What he is doing with your credentials? In webview, the page loads itself and developer cannot manipulate a lot.

Second question, why he is asking for Phone Call permission?


100% he is doing something with your login and password, but you cannot guess what, because rest of code is smart obfuscated.

mFRhKpz



Here you can report this app, @Diamond Damien
https://support.google.com/legal/troubleshooter/1114905
It's link for DMCA request, faster removal
Only for copyright owner


For other people you can use this
  1. Open the Google Play Store app
    7R1uFoIRzvb36XFP28r43j53tmk94Y0IfBNNOeIqlvtAvVlzxobBCxFku2aHloYYoR4=h18
    .
  2. Go to the detail page for an app or game.
  3. Tap More
    pchbZu1korOUia579bPibTPzQ4CrRH9-MpsIz79d-560lGwSA-sEx6MGO0F85TuG_Q=w18-h18
    v21SBxYgtayWPvV7AvdC_6nNH6eQjkg5erVFjsD1Y9WqqcLAp2BCN03bxOnWM7xw3CQ=w18-h18
    Flag as inappropriate.
  4. Choose a reason.
  5. Tap Submit.

    Same you can do on PC
 
The biggest question, if this is a webview, why he is reading login and password? What he is doing with your credentials?

That might just be the answer to all the accounts that got hacked and logs back in after several years.
 
That might just be the answer to all the accounts that got hacked and logs back in after several years.
Nah, this app is fresh, but I see it's professional coded. Everything vital is obfuscated.
but previously, in the past, there could be some apps in store. I don't know if staff reported them.
 
Nah, this app is fresh, but I see it's professional coded. Everything vital is obfuscated.
but previously, in the past, there could be some apps in store. I don't know if staff reported them.

Reported the app both from PC and Mobile for collecting the login credentials of BHW members.
 
The app doesn't actually hack login details though, the screenshot by @vinku is an RxJava dependency :)

@sweeside but we both don't know what he is doing in obfuscated code :) there is a lot of this, even in main package :)

it's not only webview ;) he is doing a lot more
 
As far as i was able to look into this, the obfuscated code is just a customized webview from codecanyon. :)

https://codecanyon.net/item/android...app-push-url-handling-apis-much-more/19487619

What you was able to just read class name GoldWebview, but he can steal credentials in single line code. Can be obfuscated.


Anyway, it's just a warning to not use NOT AUTHORIZED APPS:
-he haven't any rights to use Blackhatworld in a way he is doing it
-any developer can hide everything, even in library you told. So what it's RxJava depedency? Do you have proof it's clean RxJava? In free version of my HelloWorld app with outside app ads (different forum, before course), I made some surprise what was putting my ad id instead developer, belive me, nobody catched it and earned few hundreds (don't worry, current is clean ;) )

Let's not make offtop, it's a warning for users, that not official app can be dangerous
 
Topic is here, but there is no warning from moderation:
https://www.blackhatworld.com/seo/is-this-bhw-app-authorized.1200360/

I decompiled this app, not run it:
https://play.google.com/store/apps/details?id=black.hat.worlds


Screenshot looks like Android WebView component, but there is so much other code here and a lot is obfuscated (ProGuarded, that we don't know what this developer is doing). He uses some own command servers, crashlytics and many other weird libraries.

The biggest question, if this is a webview, why he is reading login and password? What he is doing with your credentials? In webview, the page loads itself and developer cannot manipulate a lot.

Second question, why he is asking for Phone Call permission?


100% he is doing something with your login and password, but you cannot guess what, because rest of code is smart obfuscated.

mFRhKpz



Here you can report this app, @Diamond Damien
https://support.google.com/legal/troubleshooter/1114905
It's link for DMCA request, faster removal
Only for copyright owner


For other people you can use this
  1. Open the Google Play Store app
    7R1uFoIRzvb36XFP28r43j53tmk94Y0IfBNNOeIqlvtAvVlzxobBCxFku2aHloYYoR4=h18
    .
  2. Go to the detail page for an app or game.
  3. Tap More
    pchbZu1korOUia579bPibTPzQ4CrRH9-MpsIz79d-560lGwSA-sEx6MGO0F85TuG_Q=w18-h18
    v21SBxYgtayWPvV7AvdC_6nNH6eQjkg5erVFjsD1Y9WqqcLAp2BCN03bxOnWM7xw3CQ=w18-h18
    Flag as inappropriate.
  4. Choose a reason.
  5. Tap Submit.

    Same you can do on PC

Hi @vinku - thanks for taking the time to raise the issue. Action has already been taken against the developer in question when we were first made aware. There is a clear warning from @Zwielicht here https://www.blackhatworld.com/seo/is-this-bhw-app-authorized.1200360/#post-12875730 Which includes helpful hints if you’re ever concerned about downloading apps. On the store or elsewhere. Finally, needless to say, if there was an official BHW app out in the wild we’d be the first to tell you about it. We’re sticking with the responsive design we have instead of developing an app.

In short always look to the source and never give your login credentials away.

asked answered closed.
 
Status
Not open for further replies.
Back
Top