Easy Hack: How to find potential vulnerabilities and hardcoded data of an Android application. WhatsApp Sniffer: a description of the program and how to protect yourself How to protect yourself from WhatsApp Sniffer

February 06, 2013 09:57 am

Console loading speed from 5 seconds to two minutes
(this specificity of work is absolutely all chips reset glitch hack)
As for the speed of launching games, games are launched as with external drive and from the inside quickly and quietly.

File manager for freeboot

XexMenu is a simple shell for running games from any media, has a built-in file manager, allows you to run games and applications with * .xex extensions
Control buttons (rb, X - source selection dvd usb hdd, Y-output menu of operations on files copy past cut) The easiest way to launch games and applications for beginners.
How to use? Very simple.
We go on the console to the "game library" section and run (if it is not displayed in the game library, then select the demo version)

Also, XexMenu can be written to a memory card, USB flash drive or internal hdd. To do this, start the hechmenu from the disc, press X, select DVD and copy the C0DE9999 folder with all its contents to the content \ 0000000000000000 (16 zeros) pack of your HDD. That's all, now you can forget about the disc with the hekhmenu.

HOW TO RUN ISO from USB?
File system hard disk should only be FAT 32 (use acronis disk director for formatting)
Download the program Xbox image browser (link below)
Create a GAMES folder on your hard (or flash drive) (ALL WITH CAPITAL LETTERS)
Open the Xbox image browser ISO file with the game.
Create a folder with the name of your game in the GAMES folder.
Now press right click"EXTRACT" and extract all files into the newly created folder with the name of the game on a USB drive.

After extracting the game, be sure to go to the external HDD into the game folder and delete the $ systemupdate folder

Now insert the USB into the xbox360. We go to the game room. Launch xexmenu. If you copied everything correctly, then the games will automatically appear in the xex menu.
Choose a game and press A. Enjoy your game!

XeXmenu program shows a list of games from a hard disk connected via usb

How to unlock arcades?

Downloading an arcade game from the Internet. Download the program YarisSwap (link below)
We launch the program. Select the game file (many numbers and letters). Click on the red button and wait. That's it, the file is patched. Then we take the patched file and paste it back into the folder where it was. Then we throw this folder on the internal hard (how to do it, read the bottom) in the section content \ 0000000000000000 \
That's it, we have a full version

How to copy games over the network:

XeXmenu shows the ip address for copying games over the network (it is the ftp server)

XeXmenu shows the temperature of the processor, memory and allows you to choose the cover to your liking

(downloading games goes through the programs total commander or FLASHFXP is better)

We connect the Xbox 360 to the computer by local network via FTP protocol

There are two ways to copy games over the network:

1) directly connect to the PC (you need to manually register the ip addresses)

2) connection via a router (the router will automatically do everything, provided that the DHCP service is configured on it)

Let's consider the first method in more detail:

directly connect to the PC (you need to manually register the ip addresses)

We connect the network ports of the computer and the xbox 360 with a patch cord cable. If this was not included in the kit, it is sold in any computer store.

Turn on xbox 360
- go to the system parameters
- network parameters
- configure the network
- tab basic settings
- select the manual mode of the ip-address parameters
- register the ip-address 192.168.0.2
- subnet mask 255.255.255.0
- we do not need the gateway, we prescribe 0.0.0.0
- save the settings by clicking done
- run the xex menu and leave it running
- go to the PC with Network connections
- Local Area Connection Properties

Go to the properties "Internet Protocol TCP / IP"

We register the IP address and network mask

Click OK
- restart the PC
- launch Total Commander (you can use any other FTP client)
- press Ctrl + F
- select New Connection
- we register the ip-address of the xbox 360 ftp server and, separated by a colon, the port number - 192.168.0.2
- xbox login and xbox password

Click OK and connect using the created connection
- we now have access to all storage devices connected to the xbox360

Copy games to section HDD1 \ content \ 0000000000000000 \

Using iso2god, you can upload games over the local network we just created.

How to install games on Freeboot from iso image to the ORIGINAL hard drive over the network

Launch the Iso2God program (link below)

if the program starts with an error, disable your antivirus
when unpacking the archive, the antivirus swore at the xextool.exe program, but there is nothing dangerous in it.
- Click Add ISO

In Image Location, specify the path to the iso image
- In Output Location - the path to save the converted freeboot result

There are 3 items in the lower drop-down list:
- None - select if we do not need to reduce the size of the image
- Partial — the image is cut off after the end of the last used sector. Saves 800-1500 MB of hard disk space
- Full - complete rebuilding of the image with the removal of all empty sectors on it. You can leave the modified image for future use. We get the best-sized result. It takes 5-10 minutes additionally.
- select the settings we need and click Add Iso
- now convert

For example, the Saboteur game image has shrunk from 7.29 GB to 5.64 GB, with the Full image rebuild mode selected.
- now, the result obtained in the Output Location, I have this folder 4541088F - the name is unique for each game, we copy it to the hard disk in partition3 to the HDD1 / Content / 0000000000000000 / folder via the local network using the FTP protocol.
Do not forget that to copy the game over the network, it must be launched on the xbox 360 XEXMENU
(he acts as FTP client server)

Video codecs for watching movies - download

DLC (add-ons to games) and patching for games

As for the various DLCs, title updates - everything is simple.
We downloaded the DLC, for example for the batman, usually the DLC has a folder 000002. So, you need to drop this folder into the hdd \ Content \ 0000000000000000 \ 4500052 folder where 4500052 is the folder with unique number games. Moreover, the game itself can be stored on USB Hdd, but the DLC for it must be on the console's HDD!

Now about the title update, they are TU, they are patches. Everything is also simple - we throw a unique file in hdd \ Cache (4L145C441000.000256 - example file) (no more manipulations are required)
We usually download the latest update.
Site with the latest title updates -

PC software:

YarisSwap
What for: unlocking arcades, avatar DLC (clothes of avatars).
Additionally: can upload content directly to the box via ftp protocol, can change XUID.

Iso2God
Why: converts games from ISO to GOD container (Games on Demand).
Additionally: can upload content directly to the box via ftp protocol, can change the picture of the shortcut that will be visible in the dash, as well as the name of the game and description.

Xbox Image Browser
if the program starts with an error, disable your antivirus
Why: unpack ISO
Additionally: after unpacking, the game must be dropped into x: \ Games \ game name \ (suitable for both the hard drive of the box and for usb flash drives and hard). Launch the game with the default.xex file through the xexmenu program, or from the shortcut in the dash if you have previously created it in the Quickboot program.

Programs for Xbox360:

Xexmenu
What for: the main program for xbr consoles. Running games, emulators, other programs, as well as the file manager, shows the temperature of the iron. FTP server.
Additionally: to connect to xbox via ftp protocol, this program must be running on the console. It has two types: NXE container (drop into content \ 0000000000000000 \ C0DE9999 \ 00080000 \) - the shortcut will appear in the game library \ demo section of the game, and unpacked (run through default.xex).

NXE2GOD
Why: converts games installed from the disc into GOD games (you no longer need a disc to run).
Additionally: it also looks like an NXE container (drop it into content \ 0000000000000000 \ C0DE9999 \ 00080000 \) - the shortcut will appear in the game library \ demo section of the game, and unpacked (run through default.xex).

Update Reset glitch hack (new freebie) to new dashboard 16197

INTERNET EXPLORER appeared in the new update 16197

Now you can walk around the Internet, view the latest entries on the wall in Vkontakte immediately on the XBox 360 game console

Sometimes it becomes necessary to find out what bugs were found in some top Android application. There can be a lot of reasons for this: from attempts to spin the vector further and search for similar vulnerabilities to banal checks for hardcode. Let's try to crank it, and the HackApp + Vulners bundle will help us with this.

HackApp is a shareware toolkit and service for finding bugs in mobile applications... HackApp maintains its own vulnerability database, where attack vectors and vulnerable versions are described in detail. Vulners is a free and open source vulnerability search engine for various products. In addition to the bugs themselves, Vulners finds and displays exploits related to the vulnerability, patches, and even news from open sources.

Using Vulners and HackApp, you can search for vulnerabilities in more than 22,025 top Android apps from Google play! Store. To search, you need to specify the type type: hackapp. The search results display the title, the number of vulnerabilities by severity level (red circle - critical, yellow circle - medium critical, gray circle - note), information about the application (icon, current version, developer and release date).

The link to the application vulnerability bulletin looks like https://vulners.com/hackapp/HACKAPP:RU.SBERBANK_SBBOL.APK. The bulletin lists all vulnerabilities with brief description and indicates which versions of the application are considered vulnerable. A full description of the vulnerabilities is available from the link on the HackApp website.


But the real killer feature is the ability to find applications whose careless developers have hardcoded inside Accounts from Amazon AWS. The simplest request https://vulners.com/search?query=type:hackapp%20AWS%20credentials will give a whole bunch of such "gems".


Great, we have AWS_KEY. Now we also need AWS_SECRET_KEY. Let's not stop and take a look at the developers' "house"? 🙂


The vulnerable APK can be conveniently downloaded directly from the HackApp website. Then we open it in all known ways:

Java -jar apktool_2.1.1.jar d.apk

Run grep and ... voila! It seems that we really found something:

MacBook-Pro: pwner $ grep -R "AKIAI5AWXTYSXJGU55QA" ./ .//smali/com/adobe/air/AdobeAIR.smali:.field private static final TEST_ACCESS_KEY: Ljava / lang / String; = "AKIAI5AWXTYSXJGU55QA" .//smali/com/adobe/air/AdobeAIR.smali: const-string v1, "AKIAI5AWXTYSXJGU55QA"

What can you say: pwned in less than 1 minute!

By combining these two tools and a simple full-text search, many more shameful secrets of mobile apps can be pulled out :).

Good luck and successful knowledge!

  1. Remember that by setting yourself third party application, you yourself are responsible for the consequences!
  2. Reading someone else's correspondence, you violate his rights, and for this criminal liability is provided!
  3. This instruction only provides information on how attackers read someone else's correspondence, but in no case calls you to take this action.

What is a sniffer? In thieves' jargon, these words mean a person who can open the safe with anything, even the most rusty pin. Let's figure out what an application like WhatsApp Sniffer is for, for a computer and a phone, which, by the way, can be downloaded from our website.

Why do you need

This utility was created in special secret laboratories in America - at least that's what the developers say. With the help of a sniffer, you can easily hack any account in Votsap and get access to all the secrets of the correspondence of the desired person. Of course, you download the program at your own peril and risk, no one is responsible for its bugs and other possible unpleasant moments.

So, according to the developers, the sniffer allows you to:

  • completely take over the accounts of the "victim", as if it were your personal account in Wotsap;
  • read all user messages;
  • send messages to the user's friends on his behalf;
  • change the photo on the avatar;
  • change status;
  • send files and receive them.

How does it work

The utility works only on Android. The developers also assure us that this application is completely safe for your phone.

So, the essence of the sniffer's work is as follows: each phone has its own original MAC-code, which the utility copies and, thus, the program thinks that it was entered from a familiar smartphone or another gadget. The sniffer can copy the MAC code in three ways:

  • SMS. Send a special SMS to the victim with a link. When the victim opens the link, the sniffer will penetrate the phone and the user's WhatsApp program, opening access for you.
  • Call. The application calls the victim's phone and when she answers it penetrates the phone and the application.
  • Wi-Fi. If you are next to the victim, and you use the same Wi-Fi with her, then you just need to launch a sniffer on your phone and indicate the victim's number: in a second, you will have access to her WhatsApp.

To use the sniffer, just start the utility, select the method of use and press "spoof" - the button that allows you to detect the phone of the person you are interested in.

Where to download and how to install

To download WhatsApp Sniffer for Android you need to type in Google: "whatsapp sniffer apk download", or use the installation file that you can find on our website. Unfortunately, Whatsapp sniffer cannot be downloaded for iphone, because for this operating system it simply does not exist.

To install the utility on your phone, follow these steps:

  1. Hand over setup file to your smartphone.
  2. Launch it - it will install normally.
  3. When opening the file, it will ask for permission to access some functions, select "Allow". That's it: the sniffer is installed on your gadget.

If you cannot install Sniffer, then it is recommended to hack it for which you need to download WhatsApp Hach Sniffer for free in Russian.

How to keep yourself safe from WhatsApp Sniffer

What if you are not a spy, but a victim? If you have the slightest suspicion that your phone is being used by intruders for their own ends, you should uninstall the Wotsap application and reinstall it. Moreover, it is recommended:

  • Clean your phone with any antivirus;
  • Contact the Wotsap developers so that they put more serious protection against penetration third-party programs into the utility.
  • Always check how reliable the Wi-Fi network you are using is. So, if you have any suspicions that hackers may be connected to it, then it is better not to connect to it.