Skip to content
P
非影
精选
最新
漏洞
研究
工具
主题
来源
搜索
搜索
🌓
English
面向安全从业者的中英双语安全研究与漏洞情报精选。
Tinder Flaw: Location-Based Application Payment Logic Bypass
netspi.com
| 博客 |
#mobile-security
|
#logic-flaw
|
#tinder
|
#payment-bypass
|
#location-spoofing
摘要
披露 Tinder Plus 的区域定价逻辑缺陷:通过 GPS 位置欺骗和印度手机号注册,美国用户可按印度区 $3/月的促销价订阅,替代本土 $10/月,文章给出复现步骤并估算公司潜在损失。
发布时间
2016-04-04 00:00
收录时间
2026-09-20 06:06
原文 ↗
← 上一篇
Maintaining Persistence via SQL Server – Part 2: Triggers
下一篇 →
Open Source Software – Is It the Death of Your Company?
相关内容
博客
·
netspi.com
移动应用威胁建模
移动平台承载着用户最私密的数据,安全却常被事后才考虑。NetSPI 提供一套移动应用威胁建模框架,支持在设计阶段或对既有应用开展威胁评估,在渗透测试暴露问题前发现薄弱环节。
博客
·
netspi.com
Reverse Engineering iOS Applications in a Fun Way
概览 iOS 应用逆向的实用路径:用 Cycript、class-dump-z 对 ipa 做类转储获取方法名,借助 MobileSubstrate 钩住并替换 Objective-C 方法,iNalyzer、Snoop-it 等工具可显著加速整个分析过程。
博客
·
netspi.com
Android Root Detection Techniques
梳理 MDM 方案检测 Android 设备 Root 状态的常用手法:检查特定软件包、文件、目录权限与命令输出,例如 BUILD 标签中的 test-keys、OTA 证书缺失、su 二进制等;实测环境为已 Root 的 Nexus 4(Android 4.2.2)。
博客
·
netspi.com
Sky Prioritize Yourself
iOS Passbook 中的登机牌本质是 .pkpass 压缩包,导出解包后可修改内部图片(如 Sky Priority / TSA PreCheck 页脚),再用 Apple 开发者账号重新签名导入。作者提醒:篡改登机牌极易招致 TSA 麻烦,切勿模仿。
博客
·
netspi.com
Bypassing AirWatch Root Restriction
AirWatch 等 MDM 方案让企业强制执行 Android 设备策略(密码、加密、禁止 Root 等),但限制并不难绕过。文章在已 Root 的 Nexus 4 上演示绕过 AirWatch 的 Root 检测,使设备保持 Root 的同时仍显示合规。
博客
·
netspi.com
Certificate Pinning in a Mobile Application
移动应用渗透测试中频繁发现中间人(MITM)漏洞。证书固定(certificate pinning)通过在应用内硬编码/存储可信证书或公钥,只信任预置证书对应的服务器,其余一律拒绝——浏览器因面向通用通信而无法采用此机制。文章还回顾了 SSL 连接的标准校验流程。
返回