dimanche 26 janvier 2014

Let's get to the bottom of kingo. topic




I would like to start a forensics thread.
I am a securiry auditor ( pen tester) and good at reverse engineering.


The most helpful thing, that could happen is any apk's files, scrips that are installed from kingo upload them. I will post the decompiled version here

If you are going to use kingo root. Install wireshark on the computer you are going use to root with kingo. I dont want personal info so use on a network that only 1 computer is on and do not use the internet. Vms are the best. Upload the pcap.

Why I want the pcap info. I noticed that there is a lot of requests to sites coming from the windows based application right after the program is installed. I want to see if these are static requests or dynamic.




**Proof so far**
1.the Kingo windows application import segments are destroyed
Typically you see this in malware that is packed the purpose of this is to make more difficult to decompile.



2. When running the windows based exe app used to root the phone. it requests a number of xml pages on many different sites.




More to come





Aucun commentaire:

Enregistrer un commentaire