导航菜单

应用安全检测报告

应用安全检测报告,支持文件搜索、内容检索和AI代码分析

移动应用安全检测报告

应用图标

公务员之家 v1.0.1

Android APK 961c1a3e...
44
安全评分

安全基线评分

44/100

中风险

综合风险等级

风险等级评定
  1. A
  2. B
  3. C
  4. F

应用存在一定安全风险,建议优化

漏洞与安全项分布

4 高危
17 中危
2 信息
1 安全

隐私风险评估

2
第三方跟踪器

中等隐私风险
检测到少量第三方跟踪器


检测结果分布

高危安全漏洞 4
中危安全漏洞 17
安全提示信息 2
已通过安全项 1
重点安全关注 0

高危安全漏洞 该文件是World Writable。任何应用程序都可以写入文件

该文件是World Writable。任何应用程序都可以写入文件
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-local-storage-for-sensitive-data-mstg-storage-1-and-mstg-storage-2

Files:
com/nirvana/tools/core/UTSharedPreferencesHelper.java, line(s) 16,9
com/nirvana/tools/logger/utils/UTSharedPreferencesHelper.java, line(s) 31

高危安全漏洞 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/fwlst/lib_base/utils/AesUtils.java, line(s) 78

高危安全漏洞 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击

不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#webview-server-certificate-verification

Files:
com/fwlst/module_user/activity/ModuleUserMemberCenterActivity.java, line(s) 578,648,576,646

高危安全漏洞 使用弱加密算法

使用弱加密算法
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/nirvana/tools/core/CryptUtil.java, line(s) 146

中危安全漏洞 应用已启用明文网络流量

[android:usesCleartextTraffic=true]
应用允许明文网络流量(如 HTTP、FTP 协议、DownloadManager、MediaPlayer 等)。API 级别 27 及以下默认启用,28 及以上默认禁用。明文流量缺乏机密性、完整性和真实性保护,攻击者可窃听或篡改传输数据。建议关闭明文流量,仅使用加密协议。

中危安全漏洞 应用数据允许备份

[android:allowBackup=true]
该标志允许通过 adb 工具备份应用数据。启用 USB 调试的用户可直接复制应用数据,存在数据泄露风险。

中危安全漏洞 Broadcast Receiver (androidx.profileinstaller.ProfileInstallReceiver) 受权限保护,但应检查权限保护级别。

Permission: android.permission.DUMP [android:exported=true]
检测到  Broadcast Receiver 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Activity (com.alipay.sdk.app.PayResultActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (com.alipay.sdk.app.AlipayResultActivity) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (com.bytedance.android.openliveplugin.stub.activity.DouyinAuthorizeActivityProxy) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (com.bytedance.android.openliveplugin.stub.activity.DouyinAuthorizeActivityLiveProcessProxy) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
cc/shinichi/library/tool/file/FileUtil.java, line(s) 26
cc/shinichi/library/tool/image/DownloadPictureUtil.java, line(s) 146
com/danikula/videocache/StorageUtils.java, line(s) 15
com/fwlst/lib_base/utils/DownBitmap.java, line(s) 28,32
com/fwlst/module_user/util/UserFileOperations.java, line(s) 11
com/ijj/tookit/file/MediaExt.java, line(s) 213
com/luck/lib/camerax/utils/FileUtils.java, line(s) 75,77,81,37,38
com/ss/android/downloadlib/addownload/h.java, line(s) 395
com/ss/android/downloadlib/addownload/k.java, line(s) 247,249
com/ss/android/downloadlib/g/m.java, line(s) 364,344,438
com/yalantis/ucrop/util/FileUtils.java, line(s) 155
top/zibin/luban/LubanUtils.java, line(s) 25,27

中危安全漏洞 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
com/fj/gong_kao/adapter/FirstLevelDirectory1Adapter.java, line(s) 15
com/fj/gong_kao/fragment/FirstTypeFragment.java, line(s) 25
com/fj/gong_kao/utils/RandomLists.java, line(s) 6
com/fwlst/lib_base/utils/BaseUtils.java, line(s) 23
com/hjq/permissions/PermissionFragment.java, line(s) 13
com/ijianji/module_play_video/utils/RandomUtils.java, line(s) 8
com/kongzue/dialogx/interfaces/OnBindView.java, line(s) 15
org/greenrobot/greendao/test/DbTest.java, line(s) 7

中危安全漏洞 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
cc/shinichi/library/glide/cache/DataCacheKey.java, line(s) 34
coil/decode/GifDecoder.java, line(s) 18,19,20,21
coil/decode/SvgDecoder.java, line(s) 37
coil/decode/VideoFrameDecoder.java, line(s) 30,31,32
coil/memory/MemoryCache.java, line(s) 121
coil/memory/MemoryCacheService.java, line(s) 41
coil/request/Parameters.java, line(s) 160
com/fenghuajueli/lib_data/entity/key/SwitchKeyEntity.java, line(s) 79
com/fenghuajueli/libbasecoreui/constants/SwitchKeyConstants.java, line(s) 35
com/fwlst/app/BuildConfig.java, line(s) 7
com/fwlst/lib_base/user/UserInfoEntity.java, line(s) 60
com/fwlst/lib_base/utils/AesUtils.java, line(s) 19
com/hjq/permissions/StartActivityManager.java, line(s) 9
com/nirvana/tools/logger/UaidTracker.java, line(s) 20,21,22
com/nirvana/tools/logger/utils/LocalDeviceUtil.java, line(s) 14
com/nirvana/tools/logger/utils/UTSharedPreferencesHelper.java, line(s) 14,15
com/zhy/http/okhttp/builder/PostFormBuilder.java, line(s) 48

中危安全漏洞 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
com/danikula/videocache/sourcestorage/DatabaseSourceInfoStorage.java, line(s) 6,7,28
com/fenghuajueli/lib_data/entity/db/CollectionDbEntityDao.java, line(s) 4,38,42
com/fenghuajueli/lib_data/entity/db/DraftRecordEntityDao.java, line(s) 4,43,47
com/fenghuajueli/lib_data/entity/db/LocalDraftEntityDao.java, line(s) 4,41,45
com/fenghuajueli/lib_data/entity/db/VideoInfoEntityDao.java, line(s) 4,46,50
com/nirvana/tools/logger/cache/db/AbstractDatabase.java, line(s) 6,388
com/nirvana/tools/logger/cache/db/DBHelper.java, line(s) 4,5,23,24,25,34
com/ss/android/downloadlib/d/b.java, line(s) 4,5,17,22
org/greenrobot/greendao/AbstractDao.java, line(s) 6,7,117,121,143,422,556
org/greenrobot/greendao/DbUtils.java, line(s) 6,15,50
org/greenrobot/greendao/database/StandardDatabase.java, line(s) 5,15,16

中危安全漏洞 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/danikula/videocache/ProxyCacheUtils.java, line(s) 67
com/nirvana/tools/core/AppUtils.java, line(s) 115
com/nirvana/tools/core/CryptUtil.java, line(s) 198
com/nirvana/tools/logger/utils/LocalDeviceUtil.java, line(s) 21

中危安全漏洞 IP地址泄露

IP地址泄露


Files:
com/danikula/videocache/HttpProxyCacheServer.java, line(s) 29
com/ss/android/download/api/constant/BaseConstants.java, line(s) 36

中危安全漏洞 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
org/repackage/a/a/a/a/c.java, line(s) 60

中危安全漏洞 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
coil/decode/SourceImageSource.java, line(s) 135
com/luck/lib/camerax/CustomCameraView.java, line(s) 333,355,438

中危安全漏洞 应用程序包含隐私跟踪程序

此应用程序有多个2隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危安全漏洞 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
nsjV57o+phSlqM0B5aPiMScxWJmCzFRX4NKcjt6KGP+3GpzmTyrpavnYQtHasperH
67e21ee265c707471a2a69fb
9be001ea83dcc05b8e14becb4b31662f
m241VerticalCustomTabLayoutjA1GFJw
4e039acf26e97cea2441197f1febbb47
014a06685f0JVDULT/MIGfMA0GCSqGSIb3DQEBAQUAA4G
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCVc1ecjpc5k7TkabF935iQONDZ0/E5XWPVv9FEsI59XTRW0+BCMK1MODRSWMvHFrPMh9ZilnRr7qXuAKCBEynQEghmpIVvMYhFu48FAI9bKfkI5lKuQK+tc4X0+zTbNrpedNoKXK4C7dDjTETBH6prwWE9j5WsAf0gbjUbIs3FxwIDAQAB
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC/YHP9utFGOhGk7Xf5L7jOgQz5
ngZlTTem7Pjdm1V9bJgQ6iQvFHsvT+vNgJ3wAIRd+iCMXm8y96yZhD2+SH5odBYS2
nWNFqUFTkvdfESehuhtvdCWVSrD47VeznZRh38MT6kfT8VLMB/da6KNxJzmgpAgMBAAGjITAfMB0G
nAQUAA4IBDwAwggEKAoIBAQDuaeaV3A1FIgriCvG3FVGURKKeAzDSFHefT5YHbLLJPLze7EoJT1bH
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC5se07mkN71qsSJHjZ2Z0+Z+4LlLvf2sz7Md38VAa3EmAOvI7vZp3hbAxicL724ylcmisTPtZQhT/9C+25AELqy9PN9JmzKpwoVTUoJvxG4BoyT49+gGVl6s6zo1byNoHUzTfkmRfmC9MC53HvG8GwKP5xtcdptFjAIcgIR7oAWQIDAQAB
nWEN6UTlWKTERMA8GA1UEBxMIKGpCakw1aSkxGzAZBgNVBAoTEihxZHhFcXlyYmI3RlhrblB2KTEa
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6YCzxZS0FaWDOdtwgcHJ
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCLShWjAtxJv3g2VPIYOOAv4rnVDdLkdseKm7+KOkCBLV9SKY5oqksFaXcLZ+nRnjnczhze5eGKhevwliUyag6x96GyXI2WagKIoB7Uwl2byl0xB5bNvYzf+x/DKHTSoGJshU6shXWXcjGFq+mUiPhM3WGZoqdY+vvqOWD+tga8XQIDAQAB
nWTYINjEc67mzqEpf43uDcduGkg68WdCUHRmdz+HTLSb2ZZAzpu85KdhfIK7G7hQQcezfQVVQi+ey
nMTAxODA2NDk1OFoYDzIxMjQwOTI0MDY0OTU4WjB9MQ0wCwYDVQQGEwQoY24pMREwDwYDVQQIEwgo
d7ce52e6635a36873f652db14ba3cbb2
nMBgGA1UECxMRKFhGZmhqdnZnc3hRbTVaZCkxDTALBgNVBAMTBChjbikwggEiMA0GCSqGSIb3DQEB
nmJLwF0KskrHRHRb4o50LF2vmpk6mkKkLmrcjYTZGtSv2t3CPzSISHsUBX0eh5PAtJeG2klAMwIdE
nzw1ULq5ScsG4OKlhhR/NbxkqeVcL+8NFQS2ia1W8RqHjjG+LK+3pYTpO1yypOXU1wWjbi7LEhL4h
n+APJWeeIsUEJHi0FSf3EmwAtNgcJwLYed8Lrem+2+qvFY8RRjH3w4jT/wl2HKGEY
nEiuheYSC69Gv00EC5unUE/OgdbubRdpjghAxDT4rWzjTOrP4uWy34CDk9U6mZgqsH7wodDJDbRvi
nsKCn7vy/+7PLS7tqCZwj5897QVCQQvMA5HM8s9wBpvPDA5uVvKHjRitdGrsgNvAT6itTylyELIn4
MIIDnzCCAoegAwIBAgIIXR628vj40zQwDQYJKoZIhvcNAQELBQAwfTENMAsGA1UEBhMEKGNuKTER
nN0ZYa25QdikxGjAYBgNVBAsTEShYRmZoanZ2Z3N4UW01WmQpMQ0wCwYDVQQDEwQoY24pMCAXDTI0
2ae8f4f5a58aa2117aae3829d2bfc8c8
91c6301b3c2ca1dbdc7354f649fa81c9
n4aw0AoExz4atTkUlZJIf9eNLj7ogTlQGANNzE2R/uskFse2GsCqJKFTk4UraBkzf
nMA8GA1UECBMIKFhDelE5VikxETAPBgNVBAcTCChqQmpMNWkpMRswGQYDVQQKExIocWR4RXF5cmJi
43933fce63b003934f0878a46129d961

安全提示信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
bin/mt/signature/KillerApplication698.java, line(s) 155,238
cc/shinichi/library/ImagePreview.java, line(s) 413
cc/shinichi/library/glide/ImageLoader.java, line(s) 36
cc/shinichi/library/tool/common/Print.java, line(s) 18,23,29
cc/shinichi/library/tool/image/ImageUtil.java, line(s) 225,231
cc/shinichi/library/view/helper/SubsamplingScaleImageViewDragClose.java, line(s) 1534,1904,1970,1974,2031,2035,577,689,1261,1270,1296,1305,2207
com/caverock/androidsvg/CSSParser.java, line(s) 991,360
com/caverock/androidsvg/SVG.java, line(s) 341
com/caverock/androidsvg/SVGAndroidRenderer.java, line(s) 111,344,1294,167,172,340
com/caverock/androidsvg/SVGImageView.java, line(s) 113,120,146,164,186,216
com/caverock/androidsvg/SVGParser.java, line(s) 609,633,653,949,523,638,2917,2953,2970
com/caverock/androidsvg/SimpleAssetResolver.java, line(s) 40,54,69
com/danikula/videocache/Logger.java, line(s) 15,33,21,27
com/davemorrissey/labs/subscaleview/SubsamplingScaleImageView.java, line(s) 1805,1210,1310,1314,1391,1395,579,693,1485,1494,1520,1529,2208
com/davemorrissey/labs/subscaleview/decoder/SkiaPooledImageRegionDecoder.java, line(s) 377
com/example/module_ui_compose/net/model/WallPaperModel$getMaintype$1.java, line(s) 43
com/example/module_ui_compose/net/model/WallPaperModel$getSpecificSubtype$1.java, line(s) 46
com/example/module_ui_compose/net/model/WallPaperModel$getSpecifictype$1.java, line(s) 45
com/example/module_ui_compose/widget/SwipeItemLayout.java, line(s) 436
com/fenghuajueli/lib_data/entity/db/DaoMaster.java, line(s) 63,78
com/fj/gong_kao/utils/ImageGetterUtils.java, line(s) 71,72,80,81
com/fj/gong_kao/view/SeekArc.java, line(s) 117
com/fwlst/lib_ad/AdUtils.java, line(s) 313,366,414,566,590,395,400,459,464
com/fwlst/lib_ad/common/InitKSSDKUtils.java, line(s) 22,26
com/fwlst/lib_ad/common/SelectCsjChannelUtils.java, line(s) 56,62,76,81,86,41,43,107,193,201,226,284,289,308,423,503,507,511,516,535,542,546,550,555,574,591,600,618,673
com/fwlst/lib_ad/common/SelectKsChannelUtils.java, line(s) 48,55,59,64,69,73,78,82,86,108,113,120,124,128,132,136,162,166,174,192,196,200,204,208,212,224,229,236,240,244,248,252,278,286,294,312,316,325,329,337,345,353,361,365,373,377,392,400,411,415,419,423,427,431,435,439,444,455,460,467,471,475,479,483,508,513,520,524,528,532,536,32
com/fwlst/lib_base/utils/AesUtils.java, line(s) 72
com/fwlst/module_setting/activity/filing/ModuleFilingActivity.java, line(s) 50,56,61,70,76
com/fwlst/module_user/activity/ModuleUserMemberCenterActivity.java, line(s) 775,785
com/fwlst/module_user/util/UserFileOperations.java, line(s) 21,31,74
com/hjq/toast/ToastLogInterceptor.java, line(s) 38
com/ijianji/module_play_video/activity/FullScreenActivity.java, line(s) 57
com/ijj/tookit/file/IFileUtils.java, line(s) 107,147,136,266,309
com/ijj/tookit/file/MediaExt.java, line(s) 283,318,130,218,239,256,268,44,65,108
com/kongzue/dialogx/DialogX.java, line(s) 79
com/kongzue/dialogx/interfaces/BaseDialog.java, line(s) 143,137
com/kongzue/dialogx/util/views/BlurView.java, line(s) 662,656
com/kongzue/dialogx/util/views/DialogXBaseRelativeLayout.java, line(s) 533
com/kwai/library/ipneigh/KwaiIpNeigh.java, line(s) 39,42
com/nirvana/tools/core/EncryptUtils.java, line(s) 54,105
com/nirvana/tools/core/NetworkUtils.java, line(s) 30,43,66
com/nirvana/tools/logger/cache/db/AbstractDatabase.java, line(s) 33
com/nirvana/tools/logger/cache/db/DBHelper.java, line(s) 27,37
com/nirvana/tools/logger/utils/ConsoleLogUtils.java, line(s) 14,20,26,32,38
com/permissionx/guolindev/request/InvisibleFragment.java, line(s) 905
com/ss/android/downloadlib/g/l.java, line(s) 26,36
com/tbruyelle/rxpermissions2/RxPermissionsFragment.java, line(s) 86,43
com/uyumao/c.java, line(s) 26,22
com/uyumao/e.java, line(s) 241,289,694
com/yalantis/ucrop/UCropActivity.java, line(s) 176
com/yalantis/ucrop/task/BitmapCropTask.java, line(s) 197,132
com/yalantis/ucrop/task/BitmapLoadTask.java, line(s) 130,152,91,94,136,143
com/yalantis/ucrop/util/BitmapLoadUtils.java, line(s) 195,53,135,137,174
com/yalantis/ucrop/util/EglUtils.java, line(s) 23
com/yalantis/ucrop/util/FileUtils.java, line(s) 163
com/yalantis/ucrop/util/ImageHeaderParser.java, line(s) 57,64,75,83,115,125,137,151,165,171,175,180,186,190,281,287,300,307,314,327,340,347,354,56,63,74,82,114,124,136,150,164,170,174,179,185,189
com/yalantis/ucrop/view/TransformImageView.java, line(s) 265,282,158,83
com/zhy/http/okhttp/cookie/store/PersistentCookieStore.java, line(s) 142,151,154
com/zhy/http/okhttp/log/LoggerInterceptor.java, line(s) 40,42,43,44,46,49,52,55,57,68,69,70,72,76,78,80,83
com/zhy/http/okhttp/utils/L.java, line(s) 10
org/greenrobot/eventbus/Logger.java, line(s) 32,37
org/greenrobot/greendao/AbstractDao.java, line(s) 281,681
org/greenrobot/greendao/DaoException.java, line(s) 28,29
org/greenrobot/greendao/DaoLog.java, line(s) 35,39,67,15,43,47,27,31,51,55,59,63
org/greenrobot/greendao/DbUtils.java, line(s) 88,30
org/greenrobot/greendao/async/AsyncOperationExecutor.java, line(s) 175,193,195,135
org/greenrobot/greendao/internal/LongHashMap.java, line(s) 132
org/greenrobot/greendao/query/QueryBuilder.java, line(s) 237,240
org/greenrobot/greendao/test/AbstractDaoTest.java, line(s) 55,57,47
org/greenrobot/greendao/test/AbstractDaoTestLongPk.java, line(s) 32,35
org/greenrobot/greendao/test/AbstractDaoTestSinglePk.java, line(s) 300
org/greenrobot/greendao/test/DbTest.java, line(s) 84
top/zibin/luban/Luban.java, line(s) 87,86
top/zibin/luban/LubanUtils.java, line(s) 66
top/zibin/luban/io/LruArrayPool.java, line(s) 86,124,87,125
xyz/doikki/videoplayer/util/L.java, line(s) 15,21,27,33

安全提示信息 此应用程序使用SQL Cipher。SQLCipher为sqlite数据库文件提供256位AES加密

此应用程序使用SQL Cipher。SQLCipher为sqlite数据库文件提供256位AES加密


Files:
org/greenrobot/greendao/database/SqlCipherEncryptedHelper.java, line(s) 15,4,5

已通过安全项 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/example/module_ui_compose/net/RetrofitClient.java, line(s) 27,27
com/fenghuajueli/lib_net/common/RetrofitUtils.java, line(s) 86,86,38,44
com/fj/gong_kao/baseurl/GongRequest.java, line(s) 17,17
com/uyumao/k.java, line(s) 38,36
com/zhy/http/okhttp/https/HttpsUtils.java, line(s) 107,166,42,106,127,165,95,105,105,164,164

综合安全基线评分总结

应用图标

公务员之家 v1.0.1

Android APK
44
综合安全评分
中风险