Q
Q
Quolib2018-02-05 21:17:37
Android
Quolib, 2018-02-05 21:17:37

Can you explain in more detail how the android CVE-2017-13156 vulnerability works?

I found out about this vulnerability and decided to try it on my phone. I changed the classes.dex file in the apk to my own, tried to update the previously installed application, it was not installed. Anroid 6.0.1 is installed, which falls under this vulnerability, but to be honest, I don’t know, I have a xaomi phone, and as I read MIUI a little, it’s a modified anroid, that is, in theory, because of MIUI 8.5.7.0, I may not work this vulnerability, so how did they fix it? Is it so? I just do not know why this vulnerability does not work for me, mb because of this. So, an article about the vulnerability (maybe you will understand better) https://m.habrahabr.ru/post/344354/ Actually, I'm just interested in a specific action plan for this vulnerability to work, create classes.dex by type, replace the original one and install.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
Q
Quolib, 2018-02-06
@Quolib

It didn’t work, because I did it fundamentally wrong, https://github.com/xyzAsian/Janus-CVE-2017-13156 here you can install everything and do everything purely intuitively, and no, MIUI did not affect the fact that that the vulnerability works on my phone.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question