I intercepted the communications made by the Huawei P20 and this is not good...
-
-
Show this thread
-
The phone sends a request to all these websites. The 1st observation, we can do is that almost all communications are unencrypted.pic.twitter.com/vAox6KGdAF
Show this thread -
This request to the subdomain http://track.uc.com to the endpoint collect seems interestingpic.twitter.com/sHWQyAy4L2
Show this thread -
In this request, the phone is sending - your country - your province - your city - phone locale - the website you requested (here http://google.com )pic.twitter.com/ks5yUWxFpp
Show this thread -
They didn't enforce the strict transport security aka http://track.uc.com is working... pic.twitter.com/17i1oA2dwP
Show this thread -
This domain is the property of UCWeb Inc. the company behind the UC Browserpic.twitter.com/VDeDlMZLNy
Show this thread -
-
It sending a lot of thing I cannot read for now, I need to find the corresponding code.pic.twitter.com/05STxd7lph
Show this thread -
If you open http://myhwclouds.com/ with chrome, you will have a warningpic.twitter.com/OcH5ostalK
Show this thread -
This endpoint is part of the Huawei Cloud from the "Object Storage Service" familypic.twitter.com/PieC4mf5WA
Show this thread -
-
Reminder: I didn't use the phone, these requests are done without any user interactions
Show this thread -
According to virustotal, 8.37.232.1 is a subdomain of http://ucweb.com which the property of MILEWEB, INCpic.twitter.com/n3Udtr4QWe
Show this thread -
Wow this is the number of requests done when I did airplane mode on/off!pic.twitter.com/xQsAEAVwJL
Show this thread -
There is a lot of thing to find in this phone but now I need to sleep . End of the episode 2, see you for the episode 3!
Show this thread
End of conversation
New conversation -
-
-
Where's the thread for Episode 1?
- End of conversation
New conversation -
-
-
@threader_app compile -
Hey, the thread is ready and compiled. You can read the whole version here:https://threader.app/thread/1051568180748013569 …
End of conversation
New conversation -
-
-
let‘s build a spammer which spams that endpoint lel
- End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.