Skip to main content

Xiaomi Is Vulnerable - Automatic App Installation

Xioami back-door detected where it can install Any App


Xiaomi which is also known by name MI a china based company founded in 2010 and getting biggest brand in couples of year. Xiaomi is famous for their cheap smartphones with better hardware. They are now a 4th largest smartphone making company in the world.

Xiaomi expected to launch their new smartphone Mi 5 on September 27. Which will come with some new features better camera update etc.

As Xiaomi going to launched their new phone in this month a news certainly spread everywhere that it xiaomi can download any app in your smartphone without any permission automatically

Thijs Broenink, a Computer Science student from Netherlands. He spell out that Xiaomi’s AnalyticsCore.apk constanly running on the background of smartphone and it's still go on even if you delete it from the smartphone.

Broenink research those codes and found that the app which checks for updates from Xiaomi every 24 hours, and sends all kinds of information to Xiaomi’s servers. This app also automatically installs the update from Xiaomi’s servers, if it finds it there, the update’s file is named ‘Analytics.apk

So these updates will install automatically in your android device without your permission which is so much weird about this phone


What Xiaomi say about this

"AnalyticsCore is a built-in MIUI system component that is used by MIUI components for the purpose of data analysis to help improve user experience, such as MIUI Error Analytics. As a security measure, MIUI checks the signature of the Analytics app during installation or upgrade to ensure that only the APK with the official and correct signature will be installed. Any APK without an official signature will fail to install. As AnalyticsCore is key to ensuring better user experience, it supports a self-upgrade feature. Starting from MIUI V7.3 released in April/May, HTTPS was enabled to further secure data transfer, to prevent any man-in-the-middle attacks."

Comments

Popular posts from this blog

Install Social Engineering Toolkit on (Windows)

                 Social Engineering Toolkit on (Windows)   Social engineering Toolkit is used by penetration tester for ethical hacking.Social engineering toolkit is a design to perform the advance attacks Attacks like  : 1.spare-phishing attack vector                                                2.fast-track penetration attacks                                                                              3.website attack vector                            4.Infectious USB/Cd/DVD generator                                                                                   5.Mass mailer attack    Social engineering toolkit is a  pre-installed in some platform like backtrack, kali linux etc.These platform are Linux-distribution aimed for penetration testing and  used in digital forensic.    Social engineering toolkit Installing Toolkit in windows 1.To install social networking on your windows you first need to download Python and install it on your wind

New Iphone let's You To Send/Read Whatsapp Messages From Siri command - Feature Leaked

A leaked Whatsapp  translation request showed the feature News Compressed :   The leaked whatsapp translation reveal a new feature in iphone siri voice.  Soon you can make an command on your iphone for sending/reading whastapp messages using siri voice, this feature will be available on ios 10 which expected to release on September. Iphone the world most selling phone not because of it's features&look but it just because of a rumor that makes iphone user a rich look.  Siri is a feature of iphone first integrated on iphone ios 5  and become famous worldwide. Iphone company apple likes to give their user surprises. This time a leaked whatsapp translation reveal this new feature of Siri voice commands for sending and reading messages, apart from making voice calls.  that will available on ios 10 which will release on september Before go more further first  let's see what is Siri Siri is a computer program that works as an intelligent personal ass

About Reliance Jio

How's guys we are back again and this time will talk about a company whos back with his new free unlimited internet sim. Yes, Reliance company is back with his sim reliances jio which become world famous in couples of day and make around  billions of sim customers worldwide. Reliance increases their customers by providing free 3 month unlimited 4G internet sim and it's happen quite same. Jio Jio, also known as Reliance Jio, is a Mumbai-based provider of 4G internet, mobile telephony, broadband services, anddigital services in  India (wiki) The reliance was first provide free jio sim to limited mobile user but now Samsung, LYF, micromax, HTC, Lenovo, SONY, Intex, Vivo, LAVA, Panasonic, Gionee, ASUS, Moto, XoLo, Karbonn, LG, Infocus, Huawei, Videocon, Celkon, Sansui, Alcatel, TCL Smartphones , can also take that sim for free