Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
http://oclean.com | product |
https://play.google.com/store/apps/details?id=com.yunding.noopsychebrushforeign | product |
https://github.com/c3r34lk1ll3r/decrypt-oclean-traffic | third party advisory exploit |