[Q] whatsapp - Security Discussion

I have an android with whatsapp installed,
I use the internet (wifi) from my work, and it has a proxy.
I would like to know, if the person responsable for the network here from my work, can see my messages, video or audio, because I already sent banking passwords.
Thank you.

Its probably no. . .
WhatsApp is more secure than you think. .
a person who didn't make mistake never tried new things. . ." - Albert Einstein

jeevan93 said:
Its probably no. . .
WhatsApp is more secure than you think. .
a person who didn't make mistake never tried new things. . ." - Albert Einstein
Click to expand...
Click to collapse
Thank you.

thats absolutely no my friend
because wifi is more privasi and separately from main network connection

rodpat said:
I have an android with whatsapp installed,
I use the internet (wifi) from my work, and it has a proxy.
I would like to know, if the person responsable for the network here from my work, can see my messages, video or audio, because I already sent banking passwords.
Thank you.
Click to expand...
Click to collapse
DAFUQ? Why do you even send BANKING PASSWORDS via WhatsApp? The way I see it, WhatsApp is following the "security through absurity"-habit. Everybody thinks its secure, but where is proof of that? You should work in your security habits.

nice

rodpat said:
I would like to know, if the person responsable for the network here from my work, can see my messages, video or audio, because I already sent banking passwords.
Click to expand...
Click to collapse
According to SecUpwN, probably is better if you don't send any password trought WHATSAPP.
Anyway, the "person responsable for the network" probably not care about your password, and even more probably he would not be able to retrieve it, thank god the WA conversation are no longer in plaintext.
However the WA guys were not always so security conscious.. .an example: http://pastebin.com/g9UPuviz

Related

intercept text messages? or sniff packets sent by phones?

Is there a app that sniff packets sent by cell phones, my whole goal would be to intercept text messages or the data thats sent by cell phones. I came up with this idea when I was messing around with packet sniffer and thought about the idea but on cell phones. Is there something already out like this?
Wireshark at a "router"
While not an on-device solution, I use this setup when I want to watch the traffic between my phone and the network:
"sorry, apparently I can't post a link to this forum, it's at my site droidhacks.com, click on the wireshark tag in the sidebar and you'll find the post"
Having a full Wireshark install running on the desktop is great for poking through the data. I think some folks do the capture on the device and then just move the capture file across. Also helps sometimes to pull the SIM to make sure all the traffic goes through the laptop and not through the network. Sharing on OS X with an handset can be a bit fidgety when first starting up.
Find shark for android and sharkreader. Both of which can be found in this forum.
Sent from my Nexus One using XDA App
can this be countermanded? stoped, disabled somehow? encrypted packets? someone's safety could be at risk.
Are you looking to capture the communications of other phones, rather than your own? If so, good luck, it's encrypted traffic.
Sounds pretty stupid and no, it is not possible. I would rather want a network sniffer for android. Connect to your local coffee shop network and start sniffing.
rTiGd2 said:
Are you looking to capture the communications of other phones, rather than your own? If so, good luck, it's encrypted traffic.
Click to expand...
Click to collapse
no, i'm just curious how this can be done.
if its encrypted how can you read the packets with your program then ?
some kind of id or serial number?
tmpmailone said:
no, i'm just curious how this can be done.
if its encrypted how can you read the packets with your program then ?
some kind of id or serial number?
Click to expand...
Click to collapse
Ok, I think we need a rather large dose of reality here. You'll not manage it, simple as that, certainly not from a consumer device. I suspect you are thinking along the line of WiFi wireless, where you can monitor what other devices are sending. If you really wish to know more then google 'usrp' and you'll soon see you'll need far more hardware and software to start capturing GSM traffic.
ok so you're saying with my router i can't capture my text messages, like those sent and received with the YMesenger app ?
so its possible to sniff datalines?
tmpmailone said:
ok so you're saying with my router i can't capture my text messages, like those sent and received with the YMesenger app ?
so its possible to sniff datalines?
Click to expand...
Click to collapse
Yes, it's possibly to sniff datalines, as well as WiFi.
I think you should break out with you gf
this thread is too funny ( lol )
encryption - lol
cant sniff - lmao!!
link1
I am a network security specialist and you people are just too funny saying "cant" "impossible" "illegal" .. .. ..
morning_wood said:
link1
Click to expand...
Click to collapse
Nice info.
Packet sniffing over public wifi is well known, but I learnt something new today
Chris Paget hapens to be a personal friend of mine
I'm pretty sure intercepting phone calls would still be "illegal", regardless of the fact that you're a network security specialist.
But yes, nothing is impossible, that's pretty much a given. Give someone enough expertise and resources, anything can be hacked. Encryption is actually important, so the general, uninformed riff-raff can't access anything they want. Like my previous statement, it can still be hacked, but it's better that not being encrypted at all.
morning_wood said:
this thread is too funny ( lol )
encryption - lol
cant sniff - lmao!!
link1
I am a network security specialist and you people are just too funny saying "cant" "impossible" "illegal" .. .. ..
Click to expand...
Click to collapse
So, my ex husband is using a packet sniffer to read all of my info that I txt over my phone. He is living with me until he closes on his new house (30 days out). I have installed a VPN on my phone. What else do I need to do? He says he can see all messages that I send, both txt and messenger as well as my calls?? He is a programmer, so I know he knows what he’s doing, how can I get my privacy back? I’m afraid that he will always be spying on me and it’s very frustrating.
Sunshine08 said:
So, my ex husband is using a packet sniffer to read all of my info that I txt over my phone. He is living with me until he closes on his new house (30 days out). I have installed a VPN on my phone. What else do I need to do? He says he can see all messages that I send, both txt and messenger as well as my calls?? He is a programmer, so I know he knows what he’s doing, how can I get my privacy back? I’m afraid that he will always be spying on me and it’s very frustrating.
Click to expand...
Click to collapse
Do you use Google Messages app for text messages? If so check if it is connected to Messages for web. Also if you use Whatsapp check if it is connected to Whatsapp web. I recommend to change password for all the services, Google, Facebook and so on and reset the phone to factory defaults. I don't think this has anything to do with packet sniffing.

[App] RemotifyMyDroid (my 3rd FREE app)

Hello Everyone,
i've finish working on my application RemotifyMyDroid, and uploaded it to the market place toy can download:
https://market.android.com/details?id=com.yazan.remotifyMyDroid&feature=more_from_developer
it sends notifications to your PC, when you got event on your mobile,
best case when you are charging your mobile in a room, and setting in another..
however you can use it in different purposes ...
the phone and the PC should be on the same LAN,
in future i may upgrade it to work over the internet ...
it notifies for those events:
1- Incoming Call (shows the caller number to)
2- Outgoing Call (someone using your mobile to call a number)
3- Your mobile is fully charged (in case you were charging it)
4- Someone unplugged the power of the charger.
5- New Incoming SMS.
to download the PC server
http://www.yazandroid.com/
and go to RemotifyMyDroid (1st link) and it contains some screen shots to.
also have a look at my other FREE 2 applications there
your feedback is appreciated
Yazan.
Sounds great, but I think setting this up might be a tad harsh for general use (firewalls etc). I would suggest building an intermediary platform (web service) to communicate to. That way you can have a very easy setup. For instance, you can use the Google login service to identify yourself from the phone and the notification program and that's it then. No IP's or port numbers as most users don't know what that is anyway.
But for the techies, good start.
Cheers
bra1nDeaD said:
Sounds great, but I think setting this up might be a tad harsh for general use (firewalls etc). I would suggest building an intermediary platform (web service) to communicate to. That way you can have a very easy setup. For instance, you can use the Google login service to identify yourself from the phone and the notification program and that's it then. No IP's or port numbers as most users don't know what that is anyway.
But for the techies, good start.
Cheers
Click to expand...
Click to collapse
good point, and that what i was afraid about in the first place
i am planning to take this to the internet as a next step, i will be doing that soon
thanks bra1nDeaD
stinger1 said:
good point, and that what i was afraid about in the first place
i am planning to take this to the internet as a next step, i will be doing that soon
thanks bra1nDeaD
Click to expand...
Click to collapse
No problem
Portal pending. Nice app
I will use this when it's possible to use it via the web. Maybe a Chrome/FireFox/IE plugin would be cool?
Really nice idea!
Another suggestion : an honeycomb client
let us be notified about our phone when it's away and we're using our favorite tablet
I'm sorry to have to say this, but I think you may have wasted your time:
http://code.google.com/p/android-notifier/
Timmmmmm said:
I'm sorry to have to say this, but I think you may have wasted your time:
[Link]
Click to expand...
Click to collapse
What a great find... The integration with Growl will be excellent on my HTPC. Also, this allows easy integration with EventGhost through Scripty.
just installed. works fine.
Any chance on a open source version, i would like to see how you did this. an maybe use some of the code in a Domotica project of mine.
Hey another MightyText. At least I can use this one lol.\
Timmmmmm said:
I'm sorry to have to say this, but I think you may have wasted your time:
http://code.google.com/p/android-notifier/
Click to expand...
Click to collapse
Have you ever heard of...dare I say it...variation of ideas? Just because there is something similar out there, does not mean it is identical. Please do not spam dev's threads with others work.
he's right though, there is google voice add on for chrome that does this, mighty text, and that last one he mentioned.
Timmmmmm I'm sorry to have to say this, but I think you may have wasted your time:
http://code.google.com/p/android-notifier/
Click to expand...
Click to collapse
its not a waste of time, and for sure i have learned couple of things while developing this app, its not a waste at all.
otherwise you will see a single app for each purpose ... on pc\mobile ...
one more thing .. why do you think there is Windows , Linux and Mac??
could not other parties just SAVE there time and NOT develop another OS!!!!
Any chance on a open source version, i would like to see how you did this. an maybe use some of the code in a Domotica project of mine.
Click to expand...
Click to collapse
for now i am not planning to open source any of my work,
sorry
Really nice idea!
Another suggestion : an honeycomb client
let us be notified about our phone when it's away and we're using our favorite tablet
Click to expand...
Click to collapse
this was on the list next
with this to
I will use this when it's possible to use it via the web. Maybe a Chrome/FireFox/IE plugin would be cool?
Click to expand...
Click to collapse
still thinking which one will go first,
thanks all
Hey, didn't try it yet but I have some suggestions, in addition to a web service:
reply to sms / transfer calls to PC
low battery event
as an option, deliver every notification from notification bar (alarms, songs played, ebay auctions ending, FB msgs, etc.)
cheers
Mac version would be awesome .
Hey, didn't try it yet but I have some suggestions, in addition to a web service:
reply to sms / transfer calls to PC
low battery event
as an option, deliver every notification from notification bar (alarms, songs played, ebay auctions ending, FB msgs, etc.)
cheers
Click to expand...
Click to collapse
hey lastnikita, thx for suggestions,
i will be working on such updates,
but regarding the call forwarding to PC as far as i know you can't do it as the call is protected by the OS. it has limitations...
Mac version would be awesome .
Click to expand...
Click to collapse
hey Bomster,
there is a MAC version...
not tested yet, i don't have a MAC, please if you try and send us a feed back, that will be great
cheers
thanks,
stinger1 said:
but regarding the call forwarding to PC as far as i know you can't do it as the call is protected by the OS. it has limitations...
Click to expand...
Click to collapse
Using bluetooth maybe ? PC as a handset (would have to be paired before)
I understand then distance range would come as a limit for many use cases, but could still be enjoyable instead of standing up to pick up the phone !
lastnikita said:
Using bluetooth maybe ? PC as a handset (would have to be paired before)
I understand then distance range would come as a limit for many use cases, but could still be enjoyable instead of standing up to pick up the phone !
Click to expand...
Click to collapse
that looks fine
now we have along list to start with lol
cheers

WhatsApp Sniffer issue

Hi guys,
I downloaded WhatsApp Sniffer in my HTC Desire, it seems to be working but can't capture any conversation. In short, when I start the app, I can only see the following message:
"There isnn't any conversations yet, wait until one has been captured. Make sure WhatsAppSniffer is listening and if you are on a WPA/WPA2 network, check that the ARP_Spoof is activated."
I've tried the app in both WEP and WPA/WPA2 networks but no luck. My phone is rooted with:
Android version: 2.3.7
Mod Version: CyanogenMod-7-11162011-NIGHTLY-Desire
WhatsApp Messenger: 2.7.8509
Any clues what might be the reason?
Thx,
Sotiris.
I thought Whats App was now fixed so that it did not send plain text.
Hmm, I am not aware of it. But it makes sense... Thx for your reply.
if your network is secured with Wpa or wpa2
the chat will not be captured
to capture chat the network must be protected with wep
or it need to be unsecured
Pl provide link to download
alinawaz said:
Pl provide link to download
Click to expand...
Click to collapse
can someone send me (PM me) a working link to whatsapp sniffer, please?!
https://docs.google.com/open?id=0B_PzeJyBdcp3UW5GOVZlOTZKYVU - google drive link cause i dont use any other servers
pransh said:
https://docs.google.com/open?id=0B_PzeJyBdcp3UW5GOVZlOTZKYVU - google drive link cause i dont use any other servers
Click to expand...
Click to collapse
thank you!
Hello all am new @ this site, awesome site... am using whatsapp sniffer or @ least am trying too...
my issue is that @ times it says that ( my devise seem not to be rooted ), I have rooted phone i do have the superuser icon... samsung GS3
and i restart the app, and it runs ok, but it don't capture anything... am i doing something wrong??? i do see that it will not
capture anything in wap or wap2...
any help will be appreciated
bumping because it seems that this app doesnt work (anymore)
anyone confirming?
Hi.
I'm also wondering the same thing. Just went through the fairly painful process of downgrading my HTC Desire Z Gingerbread to Froyo in order to then gain root, specifically so that I could use WhatsAppSniffer.
The app seems to have installed correctly, it's running fine, the other apps like SuperUser and BusyBox have no problems. I've run the sniffer for several hours on my shared WPA network at home, and for a couple of hours on a shared Open network last night with no results. It could very easily be the case that there were no conversations to capture, but the other possibility is that WhatsApp have fixed the vulnerability. I'm going to keep trying for a couple more days, and on one more network connection. Will confirm if whether or not I get anything here.
Just reading a couple of open-source articles it seems that WhatsApp pushed release 2.8.3 to iPhones on 27th August 2012, and a similar release to Androids around the same time. This release included (relatively poor) encryption. Anyone who has downloaded the update will now be protected from WhatsAppSniffer. Seems that sniffing is still possible if you can fathom this: ezioamodio.it/?p=29. It's beyond me though. #noob
I tried yesterday found on web the versione 1.03 donate root,
also for myself it seems doens't work,
the spoof says that if I'm scanning a WPA/WPA2 network I have to activated the ARP Spoof, otherwise for WEP it doens't need.
But I supposed it worked in one of the two cases, instead the app continue to search but see nothing.
I tried to send a whatsapp message connecting to the same network that sniffer is connecting too, and it see even not my message.
Is it an older version that doesn't work or maybe it needs a rooted phone and mine one is not?
THANKS
pransh said:
https://docs.google.com/open?id=0B_PzeJyBdcp3UW5GOVZlOTZKYVU - google drive link cause i dont use any other servers
Click to expand...
Click to collapse
Google removed it, can you give another link?
FardeenTGO said:
Google removed it, can you give another link?[/QU
same here too
Click to expand...
Click to collapse

Best practice when using Android Messages on work laptop?

How should this be done properly? Proxy or ?
I'm not sure if it even matters, but I hate to have inappropriate messages coming in while I'm on my work's network or their VPN when remote... I'm thinking a proxy may mess with the VPN?
Inb4 don't text at work
Texting with AM is much more productive than stopping everything to unlock my phone and give it attention. Don't judge me
typhoonikan said:
How should this be done properly? Proxy or ?
I'm not sure if it even matters, but I hate to have inappropriate messages coming in while I'm on my work's network or their VPN when remote... I'm thinking a proxy may mess with the VPN?
Inb4 don't text at work
Texting with AM is much more productive than stopping everything to unlock my phone and give it attention. Don't judge me
Click to expand...
Click to collapse
If your worries about such messages at work use a VPN whilst at work so no one can read the data. Only problem is if they have RAT's running you can't bypass them. They will be able to directly view your screen.
Also you're posting on a forum. Every man and his dog will judge you

Whatsapp Suddenly asking for Phone permission...

My Whatsapp is popping up with this notification when I try to make or receive a Video Call...
"To make and receive calls on WhatsApp, WhatsApp needs to know whether you are on an active call so that you carrier calls are not disturbed"
It wants me to grant permission to the 'Phone'. Are you all just agreeing to this? I do not need the functionality, so why must I grant the permission? I couldn't care a toss is a carrier call is disturbed by a Whatsapp call.
My Wife's phone is on the same version (2.22.14.74) and has not requested this update.
Get this junkware off the phone... I will not install any social media apps. They are a multifaceted security issue.
blackhawk said:
Get this junkware off the phone... I will not install any social media apps. They are a multifaceted security issue.
Click to expand...
Click to collapse
What do you use for messaging please?
christianbeccy said:
What do you use for messaging please?
Click to expand...
Click to collapse
Samsung Messages, SMS only people I know.
blackhawk said:
Get this junkware off the phone... I will not install any social media apps. They are a multifaceted security issue.
Click to expand...
Click to collapse
Whatsapp is not social media app. It's communication app.
Dayuser said:
Whatsapp is not social media app. It's communication app.
Click to expand...
Click to collapse
It's reputation precedes it... nothing but trouble.
It has a lot of users, hence a huge bullseye on it.
WhatsApp is what it is.
blackhawk said:
It's reputation precedes it... nothing but trouble.
It has a lot of users, hence a huge bullseye on it.
WhatsApp is what it is.
Click to expand...
Click to collapse
Old post I stumbled upon. While I dont disagree with you, the "article" you linked is a complete joke. An6 kind of point you are trying to make is undermined by this. It made me throw up a bit in my mouth if Im being truthful.
My unsolicited advice is to stop being intelectually dishonest. The wild part here, is that you're... right. Wild.

Categories

Resources