[CLOSED] Can a webview bypass a FRP lock? - Samsung Galaxy S7 Questions and Answers

I'm having a little trouble with an FPR.
I followed the RealTerm solution only to find out "Scan business card" which takes me to samsung's app store was removed and all external links are denied by "Security policy forbids yada yada".
However, I was able to worm my way into a webview. (No url bar btw)
I can go to RootJunky's bypass.apk located in his site however, it can't download.
I have a way to explore the internet, but I'm running out of ideas considering you can't remotely download apps on a device that you aren't logged into.
Does anyone have any bright ideas?
Edit: I was also thinking about handlers like intent://searchapp.goo.gl
If I could somehow create a hotlink to samsung apps, I think I could get away with it if it's not forbidden.
Does anyone know the handler for Samsung's playstore?
I could go right on this thread and click it if turned into a url handler if anyone has a clue

Why don't you log back into the phone with the account it is locked to?

nerdblaster said:
I'm having a little trouble with an FPR.
I followed the RealTerm solution only to find out "Scan business card" which takes me to samsung's app store was removed and all external links are denied by "Security policy forbids yada yada".
However, I was able to worm my way into a webview. (No url bar btw)
I can go to RootJunky's bypass.apk located in his site however, it can't download.
I have a way to explore the internet, but I'm running out of ideas considering you can't remotely download apps on a device that you aren't logged into.
Does anyone have any bright ideas?
Edit: I was also thinking about handlers like intent://searchapp.goo.gl
If I could somehow create a hotlink to samsung apps, I think I could get away with it if it's not forbidden.
Does anyone know the handler for Samsung's playstore?
I could go right on this thread and click it if turned into a url handler if anyone has a clue
Click to expand...
Click to collapse
OK so this phone obviously does not belong to you. I really couldn't care less how you obtained it so no need to try and defend yourself on the action. However, is clear the device was either lost or stolen otherwise you could unlock it yourself.
With that being said, we do not allow discussion that pertains to circumventing the security feature in place to protect the rightful owner of the phone. I suggest you put the phone back in the lost and found or turn into the carrier that it came from.
Thread Closed

Related

If you want Google to let you to remove apps from your market account tell them

I have seen a lot of people with the same issue I have. I download an app from the market, and it sucks so I uninstall... but now It's tied to my account forever.
When I flash, or get a new device, I like to use the web based market to re-install my apps. But I have pages and pages of apps I will never use again.
I proposed the following to Google to fix this.
If you agree that this is a good idea and would like to see this feature.. or if you have a better idea, please let Google know. They will only change this stuff if enough people request it to be changed.
I submitted a request here:
https://support.google.com/androidm...tact_type=market_phone_tablet_web&paginated=1
This was my request:
There needs to be a way to remove unused applications from our market accounts. I have many applications that I tried, dont like, and will never install again. Every time I get a new device or do a factory reset, I have to search through tons of unwanted applications just to find the apps I'd actually like to install. I understand giving the user the ability to delete apps that were paid for and the possibility of accidental deletions can become a support nightmare. To solve this I’d like to propose an “Archived Apps” section. Users can Archive applications they do not use. The application is then moved into a special Archive section where it can remain tied to the users account without being “In the Way”. Applications in the Archive section should have a “Restore” (button rather than install) that when pressed, would move it back to the users regular account and become active and installable again. When searching in the market mobile app, these apps will also show with the status Archived rather than purchased or installed. Selecting the app will give the option to “Restore” it to your active applications at which point it can be installed.
i actually have an open ticket with them regarding this problem
google tech support says it's a known issue, and they have no way to fix it yet.
AllGamer said:
i actually have an open ticket with them regarding this problem
google tech support says it's a known issue, and they have no way to fix it yet.
Click to expand...
Click to collapse
Awesome!
It's a lot of work for them to fix, and my concern is that it wont be on the radar unless it's highly requested.
Same thing with Amazon's store. I chatted with a rep, and they said there was no way to remove them, but they are aware people are interested in doing this.

[Q] How can I test an .apk to see if it's "safe" to install?

Hi,
Sometimes an app (.apk) is either simply not available through Google's store, or it might say "not compatible with your device", etc. There can be various reasons why a person might download a .apk from somewhere other than a "trusted" source.
If this was a file for my PC I could test it in a "sandbox", and I could scan it with both Microsoft Security Essentials and Malware Bytes Antimalware.
On my Android phone(s) I'm not aware of something like the "sandbox" option, and I don't really want to run an "antivirus" program on my phone. Is there an easy way to scan .apk files on the PC to see if they are rogue apps, might send SMS, "phone home", or otherwise mess with other applications or the system software installed on my phone?
Lets give another example: say I thought 15 minutes was not long enough to evaluate a relatively expensive Android game (it certainly isn't!) and I want to test it out first. Let's assume my only option in that case might be an illegally downloaded copy from unknown sources. Of course, we shouldn't do that. But if we did, how could we know if the file is safe and not risk installing some Chinese spyware?
About Android AV programs: anybody know how effective they are? Do some defend against "trojans" - I would think these days trojans are 99% of problems and viruses mostly a relic of the past?
My biggest concern is actually just unwanted crap that runs in the background which eats up battery, makes my phone warm (which I hate), or, perhaps even sends SMS message [this would be even worse because I don't have a text message plan].
EDIT: I see web pages with tiles like "new study finds Android antivirus apps not effective" and articles like this one: http://www.zdnet.com/blog/hardware/...bouncer-does-it-offer-enough-protection/17981
Do we have an easy way to boot Galaxy S3 off of "external" SDCARD instead of internal memory?
Search play store for avast antivirus, completely free, updates daily and works really well (firewall. Anti theft. And many more Features
sony xperia ray ics 4.0.4
stock rom unrooted
I found this website, maybe it can help someone.
h t t p://scan.netqin.com/en/
Maybe someone can post another one...
an easy way to check for safe apk
The easiest way to check for safe apk is to have one gmail account and another "whatever" email account. Then just send the apk from the gmail one to the second account, gmail always find viruses in any apk and stop the process to join the file (virus alert). Bad point is you are limited with the size of the file you wanna send.
Nowadays, even pc antiviruses can detect viruses in apks. I would rather not burden my phone with any android antivirus,since they are literally battery hogs.
sent using my HTC One S
Go here and upload the APK
http://anubis.iseclab.org/
Anubis is a service for analyzing malware.
Submit your Windows executable or Android APK and receive an analysis report telling you what it does. Alternatively, submit a suspicious URL and receive a report that shows you all the activities of the Internet Explorer process when visiting this URL.
Andrubis executes Android apps in a sandbox and provides a detailed report on their behavior, including file access, network access, crypto operations, dynamic code loading and information leaks. In addition to the dynamic analysis in the sandbox, Andrubis also performs static analysis, yielding information on e.g. the app's activities, services, required external libraries and actually required permissions.
Found a good one too
apkscan.nviso.be - give it a try. Drag and drop - wait for the upload - than click SCAN . Wait for a few minutes. That`s all. Unlike ANUBIS it has a resolution at the end of the analysis . Usually helpful.
You can also email the file to [email protected] and it will email the report back in about ten minutes. Virustotal can display some interesting info, for example it said that Lucky Patcher is a "Potentially Infected Hosts File (v)", as reported by VIPRE and AVware.
Virustotal also has an official android app.
The Netqin scanner is also an android mobile app.
Late answer, sure, but I think ClamAV is what you want. You also want its bytecode signature file, and to speed things up, you only want that single file (speeds up things quite a bit).
It is the only offline apk scanner i know of, and as for its efficiency i cannot say, but it seems like it is what you are asking for.
An alternative would be to install something like BlueStacks and remap your "Windows shared folder" (through registry) to the folder you have your apk files in, and then run BitDefender on it. BD is by far the most pernickety AV app out there for Android.
I'll have to check out bitdefender (it's also included on virustotal.com)
apkscan.nviso.be seems to be pretty good at analyzing files for suspicious activity, and it also uploads the file to virustotal for you. Then you can copy the sha256 hash into the virustotal's search, to get all the gory details.
anubis.iseclab.org limits files to 8 megabytes.
Another way to avoid malware is:
when installing an update to an already-installed version of an application, it will 99% of the time prompt you to update an existing app. There's been rare instances where some apps do use a new digital signature (for example when spotify had a big security hole, and for awhile there were two apps by spotify in the app store).
One other way to tell, as a final check when launching the apk for installation on the phone: the icon will not have the right icon. I've installed apps before that I thought came from a trusted source, but the icon was not right. In fact, I was considering not posting this publically, so the "bad dudes" would not update their methods.
Another tool I found:
http://andrototal.org/
Although it might be a duplicate of virustotal.
nintendo1889 said:
Another tool I found:
http://andrototal.org/
Although it might be a duplicate of virustotal.
Click to expand...
Click to collapse
I just tried out this site. To me, it appears to be the most thorough virus testing site that I have seen. It takes some time for it to complete the scans. mainly because it scans the file with about 7 or 8 different scanning engines. Just just have to keep refreshing the page every few minutes to see if the results have updated.
I will be using this one as my go to site for apk scanning.
Just install it on the default emulator in the Android SDK
You can also install your apps on other emulator live bluestacks(best for games), jar of beans(best for rooted app) and windroy(the lightest)
Hit thanks if this helps
nintendo1889 said:
I'll have to check out bitdefender ...
Click to expand...
Click to collapse
Your signature photo ... awesome ... Bad Dudes
By using GDATA security , When you want to install an app the GDATA will scan it befor installing
Sent from my LG-D855 using Tapatalk
Use google scanning service VirusTotal to scan any app, secondly always use secure source. There are many well reputed apk sites but I personally use apklink.com , on this site required apk file is just a click away and its quite easy as well...
be safe & secure
This threads out of date, but it has me thinking I want to use something as mentioned in several replies to OP.
Are there any sites, or apps that can warn me if an .apk (for example) has malware etc.?
Thanks in advance for any help, including a link to another discussion that may have my answer
denise1952 said:
This threads out of date, but it has me thinking I want to use something as mentioned in several replies to OP.
Are there any sites, or apps that can warn me if an .apk (for example) has malware etc.?
Thanks in advance for any help, including a link to another discussion that may have my answer
Click to expand...
Click to collapse
Malwarebytes can detect malware.
Sent from my LGL84VL using Tapatalk
I tried this site and I like it because it goes into a lot of detail after analyzing and sends me a report in email. It was mentioned, and it is still available to use: https://apkscan.nviso.be/
Thank you for the heads up on MB, I use that on my PC and works great
You can use virustotal.

WTF subways

I downloaded the subway app today & when i opened it i got this message. Question is why would the app look to see if im rooted?
It's not uncommon for apps that allow pre-payment or NFC payments to disable that function or not work at all if you're rooted. If all you want to do is find a store or look at the menu, root obviously wouldn't allow anything nefarious, but anything involving payment could be suspect if you're rooted (at least in their eyes).
Because with root it's possible to hack the device to alter digital transactions and steal money from the account on the phone.
Not sure why you'd want to rob your own bank account, but alas.
It's there for the same reason they put "Don't put your baby or cat in the microwave" warning labels on microwave ovens. Someone, somewhere (we all know where) will no doubt find a way to sue them over it if they don't slap a warning on it.

Could a rootkit install on your phone via website?

I went on a website that i later found out was known for installing rootkits . I was on firefox and have ublock origin installed. I didnt know about the third party filter settings so those werent up to date. And the page was saying how it was scanning my browser and initiating a dd something. I backed out before more stuff could load. And i cleared my cookies and downloaded several antivirus apps from the appstore and they all said im fine. But those dont scan for rootkits. I dont think theres a app that does that. I didnt click anything on the site but idk i something downloaded to my phone. Would i see it in my downloaded history or my download folder?
Tldr i just want to know if i may have gotten a rootkit by visiting a malicious website on my android phone.
I have a samsung galaxt s6
poopcycles said:
I went on a website that i later found out was known for installing rootkits . I was on firefox and have ublock origin installed. I didnt know about the third party filter settings so those werent up to date. And the page was saying how it was scanning my browser and initiating a dd something. I backed out before more stuff could load. And i cleared my cookies and downloaded several antivirus apps from the appstore and they all said im fine. But those dont scan for rootkits. I dont think theres a app that does that. I didnt click anything on the site but idk i something downloaded to my phone. Would i see it in my downloaded history or my download folder?
Tldr i just want to know if i may have gotten a rootkit by visiting a malicious website on my android phone.
I have a samsung galaxt s6
Click to expand...
Click to collapse
yes you could have got malware, though normally you would have had to interact with it to enable install. If it did gain root then nothing may show in downloads etc. If your rom is up to date or you backed out quickly you have a good chance you may be ok.
You could try a few root checker apps, but bear in mind it could have unrooted itself once installed as a system app. Else look out for any signs of strange behaviour or changes to system eg admin being added (maybe also try hidden admin finder app), install a firewall and check logs ....
go to virustotal or similar website and look for (or submit) that domain and see what malware it is being distributed, that might give you an idea where/what to look for (assuming it's still serving the same malware if you just submited url)
IronRoo said:
yes you could have got malware, though normally you would have had to interact with it to enable install. If it did gain root then nothing may show in downloads etc. If your rom is up to date or you backed out quickly you have a good chance you may be ok.
You could try a few root checker apps, but bear in mind it could have unrooted itself once installed as a system app. Else look out for any signs of strange behaviour or changes to system eg admin being added (maybe also try hidden admin finder app), install a firewall and check logs ....
go to virustotal or similar website and look for (or submit) that domain and see what malware it is being distributed, that might give you an idea where/what to look for (assuming it's still serving the same malware if you just submited url)
Click to expand...
Click to collapse
Why are you giving fake info ??? He couldnt had got malware on android when he hadnt installed anything!

Help! Galaxy tab s4 with virus!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Hi guys, I believe my galaxy tab s4 is contaminated with a virus . I already did many factorys resets and didnt installed no apps but from time to time , even when Im at the home screen with Avast only or with the antivirus that comes with the tablet activated, google play store opens without my request showing a program called IQ Option broker. What should I do?
malandrex said:
Hi guys, I believe my galaxy tab s4 is contaminated with a virus . I already did many factorys resets and didnt installed no apps but from time to time , even when Im at the home screen with Avast only or with the antivirus that comes with the tablet activated, google play store opens without my request showing a program called IQ Option broker. What should I do?
Click to expand...
Click to collapse
Could be a fake Play store app reinstalling itself somehow eg from SD card. Is your antivirus scanning your external storage also? Check if you have more than one play store app shown in settings>apps (not your normal apps screen as they can be hidden there). Or it could be an overlay made to look like Playstore screen ... you did get official Avast app right?
else something has installed itself in system folder which is why factory reset not working and you will need to reinstall your FULL Samsung factory ROM suggest you use Samsung SmartSwitch like RootJunky here (use high quality cable eg samsung usb cable, else danger of bricking)
https://m.youtube.com/watch?v=9QhJngOuLQ4
malandrex said:
Hi guys, I believe my galaxy tab s4 is contaminated with a virus . I already did many factorys resets and didnt installed no apps but from time to time , even when Im at the home screen with Avast only or with the antivirus that comes with the tablet activated, google play store opens without my request showing a program called IQ Option broker. What should I do?
Click to expand...
Click to collapse
Download Odin 3.xx (current version)
Browse SamMobile for firmware for your device, download factory ROM. Pay close attention to the region code for your ROM, CSC code. Use one compatible with your device and regional settings. It can be found on the IMEI sticker on the back of the device
Follow the flashing instructions to the letter that you will find on SamMobile website.
Once completed the device is fully refreshed and has latest available software at the time of the build. Do device setup and download app updates.
Enjoy.
Many thanks for both replies , but I have a few more questions:
a) Does this virus have the power to attack my router? If so, what should I inspect at my router? Should I use my brother´s ios iphone as a router while cleaning my device?
b) If I attach the tablet at my PC to perform the firmwire installation, could the virus be transmitted to it? What should I do to avoid it?
c) Where can I safely download this ODIN?
And answering some questions you made:
a) The avast app was downloaded from the store
b) Ive already tried disconnecting the sd card, perform a factory reset without the card but the problem persists.
c) I logged at my google account and when looking at my registered activity, Google claims I did opened the Google Play Store and searched for the IQ Option Broker app. So the virus acts as if it was me.
malandrex said:
Many thanks for both replies , but I have a few more questions:
a) Does this virus have the power to attack my router? If so, what should I inspect at my router? Should I use my brother´s ios iphone as a router while cleaning my device?
b) If I attach the tablet at my PC to perform the firmwire installation, could the virus be transmitted to it? What should I do to avoid it?
c) Where can I safely download this ODIN?
And answering some questions you made:
a) The avast app was downloaded from the store
b) Ive already tried disconnecting the sd card, perform a factory reset without the card but the problem persists.
c) I logged at my google account and when looking at my registered activity, Google claims I did opened the Google Play Store and searched for the IQ Option Broker app. So the virus acts as if it was me.
Click to expand...
Click to collapse
b) Possibly access is possible via your modem (or Bluetooth as serious bug was just patched this month if an attacker knows your BT MAC ... though likely take a while to rollout to all Samsung so you moray not be patched). If you suspect modem then you need to therefore also update your modem firmware (assuming its been patched & is not old & still vulnerable to some old bug, or buy new one) AND change both user & admin passwords
There is an XDA article with link to safe Odin download, google to find. But I'd recommend using Samsung SmartSwitch as this is official way & no special knowledge required.
Re item c) then possible it's just someone trying to load an app remotely via your Google account, does it show any unrecognised login from another device? Also I'm not 100% sure if this requires user to tap install on newer phones, so might not be what you are seeing. Change Google password. (your phone not infected in this case as you didn't click install) Always use a different password)(used same password then check your email address on have I been pwnd)
See below
IronRoo said:
b) Possibly access is possible via your modem (or Bluetooth as serious bug was just patched this month if an attacker knows your BT MAC ... though likely take a while to rollout to all Samsung so you moray not be patched). If you suspect modem then you need to therefore also update your modem firmware (assuming its been patched & is not old & still vulnerable to some old bug, or buy new one) AND change both user & admin passwords
There is an XDA article with link to safe Odin download, google to find. But I'd recommend using Samsung SmartSwitch as this is official way & no special knowledge required.
Re item c) then possible it's just someone trying to load an app remotely via your Google account, does it show any unrecognised login from another device? Also I'm not 100% sure if this requires user to tap install on newer phones, so might not be what you are seeing. Change Google password. (your phone not infected in this case as you didn't click install) Always use a different password)(used same password then check your email address on have I been pwnd)
Click to expand...
Click to collapse
b) I have 2 modens here, one from the internet provider , which is at bridge mode and one that spreads the signal. THe last one is modern and updated and the bridged one , there is no way I can acesss the firmwire besides its info. However , when I had to put it at bridge mode, I had to use an ethernet cable with a computer which maybe wasnt the most protected one. Could that process corrupts a firmwire modem?
c) But I have 2 stage factor. Shouldnt my phone receive an SMS alerting someone is logging at my account? And no, I havent seen any unrecognized login when I accessed my google account.
But your reply gave me an idea...: Maybe an access to my google account was made from a "public" computer and since the access wasnt terminated, as I use this computer a lot, a bot may be trying to remotely install this app.
malandrex said:
b) I have 2 modens here, one from the internet provider , which is at bridge mode and one that spreads the signal. THe last one is modern and updated and the bridged one , there is no way I can acesss the firmwire besides its info. However , when I had to put it at bridge mode, I had to use an ethernet cable with a computer which maybe wasnt the most protected one. Could that process corrupts a firmwire modem?
c) But I have 2 stage factor. Shouldnt my phone receive an SMS alerting someone is logging at my account? And no, I havent seen any unrecognized login when I accessed my google account.
But your reply gave me an idea...: Maybe an access to my google account was made from a "public" computer and since the access wasnt terminated, as I use this computer a lot, a bot may be trying to remotely install this app.
Click to expand...
Click to collapse
b) would need to be a modem exposed hero their internet with known vulnerability, so not sure.
C) yes, should have got a msg so can role that out, I guess.
Suppose it' possible that public pc could be comprised and doing that ... bit of a long shot ...
IronRoo said:
b) would need to be a modem exposed hero their internet with known vulnerability, so not sure.
C) yes, should have got a msg so can role that out, I guess.
Suppose it' possible that public pc could be comprised and doing that ... bit of a long shot ...
Click to expand...
Click to collapse
I think I found the culprit , when I reviewd the few apps Ive installed on my tablet and googled them . There is Netflix, Omega Wars game, PUBG and COD Mobile, handycalc, Go Read, Hube and... QuickPic gallery!!!!!!!!! I used this app on my ancient galaxy S2 and at my other 2 previous tablets. When I looked for the program at Google Play one hour ago ,QuickPic wasnt available anymore!!!! I googled about it and saw many people complaining about this program when a chinese company bought it a few years ago . Maybe QuickPiC installed some crapware at my device!!!!
malandrex said:
Hi guys, I believe my galaxy tab s4 is contaminated with a virus . I already did many factorys resets and didnt installed no apps but from time to time , even when Im at the home screen with Avast only or with the antivirus that comes with the tablet activated, google play store opens without my request showing a program called IQ Option broker. What should I do?
Click to expand...
Click to collapse
BTW, can you find same app on Google, is it called IQ Forex, is closest I could fined
IronRoo said:
BTW, can you find same app on Google, is it called IQ Forex, is closest I could fined
Click to expand...
Click to collapse
The name of the program is IQ Option , from IQ Option developer
malandrex said:
The name of the program is IQ Option , from IQ Option developer
Click to expand...
Click to collapse
I can't find this one but doesn't mean anything, maybe not available in my country or not compatible with my phone.
PS: Don't rule out a compromised router even top of her range can be affected eg
https://threatpost.com/critical-netgear-bug-impacts-nighthawk-router/153445/
IronRoo said:
I can't find this one but doesn't mean anything, maybe not available in my country or not compatible with my phone.
PS: Don't rule out a compromised router even top of her range can be affected eg
https://threatpost.com/critical-netgear-bug-impacts-nighthawk-router/153445/
Click to expand...
Click to collapse
Dont have much free time , but despite the fact I think the router is still safe, Ill reset it on a weekend and change again its id and password as this is a process that takes too much time ( mostly due to my ignorance at the beginning of the process ).
Im thinking about taking my tablet for a Samsung assistance, but Im worried theyll change one virus for another if the employees are corrupt. Do you think I should take the risk or Im beeing too paranoic?

Categories

Resources