-
Notifications
You must be signed in to change notification settings - Fork 169
Open
Labels
information requiredThis issue lacks information or requires feedback.This issue lacks information or requires feedback.
Description
Describe the Bug
SEB has a mechanism to check the integrity of the application by sending the hash code to the server to check, but that hash code can be easily replayed and sent directly to the server and used again
Steps to Reproduce
Steps to reproduce the behavior:
- open friddler everywhere
- open seb
- capture the hash
- when you have the hash string you can edit the seb source code to send it directly or use proxy to inject hash header
- done you passed integrity check, enjoy the exam
Version Information
- OS: window 10
- seb 3.10
Metadata
Metadata
Assignees
Labels
information requiredThis issue lacks information or requires feedback.This issue lacks information or requires feedback.