Skip to content

SEB integrity bypass #1366

@uznplay

Description

@uznplay

Describe the Bug
SEB has a mechanism to check the integrity of the application by sending the hash code to the server to check, but that hash code can be easily replayed and sent directly to the server and used again

Steps to Reproduce
Steps to reproduce the behavior:

  1. open friddler everywhere
  2. open seb
  3. capture the hash
  4. when you have the hash string you can edit the seb source code to send it directly or use proxy to inject hash header
  5. done you passed integrity check, enjoy the exam

Version Information

  • OS: window 10
  • seb 3.10

Metadata

Metadata

Assignees

Labels

information requiredThis issue lacks information or requires feedback.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions