Hello all.
Recently my app made with B4A passed a penetration test and one of the issues discovered was:
Signature algorithm v1 used (Janus CVE-2017-13156)
Is it possible to use a newer signature algorithm in B4A?
Kind regards,
Alberto
Recently my app made with B4A passed a penetration test and one of the issues discovered was:
Signature algorithm v1 used (Janus CVE-2017-13156)
Reference: https://www.guardsquare.com/blog/ne...ithout-affecting-their-signatures-guardsquareThe provided application is signed with, among others, the v1 version of the Google
Android signature algorithm.
For Android 5 to 7 phones, it has been demonstrated that it is possible to alter parts
of the DEX files when version 1 of the algorithm is used: vulnerability called "Janus"
and referenced as CVE-2017-13156.
An attacker could decompile the application and modify it to inject a backdoor.
Through phishing or social engineering strategies, he could trick a user by offering to
download the modified application that would legitimately update the old application.
Is it possible to use a newer signature algorithm in B4A?
Kind regards,
Alberto