漏洞分析

0

高危漏洞

7

中危漏洞

7

低危漏洞

7

警告

文件名 kuaibao_63.apk
上传者
文件大小 18.333355903625MB
MD5 ee952dd59fc04aa41af9bd4ab3171038
包名 com.tencent.reading
Main Activity com.tencent.reading.activity.SplashActivity
Min SDK 14
Target SDK 19

权限列表

# 名称 说明 提示
0 android.permission.CALL_PHONE 允许应用程序在您不介入的情况下拨打电话。恶意应用程序可借此在您的话费单上产生意外通话费。请注意,此权限不允许应用程序拨打紧急呼救电话。 警告
1 android.permission.READ_SMS 允许应用程序读取您的手机或SIM卡中存储的短信。恶意应用程序可借此读取您的机密信息。 警告
2 android.permission.SEND_SMS 允许应用程序发送短信。恶意应用程序可能会不经您的确认就发送信息,给您带来费用。 警告
3 android.permission.ACCESS_COARSE_LOCATION 访问大概的位置源(例如蜂窝网络数据库)以确定手机的大概位置(如果可以)。恶意应用程序可借此确定您所处的大概位置。 注意
4 android.permission.ACCESS_FINE_LOCATION 访问精准的位置源,例如手机上的全球定位系统(如果有)。恶意应用程序可能会借此确定您所处的位置,并可能消耗额外的电池电量。 注意
5 android.permission.ACCESS_LOCATION_EXTRA_COMMANDS 访问额外的位置信息提供程序命令。恶意应用程序可借此干扰GPS或其他位置源的正常工作。 注意
6 android.permission.BROADCAST_STICKY 允许应用程序发送顽固广播,这些广播在结束后仍会保留。恶意应用程序可能会借此使手机耗用太多内存,从而降低其速度或稳定性。 注意
7 android.permission.CHANGE_WIFI_MULTICAST_STATE 允许应用程序接收并非直接向您的设备发送的数据包。这样在查找附近提供的服务时很有用。这种操作所耗电量大于非多播模式。 注意
8 android.permission.GET_TASKS 允许应用程序检索有关当前和最近运行的任务的信息。恶意应用程序可借此发现有关其他应用程序的保密信息。 注意
9 android.permission.READ_CONTACTS 允许应用程序读取您手机上存储的所有联系人(地址)数据。恶意应用程序可借此将您的数据发送给其他人。 注意
10 android.permission.READ_PHONE_STATE 允许应用程序访问设备的手机功能。有此权限的应用程序可确定此手机的号码和序列号,是否正在通话,以及对方的号码等。 注意
11 android.permission.RECEIVE_BOOT_COMPLETED 允许应用程序在系统完成启动后即自行启动。这样会延长手机的启动时间,而且如果应用程序一直运行,会降低手机的整体速度。 注意
12 android.permission.RECORD_AUDIO 允许应用程序访问录音路径。 注意
13 android.permission.REORDER_TASKS 允许应用程序将任务移至前端和后台。恶意应用程序可借此强行进入前端,而不受您的控制。 注意
14 android.permission.SYSTEM_ALERT_WINDOW 允许应用程序显示系统警报窗口。恶意应用程序可借此掌控整个手机屏幕。 注意
15 android.permission.WRITE_SETTINGS 允许应用程序修改系统设置方面的数据。恶意应用程序可借此破坏您的系统配置。 注意
16 android.permission.WRITE_SYNC_SETTINGS 允许应用程序修改同步设置,例如是否为\“联系人\”启用同步。 注意
17 android.permission.ACCESS_NETWORK_STATE 允许应用程序查看所有网络的状态。 提示
18 android.permission.ACCESS_WIFI_STATE 允许应用程序查看有关WLAN状态的信息。 提示
19 android.permission.AUTHENTICATE_ACCOUNTS 允许应用程序使用AccountManager的帐户身份验证程序功能,包括创建帐户以及获取和设置其密码。 提示
20 android.permission.CAMERA 允许应用程序使用相机拍照,这样应用程序可随时收集进入相机镜头的图像。 提示
21 android.permission.CHANGE_NETWORK_STATE 允许应用程序更改网络连接的状态。 提示
22 android.permission.CHANGE_WIFI_STATE 允许应用程序连接到WLAN接入点以及与WLAN接入点断开连接,并对配置的WLAN网络进行更改。 提示
23 android.permission.DISABLE_KEYGUARD 允许应用程序停用键锁和任何关联的密码安全设置。例如,在手机上接听电话时停用键锁,在通话结束后重新启用键锁。 提示
24 android.permission.GET_ACCOUNTS 允许应用程序获取手机已知的帐户列表。 提示
25 android.permission.INTERNET 允许程序访问网络. 提示
26 android.permission.MODIFY_AUDIO_SETTINGS 允许应用程序修改整个系统的音频设置,如音量和路由。 提示
27 android.permission.MOUNT_UNMOUNT_FILESYSTEMS 允许应用程序装载和卸载可移动存储器的文件系统。 提示
28 android.permission.READ_LOGS 允许应用程序从系统的各日志文件中读取信息。这样应用程序可以发现您的手机使用情况,但这些信息不应包含任何个人信息或保密信息。 提示
29 android.permission.READ_SYNC_STATS 允许应用程序读取同步统计信息;例如已发生的同步历史记录。 提示
30 android.permission.USE_CREDENTIALS 允许应用程序请求身份验证标记。 提示
31 android.permission.VIBRATE 允许应用程序控制振动器。 提示
32 android.permission.WAKE_LOCK 允许应用程序防止手机进入休眠状态。 提示
33 android.permission.WRITE_EXTERNAL_STORAGE 允许应用程序写入SD卡。 提示

四大组件

组件名称

com.tencent.reading.startup.InitAppActivity
com.tencent.reading.activity.SplashActivity
com.tencent.reading.ui.TestEmptyActivity
com.tencent.reading.ui.NewsDetailActivity
com.tencent.reading.ui.QaContentActivity
com.tencent.reading.ui.ChannelPreViewActivity
com.tencent.reading.ui.RecommendActivity
com.tencent.reading.ui.CommentViewActivity
com.tencent.reading.rose.RoseSlideShowCommentActivity
com.tencent.reading.ui.PushNewsDetailActivity
com.tencent.reading.ui.ADInnerJumpActivity
com.tencent.reading.ui.InternalJumpActivity
com.tencent.reading.ui.NewsJumpActivity
com.tencent.reading.ui.ReportLogActivity
com.tencent.reading.ui.MicroNewsSpecialListActivity
com.tencent.reading.ui.ImageDetailActivity
com.tencent.reading.ui.GalleryDetailActivity
com.tencent.reading.ui.SettingActivity
com.tencent.reading.rose.RoseLiveDetailActivity
com.tencent.reading.rose.RoseRewardListActivity
com.tencent.reading.rose.RoseReplyMessageActivity
com.tencent.reading.rose.LiveVideoDetailActivity
com.tencent.reading.rose.RoseMultiVoteDetailActivity
com.tencent.reading.rose.RoseCommentOnLiveActivity
com.tencent.reading.rss.special.RssSpecialListActivity
com.tencent.reading.wxapi.WXEntryActivity
com.tencent.reading.wxapi.WXPayEntryActivity
com.tencent.reading.ui.DetailPreViewActivity
com.tencent.reading.ui.LivePreViewActivity
com.tencent.reading.ui.LivePreViewActivityForCommentImage
com.tencent.reading.ui.SuggestActivity
com.tencent.reading.ui.LoginActivity
com.tencent.reading.ui.LoginDialogActivity
com.tencent.reading.ui.LoginProxyActivity
com.tencent.reading.ui.AboutActivity
com.tencent.reading.debug.DebugActivity
com.tencent.reading.ui.AdvertDebugActivity
com.tencent.reading.ui.SupriseDebugActivity
com.tencent.reading.debug.SlidingOutSettingActivity
com.tencent.reading.debug.DebugAddPushActivity
com.tencent.reading.webview.WebSearchActivity
com.tencent.reading.login.activity.SinaWeiboSSOActivity
com.tencent.reading.webview.WebDetailActivity
com.tencent.reading.webview.WebBrowserActivity
com.tencent.reading.tad.ui.WebAdvertActivity
com.tencent.reading.tad.ui.WebDialogActivity
com.tencent.reading.webview.WebMusicActivity
com.tencent.reading.webview.WebBrowserForItemActivity
com.tencent.reading.webview.CustomWebBrowserForItemActivity
com.tencent.reading.ui.LaunchPageActivity
com.tencent.reading.webview.WebVideoActivity
com.tencent.reading.ui.ReLoginActivity
com.tencent.reading.ui.FlowerActivity
com.tencent.reading.ui.LiveVideoActivity
com.tencent.reading.ui.LiveVideoPreViewActivity
com.tencent.reading.rss.channels.custom.MenuSettingActivity
com.tencent.reading.ui.HotAppListActivity
com.tencent.reading.subscription.activity.RssAddActivity
com.tencent.reading.subscription.activity.MySubscriptionActivity
com.tencent.reading.subscription.activity.MySubQuestionsActivity
com.tencent.reading.rss.channels.activity.ChannelExploreActivity
com.tencent.reading.rss.RssSearchActivity
com.tencent.reading.favorites.FavoritesListActivity
com.tencent.reading.ui.FullScreenActivity
com.tencent.reading.push.assist.PushAssistEmptyActivity
com.tencent.reading.push.alive.foreground.ForegroundEmptyActivity
com.tencent.reading.map.LocationMapActivity
com.tencent.reading.map.CommentMapActivity
com.tencent.reading.search.activity.NewsSearchActivity
com.tencent.reading.search.activity.ChannelSearchLocalActivity
com.tencent.reading.search.activity.FocusTagDetailActivity
com.tencent.reading.search.activity.NewsListActivity
com.tencent.reading.search.activity.RelatedTagsDetailActivity
com.tencent.reading.search.activity.QaSearchActivity
com.tencent.reading.debug.HookActivity
com.tencent.reading.kkvideo.KKVideoSearchActivity
com.tencent.reading.ui.ChatPreviewActivity
com.tencent.reading.ui.MobleQQActivity
com.tencent.connect.common.AssistActivity
com.tencent.tauth.AuthActivity
com.tencent.reading.mediacenter.MediaCenterActivity
com.tencent.reading.mediacenter.UserCenterActivity
com.tencent.reading.mediacenter.activity.MediaDetailActivity
com.tencent.reading.ui.LiveEveActivity
com.tencent.reading.ui.LiveSubActivity
com.tencent.reading.ui.view.StorySubActivity
com.tencent.reading.ui.CommonPlayVideoActivity
com.tencent.reading.webview.WebBrowserForSearchDetailActivity
com.tencent.reading.ui.SupportActivity
com.tencent.reading.ui.EggActivity
com.tencent.reading.module.comment.answer.view.NewAnswerActivity
com.tencent.reading.module.comment.answer.view.EditAnswerActivity
com.tencent.reading.user.message.UserMessageActivity
com.tencent.reading.user.activity.UserSystemMessageActivity
com.tencent.reading.ui.view.CyCityListActivity
com.tencent.reading.dynamicload.internal.DLProxyActivity
com.tencent.reading.dynamicload.internal.DLProxyActivityTransparent
com.tencent.reading.dynamicload.internal.DLProxyActivitySingleIns
com.tencent.reading.debug.PluginCenterActivity
com.tencent.reading.debug.WebDetailTestActivity
com.tencent.reading.debug.PluginDetailActivity
com.tencent.reading.dynamicload.vertical.SportsWebBrowserActivity
com.tencent.reading.ui.VideoTagMergeActivity
com.tencent.reading.kkvideo.videotab.VideoSubChannel.KkVideoSubChannelActivity
com.tencent.reading.kkvideo.detail.KkShortVideoDetailActivity
com.tencent.reading.kkvideo.wifi.KkFreeWifiListActivity
com.tencent.reading.kkvideo.detail.KkAlbumDetailActivity
com.tencent.reading.kkvideo.KkVideoTagMergeActivity
com.tencent.reading.ui.MyStickListActivity
com.tencent.news.push.alive.offactivity.HollowActivity
com.tencent.news.push.notify.lock.LockActivity
com.tencent.reading.share.activity.QzoneShareActivity
com.tencent.reading.share.activity.SinaWeiboShareActivity
com.sina.weibo.sdk.component.WeiboSdkBrowser
com.tencent.reading.debug.WxSdkTestActivity
com.tencent.midas.proxyactivity.APMidasPayProxyActivity
com.tencent.midas.wx.APMidasWXPayActivity
com.tencent.midas.qq.APMidasQQWalletActivity
com.tencent.midas.jsbridge.APWebJSBridgeActivity
com.tencent.reading.subscription.activity.FocusTagAddActivity
oicq.wlogin_sdk.quicklogin.QuickLoginWebViewActivity
com.tencent.reading.ui.AnswerDetailActivity
com.tencent.reading.ui.CommentReplyListActivity
com.huawei.android.pushselfshow.richpush.RichPushActivity
com.tencent.reading.pubweibo.PublishTextPicWeiboActivity
com.tencent.reading.pubweibo.PublishVideoWeiboActivity
com.tencent.reading.pubweibo.SelectVideoCoverActivity
com.tencent.reading.pubweibo.PubWeiboRetryDialogActivity
com.tencent.reading.weibo.view.MediaGridActivity
com.tencent.reading.weibo.view.MediaFolderListActivity
com.tencent.reading.weibo.view.MediaImagePreviewActivity
com.tencent.reading.weibo.view.CameraTakePhotoActivity
com.tencent.reading.weibo.view.CameraRecordVideoActivity
com.tencent.reading.skin.SkinActivity
com.tencent.reading.ui.WeiboDetailActivity
com.tencent.reading.ui.QaFoldedListActivity
com.tencent.intervideo.nowproxy.proxyinner.activity.NowLoadingActivity
com.tencent.intervideo.nowproxy.proxyinner.activity.WebActivity
com.tencent.intervideo.nowproxy.proxyinner.activity.NowLoadedApkActivity
com.tencent.intervideo.nowproxy.proxyinner.container.DefaultContainerActivity
com.tencent.intervideo.nowproxy.proxyinner.container.WebProxyActivity
com.tencent.intervideo.nowproxy.proxyinner.container.RoomContainerActivity
com.tencent.sigma.patch.ForegroundServiceEmptyActivity

com.tencent.reading.push.PushService
com.tencent.reading.push.alive.foreground.CoreService
com.xiaomi.push.service.XMPushService
com.xiaomi.mipush.sdk.PushMessageHandler
com.xiaomi.mipush.sdk.MessageHandleService
com.tencent.reading.account.SyncService
com.tencent.reading.account.AccountService
com.tencent.reading.dynamicload.internal.DLAbsPluginService
com.igexin.sdk.PushService
cn.jpush.android.service.DaemonService
com.baidu.android.pushservice.CommandService
com.tencent.news.push.pullwake.jobsched.JobService
com.huawei.android.pushagent.PushService
com.meizu.cloud.pushsdk.NotificationService
com.tencent.intervideo.nowproxy.proxyinner.channel.ChannelService
com.tencent.intervideo.nowproxy.proxyinner.container.FakaForgroundContainerService
com.tencent.intervideo.nowproxy.proxyinner.container.WnsContainerService
com.tencent.intervideo.nowproxy.proxyinner.container.NowQTContainerService
com.tencent.intervideo.nowproxy.proxyinner.container.WnsPushContainerService
com.tencent.intervideo.nowproxy.proxyinner.container.DownloadContianerService
com.tencent.sigma.patch.HotPatchService

com.tencent.reading.system.BootBroadcastReceiver
com.tencent.reading.report.OmgIdBroadcastReceiver
com.tencent.reading.push.notify.PushNotificationRemoveReceiver
com.tencent.reading.push.notify.visual.send.HaltLockScreenNotifyReceiver
com.tencent.reading.system.PushAlarmReceiver
com.tencent.reading.system.MonitorServiceReceiver
com.tencent.reading.download.DownloadPackageReceiver
com.tencent.reading.push.mipush.MiPushMessageReceiver
com.tencent.reading.dynamicload.internal.DLAbsPluginBroadCastReceiver
com.baidu.android.pushservice.RegistrationReceiver
com.tencent.news.push.alive.offactivity.OffScreenReceiver
com.tencent.reading.push.hwpush.HWPushMessageReceiver
com.huawei.android.pushagent.PushEventReceiver
com.huawei.android.pushagent.PushBootReceiver
com.meizu.cloud.pushsdk.SystemReceiver
com.tencent.reading.push.mzpush.MeizuPushMessageReceiver
com.tencent.sigma.patch.NotifyBroadcastReceiver

com.tencent.reading.account.AccountProvider
com.igexin.download.DownloadProvider

第三方库

# 库名 介绍
0 com.alibaba.fastjson Fast JSON Processor https://github.com/alibaba/fastjson/wiki
1 com.coremedia.iso Provides a Java API for parsing MP4 files
2 org.apache.thrift Apache Thrift 是 Facebook 实现的一种高效的、支持多种编程语言的远程服务调用的框架。
3 com.tencent.map.geolocation 腾讯地图定位SDK是一套基于Android 2.1及以上版本设备的应用程序接口,通过该接口,您可以轻松使用腾讯地图定位服务,构建LBS应用程序。
定位SDK包括GPS定位与网络定位,实现了经纬度坐标偏转与当前位置的POI名称、地址或者行政区划的查询。采用了移动缓存策略,节省流量与电量。定位原理
定位SDK使用当前设备的GPS、基站信号和WiFi信号生成定位依据,并将定位依据发送到腾讯的定位服务器。
定位服务器对定位依据进行计算得到定位结果,最后将结果返回给定位SDK。
4 com.tencent.tencentmap 腾讯地图Android SDK是一套基于Android2.3及以上设备的应用接口,通过该接口,您可以方便地访问腾讯地图为您提供的高质量地点数据和服务,构建丰富而实用的地图及位置服务类应用。腾讯地图Android SDK除提供创建底图、缩放、平滑移图等基础功能外,还提供定位、地址解析、反地址解析、周边搜索、路线方案等拓展服务,助你在应用开发中事半功倍。腾讯地图Android SDK的服务需要注册,免费的向第三方提供,任何非盈利性网站均可使用。
5 com.tencent.connect 腾讯开放平台
6 com.igexin 通过个推的技术,APP可主动向用户推送新闻动态、版本更新、优惠活动、生活服务等各类信息,并通过多维度用户群组分析进行智能匹配,给合适的人群合适的场景推送合适的内容,大幅度提升消息点击率、用户活跃度和留存率
7 rx RxJava – Reactive Extensions for the JVM – a library for composing asynchronous and event-based programs using observable sequences for the Java VM.
8 com.tencent.bugly 腾讯Bugly,面向移动开发者提供最专业的Crash监控、崩溃分析等质量跟踪服务,为您修复用户的每一次Crash!
9 com.huawei.android.pushagent 华为推送
10 com.tencent.tauth 腾讯QQ互联平台为广大开发者整理了SDK列表,辅助开发者快速接入QQ登录、分享等功能。QQ互联是腾讯旗下的开放平台,通过QQ互联,网站主和开发者可以申请接入QQ登录、用户可以使用QQ账号登录接入的站点,通过添加分享和赞组件,将站点内容分享到QQ空间和朋友网,通过获取API授权,网站主还可以将用户操作同步到QQ空间和朋友网。
11 com.baidu.android.pushservice 百度云推送(Push)是一站式APP信息推送平台,为企业和开发者提供免费的消息推送服务,开发者可以通过云推送向用户精准推送通知和自定义消息以提升用户留存率和活跃度。
12 android.support.multidex DEPRECATED
13 com.xiaomi.mipush.sdk 小米推送(MiPush)是小米公司为开发者提供的消息推送服务,通过在云端和客户端之间建立一条稳定、可靠的长连接,为开发者提供向客户端应用推送实时消息的服务,帮助开发者有效地拉动用户活跃。
14 com.sina.weibo 新浪微博开放平台(Weibo Open Platform)是基于新浪微博海量用户和强大的传播能力,接入第三方合作伙伴服务,向用户提供丰富应用和完善服务的开放平台。将你的服务接入微博平台,有助于推广产品,增加网站/应用的流量、拓展新用户,获得收益。
15 com.tencent.mapsdk 腾讯地图开放平台
16 com.tencent.bugly 腾讯Bugly,面向移动开发者提供最专业的Crash监控、崩溃分析等质量跟踪服务,为您修复用户的每一次Crash!
17 org.apache.thrift Apache Thrift 是 Facebook 实现的一种高效的、支持多种编程语言的远程服务调用的框架。
18 com.tencent.map.geolocation 腾讯地图定位SDK是一套基于Android 2.1及以上版本设备的应用程序接口,通过该接口,您可以轻松使用腾讯地图定位服务,构建LBS应用程序。
定位SDK包括GPS定位与网络定位,实现了经纬度坐标偏转与当前位置的POI名称、地址或者行政区划的查询。采用了移动缓存策略,节省流量与电量。定位原理
定位SDK使用当前设备的GPS、基站信号和WiFi信号生成定位依据,并将定位依据发送到腾讯的定位服务器。
定位服务器对定位依据进行计算得到定位结果,最后将结果返回给定位SDK。
19 com.tencent.tencentmap 腾讯地图Android SDK是一套基于Android2.3及以上设备的应用接口,通过该接口,您可以方便地访问腾讯地图为您提供的高质量地点数据和服务,构建丰富而实用的地图及位置服务类应用。腾讯地图Android SDK除提供创建底图、缩放、平滑移图等基础功能外,还提供定位、地址解析、反地址解析、周边搜索、路线方案等拓展服务,助你在应用开发中事半功倍。腾讯地图Android SDK的服务需要注册,免费的向第三方提供,任何非盈利性网站均可使用。
20 com.tencent.tauth 腾讯QQ互联平台为广大开发者整理了SDK列表,辅助开发者快速接入QQ登录、分享等功能。QQ互联是腾讯旗下的开放平台,通过QQ互联,网站主和开发者可以申请接入QQ登录、用户可以使用QQ账号登录接入的站点,通过添加分享和赞组件,将站点内容分享到QQ空间和朋友网,通过获取API授权,网站主还可以将用户操作同步到QQ空间和朋友网。
21 rx RxJava – Reactive Extensions for the JVM – a library for composing asynchronous and event-based programs using observable sequences for the Java VM.
22 okhttp3 An HTTP+SPDY client for Android and Java applications.
23 com.mp4parser A Java API to read, write and create MP4 files.
24 com.huawei.android.pushagent 华为推送
25 com.tencent.connect 腾讯开放平台
26 com.xiaomi.mipush.sdk 小米推送(MiPush)是小米公司为开发者提供的消息推送服务,通过在云端和客户端之间建立一条稳定、可靠的长连接,为开发者提供向客户端应用推送实时消息的服务,帮助开发者有效地拉动用户活跃。
27 com.sina.weibo 新浪微博开放平台(Weibo Open Platform)是基于新浪微博海量用户和强大的传播能力,接入第三方合作伙伴服务,向用户提供丰富应用和完善服务的开放平台。将你的服务接入微博平台,有助于推广产品,增加网站/应用的流量、拓展新用户,获得收益。

静态扫描发现风险点

风险等级 风险名称

中危

检测到11个未移除的敏感Test或Debug组件

com.tencent.reading.ui.TestEmptyActivity
com.tencent.reading.debug.DebugActivity
com.tencent.reading.ui.AdvertDebugActivity
com.tencent.reading.ui.SupriseDebugActivity
com.tencent.reading.debug.SlidingOutSettingActivity
com.tencent.reading.debug.DebugAddPushActivity
com.tencent.reading.debug.HookActivity
com.tencent.reading.debug.PluginCenterActivity
com.tencent.reading.debug.WebDetailTestActivity
com.tencent.reading.debug.PluginDetailActivity
com.tencent.reading.debug.WxSdkTestActivity

建议:
在正式发布app前移除敏感的Test或Debug组件

中危

该app需要移除大部分日志打印代码。
经扫描该包仍存在大量打日志代码,共发现336处打日志代码.(此处扫描的日志打印代码,是指调用android.util.Log.* 打印的.)
详情如下:

位置: classes.dex
com.tencent.fresco.imagepipeline.memory.NativeMemoryChunk;->finalize()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.msg.a.e;->ʻ(Ljava/lang/String;)Ljava/util/ArrayList;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.StatLogger;->error(Ljava/lang/Object;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
ct.ca$a;->run()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.log.e;->ʽ(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mid.api.MidService;->getMid(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.b.a.a.a;->ʻ()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.pullwake.e$a;->ʼ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.proguard.w;->a(I Ljava/lang/String; [Ljava/lang/Object;)Z==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʽ(Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->isNetworkAvailable(Landroid/content/Context;)Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
oicq.wlogin_sdk.tools.util;->LOGI(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omgid.a;->ʼ(Z)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omgid.f.e;->ʼ(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʾ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʻ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APFileSizeUtil;->FormetFileSize(J I)D==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.b.a;->ʼ(Ljava/lang/String; Ljava/lang/String; Z)Z==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.oma.a.a.a;->a(Lcom/tencent/oma/a/a/c; Ljava/lang/String; Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʿ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʼ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.oma.a.a.a;->a(Lcom/tencent/oma/a/a/c; Ljava/lang/String; Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->v(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->getWifiTopN(Landroid/content/Context; I)Lorg/json/JSONArray;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.StatLogger;->debug(Ljava/lang/Object;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.StatLogger;->verbose(Ljava/lang/Object;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->writer(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->i(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.b.a.a.a;->ʼ()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->getSimOperator(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->getDeviceID(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->closeLog()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->w(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.log.e;->ʻ(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.a.b;->ʻ(Ljava/lang/String; J Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->isNetworkAvailable(Landroid/content/Context;)Z==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.WDK.WDKConfig;->setDebugEnable(Z)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.network.g;->ʻ(Landroid/content/Context; Ljava/net/URL; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.b.a;->ʻ(Ljava/lang/String; Ljava/lang/String; Z)Z==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
cn.com.iresearch.dau.IRDau;->a(Landroid/content/Context;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.log.e;->ʻ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->deleteElseLog()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.StatLogger;->info(Ljava/lang/Object;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.proguard.w;->a(I Ljava/lang/String; [Ljava/lang/Object;)Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.oma.a.a.a;->a(Lcom/tencent/oma/a/a/c; Ljava/lang/String; Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʽ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
cn.com.iresearch.dau.c.b;->a(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->isLogFileExist()Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.proguard.w;->a(I Ljava/lang/String; [Ljava/lang/Object;)Z==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.alive.d$a;->ʻ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.fresco.imagepipeline.memory.NativeMemoryChunk;->copy(I Lcom/tencent/fresco/imagepipeline/memory/NativeMemoryChunk; I I)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.alive.d$a;->ʼ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.network.f;->ʼ()Z==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.b;->a(Landroid/content/Context; Lcom/tencent/bugly/BuglyStrategy;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʼ(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->createDir(Ljava/lang/String;)Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->createWriter()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.b;->a(Landroid/content/Context; Ljava/lang/String; Z Lcom/tencent/bugly/BuglyStrategy;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.oma.a.a.a;->a(Lcom/tencent/oma/a/a/c; Ljava/lang/String; Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.pushsdk.common.util.Logger;->e(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter$3;->run()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.pushsdk.common.util.Logger;->i(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
oicq.wlogin_sdk.tools.util;->LOGD(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->createWriteThread()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APFileSizeUtil;->FormetFileSize(J)Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.alive.d$a;->ʼ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->getWifiMacAddress(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.a.a.a.b;->ʻ(Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.pullwake.e$a;->ʻ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.network.g;->ʻ(Landroid/content/Context; Ljava/lang/String; Ljava/util/List; Ljava/util/Map; Ljava/lang/String; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
cn.com.iresearch.dau.c.b;->e(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->isLogFileUpMax()Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->createLogFile()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.map.geolocation.internal.TencentExtraKeys$1;->println(Ljava/lang/String; I Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
cn.com.iresearch.dau.b.e;->a(Ljava/lang/String;)Lcn/com/iresearch/dau/b/f;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.log.e;->ʼ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.odk.client.utils.i;->ʻ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omgid.f.e;->ʽ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.b;->a(Landroid/content/Context; Lcom/tencent/bugly/BuglyStrategy;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.StatConfig;->setBackgroundDelayTimestamp(J)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.pushsdk.common.base.EncryptLogger;->open()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->printLog(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.proguard.w;->a(I Ljava/lang/String; [Ljava/lang/Object;)Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omgid.f.e;->ʻ(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
cn.com.iresearch.dau.IRDau;->c(Landroid/content/Context;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.log.e;->ʼ(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mid.api.b;->onFail(I Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->print(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
oicq.wlogin_sdk.tools.util;->LOGI(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->getLinkedWay(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.odk.client.utils.i;->ʽ(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
cn.com.iresearch.dau.IRDau;->b(Landroid/content/Context;)Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.b.a.a.a;->ʽ()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.map.geolocation.internal.TencentExtraKeys$1;->println(Ljava/lang/String; I Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.pullwake.e$a;->ʼ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mid.util.Util;->logInfo(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.msg.a.e;->ʻ(Ljava/lang/String; Ljava/util/ArrayList;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
oicq.wlogin_sdk.tools.util;->LOGD(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->print(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->e(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.network.g;->ʻ(Ljava/util/List;)Ljava/lang/String;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.oma.a.a.a;->a(Lcom/tencent/oma/a/a/c; Ljava/lang/String; Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omgid.f.e;->ʾ(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->createLogFileName()Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.a.g;->(Ljava/lang/Class; Ljava/lang/String; [Ljava/lang/Class;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->isWifiNet(Landroid/content/Context;)Z==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.odk.client.utils.i;->ʼ(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.odk.client.utils.i;->ʾ(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.a.a.c.a;->ʻ(Landroid/content/Context; Ljava/lang/String; Ljava/util/List; Lcom/xiaomi/a/a/c/a$b; Ljava/lang/String; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLog;->isWritePermission()Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
oicq.wlogin_sdk.tools.util;->LOGW(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.b;->a(Landroid/content/Context; Ljava/lang/String; Z Lcom/tencent/bugly/BuglyStrategy;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
oicq.wlogin_sdk.tools.util;->LOGW(Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->ʻ(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.pushsdk.common.util.Logger;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->getFileDirName()Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.a.a;->ʻ(Landroid/content/Context;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.xiaomi.a.a.c.a;->ʻ(Ljava/util/List;)Ljava/lang/String;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.ads.utility.h;->()V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter$2;->run()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.StatLogger;->warn(Ljava/lang/Object;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.Util;->getExternalStorageInfo(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.comm.APLogWriter;->getPackage(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.pushsdk.common.util.Logger;->w(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mid.util.Util;->isNetworkAvailable(Landroid/content/Context;)Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.meizu.cloud.pushsdk.handler.impl.notification.NotificationClickMessageHandler;->urlEncode(Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.msg.a.e;->ʻ(Ljava/lang/String;)Ljava/util/HashMap;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I

位置: classes2.dex
com.tencent.bugly.crashreport.CrashReport;->getUserData(Landroid/content/Context; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.httpproxy.CKeyFacade;->CKeyBackup(Ljava/lang/String; J Ljava/lang/String; I Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.report.c;->ʻ(I I I I I Ljava/lang/String; Ljava/lang/String; I I Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqmusic.module.ipcframework.toolbox.n;->ʻ(Ljava/lang/String; Ljava/lang/String; [Ljava/lang/Object;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.a.a.i;->a(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->putUserData(Landroid/content/Context; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserDatasSize(Landroid/content/Context;)I==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.a.h;->ʻ(Ljava/lang/String; Ljava/lang/String; Lcom/tencent/txproxy/a;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.report.c;->ʻ(Z I I I Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.c;->ʽ()Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.googlecode.mp4parser.util.AndroidLogger;->logError(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqmusic.module.ipcframework.toolbox.n;->ʽ(Ljava/lang/String; Ljava/lang/String; [Ljava/lang/Object;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->setNetWorkState(I)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.vodcgi.VideoInfo;->i()Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setCrashFilter(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.httpproxy.HttpproxyFacade;->jsonReport(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.a.e;->ˆ()Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.a.a;->ʻ(Ljava/lang/String; Landroid/os/Bundle;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.i;->f(Landroid/content/Context;)Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setAppPackage(Landroid/content/Context; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.Bugly;->init(Landroid/content/Context; Ljava/lang/String; Z Lcom/tencent/bugly/BuglyStrategy;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAppVer()Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.a.a;->ʽ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.map.geolocation.internal.TencentLogImpl;->(Landroid/content/Context; Ljava/io/File;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.c.c;->a(I Ljava/lang/String;)I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.uploadsdk.upload.HttpRequest;->postRequestBody(Ljava/net/HttpURLConnection;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.i;->a(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.c.d;->ʻ()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.a.c;->run()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.odk.client.store.d;->ʻ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.BuglyLog;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setUserSceneTag(Landroid/content/Context; I)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.q;->a(Ljava/lang/String; I)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.pay.http.APBaseHttpReq;->stopRequest()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->removeUserData(Landroid/content/Context; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.googlecode.mp4parser.util.AndroidLogger;->logDebug(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.qq.e.mobsdk.lite.api.util.GDTLogger;->i(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.intervideo.nowproxy.proxyinner.a.a;->ʻ(Landroid/content/Context; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getSdkExtraData()Ljava/util/Map;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.a.b;->onReceive(Landroid/content/Context; Landroid/content/Intent;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setJavascriptMonitor(Landroid/webkit/WebView; Z Z)Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.b;->ʻ(Z I)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setIsDevelopmentDevice(Landroid/content/Context; Z)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mm.opensdk.utils.Log;->i(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->testJavaCrash()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.pay.http.APHttpHandle;->a(Landroid/os/Message;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setUserId(Landroid/content/Context; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.component.ContainerService;->onBind(Landroid/content/Intent;)Landroid/os/IBinder;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.sdkupdate.UpdateUtils;->a(Lcom/tencent/qqlive/mediaplayer/sdkupdate/UpdateUtils$LogType; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.i;->f(Landroid/content/Context;)Z==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->closeCrashReport()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.b.a;->ʻ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.c.e;->onSurfaceChanged(Ljavax/microedition/khronos/opengles/GL10; I I)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->init(Landroid/content/Context; I Ljava/lang/String;)I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->removeUserData(Landroid/content/Context; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.http.l;->c(Ljava/lang/String; [Ljava/lang/Object;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.httpproxy.HttpproxyFacade;->print(I Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.qq.e.mobsdk.lite.api.util.GDTLogger;->e(Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.uicontroller.UIController$9;->run()V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getSdkExtraData(Landroid/content/Context;)Ljava/util/Map;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.g;->a(Landroid/graphics/Bitmap; Ljava/io/File;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqmusic.module.ipcframework.toolbox.n;->ʼ(Ljava/lang/String; Ljava/lang/String; [Ljava/lang/Object;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.map.geolocation.internal.TencentLogImpl;->println(Ljava/lang/String; I Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->setPlayerState(I I I)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sina.weibo.sdk.utils.f;->ʼ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.StatLogger;->warn(Ljava/lang/Object;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserId()Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.qq.e.mobsdk.lite.api.util.GDTLogger;->d(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.httpproxy.b.c;->a(I Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserData(Landroid/content/Context; Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setIsAppForeground(Landroid/content/Context; Z)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserId()Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.b.a;->ʻ(Ljava/lang/String; Ljava/lang/String; I)I==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.q;->g(Landroid/content/Context;)Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.a.h;->ʻ(Lcom/tencent/proxyinner/plugin/a/h$a; Z Ljava/lang/String;)Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->testANRCrash()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.bullet.BulletController;->checkBulletComment(J Z Z)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setAppChannel(Landroid/content/Context; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setCrashRegularFilter(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAppID()Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAppVer()Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->preLoad(I I I)I==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.sdkupdate.UpdateUtils;->a(Lcom/tencent/qqlive/mediaplayer/sdkupdate/UpdateUtils$LogType; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.BuglyLog;->w(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.qq.e.mobsdk.lite.api.util.GDTLogger;->e(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.sdkupdate.UpdateUtils;->a(Lcom/tencent/qqlive/mediaplayer/sdkupdate/UpdateUtils$LogType; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->closeNativeReport()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setSessionIntervalMills(J)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mm.opensdk.utils.Log;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->testANRCrash()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->testJavaCrash()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.uploadsdk.upload.HttpRequest;->buildConnection(Ljava/lang/String;)Ljava/net/HttpURLConnection;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.b;->ʻ(Landroid/content/Context; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.a.e$a;->ʻ(Ljava/lang/String; Ljava/lang/String; Z)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.httpproxy.HttpproxyFacade;->idKeyReport(Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sina.weibo.sdk.utils.f;->ʾ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.sina.weibo.sdk.utils.f;->ʽ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.sdkupdate.UpdateUtils;->a(Lcom/tencent/qqlive/mediaplayer/sdkupdate/UpdateUtils$LogType; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->testNativeCrash()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.map.geolocation.internal.TencentLogImpl;->println(Ljava/lang/String; I Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getSdkExtraData()Ljava/util/Map;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserSceneTagId(Landroid/content/Context;)I==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.report.c;->ʻ(I I)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setUserSceneTag(Landroid/content/Context; I)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.StatLogger;->info(Ljava/lang/Object;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAllUserDataKeys(Landroid/content/Context;)Ljava/util/Set;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.BuglyLog;->e(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.b;->ʻ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setUserId(Landroid/content/Context; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.intervideo.nowproxy.proxyinner.a.d;->ʻ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setAppVersion(Landroid/content/Context; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->isLastSessionCrash()Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.c.d;->a(I [B I I)I==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->isLastSessionCrash()Z==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.http.l;->b(Ljava/lang/String; [Ljava/lang/Object;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
tmsdk.bg.module.wificonnect.f;->startScan()Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setSdkExtraData(Landroid/content/Context; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->getProxyVersion()Ljava/lang/String;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.googlecode.mp4parser.util.AndroidLogger;->logWarn(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.lib.skin.a.b;->ʻ(Landroid/view/View;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.midas.plugin.APPluginActivity;->finish()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->appToFront(I)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.lib.skin.d.a;->ʻ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->putSdkData(Landroid/content/Context; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->startCrashReport()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.i;->b(Landroid/content/Context;)Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.qq.e.mobsdk.lite.api.util.GDTLogger;->w(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.map.geolocation.internal.TencentLogImpl;->(Landroid/content/Context; Ljava/io/File;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.http.l;->a(Ljava/lang/String; [Ljava/lang/Object;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->closeBugly()V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.mm.opensdk.utils.Log;->e(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAppID()Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.BuglyLog;->i(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.lib.skin.d.a;->ʻ(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->testNativeCrash()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.bullet.protocol.e;->a(I Ljava/lang/Exception; Lcom/tencent/qqlive/mediaplayer/bullet/protocol/jce/ResponseHead; Lcom/tencent/qqlive/mediaplayer/qq/taf/jce/JceStruct;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.BuglyLog;->v(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->postCatchedException(Ljava/lang/Throwable; Ljava/lang/Thread; Z)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.lib.skin.d.a;->ʼ(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setJavascriptMonitor(Lcom/tencent/bugly/crashreport/CrashReport$WebViewInterface; Z Z)Z==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.c.c;->a(Ljava/lang/String; Ljava/lang/String;)I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.c.c;->a(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.lib.skin.d.a;->ʽ(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setUserId(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.httpproxy.b.c;->a(I Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.plugin.b;->ʻ(Ljava/lang/String; Ljava/util/List;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserDatasSize(Landroid/content/Context;)I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAllUserDataKeys(Landroid/content/Context;)Ljava/util/Set;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.httpproxy.HttpproxyFacade;->jsonReport(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.news.push.a.e$a;->ʼ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.vodcgi.VideoInfo;->j()I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.httpproxy.HttpproxyFacade;->javaUtilLog(I Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.b.a;->ʻ(Ljava/lang/String; Ljava/lang/String; I)I==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sina.weibo.sdk.utils.f;->ʿ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.lib.skin.a.h;->ʻ(Landroid/view/View;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getUserSceneTagId(Landroid/content/Context;)I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->setUserId(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->setUtilsObject(Lcom/tencent/qqvideo/proxy/uniform/api/IUtils;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->startPlay(I Ljava/lang/String; I Ljava/lang/String; J I)I==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sixgod.pluginsdk.component.ContainerService;->onStartCommand(Landroid/content/Intent; I I)I==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->buildPlayURLMp4(I)Ljava/lang/String;==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.StatLogger;->error(Ljava/lang/Object;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
ct.bo;->ʼ()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.httpproxy.CKeyFacade;->CKey41Gen(Ljava/lang/String; J Ljava/lang/String; I Ljava/lang/String;)Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.stat.common.d;->a()Ljava/lang/String;==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.proxyinner.b.a;->ʻ(Ljava/lang/String; Ljava/lang/String; I)I==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->appToBack(I)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.qq.e.mobsdk.lite.api.util.GDTLogger;->w(Ljava/lang/String; Ljava/lang/Throwable;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.httpproxy.b.c;->a(I Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAppChannel()Ljava/lang/String;==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqvideo.proxy.uniform.common.PlayManagerImp;->init(Landroid/content/Context; I Ljava/lang/String;)I==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.StatLogger;->verbose(Ljava/lang/Object;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->getAppChannel()Ljava/lang/String;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.StatLogger;->debug(Ljava/lang/Object;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.sina.weibo.sdk.utils.f;->ʻ(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.httpproxy.b.c;->a(I Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.qqlive.mediaplayer.sdkupdate.UpdateUtils;->a(Lcom/tencent/qqlive/mediaplayer/sdkupdate/UpdateUtils$LogType; Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->closeNativeReport()V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.bugly.crashreport.CrashReport;->postCatchedException(Ljava/lang/Throwable; Ljava/lang/Thread; Z)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.omg.stat.common.i;->a(Landroid/content/Context; I)Lorg/json/JSONArray;==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I

位置: assets/plugin/com.tencent.reading.car.apk
com.tencent.reading.car.utils.LogUtil;->d(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->e(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.helper.CarConfigHelper;->writeCarHistory(Landroid/content/Context; Ljava/lang/String; Ljava/lang/String;)Z==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->i(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->w(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->v(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->v(Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->w(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->i(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.car.utils.LogUtil;->e(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I

位置: assets/plugin/com.tencent.reading.minsheng.apk
com.tencent.reading.minsheng.utils.LogUtil;->w(Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->e(Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->d(Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->e(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->w(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->i(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->i(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->v(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.minsheng.utils.LogUtil;->v(Ljava/lang/String;)V==>android.util.Log;->v(Ljava/lang/String; Ljava/lang/String;)I

位置: assets/plugin/com.tencent.reading.sports.apk
com.tencent.reading.sports.copy.c;->a(Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.sports.copy.c;->d(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.sports.copy.c;->b(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->e(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.sports.utils.v7.widget.GridLayoutManager;->a(Lcom/tencent/reading/sports/utils/v7/widget/RecyclerView$l; Lcom/tencent/reading/sports/utils/v7/widget/RecyclerView$p; I)I==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.sports.copy.c;->a(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->d(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.sports.copy.c;->c(Ljava/lang/String; Ljava/lang/String;)V==>android.util.Log;->i(Ljava/lang/String; Ljava/lang/String;)I
com.tencent.reading.sports.utils.v7.widget.GridLayoutManager;->b(Lcom/tencent/reading/sports/utils/v7/widget/RecyclerView$l; Lcom/tencent/reading/sports/utils/v7/widget/RecyclerView$p; I)I==>android.util.Log;->w(Ljava/lang/String; Ljava/lang/String;)I

中危

检测到8个WebView远程执行漏洞。

位置: classes.dex
com.tencent.reading.module.webdetails.pagemanage.m;->ٴ()V
com.tencent.reading.module.webdetails.pagemanage.m;->ٴ()V
com.tencent.reading.module.webdetails.pagemanage.m;->ٴ()V

位置: classes2.dex
com.tencent.reading.ui.view.RichEditor;->ʼ()V
com.huawei.android.pushselfshow.richpush.html.HtmlViewer;->enableJavaJS(Ljava.lang.String;)V
com.huawei.android.pushselfshow.richpush.html.HtmlViewer;->enableJavaJS(Ljava.lang.String;)V
com.tencent.bugly.crashreport.b;->addJavascriptInterface(Lcom.tencent.bugly.crashreport.crash.h5.H5JavaScriptInterface; Ljava.lang.String;)V
oicq.wlogin_sdk.quicklogin.QuickLoginWebViewLoader;->load(Landroid.app.Activity; Landroid.content.Intent;)V

Android API < 17之前版本存在远程代码执行安全漏洞,该漏洞源于程序没有正确限制使用addJavaScriptInterface方法,攻击者可以通过Java反射利用该漏洞执行任意Java对象的方法,导致远程代码执行安全漏洞。
(1)API等于高于17的Android系统。出于安全考虑,为了防止Java层的函数被随意调用,Google在4.2版本之后,规定允许被调用的函数必须以@JavascriptInterface进行注解。
(2)API等于高于17的Android系统。建议不要使用addJavascriptInterface接口,以免带来不必要的安全隐患,如果一定要使用该接口,建议使用证书校验。
(3)使用removeJavascriptInterface移除Android系统内部的默认内置接口:searchBoxJavaBridge_、accessibility、accessibilityTraversal。

参考案例:
www.wooyun.org/bugs/wooyun-2015-0140708
www.wooyun.org/bugs/wooyun-2016-0188252
http://drops.wooyun.org/papers/548

参考资料:
http://jaq.alibaba.com/blog.htm?id=48
http://blog.nsfocus.net/android-webview-remote-code-execution-vulnerability-analysis
https://developer.android.com/reference/android/webkit/WebView.html

中危

检测到20条敏感明文信息,建议移除。

位置: classes.dex
'10.0.0.172' used in: Lcom/tencent/renews/network/http/d/a;->ʻ(Ljava/lang/String;)Z
'10.0.0.172' used in: Lcom/xiaomi/network/g;->ʻ(Ljava/net/URL;)Ljava/lang/String;
'10.0.0.172' used in: Lcom/tencent/renews/network/http/d/a;->ʻ(Landroid/content/Context;)Ljava/net/Proxy;
'10.0.0.172' used in: Lcom/tencent/mid/util/Util;->getHttpProxy(Landroid/content/Context;)Lorg/apache/http/HttpHost;
'10.0.0.172' used in: Lcom/tencent/stat/common/StatCommonHelper;->getHttpProxy(Landroid/content/Context;)Lorg/apache/http/HttpHost;
'10.0.0.172' used in: Lcom/xiaomi/a/a/c/a;->ʻ(Ljava/net/URL;)Ljava/lang/String;
'10.0.0.172' used in: Lcom/tencent/renews/network/http/d/a;->ʼ(Landroid/content/Context;)Z
'10.0.0.200' used in: Lcom/tencent/renews/network/http/d/a;->ʻ(Ljava/lang/String;)Z
'10.0.0.200' used in: Lcom/tencent/renews/network/http/d/a;->ʻ(Landroid/content/Context;)Ljava/net/Proxy;
'10.0.0.200' used in: Lcom/tencent/mid/util/Util;->getHttpProxy(Landroid/content/Context;)Lorg/apache/http/HttpHost;
'10.0.0.200' used in: Lcom/tencent/stat/common/StatCommonHelper;->getHttpProxy(Landroid/content/Context;)Lorg/apache/http/HttpHost;
'10.0.0.200' used in: Lcom/tencent/renews/network/http/d/a;->ʼ(Landroid/content/Context;)Z
'10.0.0.200' used in: Lcom/xiaomi/network/g;->ʻ(Landroid/content/Context; Ljava/net/URL;)Ljava/net/HttpURLConnection;
'10.0.0.200' used in: Lcom/xiaomi/a/a/c/a;->ʻ(Landroid/content/Context; Ljava/net/URL;)Ljava/net/HttpURLConnection;
'10.237.12.17' used in: Lcom/xiaomi/smack/l;->ʼ()Ljava/lang/String;
'http://10.237.12.17:9085/pass/register' used in: Lcom/xiaomi/push/service/u;->ʻ()Ljava/lang/String;

位置: classes2.dex
'10.0.0.172' used in: Lct/y;->ʻ()V
'10.0.0.172' used in: Lcom/tencent/omg/stat/common/g;->a(Landroid/content/Context;)Lorg/apache/http/HttpHost;
'10.0.0.200' used in: Lct/y;->ʻ()V
'10.0.0.200' used in: Lcom/tencent/omg/stat/common/g;->a(Landroid/content/Context;)Lorg/apache/http/HttpHost;

中危

检测到34处setSavePassword密码明文存储漏洞。

位置: classes.dex
com.tencent.ads.view.AdPage;
com.tencent.reading.module.webdetails.pagemanage.m;
com.tencent.reading.ui.SupportActivity;
com.tencent.reading.ui.view.WebDetailView;
com.tencent.reading.webview.CustomWebBrowserForItemActivity$CustomWebViewClient;
com.tencent.reading.ui.view.NewsWebView;
com.tencent.reading.webview.jsapi.ScriptInterface;
com.tencent.reading.webview.utils.WebViewUtil;
com.tencent.reading.ui.view.BaseWebView;
com.tencent.ads.view.AdWebView;
com.tencent.reading.webview.WebMusicActivity;
com.tencent.reading.webview.jsbridge.CustomWebViewClient;
com.tencent.reading.webview.jsapi.bg;

位置: classes2.dex
com.tencent.open.SocialApiIml;
com.tencent.reading.rose.view.RosePageWebView;
com.tencent.midas.jsbridge.APWebView;
com.tencent.reading.dynamicload.exportView.PluginWebView;
com.tencent.reading.webview.WebDetailActivity$b;
com.tencent.reading.tad.ui.WebAdvertActivity$b;
com.tencent.reading.webview.au;
com.tencent.reading.webview.WebBrowserForItemActivity$CustomWebViewClient;
com.tencent.intervideo.nowproxy.proxyinner.activity.WebActivity;
com.tencent.reading.rose.view.RoseWebView;
com.tencent.reading.ui.view.RichEditor;
com.tencent.reading.webview.WebBrowserActivity$b;
com.tencent.reading.tad.ui.WebDialogActivity;
oicq.wlogin_sdk.quicklogin.QuickLoginWebViewLoader;
com.tencent.bugly.crashreport.b;
com.tencent.reading.tad.ui.y;
com.tencent.ads.mraid.MraidWebView;
com.tencent.intervideo.nowproxy.proxyinner.a.a;

位置: assets/plugin/com.tencent.reading.car.apk
com.tencent.reading.car.view.CarWebView;

位置: assets/plugin/com.tencent.reading.minsheng.apk
com.tencent.reading.minsheng.ui.AffairWebBrowserActivity$HandlerCallback;
com.tencent.reading.minsheng.ui.AffairChannelContentViewActivity$HandlerCallback;

webview的保存密码功能默认设置为true。Webview会明文保存网站上的密码到本地私有文件”databases/webview.db”中。对于可以被root的系统环境或者配合其他漏洞(如webview的同源绕过漏洞),攻击者可以获取到用户密码。
建议:显示设置webView.getSetting().setSavePassword(false)。

参考案例:
www.wooyun.org/bugs/wooyun-2010-021420
www.wooyun.org/bugs/wooyun-2013-020246

参考资料:
http://wolfeye.baidu.com/blog/
www.claudxiao.net/2013/03/android-webview-cache/

中危

检测到5使用全局可读写操作文件。

位置: classes.dex
com.tencent.oma.push.guid.GuidClient;->a(Landroid.content.Context; Ljava.lang.String; Ljava.util.Map;)Z===>getSharedPreferences
com.tencent.oma.push.guid.GuidClient;->f(Landroid.content.Context;)Ljava.lang.String;===>getSharedPreferences
com.tencent.oma.push.guid.GuidClient;->a(Landroid.content.Context; Ljava.lang.String; Ljava.util.Map; Lcom.tencent.oma.push.guid.GuidReportCallBack; Z)V===>getSharedPreferences
com.tencent.oma.push.guid.GuidClient;->c(Landroid.content.Context; Ljava.lang.String;)V===>getSharedPreferences

位置: classes3.dex
tmsdkobf.cz;->e(Z)I===>openFileOutput

在使用getDir、getSharedPreferences(SharedPreference)或openFileOutput时,如果设置了全局的可读权限,攻击者恶意读取文件内容,获取敏感信息。在设置文件属性时如果设置全局可写,攻击者可能会篡改、伪造内容,可以能会进行诈骗等行为,造成用户财产损失。建议:
(1)使用MODE_PRIVATE模式创建内部存储文件。
(2)加密存储敏感数据。
(3)避免在文件中存储明文和敏感信息。

参考案例:
http://wooyun.org/bugs/wooyun-2010-047172
http://wooyun.org/bugs/wooyun-2010-054438
http://wooyun.org/bugs/wooyun-2010-0151270

参考资料:
https://jaq.alibaba.com/blog.htm?id=56
https://jaq.alibaba.com/blog.htm?id=58
http://wolfeye.baidu.com/blog/global-rw-of-file
http://wolfeye.baidu.com/blog/global-rw-of-sharepreference/

低危

检测到27个WebView系统隐藏接口未移除。

位置: classes.dex
com.tencent.reading.webview.CustomWebBrowserForItemActivity$CustomWebViewClient;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.tencent.reading.webview.WebVideoActivity;->initView()V
com.tencent.reading.webview.jsapi.ScriptInterface;->changeFontSize()V
com.tencent.reading.webview.WebBrowserForItemActivity;->initView()V
com.tencent.reading.tad.ui.WebAdvertActivity;->ʿ()V
com.tencent.reading.webview.WebBrowserActivity;->initView()V
com.tencent.reading.ui.SupportActivity;->ʽ()V
com.tencent.reading.webview.jsapi.bg;->run()V
com.tencent.reading.tad.ui.WebAdvertActivity;->ˉ()V
com.tencent.reading.webview.WebMusicActivity;->initView()V
com.tencent.reading.webview.CustomWebBrowserForItemActivity;->initView()V
com.tencent.reading.webview.jsbridge.CustomWebViewClient;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.tencent.reading.webview.WebDetailActivity;->initWebView()V

位置: classes2.dex
com.tencent.reading.webview.WebBrowserActivity$b;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.tencent.reading.webview.WebSearchActivity;->initView()V
com.tencent.intervideo.nowproxy.proxyinner.activity.WebActivity;->ʻ()Ljava.lang.String;
com.tencent.midas.jsbridge.APWebView;->a()V
com.tencent.reading.tad.ui.WebAdvertActivity$b;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.tencent.reading.webview.au;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.tencent.reading.tad.ui.y;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.tencent.reading.webview.WebBrowserForSearchDetailActivity;->initView()V
com.tencent.reading.rose.view.RosePageWebView;->ʼ(Landroid.content.Context;)V
com.tencent.intervideo.nowproxy.proxyinner.activity.WebActivity;->onCreate(Landroid.os.Bundle;)V
com.tencent.bugly.crashreport.b;->setJavaScriptEnabled(Z)V
com.tencent.reading.webview.WebDetailActivity$b;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V
com.sina.weibo.sdk.component.WeiboSdkBrowser;->ʽ()V
com.tencent.reading.webview.WebBrowserForItemActivity$CustomWebViewClient;->onPageFinished(Landroid.webkit.WebView; Ljava.lang.String;)V

android webview组件包含3个隐藏的系统接口:searchBoxJavaBridge_,accessibilityTraversal以及accessibility,恶意程序可以利用它们实现远程代码执行。
如果使用了WebView,那么使用WebView.removeJavascriptInterface(String name) API,显示的移除searchBoxJavaBridge_、accessibility、accessibilityTraversal这三个接口。

参考资料:
http://wolfeye.baidu.com/blog/android-webview/
http://blog.csdn.net/u013107656/article/details/51729398
http://wolfeye.baidu.com/blog/android-webview-cve-2014-7224/

低危

检测到10处使用了DES弱加密算法。

位置: classes.dex
'DES/CBC/PKCS5Padding' used in: Lcom/tencent/reading/utils/i;->ʻ(Ljava/lang/String; [B [B Ljava/lang/String;)[B
'DES/CBC/PKCS5Padding' used in: Lcn/com/iresearch/dau/c/a;->a([B Ljava/lang/String;)[B
'DES/CBC/PKCS5Padding' used in: Lcn/com/iresearch/dau/c/a;->a(Ljava/lang/String; [B)[B
'DES/CBC/PKCS5Padding' used in: Lcom/tencent/ads/utility/d;->ʻ(Ljava/lang/String; Ljava/lang/String; [B)[B
'DES/CBC/PKCS5Padding' used in: Lcom/tencent/reading/utils/i;->ʻ(Ljava/lang/String; Ljava/lang/String; [B)[B
'DES/ECB/NoPadding' used in: Ltmsdkobf/bx;->a([B [B)[B
'DES/ECB/PKCS5Padding' used in: Lcom/tencent/reading/ui/SupportActivity;->ʻ(Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)Ljava/lang/String;

位置: classes2.dex
'DES/CBC/PKCS5Padding' used in: Lcom/tencent/bugly/proguard/ae;->b([B)[B
'DES/CBC/PKCS5Padding' used in: Lcom/tencent/bugly/proguard/ae;->a([B)[B
'DES/ECB/PKCS7Padding' used in: Lcom/tencent/reading/contact/report/a;->ʻ(Landroid/database/Cursor; I)V

使用弱加密算法会大大增加黑客攻击的概率,黑客可能会破解隐私数据、猜解密钥、中间人攻击等,造成隐私信息的泄漏,甚至造成财产损失。建议使用AES加密算法。

参考资料:
http://drops.wooyun.org/tips/15870
https://developer.android.com/training/articles/keystore.html
http://wolfeye.baidu.com/blog/weak-encryption/
http://www.freebuf.com/articles/terminal/99868.html

低危

检测6处Intent Scheme URI漏洞。

位置: classes.dex
Lcom/huawei/android/pushselfshow/a/a;->f()V
Lcom/huawei/android/pushselfshow/c/d;->b(Landroid/content/Context; Lcom/huawei/android/pushselfshow/b/a;)Landroid/content/Intent;
Lcom/meizu/cloud/pushsdk/handler/impl/notification/NotificationClickMessageHandler;->buildIntent(Landroid/content/Context; Lcom/meizu/cloud/pushsdk/handler/MessageV3;)Landroid/content/Intent;
Lcom/xiaomi/mipush/sdk/f;->ʻ(Lcom/xiaomi/xmpush/thrift/k; Z [B)Lcom/xiaomi/mipush/sdk/PushMessageHandler$a;

位置: classes2.dex
Lcom/huawei/android/pushselfshow/richpush/html/a/d;->a(Ljava/lang/String; Ljava/lang/String; Z)V

位置: classes3.dex
Ltmsdkobf/ci;->aI()Landroid/content/Intent;


Intent Scheme URI是一种特殊的URL格式,用来通过Web页面启动已安装应用的Activity组件,大多数主流浏览器都支持此功能。如果在app中,没有检查获取到的load_url的值,攻击者可以构造钓鱼网站,诱导用户点击加载,就可以盗取用户信息。所以,对Intent URI的处理不当时,就会导致基于Intent的攻击。建议:
如果使用了Intent.parseUri函数,获取的intent必须严格过滤,intent至少包含addCategory(“android.intent.category.BROWSABLE”),setComponent(null),setSelector(null)3个策略。

参考资料:
http://wolfeye.baidu.com/blog/intent-scheme-url/
http://drops.wooyun.org/papers/2893
http://drops.wooyun.org/mobile/15202

低危

检测到8处AES/DES弱加密风险。

位置: classes.dex
Lcom/tencent/reading/ui/SupportActivity;->ʻ(Ljava/lang/String; Ljava/lang/String; Ljava/lang/String;)Ljava/lang/String;
Ltmsdkobf/bx;->a([B [B)[B

位置: classes2.dex
Lcom/sina/weibo/sdk/utils/a;->ʻ(Ljava/lang/String;)Ljava/lang/String;
Lcom/huawei/android/pushagent/utils/a/a/b;->a([B I [B I I)[B
Lcom/tencent/reading/contact/report/a;->ʻ(Landroid/database/Cursor; I)V
Lcom/tencent/reading/e/e;->ʻ(Ljava/lang/String;)Ljava/util/List;
Lct/j;->([B)V
Lcom/tencent/reading/e/e;->ʻ(Ljava/io/ByteArrayOutputStream; Ljava/io/File; Z)Ljava/lang/String;

使用AES/DES/DESede加密算法时,如果使用ECB模式,容易受到攻击风险,造成信息泄露。建议在使用AES/DES/DESede加密算法时,应显示指定使用CBC或CFB加密模式

参考资料:
http://blog.csdn.net/u013107656/article/details/51997957
https://developer.android.com/reference/javax/crypto/Cipher.html
http://drops.wooyun.org/tips/15870
https://developer.android.com/training/articles/keystore.html
http://wolfeye.baidu.com/blog/weak-encryption/
http://www.freebuf.com/articles/terminal/99868.html

低危

非debug包,需要通过打包平台proguard脚本,移除大部分系统输出代码。
经扫描该包仍存在大量系统输出代码,共发现31处系统输出代码.(此处扫描的系统输出代码,是指调用System.out.print*输出的,本应在打包平台移除的系统输出代码.)
各个bundle系统输出代码详情如下:

位置: classes.dex
com.xiaomi.push.service.an;
com.xiaomi.smack.x;
com.googlecode.mp4parser.authoring.tracks.h265.SEIMessage;
com.tencent.ads.utility.k;
com.googlecode.mp4parser.authoring.tracks.h265.H265TrackImplOld;
rx.c.c;
com.tencent.reading.tad.utils.l;
rx.exceptions.CompositeException$b;
com.googlecode.mp4parser.boxes.cenc.CencDecryptingSampleList;
com.googlecode.mp4parser.authoring.tracks.DTSTrackImpl;
com.coremedia.iso.boxes.sampleentry.AudioSampleEntry;
com.googlecode.mp4parser.authoring.tracks.H263TrackImpl;
com.xiaomi.smack.s;
com.googlecode.mp4parser.AbstractBox;
rx.internal.util.f;
com.googlecode.mp4parser.authoring.tracks.DTSTrackImpl$LookAhead;
com.googlecode.mp4parser.authoring.tracks.h265.H265TrackImpl;

位置: classes2.dex
com.xiaomi.smack.d.c;
com.tencent.qqlive.mediaplayer.qq.taf.RequestPacket;
com.qq.taf.RequestPacket;
com.tencent.open.utils.Util;
com.googlecode.mp4parser.boxes.microsoft.XtraBox;
com.tencent.bugly.proguard.f;
org.mp4parser.aspectj.lang.SoftException;
com.tencent.odk.client.utils.d;
com.tencent.sharpP.SharpPDecoder;
com.huawei.android.pushselfshow.richpush.html.a.c;
com.tencent.odk.client.utils.h;
com.tencent.odk.client.utils.c;
com.mp4parser.streaming.rawformats.H264TrackAdapter;
com.tencent.mapsdk.rastercore.tile.a.a;

低危

检测到1处地方在自定义实现的WebViewClient类在onReceivedSslError调用proceed()方法。

位置: classes2.dex
oicq.wlogin_sdk.quicklogin.d;->onReceivedSslError(Landroid.webkit.WebView; Landroid.webkit.SslErrorHandler; Landroid.net.http.SslError;)V

Android WebView组件加载网页发生证书认证错误时,会调用WebViewClient类的onReceivedSslError方法,如果该方法实现调用了handler.proceed()来忽略该证书错误,则会受到中间人攻击的威胁,可能导致隐私泄露。建议:
当发生证书认证错误时,采用默认的处理方法handler.cancel(),停止加载问题页面当发生证书认证错误时,采用默认的处理方法handler.cancel(),停止加载问题页面。

参考案例:
http://www.wooyun.org/bugs/wooyun-2010-0109266

参考资料:
https://jaq.alibaba.com/blog.htm?id=60
http://wolfeye.baidu.com/blog/webview-ignore-ssl-error/

警告

检测到42处addFlags使用Intent.FLAG_ACTIVITY_NEW_TASK。

位置: classes.dex
com.xiaomi.mipush.sdk.f;->ʻ
com.tencent.reading.tad.fodder.AdApkManager;->ʼ
com.tencent.reading.share.a.b;->ʻ
com.tencent.reading.k.l;->ʻ
com.tencent.reading.download.filedownload.r;->ʻ
com.tencent.news.push.alive.offactivity.HollowActivity;->ʻ
com.tencent.reading.ui.LoginActivity;->ʻ
com.xiaomi.push.service.ag;->ʻ
com.tencent.reading.vertical.e;->ʻ
com.tencent.reading.login.c.c;->ʻ
com.tencent.reading.live.now.a;->ʼ
com.tencent.reading.tad.utils.l;->ʻ
com.tencent.news.push.msg.a.h;->ʻ
com.tencent.reading.dynamicload.internal.a;->ʻ
com.tencent.reading.download.filedownload.util.b;->ʼ
com.tencent.reading.startup.j;->ʼ
com.sixgod.pluginsdk.b;->ʻ
com.sixgod.pluginsdk.apkmanager.SixGodAppContext;->startActivity
com.tencent.reading.push.b.a;->ʿ
com.meizu.cloud.pushsdk.handler.impl.notification.NotificationClickMessageHandler;->unsafeSend
com.tencent.reading.activity.SplashActivity;->ʻ
com.tencent.reading.common.a.a.b;->ʽ

位置: classes2.dex
com.tencent.ads.mraid.MraidAdView$WebViewHandler;->webViewShouldOverrideUrlLoading
com.tencent.reading.dynamicload.bridge.HostJumpUtil;->gotoNetSettingsActivity
com.tencent.qqlive.mediaplayer.uicontroller.recommendController.VideoCompleteView;->dealDownload
com.tencent.qqlive.mediaplayer.uicontroller.recommendController.VideoCompleteViewNew;->dealDownload
com.tencent.qqlive.mediaplayer.uicontroller.recommendController.VideoCompleteView;->dealDownloadForBaiduVideo
com.tencent.reading.dynamicload.bridge.account.DLAccountManager;->triggerLogin
com.tencent.connect.auth.AuthDialog$a;->shouldOverrideUrlLoading
com.tencent.ads.mraid.MraidAdView$MraidHandler;->mraidOpen
com.tencent.open.TDialog$FbWebViewClient;->shouldOverrideUrlLoading
com.tencent.reading.ui.view.gu;->onClick
com.tencent.qqlive.mediaplayer.uicontroller.Utils;->openLocalAPP
com.tencent.reading.startup.c.d;->ʻ
com.tencent.open.utils.Util;->a
com.tencent.open.PKDialog;->loadUrlWithBrowser
com.tencent.news.push.notify.a;->ʻ
com.tencent.mobileqq.a.a.d;->ʽ
com.tencent.mobileqq.a.a.d;->ʼ
com.tencent.mm.opensdk.channel.MMessageActV2;->send

位置: classes3.dex
tmsdkobf.ci;->f

位置: assets/plugin/com.tencent.reading.vertical.portfolio.apk
com.tencent.reading.vertical.portfolio.data.ui.PortfolioStockDetailActivity$2;->onDownloadStart

APP创建Intent传递数据到其他Activity,如果创建的Activity不是在同一个Task中打开,就很可能被其他的Activity劫持读取到Intent内容,跨Task的Activity通过Intent传递敏感信息是不安全的。建议:
尽量避免使用包含FLAG_ACTIVITY_NEW_TASK标志的Intent来传递敏感信息。

参考资料:
http://wolfeye.baidu.com/blog/intent-data-leak

警告

检测到31个导出的组件接收其他app的消息,这些组件会被其他app引用并导致dos攻击。

activity com.tencent.reading.ui.TestEmptyActivity
activity com.tencent.reading.ui.PushNewsDetailActivity
activity com.tencent.reading.ui.NewsJumpActivity
activity com.tencent.reading.wxapi.WXEntryActivity
activity com.tencent.reading.wxapi.WXPayEntryActivity
activity com.tencent.reading.push.assist.PushAssistEmptyActivity
activity com.tencent.reading.push.alive.foreground.ForegroundEmptyActivity
activity com.tencent.reading.search.activity.NewsSearchActivity
activity com.tencent.tauth.AuthActivity
activity com.tencent.reading.kkvideo.wifi.KkFreeWifiListActivity
activity com.tencent.reading.share.activity.SinaWeiboShareActivity
activity com.tencent.midas.wx.APMidasWXPayActivity
activity com.tencent.midas.qq.APMidasQQWalletActivity
activity com.huawei.android.pushselfshow.richpush.RichPushActivity
service com.tencent.reading.push.PushService
service com.xiaomi.mipush.sdk.PushMessageHandler
service com.tencent.reading.account.SyncService
service com.tencent.reading.account.AccountService
service com.igexin.sdk.PushService
service cn.jpush.android.service.DaemonService
service com.baidu.android.pushservice.CommandService
service com.meizu.cloud.pushsdk.NotificationService
receiver com.tencent.reading.push.notify.visual.send.HaltLockScreenNotifyReceiver
receiver com.tencent.reading.push.mipush.MiPushMessageReceiver
receiver com.baidu.android.pushservice.RegistrationReceiver
receiver com.tencent.news.push.alive.offactivity.OffScreenReceiver
receiver com.tencent.reading.push.hwpush.HWPushMessageReceiver
receiver com.huawei.android.pushagent.PushEventReceiver
receiver com.huawei.android.pushagent.PushBootReceiver
receiver com.meizu.cloud.pushsdk.SystemReceiver
receiver com.tencent.reading.push.mzpush.MeizuPushMessageReceiver

建议:
(1)最小化组件暴露。对不会参与跨应用调用的组件建议显示添加android:exported="false"属性。
(2)设置组件访问权限。对provider设置权限,同时将权限的protectionLevel设置为"signature"或"signatureOrSystem"。
(3)组件传输数据验证。对组件之间,特别是跨应用的组件之间的数据传入与返回做验证和增加异常处理,防止恶意调试数据传入,更要防止敏感数据返回。

参考案例:
http://www.wooyun.org/bugs/wooyun-2010-0169746
http://www.wooyun.org/bugs/wooyun-2010-0104965

参考资料:
http://jaq.alibaba.com/blog.htm?spm=0.0.0.0.Wz4OeC&id=55
《Android安全技术解密与防范》

警告

检测到4个导出的隐式Service组件。
service com.tencent.reading.push.PushService
service com.tencent.reading.account.SyncService
service com.tencent.reading.account.AccountService
service cn.jpush.android.service.DaemonService

建议:为了确保应用的安全性,启动Service时,请始终使用显式Intent,且不要为服务声明Intent过滤器。使用隐式Intent启动服务存在安全隐患,因为您无法确定哪些服务将响应Intent,且用户无法看到哪些服务已启动。从Android 5.0(API 级别 21)开始,如果使用隐式 Intent 调用 bindService(),系统会抛出异常。

参考资料:
https://developer.android.com/guide/components/intents-filters.html#Types

警告

检测7处組件設置了android.intent.category.BROWSABLE属性。
com.tencent.reading.ui.TestEmptyActivity
com.tencent.reading.ui.PushNewsDetailActivity
com.tencent.reading.ui.NewsJumpActivity
com.tencent.reading.push.assist.PushAssistEmptyActivity
com.tencent.tauth.AuthActivity
com.tencent.midas.qq.APMidasQQWalletActivity
com.tencent.reading.push.PushService


在AndroidManifest文件中定义了android.intent.category.BROWSABLE属性的组件,可以通过浏览器唤起,这会导致远程命令执行漏洞攻击。建议:
(1)APP中任何接收外部输入数据的地方都是潜在的攻击点,过滤检查来自网页的参数。
(2)不要通过网页传输敏感信息,有的网站为了引导已经登录的用户到APP上使用,会使用脚本动态的生成URL Scheme的参数,其中包括了用户名、密码或者登录态token等敏感信息,让用户打开APP直接就登录了。恶意应用也可以注册相同的URL Sechme来截取这些敏感信息。Android系统会让用户选择使用哪个应用打开链接,但是如果用户不注意,就会使用恶意应用打开,导致敏感信息泄露或者其他风险。

參考案例:
http://www.wooyun.org/bugs/wooyun-2014-073875
http://www.wooyun.org/bugs/wooyun-2014-067798

参考资料:
http://wolfeye.baidu.com/blog/intent-scheme-url/
http://www.jssec.org/dl/android_securecoding_en.pdf
http://drops.wooyun.org/mobile/15202
http://blog.csdn.net/l173864930/article/details/36951805
http://drops.wooyun.org/papers/2893

警告

检测到29潜在的XSS漏洞。

位置: classes.dex
com.tencent.ads.view.AdWebView;->setJsWebChromeClient(Lcom.tencent.ads.a.a; Landroid.webkit.WebChromeClient;)V
com.tencent.reading.tad.ui.WebAdvertActivity;->ˉ()V
com.tencent.reading.ui.SupportActivity;->ʽ()V
com.tencent.reading.ui.view.NewsWebView;->ʻ(Landroid.content.Context;)V
com.tencent.reading.webview.CustomWebBrowserForItemActivity;->initView()V
com.tencent.reading.webview.WebBrowserActivity;->initView()V
com.tencent.reading.webview.WebDetailActivity;->initWebView()V
com.tencent.reading.webview.WebMusicActivity;->initView()V
com.tencent.reading.webview.WebVideoActivity;->initView()V

位置: classes2.dex
com.huawei.android.pushselfshow.richpush.html.HtmlViewer;->a()V
com.sina.weibo.sdk.component.WeiboSdkBrowser;->ʽ()V
com.tencent.bugly.crashreport.b;->setJavaScriptEnabled(Z)V
com.tencent.connect.auth.AuthDialog;->ʽ()V
com.tencent.intervideo.nowproxy.proxyinner.activity.WebActivity;->onCreate(Landroid.os.Bundle;)V
com.tencent.midas.jsbridge.APWebView;->a()V
com.tencent.open.PKDialog;->initViews()V
com.tencent.open.SocialApiIml;->writeEncryToken(Landroid.content.Context;)V
com.tencent.open.TDialog;->b()V
com.tencent.reading.rose.view.RosePageWebView;->ʼ(Landroid.content.Context;)V
com.tencent.reading.rose.view.RoseWebView;->setData(I I Ljava.lang.String; I)V
com.tencent.reading.tad.ui.WebDialogActivity;->ʼ()V
com.tencent.reading.ui.WebVideoActivity;->ʻ()V
com.tencent.reading.ui.view.RichEditor;->ʼ()V
com.tencent.reading.webview.WebBrowserForSearchDetailActivity;->initView()V
com.tencent.reading.webview.WebSearchActivity;->initView()V
oicq.wlogin_sdk.quicklogin.QuickLoginWebViewLoader;->load(Landroid.app.Activity; Landroid.content.Intent;)V

位置: assets/plugin/com.tencent.reading.car.apk
com.tencent.reading.car.view.CarWebView;->initView(Landroid.content.Context;)V

位置: assets/plugin/com.tencent.reading.minsheng.apk
com.tencent.reading.minsheng.view.AffairWebView;->initView(Landroid.content.Context;)V

位置: assets/plugin/com.tencent.reading.vertical.portfolio.apk
com.tencent.reading.vertical.portfolio.data.ui.PortfolioStockDetailActivity;->onCreate(Landroid.os.Bundle;)V

允许WebView执行JavaScript(setJavaScriptEnabled),有可能导致XSS攻击。建议尽量避免使用。
(1)API等于高高于17的Android系统。出于安全考虑,为了防止Java层的函数被随意调用,Google在4.2版本之后,规定允许被调用的函数必须以@JavascriptInterface进行注解。
(2)API等于高高于17的Android系统。建议不要使用addJavascriptInterface接口,以免带来不必要的安全隐患,如果一定要使用该接口,建议使用证书校验。
u(3)使用removeJavascriptInterface移除Android系统内部的默认内置接口:searchBoxJavaBridge_、accessibility、accessibilityTraversal。

参考案例:
www.wooyun.org/bugs/wooyun-2015-0140708
www.wooyun.org/bugs/wooyun-2016-0188252

参考资料:
http://jaq.alibaba.com/blog.htm?id=48
http://blog.nsfocus.net/android-webview-remote-code-execution-vulnerability-analysis

警告

检测到15处IvParameterSpec的使用。

位置: classes.dex
cn.com.iresearch.dau.c.a;->()V
com.googlecode.mp4parser.boxes.cenc.CencDecryptingSampleList;->getCipher(Ljavax.crypto.SecretKey; [B)Ljavax.crypto.Cipher;
com.googlecode.mp4parser.boxes.cenc.CencDecryptingSampleList;->getCipher(Ljavax.crypto.SecretKey; [B)Ljavax.crypto.Cipher;
com.googlecode.mp4parser.boxes.cenc.CencEncryptingSampleList;->initCipher([B Ljavax.crypto.SecretKey;)V
com.huawei.android.pushagent.utils.a.a.a;->a(Ljava.lang.String;)Ljava.lang.String;
com.huawei.android.pushagent.utils.a.a.a;->b(Ljava.lang.String;)Ljava.lang.String;
com.tencent.ads.utility.d;->ʻ(Ljava.lang.String; Ljava.lang.String; [B)[B
com.tencent.bugly.proguard.y;->a(I [B [B)[B
com.tencent.reading.utils.i;->ʻ(Ljava.lang.String; [B [B Ljava.lang.String;)[B
com.xiaomi.mipush.sdk.e;->ʻ([B I)Ljavax.crypto.Cipher;

位置: classes2.dex
com.huawei.android.pushagent.plugin.c.a.a;->a([B Ljava.security.Key; I)[B
com.tencent.bugly.proguard.ad;->a([B)[B
com.tencent.bugly.proguard.ad;->b([B)[B
com.tencent.bugly.proguard.ae;->a([B)[B
com.tencent.bugly.proguard.ae;->b([B)[B

使用IVParameterSpec函数,如果使用了固定的初始化向量,那么密码文本可预测性高得多,容易受到字典攻击等。建议禁止使用常量初始化矢量构造IVParameterSpec,使用聚安全提供的安全组件。

参考资料:
http://drops.wooyun.org/tips/15870
https://developer.android.com/training/articles/keystore.html
http://wolfeye.baidu.com/blog/weak-encryption/
http://www.freebuf.com/articles/terminal/99868.html

警告

检测到16处使用了加解密算法。密钥处理不当可能会导致信息泄露。

位置: classes.dex
cn.com.iresearch.dau.c.a;->a(Ljava.lang.String; [B)[B
com.tencent.bugly.proguard.y;->a(I [B [B)[B
cn.com.iresearch.dau.c.a;->a([B Ljava.lang.String;)[B
com.xiaomi.mipush.sdk.e;->ʻ([B I)Ljavax.crypto.Cipher;
com.huawei.android.pushagent.utils.a.a.a;->a(Ljava.lang.String;)Ljava.lang.String;
com.tencent.omgid.c.b;->ʻ([B)Ljava.lang.String;
com.tencent.mid.util.Util;->getHMAC(Ljava.lang.String; Ljava.lang.String;)[B
com.huawei.android.pushagent.utils.a.a.a;->b(Ljava.lang.String;)Ljava.lang.String;

位置: classes2.dex
com.sina.weibo.sdk.utils.a;->ʻ(Ljava.lang.String;)Ljava.security.Key;
com.tencent.bugly.proguard.ad;->b([B)[B
oicq.wlogin_sdk.request.d;->c(Landroid.content.Context; Ljava.lang.String;)Ljava.util.TreeMap;
ct.j;->([B)V
okio.ByteString;->hmac(Ljava.lang.String; Lokio.ByteString;)Lokio.ByteString;
oicq.wlogin_sdk.request.d;->a(Landroid.content.Context; Ljava.lang.String;)Ljava.util.TreeMap;
com.tencent.bugly.proguard.ad;->a([B)[B
com.huawei.android.pushagent.plugin.c.a.a;->b([B)V

参考案例:
http://www.wooyun.org/bugs/wooyun-2010-0105766
http://www.wooyun.org/bugs/wooyun-2015-0162907
http://www.wooyun.org/bugs/wooyun-2010-0187287

参考资料:
http://drops.wooyun.org/tips/15870
https://developer.android.com/training/articles/keystore.html


动态扫描发现风险点

风险等级 风险名称

中危

com.igexin.sdk.PushService
com.tencent.reading.wxapi.WXEntryActivity
com.tencent.reading.wxapi.WXPayEntryActivity

低危

com.tencent.reading tcp 0 0 10.0.3.15:44272 163.177.83.171:8080 CLOSE_WAIT

服务端分析

风险等级 风险名称

警告

检测到?处XSS漏洞。
开发中...

警告

检测到?处XSS跨站漏洞。
开发中...

应用证书