SlideShare a Scribd company logo
1 of 17
My bored Sunday morning PWN
Sarodj
Some of my IRC buddys were playing something called
Mypetgirlfriend (i know right..). They were bragging about how high
there level was an how many videos they unlocked.
So i thought hey lets check out where all the fuzz is about. And so
my little adventure started...
My bored Sunday morning PWN
Sarodj
I jumped to my Blackmart app and
downloaded+installed the APK.
Ofcourse i did some restrictions with
Xprivacy just to be sure ;)
My bored Sunday morning PWN
Sarodj
So i ran the app. And OH MY GOD
what the fuck is this... how
pathetic...
I hope these guys were doing this
for fun.
My bored Sunday morning PWN
Sarodj
So i wanted to check out the vid
thingy they were talking about,
anddd dammit. You need to do
some kind of leveling. Im not into
this shit, im a IT guy and i want a
quick profit so.....
My bored Sunday morning PWN
Sarodj
So i went to the folder where
appdata is stored in common and
found some config files. I tweaked
some game values like the user
points, energy, fullnes, hygiene,
love and comfort.
I also set my user level to 1337 :)
My bored Sunday morning PWN
Sarodj
I unlocked all the video's and
can watch anything i want within
a few minutes of poking around.
What i did noticed is that it
downloaded the videos from a
external source.
But the story did not end here :)
PROFITTTT
My bored Sunday morning PWN
Sarodj
So i tried the changing clothes option. It turned
out that the only casual was free. By this time i
told my IRC buddys about my pwn and they
said i should hack the app in such way that the
bikini clothes are activated.
So i had this idea that the data is not stored
localy but on a external server, I know this
because all the movies in the movie shop are
being downloaded. It is time for some
TCPdump magic >:)
My bored Sunday morning PWN
Sarodj
So i installed TCPdump on my phone and
started a capture trough a ADB shell.
Simultaneously I download a video from the
video store to see where the app is
downloading its videos from.
I copied the PCAP capture to my desktop and
for further analysis.
My bored Sunday morning PWN
Sarodj
Wireshark did gave back a URL so i decided
it was time to download the bikini clothes
video. The only problem was that i did not
know the filename of the video, so i was
hoping on a directory listing.
My bored Sunday morning PWN
Sarodj
But no directory listing was
given that day... FUCK
My bored Sunday morning PWN
Sarodj
So now i have to pull the APK from my
phone and reverse engineer it in order
to find the video ID's.
My bored Sunday morning PWN
Sarodj
After i poked aroud a bit i
found a file with allot of
videonames in it. I decided to
filter out the list with some
commands and write a script
to download them all.
My bored Sunday morning PWN
Sarodj
Did exactly that...
My bored Sunday morning PWN
Sarodj
Execute and downloading
My bored Sunday morning PWN
Sarodj
And i found the bikini videos :).
The only thing have to do is
push them to my phone and
change the config.
PROFITTTT
My bored Sunday morning PWN
Sarodj
But what ID to put in the
config?
I messed around a bit with
grep and found out that the
current video has videoname
v004111.mp4. The
USER_DRESS int is 14111.
Now lets change that to the
bikini video ID of
v00(4411).mp4.
My bored Sunday morning PWN
Sarodj
Changed it and p00f. I have
absolutely no life. But it was
fun :)
+ i can brag about it @ my irc
buddys
PROFITTTT

More Related Content

Viewers also liked

Poundland interview questions and answers
Poundland interview questions and answersPoundland interview questions and answers
Poundland interview questions and answersannaari925
 
汉字Ppt
汉字Ppt汉字Ppt
汉字Ppttimrudy
 
ملتقي سواعد النجاح
ملتقي سواعد النجاحملتقي سواعد النجاح
ملتقي سواعد النجاحLatifa85
 
Case Study Managing Information System
Case Study Managing Information System Case Study Managing Information System
Case Study Managing Information System alinohalin
 
مركز ايليت لرعاية الخصوبه وحل مشاكل العقم
مركز ايليت  لرعاية الخصوبه  وحل مشاكل  العقممركز ايليت  لرعاية الخصوبه  وحل مشاكل  العقم
مركز ايليت لرعاية الخصوبه وحل مشاكل العقمelitefertilitycare
 
Presentation course slide show TED5401 UNAD Florida - Prof. Flor Lepervanche
Presentation course slide show TED5401 UNAD Florida - Prof. Flor LepervanchePresentation course slide show TED5401 UNAD Florida - Prof. Flor Lepervanche
Presentation course slide show TED5401 UNAD Florida - Prof. Flor Lepervancheflepervanche
 
tentang Mahkamah Konstitusi dan Judicial Review
tentang Mahkamah Konstitusi dan Judicial Reviewtentang Mahkamah Konstitusi dan Judicial Review
tentang Mahkamah Konstitusi dan Judicial ReviewAndo Medan
 

Viewers also liked (8)

Poundland interview questions and answers
Poundland interview questions and answersPoundland interview questions and answers
Poundland interview questions and answers
 
汉字Ppt
汉字Ppt汉字Ppt
汉字Ppt
 
ملتقي سواعد النجاح
ملتقي سواعد النجاحملتقي سواعد النجاح
ملتقي سواعد النجاح
 
Ultraopowieść
Ultraopowieść Ultraopowieść
Ultraopowieść
 
Case Study Managing Information System
Case Study Managing Information System Case Study Managing Information System
Case Study Managing Information System
 
مركز ايليت لرعاية الخصوبه وحل مشاكل العقم
مركز ايليت  لرعاية الخصوبه  وحل مشاكل  العقممركز ايليت  لرعاية الخصوبه  وحل مشاكل  العقم
مركز ايليت لرعاية الخصوبه وحل مشاكل العقم
 
Presentation course slide show TED5401 UNAD Florida - Prof. Flor Lepervanche
Presentation course slide show TED5401 UNAD Florida - Prof. Flor LepervanchePresentation course slide show TED5401 UNAD Florida - Prof. Flor Lepervanche
Presentation course slide show TED5401 UNAD Florida - Prof. Flor Lepervanche
 
tentang Mahkamah Konstitusi dan Judicial Review
tentang Mahkamah Konstitusi dan Judicial Reviewtentang Mahkamah Konstitusi dan Judicial Review
tentang Mahkamah Konstitusi dan Judicial Review
 

Recently uploaded

A Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyA Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyUXDXConf
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxDavid Michel
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyJohn Staveley
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessUXDXConf
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераMark Opanasiuk
 
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FIDO Alliance
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfFIDO Alliance
 
Agentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdfAgentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdfChristopherTHyatt
 
Strategic AI Integration in Engineering Teams
Strategic AI Integration in Engineering TeamsStrategic AI Integration in Engineering Teams
Strategic AI Integration in Engineering TeamsUXDXConf
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfFIDO Alliance
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Patrick Viafore
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutesconfluent
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2DianaGray10
 
UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1DianaGray10
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfFIDO Alliance
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlPeter Udo Diehl
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...FIDO Alliance
 
Powerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara LaskowskaPowerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara LaskowskaCzechDreamin
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...CzechDreamin
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfFIDO Alliance
 

Recently uploaded (20)

A Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System StrategyA Business-Centric Approach to Design System Strategy
A Business-Centric Approach to Design System Strategy
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
Structuring Teams and Portfolios for Success
Structuring Teams and Portfolios for SuccessStructuring Teams and Portfolios for Success
Structuring Teams and Portfolios for Success
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджера
 
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
FDO for Camera, Sensor and Networking Device – Commercial Solutions from VinC...
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 
Agentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdfAgentic RAG What it is its types applications and implementation.pdf
Agentic RAG What it is its types applications and implementation.pdf
 
Strategic AI Integration in Engineering Teams
Strategic AI Integration in Engineering TeamsStrategic AI Integration in Engineering Teams
Strategic AI Integration in Engineering Teams
 
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdfSimplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
Simplified FDO Manufacturing Flow with TPMs _ Liam at Infineon.pdf
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2
 
UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1UiPath Test Automation using UiPath Test Suite series, part 1
UiPath Test Automation using UiPath Test Suite series, part 1
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
 
Powerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara LaskowskaPowerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara Laskowska
 
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
Behind the Scenes From the Manager's Chair: Decoding the Secrets of Successfu...
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 

Some stupid app i pwned on a sunday morning

  • 1. My bored Sunday morning PWN Sarodj Some of my IRC buddys were playing something called Mypetgirlfriend (i know right..). They were bragging about how high there level was an how many videos they unlocked. So i thought hey lets check out where all the fuzz is about. And so my little adventure started...
  • 2. My bored Sunday morning PWN Sarodj I jumped to my Blackmart app and downloaded+installed the APK. Ofcourse i did some restrictions with Xprivacy just to be sure ;)
  • 3. My bored Sunday morning PWN Sarodj So i ran the app. And OH MY GOD what the fuck is this... how pathetic... I hope these guys were doing this for fun.
  • 4. My bored Sunday morning PWN Sarodj So i wanted to check out the vid thingy they were talking about, anddd dammit. You need to do some kind of leveling. Im not into this shit, im a IT guy and i want a quick profit so.....
  • 5. My bored Sunday morning PWN Sarodj So i went to the folder where appdata is stored in common and found some config files. I tweaked some game values like the user points, energy, fullnes, hygiene, love and comfort. I also set my user level to 1337 :)
  • 6. My bored Sunday morning PWN Sarodj I unlocked all the video's and can watch anything i want within a few minutes of poking around. What i did noticed is that it downloaded the videos from a external source. But the story did not end here :) PROFITTTT
  • 7. My bored Sunday morning PWN Sarodj So i tried the changing clothes option. It turned out that the only casual was free. By this time i told my IRC buddys about my pwn and they said i should hack the app in such way that the bikini clothes are activated. So i had this idea that the data is not stored localy but on a external server, I know this because all the movies in the movie shop are being downloaded. It is time for some TCPdump magic >:)
  • 8. My bored Sunday morning PWN Sarodj So i installed TCPdump on my phone and started a capture trough a ADB shell. Simultaneously I download a video from the video store to see where the app is downloading its videos from. I copied the PCAP capture to my desktop and for further analysis.
  • 9. My bored Sunday morning PWN Sarodj Wireshark did gave back a URL so i decided it was time to download the bikini clothes video. The only problem was that i did not know the filename of the video, so i was hoping on a directory listing.
  • 10. My bored Sunday morning PWN Sarodj But no directory listing was given that day... FUCK
  • 11. My bored Sunday morning PWN Sarodj So now i have to pull the APK from my phone and reverse engineer it in order to find the video ID's.
  • 12. My bored Sunday morning PWN Sarodj After i poked aroud a bit i found a file with allot of videonames in it. I decided to filter out the list with some commands and write a script to download them all.
  • 13. My bored Sunday morning PWN Sarodj Did exactly that...
  • 14. My bored Sunday morning PWN Sarodj Execute and downloading
  • 15. My bored Sunday morning PWN Sarodj And i found the bikini videos :). The only thing have to do is push them to my phone and change the config. PROFITTTT
  • 16. My bored Sunday morning PWN Sarodj But what ID to put in the config? I messed around a bit with grep and found out that the current video has videoname v004111.mp4. The USER_DRESS int is 14111. Now lets change that to the bikini video ID of v00(4411).mp4.
  • 17. My bored Sunday morning PWN Sarodj Changed it and p00f. I have absolutely no life. But it was fun :) + i can brag about it @ my irc buddys PROFITTTT