导航菜单

应用安全检测报告

应用安全检测报告,支持文件搜索、内容检索和AI代码分析

移动应用安全检测报告

应用图标

NetGuard v2.334

Android APK c9383bce...
53
安全评分

安全基线评分

53/100

低风险

综合风险等级

风险等级评定
  1. A
  2. B
  3. C
  4. F

应用存在一定安全风险,建议优化

漏洞与安全项分布

0 高危
20 中危
2 信息
1 安全

隐私风险评估

0
第三方跟踪器

隐私安全
未检测到第三方跟踪器


检测结果分布

高危安全漏洞 0
中危安全漏洞 20
安全提示信息 2
已通过安全项 1
重点安全关注 0

中危安全漏洞 Activity (eu.faircode.netguard.ActivitySettings) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Activity (eu.faircode.netguard.ActivityForwardApproval) 未受保护。

[android:exported=true]
检测到  Activity 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Service (eu.faircode.netguard.ServiceSinkhole) 受权限保护,但应检查权限保护级别。

Permission: android.permission.BIND_VPN_SERVICE [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Service (eu.faircode.netguard.ServiceExternal) 未受保护。

[android:exported=true]
检测到  Service 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Service (eu.faircode.netguard.ServiceTileMain) 受权限保护,但应检查权限保护级别。

Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Service (eu.faircode.netguard.ServiceTileGraph) 受权限保护,但应检查权限保护级别。

Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Service (eu.faircode.netguard.ServiceTileFilter) 受权限保护,但应检查权限保护级别。

Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Service (eu.faircode.netguard.ServiceTileLockdown) 受权限保护,但应检查权限保护级别。

Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true]
检测到  Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。

中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.ReceiverAutostart) 未受保护。

[android:exported=true]
检测到  Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.ReceiverPackageRemoved) 未受保护。

[android:exported=true]
检测到  Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.WidgetMain) 未受保护。

[android:exported=true]
检测到  Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.WidgetLockdown) 未受保护。

[android:exported=true]
检测到  Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。

中危安全漏洞 高优先级 Intent(999) - {1} 个命中

[android:priority]
通过设置较高的 Intent 优先级,应用可覆盖其他请求,可能导致安全风险。

中危安全漏洞 IP地址泄露

IP地址泄露


Files:
eu/faircode/netguard/ActivityForwardApproval.java, line(s) 31
eu/faircode/netguard/ActivityLog.java, line(s) 261
eu/faircode/netguard/ActivitySettings.java, line(s) 1027,1419
eu/faircode/netguard/AdapterLog.java, line(s) 86
eu/faircode/netguard/ServiceSinkhole.java, line(s) 1759,1784,1710,1891,1669,1754,1703,1711,1892,1748,1712,1893,1705,1706,1707,1739,1756,1773,1773,1773,1743,1744,1736,1737,1738,1745,1746,1749,1750,1919,1918,1751,1747

中危安全漏洞 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
eu/faircode/netguard/DatabaseHelper.java, line(s) 9,10,11,96,476,491,505,514,523,532,541,587,960
h0/C0502C.java, line(s) 4,9
h0/C0504E.java, line(s) 5,6,121
h0/C0518m.java, line(s) 4,19
h0/y.java, line(s) 6,7,98,243,324,355,373,445,490

中危安全漏洞 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
R0/a.java, line(s) 4
q0/a.java, line(s) 3
q0/b.java, line(s) 3
q0/c.java, line(s) 4

中危安全漏洞 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
eu/faircode/netguard/Util.java, line(s) 625

中危安全漏洞 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
eu/faircode/netguard/Util.java, line(s) 188

中危安全漏洞 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
e/h.java, line(s) 63

中危安全漏洞 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
dhP3Rfh0vnw9MEEKJLE8JwfRuSfSH0ZKYmNfsb86hCjjwYCaHHfqB0vUlB
FJsDEZ08LyD2sycgEA0F9pTi7Sjbe3xgGY
nk9RyZcJSaGcVgXXvK13Y1DuGlmuEOr1iltGs3hWNatjJ41W0KTC
eyJhdWQiOiJUQVpPV1FMUCIsImV4cCI6MTg0MzE1ODcxNywiaWF0Ijo5NDM5MTQ3OTI1LCJpc3MiOiIiLCJqdGkiOiIiLCJuYmYiOjAsInN1YiI6IjIxNzEwNjU2MDMiLCJ0eXBlIjoiIn0=
nF8fMHj1vNyQFxXjHD6cY7tM87wHubuabpQgpVA==
mwWWSFaZ29ZxlAQk5JsrN606Q4HHMTssVuIq3sT

安全提示信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
B/g.java, line(s) 51
B/i.java, line(s) 34
C/g.java, line(s) 291
D/d.java, line(s) 51,78,50,77
D/e.java, line(s) 563,583,600,562,582,599
F/d.java, line(s) 77,76
F/f.java, line(s) 59,105,58,104
G/l.java, line(s) 48,81,49,82
G/n.java, line(s) 60,94,106,164,59,70,73,83,93,96,105,143,146,152,163,49,71,144,153,84
H/h.java, line(s) 32,43,72,87,33,73,44,88
H/o.java, line(s) 48,33
I/f.java, line(s) 9,8
J/C0017i.java, line(s) 18,17
J/C0018j.java, line(s) 42,41
J/C0026s.java, line(s) 82,81
J/E.java, line(s) 51,50
J/S.java, line(s) 26,27
L/e.java, line(s) 66,67
M/B.java, line(s) 87,93,99,105,111,118,124,138,147,88,94,100,106,112,119,125,148,139
M/C0034b.java, line(s) 51,50,60,90,91
M/C0035c.java, line(s) 58,59
M/C0041i.java, line(s) 20,25,21,28
M/C0047o.java, line(s) 21,28,119,129,141,151,172,180,198,208,211,214,217,220,20,27,118,128,140,150,171,179,197,207,210,213,216,219
M/C0053v.java, line(s) 219,383,528,218,308,365,382,406,464,490,505,527,346,426,465
M/C0055x.java, line(s) 47,50,48,51
M/N.java, line(s) 69,78,85,70,79,86,87,88,91
M/Y.java, line(s) 61,96,101,60,95,100
O0/BinderC0566J.java, line(s) 48
O0/C0557A.java, line(s) 51
O0/C0577f.java, line(s) 202,303
O0/HandlerC0575d.java, line(s) 20
O0/x.java, line(s) 211,335
O0/z.java, line(s) 37
P0/AbstractC0616g.java, line(s) 152,186,319,323,329,338
P0/AbstractDialogInterfaceOnClickListenerC0597A.java, line(s) 23
P0/C0609M.java, line(s) 25
P0/C0620k.java, line(s) 76
P0/C0633y.java, line(s) 89,92,95,98,101,104,112,115,118,121,159,164
P0/N.java, line(s) 82
P0/O.java, line(s) 27
P0/P.java, line(s) 41
P0/S.java, line(s) 39,53
P0/V.java, line(s) 45,50
P0/X.java, line(s) 39
Q/c.java, line(s) 51,68,74,79,92,52,69,75,80,93
Q/o.java, line(s) 43,44
S0/C0649a.java, line(s) 74,85
T0/C0651a.java, line(s) 357,364,371,133,356,363,370,505,506,134
U/h.java, line(s) 17,18
U/i.java, line(s) 42,43
Y/d.java, line(s) 33,34
Y0/C0690a.java, line(s) 57,61
c0/l.java, line(s) 34,37,41,45,77,80,83,86,89
e/d.java, line(s) 259,242,260
eu/faircode/netguard/ActivityDns.java, line(s) 91,33,50,83,204
eu/faircode/netguard/ActivityForwardApproval.java, line(s) 40,56,61
eu/faircode/netguard/ActivityLog.java, line(s) 138,264,289,297,81,85,103,118,209,450,606,253,259,266,217,464,469
eu/faircode/netguard/ActivityMain.java, line(s) 174,1047,94,119,129,224,413,471,497,504,508,556,564,572,589,601,866,912,929,999,1054,1076,477
eu/faircode/netguard/ActivityPro.java, line(s) 55,99,242,328,338
eu/faircode/netguard/ActivitySettings.java, line(s) 228,263,299,684,763,855,215,221,570,663,869,927,1097,236,255,898,1528
eu/faircode/netguard/AdapterLog.java, line(s) 89,213,230,259,266,306
eu/faircode/netguard/AdapterRule.java, line(s) 409,848
eu/faircode/netguard/ApplicationEx.java, line(s) 46,59
eu/faircode/netguard/DatabaseHelper.java, line(s) 102,242,266,629,634,699,976,1022,1025,1099,113,121,127,134,140,295,311,654,721,732,866,76,81,423
eu/faircode/netguard/DownloadTask.java, line(s) 214,76,88,102,134,145,197
eu/faircode/netguard/IAB.java, line(s) 157,41,47,51,59,164,169,183,188,200,212,228,235,241,265,276,299,304,317
eu/faircode/netguard/IPUtil.java, line(s) 21,89,110
eu/faircode/netguard/ReceiverAutostart.java, line(s) 22,25,30,75
eu/faircode/netguard/ReceiverPackageRemoved.java, line(s) 13
eu/faircode/netguard/Rule.java, line(s) 260,354,444,655,727,760,784,832,145
eu/faircode/netguard/ServiceExternal.java, line(s) 102,107,113,121,128,44,65,92
eu/faircode/netguard/ServiceSinkhole.java, line(s) 791,797,862,868,897,910,1239,1468,1473,3497,3506,264,557,597,707,915,948,1150,1485,1730,1768,1777,1781,1809,1816,1823,1833,2407,2503,2697,2813,2832,2860,3110,3196,3340,3458,139,186,189,204,207,220,237,241,247,253,265,295,299,306,310,317,323,331,341,344,357,375,584,588,591,617,620,628,633,645,654,658,672,686,782,803,809,939,959,978,1123,1216,1232,1501,1529,1545,1547,1551,1587,1605,1622,1644,1648,1670,1674,1680,1694,1723,1763,1786,1791,1807,1830,1851,1906,1928,2003,2007,2078,2085,2109,2178,2183,2192,2207,2221,2226,2252,2270,2278,2341,2366,2373,2402,2422,2463,2470,2498,2529,2680,2870,3120,3153,3158,3160,3166,3202,3204,3209,3212,3218,3223,3347,3360,3414,3465,3472,3482,3492,3517,3526,3551,746,815,937,957,976,1135,1170,1536,2052,2055,2072,2088,2309,2314,2677,2693,2736,3351,3398
eu/faircode/netguard/ServiceTileFilter.java, line(s) 23,44,50
eu/faircode/netguard/ServiceTileGraph.java, line(s) 24,43,49
eu/faircode/netguard/ServiceTileLockdown.java, line(s) 22,36,42
eu/faircode/netguard/ServiceTileMain.java, line(s) 28,44,61,67
eu/faircode/netguard/Util.java, line(s) 614,169,559,510
eu/faircode/netguard/WidgetAdmin.java, line(s) 20,59
eu/faircode/netguard/WidgetLockdown.java, line(s) 29
eu/faircode/netguard/WidgetMain.java, line(s) 29
k/C0536e.java, line(s) 68
m0/d.java, line(s) 67,113,120
m0/g.java, line(s) 31,52,61,65,75,81,84,89
m0/h.java, line(s) 39
m0/j.java, line(s) 30
m0/o.java, line(s) 50
m0/s.java, line(s) 25
r/C0645d.java, line(s) 106,111,118,122,134,142
s/d.java, line(s) 53,60,71,76,52,59,64,70,75,65

安全提示信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
eu/faircode/netguard/ActivityLog.java, line(s) 6,379
eu/faircode/netguard/ActivityPro.java, line(s) 5,150
eu/faircode/netguard/AdapterRule.java, line(s) 6,157

已通过安全项 此应用程序没有隐私跟踪程序

此应用程序不包括任何用户或设备跟踪器。在静态分析期间没有找到任何跟踪器。

综合安全基线评分总结

应用图标

NetGuard v2.334

Android APK
53
综合安全评分
中风险