应用安全检测报告
应用安全检测报告,支持文件搜索、内容检索和AI代码分析
移动应用安全检测报告
NetGuard v2.334
53
安全评分
安全基线评分
53/100
低风险
综合风险等级
风险等级评定
- A
- B
- C
- F
应用存在一定安全风险,建议优化
漏洞与安全项分布
0
高危
20
中危
2
信息
1
安全
隐私风险评估
0
第三方跟踪器
隐私安全
未检测到第三方跟踪器
检测结果分布
高危安全漏洞
0
中危安全漏洞
20
安全提示信息
2
已通过安全项
1
重点安全关注
0
中危安全漏洞 Activity (eu.faircode.netguard.ActivitySettings) 未受保护。
[android:exported=true] 检测到 Activity 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 Activity (eu.faircode.netguard.ActivityForwardApproval) 未受保护。
[android:exported=true] 检测到 Activity 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 Service (eu.faircode.netguard.ServiceSinkhole) 受权限保护,但应检查权限保护级别。
Permission: android.permission.BIND_VPN_SERVICE [android:exported=true] 检测到 Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。
中危安全漏洞 Service (eu.faircode.netguard.ServiceExternal) 未受保护。
[android:exported=true] 检测到 Service 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 Service (eu.faircode.netguard.ServiceTileMain) 受权限保护,但应检查权限保护级别。
Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true] 检测到 Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。
中危安全漏洞 Service (eu.faircode.netguard.ServiceTileGraph) 受权限保护,但应检查权限保护级别。
Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true] 检测到 Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。
中危安全漏洞 Service (eu.faircode.netguard.ServiceTileFilter) 受权限保护,但应检查权限保护级别。
Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true] 检测到 Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。
中危安全漏洞 Service (eu.faircode.netguard.ServiceTileLockdown) 受权限保护,但应检查权限保护级别。
Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true] 检测到 Service 已导出并受未在本应用定义的权限保护。请在权限定义处核查其保护级别。若为 normal 或 dangerous,恶意应用可申请并与组件交互;若为 signature,仅同证书签名应用可访问。
中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.ReceiverAutostart) 未受保护。
[android:exported=true] 检测到 Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.ReceiverPackageRemoved) 未受保护。
[android:exported=true] 检测到 Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.WidgetMain) 未受保护。
[android:exported=true] 检测到 Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 Broadcast Receiver (eu.faircode.netguard.WidgetLockdown) 未受保护。
[android:exported=true] 检测到 Broadcast Receiver 已导出,未受任何权限保护,任意应用均可访问。
中危安全漏洞 高优先级 Intent(999) - {1} 个命中
[android:priority] 通过设置较高的 Intent 优先级,应用可覆盖其他请求,可能导致安全风险。
中危安全漏洞 IP地址泄露
IP地址泄露 Files: eu/faircode/netguard/ActivityForwardApproval.java, line(s) 31 eu/faircode/netguard/ActivityLog.java, line(s) 261 eu/faircode/netguard/ActivitySettings.java, line(s) 1027,1419 eu/faircode/netguard/AdapterLog.java, line(s) 86 eu/faircode/netguard/ServiceSinkhole.java, line(s) 1759,1784,1710,1891,1669,1754,1703,1711,1892,1748,1712,1893,1705,1706,1707,1739,1756,1773,1773,1773,1743,1744,1736,1737,1738,1745,1746,1749,1750,1919,1918,1751,1747
中危安全漏洞 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2 Files: eu/faircode/netguard/DatabaseHelper.java, line(s) 9,10,11,96,476,491,505,514,523,532,541,587,960 h0/C0502C.java, line(s) 4,9 h0/C0504E.java, line(s) 5,6,121 h0/C0518m.java, line(s) 4,19 h0/y.java, line(s) 6,7,98,243,324,355,373,445,490
中危安全漏洞 应用程序使用不安全的随机数生成器
应用程序使用不安全的随机数生成器 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators Files: R0/a.java, line(s) 4 q0/a.java, line(s) 3 q0/b.java, line(s) 3 q0/c.java, line(s) 4
中危安全漏洞 MD5是已知存在哈希冲突的弱哈希
MD5是已知存在哈希冲突的弱哈希 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4 Files: eu/faircode/netguard/Util.java, line(s) 625
中危安全漏洞 SHA-1是已知存在哈希冲突的弱哈希
SHA-1是已知存在哈希冲突的弱哈希 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4 Files: eu/faircode/netguard/Util.java, line(s) 188
中危安全漏洞 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
文件可能包含硬编码的敏感信息,如用户名、密码、密钥等 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10 Files: e/h.java, line(s) 63
中危安全漏洞 此应用可能包含硬编码机密信息
从应用程序中识别出以下机密确保这些不是机密或私人信息 dhP3Rfh0vnw9MEEKJLE8JwfRuSfSH0ZKYmNfsb86hCjjwYCaHHfqB0vUlB FJsDEZ08LyD2sycgEA0F9pTi7Sjbe3xgGY nk9RyZcJSaGcVgXXvK13Y1DuGlmuEOr1iltGs3hWNatjJ41W0KTC eyJhdWQiOiJUQVpPV1FMUCIsImV4cCI6MTg0MzE1ODcxNywiaWF0Ijo5NDM5MTQ3OTI1LCJpc3MiOiIiLCJqdGkiOiIiLCJuYmYiOjAsInN1YiI6IjIxNzEwNjU2MDMiLCJ0eXBlIjoiIn0= nF8fMHj1vNyQFxXjHD6cY7tM87wHubuabpQgpVA== mwWWSFaZ29ZxlAQk5JsrN606Q4HHMTssVuIq3sT
安全提示信息 应用程序记录日志信息,不得记录敏感信息
应用程序记录日志信息,不得记录敏感信息 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs Files: B/g.java, line(s) 51 B/i.java, line(s) 34 C/g.java, line(s) 291 D/d.java, line(s) 51,78,50,77 D/e.java, line(s) 563,583,600,562,582,599 F/d.java, line(s) 77,76 F/f.java, line(s) 59,105,58,104 G/l.java, line(s) 48,81,49,82 G/n.java, line(s) 60,94,106,164,59,70,73,83,93,96,105,143,146,152,163,49,71,144,153,84 H/h.java, line(s) 32,43,72,87,33,73,44,88 H/o.java, line(s) 48,33 I/f.java, line(s) 9,8 J/C0017i.java, line(s) 18,17 J/C0018j.java, line(s) 42,41 J/C0026s.java, line(s) 82,81 J/E.java, line(s) 51,50 J/S.java, line(s) 26,27 L/e.java, line(s) 66,67 M/B.java, line(s) 87,93,99,105,111,118,124,138,147,88,94,100,106,112,119,125,148,139 M/C0034b.java, line(s) 51,50,60,90,91 M/C0035c.java, line(s) 58,59 M/C0041i.java, line(s) 20,25,21,28 M/C0047o.java, line(s) 21,28,119,129,141,151,172,180,198,208,211,214,217,220,20,27,118,128,140,150,171,179,197,207,210,213,216,219 M/C0053v.java, line(s) 219,383,528,218,308,365,382,406,464,490,505,527,346,426,465 M/C0055x.java, line(s) 47,50,48,51 M/N.java, line(s) 69,78,85,70,79,86,87,88,91 M/Y.java, line(s) 61,96,101,60,95,100 O0/BinderC0566J.java, line(s) 48 O0/C0557A.java, line(s) 51 O0/C0577f.java, line(s) 202,303 O0/HandlerC0575d.java, line(s) 20 O0/x.java, line(s) 211,335 O0/z.java, line(s) 37 P0/AbstractC0616g.java, line(s) 152,186,319,323,329,338 P0/AbstractDialogInterfaceOnClickListenerC0597A.java, line(s) 23 P0/C0609M.java, line(s) 25 P0/C0620k.java, line(s) 76 P0/C0633y.java, line(s) 89,92,95,98,101,104,112,115,118,121,159,164 P0/N.java, line(s) 82 P0/O.java, line(s) 27 P0/P.java, line(s) 41 P0/S.java, line(s) 39,53 P0/V.java, line(s) 45,50 P0/X.java, line(s) 39 Q/c.java, line(s) 51,68,74,79,92,52,69,75,80,93 Q/o.java, line(s) 43,44 S0/C0649a.java, line(s) 74,85 T0/C0651a.java, line(s) 357,364,371,133,356,363,370,505,506,134 U/h.java, line(s) 17,18 U/i.java, line(s) 42,43 Y/d.java, line(s) 33,34 Y0/C0690a.java, line(s) 57,61 c0/l.java, line(s) 34,37,41,45,77,80,83,86,89 e/d.java, line(s) 259,242,260 eu/faircode/netguard/ActivityDns.java, line(s) 91,33,50,83,204 eu/faircode/netguard/ActivityForwardApproval.java, line(s) 40,56,61 eu/faircode/netguard/ActivityLog.java, line(s) 138,264,289,297,81,85,103,118,209,450,606,253,259,266,217,464,469 eu/faircode/netguard/ActivityMain.java, line(s) 174,1047,94,119,129,224,413,471,497,504,508,556,564,572,589,601,866,912,929,999,1054,1076,477 eu/faircode/netguard/ActivityPro.java, line(s) 55,99,242,328,338 eu/faircode/netguard/ActivitySettings.java, line(s) 228,263,299,684,763,855,215,221,570,663,869,927,1097,236,255,898,1528 eu/faircode/netguard/AdapterLog.java, line(s) 89,213,230,259,266,306 eu/faircode/netguard/AdapterRule.java, line(s) 409,848 eu/faircode/netguard/ApplicationEx.java, line(s) 46,59 eu/faircode/netguard/DatabaseHelper.java, line(s) 102,242,266,629,634,699,976,1022,1025,1099,113,121,127,134,140,295,311,654,721,732,866,76,81,423 eu/faircode/netguard/DownloadTask.java, line(s) 214,76,88,102,134,145,197 eu/faircode/netguard/IAB.java, line(s) 157,41,47,51,59,164,169,183,188,200,212,228,235,241,265,276,299,304,317 eu/faircode/netguard/IPUtil.java, line(s) 21,89,110 eu/faircode/netguard/ReceiverAutostart.java, line(s) 22,25,30,75 eu/faircode/netguard/ReceiverPackageRemoved.java, line(s) 13 eu/faircode/netguard/Rule.java, line(s) 260,354,444,655,727,760,784,832,145 eu/faircode/netguard/ServiceExternal.java, line(s) 102,107,113,121,128,44,65,92 eu/faircode/netguard/ServiceSinkhole.java, line(s) 791,797,862,868,897,910,1239,1468,1473,3497,3506,264,557,597,707,915,948,1150,1485,1730,1768,1777,1781,1809,1816,1823,1833,2407,2503,2697,2813,2832,2860,3110,3196,3340,3458,139,186,189,204,207,220,237,241,247,253,265,295,299,306,310,317,323,331,341,344,357,375,584,588,591,617,620,628,633,645,654,658,672,686,782,803,809,939,959,978,1123,1216,1232,1501,1529,1545,1547,1551,1587,1605,1622,1644,1648,1670,1674,1680,1694,1723,1763,1786,1791,1807,1830,1851,1906,1928,2003,2007,2078,2085,2109,2178,2183,2192,2207,2221,2226,2252,2270,2278,2341,2366,2373,2402,2422,2463,2470,2498,2529,2680,2870,3120,3153,3158,3160,3166,3202,3204,3209,3212,3218,3223,3347,3360,3414,3465,3472,3482,3492,3517,3526,3551,746,815,937,957,976,1135,1170,1536,2052,2055,2072,2088,2309,2314,2677,2693,2736,3351,3398 eu/faircode/netguard/ServiceTileFilter.java, line(s) 23,44,50 eu/faircode/netguard/ServiceTileGraph.java, line(s) 24,43,49 eu/faircode/netguard/ServiceTileLockdown.java, line(s) 22,36,42 eu/faircode/netguard/ServiceTileMain.java, line(s) 28,44,61,67 eu/faircode/netguard/Util.java, line(s) 614,169,559,510 eu/faircode/netguard/WidgetAdmin.java, line(s) 20,59 eu/faircode/netguard/WidgetLockdown.java, line(s) 29 eu/faircode/netguard/WidgetMain.java, line(s) 29 k/C0536e.java, line(s) 68 m0/d.java, line(s) 67,113,120 m0/g.java, line(s) 31,52,61,65,75,81,84,89 m0/h.java, line(s) 39 m0/j.java, line(s) 30 m0/o.java, line(s) 50 m0/s.java, line(s) 25 r/C0645d.java, line(s) 106,111,118,122,134,142 s/d.java, line(s) 53,60,71,76,52,59,64,70,75,65
安全提示信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它 https://github.com/OWASP/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard Files: eu/faircode/netguard/ActivityLog.java, line(s) 6,379 eu/faircode/netguard/ActivityPro.java, line(s) 5,150 eu/faircode/netguard/AdapterRule.java, line(s) 6,157
已通过安全项 此应用程序没有隐私跟踪程序
此应用程序不包括任何用户或设备跟踪器。在静态分析期间没有找到任何跟踪器。
综合安全基线评分总结
NetGuard v2.334
Android APK
53
综合安全评分
中风险