PixelifyNext | channel
142 subscribers
32 photos
36 files
30 links
Mainly updates to pixelify next but other projects too
Download Telegram
Yesterday I decided to give color to all the outputs of the customize, but what I didn't realize it's that magisk app doesn't let you output color (+1h changing prints for log and error definitions) 😭😭
😭21
BREAKING: Google Announced New Rules For Sideloading Apps

1. Enable developer mode

2. Confirm you aren't being coached:
A quick check to make sure that no one is talking you into turning off your security as scammers often pressure victims into disabling protections.

3. Restart your phone & reauthenticate:
This cuts off any remote access or active phone calls a scammer might be using to watch what you’re doing.

4. Come back after the protective waiting period and verify:
There is a one-time, one-day wait & then you can confirm that this is really you who’s making this change with our biometric authentication or device PIN. Scammers rely on manufactured urgency, so this breaks their spell.

5. Install apps:
Once you confirm you understand the risks, you’re all set to install apps from unverified developers, with the option of enabling for 7 days or indefinitely. For safety, you’ll still see a warning that the app is from an unverified developer, but you can just tap “Install Anyway.”
1
Btw, ik I havent updated the module in a while, but Im full with school, so prob it will be a while before I update it, but it will be soon
👍2
This isn't a leak, but...

BREAKING: Nekogram is secretly sending your phone numbers to the developer


The backdoor is hidden in the http://Extra.java
file, which differs from the template uploaded to the repository. The obfuscated code sends data as an inline request to the @nekonotificationbot, leaving no trace.

More info about the backdoor: https://github.com/Nekogram/Nekogram/issues/336 (locked by Nekogram devs)

To validate this, we made a PoC: an LSPosed module that replaces the bot ID and username to ours so all requests are going to it. That way, we confirmed that the phone numbers are being collected. Every. Login.

The PoC is available here: https://github.com/RomashkaTea/nekogram-proof-of-logging
1👏1
Via mystic leaks
👏1
There are also allegations around Cherrygram having the same backdoor as well. But the developer has made out his response, denying the usage of that "function" in release builds and the code itself existed by accident after base syncing: https://t.me/cherrygram/1138
New keybox!!
2
keybox.xml
12.6 KB
Status: 🟢🟢🟢
1
Btw, If anyone it's interested, don't use Firefox on Linux, via a cookie hijacking attack with less than 50 lines of code I stole all my accounts I had on the browser, so pls be careful and don't execute code you don't trust
Every chromium based it's vulnerable too, bur the attack it's a little more difficult, but it's still possible
I won't release the code (for obvious reasons) for now until I make sure the vulnerability it's patched
Google responded to the bug report, they WONT fix it 😭😭
Firefox say they won't fix it too, well, here's the files for Linux if anyone wants it
Here is the explanation, files and how to use the scripts, but pls use it responsibly
New keybox, strong integrity
If it's real it's gonna be amazing!
New keybox
🔥1