Data leakage between C/S communication: A case study on Android music app
Huanhuan Li, Qian Luo, Shubin Zhang, Haibin Zhang, Jiajia Liu · 2017
As the rapid development of mobile communication technology, smartphones have become indispensable elements in our daily life. Particularly, the increasingly rich smartphone applications (apps) bring great convenience to people while the defects generated in app designing and coding may pose unexpected threats to users. In this paper, we focus on the issue of data leakage between the app client and server. By analyzing the vulnerabilities of client-to-server communication and eavesdropping on the session data, we implement spoofing attack on a popular music app client. Two experiments are introduced in details: downloading songs freely by means of bypassing the payment mechanism and deceiving user into installing malware. In addition, the countermeasures are also provided.