Author Topic: Whatsapp stealer  (Read 17342 times)

0 Members and 3 Guests are viewing this topic.

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Whatsapp stealer
« on: May 24, 2014, 04:34:14 pm »
This is a 12 page walkthrough on how to make a fake apk to grap whatsapp database, decrypt the crypt5 file and read the messages.
http://upload.evilzone.org/download.php?id=5313095&type=zip
« Last Edit: May 24, 2014, 04:36:12 pm by Axon »

Offline Traitor4000

  • Knight
  • **
  • Posts: 191
  • Cookies: 8
    • View Profile
Re: Whatsapp stealer
« Reply #1 on: May 25, 2014, 05:07:59 am »
Too bad i have ishit not android...
The most vulnerable part of an impenetrable system is those who believe it to be so.

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: Whatsapp stealer
« Reply #2 on: May 25, 2014, 09:38:59 am »
It's a very simple method it seems. The "tutorial" was very simple, with lots of grammar mistakes though.
Thanks for the find, +cookie.

@Traitor4000: you can always change this awkward situation.

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Re: Whatsapp stealer
« Reply #3 on: May 25, 2014, 05:59:30 pm »
It's a very simple method it seems. The "tutorial" was very simple, with lots of grammar mistakes though.
Thanks for the find, +cookie.

Indeed it's a simple trick, but the next step is how convince the victim to download and install the apk?

Offline M1lak0

  • Peasant
  • *
  • Posts: 129
  • Cookies: 10
    • View Profile
Re: Whatsapp stealer
« Reply #4 on: May 25, 2014, 09:56:02 pm »
Indeed it's a simple trick, but the next step is how convince the victim to download and install the apk?
Hahah yes, thats where SE plays its role! :D
And thanks for the share! :)
"Security is just an illusion"

Offline d4rkcat

  • Knight
  • **
  • Posts: 287
  • Cookies: 115
  • He who controls the past controls the future. He who controls the present controls the past.
    • View Profile
    • Scripts
Re: Whatsapp stealer
« Reply #5 on: May 25, 2014, 10:10:29 pm »
There is a metasploit module exploit/android/browser/webview_addjavascriptinterface
This allows you to get an unprivileged java meterpreter on certain browsers used with android by simply getting the user to visit a malicious link.
You could then use a root exploit to escalate privileges and install your apk.
Jabber (OTR required): thed4rkcat@einfachjabber.de    Email (PGP required): thed4rkcat@yandex.com    PGP Key: here and here     Blog

<sofldan> not asking for anyone to hold my hand uber space shuttle door gunner guy.


Offline rex17

  • NULL
  • Posts: 4
  • Cookies: -2
    • View Profile
Re: Whatsapp stealer
« Reply #6 on: July 30, 2014, 11:57:34 am »
great post. But whatsapp has moved to crypt7 can i still use the same method

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Re: Whatsapp stealer
« Reply #7 on: August 28, 2014, 05:35:40 pm »
cool tutorial but I am unable to download the script from the below link

http://whatsapp123q.byethost16.com/wp.php
You got to be fucking kidding me?

Offline Schalla

  • VIP
  • Peasant
  • *
  • Posts: 81
  • Cookies: 29
    • View Profile
Re: Whatsapp stealer
« Reply #8 on: August 29, 2014, 07:02:51 am »
Wow.

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: Whatsapp stealer
« Reply #9 on: August 29, 2014, 07:41:47 am »
Wow.
You got to be fucking kidding me?

^This. Lol, at least he knows how to grab screenshots, pic related:

>>>import this
-----------------------------

Offline khofo

  • EZ's Swashbuckler
  • Knight
  • **
  • Posts: 350
  • Cookies: 25
  • My humor is so black, it could go cotton picking.
    • View Profile
Re: Whatsapp stealer
« Reply #10 on: August 31, 2014, 03:35:19 am »
Thanks dude I made a thread before to create a something like this
+1

Quote from: #Evilzone
<Spacecow18> priests are bad ppl
<Insanity> Holy crap
Of course God isnt dead. He's out there partying with the Easter Bunny, Santa Clause, Tooth Fairy, and the Man on the moon...
Some of my work: Introduction to Physical Security

Offline Devil_Zone

  • NULL
  • Posts: 1
  • Cookies: 0
    • View Profile
Re: Whatsapp stealer
« Reply #11 on: September 17, 2014, 07:20:17 pm »
hi Axon,


I tried it but when I want to export it to APK it says that it have some erros


 8)

Offline OfficialBossa

  • NULL
  • Posts: 1
  • Cookies: 0
    • View Profile
Re: Whatsapp stealer
« Reply #12 on: December 07, 2014, 10:19:38 pm »
This looks very interesting! Thanks for the post.
Is there any way of doing anything similar with iPhones?

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Re: Whatsapp stealer
« Reply #13 on: December 07, 2014, 10:22:39 pm »
This looks very interesting! Thanks for the post.
Is there any way of doing anything similar with iPhones?
I haven't come across anything related to apple phones, but if you manage to dig up something useful from the web. Don't hesitate to share.

Offline Jee_genius

  • NULL
  • Posts: 1
  • Cookies: 0
    • View Profile
Re: Whatsapp stealer
« Reply #14 on: April 07, 2015, 10:21:02 pm »
Just to add an idea,shall we place the crypt5 from the victims phone and place in our phone,and re install whats app and recover messages??