Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / NewStats: 3,201,240 members, 7,977,692 topics. Date: Thursday, 17 October 2024 at 12:05 PM |
Nairaland Forum / Science/Technology / Programming / N5000 For Correct Answer: How Does Palmpay Do This? (2372 Views)
Please help: Which API Does Opay/palmpay/kuda Use For Their Free Transactions? / 2nd Batch of Project-driven Fullstack Developer Training With N5000 Installment! / Any Way To Stop Palmpay Security Plugin On A Phone (2) (3) (4)
Re: N5000 For Correct Answer: How Does Palmpay Do This? by devdev: 7:36am On Sep 03, 2023 |
gistray:*** |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by silento(m): 9:08am On Sep 03, 2023 |
gistray: I don't know much about app development on Android or iPhone , but on web , the tricks is browser fingerprinting Then the hash will be stored on server When request is made u compare to detect new browser or device I believe android development pack will have something similar |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 10:18am On Sep 03, 2023 |
silento: Seems you're the one who doesn't know how JWT works. Well thanks. 1 Like |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by Millerules(m): 10:22am On Sep 03, 2023 |
gistray: Hi. Have you tried resetting the AdvertisingID? I have used it once for an app to limit content. Clearing app data or reinstalling wouldn’t work until you do a hard reset of the device or reset the ads id. Even Google uses the ads id for ads tracking thats how they serve targeted ads. It’s wrong though according to Android best practices if you are not using it for Ads related purposes. I have shared a link. Try all the possible ways highlighted there it definitely should be one of those. Updated: I’m no sure even resetting the device would work as I believe it’s tied to your PlayStore account. So signing in same Google Play Store account should restore the previous AdvertisingID. I have not tested that before, you should. PS: Don’t use this for illegal purposes oo. If you collect loan go pay am [url] https://developer.android.com/training/articles/user-data-ids[/url] |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by silento(m): 1:13pm On Sep 03, 2023 |
gistray: U are welcome |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 1:39pm On Sep 03, 2023 |
Millerules: I'll definitely give this a try. But what if the app wasn't downloaded from play store or the user haven't logged into playstore? Thank u. |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by Millerules(m): 8:18am On Sep 04, 2023 |
gistray: If the app is not on PlayStore and downloaded from the web the app can still call the AdvertisingClient to get the ID since it has been programmed so. I’m really not sure if it’s PlayStore alone I was only guessing it could be tied to PlayStore user instance. However, I have seen some cases where the client returns a generic ID something like 000000. Be sure to test for your requirements. |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by minato12: 12:52am On Sep 06, 2023 |
gistray: Ur phone has its own unique IP whenever it connects to the internet, it can never be changed, websites register and stores this IP's in there database server for easy identification of gadgets.., you can try everything but you can't change ur internet address IP, because everytime you off and on ur data, it generates another static IP linked to the original, it only displays when you are connected to the internet |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 12:59am On Sep 06, 2023 |
minato12: VPN changes this. All what was posted here non works as I have tried them all Only thing I think of now is the Android GSF which is always unique and only changes after factory reset |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by minato12: 5:38am On Sep 06, 2023 |
gistray: Not VPN |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 5:40am On Sep 06, 2023 |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by Elscott007: 4:45pm On Sep 18, 2023 |
As stated before almost all banking app could dictate that a particular device had been used to register the app this is due to the fact that each device contain a specific ID which is used to identify it for each current season. So a token is generated by the device or ID which the app sever recognizes and that token is saved within the device storage so when next it sees the system it tends to identify it. But once the device undergoes hard rest all the information held by the device secondary storage is lost so the initial ID is lost and must be regenerated. |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 5:03pm On Sep 18, 2023 |
Elscott007: Non of this worked. I found out what worked already albeit a hectic and cumbersome process that involved me downloading and unpacking Palmpay raw apk to see what the heck they where doing |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by Millerules(m): 6:01pm On Sep 18, 2023 |
gistray: Kindly share what you found. 1 Like |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 11:39am On Sep 19, 2023 |
Millerules: Sure! When I'm done with why I asked the question in the first place. |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by bassdow: 11:52am On Sep 23, 2023 |
gistray: There are several ways I could implement such feature. I could use the DeviceID, IMEI, deviceHostName, etc. i could equally use a combination of those to generate a secrete code that would be stored serverSide with a reference probably stored on the device for quick access. Now, most times, I prefer using hard to alter values to generrate secretes, rather than assigning fresh vales. that way, rather than assigning your device a random unique secrete code, I could generate that out of a combination of IMEI + DeviceID, then garnish it with few other variables. that way, even if I generates it 1-million times, it always would be same. Just like how olden Days password checkings worked. Now depending on how complex I want to go, just changing your IMEI alone, and not your deviceID is enough for me to susppect foulPlay because I would see IMEI looks new, but deviceID is known. Who knows how many other variables I use in considerations ; hence even despite changing your IMEI, I still could make the system reAssign you same token generated earlier, rather than generating a Fresh token. As for storage, I would choose storage locations that couldn't be easily clearred without doing hardReset, or flashing the device. The way I do most of these, are quite similar to [b]fingerPrinting , hence just changing a couple of variables e.g IMEI, wouldn't be enough to get you a new token. Don't Forget to Never trust the User[/b] |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by gistray: 1:51pm On Sep 23, 2023 |
bassdow: All what u mentioned can be changed. Unfortunately that still won't work. |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by ANormalHuman: 5:09pm On Sep 23, 2023 |
gistray: Still looking for help on this? Can we meet on WhatsApp? If yes, drop your number. (I'm hoping the bounty is still intact?) |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by bassdow: 6:26pm On Sep 23, 2023 |
gistray: just gave idea on how it's done and I said fingerPrinting. No matter how it's done, if it's rooted, and the user is determined, it could always be byPassed. except I didn't understand what OP stated |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by BlackhatMentor: 8:11pm On Sep 23, 2023 |
OP u need this for hacking multiple accounts. I perceive this is the last piece of your puzzle. |
Re: N5000 For Correct Answer: How Does Palmpay Do This? by bassdow: 12:04am On Sep 24, 2023 |
BlackhatMentor:you mean like having multiple accounts with same login ? or maybe the mobile app is a trial version, He wants to always extend it by appearing to be a new user |
How Can I Send Bulk SMS To MTN Numbers With My Sender Id / Your Career Is Your Future,get Best Web Development Training With Yemlat / What It Takes To Develop An Android App (for Beginners Only)
(Go Up)
Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health religion celebs tv-movies music-radio literature webmasters programming techmarket Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10) Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 48 |