{"id":3199,"date":"2011-12-01T16:19:32","date_gmt":"2011-12-01T08:19:32","guid":{"rendered":"https:\/\/www.icocean.com\/wp\/?p=3199"},"modified":"2011-12-01T16:23:10","modified_gmt":"2011-12-01T08:23:10","slug":"%e9%9a%90%e7%a7%81%e8%ad%a6%e5%91%8a-%e6%b5%b7%e8%b1%9a%e6%b5%8f%e8%a7%88%e5%99%a8%e6%94%b6%e9%9b%86%e4%b8%8a%e4%bc%a0%e6%82%a8%e7%9a%84%e6%b5%8f%e8%a7%88%e5%8e%86%e5%8f%b2","status":"publish","type":"post","link":"https:\/\/www.icocean.com\/blog\/?p=3199","title":{"rendered":"[\u9690\u79c1]\u8b66\u544a: \u6d77\u8c5a\u6d4f\u89c8\u5668\u6536\u96c6\u4e0a\u4f20\u60a8\u7684\u6d4f\u89c8\u9690\u79c1\u4fe1\u606f"},"content":{"rendered":"<p>[PRIVACY] WARNING: Dolphin&#8217;s collection of your browsing history<\/p>\n<p>If it weren&#8217;t for things like this, I&#8217;d still be a fan of Dolphin Browser.<\/p>\n<p>Ever since the &#8216;webzine&#8217; &#8216;feature&#8217; came out (in version 6), this app forwards the URL of:<\/p>\n<ul>\n<li>Every link you click.<\/li>\n<li>Every search you enter.<\/li>\n<li>Every page you load.<\/li>\n<\/ul>\n<p>To: http:\/\/en.mywebzines.com\/v3\/columns?u=(URLencodedURL)&amp;t=(TIMESTAMP<\/p>\n<p>This includes:<\/p>\n<ul>\n<li>SSL URLs.<\/li>\n<li>QUERY_STRINGS.<\/li>\n<li>IP addresses on private networks and file:\/\/ urls.<\/li>\n<\/ul>\n<p>In addition, when I mentioned this on http:\/\/blog.dolphin-browser.com, the comment awaited moderation for two days before being deleted. I&#8217;ve yet to receive an email.<\/p>\n<p>Proof as following:<!--more--><\/p>\n<p>Code:<br \/>\n<code>[root@phone]~# ngrep -P '!' -lq -R -W single -M '(^GET|^POST|^Host:|^[^ ]ookie:)' \"tcp port 80\"<br \/>\ninterface: eth0 (10.23.1.0\/255.255.255.0)<br \/>\nfilter: (ip or ip6) and ( tcp port 80 )<br \/>\nmatch: (^GET|^POST|^Host:|^[^ ]ookie:)<\/code><\/p>\n<p>T 10.23.1.220:60126 -&gt; 107.20.41.53:80 [AP] GET \/v3\/columns?u=http%3A%2F%2F10.23.1.254%2F&amp;t=1319574537635 HTTP\/1.1!!Authorization: cd7f573ec9e6e865a28aaab7a1793796!!Accept-Encoding: gzip!!Host: en.mywebzines.com!!Connection: Keep-Alive!!!!<\/p>\n<p>(less spammy proof)<br \/>\n[G] www.google.com:80\/search?q=wut<br \/>\n[G] en.mywebzines.com:80\/v3\/columns?u=http%3A%2F%2Fwww.google.com%2Fsearch%3Fq%3Dwut&amp;t=1319574984926<br \/>\n[G] en.mywebzines.com:80\/v3\/columns?u=https%3A%2F%2Fwww.google.com%2Fsearch%3Fq%3Dwhat%2Bis%2Bthis%2Bi%2Bdont%2Beven&amp;t=1319575011872<br \/>\n[G] en.mywebzines.com:80\/v3\/columns?u=file%3A%2F%2Fsdcard%2Fdata%2Fhome.html&amp;t=1319575109160<\/p>\n<p>Stick this in your \/system\/etc\/hosts to make the Orwellian nightmare stop. This will break webzine &#8216;functionality&#8217;, and is only possible on rooted phones:<br \/>\nCode:<\/p>\n<p>127.0.0.1 en.mywebzines.com mywebzines.com<\/p>\n<p>Alternatively, here is how to remove this via APKTool:<br \/>\nCode:<br \/>\n<code>* apktool d mobi.mgeek.TunnyBrowser-1.apk<br \/>\n* apply the this patch to smali\/mobi\/mgeek\/TunnyBrowser\/WebViewCallbackHandler.smali<\/code><\/p>\n<p>#####<br \/>\n&#8212; orig-7.0\/smali\/mobi\/mgeek\/TunnyBrowser\/WebViewCallbackHandler.smali 2011-10-22 11:41:43.000000000 +0000<br \/>\n+++ mobi.mgeek.TunnyBrowser-7\/smali\/mobi\/mgeek\/TunnyBrowser\/WebViewCallbackHandler.smali 2011-10-22 11:40:18.000000000 +0000<br \/>\n@@ -2189,7 +2189,7 @@<\/p>\n<p>.line 576<br \/>\n:cond_2<br \/>\n&#8211; invoke-direct {p0, p1, v0}, Lmobi\/mgeek\/TunnyBrowser\/WebViewCallbackHandler;-&gt;a(Lcom\/dolphin\/browser\/core\/IWebView;Ljava\/lang\/String;)V<br \/>\n+# invoke-direct {p0, p1, v0}, Lmobi\/mgeek\/TunnyBrowser\/WebViewCallbackHandler;-&gt;a(Lcom\/dolphin\/browser\/core\/IWebView;Ljava\/lang\/String;)V<\/p>\n<p>goto :goto_0<br \/>\n.end method<br \/>\n#####<\/p>\n<p>I would attach an .apk of dolphin cleansed of it&#8217;s spyware AIDS, however I&#8217;m not sure if the mods would like that.<\/p>\n<p>update:<br \/>\nModified APKs posted http:\/\/forum.xda-developers.com\/showpost.php?p=18799432&amp;postcount=61<\/p>\n<p>update: Fiasco appears on http:\/\/www.androidpolice.com\/2011\/10\/27\/privacy-advisory-dolphin-hd-sends-url-of-every-page-you-visit-to-a-remote-server-in-plain-text\/<\/p>\n<p>update: Dolphin writes blog post claiming data is not retained, and that &#8216;feature&#8217; is disabled. Latest market version. (7.0.1\/id105) appears, still forwards urls<\/p>\n<p>update: Version 7.0.2 (id 106) no longer forwards urls.<\/p>\n<p>Last edited by Fnorder; 29th October 2011 at 02:03 AM.<br \/>\nFrom: http:\/\/forum.xda-developers.com\/showthread.php?t=1319529<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[PRIVACY] WARNING: Dolphin&#8217;s collection of your b <a href='https:\/\/www.icocean.com\/blog\/?p=3199' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3561,3562,172,1828,3560,1682,1157],"class_list":["post-3199","post","type-post","status-publish","format-standard","hentry","category-4","tag-dolphin","tag-privacy","tag-172","tag-1828","tag-3560","tag-1682","tag-1157","category-4-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3199"}],"version-history":[{"count":4,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3199\/revisions"}],"predecessor-version":[{"id":3203,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3199\/revisions\/3203"}],"wp:attachment":[{"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icocean.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}