Facebook Lite Report
Facebook Lite Report
Facebook Lite Report
Lite (373.0.0.0.3)
File Name: Facebook Lite.apk
Grade:
F
FINDINGS SEVERITY
55 16 2 4 1
FILE INFORMATION
File Name: Facebook Lite.apk
Size: 2.15MB
MD5: d8340f4a444f33f20cc752450de7eff1
SHA1: 8b1a1d3400cf7e39643b2466e1009dc6a2fdcdd7
SHA256: b0af382547043e98507e2702cce931273eed7cc26f378c9c011e20ce82f6279e
APP INFORMATION
App Name: Lite
Package Name: com.facebook.lite
Main Activity: com.facebook.lite.MainActivity
Target SDK: 33
Min SDK: 15
Max SDK:
Android Version Name: 373.0.0.0.3
Android Version Code: 500700028
APP COMPONENTS
Activities: 18
Services: 35
Receivers: 31
Providers: 9
Exported Activities: 30
Exported Services: 2
Exported Receivers: 11
Exported Providers: 4
CERTIFICATE INFORMATION
Binary is signed
v1 signature: True
v2 signature: True
v3 signature: False
v4 signature: False
X.509 Subject: C=US, ST=CA, L=Palo Alto, O=Facebook Mobile, OU=Facebook, CN=Facebook Corporation
Signature Algorithm: rsassa_pkcs1v15
Valid From: 2009-08-31 21:52:16+00:00
Valid To: 2050-09-25 21:52:16+00:00
Issuer: C=US, ST=CA, L=Palo Alto, O=Facebook Mobile, OU=Facebook, CN=Facebook Corporation
Serial Number: 0x4a9c4610
Hash Algorithm: md5
md5: 3fad024f2dcbe3ee693c96f350f8e376
sha1: 8a3c4b262d721acd49a4bf97d5213199c86fa2b9
sha256: e3f9e1e0cf99d0e56a055ba65e241b3399f7cea524326b0cdd6ec1327ed0fdc1
sha512: cd0c5bea15efd4c2620b5632a2d7618bc1cffb2edfc0f70e2f03ce593c162a93f655771bb2e222238889d4a5740f3dcbcd5b14b8a266602048500c67b0f07d14
PublicKey Algorithm: rsa
Bit Size: 1024
Fingerprint: f399a11f1d0ba109236e9b0cd20c7384a55d02042ba6c2500cec5a0001e165a1
Found 1 unique certificates
APPLICATION PERMISSIONS
read/modify/delete
Allows an application to write to external
android.permission.WRITE_EXTERNAL_STORAGE dangerous external storage
storage.
contents
PERMISSION STATUS INFO DESCRIPTION
FILE DETAILS
FINDINGS DETAILS
BROWSABLE ACTIVITIES
ACTIVITY INTENT
Schemes: fblite://,
com.facebook.lite.MainActivity
Mime Types: text/plain,
ACTIVITY INTENT
NETWORK SECURITY
HIGH: 4 | WARNING: 1 | INFO: 1 | SECURE: 2
NO SCOPE SEVERITY DESCRIPTION
1 * high Base config is insecurely configured to permit clear text traffic to all domains.
facebook.com
fbcdn.net
fbsbx.com
facebookcorewwwi.onion
fbcdn23dssr3jqnq.onion
fbsbx2q4mvcl63pw.onion
instagram.com
cdninstagram.com
workplace.com
oculus.com
5 secure Domain config is securely configured to disallow clear text traffic to these domains in scope.
facebookvirtualassistant.com
discoverapp.com
freebasics.com
internet.org
viewpointsfromfacebook.com
h.facebook.com
l.facebook.com
l.alpha.facebook.com
lm.facebook.com
l.instagram.com
NO SCOPE SEVERITY DESCRIPTION
facebook.com
Certificate pinning expires on 2024-09-04. After this date pinning will be disabled. [Pin:
fbcdn.net
x4QzPSC810K5/cMjb05Qm4k3Bw5zBn4lTdO/nEW/Td4= Digest: SHA-256,Pin:
fbsbx.com
ICGRfpgmOUXIWcQ/HXPLQTkFPEFPoDyjvH7ohhQpjzs= Digest: SHA-256,Pin:
facebookcorewwwi.onion
grX4Ta9HpZx6tSHkmCrvpApTQGo67CYDnvprLg5yRME= Digest: SHA-256,Pin:
fbcdn23dssr3jqnq.onion
58qRu/uxh4gFezqAcERupSkRYBlBAvfcw7mEjGPLnNU= Digest: SHA-256,Pin:
fbsbx2q4mvcl63pw.onion
r/mIkG3eEpVdm+u/ko/cwxzOMo1bk4TyHIlByibiA5E= Digest: SHA-256,Pin:
instagram.com
i7WTqTvh0OioIruIfFR4kMPnBqrS2rdiVPl/s2uC/CY= Digest: SHA-256,Pin:
cdninstagram.com
uUwZgwDOxcBXrQcntwu+kYFpkiVkOaezL0WYEZ3anJc= Digest: SHA-256,Pin:
workplace.com
WoiWRyIOVNa9ihaBciRSC7XHjliYS9VwUGOIud4PB18= Digest: SHA-256,Pin:
oculus.com
6 info Wd8xe/qfTwq3ylFNd3IpaqLHZbh2ZNCLluVzmeNkcpw= Digest: SHA-256,Pin:
facebookvirtualassistant.com
ape1HIIZ6T5d7GS61YBs3rD4NVvkfnVwELcCRW4Bqv0= Digest: SHA-256,Pin:
discoverapp.com
oC+voZLIy4HLE0FVT5wFtxzKKokLDRKY1oNkfJYe+98= Digest: SHA-256,Pin:
freebasics.com
K87oWBWM9UZfyddvDfoxL+8lpNyoUB2ptGtn0fv6G2Q= Digest: SHA-256,Pin:
internet.org
cGuxAXyFXFkWm61cF4HPWX8S0srS9j0aSqN0k4AP+4A= Digest: SHA-256,Pin:
viewpointsfromfacebook.com
aCdH+LpiG4fN07wpXtXKvOciocDANj0daLOJKNJ4fx4= Digest: SHA-256,Pin:
h.facebook.com
rn+WLLnmp9v3uDP7GPqbcaiRdd+UnCMrap73yz3yu/w= Digest: SHA-256,Pin:
l.facebook.com
C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M= Digest: SHA-256,Pin:
l.alpha.facebook.com
diGVwiVYbubAI3RW4hB9xU8e/CH2GnkuvVFZE8zmgzI= Digest: SHA-256,Pin:
lm.facebook.com
q4PO2G2cbkZhZ82+JgmRUyGMoAeozA+BSXVXQWB8XWQ= Digest: SHA-256]
l.instagram.com
h.facebook.com
l.facebook.com
7 l.alpha.facebook.com high Domain config is insecurely configured to permit clear text traffic to these domains in scope.
lm.facebook.com
l.instagram.com
h.facebook.com
l.facebook.com
8 l.alpha.facebook.com secure Certificate pinning does not have an expiry. Ensure that pins are updated before certificate expire. []
lm.facebook.com
l.instagram.com
CERTIFICATE ANALYSIS
HIGH: 1 | WARNING: 1 | INFO: 1
Application is signed with v1 signature scheme, making it vulnerable to Janus vulnerability on Android 5.0-8.0, if signed
Application vulnerable
warning only with v1 signature scheme. Applications running on Android 5.0-7.0 signed with v1, and v2/v3 scheme is also
to Janus Vulnerability
vulnerable.
Certificate algorithm
vulnerable to hash high Application is signed with MD5. MD5 hash algorithm is known to have collision issues.
collision
MANIFEST ANALYSIS
HIGH: 49 | WARNING: 8 | INFO: 0 | SUPPRESSED: 0
CODE ANALYSIS
HIGH: 1 | WARNING: 5 | INFO: 1 | SECURE: 1 | SUPPRESSED: 0
X/AnonymousClass017.java
X/AnonymousClass027.java
X/AnonymousClass032.java
X/AnonymousClass066.java
X/C003501n.java
X/C013005t.java
X/C022009o.java
The App logs information. Sensitive CWE: CWE-532: Insertion of Sensitive Information into Log File X/C02330Af.java
1 info
information should never be logged. OWASP MASVS: MSTG-STORAGE-3 X/C02M.java
X/C05H.java
X/C05T.java
X/C05V.java
X/C07E.java
X/C09X.java
X/C0AS.java
X/C0AZ.java
X/AnonymousClass093.java
CWE: CWE-330: Use of Insufficiently Random Values X/AnonymousClass095.java
The App uses an insecure Random
5 warning OWASP Top 10: M5: Insufficient Cryptography X/C03B.java
Number Generator.
OWASP MASVS: MSTG-CRYPTO-6 X/C03C.java
X/C0B8.java
NO ISSUE SEVERITY STANDARDS FILES
SYMBOLS
NO SHARED OBJECT NX STACK CANARY RPATH RUNPATH FORTIFY
STRIPPED
SYMBOLS
NO SHARED OBJECT NX STACK CANARY RPATH RUNPATH FORTIFY
STRIPPED
DOMAIN COUNTRY/REGION
IP: 157.240.205.35
Country: Netherlands
Region: Noord-Holland
m.facebook.com ok City: Amsterdam
Latitude: 52.374031
Longitude: 4.889690
View: Google Map
DOMAIN STATUS GEOLOCATION
IP: 157.240.205.35
Country: Netherlands
Region: Noord-Holland
www.facebook.com ok City: Amsterdam
Latitude: 52.374031
Longitude: 4.889690
View: Google Map
IP: 142.250.74.78
Country: United States of America
Region: California
www.android.com ok City: Mountain View
Latitude: 37.405991
Longitude: -122.078514
View: Google Map
HARDCODED SECRETS
POSSIBLE SECRETS
"google_api_key" : "AIzaSyBWJZPw7wVi-NQEViQV9ZnadO-xbX4S8o0"
aCdH+LpiG4fN07wpXtXKvOciocDANj0daLOJKNJ4fx4=
1RBv0Am3VA2bLMifS4uOCNDeaKSVc7CU
7oVvh3Fck1xX0J5u42DHceCqMyIqewU2TWaJlChTsZA
uUwZgwDOxcBXrQcntwu+kYFpkiVkOaezL0WYEZ3anJc=
POSSIBLE SECRETS
oSjSY8pqhXpum64U6nRyis9rV9XfVU3BgyBK6ru6RS8
i1R0ZwdXk2ev6WLsW1iXdNyytsuVi570wNd9O6D5wkA
AbX42B4J9OEFPkJ2iesKntcZmdU
Wd8xe/qfTwq3ylFNd3IpaqLHZbh2ZNCLluVzmeNkcpw=
eBLxbTAHR6nuEIur96W48dDc7Io
jriiCfLl5AQq3PaWv3Uemavb2hMrZhZ
ape1HIIZ6T5d7GS61YBs3rD4NVvkfnVwELcCRW4Bqv0=
HC4rwCH0AxqzQcvYDrHg5ikHBl2GnUuRnJLwuJJyt8o
diGVwiVYbubAI3RW4hB9xU8e/CH2GnkuvVFZE8zmgzI=
oC+voZLIy4HLE0FVT5wFtxzKKokLDRKY1oNkfJYe+98=
Dp3faO2KC6cZg6irlvtu9yL9H3E
Jm4bl26QMphvIVgzVUeQb6f37Ys3IKRmCw0LBgLJBzs
F5OoLdx6B8GGOezxJY0QifKgn3FjXCyp54J8bPv3yfI
sXPIxiZ1lvokCdbRCr64p0GHvtNvywjWNQmqJtqWw8Q
58qRu/uxh4gFezqAcERupSkRYBlBAvfcw7mEjGPLnNU=
POSSIBLE SECRETS
62Yjx8iYhpF3VA6BQQvyUObpLzjXx0Gs5PEm1cLJaf4
oXiTMLDip81kTvgXrtXtypfecxU3vmuNPlCfkOM
Y5Hqye7Bbux7I1qFFmbE6EqILj2ssTFQB9Ss6LwpmGE
4dJKibgNvwschNsyH9YBK3Hwl5zTIkQlBgZu10E
56Okh3GNc5c7nKYtifJU6wAaMW8
jYWbZ4GQZ28iGykpgUFoIDlGPXHb2sIWpDljhlYw
qadsRSPy8q2oOtZucRAyNlbBCyrbDQYWnD6ZESwR0vs
IIi8UGlEtWJZu9Pd7CjQO8rHxTA
pGLr1wNX3vElqWNF4QYKaubskS4
FRNYKa3Xwpy4PBUuvctQLZyChQw
Sr9mhPKOEwo6NysnYn803dZ3UiY
Xz5Q9DVYPJrmJjAqcfc0AEQIen4sYK2s
ICGRfpgmOUXIWcQ/HXPLQTkFPEFPoDyjvH7ohhQpjzs=
ovbQAw7LTrM4PSNadgRBwp4vfR5ma3mkb1x
WoiWRyIOVNa9ihaBciRSC7XHjliYS9VwUGOIud4PB18=
POSSIBLE SECRETS
j7DW1GBqpKusFNd9HZfVNAhgyfgQRaoVc
q4PO2G2cbkZhZ82+JgmRUyGMoAeozA+BSXVXQWB8XWQ=
K87oWBWM9UZfyddvDfoxL+8lpNyoUB2ptGtn0fv6G2Q=
ztXcjgEmmxMKYWXyXR1OtAW6codwAh6kiOzYzpxMCM4
BcapvdaWLq6ZfAglJbxXazMNBFU
5MCO54QyiJ31mua72pgMV7lET8XxQmxVGsxMmN3dAkA
rn+WLLnmp9v3uDP7GPqbcaiRdd+UnCMrap73yz3yu/w=
AuYCk4ZRoWy5MJTr4GmbZSKv7vsGVtVR2oLiOKKp3qs
uSEJtZCVlVzKr17Lzw8VPslkCkZYwQFmetlrfkmaQJI
IbLe4s4vmD9fTAOkRpKbhqq5uo8
MCluzmTgXDuTHyG9AnpK6nb1ffPe
cGuxAXyFXFkWm61cF4HPWX8S0srS9j0aSqN0k4AP+4A=
BhbXF71VGdruXI2K92clfscrAA8xTQxV0mTVQSyTzJM
ZiIZ7fdUdXcbGMNL6M656x4mTCC9kdSoSNBOifLrBAA
grX4Ta9HpZx6tSHkmCrvpApTQGo67CYDnvprLg5yRME=
POSSIBLE SECRETS
6PDrONEnh3P7htSccijrhAA8B9sXJeGvGHy
XdkQEeiVeIyDkvBEAHtGJKKHfdsrOFf9te68UpyJVhA
C5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=
RdBiQjfrXe1WnMMVVkuOoFfs8ri2eE
b2sRSFyeAdgq4NbTDsF6EuDfHreyS9x2Pp7oKe8QclI
2eC54WVokOBCMfraLI5w5AkPzV4OhG2rUnfhWHKBM0M
W1BzWTPVNZBtrA45RvTcbkVphwqyUdZwQEL7X
OaxNl9DzmpbAu1HcjBRq8oUlJBWeTEWmnftIpuLE0dY
PLAYSTORE INFORMATION
Title: Facebook Lite
Score: 4.044712 Installs: 1,000,000,000+ Price: 0 Android Version Support: Category: Social Play Store URL: com.facebook.lite
Developer Details: Meta Platforms, Inc., Meta+Platforms,+Inc., 1 Hacker Way Menlo Park, CA 94025, https://www.facebook.com/facebook, [email protected],
Description:
Keeping up with friends is faster and easier than ever with the Facebook Lite app! Use Facebook Lite as a friends app to connect and keep up with your social network.
The Facebook Lite app is small, allowing you to save space on your phone and use Facebook in 2G conditions. Many of the classic features of Facebook are available on
the app, such as sharing to a Timeline, liking photos, searching for people, and editing your profile and groups. Specific features include: • Find friends and family • Post
status updates & use Facebook emoji to help relay what’s going on in your world • Share photos and your favorite memes • Get notified when friends like and comment
on your posts • Find local social events, RSVP, and make plans to meet up with friends • Interact with your friends by adding your own comments or reactions to their
Facebook posts • Save photos by adding them to photo albums • Follow people to get their latest news • Look up local businesses to see reviews, operation hours, and
pictures • Buy and sell locally on Facebook Marketplace The Facebook app does more than help you stay connected with your friends and interests. It's also your personal
organizer for storing, saving and sharing photos. It's easy to share photos straight from your Android camera, and you have full control over your photos and privacy
settings. You can choose when to keep individual photos private or even set up a secret photo album to control who sees it. Facebook Lite also helps you keep up with
the latest news and current events around the world. Subscribe to your favorite celebrities, brands, websites, artists, or sports teams to follow their News Feeds from the
convenience of your Facebook Lite app! Problems with downloading or installing the app? See https://www.facebook.com/help/fblite Still need help? Please tell us more
about the issue: https://www.facebook.com/help/contact/640732869364975 Facebook is only available to people aged 13 and over. Terms of Service:
http://m.facebook.com/terms.php