diff --git a/.jules/sentinel.md b/.jules/sentinel.md index dcfee25..c4108fe 100644 --- a/.jules/sentinel.md +++ b/.jules/sentinel.md @@ -2,3 +2,7 @@ **Vulnerability:** OAuth state parameter used a predictable `System.currentTimeMillis()` value, vulnerable to CSRF attacks. **Learning:** Always use a cryptographically secure random value for OAuth state parameter and persist it across process boundaries using shared preferences or similar mechanisms to verify during the callback. **Prevention:** Follow OAuth 2.0 security guidelines and utilize `java.security.SecureRandom` or UUIDs to generate state parameters, ensuring they are verified in the callback process. +## 2024-05-31 - [Android Manifest Security Baseline] +**Vulnerability:** Weak default Android application security settings (`allowBackup="true"` implicitly allowed, `usesCleartextTraffic` implicitly allowed on older APIs). +**Learning:** The application was vulnerable to data extraction (including sensitive OAuth tokens) via adb backup and Man-In-The-Middle (MITM) attacks for unencrypted traffic. +**Prevention:** Explicitly set `android:allowBackup="false"` and `android:usesCleartextTraffic="false"` in `AndroidManifest.xml` unless there is a specific, well-justified reason to enable them. diff --git a/app/src/main/AndroidManifest.xml b/app/src/main/AndroidManifest.xml index f481980..6eb1b3a 100644 --- a/app/src/main/AndroidManifest.xml +++ b/app/src/main/AndroidManifest.xml @@ -3,9 +3,11 @@ + + + + + \ No newline at end of file diff --git a/app/src/main/res/values/themes.xml b/app/src/main/res/values/themes.xml index 5dbee4f..09278c7 100644 --- a/app/src/main/res/values/themes.xml +++ b/app/src/main/res/values/themes.xml @@ -6,6 +6,5 @@ @android:color/black @android:color/black false - false - \ No newline at end of file +