Hi everyone! I would like to warm you about scam pages using HTML5 Vibrate API to mimic system notifications!
The problem is quite old and you can read about it here for ex. link to the blog.
But really bad news that our Note 4 with stock browser allows the using of Vibrate API without asking the user for permission!
You can test this yourself by going with your Note on this test page https://shkspr.mobi/vibratescam/. Please take in mind that it is not harmful example.
But I decided to write this topic because there exists real scam using Vibrate API like this one:
http://wonderlandads.com/?zoneid=292440&pbk2=e7365e726b0ca06f51ec06c833fa6db16188134738946672277&r=%2Foc%2Fhan%2Ftomb
The link is adapting to the device and outputs different pages for them. I have attached screenshot of the page opened in Note 4 stock browser so you don't have to try it by yourself.
I also made a test of some popular browsers to find a way for safe browsing and here is my results:
Test on device Note 4 stock android 4.4.4
Stock browser vibrates
UC Browser vibrates and plays sound
Chrome does nothing of this
I believe that other Samsung devices and firmware versions are vulnerable too! If you wish you can test a link from the article I mentioned in the beginning of this topic and write here in the comments the results. I am particually interested if new firmware with 5.1 is safe or not from this threat.
Thanks all!
all browsers do the same for me Vibrate only
Stock , chrome and chrome beta.
you gave permission to browzer....it is not new. BTW is soo old like my grandmother
EclipseX said:
you gave permission to browzer....it is not new. BTW is soo old like my grandmother
Click to expand...
Click to collapse
There is permission settings in stock kitkat browser then?
Man, you have what? 5 years? when u install the browzer it not ask you for use vibrator and other stuff? damm
EclipseX said:
Man, you have what? 5 years? when u install the browzer it not ask you for use vibrator and other stuff? damm
Click to expand...
Click to collapse
Man. Stock browser? install? seriously? I just told that there exists real scam regarding this API, which everbody can get right NOW. Your smart talks makes no sence regarding the topic.
I have the same concern experiencing the same problem with my S4's stock browser by Samsung. It does not present an option or an in-deep setting to disable that behaviour buried in somewhere like Firefox's about:config.
What should we do?
Related
Ive searched high and low, here, google, bing and forceclose.com' even tried ADB and terminal to look under the hood. nothing so far.
I hate the 1.6 camcorder; no auto-focus...not even sure if there is a zoom feature. Can anybody tell me which version or which image the camera/camcorder.apk in CM.4.0.4 is from so i can port.
It looks like a mesh of Magic's and Hero's modified, but im not sure and very confused.
This is the only thing keeping me from going full-donut.
that would be the htc camera port, give me a sec and i should be able to get you a link to it
it's a little bit old but the first one i found with the search
http://forum.xda-developers.com/showthread.php?t=521837
umm here is a newer one with terminal commands
http://forum.xda-developers.com/showthread.php?t=535736
first 2 with the search you just gotta be more specific
remember to type in android or g1 or mytouch since xda is a very large resource place for different types of os es
gridlock32404 said:
it's a little bit old but the first one i found with the search
http://forum.xda-developers.com/showthread.php?t=521837
Click to expand...
Click to collapse
THANX bro
you say first...i assume reguarding the search results but there arent any updated or modified versions of said info right?
EDIT: also there shouldnt be any stability issues to encounter. i mean why release 1.6 downgraded w/ less features?
it is not less features, just the stock camera that came with the phone's most likely
i don't use the camera on my phone ever so i couldn't tell you much about it, just from helping out or reading threads
try adding the month in on your search sometimes that helps
i put in htc camera .apk android so try it with a oct after it
gridlock32404 said:
i don't use the camera on my phone ever so i couldn't tell you much about it,
Click to expand...
Click to collapse
For everday use, me neither. But i got 2 G1s, no HD Cam and I wanted to create some basic tutorial vids for some fellow users.
here is a great guide to base it off of
http://forum.xda-developers.com/showthread.php?t=563679
If I load a custom rom on my Captivate will it ever be possible to restore back and start receiving OTA updates again?
bigroof said:
If I load a custom rom on my Captivate will it ever be possible to restore back and start receiving OTA updates again?
Click to expand...
Click to collapse
Yup! You can either reflash it back using odin, or go back and forth with a program called rom manager.
I'd be careful, I don't think this post was supposed to go into android development.
Welcome to the Captivate. Like most forums please read the sticky's, they are there for your help. We have the Odin 3 one click that is very useful, as well as the Clockworkmod recovery which your question is about. Also just search the site and look at lots of threads as there are a lot of knowledgeable people to help on the site.
Reading through those stickies has helped wonders for me.
And your posting in the wrong captivate forum section, this is development not Q&A...
Moved to QnA.
Welcomed to the forum!
Welcome! And once you start playing with android apps that are actually useful you won't miss face time and 300 flashlight apps. I'm having fun setting key bindings and gestures to simplify my phone.
Ok that was off topic, but I just don't see the appeal of iOS in any version. Though I admit apple gave the form factor for todays smart phones.
Sent from my SAMSUNG-SGH-I897 using Tapatalk
Is there anyway to edit video that is to long to email or message? When I used to send video from my iPhone via email or MMS it would tell me the video was to large and let me edit it so I could send it.
bigroof said:
Is there anyway to edit video that is to long to email or message? When I used to send video from my iPhone via email or MMS it would tell me the video was to large and let me edit it so I could send it.
Click to expand...
Click to collapse
I'm sure an app exists but the trick is to set the camera to a text friendly setting. Play with the camera app a bit. Its pretty good. The mms setting for video automatically times you out at the size limit.
Sent from my SAMSUNG-SGH-I897 using Tapatalk
For all ppl who are also annoyed by missing MP3-tags over bluetooth.
Please star following issue on code.google.com:
http://code.google.com/p/android/is...id&colspec=ID Type Status Owner Summary Stars
Thanks!
AOSP doesn't support AVRCP 1.13 which is the version that introduced metadata support. Until it does, custom ROMs the devs have added it to are the only one's that'll display song/album/artist.
Audio/Video Remote Control Profile (AVRCP)
This profile is designed to provide a standard interface to control TVs, Hi-fi equipment, etc. to allow a single remote control (or other device) to control all of the A/V equipment to which a user has access. It may be used in concert with A2DP or VDP.
It has the possibility for vendor-dependent extensions.
AVRCP has several versions with significantly increasing functionality:
1.0—Basic remote control commands (play/pause/stop, etc.)
1.3—all of 1.0 plus metadata and media-player state support The status of the music source (playing, stopped, etc.)
Metadata information on the track itself (artist, track name, etc.).
1.4—all of 1.0, 1.3, plus media browsing capabilities for multiple media players Browsing and manipulation of multiple players
Browsing of media metadata per media player, including a "Now Playing" list
Basic search capabilitieshttp://en.wikipedia.org/wiki/Bluetooth_profile
https://www.bluetooth.org/Building/HowTechnologyWorks/ProfilesAndProtocols/AVRCP.htm
As far as I know, no n4 custom rom supports it until today. Google will most likely never update it, don't know what the heck they are thinking.
it's such an elementary feature. Can't believe it's not integrated....This really makes me mad.
Lownita said:
As far as I know, no n4 custom rom supports it until today. Google will most likely never update it, don't know what the heck they are thinking.
Click to expand...
Click to collapse
What do you mean no custom ROM supports it?
I was waiting for someone to confirm if AVRCP 1.3 was going to be added in android 4.2.2 but now I'm planning on rooting and getting a ROM that does support this...
This is my most wanted bug fix for android 4.2.2, and I can't believe they missed it. Shame on Google.
jc monkeyballs said:
This is my most wanted bug fix for android 4.2.2, and I can't believe they missed it. Shame on Google.
Click to expand...
Click to collapse
I completely agree
Does anyone know of a stable mod that does have AVRCP 1.3?
I'm glad that I am not the only one^^
Please share this bug report as often as possible in other forums. Maybe if enough ppl will star this google will react - MAYBE^^
main reason
This was the main reason I was looking forward to the update...now, I'm sad. Guess I'm going to be forced to root now...anyone know when any of the ROMs will add this much needed feature?
alternetconcept said:
What do you mean no custom ROM supports it?
I was waiting for someone to confirm if AVRCP 1.3 was going to be added in android 4.2.2 but now I'm planning on rooting and getting a ROM that does support this...
Click to expand...
Click to collapse
There is no rom that supports it! If you find one, let me know
sarasotaguy said:
This was the main reason I was looking forward to the update...now, I'm sad. Guess I'm going to be forced to root now...anyone know when any of the ROMs will add this much needed feature?
Click to expand...
Click to collapse
That's all I was looking forward to also.
Its no wonder companies ignore their users when they needlessly and wrongly report bugs for something which is clearly not a bug.
If I was Google I'd ignore every single bug report which was actually reporting a missing feature.
For whatever reason, Google left it out, probably because its a niche requirement. It's not a bug.
thank god ur not google
maybe it's not the right category but at least I did something to point out that there's a problem and gave other ppl the chance to express their madness about this problem aswell.
And a niche? C'mon this is absolute standard nowadays and we can expect this from a 2012 smartphone when even my 2010 i9000 had it!
Lownita said:
There is no rom that supports it! If you find one, let me know
Click to expand...
Click to collapse
cm10 has it.
AnonymousPenguin said:
cm10 has it.
Click to expand...
Click to collapse
Is it possible for anyone to confirm this?
I was about to root when looking at CM but thought they didn't have it?
alternetconcept said:
Is it possible for anyone to confirm this?
I was about to root when looking at CM but thought they didn't have it?
Click to expand...
Click to collapse
I dont have NEXUS but CM10 M2 for Galaxy S III has it. 100% working. keep in mind, its 4.1.2 though !
It is funny how google is missing this very important feature.
bump. Which ROM has it?
Bump Anyone know if any of the custom ROMs for Nexus are putting this feature in? I've search...but didn't see a mention. Please link. Thanks!
sarasotaguy said:
Bump Anyone know if any of the custom ROMs for Nexus are putting this feature in? I've search...but didn't see a mention. Please link. Thanks!
Click to expand...
Click to collapse
Same here, don't understand it
i can confirm it works in cm 10. i use it on my car all the time. the cover art doesnt work but the tags work perfect.
Which ROM?
Sent from my Nexus 4 using Tapatalk 2
Hi guys, is not usual to me write post in this forum by two reasons:
1. Im Spanish and the English is not a language that I use normally and I write like a 3 years old boy...
2. Before start a new post, first i look about the case, but this case is a **** for me.
I installed, Cinema fv5, L camera, and a lot of apps of playstore (and apptoide) and no ones are able to record in slow motion.
The L camera has te option to record, but in nexus 6 cant choose it because is disabled (i think in other model like nexus 5 it works)
Where is the problem?
In build.prop?
In kernel?
Some developer can answer me?
If they are no way to enable the slow motion, I will sell it on ebay..
XDA is The big think that exist on Internet!
BertoAZ said:
Hi guys, is not usual to me write post in this forum by two reasons:
1. Im Spanish and the English is not a language that I use normally and I write like a 3 years old boy...
2. Before start a new post, first i look about the case, but this case is a **** for me.
I installed, Cinema fv5, L camera, and a lot of apps of playstore (and apptoide) and no ones are able to record in slow motion.
The L camera has te option to record, but in nexus 6 cant choose it because is disabled (i think in other model like nexus 5 it works)
Where is the problem?
In build.prop?
In kernel?
Some developer can answer me?
If they are no way to enable the slow motion, I will sell it on ebay..
XDA is The big think that exist on Internet!
Click to expand...
Click to collapse
Have a look in some relevant threads:
http://forum.xda-developers.com/showthread.php?t=3038871
http://forum.xda-developers.com/showthread.php?t=2913021
http://forum.xda-developers.com/showthread.php?t=3089028
http://forum.xda-developers.com/showthread.php?t=3071964
If you use the "search this forum" box, you can usually find what you're looking for. Try Google translate for language barriers.
Evolution_Tech said:
Have a look in some relevant threads:
http://forum.xda-developers.com/showthread.php?t=3038871
http://forum.xda-developers.com/showthread.php?t=2913021
http://forum.xda-developers.com/showthread.php?t=3089028
http://forum.xda-developers.com/showthread.php?t=3071964
If you use the "search this forum" box, you can usually find what you're looking for. Try Google translate for language barriers.
Click to expand...
Click to collapse
Soooo my english is not too bad if you understood meee!
Your English is not bad at all! I've seen much, much worse.
Hi all,
So I was testing the GN5 and came across a built-in permission manager first thing. Didn't think much of it I mean yes it's a very nice feature and all but then after I had to return the phone, I looked for other references to it online but couldn't find any. It's not available on the Galaxy A8 that's for sure.
So I'm just looking for confirmation that it does indeed exist on every other GN5 out there..
yellowchilli said:
Hi all,
So I was testing the GN5 and came across a built-in permission manager first thing. Didn't think much of it I mean yes it's a very nice feature and all but then after I had to return the phone, I looked for other references to it online but couldn't find any. It's not available on the Galaxy A8 that's for sure.
So I'm just looking for confirmation that it does indeed exist on every other GN5 out there..
Click to expand...
Click to collapse
i can't find it on my note5 N920I so if you could describe how to access it that would be nice
imfaraz said:
i can't find it on my note5 N920I so if you could describe how to access it that would be nice
Click to expand...
Click to collapse
Should've noted that down... but it pops up by itself either before or after download. Didn't need to set anything before hand. Will see if I can dig up the rom info too... it was a test unit for HK
Thanks
yellowchilli said:
Hi all,
So I was testing the GN5 and came across a built-in permission manager first thing. Didn't think much of it I mean yes it's a very nice feature and all but then after I had to return the phone, I looked for other references to it online but couldn't find any. It's not available on the Galaxy A8 that's for sure.
So I'm just looking for confirmation that it does indeed exist on every other GN5 out there..
Click to expand...
Click to collapse
That's the only reason I miss aosp or root for. How do you get that? Is it third party app or what? Seems like test build samsung has around for android M update coming soon to note 5.
Sent from my SAMSUNG-SM-N920A
Does the phone runs on android 6.0 by any chance?
Sent from my SM-N920C using Tapatalk
He probably came across a test phone of some sort - with Android 6.0
Android definitely needs something like this...
I hate downloading apps that need random permissions for things (Like a photo editor that needs to read my SMS messages) - It creeps me out and is just weird. I'm sure some permissions are innocent and others are malicious.
This feature will definitely help Android!
fail..... of all the screenshots I took I forgot to take one of the build info. is there anywhere on google that might store that? I already checked Play store.. that only remembers my model number.
on my GN5 it was built in. I was setting it up from scratch, installing new apps etc.
HNIC215 said:
He probably came across a test phone of some sort - with Android 6.0
Android definitely needs something like this...
I hate downloading apps that need random permissions for things (Like a photo editor that needs to read my SMS messages) - It creeps me out and is just weird. I'm sure some permissions are innocent and others are malicious.
This feature will definitely help Android!
Click to expand...
Click to collapse
yup I was surprised to see it. I'll see if I can clarify with my PR contact...
I've got Android M on my Nexus 6 and that was pretty buggy. Samsung would've needed a miracle to put their touchwiz on it and maintain such stability at this time so that's highly unlikely.
I am pretty sure that ROM wasn't a 6.0 test rom, but just something Samsung cooked into the Chinese (and HK) ROM... already seen it in some Chinese N9200 before... Could be something unique to said variant, or could be something that can be triggered by change of build file...
alexcarterkarsus said:
I am pretty sure that ROM wasn't a 6.0 test rom, but just something Samsung cooked into the Chinese (and HK) ROM... already seen it in some Chinese N9200 before... Could be something unique to said variant, or could be something that can be triggered by change of build file...
Click to expand...
Click to collapse
Well lg g4 had it cooked un and you could access it by creating widget of activities and sellecting permissions settings but I am not able to find it on this phone
Sent from my SAMSUNG-SM-N920A
this function exist in Note 5 Hong Kong version... it will pop out everytime when you install an app.
thank you for clarifying this!
prodigiez said:
this function exist in Note 5 Hong Kong version... it will pop out everytime when you install an app.
Click to expand...
Click to collapse
Can't wait to get that feature!
Flash Ditto Rom for N5, you will have this feature without Hongkong CSC
Zanr Zij said:
Flash Ditto Rom for N5, you will have this feature without Hongkong CSC
Click to expand...
Click to collapse
No root for my Note 5 lol