part 2 of the #FuckStalkerware series, this one is pretty big!

https://maia.crimew.gay/posts/fuckstalkerware-2/

also exclusively covered by techcrunch (less technical but more analysis than my post) here:

https://techcrunch.com/2023/07/24/spyhide-stalkerware-android/
Akkoma

@[email protected] very cool, fun read! A few questions:
1. Is there anywhere else I can read these kinds of hack breakdowns? They're super interesting
2. In one of the vscode screenshots (when the php script is uploaded) there's "fuck3333" and "fuckNOOO". What are those from/what do they mean?
3. If I understand the hack right, on a server that runs php, simply uploading a PHP file automatically gives you the ability to run stuff (presumably permission levels that depend on the setup or smth)? Is that inherent to PHP? That's... horribly cursed, if so.