AndroScope
React Native
FH-ID · traffic
no root
Summary
Lab package com.labnet.console sent login as POST but put email and the plaintext password in the query string. TLS was on. The secret still landed in logs and in a third-party error SDK breadcrumb.
Class: secret in URL query. AndroScope saw it on the RN bridge before TLS. Fix: move fields into the POST body.
Lab frames
Rebuilt from the device captures. Same layout — status bar, yellow RN lines, keychain block, soft keyboard. Account and vendor host replaced.
What AndroScope printed
[RN-native] NetworkingModule POST https://login.labnet.example/session/login?email=lab.user%40example.com&password=[REDACTED] [RN-native] error-sdk.Breadcrumb url=…/session/login?email=…&password=[REDACTED] [keychain] setGenericPassword arg0=lab.user@example.com arg2=[REDACTED] mitsec@com.labnet.console:
Why the URL is the wrong place
The request already declared JSON content-type. The body was unused. Query strings are copied into access logs, WAF events, and HTTP breadcrumbs.
Two consumers
- Error-monitoring SDK breadcrumb
urlheld the raw login URL. - Cookie helper received the same URL.
Fix
- Move email, password, remember_user into the POST body.
- Scrub the login path in the error SDK.
- Purge historical URL logs that stored the parameter.