WRITEUP · MOBILE · RN BRIDGE · 2026 · @YNSMROZTAS

Password in the query string

● live clk --:--:-- com.labnet.console

AndroScope runtime on an authorized lab build. Original device frames rebuilt. Vendor host and secrets stripped.

rn // liveunrooted
radar--:--:--
AndroScope React Native FH-ID · traffic no root

Summary

Lab package com.labnet.console sent login as POST but put email and the plaintext password in the query string. TLS was on. The secret still landed in logs and in a third-party error SDK breadcrumb.

Class: secret in URL query. AndroScope saw it on the RN bridge before TLS. Fix: move fields into the POST body.

Lab frames

Rebuilt from the device captures. Same layout — status bar, yellow RN lines, keychain block, soft keyboard. Account and vendor host replaced.

Redacted AndroScope bridge capture
Frame 1 — Sentry breadcrumb + keychain, password redacted
Redacted login URL capture
Frame 2 — POST login URL with password=[REDACTED]

What AndroScope printed

[RN-native] NetworkingModule
  POST  https://login.labnet.example/session/login?email=lab.user%40example.com&password=[REDACTED]

[RN-native] error-sdk.Breadcrumb
  url=…/session/login?email=…&password=[REDACTED]

[keychain] setGenericPassword
  arg0=lab.user@example.com
  arg2=[REDACTED]

mitsec@com.labnet.console:

Why the URL is the wrong place

The request already declared JSON content-type. The body was unused. Query strings are copied into access logs, WAF events, and HTTP breadcrumbs.

Two consumers

  1. Error-monitoring SDK breadcrumb url held the raw login URL.
  2. Cookie helper received the same URL.

Fix

YUNUS EMRE ÖZTAŞ · MITSEC · LAB BUILD ONLY