Modul🅾️s #AntiRetardModules – Telegram
Modul🅾️s #AntiRetardModules
966 subscribers
66 photos
3 videos
2 files
22 links
Dedicated to expose retardation in modules.

By @Rem01Gaming
Download Telegram
First this I see is the service noscript, and immediately I spot some missing variables here, $config and $MODPATH. Although $MODPATH is declared automatically by Magisk/KSU/AP when module installation, this is not the case with the late_start service noscript.

The shebang is also wrong as you can see it's system/sh instead of /system/bin/sh.

The service noscript itself only does setprop spectrum props. Just looking into the service noscript we know the noscript kiddie that creates this bs doesn't know shit and only cares about money.
🤣2
The next is the "phx" folder, inside it it contains an executable called phx and when I run the file command to see what format it is, I'm shocked.

HOW THIS IDIOT THOUGHT THAT EXECUTABLES FOR LINUX CAN WORK ON ANDROID?

Wait doesn't Android is based on Linux?


It is based on the Linux kernel but other than that it's very different from Linux distros such as Ubuntu. Android uses musl libc while Linux distros uses GNU libc, both are not compatible with each other and hence this shit won't be able to run in Android.

This means, this fancy $50 module is just a placebo and scam. This also confirms my suspicion that this module has never been tested before it's actually bought and used by the user.
🔥3🤣1
The executable itself is not a compiled language that you may expect such as C or C++, but rather it was a shell noscript obfuscated with SHC (Shell Script Compiler). Let's assume the idiot that sells this shit obfuscates this noscript and just uses regular Linux GCC ARM64 to compile it.

It's easily detectable since SHC has unique strings on its executables.

E: neither argv[0] nor $_ works.


SHC itself can be easily deobfuscated using tools like Unshell, but since this shit was made for Linux, I have to create a Linux chroot container on my phone just to deobfuscate this noscript.

Even though I know this shit will not work at all, I decided to deobfuscate the noscript anyway. I'm curious, what is this thing doing under the hood.
2
phx
36.7 KB
This is the deobfuscated version of the phx noscript, the serial number is removed for the user's privacy and safety.

Some take on this noscript:
- Copy paste everywhere
- Hardcoded values everywhere
- No shfmt, horrible indentation
- Use a 16 year old governor named "interactivex"
💩3🔥2🖕2
Autistic module just got an update 👅

So takes from this update:

- No more downloading 🔑📦 from the cloud and instead ship it directly on the zip as "bin.so" (I still wondering why she have to encode this if it will decoded in tricky store dir anyway?)
- Massive debloat of Termux ROOTFS from 80 TONS to 5 TONS 👅
- Additional untested vibe coded WebUI 😭🤮🤮


The JavaScript for KSU exec is questionable at best like how TF useragent contains MMRL's package name?????

Not only this "compatibility" check was not required (MMRL have the same API as KSU) it's blatantly wrong and AI generated code at best 🔥🗑️🚮
😱141👍1
You may be wondering why shamiko stuck in whitelist mode?

It's because you're installed that Meow-Autistic module
💩21🤣6
logd is killed by Meow-Autistic module, a new root detection point.

Nice
🥰8🤮7😁4👍2
Yang namanya putraxitersz mana yah 😍😍😍
Module kamu cantik betul pgn ku cipok 💋💋💋
🥰4😱2😁1💩1
Oh yes I forgot to say something, since this new channel was created over the old one that was already killed by telegram, I won't share any files here which telegram may find violating its TOS.

All posts here are just screenshot of proof of gimmicks and some yapping, if you want to get the file, we will provide it in the group or other links later.

EDIT: https://news.1rj.ru/str/+72Luw2utc3U2MjFl
🔥5👍3🤮1💩1
💥 OPEN JASA DECRYPT/ENCRYPT SHELL SCRIPT

🔥 DEOBFUSCATE SHELL SCRIPT
🎭 ENCRYPT SHELL SCRIPT
⚡️ HARGA MULAI DARI 15K*

➡️ Langsung PM Admin @Rem01Gaming

*Harga jasa sesuai situasi & kondisi
Please open Telegram to view this post
VIEW IN TELEGRAM
💩22🤮72👍2
Modul🅾️s #AntiRetardModules
logd is killed by Meow-Autistic module, a new root detection point. Nice
Heya! A PoC detection for Meowna module is ready, will publish it very soon 👅👅👅
😁7🤮2💩2🔥1
Introducing The Meowna Detector!

A prove-of-concept of fatal blunder on the Integrity Box module by Meowna—a root-hiding module that spectacularly backfires by killing logd (Android’s logger daemon).

Integrity Box promises Strong Play Integrity 🟢🟢🟢 and root hiding, while in the reality this module isn't more than vibe coded project with one massive blunder which is killing logd.

There's no reason whatsoever to include a kill logger into a root hiding module or any modules since this was futile meant it will cause root detection. The irony was this module was supposed to hide root but actually opened a new root detection itself.

If you have installed any module by Meowna remove it immediately since it was useless. Everything that the module does is configurate things that you can do yourself.

BOYCOTT MEOWNA TOGETHER WITH IT'S MODULES!

🔗 https://github.com/Rem01Gaming/meowna_detector
Please open Telegram to view this post
VIEW IN TELEGRAM
😁26🤮11👍5🥰2
Forwarded from 𝗠𝗘𝗢𝗪𝗻𝗮 💅
Bro wants attention maybe for some subscribers for his dead project & channel
🤣45💯2👍1🥰1
This media is not supported in your browser
VIEW IN TELEGRAM
1👍1
Modul🅾️s #AntiRetardModules
Huh? My lsposed fine without killing logd 🍦
I don't understand, why you would close a detection with another detection loophole?
💯15
Also, even if Meowna adds a toggle to on/off the kill logger feature it will still detected since "logd socket" detection is not the only detection on this Meowna Detector.

Meowna also added a "helper app" to make toast notification (I know where she/he kanged that) which package name is meow.helper, another detection loophole of this module.

This app is also installed in such a way that you have to manually remove it via adb/shell, removing the module won't remove the app which is massive security red flag.

It just matters of time that detectors and banking apps start to flag this app as malicious.

If you need to remove it, run this command as root or adb:

pm uninstall meow.helper
👍19🖕63🤮3
Can you guys mail those security companies to blacklist this app from banking apps faster 😅
Please open Telegram to view this post
VIEW IN TELEGRAM
👍13🤣9👎1