Let’s Talk About TikTok
ID: 775ba5b6-e6f9-5242-a211-503f65f77a21
STIX ID: report--775ba5b6-e6f9-5242-a211-503f65f77a21
Feed Name: Black Hills Infosec Blog
The report documents a passive analysis of an Android device’s baseline network activity and subsequent inspection of TikTok traffic using a Raspberry Pi AP, tcpdump/Wireshark, Burp Suite, and MobSF. Baseline DNS anomalies were investigated and largely explained (e.g., CloudFront downloads of trust stores), while TikTok’s APK (com.zhiliaoapp.musically) exhibited a large attack surface and numerous permissions; intercepted API requests showed encrypted bodies with high entropy, and broader social media apps were noted to employ certificate pinning. The author found no clear signs of malicious exfiltration during observation but flagged the app’s extensive permissions and opaque encrypted communications as risk factors, emphasizing the difficulty of definitive conclusions without deeper reverse engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
