This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
faq:dataleakage:chatter [2017/08/10 06:17] czokie [Network Analysis Findings] |
faq:dataleakage:chatter [2017/09/09 23:10] (current) czokie [https://mydjiflight.dji.com] |
||
---|---|---|---|
Line 72: | Line 72: | ||
==== TCP Port 7001 ==== | ==== TCP Port 7001 ==== | ||
TCP traffic has been oberved talking to 103.229.215.31 on port 7001. [[https:// | TCP traffic has been oberved talking to 103.229.215.31 on port 7001. [[https:// | ||
+ | |||
+ | This IP and PORT changes, but it is the first address in the answer paket of the UDP chatter on port 9000. This payload is not readable and we have no idea what it is used for. Very strange, if anyone has more info about this please add it here. For now this is " | ||
< | < | ||
Line 91: | Line 93: | ||
==== https:// | ==== https:// | ||
+ | Multiple requests during startup | ||
+ | * / | ||
+ | * GET / | ||
+ | * GET / | ||
+ | * GET / | ||
+ | * GET / | ||
+ | * / | ||
+ | * GET / | ||
+ | * GET / | ||
+ | * /api/msg/ | ||
+ | * GET / | ||
+ | * / | ||
+ | * GET / | ||
+ | * / | ||
+ | * GET / | ||
+ | * GET / | ||
+ | * GET / | ||
+ | * / | ||
+ | * GET / | ||
+ | * /api/ | ||
+ | * GET / | ||
==== https:// | ==== https:// | ||
+ | * / | ||
+ | * GET / | ||
+ | * / | ||
+ | * profile? | ||
+ | * / | ||
+ | * geoip? | ||
+ | * geoip? | ||
+ | * geoip? | ||
+ | * /api/v2/ | ||
+ | * POST register_device (Four times) | ||
+ | |||
+ | ^device_sn|[[device_sn]]| | ||
+ | ^app_version|[[4.1.9]]| | ||
+ | ^lang|en| | ||
+ | ^os_platform|ios| | ||
+ | ^operator|[[my-carrier]]| | ||
+ | ^os_version|[[10.3.2]]| | ||
+ | ^api_version|1| | ||
+ | ^sign|[[hash-value]]| | ||
+ | ^app_name|djigo_ios| | ||
+ | ^app_datetime|[[timestamp]]| | ||
+ | |||
+ | * /api/djigo/ | ||
+ | * POST / | ||
+ | |||
+ | ^app_version|[[4.1.9]]| | ||
+ | ^lang|en| | ||
+ | ^nation_code|AU| | ||
+ | ^notify_type|0| | ||
+ | ^os_platform|ios| | ||
+ | ^signature|[[hash-value]]| | ||
+ | ^time|[[timestamp]]| | ||
+ | |||
+ | * / | ||
+ | * POST / | ||
+ | |||
+ | ^os|ios| | ||
+ | ^signature|[[hash-value]]| | ||
+ | ^time|[[timestamp]]| | ||
+ | ^version|[[4.1.9]]| | ||
+ | |||
+ | * / | ||
+ | * GET / | ||
+ | * /getfile/ | ||
+ | * POST / | ||
+ | |||
+ | ^language|en| | ||
+ | ^product_id|wm331| | ||
+ | ^signature|[[hash-value]]| | ||
+ | ^token|[[session-key]]| | ||
+ | |||
+ | * /getfile/ | ||
+ | * POST / | ||
+ | |||
+ | ^product_id|[[wm331]]| | ||
+ | ^product_version|[[01.04.0602]]| | ||
+ | ^signature|[[hash-value]]| | ||
+ | ^token|[[session-key]]| | ||
+ | |||
+ | * / | ||
+ | * GET /getdayv3 | ||
+ | * CONNECT https:// | ||
+ | |||
+ | |||
==== https:// | ==== https:// | ||
+ | An unknown DJI service | ||
==== https:// | ==== https:// | ||
+ | [[https:// | ||
==== https:// | ==== https:// | ||
==== https:// | ==== https:// | ||
+ | An unknown DJI service | ||
==== https:// | ==== https:// | ||
==== https:// | ==== https:// | ||
Line 104: | Line 194: | ||
==== https:// | ==== https:// | ||
==== https:// | ==== https:// | ||
+ | [[https:// | ||
==== https:// | ==== https:// | ||
+ | Some form of push notification interface. | ||
+ | **This one sends a list of all installed apps on your phone to the service! Atleast on Android.** | ||
==== http:// | ==== http:// | ||
+ | This is related to the DJI.com website | ||
==== https:// | ==== https:// | ||
+ | Unknown DJI activity. | ||
==== https:// | ==== https:// | ||
+ | Assumed to be DJI GEO related | ||
==== http:// | ==== http:// | ||
+ | Assumed to be DJI GEO related | ||
==== https:// | ==== https:// | ||
+ | Unknown - may not be DJI related | ||
==== https:// | ==== https:// | ||
+ | An unknown DJI service | ||
==== https:// | ==== https:// | ||
+ | Assumed to be tracking usage for DJI | ||
==== https:// | ==== https:// | ||
+ | Looks to be a bug in DJI-GO... | ||
==== https:// | ==== https:// | ||
+ | [[https:// | ||
==== https:// | ==== https:// | ||
+ | Not unusual traffic... | ||
==== https:// | ==== https:// | ||
+ | [[http:// | ||
==== https:// | ==== https:// | ||
+ | [[http:// | ||
==== https:// | ==== https:// | ||
+ | [[https:// | ||
==== https:// | ==== https:// | ||
+ | [[http:// | ||