{"id":7388,"date":"2019-07-01T11:36:05","date_gmt":"2019-07-01T09:36:05","guid":{"rendered":"https:\/\/hansesecure.de\/2019\/07\/hmv-01-automatically-generated-screenshots\/"},"modified":"2023-06-12T14:11:33","modified_gmt":"2023-06-12T12:11:33","slug":"hmv-01-automatically-generated-screenshots","status":"publish","type":"post","link":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/","title":{"rendered":"HMV-01: Automatically generated screenshots"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Description<\/p>\n\n<p>Screenshots of applications that are moved to the background are created for better user experience. Unfortunately, other apps can access them, exposing sensitive data such as banking information, passwords, or personal information.<\/p>\n\n<p class=\"has-large-font-size\">Example<\/p>\n\n<p>All applications in the background can be viewed (screen shots).<\/p>\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/hansesecure.de\/wp-banane\/uploads\/2019\/05\/Screenshot_20190525-184440_Samsung-Experience-Home-498x1024.jpg\" alt=\"\" class=\"wp-image-1074\" width=\"249\" height=\"512\"\/><\/figure>\n\n<p class=\"has-large-font-size\">Countermeasures<\/p>\n\n<p>Use the <code>FLAG_SECURE<\/code> to hide the screen when an app is put into hang mode. This will only display a black placeholder.<\/p>\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/hansesecure.de\/wp-banane\/uploads\/2019\/05\/Screenshot_20190525-185137_Samsung-Experience-Home-498x1024.jpg\" alt=\"\" class=\"wp-image-1077\" width=\"249\" height=\"512\"\/><\/figure>\n\n<p class=\"has-large-font-size\">References<\/p>\n\n<p><a href=\"https:\/\/github.com\/OWASP\/owasp-mstg\/blob\/master\/Document\/0x05d-Testing-Data-Storage.md#finding-sensitive-information-in-auto-generated-screenshots\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"  (&#xF6;ffnet in neuem Tab)\">OWASP-MSTG Android Reference<\/a><\/p>\n\n<p><a rel=\"noreferrer noopener\" aria-label=\"OWASP-MSTG iOS Reference (&#xF6;ffnet in neuem Tab)\" href=\"https:\/\/github.com\/OWASP\/owasp-mstg\/blob\/master\/Document\/0x06d-Testing-Data-Storage.md#testing-auto-generated-screenshots-for-sensitive-information\" target=\"_blank\">OWASP-MSTG iOS Reference<\/a><\/p>\n\n<p><\/p>\n\n<p><\/p>\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Description Screenshots of applications that are moved to the background are created for better user experience. Unfortunately, other apps can access them, exposing sensitive data such as banking information, passwords, or personal information. Example All applications in the background can be viewed (screen shots). Countermeasures Use the FLAG_SECURE to hide the screen when an app [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":7031,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[261],"tags":[285,286,266,287,288,289],"class_list":["post-7388","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerabilities","tag-android-en","tag-ios-en","tag-migration-en","tag-mobile-en","tag-owasp-en","tag-security-en-2"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HMV-01: Automatically generated screenshots &#8211; HanseSecure GmbH<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HMV-01: Automatically generated screenshots &#8211; HanseSecure GmbH\" \/>\n<meta property=\"og:description\" content=\"Description Screenshots of applications that are moved to the background are created for better user experience. Unfortunately, other apps can access them, exposing sensitive data such as banking information, passwords, or personal information. Example All applications in the background can be viewed (screen shots). Countermeasures Use the FLAG_SECURE to hide the screen when an app [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/\" \/>\n<meta property=\"og:site_name\" content=\"HanseSecure GmbH\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/facebook.com\/hansesecure\" \/>\n<meta property=\"article:published_time\" content=\"2019-07-01T09:36:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-12T12:11:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/hansesecure.de\/wp-content\/uploads\/2019\/07\/blog-screenshots.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"HanseSecure\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@CyberWarship\" \/>\n<meta name=\"twitter:site\" content=\"@CyberWarship\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"HanseSecure\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/\"},\"author\":{\"name\":\"HanseSecure\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#\\\/schema\\\/person\\\/6ec6ef4887ff2fc97a14f1a7f390f593\"},\"headline\":\"HMV-01: Automatically generated screenshots\",\"datePublished\":\"2019-07-01T09:36:05+00:00\",\"dateModified\":\"2023-06-12T12:11:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/\"},\"wordCount\":77,\"publisher\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hansesecure.de\\\/wp-content\\\/uploads\\\/2019\\\/07\\\/blog-screenshots.jpg\",\"keywords\":[\"android\",\"iOS\",\"Migration\",\"mobile\",\"owasp\",\"security\"],\"articleSection\":[\"Vulnerabilities\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/\",\"url\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/\",\"name\":\"HMV-01: Automatically generated screenshots &#8211; HanseSecure GmbH\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hansesecure.de\\\/wp-content\\\/uploads\\\/2019\\\/07\\\/blog-screenshots.jpg\",\"datePublished\":\"2019-07-01T09:36:05+00:00\",\"dateModified\":\"2023-06-12T12:11:33+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#primaryimage\",\"url\":\"https:\\\/\\\/hansesecure.de\\\/wp-content\\\/uploads\\\/2019\\\/07\\\/blog-screenshots.jpg\",\"contentUrl\":\"https:\\\/\\\/hansesecure.de\\\/wp-content\\\/uploads\\\/2019\\\/07\\\/blog-screenshots.jpg\",\"width\":400,\"height\":300},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/2019\\\/07\\\/hmv-01-automatically-generated-screenshots\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HMV-01: Automatically generated screenshots\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/\",\"name\":\"HanseSecure GmbH\",\"description\":\"Choose the Intruder\",\"publisher\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#organization\",\"name\":\"HanseSecure GmbH\",\"url\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/hansesecure.de\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/cropped-000-LOGO-intensiv-schwarz-rot-HanseSecure_LOGO_CTI_Vektor_rotes_H11806.png\",\"contentUrl\":\"https:\\\/\\\/hansesecure.de\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/cropped-000-LOGO-intensiv-schwarz-rot-HanseSecure_LOGO_CTI_Vektor_rotes_H11806.png\",\"width\":512,\"height\":512,\"caption\":\"HanseSecure GmbH\"},\"image\":{\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/facebook.com\\\/hansesecure\",\"https:\\\/\\\/x.com\\\/CyberWarship\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hansesecure\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCAABbKOA_stDFkEKS3MSF7Q\",\"https:\\\/\\\/www.instagram.com\\\/hansesecure\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/hansesecure.de\\\/en\\\/#\\\/schema\\\/person\\\/6ec6ef4887ff2fc97a14f1a7f390f593\",\"name\":\"HanseSecure\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/58fe26b2270315f2ab1268b229465b72c497c86aac3696aaaf2e629ae4e4f0af?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/58fe26b2270315f2ab1268b229465b72c497c86aac3696aaaf2e629ae4e4f0af?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/58fe26b2270315f2ab1268b229465b72c497c86aac3696aaaf2e629ae4e4f0af?s=96&d=mm&r=g\",\"caption\":\"HanseSecure\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HMV-01: Automatically generated screenshots &#8211; HanseSecure GmbH","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/","og_locale":"en_US","og_type":"article","og_title":"HMV-01: Automatically generated screenshots &#8211; HanseSecure GmbH","og_description":"Description Screenshots of applications that are moved to the background are created for better user experience. Unfortunately, other apps can access them, exposing sensitive data such as banking information, passwords, or personal information. Example All applications in the background can be viewed (screen shots). Countermeasures Use the FLAG_SECURE to hide the screen when an app [&hellip;]","og_url":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/","og_site_name":"HanseSecure GmbH","article_publisher":"https:\/\/facebook.com\/hansesecure","article_published_time":"2019-07-01T09:36:05+00:00","article_modified_time":"2023-06-12T12:11:33+00:00","og_image":[{"width":400,"height":300,"url":"https:\/\/hansesecure.de\/wp-content\/uploads\/2019\/07\/blog-screenshots.jpg","type":"image\/jpeg"}],"author":"HanseSecure","twitter_card":"summary_large_image","twitter_creator":"@CyberWarship","twitter_site":"@CyberWarship","twitter_misc":{"Written by":"HanseSecure"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#article","isPartOf":{"@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/"},"author":{"name":"HanseSecure","@id":"https:\/\/hansesecure.de\/en\/#\/schema\/person\/6ec6ef4887ff2fc97a14f1a7f390f593"},"headline":"HMV-01: Automatically generated screenshots","datePublished":"2019-07-01T09:36:05+00:00","dateModified":"2023-06-12T12:11:33+00:00","mainEntityOfPage":{"@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/"},"wordCount":77,"publisher":{"@id":"https:\/\/hansesecure.de\/en\/#organization"},"image":{"@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#primaryimage"},"thumbnailUrl":"https:\/\/hansesecure.de\/wp-content\/uploads\/2019\/07\/blog-screenshots.jpg","keywords":["android","iOS","Migration","mobile","owasp","security"],"articleSection":["Vulnerabilities"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/","url":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/","name":"HMV-01: Automatically generated screenshots &#8211; HanseSecure GmbH","isPartOf":{"@id":"https:\/\/hansesecure.de\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#primaryimage"},"image":{"@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#primaryimage"},"thumbnailUrl":"https:\/\/hansesecure.de\/wp-content\/uploads\/2019\/07\/blog-screenshots.jpg","datePublished":"2019-07-01T09:36:05+00:00","dateModified":"2023-06-12T12:11:33+00:00","breadcrumb":{"@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#primaryimage","url":"https:\/\/hansesecure.de\/wp-content\/uploads\/2019\/07\/blog-screenshots.jpg","contentUrl":"https:\/\/hansesecure.de\/wp-content\/uploads\/2019\/07\/blog-screenshots.jpg","width":400,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/hansesecure.de\/en\/2019\/07\/hmv-01-automatically-generated-screenshots\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/hansesecure.de\/en\/"},{"@type":"ListItem","position":2,"name":"HMV-01: Automatically generated screenshots"}]},{"@type":"WebSite","@id":"https:\/\/hansesecure.de\/en\/#website","url":"https:\/\/hansesecure.de\/en\/","name":"HanseSecure GmbH","description":"Choose the Intruder","publisher":{"@id":"https:\/\/hansesecure.de\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/hansesecure.de\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/hansesecure.de\/en\/#organization","name":"HanseSecure GmbH","url":"https:\/\/hansesecure.de\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hansesecure.de\/en\/#\/schema\/logo\/image\/","url":"https:\/\/hansesecure.de\/wp-content\/uploads\/2023\/05\/cropped-000-LOGO-intensiv-schwarz-rot-HanseSecure_LOGO_CTI_Vektor_rotes_H11806.png","contentUrl":"https:\/\/hansesecure.de\/wp-content\/uploads\/2023\/05\/cropped-000-LOGO-intensiv-schwarz-rot-HanseSecure_LOGO_CTI_Vektor_rotes_H11806.png","width":512,"height":512,"caption":"HanseSecure GmbH"},"image":{"@id":"https:\/\/hansesecure.de\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/facebook.com\/hansesecure","https:\/\/x.com\/CyberWarship","https:\/\/www.linkedin.com\/company\/hansesecure","https:\/\/www.youtube.com\/channel\/UCAABbKOA_stDFkEKS3MSF7Q","https:\/\/www.instagram.com\/hansesecure\/"]},{"@type":"Person","@id":"https:\/\/hansesecure.de\/en\/#\/schema\/person\/6ec6ef4887ff2fc97a14f1a7f390f593","name":"HanseSecure","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/58fe26b2270315f2ab1268b229465b72c497c86aac3696aaaf2e629ae4e4f0af?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/58fe26b2270315f2ab1268b229465b72c497c86aac3696aaaf2e629ae4e4f0af?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/58fe26b2270315f2ab1268b229465b72c497c86aac3696aaaf2e629ae4e4f0af?s=96&d=mm&r=g","caption":"HanseSecure"}}]}},"_links":{"self":[{"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/posts\/7388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/comments?post=7388"}],"version-history":[{"count":1,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/posts\/7388\/revisions"}],"predecessor-version":[{"id":7389,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/posts\/7388\/revisions\/7389"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/media\/7031"}],"wp:attachment":[{"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/media?parent=7388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/categories?post=7388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hansesecure.de\/en\/wp-json\/wp\/v2\/tags?post=7388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}