Share This Post

Ask For Help

Loopholes/ Poor Encryption by Music Apps

Guys,

There is a loophole in the encryption of online music Apps and you can download unlimited free music without paying subscription charges with the help of a simple trick. At present what happens is if you download a song for offline listening, it won’t appear in the file manager neither any other music player app would detect it. But with this technique you can download them, move them and even share them with anyone.

The trick works like this:

1. Download application from play store and sign in/ register.
2. Download songs for listening them offline. These songs are then stored to the hidden folder on the phone.
3. Go to the File Manager and select ‘show hidden files.’
4. Select folder ‘android’ and then select ‘data’ and look for the folder with the name ‘gaana’ and open.
5. Open the file folder under it and the files showing up as numbers are actually the songs you have downloaded.
6. Now edit each of these files and put ‘.mp3’ after them.
7. Copy these songs and move to another place and they are there on your phone permanently.

I have done this using ‘gaana’ app and it worked successfully.

Also, it’s a request if anyone knows someone in ‘Times media’ plz let them know of this but don’t forget to download songs before telling them. I already wrote them about this but they are not replying.

Enjoy!

Comments

Share This Post

6 Comments

  1. kunal – what’s your twitter handle?

    have you tried tweeting them? i tweeted your post and someone RTed mentioning folks from the other side.

    will add you once i get your twitter handle.

  2. My twitter handle is kunalkalra88.

    I have already written to ‘gaana’ with this feedback but they didn’t seem. care about this so I thought to share here so that maximum people can get this benefit.

  3. Should know someone definitely 🙂 dhaval (at) webventurous.com As CEO of Indiatimes…

    Also someone actually asked this same question 😀

  4. Thanks Darshan for the reply, I have opened the group page you mentioned above but unable to post the content there due to restrictions.

    Also, the opening mentioned in the other link has hardly to do anything with me. I didn’t have any work experience in this feild neither I know any programming languages, its just my curiosity and passion which made me a ethical hacker. I am a good product developer though. I would love to take such opportunity where technical criteria is less demanded.

  5. We can help to keep file encrypted offline and still play the same without generating a plain copy of file on the android file system. we can do this with streaming.

  6. Hi Kunal. I don’t think they would care enough for this issue as what they charge you is for the songs with high bitrate quality. So what you see in those folders are intentionally low bitrate (low sound quality)  songs meant for offline playback (also used by websites for previewing a song before a purchase). If you do some findings there are already a lot of plugins or add-ons (download helper) of mozilla that will download the complete file for you picking from the temp directory. So its quite possible gaana developers know of this as any type of file before a preview (in android) tends to be saved to a temp directory (on the external storage card in a folder called data..don’t remember the exact location though).

Comments are now closed for this post.

Lost Password

Register