suspicious activity from "Linux" on an android phone
I need help with fixing certs I beleive were changed by an application. I found some files in an application I installed through another without fully looking at the extr… (read more)
I need help with fixing certs I beleive were changed by an application. I found some files in an application I installed through another without fully looking at the extra packaged material. One seems to be a configuration file for CA certs and the other is a list of SSL certs taken from Mozilla that were included with the intent of editing trusted user certs. I now see the evidence of a Linux device using my Firefox. To me, that is pretty clear evidence that Shell was used for some connection. So, with that, I'm assuming the certs on my device are not correct, and need to be fixed. Please let me know what I can do for this and if there is any other information you can give me on how to find out more about what to do. Unfortunately, there are also files that seem to also change user to a fake user while they gain root as guest. Any additional information including removing and replacing all certs wouldbe very helpful. Im trying to get to a certain point of restricting access and making a move to alert the correct people in Github and a couple of others with/towards some of the files before I do any kind of reset as I am not fully sure how tainted the restore might be.