Monday, December 15, 2014

Appnana version 2.4.5

Last Saturday I noticed an update of the AppNana app: version 2.4.5 had been released.
Apparently 2.4.4 has been skipped?
You can find the version number on the bottom of the 'Invite' tab.

Personally I don't see any changes. Might have been some bug fixed on the 'Random Free Nanas' on the 'Get Nanas' page, as that is announced as 'What's New' on the Google Apps page.

If you know of other tweeks or modifications on this app that I might have missed; please feel free to add it to the comments!

Exchange your code with mine: n6215050 and I will definitely try to return the favor!

Saturday, December 13, 2014

AppNana behind the scenes: offer suppliers

In Europe, these offers are supplied:
Nana Offers section one: the AppNana app connects to present offers hosted by aarki.net Website: http://www.aarki.com/
Nana Offers section two: advertisements are delivered by appclick.co NativeX (their privacy policy states they cannot be held liable for anything that exceeds a total of $10.00). Website: http://nativex.com/
Nana Offers section three: temporarily no offers (26-11-2014)
Nana Offers section four: videos are offered by Vungle and AdColony
Nana Offers section five: contains offers provided by TrialPay
Nana Offers section six: offers by TokenAds.
        NOTE : In my opnion this section contains very questionable contents
                     with SMS text message subscriptions.

Saturday, December 6, 2014

AppNana behind the scenes: what is send with an offer?

When clicking on one of the AppNana offers from the first Appnana Offers section, when actually clicking the following is happening:

The AppNana app connects to aarki.net (to be prcecise: http://hs.aarki.net/adpick/garden), and with a lot of parameters. A lot of your personal phone information is handed out!

Here is an example of a call from my Dutch HTC phone:

http://hs.aarki.net/adpick/garden?
src=49D4B67277BAA3E4AA
&xbtn=y
&platform=android
&sdk_version=3.0
&device_platform=android/4.2.2
&device_model=HTC One X
&device_manufacturer=HTC
&device_brand=htc
&device_product=htc_europe
&uixe=6c1c1b586f671f0f101a07406f686f
&pixe=691b195466671f401314014e606869
&dixe=631b1d5a6b65194414120716696d6f61
&nixe=6b4d100f6f6816411f42034d3d6c64300a
&user_agent=Mozilla/5.0 (Linux; U; Android 4.2.2; en-nl; HTC One X Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
&app_sec_key=TfSMSG6o3wrtFGzBKhIhG33Vf60N
&advertising_id=06484d41-c02f-490f-997c-67465feae167
&tracking_limited=n
&package_name=com.appnana.android.giftcardrewards
&country_code=NL
&current_locale=en_NL

As you can see, my AppNana number n6215050 is probably somewhere encrypted in one of the uixe, pixe, dixe and/or nixe parameters.
Aarki.net is the production advertisement domain of aarki.com, a media advertisement company.
This all seems within the bounderies of the standard AppNana app  permissions.