asr-exploit
This webview was found by me, S-PScripts.
Discovery:
-> ASR was one of the two apps our school allowed from the Play Store, the other being myViewboard WhiteBoard. Unlike myViewboard, ASR was force-installed without any way to uninstall it.
-> I knew that this app had to have a webview somewhere. Even though I had already found one in myViewboard, I was determined. I had tried finding it for quite a bit but couldn’t find any… but I eventually found it! At 11:00pm…
-> Enough of me talking now, here are the instructions.
Instructions:
- Go to the download page for ASR here: https://play.google.com/store/apps/details?id=com.nll.asr&referrer=utm_source%3Dwebsite%26utm_medium%3Dhome-page
- Install ASR. If you can’t, you cannot do this exploit.
- Open ASR.
- Click the 3 dots icon at the top right.
- Click Settings.
- After the settings window opens, click the Cloud Services section.
- Click the green + Add button at the bottom right.
- Follow one of the two methods below.
Method 1:
- Click OneDrive/Business.
- Click the green Connect to the service button.
- A Microsoft sign-in screen will appear. If you’ve seen other webviews, you probably know what will happen now.
- Click Sign-in options.
- Click Sign in with Github.
- Click the Github logo.
- In the search box at the top right, type Google.
- Click Search all of Github.
- Click the Google link in the infobox about Google to the right of the screen.
- You are in Google and all websites are unblocked!
- As there are no tabs, use the forward and back keys on the top row of your keyboard.
Method 2:
- Click Box.
- Click the green Connect to the service button.
- After the authenticating screen, a box sign-in screen will show up. Click Terms of Service or Privacy Policy.
- On the cookie popup at the bottom that shows up (with the Accept all, Reject all and Customize buttons), click on “here” in the second/last sentence.
- On the cookie notice page, scroll down a bit to see a table.
- Find Google in this table (second column) and look at the third column next to it.
- In this third column, click the first “here”.
- Scroll to the bottom on the Google Privacy page.
- Click the small grey Google text.
- You are in Google and all websites are unblocked!
- As there are no tabs, use the forward and back keys on the top row of your keyboard.
Issues:
-> It’s a bit slow and images load slowly/don’t load correctly.
Credits:
S-PScripts (me) | https://github.com/S-PScripts