Comdirect photoTAN app detecting root

Search This thread

swour

Senior Member
Jan 22, 2012
73
63
What about safetynet / unlocked bootloader? (Stock ROM / SM-G991B)
Since my device is running a custom rom, the bootloader is unlocked and the known methods via Magisk to pass the check by Google have been applied. SafetyNet doesn't seem to play a role here. However it is generally a good idea to make sure it will pass to avoid running into trouble if not already a requirement for another app like Google Pay.

It could also be the phone is simply too old for some of the root detection methods to yield results.
 

tko

Senior Member
Oct 23, 2005
122
21
I flashed magisk Canary
...
After reboot, i can open phototan app one time witout root detetion, second (or more) time its cam the root decetion screen.

okay thats wierd.
btw i was only talking about the carnary manager app. i have 23.0 flashed .... no idea if that makes a difference...

manager app name is changed?

(just for info... my bootloader is unlocked, safetynet full pass)
Screenshot_20210517-192211.png
 

Conan179

Senior Member
Apr 28, 2010
923
111
oh embarrassing embarrassing, after I switched to canary earlier, I forgot to hide the magisk app, just checked in and will now watch it.
 

hueuebi

New member
May 18, 2021
1
0
I got it working as well.

Safety net is intact.

I only installed riru and riru unshared, I didn't bother renaming magisk.
Also I used magisk hide to hide all 3 photo tan processes.
 

Conan179

Senior Member
Apr 28, 2010
923
111
I have found my problem,
I created a module with the smali-patcher to always take a screenshot, even for apps protected by drm.
If this is running, the phototan app does not start, without a module it always starts.
 
  • Like
Reactions: swour

Knotte

Senior Member
Nov 19, 2012
153
26
Munich
Just went through this process. For me it was sufficiant to update to magisk v23, rename magisk, install riru and riru unshare, hide all processes of phototan app in magisk hide and *clear cache* only for phototan app. This way I did not have to re-activate the phototan app (nor to wait 2 days) again.
Thank you as well. I did not even have to rename Magisk, just install the modules, hide all 3 PhotoTAN processes, clear its cache, done!
 

TheFerhatKing

Senior Member
Jul 22, 2012
868
241
For me Commerzbank photoTan and Comdirect don't work. Note10+ Exynos (N975F) Android 11 One UI 3.1 May Patch DrKetan ROM.
Installed both modules, hidden in magisk and renamed magisk. Last time it worked was on February Security Patch. I still ask me why I tried it again after tried so much things out.

I still think that the SafetyNet Fix included in ROM does interrupt the Banking App, but ROM Developer doesn't care. Maybe I will change the ROM if I have time.
 
Last edited:

Seppel007

Member
Jun 10, 2012
28
2
Stuttgart
Hi, I got it working too :) with Magisk 23.0 then Hiding Magisk and

- installed the 2 Riru Modules (Riru v25.4.4 and Riru Unshare 2.0)
- applied magiskhide on all 3 processes of the phototan-app

Instantly works again (didnt use it since it updated to 8.3.0 and wasnt working anymore.

Machine: OnePlus 5 Android 9.0.11 unlocked/rooted
 
  • Like
Reactions: langweiligh3

Marty4

Member
Jan 8, 2013
18
5
Hi,

Is there anyone on rooted Android 11 who actually found a way to make the latest photoTAN app work?
I'm running out of ideas...

My current config:
  • Magisk Canary with the following modules:
    • Riru 25.4.4
    • Riru - EdXposed
    • Riru - Enhanced mode for Magisk Hide
    • Systemless Hosts
    • Universal SafetyNet Fix
(disabling these modules doesn't make a difference)

  • Magisk Hide: all three photoTAN processes enabled
  • EdXposed Hide: photoTAN blacklisted
  • SafetyNet passed with BASIC
  • XPrivacyLua: "Get applications" restricted for photoTAN

Even Google Pay works like a charm! Any ideas what could be the problem for photoTAN?
 

RfBob

Member
Oct 8, 2011
39
26
Augsburg
I'm on Oxygen OS 11.0.0.2 GM21BA on a OnePlus 7 Pro / Android 11
Finally managed to get it running with the following setup:

Magisk Canary f822ca5b (23001)
Magisk Manager Canary f822ca5b (23001) (21)
comdirect Phototan 8.3.0 (latest version atm)

1. Hid the three processes of phototan in Magisk Manager
2. renamed Magisk Manager to sth else (This did the trick in the end, I think. I had not known of the possibility to do so via magisks settings)
(3. Hid the Adaway process in Magisk Manager - propably not necessary) Propably not necessary. Will trigger new problems once adaway or the ROM itself need updating.
4. started phototan.
 
Last edited:
  • Like
Reactions: allrightlite

ralphabt

New member
May 24, 2021
4
7
I managed to get it working (Magisk 23.0).

Using only riru unshare was not sufficient for me. A few root apps are installed on my phone, Magisk has been renamed. Still phototan crashed on startup. After trying many things, XPrivacyLua did the trick (-> disable XPosed Hide for phototan & restrict "Get applications" for phototan).

@RfBob AdAway is installed on my phone, I did not need to hide the process
 

Top Liked Posts

  • There are no posts matching your filters.
  • 1
    To my experience a deletion of any phototan related data is not needed. If one can get rid of the root cause, the app continues to work.

    You might have a look to the path /system, especially /system/addon.d . If you find this directory on your phone, and is contains a file with "magisk" in its name, you should change the permissions of addon.d to 700 (chmod 700 /system/addon.d), so that the phototan app is not longer able to find the file.
  • 14
    Since version 8.3.0 additional measures to detect root have been added, do not update as MagiskHide won't be able to prevent detection. Until a solution is found I would recommend staying on the previous version for as long as possible.

    Finding out what exactly is causing the root detection is beyond my technical abilities but I would provide as much information needed to those willing to help.

    ---

    Update: December 14th 2021 - Method no longer sufficient

    ---

    The solution found by @pxrave appears to be working:


    Hey fellas I got it working and others apps detect magisk before.

    Update to latest v23
    Install modules riru and riru unshare
    Remove data from tan app
    Go to magisk hide and tick all process to hide included the isolated
    Start the tan app and do the activation again.

    Problem you need wait 2 days to activate because comdirect use new activation process for photo tan app.

    Working fine all version 8.3


    Link to the Riru Unshare module:
    11
    1. deinstall old magisk-app
    2. install canary.apk
    https://raw.githubusercontent.com/topjohnwu/magisk-files/canary/app-debug.apk
    2.1 install safenet-fix modul
    https://github.com/kdrag0n/safetynet-fix/releases/download/v2.2.1/safetynet-fix-v2.2.1.zip
    (will not be active until you finished step 3.)
    3. repatch boot.rom with "install" & "direct" (installieren & direkte installation)
    4. after that reboot, etc... it should look sth like this
    1.jpg

    5. go to settings (red arrow)
    6. hide app (2.), enable zygisk (if not allready running) 3, enable deny-list (4), config deny-list (5)
    2.jpg

    7. enable all 3 processes
    3.jpg

    8. add other apps you may need in deny-list... like google pay & google play services

    during the hole process you may have to reboot your phone
    9
    Hey fellas I got it working and others apps detect magisk before.

    Update to latest v23
    Install modules riru and riru unshare
    Remove data from tan app
    Go to magisk hide and tick all process to hide included the isolated
    Start the tan app and do the activation again.

    Problem you need wait 2 days to activate because comdirect use new activation process for photo tan app.

    Working fine all version 8.3
    6
    To get rid of the Airplane mode (or toggling data off/on) I figured how to block the connection to the upgrade service right on the phone. The requests go to 'api.comdirect.de'.

    Use blacklist in TrackerControl
    -> Settings / Advanced options / Import hosts file (append)

    Create a file on the phone with this content:
    0.0.0.0 api.comdirect.de

    This way I can leave the connection to the internet on when starting/using the app.
    No version check can be performed, so the app should work forever ...

    One cannot use the TAN push service anymore but only the „photoTAN Grafik“.
    6
    So guys
    My favorite solution:
    Magisk canary
    Riru
    Riru unshare
    Riru lsposed
    Xprivacilua 1.30

    Safety net is ok
    Phototan working