[ROOT][SECURITY] Root exploit on Exynos - Galaxy S III General

Hi,
Recently discover a way to obtain root on S3 without ODIN flashing.
The security hole is in kernel, exactly with the device /dev/exynos-mem.
This device is R/W by all users and give access to all physical memory ... what's wrong with Samsung ?
Its like /dev/mem but for all.
Three libraries seems to use /dev/exynos-mem:
/system/lib/hw/camera.smdk4x12.so
/system/lib/hw/gralloc.smdk4x12.so
/system/lib/libhdmi.so
Many devices are concerned :
Samsung Galaxy S2
Samsung Galxy Note 2
MEIZU MX
potentialy all devices who embed exynos processor (4210 and 4412) which use Samsung kernel sources.
The good news is we can easily obtain root on these devices and the bad is there is no control over it.
Ram dump, kernel code injection and others could be possible via app installation from Play Store. It certainly exists many ways
to do that but Samsung give an easy way to exploit. This security hole is dangerous and expose phone to malicious apps.
To be continued ...
In attachment, binary and source for root shell.

Pretty cool and advanced method, thanks on the source of it. One had to actually come up with that or find the exploit even. Ironical since there's comments in the ramfs init files warning to set the permissions correctly.
Might be more meaningful if you posted this in the original development forum or the Note 2 developer talk forum as more people might be interested in it.

Posted too in GN2 and maybe a moderator could move this one to original development to avoid multiple post

it would be fantastic to have an apk for root

yo_7 said:
it would be fantastic to have an apk for root
Click to expand...
Click to collapse
Building one now.
EDIT: Built. http://forum.xda-developers.com/showthread.php?t=2050297

alephzain said:
Posted too in GN2 and maybe a moderator could move this one to original development to avoid multiple post
Click to expand...
Click to collapse
As the other thread in GN2 has more information, and we do not allow cross-posting, I'm going to close this one (PM me if you want to propose a different solution)
More information here: http://forum.xda-developers.com/showthread.php?t=2048511

Chainfire said:
Building one now.
Click to expand...
Click to collapse
thanks CF, let we know when done please

Related

One Click Root for 10.1 Tab

Hello, just wondering if there be ever a one click auto root compiled for the Limited 10.1 ???
Thanks.
Nope there isn't cause this device doesn't have an external sdcard.
seraphimserapis said:
Nope there isn't cause this device doesn't have an external sdcard.
Click to expand...
Click to collapse
Doesn't the Samsung internal hard drive act as an external SD card ?? You can you adb to push data as a SD card.
Just trying to put my pennies across. Not a big brain to this stuff.
Wrong section, this is for 10.1v
I''d be interested in a one click root for the 10.1v too, so we can keep the thread alive at least.
fgarcia25 said:
Hello, just wondering if there be ever a one click auto root compiled for the Limited 10.1 ???
Thanks.
Click to expand...
Click to collapse
Not Android Development
Please Post in the Correct Forums
Moving to General
lufc said:
Not Android Development
Please Post in the Correct Forums
Moving to General
Click to expand...
Click to collapse
Sorry, was not aware requesting 1 click root was not a development question.
Sent from my GT-P7510 using XDA Premium App
fgarcia25 said:
Sorry, was not aware requesting 1 click root was not a development question.
Sent from my GT-P7510 using XDA Premium App
Click to expand...
Click to collapse
It was moved because you are not a developer working on 1 click root. Main difference is working vs asking.
What are the benefits of rooting the tablet?
coolacid217 said:
What are the benefits of rooting the tablet?
Click to expand...
Click to collapse
People do it for a variety of reasons. I'll just name a few.
1. To get updates before they are official
2. To run custom roms
3. Change processor speed (underclock/overclock)
4. View and edit system files
5. Modify anything you want
6. Wireless tether
7. Put themes on your phone
8. Use some apps that require root.
9. etc
It basically just gives you full control of your device, so you can do whatever you want to it. That's why its so beneficial.
tghockey07 said:
People do it for a variety of reasons. I'll just name a few.
1. To get updates before they are official
2. To run custom roms
3. Change processor speed (underclock/overclock)
4. View and edit system files
5. Modify anything you want
6. Wireless tether
7. Put themes on your phone
8. Use some apps that require root.
9. etc
It basically just gives you full control of your device, so you can do whatever you want to it. That's why its so beneficial.
Click to expand...
Click to collapse
*cough* adblock *cough*
I believe there's a process of program called oiden that will do this for you. Look in the development section.
the main problem is to find an easier way to unroot rather than flashing a stock rom (some original firmwares aren't avaiable on samfirmware )
It's called ODIN3, and you use it to flash a different kernel on your Tab. You can find tons of kernels in the development section. I'm a fan of Pershoot's. Those kernels will enable you to root and/or install a different ROM on your Tab.

One click rooting method in less than 2 minutes

Root your phone without unlocking the bootloader. How? A new application called UnlockRoot does it all for you! Literally, all you need to do is download the UnlockRoot.exe, run it and enjoy your new rooted device. I can confirm that it is 100% working and took about 2 minutes from start to finish.
All you have to do is connect to your computer, enable USB debugging which is accessible through Settings>applications>devlopment>USB debugging
open UnlockRoot.exe and click root, after that it should take the comp. 1 min tounlock then 1 min to reboot then voila you have it rooted! You will then see the superuser app inside your app drawer. I recommend you to download busybox and titanium backup to have full control on your device. I've just rooted my xperia play and my wife's arc s using method. Both of them are running v2.3.4 so this should work on lower versions.
If there will be an instance wherein your device didn't reboot automatically,manually restart your device.
http://rom.anshouji.com/root/unlockroot23-eng.exe
Have fun
Is this in any way better than supetoneclick, zergrush?
Sent from my Xperia Play
sorry but this does not sound legit
PHOENIXROSE said:
sorry but this does not sound legit
Click to expand...
Click to collapse
I checked out the site and it doesnt say compatible with Xperia PLAY or any SE phones for that matter. Plus I am already rooted and unlocked bootloader. The site looks a little questionable like maybe the software could be virus filled. I dont know though. Only way to find out would be to try it, and for that I have no reason to. IT show support for the Kindle Fire. Anyone try it?
3 posts. All the same but in different forums... Spammer.
Even if it does work, this sort of thing shouldn't be allowed. Just trying to promote your own site.
BAN THE SPAM!
Edit: he only posted twice... Still though, at the very least, I call shill.​
I may have been overly judgemental in this case.
Sent from my R800i using Tapatalk
It's put out by AnTuTu, the same people who do CPU Master. They have a link in the newest version of their app.
Probably uses exact same exploits as superoneclick
Sent from my R800x using Tapatalk
d31b0y said:
3 posts. All the same but in different forums... Spammer.
Even if it does work, this sort of thing shouldn't be allowed. Just trying to promote your own site.
BAN THE SPAM!
Edit: he only posted twice... Still though, at the very least, I call shill.
Sent from my R800i using Tapatalk
Click to expand...
Click to collapse
First of all that is not my site and i'm not a spammer. I only posted this method in two different forums,the other one is in the android general hacking tips. The only reason why i mentioned the site is because i'm having problems uploading the unlockroot.exe launcher in this thread. As you can see,i'm only a new member and i don't usually start threads. I'm just trying to help because i had a lot of frustrations using other rooting methods. I have a descent job and i'm not gonna benefit in spamming so don't accuse me. I just felt very excited to share this method as this worked like a charm for my xperia play. I'm not forcing you to try this so ban me if you feel like doing so.
First of all that is not my site and i'm not a spammer. I only posted this method twice,the other one in the android general hacking tips. The only reason why i mentioned their site is because i'm having problems attaching the unlockroot.exe launcher in this thread. As you can see i'm only a new member and i don't usually start threads. I'm just trying to help man as trying other rooting methods gave me a lot of frustrations. I just felt excited sharing this method because it worked like a charm for my xperia play. I'm not forcing you to try this,it's up to you if you don't want to. I have descent job so i'm not in any way gonna benefit in spamming so don't accuse me. Just ban me if you feel like doing so.
Sorry if i double-posted,please remove this post mods. Thanks!
jgregoryj1 said:
I checked out the site and it doesnt say compatible with Xperia PLAY or any SE phones for that matter. Plus I am already rooted and unlocked bootloader. The site looks a little questionable like maybe the software could be virus filled. I dont know though. Only way to find out would be to try it, and for that I have no reason to. IT show support for the Kindle Fire. Anyone try it?
Click to expand...
Click to collapse
I noticed that too but trust me,it worked for my xperia play and my wife's arc s. Both of them are running the latest android v2.3.4 that's why i'm very surprised that it worked. Other rooting methods didn't work for that version so i resorted to doomlord's method but i'm having problems installing the adb drivers as i'm using windows7. I'm so happy using this method because it's very safe,no need to unlock your bootloader. Best regards!
d31b0y said:
3 posts. All the same but in different forums... Spammer.
Even if it does work, this sort of thing shouldn't be allowed. Just trying to promote your own site.
BAN THE SPAM!
Edit: he only posted twice... Still though, at the very least, I call shill.
Sent from my R800i using Tapatalk
Click to expand...
Click to collapse
I already uploaded the direct link to the file so you can shut your mouth now. I've been itching to do that right from the start but this site won't allow me because i need to have at least 8 posts before i can attach external link. You're a senior member so you should've known that,think first before accussing me a spammer.
lesthur said:
I already uploaded the direct link to the file so you can shut your mouth now. I've been itching to do that right from the start but this site won't allow me because i need to have at least 8 posts before i can attach external link. You're a senior member so you should've known that,think first before accussing me a spammer.
Click to expand...
Click to collapse
I'm curious, why not post directly to their site, instead of a link to a file host?
No, offense, but if you post directly to their home site, it makes it seem a lot more legit than just posting a link to your download account.
http://www.unlockroot.com/index.htm
paxChristos said:
I'm curious, why not post directly to their site, instead of a link to a file host?
No, offense, but if you post directly to their home site, it makes it seem a lot more legit than just posting a link to your download account.
http://www.unlockroot.com/index.htm
Click to expand...
Click to collapse
Sorry bro but i already did that when i started this thread. I just edited my post because that d31boy guy is accussing me of being a spammer and just promoting that site.
When I see a brand new poster posting a link to relatively unknown website for use of an unknown exe file, it's hard not to be suspicious. I mean, you obviously know the benefits of root and you know your way around this site. The site has absolutely no mention of how the root is applied (which isn't your fault provided you don't have an affiliation to the site ). It's a pretty big leap of faith.
However, I may have jumped in a bit too quick on this one. It would have been better just to report the post and allow a mod to make a more informed decision. For that, I apologise.
All this method is, is the zergRush method with a different name...
Here's what I did (quick run thought of what i did, attached screenshot for reference)
Downloaded it from the OP's post (http://unlockroot.com was running at 2000BYTES/SEC)
Installed it on my XP partition
rebooted, went to my linux partition
Mounted XP Partition
went to \Program Files\Unlockroot\tools\
Copied rootutility to /home/myusername/
adb shell rm -r /data/local/tmp
adb shell mkdir /data/local/tmp
adb push rootutility /data/local/tmp
adb shell chmod 755 /data/local/tmp/rootutility
adb shell /data/local/rootutility
and got the attachment
works on the .62 firmware?
-------------------------------------------
Fma965 - ForgottenCoders
http://forgottencoders.co.uk
fma965 said:
works on the .62 firmware?
-------------------------------------------
Fma965 - ForgottenCoders
http://forgottencoders.co.uk
Click to expand...
Click to collapse
Someone posted that it didn't worked on his .62 play,mine is .42. Give it try so we will know if it's really not working on that build.
Best regards!
lesthur said:
Someone posted that it didn't worked on his .62 play,mine is .42. Give it try so we will know if it's really not working on that build.
Best regards!
Click to expand...
Click to collapse
I will if you tell me how to unroot lol used doonlord kernel for auto root.
-------------------------------------------
Fma965 - Forgottencoders.co.uk
Want to make me a banner? PM me

FC Samsung apps

Hi.
I was busy debloating and I've gone a bit too far.
All samsung apps which index the file system force close on me.
Gallery, My Music, Videos, My Files...
Do any of you know which framework, service or apk they all rely on?
Thanks.
rayone said:
Hi.
I was busy debloating and I've gone a bit too far.
All samsung apps which index the file system force close on me.
Gallery, My Music, Videos, My Files...
Do any of you know which framework, service or apk they all rely on?
Thanks.
Click to expand...
Click to collapse
Wrong thread!!!
yussuf007 said:
Wrong thread!!!
Click to expand...
Click to collapse
You mean forum.... it's development bcos I'm building a bloat free SD English ROM, and I can't figure out which of the 589 files I've removed is causing the Samsung app fc's.
But I'm also more than happy for a mod to move it the thread.
I agree that this is wrong forum/thread. If CM12 PORTING thread was moved from development thread even though there was clearly active/documented development going on on a daily basis simply because Mods could see a working ROM at the time then this thread definitely needs to be moved or I declare shenanigans!
Anyway, have you thought to pm SkywakerZ? He has developed the SmartDebloater Tool so he may be able to give you a hint of what you can and can't safely delete.
rayone said:
You mean forum.... it's development bcos I'm building a bloat free SD English ROM, and I can't figure out which of the 589 files I've removed is causing the Samsung app fc's.
But I'm also more than happy for a mod to move it the thread.
Click to expand...
Click to collapse
Sorry for the trolling, but read the rules. If you have a question then ask it in the Q & A .
And i just recomended if you dont know the answer for your question dont try building roms.
Eddster3000 said:
I declare shenanigans!
Anyway, have you thought to pm SkywakerZ? He has developed the SmartDebloater Tool so he may be able to give you a hint of what you can and can't safely delete.
Click to expand...
Click to collapse
OK, sorry for posting the wrong forum.
I've seen SmartDebloater, but it doesn't go deep enough also it (and all the other scripts) don't remove knox properly... (/init.container.rc needs to be addressed) and boot still requires a knox encryption class.
I wish there was a tool like procmon in windows for Android.
If nobody knows which framework or component all those Samsung apps require I'll just put everything back and start again.
yussuf007 said:
i just recomended if you dont know the answer for your question dont try building roms.
Click to expand...
Click to collapse
making roms (system updates) is easy I've been doing it 1/0 since Win CE, XDA 2 (WinMo 2003). Making generic roms which everyone likes and answering their questions is hard.
[Update] Nothing in priv_app, app, framework or lib fixes my issue even with f.reset. So I'm stumped but I think it might have something to do with knox.

Any kernel verizon s5

Lokking for kernel for s5
http://forum.xda-developers.com/showthread.php?p=61150320
I didn't see where you specified which kernels, and as a new member I'm not allowed to post links directly, but you can try to search androidfilehost.com for Samsung Galaxy S5, etc., be sure to verify the version downloaded is what you need, and good luck!
Bruce.
bbourdon said:
I didn't see where you specified which kernels, and as a new member I'm not allowed to post links directly, but you can try to search androidfilehost.com for Samsung Galaxy S5, etc., be sure to verify the version downloaded is what you need, and good luck!
Bruce.
Click to expand...
Click to collapse
Ummm .... I guess I am missing something here? The kernels are CLEARLY specified in the download list from the above link. There is one for each version of 5.0 that is out there. Now, on the other hand, if you don't know which one you need, you obviously need to do further research and have no business flashing anything !!
Chopstix9 said:
Ummm .... I guess I am missing something here? The kernels are CLEARLY specified in the download list from the above link. There is one for each version of 5.0 that is out there. Now, on the other hand, if you don't know which one you need, you obviously need to do further research and have no business flashing anything !!
Click to expand...
Click to collapse
sorry friend, I should've been more specific, I was referring to the OP's statement: "Lokking for kernel for s5"
Hope they found what they were looking for
yes i was looking for a kernel for my s5

[Samsung Galaxy A8] Dear, Developers

First of all, I would like to give my thanks to all developers in XDA.
I'm just questioning several matters here. And they are about Galaxy A8.
I found that this device is actually a beast that can 'attract' people immediately once they hold this phone. A lot of people, including me, are really interested about how we can 'play' this device in some ways possible. Yet, it seems like there are not many developers in XDA actually 'attracted' with A8. This device was launched on August, several months ago. But sadly, even the start step on how we can 'play' this device is still not clear. Root is our first tool for devices we want to 'play' with. I've searched methods mentioned here on XDA on how to root this A8, yet I haven't found a suitable one. While there is a way possibly work for one of A8 models, the A800F, it is from another source. And how about the other models like A800I or A800YF? Some people said that A800F rooting method from other source outside XDA works, some people said not. I would consider myself to not to trust that source (even though mine is A800F itself) because I prefer XDA and the people within who involved.
They might say it works, but what's the point if we can't find the answer from developers in XDA we're counting in?
Is A8 not too good enough for development that trigger developers leave this device alone? A lot of people came here to find the answers since this is a section for A series, including A8, yet we found nothing.
I'm not questioning the competence of the developers because I know you guys are our green android who could bring more happiness to our Stock Device. Even it starts with a legit root ways, hopefully there will be helps in using recovery or even Custom ROMS in the future.
So please, dear, developers.
Help us even though we can only show our appreciation and our thanks which is not enough for your effort, please remember you guys are the only ones who can spread the happiness.
Best regards.
Hey dude, I ain't no dev . Just your average tester here. Uhm I get the fact that y'all are fed up with not having any development for your phone but trust me it's not that easy I mean , I have the Galaxy A7 and believe me dude we had to wait an awful long time too... There are not a lot of things you can do . You can try attracting devs to get yourself a rooting method. Uhm there was a dev that helped us called ShinySide ( http://forum.xda-developers.com/member.php?u=5580710 ) This holy dude helped us , he might help you as well . I suggest you kindly ask him he is a cool guy. I hope you guys get it short it out. Cause as it seems our phone too doesn't get much love . NOT EVEN from sasmung . Best regards
@Alberto96, @modpunk, @jackeagle, @RVR
@Manh_IT
I will consider updating the kernel support for A8 series, but I can not be sure because I not have a A8 device now!
Manh_IT said:
I will consider updating the kernel support for A8 series, but I can not be sure because I not have a A8 device now!
Click to expand...
Click to collapse
Post your SpaceX Kernel here at xda forums also!!
shubham540 said:
Post your SpaceX Kernel here at xda forums also!!
Click to expand...
Click to collapse
Attach a stock kernel of you, here:
http://forum.xda-developers.com/sam...t/project-spacex-kernel-root-support-t3277159
Manh_IT said:
Attach a stock kernel of you, here:
http://forum.xda-developers.com/sam...t/project-spacex-kernel-root-support-t3277159
Click to expand...
Click to collapse
I'll upload the files you need and post them on your thread, I have SM-A800I and I can test your kernels on my device so don't worry about testing.
Thanks for your help
Cheers
@RaymanFX @sunsettrack4
Samsung Galaxy A8 (SM-A800F) also uses Exynos 5430 Chipset (same as Galaxy Alpha (SM-G850F)
wow.. dead end? :/
Rei Zazie said:
First of all, I would like to give my thanks to all developers in XDA.
I'm just questioning several matters here. And they are about Galaxy A8.
I found that this device is actually a beast that can 'attract' people immediately once they hold this phone. A lot of people, including me, are really interested about how we can 'play' this device in some ways possible. Yet, it seems like there are not many developers in XDA actually 'attracted' with A8. This device was launched on August, several months ago. But sadly, even the start step on how we can 'play' this device is still not clear. Root is our first tool for devices we want to 'play' with. I've searched methods mentioned here on XDA on how to root this A8, yet I haven't found a suitable one. While there is a way possibly work for one of A8 models, the A800F, it is from another source. And how about the other models like A800I or A800YF? Some people said that A800F rooting method from other source outside XDA works, some people said not. I would consider myself to not to trust that source (even though mine is A800F itself) because I prefer XDA and the people within who involved.
They might say it works, but what's the point if we can't find the answer from developers in XDA we're counting in?
Is A8 not too good enough for development that trigger developers leave this device alone? A lot of people came here to find the answers since this is a section for A series, including A8, yet we found nothing.
I'm not questioning the competence of the developers because I know you guys are our green android who could bring more happiness to our Stock Device. Even it starts with a legit root ways, hopefully there will be helps in using recovery or even Custom ROMS in the future.
So please, dear, developers.
Help us even though we can only show our appreciation and our thanks which is not enough for your effort, please remember you guys are the only ones who can spread the happiness.
Best regards.
Click to expand...
Click to collapse
hey mate i got the A800I A800Y A800YZ root.
M
IzArsha said:
hey mate i got the A800I A800Y A800YZ root.
Click to expand...
Click to collapse
Please post links or how to. I have a800yz and cant find a custom recovery mod for it
I'd love to see some custom roms for this device. Galaxy alpha has the same exynos chipset and still has plenty of roms. For the sm-a800f i know there is cm13 and rr but still in alpha stage. I don't think its that we can't port roms for this drvice, but the lack of developer interest for it. I am willing to test any rom for this device, if any developers are interested.
---------- Post added at 10:21 PM ---------- Previous post was at 09:53 PM ----------
Styx1212 said:
M
Please post links or how to. I have a800yz and cant find a custom recovery mod for it
Click to expand...
Click to collapse
Here, just scroll down and look for it. Flash it with odin.
https://autoroot.chainfire.eu
It seems like everyone has stopped developing / customizing for this device

Categories

Resources