Possible new root method?

This is a discussion on Possible new root method? within the Motorola Backflip Development & Hacking forums, part of the Motorola Backflip category; I'm not sure if anyone else has seen this, but the guys over at m3 are working on a new root method that sounds pretty ...

Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Possible new root method?

  1. #1
    Junior Member Yawnses's Avatar
    Join Date
    Jul 2010
    Posts
    21

    Possible new root method?

    I'm not sure if anyone else has seen this, but the guys over at m3 are working on a new root method that sounds pretty promising.
    Potential NEW method for root on the MB300 (in progress)

    After 40 hours of auditing code, I think I have a working method to gain root on the MB300. Long story short, from the code I went over, it appears I have the ability to now create mode 0666 block devices with any major/minor number I want.

    The question is, can I get a block device with write access to the underlying mtd subsystem? I'm thinking a loopback block device to the existing mtdblock1 block device may work, but not entirely sure off the top of my head if that'll work due to how the loopback subsystem works. If anyone wants to create a mode 666 loopback device linked to another block device root owned w/ mode 0600 and mounted as a read-only filesystem, please do so as it will save me a little bit of time.

    There also appears to be a reference to a /dev/root device for utilization on read-only file systems, but still need to investigate this.

    Anyway, assuming I can actually initiate the creation of the mode 0666 block device and I do control the major/minor numbers, ideas on how to gain write access to an already mounted and existing mtd block device without the nosuid option set would be great.

    I'll release more details once I've confirmed this is working as I want to evaluate how wide spread the vulnerability is.


    Ideas and feedback are appreciated.

    Thanks.

    Status

    1. User land netlink message accepted. (confirmed)
    2. Block device creation w/ mode 0666. (in progress)
    3. Ability to control block device major/minor numbers. (confirmed)
    4. Determination of block device to create. (pending)
    5. Method of privilege escalation. (pending)

  2. Android.net is the premier Android Forum. Registered users do not see these ads. .

  3. #2
    Senior Member Joe Coolcool's Avatar
    Join Date
    Apr 2010
    Posts
    408
    I'd like to get my hopes up, but after they got crushed so many times...
    Credit goes to ee0r.com for my avatar.

  4. #3
    Member gir489's Avatar
    Join Date
    Jul 2010
    Posts
    44
    This guy looks legit.

  5. #4
    Senior Member Joe Coolcool's Avatar
    Join Date
    Apr 2010
    Posts
    408
    Quote Originally Posted by gir489 View Post
    This guy looks legit.
    :confused: You mean his method looks legit or that he's not just making this up.

    Edit: Oh wait a minute, that's the same thing. Wow. Slow moment.
    Credit goes to ee0r.com for my avatar.

  6. #5
    Member gir489's Avatar
    Join Date
    Jul 2010
    Posts
    44

    .

    The main reason it's not been root is the old OS version. Secondary reason is lack of intrest

  7. #6
    Junior Member andershizzle's Avatar
    Join Date
    Jun 2010
    Posts
    22
    When I saw the Backflip I was like YO and hopped on that.

    Now I find it's a bummed down device. Bummer. Honestly, the backflip for the keyboard is a pain. I spend half my time too lazy to flip the keyboard and just swype it, and tons of errors on that swype lol.

    Used it on AT&T for a bit. Discovered T Mobile gets better 3g AND edge speeds and better coverage than AT&T, in Pittsburgh at least. (Did tests)

    Now I'm using it unlocked on T Mobile cause it's cheaper, and AT&T dropped 50% of my calls. But meh. EDGE only. Lookin at that MyTouch Slide... Already rooted and tons of ROMs.

    The backflip would be GODLY if:

    1GHz Snap Dragon
    Root
    Froyo
    512 RAM

    =But no... It's dumbed down. CupCake... Getting old. Getting sick and sad about this phone...

    Got it on eBay for 290$... Now they're only going for 240~. Looks like I lose 50$ if I sell it now. Bummer.

    I hate how prices go down. Bought a Touch Pro 2 in December for 600$. Just sold it for $199. So depressing.

    Either way, what the hell am I doing ranting.

    Sigh.

    Then again there's the Samsung Vibrant, which really tears up the Captivate cause you can get it on T-Mobile and it's slicker. Pretty much same model though.

    Vibrant is 400+ on eBay though. Major pain.

    Oh well. MyTouch Slide it is... Unless this Backflip gets rooted by tomorrow. Lol.

    Even then, dunno. AT&T is a real bummer. I went from T Mobile to pay almost twice as more on AT&T for less, and the service was worse. Plus the reps aren't even nice.

    And then there's Motorola. Huge D's. Effing hate them.

    >AFDMALFM

    Spam rant over, lmao.

  8. #7
    Senior Member Joe Coolcool's Avatar
    Join Date
    Apr 2010
    Posts
    408
    Sounds like in your area T-Mobile is better than At&t. Go with T-Mobile then if it works the best for you.
    Credit goes to ee0r.com for my avatar.

  9. #8
    Member weasel5i2's Avatar
    Join Date
    May 2010
    Location
    Austin, TX
    Posts
    87
    (like a doofus, I replied in the wrong forum, hehe) - now posted on m3 where it should be

  10. #9
    Member gir489's Avatar
    Join Date
    Jul 2010
    Posts
    44
    Mount is a su command on Android.

  11. #10
    Senior Member Joe Coolcool's Avatar
    Join Date
    Apr 2010
    Posts
    408
    I wonder if he's been working so hard on root that he hasn't been able to update anything for three days...

    Or gave up and didn't bother posting.
    Credit goes to ee0r.com for my avatar.

Page 1 of 2 12 LastLast

Remove Ads

http://www.scramblerducati.org/

Sponsored Links

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search tags for this page

new root method

Click on a term to search our sites for related topics.
Android Forum