+ Reply to Thread
Results 1 to 8 of 8

Thread: Behind The Scene : Android Rooting Share/Save - My123World.Com!

  1. #1
    Security Researcher Anant Shrivastava has a spectacular aura aboutAnant Shrivastava has a spectacular aura about
    Join Date
    May 2011
    Location
    Pune, Maharashtra, India
    Posts
    226
    Blog Entries
    1
    Thanks
    75
    Thanked 91 Times in 50 Posts

    Behind The Scene : Android Rooting



    We all hear a lot of stuff about android rooting techniques and how a phone could be rooted. this articles a a small tribute to the rooting work that is going on.

    Note : please don't ask me how to root a specific model of android handset.

    Rooting what exactly it is?

    Android Devices are consumer devices and as such stuff's like Terminal client, super user access (su Binary), busybox are not provided by default. What this effectively means is a person has no direct means of becoming a root. However due to the openness of Android people have submitted or create a large number of applications which can use this super user mode to do wonders.


    now the big question is how to gain root access, this is where rooting techniques come into picture.


    Rooting is a simple process of gaining a temporary root access by exploiting a know vulnerability in the android system and then install su binary and optionally superuser apk (which is a kind of permission manager). we find large number of applications running around such as gingerbreak, rageinthecage, superoneclickroot etc all these application employe one or the other exploit's to gain root access.


    We also find large number of images claiming to be pre rooted when they say the are pre rooted it only means that they have su binary and superuserapk pre installed.




    Later i will add analysis of how these rooting techniques work, such as psneuter rageinthecage or gingerbreak.
    Last edited by Anant Shrivastava; 08-21-2011 at 10:54 AM.
    Website :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Blog :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  2. The Following 5 Users Say Thank You to Anant Shrivastava For This Useful Post:

    "vinnu" (11-09-2011), 41.w4r10r (08-18-2011), b0nd (08-18-2011), fb1h2s (08-17-2011), neo (08-22-2011)

  3. #2
    Security Researcher Anant Shrivastava has a spectacular aura aboutAnant Shrivastava has a spectacular aura about
    Join Date
    May 2011
    Location
    Pune, Maharashtra, India
    Posts
    226
    Blog Entries
    1
    Thanks
    75
    Thanked 91 Times in 50 Posts
    ===== reserved for analysis ==========
    Website :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Blog :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  4. #3
    Garage Newcomer c1ph3r is on a distinguished road
    Join Date
    Jun 2011
    Posts
    10
    Thanks
    4
    Thanked 1 Time in 1 Post
    Rooting is a simple process of gaining a temporary root excess by exploiting a know vulnerability in the android system.

    str_replace("excess", "access" )

  5. #4
    Security Researcher Anant Shrivastava has a spectacular aura aboutAnant Shrivastava has a spectacular aura about
    Join Date
    May 2011
    Location
    Pune, Maharashtra, India
    Posts
    226
    Blog Entries
    1
    Thanks
    75
    Thanked 91 Times in 50 Posts
    Quote Originally Posted by c1ph3r View Post
    Rooting is a simple process of gaining a temporary root excess by exploiting a know vulnerability in the android system.

    str_replace("excess", "access" )
    thanks for pointing it out .... post updated....

    Everyone give me a day or two i will be writing remaining content on it as soon as i get some spare time out....
    Website :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Blog :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  6. #5
    Security Researcher Anant Shrivastava has a spectacular aura aboutAnant Shrivastava has a spectacular aura about
    Join Date
    May 2011
    Location
    Pune, Maharashtra, India
    Posts
    226
    Blog Entries
    1
    Thanks
    75
    Thanked 91 Times in 50 Posts
    Sorry for not posting more on this.

    no excuses i am just acting plain lazy.


    In the mean time : Latest exploit for 2.2 and 2.3
    Revolutionary - zergRush local root 2.2/2.3 [22-10: Samsung/SE update] - xda-developers

    source code : https://github.com/revolutionary/zer...ter/zergRush.c
    Website :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Blog :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  7. #6
    Security Researcher Anant Shrivastava has a spectacular aura aboutAnant Shrivastava has a spectacular aura about
    Join Date
    May 2011
    Location
    Pune, Maharashtra, India
    Posts
    226
    Blog Entries
    1
    Thanks
    75
    Thanked 91 Times in 50 Posts
    More Info on latest ZergRush Exploit, as per the latest request for CVE states.
    copying the content of mail for reference.

    A local user with group "log" on Android may send a malformed message to vold ("volume daemon"), causing a stack buffer overflow. This has been demonstrated to be exploitable to escalate privileges to root on all Froyo (2.2.x) and Gingerbread (2.4.x) devices via freeing an arbitrary heap object and triggering a use-after-free condition [1]. It appears the bug was silently patched in Honeycomb (3.x), but note that since Honeycomb is not open source, it does not fall within the scope of this list. Bug discovered and exploited by the Revolutionary team [2].

    [1] https://github.com/revolutionary/zer...ter/zergRush.c
    [2] Revolutionary

    CVE hass been assiged as CVE-2011-4123


    This exploit as of now is working on largest device base currently available.

    Confirmed to be working on the following devices:

    • Sony Xperia X10 (GB firmware)
    • Sony Xperia Arc (.42 firmware)
    • Sony Xperia Arc S
    • Sony Xperia Play [R800i/R800x]
    • Sony Xperia Ray
    • Sony Xperia Neo
    • Sony Xperia Mini
    • Sony Xperia Mini Pro
    • Sony Xperia Pro
    • Sony Xperia Active
    • NTT Docomo Xperia ARCO SO-02C
    • Samsung Galaxy S2 [GT-9100/GT-9100P]
    • Samsung Galaxy S II for T-Mobile (SGH-T989)
    • Samsung Galaxy S II for AT&T (SGH-I777), Skyrocket (SGH-i727)
    • Samsung Galaxy S [i9000B] & [i9000 2.3.3 (PDA I9000BOJV8, Phone I9000XXJVO, CSC I9000GDTMJV7) and german T-Mobile branding]
    • Samsung Galaxy Mini GT-S5570
    • Samsung Galaxy W [i8150]
    • Samsung Galaxy Y
    • Samsung Galaxy Tab [P1000] (2.3.3 firmware), [P1000N]
    • Samsung Galaxy Note [N7000]
    • Samsung Galaxy Player YP-G70 2.3.5 (GINGERBREAD.XXKPF)
    • Samsung Nexus S [i9023] (2.3.6)
    • Samsung Nexus S 4G 2.3.7
    • Samsung Exhibit (SGH-T759)
    • Samsung Exhibit 4G (SGH-T759) (2.3.3) Build UVKE8
    • Motorola Milestone 3 [ME863 HK]
    • Motorola XT860, Bell XT860
    • Motorola Defy+
    • Motorola Droid X sys ver 4.5.605 w/ gingerbread
    • Motorola Droid X2 (2.3.4) Sys ver 1.3.380.MB870.Verizon.en.US Build 4.5.1A-DTN-150-30
    • Motorola XT883 (China Telecom)
    • Motorola XT862 (Verizon Droid3)
    • Nexus One (2.3.6 stock)
    Website :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Blog :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  8. #7
    Security Researcher Anant Shrivastava has a spectacular aura aboutAnant Shrivastava has a spectacular aura about
    Join Date
    May 2011
    Location
    Pune, Maharashtra, India
    Posts
    226
    Blog Entries
    1
    Thanks
    75
    Thanked 91 Times in 50 Posts
    excellent work by Dan Rosenberg with Sony S tablet.

    detailed writeup of his exploit.

    Security Research by Dan Rosenberg

    you can find some more quality articles on other device rooting also.
    Website :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Blog :
    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  9. #8
    Garage Newcomer hirap1234 is on a distinguished road
    Join Date
    Jul 2012
    Posts
    1
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Things that require root access on a typical Linux system mounting and unmounting file systems, starting your favorite SSH or HTTP or DHCP or DNS or proxy servers, killing system processes, chroot-ing, etc., — require root access on Android as well.

    SMS

LinkBacks (?)

  1. 11-01-2011, 09:53 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts