4 ms·
The stagefright bugs gave control over the media-player daemon of Android. This daemon is not running as root, it's even jailed with SELinux, but it has some in
by soisses 11y ago
The stagefright bugs gave control over the media-player daemon of Android. This daemon is not running as root, it's even jailed with SELinux, but it has some interesting permissions like microphone-access.
Despite the media hype you can't root your phone with the stagefright bugs and so it wouldn't qualify for the bounty.
- concernedctzn 11y agoSome of those other interesting permissions are the ability to open arbitrary network/bluetooth sockets, read/write to external storage, and access the camera[1]. Mediaserver is not full root but it is pretty privileged. Given all of this access it wouldn't take much work to incorporate another privilege escalation bug to get root on the phone anyway, and there is zero user interaction. [1] https://www.blackhat.com/docs/us-15/materials/us-15-Drake-Stagefright-Scary-Code-In-The-Heart-Of-Android.pdf https://www.blackhat.com/docs/us-15/materials/us-15-Drake-St...
- soisses 11y agoThere isn't much in the list that applications like Hangout or Chrome don't have anyway. It's still a very serious vulnerability, but the overstating is just clever marketing by a security company.
- saurik 11y ago> Despite the media hype you can't root your phone with the stagefright bugs and so it wouldn't qualify for the bounty. Alone? No. As part of a "chain" of exploits, which is what this bounty is calling for, in concert with a privilege escalation? Yes. That bug allowed for remote and silent (due to executing in a way which would allow it to suppress notifications of the incoming message) arbitrary code execution as a user on the device, which, even as a user with minimal permissions or which has been sandboxed in some way, affords you the ability to do much much more on the device than you could before the exploit. FWIW, the actual release included a demo of rooting a device on stage; they have a video with a similar demo. I presume the second bug they were using was an already-fixed kernel bug, but if you have something like stagefright your next step is to go hunting for such a bug. (Regardless, the question you were responding to was more about how most of the exploits people put together do not satisfy the "remote" and "silent" parts, as opposed to the "I got root" part; the latter is comparatively easy.) https://www.youtube.com/watch?v=PxQc5gOHnKs https://www.youtube.com/watch?v=PxQc5gOHnKs
- soisses 11y ago> I presume the second bug they were using was an already-fixed kernel bug That's true, @jduck confirmed that on twitter. It's an old, fixed, bug that has nothing to do with stagefright and could be exploited by every app on the phone or every rce in any app on the phone. > Regardless, the question you were responding to was more about how most of the exploits people put together do not satisfy the "remote" and "silent" parts, as opposed to the "I got root" part; the latter is comparatively easy FWIW, "throughout the whole chain" was part of the question.