5 ms·
I put 'root' in quotes, because technically, it isn't rooting. However, it creates a binary called 'run-as' that can execute packages as root. Not sure what the
by Arinerron 10y ago
I put 'root' in quotes, because technically, it isn't rooting. However, it creates a binary called 'run-as' that can execute packages as root. Not sure what the right term would be in this case.
- jmickey 10y agoWell if you can run any executable as root, that sure counts as rooting in my book.
- sdrothrock 10y agoThe advantage I see here is that you don't have to actually root your phone, which means that apps/games that check for root access would continue to work normally.
- daveloyall 10y agoI've always wondered: what exactly are they checking for? What's the difference between "I can become the root user on my phone whenever I want" and "My phone is rooted"? Note: I'm asking as a GNU/Linux user, not as a phone user.
- sdrothrock 10y agohttp://www.cs.ucr.edu/~zhiyunq/pub/ccs15_root_providers.pdf http://www.cs.ucr.edu/~zhiyunq/pub/ccs15_root_providers.pdf
- daveloyall 10y ago2015-08-20. The document describes analysis performed on those apps which root your phone for you. Thanks!
- sdrothrock 10y agoNo problem! I don't do Android development of any kind and didn't trust my ability to properly explain it, but it's an interesting paper. :)
- scrollaway 10y agoSure, but as soon as it's patched out, you're back to no root.
- omribahumi 10y agoMaybe I'm missing something here, but what stops you from putting a setuid "su" binary and keeping the root access, even if the kernel is upgraded?
- deleted 10y ago[deleted]
- therein 10y agoYou're root running in a limited selinux context.
- omribahumi 10y agoI'm assuming that's because of the Android security model, rather than a limitation of the exploit itself? edit: Apparently SETUID is disabled on Android: ... using kernel features that help block privilege escalation (e.g. NOSUID, NO_NEW_PRIVS). source: https://lwn.net/Articles/609511/ https://lwn.net/Articles/609511/ also: https://unix.stackexchange.com/a/250806/95938 https://unix.stackexchange.com/a/250806/95938
- daveloyall 10y agoAre you saying that on Android, you can achieve UID=0 via this exploit, but still not write to anywhere important on the device? What are these different "methods" listed in the table here? https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs Can one of those methods allow me to write to some file in /etc? (Which is enough to grant me the access I want, unless selinux is just MAGIC.)
- therein 10y agoSELinux can still prevent you (even if you are `$UID=0`) from performing an operation such as writing to a file under `/etc`. You would need to be able to `setenforce 0 `. A properly configured SELinux context can prevent you from doing that however we are starting to finally see some reports of dirtyc0w successfuly leading to `SELinux status: permissive` and permanent root.
- voltagex_ 10y agoA (somewhat cringeworthy) thread on how to gain persistence via this exploit is at https://github.com/timwr/CVE-2016-5195/issues/9 https://github.com/timwr/CVE-2016-5195/issues/9 I think this would be a "temporary root", rather than something like CF-AutoRoot that gains persistence by modifying the system itself.
- cyphar 10y agoIt's painful to read. Only one person in that thread appears to know what SELinux actually does, and nobody has mentioned the fact that SELinux was explicitly designed to make a root privesc contained. The ironic part is that since DirtyCOW is a kernel bug they could probably modify the exploit to disable SELinux from inside the kernel (or load a module that disables SELinux). But they're just trying to use the PoC as the only thing you can get from the exploit.
- digi_owl 10y agoWelcome to the world of phone firmware modding. I suspect you got much the same back in the microcomputer era. Just look at the various phreaker stuff salvaged from BBSs.
- daveloyall 10y agoWell at least these github repos and gists are an improvement beyond "here, download this .apk from megaupload and install it!"
- executesorder66 10y ago> Not sure what the right term would be in this case. Maybe pseudo-sudo?
- deleted 10y ago[deleted]