android mms vuln - Verizon Motorola Droid Turbo Q&A, Help & Troublesh

Hello guys!
There's still not much info, but maybe these vulnerabilities would help gain root for those who took 5,1 ota?
CVE-2015-1538
CVE-2015-1539
CVE-2015-3824
CVE-2015-3826
CVE-2015-3827
CVE-2015-3828
CVE-2015-3829
whar do you think?

Well there isn't much info about the exploits out to the public yet, might be possible though since these exploits allow for remote code execution. I'm hoping for root, but do not need it all that much
Sent from my XT1254 using XDA Forums

Make lemonade out of lemons. Actually a good idea!

I love this idea, i wish i could help but i wouldn't even know where to begin. more information was released link below.
https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/
I ran the check and as expected the turbo is vulnerable.

No surprise. It will take Moto half a year or more to patch this. Intrigued to see if this could be used as tools for a real root for those that are already on 5.1. Maybe a door to BL unlock? Would be shweeeet
Sent from my XT1254 using XDA Free mobile app

https://www.youtube.com/watch?v=PxQc5gOHnKs
judging by this video we are able to get root access from this exploit, no idea if it is permenant root or not, but it is definately something to toy around with..

Murd0c said:
judging by this video we are able to get root access from this exploit, no idea if it is permenant root or not, but it is definately something to toy around with..
Click to expand...
Click to collapse
Has anyone tried contacting the poster of the video?

Apparently, Google has already sent out the patch to carriers and manufacturers. Its up to them to create whatever they want to fix the exploit.

any news?

Good news guys. Zimperium has finally published stagefright exploit source! So we can start developing new root method
https://blog.zimperium.com/the-late...xploit-is-now-available-for-testing-purposes/

MutualFiend said:
Good news guys. Zimperium has finally published stagefright exploit source! So we can start developing new root method
https://blog.zimperium.com/the-late...xploit-is-now-available-for-testing-purposes/
Click to expand...
Click to collapse
That is great news, hopefully someone will be able to figure out a root method with this.
Sent from my XT1254 using XDA Forums

Maybe there's one more chance for our Turbos (and others) to be rooted on 5.* stagefright 2.0 (CVE-2015-6602 and CVE-2015-3876 ) There's still no POC but we can wait

I doubt it..
Sent from my XT1254 using Tapatalk

Related

development- unlock the bootloader

I want to take another stab at unlocking the bootloader, I see the forums seem to be next to dead and i believe if we can successfuly unlock this thing it will breath a bit of new life into our device. anyone who is willing to help and has some information to share please post it here. ive got a few ideas on people to talk to.
until then
lets brain storm
Not trying to be a negative Nancy but why? We got Kexec but just a lack of good developers.
Sent from my DROID3 using xda app-developers app
MrObvious said:
Not trying to be a negative Nancy but why? We got Kexec but just a lack of good developers.
Sent from my DROID3 using xda app-developers app
Click to expand...
Click to collapse
Because we have a pretty good device, and development was great for a while but the bootloader has kept this device from being truly great for a long time. i think if we can crack it it would bring back some development. and not only that but if we can find a way to crack this maybe we can put our information forward to other motorola devices with the same issue. id love to have the kernel options, and variety of roms available ive had on past devices. the og evo was awesome for that one reason. and i honestly believe its possible....
idontwanttobeanoob said:
Because we have a pretty good device, and development was great for a while but the bootloader has kept this device from being truly great for a long time. i think if we can crack it it would bring back some development. and not only that but if we can find a way to crack this maybe we can put our information forward to other motorola devices with the same issue. id love to have the kernel options, and variety of roms available ive had on past devices. the og evo was awesome for that one reason. and i honestly believe its possible....
Click to expand...
Click to collapse
An unlocked bootloader would make no difference. With kexec we can bypass and use a custom kernel anyways. However the custom kernel is still in development as motorola never released an ics/JB kernel
Sent from my DROID3 using xda premium
idontwanttobeanoob said:
I want to take another stab at unlocking the bootloader, I see the forums seem to be next to dead and i believe if we can successfuly unlock this thing it will breath a bit of new life into our device. anyone who is willing to help and has some information to share please post it here. ive got a few ideas on people to talk to.
until then
lets brain storm
Click to expand...
Click to collapse
Lmao
I think it would be great to crack the bootloader. However, has any phone with a locke bootloader been cracked without a leak from the manufacturer?
Moto must be using pretty large bit keys to lock the bootloader. You'll have to be lucky to crack it, not good.
I don't really see the actually bootloader lock changing in anyway. As said above kexec is a good system, just have to be patient.
The-Captain said:
I don't really see the actually bootloader lock changing in anyway. As said above kexec is a good system, just have to be patient.
Click to expand...
Click to collapse
Patient for what? Hashcode himself said "What do you want me to improve on JB for D3?!". I don't really see D3 getting camera on 4.x anymore
DoubleYouPee said:
Patient for what? Hashcode himself said "What do you want me to improve on JB for D3?!". I don't really see D3 getting camera on 4.x anymore
Click to expand...
Click to collapse
He didn't specify camera in OP. I don't care about camera TBH. I have an actual camera I carry around. I though he wanted 4.2
Sent from my XT862 using Tapatalk 2
The-Captain said:
He didn't specify camera in OP. I don't care about camera TBH. I have an actual camera I carry around. I though he wanted 4.2
Sent from my XT862 using Tapatalk 2
Click to expand...
Click to collapse
well glad to see my dumb post has gotten a bit of attention.... lol
id not touched my d3 since long before kexec, found it in a drawer and got a bit carried away.
went back and looked into kexec after everyone mentioned it and i agree its a pretty good system so im gonna start doing my research and see if there is anything i might be able to do.
sorry guys
idontwanttobeanoob said:
well glad to see my dumb post has gotten a bit of attention.... lol
id not touched my d3 since long before kexec, found it in a drawer and got a bit carried away.
went back and looked into kexec after everyone mentioned it and i agree its a pretty good system so im gonna start doing my research and see if there is anything i might be able to do.
sorry guys
Click to expand...
Click to collapse
Focus on the camera.
Sent from my DROID3 using xda app-developers app
The-Captain said:
He didn't specify camera in OP. I don't care about camera TBH. I have an actual camera I carry around. I though he wanted 4.2
Sent from my XT862 using Tapatalk 2
Click to expand...
Click to collapse
Amen. Motorola DROID 3's camera is a total bs anyways.
Hey guys, can anyone tell me in a nutshell what's wrong with our D3's cam? For example It doesn't work under CM7. Is it that special?
Sent from my LG-P990 using xda app-developers app
paleee said:
Hey guys, can anyone tell me in a nutshell what's wrong with our D3's cam? For example It doesn't work under CM7. Is it that special?
Sent from my LG-P990 using xda app-developers app
Click to expand...
Click to collapse
For CM7 you need a 3rd party app like camera 360
I know that we have Kexec on D3, but I'm going to try an experiment on the Bootloader this weekend to see if I can unlock it. Reason being other devices do not have kexec and something crazy happened last night at work. In short, I cracked an AES encryption on a Motorola Radio(the ones Ambulances use). I know that may not sound like much, but I think I might have a way to do the same method on the Bootloaders for our Motorola Phones. I don't wanna go into too many details on it, but I'll try to get you guys a response next week sometime.
Please lol no trolling, I just like trying things. Chances are the method may not work.
Peperm1nt said:
I know that we have Kexec on D3, but I'm going to try an experiment on the Bootloader this weekend to see if I can unlock it. Reason being other devices do not have kexec and something crazy happened last night at work. In short, I cracked an AES encryption on a Motorola Radio(the ones Ambulances use). I know that may not sound like much, but I think I might have a way to do the same method on the Bootloaders for our Motorola Phones. I don't wanna go into too many details on it, but I'll try to get you guys a response next week sometime.
Please lol no trolling, I just like trying things. Chances are the method may not work.
Click to expand...
Click to collapse
Good luck
Peperm1nt said:
I know that we have Kexec on D3, but I'm going to try an experiment on the Bootloader this weekend to see if I can unlock it. Reason being other devices do not have kexec and something crazy happened last night at work. In short, I cracked an AES encryption on a Motorola Radio(the ones Ambulances use). I know that may not sound like much, but I think I might have a way to do the same method on the Bootloaders for our Motorola Phones. I don't wanna go into too many details on it, but I'll try to get you guys a response next week sometime.
Please lol no trolling, I just like trying things. Chances are the method may not work.
Click to expand...
Click to collapse
Hopefully waiting
Sent from my MILESTONE3 using xda app-developers app

[Q] Accidentally accepted update

Let me explain: So I got the OTA overnight, and when I woke up (to my alarm clock) I accidentally accepted the update. I had planned to root my phone and looked into keeping root through the OTA. I postponed it for the last two days, trying to figure out how to root/keep root through OTA. I've been busy with work and had to put it aside until I had a day off. To get to my question, am I screwed or will there be a way to root this phone after the update? This is my first Motorola phone, so pardon me if this is a dumb question. Thanks for any and all comments.
Sent from my XT1060 using xda app -developers app
pborner said:
Let me explain: So I got the OTA overnight, and when I woke up (to my alarm clock) I accidentally accepted the update. I had planned to root my phone and looked into keeping root through the OTA. I postponed it for the last two days, trying to figure out how to root/keep root through OTA. I've been busy with work and had to put it aside until I had a day off. To get to my question, am I screwed or will there be a way to root this phone after the update? This is my first Motorola phone, so pardon me if this is a dumb question. Thanks for any and all comments.
Sent from my XT1060 using xda app -developers app
Click to expand...
Click to collapse
screwed for the time being. jcase already verified there's other ways to root the update but won't release them yet. in due time I'm sure someone will release something. I'm patiently waiting too.. bought a used moto x with the update already applied. sucks.
If its still within the return time, shoot compressed air in the ear piece and speakers. It'll screw it up, take it in and get a replacement. Then don't screw up the next time around.
gokart2 said:
If its still within the return time, shoot compressed air in the ear piece and speakers. It'll screw it up, take it in and get a replacement. Then don't screw up the next time around.
Click to expand...
Click to collapse
Um... As much as I'm in favor of screwing Verizon (and all other multi-national corporations), why not just search the threads for how to use RSDLite to reflash the original stock firmware, then don't accept the OTA until you've waded through the process for keeping root? Or, you can destroy a perfectly good piece of technology for no reason.
hazenberger said:
Um... As much as I'm in favor of screwing Verizon (and all other multi-national corporations), why not just search the threads for how to use RSDLite to reflash the original stock firmware, then don't accept the OTA until you've waded through the process for keeping root? Or, you can destroy a perfectly good piece of technology for no reason.
Click to expand...
Click to collapse
You cannot downgrade firmware.
mandrsn1 said:
You cannot downgrade firmware.
Click to expand...
Click to collapse
I'm pretty sure you can:
http://forum.xda-developers.com/showthread.php?t=2446515
hazenberger said:
I'm pretty sure you can:
http://forum.xda-developers.com/showthread.php?t=2446515
Click to expand...
Click to collapse
Nope. When you bootloader updates as part of the camera update, it prevents firmware downgrades. That link is just for restoring to stock if you haven't updated.
mandrsn1 said:
Nope. When you bootloader updates as part of the camera update, it prevents firmware downgrades. That link is just for restoring to stock if you haven't updated.
Click to expand...
Click to collapse
Sorry. You're right.
So go ahead and screw Verizon using the air trick. Or wait until someone finds a new root exploit for this firmware.
hazenberger said:
Sorry. You're right.
So go ahead and screw Verizon using the air trick. Or wait until someone finds a new root exploit for this firmware.
Click to expand...
Click to collapse
There are other known, but unreleased, root exploits. They aren't going to be released until another major firmware upgrade (e.g., 4.4).
Thanks for the heads up guys. Not really in favor of the air method. There's nothing wrong with this phone unrooted, actually the first phone I can say that about. Just wanna tweak some things, preferably a CM MOD. Will wait for a new method.
Sent from my XT1060 using xda app-developers app
pborner said:
Thanks for the heads up guys. Not really in favor of the air method. There's nothing wrong with this phone unrooted, actually the first phone I can say that about. Just wanna tweak some things, preferably a CM MOD. Will wait for a new method.
Sent from my XT1060 using xda app-developers app
Click to expand...
Click to collapse
if you are on verizon and you go to a verizon store, they are typically pretty nice there. Basically, you could walk in say that you accidentally took the OTA and you wanted to root so can give you me a new one. They will probably say yes. Or you can just say your battery drain is really bad and you have spent hours trying to fix it but people on forums said you needed to return it. The guy at my store doesn't even ask or look at my phone anymore if i bring it in...
mandrsn1 said:
There are other known, but unreleased, root exploits. They aren't going to be released until another major firmware upgrade (e.g., 4.4).
Click to expand...
Click to collapse
This is good to hear... Do you happen to know if there's been any solid progress made on a bootloader unlock for Verizon? I wish I knew the first thing about Android programming so I could help out in this effort. I love my Moto X as is, but would love to see permanent root methods so we could have access to custom kernels (and so I can try to get rid of the damn NLP wakelocks).

Verizon Motorola X 2014 XT1096 Root?

If your one of the many that got in on the Cyber Monday deal for the Moto X 2nd Generation then you may be like me and want to root this phone. Does anyone know if this is possible yet? I can't find anything on it yet so figured I'd start a thread on it.
There are actually a few threads on this already (general & q/a). No luck on root yet...
rickyg946 said:
There are actually a few threads on this already (general & q/a). No luck on root yet...
Click to expand...
Click to collapse
Maybe after the deal a few devs got a hold of these and we'll see it soon. Fingers crossed here
Do I return this or hold off for root?
GrandMstrBud said:
Do I return this or hold off for root?
Click to expand...
Click to collapse
My $0.02... If root is really important to you, return it.
I just need the wireless tether that's the main reason and custom roms of course.
We need to start a bounty thread for rooting the VZW version.
TokedUp said:
We need to start a bounty thread for rooting the VZW version.
Click to expand...
Click to collapse
I agree, it's really the only thing stopping me from activating my brand new Moto X 2014
So we don't have any ROM for XT1096 ?
Sent from my XT1096 using XDA Free mobile app
niilartey1 said:
So we don't have any ROM for XT1096 ?
Sent from my XT1096 using XDA Free mobile app
Click to expand...
Click to collapse
Correct. I wouldn't count on ever getting root for this phone. If root is that important to you, you should probably go a different route.
ssick92 said:
Correct. I wouldn't count on ever getting root for this phone. If root is that important to you, you should probably go a different route.
Click to expand...
Click to collapse
How confident are you on this? I didn't think there were any phones that root was not possible on. I really don't want to keep the iPhone 6 but I don't have much longer before my return period is up. The only good thing is I have tethering with it
GrandMstrBud said:
How confident are you on this? I didn't think there were any phones that root was not possible on. I really don't want to keep the iPhone 6 but I don't have much longer before my return period is up. The only good thing is I have tethering with it
Click to expand...
Click to collapse
Well I mean I can't say that it will never happen, but these newer phones are a lot more secure and locked down than android phones were a couple years ago. That, and the fact that most users of this phone purchased it because of the amazing motorola features that it comes with, so many users don't have the need or want for custom ROMs.
GrandMstrBud said:
How confident are you on this? I didn't think there were any phones that root was not possible on. I really don't want to keep the iPhone 6 but I don't have much longer before my return period is up. The only good thing is I have tethering with it
Click to expand...
Click to collapse
Tons of phones. My S5 was out for a solid year until geohot came out and saved the day with towel root. This phone could easily never gain root.
Yeah. I think too many ppl are being too negative about root. It might not happen today but I think it will eventually. If Devs can root any of the Samsung Knox filled crap phones than we should have more faith.
Btw, there is a bounty thread started so donate if u can, give a dev more reason to help us.
While I'm missing having a rooted phone, the x doesn't need it IMHO. That's not saying I would root this bad boy immediately though. I'm just happy right now with 5.0. I have other devices rooted to hold me over anyways.
No no not negative. Just being frank with someone who thought every android phone automatically gets root.
I'm optimistic. I pledged money as well.
CF Autoroot Possibly?
Has anyone tried the latest CF Autoroot? It works on other Moto X 2014 editions...
Perefin said:
Has anyone tried the latest CF Autoroot? It works on other Moto X 2014 editions...
Click to expand...
Click to collapse
Your bootloader has to be unlocked to run CF-Autoroot.
Where is the link for the CF Autoroot
Sent from my XT1092 using XDA Free mobile app
Has anyone tried this ?
http://androidbiits.com/android-5-0...-rom-motorola-moto-x-2nd-gen-xt1096-tutorial/

Root on Z3v and D6616

Since zxzo0o collected the bounty for the Z3 root, us D6616 and Z3v users have been left out in the cold. I figured I would take it upon myself, with the help of anyone who is interested, to work towards root on these two models. This will be my first Android project, so the more assistance, the better.
There is a new CVE that may affect our devices, as well as most other Android devices. This is CVE-2015-1474, which is an overflow in the Graphics Buffer. This should be able to escalate privileges and allow us to run giefroot from there.
To start, I'll need this file from a Z3 (any model) that is currently rooted on the latest KK build (E or later): /system/lib/libui.so
From that file we should be able to see if Sony has patched this exploit (which I doubt). Then we need to figure out a way to exploit the buffer, gain escalated privileges, and run giefroot or our own tool to obtain root.
Here
Link does not work for me.
Sent from my D6616 using Tapatalk
Are you still working on this?
Doubtful.
+1 would really hope this is still being worked on.
It is not being worked on by me. I lack the necessary time and am most likely switching devices sometime soon. I hope someone else is looking into it
Good to know that boy, I have an Xperia Z3 T - mobile, D6616 I can help you anything you need. Just tell me what can I do to help, I will download stock ftf today to decompress it and see what files we can see. Using Fx file Explorer we can access to much information from the phone.
Sent from my D6616 using XDA Free mobile app
Don't forget we have a bounty for our Z3v in the subforum. Right now it's amounted to between $500 and $600. It'd be great to have support.
Anything happening with this?
Not for now, our hope is the new cve which developers are working to make a root tool with it, or the new software update which it's suppose to be on may 31st.
Sent from my D6616 using XDA Free mobile app
http://forum.xda-developers.com/showpost.php?p=60485574&postcount=93

Is the reason people can't find a stable root for US LG G4's cause of an unknown boot

Just browsing on signal strength app and saw that a boot loader was unknown and wondered if it was keeping blocking root stability?
Sent from my LG-H811 using Tapatalk
UktenaWarrior28 said:
Just browsing on signal strength app and saw that a boot loader was unknown and wondered if it was keeping blocking root stability?
Sent from my LG-H811 using Tapatalk
Click to expand...
Click to collapse
It probably shows that because it is a brand new phone and the app doesn't have the bootloader in it's database. just a guess
root has already been achieved in multiple ways, on all carrier devices. We are just waiting on the devs to release now.
Thank you for the reply. I was kinda curious about why mine shower no boot loader.
Sent from my LG-H811 using Tapatalk
Has anyone heard any news? I keep looking and have found nothing new.
DattKiddKFC said:
Has anyone heard any news? I keep looking and have found nothing new.
Click to expand...
Click to collapse
I don't understand why they don't release the root method with an "at your own risk" disclaimer. A good number of us root users cut our teeth on the original HTC Dream and understand the involved risks.
Sent from my toaster
blackknightavalon said:
I don't understand why they don't release the root method with an "at your own risk" disclaimer. A good number of us root users cut our teeth on the original HTC Dream and understand the involved risks.
Sent from my toaster
Click to expand...
Click to collapse
I'm pretty sure the devs want to release the dummy-friendly version, like myself, who knows nothing about root but would like to try it.
xfearlz said:
I'm pretty sure the devs want to release the dummy-friendly version, like myself, who knows nothing about root but would like to try it.
Click to expand...
Click to collapse
I'll take the step-by-step version where you have to read the instructions at least twice before going through with it. It'll remind me of the old days.
Sent from my toaster
Tomyk89 said:
It probably shows that because it is a brand new phone and the app doesn't have the bootloader in it's database. just a guess
root has already been achieved in multiple ways, on all carrier devices. We are just waiting on the devs to release now.
Click to expand...
Click to collapse
From the research I've done, I've yet to see any proof that devs have achieved root on all carriers. Where did you find this information?
I have yet to see it done on a T-Mobile, Verizon and Sprint variation. I have seen it done on a AT&T phone. I am patient enough for the root
Sent from my LG-H811 using Tapatalk
thenewbigmack said:
From the research I've done, I've yet to see any proof that devs have achieved root on all carriers. Where did you find this information?
Click to expand...
Click to collapse
I agree. I'd love to see someone that has achieved root comment.
blackknightavalon said:
I don't understand why they don't release the root method with an "at your own risk" disclaimer. A good number of us root users cut our teeth on the original HTC Dream and understand the involved risks.
Sent from my toaster
Click to expand...
Click to collapse
They do not have it.
Sent from my SM-G920T
ambervals6 said:
They do not have it.
Sent from my SM-G920T
Click to expand...
Click to collapse
Agreed. If root were available, even if the devs didn't feel it was ready for prime-time, we'd know about it. The fact that nobody has actually seen a rooted 811, pretty much proves that root has not been achieved.
There is a root method that does work. Its not prime ready. But there are articles ststimg root was achieved on an U.S. variant G4. As I stated before the dev bricked the first phone from the unstable root. After his second attempt he was sucessful. So how can justify there is no root for G4 stable or unstable?
Sent from my LG-H811 using Tapatalk
UktenaWarrior28 said:
There is a root method that does work. Its not prime ready. But there are articles ststimg root was achieved on an U.S. variant G4. As I stated before the dev bricked the first phone from the unstable root. After his second attempt he was sucessful. So how can justify there is no root for G4 stable or unstable?
Sent from my LG-H811 using Tapatalk
Click to expand...
Click to collapse
Not sure if this was directed at me or not, however.... There is clearly root for a "U.S. variant G4". There is clearly no root for the H811/T-Mobile variant. Nobody has claimed to see it either (that I am aware of).
ShermCraig said:
Not sure if this was directed at me or not, however.... There is clearly root for a "U.S. variant G4". There is clearly no root for the H811/T-Mobile variant. Nobody has claimed to see it either (that I am aware of).
Click to expand...
Click to collapse
just because you haven't experienced it, doesn't mean it doesn't exist. Look at the female orgasm for example. Just believe.
The only thing I can see why one carrier may take longer is only the fact that carrier has just added something in a file that made it harder to exploit. But it has never really been that way.
Sent from my LG-H811 using Tapatalk
UktenaWarrior28 said:
There is a root method that does work. Its not prime ready. But there are articles ststimg root was achieved on an U.S. variant G4. As I stated before the dev bricked the first phone from the unstable root. After his second attempt he was sucessful. So how can justify there is no root for G4 stable or unstable?
Sent from my LG-H811 using Tapatalk
Click to expand...
Click to collapse
As I've said, devs should release it with an "at your own risk" disclaimer.
Sent from my toaster
blackknightavalon said:
As I've said, devs should release it with an "at your own risk" disclaimer.
Sent from my toaster
Click to expand...
Click to collapse
I was agreeing with you and telling the others that there is one
Sent from my LG-H811 using Tapatalk
Root achieved. Go get it. Already rooted and install TWRP on mines. http://forum.xda-developers.com/g4/...-tmo-vzw-intl-variants-soon-root-lg-t3164765/

Categories

Resources