Unpatched Oreo: DnsMasq - Heap buffer overflow vulnerability (P10 VTR-L29) - Huawei P10 Questions & Answers

Avast Premier detects DnsMasq vulnerability, Huawei support was supposed to get back to me concerning the questions:
1. What patch am I running?
2. How can I check which patch I am running?
3. If the patch reported (System info: "1 February 2018" ) is false or defective, how is this solved?
This was more than two weeks ago now, and tbh I'm considering filing a complaint under EU law to have them buy back the phone
Any ideas on how to solve this issue? General tips on how to face Huawei support?
P10 VTR-L29 8.0.0.360 (C432)
Sweden
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}

ROFL made my day.. law suit. ?

DallasCZ said:
ROFL made my day.. law suit. ?
Click to expand...
Click to collapse
What law suit?
Perhaps I should clarify:
What I am considering is to file a complaint (Consumer complaint to Huawei). Under certain circumstances, to which this case very much qualifies: Huawei would have to buy back the phone.
'EU law' was to shorten my post, referring to the consumer protection laws set by the European regulatory agencies.

...Anybody?

nobody cares... ??
I think you cannot complain and want money back because of software security updates. Just buy every year Google pixel phone and you will get all security patches every month. ?
Or don't use wifi tethering.
Or don't be so paranoid. ?

DallasCZ said:
nobody cares... ??
I think you cannot complain and want money back because of software security updates. Just buy every year Google pixel phone and you will get all security patches every month. ?
Or don't use wifi tethering.
Or don't be so paranoid. ?
Click to expand...
Click to collapse
Fair point.
Also: I guess I should have known better than having expected some kind of reaction, I mean F*©# me right!?
Well, I'll cut the crap and end with my core concern:
If we have accepted and become so used to being lied to, if we are so pessimistic that deception has become the norm and the call for basic decency is met with pitty and ridicule, what are we living in if not a dystopia?

Come on, It's only a mobile phone... nobody is lying to you and you should focus on more important things in life than some DnsMasq patch.

DallasCZ said:
Come on, It's only a mobile phone... nobody is lying to you and you should focus on more important things in life than some DnsMasq patch.
Click to expand...
Click to collapse
Actually yes:
"Android Security patch 1 February 2018" = Not true

so you was connected to your PC and internet connection was established from your mobile phone.

Related

How about getting this video driver issue on TV?

I was wondering if anyone has tried to get this issue on TV? Something like CNN TECH, X-Play, or Attack of the Show. Maybe something a bit more national and mainstream would spark a bigger fire. I think all of the technology websites linking the story are a HUGE help, maybe its time to call in the larger media cannons.
Can we get more threads about this today?
I have five Browser Tabs open on this subject just so I can keep up....
http://forum.xda-developers.com/showthread.php?t=314615
didn't HTC say they are fixing the drivers in the next update?
jallenclark said:
didn't HTC say they are fixing the drivers in the next update?
Click to expand...
Click to collapse
Congrats Senior Member..... the big 100 and isn't status what it's all about?
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
This just in, HTC an electronic gadget creater has pissed off some 13000 nerds with overpriced phones. From our understanding the gadgeteers decided to neglect its customer base by omitting a video driver in it's software package. This missing video driver is responsible for poor renduring of the display and the nerds also accuse it of slowing down the phone and causing crappy camera quality.
Now back to your regurly scheduled program.
ChumleyEX said:
This just in, HTC an electronic gadget creater has pissed off some 13000 nerds with overpriced phones. From our understanding the gadgeteers decided to neglect its customer base by omitting a video driver in it's software package. This missing video driver is responsible for poor renduring of the display and the nerds also accuse it of slowing down the phone and causing crappy camera quality.
Now back to your regurly scheduled program.
Click to expand...
Click to collapse
hahah, good stuff
btw, you realize by being here you are one of those 13000
Sure, I'm one of the ones that signed the thing. I dont' mind being called a nerd.
It's amazing how all these newcomers with only 1 post ask about the video issue. Makes me wonder if existing members register with a new username and post either to piss others off or ask questions without harming their reputation.
Things that make you go, Hmmmm?
sherpa said:
It's amazing how all these newcomers with only 1 post ask about the video issue. Makes me wonder if existing members register with a new username and post either to piss others off or ask questions without harming their reputation.
Click to expand...
Click to collapse
Lol paranoid much?
What would make you think that?
Please use the existing threads on this issue.
Mike

iphone call record

does anyone know of any software to record a telephone conversation on the iphone?
I think it is illegal to record a conversation without notifying the other person that you are doing so, I was looking for some similiar software last year but couldnt find any, maybe for that reason!!
it is only illigal if you don't notify the person. I wouldn't be using for illegal activities. the person will be notified.
vik_x said:
it is only illigal if you don't notify the person. I wouldn't be using for illegal activities. the person will be notified.
Click to expand...
Click to collapse
its not illegal everywhere..... it all depends on local laws
It's not illegal, you just can't use it in a court of law if the other person is not notified in some states.
burgertime said:
It's not illegal, you just can't use it in a court of law if the other person is not notified in some states.
Click to expand...
Click to collapse
in some countries it is illegal, you are refering to US law, this is an international website though
Sorry, I see the world as Stephen Colbert does..through America glasses buddy! Note that these glasses aren't for the color blind as you need to see in red white and blue.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
thats rediculous hahaha...........
Its not a matter of be legal or not.
ITs a matter of need be specific wm device implementation, because this its hard release.
All phone today do it, by native in any country. the ones don't do? THE GREAT SMARTPHONES FROM MICROSOFT.
But its possible, just hard ( until now, because some new models have registry entries that let us imaginate will be possible later).
F_R_I_T_Z said:
Its not a matter of be legal or not.
ITs a matter of need be specific wm device implementation, because this its hard release.
All phone today do it, by native in any country. the ones don't do? THE GREAT SMARTPHONES FROM MICROSOFT.
But its possible, just hard ( until now, because some new models have registry entries that let us imaginate will be possible later).
Click to expand...
Click to collapse
what a random post
abyway, back on topic:
i think when i has my jailbroken iphone, there was some software to do it, ut it might have just been for voice recording normally.
i doubt anything on the app store will do it though, only cydia (jailbroken iphone appstore)
well you aren't gonna find much support here
windows fans = make pie out of apple
apple fans = very confused people
thanks for the feedback, I'll check out cydia.

Apk Update Date? (Says Feb 1st 2016 on the Google Market)

The past year I have been putting together proof the Google Play store has been cloned by the government and is being used for remote surveillance, updating key apps with hacked versions. I am a former security clearance holding federal employee; know (ie it said they could years after leaving in my original paperwork) I have been watched for my standpoint on the crap the US government has pulled over the past 15 years. After Snowden things got worse for everyone who works (or in my case used to work) for the DoD.
I already have enough to think at least Google 2 Step Authentication (idiots used a Langley # on 2 Step phone Auth callback until I tried to blog about it over two years ago) has been thwarted, and now am going further down the rabbit hole. Once I decide how I am going to proceed (after talking to a lawyer) I will probably dump everything I have (as well as some other fun treats) on the surveillance here on XDA.
When did you update SuperSU? I am a paid user that keeps all my apps up to date DAILY and rarely miss a day hitting the play store to check.
Today I got an update alert for SuperSU. The update date says February 1st (Screen Shot Below) and yet it's February 21st. I did not miss 21 days of checking for updates; it was yesterday I last checked. I have not gotten an update for SuperSu since 2.52 and the latest says 2.65, so this update that just popped took at least 21 days to show up on my play store app.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Trying to figure out if this is a joke or not.
Is this true??
Sent from my GT-I9500 using Tapatalk
Wow... You typed out a back story and conspiracy theories just to ask about an update? Ever hear of this thing called a rollout? Google does the exact same thing with their updates, old date and all. Loosen the tinfoil please.
Sent from my Moto X Pure Edition using Tapatalk
Hello,
First of all this not the place for conspiracy theories. What you're describing seems like a simple issue with the Play Store. Nothing more and nothing less.
This thread will be closed so that you can sort this out. Try cleaning your cache, restarting your phone, etc.

BlueBorn is still rampant and enough is enough: g'bye M3 and thanks for all the fish

In short:
- I bought my M3 in March 2017, EU version w/ Wi-Fi and 4G; I use it out of home.
- BlueBorn is a very bad vulnerability that affects Bluetooth protocol, and VERY NASTY exploits exist; only workaround available for M3: bluetooth off. Other firms have patched their products long time ago.
- I have the latest firmware available -B303 which is still vulnerable (https://play.google.com/store/apps/details?id=com.armis.blueborne_detector).
In conclusion: hardware is perfect but software prevents me to use the bluetooth functionality, so this item is to be considered broken (or better defective by design) withouth chance of repair. Flash a custom rom? No way, since unlocking the bootloader by software would affect the warranty on hardware (it was your choice, Huawei).
I called the reseller (not Huawei) to complain for this: I will send the item back soon and get a full refund.
BTW: European Union customer protection laws apply. YMMV. Reseller is responsible. Reseller may complain with Huawei (and I think it will, in my case). Sorry Brexiters.
End of story.
Goodbye Huawei and thanks for all the fish, but after four month, it stinks a lot.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
jcyb9 said:
- I have the latest firmware available -B303 which is still vulnerable (https://play.google.com/store/apps/details?id=com.armis.blueborne_detector).
Click to expand...
Click to collapse
I don't know if there are any hardware or firmware differences between models sold in the UK and EU, but just for anyone else's info, I just ran the same app on B303 on my UK, wifi-only version and got a clean bill of health. I'm relieved, but it's slightly surprising (to me at least) that the 4G version fails with what I assume is otherwise the same firmware release.
(Disclaimer: I'm new to Huawei devices so apologies if I'm missing something about hardware/ROM versions. I have BTV-W09C100B303 with 6th Nov Android patch level.)
Unfortunately BTV-DL09C100B303 is still vulnerable.
Just to be shure before packaging: I just started a check for new updates. Nothing found.
B352 came down on to my tablet just now! Includes the November 2017 patch level and is clear of BlueBorn.
CL0SeY said:
B352 came down on to my tablet just now! Includes the November 2017 patch level and is clear of BlueBorn.
Click to expand...
Click to collapse
Very good thing!
btv-w09c128b352 is the full build number.
CL0SeY said:
B352 came down on to my tablet just now! Includes the November 2017 patch level and is clear of BlueBorn.
Click to expand...
Click to collapse
check on another device (smartphone?) your bt-area with the app and "BTV-..." will be shown as vulnerable. so looks like not fixed.
Interesting - the scanner shows my Xiaomi mi5s as being potentially vulnerable remotely as well. It has December 2017 patch level. Running it from either device shows the local device as being OK though. Strange

Advertizing and Revenue

I got a Tecno advertorial page pushed to me, regarding Phantom and did some research. I would have asked them directly, but no contact information I could find, #1 issue.
In spite of making a "presence" claim of dozens of countries, No US, Canada, or EU. Europe included Russia and Turkey on one product but not the other. The world is much larger that just those places, full of competition, safety and other enforced standards. #2
A claim of high-end or exclusivity which translates to me high prices and false claims of better. There is s history with mobile phones, but elsewhere as well. Exclusive, premium, luxury are never claimed, especially on web sites, if other than high prices. #3
Web content or printed material has no errors in spelling or syntax. I only am barely fluent in English. Their website is not. #4
Models are released over time. A single model indicates a lot of new or unique ideas, limited experience with product. A lot of models with very similar features released about the same time indicates lack of experience as does non-unique parts like shared screen sizes or lack of features or functions not available elsewhere. #5 and #6
Claims made that are not compared to avoid exposure as invalid. See post consumer recycle claim, foldable premium claim for obvious doubt generators. #7
There is a lot more to be skeptical of. I also wonder what seasoned Android developer would pay full retail for one to use dail While non-devopers aren't excluded, are there no standards for what is advocated with a kick-back revenue component?
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
jwoegerbauer said:
Click to expand...
Click to collapse
I definitely had the same reaction...and I was sure most of it was lost in translation -- but looking at OP's posting history, all other posts are well spoken not broken English well enough, so.....
I barely get the gist of what OP's saying; there's an ad that may or may not be legit...? Even the numbers counting the listed reasons are at the end of the sentence? Maybe the original language is like Hebrew or Middle Eastern and writes from right to left?

Categories

Resources