[XZ3] temp root exploit via CVE-2020-0041 including magisk setup - Sony Xperia XZ3 ROMs, Kernels, Recoveries, & Other

temp root exploit for sony xperia XZ2/XZ2c/XZ2p/XZ3 with android 10 firmware​Get a root shell with still locked bootloader.
The main thread is located in xz2 forum section here.

implemented magisk setup from temproot
finally got magisk from temp root working including permission asking feature - released as tama-mroot.zip - get it here

j4nn said:
finally got magisk from temp root working including permission asking feature - released as tama-mroot.zip - get it here
Click to expand...
Click to collapse
Hello guys. I need your help finding 52.1.A.0.618 for H9436

@Redlun3, do you still need it?
I could eventually upload the H9436_Customized FR_1316-3076_52.1.A.0.618_R6C in the main thread.

j4nn said:
@Redlun3, do you still need it?
I could eventually upload the H9436_Customized FR_1316-3076_52.1.A.0.618_R6C in the main thread.
Click to expand...
Click to collapse
Yes, please. I want to save keys.

@Redlun3, it's uploaded, see the main thread please.

exploit sources released
Exploit sources for all temp root releases are available at my github here.

has anyone checked it at all?

Hi, i need H8416-52.1.A.0.618, where i could find it, please?

@pipitkusumanjaya, uploaded the H8416_Customized IBE_1316-6423_52.1.A.0.618_R5C.zip - check the main thread for the link.

update magisk24.1 bro for temproot

Related

If anyone still has 5.0.2, I need you to check something for me...

Hello XDA,
I have a G890A on 5.1.1, and was wondering if anyone on 5.0.2 could tell me if their '/data/' folder is or is not read-protected. I've been looking at a possible root opportunity but it requires that folder to be readable.
Thanks!
-PeregrineX
I have a G890A running 5.0.2 with build lrx22g.g890aucu2aof4
Using explorer (root explorer without the root), the /data/ folder has the permissions of rwxrwx--x
UPDATE: The exploit I'm using requires the file '/data/local/tmp/fifo_dat' to be writable by a non-root user, which it is (somehow).
We might just be able to get this exploit working on the G890A!
BTW, if you want to help, search up the sensord exploit, and msg me!
the exploit doesnt work for me (i have 5.0.2), at first step it says "it looks likey is not vurneable". i dont think that fifo_dat or fifo_cmd is r or w without root. (it can not be when the whole /data folder is --x no?)
i have the same device with 5.0.2, what i have to do sir?
What's next? There must be a way!
Any news about this??
EDIT: delete post, wrong thread
eurosport360 said:
I have a G890A running 5.0.2 with build lrx22g.g890aucu2aof4
Using explorer (root explorer without the root), the /data/ folder has the permissions of rwxrwx--x
Click to expand...
Click to collapse
Hey, any progress?
My S6 Active is on Android 5.0.2 Build LRX22G.G890AUCU1AOE9 and see same permissions as eurosport360 : rwxrwx--x for /data/ using same Root Explorer app with no root (obviously).
I am also about to follow this post by lirex to manually update, so please let me know if you need my help on 5.0.2 ASAP or I will be upgrading.
http://forum.xda-developers.com/gal...e/downloading-flashing-att-galaxy-s6-t3260744
Cheers,
Kase
---------- Post added at 05:48 AM ---------- Previous post was at 05:29 AM ----------
Just found this:
diablo666estrada said:
SM-G890A ROOT 5.1.1 & 5.0.2
*link removed because i'm a noob and can't post links apparently until after 10 posts*
Click to expand...
Click to collapse
So might follow that unless you need my vanilla S6A for testing? Please let me know ASAP
Cheers,
Kase
Hel??
A few days ago I was able to use the terminal or and my pc to be able to read/write sys files if I could be of any assistance
Testing the expliot using third party pc to inject one successful root then shut down
One success then shut down my phone and lost it grr
legoman9753 said:
One success then shut down my phone and lost it grr
Click to expand...
Click to collapse
:/ so close
Accomplished this morning. As well as bootloader work around. On 5.0.2 But won't release until bounty and community confirmed. OP please feel free to message me. I'll work on setting up EX KERNEL while awaiting Chainfire and twrp team response.
kobos311 said:
Accomplished this morning. As well as bootloader work around. On 5.0.2 But won't release until bounty and community confirmed. OP please feel free to message me. I'll work on setting up EX KERNEL while awaiting Chainfire and twrp team response.
Click to expand...
Click to collapse
Hey hows this coming? I have an active and I've been poking around with it while building Lineage for some older devices and trying to find bootloader exploits.... But now I'm really focused on the Active.
Well if the permissions are RWXRWX--X, what is the owner and group? Isn't the shell user part of the system group to a degree?

[DEVS NEEDED] Possible Root Exploit

I was looking at Android exploits and found this: https://bugs.chromium.org/p/project-zero/issues/detail?id=734&redir=1. It says it is a DOS which I have tested on OI5 (crashes the system). But at the bottom it says it can be used for local privilege escalation. I have very limited knowledge of C and C++ so I am asking you guys if it is possible to write some code into the file that will escalate our privelleges to root. File is at the bottom of the site on the link. This would be great for the entire community. Thanks!
CVE Page:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2062
CVE ID: CVE-2016-2062
This looks promising. I was looking into the Android version update history on AT&T's website for the S5, and found out that, up until now, the patch for this bug hasn't been applied (as all firmware updates are using Kernel version 3.4).
According to one of the comments from the link NavSad posted, "[T]his patch was not applied to all msm branches at the time of the patch release (July 2015) and no security bulletin was issued, so the majority of Android kernels based on 3.4 or 3.10 are still affected despite the patch being available for 6 months."
High hopes and praises to whoever can figure out how to use this exploit to finally root this phone.
I wish I knew how to code in C... :crying:
Interesting, but with a locked bootloader, what good is it?
Sent from my SAMSUNG-SM-G900A using XDA-Developers mobile app
johnnynmonic said:
Interesting, but with a locked bootloader, what good is it?
Sent from my SAMSUNG-SM-G900A using XDA-Developers mobile app
Click to expand...
Click to collapse
I turns out somebody obtained root on the Samsung Galaxy S5 ATT 5.1.1. I checked on the global statistics for root with Root Checker Basic. It used to be no root available but now it says root available, method hard.
Is there a tutorial for this "method" for root on 5.1.1?
macasus76 said:
Is there a tutorial for this "method" for root on 5.1.1?
Click to expand...
Click to collapse
Not yet
With root you can get rid of the bloatware and are able to backup apps etc..... I could care less about the boot loader.
NavSad said:
Not yet
Click to expand...
Click to collapse
So any update on the progress of this?
The phone is vulnerable to Quadrooter. Now we just need a developer to use it to develop a root tool
AptLogic said:
So any update on the progress of this?
Click to expand...
Click to collapse
No not yet, we need a dev.

Looking for method to root from Marshmallow 6.0.1 (build 23.5.A.0.575) ?

Hello xda !
I am a proud owner of a z3 compact, D5803, and was looking to unlock the endless possibilities of rooting my device.
I've stumbled on a few "how to", but they seem to only refer to android 4 or 5
example : ( http://forum.xda-developers.com/z3-c...-keys-t3013343 )
Or some quotes here and there, but as I am greatly inexperienced, I did not understand much
here : http://forum.xda-developers.com/z3-c...2#post66862792
and there : http://forum.xda-developers.com/z3-c...75-lb-t3418714
or there : http://forum.xda-developers.com/z3-compact/development/guide-twrp-to-root-access-t3355096
and something here : http://forum.xda-developers.com/z3-c...75-lb-t3418714
I'm getting lost !
Hence, I was wondering if by any chance there was a more simple/straightforward "how to" for my Marshmallow...
Any help/advice/clue would be so appreciated !
I wish you an awesome day !
See you and thanks in advance
Why start two threads with the same question?
Didgesteve said:
Why start two threads with the same question?
Click to expand...
Click to collapse
Somebody told me on my other thread that it should be in Q&A... I didn't know if I could move, or if I should delete the other one :/
Sorry :!
Nazha_Ember said:
Somebody told me on my other thread that it should be in Q&A... I didn't know if I could move, or if I should delete the other one :/
Sorry :!
Click to expand...
Click to collapse
Back-up your DRM Keys, and proceed to Unlock your Bootloader. After which just flash a Kernel for MM, ( just check the Android Dev section ) via fastboot in Flashtool. You would have TWRP in which you could flash SuperSU and get Root and Busybox installed
Revontheus said:
Back-up your DRM Keys, and proceed to Unlock your Bootloader. After which just flash a Kernel for MM, ( just check the Android Dev section ) via fastboot in Flashtool. You would have TWRP in which you could flash SuperSU and get Root and Busybox installed
Click to expand...
Click to collapse
Thanks !
Actually I've found on my other topic this link : http://forum.xda-developers.com/z3-compact/general/recovery-root-mm-575-lb-t3418714
that doesn't require to unlock the bootloader and hence no problem with DRM. No nned for backup too !
perfect, it worked flawlessly !
Thanks !

Root Mate 10 with/without PC

Since no video yet on how to root mate 10 found a way to root without pc.
Here is the link I followed
https://www.google.com/amp/featuresunlocker.com/root-huawei-mate-10-without-pc/amp/
http://featuresunlocker.com/root-huawei-mate-10-without-pc/
is this legit and working?
rjan22 said:
Since no video yet on how to root mate 10 found a way to root without pc.
Here is the link I followed
https://www.google.com/amp/featuresunlocker.com/root-huawei-mate-10-without-pc/amp/
http://featuresunlocker.com/root-huawei-mate-10-without-pc/
Click to expand...
Click to collapse
Installing Kingroot? no, thanks! I don´t want my phone full of undesirable apps which will be very hard to uninstal
rjan22 said:
Since no video yet on how to root mate 10 found a way to root without pc.
Here is the link I followed
https://www.google.com/amp/featuresunlocker.com/root-huawei-mate-10-without-pc/amp/
http://featuresunlocker.com/root-huawei-mate-10-without-pc/
Click to expand...
Click to collapse
These methods do not work. I do not think the writer has tested it on the mate 10.
First, this thread i not in the right section.
So moved to Guides, News & Discussion
Second, OP @rjan22 could you please clarify if you have successfully rooted your device by this method?
for the legit part, I will come back to give you the ANSWER.
Thanks
This didn't work for huawei mate 10 pro.
SREEPRAJAY said:
First, this thread i not in the right section.
So moved to Guides, News & Discussion
Second, OP @rjan22 could you please clarify if you have successfully rooted your device by this method?
for the legit part, I will come back to give you the ANSWER.
Thanks
Click to expand...
Click to collapse
None of them work. You have to flash a pre-rooted ramdisk image. I'm not sure if flashfire can do this, but none of the methods in OPs link can.

HELP!!! Root my SM-G920A, ATT SAMSUNG S6, BUILD UCS4XXX

I ve been searching through out all forums of XDA but i cant find the same build that anyone rooted. It was a security patch update but my Build is G920AUCS4CPG1.
Everyone seems to have a root for UCS5xxx.
Can anyone please help. I badly need to root this one.
iRyanBrooks said:
I ve been searching through out all forums of XDA but i cant find the same build that anyone rooted. It was a security patch update but my Build is G920AUCS4CPG1.
Everyone seems to have a root for UCS5xxx.
Can anyone please help. I badly need to root this one.
Click to expand...
Click to collapse
Can't keep track of all the build numbers anymore, but I'm assuming this is a Nougat (7.x.x) build? If so, no root at this time, and I'm not aware of anyone working on it. If you NEED root, buy a different phone.
Look @ this
trulane said:
Look @ this
Click to expand...
Click to collapse
Could you explain or link to how you accomplished this?
There is no link, I can't explain it, I downloaded an app called phone info. It shows root. I've tried all the root without PC apps. I didn't get any success. And I can't use headphones with this phone, it doesn't recognize any type. I have 2 use an app audio router. But the headphones mic will never be recognized. I'm gonna post my build number too. NRD90.G925AUCS6EQH1
Android 7 requires systemless root and you would need to install SuperUser or SuperSU .zip via twrp
dandrumheller said:
Could you explain or link to how you accomplished this?
Click to expand...
Click to collapse
No I can't, as a matter of fact it has since changed

Categories

Resources