Join the Talk | 70,040 members - 273,184 posts Advertise | Have a scoop? Tip us!

Very odd bug found in jailbreaking process

09 November 2008 by Staff Editor


Worth Reading?

NoYes

+18 [28 votes]


In the most recent T-Mobile G1 update that has been pushed out, we know that Google is sending out a patch that will prevent us from gaining root access. Another bug that Google has fixed in the RC30 update has been discovered. Many G1 owners have yet to run into this bug because it is a bit of a rarity.

After setting up a telnet server on the G1 to allow root access, anyone who knows your IP address can log into your phone without a password.  This hole in the security of the phone also has a very odd bug, after your phone starts up a command shell as root, every keystroke you type is then sent to that shell.  Now every keystroke that is typed in any application is secretly sent to the shell with Admin user privileges.

In the bug report (issue 1207) jdhorvat writes:

Funny story behind finding this:

I was in the middle of a text conversation with my girl when she asked why I hadn’t responded. I had just rebooted my phone and the first thing I typed was a response to her text, which simply stated “Reboot” – which, to my surprise, rebooted my phone.

Without the bug users can still see what was happening by typing <return>-r-e-b-o-o-t-<return>. The return parts send it to the shell as a command, the bug on the other hand already did this with all the keystrokes you make, making it impossible to type some words. For those of you experiencing this problem who do not wish to upgrade to RC30, just type <return>-c-a-t-<return> to disable it. This should work for everyone, at least till the phone is rebooted.

[Via ZDNet]

  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • Slashdot
  • SphereIt
  • Technorati
  • blogmarks
  • Blogosphere News
  • email
  • NewsVine
  • StumbleUpon
  • FriendFeed
  • Live
  • Reddit
  • Twitter
  • Wikio
  1. I tried it out when I had the RC29 and it was kind of weird and somewhat convenient to do it. But I realized to restart my phone I just had to hold the end key and turn on and off anyway. I decided to look into it more to see what other commands would effect the phone.
    I found out if you press
    Return-s-t-o-p-Return you will freeze your phone. Only way to fix is to open up your phone and remove battery then restart.
    So I'm glad after getting the RC30 update this has been removed.
    I didn't feel like removing my battery if I accidentally type in another command. Thanks Google.
  2. very funny bug!
  3. You really need to post a warning about that picture for those of us that are squeamish about bugs. LOL.
  4. So the Android process is running around as root on the underlying Linux installation? Holy****, that's a rather large oversight on Google's part.

    Can someone with a "jailbroken" phone PLEASE do a "ps auxwww" or "ps auxwwwf" and paste the results here?
Join AndroidCommunity Forums

Android Phone Accessories


T-Mobile G1 Accessories
Palm Pre Accessories
iPod Touch Accessories
Advertise with SlashGear
Free Tech Support at SlashGear Forums

© 2008 Android Community. Part of R3 Media Network

Contact | Advertising | About Us