Bug In Android Passes Keystrokes To Root Shell
pasokon writes "ZDNet reports on an Android bug in T-Mobile G1s with early versions of the firmware: 'When the phone booted it started up a command shell as root and sent every keystroke you ever typed on the keyboard from then on to that shell. Thus every word you typed, in addition to going to the foreground application would be silently and invisibly interpreted as a command and executed with superuser privileges. ... open the keyboard tray on your G1, ignore anything you see on the screen, and type these 8 keystrokes: (enter)-r-e-b-o-o-t-(enter). Poof, your phone will reboot.'"
Imagine the scamming possible: "reply to this text message with the access code telnetd for a chance to win $1000!"
Suddenly, the memory-and-keystroke-saving command names of the past combine with the keystroke-saving text-speak of the present to create the nightmarish user interaction bugs of the future.
RomSteady - I came, I saw, I tested. GamerTag: RomSteady / http://www.romsteady.net
doesn't wo
I am typing this from my Android. I have tried this and I don't have any pr
NO CARRIER
Knowledge is power. Knowledge shared is power lost.
http://pinopsida.com
In the name of all that is holy, who has a file matching *.* in their root?!
This is obviously bad for Apple. I mean if the iPhone weren't all like, locked down, and, um....
Yeah, anyway, the iPhone is done for, no question. I mean you can't even GET to root shell on an iPhone, and here it is a standard feature on Android! Mind-boggling indeed!
You catch enchiladas by picking them up behind the head and holding them underwater until they don't kick anymore -VeGas
For once, it would make sense not to use the garbled swear phrase, "Go fsck yourself".
Face your daemons!
In the name of all that is holy, who has a file matching *.* in their root?!
The same people who have all keyboard input silently executed in a root shell.
Do you even lift?
These aren't the 'roids you're looking for.
Instant karma's a bitch.
Good. You should never enter a command you don't understand. I'm all for raising the bar above water level.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
Yeah the iPhone is really dead now. Apple totally blew it, I agree. It's totally done for. This is a total misfeature: a hidden root shell!
BTW what's this 'Android' you're talking about?
Power corrupts the few, while weakness corrupts the many.
If you want to keep from fubar-ing your G1 by typing in the wrong stuff accidentally, just type "cat [enter]" first thing when you power on the device, and it will be defused from then on. All input will be harmlessly filed away to stdout.
Wait--you're missing the big picture.
Jailbreak the phone!
Woo! We now have root access! We can hax0r the phone and load our own custom applic...what? Oh. Shit. Wrong phone. I'll wait for the next iPhone article.
There's no place like