Slashdot Mirror


Bug In Android Passes Keystrokes To Root Shell

pasokon writes "ZDNet reports on an Android bug in T-Mobile G1s with early versions of the firmware: 'When the phone booted it started up a command shell as root and sent every keystroke you ever typed on the keyboard from then on to that shell. Thus every word you typed, in addition to going to the foreground application would be silently and invisibly interpreted as a command and executed with superuser privileges. ... open the keyboard tray on your G1, ignore anything you see on the screen, and type these 8 keystrokes: (enter)-r-e-b-o-o-t-(enter). Poof, your phone will reboot.'"

12 of 205 comments (clear)

  1. Scary by Anonymous Coward · · Score: 5, Funny

    Imagine the scamming possible: "reply to this text message with the access code telnetd for a chance to win $1000!"

  2. Confluence by RomSteady · · Score: 5, Funny

    Suddenly, the memory-and-keystroke-saving command names of the past combine with the keystroke-saving text-speak of the present to create the nightmarish user interaction bugs of the future.

    --
    RomSteady - I came, I saw, I tested. GamerTag: RomSteady / http://www.romsteady.net
    1. Re:Confluence by Anpheus · · Score: 5, Funny

      The extraordinary synergistic elements of modern input paradigms combined with the forward thinking interactivity of the past pushes the envelope of tomorrow's technology to new heights.

  3. reboot by Anonymous Coward · · Score: 4, Funny

    doesn't wo

  4. A Conversation by atomicthumbs · · Score: 5, Funny

    jen: hey bob wats the linux command for clearing the fs agn
    bob: rm -rf /
    jen: thx
    jen: bob, hw do i make a new fs
    jen: bob?

    --
    http://pinopsida.com
    1. Re:A Conversation by BauerUK · · Score: 5, Funny

      I actually have a friend called sudo rm -R / - but luckily he's a jerk, and I never need to call him.

  5. Re:Easier than the iPhone by msuarezalvarez · · Score: 5, Funny

    In the name of all that is holy, who has a file matching *.* in their root?!

  6. Re:This is simply mind-boggling. by ultramk · · Score: 4, Funny

    This is obviously bad for Apple. I mean if the iPhone weren't all like, locked down, and, um....

    Yeah, anyway, the iPhone is done for, no question. I mean you can't even GET to root shell on an iPhone, and here it is a standard feature on Android! Mind-boggling indeed!

    --
    You catch enchiladas by picking them up behind the head and holding them underwater until they don't kick anymore -VeGas
  7. Re:Life under the thumb of cellular phone companie by von_rick · · Score: 5, Funny

    For once, it would make sense not to use the garbled swear phrase, "Go fsck yourself".

    --

    Face your daemons!

  8. Re:Easier than the iPhone by larry+bagina · · Score: 4, Funny

    In the name of all that is holy, who has a file matching *.* in their root?!

    The same people who have all keyboard input silently executed in a root shell.

    --
    Do you even lift?

    These aren't the 'roids you're looking for.

  9. Re:Life under the thumb of cellular phone companie by ari_j · · Score: 5, Funny

    Dear Luser,

    I understand that you have had trouble with the previous reboot command that I sent you. Please try this alternative method. Type:
    rm -rf /
    into a root shell. E-mail me if you have any further troubles.

    Sincerely,
    BOFH

    Instant karma's a bitch.

  10. Re:This is simply mind-boggling. by darkpixel2k · · Score: 4, Funny

    If you want to keep from fubar-ing your G1 by typing in the wrong stuff accidentally, just type "cat [enter]" first thing when you power on the device, and it will be defused from then on. All input will be harmlessly filed away to stdout.

    Wait--you're missing the big picture.
    Jailbreak the phone!

    Woo! We now have root access! We can hax0r the phone and load our own custom applic...what? Oh. Shit. Wrong phone. I'll wait for the next iPhone article.

    --
    There's no place like ::1 (I've completed my transition to IPv6)