Bug In Android Passes Keystrokes To Root Shell
pasokon writes "ZDNet reports on an Android bug in T-Mobile G1s with early versions of the firmware: 'When the phone booted it started up a command shell as root and sent every keystroke you ever typed on the keyboard from then on to that shell. Thus every word you typed, in addition to going to the foreground application would be silently and invisibly interpreted as a command and executed with superuser privileges. ... open the keyboard tray on your G1, ignore anything you see on the screen, and type these 8 keystrokes: (enter)-r-e-b-o-o-t-(enter). Poof, your phone will reboot.'"
I can't imagine how or why anyone could accidentally pipe all user input through a root shell. This is one for the WTF of the decade.
-jcr
The only title of honor that a tyrant can grant is "Enemy of the State."
Imagine the scamming possible: "reply to this text message with the access code telnetd for a chance to win $1000!"
Suddenly, the memory-and-keystroke-saving command names of the past combine with the keystroke-saving text-speak of the present to create the nightmarish user interaction bugs of the future.
RomSteady - I came, I saw, I tested. GamerTag: RomSteady / http://www.romsteady.net
doesn't wo
I am typing this from my Android. I have tried this and I don't have any pr
NO CARRIER
Knowledge is power. Knowledge shared is power lost.
Are we really that messed up as a society?
If I type "Reboot" and the device actually reboots, doesn't that mean it's working?
http://pinopsida.com
Not when it reboots as a result of you including the reboot command into, to pick a ramdom example, the text of a comment that you are posting to Slashdot.
Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
That's some amateur shit to have made it beyond beta 1. What the hell are your programmers doing all day?
I'm starting to get a little suspicious, to be frank. You've existed for many, many moons, Google...you have over 20,000 employees. You have computing capacity that's normally limited to that of small countries. Shouldn't you be a little further along by now?
This coming from Google? That surprises (and scares) me. I don't know how something like that would get through a QA process unless the QA process was rushed ... oh no, please don't become like almost every other software company out there Google! :-/
shred won't be installed.
cat /dev/urandom > /dev/hda is far more likely to work.
HTH
Deleted
I still haven't received the first OTA update for my Android yet (meaning I'm running RC19), and "the test" fails. My phone does not reboot.
I know more than you drink.
In the name of all that is holy, who has a file matching *.* in their root?!
I'm on firmware 1.0 and TC4-RC29 and it works. That's kind of scary... Especially because I SSH'd into a friend's server and wrote out rm -rf / ... just to be funny ... I didn't hit enter of course but if I did...
I wondered why I couldn't use my phone anymore. I thought Slashdot got pwned by some worm that infected my Android browser after the last time I logged in...
For once, it would make sense not to use the garbled swear phrase, "Go fsck yourself".
Face your daemons!
Nah, this was definitely a bug. A root terminal always capturing input? Definitely debugging code left behind. That would be so easy to exploit it's ridiculous.
All your base are belong to Wii.
Frankly, I wanted to make sure it would NOT work, but convey the idea. Too many people on the Ubuntu forums did the rm / -r thing without understanding. It is even sticky now...
In the name of all that is holy, who has a file matching *.* in their root?!
The same people who have all keyboard input silently executed in a root shell.
Do you even lift?
These aren't the 'roids you're looking for.
I'm beginning to suspect it could be intentional for free advertising at this point.
Only if they're advertising iPhones or BlackBerrys.
This comment is for entertainment purposes only. Any similarity to real insight or information is purely coincidental.
Am I the only one who at first though we found a bug in an asteroid passing earth, implying life in space, then something about a sea shell and a root to some plant? And all of this being some key to something, not sure what... Hmmm... I think I need more sleep.
A unique way to learn a language: http://languageloom.com
Comment removed based on user account deletion
Instant karma's a bitch.
After hearing about the backdoor kill switch, the platform became irrelevant to me in the first place. :/
Sad because I was looking forward to it. I guess there must be a way to block that though, right? Unless software updates remove the remover remover?
*looks at last sentence*
Wow... it's just not worth the effort to even begin that fight...
If that was the iPhone slashdot users would be going ballistic right now - and rightly so.
Good. You should never enter a command you don't understand. I'm all for raising the bar above water level.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
NEWS AT 11: Slashdot poster confirms this is a bug!
Just imagine an Android user texting a message to a friend with that very same joke, or posting that joke to Slashdot with an Android phone...