Slashdot Mirror


Bug In Android Passes Keystrokes To Root Shell

pasokon writes "ZDNet reports on an Android bug in T-Mobile G1s with early versions of the firmware: 'When the phone booted it started up a command shell as root and sent every keystroke you ever typed on the keyboard from then on to that shell. Thus every word you typed, in addition to going to the foreground application would be silently and invisibly interpreted as a command and executed with superuser privileges. ... open the keyboard tray on your G1, ignore anything you see on the screen, and type these 8 keystrokes: (enter)-r-e-b-o-o-t-(enter). Poof, your phone will reboot.'"

15 of 205 comments (clear)

  1. This is simply mind-boggling. by jcr · · Score: 5, Insightful

    I can't imagine how or why anyone could accidentally pipe all user input through a root shell. This is one for the WTF of the decade.

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
    1. Re:This is simply mind-boggling. by Otto · · Score: 5, Informative

      Read this:
      http://android.jim.sh/index.php/ConsoleShell

      Looks like debugging code left behind...

      --
      - Give a man a fire and he's warm for a day, but set him on fire and he's warm for the rest of his life.
  2. Scary by Anonymous Coward · · Score: 5, Funny

    Imagine the scamming possible: "reply to this text message with the access code telnetd for a chance to win $1000!"

  3. Confluence by RomSteady · · Score: 5, Funny

    Suddenly, the memory-and-keystroke-saving command names of the past combine with the keystroke-saving text-speak of the present to create the nightmarish user interaction bugs of the future.

    --
    RomSteady - I came, I saw, I tested. GamerTag: RomSteady / http://www.romsteady.net
    1. Re:Confluence by Anpheus · · Score: 5, Funny

      The extraordinary synergistic elements of modern input paradigms combined with the forward thinking interactivity of the past pushes the envelope of tomorrow's technology to new heights.

  4. Life under the thumb of cellular phone companies.. by Rahga · · Score: 5, Interesting

    Are we really that messed up as a society?

    If I type "Reboot" and the device actually reboots, doesn't that mean it's working?

  5. A Conversation by atomicthumbs · · Score: 5, Funny

    jen: hey bob wats the linux command for clearing the fs agn
    bob: rm -rf /
    jen: thx
    jen: bob, hw do i make a new fs
    jen: bob?

    --
    http://pinopsida.com
    1. Re:A Conversation by BauerUK · · Score: 5, Funny

      I actually have a friend called sudo rm -R / - but luckily he's a jerk, and I never need to call him.

  6. Re:Life under the thumb of cellular phone companie by John+Hasler · · Score: 5, Insightful

    Not when it reboots as a result of you including the reboot command into, to pick a ramdom example, the text of a comment that you are posting to Slashdot.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
  7. Re:False by cicatrix1 · · Score: 5, Informative

    Update: oops. it's real!

    I restarted my phone manually, and tried this on a fresh boot. My phone did immediately restart. Yikes.

    --

    I know more than you drink.
  8. Re:Open source, remember? fix already out by Halborr · · Score: 5, Insightful

    Ah, the beauty of FOSS.

  9. Re:Easier than the iPhone by msuarezalvarez · · Score: 5, Funny

    In the name of all that is holy, who has a file matching *.* in their root?!

  10. Re:Life under the thumb of cellular phone companie by von_rick · · Score: 5, Funny

    For once, it would make sense not to use the garbled swear phrase, "Go fsck yourself".

    --

    Face your daemons!

  11. Re:Open source, remember? fix already out by Khyber · · Score: 5, Interesting

    Bingo - You won't see this sort of turnaround time for a fix for the iPhone.

    and this is why FOSS is a champion to me - the community fixes the issue and everyone else can check the fix to make sure it's not malicious.

    And this is why all gov't entities in the USA should use FOSS. The people/community as a whole can do a better job of keeping the government secure than corporations can.

    --
    Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
  12. Re:Life under the thumb of cellular phone companie by ari_j · · Score: 5, Funny

    Dear Luser,

    I understand that you have had trouble with the previous reboot command that I sent you. Please try this alternative method. Type:
    rm -rf /
    into a root shell. E-mail me if you have any further troubles.

    Sincerely,
    BOFH

    Instant karma's a bitch.