[Q] Are we safe yet? (exynos exploit) - Verizon Samsung Galaxy Note II

so I've been reading about this Exynos exploit for the last couple of days and it seems pretty scary...now it maybe due to the fact that I'm new at this kinda stuff, but I wanna learn. So are we safe yet from attacks!? is it safe to root our galaxy note 2 and do all the cool stuff to our phone again? if anyone has a answer to this it would be great for all us nubs: fingers-crossed:
Thanks

Please search before posting.
You can get an apk that fixes the security hole.
Sent from my SCH-I605 using XDA Premium HD app

Related

Root access??

I know its to early to request this...but i must have Root access!! Must have Rootcall blocker <3 ;-)
LOL... I was just wondering if there's a way to root it yet...
Sent from my SAMSUNG-SGH-I727 using XDA App
Yeah. All I want is my titanium backup mane!
Sent from my Inspire 4G using Tapatalk
CXENTE said:
I know its to early to request this...but i must have Root access!! Must have Rootcall blocker <3 ;-)
LOL... I was just wondering if there's a way to root it yet...
Sent from my SAMSUNG-SGH-I727 using XDA App
Click to expand...
Click to collapse
I think they can tweak the Root method for the international Note once they get a system dump from an ATT Note. I don't think it's a big stretch.
droidal said:
I think they can tweak the Root method for the international Note once they get a system dump from an ATT Note. I don't think it's a big stretch.
Click to expand...
Click to collapse
Sweeett!!!!!
Sent from my SAMSUNG-SGH-I727 using XDA App
I have the international version, rom LA4. I screwed up and updated with KIES from the previous rom to LA4 and lost root. To get it back, I'd have to downgrade (wipe), root, then update OTA to get it back. The exploit used for the older rom won't work on the newer. Not sure if they will figure it out, I think they would rather spend their time tinkering with ICS (can't blame em). Make sure one the at&t version can be hacked, that you watch how you update it. First time I've had a non rooted phone for 9 months, the ads are about to drive me nuts
I'm sure when ICS hits, it will be full of exploits to root it until Sammy figures out where the holes are located and plugs them up.
More then likely we can root with Skyrocket's version.
Sent from my SGH-I997 using XDA App
+1 ..staying away from updates
Sent from my SAMSUNG-SGH-I727 using XDA App

Will TurkbeyRom work with AT&T version of GS3?

I really like what I see from this rom: rootgalaxys3iii.com/turkbeyrom-v3/
But everywhere I've read about it, it references the international version of the phone.. this will be my first root and Rom flash so I am really nervous about bricking my phone if it isnt meant for att version.
Thanks for helping
If it is made for the international version then do not flash it on the us version. Since you are new I would suggest you flash roms that are for your carrier, ie the ones listed in whatever carrier development forum you use for your service. Be advised though to please do plenty of research on whatever questions you may have in the future as it will save you major headaches
Sent from my SAMSUNG-SGH-I747 using xda premium
Unfortunately no it wont work. I9300 roms cannot be flashed due to different internals. You'll be lucky to get a boot screen if you flash but could probably still recover. Definitely wont work though until someone ports it over for your model.
Sent from my SGH-I747M using xda app-developers app
Thanks for the heads up guys, Def will stay away! I'm just liking to maximize my battery life anyway since I'm having a terrible time making it through a day even with power saving steps taken.performance boost is good too haha but battery far more important
Sent from my SAMSUNG-SGH-I747 using xda app-developers app
I wish it was out for us. Turkbey rocked on the GS2
Sent from my GT-P7510 using Tapatalk 2

holo blue themed factory based?

im looking for a factory based holo blue themed rom for a buddy.... also looking up what else i need to do before flashing anything on it... its bone stock
Jelly Beans is the ROM to go to.
But make sure your buddies phone is already unlocked. If he didn't unlock his bootloader and install a custom recovery by now he's probably screwed. That OTA has destroyed any current working methods of getting custom recovery capabilities.
If he didn't get the OTA then have him read the Unlocking the Bootloader thread under the Original Development sub forum for the Verizon Galaxy Note 2.
Quick question. If I haven't updated am I still good to use the old unlock?
Sent from my SCH-I605 using xda premium
DJ1994 said:
Quick question. If I haven't updated am I still good to use the old unlock?
Sent from my SCH-I605 using xda premium
Click to expand...
Click to collapse
Yes do it asap.
He just updated yesterday! Dang. I thought samsung didnt lock down anything? Didnt with my e4gt
Sent from an Apple killing JellyBean
moparfreak426 said:
He just updated yesterday! Dang. I thought samsung didnt lock down anything? Didnt with my e4gt
Sent from an Apple killing JellyBean
Click to expand...
Click to collapse
Samsung doesn't, Verizon does. I can't tell you what their real reasons are for locking bootloaders but I believe their public statement is that they feel by locking these phones down securely they can provide a better network experience for everyone.
Yeah, bull****. It's so they can force bloatware down our throats and prevent people from using root required workarounds to things they keep locked on us. See Google Wallet vs Isis for further study.
Dang. Verizon sucks balls. Hope theres a workaround soon
Sent from an Apple killing JellyBean

Why are you updating?

Anybody here feel confused with some of the users that are updating to the latest locked down firmware, I just find it weird that people are knowingly locking down their phones, the main reason people come here is to do the opposite. I've read people apply the update and they still ask for some sort of support from community members. I just dont get it.
Sent from my SCH-I545 using xda app-developers app
I read some saying they didn't care and after some did the update they said the phone was faster and worth losing root. Others just want root and were able to update using voodoo ota rootkeeper. To keep root and update.
Sent from my VZW Galaxy S4 using Tapatalk 4 Beta
They kept root in a sense. Yes, they can still run some apps that require root, but they cannot flash a custom kernel or recovery.
Sent from my SCH-I545 using Tapatalk 4 Beta
I traded my note 2 and got this. Met the guy at Verizon. Got the prompt for the OTA and took it before I knew what was good for me. Although I would have preferred not to, I am very impressed with the stock firmware.
Only disappointment which would make me want to root is WiFi tethering doesn't work in Pdanet, and of course the annoying WiFi toggle - both things I'm content dealing with without pulling hair out while I wait for the new exploit.
Sent from my SCH-I545 using xda app-developers app
I've noticed a few of the update fans haven't posted in here for awhile. Possible a good thing for the community.
Sent from my SCH-I545

Native root method found! Towelroot.com (CVE-2014-3153)

Just found this thread that confirms root for the vzw and att s5.
http://forum.xda-developers.com/showthread.php?t=2780319
Would this vulnerability work on the s4 with kitkat?
Here's info on the exploit (CVE-2014-3153):
http://seclists.org/oss-sec/2014/q2/467
http://www.reddit.com/r/netsec/comments/27fl04/another_linux_kernel_exploit_this_time_reachable/
http://www.securelist.com/en/advisories/59029
Edit @geohot has made a root method that works. All you have to do is go to http://towelroot.com and click the icon in the center to download tr.apk . Install the tr.apk after allowing installation from unknown sources. The click the button to root and the phone will reboot and you will have root. I recommend you download the updatesupersu1.99 zip and install the supersu from the common folder after extracting.
joshuabg said:
Just found this thread that confirms root for the vzw and att s5.
http://forum.xda-developers.com/showthread.php?t=2780319
Would this vulnerability work on the s4 with kitkat
Here's info on the exploit.
http://seclists.org/oss-sec/2014/q2/467
http://www.reddit.com/r/netsec/comments/27fl04/another_linux_kernel_exploit_this_time_reachable/
http://www.securelist.com/en/advisories/59029
Click to expand...
Click to collapse
That vulnerability is going to be like Cube's getroot - it's going to work on a huge number of devices.
I've been looking on how to exploit it but haven't had much time to devote to it, but apparently it's been cracked for at least one phone.
We'll have native root on the S4/S5 and who knows what else pretty soon if I'm not mistaken. Good news.
Any devs willing to work on this? @k1mu @Surge1223 @ryanbg
Sent from my SCH-I545 using Tapatalk
After reading the linked post it seems this is more a "nah-na-nah-na boo-boo" thing. It's not released, but it does give me hope that we can get a native root method like JB had.
My question is, to what end? Surge's pre - rooted functions well and is effectively stock, would this make any functionality differences vs a pre rooted rom?
Sent from Tapatalk on my rooted Verizon NC5 Galaxy S4
ffchampmt said:
After reading the linked post it seems this is more a "nah-na-nah-na boo-boo" thing. It's not released, but it does give me hope that we can get a native root method like JB had.
My question is, to what end? Surge's pre - rooted functions well and is effectively stock, would this make any functionality differences vs a pre rooted rom?
Sent from Tapatalk on my rooted Verizon NC5 Galaxy S4
Click to expand...
Click to collapse
It would be easier to do, and for example, if you dont flash SuperSu before a reboot after installing a rom, you will lose root and have to start the downgrade and upgrade process all over again. If there was a native root method all you would have to do would be to probably run a script on your computer with your phone plugged in and you will have root back. I'd imagine it would be safer and have less chance of bricking.
I actually prefer the more difficult hacks...less likely to be exploited for malware. Not saying this one will be or even could be, but easy root is not necessarily good. I'm sure jcase is shaking his finger at everyone somewhere, lol.
Sent from my SCH-I545 using Tapatalk
brizey said:
I actually prefer the more difficult hacks...less likely to be exploited for malware. Not saying this one will be or even could be, but easy root is not necessarily good. I'm sure jcase is shaking his finger at everyone somewhere, lol.
Sent from my SCH-I545 using Tapatalk
Click to expand...
Click to collapse
I think jcase liked that a guy got root from this on the att s5. But jcase isn't working on this because he is on break.
Sent from my OtterX running SlimKat 4.4.3 using Tapatalk
joshuabg said:
Any devs willing to work on this? @k1mu @Surge1223 @ryanbg
Sent from my SCH-I545 using Tapatalk
Click to expand...
Click to collapse
As I said above, I'm already working on it. Been on travel all week and very busy, but I do intend to try to exploit this.
k1mu said:
As I said above, I'm already working on it. Been on travel all week and very busy, but I do intend to try to exploit this.
Click to expand...
Click to collapse
I for one would love this as I have had zero ability to use any of the other ways for rooting my s4...I have had every problem trying every method so I have just given up and would love this...thanks anyone for working on it...
It's already worked out question is how the bounty is going to be paid and or split. It's not just one persons work but a bunch of contribute used info being used and who will get full credit. The bounty is what's holding up release because now yall want to pay
Sent from my SAMSUNG-SM-N900A using Tapatalk
joshuabg said:
Any devs willing to work on this? @k1mu @Surge1223 @ryanbg
Sent from my SCH-I545 using Tapatalk
Click to expand...
Click to collapse
@joshuabg @k1mu @Surge1223 @ryanbg
count me in for testing....[emoji41][emoji106]
☆Swyped From California Chrome Custom☆
Cod3L1ne said:
It's already worked out question is how the bounty is going to be paid and or split. It's not just one persons work but a bunch of contribute used info being used and who will get full credit. The bounty is what's holding up release because now yall want to pay
Sent from my SAMSUNG-SM-N900A using Tapatalk
Click to expand...
Click to collapse
As I've said before, bounties aren't my motivation. I post what I find and make it public.
This particular vulnerability is an interesting one, with a good potential for exploit. It is not going to be easy to exploit across a large number of phones.
Cod3L1ne said:
It's already worked out question is how the bounty is going to be paid and or split. It's not just one persons work but a bunch of contribute used info being used and who will get full credit. The bounty is what's holding up release because now yall want to pay
Sent from my SAMSUNG-SM-N900A using Tapatalk
Click to expand...
Click to collapse
Easy first one to post the root or a stock rooted image... if someone has it but another puts it up for public use, then they should get the whole bounty not one who shows it but does not share... JMO.
Sent from my SAMSUNG-SM-G900A
k1mu said:
As I've said before, bounties aren't my motivation. I post what I find and make it public.
This particular vulnerability is an interesting one, with a good potential for exploit. It is not going to be easy to exploit across a large number of phones.
Click to expand...
Click to collapse
I was told by someone on another forum that's been looking at it for the RAZR HD/M that it needs to be able to directly access memory, which as we know, can't be done in Java. Are you looking at doing it in C? Just a curiosity is all.
Would this method allow custom kernels? Or just root?
Sent from my SCH-I545 using Tapatalk
sherdog16 said:
Would this method allow custom kernels? Or just root?
Sent from my SCH-I545 using Tapatalk
Click to expand...
Click to collapse
Just root. Unlocked bootkoader is needed for custom kernels.
Sent from my white SM G900V on XDA Premium 4
Probably Safestrap recovery by @Hashcode just like ATT S4 and Note 3..... per my buddy @Surge1223 we might able to use Note3 Kitkat Safestrap Recovery v3.72.... time would tell.
☆Swyped From California Chrome Custom☆
I couldn't care or less if they release this root method. We already have several pre rooted ROMs with kitkat. I understand the exploit could be easier to root but I don't care how long it takes to root. I just want an unlocked bootloader. If anything we need to get more people to add to the bounty to maybe attract attention. And get as many devs working on it as possible. I am sure surge is probally getting tired of working on this for so long. It's been close to a year and nothing since loki. I bought my s4 because I thought it could be unlocked but I bought it just around the time Verizon patched loki which sucks
Sent from my SCH-I545 using XDA Free mobile app
Im just curious. Will this exploit trip the Knox counter?
Sent from my white SM G900V on XDA Premium 4
I hate to burst everyone's bubble, but this vulnerability is very difficult to exploit, and even if done correctly, will not be stable on the majority of devices. @jcase has already taken a look at this since the day it came out, and if he says it's not worth the time, it's not worth the time. Geohot may have been able to exploit it, but you only have access to a root shell for 15-20 seconds before the device becomes unstable and shuts down. SEAndroid is also an obstacle after the vulnerability has been exploited. While it's certainly possible, it's a bit far out of the ballpark to be feasible at this point in time.

Categories

Resources