Well , thanks for complement, I don't hesitate to put things rationally , everyone should ...
Is k0mraid3 releasing system shell for March and april oneui 5.1 update?
- 20 May 2023 (7 messages)
-
-
That's something I wanted to hear , well then , after paycheck , I guess ๐
-
UD -
im knowings theres some exploits that got released could try that ๐คทโโ๏ธ if ur lazy -
so you actually have something new @K0mraid3 lol -
@K0mraid3 https://github.com/0xkol/badspin -
we need to compile the app and try this - 21 May 2023 (9 messages)
-
That states it's for Android 12. And this was posted on the readme on that github "The vulnerability is patched on Android's Security Bulletin of October 2022."
Tested devices
$ make list
0: Samsung Galaxy S22, Android 12 (6/2022), kernel 5.10.81
1: Samsung Galaxy S21 Ultra, Android 12 (3/2022), kernel 5.4.129
2: Google Pixel 6, Android 12 (5/2022), kernel 5.10.66
3: Google Pixel 6, Android 13 (9/2022), kernel 5.10.107
also
Full root and SELinux bypass for Pixel 6. For Samsung devices, the exploit achieves kernel R/W only.
So on newer devices, this may not give full root, but it's worth a shot, you can build the start of it on Linux and then make the demo app that is the 2nd part, in Android studio -
-
broh -
I have A9 unfortunately -
I think it's definitely worth a look, atleast to see how it was patched and if the patch was done well. Worst case, we look at maybe the ability to chain another exploit in front of this one in order to make this one work possibly. If the patch is well done, it may simply not be possible. But let's check it out! -
-
-
I'm not sure what version of Android his A9 is on, but one could always lower the SDK target in the build.gradle of the Android Studio portion, and I believe it also stated there is a command line to test the exploit part and an option to increase verbose logging, so there should be some feedback from that... -
Android 9 - 24 May 2023 (32 messages)
-
๐
-
๐๐๐ -
It's back. -
Joined.
-
Oh it's alive -
@K0mraid3 have a look, https://vuldb.com/?id.228061 -
And this ladies and gentlemen, is a perfect example of why NOT to update firmware/software every time it becomes available. I've not updated my S23 at all thankfully -
I agree, updating patches vulnerabilities -
-
No -
No root= No power -
why ๐
-
-
-
-
-
You may use a network usb with an otg to have a different address -
-
not working on s5
-
-
I don't think that system shell exploit is enough to change mac address -
-
Another one bites the dust:https://t.me/redhotcyberchat/9999
In Italian unfortunately
@K0mraid3 check if it could be useful -
CISA warns of an actively exploited bug affecting Samsung devices
The US Infrastructure and Cyber โโโโโโSecurity Agency (#CISA) has listed an actively exploited #vulnerability affecting some #Samsung devices running #Android versions 11, 12 and 13 in its Known Exploited Vulnerabilities Catalog.
The issue has been identified as CVE-2023-21492 and is related to #disclosure of #information, which can possibly be used by privileged #attackers to bypass the #ASLR (Address Space Layout Randomization) protection mechanism.
Samsung says it was made aware of an #exploit for this #issue as early as mid-January 2023 which was privately #disclosed to the company. The #bug has been fixed.
Neither CISA nor the manufacturer provide further details on the exploitation of this #vulnerability. It is worth noting that #vulnerabilities in Samsung phones used to be used by commercial #spyware vendors to distribute various #malware.
#redhotcyber #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #privacy #infosecurity
https://www.redhotcyber.com/post/la-cisa-warns-of-an-actively-exploited-bug-affecting-samsung-devices/ -
And translated. Your welcome -
-
That's fine not everyone should be interested lol -
ู ู ุทูุจ ุฑุฃููุ
-
Counterargument:
-
.
-
-
ุงุฎุชู
- 25 May 2023 (1 messages)
-
and not every vulnerability isn't either...it goes both ways. If you're trying to use CISA to demonstrate that, well they're not exactly a wholesome government agency of the USA so you're just wasting your energy with me in regards to them... - 26 May 2023 (3 messages)
-
Here someone sells shell priv esc https://t.me/Tracer0xexploits @K0mraid3 maybe you are interested? -
-
None
- 27 May 2023 (3 messages)
-
i smel skid -
-
Would this help - 30 May 2023 (2 messages)
-
-
๐ - 31 May 2023 (2 messages)
-
Who has s21 ultra and root. Could you upload your file: /vendor/firmware/wifi/nvram.txt
I'm trying to bypass the wifi regional restrictions and learn how to change the wifi region of the module for more power and work on forbidden frequencies on my county
Everyone except the Russians. I need a different region from SER(RU) -