WELCOME TO EHOST.COM.NP

Wednesday, August 2, 2017

OnePlus 2 Boots with a Tampered Secondary Bootloader

ads space

It’s fair to say the OnePlus 2 doesn’t have the best reputation when it comes to the Android enthusiast community. It used the Snapdragon 810 SoC (which has had a ton of criticism), never received Android 7.0 Nougat (even though it was promised), and has been shown to have vulnerabilities in the past that OnePlus refuses to fix. Now, a new discovery from Aleph Security again shows the OnePlus 2 boots with a tampered Secondary Bootloader.

This means that OnePlus has designed the Primary Bootloader of the OnePlus 2 to not do any validation of the Secondary Bootloader at all. Speculation from the research team says this may be due to a lenient hardware configuration. So this vulnerability allows an attacker to tamper with the secondary bootloader partition and then completely disable the signature validation of the rest of the bootloader chain. Not only that, but this can also result in signature validation being disabled for other SBL-validated partitions such as TrustZone and ABOOT as well.

They continued working with the vulnerability and were able to easily pinpoint the exact SBL function that validates the rest of the chain. After a quick patching of the call @ 0xFEC0E90C they avoid the failing path and booting with tampered aboot and tz now succeeds. The team then proceeded to modify one of the fastboot oem commands. This enabled them to temporarily unlock the bootloader and turn off the device tampering flag.

They also confirmed equivalent partitions of older OnePlus devices (OnePlus One and OnePlus X) have no digital signatures at all so they are vulnerable as well. When they got in contact with OnePlus about this OnePlus 2 vulnerability, they were told the device would not be fixed since it is “about to reach the product’s lifecycle.”


Source: Aleph Security

ads space
ADS SPACE

0 comments:

Post a Comment

Categories

Article How-to All Posts WordPress Android Web design Blogger Plugins CSS Google JQuery Plugins Programming Reviews Web Hosting Blogger Blogging Blogging Tips Tricks Web Development Facebook Git Internet Make Money Online Social Plugins Tips Tips and Tricks Tools Tutorials Windows WordPress Plugins Blogging Tips and Tricks Freebies GSM Google Analytics HTML How To's JavaScript Plugin Development S.E.O SEO SMS SmartPhone Social Media Tips amp; Tricks Top-Most Updates Webmaster Tools Whatsapp Applications Apps Blogger Basics Documentary Downloads Entertainment Gadgets Games Gmail Google AdSense Guest Post IPhone Make Money Blogging SVN Security Softwares Web Hosting Tips and Tricks Wordpress Tips Wordpress Tips and Tricks hostgator iOS Advertising Networks Advertising Technology Affiliates Antivirus Audience amp; Traffic Biography Blog post Blog post Blogger Blogger Errors Blogger Tips Blogger Tools Blogger Widget Blogosphere Bogger Widgets CSS selectors CSS symbols CSS3 Computer amp; Internet Content Writing Coupon Codes Data amp; Analytics Deleted blog Design DoubleClick for Publishers Email and newsletter marketting Email marketing Excel Tips Excel Tips and Tricks Facebook Tricks Feed Feedburner Feedburner subscribers Font Fun GitHub Giveaways Gmail primary inbox Gmail tabs Google sign-in Guides HTML amp; CSS HTML5 Infographics Inspirational Instagram Internet Marketing Internet Tips amp; Tricks Job Listings Knowledge Life Hacks Lists Make-Money Monetization amp; Conversion Monetize Navigation Online Marketing Other PHP Tutorials Passport Publishing amp; Content Quotes RSS Sidebar Smartphones Social Networking Status Tech Tech Blog Technology Telegram Themes UI / UX User Psychology amp; Research VB.Net Web Tools Web browser Widget Windows Tips Windows-10 ad viewability admin notice blogging tools bluehost cherry-pick clone cors custom scrollbar customizer dismissible notices duplicate post feed title git branch git clone gpg gpg2 hybridauth iPad icon font notice responsive wordpress theme same origin policy scrollbar signed git commit smartsvn theme customizer vcs wordpress theme wordpress themes

Blog Archive