Register Guidelines E-Books Search Today's Posts Mark Forums Read

Go Back   MobileRead Forums > E-Book Readers > More E-Book Readers > iRex > iRex Developer's Corner

Notices

Reply
 
Thread Tools Search this Thread
Old 10-25-2006, 07:29 AM   #1
Mike Kostousov
Connoisseur
Mike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-books
 
Posts: 50
Karma: 861
Join Date: Aug 2006
Device: Zaurus C1000/iLiad/SE K750i
How to get 2.7.1 without closing holes

Hello!

For them, who are really interesed in new patch but still want to have some place to play I tried to download update without updating. I just canceled update in the right time. I have no time to discover what they have realy done in this patch, but if some body wants - see attachment.
Attached Files
File Type: gz 2708-patch.tar.gz (856.6 KB, 237 views)

Last edited by Mike Kostousov; 10-25-2006 at 07:42 AM.
Mike Kostousov is offline   Reply With Quote
Old 10-25-2006, 07:44 AM   #2
design256
Connoisseur
design256 doesn't litterdesign256 doesn't litter
 
Posts: 78
Karma: 103
Join Date: Aug 2006
Location: Ipswich, UK
Device: Irex Iliad
Quote:
Originally Posted by Mike Kostousov
Hello!

For them, how are really interesed in new patch but still want to have some place to play I tried to download update without updating. I just canceled update it in right time. I have no time for discover what they realy done in this patch, but if some body wants - see attachment.
Thanks Mike. You've saved me lots of worry. Loads of ways to leave a backdoor in place now we know what's in it. Major changes look like:

Xfbdev in start.sh now run with -nolisten tcp


main updated files:

browser
connectionMgr
contentLister
downloadMgr
ipdf (replaces xpdf in er_registry - I wonder why...)
mb-applet-icon-container
design256 is offline   Reply With Quote
 
Enthusiast
Old 10-25-2006, 07:56 AM   #3
Mike Kostousov
Connoisseur
Mike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-books
 
Posts: 50
Karma: 861
Join Date: Aug 2006
Device: Zaurus C1000/iLiad/SE K750i
Quote:
Originally Posted by design256
ipdf (replaces xpdf in er_registry - I wonder why...)
I see libpoppler in /usr/lib. It is pdf rendering library, it is based on xpdf. poppler team works together with kpdf project, so this library are in develop. ipdf can be quicker..
Mike Kostousov is offline   Reply With Quote
Old 10-25-2006, 08:35 AM   #4
TadW
Uebermensch
TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.TadW ought to be getting tired of karma fortunes by now.
 
TadW's Avatar
 
Posts: 2,580
Karma: 1094606
Join Date: Jul 2003
Location: Italy
Device: Kindle
Excellent Mike.

Is the patch everything that is being executed during the update? I don't see any attempt to remote root access again (e.g. by changing passwords, uninstalling dropbear, etc.)...
TadW is offline   Reply With Quote
Old 10-25-2006, 09:08 AM   #5
Mike Kostousov
Connoisseur
Mike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-booksMike Kostousov has learned how to read e-books
 
Posts: 50
Karma: 861
Join Date: Aug 2006
Device: Zaurus C1000/iLiad/SE K750i
It seems that it is everything. But I am not sure, because after this update iLiad can connect to iDS one more time. See ./usr/bin/post_download.sh in patch. It has lines:
Code:
# write flag to reconnect to iDS after reboot
sysset -w -a 153 -l 1 -v 1
Mike Kostousov is offline   Reply With Quote
Old 10-25-2006, 09:10 AM   #6
Alexander Turcic
Fully Converged
Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.Alexander Turcic ought to be getting tired of karma fortunes by now.
 
Alexander Turcic's Avatar
 
Posts: 17,094
Karma: 10000000
Join Date: Oct 2002
Location: Switzerland
Device: Sony PRS-650 / Nexus 7 / Kindle PW
From the announcement:

Quote:
# After connecting to the server you will get a message: Downloading Software Patch v2.7.1 and the progress of the download.
# When the download is complete wait until the screen of the iLiad turns white.
# After this the iLiad will automatically restart itself.
# When the iLiad has restarted, it will reconnect to the iDS to check for any further downloads.
# When there are no additional downloads you will return to the Download history screen, and the installation is complete.
Alexander Turcic is offline   Reply With Quote
Old 10-25-2006, 11:42 AM   #7
scotty1024
Banned
scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.scotty1024 is no ebook tyro.
 
Posts: 1,300
Karma: 1479
Join Date: Jul 2006
Location: Peoples Republic of Washington
Device: Reader / iPhone / Librie / Kindle
As much as I liked Design256's pre-exploit work around, , I'd rather encourage iRex to post the patches.

I'm quite capable of applying them manually.
scotty1024 is offline   Reply With Quote
Old 10-25-2006, 01:17 PM   #8
CommanderROR
eink fanatic
CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.CommanderROR is fluent in JavaScript as well as Klingon.
 
CommanderROR's Avatar
 
Posts: 2,022
Karma: 4924
Join Date: Mar 2006
Location: Germany
Device: STAReBOOK, iRex Iliad, Sony 505, Kindle 2
Should I move this to the development subforum? I think so...any objections?
CommanderROR is offline   Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Closing The Gap indie Self-Promotions by Authors and Publishers 6 09-25-2010 02:04 AM
What is the purpose of the holes on the left side of the device lunixer Amazon Kindle 4 09-04-2010 01:43 PM
Closing Threads tompe Feedback 21 03-22-2009 10:29 AM
iRex iLiad patch V2.7.1 closes security holes Alexander Turcic iRex 11 10-26-2006 11:41 AM
PRS-500 PDF or similar holes? arivero Sony Reader Dev Corner 1 10-20-2006 04:25 PM


All times are GMT -4. The time now is 12:05 PM.


MobileRead.com is a privately owned, operated and funded community.