|
![]() |
|
Thread Tools | Search this Thread |
![]() |
#46 |
Goodest E-Reader
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 64
Karma: 300094
Join Date: Jul 2007
Device: PRS 500 / Kindle 5th / Kindle PW4
|
shouldn't the shell script to be run just be copying the certificate from the usb reachable place to the right location?
|
![]() |
![]() |
![]() |
#47 |
BLAM!
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 13,506
Karma: 26047202
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
|
@melksnor: Yep, my point exactly
![]() (The post I linked to does just that (and a tiny bit more, but in the same spirit of "just dump that file here for now, and let a reboot and hotfix fix it up nicely")). |
![]() |
![]() |
Advert | |
|
![]() |
#48 |
Warm Lighting Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 91
Karma: 754136
Join Date: Dec 2020
Device: Kindle Oasis 3 (jailbroken)
|
We have root!
We have root!
Here is a picture of what is ?probably? the first jailbroken Oasis 3, with KUAL open: ![]() (It's running 5.12.4.) Tomorrow I'll go through all the firmware versions and create images for them. I'll be making a new thread for this exploit in the upcoming days. Thanks to everybody who helped me either here or in private! ![]() Last edited by tryol; 03-19-2021 at 11:17 PM. |
![]() |
![]() |
![]() |
#49 |
hopeless n00b
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 5,110
Karma: 19597086
Join Date: Jan 2009
Location: in the middle of nowhere
Device: PW4, PW3, Libra H2O, iPad 10.5, iPad 11, iPad 12.9
|
That's awesome. Thanks for all your hard work!
|
![]() |
![]() |
![]() |
#50 | |
Junior Member
![]() Posts: 1
Karma: 10
Join Date: Mar 2021
Device: Kindle Paperwhite (10th gen)
|
Quote:
![]() |
|
![]() |
![]() |
Advert | |
|
![]() |
#51 |
Goodest E-Reader
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 64
Karma: 300094
Join Date: Jul 2007
Device: PRS 500 / Kindle 5th / Kindle PW4
|
I am really impressed, would love to read a write up on how you got there!
|
![]() |
![]() |
![]() |
#52 |
Fanatic
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 507
Karma: 2390534
Join Date: Jun 2020
Location: Somewhere in the Universe
Device: Kobo Libra, Glo HD, Touch C/B, Mini, Glo, Aura SE, Clara HD, KT
|
|
![]() |
![]() |
![]() |
#53 | ||
Warm Lighting Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 91
Karma: 754136
Join Date: Dec 2020
Device: Kindle Oasis 3 (jailbroken)
|
Status update
Status update:
Seems like this won't be as easy as I thought... I'm not sure if I talked about this already, but 1 image won't work for all the firmware version. This is because they have their global offset tables and writable/executable memory pages in different places. I've spent the last 2 days downloading and going through each and every one of them, and categorizing them based on those two things. It seems like we'll have about ~20-30 ![]() Once I finalized all the groups, I'll make a new post here about them and talk about which version interval each of them represent. I hope we can get enough people to test at least the most popular ones. ![]() I've already made testing kits for some of the groups, but right now the only one that's confirmed to be working is 5.11.1 - 5.13.3. Quote:
Quote:
75% of the time I've spent on making this was basically studying stuff I didn't know. I had to learn IDA and Ghidra to reverse engineer the binaries/libraries. I had to deepen my knowledge on memory management. I also learned how to write shellcodes on different CPUs, how ELF files work, etc. The other 25% was spent on reproducing what Yogev documented, and figuring out some of the details in the places where they - probably intentionally - left some things out. Maybe I could write about that, but given how dangerous it could be if somebody made malicious images, - like the one Yogev demonstrated the exploit with - I think it's best if I keep quiet on that. Last edited by tryol; 03-21-2021 at 06:42 PM. |
||
![]() |
![]() |
![]() |
#54 | |
Member
![]() Posts: 12
Karma: 10
Join Date: Oct 2019
Device: Kindle PW3, KT4 , Kobo Glo (dead)
|
Quote:
|
|
![]() |
![]() |
![]() |
#55 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,179
Karma: 3592925
Join Date: Sep 2014
Location: Ukraine
Device: Kindle
|
The main difference between firmwares 5.11.* and 5.12 (and above) is an ability to block firmware ota updates: simple blocking directory vs renaming sys fles.
If a user has upgraded over 5.12 - there are no reasons not to upgrade to 5.13.3. So it might be enough to have just two magic images: for 5.11.2 (the last 5.11.*) and for 5.13.3 (the last jailbreakable) for all models starting from PW3 and newer (except PW4). No need for PW4 images at all (well, not urgent). The latest update for PW2 and KT2 is 5.12.2.1.1, highly likely with closed vulneability, need to be tested. 5.12.2 is good for sure. Last edited by hius07; 03-22-2021 at 02:58 AM. |
![]() |
![]() |
![]() |
#56 |
Member
![]() Posts: 10
Karma: 10
Join Date: Dec 2017
Device: Kindle Paperwhite 3
|
I'm only a dumb end-user, but I've been following these forums for a while in hopes of a jailbreak for my PW3 running 5.12.2.
If I'm not misunderstanding, that's what this exploit might be able to do? Then I would like to help out if it's useful. |
![]() |
![]() |
![]() |
#57 |
abibliophobic
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 220
Karma: 219708
Join Date: Aug 2012
Device: KV jailbroken
|
@tryol Is it worth releasing what you have working for the latest firmwares, just so that there are some of us who've done this and can then help those that struggle?
I've a Voyage on 5.13.1 which I'd love to get jailbroken and am more than happy to help others once I know the process. ![]() |
![]() |
![]() |
![]() |
#58 | |||||
Warm Lighting Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 91
Karma: 754136
Join Date: Dec 2020
Device: Kindle Oasis 3 (jailbroken)
|
Quote:
Quote:
Quote:
![]() Quote:
Quote:
I'll PM you both soon, 5.12.2 and 5.13.1 are versions I haven't explicitly tested yet, and I want to before I make the new thread. If anybody else wants to help with testing, PM me with your device and firmware version! Untested firmwares preferred, especially the 2 extremities; 5.10.3 and 5.13.3. ![]() The working firmware/device combinations for firmware versions (5.10.3 - 5.13.3) that got tested so far (constantly updated): Spoiler:
Once I get enough data I'll make it public for everybody. Last edited by tryol; 03-23-2021 at 06:49 PM. Reason: Added 5.10.3 since it was found out that it belongs to the same group |
|||||
![]() |
![]() |
![]() |
#59 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,179
Karma: 3592925
Join Date: Sep 2014
Location: Ukraine
Device: Kindle
|
Great, thanks!
Regarding block OTA. You can test it as follows: download your version of the firmware (5.12.4, right?) and put it to the device usb-root. Non-blocked device should be able to upgrade (to the same vesion). Your device should not. I maintain Kindle cyrillic forum (4pda.ru), I hope we can find any combination of device/firmware for testing. |
![]() |
![]() |
![]() |
#60 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,179
Karma: 3592925
Join Date: Sep 2014
Location: Ukraine
Device: Kindle
|
Also you can try Kindle firewall to block Amazon sites
https://www.mobileread.com/forums/sh....php?p=2425330 |
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Email address for Kindle | ayjay3 | Amazon Kindle | 2 | 07-05-2020 04:33 AM |
Adding a shortcut to [Send via email to my Kindle email address]? | jteodoro | Calibre | 7 | 04-30-2020 10:55 AM |
Have US address but no US issued credit card: Buy from Kindle Store? | khazaddum | Amazon Kindle | 6 | 12-23-2013 10:19 PM |
Sending to kindle email address | cagey1953 | Devices | 1 | 11-28-2012 03:11 AM |