| 
 | |||||||
|  | 
|  | Thread Tools | Search this Thread | 
|  03-19-2021, 11:11 AM | #46 | 
| Goodest E-Reader            Posts: 64 Karma: 300094 Join Date: Jul 2007 Device: PRS 500 / Kindle 5th / Kindle PW4 | 
			
			shouldn't the shell script to be run just be copying the certificate from the usb reachable place to the right location?
		 | 
|   |   | 
|  03-19-2021, 11:17 AM | #47 | 
| BLAM!            Posts: 13,506 Karma: 26047202 Join Date: Jun 2010 Location: Paris, France Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E | 
			
			@melksnor: Yep, my point exactly   . (The post I linked to does just that (and a tiny bit more, but in the same spirit of "just dump that file here for now, and let a reboot and hotfix fix it up nicely")). | 
|   |   | 
|  03-19-2021, 11:15 PM | #48 | 
| Warm Lighting Enthusiast            Posts: 91 Karma: 754136 Join Date: Dec 2020 Device: Kindle Oasis 3 (jailbroken) | 
				
				We have root!
			 
			
			We have root! Here is a picture of what is ?probably? the first jailbroken Oasis 3, with KUAL open:  (It's running 5.12.4.) Tomorrow I'll go through all the firmware versions and create images for them. I'll be making a new thread for this exploit in the upcoming days. Thanks to everybody who helped me either here or in private!   Last edited by tryol; 03-19-2021 at 11:17 PM. | 
|   |   | 
|  03-20-2021, 12:27 AM | #49 | 
| hopeless n00b            Posts: 5,126 Karma: 19597086 Join Date: Jan 2009 Location: in the middle of nowhere Device: PW4, PW3, Libra H2O, iPad 10.5, iPad 11, iPad 12.9 | 
			
			That's awesome. Thanks for all your hard work!
		 | 
|   |   | 
|  03-20-2021, 05:28 AM | #50 | |
| Junior Member  Posts: 1 Karma: 10 Join Date: Mar 2021 Device: Kindle Paperwhite (10th gen) | Quote: 
   | |
|   |   | 
|  03-20-2021, 02:34 PM | #51 | 
| Goodest E-Reader            Posts: 64 Karma: 300094 Join Date: Jul 2007 Device: PRS 500 / Kindle 5th / Kindle PW4 | 
			
			I am really impressed, would love to read a write up on how you got there!
		 | 
|   |   | 
|  03-21-2021, 12:43 AM | #52 | 
| Fanatic            Posts: 507 Karma: 2390534 Join Date: Jun 2020 Location: Somewhere in the Universe Device: Kobo Libra, Glo HD, Touch C/B, Mini, Glo, Aura SE, Clara HD, KT | |
|   |   | 
|  03-21-2021, 05:32 PM | #53 | ||
| Warm Lighting Enthusiast            Posts: 91 Karma: 754136 Join Date: Dec 2020 Device: Kindle Oasis 3 (jailbroken) | 
				
				Status update
			 
			
			Status update: Seems like this won't be as easy as I thought... I'm not sure if I talked about this already, but 1 image won't work for all the firmware version. This is because they have their global offset tables and writable/executable memory pages in different places. I've spent the last 2 days downloading and going through each and every one of them, and categorizing them based on those two things. It seems like we'll have about ~20-30  different images if I'm planning to support everything from 5.3.0 to 5.13.3. Once I finalized all the groups, I'll make a new post here about them and talk about which version interval each of them represent. I hope we can get enough people to test at least the most popular ones.  I've already made testing kits for some of the groups, but right now the only one that's confirmed to be working is 5.11.1 - 5.13.3. Quote: 
 Quote: 
 75% of the time I've spent on making this was basically studying stuff I didn't know. I had to learn IDA and Ghidra to reverse engineer the binaries/libraries. I had to deepen my knowledge on memory management. I also learned how to write shellcodes on different CPUs, how ELF files work, etc. The other 25% was spent on reproducing what Yogev documented, and figuring out some of the details in the places where they - probably intentionally - left some things out. Maybe I could write about that, but given how dangerous it could be if somebody made malicious images, - like the one Yogev demonstrated the exploit with - I think it's best if I keep quiet on that. Last edited by tryol; 03-21-2021 at 06:42 PM. | ||
|   |   | 
|  03-21-2021, 10:53 PM | #54 | |
| Member  Posts: 12 Karma: 10 Join Date: Oct 2019 Device: Kindle PW3, KT4 , Kobo Glo (dead) | Quote: 
 | |
|   |   | 
|  03-22-2021, 12:23 AM | #55 | 
| Wizard            Posts: 1,190 Karma: 3592925 Join Date: Sep 2014 Location: Ukraine Device: Kindle | 
			
			The main difference between firmwares 5.11.* and 5.12 (and above) is an ability to block firmware ota updates: simple blocking directory vs renaming sys fles. If a user has upgraded over 5.12 - there are no reasons not to upgrade to 5.13.3. So it might be enough to have just two magic images: for 5.11.2 (the last 5.11.*) and for 5.13.3 (the last jailbreakable) for all models starting from PW3 and newer (except PW4). No need for PW4 images at all (well, not urgent). The latest update for PW2 and KT2 is 5.12.2.1.1, highly likely with closed vulneability, need to be tested. 5.12.2 is good for sure. Last edited by hius07; 03-22-2021 at 02:58 AM. | 
|   |   | 
|  03-22-2021, 05:29 AM | #56 | 
| Member  Posts: 10 Karma: 10 Join Date: Dec 2017 Device: Kindle Paperwhite 3 | 
			
			I'm only a dumb end-user, but I've been following these forums for a while in hopes of a jailbreak for my PW3 running 5.12.2. If I'm not misunderstanding, that's what this exploit might be able to do? Then I would like to help out if it's useful. | 
|   |   | 
|  03-22-2021, 05:44 AM | #57 | 
| abibliophobic            Posts: 220 Karma: 219708 Join Date: Aug 2012 Device: KV jailbroken | 
			
			@tryol Is it worth releasing what you have working for the latest firmwares, just so that there are some of us who've done this and can then help those that struggle? I've a Voyage on 5.13.1 which I'd love to get jailbroken and am more than happy to help others once I know the process.   | 
|   |   | 
|  03-22-2021, 06:37 AM | #58 | |||||
| Warm Lighting Enthusiast            Posts: 91 Karma: 754136 Join Date: Dec 2020 Device: Kindle Oasis 3 (jailbroken) | Quote: 
 Quote: 
 Quote: 
  I'm planning to test that "SHOULD" though before I make the image public. Quote: 
 Quote: 
 I'll PM you both soon, 5.12.2 and 5.13.1 are versions I haven't explicitly tested yet, and I want to before I make the new thread. If anybody else wants to help with testing, PM me with your device and firmware version! Untested firmwares preferred, especially the 2 extremities; 5.10.3 and 5.13.3.  The working firmware/device combinations for firmware versions (5.10.3 - 5.13.3) that got tested so far (constantly updated): Spoiler: 
 Once I get enough data I'll make it public for everybody. Last edited by tryol; 03-23-2021 at 06:49 PM. Reason: Added 5.10.3 since it was found out that it belongs to the same group | |||||
|   |   | 
|  03-22-2021, 07:21 AM | #59 | 
| Wizard            Posts: 1,190 Karma: 3592925 Join Date: Sep 2014 Location: Ukraine Device: Kindle | 
			
			Great, thanks! Regarding block OTA. You can test it as follows: download your version of the firmware (5.12.4, right?) and put it to the device usb-root. Non-blocked device should be able to upgrade (to the same vesion). Your device should not. I maintain Kindle cyrillic forum (4pda.ru), I hope we can find any combination of device/firmware for testing. | 
|   |   | 
|  03-22-2021, 07:25 AM | #60 | 
| Wizard            Posts: 1,190 Karma: 3592925 Join Date: Sep 2014 Location: Ukraine Device: Kindle | 
			
			Also you can try Kindle firewall to block Amazon sites https://www.mobileread.com/forums/sh....php?p=2425330 | 
|   |   | 
|  | 
| 
 | 
|  Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post | 
| Email address for Kindle | ayjay3 | Amazon Kindle | 2 | 07-05-2020 04:33 AM | 
| Adding a shortcut to [Send via email to my Kindle email address]? | jteodoro | Calibre | 7 | 04-30-2020 10:55 AM | 
| Have US address but no US issued credit card: Buy from Kindle Store? | khazaddum | Amazon Kindle | 6 | 12-23-2013 10:19 PM | 
| Sending to kindle email address | cagey1953 | Devices | 1 | 11-28-2012 03:11 AM |