Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Software > KOReader

Notices

Reply
 
Thread Tools Search this Thread
Old 10-04-2026, 10:41 AM   #91
Cuikis
Junior Member
Cuikis began at the beginning.
 
Posts: 3
Karma: 10
Join Date: Sep 2026
Device: Fnac Touch Light
Quote:
Originally Posted by tx4man View Post
Hello everyone,

I'm not sure if anyone mentioned this before, but the reader's stock web browser has a vulnerability that allows you to write to /mnt/private directly. So there's no need to bother with serial a COM adapter and disassemble your device.

You just need to run your own web server to download the "hackers_e60q22_ok" authorisation marker from the webserver and take advantage of the Content-Disposition header, and the parent directory ("..") descriptor.

So if a regular download from the webserver without setting up this response header would save your file at /mnt/public/file, in this case we would set the header to /../../private/file to esentially write to /mnt/private:

Content-Disposition: attachment; filename="/mnt/public/randomfolder/../../private/hackers_e60q22_ok"

I've published my findings to https://github.com/x4m4n/bq-cervantes3-offline-unlock, if anyone is interested in following this method. There you'll also find a python3 server preconfigured and ready to go for you to take advantage of this flaw. It's honestly very easy and fast.
Thanks you very much, I am going to try this with my BQ Cervantes Fnac Touch light to install Koreader, I hope it works.
Cuikis is offline   Reply With Quote
Old 10-04-2026, 09:15 PM   #92
Cuikis
Junior Member
Cuikis began at the beginning.
 
Posts: 3
Karma: 10
Join Date: Sep 2026
Device: Fnac Touch Light
Quote:
Originally Posted by tx4man View Post
Hello everyone,

I'm not sure if anyone mentioned this before, but the reader's stock web browser has a vulnerability that allows you to write to /mnt/private directly. So there's no need to bother with serial a COM adapter and disassemble your device.

You just need to run your own web server to download the "hackers_e60q22_ok" authorisation marker from the webserver and take advantage of the Content-Disposition header, and the parent directory ("..") descriptor.

So if a regular download from the webserver without setting up this response header would save your file at /mnt/public/file, in this case we would set the header to /../../private/file to esentially write to /mnt/private:

Content-Disposition: attachment; filename="/mnt/public/randomfolder/../../private/hackers_e60q22_ok"

I've published my findings to https://github.com/x4m4n/bq-cervantes3-offline-unlock, if anyone is interested in following this method. There you'll also find a python3 server preconfigured and ready to go for you to take advantage of this flaw. It's honestly very easy and fast.
I get the bq_download_probe file with the correct message and size. But when I press Write the Cervantes 3 authorization marker, and insert an empty microsd, I don't get the Device already authorised for hackers firmware installation message.

I understand that it should work in a different way as my device is older. Can you tell me how do you know what should be write and where in your version?

Thanks again for all
Cuikis is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Koreader running on Kobos (all of them, hopefully!) giorgio130 KOReader 3553 09-17-2026 10:53 PM
Does KOReader work on keyboard based Kindle Devices now? hayden KOReader 2 06-10-2018 08:56 PM
KOReader problems with Boyue devices chromeuser KOReader 0 06-12-2016 06:39 PM
Errors with EPUB rendering on Kobo Aura H2O running koreader-stable-v2015.11 algernonramone KOReader 8 03-16-2016 12:55 AM
Running 2 devices with calibre trott3r Devices 7 02-12-2011 10:05 AM


All times are GMT -4. The time now is 10:11 PM.


MobileRead.com is a privately owned, operated and funded community.