|
![]() |
|
Thread Tools | Search this Thread |
![]() |
#31 | |
Member
![]() Posts: 15
Karma: 10
Join Date: Jul 2018
Device: Kindle Oasis 2 (Jailbroken)
|
Quote:
|
|
![]() |
![]() |
![]() |
#32 |
Warm Lighting Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 91
Karma: 754136
Join Date: Dec 2020
Device: Kindle Oasis 3 (jailbroken)
|
Yes. 1 is needed for writing the shellcode and 1 for spraying GOT for its address. I figured out how to do that though so it's not a problem anymore. Right now i'm working with 25 tiles that allows me to completely overwite all of the GOT.
So far i've only managed to make it work with the JPEGRX reference app, not mesquite (the web browser on Kindles). Unfortunately even though yparitcher helped me with finding the correct memory addresses, it seems like the JPEGRX library that mesquite got compiled with differs from the reference one (the one i'm using). Right now i'm trying to make mesquite run with QEMU on my Debian VM to be able to debug the image. If anybody can help me with that I'd appreciate it! |
![]() |
![]() |
Advert | |
|
![]() |
#33 | |
Enthusiast
![]() ![]() Posts: 35
Karma: 102
Join Date: Jul 2016
Device: KOA4
|
Quote:
As for hosting I'd recommend GitHub. Its free, and with GitHub Pages you can get a proper website up and running, hosting the image, in no time. I've set up a repo and once we get the image working, I'll write up a guide as well. Also, automatic updates can be disabled relatively easily - I'm talking about the "update bin partial" folder name trick. |
|
![]() |
![]() |
![]() |
#34 | |
Guru
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 910
Karma: 3000002
Join Date: Jun 2010
Device: K3W, PW4
|
Quote:
Dave |
|
![]() |
![]() |
![]() |
#35 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,179
Karma: 3592925
Join Date: Sep 2014
Location: Ukraine
Device: Kindle
|
This blocking OTA method works so far
https://www.mobileread.com/forums/sh...d.php?t=327879 |
![]() |
![]() |
Advert | |
|
![]() |
#36 |
Member
![]() Posts: 15
Karma: 10
Join Date: Jul 2018
Device: Kindle Oasis 2 (Jailbroken)
|
https://i.imgur.com/xfOnpdX.png
...took a look at libjpegXR.so in IDA and realized that there was no way I'd be able to do this exploit. Some windows RE'ing experience doesn't make me remotely qualified lol Hope someone here can help with mesquite & priv escalation, would love to finally have a working jailbreak for the oasis 2 Last edited by jp12323; 02-26-2021 at 12:37 PM. |
![]() |
![]() |
![]() |
#37 | |
hopeless n00b
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 5,110
Karma: 19597086
Join Date: Jan 2009
Location: in the middle of nowhere
Device: PW4, PW3, Libra H2O, iPad 10.5, iPad 11, iPad 12.9
|
Quote:
|
|
![]() |
![]() |
![]() |
#38 |
Enthusiast
![]() ![]() Posts: 35
Karma: 102
Join Date: Jul 2016
Device: KOA4
|
Good to know. I've followed the above linked guide and disabled the services. Took a few looks around, looking for obvious URLs or configs to allow some DNS-based blocking, but alas no luck.
|
![]() |
![]() |
![]() |
#39 | |
Grand Sorcerer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 5,791
Karma: 103362673
Join Date: Apr 2011
Device: pb360
|
Quote:
https://www.mobileread.com/forums/sh...d.php?t=205925 |
|
![]() |
![]() |
![]() |
#40 | |
Enthusiast
![]() ![]() Posts: 35
Karma: 102
Join Date: Jul 2016
Device: KOA4
|
Quote:
Once we have the domain names, it's also relatively straightforward to use the hosts file instead of firewall hacks to disable OTAs. |
|
![]() |
![]() |
![]() |
#41 |
abibliophobic
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 220
Karma: 219708
Join Date: Aug 2012
Device: KV jailbroken
|
Have you made any progress with this?
The suspense is all but killing me! |
![]() |
![]() |
![]() |
#42 | |
Warm Lighting Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 91
Karma: 754136
Join Date: Dec 2020
Device: Kindle Oasis 3 (jailbroken)
|
Quote:
I managed to make the image parse on 3 different versions of the reference code, but I can't seem to be able to do the same on Amazon's version of the JPEGXR library. I've reverse engineered the (.jxr) parsing code in their library for the most part, but I can't find any differences from the reference code except for the lack of asserts and the way in which the image is stored in memory (which I already accounted for). Seems like that something stops the image before or while it's parsing, so I can't write anything to memory. I didn't have much time for the past few days so I couldn't progress any further, but I'm definitely not giving up yet. Last edited by tryol; 03-08-2021 at 11:19 AM. |
|
![]() |
![]() |
![]() |
#43 | |
Warm Lighting Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 91
Karma: 754136
Join Date: Dec 2020
Device: Kindle Oasis 3 (jailbroken)
|
Update:
I managed to figure out a few days ago why my image wasn't parsing, and ever since then it's been smooth sailing. Right now I'm writing / testing the shellcode that'll do the PE, so this shouldn't take long now. I'm new to the Kindle jailbreaking scene, I only got my first Kindle a few months ago, so I'm not sure what would need to be done after the PE. Quote:
Is there a more up-to-date jailbreak that works on all devices? What would I need to do in order to get my Oasis 3 jailbroken? (This is all post-PE obviously.) |
|
![]() |
![]() |
![]() |
#44 |
BLAM!
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 13,506
Karma: 26047202
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
|
BD's *exploit* won't work above 5.6.5. There's nothing against running a script on a noexec mount like that to bypass the binfmt handler, this isn't ChromeOS
![]() |
![]() |
![]() |
![]() |
#45 |
BLAM!
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 13,506
Karma: 26047202
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
|
By which I mean, you can make roughly the same assumptions as a serial JB.
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Email address for Kindle | ayjay3 | Amazon Kindle | 2 | 07-05-2020 04:33 AM |
Adding a shortcut to [Send via email to my Kindle email address]? | jteodoro | Calibre | 7 | 04-30-2020 10:55 AM |
Have US address but no US issued credit card: Buy from Kindle Store? | khazaddum | Amazon Kindle | 6 | 12-23-2013 10:19 PM |
Sending to kindle email address | cagey1953 | Devices | 1 | 11-28-2012 03:11 AM |