Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Amazon Kindle > Kindle Developer's Corner

Notices

Reply
 
Thread Tools Search this Thread
Old 08-15-2022, 05:01 AM   #1
inexplicable_ham
Junior Member
inexplicable_ham began at the beginning.
 
inexplicable_ham's Avatar
 
Posts: 3
Karma: 10
Join Date: Aug 2022
Device: PW5
Spitballing on future JBs

Hi all, long time listener, first time caller. I read the writeup on KindleDrip and KindleBreak which exploited a couple vulnerabilities to get root access on kindles that facilitated their jailbreaks.

I dunno if this is a dumb question, but is it possible that >=5.14.3 firmwares are running vulnerable versions of the linux kernel where there are known privilege escalation exploits?

I'm on my phone right now so I only did a little poking around in the termux app, but I downloaded Kindle_src_5.14.3.0.1_3838590001.tar.gz from the GPL release page, and it appears to include linux kernel version 4.9.77, which is a pretty old release. There are a few big exploits that could get us root access if they haven't been patched.

Maybe I'm just being dumb and the GPL releases aren't all that close to the linux kernel that's actually included in the Kindle firmware, but this seems like a really nice community so I thought I'd ask!
inexplicable_ham is offline   Reply With Quote
Old 08-15-2022, 02:09 PM   #2
NiLuJe
BLAM!
NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.
 
NiLuJe's Avatar
 
Posts: 13,477
Karma: 26012494
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
The main issue is getting code execution, privilege escalation is (usually) far "easier" (once upon a time because what flaws we found were already in stuff running as a privileged user ;p).
NiLuJe is offline   Reply With Quote
Advert
Old 08-15-2022, 07:40 PM   #3
Mike Li
Member
Mike Li began at the beginning.
 
Mike Li's Avatar
 
Posts: 16
Karma: 10
Join Date: Dec 2014
Device: KW4
My system version is 5.14.3.0.1. how can I BJ? I seemed hopeless for a while....
Mike Li is offline   Reply With Quote
Old 08-16-2022, 01:40 AM   #4
inexplicable_ham
Junior Member
inexplicable_ham began at the beginning.
 
inexplicable_ham's Avatar
 
Posts: 3
Karma: 10
Join Date: Aug 2022
Device: PW5
Quote:
Originally Posted by NiLuJe View Post
The main issue is getting code execution, privilege escalation is (usually) far "easier" (once upon a time because what flaws we found were already in stuff running as a privileged user ;p).
I see, in which case I can dig around for code execution! Do you have any tips? I figure since the kernel is from 2018, it's likely there's going to be a library or dependency somewhere that's old enough to be vulnerable to something for which POCs already exist. Have people already gone through metasploit and exploitdb for these?

I'm going to look for stuff related to file formats, the browser, bluetooth, and email as a first pass. If there's nothing obvious then I'll have to walk all the way over to my laptop and probe for running services...

I'm not an experienced hacker and I just like making my devices work on my terms rather than someone else's, so I don't know how far I'll get. Hopefully I'm not embarrassing myself in my naivete!
inexplicable_ham is offline   Reply With Quote
Old 08-17-2022, 06:24 PM   #5
inexplicable_ham
Junior Member
inexplicable_ham began at the beginning.
 
inexplicable_ham's Avatar
 
Posts: 3
Karma: 10
Join Date: Aug 2022
Device: PW5
WebKit seems like a good target. Maybe someone will have a POC or write-up sometime this week.
https://www.macworld.com/article/833...y-updates.html

If not, I think there are still older webkit RCEs and other parts of gtk like cairo that may work.

Last edited by inexplicable_ham; 08-17-2022 at 06:26 PM. Reason: typo
inexplicable_ham is offline   Reply With Quote
Advert
Old 08-17-2022, 07:40 PM   #6
JSWolf
Resident Curmudgeon
JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.JSWolf ought to be getting tired of karma fortunes by now.
 
JSWolf's Avatar
 
Posts: 74,015
Karma: 129333114
Join Date: Nov 2006
Location: Roslindale, Massachusetts
Device: Kobo Libra 2, Kobo Aura H2O, PRS-650, PRS-T1, nook STR, PW3
Quote:
Originally Posted by Mike Li View Post
My system version is 5.14.3.0.1. how can I BJ? I seemed hopeless for a while....
Trust me when I say this...

You do not want to BJ your Kindle. Not now and not ever.
JSWolf is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
The future crutledge Editor 1 01-06-2014 02:47 PM
Seriously thoughtful Future of TV Kumabjorn Lounge 0 08-02-2013 02:41 AM
The Future of Print Crusader General Discussions 42 07-16-2012 12:25 PM
Think of the Future! TGS Apple Devices 1 11-24-2010 10:53 AM
Classic BN future Falcao Barnes & Noble NOOK 0 09-21-2010 12:35 PM


All times are GMT -4. The time now is 08:52 AM.


MobileRead.com is a privately owned, operated and funded community.