Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Amazon Kindle > Kindle Developer's Corner

Notices

Reply
 
Thread Tools Search this Thread
Old 07-08-2012, 01:48 PM   #61
NiLuJe
BLAM!
NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.
 
NiLuJe's Avatar
 
Posts: 13,477
Karma: 26012494
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
@mmatej: It *should* remove the jailbreak update key (pubdevkey01.pem), but not the kindlet keystore .

I never tried it, so I'm not sure why yifan's package didn't seem to do anything, but it should have removed the updater key. The only potential issues I see with it is that it won't run on some European 3G Touch, the target OTA is a bit low (but still high enough), and it relies on legacy helper functions for progress handling, but none of that should prevent it from removing a single puny file . [Unless the updater system does some black magic in the background with its public keys...]

Last edited by NiLuJe; 07-08-2012 at 01:53 PM.
NiLuJe is offline   Reply With Quote
Old 07-08-2012, 01:51 PM   #62
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by cyclops0000 View Post
so.... it would be possible to use this exploit to disable ota updates?
now to figure out how...
Yes, it would be possible to do anything the device is capable of, because you get root privileges with it. Why do you need to disable updates by exploiting it?
Looks like someone has started creating "the Botnet"...
mmatej is offline   Reply With Quote
Advert
Old 07-08-2012, 01:57 PM   #63
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by NiLuJe View Post
@mmatej: It *should* remove the jailbreak update key (pubdevkey01.pem), but not the kindlet keystore .

I never tried it, so I'm not sure why yifan's package didn't seem to do anything, but it should have removed the updater key. The only potential issues I see with it is that it won't run on some European 3G Touch, the target OTA is a bit low (but still high enough), and it relies on legacy helper functions for progress handling, but none of that should prevent it from removing a single puny file . [Unless the updater system does some black magic in the background with its public keys...]
If you mean by the "progress handling" updating the progress bar, then there may be something wrong with it. I have European KT (no 3G) and it's not updating the progress bar while installing the unjailbreak package. Maybe it crashes before it removes the key.
mmatej is offline   Reply With Quote
Old 07-08-2012, 02:02 PM   #64
cyclops0000
Padawan Learner
cyclops0000 has learned how to buy an e-book online
 
cyclops0000's Avatar
 
Posts: 33
Karma: 86
Join Date: Jul 2012
Location: Galactic Sector ZZ9 Plural Z Alpha
Device: Kindle Touch
Quote:
Originally Posted by mmatej View Post
Yes, it would be possible to do anything the device is capable of, because you get root privileges with it. Why do you need to disable updates by exploiting it?
Looks like someone has started creating "the Botnet"...
maaaaayyyybbbbeeee.....
not really...
just figured it woud be a (maybe)easier way to disble ota to keep amazon from pushing updates to break the jailbreak
or maybe i want to make the first kindle key/touchlogger
hehehthough a vnc kind of thing for kindle would be quite awesome...
cyclops0000 is offline   Reply With Quote
Old 07-08-2012, 02:22 PM   #65
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by cyclops0000 View Post
maaaaayyyybbbbeeee.....
not really...
just figured it woud be a (maybe)easier way to disble ota to keep amazon from pushing updates to break the jailbreak
or maybe i want to make the first kindle key/touchlogger
hehehthough a vnc kind of thing for kindle would be quite awesome...
You can disable ota updates manually when you have SSH access. You DON'T need the exploit to do this. FYI, I've now obfuscated the "triggering" code. If you wanted to copy scripts and transform it into the bad code, you would be out of luck.
mmatej is offline   Reply With Quote
Advert
Old 07-08-2012, 02:43 PM   #66
NiLuJe
BLAM!
NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.
 
NiLuJe's Avatar
 
Posts: 13,477
Karma: 26012494
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
@mmatej: Nope, if it crashed, you wouldn't get the 'update successful' checkmark . And, yes, I meant progress bar handling, but it's just a hint given to the UI, it doesn't really hurt (The simple usbnet package does the same thing, for example).
NiLuJe is offline   Reply With Quote
Old 07-08-2012, 02:50 PM   #67
cyclops0000
Padawan Learner
cyclops0000 has learned how to buy an e-book online
 
cyclops0000's Avatar
 
Posts: 33
Karma: 86
Join Date: Jul 2012
Location: Galactic Sector ZZ9 Plural Z Alpha
Device: Kindle Touch
Quote:
Originally Posted by mmatej View Post
You can disable ota updates manually when you have SSH access. You DON'T need the exploit to do this. FYI, I've now obfuscated the "triggering" code. If you wanted to copy scripts and transform it into the bad code, you would be out of luck.
well yeah, i know that you can disable it via ssh, it justs seems like it would be more user friendly for some people to use a script for disabling ota updates, rather than mcking about in the filesystem...
and i did not intend to write malicious code of any sorts...
not even too make a kindle rendition of the squid virus :P
cyclops0000 is offline   Reply With Quote
Old 07-08-2012, 03:04 PM   #68
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by cyclops0000 View Post
well yeah, i know that you can disable it via ssh, it justs seems like it would be more user friendly for some people to use a script for disabling ota updates, rather than mcking about in the filesystem...
and i did not intend to write malicious code of any sorts...
not even too make a kindle rendition of the squid virus :P
Then why not make update package which disables ota update? Update packages are more user-friendly than changing files via SSH and it should not be that hard to create.
mmatej is offline   Reply With Quote
Old 07-08-2012, 03:08 PM   #69
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by NiLuJe View Post
@mmatej: Nope, if it crashed, you wouldn't get the 'update successful' checkmark . And, yes, I meant progress bar handling, but it's just a hint given to the UI, it doesn't really hurt (The simple usbnet package does the same thing, for example).
So why it doesn't remove the key if it's successful? It's a big mystery for me...
mmatej is offline   Reply With Quote
Old 07-08-2012, 05:22 PM   #70
NiLuJe
BLAM!
NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.NiLuJe ought to be getting tired of karma fortunes by now.
 
NiLuJe's Avatar
 
Posts: 13,477
Karma: 26012494
Join Date: Jun 2010
Location: Paris, France
Device: Kindle 2i, 3g, 4, 5w, PW, PW2, PW5; Kobo H2O, Forma, Elipsa, Sage, C2E
@mmatej: Figured it out. Because the uninstall script isn't marked as an update script, so it isn't run by the update system. Hence nothing actually happening . (ID 128 instead of 129 in the bundlefile).

(For the curious: because it's a .sh and yifan's original kindletool wasn't marking .sh files as scripts, only .ffs).

Last edited by NiLuJe; 07-08-2012 at 05:25 PM.
NiLuJe is offline   Reply With Quote
Old 07-09-2012, 02:20 AM   #71
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by NiLuJe View Post
@mmatej: Figured it out. Because the uninstall script isn't marked as an update script, so it isn't run by the update system. Hence nothing actually happening . (ID 128 instead of 129 in the bundlefile).

(For the curious: because it's a .sh and yifan's original kindletool wasn't marking .sh files as scripts, only .ffs).
Thanks for figuring it out. I don't know much about update packages / updating process on Kindle.

Last edited by mmatej; 07-09-2012 at 02:23 AM.
mmatej is offline   Reply With Quote
Old 07-09-2012, 02:32 AM   #72
thomass
Wizard
thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.thomass ought to be getting tired of karma fortunes by now.
 
Posts: 1,669
Karma: 2300001
Join Date: Mar 2011
Location: Türkiye
Device: Kindle 5.3.7
you can also add the version numbers for the hacks.
thomass is offline   Reply With Quote
Old 07-09-2012, 03:04 AM   #73
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by thomass View Post
you can also add the version numbers for the hacks.
done
mmatej is offline   Reply With Quote
Old 07-09-2012, 03:17 AM   #74
ixtab
(offline)
ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.ixtab ought to be getting tired of karma fortunes by now.
 
ixtab's Avatar
 
Posts: 2,907
Karma: 6736092
Join Date: Dec 2011
Device: K3, K4, K5, KPW, KPW2
Woah... guys, it's not like I want to spoil the party. This is indeed a very nice project, and I'm seriously impressed (honest!).

However, it will necessarily come to an end, rather sooner than later. After all, you're exploiting a serious security flaw on the Kindle, which is on Amazon's radar, and which either has been fixed with that ominous 5.1.1 FW (which we're all craving for, but noone seems to have been able to publish yet), or will be fixed soon.

In fact, I don't understand at all how, a month after the publishing of such a gaping vulnerability (and they *were* alerted to it), Amazon can still not give a fuck about their customers', and their own security. I'm seriously puzzled.

The point is ... this security hole should have actually been closed yesterday - but it hopefully (from a security standpoint) will be closed soon.

All IMO of course, but just before you spend too much effort...

... just sayin'.

PS: just to make that clear again: I really DO appreciate your work -- I'm just wondering whether the effort will be well-spent in the long run.

Last edited by ixtab; 07-09-2012 at 03:29 AM.
ixtab is offline   Reply With Quote
Old 07-09-2012, 03:39 AM   #75
mmatej
Connoisseur
mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.mmatej is less competitive than you.
 
Posts: 91
Karma: 14730
Join Date: Jun 2012
Device: none
Quote:
Originally Posted by ixtab View Post
...
You are right, Amazon is very late about this issue. Maybe if we created "the Botnet", long time mentioned, but never really made, Amazon would react very quickly.
BTW, does Amazon know about this web jailbreak? As far as I know, it's the first practical use of the exploit. Maybe I should show off them
And about that effort... I know that with the next FW released, it won't work. But I've learned a lot of things from this project, so it wasn't that useless.
mmatej is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hacks Kindle (3) Keyboard : Upgrade and Jailbreak or Jailbreak and Upgrade?? prado Amazon Kindle 3 06-11-2021 10:13 PM
Kindle Fire Web Browser will likely allow for web based games. sirmaru Kindle Fire 10 11-15-2011 02:55 PM
problem browsing web, web's with many links? KRorschachZ Amazon Kindle 1 11-20-2010 02:05 AM
Web Standards for E-books by Joe Clark (web article) guyanonymous General Discussions 2 03-18-2010 10:36 PM
Mobile Web surfing on the rise says Face of the Web Alexander Turcic Lounge 2 04-20-2006 01:17 PM


All times are GMT -4. The time now is 04:12 PM.


MobileRead.com is a privately owned, operated and funded community.