[BOUNTY] New Root Method Exploit or Full Bootloader Unlock ***Updated Daily***

Status
Not open for further replies.
Search This thread

jcase

Retired Forum Mod / Senior Recognized Developer
Feb 20, 2010
6,308
15,761
Raleigh NC
Since when? I thought people who took ota currently had no method to obtain root. Im not requesting it nor want it but just curious because I havent seen this mentioned.

Sent from my SCH-I545 using xda app-developers app

Just because root has not been released, does not mean it has not been accomplished.

Gaining root on a device is generally far easier than unlocking/hacking the bootloader and really shouldn't be stressed on
 

matt_1224

Member
Nov 1, 2010
45
17
Personally I believe that it won't be to long before someone unlocks the bootloader. If they havn't already.

Sent from my SCH-I605 using xda premium
 

Surge1223

Recognized Contributor
Nov 6, 2012
2,622
7,466
Florida
Google Pixel 6 Pro
Just because root has not been released, does not mean it has not been accomplished.

Gaining root on a device is generally far easier than unlocking/hacking the bootloader and really shouldn't be stressed on

I agree entirely. Its just when you were responding lolzadam, you said he was in incorrect. I don't know though since you said it hasnt been released then I guess there isn't a way to make it happen for people, unless as you implied, they accomplish it themselves.
 

dobo84

Senior Member
Mar 22, 2011
399
77
Seriously people quit probing.... in case you can't take the many hints dropped root has been or is not a issue obtaining. If you read Jcase's replies he states this more than once. Be patient let things become stable. Everyone is acting like this is the last device to be made.... The crave to have and the need is a fine line :good:

Sent from my SCH-I545 using Tapatalk 4 Beta
 

10ECN

Member
May 23, 2013
16
11
Seriously people quit probing.... in case you can't take the many hints dropped root has been or is not a issue obtaining. If you read Jcase's replies he states this more than once. Be patient let things become stable. Everyone is acting like this is the last device to be made.... The crave to have and the need is a fine line :good:

Sent from my SCH-I545 using Tapatalk 4 Beta

+1. Read, Learn, then DO or WAIT.
 

Galaxys4bean

Senior Member
Jul 13, 2013
84
11
I i was a developer i would wait until the bounty grows huge before i release anything. There may be a dev that already has the exploit but wants to wait for the bounty to get bigger. Maybe you should close the bounty at 2000-3000? If it goes that far!
Please no hate, just a suggestion.
 
  • Like
Reactions: ogredeschnique

318sugarhill

Senior Member
Aug 31, 2010
813
223
I i was a developer i would wait until the bounty grows huge before i release anything. There may be a dev that already has the exploit but wants to wait for the bounty to get bigger. Maybe you should close the bounty at 2000-3000? If it goes that far!
Please no hate, just a suggestion.

Just my opinion but while there may be financial gain involved, I don't believe developers primary motivation for what they do is money. I'm not saying people won't respond to a bounty but if a way is possible, with or without a bounty a way is likely to be found. The primary goal of a bounty is to help entice one with the skills to focus their attention our way. Just take a look at this site. Many devs work in teams.....and also have friendly (and possibly unfriendly:silly:) competition with others. If you had a way and were sitting on it for a bounty pot to get bigger, you run the risk of losing out to someone who beats you to the punch.

I only encourage anyone on xda who has/will use it to add to the bounty.
 
  • Like
Reactions: nnnnr14
J

jetlitheone

Guest
I cannot see how anyone can do the bootloader unlock. Its not confirmed but most likely a QFuse is blown and unless something leaks or miraculously qualcomm has another exploitable method

Sent from my SAMSUNG-SGH-I337 using Tapatalk 2
 

open1your1eyes0

Senior Member
Dec 13, 2010
2,651
3,671
New York City
I cannot see how anyone can do the bootloader unlock. Its not confirmed but most likely a QFuse is blown and unless something leaks or miraculously qualcomm has another exploitable method

Sent from my SAMSUNG-SGH-I337 using Tapatalk 2

Through root, things will be had, it might just take a few steps but the result is possible. That's why it's very important that we get root and recovery first. Unlock will be possible down the road after that.
 
Last edited:

durrell12

Member
Mar 4, 2010
35
5
Raleigh
It seems ridiculous to me to say "root is possible" and "root is easy, we just want unlocked bootloader" and then not share the root exploit. Considering soft root isn't linked to the unlocked bootloader at all, why not go ahead and help those of us out who could care less about an unlocked bootloader?

I'd be perfectly happy with soft root and a locked bootloader if it's all I could have, as I'm sure other ME7 users would.

I stupidly un-rooted and updated thinking root/loki (or some equivalent) would be relatively easy to obtain with time considering the size of the GS4 user base, but now I'm getting worried. And the ridiculous fighting in this thread isn't making me feel much better. There's no reason to have a ... measuring contest around here. It's pretty clear who knows what.
 
Last edited:

jcase

Retired Forum Mod / Senior Recognized Developer
Feb 20, 2010
6,308
15,761
Raleigh NC
It seems ridiculous to me to say "root is possible" and "root is easy, we just want unlocked bootloader" and then not share the root exploit. Considering soft root isn't linked to the unlocked bootloader at all, why not go ahead and help those of us out who could care less about an unlocked bootloader?

I'd be perfectly happy with soft root and a locked bootloader if it's all I could have, as I'm sure other ME7 users would.

I stupidly un-rooted and updated thinking root/loki (or some equivalent) would be relatively easy to obtain with time, but now I'm getting worried. And the ridiculous fighting in this thread isn't making me feel much better. There's no reason to have a ... measuring contest around here. It's pretty clear who knows what.

Actually, it would be stupid to share one before the other was ready, when the other likely requires the first. Why you might ask? Because they could patch the root before the bootloader was done. Of course people always complain about work that doesn't belong to them, no matter what.
 

open1your1eyes0

Senior Member
Dec 13, 2010
2,651
3,671
New York City
It seems ridiculous to me to say "root is possible" and "root is easy, we just want unlocked bootloader" and then not share the root exploit. Considering soft root isn't linked to the unlocked bootloader at all, why not go ahead and help those of us out who could care less about an unlocked bootloader?

There are reasons root exploits are not always shared (especially for free). Believe it or not but sources other than people who use the devices value root exploits as well (in almost all cases at a far pricier payout too).

There's no reason to have a ... measuring contest around here. It's pretty clear who knows what.

This! :good:
 

durrell12

Member
Mar 4, 2010
35
5
Raleigh
Actually, it would be stupid to share one before the other was ready, when the other likely requires the first. Why you might ask? Because they could patch the root before the bootloader was done. Of course people always complain about work that doesn't belong to them, no matter what.

I'm not complaining. I don't know enough about it (yet) to really say one way or the other. But I've been around long enough to know my fair share.

I was under the impression that obtaining root at the ROM level wouldn't be affected by the bootloader at all. Obviously you know more about it than me, so care to explain to the rest of us how the bootloader and root at that level is linked?

I think the majority of us are here to learn, so any guidance is appreciated.
 
Status
Not open for further replies.

Top Liked Posts

  • There are no posts matching your filters.
  • 58
    Samsung Galaxy S4

    (Live in a world of infinite possibilities)


    aQmpOr9.jpg


    Bounty Details

    So as we all know, the new VRUAME7 update that came out on July 9th (initially starting as just an update via Samsung Kies or the Verizon Upgrade Assistant) and the following day releasing as an official OTA for everyone has officially broken the current root method that is available. The reason being is the new bootloader now prevents you from flashing the VRUAMD2 pre-release kernel (or any kernel for that matter) and even prevents you from downgrading the bootloader itself back to the original VRUAMDK firmware that came on our devices. As a result, everyone that has received this update has officially lost root (no surprise there), with no way of getting root back at the moment (slightly surprising there but ultimately not).

    Since this is XDA, a vast percentage of us here desperately need root for many of our apps and mods that we use on a daily basis (including myself), not to mention custom recoveries so we could flash custom ROMs and such. It is now very critical that we (at the minimum) get root access back on this new firmware as soon as possible. As a result of this necessity, I would like to personally offer a $100 bounty to the first person able to find or create a method, exploit, or unlock that allows us to fully root and provide the necessary steps for rooting the Verizon Galaxy S4 here on XDA. I know it may not be much but seeing as how the previous root exploit was provided for free impressively quick with a huge thanks to Dan Rosenberg, I am hoping this small bounty will be able to motivate a few advanced developers or security experts to attempt and do likewise on this new highly secure update for our devices.

    Whoever you are, you will be doing us and many other upcoming owners of this device a great justice and for that consider this as a token of my appreciation. I also greatly encourage and welcome anyone else willing to chip in to this bounty to post here and I will have the OP updated of all users' donations to this request.

    Greatly looking forward to anyone interested in becoming a candidate.


    Root and Recovery Bounty

    ***Root (alone) has been achieved***

    Link here


    Requirements


    1. Be the first person to create or find a method to achieve the following:

      • Exploiting a fully stock VRUAME7 build to get root and custom recoveries (loki or new method)
    2. Make a post in this thread with the following:
      • Proving it works with appropriate photos and/or screenshots
      • Providing full step-by-step instructions for which anyone else can follow
    3. Wait for at least one member to follow the same method and confirm it works the same on their fully stock device with VRUAME7 build
    4. Claim your bounty via PM from donator(s)
    Payment will be processed between each member and the bounty collector via PM on an individual basis.


    List of Donators

    • Open1Your1Eyes0 - $100
    • skiddingus - $10
    • cresny - $20
    • 10ECN - $10
    • jignasze - $20
    • tbcpn - $10
    • beanstown106 - $10
    • 318sugarhill - $20
    • 808phoneaddict - $20
    • h_10 - $20
    • owenbeals - $10
    • Mayze23 - $10
    • killer2239 - $20
    • dobo84 - $10
    • Dubbsy - $10
    • shuddle13 - $20
    • theresin - $10
    • Tsukasa Buddha - $20
    • pstgh - $10
    • SmokeyMon - $25
    • asdecker - $20
    • cd23murray - $15
    • drunkfatjew - $25
    • sshams95 - $25
    • bobby janow - $20
    • cordell12 - $10
    • an21281 - $20
    • bigryanb - $10
    • bfmetcalf - $20
    • yankzfan007 - $20
    • milenkosmagic - $10
    • bajasur - $10
    • mikekid7 - $20
    • iwearthebelt - $20
    • dstreng - $10
    • niv3d - $10
    • rdcamero - $10
    • droidrev71 - $20
    • Delakit - $10
    • matt_1224 - $200 :good:
    • loveEA - $10
    • lsneekerpimpz - $10
    • Easton999GS - $20
    • mentosone - $40
    • Bait-Fish - $20
    • brycekerr - $20
    • joshw0000 - $10
    • Dragonsla - $10
    • Protibus - $20
    • kvswim - $5
    • Ryno77 - $10
    • SirLance99 - $20
    • ogredeschnique - $100
    • shortstuff_mt - $10
    • topolovich - $20
    • kcl71 - $25
    • lolzadam - $20
    • tkacer - $25
    • moldmaker1 - $25
    • DarkMenace - $25
    • d.ouyang - $30
    • Bloodcrav - $20
    • Rizon216 - $20
    • r1ndr3w - $15
    • jacksonpeebles - $15
    • JamesPumaEnjoi - $20
    • darmot7 - $10
    • dorioo - $20
    • jorceshaman - $25
    • dirtyfingers - $10
    • ilkevinli - $25
    • heyazzo - $25
    • Unicorn512 - $25
    • R4NDR01D - $5
    • sstingrae - $10
    • obstinate1 - $10
    • Redflea - $10
    • rlivin - $10
    • lmalinofsky - $50
    • jessrbird - $20
    • patience1 - $20
    • delaneybob - $30
    • hoboballer - $10
    • m3Jorge - $10
    • johnc0865 - $20
    • kanostic - $50
    • markanthonyjohn - $10
    • randy hoopes - $25
    • Shotjas - $25
    • Rhodesy757 - $10
    • morgej - $20
    • wrecklesswun - $100
    • bhp090808 - $10
    • chiaggie03 - $10
    • tech-ninja - $10
    • tee00max - $20
    • dougshepard - $20
    • jeromeh - $10
    • Sim-X - $20
    • jova33 - $20
    • TTcell - $30
    • prsterero - $30
    • mikedgre - $10
    • ViperGeek - $60
    • Antdagod - $50
    • bjbinc - $100
    • acheong87 - $20
    • Saber - $20
    • Verdictator - $5
    • Tammy661 - $10
    • gadget! - $25
    • jettadieselguy - $10
    • rtc1036 - $20
    • Chopes - $50
    • udmatador - $20
    • maretus - $20
    • jwick2866 - $25
    • Pro Toucher - $10
    • djsiva - $10
    • mlin - $15
    • xXPrOwLeRXx - $5
    • afmracer6 - $30
    • pheitmeyer - $10
    • ddemlong - $10
    • chunger - $20
    • lastfreedom - $50
    • thornev - $20
    • GreenGoblin227 - $10
    • AsaSpades - $10
    • jlegros - $20
    • MecDjino - $10
    • ncope562 - $10
    • darthmuffin - $10
    • jab476 - $20
    • Nathanias - $15
    • flanger001 - $10
    • TheSavageSquid - $10
    • dvsgod - $15
    • fordmanck - $20
    • jackwagon06 - $10
    • fenguepay - $25
    • waltersobchak96 - $20
    • andybones - $20
    • pschatz12 - $100
    • Covert_Death - $10
    • resurektz - $10
    • jbis - $20
    • TheJ0hnman - $100
    • clemente718 - $40
    • thelink12 - $20
    • soad1789 - $35
    • samiamapirate - $30
    • mu5a5hi - $10
    • SilverCi - $100
    • _base2 - $50
    • ruffneckZeVo - $200 :good:
    • sppatel - $10
    • jpl81905 - $20
    • T3HBR1AN - $20
    • TheWhiteChallenger - $10
    Total Donations - $3,965


    Full Bootloader Unlock + Root/Recovery Bounty

    ***Root (alone) has been achieved***

    Link here


    Requirements


    1. Be the first person to create or find a method to achieve the following:

      • Unlocking, exploiting, or patching the bootloader on a stock VRUAME7 device, to get root and custom recovery as well (never yet achieved)

        ***A workaround like Loki or similar does not qualify for this bounty***
    2. Make a post in this thread with the following:
      • Proving it works with appropriate photos and/or screenshots
      • Providing full step-by-step instructions for which anyone else can follow
    3. Wait for at least one member to follow the same method and confirm it works the same on their fully stock device with VRUAME7 build
    4. Claim your bounty via PM from donator(s)
    Payment will be processed between each member and the bounty collector via PM on an individual basis.


    List of Donators

    • Open1Your1Eyes0 - $100
    • skiddingus - $10
    • cresny - $20
    • 10ECN - $10
    • jignasze - $20
    • tbcpn - $10
    • beanstown106 - $100
    • 318sugarhill - $20
    • 808phoneaddict - $20
    • h_10 - $20
    • owenbeals - $10
    • Mayze23 - $10
    • killer2239 - $20
    • dobo84 - $25
    • Dubbsy - $25
    • shuddle13 - $20
    • theresin - $50 (includes bonus item)
    • Tsukasa Buddha - $20
    • pstgh - $10
    • SmokeyMon - $25
    • asdecker - $20
    • cd23murray - $30
    • drunkfatjew - $25
    • sshams95 - $25
    • bobby janow - $20
    • cordell12 - $20
    • an21281 - $20
    • bigryanb - $20
    • bfmetcalf - $20
    • yankzfan007 - $20
    • milenkosmagic - $10
    • bajasur - $100
    • mikekid7 - $100 (includes bonus item)
    • iwearthebelt - $20
    • dstreng - $10
    • niv3d - $10
    • rdcamero - $10
    • droidrev71 - $50
    • Delakit - $10
    • matt_1224 - $200 :good:
    • loveEA - $10
    • lsneekerpimpz - $10
    • Easton999GS - $50
    • mentosone - $40
    • Bait-Fish - $40
    • brycekerr - $20
    • joshw0000 - $20
    • Dragonsla - $10
    • Protibus - $20
    • kvswim - $10
    • Ryno77 - $30
    • SirLance99 - $20
    • ogredeschnique - $100
    • shortstuff_mt - $10
    • topolovich - $20
    • kcl71 - $25
    • lolzadam - $40
    • tkacer - $25
    • moldmaker1 - $25
    • DarkMenace - $25
    • d.ouyang - $30
    • Bloodcrav - $70
    • Rizon216 - $20
    • r1ndr3w - $15
    • jacksonpeebles - $15
    • JamesPumaEnjoi - $20
    • darmot7 - $10
    • dorioo - $20
    • jorceshaman - $100
    • dirtyfingers - $20
    • ilkevinli - $50
    • heyazzo - $25
    • Unicorn512 - $25
    • R4NDR01D - $5
    • sstingrae - $10
    • obstinate1 - $10
    • Redflea - $10
    • rlivin - $10
    • lmalinofsky - $100
    • jessrbird - $20
    • patience1 - $20
    • delaneybob - $30
    • hoboballer - $10
    • m3Jorge - $20
    • johnc0865 - $40
    • kanostic - $50
    • markanthonyjohn - $20
    • randy hoopes - $25
    • Shotjas - $25
    • Rhodesy757 - $10
    • morgej - $20
    • wrecklesswun - $100
    • bhp090808 - $100
    • chiaggie03 - $10
    • tech-ninja - $10
    • tee00max - $20
    • dougshepard - $30
    • jeromeh - $20
    • Sim-X - $50
    • jova33- $50
    • TTcell - $30
    • prsterero - $30
    • mikedgre - $10
    • ViperGeek - $75
    • Antdagod - $50
    • bjbinc - $100
    • acheong87 - $20
    • Saber - $20
    • Verdictator - $5
    • Tammy661 - $10
    • gadget! - $25
    • jettadieselguy - $20
    • rtc1036 - $20
    • Chopes - $50
    • udmatador - $50
    • maretus - $20
    • jwick2866 - $50
    • Pro Toucher - $10
    • djsiva - $10
    • mlin - $30
    • xXPrOwLeRXx - $5
    • afmracer6 - $30
    • pheitmeyer - $10
    • ddemlong - $20
    • chunger - $20
    • lastfreedom - $50
    • thornev - $20
    • GreenGoblin227 - $10
    • AsaSpades - $10
    • jlegros - $20
    • MecDjino - $75
    • ncope562 - $10
    • darthmuffin - $50
    • jab476 - $20
    • Nathanias - $15
    • flanger001 - $10
    • TheSavageSquid - $15
    • dvsgod - $15
    • fordmanck - $20
    • jackwagon06 - $10
    • fenguepay - $25
    • waltersobchak96 - $50
    • andybones - $20
    • pschatz12 - $100
    • Covert_Death - $10
    • resurektz - $10
    • jbis - $20
    • TheJ0hnman - $100
    • clemente718 - $40
    • thelink12 - $20
    • soad1789 - $35
    • samiamapirate - $100
    • mu5a5hi - $10
    • SilverCi - $100
    • _base2 - $50
    • ruffneckZeVo - $200 :good:
    • sppatel - $20
    • jpl81905 - $20
    • T3HBR1AN - $20
    • TheWhiteChallenger - $20
    Total Donations - $5,120


    Disclaimer

    • Please note before making a post in the thread please refer to this post to see if your post will be acceptable. If it is not part of this list, your post will be reported and you may risk getting an infraction as per forum moderators.

    • Please note if you do not explicitly state separate prices for root/recovery and full bootloader unlock bounties, your contribution of the same price will be add to both lists.

    • Please note you may not submit a contribution for only ONE bounty. If you post a contribution, one price will be applied to both bounties unless separate prices are explicitly stated.

    • Please note you do not have to pay for both bounties separately. Whichever bounty gets fulfilled first is the one that you pay for upon collection. This is why your contribution is added to both lists automatically.

    • Please note you may not make any specific restrictions or requirements that aren't listed in the OP. By making a post with your contribution price you are agreeing to paying out based on all terms listed in OP only and nowhere else.

    • Please note once you make a post with your contribution you may not withdraw it at any time and are responsible for paying out once the bounty is claimed. The only changes that can be made are another post raising the prices if you choose so. Please make sure you read everything carefully. No exceptions!

    • Please be advised that if Verizon or Samsung is to release an official method of unlocking the bootloader (extremely unlikely but must be accounted for) prior to any member of XDA's submission, this bounty automatically becomes invalidated.
    32
    First Samsung device however, and most surprising of all the fact that this time around even using official firmware downgrades are blocked (the whole issue here and reason starting this thread was necessary). But regardless as others have stated, please do not spend time on a post if your post is only going to contain insults. We need support here not criticism. What's done is done and I'm sure everyone here knows the mistake they made (even though to what extent this was a bit surprising).

    Seriously, this is ridiculous. The only real excuse is if someone bought or otherwise received a new device with the new update already on it.

    When Motochopper was published, I included this warning:

    As always, future OTA updates may remove the ability to regain root access, so proceed with caution when updating.

    When Loki was published, I included this warning:

    Can this be patched?

    Absolutely. Any update that includes a new aboot will almost definitely cause your custom kernel or recovery to fail to boot without running it through loki_patch again, and if the update contains a fix for the vulnerability Loki exploits, it may permanently prevent using the tool. It's possible for Samsung to ship an update that prevents downgrading aboot to a vulnerable version, so I recommend avoiding installing any OTA updates without confirmation that it's safe.

    This is not the first Samsung device to be locked on Verizon (see Galaxy S3 and Galaxy Note 2). This is not the first device capable of preventing downgrading. You're allowed to be upset at these restrictions, but you shouldn't be surprised, because the reality is most of the people in this thread just weren't paying attention and paid the price for ignoring what people have repeatedly warned. You should have known this device was going to be locked in the first place, and you should have known that applying an OTA update would prevent rooting or using Loki. Ignorance is no excuse.

    As for achieving root, I'd say it's fairly embarrassing that at least two public exploits will work on this device, and no one can even get those working. Hint: the perf_event_open() exploit and the second Android "master key" exploit both affect this device. If the entire community can't even get two existing exploits working for a device, I don't have a lot of faith in its ability to find and exploit a new flaw in the bootloader.
    28
    I know I'm late to join the game and honestly won't make much use of it but I'll donate 15$ to the man responsible for this root method :)

    No donations necessary (to ME, I won't speak for DooMLoRD as I don't even know the guy. However, if you DID want to donate to someone he would be much more appropriate). I just happened to be in a position where I could make a minor contribution to the overall effort.

    I did not discover the vulnerability (this has been around quite a while), nor did I write the exploit - DooMLoRD generously posted his work for others to modify.

    Which I did. So it worked out, team effort!
    26
    Guys, I can officially confirm we have root access, thanks to PWM978's modification of DooMLoRD's exploit

    See my personal results below as a tester on my stock VRUAME7 build:

    XbR473p.png


    Next step is beanstown106 is working on fixing his CASUAL application to make an easy one-click method for this exploit.

    Remember the bounty is for root AND recovery. So nobody give your contributions just yet because when the person who creates the recovery method is going to collect, you will be responsible for submitting that contribution to them.
    20
    Guys, I'm going to have to ask everyone to prevent any posts not directly related to the bounty, questions about development, or assistance in development for any of the topic-related methods. This thread is getting too large and will become an unorganized off-topic mess if we carry on with general posts about criticism of each other, Verizon, Samsung, or anything else related or unrelated. From now on, please remember if your post is not on topic, it will be submitted for deletion. To keep this thread as clean as possible I'm going make a list below of acceptable posts and I'd like to ask anyone that sees a post not part of the list below to click the report button on the post so it gets deleted as soon as possible. I appreciate everyone's assistance and cooperation to keep this thread on topic.

    Respectfully,
    Open1Your1Eyes0


    List of acceptable posts
    • New bounty submission or increase of current bounty
    • Questions or assistance in development of a root, recovery, or bootloader unlock method
    • Questions and answers regarding bootloaders on this device
    • Questions and answers regarding the nature of lockdown on this device
    • Questions and answers regarding eFuse/qFuse and emmc write-protects
    • Questions and answers regarding kernel and bootloader-related exploits
    • If you're working on such a method then any status updates you have on it
    Remember, absolutely NO criticism is allowed of any kind.

    If you're not sure if what you're about to post fits into the description of one of the above please PM me and I will give you a simple yes or no answer. Upon that answer you may submit or withhold your post.