Attend XDA's Second Annual Developer Conference, XDA:DevCon 2014!
5,779,301 Members 50,182 Now Online
XDA Developers Android and Mobile Development Forum

[DEV] ICS rooting for kernel 10 users

Tip us?
 
Nesquick95
Old
#1  
Member - OP
Thanks Meter 46
Posts: 82
Join Date: Jan 2009
Cool [DEV] ICS rooting for kernel 10 users

I finally did it...

http://forum.xda-developers.com/show...6#post25157446

Now let's wait for ICS and hope that Sony's one will be built on a "good" kernel.
Samsung Galaxy Nexus - JB 4.2.2 - rooted
Samsung Galaxy Tab 2 7" - Cyanogen Mod v9.1
The Following 6 Users Say Thank You to Nesquick95 For This Useful Post: [ Click to Expand ]
 
condi
Old
#2  
Senior Member
Thanks Meter 885
Posts: 680
Join Date: Feb 2007

 
DONATE TO ME
looks very promising, great work Nesquick
maybe in a week (or little more..) we could test it in practice!
keep up the good work

br
condi
Sony Tablet S/P/Xperia:
S.onyXT.S v1.0 [UNBRICKER] - Xperia Tab S auto unbrick tool!
S.onyTablet.S v6.5 [ALLinONE] - root for ICS, JB!
S.onyTablet.S v3.0 [FLASHER]
[FW R5A WIFI/3G] NEW! custom preROOTed newest stock nbx03 R5A with R1A's recovery!

Files mirror - My Google Drive

If u found this post useful, click on the 'thanks' button...
Like my work? Feel free to buy a pack of pampers for my baby
The Following 2 Users Say Thank You to condi For This Useful Post: [ Click to Expand ]
 
ssojyeti2
Old
#3  
ssojyeti2's Avatar
Recognized Themer
Thanks Meter 2643
Posts: 3,090
Join Date: Jan 2011
Location: North Miami Beach

 
DONATE TO ME
Not exactly sure what this does, but it seems important so good job
 
blambo
Old
#4  
blambo's Avatar
Member
Thanks Meter 22
Posts: 63
Join Date: Jul 2010
This should be very interesting. Thanks for continuing to stay with it.

Sent from my Sony Tablet S using xda premium
 
OCedHrt
Old
(Last edited by OCedHrt; 27th April 2012 at 01:21 PM.)
#5  
Senior Member
Thanks Meter 51
Posts: 648
Join Date: May 2009
Location: San Jose
Quote:
Originally Posted by Nesquick95 View Post
I finally did it...

http://forum.xda-developers.com/show...6#post25157446

Now let's wait for ICS and hope that Sony's one will be built on a "good" kernel.
But it seems we are unable to chmod without root. So this would require one of our rooted ICS friends to give us the offsets?

chmod not needed in recovery, but it doesn't get root:

Quote:
/sdcard/n95-offsets

n95-offsets by Nesquick95
Gets requiered offsets for mempodroid exploit

./mempodroid 0xd9ec 0xaf47 sh

1|@android:/system/bin $ /sdcard/mempodroid 0xd9ec 0xaf47 sh
/sdcard/mempodroid 0xd9ec 0xaf47 sh
1|@android:/system/bin $
 
Nesquick95
Old
#6  
Member - OP
Thanks Meter 46
Posts: 82
Join Date: Jan 2009
Default Too bad...

Well... That's the copy of a successful session, taken from my Galaxy Nexus (see image attached).
Too bad if the exploit doesn't root our ICS release.
Can you please post your run-as (/system/bin/run-as) binary ? I'll try to get the offsets another way.
Attached Thumbnails
Click image for larger version

Name:	n95-offsets.jpg
Views:	439
Size:	36.3 KB
ID:	1027552  
Samsung Galaxy Nexus - JB 4.2.2 - rooted
Samsung Galaxy Tab 2 7" - Cyanogen Mod v9.1
 
condi
Old
#7  
Senior Member
Thanks Meter 885
Posts: 680
Join Date: Feb 2007

 
DONATE TO ME
Quote:
Originally Posted by Nesquick95 View Post
Well... That's the copy of a successful session, taken from my Galaxy Nexus (see image attached).
Too bad if the exploit doesn't root our ICS release.
Can you please post your run-as (/system/bin/run-as) binary ? I'll try to get the offsets another way.
I've managed to run your bin, got offsets, but still no root...:

Code:
n95-offsets by Nesquick95
Gets requiered offsets for mempodroid exploit

./mempodroid 0xd9ec 0xaf47 sh

and then:

Code:
shell@android:/ $ /data/local/tmp/mempodroid 0xd9ec 0xaf47 sh
/data/local/tmp/mempodroid 0xd9ec 0xaf47 sh
1|shell@android:/ $
Sony Tablet S/P/Xperia:
S.onyXT.S v1.0 [UNBRICKER] - Xperia Tab S auto unbrick tool!
S.onyTablet.S v6.5 [ALLinONE] - root for ICS, JB!
S.onyTablet.S v3.0 [FLASHER]
[FW R5A WIFI/3G] NEW! custom preROOTed newest stock nbx03 R5A with R1A's recovery!

Files mirror - My Google Drive

If u found this post useful, click on the 'thanks' button...
Like my work? Feel free to buy a pack of pampers for my baby
The Following User Says Thank You to condi For This Useful Post: [ Click to Expand ]
 
Nesquick95
Old
#8  
Member - OP
Thanks Meter 46
Posts: 82
Join Date: Jan 2009
Default Really too bad

Sony's ICS is built on kernel 2.6.39, normally rootable by this exploit... Maybe they have patched it...
Need a copy of /system/bin/run-as binary to try finding offsets another way, as a last chance. My tablet hasn't got the update (unrootable kernel 10 - French region)
Samsung Galaxy Nexus - JB 4.2.2 - rooted
Samsung Galaxy Tab 2 7" - Cyanogen Mod v9.1
The Following User Says Thank You to Nesquick95 For This Useful Post: [ Click to Expand ]
 
OCedHrt
Old
#9  
Senior Member
Thanks Meter 51
Posts: 648
Join Date: May 2009
Location: San Jose
Binary attached.

Since we're unable to chmod under normal boot (operation not permitted), the only way is to run under recovery. Is it possible that mempodroid doesn't work under recovery?
Attached Files
File Type: zip run-as.zip - [Click for QR Code] (42.0 KB, 66 views)
The Following 3 Users Say Thank You to OCedHrt For This Useful Post: [ Click to Expand ]
 
Nesquick95
Old
(Last edited by Nesquick95; 27th April 2012 at 11:35 PM.)
#10  
Member - OP
Thanks Meter 46
Posts: 82
Join Date: Jan 2009
Default The worst thing that could happend

I don't know if running in recovery can make mempodroid fail... It probably doesn't. But as you can see, Condi has run n95-offsets in "regular" /data/local/tmp without success.

I have verified the offsets in the run-as binary posted with IDA disassembler, the offsets returned by n95-offsets are the good ones.

I think Sony's 2.6.39 kernel is patched, the exploit won't work...



(Maybe) we will find an other one (some day)...
Samsung Galaxy Nexus - JB 4.2.2 - rooted
Samsung Galaxy Tab 2 7" - Cyanogen Mod v9.1

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes