Introducing XDA:DevCon – A Conference For Developers By Developers
XDA Developers Android and Mobile Development Forum
Forgot your password?
 
Post Reply+
Tip us?
 
GODZSON
Old
(Last edited by GODZSON; 6th November 2011 at 07:19 PM.)
#1  
GODZSON's Avatar
Retired Forum Moderator / Recognized Themer - OP
Thanks Meter 564
Posts: 1,498
Join Date: Jul 2007
Location: Earth

 
DONATE TO ME
Default HTC EVO VIEW Security Patch and updates

Thanks to Treve in Evo3D for his amazing work finding this security breach and sharing it with us, and the word reached HTC and now we have several security patches in Sprint via OTA to HTC Evo, HTC Evo3D, HTC Evo View and HTC Sensation.. may have more coming out to their line up.

10/25 Do not let it update itself. See attached pic. Reset will get it back to norm.


Just received in my EVO View a Sprint HTC update for security patch...
Total Download size: 4.63 MB






Here is link for download of the patch in zip file from HTC/Sprint:
http://www.wupload.com/folder/951541




Per Treve after viewing patch file I sent to him (Credits to Treve)

It looks like it deleted these files for you guys
Code:
 
       "/system/app/HtcLoggers.apk", "/system/app/HtcLoggers.odex",
       "/system/lib/libhtc_loggers.so",
       "/system/recovery.img");
But on our ota on the 3d it also deleted these files, id make sure you dont have them in your phone as well, especially the /data/data one, thats where the binaries for htcloggers live that made the exploit possible, an the other stuff is just garbage

Code:
delete_recursive("/data/data/com.htc.loggers/",
                 "/sdcard/htclog/");
       "/system/app/QXDM2SD.apk", "/system/app/QXDM2SD.odex",
       "/system/bin/androidvncserver", "/system/bin/usbnet",
       "/system/lib/libhtc_loggers.so", "/system/lib/libhtcqxdm2sd.so",
       "/system/recovery.img");
Everything i'm releasing I will be posting patches for - http://forum.xda-developers.com/show....php?t=1247108

Its the main thread and i wrote a scanner app at post 110 http://forum.xda-developers.com/show...&postcount=110

Im sure most of it will be the same on the HTC Flyer/ HTC EVO View.

Thank you again Treve.

Dev's lets take a look into the /data/data one, thats where the binaries for htcloggers as Treve indicates.. Let's get this worked out for our benefits
A dream becomes a goal when action is taken towards its achievement. - God Bless-






 
LeeDroid
Old
#2  
LeeDroid's Avatar
Recognized Developer
Thanks Meter 11425
Posts: 12,450
Join Date: Jan 2007
Location: Darlington

 
DONATE TO ME
My ROM is based on the fully patched build matey, got the ota last week

Sent from my LeeDrOiD loaded s-off HTC EVO 3D
Android Rom & Kernel Developer
HTC Desire, Desire HD, Sensation, EVO 3D, Flyer, One S & The One X
And yes.. I have them all, I only work on devices I can test on (perks of my job )

If you like my work and appreciate the 1000's of hours i have put in, please consider a small donation


Donate Via >> << Many Thanks

Please be aware, if you select the market option, Google take 30%


Follow me Twitter:@LeeDrOiD or LeeDrOiD ROMs on Facebook | To view my kernel source, visit @GitHub.com: LeeDroid-
Lee Bailey, Android ROM & Kernel developer!
 
GODZSON
Old
#3  
GODZSON's Avatar
Retired Forum Moderator / Recognized Themer - OP
Thanks Meter 564
Posts: 1,498
Join Date: Jul 2007
Location: Earth

 
DONATE TO ME
Quote:
Originally Posted by LeeDroid View Post
My ROM is based on the fully patched build matey, got the ota last week

Sent from my LeeDrOiD loaded s-off HTC EVO 3D
Would like to try yours out but mine is the Evo View, not many dev's have it... would be nice though, thx.
A dream becomes a goal when action is taken towards its achievement. - God Bless-






 
geebee1932
Old
#4  
geebee1932's Avatar
Senior Member
Thanks Meter 7
Posts: 103
Join Date: Nov 2007
Do you think that you can just flash the attached file from recovery?
 
GODZSON
Old
(Last edited by GODZSON; 28th October 2011 at 06:02 AM.)
#5  
GODZSON's Avatar
Retired Forum Moderator / Recognized Themer - OP
Thanks Meter 564
Posts: 1,498
Join Date: Jul 2007
Location: Earth

 
DONATE TO ME
Quote:
Originally Posted by geebee1932 View Post
Do you think that you can just flash the attached file from recovery?
Need to revert to Stock RUU and then do the update(s) once done the do root process again

In case you need the zip 1.22.651.1
OTA_Express_Sprint_WWE_1.22.651.1-1.18.651.1_release_198260xikterg48lc0snx1.zip

New Update-Security Patch 1.22.651.2
OTA_Express_Sprint_WWE_1.22.651.2-1.22.651.1_release_220183oqo49zm8mw3kfeuv.zip

Odd it shows 2.1 not 3.0
A dream becomes a goal when action is taken towards its achievement. - God Bless-






 
geebee1932
Old
#6  
geebee1932's Avatar
Senior Member
Thanks Meter 7
Posts: 103
Join Date: Nov 2007
I just flashed the ota zip through recovery. It worked fine no need to revert to stock. The View does not have sense 3.0. I think it has a modified sense 2.
 
GODZSON
Old
#7  
GODZSON's Avatar
Retired Forum Moderator / Recognized Themer - OP
Thanks Meter 564
Posts: 1,498
Join Date: Jul 2007
Location: Earth

 
DONATE TO ME
Quote:
Originally Posted by geebee1932 View Post
I just flashed the ota zip through recovery. It worked fine no need to revert to stock. The View does not have sense 3.0. I think it has a modified sense 2.
I flashed and no go on first attempt got the error as shown in first post.. HTC description is as sense 3.0 mostly do to the carousel I believe..
A dream becomes a goal when action is taken towards its achievement. - God Bless-






 
geebee1932
Old
#8  
geebee1932's Avatar
Senior Member
Thanks Meter 7
Posts: 103
Join Date: Nov 2007
I downloaded the OTA through GoodandEvo.com. I then booted into recovery and was able to flash. I did have to reflash the supersuer to get SU back however. My sense version was 2.1 before I began the update.

 
Post Reply+
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Go to top of page...

XDA PORTAL POSTS

Nandroid Manager Receives Major Update

Do you find yourself obsessively jumping from ROM to ROM? And do you hate having to restore a full … more

Careers in Android: Recruiter Reveals How Resumes are Chosen – XDA Developer TV

XDA Developer TV Producer Jayce released a video a … more

HttpClient Tutorial to Upload and Download with Your App

Developers wanting to interact with the Internet need to choose a package to do the … more

Profile Flow: A Tasker Alternative

By now, we’re all quite familiar with Tasker, the personal automation app that seems to be able to … more