Attend XDA's Second Annual Developer Conference, XDA:DevCon 2014!
5,736,817 Members 53,686 Now Online
XDA Developers Android and Mobile Development Forum

[PATCH/MOD] EnSec Enhanced Security + Operative w TWRP 20140318

Tip us?
 
Lokifish Marz
Old
(Last edited by Lokifish Marz; 2nd May 2014 at 05:34 PM.) Reason: New release
#1  
Lokifish Marz's Avatar
Recognized Contributor / Recognized Developer - OP
Thanks Meter 3258
Posts: 3,145
Join Date: Mar 2011
Location: Olympus Mons, Mars

 
DONATE TO ME
Default [PATCH/MOD] EnSec Enhanced Security + Operative w TWRP 20140318

ALL non-development related question need to be posted in the dedicated Q&A thread.Any future support questions posted here will be deleted.

Support Thread for the Root + Security Patch for the Umeox x201 (TrueSmart, AW-414/420, etc..)


The Q&A/T thread will usually have discussions about battery life, general questions, such as, "will this app work with this ROM", "can I use this kernel with it", "+1" and any other non-development related questions and topics.

Development on this project has stopped. Seeing it has failed as both a companion and standalone device, I have moved over to the S4 Zoom and Gear.

With Omate's lack of consistent access to firmware releases, proper source code, failure to fix firmware after months of being aware of the issues and countless other issues, it requires far more time than I am willing to sacrifice.


Umeox x201s (512/4 2100, 1/8 1900 ONLY) run in rootuser mode with no su or superuser checks in place. This allows malicious apps and someone with direct access to the x201 the ability copy all the users data, alter files and even going so far as to erase the IMEI and force the user to flash firmware to get to x201 even semi-functional.

For those that know a bit about rooting, this is NOT a insecure kernel (ro.secure=0) issue as the kernel is using ro.secure=1. The firmware is also more insecure that what most are used to seeing as they are not even a "user keys" but "test keys" engineering builds.

Additionally, the x201's have the following known security flaws (this is only a partial list)
CVE-2013-6271
CVE-2014-1600
Masterkey bug 9950697
MasterKey bug 10148049
Mempodroid
USSD Exploit



................. .........
IMAGES ARE FROM OPERATIVE. ENSEC IS EXACTLY LIKE STOCK EXCEPT FOR "SETTINGS"





Support Thread with Tips and Suggestions

EnSec + Operative 20140318 20140120 firmware ONLY!
ENHANCEMENTS
*Verified GPS working in airplane mode on both 2100 and 1900 TrueSmart (EU 512/4 2100 x201 will want to flash 20140120 working sensors firmware)
Custom default watch face (Operative ONLY)
Backs up all changes into a "Removed" folder on internal storage
Brightness fix (TrueSmart ONLY)
Full root
Fotabinder vulnerability fix (CVE-2014-1600)
OpenSSL
curl
MVNO patched APN's list
adware and malware hosts list
Internal Storage/SDCard Cache tweaks
Backs up all changes into a "Removed" folder on internal storage
build.prop tweaks
Governor tweaks
sysctl tweaks
Network tweaks
Dalvik tweaks
Memory usage tweaks
Ram tuning
9 to 11 days of clean standby
Auto brightness


REMOVED
AdupsFota
AdupsFotaReboot
MTKLogger
SystemUpdate
SystemUpdateAssistant
OUI 1.0 (Operative ONLY)
OUI 2.0 (Operative ONLY)
Bloat (Operative only, see list)
 
Code:
20140117_launcher_watch_822040a (OUI 2.0)
AdupsFota
AdupsFotaReboot
BasicDreams
DataTransfer
DownloadProviderUi
FacebookV3.9
Fleksy
Foursquare
Galaxy4
HoloSpiralWallpaper
HTMLViewer
InstagramV4.2.4
Launcher2
MagicSmokeWallpapers
MtkWorldClockWidget
NoiseField
PhaseBeam
PhotoTable
Protips
SkypeV4.4.0.34403
sonicemotionAbsolute3D
SystemUpdate
SystemUpdateAssistant
Todos
TwitterV4.1.10
VisualizationWallpapers
WeChatV5.0.3
WhatsAppV2.11.109


REPLACED
Settings
Custom Default Watchface (Operative ONLY)
Custom boot logo and animation (Operative ONLY)

ADDED
GravityBox (Operative ONLY)
Luxlite
PlayStore
OwatchON (TrueSmart ONLY)
ROMToolbox (Operative ONLY)
SuperSU
Custom Default Watchface (Operative ONLY)
Custom boot logo and animation (Operative ONLY)
Smart Launcher (Operative ONLY)
SmartLauncher Notifier (Operative ONLY)
SwipeStatusbar (Operative ONLY)
WP8 Launcher (Operative ONLY)
XposedInstaller (Operative ONLY)


DOWNLOAD HERE



EnSec + Operative Casual Edition 20140312 (thanks @AdamOutler)
512/4 2100 and 1/8 1900 ONLY!!!
ALL 512/4 2100 must flash EU 512-4 2100 20140120 working sensors.zip using SPTools
ALL 1/8 1900 must be on 20140120 firmware
  1. Install Koush's Universal ADB Drivers (Windows users)
  2. Install Java on your computer (Win/Lin/Mac)
  3. Download and extract "EnSec+Operative-CASUAL-Edition-20140318.zip"
  4. Double click "EnSec + Operative 20140318.jar"
  5. Follow the instructions
  6. DONE!


Credits:
My daughter, Her Imperial Highness Khalia Elaine
djrbliss (Motochopper Exploit) actually did need it seeing the firmware is unsecured but still used the script as a template
Koush (Universal ADB Drivers)
BSDgeek_Jake (hosts list)
Adam Outler (Casual)
Dees Troy (TWRP & Settings)
JASKRU (Asking Omate to send me TrueSmart)
Omate & Laurent Le Pen (Sending me a TrueSmart)
All the folks that have donated and supported my efforts in bring you a secure and improved firmware
Ubuntop- U4A/Webtop hybrid for all Tegra2 Motorola phones (Fully integrated Ubuntu Desktop)
Live ROM (One "ROM" over 12 phones) (Featured on XDA Portal and multiple other sites around the world and as base by many devs)
Imperium Initiative Photon (used as base by many Photon devs)
Imperium Initiative LS970 (used as base by many LS970 devs)
Imperium Agent LS970 (LS970 version of Live ROM)
Evo Desktop PC (Featured on XDA Portal and multiple other sites around the world)
(Nexus Q)uantum Singularity Project (Media Center, File Server, Website Server, LinuxonAndroid in little black ball of joy)
Umeox x201 EnSec Enhanced Security Patch and Live ROM Installer (used by multiple devs world wide on over 6 different models/versions of x201's)
Every Android device I've owned since the Hero- Media Center, File Server, Website Server
The Following 34 Users Say Thank You to Lokifish Marz For This Useful Post: [ Click to Expand ]
 
Lokifish Marz
Old
(Last edited by Lokifish Marz; 18th March 2014 at 03:50 PM.) Reason: New release
#2  
Lokifish Marz's Avatar
Recognized Contributor / Recognized Developer - OP
Thanks Meter 3258
Posts: 3,145
Join Date: Mar 2011
Location: Olympus Mons, Mars

 
DONATE TO ME
Version History


EnSec + Operative 20140318
Luxlite Auto Brightness
Reorganized items in all scripts
Fixed missing lines in installer script

EnSec + Operative 20140317
Increased security by removing ALL possible OTA related apps and MTKLogger
Added WP8 Launcher to Operative
Made EnSec closer to Stock Umeox Firmware
Made custom launcher and watchface Operative exclusive
Made Custom boot logo and animation Operative exclusive
Added OwatchON to TrueSmart specific builds (only works on 512/4 work sensors firmware)



EnSec + Operative 20140312 will make a proper change log later
*Verified GPS working in airplane mode on both 2100 and 1900 TrueSmart (EU 2100 x201 will want to flash 20140120 working sensors firmware)
All-In-One Casual installer with Windows, Linux and Mac support
All versions add Play Store and TWRP Custom Recovery
Operative adds GravityBox, ROM Toolbox, SmartLauncher, Swipe Statusbar xPosed Framework
Brightness fix (TrueSmart)
Full root
Fotabinder vulnerability fix
OpenSSL
curl
MVNO patched APN's list
adware and malware hosts list
Internal Storage/SDCard Cache tweaks
Custom default watch face
9 to 11 days of clean standby
Backs up all changes into a "Removed" folder on internal storage

Older Releases
 
EnSec 20010305 FINAL
*Verified GPS working in airplane mode on both 2100 and 1900 TrueSmart
*No bloat removal, Operative or undo
*Custom default watch face
*Working init.d and build.prop edits working so 9 to 11 days of clean standby
*Brightness fix (TrueSmart)
*Full root
*OpenSSL
*curl
*MVNO patched APN's list
*adware and malware hosts list
*Internal Storage/SDCard Cache tweaks

(if you have something other than a TrueSmart, delete the /system/framework before running)

EnSec Patch & Imperium Operative Installer 20140221
Switched to build date instead of version number
Changed name to "EnSec Patch & Imperium Operative Installer"
Readded build.prop tweaks
Brightness fix TrueSmart (TrueSmart specific)
All-In-One installer for EnSec security Patch and Imperium Operative for the x201 family of smartwatches
Backs up all changes into a "Removed" folder on internal storage
APN list updated
Adds Play Store, Swipe Statusbar
EnSec removes bloat (@150MB), adds Play Store, Swipe Statusbar
Imperium Installer removes even more bloat and adds CPUSpy, GravityBox, ROM Toolbox, SmartLauncher, xPosed Framework
Imperium Installer adds Martian Imperium boot logo and animation


v1.0.2
Fixed error in *nix script (Thanks Joe Avery for looking out for me)

v1.0.1
OpenSSL
cURL
Universal x201 Smartwatch Support
No longer includes build.prop enhancements to make usable for all the x201 family
Removes firmware specific requirements
Linux and Mac compatibility
adware and malware hosts list updated
Screen state switching (screen on=tuned hotplug, screen off=powersave)

v1.0.0 (Initial release)
Secures your ****
Properly rooted
Adds init.d support via workaround
Installs Loki All in One init.d script (OOM tweaks, SDCard Read Ahead increased to 3072KB, and more)
Updates busybox
Installs su
Installs SuperSU
Dalvik tweaks
Memory usage tweaks
Ram tuning
Enhanced protection against adware and malware
Ubuntop- U4A/Webtop hybrid for all Tegra2 Motorola phones (Fully integrated Ubuntu Desktop)
Live ROM (One "ROM" over 12 phones) (Featured on XDA Portal and multiple other sites around the world and as base by many devs)
Imperium Initiative Photon (used as base by many Photon devs)
Imperium Initiative LS970 (used as base by many LS970 devs)
Imperium Agent LS970 (LS970 version of Live ROM)
Evo Desktop PC (Featured on XDA Portal and multiple other sites around the world)
(Nexus Q)uantum Singularity Project (Media Center, File Server, Website Server, LinuxonAndroid in little black ball of joy)
Umeox x201 EnSec Enhanced Security Patch and Live ROM Installer (used by multiple devs world wide on over 6 different models/versions of x201's)
Every Android device I've owned since the Hero- Media Center, File Server, Website Server
The Following 8 Users Say Thank You to Lokifish Marz For This Useful Post: [ Click to Expand ]
 
BurnQc
Old
#3  
Junior Member
Thanks Meter 6
Posts: 22
Join Date: Apr 2010

 
DONATE TO ME
Does the Update OTA still activated ?

Could you explain what is suppose to secures on our TS ?
 
Lokifish Marz
Old
#4  
Lokifish Marz's Avatar
Recognized Contributor / Recognized Developer - OP
Thanks Meter 3258
Posts: 3,145
Join Date: Mar 2011
Location: Olympus Mons, Mars

 
DONATE TO ME
Quote:
Originally Posted by BurnQc View Post
Does the Update OTA still activated ?

Could you explain what is suppose to secures on our TS ?
It removes no features from the TS. So yes, OTA is still activated but cannot imagine why you would want that.
Ubuntop- U4A/Webtop hybrid for all Tegra2 Motorola phones (Fully integrated Ubuntu Desktop)
Live ROM (One "ROM" over 12 phones) (Featured on XDA Portal and multiple other sites around the world and as base by many devs)
Imperium Initiative Photon (used as base by many Photon devs)
Imperium Initiative LS970 (used as base by many LS970 devs)
Imperium Agent LS970 (LS970 version of Live ROM)
Evo Desktop PC (Featured on XDA Portal and multiple other sites around the world)
(Nexus Q)uantum Singularity Project (Media Center, File Server, Website Server, LinuxonAndroid in little black ball of joy)
Umeox x201 EnSec Enhanced Security Patch and Live ROM Installer (used by multiple devs world wide on over 6 different models/versions of x201's)
Every Android device I've owned since the Hero- Media Center, File Server, Website Server
 
kuronosan
Old
#5  
Senior Member
Thanks Meter 344
Posts: 1,418
Join Date: Nov 2008
Quote:
Originally Posted by BurnQc View Post
Does the Update OTA still activated ?

Could you explain what is suppose to secures on our TS ?
It secures you.

Sent from my Galaxy Nexus using Tapatalk 2
Click here to donate.
 
kyle_ken
Old
#6  
Junior Member
Thanks Meter 2
Posts: 6
Join Date: Jan 2009
Default Screenshots

First off, thanks for your hard work Lokifish!!!

Do you have any screenshots of this new root/enhanced security end result? Or is it just like this one you did http://forum.xda-developers.com/show....php?t=2549404

Thanks again for your work!!!
 
Lokifish Marz
Old
(Last edited by Lokifish Marz; 18th December 2013 at 03:53 PM.)
#7  
Lokifish Marz's Avatar
Recognized Contributor / Recognized Developer - OP
Thanks Meter 3258
Posts: 3,145
Join Date: Mar 2011
Location: Olympus Mons, Mars

 
DONATE TO ME
Quote:
Originally Posted by kyle_ken View Post
First off, thanks for your hard work Lokifish!!!

Do you have any screenshots of this new root/enhanced security end result? Or is it just like this one you did http://forum.xda-developers.com/show....php?t=2549404

Thanks again for your work!!!
Thanks. Two different projects. This is fairly invisible to the end user and removes nothing from the stock features, feel and functions. The only obvious difference is this add SuperSU.

Apparently it just got Omate Recommended Status
Ubuntop- U4A/Webtop hybrid for all Tegra2 Motorola phones (Fully integrated Ubuntu Desktop)
Live ROM (One "ROM" over 12 phones) (Featured on XDA Portal and multiple other sites around the world and as base by many devs)
Imperium Initiative Photon (used as base by many Photon devs)
Imperium Initiative LS970 (used as base by many LS970 devs)
Imperium Agent LS970 (LS970 version of Live ROM)
Evo Desktop PC (Featured on XDA Portal and multiple other sites around the world)
(Nexus Q)uantum Singularity Project (Media Center, File Server, Website Server, LinuxonAndroid in little black ball of joy)
Umeox x201 EnSec Enhanced Security Patch and Live ROM Installer (used by multiple devs world wide on over 6 different models/versions of x201's)
Every Android device I've owned since the Hero- Media Center, File Server, Website Server
The Following 2 Users Say Thank You to Lokifish Marz For This Useful Post: [ Click to Expand ]
 
kyle_ken
Old
#8  
Junior Member
Thanks Meter 2
Posts: 6
Join Date: Jan 2009
Thumbs up BTW Lokifish

Lokifish, you just got pimped on Omate's facebook page for this thread.
The Following 2 Users Say Thank You to kyle_ken For This Useful Post: [ Click to Expand ]
 
kuronosan
Old
#9  
Senior Member
Thanks Meter 344
Posts: 1,418
Join Date: Nov 2008
Oh good. Wait till they see what he does next.

Sent from my Galaxy Nexus using Tapatalk 2
Click here to donate.
 
tobitronics
Old
#10  
tobitronics's Avatar
Senior Member
Thanks Meter 34
Posts: 427
Join Date: Jan 2011
Location: The Hague

 
DONATE TO ME
Does this break OTA compatibility?

THREAD CLOSED
Subscribe
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes