Z2 Root Exploit

Search This thread

poo-tang

Senior Member
Nov 21, 2011
1,288
1,374
www.xperiagamer.com
@cubeundcube made binary to search ric_enable address and disable ric.
I tested it and it worked, I could remount system as rw!
Now he is creating script to automatically disable ric...
https://twitter.com/cubeundcube
.
Yes, I tried to copy su binary and it succeeded.
View attachment 2797571
I can't make it fully work thanks to my skill, but cubeundcube will do it!
.
Hmm, my data went crazy and It's night here...
Can someone test ric_disabler, which searches ric_enable address and automatically write 0?

Link for ric_disabler (GPL)
https://twitter.com/cubeundcube/status/477778282490781696

Place ric_disabler in /data/local/tmp.
ric_disabler needs root to work, so you should write the following commands in rootcmd.sh.
Code:
cd /data/local/tmp
chmod 0755 ric_disabler
./ric_disabler

Just quoting and notifying by mention @DooMLoRD as could help with his tool and quest for root.
 

RHBH

Senior Member
Apr 1, 2013
766
459
31
Sao Paulo
The best would be if @[NUT] implement an option on XZDualRecovery installer that is capable of install recovery on Z2 ?

Sent from my Xperia Z1 using Tapatalk Pro
 
Dec 1, 2011
25
8
@DooMLoRD's Windows script worked just fine to pull a TA.img backup.

Windows 8.
.55 firmware. (3 UK)

Now, I suppose the next step is to unlock bootloader, root and then restore the TA backup.

Here goes!
 

schnurzelat

Senior Member
Oct 20, 2007
54
5
su drop doesn't work for me. TA will be dumped, but remount failed. No su binary in xbin folder.

Another Issue: I dumped the TA partition several times now, but nearly every dump is different. Is that Ok?!
 
T

Tomcan

Guest
Nice job on the root! Too bad I rooted my Z2 some time ago w/ unlocked BL.
 

funky0308

Inactive Recognized Themer
Aug 27, 2012
7,029
5,681
Osijek
Anyone tried to install TWRP after updating su binaries (in v5)? @xsacha
Is that even possible in this moment?

I'm not sure something like that would even work, just asking...

Sent from my D6503 using Tapatalk
 
Last edited:

funky0308

Inactive Recognized Themer
Aug 27, 2012
7,029
5,681
Osijek
I'll try to release a new xzdualrecovery installer with this new rooting method as a secondary option as soon as I can. Probably tonight. That will also make it usable on any os and will disable ric at every boot as that's standard functionality in it's scripting.

You'll have to prepare firmware for 402 update or we could use Ben Ling prerooted flashable ROM?
I doubt it's "that easy" but who knows :)

Sent from my D6503 using Tapatalk
 

Top Liked Posts

  • There are no posts matching your filters.
  • 88
    Hey guys, this is a cross-post of sorts. I just got root execution on my stock Z2 Tablet and it appears that the same method should work for Z2 phone. I have a Z2 phone but just haven't tested it on that one yet.

    Here is my Windows, Linux and Mac OSX script to grab the TA partition from Sony devices and deploy full root (superuser + reboot script):
    https://mega.co.nz/#!jRB1FBJT!RKIi13TRj__mi7pKIGXP654CBJHi2gc0bIlYONcSfZQ [Update, v11]

    Requirements:
    1. Be on a firmware earlier than .402
    Instructions:
    1. Extract exploit.tar.gz and run ./root.sh (Linux) or root.bat (Windows)
    2. Follow the instructions and your TA.img will be given and su will be deployed.

    Features:
    This disables SELinux, takes out sony_ric and then deploys su to /system/xbin/su
    This works on ALL Sony Android mobile phones.
    This can be run on any operating system.
    Survives reboots [thanks to chargemon by DooMLoRD]
    41
    and its done!!! full root achieved! no more remount /system issues :)

    doing some final testing with @norti!
    38
    @xsacha

    great work!

    i am just cleaning up some of the code and making it more automated for a full root :)
    30
    Till the time I am figuring this out here is a windows port of the exploit...

    Download: exploitv4-TA_BACKUP-WINDOWS.7z


    its a bit cleaner... slightly more automated....

    just follow the instructions which come in the command prompt!

    it will automatically pull the TA.img too :)


    regards,

    DooMLoRD
    29
    and its done!!!


    tested on Xperia Z2 .69 & .55 firmwares!!!



    [FULL ROOT] Community Rootkit v01! (using ASEC vulnerability) [20140615]


    HUGE THANKS TO: xsacha, GranPC, DooMLoRD, norti, RyokoN, [NUT] & jcase


    file is now available for download!



    regards,

    DooMLoRD