Quadrooter affected

CmDaRkShAdOw

Senior Member
Jan 5, 2016
308
130
0
20
Kętrzyn
You are not infected, but affected. It is a big difference. Get a rom that is maintained, as opposed to abandoned....
Hmm..I'm using dstrikerz1 but sp001(the newest version is sp002, but I prefer that) update is planned..changing rom will help? I never met that virus, so I don't know what to do right now.
 

optimumpro

Senior Member
Jan 18, 2013
6,267
13,596
253
Hmm..I'm using dstrikerz1 but sp001(the newest version is sp002, but I prefer that) update is planned..changing rom will help? I never met that virus, so I don't know what to do right now.
I don't think you fully understand: the only way to patch the vulnerabilities is to change the code and re-build the rom. No stock rom can be build from sources by anyone, except OEM, because stock roms are closed source, i.e., code is not available. They can only be moded: delete an app, change wallpaper etc... . So, no matter how many more releases of moded stock roms can appear, none of them will include any security patches after the last official release, which was about the end of last year....
 
Last edited:

CmDaRkShAdOw

Senior Member
Jan 5, 2016
308
130
0
20
Kętrzyn
I don't think you fully understand: the only way to patch the vulnerabilities is to change the code and recompile the rom. No stock rom can be recompiled by anyone, except Sony, because stock roms are closed source, i.e., code is not available. They can only be moded: delete an app, change wallpaper etc... . So, no matter how many more release of moded stock roms can appear, none of them will include any security patches after the last official release, which was about the end of last year....
I didn't understand because I told you that this is my first time with this. Ehh so I must accept this... Thank for reply.
 

derf elot

Senior Member
May 7, 2011
817
1,706
0
The problem here is that most of these vulnerabilities (with the exception of the first, which is in the kernel) are inside proprietary files from qualcomm. So binaries which we don't have access to the source code to. Chances of this ever being fixed on our phones are pretty slim to none. The only chance might be the release of patched binaries for MM AOSP, which could then be used in custom (non-stock) ROMs.
 

Emperor.dk

Senior Member
Jul 27, 2011
774
913
93
Copenhagen
www.Emperor.dk
Also we all just needs to "Keep calm and carry on".

We are also all "affected" to be run down by a car in the street, but we some how don't get run down every day.

How: we don't walk out on the street in front of a car. We carefully look both sides first.

Just as we don't download and install unknown apps from unknown sources :)
 

Dethfull

Senior Member
Jun 4, 2016
259
28
0
This is A gpu error, only you need is to check new apks, and be sure that are safe, before installing.
Nothing bad.
Sent from my XT687 using xda premium

---------- Post added at 01:50 PM ---------- Previous post was at 01:49 PM ----------

[QuadRooter?]

http://forum.xda-developers.com/showthread.php?t=3435492

[QuadRooter?]

Sent from my XT687 using xda premium

---------- Post added at 01:51 PM ---------- Previous post was at 01:50 PM ----------

Qualcomm Vulnerability - Possible Root?

http://forum.xda-developers.com/showthread.php?t=3435425

Qualcomm Vulnerability - Possible Root?

Sent from my XT687 using xda premium

---------- Post added at 01:54 PM ---------- Previous post was at 01:51 PM ----------

They NEVER will update our roms, all they are piggest dollar bill, saying to buy a new CVE BUG ERRORED DEVICE (AFTER ONE YEAR EXACTLY)

:D

Sent from my XT687 using xda premium
 

optimumpro

Senior Member
Jan 18, 2013
6,267
13,596
253
The problem here is that most of these vulnerabilities (with the exception of the first, which is in the kernel) are inside proprietary files from qualcomm. So binaries which we don't have access to the source code to. Chances of this ever being fixed on our phones are pretty slim to none. The only chance might be the release of patched binaries for MM AOSP, which could then be used in custom (non-stock) ROMs.
Not true. They are all open source. In fact most Qualcomm's fixes are open source. Just because Google is lazy to reference sources and instead chooses to publish binaries, doesn't mean they are not open source. You just have to get them from Code Aurora directly.

Here they are:

CVE-2016-2059: https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=9e8bdd63f7011dff5523ea435433834b3702398d

CVE-2016-2503 and 4: https://www.codeaurora.org/use-after-free-due-race-conditions-kgsl-module-cve-2016-2504-cve-2016-2503

CVE-2016-5340: https://www.codeaurora.org/invalid-path-check-ashmem-memory-file-cve-2016-5340
 
Last edited:
  • Like
Reactions: derf elot

derf elot

Senior Member
May 7, 2011
817
1,706
0
Yes, I was mis-informed by an article I read yesterday.

I found those patches last night and made a new build. Funnily though, CVE-2016-5340 is still shown as unfixed in the program, but other people are having that problem as well it seems. So for now I'm blaming the App :)
 

Dethfull

Senior Member
Jun 4, 2016
259
28
0
This is why i suspect if this app haves a png inside , for when we open, display "device affected" by a fake scanner

:D





Sent from my XT687 using xda premium
 

optimumpro

Senior Member
Jan 18, 2013
6,267
13,596
253
Yes, I was mis-informed by an article I read yesterday.

I found those patches last night and made a new build. Funnily though, CVE-2016-5340 is still shown as unfixed in the program, but other people are having that problem as well it seems. So for now I'm blaming the App :)
The app and the whole Checkpoint's blog are nothing more than a deceitful commercial pitch for business customers. I don't think there is even a way to know whether vulnerabilities are fixed on a live device. It is all crap...

---------- Post added at 09:36 AM ---------- Previous post was at 09:31 AM ----------

This is why i suspect if this app haves a png inside , for when we open, display "device affected" by a fake scanner
Could you post the app please. We can expose Checkpoint if the app is fake....
 
  • Like
Reactions: Dethfull

Dethfull

Senior Member
Jun 4, 2016
259
28
0
You find this as Quadroot Scanner in goglebley store or 9apps store

If you read the checkpoint site, they explicitly are promoting goglebley store with this invalid argument :

"OnLy dOwnLoAD aPps fRoM goGleBlEy sToRe"

Lamentable!

:sly:

Sent from my XT687 using xda premium
 

gbr3h

Member
Aug 10, 2016
5
2
0
Just to be 100% sure: if I use a stock ROM (as we know there will be no updates...) the only way to protect myself is to:
  1. stop using it and use some custom ROM
  2. use some apk scanner (e.g. AVG), do not install from unknown sources, do not install suspicious apps (and "that's all")
So no way to e.g. somehow patch my ROM.
As a second question, I know that I can be hit by a car at any time but am I safe on a stock ROM? It is fast and works fine for me. Btw I would need some OS where I can download my company mails and things like that which need a "very secure environment"... and also a very stable one, as I know current Marshmallow ROMs for Z1 are unstable.
 

Dethfull

Senior Member
Jun 4, 2016
259
28
0
You don't need follow google craps, you may stay installing unknown source apks, by scanning after...



Sent from my XT687 using xda premium
 
Our Apps
Get our official app!
The best way to access XDA on your phone
Nav Gestures
Add swipe gestures to any Android
One Handed Mode
Eases uses one hand with your phone