Row hammer root method? (Now Dirty Cow)

hecksagon

Senior Member
Dec 15, 2010
231
119
0
Freeport, IL
Ram is made up of cells in a grid-like pattern inside of a chip. If you know the particular memory location of a specific piece of software you can access the rows above and below with certain patterns of memory accesses and writes. This causes specific bits in the target memory location to change their contents. If the software at that target location happens to handle privilege escalation... This does not rely on buggy software but underlying properties of the ram itself. Some mitigating strategies include address space layout randomization and full encryption of ram. ECC ram can also help with this if you use the error detection abilities to cause an instant device reset.
 

CygnusBlack

Senior Member
Feb 20, 2011
759
284
0
There's an app to check if you're vulnerable to the Hammer bug.
Devs stated that they've rooted the G4 exploiting it... So... Is there hope for bootloader locked devices after all?
 

LaughingCarrot

Senior Member
Jan 5, 2013
114
31
0
Now I'm a bit pessimistic about this mainly due to the fact that there have been several exploits since MM which didn't really help our situation. The only difference here is they've claimed that they were able to root our specific device using this method which is promising I suppose.
 

phonexpert_alex

Senior Member
Nov 29, 2007
163
25
48
Bremen
It does not do anything YET. The researchers said that they did not release the exploit and are not so inclined to do so. I got a warning about the apk being malicious. Maybe someone will create an app in good faith that will only root out phones.
EN: It was a statement. I know that it does nothing. It is just a test. It doesn't root your phone.
RO: Era o afirmatie. Doar intaream ideea ca e un test si ca nu ajuta cu nimic in cazul de fata (si anume la root).
 

th3y

Member
Oct 9, 2014
12
2
0
I want to use Drammer to root my phone. Where can I download the exploit code?

You cannot. We decided to not (yet) release the exploit. We did open source our templating code, however.


So, maybe we need to wait until November Security Patch Release.