Skip to content

[FEATURE] Shell password #305

Description

@hiruocha

sorry chinese, i cant use translator now

我注意到目前从应用进入容器的shell是不需要任何权限验证的,哪怕是root shell

通常,类原生系统(aosp based roms)并没有应用锁功能,如果只用锁屏密码来保护一个几乎完整的root权限,我认为是不够安全的

所以,我希望在应用内打开shell前可以做一个验证,无论是验证容器内用户密码,还是走安卓锁屏密码或生物识别,都可以

Activity

  1. Re-s commented on Sep 7, 2026

    @Re-s

    这几乎没有意义,rootfs本身就在/data/local/里面,真要访问可以直接通过rootfs原始路径,不需要经过app。

  2. hiruocha commented on Sep 7, 2026

    @hiruocha
    Author

    我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)

  3. Re-s commented on Sep 7, 2026

    @Re-s

    我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)

    应该是没的,adb shell除非用户在已经对shell设置root权限,正常情况下对/data/local目录下的文件没有执行权限。

  4. hiruocha commented on Sep 7, 2026

    @hiruocha
    Author

    我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)

    应该是没的,adb shell除非用户在已经对shell设置root权限,正常情况下对/data/local目录下的文件没有执行权限。

    但需要注意:Droidspaces有一个选项,允许将二进制文件链接到/system/bin下,这时候就在普通用户的shell的PATH里了

    我不是特别了解,这种情况下普通用户是否有执行的能力?如果有,那么可能就需要依赖软件本身的鉴权了

  5. ravindu644 commented on Sep 7, 2026

    @ravindu644
    Owner

    我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)

    应该是没的,adb shell除非用户在已经对shell设置root权限,正常情况下对/data/local目录下的文件没有执行权限。

    但需要注意:Droidspaces有一个选项,允许将二进制文件链接到/system/bin下,这时候就在普通用户的shell的PATH里了

    我不是特别了解,这种情况下普通用户是否有执行的能力?如果有,那么可能就需要依赖软件本身的鉴权了

    Only the root user and the users that's part of the droidspaces group can connect with the daemon; in direct mode, root access is mandatory.

    This is not a droidspaces issue at all. If your root solution is compromised, droidspaces and your entire device is compromised too. There's a no fix for this.

  6. ravindu644 commented on Sep 7, 2026

    @ravindu644
    Owner

    这几乎没有意义,rootfs本身就在/data/local/里面,真要访问可以直接通过rootfs原始路径,不需要经过app。

    yeah, this is a problem that never existed and cannot be fixed..

    If someone can open droidspaces app and enter into a root shell, they can do other things as well, like granting root access to their backdoor/malware by opening the KernelSU/Magisk app.

  7. hiruocha commented on Sep 7, 2026

    @hiruocha
    Author

    这几乎没有意义,rootfs本身就在/data/local/里面,真要访问可以直接通过rootfs原始路径,不需要经过app。

    yeah, this is a problem that never existed and cannot be fixed..

    If someone can open droidspaces app and enter into a root shell, they can do other things as well, like granting root access to their backdoor/malware by opening the KernelSU/Magisk app.

    好的,我理解了,我会关闭这个issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions