Repository navigation
[FEATURE] Shell password #305
Description
Activity
这几乎没有意义,rootfs本身就在/data/local/里面,真要访问可以直接通过rootfs原始路径,不需要经过app。
Reacted by Ravindu Deshan我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)
我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)
应该是没的,adb shell除非用户在已经对shell设置root权限,正常情况下对/data/local目录下的文件没有执行权限。
我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)
应该是没的,adb shell除非用户在已经对shell设置root权限,正常情况下对/data/local目录下的文件没有执行权限。
但需要注意:Droidspaces有一个选项,允许将二进制文件链接到/system/bin下,这时候就在普通用户的shell的PATH里了
我不是特别了解,这种情况下普通用户是否有执行的能力?如果有,那么可能就需要依赖软件本身的鉴权了
我额外的问一句,二进制文件是否有做过鉴权?假如未鉴权,攻击者也可能在未输入解锁密码的前提下通过未提权的adb shell获取容器root权限,形成一条可实际利用的漏洞链(总不可能指望所有用户都在每次使用完手机后重启吧)
应该是没的,adb shell除非用户在已经对shell设置root权限,正常情况下对/data/local目录下的文件没有执行权限。
但需要注意:Droidspaces有一个选项,允许将二进制文件链接到/system/bin下,这时候就在普通用户的shell的PATH里了
我不是特别了解,这种情况下普通用户是否有执行的能力?如果有,那么可能就需要依赖软件本身的鉴权了
Only the root user and the users that's part of the
droidspacesgroup can connect with the daemon; in direct mode, root access is mandatory.This is not a droidspaces issue at all. If your root solution is compromised, droidspaces and your entire device is compromised too. There's a no fix for this.
这几乎没有意义,rootfs本身就在/data/local/里面,真要访问可以直接通过rootfs原始路径,不需要经过app。
yeah, this is a problem that never existed and cannot be fixed..
If someone can open droidspaces app and enter into a root shell, they can do other things as well, like granting root access to their backdoor/malware by opening the KernelSU/Magisk app.
这几乎没有意义,rootfs本身就在/data/local/里面,真要访问可以直接通过rootfs原始路径,不需要经过app。
yeah, this is a problem that never existed and cannot be fixed..
If someone can open droidspaces app and enter into a root shell, they can do other things as well, like granting root access to their backdoor/malware by opening the KernelSU/Magisk app.
好的,我理解了,我会关闭这个issue
sorry chinese, i cant use translator now
我注意到目前从应用进入容器的shell是不需要任何权限验证的,哪怕是root shell
通常,类原生系统(aosp based roms)并没有应用锁功能,如果只用锁屏密码来保护一个几乎完整的root权限,我认为是不够安全的
所以,我希望在应用内打开shell前可以做一个验证,无论是验证容器内用户密码,还是走安卓锁屏密码或生物识别,都可以