Fix for Security Hole in Android G1
In one fell swoop and with an automatically distributed patch, Google and T-Mobile fixed a problem with the G1 mobile phone whereby users could access root privileges and possibly raise all kinds of havoc.
In its originally delivered state, the G1 interpreted keyboard input as a remote shell request. This could be pretty annoying if you happen to type in "reboot" with applications running.
T-Mobile has since plugged the security hole with firmware update RC30, hoping thereby to raise the bar for any future hacks. The problem was discovered in early November, but got special notice after an experience by user jdhorvat. While talking on the G1 with his girlfriend, he restarted it.
When she asked why he wasn't responding, he IM'd her with the natural response "Reboot." He was surprised to see the device do just that.
Source of the security hole was boiled down to two lines of code in the init.rc file, according to the bug report. The file is a script that drives the boot process. A number of websites declared the problem one of the most embarrassing in recent history.
The G1 is manufactured by HTC and based on Google's Android platform, which is itself a knockoff of Linux and other Open Source components. Since its introduction, the G1 proved to be a favorite sport for hackers, who even managed to install and start Debian Lenny on it. The device is available in the U.S., but when other parts of the world start seeing it early 2009, all security holes will likely be plugged.
Tag Cloud
News
-
Google and NASA Partner in Quantum Computing Project
Vendor D-Wave scores big with a sale to NASA's Quantum Intelligence Lab.
-
Mageia Project Announces Mageia 3 Linux
Many package updates and Steam integration highlight the latest from the Mandriva-based community Linux.
-
FSF Outs the World Wide Web Consortium over DRM Proposal
Richard Stallman calls for the W3C to remain independent of vendor interests.
-
Debian 7.0 Debuts
The new release supports nine architectures, 73 human languages, and zero non-Free components.
-
Alpha Version of Fedora 19 Released
Fedora developers release the first alpha version of Fedora 19, known as Schrödinger’s Cat, for general testing. The final release is expected in July 2013.
-
ack 2.0 Released
ack is a grep-like, command-line tool that has been optimized for programmers to search large trees of source code.
-
SUSE Studio 1.3 Released
New features in SUSE Studio 1.3 include enhanced cloud integration, VM platform support, and lifecycle management.
-
Xen To Become Linux Foundation Collaborative Project
The Linux Foundation recently announced that the Xen Project is becoming a Linux Foundation Collaborative Project.
-
RunRev Releases Open Source Version of LiveCode
Open source version of LiveCode is now available for developing apps, games, and utilities for all major platforms.
-
OpenDaylight Project Formed
OpenDaylight is an open source software-defined networking project committed to furthering adoption of SDN and accelerating innovation in a vendor-neutral and open environment.

