Spotlight | Reviews | Current Issue | Newsletter | Subscribe | Contact |
Departments

Partner Links
Website builder
WinWeb OnlineOffice
Shopping and price comparison with product reviews at dooyoo.co.uk

user friendly

CeBIT 2010 CFP

Linux Magazine is offering free booths for the CeBIT 2010 computer fair to selected open source projects. Apply Now!

  linux-magazine.com » Online » News » Fix for Security Hole in Android G1  

Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg

Fix for Security Hole in Android G1

In one fell swoop and with an automatically distributed patch, Google and T-Mobile fixed a problem with the G1 mobile phone whereby users could access root privileges and possibly raise all kinds of havoc.

In its originally delivered state, the G1 interpreted keyboard input as a remote shell request. This could be pretty annoying if you happen to type in "reboot" with applications running.

T-Mobile has since plugged the security hole with firmware update RC30, hoping thereby to raise the bar for any future hacks. The problem was discovered in early November, but got special notice after an experience by user jdhorvat. While talking on the G1 with his girlfriend, he restarted it.
When she asked why he wasn't responding, he IM'd her with the natural response "Reboot." He was surprised to see the device do just that.

Source of the security hole was boiled down to two lines of code in the init.rc file, according to the bug report. The file is a script that drives the boot process. A number of websites declared the problem one of the most embarrassing in recent history.

The G1 is manufactured by HTC and based on Google's Android platform, which is itself a knockoff of Linux and other Open Source components. Since its introduction, the G1 proved to be a favorite sport for hackers, who even managed to install and start Debian Lenny on it. The device is available in the U.S., but when other parts of the world start seeing it early 2009, all security holes will likely be plugged.

(Kristian Kissling)

Comments


Print this page. Recommend
Slashdot it! Delicious Share on Facebook Tweet! Digg
Related Articles
G2: This Time on Vodafone
Hackers Find Root Access to Android G1
Android-Powered Mobile Phone on Its Way
Funambol Synchronizes with Google Android
Kernel Hacker Wants to Crack Android Code
Google Android and the Dream Phone
No More Downloads!

Save the download and take Linux Magazine DVDs instead.

Each DVD contains a full distro like Ubuntu, SUSE, Mandriva, Fedora, or Debian and comes with the corresponding issue of Linux Magazine.

Don't waste timedownloading Linux!

more...

 

In the US and Canada, Linux Magazine is known as Linux Pro Magazine.
Entire contents © 2009 [Linux New Media USA, LLC]
Linux New Media web sites:
North America: [Linux Pro Magazine]
UK/Worldwide: [Linux Magazine]
Germany: [Linux-Magazin] [LinuxUser] [EasyLinux] [Linux-Community] [Linux Technical Review]
Eastern Europe: [Linux Magazine Poland] [Linux Community Poland] [Open Source DVD Poland]
International: [Linux Magazine Brazil] [EasyLinux Brazil] [Linux Magazine Spanish]
Corporate: [Linux New Media AG]