Fix for Security Hole in Android G1
In one fell swoop and with an automatically distributed patch, Google and T-Mobile fixed a problem with the G1 mobile phone whereby users could access root privileges and possibly raise all kinds of havoc.
In its originally delivered state, the G1 interpreted keyboard input as a remote shell request. This could be pretty annoying if you happen to type in "reboot" with applications running.
T-Mobile has since plugged the security hole with firmware update RC30, hoping thereby to raise the bar for any future hacks. The problem was discovered in early November, but got special notice after an experience by user jdhorvat. While talking on the G1 with his girlfriend, he restarted it.
When she asked why he wasn't responding, he IM'd her with the natural response "Reboot." He was surprised to see the device do just that.
Source of the security hole was boiled down to two lines of code in the init.rc file, according to the bug report. The file is a script that drives the boot process. A number of websites declared the problem one of the most embarrassing in recent history.
The G1 is manufactured by HTC and based on Google's Android platform, which is itself a knockoff of Linux and other Open Source components. Since its introduction, the G1 proved to be a favorite sport for hackers, who even managed to install and start Debian Lenny on it. The device is available in the U.S., but when other parts of the world start seeing it early 2009, all security holes will likely be plugged.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Armbian 24.11 Released with Expanded Hardware Support
If you've been waiting for Armbian to support OrangePi 5 Max and Radxa ROCK 5B+, the wait is over.
-
SUSE Renames Several Products for Better Name Recognition
SUSE has been a very powerful player in the European market, but it knows it must branch out to gain serious traction. Will a name change do the trick?
-
ESET Discovers New Linux Malware
WolfsBane is an all-in-one malware that has hit the Linux operating system and includes a dropper, a launcher, and a backdoor.
-
New Linux Kernel Patch Allows Forcing a CPU Mitigation
Even when CPU mitigations can consume precious CPU cycles, it might not be a bad idea to allow users to enable them, even if your machine isn't vulnerable.
-
Red Hat Enterprise Linux 9.5 Released
Notify your friends, loved ones, and colleagues that the latest version of RHEL is available with plenty of enhancements.
-
Linux Sees Massive Performance Increase from a Single Line of Code
With one line of code, Intel was able to increase the performance of the Linux kernel by 4,000 percent.
-
Fedora KDE Approved as an Official Spin
If you prefer the Plasma desktop environment and the Fedora distribution, you're in luck because there's now an official spin that is listed on the same level as the Fedora Workstation edition.
-
New Steam Client Ups the Ante for Linux
The latest release from Steam has some pretty cool tricks up its sleeve.
-
Gnome OS Transitioning Toward a General-Purpose Distro
If you're looking for the perfectly vanilla take on the Gnome desktop, Gnome OS might be for you.
-
Fedora 41 Released with New Features
If you're a Fedora fan or just looking for a Linux distribution to help you migrate from Windows, Fedora 41 might be just the ticket.