[FOR DEVS] Possible bootloader unlock exploit - G2 General

Hi! I found this now on reddit, there is LG G2 on the list, can we use it?!
It's the documentation by @djrbliss (Dan Rosenberg, XDA Recognized Developer)
http://imgur.com/TXKDpOI
Reddit link:
http://pl.reddit.com/r/Android/comments/2csyiq/looks_like_many_android_phones_are_getting_a/
Please check it guys, but if it's not useful, then sorry.
@dorimanx @dr87 @savoca @Cloudyfa @OptimusRs @RenderBroken @Amperific @JackpotClavin (just wanted to show it to someone who is experienced and who would have a while, it's not like i just mentioned everyone here)
EDIT: https://www.blackhat.com/us-14/briefings.html#reflections-on-trusting-trustzone
The talk will conclude with a discussion of the ramifications of this vulnerability and others like it, including a live demonstration of using it to permanently unlock the bootloader of a major Android phone.
Click to expand...
Click to collapse
EDIT2:
Dan performed a permanent boot loader unlock of the Moto X live. We shall see how this pans out to other devices in the coming weeks.
Click to expand...
Click to collapse

Looks like I need a g2...

savoca said:
Looks like I need a g2...
Click to expand...
Click to collapse
looks like someone regrets that he left us? :> Now seriously, is it useful?

reas0n said:
looks like someone regrets that he left us? :> Now seriously, is it useful?
Click to expand...
Click to collapse
Yepp and yepp, will have to wait for more documentation, but I'd love to be able to get dtb appended on this device's zImage without any silly downgrades.

savoca said:
Yepp and yepp, will have to wait for more documentation, but I'd love to be able to get dtb appended on this device's zImage without any silly downgrades.
Click to expand...
Click to collapse
Check this reddit http://pl.reddit.com/r/Android/comments/2csyiq/looks_like_many_android_phones_are_getting_a/
Dan Rosenberg will be giving a demo in couple of hours demonstrating how to permanently unlock the boot loader of a major phone. So a boot loader unlock. No spoofing, although the arbitrary code execution could lead to many possibilities.
Click to expand...
Click to collapse
Well, seems like the G2 may be a hot phone for developers soon The phone still has the beast specs, so.
Btw, I read that S5 and M8 are patched, as we know they have Snap801, so this exploit is hardware related? If yes, then LG couldn't even relock it, i suppose, lol

Thanks @reas0n for sharing this with us. The imgur link you shared, i compared it first with the loki script but it didnt contained anythin about qsee i thought and no similair lines. If @dr87 has the way to permanently unlock the gs4 then it would be also maybe possible for the g2 like said in the imgur link you gave. Seems trustable that link. But i bet dr87 is having now some kind of top secret area 51 project to unlock the lg bootloader.
Thanks again reas0n continue your search you`re doing great.
I could also be wrong and it maybe contained in the loki script but i didnt saw it since i`m watching from my tab now.

Thanks, I want to do as much as I can for the G2 community.
Edited the thread, lol, it would be epic if he used our lovely G2 as unlocking example We just have to wait now.

I saw now that he will present at blackhat so pretty big. First i came on an website from azimuth security about galaxy s4 loki etc i just found out on that link from you that dr87 works/ is part of azimuth security so i bet he will bypass and unlock it
The security doctor will fix ill locked devices.
Maybe the device wil get unlocked before lg provides an official unlock method. Is it about me or is LG doing the same as samsung? Same with bootloader, roundicons in notification bar etc, i wonder how LG will become.

Update:
Dan performed a permanent boot loader unlock of the Moto X live. We shall see how this pans out to other devices in the coming weeks.
Click to expand...
Click to collapse
Oh God.... WEEKS......
EDIT: so... Does anyone knows how to use it now? Maybe @jakew02 @arcardinal @fabioio @houstonn @bart452 @EvilDobe @driodmaster92 @bruce2728 ... Anyone?

http://www.droid-life.com/2014/08/07/moto-x-bootloader-unlock-qualcomm/
Sent from my VS980 4G using XDA Free mobile app

reas0n said:
Update:
Oh God.... WEEKS......
EDIT: so... Does anyone knows how to use it now? Maybe @jakew02 @arcardinal @fabioio @houstonn @bart452 @EvilDobe @driodmaster92 @bruce2728 ... Anyone?
Click to expand...
Click to collapse
edit: rekt

lolol https://twitter.com/djrbliss/status/497552086171533312

Ouch.... So we are still f*cked.

Other vulnerable devices specifically noted in this report include the Galaxy S4, Galaxy Note 3, Nexus 4, Nexus 5, G2, and original HTC One (M7).
Click to expand...
Click to collapse
LG and Samsung devices cannot be bootloader unlocked via TrustZone, so please stop asking me about it
Click to expand...
Click to collapse
???

I don't know, but I can suppose that money is the answer... or?

reas0n said:
I don't know, but I can suppose that money is the answer... or?
Click to expand...
Click to collapse
The guy's in Vegas, just sit tight.

savoca said:
The guy's in Vegas, just sit tight.
Click to expand...
Click to collapse
u wot m8, I don't understand what u want to tell lol (well, a hard day)

http://phandroid.com/2014/08/08/lg-official-bootloader-unlock-solution-coming-soon/
Sent from my VS980 4G using XDA Free mobile app

Check out the portal.
http://www.xda-developers.com/andro...mctr=(not provided)&__utmv=-&__utmk=130646152
...He demonstrated his claim by unlocking a Moto X bootloader on stage, going on to say that a number of devices including Nexus 4 and Nexus 5, LG G2, Samsung Galaxy Note 3 were vulnerable...

Now we just have to wait for him to release this exploit

Related

Will Motorola's Official Bootloader Unlocking Tool for Photon allow working 4G?

Since the Unlocking Tool is from Motorola, will it allow the Photon Bootloader to be unlocked without disabling 4G/WiMax on custom ROMs that require an unlocked bootloader?
LilCozyFab said:
Since the Unlocking Tool is from Motorola, will it allow the Photon Bootloader to be unlocked without disabling 4G/WiMax on custom ROMs that require an unlocked bootloader?
Click to expand...
Click to collapse
No. Doesn't currently work with photon. This can easily be found out by looking at the supported devices.
Acvice said:
No. Doesn't currently work with photon. This can easily be found out by looking at the supported devices.
Click to expand...
Click to collapse
Damn, I feel stupid. I read way too fast over the 4 pages I looked at. I seen Photon, but didn't read the "LTE" and the end of it. Sorry folks.
LilCozyFab said:
Damn, I feel stupid. I read way too fast over the 4 pages I looked at. I seen Photon, but didn't read the "LTE" and the end of it. Sorry folks.
Click to expand...
Click to collapse
Its all good, you certainly arnt the only one you has asked.
Acvice said:
Its all good, you certainly arnt the only one you has asked.
Click to expand...
Click to collapse
And certainly not the last...
It's not on the unlockable device list, but it may be in the near future.
We can sit around and wait for Motorola to do it. Or we could all sign an online petition and show them how big the community is, and how much business they'll loose if they don't unlock bootloaders!
brunomcf said:
It's not on the unlockable device list, but it may be in the near future.
We can sit around and wait for Motorola to do it. Or we could all sign an online petition and show them how big the community is, and how much business they'll loose if they don't unlock bootloaders!
Click to expand...
Click to collapse
Already been done. Either they will or won't and I think they've already decided which way they plan on going. I don't believe that anything that we do now will change their mind.
Acvice said:
Already been done. Either they will or won't and I think they've already decided which way they plan on going. I don't believe that anything that we do now will change their mind.
Click to expand...
Click to collapse
Buying Samsungs will definatelly change their minds! hehe
Btw, where's that petition? Wanna sign it!
Has anyone actually tried getting it to work on the Photon 4G?
http://www.phonedog.com/2012/08/22/...r-previous-devices-not-currently-in-the-plan/
Hope no one had put to many of their hopes and dreams in that
brunomcf said:
It's not on the unlockable device list, but it may be in the near future.
We can sit around and wait for Motorola to do it. Or we could all sign an online petition and show them how big the community is, and how much business they'll loose if they don't unlock bootloaders!
Click to expand...
Click to collapse
Acvice said:
Already been done. Either they will or won't and I think they've already decided which way they plan on going. I don't believe that anything that we do now will change their mind.
Click to expand...
Click to collapse
When was that petition make? We should make it again anyway to remind them we are still a big community, just in case they have forgotten us xD
What can we loose?
Enviado desde mi MB855 usando Tapatalk 2
Or, maybe have someone tinker with the unlocking tool...
XxReApErxX said:
When was that petition make? We should make it again anyway to remind them we are still a big community, just in case they have forgotten us xD
What can we loose?
Enviado desde mi MB855 usando Tapatalk 2
Click to expand...
Click to collapse
I'm not sure but we are sitting at 2,793 more signatures needed. The petition can be found here http://chn.ge/PaVpIX
---------- Post added at 12:48 PM ---------- Previous post was at 12:47 PM ----------
brunomcf said:
Buying Samsungs will definatelly change their minds! hehe
Btw, where's that petition? Wanna sign it!
Click to expand...
Click to collapse
In case you haven't had a chance to sign it yet...http://chn.ge/PaVpIX

Verizon kernel source code released

shocking news! Samsung just released verizon kernel source code and yet they don't have cases or chargers available for purchase yet! :crying:
but here is the source code link if anybody wants to take a look!
http://opensource.samsung.com/reception/receptionSub.do?method=search&searchValue=SM-N900V
What does this mean for root and unlockable BL possibilities?
Sent from my Crapple iPhone 5
oneandroidnut said:
shocking news! Samsung just released verizon kernel source code and yet they don't have cases or chargers available for purchase yet! :crying:
but here is the source code link if anybody wants to take a look!
http://opensource.samsung.com/reception/receptionSub.do?method=search&searchValue=SM-N900V
Click to expand...
Click to collapse
That's amazing let's hope a miracle can be performed with the bootloader.... If not the kernel source is useless for the most part, yes I know we have safestap and loki potentially
Han Solo 1 said:
What does this mean for root and unlockable BL possibilities?
Sent from my Crapple iPhone 5
Click to expand...
Click to collapse
Completely different animal but it is a very good start. if we get loki or safestrap we will be excited!!
2swizzle said:
That's amazing let's hope a miracle can be performed with the bootloader.... If not the kernel source is useless for the most part, yes I know we have safestap and loki potentially
Click to expand...
Click to collapse
i know man! if verizon can get the bootloader unlocked or even bypassed somehow it will be a true miracle!! :good:
This seems like great news from developers always replying to user requests, "whenever %said_carrier% releases their source code.."
lmike6453 said:
This seems like great news from developers always replying to user requests, "whenever %said_carrier% releases their source code.."
Click to expand...
Click to collapse
yes hopefully it will be great news!

I unlock ls990 bootloader

my bootloader for ls990 is unlock but dont have a custom recovery
I did manage to fastboot and oem unlock
Elaborate. If you just typed that in fastboot then it's a no go. Sorry mayn.
I use LG Laf Recovery Multitool
papote777 said:
I use LG Laf Recovery Multitool
Click to expand...
Click to collapse
This looks interesting, and the names seem legit.
I'll bite. Would you mind sharing where you got that?
http://androidforums.com/l70-all-things-root/863389-tool-lg-laf-recovery-multitool-v1-2-a.html
I'm sorry, but I wouldn't touch that with an 80ft pole!!!
First off, it's not for the G3. It's L90
Second, and most important, None of the devs working on it have put it out there yet. I'm sorry, but maybe I'm too sceptical to believe that if this has been out since Aug 8th, Why is it not available here?! Or even rumor of it?
I really hope you didn't just ruin your phone. My guess is this has something to do with the T-mo version of the G3 at best. Not to be used on the Sprint version.
I got an 81ft pole if your down. Haha. Just kidding man. I hate seeing threads like this that give us hope for a minute and turn out to be snake oil.
engine95 said:
I'm sorry, but I wouldn't touch that with an 80ft pole!!!
First off, it's not for the G3. It's L90
Second, and most important, None of the devs working on it have put it out there yet. I'm sorry, but maybe I'm too sceptical to believe that if this has been out since Aug 8th, Why is it not available here?! Or even rumor of it?
I really hope you didn't just ruin your phone. My guess is this has something to do with the T-mo version of the G3 at best. Not to be used on the Sprint version.
Click to expand...
Click to collapse
I looked into it too and it seems legit for the phone they advertise but as you said it didn't mention the LS990 anywhere., and how jcase or no one else over here knew about it and if they did and it was legit they would share it here. Hopefully his phone isn't ruined.
no is not damage it even do a back up of the laf.img and boot.img
this looks shady if you ask me.
Mahapederdon said:
I got an 81ft pole if your down. Haha. Just kidding man. I hate seeing threads like this that give us hope for a minute and turn out to be snake oil.
Click to expand...
Click to collapse
Still not long enough, but thanks.
papote777 said:
no is not damage it even do a back up of the laf.img and boot.img
Click to expand...
Click to collapse
You're a braver person than I.
In that thread you linked, Sammyz has the partition layout. It's no where near what ours is as far as I could tell. There were many differences.
So even if you managed to get it unlocked, I would think your offsets and partition names/sizes would be wrong now.
I may be totally wrong, and I truly hope I am. But this is a risk I wouldn't recommend to anybody yet. And definitely not for me.
But to try to help you if you want to continue, AT YOUR OWN RISK, I guess you could try the recoveries in the LG G3 forums, under general. It's tethered and might be the safest, but it's also not for Sprint
Bare in mind though, Sprint Does Not have a recovery yet.
Tried an failed lol
Sent from my LGLS990 using XDA Premium HD app
pbedard said:
Tried an failed lol
Sent from my LGLS990 using XDA Premium HD app
Click to expand...
Click to collapse
We all thought you sold this hawk.
Mahapederdon said:
We all thought you sold this hawk.
Click to expand...
Click to collapse
No i love my phoneci wont get rid of it just wait n be patient like is all
Sent from my LGLS990 using XDA Premium HD app
Anyone in the know, determine what this really is?
JustusIV said:
Anyone in the know, determine what this really is?
Click to expand...
Click to collapse
someone said it unlocked their bootloader
Sent from my LGLS990 using XDA Premium HD app
I wouldn't wouldn't touch this
mhsbrian said:
I wouldn't wouldn't touch this
Click to expand...
Click to collapse
Neither would i
Sent from my LGLS990 using XDA Premium HD app
JustusIV said:
Anyone in the know, determine what this really is?
Click to expand...
Click to collapse
It's an unlock for a different model lg phone. At best trying it wont work - at worst you are now bricked. People can be a$$hats.....
I looked through the script and its pulling the partitions by name which is good. The thing i see that would worry me is erasing the the boot img to access fastboot, But it does backup the boot and then flashes it again. I think i might give this a go later when i grow a bigger pair...lol

[Discussion] BUMP by Team Codefire is Officially Out

Finally BUMP has been officially released by Team Codefire
@thecubed has posted a thread on G3 forum which can be found over here
BUMP for LG Devices
OP quotes as follows
What is this?
This is Bump! A new and easy way to sign boot images for most modern LG phones so they'll boot on any locked phone.
Bump an image once, and flash it to however many phones you please.
Click to expand...
Click to collapse
Which suggests that it will be available for our G2 too and finally we will be able to use Bumped Kernel based on Kitkat sources and with Lollipop sources too in near future.
Edit:-
It will work on our G2 too. This is the extract from the BUMP website
Will Bump work on other phones?
Bump only supports LG phones, specifically the Optimus series of phones. Bump will not work on Samsung, Motorola, HTC, or other vendor hardware.
How is Bump different from Loki?
Bump works on LG devices that have Loki patched. There is no need to downgrade your firmware to use Loki anymore.
Click to expand...
Click to collapse
P.S. :- I am no way associated with Team Codefire and all the credits for the work goes to the respective members of the team. Do consider donating them for their efforts. Let the good days for our G2 begin
Yes, it works on ALL LG devices. G Pad, G Pro, G Pro 2, Optimus G, G2, G2 Summit, World Leader Conference, oh wait...
Ok, so I know this thread is ancient, but does anyone know how to BUMP img files as codefi.re isn't existing anymore?
Sent from my LG-K121 using XDA Labs
iloveoreos said:
Ok, so I know this thread is ancient, but does anyone know how to BUMP img files as codefi.re isn't existing anymore?
Sent from my LG-K121 using XDA Labs
Click to expand...
Click to collapse
Yeah, the guy who killed BUMP someone who reverse engineered the site open sourced what he did: https://forum.xda-developers.com/lg-g2/orig-development/tool-bump-sign-boot-images-t2950595
Raymonf said:
Yeah, the guy who killed BUMP someone who reverse engineered the site open sourced what he did: https://forum.xda-developers.com/lg-g2/orig-development/tool-bump-sign-boot-images-t2950595
Click to expand...
Click to collapse
I always wondered what happened there...
Sent from my Samsung SM-A520W using XDA Labs
iloveoreos said:
I always wondered what happened there...
Sent from my Samsung SM-A520W using XDA Labs
Click to expand...
Click to collapse
Heh, just some petty drama.

Possible Resurrection Remix?

Since a bootloader unlock has already been found (it requires Medusa), maybe someone can begin porting resurrection remix to the V60?
Nothing going forward til Firehose.
hooutoo said:
Nothing going forward til Firehose.
Click to expand...
Click to collapse
We already have a firehouse for the V60, and no it's not the zte one
crimsonrommer said:
We already have a firehouse for the V60, and no it's not the zte one
Click to expand...
Click to collapse
Well that good to here 'cause I'm about to close on a AT&T v60 on ebay. Am I using Magisk 23? And Twpr?
hooutoo said:
Well that good to here 'cause I'm about to close on a AT&T v60 on ebay. Am I using Magisk 23? And Twpr?
Click to expand...
Click to collapse
There's no proper twrp yet, however yes you'll be using magisk
In a 2hr 17min I tell you what I paid. I'm guess short of 200.
crimsonrommer said:
We already have a firehouse for the V60, and no it's not the zte one
Click to expand...
Click to collapse
Why are you spreading false information? We don't have a firehose, we only have *a tool i am not allowed to mention bc xda is... well xda* that bypasses the verification process and lets us use a generic firehose.
Your happen to know if anyone got a solution for QDaq on A12 gsi? My v450pm won't give me any sound.
Leronex_1 said:
Why are you spreading false information? We don't have a firehose, we only have *a tool i am not allowed to mention bc xda is... well xda* that bypasses the verification process and lets us use a generic firehose.
Click to expand...
Click to collapse
Dude... not to cry. I'm a big boy. I read long before I buy and just like the v50 it'll drop. Everybody gotta make a dime.
Leronex_1 said:
Why are you spreading false information? We don't have a firehose, we only have *a tool i am not allowed to mention bc xda is... well xda* that bypasses the verification process and lets us use a generic firehose.
Click to expand...
Click to collapse
Oh, sorry about that, it seemed like you guys do have a working one from the reddit unlock thingy
Well, its fine, i just overreacted a bit because a couple of people were telling me to just release the firehose after i said like 10 times that its just a generic one.
As promised. $232.71 Tax title and tip + shipping.
I just bought a $1,000-$1,200 phone for a 1/5 price.

Categories

Resources