Can anyone try the recently discovered "Copy Fail" vulnerability on Droidspaces?
https://github.com/tgies/copy-fail-c/releases/tag/v0.2.0
Looks like I don't have a supported kernel.
What is expected is gaining root access inside the container or total container escape.
https://github.com/tgies/copy-fail-c/releases/tag/v0.2.0
Looks like I don't have a supported kernel.
What is expected is gaining root access inside the container or total container escape.
💩1
Droidspaces
Can anyone try the recently discovered "Copy Fail" vulnerability on Droidspaces? https://github.com/tgies/copy-fail-c/releases/tag/v0.2.0 Looks like I don't have a supported kernel. What is expected is gaining root access inside the container or total container…
It seems like Google saved all ya all asses by turning off the core Android kernel configuration necessary for this vulnerability:
But that doesn’t mean we are immune to this kind of attack since non-GKI kernels exist.
We still gotta block the necessary syscalls needed for this kind of attack using seccomp for the greater good.
CONFIG_CRYPTO_USER_API_AEAD=yBut that doesn’t mean we are immune to this kind of attack since non-GKI kernels exist.
We still gotta block the necessary syscalls needed for this kind of attack using seccomp for the greater good.
❤3💩1
Droidspaces
Can anyone try the recently discovered "Copy Fail" vulnerability on Droidspaces? https://github.com/tgies/copy-fail-c/releases/tag/v0.2.0 Looks like I don't have a supported kernel. What is expected is gaining root access inside the container or total container…
Well, you are vulnerable on Linux Desktop
What happened was a Local Privilege Escalation, not a container escape.
Therefore, this is a kernel issue rather than an issue with Droidspaces.
However, we will work on a fix from our side if possible ❤️
What happened was a Local Privilege Escalation, not a container escape.
Therefore, this is a kernel issue rather than an issue with Droidspaces.
However, we will work on a fix from our side if possible ❤️
😨3💩1
I know. Most users use hw-access by default, and you all want freedom.
But we have to admit this: if your rooting method is compromised, if
Our goal is to make devices real Linux servers that need real capabilities, not sandboxes.
But we have to admit this: if your rooting method is compromised, if
sudo, su, or the kernel is compromised, Droidspaces is compromised too. We can't prevent that.Our goal is to make devices real Linux servers that need real capabilities, not sandboxes.
❤9💩1
Droidspaces
I know. Most users use hw-access by default, and you all want freedom. But we have to admit this: if your rooting method is compromised, if sudo, su, or the kernel is compromised, Droidspaces is compromised too. We can't prevent that. Our goal is to make…
With great power comes great responsibility
🗿7❤5💩1😭1