Sign in

David Buchanan

@retr0.id
56K followers 614 following 30K posts

reverse engineering, cryptography, exploits, hardware, file formats, and generally giving computers a hard time Fedi: @retr0id@retr0.id Macroblog: www.da.vidbuchanan.co.uk/blog

PostsRepliesMedia
David Buchanan @retr0.id · 13/05/2026
oh nice I missed this, does it include 9a too?
130
David Buchanan @retr0.id · 13/05/2026
📝
050
Reposted by David Buchanan
David Buchanan @retr0.id · 31/03/2026
have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.
262845850
David Buchanan @retr0.id · 11/05/2026
[ accept bonus cookies ]
2512
David Buchanan @retr0.id · 11/05/2026
could be from customers attempting their own installs and then sending them in to get fixed (and then being told they're beyond repair)
110
David Buchanan @retr0.id · 11/05/2026
I think I slightly look down on people who use vscode but I also use vscode myself
121695
David Buchanan @retr0.id · 11/05/2026
outdated comment
010
David Buchanan @retr0.id · 11/05/2026
now the bread is portable
0100
David Buchanan @retr0.id · 11/05/2026
hmm
youtube thumbnail: "Pouring Coca-Cola and batteries into a hole will amaze the whole world! 😱"
24619100
David Buchanan @retr0.id · 11/05/2026
A bit of both I guess?
020
David Buchanan @retr0.id · 11/05/2026
anyway I guess this is proof that a full Play Integrity bypass is within "weekend project" territory. this approach does not exploit any bugs or rely on leaked key material, so it cannot be patched.
418217
Reposted by David Buchanan
David Buchanan @retr0.id · 10/05/2026
injected frida-gadget via slightly modified AndKittyInjector
2957
David Buchanan @retr0.id · 11/05/2026
also this
2170
David Buchanan @retr0.id · 11/05/2026
no, just me remembering that C2PA exists
190
David Buchanan @retr0.id · 10/05/2026
injected frida-gadget via slightly modified AndKittyInjector
2957
David Buchanan @retr0.id · 10/05/2026
I just migrated into dumpstate which has, afaict, the most permissive selinux policy
1370
David Buchanan @retr0.id · 10/05/2026
it's very funny to me that you can't mmap an anonymous+exec page, but you can map an executable file just fine and then overwrite it with your own code. all these mitigations are very annoying, but they are only an annoyance.
1450
David Buchanan @retr0.id · 10/05/2026
aaaand there it is, root shell in pid 1 context (which isn't the best selinux context but hey, it's root)
59112
David Buchanan @retr0.id · 10/05/2026
If I have a play integrity bypass, what's the best way to demo it?
0190
David Buchanan @retr0.id · 10/05/2026
Do the 3.x betas use the same play integrity + remote c2pa signing flow that the final release will use, just with a "non-trusted" signer?
100
David Buchanan @retr0.id · 10/05/2026
frida fails with opaque permission errors so I think I probably will need a root shell before I can try frida
110
David Buchanan @retr0.id · 10/05/2026
yup, although I really do want that root prompt just for style points, so now I'm writing a ptrace shellcode injector heh
120
David Buchanan @retr0.id · 10/05/2026
now we're cooking - thinking about it, I can probably use this to inject shellcode into pid1 and spawn myself a root shell that way
gdb attaching to pid 1
2281
David Buchanan @retr0.id · 10/05/2026
however it looks like ptrace_attach does a different (inlined?) check, so I need to patch that too!
1160
David Buchanan @retr0.id · 10/05/2026
I gave up on getting a root shell, since that isn't my real goal here. I just want to be able to inject code into other processes. I patched ptrace_may_access in kernel .text to always return true, so now I can access anything that would normally be gated on that - e.g. /proc/pid/maps.
output of `cat /proc/1/maps`
1190
David Buchanan @retr0.id · 10/05/2026
how come?
100
David Buchanan @retr0.id · 10/05/2026
claude's exploit did not work so I'll have to use my brain oldschool style (claude seems repeatedly confused by physical vs virtual address spaces)
1300
David Buchanan @retr0.id · 09/05/2026
for this device, the kernel is always at a fixed physical address - so walking kernel structs is easy. so the plan is, find pid1's cred struct and duplicate it into the current process. and also disable DEFEX (which seems easy once the offsets are known)
1220
David Buchanan @retr0.id · 09/05/2026
I let claude devise a new LPE strat and I haven't reviewed it, but trying things is ~free
1220
David Buchanan @retr0.id · 09/05/2026
and to be clear this is definitely a case of "I already know what I'm doing", but it is saving me a bunch of time and/or effort
130
David Buchanan @retr0.id · 09/05/2026
opus 4.7 (with CVP)
210
David Buchanan @retr0.id · 09/05/2026
noice
2261
David Buchanan @retr0.id · 09/05/2026
now I'm pointing claude at the headless loader scripts I wrote for github.com/DavidBuchana..., so I should get a nice clean symbolicated kernel loaded in ghidra, with struct layouts, without any manual effort
2191
David Buchanan @retr0.id · 09/05/2026
reverse engineering in 2026 is so cool
56311
David Buchanan @retr0.id · 09/05/2026
finally had some good luck, physmem dump is in progress
1240
David Buchanan @retr0.id · 09/05/2026
I've had an unlucky streak in terms of getting the exploit to trigger, I'm currently trying to dump all of physmem to a file for analysis but it hasn't landed yet.
1220
David Buchanan @retr0.id · 09/05/2026
maybe a better strat would be for me to try to inject shellcode into pid 1, and have it fork and spawn a shell hooked up to a pty
000
David Buchanan @retr0.id · 09/05/2026
I'm able to write the memory, it just doesn't like when I set the ruid to 0
100
David Buchanan @retr0.id · 09/05/2026
possibly, but my goal is to bypass play integrity and I assume that will check selinux status
020
David Buchanan @retr0.id · 09/05/2026
Actually I might be hitting samsung's "DEFEX" mitigations: docs.samsungknox.com/admin/fundam...
3240
David Buchanan @retr0.id · 09/05/2026
current plan: dump /sys/kernel/btf/vmlinux out of kernel memory (normally it needs root to read), then I can infer layouts of all the kernel structs I care about, and do more targeted struct-walking instead of pattern scanning
2230
David Buchanan @retr0.id · 09/05/2026
ok yeah this is a SELinux Thing™, will need a more intelligent exploit strat. surely there is good prior art of anrdoid phys r/w -> root?
2220
David Buchanan @retr0.id · 09/05/2026
plausibly this is a SELinux thing™, I thought I'd keep things simple to start with so I'm just patching cred - if anyone has any guesses what the issue might be lmk
1240
David Buchanan @retr0.id · 09/05/2026
debugging it is tedious because it takes several attempts for the phys r/w setup to not crash the whole device
2240
David Buchanan @retr0.id · 09/05/2026
succeed at locating the current pid's struct cred, but for some reason died during/after trying to patch it
[+] Found glitched PTE @ 0x0000005ec4200000
[*] PTE value: 0x0068000065641fc3
[*] Searching for corresponding mapping...
Found it! @ 0x0000005ec4000000
Found it! @ 0x000000655fa00000
[+] Found the mapping @ 0x000000655fa00000
[*] my ids: ruid=000007d0 rgid=000007d0 suid=000007d0 sgid=000007d0 euid=000007d0 egid=000007d0 fsuid=000007d0 fsgid=000007d0
[*] Scanning physmem for our cred...
[*] phys=0x0000000044000000


[*] phys=0x000000012c000000
[+] our cred at PA=0x000000012e31b308
1310
David Buchanan @retr0.id · 09/05/2026
even memory auth doesn't fully fix this, but it would take a modified exploit strat (e.g. block a write during a page table unmap)
110
David Buchanan @retr0.id · 09/05/2026
the exploit so far: github.com/DavidBuchana...
github.com
2391
David Buchanan @retr0.id · 09/05/2026
hell yeah - second attempt after this, the r/w primitive worked fully. now I need to figure out the second half of the LPE - overwriting a setuid binary won't work
2400
David Buchanan @retr0.id · 09/05/2026
some *very* promising initial results, although it crashed at the end, while trying to test the r/w primitive. plausibly because I flipped too many bits - will keep attempting (this one was on the third attempt, previous attempts just crashed the device)
[*] Setting up memfd
[*] Spraying pagetables
[*] Searching for bitflipped PTEs

FAULT!

FAULT!
[+] Found glitched PTE @ 0x00000012b7600000
[*] PTE value: 0x00680000b9f9dfc3
[*] Searching for corresponding mapping...
Found it! @ 0x00000051cb600000
[+] Found the mapping @ 0x00000051cb600000
[*] Sweeping physmem and dumping samples...
[*] phys=0x0000000040000000 first_qword=0x00680000ac665fc3 hits=00000000
2410
David Buchanan @retr0.id · 09/05/2026
selinux is enforce by kernel so once you pwn kernel it is useless
050