Reposted by David BuchananDavid Buchanan @retr0.id · 31/03/2026have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you. 262845850
David Buchanan @retr0.id · 11/05/2026could be from customers attempting their own installs and then sending them in to get fixed (and then being told they're beyond repair) 110
David Buchanan @retr0.id · 11/05/2026I think I slightly look down on people who use vscode but I also use vscode myself 121695
David Buchanan @retr0.id · 11/05/2026anyway I guess this is proof that a full Play Integrity bypass is within "weekend project" territory. this approach does not exploit any bugs or rely on leaked key material, so it cannot be patched. 418217
Reposted by David BuchananDavid Buchanan @retr0.id · 10/05/2026injected frida-gadget via slightly modified AndKittyInjector 2957
David Buchanan @retr0.id · 10/05/2026injected frida-gadget via slightly modified AndKittyInjector 2957
David Buchanan @retr0.id · 10/05/2026I just migrated into dumpstate which has, afaict, the most permissive selinux policy 1370
David Buchanan @retr0.id · 10/05/2026it's very funny to me that you can't mmap an anonymous+exec page, but you can map an executable file just fine and then overwrite it with your own code. all these mitigations are very annoying, but they are only an annoyance. 1450
David Buchanan @retr0.id · 10/05/2026aaaand there it is, root shell in pid 1 context (which isn't the best selinux context but hey, it's root) 59112
David Buchanan @retr0.id · 10/05/2026If I have a play integrity bypass, what's the best way to demo it? 0190
David Buchanan @retr0.id · 10/05/2026Do the 3.x betas use the same play integrity + remote c2pa signing flow that the final release will use, just with a "non-trusted" signer? 100
David Buchanan @retr0.id · 10/05/2026frida fails with opaque permission errors so I think I probably will need a root shell before I can try frida 110
David Buchanan @retr0.id · 10/05/2026yup, although I really do want that root prompt just for style points, so now I'm writing a ptrace shellcode injector heh 120
David Buchanan @retr0.id · 10/05/2026now we're cooking - thinking about it, I can probably use this to inject shellcode into pid1 and spawn myself a root shell that way 2281
David Buchanan @retr0.id · 10/05/2026however it looks like ptrace_attach does a different (inlined?) check, so I need to patch that too! 1160
David Buchanan @retr0.id · 10/05/2026I gave up on getting a root shell, since that isn't my real goal here. I just want to be able to inject code into other processes. I patched ptrace_may_access in kernel .text to always return true, so now I can access anything that would normally be gated on that - e.g. /proc/pid/maps. 1190
David Buchanan @retr0.id · 10/05/2026claude's exploit did not work so I'll have to use my brain oldschool style (claude seems repeatedly confused by physical vs virtual address spaces) 1300
David Buchanan @retr0.id · 09/05/2026for this device, the kernel is always at a fixed physical address - so walking kernel structs is easy. so the plan is, find pid1's cred struct and duplicate it into the current process. and also disable DEFEX (which seems easy once the offsets are known) 1220
David Buchanan @retr0.id · 09/05/2026I let claude devise a new LPE strat and I haven't reviewed it, but trying things is ~free 1220
David Buchanan @retr0.id · 09/05/2026and to be clear this is definitely a case of "I already know what I'm doing", but it is saving me a bunch of time and/or effort 130
David Buchanan @retr0.id · 09/05/2026now I'm pointing claude at the headless loader scripts I wrote for github.com/DavidBuchana..., so I should get a nice clean symbolicated kernel loaded in ghidra, with struct layouts, without any manual effort 2191
David Buchanan @retr0.id · 09/05/2026I've had an unlucky streak in terms of getting the exploit to trigger, I'm currently trying to dump all of physmem to a file for analysis but it hasn't landed yet. 1220
David Buchanan @retr0.id · 09/05/2026maybe a better strat would be for me to try to inject shellcode into pid 1, and have it fork and spawn a shell hooked up to a pty 000
David Buchanan @retr0.id · 09/05/2026I'm able to write the memory, it just doesn't like when I set the ruid to 0 100
David Buchanan @retr0.id · 09/05/2026possibly, but my goal is to bypass play integrity and I assume that will check selinux status 020
David Buchanan @retr0.id · 09/05/2026Actually I might be hitting samsung's "DEFEX" mitigations: docs.samsungknox.com/admin/fundam... 3240
David Buchanan @retr0.id · 09/05/2026current plan: dump /sys/kernel/btf/vmlinux out of kernel memory (normally it needs root to read), then I can infer layouts of all the kernel structs I care about, and do more targeted struct-walking instead of pattern scanning 2230
David Buchanan @retr0.id · 09/05/2026ok yeah this is a SELinux Thing™, will need a more intelligent exploit strat. surely there is good prior art of anrdoid phys r/w -> root? 2220
David Buchanan @retr0.id · 09/05/2026plausibly this is a SELinux thing™, I thought I'd keep things simple to start with so I'm just patching cred - if anyone has any guesses what the issue might be lmk 1240
David Buchanan @retr0.id · 09/05/2026debugging it is tedious because it takes several attempts for the phys r/w setup to not crash the whole device 2240
David Buchanan @retr0.id · 09/05/2026succeed at locating the current pid's struct cred, but for some reason died during/after trying to patch it 1310
David Buchanan @retr0.id · 09/05/2026even memory auth doesn't fully fix this, but it would take a modified exploit strat (e.g. block a write during a page table unmap) 110
David Buchanan @retr0.id · 09/05/2026hell yeah - second attempt after this, the r/w primitive worked fully. now I need to figure out the second half of the LPE - overwriting a setuid binary won't work 2400
David Buchanan @retr0.id · 09/05/2026some *very* promising initial results, although it crashed at the end, while trying to test the r/w primitive. plausibly because I flipped too many bits - will keep attempting (this one was on the third attempt, previous attempts just crashed the device) 2410
David Buchanan @retr0.id · 09/05/2026selinux is enforce by kernel so once you pwn kernel it is useless 050