OnePlus Left A Backdoor That Allows Root Access Without Unlocking Bootloader. - Technopweb

Technopweb

Much About Technology And A Bit About Everything

Facebook

Post Top Ad

OnePlus Left A Backdoor That Allows Root Access Without Unlocking Bootloader.

Share This
OnePlus-Root Backdoor
Another awesome news for OnePlus users

Only one month after collecting OnePlaces, personally identifiable information on their users, the Chinese smartphone company has left a backdoor on almost all one-page handsets.

A Twitter user, known as "Elliott Anderson" (named after Mr. Robot's main character), discovered a back door (an exploitation) in all onePlus Devices running the oxygenos, which anyone Could get root access for the device

The application in question "EngineRoad" is a diagnostic testing application created by Qualcomm for device manufacturers to easily test all the hardware components of the device.

It comes pre-installed (accidentally left behind) on most oneplus devices, including the Apke One-Plus 2, 3, 3T, and the newly-launched OnePlus 5. We can confirm its existence on OnePlus 2, 3 and 5.

You can also check if this app is installed on your OnePlus device. For this, just go to Settings, Open App, Enable Show System App from the top right corner menu (three points) in the list and search EngineerMode.APK.
OnePlus

If so, anyone with physical access to your device can take advantage of the engineer's mood to get root access on your smartphone.

An engineer mode has been designed to diagnose issues with the genus, check the device's original position, make a series of automatic 'production line' tests and much more

After decompressing the Engine MOD APK, the Twitter user got 'Diagnostic' activity, which, when opened with a specific password (this is "Angela", found after reverse engineering) users get full root access on the smartphone Allows you to do without unlocking without bootloader

Although the possibility of this application is already being exploited in the wild, it is a serious security concern for OnePlus users as the root access can be obtained by using any simple command.
Root OnePlus- Android Phone

Apart from this, with root access in hand, one attacking victim's oneplug can do many dangerous tasks on the phone, in which sleepless refined forgery malware has been installed, which is difficult to detect or remove.

In the meantime, to protect themselves and their devices, OnePlus owners can simply disable the route on their phones. To do this, run the following command on the ADB shell:

    
"setprop persist.sys.adb.engineermode 0" and "setprop persist.sys.adbroot 0" or call code * # 8011 #
In response to this issue, OnePlus co-founder Carl Pei said that the company is considering this issue.

No comments:

Post a Comment

Search This Blog

Post Bottom Ad