Can Virus Rewrite Permissions? - Security Discussion

Can virus disguised in some apps rewrite permissions to allow them access to personal data?

derod said:
Can virus disguised in some apps rewrite permissions to allow them access to personal data?
Click to expand...
Click to collapse
Don't think they can unless they have root permissions, which the user have to allow/deny (unless the user sets the SuperSU to auto allow, which is stupid)
Smack that Thanks button if I helped!
XDAing from a N7105 powered by Illusion ROM.
Sent from a small country called Singapore.
P.S. Time for school, not much time for XDA

derod said:
Can virus disguised in some apps rewrite permissions to allow them access to personal data?
Click to expand...
Click to collapse
Any application that can gain root privileges can "rewrite" permissions, or give apps permissions they were previously denied. Given if an app can escalate that far, they dont need more permissions.
Second option would be a silent install vulnerability, allowing another app to sideload a new one. Look at my LGInstallServices vulnerability as a prime example.
Irwenzhao said:
Don't think they can unless they have root permissions, which the user have to allow/deny (unless the user sets the SuperSU to auto allow, which is stupid)
Smack that Thanks button if I helped!
XDAing from a N7105 powered by Illusion ROM.
Sent from a small country called Singapore.
P.S. Time for school, not much time for XDA
Click to expand...
Click to collapse
This is incorrect, superuser/supersu would only impact applications using the associated su binary to gain root. it would have no impact on applications gaining root through another route.

jcase said:
Any application that can gain root privileges can "rewrite" permissions, or give apps permissions they were previously denied. Given if an app can escalate that far, they dont need more permissions.
Second option would be a silent install vulnerability, allowing another app to sideload a new one. Look at my LGInstallServices vulnerability as a prime example.
This is incorrect, superuser/supersu would only impact applications using the associated su binary to gain root. it would have no impact on applications gaining root through another route.
Click to expand...
Click to collapse
Sorry for wrong information, and thanks @jcase for the right info.
Smack that Thanks button if I helped!
XDAing from a N7105 powered by Illusion ROM.
Sent from a small country called Singapore.
P.S. Time for school, not much time for XDA

jcase said:
This is incorrect, superuser/supersu would only impact applications using the associated su binary to gain root. it would have no impact on applications gaining root through another route.
Click to expand...
Click to collapse
Youre saying that as long as youre rooted that apps wont be affected by virus?

derod said:
Youre saying that as long as youre rooted that apps wont be affected by virus?
Click to expand...
Click to collapse
Where did I say that? No not at all. Rooting decreases the security of the device.

jcase said:
Where did I say that? No not at all. Rooting decreases the security of the device.
Click to expand...
Click to collapse
Thats what we thought you said.

Irwenzhao said:
Sorry for wrong information, and thanks @jcase for the right info.
Smack that Thanks button if I helped!
XDAing from a N7105 powered by Illusion ROM.
Sent from a small country called Singapore.
P.S. Time for school, not much time for XDA
Click to expand...
Click to collapse
No worries man, if you see me with wrong info please call it out.

Are you sure that the app would need root? I don't need root with CM to change app-permissions.

wk3054 said:
Are you sure that the app would need root? I don't need root with CM to change app-permissions.
Click to expand...
Click to collapse
Thats odd I thought that you would need it.

Related

Super SU Flashed without root on evo lte?

I've searched high and low but yet to find the correct answer. I also can't post in the development thread due to the 10 post limit. It is what it is.
The question that remains to be answered is it possible to have Super SU flashed but still not have full root access?
Back-story: I have an EVO 4g LTE that I rooted using regaw_leinad's one click RegawMOD EVO LTE Rooter. Worked like a charm. Due to unforseen circumstances I received a new EVO LTE and, like a dummy, applied the latest OTA. Well, the one click rooter did not work as planned. Got the phone unlocked and that was it. I still needed to flash Super SU, which I did. I thought all was well and good until I tried using build.prop and found out that I did not have root access, or at least couldn't use build.prop to edit. I tried another build.prop editor and it flat out told me I had no root access, yet Titanium Backup says I do.
Any suggestions?
Moved to General Q&A section.
Still no luck
Some one suggested reflashing Super SU. I did, but still have the same issue.
Have you tried just regular super user instead of super su. Idk exactly how the super user really works besides allowing apps root access. Maybe not all apps have a command to signal super su, but have it to signal super user since its kinda top seat between those two.
Just a thought to try. Its in play store
dumbest thing lately.....miui roms
Did you open the APK to see if binaries need to be updated?
lowandbehold said:
Did you open the APK to see if binaries need to be updated?
Click to expand...
Click to collapse
jaredw444 said:
Have you tried just regular super user instead of super su. Idk exactly how the super user really works besides allowing apps root access. Maybe not all apps have a command to signal super su, but have it to signal super user since its kinda top seat between those two.
Just a thought to try. Its in play store
dumbest thing lately.....miui roms
Click to expand...
Click to collapse
Would it be wise to install Super User with SuperSU already installed or do I need uninstall SuperSU first?
Haven't checked the APK.
It wouldn't hurt, but never messed with supersu so I don't know if it'd interfere
dumbest thing lately.....miui roms
jaredw444 said:
It wouldn't hurt, but never messed with supersu so I don't know if it'd interfere
dumbest thing lately.....miui roms
Click to expand...
Click to collapse
I'm at a loss. I installed Superuser and updated binaries yet still have the same result.
I get the following error running build.prop Editor...
"Error.java.io.FileNotFoundException:/mnt/sdcard/buildprop.tmp: open failed:ENOENT (No such file or directory)
Then I receive this error running BuildProp Editor (different program)...
"No root access is given! This Tool makes heavy use of it. You can't make changes, add propertys nor restore your build.prop file."
What file explorer are you using
Sent from my LG-VM670 using xda app-developers app
jaredw444 said:
What file explorer are you using
Sent from my LG-VM670 using xda app-developers app
Click to expand...
Click to collapse
File Expert v4.2.4 by Geek Wireless Technology and
Root Browser v1.4.0 by JRummy Apps
I'm wondering at this point if it would be possible to reset my phone to before the 1.22 update.
Download rootchecker from the market and run it to see what it says. It seems like you don't have full root.
lowandbehold said:
Download rootchecker from the market and run it to see what it says. It seems like you don't have full root.
Click to expand...
Click to collapse
We may be on to something here. Used rootchecker and another app to check access. Sure enough, I have complete root access...but...busybox is a different story. Downloading busybox as we speak and will post results afterwards. (May take awhile because the Sprint network at this location is SLOW).
truetexan71 said:
We may be on to something here. Used rootchecker and another app to check access. Sure enough, I have complete root access...but...busybox is a different story. Downloading busybox as we speak and will post results afterwards. (May take awhile because the Sprint network at this location is SLOW).
Click to expand...
Click to collapse
And we have liftoff...so to speak. Busybox was the culprit. I ASSUMED during the initail root process that busy box was intalled, it wasn't.
Thanks to everyone.
truetexan71 said:
And we have liftoff...so to speak. Busybox was the culprit. I ASSUMED during the initail root process that busy box was intalled, it wasn't.
Thanks to everyone.
Click to expand...
Click to collapse
Nice! Glad you got it figured out.

ROOT but no need root access managerment

root always provide with superuser or superSU, which I don't need them in fact, I want to grant any app permission they want, how can I do that.
in other word, I want to root access without the permit of superuser or superSU
randommmm said:
root always provide with superuser or superSU, which I don't need them in fact, I want to grant any app permission they want, how can I do that.
in other word, I want to root access without the permit of superuser or superSU
Click to expand...
Click to collapse
why so for example you want a app that you might download that seems fine but gets root access (and as there no manger gets it right away) and then steals all your info and then deletes your android fiel system...sounds good to me
zacthespack said:
why so for example you want a app that you might download that seems fine but gets root access (and as there no manger gets it right away) and then steals all your info and then deletes your android fiel system...sounds good to me
Click to expand...
Click to collapse
I don't care. And I do know what root access mean, I just use app got good reputation, but I do care there are issue cause by superSU or superuser.
randommmm said:
I don't care. And I do know what root access mean, I just use app got good reputation, but I do care there are issue cause by superSU or superuser.
Click to expand...
Click to collapse
Well you should beable to just manually install the SU binary and check its working by typing su in the terminal app or something...
zacthespack said:
Well you should beable to just manually install the SU binary and check its working by typing su in the terminal app or something...
Click to expand...
Click to collapse
That is exactly why I post this question, I don't know where I should put the su binary in.
randommmm said:
That is exactly why I post this question, I don't know where I should put the su binary in.
Click to expand...
Click to collapse
The supersu website has a flashable binary so you can just flash it from recovery (or open the zip and see where it gets put)
Sent from my GT-N7000 using xda premium
zacthespack said:
The supersu website has a flashable binary so you can just flash it from recovery (or open the zip and see where it gets put)
Sent from my GT-N7000 using xda premium
Click to expand...
Click to collapse
not working, every apps need root stop function after uninstall supersu then flash the su binary
The su binaries are written for the su control apps, they probably refuse to grant su without the app being installed.
A not so unwise security decision.
Isn't there an option in SuperSu to grant root to all by default?

[Q] When an app get root access, what can it do?

Hi
I recently rooted my phone and started using a few "root only" apps.
When I look at app permissions and let's say it example says that it can access "Phone" and "Other". By other it means root.
Does that actually gives it permission to anything? So if I accept the permissions "Phone" and "Other" it can actually access my camera too (just an example) or do I understand the root access wrong?
Thanks in advance
what i understand if an apps ask for a root permission, the apps will ask for the permission to read/write in a secure area, eg : /data, /etc
It is different from the permission of using camera, message, etc like when we install apps from playstore.
dubay.yabud said:
what i understand if an apps ask for a root permission, the apps will ask for the permission to read/write in a secure area, eg : /data, /etc
It is different from the permission of using camera, message, etc like when we install apps from playstore.
Click to expand...
Click to collapse
Thanks. Was what I was curious about. As I understood root, as the app could do whatever it wanted to.
No. It is not as you think. By allowing an app root permission, it means you're allowing it to do more than controlling limited applications. It can do more than that. And dont worry it wont damage your phone because everything has its limit but yeah be careful of what you're doing as sometimes you can risk your phone if you(not by allowing an app root permissions) but by using it after giving it root permission. So be careful and know what you're doing.
Please press the thanks button if you think I helped

Debloater 3.7 released

Just letting everyone know of a tool I wrote for both rooted and non-rooted(KitKat) devices. So if your running 4.4.x you can still block all applications even from receiving updates, etc.. Most other apps will not even show the applications in their lists once the tool is run against your device. It is completely safe and will not trip Knox, etc..
http://forum.xda-developers.com/android/software/debloater-remove-carrier-bloat-t2998294
Leave all questions, suggestions, etc. in the thread above.
gatesjunior said:
Just letting everyone know of a tool I wrote for both rooted and non-rooted(KitKat) devices. So if your running 4.4.x you can still block all applications even from receiving updates, etc.. Most other apps will not even show the applications in their lists once the tool is run against your device. It is completely safe and will not trip Knox, etc..
http://forum.xda-developers.com/android/software/debloater-remove-carrier-bloat-t2998294
Leave all questions, suggestions, etc. in the thread above.
Click to expand...
Click to collapse
This has already been done:
http://forum.xda-developers.com/showthread.php?t=2792478
Unless you have a script that is lollipop specific (not done yet...) your tool is redundant and less than useful.
RBThompsonV said:
This has already been done:
http://forum.xda-developers.com/showthread.php?t=2792478
Unless you have a script that is lollipop specific (not done yet...) your tool is redundant and less than useful.
Click to expand...
Click to collapse
My application is far from a script. It is a full application that will work with any release if rooted. If not rooted, it will work native with KitKat, It will also remove all associated data as well with removal, if rooted, and supports Xposed framework as well.
so its pc software to disable system apps? why not just disable them on the device?
either way, nice work (i do not know how to make a exe lol)
Sent from my SM-G900V using XDA Free mobile app
elliwigy said:
so its pc software to disable system apps? why not just disable them on the device?
either way, nice work (i do not know how to make a exe lol)
Sent from my SM-G900V using XDA Free mobile app
Click to expand...
Click to collapse
Thank you. Well, it doesn't just disable apps. Also, most apps you cannot disable on the device without installing some more apps to do it on the device. I am a person who likes less apps on my device. So when I was building this, I thought, do I want to install something to remove something on my device ? Agree to all the access privileges, take up more space, etc ?? So I wrote this.. It will also remove apps and delete all associated data with the app. if rooted. Allow people to share blocked lists and allow you to import and export blocked and unblocked lists as well as many other things.
gatesjunior said:
Thank you. Well, it doesn't just disable apps. Also, most apps you cannot disable on the device without installing some more apps to do it on the device. I am a person who likes less apps on my device. So when I was building this, I thought, do I want to install something to remove something on my device ? Agree to all the access privileges, take up more space, etc ?? So I wrote this.. It will also remove apps and delete all associated data with the app. if rooted. Allow people to share blocked lists and allow you to import and export blocked and unblocked lists as well as many other things.
Click to expand...
Click to collapse
yea, options are always good.. i for one would rather have a rom without the bloat to begin with lol. you can disable most system apps without root in the application manager so you only need to install lets say tibu on rooted devices to remove them but to me tibu is essential for any rom
Sent from my SM-G900V using XDA Free mobile app
elliwigy said:
yea, options are always good.. i for one would rather have a rom without the bloat to begin with lol. you can disable most system apps without root in the application manager so you only need to install lets say tibu on rooted devices to remove them but to me tibu is essential for any rom
Sent from my SM-G900V using XDA Free mobile app
Click to expand...
Click to collapse
Been there. A lot of users want stock though.

NoFrills CPU - Asking for Root on Rooted phone

Hi,
All other apps that require root seem to request it - NoFrills CPU doesn't and consequently offers me no option other than to close the app. Just says "...Root access requires..." - without the usual dialogue affording me the chance to grant it.
Anyone else seen this?
Trying to get a little more life out of my Galaxy S6 by trying a few tweaks.
Thanks...
myotai said:
Hi,
All other apps that require root seem to request it - NoFrills CPU doesn't and consequently offers me no option other than to close the app. Just says "...Root access requires..." - without the usual dialogue affording me the chance to grant it.
Anyone else seen this?
Trying to get a little more life out of my Galaxy S6 by trying a few tweaks.
Thanks...
Click to expand...
Click to collapse
Go into the super user app and see if it shows up there. If it does, grant it root from there.
GDReaper said:
Go into the super user app and see if it shows up there. If it does, grant it root from there.
Click to expand...
Click to collapse
I can't see an option to manually add any apps in the SU App...??
myotai said:
I can't see an option to manually add any apps in the SU App...??
Click to expand...
Click to collapse
I did not say there was any.
I only asked to go inside the app and see if no frills is there with a root denied entry.
Maybe you can set default access to granted. This means that any app will get root access without asking you for permission.
GDReaper said:
I did not say there was any.
I only asked to go inside the app and see if no frills is there with a root denied entry.
Maybe you can set default access to granted. This means that any app will get root access without asking you for permission.
Click to expand...
Click to collapse
thanks, but tried that too - so all apps requiring root are granted it automatically....still asks for root when I start it up.
I did try another app that required root access (can't recall what it was though) and it said that SU wasn't in the expected directory???
Is that any help?
myotai said:
thanks, but tried that too - so all apps requiring root are granted it automatically....still asks for root when I start it up.
I did try another app that required root access (can't recall what it was though) and it said that SU wasn't in the expected directory???
Is that any help?
Click to expand...
Click to collapse
It may cause the problem. How did you root?
By the way, why don't you simply try another app. Kernel adiutor for example. It does the same stuff as no frills, maybe it does it even better.
GDReaper said:
It may cause the problem. How did you root?
By the way, why don't you simply try another app. Kernel adiutor for example. It does the same stuff as no frills, maybe it does it even better.
Click to expand...
Click to collapse
Flashed CF-Root
Yeah you're right, using CPU Tuner, seems to do the job. Also installed Xposed and using Amplify with Greenify and I have to say I have noticed a MASSIVE difference already today
Thanks for your feedback as ever!
magisk killed no frills cpu

Categories

Resources