How to check if phone has been tamped with - Samsung Galaxy S8+ Questions & Answers

Hi, i have ordered a Samsung S8+ that was discounted as it had left the store and been returned and I'm a paranoid guy so.
Is there any way to check if the software on the phone has been tampered with?
I live in Sweden so its a Exynos version.
Would a factory reset restore the device to its original state?

Petoj87 said:
Hi, i have ordered a Samsung S8+ that was discounted as it had left the store and been returned and I'm a paranoid guy so.
Is there any way to check if the software on the phone has been tampered with?
I live in Sweden so its a Exynos version.
Would a factory reset restore the device to its original state?
Click to expand...
Click to collapse
Put it in Download Mode, and check the KNOX Flag. If it's 0x0, The phone's cherry is still not popped.

JazonX said:
Put it in Download Mode, and check the KNOX Flag. If it's 0x0, The phone's cherry is still not popped.
Click to expand...
Click to collapse
Does Magisk trigger KNOX?
If the KNOX flag is popped so to say , does a factory reset unpop it?

Petoj87 said:
Does Magisk trigger KNOX?
Click to expand...
Click to collapse
Yes, As Magisk is installed through TWRP.
Petoj87 said:
If the KNOX flag is popped so to say , does a factory reset unpop it?
Click to expand...
Click to collapse
Once the Knox is 0x1, There is no way yet to put it back to 0x0

If you are okay with the phone being rooted or knox being tripped you can installed TWRP on it and wipe the internal storage and then use ODIN to flash stock firmware. Anything that could have been tampered with on the phone should get erased then.

ShrekOpher said:
If you are okay with the phone being rooted or knox being tripped you can installed TWRP on it and wipe the internal storage and then use ODIN to flash stock firmware. Anything that could have been tampered with on the phone should get erased then.
Click to expand...
Click to collapse
Lots of software checks for KNOX, and if it's not the factory default value (i.e it isn't 0x0 but 0x1), it won't run. Only solution is a custom firmware that hides this from these software.

Petoj87 said:
Hi, i have ordered a Samsung S8+ that was discounted as it had left the store and been returned and I'm a paranoid guy so.
Is there any way to check if the software on the phone has been tampered with?
I live in Sweden so its a Exynos version.
Would a factory reset restore the device to its original state?
Click to expand...
Click to collapse
Install this app and you will find everything.
https://play.google.com/store/apps/details?id=org.vndnguyen.phoneinfo

Related

How to OTA on a rooted S6?

When I try to check for updates it tells me that my device has been updated in an unauthorized way. Is there a way to fix this aside from unrooting my device and reflashing stock?
would rootcloak fix this....once we get xposed.
ke9n said:
When I try to check for updates it tells me that my device has been updated in an unauthorized way. Is there a way to fix this aside from unrooting my device and reflashing stock?
Click to expand...
Click to collapse
No, when you root your phone the knox counter go to 0x0 to 0x1 and that is the issue, no ota updates with konox 0x1 only via odin.
jah2110 said:
No, when you root your phone the knox counter go to 0x0 to 0x1 and that is the issue, no ota updates with konox 0x1 only via odin.
Click to expand...
Click to collapse
Knox stays untripped with PingPong-root. But the OTA update thing finds that the phone has been tampered with so you can't get any OTAs through your phone. I guess we'll have to update with Smart Switch and re-root afterwards?
ZoZo- said:
I guess we'll have to update with Smart Switch and re-root afterwards?
Click to expand...
Click to collapse
I would imagine someone will upload a file to flash through Odin to update. That will surely trip Knox though. If we're lucky we can do what you said (If that exploit isn't patched in 5.1).
I'm guessing as this is only my third smartphone, and the first two where HTC.
If you have root you can flash official firmware from Sammobile through Odin, that gets rid of root and any modified system settings and then you will be able to update ota. The best part is that it keeps your data in tact and also not trip Knox counter
mellomelon45 said:
The best part is that it keeps your data in tact
Click to expand...
Click to collapse
By "data" do you really also mean all programs with their data included?
Dmitry N said:
By "data" do you really also mean all programs with their data included?
Click to expand...
Click to collapse
Yes that is correct
jah2110 said:
No, when you root your phone the knox counter go to 0x0 to 0x1 and that is the issue, no ota updates with konox 0x1 only via odin.
Click to expand...
Click to collapse
But if you reflash stock-rom via Smart Switch, you can get OTA again.

KNOX 0*1 >> Can i still get OTA updates?

Hi Guys!
(I don't care whole knox thing, even warranty)
Can i still get ota updates if i got knox warranty void 0x1(phone into *samsung*)?
Of course i flashed stock firmware back with odin.
In downloading mode i get
Current Status: Samsung Official
System Status: Official
Knox warranty void: 1 (0*0301)
Knox doesnt affect ota updates. Only root disables ota.
Is it possible to set the code back? Im on 5.1.1
gersp said:
Is it possible to set the code back? Im on 5.1.1
Click to expand...
Click to collapse
Absolutely not.
Snowby123 said:
Absolutely not.
Click to expand...
Click to collapse
What do you mean by absolutely not? I thought Triangle Away resets the KNOX tripping. And I was reading it still worked on S6... Are you saying it's impossible to "un-trip" KNOX now?
hamstrman said:
What do you mean by absolutely not? I thought Triangle Away resets the KNOX tripping. And I was reading it still worked on S6... Are you saying it's impossible to "un-trip" KNOX now?
Click to expand...
Click to collapse
As of now, unfortunately yes. There is no way
hamstrman said:
What do you mean by absolutely not? I thought Triangle Away resets the KNOX tripping. And I was reading it still worked on S6... Are you saying it's impossible to "un-trip" KNOX now?
Click to expand...
Click to collapse
Triangle away doenst reset the Knox counter, it resets the flash counter. This is very different.
There is no tool which can reset the Knox counter.
XxM4tzexX said:
Triangle away doenst reset the Knox counter, it resets the flash counter. This is very different.
There is no tool which can reset the Knox counter.
Click to expand...
Click to collapse
So the two years that I've had my S5 rooted, my warranty was voided and irreversible? Huh. I've never needed any assistance from Sprint and I'm hoping I won't now. Makes me feel better to know that I'm in no different a position than I have been. I just have to hope my phone works perfectly.
Would that affect my ability to sell my S5 back to Sprint? Sorry if I'm not on this thread's topic exactly... Should I end my line of questioning in this thread?
Just keep flashing the latest updates on your own by getting stock firmware and using Odin, that's what I would do if I ever went back to a non-rooted device - might go back just to try Samsung Pay.

Unroot S7 Edge (GM-G935F) to official stock? Set Knox to 0x0 ? (back to untouched)

Hello guys. Just a short but very important question. I'll root my S7 Edge incl. TWRP. I've made some experience in past with rooting, customizing and so on... In almost every case I noticed performance issues. In past I tried do flash the stock firmwares to get it to the original back again, but I didn't get any offcial updates about OTA. Its my first Samsung smartphone and I read there is a problem with Knox (security system for customization).
So: If I root and so on, is there any REAL solution to get it in the current untouched original state back incl. the untouched Knox status? (can I completely backup the current firmware and data so that have in case of issue just to flash it back?)
Hope you understand my thoughts
Metero said:
Hello guys. Just a short but very important question. I'll root my S7 Edge incl. TWRP. I've made some experience in past with rooting, customizing and so on... In almost every case I noticed performance issues. In past I tried do flash the stock firmwares to get it to the original back again, but I didn't get any offcial updates about OTA. Its my first Samsung smartphone and I read there is a problem with Knox (security system for customization).
So: If I root and so on, is there any REAL solution to get it in the current untouched original state back incl. the untouched Knox status? (can I completely backup the current firmware and data so that have in case of issue just to flash it back?)
Hope you understand my thoughts
Click to expand...
Click to collapse
Hi
Untouched firmware ...yes . just reflash a stock firmware
Reset knox back to 0 x 0 ......not possible , at least not at the moment
MAX 404 said:
Hi
Untouched firmware ...yes . just reflash a stock firmware
Reset knox back to 0 x 0 ......not possible , at least not at the moment
Click to expand...
Click to collapse
thank you. so it could be possible in future to set an almost changed knox value to 0x0? or just to prevent any change of the knox?
just another thought about bypassing knox... if it would be possible wouldn't it be a >big< security problem for samsung payment? not just for the costumer but for the seller?
what is actually the best method of rooting? is threre any difference? i found the CF auto root and the TWRP method (rooting after flashing the recovery). Just the difference between recovery or not?
Metero said:
thank you. so it could be possible in future to set an almost changed knox value to 0x0? or just to prevent any change of the knox?
just another thought about bypassing knox... if it would be possible wouldn't it be a >big< security problem for samsung payment? not just for the costumer but for the seller?
Click to expand...
Click to collapse
Hi
Bypass knox bit setting to one , has been possible in older models and there been some progress and success in the S7 family but resetting it back to 0 never been possible
The e fuse 0 x 1 is not a security issue at all is just a way for Samsung to know you been messing with the device , you can reflash a stock firmware (odin) , have the knox bit set and be 1000% safe and knox security cover...
MAX 404 said:
Hi
Bypass knox bit setting to one , has been possible in older models and there been some progress and success in the S7 family but resetting it back to 0 never been possible
The e fuse 0 x 1 is not a security issue at all is just a way for Samsung to know you been messing with the device , you can reflash a stock firmware (odin) , have the knox bit set and be 1000% safe and knox security cover...
Click to expand...
Click to collapse
yea for sure. but when you could costumize the software and the knox wouldn't change, samsung payment would be fully functional, you know? or doesn't it matter for samsung payment, if you change the knox value or not?
Metero said:
yea for sure. but when you could costumize the software and the knox wouldn't change, samsung payment would be fully functional, you know? or doesn't it matter for samsung payment, if you change the knox value or not?
Click to expand...
Click to collapse
Samsung payment or knox does not care about the e fuse ( 0x 1 ) state , it cares about the integrity of the firmware installed , for example if stock firmware is flashed knox will see the system as original regardless of the e fuse state
MAX 404 said:
Samsung payment or knox does not care about the e fuse ( 0x 1 ) state , it cares about the integrity of the firmware installed , for example if stock firmware is flashed knox will see the system as original regardless of the e fuse state
Click to expand...
Click to collapse
That goes against everything I've seen about Samsung Pay (or even Knox). Once you've tripped it (0x1) there's no way to get it back. Samsung Pay will not work even if you re-flash stock (unrooted) rom.
Sent from my SM-G930W8 using Tapatalk
Devhux said:
That goes against everything I've seen about Samsung Pay (or even Knox). Once you've tripped it (0x1) there's no way to get it back. Samsung Pay will not work even if you re-flash stock (unrooted) rom.
Sent from my SM-G930W8 using Tapatalk
Click to expand...
Click to collapse
Hi
my bad you are right , knox tripped no samsung pay

Unroot?

Is there a way to fully unroot and return this phone to stock at this time? Im assuming root will also trip the knox counter - can this be undone? I often resell my phones on Craigslist when I upgrade and I wanna make sure I can sell it right.
Just flash the stock firmware, knox can't be undone, and the amount of people that checked if my previous phones were rooted is none.
DinoSoup said:
Is there a way to fully unroot and return this phone to stock at this time? Im assuming root will also trip the knox counter - can this be undone? I often resell my phones on Craigslist when I upgrade and I wanna make sure I can sell it right.
Click to expand...
Click to collapse
Depends, root doesn't trip Knox counter for snapdragon devices, so you fully unroot them just like before
peachpuff said:
Just flash the stock firmware, knox can't be undone, and the amount of people that checked if my previous phones were rooted is none.
Click to expand...
Click to collapse
Doesn't atripped knox disable Samsung pay though?
DinoSoup said:
Doesn't atripped knox disable Samsung pay though?
Click to expand...
Click to collapse
Most likely, you also won't get updates anymore.
You'll have to sell root as a feature, somehow, when getting rid of the phone.
I rooted my S8+ three days ago it was all good except a crazy bixby home app crash. It made me crazy . So i dowloaded stock firm g955u verison.
After flashing it again using odin . I had an error ... I reboot again and did a factory reset ... .and it s all good now . .. unrooted with full functionalities

Rooted phone?

Okay so my device is Galaxy S7 and I had it rooted and running LineageOS for a few days. Because of security, I decided to install stock firmware using Odin. This runs well as stock. Play store and phone info sata this is certified and official software. SafetyNet gets everything passed and says no root. But still my Samsung apps cant run, since they think this is rooted... What to do? Can there be some files left?
Henubenu said:
Okay so my device is Galaxy S7 and I had it rooted and running LineageOS for a few days. Because of security, I decided to install stock firmware using Odin. This runs well as stock. Play store and phone info sata this is certified and official software. SafetyNet gets everything passed and says no root. But still my Samsung apps cant run, since they think this is rooted... What to do? Can there be some files left?
Click to expand...
Click to collapse
What country / region ?
What firmware? 7.0? 8.0?
Where did you get the firmware?
Did you flash with Odin?
Henubenu said:
Okay so my device is Galaxy S7 and I had it rooted and running LineageOS for a few days. Because of security, I decided to install stock firmware using Odin. This runs well as stock. Play store and phone info sata this is certified and official software. SafetyNet gets everything passed and says no root. But still my Samsung apps cant run, since they think this is rooted... What to do? Can there be some files left?
Click to expand...
Click to collapse
After rooting your phone warranty will be set to 1.
You can check by going to download mode and reading the property : Warranty void
If its a 1 you can never use these apps again for security reasons
kpwnApps said:
After rooting your phone warranty will be set to 1.
You can check by going to download mode and reading the property : Warranty void
If its a 1 you can never use these apps again for security reasons
Click to expand...
Click to collapse
This isn't correct, once you flash back to stock with Odin the security is restored. The knox counter trip means the warranty is void because the phone had been rooted etc
cooltt said:
This isn't correct, once you flash back to stock with Odin the security is restored. The knox counter trip means the warranty is void because the phone had been rooted etc
Click to expand...
Click to collapse
Yes it is. The apps dont check the status of your phone they check ro.boot.warranty_bit
cooltt said:
What country / region ?
What firmware? 7.0? 8.0?
Where did you get the firmware?
Did you flash with Odin?
Click to expand...
Click to collapse
I downloaded the nordic country most recent one. So I guess its 8.0... And got recommendations for SamMobile. And yes, I used Odin to flash this firmware.
kpwnApps said:
Yes it is. The apps dont check the status of your phone they check ro.boot.warranty_bit
Click to expand...
Click to collapse
Is there a way to modify that?
Henubenu said:
Is there a way to modify that?
Click to expand...
Click to collapse
Yes, but ask @kpwnApps because clearly he knows more than anyone else on the forum. We're all too stupid.
Henubenu said:
Is there a way to modify that?
Click to expand...
Click to collapse
You cannot modify that anymore you need to replace your mainboard

Categories

Resources