CVE-2020-12753 + lafsploit? - Security Discussion

was reading up on this vulnerability used to patch the author's lg stylo 4 bootloader: https://douevenknow.us/post/639414006930702336/tying-it-all-together-pwning-to-own-on-lg-phones/amp
has anyone tried this before? anybody interested in getting offsets to patch raw_resources and use lafsploit to write the partition and exploit their old lg devices? it's already patched after may 2020 but maybe previously unrootable devices like the sprint lg g4 zvi can finally be boot loader unlocked

Related

Flashing Recovery Through LAF Partition?

Hi I have seen a method used in the past on LG devices to root using the LAF partition. Certain devices, like the LG G2, had fastboot turned off so people "nuked' the LAF partition (where LG keeps their download mode) as in here, which allowed for fastboot to be able to be accessed.
I also saw a post here where someone was discussing flashing a custom recovery directly in place of the LAF partition so the button combination to access the download mode would instead boot into recovery.
I understand that since the T-Mobile LG G5 has an unlocked bootloader it should be a simple thing to get a custom recovery on our device. However, it has still been a challenge. For those more knowledgable than me please let me know if this is at all a possibility.
On an unrelated note:
A Vietnamese dev team has gotten root on the LG V10 H901 on Marshmallow. Hopefully that bodes well for us also!
http://forum.xda-developers.com/tmobile-lg-v10/general/hopefully-root-h901-t3374723
arjuna) said:
On an unrelated note:
A Vietnamese dev team has gotten root on the LG V10 H901 on Marshmallow. Hopefully that bodes well for us also!
http://forum.xda-developers.com/tmobile-lg-v10/general/hopefully-root-h901-t3374723
Click to expand...
Click to collapse
yes, for sure. on tmo G5 it's the same method for sure.
Maybe another method different from one Codefire used.
We will see
arjuna) said:
On an unrelated note:
A Vietnamese dev team has gotten root on the LG V10 H901 on Marshmallow. Hopefully that bodes well for us also!
http://forum.xda-developers.com/tmobile-lg-v10/general/hopefully-root-h901-t3374723
Click to expand...
Click to collapse
That is awesome news!

twrp wip for lgg4

sorry for cross postin in threads but i had to let more know
after almost 2 years all the locked bls on g4 have had a hack found by hijacking the ramdisk and booting twrp
i have the first sprint lg g4 in the world with twrp on it and it works other than flashing boot and recovery partitions due to still locked bl but efidroid will soon be released as same method and should allow us to boot anything.
now the reason i am posting this here to is cause this could easilly be adapted to almost any device with the requirements of having root and kernel set to permissive and being on lolipop for rite now.
this is a great day for the g4 community with all the hardware issues weve had
yall should check it out
https://forum.xda-developers.com/g4/development/locked-twrpinfish-locked-g4-devices-t3573048

VS99516B update

Didn't see any threads or posts on this one yet. Anyone get the update yet? Android version still says 7.0
718.5 MB is a pretty big file.
Droid- Life just said it's the September security patch, but I got this from LG.
------Reply to Your Inquiry-------
Verizon Wireless is pleased to announce a software update for your device. This software update has been tested to help optimize device performance, resolve known issues and apply the latest security patches. The latest software for the LG V20 for Verizon Wireless is software version VS99516B.
I'm attempting a rollback to 13A, was on 16B (I took the OTA) to run the exploit to gain root access. Looks like it is successful... Will post back if it is not.
Anyone found a KDZ of 16B? I am using a US996 and I flashed the system and kernel from a VS995 with LGUP to use it better on Verizon. So I need a KDZ to update further.

[FIRMWARE] Stock Partition Images for LG Stylo 3 (LS777) Boost Mobile/Sprint/Virgin Mobile

LG Stylo 3 (LS777)
Boost Mobile, Sprint, Virgin Mobile
Android Version: 7.0 Nougat
Kernel Version: 3.18.31
Build No. NRD90U
Software Version: LS777ZVE
Baseband Version:
MPSS.TA.2.3.c4-00034-8940_GEN_PACK-1
Security Patch Level: July 1, 2018
BUILD FEATURES:
• Calling Plus bug fixes (VoLTE/VoWiFi)
• Sprint Caller ID updates
• WiFi Scanning bug fixes
• Audio/Video Codec updates
• Improved Battery Efficiency
OVERVIEW:
This stock firmware for the Boost Mobile LG Stylo 3 is not packaged in KDZ or TOT format, nor is it an official carrier or OEM firmware package. Rather, this archived package consists of all partition images encompassed in the stock GPT index. As such, utilities such as LG Flash Tool and LG Bridge are not viable options for installation. This package consists of 57 unmodified partition images dumped from the Boost Mobile LG Stylo 3, including /system, /boot, /recovery, /laf, /modem, /fsg, etc., archived into a zip format file. These images can be used to fully restore an LG Stylo 3 (LS777) to a factory stock state. Please note that this firmware is not the latest build for the LS777. The latest build is LS777ZVH with a security patch level of January 1, 2019. I will include that package here as well once I have time to archive the partition images and upload the zip.
INSTALLATION:
The manner in which you use or install this firmware package is completely up to you. This thread is not intended to be an installation guide or restoration tutorial -- it is intended as a resource only, for stock firmware images. I can confirm that these images may be installed using LG-UP Dev Edition, by selecting the PARTITION DL option to flash partitions individually. But again, the manner in which you use these stock images is entirely your prerogative. Simply download the package from the below link and extract the contents to your desired directory.
DISCLAIMER:
By downloading this firmware package, you are assuming sole responsibility for your device with respect to the manner in which you use this firmware. Please do not blame me in the event something goes wrong. I have restored my own LS777 using partition images from this package. However, I am not responsible or liable for any adverse consequences that may occur during your own installation of these images.
NOTES:
There are very few scenarios that would require flashing all 57 partition images. Typically, for a soft bricked device, or a device which will not otherwise boot into the Android OS, flashing only the system.img and boot.img should fix your device. For radio, data connection or cell signal problems, install modem.img and fsg.img to restore the baseband radio firmware. In a nutshell, tailor your installation to the particular needs of your device.
NOTICE: flashing.bootloader type partitions can be very risky (/rpm, /aboot, /sbl1, etc.). Do not flash sensitive partitions unless you know what you are doing. Also, because the LS777 has a locked down bootloader, flashing any type of patched or modified boot image to the device will result in a SECURE BOOT ERROR and failure to boot into the OS. Root can only be attained by pushing a pre-rooted system image to your device using LG-UP Dev Edition, which will install system-wide root binaries (/system/xbin/su). A root management application such as SuperSU can then be used. However, this is for informational purposes only, as this is not an installation guide, rooting tutorial, etc. This thread is intended as a resource only. On a final note, in the event you have a more recent build than LS777ZVE, flashing this firmware using the modded LG-UP will allow downgrading of the firmware build. You may subsequently install any pending OTA updates to bring the firmware build up to the latest version.
LS777ZVE Download Link: https://drive.google.com/file/d/1-N--U88RBd00AzZMVCgznayH8QOnGye9/view?usp=drivesdk
Can you get LGL83BL Firmware?
Viva La Android said:
LG Stylo 3 (LS777)
Boost Mobile, Sprint, Virgin Mobile
Android Version: 7.0 Nougat
Kernel Version: 3.18.31
Build No. NRD90U
Software Version: LS777ZVE
Baseband Version:
MPSS.TA.2.3.c4-00034-8940_GEN_PACK-1
Security Patch Level: July 1, 2018
BUILD FEATURES:
• Calling Plus bug fixes (VoLTE/VoWiFi)
• Sprint Caller ID updates
• WiFi Scanning bug fixes
• Audio/Video Codec updates
• Improved Battery Efficiency
OVERVIEW:
This stock firmware for the Boost Mobile LG Stylo 3 is not packaged in KDZ or TOT format, nor is it an official carrier or OEM package. As such, utilities such as LG Flash Tool and LG Bridge are not viable options for installation. This package consists of 57 unmodified partition images dumped from the Boost Mobile LG Stylo 3, including /system, /boot, /recovery, /laf, /modem, /fsg, etc., archived into a zip format file. These images can be used to fully restore an LG Stylo 3 (LS777) to a factory stock state. Please note that this firmware is not the latest build for the LS777. The latest build is LS777ZVH with a security patch level of January 1, 2019. I will include that package here as well once I have time to archive the partition images and upload the zip.
INSTALLATION:
The manner in which you use or install this firmware package is completely up to you. This thread is not intended to be an installation guide or restoration tutorial -- it is intended as a resource only for stock firmware images. I can confirm that these images may be installed using LG-UP Dev Edition, by selecting the PARTITION DL option to flash partitions individually. But again, the manner in which you use these stock images is entirely your prerogative. Simply download the package from the below link and extract the contents to your desired directory.
DISCLAIMER:
By downloading this firmware package, you are assuming sole responsibility for your device with respect to the manner in which you use this firmware. Please do not blame me in the event something goes wrong. I have restored my own LS777 using partition images from this package. However, I am not responsible or liable for any adverse consequences that may occur during your own installation of these images.
NOTES:
There are very few scenarios that would require flashing all 57 partition images. Typically, for a soft bricked device, or a device which will not otherwise boot into the Android OS, flashing only the system.img and boot.img should fix your device. For radio, data connection or cell signal problems, install modem.img and fsg.img to restore the baseband radio firmware. In a nutshell, tailor your installation to the particular needs of your device.
NOTICE: flashing.bootloader type partitions can be very risky (/rpm, /aboot, /sbl1, etc.). Do not flash sensitive partitions unless you know what you are doing. Also, because the LS777 has a locked down bootloader, flashing any type of patched or modified boot image to the device will result in a SECURE BOOT ERROR and failure to boot into the OS. Root can only be attained by pushing a pre-rooted system image to your device using LG-UP Dev Edition, which will install system-wide root binaries (/system/xbin/su). A root management application such as SuperSU can then be used. However, this is for informational purposes only, as this is not an installation guide, rooting tutorial, etc. This thread is intended as a resource only. On a final note, in the event you have a more recent build than LS777ZVE, flashing this firmware using the modded LG-UP will allow downgrading of the firmware build. You may subsequently install any pending OTA updates to bring the firmware build up to the latest version.
LS777ZVE Download Link: https://drive.google.com/file/d/1-N--U88RBd00AzZMVCgznayH8QOnGye9/view?usp=drivesdk
Click to expand...
Click to collapse
Can you get TracFone Firmware for the Stylo 3? Model number LGL83BL.
hydroman202 said:
Can you get TracFone Firmware for the Stylo 3? Model number LGL83BL.
Click to expand...
Click to collapse
I'm sorry but I don't own that variant. I pulled this firmware from my own LS777. You can use LG-UP Dev Edition to dump the firmware images from your device partitions. Root isn't needed.
hydroman202 said:
Can you get TracFone Firmware for the Stylo 3? Model number LGL83BL.
Click to expand...
Click to collapse
I had meant to tell you also, if you are needing firmware to repair or restore a non-working LGL83BL, ask on the device forums for an owner of the TracFone variant to dump his/her partition images and upload them for you to install using LG-UP.
Lg stylo 3 ls777 hard bricked
I have an lg stylo 3 that got stuck on the lg life’s good powered by android screen so I took out the battery and put it back in and tried to turn it on again and it wouldn’t turn on and it is now stuck in Qualcomm hs usb qd loader mode, does anyone have the Qualcomm firehose programmer for the lg stylo 3 ls777
chris2288 said:
I have an lg stylo 3 that got stuck on the lg life’s good powered by android screen so I took out the battery and put it back in and tried to turn it on again and it wouldn’t turn on and it is now stuck in Qualcomm hs usb qd loader mode, does anyone have the Qualcomm firehose programmer for the lg stylo 3 ls777
Click to expand...
Click to collapse
I'll reach out to my sources over at 4PDA and check on blankflash files for the LS777. Your issue seems to be more related to hardware than firmware. Unless you corrupted your bootloader /sbl1 partition, your hard brick status would not seem firmware related. But in any event, it's definitely worth trying at this point. I'll see what I can find. Out of curiosity, have you done any system-level modifications on your LS777 at any time prior to its current status?
No luck on locating a blankflash file for reviving the LS777 from a hard brick. While searching I did stumble across a promising method for recovering hard bricked Qualcomm devices by way of remapping and rewriting the entire eMMC partition table to an external microSD card and then booting your device thus. You may want to check this out @chris2288
https://forum.xda-developers.com/g-pad-7/help/qd-9008-fix-tested-lg-v410g-pad-7-0-att-t3269057
Viva La Android said:
I'll reach out to my sources over at 4PDA and check on blankflash files for the LS777. Your issue seems to be more related to hardware than firmware. Unless you corrupted your bootloader /sbl1 partition, your hard brick status would not seem firmware related. But in any event, it's definitely worth trying at this point. I'll see what I can find. Out of curiosity, have you done any system-level modifications on your LS777 at any time prior to its current status?
Click to expand...
Click to collapse
I have not done any modifications to the system, it just randomly got stuck on lg lifes good screen with the red led on, then i pulled the battery so i can restart it and see if it would boot up the 2nd time but it didn't turn on
chris2288 said:
I have not done any modifications to the system, it just randomly got stuck on lg lifes good screen with the red led on, then i pulled the battery so i can restart it and see if it would boot up the 2nd time but it didn't turn on
Click to expand...
Click to collapse
It sounds almost definitely like hardware failure. But, again, it sure cannot hurt to try restoring it on the firmware side. I've not found any blankflash files for the LS777, but you may want to check out the link I posted above.
pregunto. tengo un lsv777ZVH que por intentar unlock perdio banda base. mi pregunta es este software le sirve para este equipo ?
javierjr12 said:
pregunto. tengo un lsv777ZVH que por intentar unlock perdio banda base. mi pregunta es este software le sirve para este equipo ?
Click to expand...
Click to collapse
I translated your question. It looks as though you are asking if the firmware will work on 777ZVH. It should work fine. The version I posted, 777ZVE, is merely an earlier release version than 777ZVH. The baseband should work. You will want to use the modem.img and the fsg.img files.
Where do I get LG up dev addition
YYou
cryptojoe37 said:
Where do I get LG up dev addi
Click to expand...
Click to collapse
You can download a verified safe build of LG-UP Lab Edition or Dev Edition from this link:
LGUP Ver 1.15, LGUP 1.16 for LG V50, LG G8 ThinQ
LGUP flash tool 1.17 is a new flashing tool to flash kdz/tot/bin format LG Stock firmware onto your LG Phones. You can use LGUP to upgrade or downgrade the software of your device. You even can unbrick a soft-bricked LG device by flashing stock kdz firmware with LGUP.
www.mylgphones.com
The Lab and Dev Editions both include the Partition DL feature, which allows you to flash partition images to the device. Ensure the image you are flashing has a file extension of .img or .bin.

Rooting Options for G970U1 Snapdragon Model

I have decided its time to root my device. How do I go about this for the G970U1 Snapdragon model? All the guides I've found only cover the other CPU model. Is it even possible? I can't find the OEM/Bootloader unlock option in dev options. I probably shouldn't have waited this long...
Hi, for what i know, it depends on your current firmware version installed. Past march 2021 patches should not let you unlock the bootloader and with that gain control of root or change os. I am waiting for someghing to happen too like android 12 and oneui 4
As of 3-7-22 Lapsus$ stole exploitable data from samsung and released it. This data included snapdragon CPU data and most likely includes information on how to unlock the latest u6 bootloader.
I have s10e US g970u1 model on the aug 1st 2021 security update. So U6 bootloader. As far as i understand there is no unlock/root unless you have the u3 bootloader or lower.
We will have to continue to wait for the lapsus$ data to be exploited for root purposes as I think that is the best we will get.
Reading other topics its very confusing, there are a lot of u3 bootloader unlocking and rooting and then the rest on later bootloaders being unsuccessful. U7 bootloader is about to be released for the s10e and will likely patch the code in u6 that was released by Lapsus$. so dont update.

Categories

Resources