Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No password protection on superuser #2

Open
GoogleCodeExporter opened this issue Jul 30, 2015 · 0 comments
Open

No password protection on superuser #2

GoogleCodeExporter opened this issue Jul 30, 2015 · 0 comments

Comments

@GoogleCodeExporter
Copy link

What steps will reproduce the problem?
1. Install superuser on a rooted android phone
2. Open a shell and run 'su'
3. Note that you're asked if you want to give that app permission to run as 
super-user, but there 
is no password.

What is the expected output? What do you see instead?

I expect to be asked for a password before being granted su access.  As it 
stands, this looks like 
it could be used by someone who got hold of my phone to, for example, get my 
gmail password 
from the gmail app.

Now I know that with physical access they could always flash the phone anyway, 
but this changes 
the attack from 'root the phone', including multiple restarts, to 'enter a few 
shell commands'.

The fix could be something as simple as enabling the lock screen (requiring the 
user the unlock 
the phone, even if the lock screen is not normally enabled) when bringing up 
the 'allow'/'deny' 
screen.  That would add a password, but in a way that is relatively unobtrusive.

Original issue reported on code.google.com by will.ut...@gmail.com on 16 Jan 2010 at 9:18

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant