Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

hashroot

a way to get root (in a limited SELinux context) without bootloader unlock on all Pico headsets (only tested on a Pico 4 Enterprise)

using

drop hashsu.sh into /sdcard like so with adb:

adb push hashsu.sh /sdcard/hashsu.sh

you can now just run

adb shell /system/bin/sh /sdcard/hashsu.sh -c 'id'

and get back

uid=0(root) gid=0(root) groups=0(root),1003(graphics),1006(camera) context=u:r:pvrtrackingservice:s0

you now have root!

how

all pico headsets ship with a system service called pvrtracking, it registers a android Binder interface, with one code to get a md5 checksum of a file.

it does this by doing popen("md5sum <usercstring>", "r"). popen is notably a /bin/sh -c wrapper, meaning we can do a command injection to gain code execution in the context and do whatever we want.

SELinux will prevent us calling this Binder normally but adb service call luckily can, but the types it accepts don't have a byte vector, so we have to get creative by encoding a byte vector into a set of i32s, you can see this achieved in generate_service_call.py (which you do not have to touch)

so our payload is as simple as a Parcel with a byte vector of $(/system/bin/sh /sdcard/hashroot-run.sh) that we send to the service, and it will run it as root

further work

various other system services may be vulnerable to similar things which could allow us to escalate our SELinux context even further and even maybe get KernelSU running, somehow, some way. i tried looking into it and there's a lot of promising gadgets but nothing conclusive.

if you want true root, go to pico4.wiki

About

command injection exploit in the Pico VR headsets tracking service to gain root

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages