Can you unlock and root Kyocera E4810?

Sorry for polluting the thread(maybe), but could you tell me if the Binder UAF exploit you used is ARMv7, and if so, could you provide a binary/source for it, I have a KYF31 I would like to root :slight_smile:

If you do gain root access (or even beforehand if you reach out), I’d appreciate if you can send me your aboot partition for additional testing.

I need root to get my aboot, no other way to get a dump as far as I know, and there’s no public firmware available either …

But you don’t flash just aboot, right? Right?

We literally can root it via web app and webusb, it’s just a backdoor in kyocera diag tools, nothing fancy. And it’s 100% working all the time, zero cons. I’d like to see PoC for binder vulnerability, I did research it before it was a mainstream, found a few issues with potential attack vectors, but couldn’t exploit them at all. @Tech_Gear can you share a public PoC?

2 Likes

Really unfortunate there’s no backdoor on my Kyocera that I can use.
There was supposed to be a diag mode on *#*#76278#*#*, unfortunately the USB mode is broken and it switches right back to mtp,adb

You have it by design if your device runs kyocera diag kit (check running ky* apps under system user)

Can you provide what apps exactly?
Any way to tap into them, or use them?
I tried Kyocera-Diag-Interface but considering this build doesn’t provide a CDROM interface, it obviously failed.

I’m so sorry, I can’t get back to this project properly, but I do think @BenTorah released publicly all the ingredients already (if not, I’d ask explicitly to share publicly all the source code I’ve shared privately previously). Also, the last thing I found working on 4610 - it’s possible to activate a proper debug mode even without CD-ROM init, there’s yet another backdoor that allows to switch the device in a proper state by adb directly.

My apologies, this entire thing is my big love, but every time I’m diving in, I’m forgetting all my current obligations, and just grinding going to the rabbit hole. I can’t afford going back yet

3 Likes

No problems, I’m just glad someone more skilled than me did the research :slight_smile:

Correct. The Japanese variants do not expose a CDROM interface or have a System Update mode.

The diag stack still exists on the phones. I don’t remember/am not familiar how trigger it via ADB, but that would be the way in
You can then interface with Kyocera Diag Interface

1 Like

Can you give me any way to contact you outside the forums?
I want to hear more about the research done here.

There is a large amount of information to be found in this thread.
If you still have questions,
Telegram @RealBenTorah

1 Like

I don’t have to l the device not do I know anything about it’s diag backdoor stuff. But regarding the binder exploit, I modified the exploit to work on a different arm32 kernel (sonim xp3). I hardcoded all offsets and they are probably different on other devices but it’s a good starting point since it solves a major issue on arm32. GitHub - flipphoneguy/root-sonim-xp3800: app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included Ā· GitHub

3 Likes

B"H — picking up the E4830 (AT&T DuraXE Epic) question from earlier in this thread. I have an E4830 on the bench and I’m trying to run the same downgrade-attack approach BenTorah documented for the E4810.

Since the E4810 magic-aboot won’t match the E4830’s HW_ID, I’m trying to source the two model-specific pieces:

  1. An older E4830 / E4830NC production aboot (matching HW_ID) that still has the fastboot unlock commands intact — or a full older E4830 firmware/OTA I could extract one from. Current build on my unit is 1.001AT.0141.a, so I’d need something older than that.

  2. The AT&T fastboot-entry path — does the E4830 expose the same ā€œSoftware Updateā€ CD-ROM + carrier upgrade tool that you kill on reboot to land in FASTBOOT, like the VZW tool on the E4810? Or is the SD-card DEVKEYDL (NOTPUSH/CHKCODE) route the way in on this one?

Has anyone made headway on the E4830 specifically, or know where an older AT&T DuraXE Epic image lives? I’m glad to dump and share whatever I can read from my unit (HW_ID / PKHASH / partition table) to help crack it. Big thanks to @ars18 @leobuskin and everyone for the groundwork.

4 Likes

Ping me later so I don’t forget. You have a few possible options.

Welcome to the forum! You were mentioned a few times over here already.
You can also ask for an official badge over here

1 Like

Yep, you all got it right. But this flip phone flashing that I’m talking here is a side project. The bombshell I’m about to drop on iVelt and everyone else is just waiting for the right moment.
Yoel Klein

2 Likes

First things first

When you plug into pc, and check USB options on the phone, do you have a system update/upgrade option?

Second, do you have any updates available (don’t update)?

Third, oem unlock is available to toggle?

Nothing bad can happen if you try. If that works, I can work with you on pulling the firmware.

There are a few routes to attempt depending on what your answers will be.

Is this for commercial purposes?