|
2016-09-17
, 00:54
|
Posts: 262 |
Thanked: 315 times |
Joined on Jun 2010
|
#33
|
Both programs that MicroB is comprised of (browser and browserd), run as the user user. For the two points above to be possible, a vulnerability would need to be exploited in the kernel or some other software. This may be possible indirectly through some other MircoB exploit, otherwise MicroB itself is completely safe from these.
|
2016-09-17
, 22:40
|
|
Posts: 634 |
Thanked: 3,266 times |
Joined on May 2010
@ Colombia
|
#34
|
If arbitrary code execution was possible, even as the user user from MicroB, yes, you're correct that they wouldn't be able to encrypt your files at the filesystem level, but wouldn't they still be able to delete/encrypt/corrupt/copy them on an individual basis?
|
2016-09-19
, 00:20
|
|
Posts: 634 |
Thanked: 3,266 times |
Joined on May 2010
@ Colombia
|
#35
|
$ debbie midori -e Fullscreen -a https://m.uber.com
|
2016-09-19
, 00:42
|
Posts: 262 |
Thanked: 315 times |
Joined on Jun 2010
|
#36
|
An arbitrary code execution exploit in MicroB would give an attacker the same privileges as the user user. This normally means they would have read/write access to everything under /home/user including MyDocs. This assumes that the device owner hasn't done anything stupid to weaken the security. One thing that I forgot is that many users here use rootsh without a password which would of course gives the attacker full access to the device.
If you ask me, Maemo is very broken in this respect. It's not that hard for an attacker to create some malware, create multiple Garage accounts and then vote it up for promotion to Extras. Actually, they probably don't even need to do that. They can just enable Extras-devel and install anything from that. It's part of the reason why I want to replace Maemo with Debian.
|
2016-09-19
, 08:51
|
|
Posts: 868 |
Thanked: 2,516 times |
Joined on Feb 2012
@ Germany
|
#37
|
If anyone has any spare time, it would be nice to update the Midori and libwebkit packages in Extras to the latest versions.
|
2019-03-16
, 23:43
|
|
Posts: 1,719 |
Thanked: 4,765 times |
Joined on Apr 2018
@ Helsinki, Finland.
|
#38
|
|
2019-03-17
, 01:56
|
|
Posts: 3,141 |
Thanked: 8,161 times |
Joined on Feb 2013
@ From my Gabriola Island hermitage, near the Edge of the World
|
#39
|
The Following User Says Thank You to endsormeans For This Useful Post: | ||
|
2019-03-17
, 08:24
|
|
Posts: 1,719 |
Thanked: 4,765 times |
Joined on Apr 2018
@ Helsinki, Finland.
|
#40
|
Not perfect test honestly.
You can still support my work by donation - click here