Kindle Touch jail broken via ID3 Tag
yifan.lu
yifan.lu
As a summary:
This guy found out that most of the GUI is HTML and Javascript. Some of the JS functions are mapped to OS calls, including one that will run any script as root (nativeBridge.dbgCmd();). This function is disabled in the browser, so it needs to be called from somewhere else.
So he injects the function call into the ID3 tag of an MP3 file and plays the file on the native mp3 player which has a html gui for displaying the id3 tag info :)
Finally he uses this exploit to enable ssh and install a certificate so he can connect to it.
<button type="button" style="width:100%;height:100%" onclick="javascript:nativeBridge.dbgCmd('dd if=/mnt/us/music/jailbreak.mp3 of=/tmp/payload.sh bs=1 skip=25');nativeBridge.dbgCmd('chmod +x /tmp/payload.sh');nativeBridge.dbgCmd('sh /tmp/payload.sh');">Press to Jailbreak!</button>
Why did Amazon allow a call that always runs as root?
Is it necessity, oversight, or something else?
It's also clear that tney didn't think about all the other potential interactions with the system. It's not the things you don't know that bite you -- it's the thing you know that isn't so.
As far as ad-supported services go, the Kindle is actually quite good - totally unobtrusive, and you actually get some good offers, things like $5 off a $10 purchase.
In fact, I wasn't even really able to find anything other than removing the ads and changing the screensaver as what you can do after your kindle is jailbroken.
After the initial effort investment (not that hard, since you can download it with the kindle's browser), I would say it's actually easier.
It's only a few more seconds than an Amazon buy.
I've been meaning to explore whether they run JavaScript too but haven't gotten around to it yet.
epub support!