Live data from Hacker News

"Potentially rogue binary" in Sprint Evo

unrevoked.com

21–23 of 23 posts

Re: "Potentially rogue binary" in Sprint Evo

#21

Earlier quoted context omitted.

Clarification request: I don't have one of these phones, but have friends who do. Are the OTA updates installed automatically, or do they need to take some action (e.g. run a software update app or the like)?

If you're running stock (or close to stock firmware), you'll get a popup notification saying there's an update available. If you haven't received one for a few days, you're more than likely up-to-date.

Thanks! I'll let my friends know.

Re: "Potentially rogue binary" in Sprint Evo

#22
post #12
post #8

Earlier quoted context omitted.

If is recognized by unrevoked that that is true, then why does it state, "At this time, we believe that skyagent was a debugging binary left over from manufacture. We have been consistently impressed with the actions taken by Google, Sprint, and HTC to expeditiously resolve this issue."

But a few paragraphs later they write: However, the security vulnerabilities present in skyagent are of less cause for concern than the purpose of the program. It appears that the binary was designed as a backdoor into the phone, allowing remote control of the device without the user's knowledge or permission. When the program is invoked, it listens for connections over TCP (by default, port 12345, on all interfaces,…

You mean skyagent makes it easybto take screenshots on an android device? Sign me up!

Re: "Potentially rogue binary" in Sprint Evo

#23
post #7
post #6

Earlier quoted context omitted.

Or an OTA update adding it to the init process (though apparently skyagent has not been removed)

It was removed in the OTA update on the EVO and Hero (not just chmodded, but unlinked).

Erm yes, I apparently mistyped, I meant to write that it had been removed (saying that it hasn't been removed makes low if any sense)
Post reply on HN