Live data from Hacker News

"Potentially rogue binary" in Sprint Evo

unrevoked.com

1–10 of 23 posts

Re: "Potentially rogue binary" in Sprint Evo

#5
Look, if your backdoor binary sits in /usr/bin or similar in a file system, you really have no business writing backdoors.

Sprint could have the same functionality built into the kernel and no one would have noticed it. It's actually a good thing it's not running by default. I would snoop around further and see how it's launched; the command list only has the shutdown commands, not the launcher. Without the trigger you really don't have the whole answer.

Re: "Potentially rogue binary" in Sprint Evo

#7
post #6
post #4

"We do not believe that skyagent could ever be invoked remotely." Whats the risk here? Possibly a debugging helper app left inadvertently?

Or an OTA update adding it to the init process (though apparently skyagent has not been removed)

It was removed in the OTA update on the EVO and Hero (not just chmodded, but unlinked).

Re: "Potentially rogue binary" in Sprint Evo

#8

What's unstated here but recognized by unrevoked is that Sprint had skyagent purposefully on their phones so that they could easily gain root access and keep their phones under their command.

If is recognized by unrevoked that that is true, then why does it state, "At this time, we believe that skyagent was a debugging binary left over from manufacture. We have been consistently impressed with the actions taken by Google, Sprint, and HTC to expeditiously resolve this issue."

Re: "Potentially rogue binary" in Sprint Evo

#9
I'm part of the team that found this backdoor. A few points:

1. "Never Trust Sprint Again" is editorializing on the part of the submitter, not our stance. It's a very, very crappy thing to put on a phone, but there's no evidence it was placed there maliciously.

2. It was released in the wild on the HTC Hero for some time. We believe it would have been in the wild on the EVO if we hadn't reported it.

3. Sprint was very responsive when we reported this to them. They turned around a patch within a few days that sealed this particular hole.

4. We have no idea where this came from or who was ultimately responsible. That information never made it back to us.

Re: "Potentially rogue binary" in Sprint Evo

#10
post #5

Look, if your backdoor binary sits in /usr/bin or similar in a file system, you really have no business writing backdoors. Sprint could have the same functionality built into the kernel and no one would have noticed it. It's actually a good thing it's not running by default. I would snoop around further and see how it's launched; the command list only has the shutdown commands, not the launcher. Without the trigger y…

Also if you name it "SkyAgent" (or anything vaguely Terminator-y), you wear the hat of shame. To parties.
Post reply on HN