• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Root ZTE Zmax Pro Official Root Discussion

Status
Not open for further replies.
What's needed for trying to grab the signing keys from the ota update? I haven't updated yet so, I can try to see if I can't get what we need. @SapphireEx @messi2050
A ZTE employee lanyard.

Or a nation class super computer.

*Edit That sounded a bit dickish. But it's true. End users almost never get access to OEM keys, and if we do, it's due to a VERY lucky bruteforce, or an employee leaking it (ZTE AXON).
 
Last edited by a moderator:
Upvote 0
Well hell, all I have is a pen testing dedicated system. Definitely not a server.

I'm assuming Kali/ Backtrack. You could always help @GarnetSunset with Broadpwn (It's a very complex exploit. Easy to execute, but extremely rough in actually exploiting), or send metasploit payloads to the phone and hope something happens. If you are skilled with reverse engineering, you could always poke the phone with us and see what comes up.
 
  • Like
Reactions: GarnetSunset
Upvote 0
I'm assuming Kali/ Backtrack. You could always help @GarnetSunset with Broadpwn (It's a very complex exploit. Easy to execute, but extremely rough in actually exploiting), or send metasploit payloads to the phone and hope something happens. If you are skilled with reverse engineering, you could always poke the phone with us and see what comes up.

Backtrack isn't available any more, unless you can find a legacy upload. Never had the chance to reverse engineer a phone, maybe Cyber Forensics can ahead a small light on something. I'll start running that and let you know if I can find anything worth while, and I'll read up on the exploits while forensics runs.
 
  • Like
Reactions: GarnetSunset
Upvote 0
Backtrack isn't available any more, unless you can find a legacy upload. Never had the chance to reverse engineer a phone, maybe Cyber Forensics can ahead a small light on something. I'll start running that and let you know if I can find anything worth while, and I'll read up on the exploits while forensics runs.

Here's a good starting place: https://www.cvedetails.com/vulnerab...7/version_id-188440/Google-Android-6.0.1.html

While most of these don't have public PoC's, they are starting points.

For a TL;DR of the Z981:
Locked bootloader
DM-Verity enabled
Fastboot has been removed/ hidden
Android version: 6.0.1
Mainboard: Qualcomm MSM8952
Driver support: Generic Google USB
/Dev/* is ---
/tmp is RWX
Phone is suspect to having a SUID user built in
Has full Toybox, and full busybox installed and symlinked.

Various commands known to work:
Reboot bootloader (Acts like a standard reboot)
Reboot recovery
Reboot disemmc (Attempts to disable EMMC write protection, only Messi has gotten anything out of this)
Reboot FTM (Field test mode, has a userland ADB interface)
Reboot EDL (Qualcomm factory interface. Only communicates over qfil and similar programs)
Updates for MetroPCS: B08, B14, B20, B21
B08 is exploitable via Quadrooter (Unconfirmed)
B14 and below confirmed exploitable via Dirty C0w variant intended for LG devices. Gives root access, but system instantly reboots, and wipes the exploit.
B20/B21 unknown

Loony has gained URD access at one point, but I think he said something failed.

Kernel source is available from ZTE (It's rather generic)
 
Upvote 0
And now i get this evertime i plug it in
 

Attachments

  • Screenshot_20170819-092104.png
    Screenshot_20170819-092104.png
    521.2 KB · Views: 334
Upvote 0
I'm assuming Kali/ Backtrack. You could always help @GarnetSunset with Broadpwn (It's a very complex exploit. Easy to execute, but extremely rough in actually exploiting), or send metasploit payloads to the phone and hope something happens. If you are skilled with reverse engineering, you could always poke the phone with us and see what comes up.
I'd recommend they give it a shot honestly. Super simple stuff. And college just started so I'm a little full of work at the moment.
 
Upvote 0
I have been following this thread for a long time now and the devs here deserve a huge pat on the back for there efforts. 
I have decided to get a new phone so I can have root and I am torn between ZTE axon 7 , even though I really don't want to give ZTE any more money lol, it has root and is in my $400 price range or the LG v20 , but from what I read the updates for the phone suck. Just wondering your guys recommendations?
I really like the zmax pro, it's been a real good phone and I got it free from metro so can't complain. I just want a phone I can root and play with. Thanks again to the devs here for trying so hard.
 
Upvote 0
I have been following this thread for a long time now and the devs here deserve a huge pat on the back for there efforts. 
I have decided to get a new phone so I can have root and I am torn between ZTE axon 7 , even though I really don't want to give ZTE any more money lol, it has root and is in my $400 price range or the LG v20 , but from what I read the updates for the phone suck. Just wondering your guys recommendations?
I really like the zmax pro, it's been a real good phone and I got it free from metro so can't complain. I just want a phone I can root and play with. Thanks again to the devs here for trying so hard.
Go with the axon 7
 
Upvote 0
Status
Not open for further replies.

BEST TECH IN 2023

We've been tracking upcoming products and ranking the best tech since 2007. Thanks for trusting our opinion: we get rewarded through affiliate links that earn us a commission and we invite you to learn more about us.

Smartphones