PDA

View Full Version : 3.2 Hole Closure



dsboyce8624
12-27-2002, 12:56 PM
So can anybody confirm or dispute whether or not 3.2 closes the hole that allows hacks posted for the HDVR2?

Dennis

KRavEN
12-28-2002, 10:02 AM
The "hole" was a really old bash xploit. It wouldd have been really easy for them to fix, just update bash. =]

dsboyce8624
12-28-2002, 12:57 PM
Actually, the hole I meant is the environment setting that is used in the post by Ingineer on TC to cause the unit to run his code.

Dennis

Ingineer
12-31-2002, 06:50 AM
Well, to my knowledge there is no 3.2 on the HDVR2. (yet) I think the Current is 3.1 for the S2 DTiVo and 3.2 for the SA S2.

However, I *Just* received a software update on my Ethernetted HDVR2 this morning, but I have not let it boot the new code yet. The strange thing, according to the tclient log, it's the same version! Maybe that's normal though. (I'm relatively new to the TiVo) Here is the excerpt I am referring to in the tclient log:

Dec 31 09:43:33 (none) comm[135]: checking for new software
Dec 31 09:43:33 (none) comm[135]: NewSoftware: getting SwSystem name
Dec 31 09:43:33 (none) comm[135]: NewSoftware: SwSystem 3.1.0-01-2-151 is present but NOT active.
Dec 31 09:43:33 (none) comm[135]: NewSoftware: software is not active, new software will be installed at 02:00.


For those that are curious, here is the file list obtained from the svclog:

FILE_NAME=/var/packages/GZbin-8046731-1.slice.gz
FILE_NAME=/var/packages/GZetc-8046733-1.slice.gz
FILE_NAME=/var/packages/GZkernel-8046735-1.slice.gz
FILE_NAME=/var/packages/GZlib-8046737-1.slice.gz
FILE_NAME=/var/packages/GZprom-8046739-1.slice.gz
FILE_NAME=/var/packages/GZsbin-8046741-1.slice.gz
FILE_NAME=/var/packages/GZtvbin-8046743-1.slice.gz
FILE_NAME=/var/packages/GZtvlib-8046745-1.slice.gz
FILE_NAME=/var/packages/deltalogo-65-67.slice.gz
FILE_NAME=/var/packages/swsystem-8046749-53.slice.gz
FILE_NAME=/var/packages/utils-8046747-1.slice.gz

dsboyce8624
12-31-2002, 09:02 AM
So, is it possible that there is something else that checks the software and asks for a reissue if it's changed?

Dennis