Skip to content

Instantly share code, notes, and snippets.

@tkawajir
Last active December 23, 2018 12:56
Show Gist options
  • Save tkawajir/74236be7ea89bdb172ea to your computer and use it in GitHub Desktop.
Save tkawajir/74236be7ea89bdb172ea to your computer and use it in GitHub Desktop.
LGL24
kernel=zImage
ramdisk=ramdisk
page_size=2048
kernel_size=10399518
ramdisk_size=2636018
base_addr=0x00000000
kernel_addr=0x00008000
ramdisk_addr=0x02000000
tags_addr=0x01e00000
cmd_line="console=ttyHSL0,115200,n8 androidboot.hardware=g3 user_debug=31 msm_rtb.filter=0x0"
# begin build properties
# autogenerated by buildinfo.sh
ro.build.id=KVT49L.LGL2410a
ro.build.display.id=KVT49L.LGL2410a
ro.build.version.incremental=LGL2410a.1403186587
ro.build.version.sdk=19
ro.build.version.codename=REL
ro.build.version.release=4.4.2
ro.build.date=Thu Jun 19 23:13:25 KST 2014
ro.build.date.utc=1403187205
ro.build.type=user
ro.build.user=phsoft.park
ro.build.host=LGEARND12B12
ro.build.tags=release-keys
ro.product.model=LGL24
ro.product.brand=KDDI
ro.product.name=g3_kddi_jp
ro.product.device=g3
ro.product.board=MSM8974
ro.product.cpu.abi=armeabi-v7a
ro.product.cpu.abi2=armeabi
ro.product.manufacturer=LGE
ro.product.locale.language=ja
ro.product.locale.region=JP
ro.wifi.channels=11
ro.board.platform=msm8974
# ro.build.product is obsolete; use ro.product.device
ro.build.product=g3
# Do not try to parse ro.build.description or .fingerprint
ro.build.description=g3_kddi_jp-user 4.4.2 KVT49L.LGL2410a LGL2410a.1403186587 release-keys
ro.build.fingerprint=KDDI/g3_kddi_jp/g3:4.4.2/KVT49L.LGL2410a/LGL2410a.1403186587:user/release-keys
ro.build.characteristics=default
# end build properties
#
# from device/lge/g3/system.prop
#
#
# system.prop for msm8974
#
rild.libpath=/vendor/lib/libril-qc-qmi-1.so
rild.libargs=-d /dev/smd0
persist.rild.nitz_plmn=
persist.rild.nitz_long_ons_0=
persist.rild.nitz_long_ons_1=
persist.rild.nitz_long_ons_2=
persist.rild.nitz_long_ons_3=
persist.rild.nitz_short_ons_0=
persist.rild.nitz_short_ons_1=
persist.rild.nitz_short_ons_2=
persist.rild.nitz_short_ons_3=
ril.subscription.types=NV,RUIM
DEVICE_PROVISIONED=1
# Start in GWL mode (NETWORK_MODE_LTE_GSM_WCDMA)
#ro.telephony.default_network=9
debug.sf.hw=1
debug.egl.hw=1
debug.composition.type=c2d
persist.hwc.mdpcomp.enable=true
debug.mdpcomp.logs=0
dalvik.vm.heapsize=36m
dev.pm.dyn_samplingrate=1
persist.demo.hdmirotationlock=false
ro.hdmi.enable=true
persist.speaker.prot.enable=false
#
# system props for the cne module
#
persist.cne.feature=1
#system props for the MM modules
media.stagefright.enable-player=true
media.stagefright.enable-http=true
media.stagefright.enable-aac=true
media.stagefright.enable-qcp=true
media.stagefright.enable-fma2dp=true
media.stagefright.enable-scan=true
mmp.enable.3g2=true
media.aac_51_output_enabled=true
#
# system props for the data modules
#
ro.use_data_netmgrd=true
#2013-08-31 kwangbin.yim@lge.com LGP_DATA_TEMPORARY_PATCH_FOR_G2_KLP_APP_TEST[START]
#persist.data.netmgrd.qos.enable=true
persist.data.netmgrd.qos.enable=false
#2013-08-31 kwangbin.yim@lge.com LGP_DATA_TEMPORARY_PATCH_FOR_G2_KLP_APP_TEST[END]
#system props for time-services
persist.timed.enable=true
#
# system prop for opengles version
#
# 196608 is decimal for 0x30000 to report version 3
ro.opengles.version=196608
# System property for cabl
ro.qualcomm.cabl=0
#
# System props for telephony
# System prop to turn on CdmaLTEPhone always
telephony.lteOnCdmaDevice=1
#Simulate sdcard on /data/media
#
persist.fuse_sdcard=true
#system prop for Bluetooth hci transport
ro.qualcomm.bt.hci_transport=smd
#
#snapdragon value add features
#
ro.qc.sdk.audio.ssr=false
##fluencetype can be "fluence" or "fluencepro" or "none"
ro.qc.sdk.audio.fluencetype=fluence
# LGE CHANGE_S, 2013-10-11, seonghyon.cho@lgepartner.com
#ro.qc.sdk.sensors.gestures=true
# LGE CHANGE_E, 2013-10-11, seonghyon.cho@lgepartner.com
ro.qc.sdk.camera.facialproc=false
#property to enable user to access Google WFD settings.
persist.debug.wfd.enable=1
#property to choose between virtual/external wfd display
persist.sys.wfd.virtual=0
# qualcomm sensors enable
#
# LGE CHANGE_S, 2013-10-29, G2-Task-Sensor@lge.com
# below sensor is default true by HAL source.
#ro.qualcomm.sensors.qmd=true
#ro.qc.sdk.sensors.gestures=true
#ro.qualcomm.sensors.pedometer=true
#ro.qc.sensors.step_detector=true
#ro.qc.sensors.step_counter=true
#ro.qualcomm.sensors.pam=true
#ro.qualcomm.sensors.scrn_ortn=true
#ro.qualcomm.sensors.smd=true
#ro.qualcomm.sensors.game_rv=true
#ro.qualcomm.sensors.georv=true
# LGE CHANGE_E, 2013-10-29, G2-Task-Sensor@lge.com
# qualcomm sensors debugging property
#
debug.qualcomm.sns.hal=i
debug.qualcomm.sns.daemon=i
debug.qualcomm.sns.libsensor1=e
# System props for audio
persist.audio.fluence.mode=endfire
persist.audio.handset.mic=digital
# LGE CHANGE_S, 2013-02-14, tomm.lee@lge.com
persist.audio.voicecall.mic=0
# LGE CHANGE_E, 2013-02-14, tomm.lee@lge.com
persist.audio.voice.clarity=none
# LGE CHANGE_E, 2013-05-09, jungsoo1221.lee@lge.com
persist.aanc.enable=false
persist.audio.headset_fluence=false
# LGE CHANGE, 2013-06-19, heejeong.seo@lge.com
persist.audio.handset_rx_type=DEFAULT
# LGE CHANGE, 2014-02-04, hoseong.kang@lge.com
use.voice.path.for.pcm.voip=true
#// LGE_CHANGE_S, [Net_Patch_0300][CALL_FRW][COMMON], 2012-05-25, Airplane Mode Pop-Up display property value {
ro.airplane.phoneapp=1
#// LGE_CHANGE_E, [Net_Patch_0300][CALL_FRW][COMMON], 2012-05-25, Airplane Mode Pop-Up display property value }
# [blue.park@lge.com] For Blue Error Handler V1.4
ro.blue_handler.level=0
# LGE_CHANGE_S [g2][framework][common] the screen auto-brightness adjustment setting
persist.power.useautobrightadj=true
# LGE_CHANGE_E [g2][framework][common] the screen auto-brightness adjustment setting
# LGE_CHANGE_S [g2][framework][protocol]
persist.radio.add_power_save=1
# LGE_CHANGE_E [g2][framework][protocol]
# LGE_CHANGE_S [g2][framework][common] Define HW key led feature
lge.hw.frontkeyled=false
# LGE_CHANGE_E [g2][framework][common] Define HW key led feature
# 2013-04-19 Bokyum.Kim (bokyum.kim@lge.com) [A1] Make a property named debug.strictmode and set it to 0 for StrictMode [START]
# Remove this property to save the space for other properties
# debug.strictmode=0
# 2013-04-19 Bokyum.Kim (bokyum.kim@lge.com) [A1] Make a property named debug.strictmode and set it to 0 for StrictMode [END]
# LGE_CHANGE_S [g2][framework][common] change lcd default brightness 149->173
#ro.lge.lcd_default_brightness=173
# LGE_CHANGE_S [g2][framework][common] change lcd default brightness 149->173
# LGE_CHANGE_S, [WiFi][hayun.kim@lge.com], 2013-01-22, Wifi Bring Up
# reserved wifi related property
dhcp.ap.macaddress=
dhcp.wlan0.dns1=
dhcp.wlan0.dns2=
dhcp.wlan0.dns3=
dhcp.wlan0.dns4=
dhcp.wlan0.gateway=
dhcp.wlan0.ipaddress=
dhcp.wlan0.leasetime=
dhcp.wlan0.mask=
dhcp.wlan0.pid=
dhcp.wlan0.reason=
dhcp.wlan0.result=
dhcp.wlan0.server=
dhcp.wlan0.vendorInfo=
dhcp.p2p.dns1=
dhcp.p2p.dns2=
dhcp.p2p.dns3=
dhcp.p2p.dns4=
dhcp.p2p.gateway=
dhcp.p2p.ipaddress=
dhcp.p2p.leasetime=
dhcp.p2p.mask=
dhcp.p2p.pid=
dhcp.p2p.reason=
dhcp.p2p.result=
dhcp.p2p.server=
dhcp.p2p.vendorInfo=
init.svc.dhcpcd_wlan0=
init.svc.dhcpcd_p2p=
init.svc.p2p_supplicant=
init.svc.iprenew_wlan0=
net.dns1=
net.dns2=
net.dnschange=
net.p2p-p2p0-0.dns1=
net.p2p-p2p0-0.dns2=
net.wlan0.dns1=
net.wlan0.dns2=
wlan.driver.status=
persist.sys.security=
persist.sys.hotssid.ksc5601=
wifi.lge.autochannel=
# LGE_CHANGE_S, [WiFi][hayun.kim@lge.com], 2013-01-22, Wifi Bring Up
# LGE_CHANGE_S Audio_Framework: HiFi Sound
# reduce Default minimum length allowed for offload in 30 sec.
audio.offload.min.duration.secs=30
# LGE_CHANGE_E
# LGE_CHANGE_S [CFW][Memory][dongsoo.joo@lge.com] Add oomAdj value
ro.sys.fw.bg_apps_limit=24
ro.sys.fw.mOomAdj1=0
ro.sys.fw.mOomAdj2=1
ro.sys.fw.mOomAdj3=2
ro.sys.fw.mOomAdj4=4
ro.sys.fw.mOomAdj5=9
ro.sys.fw.mOomAdj6=15
ro.sys.fw.mOomMinFree1=49152
ro.sys.fw.mOomMinFree2=61440
ro.sys.fw.mOomMinFree3=73728
ro.sys.fw.mOomMinFree4=114688
ro.sys.fw.mOomMinFree5=196608
ro.sys.fw.mOomMinFree6=245760
# LGE_CHANGE_E
#
# ADDITIONAL_BUILD_PROPERTIES
#
ro.build.target_operator=KDDI
ro.build.target_country=JP
ro.lge.swversion=LGL2410a
ro.lge.swversion_short=V10a
ro.lge.swversion_rev=0
ro.lge.factoryversion=LGL24AT-00-V10a-KDDI-JP-JUN-19-2014+0
ro.config.vibrate_type=2
ro.3lm.build.lg=true
ro.3lm.build.sdencryption=true
persist.security.oneseg.lockout=1
persist.security.felica.lockout=1
persist.security.irda.lockout=1
persist.security.nfc.lockout=1
persist.audio.nsenabled=OFF
persist.audio.spkcall_2mic=OFF
persist.audio.spk_sm_fluence=OFF
persist.audio.voip_nsenabled=OFF
ro.lge.bt_gain_control_factor=0.9
persist.cne.feature=6
persist.sys.cnd.nsrm=2
persist.cne.rat.wlan.chip.oem=nonwcn
persist.sys.cnd.wqe=2
wlan.chip.vendor=qcom
wlan.chip.version=wcn
wifi.lge.patch=true
dhcp.dlna.using=false
wifi.lge.sleeppolicy=0
wifi.lge.offdelay=false
wlan.lge.concurrency=MCC
wlan.lge.supportsimaka=YES
wlan.lge.powermode=false
wlan.lge.passpoint_setting=false
wifi.lge.hanglessid=false
wifi.lge.ftm_test=3
wlan.lge.wifidisplay=both
wifi.lge.common_hotspot=true
ime_extend_row_keyboard=true
ime_onehand_keyboard=true
ime_split_keyboard=true
ime_theme=true
ime_keyboard_layout=ko=QWERTY
ime_vibration_pattern=0:20
ro.config.vc_call_vol_steps=6
ro.config.vc_call_vol_default=3
tangible_device_config=B1BCNAOTDO
ro.lge.lcd_default_brightness=177
ro.lge.dataprotect=1
persist.sys.mlt_swupdt=1
lge.nfc.setype=uicc
lge.nfc.defaultonoff=offcardrwp2p
lge.nfc.handover=directbeam
lge.nfc.rwp2pserversync=yes
lge.nfc.oscomparability=icsjb
lge.nfc.vendor=sony
ro.nfc.port=UART
ro.com.google.gmsversion=4.4_r3
ro.setupwizard.mode=DISABLED
ro.livewallpaper.map=DISABLED
ro.com.google.apphider=off
ro.com.google.clientidbase.am=android-kddi-jp
ro.com.google.clientidbase.gmm=android-om-lge
ro.com.google.clientidbase.ms=android-kddi-jp
ro.com.google.clientidbase.yt=android-om-lge
ro.com.google.clientidbase=android-om-lge
ro.lge.vib_magnitude_index=0,20,40,60,80,100,120,127
lge.normalizer.param=version2.0/true/8.0/true/14500/1.0/2000/0.6
ro.config.ringtone=01_Frost.ogg
ro.config.notification_sound=Aqua_Blue.ogg
ro.config.alarm_alert=Piece_of_Moonlight.ogg
ro.config.timer_alert=Timer.ogg
drm.service.enabled=true
persist.sys.strictmode.disable=true
persist.hwc.mdpcomp.enable=true
ro.opengles.version=196608
ro.hwui.texture_cache_size=72
ro.hwui.layer_cache_size=48
ro.hwui.r_buffer_cache_size=8
ro.hwui.path_cache_size=32
ro.hwui.gradient_cache_size=1
ro.hwui.drop_shadow_cache_size=6
ro.hwui.texture_cache_flushrate=0.4
ro.hwui.text_small_cache_width=1024
ro.hwui.text_small_cache_height=1024
ro.hwui.text_large_cache_width=2048
ro.hwui.text_large_cache_height=1024
qcom.thermal=thermal-engine
ro.sf.lcd_density=640
persist.fuse_sdcard=true
persist.sys.emmc_size=0
persist.service.crash.enable=0
persist.sys.ssr.restart_level=3
ro.lge.zwait=false
audio.offload.disable=0
av.offload.enable=0
mm.enable.qcom_parser=37491
vidc.debug.level=1
mm.enable.smoothstreaming=true
persist.qcril.disable_retry=true
ro.com.android.dataroaming=false
ro.afwdata.LGfeatureset=KDDIBASE
ro.support_mpdn=true
net.tethering.noprovisioning=true
persist.lg.data.fd=-1
ro.vendor.extension_library=/vendor/lib/libqc-opt.so
ro.boot.svelte=1
keyguard.no_require_sim=true
ro.com.android.dateformat=MM-dd-yyyy
ro.carrier=unknown
dalvik.vm.heapstartsize=8m
dalvik.vm.heapgrowthlimit=256m
dalvik.vm.heapsize=512m
dalvik.vm.heaptargetutilization=0.25
dalvik.vm.heapminfree=4m
dalvik.vm.heapmaxfree=16m
persist.radio.apm_sim_not_pwdn=1
lge.signed_image=true
ro.lge.capp_splitwindow=true
persist.splitwindow.support_all=false
ro.lge.capp_ZDi_O=true
lge.zdi.actionsend=false
lge.zdi.onactivityresult=true
lge.zdi.dragdropintent=false
ro.lge.lcd_auto_brightness_mode=false
ro.lge.audio_soundexception=true
ro.lge.capp_emotional_led=true
ro.lge.capp_wfd=true
ro.lge.capp_almond=true
ro.lge.capp_smartcard_ac_gp=false
ro.lge.capp_smartcard_ac_gto=true
ro.lge.capp_smartcard_lgril=false
ro.lge.capp_smartcard_uicc=true
ro.lge.capp_smartcard_smartmx=false
ro.lge.irrc.type=sw
ro.lge.capp_jfullseg=true
ro.lge.qslide.max_window=2
persist.sys.country=JP
persist.sys.language=ja
ro.telephony.default_network=10
ro.radio.topreviousmode=disable
persist.radio.atfwd.start=false
persist.sys.dalvik.vm.lib=libdvm.so
net.bt.name=Android
dalvik.vm.stack-trace-file=/data/anr/traces.txt
ro.qc.sdk.izat.premium_enabled=0
ro.qc.sdk.izat.service_mask=0x0
persist.gps.qc_nlp_in_use=1
persist.loc.nlp_name=com.qualcomm.services.location
ro.gps.agps_provider=1
Device detected: LGL24 (KVT49L.LGL2410a)
Try without fb_mem_exploit fist...
Try to find address in memory...
Attempt msm_cameraconfig exploit...
Detected kernel physical address at 0x00008000 from iomem
You need to manage to get remap_pfn_range address.
Try copying kernel memory... It will take a long time.
Attempt futex exploit...
futex_exploit: Server started
Search address in memory...
Using kallsyms_in_memory...
Essential address are:
prepare_kernel_cred = 0xc01bd5c8
commit_creds = 0xc01bd090
remap_pfn_range = 0xc023e48c
vmalloc_exec = 0xc024a854
ptmx_fops = 0xc147e950
shell@g3:/data/local/tmp $ ./install_backdoor
./install_backdoor
Attempt acdb exploit...
LGL24 (KVT49L.LGL2410a) is not supported.
Attempt put_user exploit...
ioctl: Bad address
Attempt futex exploit...
install_mmap: success
shell@g3:/data/local/tmp $ ./disable_ccsecurity
./disable_ccsecurity
LGL24 (KVT49L.LGL2410a) is not supported.
1|shell@g3:/data/local/tmp $
1|shell@g3:/data/local/tmp $ ./run_root_shell
./run_root_shell
shell@g3:/data/local/tmp #
lrwxrwxrwx root root 1970-02-25 07:18 DDR -> /dev/block/mmcblk0p4
lrwxrwxrwx root root 1970-02-25 07:18 aboot -> /dev/block/mmcblk0p5
lrwxrwxrwx root root 1970-02-25 07:18 abootf -> /dev/block/mmcblk0p16
lrwxrwxrwx root root 1970-02-25 07:18 boot -> /dev/block/mmcblk0p18
lrwxrwxrwx root root 1970-02-25 07:18 cache -> /dev/block/mmcblk0p42
lrwxrwxrwx root root 1970-02-25 07:18 dbi -> /dev/block/mmcblk0p3
lrwxrwxrwx root root 1970-02-25 07:18 dbibak -> /dev/block/mmcblk0p10
lrwxrwxrwx root root 1970-02-25 07:18 drm -> /dev/block/mmcblk0p36
lrwxrwxrwx root root 1970-02-25 07:18 eksst -> /dev/block/mmcblk0p29
lrwxrwxrwx root root 1970-02-25 07:18 encrypt -> /dev/block/mmcblk0p28
lrwxrwxrwx root root 1970-02-25 07:18 factory -> /dev/block/mmcblk0p40
lrwxrwxrwx root root 1970-02-25 07:18 felica -> /dev/block/mmcblk0p39
lrwxrwxrwx root root 1970-02-25 07:18 fota -> /dev/block/mmcblk0p34
lrwxrwxrwx root root 1970-02-25 07:18 fsc -> /dev/block/mmcblk0p25
lrwxrwxrwx root root 1970-02-25 07:18 fsg -> /dev/block/mmcblk0p24
lrwxrwxrwx root root 1970-02-25 07:18 grow -> /dev/block/mmcblk0p44
lrwxrwxrwx root root 1970-02-25 07:18 laf -> /dev/block/mmcblk0p33
lrwxrwxrwx root root 1970-02-25 07:18 misc -> /dev/block/mmcblk0p32
lrwxrwxrwx root root 1970-02-25 07:18 modem -> /dev/block/mmcblk0p1
lrwxrwxrwx root root 1970-02-25 07:18 modemst1 -> /dev/block/mmcblk0p21
lrwxrwxrwx root root 1970-02-25 07:18 modemst2 -> /dev/block/mmcblk0p22
lrwxrwxrwx root root 1970-02-25 07:18 mpt -> /dev/block/mmcblk0p38
lrwxrwxrwx root root 1970-02-25 07:18 pad -> /dev/block/mmcblk0p8
lrwxrwxrwx root root 1970-02-25 07:18 pad1 -> /dev/block/mmcblk0p23
lrwxrwxrwx root root 1970-02-25 07:18 pad2 -> /dev/block/mmcblk0p27
lrwxrwxrwx root root 1970-02-25 07:18 persist -> /dev/block/mmcblk0p19
lrwxrwxrwx root root 1970-02-25 07:18 rct -> /dev/block/mmcblk0p30
lrwxrwxrwx root root 1970-02-25 07:18 recovery -> /dev/block/mmcblk0p20
lrwxrwxrwx root root 1970-02-25 07:18 rpm -> /dev/block/mmcblk0p6
lrwxrwxrwx root root 1970-02-25 07:18 rpmbak -> /dev/block/mmcblk0p11
lrwxrwxrwx root root 1970-02-25 07:18 rpmf -> /dev/block/mmcblk0p13
lrwxrwxrwx root root 1970-02-25 07:18 sbl1 -> /dev/block/mmcblk0p2
lrwxrwxrwx root root 1970-02-25 07:18 sbl1b -> /dev/block/mmcblk0p9
lrwxrwxrwx root root 1970-02-25 07:18 sdif -> /dev/block/mmcblk0p15
lrwxrwxrwx root root 1970-02-25 07:18 sns -> /dev/block/mmcblk0p37
lrwxrwxrwx root root 1970-02-25 07:18 spare1 -> /dev/block/mmcblk0p17
lrwxrwxrwx root root 1970-02-25 07:18 spare2 -> /dev/block/mmcblk0p31
lrwxrwxrwx root root 1970-02-25 07:18 spare3 -> /dev/block/mmcblk0p35
lrwxrwxrwx root root 1970-02-25 07:18 ssd -> /dev/block/mmcblk0p26
lrwxrwxrwx root root 1970-02-25 07:18 system -> /dev/block/mmcblk0p41
lrwxrwxrwx root root 1970-02-25 07:18 tz -> /dev/block/mmcblk0p7
lrwxrwxrwx root root 1970-02-25 07:18 tzbak -> /dev/block/mmcblk0p12
lrwxrwxrwx root root 1970-02-25 07:18 tzf -> /dev/block/mmcblk0p14
lrwxrwxrwx root root 1970-02-25 07:18 userdata -> /dev/block/mmcblk0p43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment