Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Amazon Kindle > Kindle Developer's Corner

Notices

Reply
 
Thread Tools Search this Thread
Old 07-16-2023, 03:48 PM   #1
HackerDude
Kindle Bricker
HackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheese
 
HackerDude's Avatar
 
Posts: 83
Karma: 1170
Join Date: Sep 2022
Location: Why do you want to know?
Device: PW5
Post Introducing Mesquito (BETA) - The WAF loader for non-jailbroken Kindles (latest ver)

Hey, I'm Bluebotlabs, a while back I created KWebBrew, just a simple loader for offline WAF-like browser stuff.

Well, now I've created Mesquito (BETA), a REAL WAF Loader for non-jailbroken Kindles. That's right, it works on the latest firmware (5.16.2.1) and lets you run actual privilaged WAFs on the Kindle.

There are some limitations of course, these WAFs run within the context of the Kindle store, meaning that whilst you can use certain WAF APIs, you can only communicate with the following LIPC services:
  • com.lab126.pillow
  • com.lab126.chromebar
  • com.lab126.readnow

A private modification to Mesquito allows it to access all LIPC services (in theory) but it's experimental and not public at the moment.

As Mesquito is still BETA, it does not ship with any apps specifically for it, but it is backwards compatible with KWebBrew apps.

Documentation for Mesquito and other WAF-related info can be found here:
https://kindlemodding.github.io/docs/Mesquito/

Mesquito itself can be installed via the steps shown in the same link


I can't wait to see what the community creates with this!!!

Thank you for reading this rather long post,
Bluebotlabs

Last edited by HackerDude; 07-16-2023 at 07:14 PM.
HackerDude is offline   Reply With Quote
Old 07-16-2023, 03:52 PM   #2
HackerDude
Kindle Bricker
HackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheese
 
HackerDude's Avatar
 
Posts: 83
Karma: 1170
Join Date: Sep 2022
Location: Why do you want to know?
Device: PW5
Here's a screenshot, btw

[screenshot replaced with link because it broke the post]
https://github.com/KindleModding/Mesquito
HackerDude is offline   Reply With Quote
Old 07-30-2023, 02:28 AM   #3
CitizenStile
Junior Member
CitizenStile began at the beginning.
 
CitizenStile's Avatar
 
Posts: 5
Karma: 10
Join Date: May 2023
Device: PW5SE, PW3(7th Gen)
Hey Blue, Awesome work with Mesquito! Do you have any plans for a consolidated place to look through apps that other people have developed, such as a wiki page or a pinned thread?
CitizenStile is offline   Reply With Quote
Old 08-02-2023, 11:47 PM   #4
johnydon3
Enthusiast
johnydon3 began at the beginning.
 
Posts: 44
Karma: 10
Join Date: Sep 2022
Device: Clara HD, Nook Glowlight Plus (2015), Kindle 4, x2 Kindle Basic 10gen
Can we install Koreader or a similar reader like that?
johnydon3 is offline   Reply With Quote
Old 08-05-2023, 04:41 PM   #5
HackerDude
Kindle Bricker
HackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheese
 
HackerDude's Avatar
 
Posts: 83
Karma: 1170
Join Date: Sep 2022
Location: Why do you want to know?
Device: PW5
At the moment Mesquito only allows you to run somewhat privellaged WAFs, we have a rudimentary privelage escallation trick in the works to gain more access to LIPC services, we can now query and write to all LIPC properties in a private beta

However, code execution remains out of bound for the time being so no full jailbreak at the moment, and therefore no koreader sadly
HackerDude is offline   Reply With Quote
Old 08-05-2023, 07:39 PM   #6
dhdurgee
Guru
dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.dhdurgee ought to be getting tired of karma fortunes by now.
 
Posts: 846
Karma: 2525050
Join Date: Jun 2010
Device: K3W, PW4
Stupid question: Do any of the WAF/LIPC services you have access to permit writing to the file system at an arbitrary location with root privilege? If so, you have the ability to JB right there.

Dave
dhdurgee is offline   Reply With Quote
Old 08-06-2023, 05:04 AM   #7
HackerDude
Kindle Bricker
HackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheeseHackerDude can extract oil from cheese
 
HackerDude's Avatar
 
Posts: 83
Karma: 1170
Join Date: Sep 2022
Location: Why do you want to know?
Device: PW5
Hah

If only it was that easy
also, you'd need code execution anyway since rootfs is mounted as readonly

Unfortunately I haven't found any LIPC service that offers FS writing or code execution (yet)
I'm going to work on decompiling and documenting the Kindle's Java Apps next
HackerDude is offline   Reply With Quote
Reply

Tags
jailbreak, kwebbrew, mesquito, waf


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
De-sandboxed kindlet loader pwr Kindle Developer's Corner 11 06-17-2012 06:43 PM
loader problem with old Ubuntu Hardy silver84 Calibre 10 01-04-2011 03:47 PM
Micro Boot Loader v1.3 OrcaBlue iRex 2 03-06-2010 12:59 PM
loader rogue_ronin Calibre 9 12-13-2009 03:36 PM
Gmail Loader (GML) Colin Dunstan Lounge 0 06-18-2004 04:23 AM


All times are GMT -4. The time now is 06:26 PM.


MobileRead.com is a privately owned, operated and funded community.