Feeds

Windows RT jailbreak smash: Run ANY app on Surface slabs

No need for Microsoft's software store

Secure remote control for conventional and virtual desktops

The security mechanism preventing unauthorised software running on ARM-powered Windows RT tablets - such as Microsoft's Surface slabtops - can be easily defeated.

The Redmond giant wanted only cryptographically signed executables, ideally those obtained from the official Windows application store, to run on its hardware. But, we're told, by twiddling a byte of memory in the Windows kernel, it is possible to disable the protection system and allow any code to run on the system.

Taking full control of the device, effectively jail-breaking the computer to run any desktop or touch-driven ARM-compatible software, is an exercise left to the user.

A security researcher calling him or herself C. L. Rokr claims to have found an oversight in the Windows kernel to allow this to happen. According to Rokr, all you have to do is fire up the Windows Debugger software with Administrator-level permissions, connect it to the tablet and manipulate the device's kernel memory.

Specifically, one needs to inject a blob of ARM code into a safe spot of RAM and have the Windows RT kernel divert the processor momentarily to run these instructions. This code locates and alters a moderately hidden variable in the kernel to disable the executable signature check. On PCs the variable contains '0' allowing any program to run, whereas it is '8' on Windows RT devices to enforce the signature check.

Trivially overwriting this byte can therefore change the level of protection on the system and circumvent Microsoft's cryptographic keys.

You can read more about the hack along with a how-to guide here.

Windows RT, which is a straight-up ARM port of Windows 8 for portable computers, was built to only run apps that are signed using a Microsoft-issued certificate.

The hack is unlikely to be something most non-techie users could pull off as it requires knowledge of WinDbg. And modifying the operating system could fall foul of the device's secure boot protection, which refuses to start the OS if it has been altered.

It's also not clear which apps can be run, although as pointed out in this programming forum the software must be compiled for, or otherwise be compatible with, ARM-powered systems. Programs already built for Intel and AMD processors need not apply, therefore.

Windows RT can be found on Microsoft's Surface tablet and fondleslabs from companies including Asus and Samsung. So far it appears sales of Windows RT devices are low and below Microsoft's expectations. Redmond has quickly turned from only selling Surface itself online and in its stores to recruiting retail partners.

One reason for the lack of interest could be lack of apps. Windows RT has been deliberately locked down because, we're told, Microsoft wants to maintain a standard of performance and security, and to ensure apps conform to the design of the interface and input via touch. This means the number of Windows RT apps is far behind the number of apps that exists for Intel machines running the exact same operating system.

Devices using Windows RT come with some built-in apps including Office Home and Student 2013 RT Preview Edition and Mail, Messaging and SkyDrive, but the official way to obtain more is via Microsoft's Windows Store, which supplies suitably signed executables. ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Not appy with your Chromebook? Well now it can run Android apps
Google offers beta of tricky OS-inside-OS tech
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
NHS grows a NoSQL backbone and rips out its Oracle Spine
Open source? In the government? Ha ha! What, wait ...?
Google extends app refund window to two hours
You now have 120 minutes to finish that game instead of 15
Intel: Hey, enterprises, drop everything and DO HADOOP
Big Data analytics projected to run on more servers than any other app
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.