Wrong confirmation ID
  • Email
  • Favorite
  • Download
  • Embed
  • Private Content

BlackHat USA 2011 - Stefan Esser - iOS Kernel Exploitation

by i0n1c on Sep 14, 2011

  • 34,378 views

Exploiting the iOS Kernel...

Exploiting the iOS Kernel

The iPhone user land is locked down very tightly by kernel level protections. Therefore any sophisticated attack has to include a kernel exploit in order to completely compromise the device. Because of this our previous session titled "Targeting the iOS Kernel" already discussed how to reverse the iOS kernel in order to find kernel security vulnerabilities. Exploitation of iOS kernel vulnerabilities has not been discussed yet.

This session will introduce the audience to kernel level exploitation of iPhones. With the help of previously disclosed kernel vulnerabilities the exploitation of uninitialized kernel variables, kernel stack buffer overflows, out of bound writes and kernel heap buffer overflows will be discussed.

Furthermore the kernel patches applied by iPhone jailbreaks will be discussed in order to understand how certain security features are deactivated. A tool will be released that allows to selectively de-activate some of these kernel patches for more realistic exploit tests.

Accessibility

Categories

Tags

iphone kernel exploitation exploitation jailbreak security ios hack ios kernel exploitation

More...

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

52 Embeds 26,823

http://osxdaily.com 18423
http://www.iguides.ru 3868
http://www.hack2learn.org 1003
http://ichitaso.blogspot.com 950
http://www.osxdaily.com 629
http://www.guomii.com 430
http://tedkenan.tistory.com 329
http://www.elementalparticles.com 306
http://nonocast.cn 214
http://newapples.ru 192
http://paper.li 117
http://feeds.feedburner.com 65
http://www.sinfuliphone.com 60
http://us-w1.rockmelt.com 36
http://twitter.com 34
http://translate.googleusercontent.com 26
https://twitter.com 15
http://ichitaso.blogspot.jp 14
http://feedproxy.google.com 13
http://www.tumblr.com 9
http://www.a-pie.com 9
http://mac-news-tips-apps.blogspot.com 8
http://127.0.0.1 7
http://fabu.duowan.com 7
http://www.netvibes.com 5
http://www.zhuaxia.com 5
http://mac--news.blogspot.com 4
http://i-store.net.ua 4
http://www.nonocast.cn 3
http://imappleaddicted.tumblr.com 3
http://a0.twimg.com 3
http://webcache.googleusercontent.com 3
http://isim.kz 3
http://ipad.duowan.com 3
http://xss.yandex.net 2
http://i--dooo.blogspot.com 2
http://reader.youdao.com 2
http://www.kuqin.com 2
http://safe.tumblr.com 2
http://yelekci.com 1
http://cache.baidu.com 1
http://localhost 1
http://onemac.org 1
http://i3rd.net 1
http://apple-n-e-w-s.blogspot.com 1
http://macminiforum.com 1
http://www.mefeedia.com 1
http://207.46.192.232 1
http://dashboard.bloglines.com 1
http://lj-toys.com 1
http://www.hanrss.com 1

More...

Statistics

Favorites
6
Downloads
344
Comments
3
Embed Views
26,823
Views on SlideShare
7,555
Total Views
34,378

13 of 3 previous next Post a comment

  • bAstimc bAstimc nice one :) 8 months ago Reply
    Are you sure you want to Yes No
  • FrankLos Frank Los at Hewlett-Packard That will get generate some traffic to slideshare I guess. 8 months ago Reply
    Are you sure you want to Yes No
  • david0n david0n omg... du bist echt so krass stefan! ich verstehe leider so gut wie gar nichts von dieser programmiererei auf allerhöchstem niveau - aber nicht nur deshalb: ganz, ganz großen respekt!! ich werde nie vergessen, als ich ende letzten jahres durch twitter auf dich aufmerksam geworden bin und wie derbe du ’mir den arsch gerettet’ hast, als du endlich einen funktionierender exploit fürs iDünf4 veröffentlicht hast - dafür werde ich dir immer dankbar sein!! und was du mittlerweile schon wieder alles für faxen angestellt hast... manmanman! :D ich wünsche dir weiterhin alles gute und viel erfolg für deine firma und freue mich schon riesig auf die nächste runde jailbreaking im oktober ;) sollte ich jemals was für dich tun können (IT-technisch - bin ausgebildet..) lass es mich wissen :D hab es nämlich nicht allzu weit zu dir. ganz liebe grüße daVid 8 months ago Reply
    Are you sure you want to Yes No
Post Comment
Edit your comment Cancel

BlackHat USA 2011 - Stefan Esser - iOS Kernel Exploitation — Presentation Transcript