SlideShare a Scribd company logo
Escaping	The	Sandbox	By	Not	
Breaking	It
Marco	Grassi (@marcograss)
Qidan He (@flanker_hqd)
About	Us
• Marco	Grassi
• Senior	Security	Researcher	@	Tencent KEEN	Lab
• Main	Focus:	Vulnerability	Research,	Android,	OS	X/iOS,	Sandboxes
• Qidan He
• Senior	Security	Researcher	@	Tencent KEEN	Lab
• Main Focus: Bug huntingand exploitingon *nix platform
Tencent KEEN	Security	Lab
• Previously	known	as	KeenTeam
• All	the	researchers	moved	to	Tencent for	business	requirements
• New	name:	TencentKEEN	Security	Lab
• In	March	of	this	year	our	union	team	with	Tencent PC	Manager	
(Tencent Security	Team	Sniper)	won	the	title	of	“Master	Of	Pwn”	at	
Pwn2Own	2016
Agenda
• Introduction	to	Sandboxes
• Safari	Sandbox	on	OS	X	(WebContent Sandbox)
• Google	Chrome	Sandbox	on	Android	(Isolated	Process)
• Comparison	of	the	Sandbox	implementation	of	the	2	platforms
• Auditing	Sandboxes	and	Case	Studies
• Full	Sandbox	Escape	demo	from	the	browser	renderer	process
• Summary	and	Conclusions
Introduction	to	Sandboxes
Sandbox
• In	modern	operating	systems,	a	“Sandbox”	is	a	mechanism	to	run	
code	in	a	constrained	environment.
• A	Sandbox	specifies	which	resources	this	code	has	access	to.
• It	became	a	crucial	component	for	security	in	the	last	years	after	it	
became	clear	that	it’s	currently	impossible	to	get	rid	of	a	big	part	of	
the	bugs,	especially	in	very	complex	software	like	browser.
• Shift	of	approach/complementary	approach:	
• Let’s	confine	software,	so	even	if	it’s	compromised	it	has	restricted	access	to	
the	system.
A	couple	of	Sandboxes	implementations	methods
First	type	(Discretionary	access	control):	
Android	base	Sandbox	mechanism
• Android	from	its	initial	version	had	a	sandbox	mechanism	
implemented	mainly	on	top	of	standard	Linux	process	isolation	with	
unique	UIDs,	and	GIDs	specifying	a	capability	(like	access	to	external	
storage).
• Almost	every	application	(usually,	except	shared	UID)	have	a	unique	
UID.
• Very	well	studied	and	understood	by	countless	resources	and	talks,	
we	will	not	talk	about	it	a	lot	in	this	talk.
• Simpler	to	understand	and	implement,	but	not	very	flexible.
Second	type (Mandatory	Access	Control):	
SELinux
• Mechanism	to	specify	access	to	resources	based	with	decision	policy.
• SELinux is	an	example	of	this,	you	can	specify	which	policy	the	
process	is	subject	to.
• When	a	resource	is	accessed,	the	policy	is	evaluated	and	a	decision	is	
made.
• SELinux was	introduced	in	Android	4.3	officially	and	it	became	
enforcing	short	after.
• Quite	flexible	but	the	policies	can	become	very	complex	and	difficult	
to	understand.
WebContent Sandbox	on	OS	X
Structure	of	the	Safari	Sandbox
• Safari	code	is	split	to	run	in	
multiple	processes,	based	on	
the	purpose	of	the	code,	
leveraging	WebKit2.
• The	2	main	processes	that	
interests	us	more	are	the	Web	
Process	and	the	UI	Process.
• The	UI	Process	is	the	parent	
and	in	charge	of	managing	the	
other	processes Image	courtesy	of:	
https://trac.webkit.org/attachment/
wiki/WebKit2/webkit2-stack.png
WebContent process
• The	WebContentprocess	is	the	process	responsible	for	handling	
javascript,	webpages,	and	all	the	interesting	stuff.
• Usually	you	get	your	initial	code	execution	inside	here,	thanks	to	a	
browser	bug.
• This	process	is	heavily	sandboxed,	unlike	his	UIProcess parent.
• WebProcess can	talk	to	UIProcess thanks	to	a	“broker”	interface,	so	
he	can	request	resources	(such	as	when	you	have	to	open	a	file	from	
your	computer)	under	the	supervision	of	the	higher	privileged	
UIProcess.
WebContent sandbox
• Regular	OS	X	sandbox	implemented	on	top	of	Sandbox.kext
• The	sandbox	profile	definition	is	currently	located	at:
“/System/Library/Frameworks/WebKit.framework/Versions/A/Resour
ces/com.apple.WebProcess.sb”
• Sandbox.kext specifies	callbacks	for	a	lot	of	TrustedBSD MAC	
framework,	which	places	hooks	in	the	kernel	where	decisions	has	to	
be	made,	to	authorize	access	to	a	resource	or	not	(for	example,	on	file	
access,	the	sandbox	profile	is	used	to	decide	if	access	should	be	
granted	or	not)
Example	profile	snippets
Everything	is	denied	by	default
Importing	“system.sb”	sandbox	definition	 file
Those	particular	mach services	are	whitelisted,	
their	mach port	can	be	asked
System	Integrity	Protection	(SIP)
• In	addition	to	those	Sandboxes,	on	recent	OS	X	versions	you	are	also	
subject	to	System	Integrity	Protection.
• “SIP”	is	a	security	policy	that	applies	to	every	process	running	on	the	
system,	even	the	root	ones.
• Usermode root	have	not	unrestricted	access	anymore
• Kernel	bugs	become	more	appealing	because	they	allow	an	attacker	
to	escape	the	sandbox	and	also	disable	SIP.
Google	Chrome	Sandbox	on	Android	
(Isolated	Process)
Chromium	Android	Sandbox	(1)
• On	Android,	Chromium	leverages	the	isolatedProcess feature	to	
implement	its	sandbox.
Chromium	Android	Sandbox	(2)
• Isolated	process	was	introduced	around	Android	4.3
• "If	set	to	true,	this	service	will	run	under	a	special	process	that	is	
isolated	from	the	rest	of	the	system	and	has	no	permissions	of	its	
own.”
• Chromium	render	process
Chromium	Android	Sandbox	(3)
• So	even	if	code	execution	in	the	render	process	is	achieved,	we	don’t	
have	a	lot	of	capabilities,	and	actually	we	have	lot	of	restrictions.
• In	order	to	do	something	more	meaningful,	a	sandbox	escape	must	
be	chained	after	initial	code	execution.
• Usually	it	can	be	a	kernel	exploit,	or	a	chromium	broker	exploit,	or	
targeting	another	available	attack	surface.
• But	what	about	SELinux?	We	have	to	check	its	SELinux policy,	
“isolated_app.te”,	under	external/sepolicy/	in	AOSP
Chromium	Android	Sandbox	(4)
• Very	restrictive	Sandbox	
profile
• No	data	file	access	at	all
• Only	2	IPC	services
• Minimum	interaction	with	
sockets
• No	graphic	drivers	access	L
• ServiceManager also
restricts implicit service
export
Per interface constraint
• Isolated_app inherits from app_domain (app.te)
• Only interfaces without enforceNotIsolatedCaller can be invoked
Auditing	and	Case	Studies
How	to	audit	a	sandbox	profile?
• Just	look	at	the	definitions	and	see	what	attack	surfaces	are	allowed!
• We	will	try	with	the	WebContent sandbox	on	OS	X.
system.sb is	imported,	 so	we	need	to	check	that	as	well
System-graphics	is	defined	in	system.sb,	let’s	check	it
How	to	audit	a	sandbox	profile?	(2)
Access	to	several	IOKit User	clients
And	services	related	to	graphics
Write	access	to	several	iokit properties	
related	to	graphics
Graphics	seems	definetely a	nice	attack	
surface,
Now	we	can	start	finding	vulnerabilities	
in	those	IOKit clients	by	fuzzing	or	
manual	auditing,	since	we	can	interact	
with	them	from	the	WebContent
process,	where	we	have	initial	code	
execution,	to	escape	the	sandbox,	
getting	kernel	code	execution.
How	to	audit	a	sandbox	profile?	(3)
• “allow-iokit-open”	(iokit-connection	
"IOAccelerator")	is	definetely interesting
• iokit-connection	allows	the	sandboxed	process	
to	open	all	the	userclient under	the	target	
IOService(much	less	restrictive	than	iokit-user-
client-class	)
• In	the	table	on	the	left	we	see	the	Userclients
that	we	can	obtain	on	the	IntelAccelerator
(default	driver	in	most	of	the	recent	Apple	
machines)
UserClient Name Type
IGAccelSurface 0
IGAccelGLContext 1
IGAccel2DContext	 2
IOAccelDisplayPipeUserClient2	 4
IGAccelSharedUserClient 5
IGAccelDevice 6
IOAccelMemoryInfoUserClient 7
IGAccelCLContext 8
IGAccelCommandQueue 9
IGAccelVideoContext 0x100
IOKit vulnerability:	CVE-2016-1744
• Race	condition	in	an	externalMethod in	AppleIntelBDWGraphics.
• Affects	every	recent	Mac	with	Intel	Broadwell CPU/Graphics.
• Discovered	by	code	auditing	when	looking	for	sandbox	escapes	into	IOKit
UserClients reachable	from	the	Safari	WebProcess sandbox.
• Unfortunately	it	got	partially	patched	1-2	weeks	before	Pwn2Own!	LLL .	
A	replacement	was	needed.	L
• Unpatched	in	OSX	10.11.3,	only	partial	fix	in	10.11.4	beta6.
• Reliably	exploitable.
• Finally	it	came	out	that	we	had	a	bug	collision	with	Ian	Beer	of	Google	
Project	Zero,	which	reported	the	bug	to	Apple.
IOKit Vulnerability	– CVE-2016-1744(cont.)
• Wrong/partial	fix	mistake	responsibly	disclosed	to	Apple.
• Fixed	in	10.11.5	beta2
• CVE-2016-1860
IOKit vulnerability:	CVE-2016-1744
• IGAccelCLContext and	
IGAccelGLContext are	2	UserClients
that	can	be	reached	from	the	
WebProcess Safari	sandbox.
• The	locking	mechanisms	in	these	
UserClients is	not	too	good,	some	
methods	expects	only	a	well	
behaved	single	threaded	access.
• First	we	targeted	
unmap_user_memory
IOKit vulnerability:	some	unsafe	code
Race	condition	– How	to	trigger	it?
1. Open	your	target	UserClient (IGAccelCLContext)
2. Call	map_user_memory to	insert	one	element	into	the	IGHashTable
3. Call	with	2	racing	threads	unmap_user_memory.
4. Repeat	2	and	3	until	you	are	able	to	exploit	the	race	window.
5. Double	free	on	first	hand
6. PROFIT!
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
The ideal situation is both threads passes hash table::contains, and when one is
retrieving IOAccelMemoryMap* after get returns valid pointer, the other frees it and
we control the pointer
However in reality more frequently they do passes contains
but thread 1 will remove it before thread 2 do get
and thread 2 hit a null pointer dereference
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
After 2 is removed
After 3 is removed
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
next
prev
mach_vm_addr_t
IOAccelMemoryMap*
IGElement
heap address leaked!
tail element
tail element
For	further	info,	check	our	talk	slides	
“Don't	Trust	Your	Eye:	Apple	Graphics	Is	Compromised!”
http://bit.ly/23GR14N
The	Python	bites	your	apple:	fuzzing	and	exploiting	
OSX	kernel	bugs
https://goo.gl/Ccgni1
For Android Sandbox Escape
• Isolated_app inherits app.te, app.te (appdomain) inherits domain.te
For	Android	Sandbox	Escape(cont.)
• Attacking	the	binder	interface	is	still	an	option
• Exploitingvulnerable basic classes
• SharedStorage integer overflow
• CVE-2015-3875
• Parcel	at	Java	level	accepts	deserialization	on	class	name	specified	by	
string	when	processing	bundle
• A	hidden	path	to	trigger	de/serialization	code	in	system_server context
For	Android	Sandbox	Escape(cont.)
• Attacking	the	binder	interface	is	still	an	option
• Unintend-export?
For	Android	Sandbox	Escape(cont.)
• Attacking	the	binder	interface	is	still	an	option
• Exploitingvulnerable basic classes/	reachable	via	bundle	interfaces
• SharedStorage integer overflow
• Attacking the Chrome IPC
• Attacking WebGL
• GL process runs in host process in Android
• Attacking	the	Kernel
• CVE-2015-1805?
1805	in	action
• Good	news
• No	pipe	policy	in	isolated_app
• Bad	news:
• Cannot	create	socket	and	spray	kernel	memory	use	sendmmsg L
Prevent	vendor’s	binder	mistake
• Integer	overflow	in	Huawei	hw_ext_service running	in	system_server
Comparison
Comparison
• Both	platforms	share	lot	of	traits.	They	both	implement	a	sandbox	
policy	in	files	that	specify	it	and	can	be	audited
• In	general	between	the	2,	the	Chromium	Android	sandbox	feels	
stronger	because	it	exposes	a	smaller	attack	surface.
• On	Android	we	have	more	layer	of	sandboxing:
• Android	sandbox,	chrome	is	an	application,	it’s	restricted	by	its	DAC	sandbox
• IsolatedProcess,	the	render	processes	run	in	their	own	unprivileged	process
• Restrictive	SELinux policy	isolated_app.te
Full	Sandbox	Escape	DEMO!
Summary	and	Conclusions
Summary	and	Conclusions
• Sandboxes	are	a	great	security	mitigation.
• They	require	usually	at	least	another	additional	bug	to	escape	them	
and	compromise	the	system,	especially	from	the	browser	context.
• They	have	the	great	advantage	of	a	very	concise	(and	smaller)	attack	
surface,	much	more	defined	to	audit.
• A	determined	and	knowledgeable	attacker	can	still	compromise	the	
system,	but	with	more	efforts.
Acknowledgments	
• Liang	Chen
• Qoobee
• Wushi
• All	our	other	colleagues	of	KEEN	Lab
Questions?
Twitter:	@keen_lab
Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox
Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox

More Related Content

What's hot

Java でつくる 低レイテンシ実装の技巧
Java でつくる低レイテンシ実装の技巧Java でつくる低レイテンシ実装の技巧
Java でつくる 低レイテンシ実装の技巧
Ryosuke Yamazaki
 
Troubleshooting PostgreSQL Streaming Replication
Troubleshooting PostgreSQL Streaming ReplicationTroubleshooting PostgreSQL Streaming Replication
Troubleshooting PostgreSQL Streaming Replication
Alexey Lesovsky
 
ebpf and IO Visor: The What, how, and what next!
ebpf and IO Visor: The What, how, and what next!ebpf and IO Visor: The What, how, and what next!
ebpf and IO Visor: The What, how, and what next!
Affan Syed
 
PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)
PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)
PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)
NTT DATA Technology & Innovation
 
Sniffing Mach Messages
Sniffing Mach MessagesSniffing Mach Messages
Sniffing Mach Messages
Mikhail Sosonkin
 
MacOS memory allocator (libmalloc) Exploitation
MacOS memory allocator (libmalloc) ExploitationMacOS memory allocator (libmalloc) Exploitation
MacOS memory allocator (libmalloc) Exploitation
Angel Boy
 
これからLDAPを始めるなら 「389-ds」を使ってみよう
これからLDAPを始めるなら 「389-ds」を使ってみようこれからLDAPを始めるなら 「389-ds」を使ってみよう
これからLDAPを始めるなら 「389-ds」を使ってみよう
Nobuyuki Sasaki
 
GoogleのSHA-1のはなし
GoogleのSHA-1のはなしGoogleのSHA-1のはなし
GoogleのSHA-1のはなし
MITSUNARI Shigeo
 
Comparing Accumulo, Cassandra, and HBase
Comparing Accumulo, Cassandra, and HBaseComparing Accumulo, Cassandra, and HBase
Comparing Accumulo, Cassandra, and HBase
Accumulo Summit
 
BuildKitでLazy Pullを有効にしてビルドを早くする話
BuildKitでLazy Pullを有効にしてビルドを早くする話BuildKitでLazy Pullを有効にしてビルドを早くする話
BuildKitでLazy Pullを有効にしてビルドを早くする話
Kohei Tokunaga
 
Kubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-cluster
Kubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-clusterKubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-cluster
Kubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-cluster
Preferred Networks
 
Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)
Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)
Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)
涛 吴
 
Differences between MariaDB 10.3 & MySQL 8.0
Differences between MariaDB 10.3 & MySQL 8.0Differences between MariaDB 10.3 & MySQL 8.0
Differences between MariaDB 10.3 & MySQL 8.0
Colin Charles
 
LISA2019 Linux Systems Performance
LISA2019 Linux Systems PerformanceLISA2019 Linux Systems Performance
LISA2019 Linux Systems Performance
Brendan Gregg
 
暗認本読書会7
暗認本読書会7暗認本読書会7
暗認本読書会7
MITSUNARI Shigeo
 
Explaining Explain
Explaining ExplainExplaining Explain
Explaining Explain
Robert Treat
 
Build an High-Performance and High-Durable Block Storage Service Based on Ceph
Build an High-Performance and High-Durable Block Storage Service Based on CephBuild an High-Performance and High-Durable Block Storage Service Based on Ceph
Build an High-Performance and High-Durable Block Storage Service Based on Ceph
Rongze Zhu
 
HTTP2 最速実装 〜入門編〜
HTTP2 最速実装 〜入門編〜HTTP2 最速実装 〜入門編〜
HTTP2 最速実装 〜入門編〜
Kaoru Maeda
 
Optimizing Autovacuum: PostgreSQL's vacuum cleaner
Optimizing Autovacuum: PostgreSQL's vacuum cleanerOptimizing Autovacuum: PostgreSQL's vacuum cleaner
Optimizing Autovacuum: PostgreSQL's vacuum cleaner
SamaySharma10
 
ProxySQL for MySQL
ProxySQL for MySQLProxySQL for MySQL
ProxySQL for MySQL
Mydbops
 

What's hot (20)

Java でつくる 低レイテンシ実装の技巧
Java でつくる低レイテンシ実装の技巧Java でつくる低レイテンシ実装の技巧
Java でつくる 低レイテンシ実装の技巧
 
Troubleshooting PostgreSQL Streaming Replication
Troubleshooting PostgreSQL Streaming ReplicationTroubleshooting PostgreSQL Streaming Replication
Troubleshooting PostgreSQL Streaming Replication
 
ebpf and IO Visor: The What, how, and what next!
ebpf and IO Visor: The What, how, and what next!ebpf and IO Visor: The What, how, and what next!
ebpf and IO Visor: The What, how, and what next!
 
PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)
PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)
PostgreSQLのgitレポジトリから見える2022年の開発状況(第38回PostgreSQLアンカンファレンス@オンライン 発表資料)
 
Sniffing Mach Messages
Sniffing Mach MessagesSniffing Mach Messages
Sniffing Mach Messages
 
MacOS memory allocator (libmalloc) Exploitation
MacOS memory allocator (libmalloc) ExploitationMacOS memory allocator (libmalloc) Exploitation
MacOS memory allocator (libmalloc) Exploitation
 
これからLDAPを始めるなら 「389-ds」を使ってみよう
これからLDAPを始めるなら 「389-ds」を使ってみようこれからLDAPを始めるなら 「389-ds」を使ってみよう
これからLDAPを始めるなら 「389-ds」を使ってみよう
 
GoogleのSHA-1のはなし
GoogleのSHA-1のはなしGoogleのSHA-1のはなし
GoogleのSHA-1のはなし
 
Comparing Accumulo, Cassandra, and HBase
Comparing Accumulo, Cassandra, and HBaseComparing Accumulo, Cassandra, and HBase
Comparing Accumulo, Cassandra, and HBase
 
BuildKitでLazy Pullを有効にしてビルドを早くする話
BuildKitでLazy Pullを有効にしてビルドを早くする話BuildKitでLazy Pullを有効にしてビルドを早くする話
BuildKitでLazy Pullを有効にしてビルドを早くする話
 
Kubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-cluster
Kubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-clusterKubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-cluster
Kubernetes meetup-tokyo-13-customizing-kubernetes-for-ml-cluster
 
Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)
Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)
Pegasus: Designing a Distributed Key Value System (Arch summit beijing-2016)
 
Differences between MariaDB 10.3 & MySQL 8.0
Differences between MariaDB 10.3 & MySQL 8.0Differences between MariaDB 10.3 & MySQL 8.0
Differences between MariaDB 10.3 & MySQL 8.0
 
LISA2019 Linux Systems Performance
LISA2019 Linux Systems PerformanceLISA2019 Linux Systems Performance
LISA2019 Linux Systems Performance
 
暗認本読書会7
暗認本読書会7暗認本読書会7
暗認本読書会7
 
Explaining Explain
Explaining ExplainExplaining Explain
Explaining Explain
 
Build an High-Performance and High-Durable Block Storage Service Based on Ceph
Build an High-Performance and High-Durable Block Storage Service Based on CephBuild an High-Performance and High-Durable Block Storage Service Based on Ceph
Build an High-Performance and High-Durable Block Storage Service Based on Ceph
 
HTTP2 最速実装 〜入門編〜
HTTP2 最速実装 〜入門編〜HTTP2 最速実装 〜入門編〜
HTTP2 最速実装 〜入門編〜
 
Optimizing Autovacuum: PostgreSQL's vacuum cleaner
Optimizing Autovacuum: PostgreSQL's vacuum cleanerOptimizing Autovacuum: PostgreSQL's vacuum cleaner
Optimizing Autovacuum: PostgreSQL's vacuum cleaner
 
ProxySQL for MySQL
ProxySQL for MySQLProxySQL for MySQL
ProxySQL for MySQL
 

Similar to Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox

Automated Malware Analysis and Cyber Security Intelligence
Automated Malware Analysis and Cyber Security IntelligenceAutomated Malware Analysis and Cyber Security Intelligence
Automated Malware Analysis and Cyber Security Intelligence
Jason Choi
 
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
Priyanka Aash
 
Building world-class security response and secure development processes
Building world-class security response and secure development processesBuilding world-class security response and secure development processes
Building world-class security response and secure development processes
David Jorm
 
Vulnex app secusa2013
Vulnex app secusa2013Vulnex app secusa2013
Vulnex app secusa2013drewz lin
 
Democratizing Fuzzing at Scale by Abhishek Arya
Democratizing Fuzzing at Scale by Abhishek AryaDemocratizing Fuzzing at Scale by Abhishek Arya
Democratizing Fuzzing at Scale by Abhishek Arya
abh.arya
 
OWASP 2013 APPSEC USA Talk - OWASP ZAP
OWASP 2013 APPSEC USA Talk - OWASP ZAPOWASP 2013 APPSEC USA Talk - OWASP ZAP
OWASP 2013 APPSEC USA Talk - OWASP ZAP
Simon Bennetts
 
ShiftGearsWithInformationSecurity.pdf
ShiftGearsWithInformationSecurity.pdfShiftGearsWithInformationSecurity.pdf
ShiftGearsWithInformationSecurity.pdf
Steven Carlson
 
Mapping Detection Coverage
Mapping Detection CoverageMapping Detection Coverage
Mapping Detection Coverage
Jared Atkinson
 
Security: The Value of SBOMs
Security: The Value of SBOMsSecurity: The Value of SBOMs
Security: The Value of SBOMs
Weaveworks
 
Understanding container security
Understanding container securityUnderstanding container security
Understanding container security
John Kinsella
 
KidoZen Mastering Unit Testing in Xamarin
KidoZen Mastering Unit Testing in Xamarin KidoZen Mastering Unit Testing in Xamarin
KidoZen Mastering Unit Testing in Xamarin
kidozen
 
BSides Manchester 2014 ZAP Advanced Features
BSides Manchester 2014 ZAP Advanced FeaturesBSides Manchester 2014 ZAP Advanced Features
BSides Manchester 2014 ZAP Advanced Features
Simon Bennetts
 
How to Choose a SandBox - Gartner
How to Choose a SandBox - GartnerHow to Choose a SandBox - Gartner
How to Choose a SandBox - Gartner
Moti Sagey מוטי שגיא
 
Sandboxing - Malware detection.pptx
Sandboxing - Malware detection.pptxSandboxing - Malware detection.pptx
Sandboxing - Malware detection.pptx
ArshadFarhad4
 
How to Use Open Source Tools to Improve Network Security
How to Use Open Source Tools to Improve Network SecurityHow to Use Open Source Tools to Improve Network Security
How to Use Open Source Tools to Improve Network Security
Mohammed Almusaddar
 
OWASP 2013 Limerick - ZAP: Whats even newer
OWASP 2013 Limerick - ZAP: Whats even newerOWASP 2013 Limerick - ZAP: Whats even newer
OWASP 2013 Limerick - ZAP: Whats even newer
Simon Bennetts
 
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
OWASP 2013 AppSec EU Hamburg - ZAP InnovationsOWASP 2013 AppSec EU Hamburg - ZAP Innovations
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
Simon Bennetts
 
Seacon Continuous Delivery Pipeline Tools Track
Seacon Continuous Delivery Pipeline Tools TrackSeacon Continuous Delivery Pipeline Tools Track
Seacon Continuous Delivery Pipeline Tools Track
Mark Rendell
 
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptxSANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
JasonOstrom1
 
EMBA Firmware analysis - TROOPERS22
EMBA Firmware analysis - TROOPERS22EMBA Firmware analysis - TROOPERS22
EMBA Firmware analysis - TROOPERS22
MichaelM85042
 

Similar to Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox (20)

Automated Malware Analysis and Cyber Security Intelligence
Automated Malware Analysis and Cyber Security IntelligenceAutomated Malware Analysis and Cyber Security Intelligence
Automated Malware Analysis and Cyber Security Intelligence
 
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
From Thousands of Hours to a Couple of Minutes: Automating Exploit Generation...
 
Building world-class security response and secure development processes
Building world-class security response and secure development processesBuilding world-class security response and secure development processes
Building world-class security response and secure development processes
 
Vulnex app secusa2013
Vulnex app secusa2013Vulnex app secusa2013
Vulnex app secusa2013
 
Democratizing Fuzzing at Scale by Abhishek Arya
Democratizing Fuzzing at Scale by Abhishek AryaDemocratizing Fuzzing at Scale by Abhishek Arya
Democratizing Fuzzing at Scale by Abhishek Arya
 
OWASP 2013 APPSEC USA Talk - OWASP ZAP
OWASP 2013 APPSEC USA Talk - OWASP ZAPOWASP 2013 APPSEC USA Talk - OWASP ZAP
OWASP 2013 APPSEC USA Talk - OWASP ZAP
 
ShiftGearsWithInformationSecurity.pdf
ShiftGearsWithInformationSecurity.pdfShiftGearsWithInformationSecurity.pdf
ShiftGearsWithInformationSecurity.pdf
 
Mapping Detection Coverage
Mapping Detection CoverageMapping Detection Coverage
Mapping Detection Coverage
 
Security: The Value of SBOMs
Security: The Value of SBOMsSecurity: The Value of SBOMs
Security: The Value of SBOMs
 
Understanding container security
Understanding container securityUnderstanding container security
Understanding container security
 
KidoZen Mastering Unit Testing in Xamarin
KidoZen Mastering Unit Testing in Xamarin KidoZen Mastering Unit Testing in Xamarin
KidoZen Mastering Unit Testing in Xamarin
 
BSides Manchester 2014 ZAP Advanced Features
BSides Manchester 2014 ZAP Advanced FeaturesBSides Manchester 2014 ZAP Advanced Features
BSides Manchester 2014 ZAP Advanced Features
 
How to Choose a SandBox - Gartner
How to Choose a SandBox - GartnerHow to Choose a SandBox - Gartner
How to Choose a SandBox - Gartner
 
Sandboxing - Malware detection.pptx
Sandboxing - Malware detection.pptxSandboxing - Malware detection.pptx
Sandboxing - Malware detection.pptx
 
How to Use Open Source Tools to Improve Network Security
How to Use Open Source Tools to Improve Network SecurityHow to Use Open Source Tools to Improve Network Security
How to Use Open Source Tools to Improve Network Security
 
OWASP 2013 Limerick - ZAP: Whats even newer
OWASP 2013 Limerick - ZAP: Whats even newerOWASP 2013 Limerick - ZAP: Whats even newer
OWASP 2013 Limerick - ZAP: Whats even newer
 
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
OWASP 2013 AppSec EU Hamburg - ZAP InnovationsOWASP 2013 AppSec EU Hamburg - ZAP Innovations
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
 
Seacon Continuous Delivery Pipeline Tools Track
Seacon Continuous Delivery Pipeline Tools TrackSeacon Continuous Delivery Pipeline Tools Track
Seacon Continuous Delivery Pipeline Tools Track
 
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptxSANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
SANS_PentestHackfest_2022-PurpleTeam_Cloud_Identity.pptx
 
EMBA Firmware analysis - TROOPERS22
EMBA Firmware analysis - TROOPERS22EMBA Firmware analysis - TROOPERS22
EMBA Firmware analysis - TROOPERS22
 

More from mark-smith

How Your DRAM Becomes a Security Problem
How Your DRAM Becomes a Security ProblemHow Your DRAM Becomes a Security Problem
How Your DRAM Becomes a Security Problem
mark-smith
 
Applied Machine Learning for Data exfil and other fun topics
Applied Machine Learning for Data exfil and other fun topicsApplied Machine Learning for Data exfil and other fun topics
Applied Machine Learning for Data exfil and other fun topics
mark-smith
 
JailBreak DIY- Fried Apple
JailBreak DIY- Fried AppleJailBreak DIY- Fried Apple
JailBreak DIY- Fried Apple
mark-smith
 
The linux kernel hidden inside windows 10
The linux kernel hidden inside windows 10The linux kernel hidden inside windows 10
The linux kernel hidden inside windows 10
mark-smith
 
Exploiting Curiosity and Context
Exploiting Curiosity and ContextExploiting Curiosity and Context
Exploiting Curiosity and Context
mark-smith
 
Abusing belkin home automation devices
Abusing belkin home automation devicesAbusing belkin home automation devices
Abusing belkin home automation devices
mark-smith
 
Greed for Fame Benefits Large Scale Botnets
Greed for Fame Benefits Large Scale BotnetsGreed for Fame Benefits Large Scale Botnets
Greed for Fame Benefits Large Scale Botnets
mark-smith
 
How your smartphone cpu breaks software level security and privacy
How your smartphone cpu breaks software level security and privacyHow your smartphone cpu breaks software level security and privacy
How your smartphone cpu breaks software level security and privacy
mark-smith
 
Attacking Network Infrastructure to Generate a 4 Tbs DDoS
Attacking Network Infrastructure to Generate a 4 Tbs DDoSAttacking Network Infrastructure to Generate a 4 Tbs DDoS
Attacking Network Infrastructure to Generate a 4 Tbs DDoS
mark-smith
 
How to Make People Click on a Dangerous Link Despite their Security Awareness
How to Make People Click on a Dangerous Link Despite their Security Awareness How to Make People Click on a Dangerous Link Despite their Security Awareness
How to Make People Click on a Dangerous Link Despite their Security Awareness
mark-smith
 
Technologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible CyberspaceTechnologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible Cyberspace
mark-smith
 
Technologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible CyberspaceTechnologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible Cyberspace
mark-smith
 

More from mark-smith (12)

How Your DRAM Becomes a Security Problem
How Your DRAM Becomes a Security ProblemHow Your DRAM Becomes a Security Problem
How Your DRAM Becomes a Security Problem
 
Applied Machine Learning for Data exfil and other fun topics
Applied Machine Learning for Data exfil and other fun topicsApplied Machine Learning for Data exfil and other fun topics
Applied Machine Learning for Data exfil and other fun topics
 
JailBreak DIY- Fried Apple
JailBreak DIY- Fried AppleJailBreak DIY- Fried Apple
JailBreak DIY- Fried Apple
 
The linux kernel hidden inside windows 10
The linux kernel hidden inside windows 10The linux kernel hidden inside windows 10
The linux kernel hidden inside windows 10
 
Exploiting Curiosity and Context
Exploiting Curiosity and ContextExploiting Curiosity and Context
Exploiting Curiosity and Context
 
Abusing belkin home automation devices
Abusing belkin home automation devicesAbusing belkin home automation devices
Abusing belkin home automation devices
 
Greed for Fame Benefits Large Scale Botnets
Greed for Fame Benefits Large Scale BotnetsGreed for Fame Benefits Large Scale Botnets
Greed for Fame Benefits Large Scale Botnets
 
How your smartphone cpu breaks software level security and privacy
How your smartphone cpu breaks software level security and privacyHow your smartphone cpu breaks software level security and privacy
How your smartphone cpu breaks software level security and privacy
 
Attacking Network Infrastructure to Generate a 4 Tbs DDoS
Attacking Network Infrastructure to Generate a 4 Tbs DDoSAttacking Network Infrastructure to Generate a 4 Tbs DDoS
Attacking Network Infrastructure to Generate a 4 Tbs DDoS
 
How to Make People Click on a Dangerous Link Despite their Security Awareness
How to Make People Click on a Dangerous Link Despite their Security Awareness How to Make People Click on a Dangerous Link Despite their Security Awareness
How to Make People Click on a Dangerous Link Despite their Security Awareness
 
Technologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible CyberspaceTechnologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible Cyberspace
 
Technologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible CyberspaceTechnologies and Policies for a Defensible Cyberspace
Technologies and Policies for a Defensible Cyberspace
 

Recently uploaded

This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!
nirahealhty
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
keoku
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
Javier Lasa
 
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptxBridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Brad Spiegel Macon GA
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
Gal Baras
 
Bài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docxBài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docx
nhiyenphan2005
 
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shopHistory+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
laozhuseo02
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
Arif0071
 
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdfMeet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Florence Consulting
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
harveenkaur52
 
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
CIOWomenMagazine
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
3ipehhoa
 
1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...
JeyaPerumal1
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
Rogerio Filho
 
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
3ipehhoa
 
Comptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guideComptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guide
GTProductions1
 
Latest trends in computer networking.pptx
Latest trends in computer networking.pptxLatest trends in computer networking.pptx
Latest trends in computer networking.pptx
JungkooksNonexistent
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
ufdana
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
3ipehhoa
 

Recently uploaded (20)

This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!This 7-second Brain Wave Ritual Attracts Money To You.!
This 7-second Brain Wave Ritual Attracts Money To You.!
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
 
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptxBridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
Bridging the Digital Gap Brad Spiegel Macon, GA Initiative.pptx
 
How to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptxHow to Use Contact Form 7 Like a Pro.pptx
How to Use Contact Form 7 Like a Pro.pptx
 
Bài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docxBài tập unit 1 English in the world.docx
Bài tập unit 1 English in the world.docx
 
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shopHistory+of+E-commerce+Development+in+China-www.cfye-commerce.shop
History+of+E-commerce+Development+in+China-www.cfye-commerce.shop
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
 
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdfMeet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
Meet up Milano 14 _ Axpo Italia_ Migration from Mule3 (On-prem) to.pdf
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
 
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
Internet of Things in Manufacturing: Revolutionizing Efficiency & Quality | C...
 
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
急速办(bedfordhire毕业证书)英国贝德福特大学毕业证成绩单原版一模一样
 
1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...1.Wireless Communication System_Wireless communication is a broad term that i...
1.Wireless Communication System_Wireless communication is a broad term that i...
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
 
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
原版仿制(uob毕业证书)英国伯明翰大学毕业证本科学历证书原版一模一样
 
Comptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guideComptia N+ Standard Networking lesson guide
Comptia N+ Standard Networking lesson guide
 
Latest trends in computer networking.pptx
Latest trends in computer networking.pptxLatest trends in computer networking.pptx
Latest trends in computer networking.pptx
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
 
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
1比1复刻(bath毕业证书)英国巴斯大学毕业证学位证原版一模一样
 

Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox