Black Hat USA 2009

This is the talk I did at Black Hat USA 2009 together with Charlie Miller(0xCharlie).

Abstract:

Iphones are now widely used by people; as a consequence the number of factory phones is slightly increasing.

Until today researchers focused on exploiting techniques for jailbroken phones, most of them are not usable on factory phones due to a number of protections including code signing. For that reason leveraging a bug on the phone today is really hard.

This presentation will show how is it possible to effectively exploiting a factory phone by defeating code signing protection.Specifically by injecting an arbitrary non-signed library in the victim’s process address space an attacker is able to run his own code thus granting a much higher attack efficacy.

In fact the ability of running a library on the phone allows an attacker to create high-level and complex payloads which were not possible before.

Slides:

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s