EuSecWest 2009

Abstract:

At the beginning of the presentation Mach-O file format is discussed, after that a way to store code inside a binary is explained.  Then the basic technique is discussed, specifically how XNU loads binaries and how to impersonate the kernel in order to avoid any execve().  Differences between Mac OS X desktop and the iPhone will be shown.  From a Metasploit meterpreter session, it will be demonstrated that an arbitrary binary can be uploaded and launched without it touching the disk.  Finally, iPhone signing and file system restrictions will be discussed and the methods of this talk will be shown to circumvent them.
Slides:

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s