36C3 - The One Weird Trick SecureROM Hates

  Рет қаралды 28,145

media.ccc.de

media.ccc.de

Күн бұрын

media.ccc.de/v/36c3-11238-the...
Checkm8 is an unfixable vulnerability present in hundreds of millions of iPhones' SecureROM. This is a critical component in Apple's Secure Boot model and allows security researchers and jailbreakers alike to take full control over the application processor's execution.
This talk will detail how we built an iOS jailbreak from the ground up - quite literally - by using an use-after-free in Apple's SecureROM. This is key code which is designed to bring up the application processor during boot but also exposes a firmware update interface over USB called DFU.
By abusing this vulnerability it is possible to unlock full control of the application processor, including enabling debugging functionalities such as JTAG, helping security researchers look for security vulnerabilities in Apple devices more effectively.
We will analyse the root-cause and techniques used for exploitation, as well mention some of the hurdles we encountered while trying to turn this into a reliable jailbreak and plans for the future of this project.
qwertyoruiop
fahrplan.events.ccc.de/congre...

Пікірлер
36C3 -  #mifail oder: Mit Gigaset wäre das nicht passiert!
54:07
media.ccc.de
Рет қаралды 33 М.
36C3 -  Open Source is Insufficient to Solve Trust Problems in Hardware
1:00:46
Doing This Instead Of Studying.. 😳
00:12
Jojo Sim
Рет қаралды 20 МЛН
Spot The Fake Animal For $10,000
00:40
MrBeast
Рет қаралды 194 МЛН
لااا! هذه البرتقالة مزعجة جدًا #قصير
00:15
One More Arabic
Рет қаралды 13 МЛН
Why The Windows Phone Failed
24:08
Apple Explained
Рет қаралды 234 М.
36C3 -  How to Break PDFs
58:43
media.ccc.de
Рет қаралды 33 М.
The moment we stopped understanding AI [AlexNet]
17:38
Welch Labs
Рет қаралды 853 М.
36C3 -  Hacking Sony PlayStation Blu-ray Drives
49:11
media.ccc.de
Рет қаралды 30 М.
36C3 -  SIM card technology from A-Z
1:03:23
media.ccc.de
Рет қаралды 19 М.
36C3 -  15 Jahre deutsche Telematikinfrastruktur (TI)
41:47
media.ccc.de
Рет қаралды 15 М.
37C3 -  Sonic Alchemy
44:14
media.ccc.de
Рет қаралды 10 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,5 МЛН
Doing This Instead Of Studying.. 😳
00:12
Jojo Sim
Рет қаралды 20 МЛН