5 ms·
Related tweet (POC): https://twitter.com/b1n4r1b01/status/1419734027565617165 https://twitter.com/b1n4r1b01/status/1419734027565617165 Also (writeup): https:
by mrunseen 5y ago
Related tweet (POC):
https://twitter.com/b1n4r1b01/status/1419734027565617165 https://twitter.com/b1n4r1b01/status/1419734027565617165
Also (writeup):
https://twitter.com/AmarSaar/status/1419770084780875779?s=20 https://twitter.com/AmarSaar/status/1419770084780875779?s=20
- sillysaurusx 5y ago> Thanks a lot Maddie! Sure, I wanted to write a full exploit and achieve tfp0 before submitting because it affects the submission quality. I'm pretty busy right now, so I planned to work on it after August. I did plan to submit it, but I wanted to get an exploit first :) As a former pentester, that's precisely the opposite of the correct thing to do. tptacek could phrase this more eloquently, but pentesters do not try to weaponize exploits. The whole point of exploiting is to demonstrate that a vuln exists. Once that demonstration is complete, weaponization serves no purpose. (No purpose for protecting users, anyway, which is the whole point of pentesting.) I'm surprised no one seems to care. Maybe times are changing.
- saagarjha 5y agoApple will generally not award you a bounty unless you send them a full chain.
- sillysaurusx 5y agoOh. Then it's totally justified. My mistake. I didn't realize that there might be a difference in the awarded bounty level. That's... unfortunate for them. As you can see here, he was sitting on this for some time.
- _kbh_ 5y agoThe only 'correct' thing to do is whatever the person who discovered the bug wants to do. Responsible disclosure is a nicety that most people in the industry follow, it is not a requirement.
- aj3 5y agoApple is asking for "a reasonably reliable exploit" for full bounty payment: https://developer.apple.com/security-bounty/ https://developer.apple.com/security-bounty/
- quenix 5y agoCan someone ELI5 what this POC actually does? As someone with little experience w/ iOS internals or its kernel, I’m not sure what I’m looking at. Does it run code as root? Write kernel memory?