3 ms·
Since NSO is able to do these 0 click exploits on iphones does this mean they have have hacked apple engs as well and have copies of iOS lying around?
by Thorncorona 5y ago
Since NSO is able to do these 0 click exploits on iphones does this mean they have have hacked apple engs as well and have copies of iOS lying around?
- moyix 5y agoNo, it just means that they've found vulnerabilities that can be triggered without user interaction. This is entirely doable by just fuzzing or reverse engineering the released iOS binaries.
- deleted 5y ago[deleted]
- distantsounds 5y agogo ahead, fuzz your own iOS exploit. you make it sound like someone just cranks one out before lunch.
- bawolff 5y agoEntirely do-able by a team of experts with multimillion dollar budgets over the course of probably many months, doesn't sound at all similar to average hn commenter being able to do it before lunch.
- toxik 5y agoI mean, you’re not going to fuzz your way to bit twiddling together a small virtual computer inside of a compression stream.
- moyix 5y agoOf course – but you can definitely fuzz your way to the initial vulnerability. The VM stuff is done once you have that vulnerability and are writing the actual exploit, which is a manual process.
- TechBro8615 5y agoThe blog says the PDF parsing was based on xpdf which is open source.
- CPLX 5y agoThat was my first guess reading this. Like they just HAVE to have the source code right?
- nexuist 5y agoI mean, it would just be a prudent business move once the first PoC comes out right? You know that Apple is going to patch it eventually. It totally makes sense to try to pop a dev box and exfiltrate the source code. The only question is if they can make it past Apple's network security - it's unlikely that devs are allowed to take their work MacBooks with iOS source code home.
- itsokimbatman 5y agoNah that’s what tools like IDAPro and Ghidra are for. You don’t need source although it does help. That said, the particular component this targets is open source. It’s the JBIG2 decoder that is part of XPDF.
- marcan_42 5y agoSource code doesn't help that much, and sometimes the assembly makes some bugs more obvious. They really don't need the source. They just decompile it. People without reverse engineering experience often think there's a massive difference between white-box and black-box auditing, but there really isn't. Yes, it takes longer, but not ridiculously so. NSO aren't interested in being an overtly criminal operation; breaking into Apple and stealing source would be a giant liability they don't need to have. Their game is feigning ignorance as to what their customers do with their software. They can't afford to be caught commiting crimes directly.