5 ms·
Geohot presents an evasi0n7 writeup
- innoying 13y agoMods, please don't remove the title as the original page does not have a title.
- scott_karana 13y agoLooks like geohot noticed your post: there's a title now. ;)
- innoying 13y agoCool! That's better than what I had before.
- innoying 13y agoAdditional/Duplicate Information: http://pastebin.com/mT2n7uyj http://pastebin.com/mT2n7uyj
- foobarqux 13y agoThat one is actually understandable.
- sheetjs 13y agomost interesting part: > I found nothing sketchy in my reversing, your phones most likely aren't being backdoored by Chinese.
- jjcm 13y agoKeep in mind: > This journey stops at root for now, since the /evasi0n7 binary is supa obfuscated good.
- bri3d 13y agoThe part geohot reversed in this article is the non-persistent set of exploits used to get root. The persistent (and buggy) stage of the exploit used to "untether" (re-exploit on reboot) and patch the OS is obfuscated. That's where a backdoored exploit would be if there was one anyway. I think it's unlikely the evad3rs actually included a backdoor in their payload, but the way they handled their release was still silly enough that I won't install it. iOS jailbreaks are all taken on faith (after all, nobody but them knows what's in that obfuscated untether/patch binary) and they didn't do a lot to build any.
- nwh 13y ago> I think it's unlikely the evad3rs actually included a backdoor in their payload They agreed to bundle an app store who's only purpose is piracy (0xabadidea and Paul Haddad worked to remove their piracy system previously) without in the slightest wondering what it would be used for. From what I've read there's still bits of the Chinese scumware installed when you jailbreak in another country, and given the opinion of the Chinese company involved.. I wouldn't put it past them. I truly hope that geohot or another skilled developer repackages their jailbreak with a copy of MobileSubstrate that actually works and a Cydia build that's built properly by saurik. The evad3rs have completely lost any trust they have, and from pod2g's tweets they're extremely aware of how badly they fucked this up.
- stingraycharles 13y agoI've just come across this write-up by the evasion team, I'm not sure how to interpret it: http://evasi0n.com/l.html http://evasi0n.com/l.html
- StavrosK 13y agoHow did they handle the release? I don't have an iPhone so I haven't seen much, but I know there's some hubbub around this.
- nwh 13y agoIn short: • evad3rs released an iOS7 jailbreak unexpectedly due to a leak • it became apparent that it bundles some Chinese piracy store with no other legitimate purpose [0] • information is made public that the evad3rs were paid $1M USD to include the piracy store • evad3rs say they weren't aware it was for piracy (and never bothered to check) • evad3rs aren't even sure if the Chinese bundle is malicious, it sends home encrypted something [1] • evad3rs remove the Chinese bundles from their server and activate their kill switch [2] • pod2g promises to release a clean jailbreak [3] The end result is that the jailbreak ruined the trust of the community by including crapware and possibly malware, enabling mass piracy, ultimately not even bothering to check the binaries that they were paid to include. They've burnt Geohot's exploits for a 7.1 jailbreak, as the release timing means that they will be patched by Apple and be completely useless in the future. The jailbreak they released is worthless for the moment due to them not bothering to include the proper Substrate releases from saurik. [0]: https://twitter.com/pod2g/status/414810029376933889 https://twitter.com/pod2g/status/414810029376933889 [0]: https://twitter.com/pod2g/status/415114461473964032 https://twitter.com/pod2g/status/415114461473964032 [0]: https://twitter.com/pod2g/status/414820772931067905 https://twitter.com/pod2g/status/414820772931067905 [1]: https://twitter.com/pod2g/status/415116127292108801 https://twitter.com/pod2g/status/415116127292108801 [2]: https://twitter.com/pod2g/status/414942393830756352 https://twitter.com/pod2g/status/414942393830756352 [3]: https://twitter.com/pod2g/status/415125262989557760 https://twitter.com/pod2g/status/415125262989557760
- 0x0 13y agoIt's kinda neat how they are sending disk/block-level reads and writes, probably using a user-space/local HFS file system implementation, to inject the exploit, since the mounted file system is read-only.
- innoying 13y agoYeah, very cool. It only works because the rootfs is mounted as read-only or else they might end up messing it up if the system was writing to the same block. But then again if it wasn't read-only this wouldn't be a problem.
- 0x0 13y agoA lot of the recent jailbreaks seem to depend on symlink shenanigans. I wonder why Apple can't simply remove symlink support from iOS' filesystem driver? Is there anything in iOS or the appstore apps that depend on it?
- innoying 13y agoMany parts of the internal system depend on it. Here's a run of `find / -type l` on a jailbroken iPhone 5: https://gist.github.com/innoying/8cd04821e17b3f67aa4b https://gist.github.com/innoying/8cd04821e17b3f67aa4b A few of those are created by the jailbreak but most are core parts of the system.
- gluxon 13y agoThat's actually a lot less than I thought would be in the iOS filesystem. It doesn't seem like it'd be incredibly hard to remove those symlinks. Although Apple would probably favor fixing the bugs that allow malicious symlinks rather than remove symlinks from their file system driver (the horror!)
- innoying 13y agoThey would also have to make sure no iOS applications make use of symlinks at any point. Since a ipa is simply a zip archive it's possible (and probable) that some applications already make use of symlinks on install or during operation. I think that's the major motivation.
- gluxon 13y agoHow does reverse engineering binaries like this work? Did geohot really go through the entire disassemble during the time of a plane ride?
- innoying 13y agoAs evidenced by hash Geohot posted on his twitter on December 8th of http://geohot.com/mt.jpg http://geohot.com/mt.jpg he has had access to some of the vulnerabilities for some time. I know for sure the use of the signed WWDC application has been known by some of the jailbreak developers for over a year.
- tomphoolery 13y agogeorge, you are amazing.
- quarterto 13y agoSomething looks a bit off with that photo [1]. The screen size is wrong. It has the aspect ratio of a pre-5 iPhone (notice the extra-large gap between the bottom of the screen and the home button compared to [2]). It also appears to be running iOS 6, which I'm pretty sure isn't possible on a 5s. [1]: http://geohot.com/mt.jpg http://geohot.com/mt.jpg [2]: http://images.apple.com/iphone/compare/images/compare_iphone5s_2x.jpg http://images.apple.com/iphone/compare/images/compare_iphone...
- pix64 13y agoThe bottom of the keyboard is not the bottom of the screen. http://i.imgur.com/TzUAKI9.jpg http://i.imgur.com/TzUAKI9.jpg
- tmgrhm 13y agoThe screen size looks wrong because the app is running in pillar box mode — it's only been compiled to run for 640x960 screens (i.e. iPhone 4S and older). The keyboard is iOS 6 styled because the app hasn't been compiled for iOS 7. Nothing out of the ordinary here.
- rounak 13y agoMobileTerminal (the app he's running) hasn't been updated with iPhone 5 support