Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
illusionofchaos
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
1.
▲
How malware gets into the App Store and why Apple can't stop that
(habr.com)
13 points
by
illusionofchaos
5y ago
|
2 comments
2.
▲
by
illusionofchaos
5y ago
I've updated the article to include a timeline for each vulnerability
3.
▲
by
illusionofchaos
5y ago
It can be shipped, static analysis is easily bypassed, you can check it yourself on gamed exploit
4.
▲
by
illusionofchaos
5y ago
Good idea, I've added the comment
5.
▲
by
illusionofchaos
5y ago
Look at the code of gamed exploit that I've uploaded to GitHub, the app is written in Swift and it calls Objective-C runtime functions from it
6.
▲
by
illusionofchaos
5y ago
If you have a developer account that you are willing to sacrifice and don't mind the possibility of legal action, you can try that. I've managed to upload the binary built from the source code from gamed exploit repository on GitH
7.
▲
by
illusionofchaos
5y ago
It's just marked as unavailable. Apple does that to try keeping people from using XPC on iOS. Use the full code from GitHub, it has a bypass for that Xcode check
8.
▲
by
illusionofchaos
5y ago
I haven't checked further, maybe authentication token can be used to gain access to Apple account and more data. Also one other method could used to write arbitrary data outside of an app sandbox, that might be useful for further explo
9.
▲
by
illusionofchaos
5y ago
You can see the logs in JSON inside Settings app. Also if two vulnerabilities are used together, you can get full name and email and connect it to health data
10.
▲
by
illusionofchaos
5y ago
That's exactly how it happened for me. I noticed that when an app logs into Game Center, the notification is shown inside the app, and not in a remote process like when you choose contacts of compose an email. That led to easily discov
11.
▲
by
illusionofchaos
5y ago
> static analysis which Apple obviously uses as part of its approval process This analysis is a joke, it just scans strings inside binaries against the list of symbols corresponding to what Apple considers to be Private API. Gamed exploi
12.
▲
by
illusionofchaos
5y ago
Furthermore, no one stops you from developing an app and planting RCE vulnerability inside the binary. Then you can exploit it remotely when necessary and execute the code that exploits any iOS vulnerabilities known to you.
13.
▲
by
illusionofchaos
5y ago
Zerodium is not interested in this kind of bugs. If they own at least one RCE+LPE, they can already access all data on any device and more
14.
▲
by
illusionofchaos
5y ago
This is just a check built into Xcode to try to keep you from accessing XPC in iOS. The code on GitHub bypasses this by calling this method dynamically through Objective-C runtime
15.
▲
by
illusionofchaos
5y ago
Follow the links to GitHub, the code there compiles perfectly, the PoC inside the article is just a shortened version