#HITB2012AMS D2T2 - Dream Team - Part 1 - Corona for iOS 5.0.1
Sign in to YouTube
Sign in to YouTube
Sign in to YouTube
Published on Jun 22, 2012
#HITB2012KUL (OCT 10-11) REGISTRATION NOW OPEN
Presentation Materials: http://conference.hitb.org/hitbseccon...
GreenPois0n Absinthe was built upon @pod2g's Corona untether jailbreak to create the first public jailbreak for the iPhone 4S and iPad 2 on for the 5.0.1 firmware. In this paper, we present a chain of multiple exploits to accomplish sandbox breakout, kernel unsigned code injection and execution that result in a fully-featured and untethered jailbreak.
Corona is an acronym for "racoon", which is the primary victim for this attack. A format string vulnerability was located in racoon's error handling routines, allowing the researchers to write arbitrary data to racoon's stack, one byte at a time, if they can control racoon's configuration file. Using this technique researchers were able to build a ROP payload on racoon's stack to mount a rogue HFS volume that injects code at the kernel level and patch its code-signing routines.
The original Corona untether exploit made use of the LimeRa1n bootrom exploit as an injection vector, to allow developers to disable ASLR and sandboxing, and call racoon with a custom configuration script. This however left it unusable for newer A5 devices like the iPad2 and iPhone 4S, which weren't exploitable to LimeRa1n, so another injection vector was needed.
ABOUT JOSHUA HILL (@p0sixninja)
Joshua Hill (@p0sixninja) is an independent Security Researcher for zImperium, as well as leader of the Chronic Dev Team and chief architect behind GreenPois0n, a cross-platform toolkit used by millions of people around the world to jailbreak their iOS mobile devices.
ABOUT CYRIL (@pod2g)
Cyril (@pod2g) is an iPhone hacker who has discovered and exploited several bootrom exploits on iDevices, including 24kpwn, steaks4uce, and SHAtter, as well as several userland and kernel exploits that have been used in various jailbreak tools. He's a member of Chronic-Dev Team and the original author the of Corona untether jailbreak.
ABOUT NIKIAS BASSEN (@pimskeks)
Nikias Bassen (@pimskeks) is a Chronic-Dev Team member and main developer of libimobiledevice, usbmuxd, and other related projects that form an open source implementation of communication and service protocols for iDevices. He found several flaws in the iDevice service protocols that also helped creating Absinthe.
ABOUT DAVID WANG (@planetbeing)
David Wang (@planetbeing) is a member of the iPhone Dev Team and former developer of many iOS jailbreak tools including redsn0w, xpwn, and QuickPwn. He is also the first to have ported the Linux kernel and Android to iOS devices.
Standard YouTube License
- 52:47 #HITB2012AMS D2T2 - Dream Team - Part 2 - Absinthe for iOS 5.0.1 (... and One More Thing)by Hack In The Box Security Conference 10,171 views
- 55:16 Google I/O 2009 - The Myth of the Genius Programmerby GoogleDevelopers 219,460 views
- 10:01 DEFCON 2012 - Hacking Smart Meters - Part 1 of 5by Mike Smith 8,195 views
- 42:45 #HITB2012AMS D1T2 - MuscleNerd - Evolution of iPhone Baseband and Unlocksby Hack In The Box Security Conference 33,754 views
- 25:27 Deleted John Stockton and Karl Malone Bits from the Dream Team Documentaryby jazzfanatical 122,843 views
- 52:08 Olimpic games 1992 Dream Team - USA@ Lithuania semifinal.by jons3000002 391,651 views
- 4:42 1992 Dream Team Top 10 playsby LittlePersians 1,697,044 views
- 57:14 #HITB2012KUL D1T2 - Mark Dowd & Tarjei Mandt - iOS 6 Securityby Hack In The Box Security Conference 5,303 views
- 2:26 "Dream Team" - 1992 USA Olympic Basketball teamby 805Bruin's channel 158,738 views
- 26:54 Top 20 Best Cydia Tweaks and Apps - 2013 - Part 2by iTwe4kz 5,873 views
- 1:28 Dragon Houseby Jason Locklear 1,128 views
- 3:52 1992 USA Olympic Dream Team, Part 6by philly zag 26,944 views
- 0:38 Chronic Dev Team announces jailbreak for iOS 5.1.1 at HITB 2012 Amsterdamby SoftpediaNews 3,656 views
- 5:07 How To: Bypass iPhone 4 Passcode on iOS 6.1.3 Firmware + How To Defend/Protect Against Itby EverythingTechBlog 20,836 views
- 9:52 The Dream Team 20th Anniversaryby ESPN 191,131 views
- 12:44 How to create and use a Custom UIMenuController with iOS (Objective-c)by www.g8production.com 1,692 views
- 3:48 1992 USA Olympic Dream Team, Part 1by philly zag 53,083 views
- 5:50 Untethered iOS 6 iPhone 4Sby Kamran Malik 12,273 views
- 4:50 How-to Jailbreak iPhone 4S & iPad 2 on iOS 5.0.1 with Absintheby Ben Stubley 277,292 views
- 2:21 How To Get cydia without Jailbreak ( no openappmkt)by john gawn 9,764 views
- Loading more suggestions...