EPISODE · Sep 19, 2016
Max Bazaliy - A Journey Through Exploit Mitigation Techniques in iOS
from DEF CON 24 [Audio] Speeches from the Hacker Convention · host DEF CON Announcements
Materials: https://media.defcon.org/DEF CON 24/DEF CON 24 presentations/DEFCON-24-Max-Bazaliy-A-Journey-Through-Exploit-Mitigation-Techniques-On-Ios-UPDATED.pdf A Journey Through Exploit Mitigation Techniques in iOS Max Bazaliy Staff Engineer, Lookout Over the past year, Apple has consistently added features to prevent exploitation of the iOS kernel. These features, while largely misunderstood, provide a path for understanding of the iOS security model going forward. This talk will examine the history of iOS’s exploit mitigations from iOS 8 to iOS 9.3 in order to teach important features of the architecture. This talk will cover various enhancements that stop attackers from dynamically modifying the functionality of system services, but also resulted in the defeat of all known exploitation through function hooking. Additionally, we will explore how the ability to use PLT interception and the use of direct memory overwrite are no longer options for exploit writers because of recent changes. Finally, we will cover the code-signing mechanism in depth, userland and kernel implementations and possible ways to bypass code-sign enforcement. Max Bazaliy is a security researcher at Lookout. He has over 9 years of experience in the security research space. Max has experience in native code obfuscation, malware detection and iOS exploitation. Before joining Lookout Max was working in malware research and software protection areas, most recently at Bluebox Security. Currently he is focused on mobile security research, XNU and LLVM internals. Max holds a Master's degree in Computer Science. Twitter: @mbazaliy
Embed this episode
NOW PLAYING
Max Bazaliy - A Journey Through Exploit Mitigation Techniques in iOS
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.