Live data from Hacker News

Million Dollar iOS9 Bug Bounty

zerodium.com

21–30 of 80 posts

Re: Million Dollar iOS9 Bug Bounty

#23

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

Yes, the stagefright vulnerability in Android (http://arstechnica.com/security/2015/07/950-million-android-...)

Re: Million Dollar iOS9 Bug Bounty

#24

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.

You're correct. jailbreak.me I think it was called

Re: Million Dollar iOS9 Bug Bounty

#25
"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)."

Can someone explain this part? Jailbreak from a website, sms, or mms seems ... impossible. Has this even been possible with older jailbreaks?

Re: Million Dollar iOS9 Bug Bounty

#26

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

You used to be able to jailbreak one of the first iPhones and install Cydia just by visiting some page in Safari and clicking on a button, IIRC. I never did this myself, so my memories might be inaccurate though.

[deleted]

Re: Million Dollar iOS9 Bug Bounty

#27
post #25

"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)." Can someone ex…

Long time ago, but yes: https://en.wikipedia.org/wiki/JailbreakMe

Re: Million Dollar iOS9 Bug Bounty

#28
post #25

"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)." Can someone ex…

[deleted]

Re: Million Dollar iOS9 Bug Bounty

#29

I might be missing something, but has there ever been any exploit (or string of simultaneous exploits) for iOS or android which meets all the criteria? It must be through a text message or web page, it must be remote, reliable, silent, require no interaction, must be entirely comprised of 0-day exploits throughout the whole chain, must affect multiple architectures and all supported devices, and must bypass all secur…

Yes, the stagefright vulnerability in Android ( http://arstechnica.com/security/2015/07/950-million-android-... )

[deleted]

Re: Million Dollar iOS9 Bug Bounty

#30
post #25

"The whole exploitation/jailbreak process should be achievable remotely, reliably, silently, and without requiring any user interaction except visiting a web page or reading a SMS/MMS (attack vectors such as physical access, bluetooth, NFC, or baseband are not eligible for the Million Dollar iOS 9 Bug Bounty. ZERODIUM may, at its sole discretion, make a distinct offer to acquire such attack vectors.)." Can someone ex…

It's not impossible and has been done several times in the past, see https://en.wikipedia.org/wiki/JailbreakMe
Post reply on HN