So similar to Stagefright?
A deep dive into iOS Exploit chains found in the wild
171–180 of 202 posts
Re: A deep dive into iOS Exploit chains found in the wild
#172Earlier quoted context omitted.
>The only way to be safe is probably to access your financial sites These folks don't want money. And statue protects you from fraud - just set up text and email alerts so large transactions alert you ASAP.
Except they have control of the phone and can intercept text and email alerts, if not with these exact vulnerabilities, it doesn't seem far fetched. And getting funds returned takes time while bills still have to be paid. These folks may not want money, but the phone is vulnerable and the next set of folks may. Do you really think the crooks who commit identity theft and ransomware attacks aren't salivating at these…
I think the nation states that will want to use them will clamp down hard on two bit hustlers who interrupt the fun.
Re: A deep dive into iOS Exploit chains found in the wild
#173Earlier quoted context omitted.
> the malicious actor chose to limit their intended recipients I wonder how many people you would need to infect, on average, until you were detected? I would guess, with this exploit chain, and the lack of auditing available of iOS internals, that the actual exploit could run 1 Billion + times before detection. The biggest risk is someone noticing the wedged webkit renderer process and going to try and debug it. I b…
> redirecting traffic, encrypted, via a popular CDN would be a good way to hide it True, but wouldn't that lead western three letter agencies to an account with a credit card attached? Sure, criminals can get stolen cards, but I imagine those have a limited lifespan and chasing after payment problems is not what the hacker wants to be doing.
For a 3 letter agency, legal issues might be the bigger hurdle. E.g. you might have to make sure the data passing though the CDN and thus CDN itself isn't in some other justification when spying on your own cities.
Re: A deep dive into iOS Exploit chains found in the wild
#174> It is worth noting that none of the exploits bypassed the new, PAC-based JIT hardenings that are enabled on A12 devices. I'm surprised Apple doesn't talk more about how they're continuously upgrading the security of iPhones with new chip generations. I remember the BlackHat presentation on iPhone security from a few years ago [0] also found that there were attacks on older iPhones which didn't work on the (then-)ne…
It is also worth noting that PAC is not a panacea. It's just one more thing to break before an attacker takes control. Given that one of the keys used in PAC is shared across all user-space processes including highly privileged unsandboxed processes (it must, as it's used by shared dynamic libraries), it's just a matter of finding one more user-space bug to leak the key and break PAC.
Re: A deep dive into iOS Exploit chains found in the wild
#175>The root causes I highlight here are not novel and are often overlooked: we'll see cases of code which seems to have never worked, code that likely skipped QA or likely had little testing or review before being shipped to users. So similar to Stagefright?
Wow Google. Like I applaud the Project Zero program and its goals but you never write this sort of stuff when discussing your android vulnerabilities. This is just petty.
Re: A deep dive into iOS Exploit chains found in the wild
#176Earlier quoted context omitted.
It is also worth noting that PAC is not a panacea. It's just one more thing to break before an attacker takes control. Given that one of the keys used in PAC is shared across all user-space processes including highly privileged unsandboxed processes (it must, as it's used by shared dynamic libraries), it's just a matter of finding one more user-space bug to leak the key and break PAC.
Even if the same key is shared by all processes, keys are stored in registers that are meant to be not accessible to userspace, so a disclosure vulnerability would not help here anyways.
Re: A deep dive into iOS Exploit chains found in the wild
#177Don’t forget mostly everyone who has a Mac runs the machine with the admin user account.
Gatekeeper is so trash and by default it is set to allow Apple signed apps and third party apps. THIRD PARTY.
Let me ask everyone this:
How many of you open keychain access on your Mac? Open spotlight and type keychain and open it. I guarantee you will see a shit ton of unknown self signed certs from who knows where buried in your system. The self signed root certificates are the problem. If your iPhone and Mac are on the same Wi-Fi network, they are communicating no matter if iCloud is on or not.
Oh and one more thing...
Flashback Trojan is out and spreading in the wild again and no one has any clue. I just found it on a patched up to date Mojave on two MacBook pros.
Download the F-Secure flashback removal tool and see for yourself. You are going to want to throw your piece of shit out the window. Apple has no fcking clue what they’re doing.
I feel so bad for the old people who are getting their info robbed all day long. The ones who still use aol email addresses. Smh
Download Patrick Wardle’s Mac security tools and you’ll cry when you see how bad your fcked. He just released Netiquitte which monitors network traffic going in and out down to the process.
Another tool everyone should download for iOS is Guardian Firewall. Fairly new, but it blocks trackers and attempted browser/page hijacking.
Oh and PS
Everyone go into iOS settings, go to safari-> advanced-> website data
Look how many persistent cookies are there. Try to clear them all see what happens. Lmfao we as a race are all about to shit the bed so bad. Say your prayers
Re: A deep dive into iOS Exploit chains found in the wild
#178Earlier quoted context omitted.
This is an odd list. Some big messaging apps like Signal and Line are notably missing, while tools like Mail Master and Voxer seem like pretty minor players compared to the rest. Is there a particular region of the world or community where this specific list makes most sense?
> Some big messaging apps like Signal and Line are notably missing Line is mostly used in Japan, Signal is mostly used by nerds. So you can assume neither japanese peopel nor nerd were their primary target. Given that this is true for the vast majority of the world population I'd not call this odd.
Re: A deep dive into iOS Exploit chains found in the wild
#179Re: A deep dive into iOS Exploit chains found in the wild
#180Mojave has a weird process that is persistently Installing self-signed certificates in the keychain. This allows teachers to remote into a students laptop. Why the mother fuck is this shit on my computer after I keep deleting it? I delete the cert and the public and private keys. Next day the shit is back with a new set. Brand new cert with key pairs. WHAT??? And the self-signed cert is not verified.
I try to make the cert untrusted thinking that will work. NOPE.
Created a little snitch rule to block all in and outbound traffic for the studentd process. Still didn’t matter the fucking thing gets remotely installed back into the keychain. Can anyone from Apple please explain to me why this bullshit keeps happening???
I remember when backtomymac was being exploited because it was something no one even knew about. They finally got rid of that but now they got a replacement!