TL;DR: reverse engineer a jailbreak exploit. > By 7 PM, I had identified the vulnerability and informed Apple I don't know why this rubbed me the wrong way. Like, it feels "lazy" (for lack of a better way) to disassemble an exploit and run off to tell the vendor. If anything, the exploit writer should get the credit. I don't know.
All this has taught me is that if I find an exploit to unlock I need to obfuscate the heck out of it to make it as onerous as possible for low-effort bug bounty do-gooders to scoop up a reward from it.
How to unc0ver a 0-day in 4 hours or less
11–20 of 120 posts
Re: How to unc0ver a 0-day in 4 hours or less
#12> By 1 AM, I had sent Apple a POC and my analysis. > Still, I'm very happy that Apple patched this issue in a timely manner once the exploit became public. Sh- should we be happy Apple fixed this so quickly? unc0ver allows consumers to get more out of their Apple devices, and Apple's fix isn't really optional (unless you disable auto-updates and tap "Later" on every update notification). Is this exploit even an issue…
Are you sure about this?
I'm far removed from the app store development world, but a cursory glance at the description and the original lightspeed bug seem to indicate this is a problem within the kernel interface, and as such I assume callable by any application??
Sorry, I could be missing something, just curious why this couldn't occur in the app store.
Re: How to unc0ver a 0-day in 4 hours or less
#13> By 1 AM, I had sent Apple a POC and my analysis. > Still, I'm very happy that Apple patched this issue in a timely manner once the exploit became public. Sh- should we be happy Apple fixed this so quickly? unc0ver allows consumers to get more out of their Apple devices, and Apple's fix isn't really optional (unless you disable auto-updates and tap "Later" on every update notification). Is this exploit even an issue…
> Apple's probably not going to let an app exploiting this zeroday into its App Store... Are you sure about this? I'm far removed from the app store development world, but a cursory glance at the description and the original lightspeed bug seem to indicate this is a problem within the kernel interface, and as such I assume callable by any application?? Sorry, I could be missing something, just curious why this couldn…
Re: How to unc0ver a 0-day in 4 hours or less
#14Re: How to unc0ver a 0-day in 4 hours or less
#15TL;DR: reverse engineer a jailbreak exploit. > By 7 PM, I had identified the vulnerability and informed Apple I don't know why this rubbed me the wrong way. Like, it feels "lazy" (for lack of a better way) to disassemble an exploit and run off to tell the vendor. If anything, the exploit writer should get the credit. I don't know.
All this has taught me is that if I find an exploit to unlock I need to obfuscate the heck out of it to make it as onerous as possible for low-effort bug bounty do-gooders to scoop up a reward from it.
Re: How to unc0ver a 0-day in 4 hours or less
#16TL;DR: reverse engineer a jailbreak exploit. > By 7 PM, I had identified the vulnerability and informed Apple I don't know why this rubbed me the wrong way. Like, it feels "lazy" (for lack of a better way) to disassemble an exploit and run off to tell the vendor. If anything, the exploit writer should get the credit. I don't know.
Re: How to unc0ver a 0-day in 4 hours or less
#17> By 1 AM, I had sent Apple a POC and my analysis. > Still, I'm very happy that Apple patched this issue in a timely manner once the exploit became public. Sh- should we be happy Apple fixed this so quickly? unc0ver allows consumers to get more out of their Apple devices, and Apple's fix isn't really optional (unless you disable auto-updates and tap "Later" on every update notification). Is this exploit even an issue…
Jail breaking cuts into their profit a small amount because the community is small.
https://www.reddit.com/r/jailbreak
The benefits are very much worth it though. Most have had iOS 13 features since iOS 11/12. They have iOS 14 features now. Then there are other features that may not be released ever but people find them invaluable.
Ex: Per app specific Firewall per website. (Block tracking/ads)
-Disable apps ability to spy on your clipboard.
-Disable apps from accessing things you do not want them to but still launch.
-Themes, so many options: remove your status bar or put new things there.
-Custom widgets
-Detailed wifi, phone information
-Download old versions of apps because the company broke something.
-Detailed phone/memory/cpu info
-Terminal access.
Those are just a few off the top of my head.
Re: How to unc0ver a 0-day in 4 hours or less
#18Re: How to unc0ver a 0-day in 4 hours or less
#19Earlier quoted context omitted.
All this has taught me is that if I find an exploit to unlock I need to obfuscate the heck out of it to make it as onerous as possible for low-effort bug bounty do-gooders to scoop up a reward from it.
Project Zero researchers don’t take bounties, to my knowledge.
Re: How to unc0ver a 0-day in 4 hours or less
#20Why is he doing that work? Does Apple not fix every jailbreak exploits by themselves?