Research / Talks

talk

Blackjacking: Owning the Enterprise via the BlackBerry

DEF CON 14 · Las Vegas, NV

Venue
DEF CON 14, Las Vegas, NV
Speakers
Jesse D'Aguanno
Material
slides

Jesse D’Aguanno demonstrated using the trust relationship between the BlackBerry Enterprise Server infrastructure and the handhelds to bypass perimeter controls and compromise an internal corporate network.

themes: #platform & os
people: Jesse D'Aguanno

Related

post

Finding Vulnerability Variants at Scale

While performing a security audit, I discovered a file format vulnerability that took me down an unexpected rabbit hole. The bug was fairly straightforward but what made it interesting was its origin …

Franco Belman

post

Playing with Libmalloc in 2024

TL;DR In this post, I introduce a new tool called heapster that allows you to play with macOS libmalloc. I walk you through how to use this tool and a couple strange things I found along the way.

Josh Pitts

tool

heapster

Python

A tool for exploring the macOS libmalloc heap from LLDB: zones, magazines, free lists and the state of individual allocations, introduced in our libmalloc post.

sourcewrite-up Blackwing

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno