Research / Talks

talk

Mach Shellcodes and Injectable OS X Rootkits

RECon · Montreal, Canada

Venue
RECon, Montreal, Canada
Speakers
Jesse D'Aguanno
Material
slides

Using the Mach interfaces in the OS X kernel to manipulate the kernel from user space, i.e. from shellcode, to alter kernel structures. Example shellcodes are included.

themes: #platform & os
people: Jesse D'Aguanno

Related

post

Finding Vulnerability Variants at Scale

While performing a security audit, I discovered a file format vulnerability that took me down an unexpected rabbit hole. The bug was fairly straightforward but what made it interesting was its origin …

Franco Belman

post

Playing with Libmalloc in 2024

TL;DR In this post, I introduce a new tool called heapster that allows you to play with macOS libmalloc. I walk you through how to use this tool and a couple strange things I found along the way.

Josh Pitts

tool

heapster

Python

A tool for exploring the macOS libmalloc heap from LLDB: zones, magazines, free lists and the state of individual allocations, introduced in our libmalloc post.

sourcewrite-up Blackwing

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno