Research / Talks

talk

XNU Spelunking or Fuzzing the kernel inside your kernel

RECon · Montreal, Canada

Venue
RECon, Montreal, Canada
Speakers
Jesse D'Aguanno
Material
video

XNU, the OS X kernel, is made up of a somewhat unholy marriage of the monolithic BSD kernel and the CMU mach microkernel. Because of this marriage, in addition to BSD syscalls, XNU provides additional system calls and a large IPC interface for userland processes to interact with the underlying mach subsystem. The presence of these IPC interfaces significantly increases the available attack surface between the kernel and userland processes over just the traditional BSD system calls. This talk explores these interfaces and details the processes devised and lessons learned from building fuzzers for bug hunting in mach territory.

themes: #platform & os
people: Jesse D'Aguanno

Related

post

Finding Vulnerability Variants at Scale

While performing a security audit, I discovered a file format vulnerability that took me down an unexpected rabbit hole. The bug was fairly straightforward but what made it interesting was its origin …

Franco Belman

post

Playing with Libmalloc in 2024

TL;DR In this post, I introduce a new tool called heapster that allows you to play with macOS libmalloc. I walk you through how to use this tool and a couple strange things I found along the way.

Josh Pitts

tool

heapster

Python

A tool for exploring the macOS libmalloc heap from LLDB: zones, magazines, free lists and the state of individual allocations, introduced in our libmalloc post.

sourcewrite-up Blackwing

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno