Research / theme

#platform & os

post

Finding Vulnerability Variants at Scale

While performing a security audit, I discovered a file format vulnerability that took me down an unexpected rabbit hole. The bug was fairly straightforward but what made it interesting was its origin …

Franco Belman

post

Playing with Libmalloc in 2024

TL;DR In this post, I introduce a new tool called heapster that allows you to play with macOS libmalloc. I walk you through how to use this tool and a couple strange things I found along the way.

Josh Pitts

tool

heapster

Python

A tool for exploring the macOS libmalloc heap from LLDB: zones, magazines, free lists and the state of individual allocations, introduced in our libmalloc post.

sourcewrite-up Blackwing

tool

iBoot64Binja

Python

A Binary Ninja binary view for iBoot, SecureROM and similar Apple boot firmware. Point it at a raw image and it identifies the firmware, finds the load address and rebases the binary so analysis is …

source Jesse D'Aguanno

post

Dissecting CVE-2013-1899

So, last week the Postgresql group released an update to its popular open-source RDBMS to address a security issue – pretty standard… This particular update though was pretty highly anticipated, …

Jesse D'Aguanno

talk

IRK: Crafting OS X Kernel Rootkits

Black Hat USA 2008 · Las Vegas, NV

Apple’s OS X operating system has been gaining in popularity. This presentation details how to manipulate the OS X kernel in order to hide an attacker’s activities and maintain access.

slides Jesse D'Aguanno

talk

Mach Shellcodes and Injectable OS X Rootkits

RECon · Montreal, Canada

Using the Mach interfaces in the OS X kernel to manipulate the kernel from user space, i.e. from shellcode, to alter kernel structures. Example shellcodes are included.

slides Jesse D'Aguanno

talk

Blackjacking: Owning the Enterprise via the BlackBerry

DEF CON 14 · Las Vegas, NV

Jesse D’Aguanno demonstrated using the trust relationship between the BlackBerry Enterprise Server infrastructure and the handhelds to bypass perimeter controls and compromise an internal …

slides Jesse D'Aguanno