Last week I presented my research about “Adding ASLR to jailbroken iPhones” at the Power of Community 2010 (POC2010) security conference in Seoul. During my talk I explained how one can use a modified ‘rebase’ utility to rebase the dynamic linker dyld on the iPhone. Rebasing dyld is important because it contains enough code gadgets that can be used to kickstart arbitrary shellcode on jailbroken iPhones. A tool called Antid0te will be released until the end of this year that allows normal users to add ASLR to their iPhones. The release of this tool was originally planned for 24th December 2010 but it had to be postponed because I got really ill and also my glasses broke.
Anyway a few days ago I demonstrated how my “rebase dyld” research that was originally done for the iPhone applies directly to the dynamic linker used by Mac OS X Snow Leopard. I released a short article describing how one can rebase his dyld binary with a patched ‘rebase’ utility which I also released. This can be used to rebase your own dyld binary to a different position. Rebasing dyld to an address other than the normal one, improves the security of your Mac because all the public articles/techniques about state of the art Mac OS X exploitation assume/require the dyld binary to be loaded at a fixed address. All attacks based on this will fail once you have rebased your dynamic linker binary.
So enjoy this little christmas present until I am fit enough to release antid0te.

February 3rd, 2012
phpmoz
Posted in
Tags: 

domenica jet set roma…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
kids art activities…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
boston computer support…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
cheap dining room sets…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
lawn grass…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
jazz radio…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
landscape supplies…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
traditional wedding cake toppers…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
camping tent…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Maschinenfick…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
baby einstein…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
garden fencing…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Buy Gold…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
How To Buy Gold…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
search engine marketing service…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
tropical landscape…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
yipit clone…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
[...] CYPRESS SEMICONDUCTOR ACCENTURE ACER ADOBE SYSTEMS ADVANCED SEMICONDUCTOR ENGINEERING ALLIANCE DATA SYSTEMS Posted by admin at [...]
[...] INSTRUMENTS TERADATA TELETECH HOLDINGS TECHNITROL TAKETWO INTERACTIVE SOFTWARE SYNTEL SYNTAXBRILLIAN This entry was posted in [...]
seo danışmanı…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
download movies to pc…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Kindle DX South Africa…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
jewish dating…
As a Newbie, I am permanently exploring online for articles that can benefit me. Thank you…
sopa and pipa…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Snappoin3…
Great blog post, saw on…
check24…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
rocket stove plans…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
lds dating sites…
Hey very nice web site!! Man .. Excellent .. Amazing .. I will bookmark your web site and take the feeds also๏ฟฝI am happy to find numerous useful information here in the post, we need work out more techniques in this regard, thanks for sharing. . . . …
HDI…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Fossil Uhren…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
e cigarette reviews…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
affordable SEO service…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
create a blog…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
apply for payday loan…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
shrimp farming…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Ryan Karben,law office new york,lawyer NY,lawyer New York,law office new york city,law office new york jobs,law office new york ny,law office new york state,law office new york website,law office new york llc,law office new york manhattan,llc law off…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Javascript swiping…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
free movies online…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Cheap Adsense Site Creation…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
SBI Personal Loans…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Recover HYIP Investment…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
fun videos…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Professional Cake Decorating…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Kindle Wi-Fi…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
stupid videos…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Happy…
Am glad that I found this – thanks….
Splendid…
I totally applauded this story!…
Gems form the internet…
[...]very few websites that happen to be detailed below, from our point of view are undoubtedly well worth checking out[...]……
Home Insurance Rates…
[...]Improving the ASLR of Mac OS X Snow Leopard | PHP Blog[...]…
Bing results…
While searching quite a lot Bing and AOL I very much happily found this interesting page in the search results and I did think it would match…