|
@ShadowLee19 | |||||
|
Does iOS low-level software components (SecureROM, LLB and iBoot) support could be possible ?
|
||||||
|
||||||
|
Aleph Research
@alephsecurity
|
17. lip |
|
We hacked our way to executing an interactive bash shell on iOS on QEMU. We based the research on the work done by @zhuowei. Thanks! alephsecurity.com/2019/06/17/xnu…
|
||
|
|
||
|
Aleph Research
@alephsecurity
|
20. lip |
|
We are not focusing on that at the moment and plus it's encrypted and therefore harder to get the binary code.
|
||
|
|
||
|
Odder
@OdderDude
|
21. lip |
|
DM me, then 😛
|
||
|
|
||
|
coconuthead
@ccnuthead
|
21. lip |
|
You need to emulate all hardware that the firmwares will hit while running. @CorelliumHQ does it with a hypevisor. You'll need to RE the firmware to find everything, or iteratively run it. Some qemu patches were required here, but patching the device tree was a big part of it.
|
||
|
|
||