Login Register






Thread Rating:
  • 1 Vote(s) - 5 Average


What do you want to learn about? filter_list
Author
Message
RE: What do you want to learn about? #11
(10-15-2016, 09:12 PM)pvnk Wrote: I want to learn about exploiting bootrom vulnerabilities on older iDevices.

This. This has been my greatest wonder since I first touched an iPhone. I've looked into it, although it would be awesome to see something from you on this. So I second this idea.
You can find me on Keybase
"Reach the state of ubiquity, and you will be in control"
Student, Technician, Designer, and more.
[Image: YUpAMpx.png]

Reply

RE: What do you want to learn about? #12
(11-08-2016, 04:19 AM)zorrophreak Wrote:
(10-15-2016, 09:12 PM)pvnk Wrote: I want to learn about exploiting bootrom vulnerabilities on older iDevices.

This. This has been my greatest wonder since I first touched an iPhone. I've looked into it, although it would be awesome to see something from you on this. So I second this idea.

Apologies for what looks like a gravedig, but I never did get an answer to my question:


(10-15-2016, 09:48 PM)phyrrus9 Wrote: Now that's an interesting one. Do you have any specific family or exploit in mind or were you hoping to find your own?


I would be happy to go over exploits like the 0x24000 segment overflow or pwnage, but it will take a large attention span from you guys to go over SHA-1 segment overflow and limera1n. On another note, if you guys have older gen devices then I can run you through a "simulation" crash course where we discover, triage, probe, and exploit one of the existing bootrom exploits.

Reply

RE: What do you want to learn about? #13
(11-08-2016, 05:14 PM)phyrrus9 Wrote:
Spoiler:
(11-08-2016, 04:19 AM)zorrophreak Wrote:
(10-15-2016, 09:12 PM)pvnk Wrote: I want to learn about exploiting bootrom vulnerabilities on older iDevices.

This. This has been my greatest wonder since I first touched an iPhone. I've looked into it, although it would be awesome to see something from you on this. So I second this idea.

Apologies for what looks like a gravedig, but I never did get an answer to my question:


(10-15-2016, 09:48 PM)phyrrus9 Wrote: Now that's an interesting one. Do you have any specific family or exploit in mind or were you hoping to find your own?
I would be happy to go over exploits like the 0x24000 segment overflow or pwnage, but it will take a large attention span from you guys to go over SHA-1 segment overflow and limera1n. On another note, if you guys have older gen devices then I can run you through a "simulation" crash course where we discover, triage, probe, and exploit one of the existing bootrom exploits.

Not the one who suggested this initially, hence why I didn't answer the question, just expressed continued interest. Your simulation crash course seems interesting/appealing as I have an old iPad 1st Generation and an iPod2G (MC model.) Although the ideas mentioned before seem appealing too. If you think SHA-1 Segment Overflow or limera1n (what was the last device succeptible to SHA-1 SO btw...?) is too much work/too confusing/etc..., then learning and diving into 0x24000 or pwnage would be cool.

Also, might I ask, pwnage 1 or 2?
You can find me on Keybase
"Reach the state of ubiquity, and you will be in control"
Student, Technician, Designer, and more.
[Image: YUpAMpx.png]

Reply

RE: What do you want to learn about? #14
Browser exploitation through Flash (and other adobe extensions) would be nice.
(This post was last modified: 11-11-2016, 02:18 AM by meow. Edit Reason: added some text )

[+] 1 user Likes meow's post
Reply

RE: What do you want to learn about? #15
How about ssh exploitation --> Maybe learn how to build a bot to sniff ports for servers.
[Image: giphy.gif]



[+] 1 user Likes d0ntjump's post
Reply

RE: What do you want to learn about? #16
(11-11-2016, 02:08 AM)zorrophreak Wrote:
(11-08-2016, 05:14 PM)phyrrus9 Wrote:
Spoiler:
(11-08-2016, 04:19 AM)zorrophreak Wrote: This. This has been my greatest wonder since I first touched an iPhone. I've looked into it, although it would be awesome to see something from you on this. So I second this idea.

Apologies for what looks like a gravedig, but I never did get an answer to my question:


(10-15-2016, 09:48 PM)phyrrus9 Wrote: Now that's an interesting one. Do you have any specific family or exploit in mind or were you hoping to find your own?
I would be happy to go over exploits like the 0x24000 segment overflow or pwnage, but it will take a large attention span from you guys to go over SHA-1 segment overflow and limera1n. On another note, if you guys have older gen devices then I can run you through a "simulation" crash course where we discover, triage, probe, and exploit one of the existing bootrom exploits.

Not the one who suggested this initially, hence why I didn't answer the question, just expressed continued interest. Your simulation crash course seems interesting/appealing as I have an old iPad 1st Generation and an iPod2G (MC model.) Although the ideas mentioned before seem appealing too. If you think SHA-1 Segment Overflow or limera1n (what was the last device succeptible to SHA-1 SO btw...?) is too much work/too confusing/etc..., then learning and diving into 0x24000 or pwnage would be cool.

Also, might I ask, pwnage 1 or 2?

SHA-1 and limera1n are different exploits. All of limera1n was fixed at the launch of the 4S, however only most of SHA was fixed then as well, the remainder fixed with the 6.


(11-11-2016, 03:54 AM)d0ntjump Wrote: How about ssh exploitation --> Maybe learn how to build a bot to sniff ports for servers.

Writing a bot to detect ports is fairly easy, and I would be happy to do that. Actually exploiting bugs in the SSH backend isn't anything I've had experience with but I would be willing to go over the general theory and process behind doing such a thing.

Reply

RE: What do you want to learn about? #17
(11-13-2016, 04:58 AM)phyrrus9 Wrote:
(11-11-2016, 02:08 AM)zorrophreak Wrote:
(11-08-2016, 05:14 PM)phyrrus9 Wrote:
Spoiler:
Apologies for what looks like a gravedig, but I never did get an answer to my question:


I would be happy to go over exploits like the 0x24000 segment overflow or pwnage, but it will take a large attention span from you guys to go over SHA-1 segment overflow and limera1n. On another note, if you guys have older gen devices then I can run you through a "simulation" crash course where we discover, triage, probe, and exploit one of the existing bootrom exploits.

Not the one who suggested this initially, hence why I didn't answer the question, just expressed continued interest. Your simulation crash course seems interesting/appealing as I have an old iPad 1st Generation and an iPod2G (MC model.) Although the ideas mentioned before seem appealing too. If you think SHA-1 Segment Overflow or limera1n (what was the last device succeptible to SHA-1 SO btw...?) is too much work/too confusing/etc..., then learning and diving into 0x24000 or pwnage would be cool.

Also, might I ask, pwnage 1 or 2?

SHA-1 and limera1n are different exploits. All of limera1n was fixed at the launch of the 4S, however only most of SHA was fixed then as well, the remainder fixed with the 6.


(11-11-2016, 03:54 AM)d0ntjump Wrote: How about ssh exploitation --> Maybe learn how to build a bot to sniff ports for servers.

Writing a bot to detect ports is fairly easy, and I would be happy to do that. Actually exploiting bugs in the SSH backend isn't anything I've had experience with but I would be willing to go over the general theory and process behind doing such a thing.

Awesome! I'm all ears... Looking forward to a tutorial.
[Image: giphy.gif]



Reply

RE: What do you want to learn about? #18
(10-15-2016, 06:10 PM)Slacker Wrote: Both. I want to be able to gain access get the db root it (I think its called lol) and deface

Then learn a server-side scripting language (PHP), and also SQL to query databases , thereby perform all sorts of actions- example modify, update, delete data from the database.

Both languages are quite easy to learn.
[Image: AD83g1A.png]

Reply

RE: What do you want to learn about? #19
Excellent I'll look I to it. Didn't disapear like y'all thought I did huh lol

Reply

RE: What do you want to learn about? #20
(11-07-2016, 08:29 PM)millionandbell Wrote: I would like to learn about server administration, implementing a server and maintaining one, this thread is too good of a thread to let die so if this is considered gravedigging I apologize

I could probably teach you on that one, I mean that's a part of my classes. We usually spend our time in VMWare setting up Server 2012 and client computers.
Certified Degenerate

[+] 1 user Likes Korvus's post
Reply







Users browsing this thread: 1 Guest(s)