iPad, iPhone, iPod touch, Jailbreak News

How Absinthe 2.0 Actually Jailbreaks Your iOS Device

During the Jailbreak Live event at the Hack in the Box conference in Amsterdam, Absinthe 2.0 was released. pod2g and the “dream team” also took the time to explain exactly how to jailbreak works its magic…

Jailbreaking a device may seem like one click of a button to the end-user but there’s a lot of complicated work that goes into injecting the code that liberates your iOS device.

Here’s the breakdown:

GreenPois0n Absinthe was built upon @pod2g’s Corona untether jailbreak to create the first public jailbreak for the iPhone 4S and iPad 2 on for the 5.0.1 firmware. In this paper, we present a chain of multiple exploits to accomplish sandbox breakout, kernel unsigned code injection and execution that result in a fully-featured and untethered jailbreak.

Corona is an acronym for “racoon”, which is the primary victim for this attack. A format string vulnerability was located in racoon’s error handling routines, allowing the researchers to write arbitrary data to racoon’s stack, one byte at a time, if they can control racoon’s configuration file. Using this technique researchers were able to build a ROP payload on racoon’s stack to mount a rogue HFS volume that injects code at the kernel level and patch its code-signing routines.

The original Corona untether exploit made use of the LimeRa1n bootrom exploit as an injection vector, to allow developers to disable ASLR and sandboxing, and call racoon with a custom configuration script. This however left it unusable for newer A5 devices like the iPad2 and iPhone 4S, which weren’t exploitable to LimeRa1n, so another injection vector was needed.

So as you can see it’s no simple process. These fellas work day and night to make these things possible and bring the latest jailbroken version of iOS to our devices. If you’re interested in learning more visit the Hack in the Box official website to check out all of the presentation notes.

Source: Hack in the Box via Cult of Mac

Share this Story

Related Posts

3 Comments

  1. pendaftaran polwan

    January 25, 2018 at 8:12 pm

    947595 878038This is going to be a terrific weblog, would you be interested in doing an interview about just how you developed it? If so e-mail me! 792108

    Reply

  2. Klinik gigi surabaya

    February 1, 2018 at 5:32 pm

    975731 202932Perfect just what I was looking for! . 528603

    Reply

  3. Outsourcing PK/PD studies

    February 5, 2018 at 5:32 am

    535361 966451How a lot of an appealing guide, maintain on creating much better half 388450

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

Join Our Mailing List

Email Format

Free iTunes Gift Cards!

Find us on Google Plus