Главная
Study mode:
on
1
Intro
2
whoami - Wojciech
3
whoami - Csaba
4
Intro to XPC
5
statistics
6
typical issues
7
No client validation in XPC server
8
Lack of /Broken runtime protections in XPC dient
9
Improper runtime protections verification in XPC server
10
MacKeeper
11
Intego Mac Security
12
Avast & AVG
13
ClamXAV (CVE-2020-26893)
14
Acronis
15
the client
16
the XPC service
17
secure sample
18
Shield.app
19
the future
20
Further resources
Description:
Explore a comprehensive conference talk from Nullcon 2021 on exploiting XPC vulnerabilities in macOS antivirus software. Delve into the research conducted on 29 different antivirus products, focusing on exposed XPC services and their security implications. Learn about typical issues, witness demonstrations of vulnerabilities leading to full product control or local privilege escalation, and gain valuable insights on developing secure XPC services. Presented by security experts Csaba Fitzl and Wojciech Reguła, this 46-minute session covers topics such as client validation, runtime protections, and specific case studies involving popular antivirus solutions.

Exploiting XPC in AntiVirus Software

nullcon
Add to list
0:00 / 0:00