Главная
Study mode:
on
1
Introduction
2
macOS security
3
Apple-proprietary
4
SIP rootless
5
Rootless entitlements
6
SIP bypasses 101
7
Hunting for SIP bypasses
8
Easy exploit!
9
What is TCC?
10
The TCC database
11
Apple takes TCC very seriously
12
TCC bypass by mounting backups
13
TCC bypass by tccd exploit
14
TCC bypass by XCSSET malware
15
Bonus round - SQL injection???
Description:
Explore macOS security features and their vulnerabilities in this 48-minute webinar presented by Jonathan Bar Or, Principal Security Researcher at Microsoft. Delve into the fascinating world of macOS security, combining traditional POSIX security, BSD-based components, and Apple-proprietary elements. Learn about System Integrity Protection (SIP) rootless, rootless entitlements, and various SIP bypass techniques. Discover the intricacies of Transparency, Consent, and Control (TCC), including its database structure and Apple's stringent approach. Examine real-world TCC bypass methods, such as mounting backups, exploiting tccd, and the XCSSET malware technique. Conclude with a bonus discussion on potential SQL injection vulnerabilities in macOS security systems.

macOS Security Features Bypasses by Example

nullcon
Add to list
0:00 / 0:00