97 karma · joined November 30, 2012
Just for the record: I did inform Apple beforehand. Not so much before, but before.
I do not consider this to be their fault in any way as someone in this thread seems to be implying. Again, I had my reasons to drop such a thing publicly. I've had this for months, and I did not intend on disclosing at all. Proof of my "for months" assertion: https://www.youtube.com/watch?v=8arPid8GtFk
> As a bare minimum Apple needs a few hours to analyze the bug
Again, for the record: Apple has full details of the underlying bug. They won't even need to check my github at all.
2) When IOServiceRelease is called, vtable+0x20 is called. the vtable pointer is controlled, at +0x20 I place a stack pivot, which sets RSP = RAX and pops 3 times. At 0x20 I place a POP RAX;RET gadget to let the chain begin after 0x28. Payload then locates the credentials structure, sets UID to 0 by bzero()ing, cleans up the memory corruption, decreases the task count for current user and increases task count for root. It then unlocks locks held by IOAudioEngine to prevent your audio from freezing up, and then returns to the userland context.
The flag essentially prevents kernel from accessing userland memory unless special routines are used. Since the bug is a NULL pointer deference (which requires a read to userland memory in order to be exploited), exploitation becomes impossible. Due to this flag, however, your kernel will have to context switch every time a system call is done, which does have a noticeable performance impact. I will be releasing a KEXT to fix the bug soon.
it will have an hefty performance penalty, but if you value security over performance, it'll also protect you against a lot of (even 0day!) exploits.
10.10.3 was actually the first version it was tested on.
It relies on two distinct bugs, an info-leak to obtain a pointer to an allocation in the kalloc.1024 zone and a memory corruption primitive (deriving from a NULL pointer dfr. in IOKit) allowing me to OR 0x10 anywhere in kernel memory.
To break kASLR I corrupt the size of a vm_map_copy struct, which allows me to read the adjacent allocation to the struct, which is a C++ object. First 8 bytes of said C++ object is a pointer to the vtable, which resides in __TEXT of some kernel extension. Since I can calculate the unslid address from userland without any issue, by subtracting what gets leaked with what gets calculated you get to know the kASLR slide.
Just to clarify: The code execution part has 100% reliability rate. The kASLR leaking part does have some chance in it, however empirical evidence indicates that the failure rate is extremely low.
tpwn has been tested from 10.9 to 10.10.5, but of course, your mileage may vary. the KASLR leak part is not 100% reliable, unlike the actual code execution which is. I'd be interested in panic logs to sort the issue out, if you could share.
The average bandwidth price I got from all the ISPs I used in the past was ~1 dollar/megabit. The ISPs I used for my Tor relays were ISPs I was using already for bandwidth-intensive HTTP hosting, so I already had quite a few deals for dirt cheap bandwidth.
I've been paying ~600€ per box (1Gbit, of which I was using at least 60% 24/7, getting to 100% during day hours).
> you basically claim to have enough spare change lying around at the age of 15 to pay €2000-3000/month just for Tor traffic because you're an idealist
Yep. I got it mostly by selling iOS Tweaks on Cydia Store, private consulting with a few companies, freelancing, and sysadmining.
> and after buying all the stuff a 15 year old normally buys first? ;-)
The only thing apart from my tech equipment and servers that I'm interesting in buying is weed anyway.
> (and btw., WW was not running the ISP, he wrote somewhere in this thread that he is just a normal employee)
Thanks for clarifying that he was not running the ISP. I misread it, probably.
You know, money isn't that hard to get. For me, a few weeks of coding got me a few thousands of euros. He was running an ISP apparently, and selling VPSs. I've been sysadmining a few boxes for a few VPS hosting companies and got enough money to run a few Tor exits pushing over 2Gbps for months.
(Also, I think that it's hilarious that me having my 15-year-old girlfriend pics is considered illegal, thanks to CP laws. )
I truly believe in this: http://datalove.me/