www.securing.pl
Wojciech Reguła
Building&Hacking modern iOS apps
@_r3ggi wojciech.regula@securing.pl
Building&Hacking modern iOS apps Wojciech Regua @_r3ggi - - PowerPoint PPT Presentation
www.securing.pl Building&Hacking modern iOS apps Wojciech Regua @_r3ggi wojciech.regula@securing.pl @_r3ggi wojciech.regula@securing.pl www.securing.pl www.securing.pl WHOAMI -Senior IT Security Consultant @ SecuRing -Focused on
www.securing.pl
Wojciech Reguła
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
2.1 Discuss problem 2.2 Show solution 2.3 Present new Apple WWDC feature }
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
https://twitter.com/orhaneee/status/1076147994574184449
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
https://github.com/pwn20wndstuff/Undecimus
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
usage of UnsafePointer)
string interpolation
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
MYTH – SWIFT AUTOOBFUSCATES ITSELF
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
MYTH – SWIFT AUTOOBFUSCATES ITSELF
www.securing.pl www.securing.pl
MYTH – SWIFT AUTOOBFUSCATES ITSELF
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
https://github.com/rockbruno/swiftshield
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
to the one time password
possibility to do social engineering
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
device that should not be there:
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
stored client-side)
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
ThisDeviceOnly
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
https://wojciechregula.blog/post/stealing-bear-notes-with-url-schemes/
www.securing.pl www.securing.pl
connected with your domain
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
instead of 3rd party AES/RSA
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
cert is trusted
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
permissions
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
fixed versions please
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
AFNetworking 2.5.1 allowed to perform Man in the Middle attack when app did not use SSL pinning
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
handler BY DEFAULT
btw
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
YAHOO IOS XSS EXAMPLE BY @OMESPINO
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
For those who:
tampered with
OWASP MASVS
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
indicators
emulator
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
h"ps://github.com/securing/IOSSecuritySuite
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
Security Aware Developers Pentesters
SECURITY ISSUES
@_r3ggi wojciech.regula@securing.pl
www.securing.pl www.securing.pl
https://www.securing.biz/en/mobile-application-security-best-practices/index.html @_r3ggi wojciech.regula@securing.pl
www.securing.pl
SecuRing Kalwaryjska 65/6 30-504 Kraków, Poland info@securing.pl
http://www.securing.biz/en
Contact Wojciech Reguła
wojciech.regula@securing.pl @_r3ggi wojciech-regula