23.12.2014 Views

Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...

Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...

Defiling Mac OS X - Ruxcon - Reverse Engineering Mac OS X - PUT ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

TECHNIQUES<br />

DODGY KERNEL SYMBOL RESOLUTION<br />

symtab<br />

strtab<br />

struct nlist_64<br />

strtab + 0x4562F<br />

strtab + 0x45647<br />

strtab + 0x4565D<br />

__LINKEDIT:<br />

<br />

<br />

"kauth_cred_setvuidgid\0"<br />

"kauth_cred_setuidgid\0"<br />

"kauth_cred_uid2gid\0"<br />

<br />

__TEXT:<br />

0xFFFFFF800052CB70<br />

Other functions' code<br />

This function's code<br />

<strong>Defiling</strong> <strong>Mac</strong> <strong>OS</strong> X - <strong>Ruxcon</strong><br />

November, 2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!