12.07.2015 Views

Apple iOS 4 Security Evaluation

Apple iOS 4 Security Evaluation

Apple iOS 4 Security Evaluation

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Bottom LineMandatory Code Signing in <strong>iOS</strong> is strong defense againstexecution of unauthorized binariesRequires incomplete code signing exploits to bypass andobtain return-oriented executionCode signing forces attackers to develop fully ROP payloadsDEP/NX only require a ROP stage to allocate newexecutable memory and copy shellcode into itJIT support in Safari reduces ROP requirements to a stage

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!