Camp 2011 - Version 1.4

Chaos Communication Camp 2011
Project Flow Control

Ilja van Sprundel
Day Day 2 - 2011-08-11
Room Baikonur
Start time 21:00
Duration 01:00
ID 4490
Event type Lecture
Track Hacking
Language used for presentation English

iOS application security

A look at the security of 3rd party iOS applications

Over the last few years there has been a signifant amount of iPhone and iPad application development going on. Although based on Mac OSX, its development APIs are new and very specific to the iPhone and iPad. In this presentation, Ilja van Sprundel, Principal Security Consultant at IOActive, will discuss lessons learned from auditing iPhone and iPad applications over the last year.

It will cover the use of specific APIs, why some of them aren't granular enough, and why they might expose way too much attack surface. The talk will cover ssl, xml, url handling, UIWebViews and more. Furthermore, it will also cover what apps are allowed to do when inside their sandbox once an application has been hacked.

Archived page - Impressum/Datenschutz