matteyeux @matteyeux.bsky.social · 26/02/2025Changed IDA icons to make it feel a bit more modern github.com/OALabs/swicons 041
matteyeux @matteyeux.bsky.social · 21/02/2025I made an ImHex pattern file for the ftab file format used for Apple C1 firmware and Apple accessories gist.github.com/matteyeux/d1... 041
matteyeux @matteyeux.bsky.social · 01/12/2024Today is December 1st, and it's your yearly reminder that Stefan Esser, made a "macOS and iOS Security Internals" Advent calendar playlist on Youtube www.youtube.com/playlist?lis...youtube.commacOS and iOS Security Internals Advent Calendar 2022 - YouTube 132
matteyeux @matteyeux.bsky.social · 25/11/2024Next gen Apple Silicon (A19/M5) should have MTE Internally there is a boot-arg to disable it : -disable_mte 0182
matteyeux @matteyeux.bsky.social · 24/11/2024Is it common to see tests added by SEAR Red Team in XNU source code (rel/xnu-11215) 030
Reposted by matteyeuxmeeko 米科奇 @meekolab.com · 21/11/2024how do you design a privacy-preserving ML inference system? Peeking Inside Apple's Private Cloud Compute, with art by @restlessrice.bsky.social research.meekolab.com/peeking-insi...research.meekolab.comPeeking Inside Apple's Private Cloud ComputeAn unprecedented look into Apple Intelligence's internal server tools and security features 042
Reposted by matteyeuxjiska @naehrdine.bsky.social · 17/11/2024How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...naehrdine.blogspot.comReverse Engineering iOS 18 Inactivity RebootWireless and firmware hacking, PhD life, Technology 12277106
matteyeux @matteyeux.bsky.social · 20/10/2024ARMv7m core, started when the sep-firmware is loaded. It's firmware can be dumped but you need a special device... 100
matteyeux @matteyeux.bsky.social · 20/10/2024I have not seen yet any research the Secure Enclave Boot Monitor 000
Reposted by matteyeuxFilippo Valsorda @filippo.abyssdomain.expert · 30/03/2024I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission. The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable. 7686276
matteyeux @matteyeux.bsky.social · 29/10/2023Old plugin I made for Binary Ninja to have the function doc of a native Windows function 000
matteyeux @matteyeux.bsky.social · 13/10/2023Linux ARM64 Kernel debugging in Binary Ninja. The target runs in qemu. 100
matteyeux @matteyeux.bsky.social · 24/09/2023Some info about DFU mode on iPhone 15 Pro : DFU with buttons goes into "Port DFU" (USB-C Controller DFU) If you use macvdmtool you can boot in DFU "Debug USB" then get OG USB string with a kis compatible tool like irecovery x.com/ghidraninja/... 000
matteyeux @matteyeux.bsky.social · 21/09/20233 bugs, including a codesign bypass 😵💫 support.apple.com/en-us/HT213926 020