Sign in

matteyeux

@matteyeux.bsky.social
143 followers 13 following 24 posts

iOS fun

PostsRepliesMedia
matteyeux @matteyeux.bsky.social · 26/02/2025
Changed IDA icons to make it feel a bit more modern github.com/OALabs/swicons
041
matteyeux @matteyeux.bsky.social · 21/02/2025
I made an ImHex pattern file for the ftab file format used for Apple C1 firmware and Apple accessories gist.github.com/matteyeux/d1...
041
matteyeux @matteyeux.bsky.social · 01/12/2024
Today is December 1st, and it's your yearly reminder that Stefan Esser, made a "macOS and iOS Security Internals" Advent calendar playlist on Youtube www.youtube.com/playlist?lis...
youtube.com
macOS and iOS Security Internals Advent Calendar 2022 - YouTube
132
matteyeux @matteyeux.bsky.social · 25/11/2024
Next gen Apple Silicon (A19/M5) should have MTE Internally there is a boot-arg to disable it : -disable_mte
0182
matteyeux @matteyeux.bsky.social · 24/11/2024
Is it common to see tests added by SEAR Red Team in XNU source code (rel/xnu-11215)
030
Reposted by matteyeux
meeko 米科奇 @meekolab.com · 21/11/2024
how do you design a privacy-preserving ML inference system? Peeking Inside Apple's Private Cloud Compute, with art by @restlessrice.bsky.social research.meekolab.com/peeking-insi...
research.meekolab.com
Peeking Inside Apple's Private Cloud Compute
An unprecedented look into Apple Intelligence's internal server tools and security features
042
Reposted by matteyeux
jiska @naehrdine.bsky.social · 17/11/2024
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...
naehrdine.blogspot.com
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
12277106
matteyeux @matteyeux.bsky.social · 20/10/2024
ARMv7m core, started when the sep-firmware is loaded. It's firmware can be dumped but you need a special device...
100
matteyeux @matteyeux.bsky.social · 20/10/2024
I have not seen yet any research the Secure Enclave Boot Monitor
000
Reposted by matteyeux
Filippo Valsorda @filippo.abyssdomain.expert · 30/03/2024
I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission. The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system(). It's RCE, not auth bypass, and gated/unreplayable.
7686276
matteyeux @matteyeux.bsky.social · 23/12/2023
One of the Limefix payload decrypted
100
matteyeux @matteyeux.bsky.social · 29/10/2023
Old plugin I made for Binary Ninja to have the function doc of a native Windows function
000
matteyeux @matteyeux.bsky.social · 21/10/2023
Swift in M1 Secure Enclave
000
matteyeux @matteyeux.bsky.social · 18/10/2023
The first Apple Security Research Device
000
matteyeux @matteyeux.bsky.social · 13/10/2023
Linux ARM64 Kernel debugging in Binary Ninja. The target runs in qemu.
100
matteyeux @matteyeux.bsky.social · 29/09/2023
iPhone 15 Pro serial output
000
matteyeux @matteyeux.bsky.social · 24/09/2023
Some info about DFU mode on iPhone 15 Pro : DFU with buttons goes into "Port DFU" (USB-C Controller DFU) If you use macvdmtool you can boot in DFU "Debug USB" then get OG USB string with a kis compatible tool like irecovery x.com/ghidraninja/...
000
matteyeux @matteyeux.bsky.social · 21/09/2023
3 bugs, including a codesign bypass 😵‍💫 support.apple.com/en-us/HT213926
020