ipwn your iphone – wifi edition

14
iPwn your iPhone – WiFi edition Fun with with CVE-2011-0228 @hubert3 [email protected]

Upload: keefer

Post on 06-Feb-2016

57 views

Category:

Documents


0 download

DESCRIPTION

iPwn your iPhone – WiFi edition. Fun with with CVE-2011-0228 @hubert3 [email protected]. Agenda. Brief intro to SSL certs The CVE-2011-0228 vulnerability iSniff Demo. SSL certificate chains. SSL certificate chains. SSL certificate chains. SSL certificate chains. Patch…. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: iPwn  your  iPhone –  WiFi  edition

iPwn your iPhone – WiFi edition

Fun with with CVE-2011-0228

@[email protected]

Page 2: iPwn  your  iPhone –  WiFi  edition

Agenda

• Brief intro to SSL certs

• The CVE-2011-0228 vulnerability

• iSniff Demo

Page 3: iPwn  your  iPhone –  WiFi  edition

SSL certificate chains

Page 4: iPwn  your  iPhone –  WiFi  edition

SSL certificate chains

Page 5: iPwn  your  iPhone –  WiFi  edition

SSL certificate chains

Page 6: iPwn  your  iPhone –  WiFi  edition

SSL certificate chains

Page 7: iPwn  your  iPhone –  WiFi  edition

Patch…

Page 8: iPwn  your  iPhone –  WiFi  edition

Man-in-the-middle setup

• Linux VM (Debian 6)• Netgear WG111v2 USB WiFi stick• R8187 driver from aircrack-ng

• airbase-ng• dhcpd• iSniff.py

Page 9: iPwn  your  iPhone –  WiFi  edition

sslsniff 0.8 AuthorityCertificateManager.cpp

Page 10: iPwn  your  iPhone –  WiFi  edition

iSniff.py

Page 11: iPwn  your  iPhone –  WiFi  edition

iSniff Demo

Page 12: iPwn  your  iPhone –  WiFi  edition

After patch…

Page 13: iPwn  your  iPhone –  WiFi  edition