Learn, hack!

Hacking and security documentation: slides, papers, video and audio recordings. All in high-quality, daily updated, avoiding security crap documents. Spreading hacking knowledge, for free, enjoy. Follow on .

iOS application security

Type
Video
Tags
iPhone, secure development
Authors
Ilja van Sprundel
Event
Chaos Communication Camp 2011
Indexed on
Mar 27, 2013
URL
http://ftp.ccc.de/events/camp2011/video/cccamp11-4490-ios_application_security-en.mp4
File name
cccamp11-4490-ios_application_security-en.mp4
File size
420.2 MB
MD5
dfa023d9a7b29cf07c521e5d70bd5e1e
SHA1
0b1e9f7c9d3e3ad1c561cde2392f07fef17a32c1

Over the last few years there has been a signifant amount of iPhone and iPad application development going on. Although based on Mac OSX, its development APIs are new and very specific to the iPhone and iPad. In this presentation, Ilja van Sprundel, Principal Security Consultant at IOActive, will discuss lessons learned from auditing iPhone and iPad applications over the last year. It will cover the use of specific APIs, why some of them aren't granular enough, and why they might expose way too much attack surface. The talk will cover ssl, xml, url handling, UIWebViews and more. Furthermore, it will also cover what apps are allowed to do when inside their sandbox once an application has been hacked.

About us

Secdocs is a project aimed to index high-quality IT security and hacking documents. These are fetched from multiple data sources: events, conferences and generally from interwebs.

Statistics

Serving 8166 documents and 531.0 GB of hacking knowledge, indexed from 2419 authors from 163 security conferences.

Contribute

To support this site and keep it alive, you can click on the buttons below. Any help is really appreciated! This service is provided for free, but real money is needed to pay bills.

Flattr this Click here to lend your support to: Keep live SecDocs for an year and make a donation at www.pledgie.com !