À念Áø ¾¾, iOS °ü·Ã ÁÖÁ¦·Î ºí·¢ÇÞ¿¡¼ 2³â ¿¬¼Ó °¿¬
[º¸¾È´º½º ±èÁö¾ð] ÃֽŠ±Û·Î¹ú º¸¾ÈÆ®·»µå¿Í ÇÖÀ̽´¸¦ Á¶¸ÁÇÒ ¼ö ÀÖ´Â ¡®ºí·¢ÇÞ 2014¡¯°¡ 8¿ù 2ÀϺÎÅÍ 7ÀÏ(ÇöÁö½Ã°¢)±îÁö ¹Ì±¹ ¶ó½ºº£°¡½º MANDALAY BAY È£ÅÚ¿¡¼ ÁøÇàµÆ´Ù.
ºí·¢ÇÞ(Black Hat)Àº 1997³â óÀ½ °³ÃÖµÈ ÄÁÆÛ·±½º·Î ¸Å³â ÃֽŠÇØÅ· ±â¹ý ¹× º¸¾È À̽´¸¦ °ø°³ÇØ ÁÖ¸ñ¹Þ°í ÀÖ´Ù. ƯÈ÷, ºí·¢ÇÞ 2014¿¡¼´Â À̺´¿µ¡¤À念Áø¡¤¿ÀÁ¤¿í ¾¾ µî 3¸íÀÇ Çѱ¹ÀÎ °¿¬ÀÚ°¡ ¹ßÇ¥¸¦ ÁøÇàÇØ ±¹³»¿¡¼µµ °ü½ÉÀÌ ¶ß°Ì´Ù.
ÀÌ °¡¿îµ¥ À念Áø ¾¾´Â Áö³ÇØ iOS ±â±â¿¡ ¾Ç¼ºÄڵ带 ¸ô·¡ ½ÉÀ» ¼ö ÀÖ´Â ÃæÀü±â¸¦ °³¹ßÇØ ÈÁ¦¸¦ ¸ðÀºµ¥ À̾î À̹ø¿¡´Â À̺´¿µ ¾¾, Tielei Wang ¾¾¿Í °øµ¿À¸·Î ¿¬±¸ÇÑ ¡®ÆÐÄ¡µÇÁö ¾ÊÀº Ãë¾àÁ¡À» ÀÌ¿ëÇÑ iOS Å»¿Á À籸¼º¡¯À̶ó´Â ÁÖÁ¦·Î ¹ßÇ¥¸¦ ÁøÇàÇß´Ù.
¹ßÇ¥¿¡ ¾Õ¼ À念Áø ¾¾´Â ¡°Å»¿Á¿¡ »ç¿ëµÈ Ãë¾àÁ¡Àº Á÷Á¢ ãÀº °ÍÀÌ ¾Æ´Ï¶ó ±âÁ¸¿¡ ¹ß°ßµÈ °Í¡±À̶ó¸ç, ¡°ÀÌ Ãë¾àÁ¡ °¡¿îµ¥ ¾ÖÇÿ¡¼ ÆÐÄ¡ÇÏÁö ¾ÊÀº Ãë¾àÁ¡À» ÀÌ¿ëÇØ Å»¿ÁÀ» ÇÒ ¼ö ÀÖ´ÂÁö¿¡ Àǹ®À» Ç°¾î ¿¬±¸¸¦ ½ÃÀÛÇÏ°Ô µÆ´Ù¡±°í ¹àÇû´Ù.
ÀÌ¾î ±×´Â ¡°À̹ø ¿¬±¸´Â 2013³â 12¿ù¿¡ ³ª¿Â Å»¿ÁÅø evasion7ÀÌ ¾î¶² ´Ü°è¸¦ °ÅÃÄ Å»¿ÁÀ» ÇÑ °ÍÀÎÁö, evasion7¿¡ »ç¿ëµÈ 8°¡Áö Ãë¾àÁ¡ÀÌ ¾î¶² °ÍÀÎÁö, iOS 7.1¿¡¼ evasion7¿¡ »ç¿ëµÈ Ãë¾àÁ¡ Áß ¾î¶² °ÍÀ» ÆÐÄ¡ÇÏ°í ÆÐÄ¡ÇÏÁö ¾Ê¾Ò´ÂÁö µîÀ» ºÐ¼®ÇØ evasion7°ú À¯»çÇÑ ¹æ¹ýÀ¸·Î Å»¿ÁÀ» ¼º°øÇÒ ¼ö ÀÖ´À³Ä¿¡ °üÇÑ °Í¡±À̶ó°í ÀüÇß´Ù.
¸ÕÀú ±×´Â iOS Å»¿ÁÀÌ ¾î·Á¿î ÀÌÀ¯¸¦ ¼³¸íÇß´Ù. ±×´Â ù¹ø° ÀÌÀ¯·Î Æß¿þ¾î°¡ ¾ÏȣȵǾî Àֱ⠶§¹®¿¡ Å»¿ÁµÈ ±â±â°¡ ¾øÀ¸¸é ºÐ¼® ÀÚü°¡ Èûµé±â ¶§¹®À̶ó°í ÀüÇß´Ù. µð¹ö±ë, ¸®¹ö½Ì µîÀ» ¸ðµÎ ¸øÇÏ´Â »óÅ·Π¹Ù±ù¿¡¼ ¾î¶² °ªÀ» ³Ö¾úÀ» ¶§ ¾î¶»°Ô µ¿ÀÛÇÏ´ÂÁö¸¸À» º¸°í ÇØÅ·ÇØ¾ß ÇÑ´Ù´Â °ÍÀÌ´Ù.
µÎ ¹ø°·Î´Â ±×´Â Ä¿³ÎÀÌ º¸È£µÇ¾î Àֱ⠶§¹®À̶ó°í ÀüÇß´Ù. iOS´Â ¸®´ª½º µî Ÿ OS¿Í´Â ´Ù¸£°Ô ·çÆ®±ÇÇÑÀÌ ÀÖ´õ¶óµµ Ä¿³Î¿¡ Äڵ带 ³ÖÀ» ¼ö ¾ø´Ù. Áï ·çÆ® ±ÇÇÑÀ» ȹµæÇß´õ¶óµµ Ä¿³Î ÀͽºÇ÷ÎÀÕÀ» ÇØ¾ß ÇÑ´Ù´Â ¾ê±â´Ù.
¼¼ ¹ø°·Î´Â ÄÚµå»çÀÎÀÌ ¾ÈµÈ ¹ÙÀ̳ʸ®¸¦ ¿Ã¸®±â Èûµé¾î ÄÚµå»çÀΠüũ¸¦ ¿ìȸÇØ¾ß ÇÑ´Ù´Â Á¡À» µé¾ú´Ù. ±×·¯³ª ÄÚµå»çÀÎÀ» ¿ìȸÇÒ ¼ö ÀÖ´Â À¯ÀÏÇÑ RWX(Àбâ, ¾²±â, ½ÇÇà) ÆäÀÌÁöµµ »çÆĸ®¿Í °°Àº ƯÁ¤ÇÑ ÇÁ·Î¼¼½º¿¡¸¸ Çã¿ëµÇ¾î ÀÖ¾î Å»¿ÁÀÌ Èûµé´Ù´Â °ÍÀÌ´Ù.
À念Áø ¾¾¿¡ µû¸£¸é evasion7ÀÇ °æ¿ì 8°³ÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇØ Å»¿Á¿¡ ½ÃµµÇß´Ù. evsion7¿¡¼ »ç¿ëµÈ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°´Ù(±½Àº ±Û¾¾ - iOS 7.1¿¡¼ ¾ÆÁ÷ ÆÐÄ¡ ¾ÈµÊ).
1. Bypassing code signature check
2. Installing an app at outside-of-container
3. Bypassing filesystem sandbox in afcd
4. Overwriting critical files using installd
5. Injecting dylib through com.apple.mobile_installation.plist
6. Use symlink to downgrade permission of a file
7. Use afcd -S to directly write into block device
8. A kernel vulnerability
±×·¯³ª ÀÌÁß 3°³¸¦ Á¦¿ÜÇÑ ³ª¸ÓÁö´Â iOS 7.1¿¡¼ ÀÌ¹Ì ÆÐÄ¡µÈ »óÅ¿´´Ù. ÀÌ¿¡ À念Áø ¾¾´Â ÆÐÄ¡µÇÁö ¾ÊÀº 3°³ÀÇ Ãë¾àÁ¡°ú ÇÔ²² ÆÐÄ¡µÈ Ãë¾àÁ¡°ú À¯»ç±â´ÉÀ» ÇÏ´Â Ãë¾àÁ¡À» ã¾Æ evasion7°ú °°Àº ¹æ½ÄÀ¸·Î iOS 7.1.1 Å»¿ÁÀ» ½ÃµµÇß´Ù. À念Áø ¾¾°¡ iOS 7.1.1 Å»¿ÁÀ» ÁøÇàÇÑ ¼ø¼´Â ´ÙÀ½°ú °°´Ù.
1. Install an app at the outside-of-container
2. Edit /var/mobile/Media/Downloads/ WWDC.app/WWDC to a hashbang (#!) file
3. Inject dylibs into afcd using installd vulnerablility
4. Forge a dylib to have constructor, then sign with a develoer license
5. Create Symlink at (µ¥¸ó) to/dev/rdisk0s1s1
6. Dump root partition, then modify it
7. Execute an app to drop /tmp/ bypass_codesign
8. Kill daemons with lockdownd
¹ßÇ¥¸¦ ¸¶Ä¡¸ç À念Áø ¾¾´Â ¡°°ø°³µÈ Ãë¾àÁ¡À» ÀÌ¿ëÇ߱⿡ Å»¿ÁÇϴµ¥ ¸¹Àº ½Ã°£ÀÌ °É¸®Áö ¾Ê¾Ò´Ù¡±¸ç ¡°°ø°³µÈ ÀڷḦ ÀÌ¿ëÇØ °øºÎÇÑ´Ù¸é ¾î·ÆÁö ¾Ê°Ô iOS Å»¿ÁÇÒ ¼ö ÀÖ´Ù¡±°í ¹àÇû´Ù.
[±èÁö¾ð ±âÀÚ(boan4@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>