Home > Àüü±â»ç

[ºí·¢ÇÞ 2014] ÆÐÄ¡µÇÁö ¾ÊÀº Ãë¾àÁ¡À¸·Î iOS Å»¿ÁÇϱâ

ÀÔ·Â : 2014-08-08 10:02
ÆäÀ̽ººÏ º¸³»±â Æ®À§ÅÍ º¸³»±â ³×À̹ö ¹êµå º¸³»±â Ä«Ä«¿À ½ºÅ丮 º¸³»±â ³×À̹ö ºí·Î±× º¸³»±â

À念Áø ¾¾, iOS °ü·Ã ÁÖÁ¦·Î ºí·¢ÇÞ¿¡¼­ 2³â ¿¬¼Ó °­¿¬


[º¸¾È´º½º ±èÁö¾ð] ÃֽŠ±Û·Î¹ú º¸¾ÈÆ®·»µå¿Í ÇÖÀ̽´¸¦ Á¶¸ÁÇÒ ¼ö ÀÖ´Â ¡®ºí·¢ÇÞ 2014¡¯°¡ 8¿ù 2ÀϺÎÅÍ 7ÀÏ(ÇöÁö½Ã°¢)±îÁö ¹Ì±¹ ¶ó½ºº£°¡½º MANDALAY BAY È£ÅÚ¿¡¼­ ÁøÇàµÆ´Ù.


ºí·¢ÇÞ(Black Hat)Àº 1997³â óÀ½ °³ÃÖµÈ ÄÁÆÛ·±½º·Î ¸Å³â ÃֽŠÇØÅ· ±â¹ý ¹× º¸¾È À̽´¸¦ °ø°³ÇØ ÁÖ¸ñ¹Þ°í ÀÖ´Ù. ƯÈ÷, ºí·¢ÇÞ 2014¿¡¼­´Â À̺´¿µ¡¤À念Áø¡¤¿ÀÁ¤¿í ¾¾ µî 3¸íÀÇ Çѱ¹ÀÎ °­¿¬ÀÚ°¡ ¹ßÇ¥¸¦ ÁøÇàÇØ ±¹³»¿¡¼­µµ °ü½ÉÀÌ ¶ß°Ì´Ù.


ÀÌ °¡¿îµ¥ À念Áø ¾¾´Â Áö³­ÇØ iOS ±â±â¿¡ ¾Ç¼ºÄڵ带 ¸ô·¡ ½ÉÀ» ¼ö ÀÖ´Â ÃæÀü±â¸¦ °³¹ßÇØ È­Á¦¸¦ ¸ðÀºµ¥ À̾î À̹ø¿¡´Â À̺´¿µ ¾¾, Tielei Wang ¾¾¿Í °øµ¿À¸·Î ¿¬±¸ÇÑ ¡®ÆÐÄ¡µÇÁö ¾ÊÀº Ãë¾àÁ¡À» ÀÌ¿ëÇÑ iOS Å»¿Á À籸¼º¡¯À̶ó´Â ÁÖÁ¦·Î ¹ßÇ¥¸¦ ÁøÇàÇß´Ù.


¹ßÇ¥¿¡ ¾Õ¼­ À念Áø ¾¾´Â ¡°Å»¿Á¿¡ »ç¿ëµÈ Ãë¾àÁ¡Àº Á÷Á¢ ãÀº °ÍÀÌ ¾Æ´Ï¶ó ±âÁ¸¿¡ ¹ß°ßµÈ °Í¡±À̶ó¸ç, ¡°ÀÌ Ãë¾àÁ¡ °¡¿îµ¥ ¾ÖÇÿ¡¼­ ÆÐÄ¡ÇÏÁö ¾ÊÀº Ãë¾àÁ¡À» ÀÌ¿ëÇØ Å»¿ÁÀ» ÇÒ ¼ö ÀÖ´ÂÁö¿¡ Àǹ®À» Ç°¾î ¿¬±¸¸¦ ½ÃÀÛÇÏ°Ô µÆ´Ù¡±°í ¹àÇû´Ù.


ÀÌ¾î ±×´Â ¡°À̹ø ¿¬±¸´Â 2013³â 12¿ù¿¡ ³ª¿Â Å»¿ÁÅø evasion7ÀÌ ¾î¶² ´Ü°è¸¦ °ÅÃÄ Å»¿ÁÀ» ÇÑ °ÍÀÎÁö, evasion7¿¡ »ç¿ëµÈ 8°¡Áö Ãë¾àÁ¡ÀÌ ¾î¶² °ÍÀÎÁö, iOS 7.1¿¡¼­ evasion7¿¡ »ç¿ëµÈ Ãë¾àÁ¡ Áß ¾î¶² °ÍÀ» ÆÐÄ¡ÇÏ°í ÆÐÄ¡ÇÏÁö ¾Ê¾Ò´ÂÁö µîÀ» ºÐ¼®ÇØ evasion7°ú À¯»çÇÑ ¹æ¹ýÀ¸·Î Å»¿ÁÀ» ¼º°øÇÒ ¼ö ÀÖ´À³Ä¿¡ °üÇÑ °Í¡±À̶ó°í ÀüÇß´Ù.


¸ÕÀú ±×´Â iOS Å»¿ÁÀÌ ¾î·Á¿î ÀÌÀ¯¸¦ ¼³¸íÇß´Ù. ±×´Â ù¹ø° ÀÌÀ¯·Î Æß¿þ¾î°¡ ¾ÏȣȭµÇ¾î Àֱ⠶§¹®¿¡ Å»¿ÁµÈ ±â±â°¡ ¾øÀ¸¸é ºÐ¼® ÀÚü°¡ Èûµé±â ¶§¹®À̶ó°í ÀüÇß´Ù. µð¹ö±ë, ¸®¹ö½Ì µîÀ» ¸ðµÎ ¸øÇÏ´Â »óÅ·Π¹Ù±ù¿¡¼­ ¾î¶² °ªÀ» ³Ö¾úÀ» ¶§ ¾î¶»°Ô µ¿ÀÛÇÏ´ÂÁö¸¸À» º¸°í ÇØÅ·ÇØ¾ß ÇÑ´Ù´Â °ÍÀÌ´Ù.


µÎ ¹ø°·Î´Â ±×´Â Ä¿³ÎÀÌ º¸È£µÇ¾î Àֱ⠶§¹®À̶ó°í ÀüÇß´Ù. iOS´Â ¸®´ª½º µî Ÿ OS¿Í´Â ´Ù¸£°Ô ·çÆ®±ÇÇÑÀÌ ÀÖ´õ¶óµµ Ä¿³Î¿¡ Äڵ带 ³ÖÀ» ¼ö ¾ø´Ù. Áï ·çÆ® ±ÇÇÑÀ» ȹµæÇß´õ¶óµµ Ä¿³Î ÀͽºÇ÷ÎÀÕÀ» ÇØ¾ß ÇÑ´Ù´Â ¾ê±â´Ù.


¼¼ ¹ø°·Î´Â ÄÚµå»çÀÎÀÌ ¾ÈµÈ ¹ÙÀ̳ʸ®¸¦ ¿Ã¸®±â Èûµé¾î ÄÚµå»çÀΠüũ¸¦ ¿ìȸÇؾߠÇÑ´Ù´Â Á¡À» µé¾ú´Ù. ±×·¯³ª ÄÚµå»çÀÎÀ» ¿ìȸÇÒ ¼ö ÀÖ´Â À¯ÀÏÇÑ RWX(Àбâ, ¾²±â, ½ÇÇà) ÆäÀÌÁöµµ »çÆĸ®¿Í °°Àº ƯÁ¤ÇÑ ÇÁ·Î¼¼½º¿¡¸¸ Çã¿ëµÇ¾î ÀÖ¾î Å»¿ÁÀÌ Èûµé´Ù´Â °ÍÀÌ´Ù.


À念Áø ¾¾¿¡ µû¸£¸é evasion7ÀÇ °æ¿ì 8°³ÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇØ Å»¿Á¿¡ ½ÃµµÇß´Ù. evsion7¿¡¼­ »ç¿ëµÈ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°´Ù(±½Àº ±Û¾¾ - iOS 7.1¿¡¼­ ¾ÆÁ÷ ÆÐÄ¡ ¾ÈµÊ).

 

1. Bypassing code signature check

2. Installing an app at outside-of-container

3. Bypassing filesystem sandbox in afcd

4. Overwriting critical files using installd

5. Injecting dylib through com.apple.mobile_installation.plist

6. Use symlink to downgrade permission of a file

7. Use afcd -S to directly write into block device

8. A kernel vulnerability

 

±×·¯³ª ÀÌÁß 3°³¸¦ Á¦¿ÜÇÑ ³ª¸ÓÁö´Â iOS 7.1¿¡¼­ À̹̠ÆÐÄ¡µÈ »óÅ¿´´Ù. ÀÌ¿¡ À念Áø ¾¾´Â ÆÐÄ¡µÇÁö ¾ÊÀº 3°³ÀÇ Ãë¾àÁ¡°ú ÇÔ²² ÆÐÄ¡µÈ Ãë¾àÁ¡°ú À¯»ç±â´ÉÀ» ÇÏ´Â Ãë¾àÁ¡À» ã¾Æ evasion7°ú °°Àº ¹æ½ÄÀ¸·Î iOS 7.1.1 Å»¿ÁÀ» ½ÃµµÇß´Ù. À念Áø ¾¾°¡ iOS 7.1.1 Å»¿ÁÀ» ÁøÇàÇÑ ¼ø¼­´Â ´ÙÀ½°ú °°´Ù.


1. Install an app at the outside-of-container

2. Edit /var/mobile/Media/Downloads/ WWDC.app/WWDC to a hashbang (#!) file

3. Inject dylibs into afcd using installd vulnerablility

4. Forge a dylib to have constructor, then sign with a develoer license

5. Create Symlink at (µ¥¸ó) to/dev/rdisk0s1s1

6. Dump root partition, then modify it

7. Execute an app to drop /tmp/ bypass_codesign

8. Kill daemons with lockdownd


¹ßÇ¥¸¦ ¸¶Ä¡¸ç À念Áø ¾¾´Â ¡°°ø°³µÈ Ãë¾àÁ¡À» ÀÌ¿ëÇ߱⿡ Å»¿ÁÇϴµ¥ ¸¹Àº ½Ã°£ÀÌ °É¸®Áö ¾Ê¾Ò´Ù¡±¸ç ¡°°ø°³µÈ ÀڷḦ ÀÌ¿ëÇØ °øºÎÇÑ´Ù¸é ¾î·ÆÁö ¾Ê°Ô iOS Å»¿ÁÇÒ ¼ö ÀÖ´Ù¡±°í ¹àÇû´Ù.

[±èÁö¾ð ±âÀÚ(boan4@boannews.com)]


<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>

  •  
  • 0
  • ÆäÀ̽ººÏ º¸³»±â Æ®À§ÅÍ º¸³»±â ³×À̹ö ¹êµå º¸³»±â Ä«Ä«¿À ½ºÅ丮 º¸³»±â ³×À̹ö ºí·Î±× º¸³»±â

  • ¡°
  •  SNS¿¡¼­µµ º¸¾È´º½º¸¦ ¹Þ¾Æº¸¼¼¿ä!! 
  • ¡±
¾Æ½ºÆ®·Ð½ÃÅ¥¸®Æ¼ ÆÄ¿öºñÁî 2023³â2¿ù23ÀÏ ½ÃÀÛ ³Ý¾Øµå ÆÄ¿öºñÁî ÁøÇà 2020³â1¿ù8ÀÏ ½ÃÀÛ~2021³â 1¿ù8ÀϱîÁö À§Áîµð¿£¿¡½º 2018
¼³¹®Á¶»ç
³»³â ȸ»ç¿¡ ²À µµÀÔÇÏ°í ½ÍÀº º¸¾È ¼Ö·ç¼Ç ¶Ç´Â Ç÷§ÆûÀº ¹«¾ùÀΰ¡¿ä?
XDR
EDR
AI º¸¾È
Á¦·ÎÆ®·¯½ºÆ®
°ø±Þ¸Á º¸¾È ü°è(SBOM)
Ŭ¶ó¿ìµå º¸¾È ¼Ö·ç¼Ç
±âŸ(´ñ±Û·Î)