ZA·023 Talk 2019

Meticulously Modern Mobile Manipulations

Event
BSides Cape Town
Region
South Africa
Language
EN

Abstract

Mobile app hacking peaked in 2015 with tools like keychain-dumper & ssl- kill-switch released but requiring jailbroken/rooted devices. Back then, wresting the power to understand & modify apps on our devices from dystopian looking mega corps was our cause. As jailbreaks became infrequent, the hackers' arsenal was left behind. While this is progress against dark uses of hacking, done to protect our freedom fighters, how can hackers still hold power to account? Can we still find flaws in apps/devices & live up to the protections the technology promises? Enter runtime binary instrumentation with Frida. It's possible to analyze apps in their final state when executed on real hardware running the latest iOS/Android with no jailbreaks. This fills a gap between source analysis & debuggers.