![Watch the 'Dream Team' of iPhone Hackers Present on the Corona Jailbreak [Video] Watch the 'Dream Team' of iPhone Hackers Present on the Corona Jailbreak [Video]](/images/news/22739/83883/83883-64.png)
Watch the 'Dream Team' of iPhone Hackers Present on the Corona Jailbreak [Video]
Posted June 22, 2012 at 9:13am by
Shalom Levytam
Watch the 'Dream Team' of iPhone hackers present on the Corona Jailbreak at HITB2012 in this video recently posted by the conference.
Overview:
GreenPois0n Absinthe was built upon @pod2g's Corona untether jailbreak to create the first public jailbreak for the iPhone 4S and iPad 2 on for the 5.0.1 firmware. In this paper, we present a chain of multiple exploits to accomplish sandbox breakout, kernel unsigned code injection and execution that result in a fully-featured and untethered jailbreak.
Corona is an acronym for "racoon", which is the primary victim for this attack. A format string vulnerability was located in racoon's error handling routines, allowing the researchers to write arbitrary data to racoon's stack, one byte at a time, if they can control racoon's configuration file. Using this technique researchers were able to build a ROP payload on racoon's stack to mount a rogue HFS volume that injects code at the kernel level and patch its code-signing routines.
The original Corona untether exploit made use of the LimeRa1n bootrom exploit as an injection vector, to allow developers to disable ASLR and sandboxing, and call racoon with a custom configuration script. This however left it unusable for newer A5 devices like the iPad2 and iPhone 4S, which weren't exploitable to LimeRa1n, so another injection vector was needed.
Presenters:
Joshua Hill (@p0sixninja) is an independent Security Researcher for zImperium, as well as leader of the Chronic Dev Team and chief architect behind GreenPois0n, a cross-platform toolkit used by millions of people around the world to jailbreak their iOS mobile devices.
Cyril (@pod2g) is an iPhone hacker who has discovered and exploited several bootrom exploits on iDevices, including 24kpwn, steaks4uce, and SHAtter, as well as several userland and kernel exploits that have been used in various jailbreak tools. He's a member of Chronic-Dev Team and the original author the of Corona untether jailbreak.
Nikias Bassen (@pimskeks) is a Chronic-Dev Team member and main developer of libimobiledevice, usbmuxd, and other related projects that form an open source implementation of communication and service protocols for iDevices. He found several flaws in the iDevice service protocols that also helped creating Absinthe.
David Wang (@planetbeing) is a member of the iPhone Dev Team and former developer of many iOS jailbreak tools including redsn0w, xpwn, and QuickPwn. He is also the first to have ported the Linux kernel and Android to iOS devices.
Read More
Overview:
GreenPois0n Absinthe was built upon @pod2g's Corona untether jailbreak to create the first public jailbreak for the iPhone 4S and iPad 2 on for the 5.0.1 firmware. In this paper, we present a chain of multiple exploits to accomplish sandbox breakout, kernel unsigned code injection and execution that result in a fully-featured and untethered jailbreak.
Corona is an acronym for "racoon", which is the primary victim for this attack. A format string vulnerability was located in racoon's error handling routines, allowing the researchers to write arbitrary data to racoon's stack, one byte at a time, if they can control racoon's configuration file. Using this technique researchers were able to build a ROP payload on racoon's stack to mount a rogue HFS volume that injects code at the kernel level and patch its code-signing routines.
The original Corona untether exploit made use of the LimeRa1n bootrom exploit as an injection vector, to allow developers to disable ASLR and sandboxing, and call racoon with a custom configuration script. This however left it unusable for newer A5 devices like the iPad2 and iPhone 4S, which weren't exploitable to LimeRa1n, so another injection vector was needed.
Presenters:
Joshua Hill (@p0sixninja) is an independent Security Researcher for zImperium, as well as leader of the Chronic Dev Team and chief architect behind GreenPois0n, a cross-platform toolkit used by millions of people around the world to jailbreak their iOS mobile devices.
Cyril (@pod2g) is an iPhone hacker who has discovered and exploited several bootrom exploits on iDevices, including 24kpwn, steaks4uce, and SHAtter, as well as several userland and kernel exploits that have been used in various jailbreak tools. He's a member of Chronic-Dev Team and the original author the of Corona untether jailbreak.
Nikias Bassen (@pimskeks) is a Chronic-Dev Team member and main developer of libimobiledevice, usbmuxd, and other related projects that form an open source implementation of communication and service protocols for iDevices. He found several flaws in the iDevice service protocols that also helped creating Absinthe.
David Wang (@planetbeing) is a member of the iPhone Dev Team and former developer of many iOS jailbreak tools including redsn0w, xpwn, and QuickPwn. He is also the first to have ported the Linux kernel and Android to iOS devices.
Read More


![Apple Says iPhone Duo's Folding Display Has a Replaceable Cover Layer [Video] Apple Says iPhone Duo's Folding Display Has a Replaceable Cover Layer [Video]](/images/news/102525/102525/102525-160.jpg)
![Touchscreen OLED MacBook Pro Could Debut as Early as October [Gurman] Touchscreen OLED MacBook Pro Could Debut as Early as October [Gurman]](/images/news/102519/102519/102519-160.jpg)
![iPhone 18 Pro Sales Rise 12% in China as Apple Leads Weekly Smartphone Market [Report] iPhone 18 Pro Sales Rise 12% in China as Apple Leads Weekly Smartphone Market [Report]](/images/news/102522/102522/102522-160.jpg)
![How To Find Your iPhone IMEI Number [Video] How To Find Your iPhone IMEI Number [Video]](/images/tutorials/83557/83557/83557-160.jpg)

![How To Change Wallpaper on Mac [Video] How To Change Wallpaper on Mac [Video]](/images/tutorials/90512/90512/90512-160.jpg)




![16-Inch M5 Max MacBook Pro Drops $900 to New Low of $3,499 [Deal] 16-Inch M5 Max MacBook Pro Drops $900 to New Low of $3,499 [Deal]](/images/news/102438/102438/102438-160.jpg)
![Magic Keyboard for iPad Air Drops to $200 on Amazon [Deal] Magic Keyboard for iPad Air Drops to $200 on Amazon [Deal]](/images/news/102402/102402/102402-160.jpg)
![13-Inch M5 MacBook Air With 1TB Drops to $1,449 on Amazon [Deal] 13-Inch M5 MacBook Air With 1TB Drops to $1,449 on Amazon [Deal]](/images/news/102345/102345/102345-160.jpg)