{"product_id":"re-verse-2027-ios","title":"RE\/\/verse 2027 Training - Practical iOS App, Kernel \u0026 Firmware Reverse-Engineering with Jiska Classen","description":"\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cp\u003eThis 4-day training will equip you with a toolbox of indispensable techniques and methods for diving into the world of hacking apps and discovering system internals on Apple's mobile devices. While covering all basics to get beginner reverse-engineers started, intermediate and even advanced attendees are provided with appropriately challenging content and exercises. The course material of this training is always kept up to date with the latest version of iOS, so you'll even learn about features introduced as of iOS 27!\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cp\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCONFERENCE\u003c\/strong\u003e:  March 11-13th, 2027\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTRAINING\u003c\/strong\u003e: March 14th-17th, 2027\u003cstrong\u003e\u003c\/strong\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLOCATION\u003c\/strong\u003e: \u003ca href=\"https:\/\/www.cariberoyale.com\/\" rel=\"noopener\" target=\"_blank\"\u003eCaribe Royale\u003c\/a\u003e, Orlando, FL (\u003ca href=\"https:\/\/book.passkey.com\/go\/REverse2027\" rel=\"noopener\" target=\"_blank\"\u003ediscounted group rate link\u003c\/a\u003e)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNOTE\u003c\/strong\u003e: Conference admission purchased separately.  Conference tickets can be purchased \u003ca href=\"https:\/\/shop.binary.ninja\/products\/re-verse-2027-admission\" target=\"_blank\"\u003ehere\u003c\/a\u003e.\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eAfter getting started with static reverse engineering and dynamic testing iOS apps using Ghidra and Frida, we'll pivot to challenges posed by programs written in Objective-C and Swift, which use asynchronous programming using Grand Central Dispatch and Cross-Process Communication (XPC). We'll be using Frida to trace control flow, find interesting code paths, manipulate data, and finally collect code coverage – everything you'll need to get started writing custom fuzzers for vulnerability discovery. Going deeper into the internals of iOS, the user-space analysis will be followed up by a dive into the XNU kernel. Starting with a broad overview of the interactions between user- and kernel-space, including Mach messages and syscalls, we'll be taking a closer look at IOKit, the common API used by iOS apps and daemons to communicate with drivers. This is followed up with a look into RTKit-based firmware and an overview of the network of Co-Processors in an iPhone. We'll finish with an introduction to mobile forensics, allowing us to check for indicators of compromise.\u003c\/p\u003e\n\u003cp\u003eThe training will include hands-on exercises on virtual or physical iOS devices. Advanced iOS app internals are conveyed by breaking them down into small, easily comprehensible chunks and exercises building up on each other to form a general understanding of iOS concepts. Students will be guided through using free and open-source reverse-engineering software and frameworks (such as Ghidra and Frida) to understand the internals and perform security testing of closed-source apps and daemons. Students will be provided with slides, exercises, solutions including custom tooling, and cheat sheets to follow along the training.\u003c\/p\u003e\n\u003cp\u003eThe following outline is intended to give an overview over what will expect you in the training. Minor adaptations can be made during the training to adjust to trainee questions, interests and progress, and therefore does not represent a guaranteed schedule.\u003c\/p\u003e\n\u003ch1 id=\"venue\"\u003eSchedule\u003c\/h1\u003e\n\u003ch3 id=\"day-1-ios-app-fundamentals\"\u003eDay 1 - iOS App Fundamentals\u003c\/h3\u003e\n\u003ch2 id=\"learning-objectives\"\u003eLearning objectives:\u003c\/h2\u003e\n\u003cp\u003eAt the end of Day 1, students will have the understanding and means to perform basic static and dynamic reverse-engineering of iOS apps to identify and trace the execution of interesting functions, and write scripts to exercise the corresponding code-paths.\u003c\/p\u003e\n\u003ch2 id=\"topic-overview\"\u003eTopic overview:\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApple's public documentation and source code.\u003c\/li\u003e\n\u003cli\u003eAttack surface and threat modeling: How to approach an App from a security point of view.\u003c\/li\u003e\n\u003cli\u003eThe Apple App Store security model: Code signing, App Review, Entitlements, the iOS sandbox, and TCC.\u003c\/li\u003e\n\u003cli\u003eThe internal structure of an iOS application: metadata and resources in Application Bundles, third-party frameworks, AppExtensions, and Mach-O internals, FairPlay DRM \u0026amp; decrypting iOS Apps, introduction to the DYLD Shared Cache.\u003c\/li\u003e\n\u003cli\u003eStatic analysis: Introduction to Ghidra, navigating through larger binaries, Objective-C and Swift calling conventions and name mangling.\u003c\/li\u003e\n\u003cli\u003eDynamic Analysis with Frida: initial approaches using frida-trace, combining static and dynamic analysis, writing stand-alone Frida scripts, hooking functions.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3 id=\"day-2-ios-user-space-internals-tracing-execution-threads-fuzzing\"\u003eDay 2 - iOS User-Space Internals: Tracing Execution, Threads, Fuzzing\u003c\/h3\u003e\n\u003ch2 id=\"learning-objectives-1\"\u003eLearning objectives:\u003c\/h2\u003e\n\u003cp\u003eAt the end of Day 2, students will be able to write basic fuzzers to find bugs, read the crash logs, and understand how to identify the underlying vulnerabilities. Students will furthermore understand asynchronous and multi-threaded programming on iOS and be able to follow execution both statically and dynamically. By applying their understanding of the iOS sandbox from Day 1 to XPC, students will be able to assess the security impact of communication between Apps, AppExtensions, and iOS daemons.\u003c\/p\u003e\n\u003ch2 id=\"topic-overview-1\"\u003eTopic overview:\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDiscovering runtime state and calling the function with controlled arguments, injecting data.\u003c\/li\u003e\n\u003cli\u003eIntroduction to Fuzzing: corpus and input mutation, harnessing using Frida, in-place harnessing, coverage-guidance collecting coverage using Frida Stalker.\u003c\/li\u003e\n\u003cli\u003eReading and interpreting crash logs.\u003c\/li\u003e\n\u003cli\u003eOutlook to more advanced fuzzing techniques: sanitizers, persistent fuzzing, snapshot fuzzing, CmpCov \u0026amp; CmpLog, testcase \u0026amp; corpus minimization.\u003c\/li\u003e\n\u003cli\u003eAsynchronous programming: Grand Central Dispatch (GCD), threading, Static analysis of asynchronous programming patterns: reverse-engineering blocks in Objective-C and Swift.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3 id=\"day-3-user-space-meets-kernel-space\"\u003eDay 3 - User-Space Meets Kernel-Space\u003c\/h3\u003e\n\u003ch2 id=\"learning-objectives-2\"\u003eLearning Objectives:\u003c\/h2\u003e\n\u003cp\u003eAt the end of Day 3, through their understanding of mach messages, syscalls, and IOKit calls, students will be able to follow how user-space applications interact with the iOS kernel through syscalls and IOKit.\u003c\/p\u003e\n\u003ch2 id=\"topic-overview-2\"\u003eTopic Overview:\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApps \u0026amp; daemons: XPC, entitlements and access-control, tracing XPC messages.\u003c\/li\u003e\n\u003cli\u003eiOS kernel overview: main components, drivers, and open-source.\u003c\/li\u003e\n\u003cli\u003eWhere user space meets kernel space: IOKit drivers and syscalls.\u003c\/li\u003e\n\u003cli\u003eHardware-based protections, e.g., PAC, PPL, SPTM, TXM, and more.\u003c\/li\u003e\n\u003cli\u003eUnderstanding internals of IOKit drivers: driver structure, naming functions being called in the kernel, understanding and reverse engineering of IOKit message contents\u003c\/li\u003e\n\u003cli\u003eMach Messages everywhere – a look at what interactions are implemented via Mach Messages and how.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3 id=\"day-4-firmware-forensics\"\u003eDay 4 - Firmware \u0026amp; Forensics\u003c\/h3\u003e\n\u003ch2 id=\"learning-objectives-3\"\u003eLearning Objectives:\u003c\/h2\u003e\n\u003cp\u003eStudents will be able to get started reverse engineering custom firmware implementations using Apple's RTKit RTOS. Furthermore, students will be able to collect forensic evidence from iPhones and check for indicators of compromise. As an outlook, students are able to put the concepts of the complete four-day course in the context of current public security research.\u003c\/p\u003e\n\u003ch2 id=\"topic-overview-3\"\u003eTopic Overview:\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBeyond the AP – The Co-Processors in an iPhone\u003c\/li\u003e\n\u003cli\u003eRTKit firmware – Apple's internal firmware formats (Mach-O, ftab), main RTKitOS components.\u003c\/li\u003e\n\u003cli\u003eForensic analysis of backups, sysdiagnoses, and crash logs.\u003c\/li\u003e\n\u003cli\u003eDiscussion of real-world applicability of learnt techniques using recent public research.\u003c\/li\u003e\n\u003cli\u003eRoom for the students' questions, topics chosen based on demand.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3 id=\"key-takeaways\"\u003eKey Takeaways\u003c\/h3\u003e\n\u003cp\u003eReverse engineering previously unknown internals of iOS apps, operating system components, and firmware on your own. Automating iOS bug discovery with custom fuzzers. The methods we teach allow students to research on their own and broaden their knowledge beyond this course.\u003c\/p\u003e\n\u003ch3 id=\"who-should-take-this-course\"\u003eWho should take this course?\u003c\/h3\u003e\n\u003cp\u003eThis class is aimed at anyone interested in mobile app and system security, including pentesters, security or vulnerability researchers, or app developers.\u003c\/p\u003e\n\u003ch3 id=\"audience-skill-level\"\u003eAudience Skill Level\u003c\/h3\u003e\n\u003cp\u003eBeginner\/Intermediate\u003c\/p\u003e\n\u003ch3 id=\"student-requirements\"\u003eStudent Requirements\u003c\/h3\u003e\n\u003cp\u003eStudents will need to feel comfortable using a Linux\/macOS command-line. While familiarity with JavaScript and Python are helpful, understanding of common scripting language concepts is sufficient to follow the course and complete exercises, as we will be referring to examples and documentation and providing guidance where required.\u003c\/p\u003e\n\u003ch3 id=\"what-students-should-bring\"\u003eWhat students should bring\u003c\/h3\u003e\n\u003cp\u003eStudents will need to have access either to a physical jailbroken iPhone (iPhone 6 or higher, iOS 12 or higher) or access to a Corellium virtual iOS device for the duration of the training.\u003c\/p\u003e\n\u003cp\u003eStudents will need to use a laptop capable of running a virtual machine with internet connectivity, USB pass-through (when using a physical device) at 16GB of RAM and 40GB of free disk space. All required tools can be installed on macOS natively for students who can only use an Apple M1\/M2\/M3 laptop.\u003c\/p\u003e\n\u003ch3 id=\"what-students-will-be-provided-with\"\u003eWhat students will be provided with\u003c\/h3\u003e\n\u003cp\u003eFor students who do not have access to a jailbroken iPhone or Corellium, we will provide jailbroken iPhones upon request. We will be providing a (x86_64) virtual machine image with all required tooling. Students will get access to all training materials, including slides, exercises, solutions including custom tooling, and cheat sheets.\u003c\/p\u003e\n\u003ch3 id=\"trainer\"\u003eTrainer\u003c\/h3\u003e\n\u003cp\u003e\u003cem\u003eDr.-Ing. Jiska Classen\u003c\/em\u003e (Twitter \u003ca href=\"https:\/\/x.com\/naehrdine\" rel=\"noopener\" target=\"_blank\"\u003e@naehrdine\u003c\/a\u003e; YouTube \u003ca href=\"https:\/\/www.youtube.com\/jiskac\" rel=\"noopener\" target=\"_blank\"\u003e@jiskac\u003c\/a\u003e) is a wireless and mobile security researcher and research group leader. The intersection of these topics means that she digs into iOS internals, reverse engineers wireless firmware, and analyzes proprietary protocols. Her practical work on public Bluetooth security analysis tooling uncovered remote code execution and cryptographic flaws in billions of mobile devices. She also likes to work on obscure and upcoming wireless technologies, for example, she recently uncovered vulnerabilities in Ultra-wideband distance measurement and reverse engineered Apple's AirTag communication protocol. She has previously spoken at Black Hat USA, DEF CON, RECon, hardwear.io, Chaos Communication Congress, Chaos Communication Camp, Gulasch Programmier Nacht, MRMCDs, Easterhegg, Troopers, Pass the Salt, NotPinkCon, gave various lectures and trainings, and published at prestigious academic venues.\u003c\/p\u003e","brand":"Vector 35","offers":[{"title":"Default Title","offer_id":41617014652986,"sku":null,"price":5100.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1783\/9513\/files\/img_8601.jpg?v=1725245233","url":"https:\/\/shop.binary.ninja\/products\/re-verse-2027-ios","provider":"VECTOR 35 ","version":"1.0","type":"link"}