Tag: iphone

Appleexploitfacebookiphonem$OSX security toolsPrivacySecuritytoolstwitterXSS

iOS SSL Kill Switch

This is a MobileSubstrate extension to disable certificate validation within NSURLConnection in order to facilitate black-box testing of iOS Apps. Once installed on a jailbroken device, iOS SSL Kill Switch patches NSURLConnection to override and disable the system's default certificate validation as well as any kind of custom certificate validation (such as certificate pinning).
Appleexploitfacebookiphonem$OSX security toolsPrivacySecuritytoolstwitterXSS

Zero Day Initiative Advisory 12-107

Zero Day Initiative Advisory 12-107 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XML elements within a TeXML file
Appleexploitfacebookiphonem$OSX security toolsPrivacySecuritytoolstwitterXSS

Zero Day Initiative Advisory 12-095

Zero Day Initiative Advisory 12-095 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XML elements within a TeXML file.