Iphone And Ipad Hacking presented at CanSecWest 2011

by Ilja van Sprundel (IOActive),

Tags: Security

Summary : Over the last few years there has been a signifant amount of iPhone and iPad application development going on. Although based on Mac OSX, its development API's are new and very specific to the iPhone and iPad. In this presentation, Ilja van Sprundel, Principal Security Consultant at IOActive, will discuss lessons learned from auditing iPhone and iPad applications over the last year. It will cover the use of specific API's, why some of them aren't granular enough, and why they might expose way too much attack surface. The talk will cover ssl, xml, url handling, UIWebView's and more. Furthermore, it will also cover what apps are allowed to do when inside their sandbox once an application has been hacked.