Brandon Azad (bazad)

bazad

Geek Repo

Company:Google Project Zero

Home Page:https://bazad.github.io

Github PK Tool:Github PK Tool

Brandon Azad's repositories

ida_kernelcache

An IDA Toolkit for analyzing iOS kernelcaches.

Language:PythonLicense:MITStargazers:284Issues:23Issues:5

blanket

CVE-2018-4280: Mach port replacement vulnerability in launchd on iOS 11.2.6 leading to sandbox escape, privilege escalation, and codesigning bypass.

memctl

An iOS kernel introspection tool.

x18-leak

CVE-2018-4185: iOS 11.2-11.2.6 kernel pointer disclosure introduced by Apple's Meltdown mitigation.

Language:CStargazers:84Issues:11Issues:0

threadexec

A library to execute code in the context of other processes on iOS 11.

presentations

Slides from my conference presentations.

ios-command-line-tool

Example showing how to build a standalone iOS executable using Xcode.

Language:Objective-CStargazers:70Issues:7Issues:2

launchd-portrep

CVE-2018-4280: Mach port replacement vulnerability in launchd on macOS 10.13.5 leading to local privilege escalation and SIP bypass.

Language:CLicense:MITStargazers:59Issues:7Issues:0

xpc-string-leak

CVE-2018-4248: Out-of-bounds read in libxpc during string serialization.

Language:CStargazers:54Issues:5Issues:0

devicetree-parse

A tool to parse Apple's binary device tree format.

Language:CStargazers:53Issues:6Issues:0

macho_gadgets

A tool to find gadgets in the iOS kernelcache.

Language:CStargazers:33Issues:5Issues:0

AppleJPEGDriver-memleak

Kernel memory leak/local DOS on iOS 11.

Language:CStargazers:30Issues:4Issues:0

ctl_ctloutput-leak

CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.

Language:CStargazers:29Issues:6Issues:0

gsscred-race

CVE-2018-4331: Exploit for a race condition in the GSSCred system service on iOS 11.2.

Language:CStargazers:25Issues:4Issues:0

memctl-kext-core

A memctl core for macOS that uses a kernel extension.

Language:C++License:MITStargazers:16Issues:4Issues:1

IOAccelerator-leak

Kernel heap pointer disclosure in IOGraphicsFamily.

Language:CStargazers:14Issues:4Issues:0

flow_divert-leak

Kernel heap read buffer overflow on macOS/iOS requiring root.

Language:CStargazers:11Issues:3Issues:0

memctl-tfp0-core

A memctl core for jailbroken iOS devices.

Language:CLicense:MITStargazers:11Issues:6Issues:0

bazad.github.io

My security blog.

Language:CSSLicense:MITStargazers:10Issues:10Issues:1

mincore-dos

Local denial of service exploit for iOS 11/macOS 10.13.

Language:MakefileStargazers:10Issues:3Issues:0

xpc-crash

An out-of-bounds read in libxpc that can be used to crash XPC services.

Language:CStargazers:10Issues:4Issues:0

kldstat-stack-disclosure

A kernel stack disclosure in FreeBSD.

Language:CStargazers:9Issues:4Issues:0

gsscred-move-uaf

CVE-2018-4343: Proof-of-concept for a use-after-free in the GSSCred daemon on macOS and iOS.

memctl-physmem-core

A memctl core that uses the physmem exploit.

Language:CLicense:MITStargazers:8Issues:4Issues:0

flow_divert-memleak

Memory leak in XNU requiring root privileges.

Language:CStargazers:7Issues:3Issues:0

IOMFB-DOS-1

Local denial of service on iOS 11.2.

Language:CStargazers:7Issues:3Issues:0

IOFireWireFamily-null-deref

CVE-2017-2388: Null-pointer dereference in IOFireWireFamily.

Language:CStargazers:4Issues:3Issues:0

sysctl_coalition_get_pid_list-dos

CVE-2017-7173: Local denial of service for iOS requiring root privileges.

Language:CStargazers:4Issues:4Issues:0

IOFireWireFamily-overflow

CVE-2016-7608: Buffer overflow in IOFireWireFamily.

Language:CStargazers:3Issues:3Issues:0

mach_portal_memctl

An example of how to use libmemctl with mach_portal.

Language:CStargazers:3Issues:4Issues:0