George Dan
George is a Principal Penetration Tester at Fujitsu Australia with over five years of professional experience. He has a strong affinity for reverse engineering weird and complex systems, and enjoys a good CTF with first bloods for trophy challenges at BSides Canberra CTF's under his belt, such as Lucky Visitor and SecElf cyOS Jailbreak.
Session
Starting security research into modern platforms that have been around for a while can be extremely daunting. Getting your foot in the door and beginning to understand the system and its components is the most challenging part in research.
This talk will go over in-depth four vulnerabilities identified in iOS 6's version of JavaScriptCore / WebKit and the logic required to gain code execution in Safari. This will be followed by analysis of core changes to the frameworks in following versions, learning how fundamental changes to framework impact the found vulnerabilities and discovering what may remain in the present day.