Wojciech Reguła (@_r3ggi) 's Twitter Profile
Wojciech Reguła

@_r3ggi

iOS/macOS app security researcher & blogger. 🍎 Black Hat / DEF CON / TyphoonCon speaker. Head of mobile appsec @SecuRingPL

ID: 3420050055

linkhttps://wojciechregula.blog/ calendar_today13-08-2015 13:08:19

1,1K Tweet

5,5K Followers

866 Following

Wojciech Reguła (@_r3ggi) 's Twitter Profile Photo

Insecurely get audit_token by PID. I spent too much time on finding the way to do so. Maybe that would help somebody: gist.github.com/r3ggi/f6d48f2f… Kudos Scott Knight, I wrote that basing on your code 👍🏻

iOS Dev Tools  (@iosdevtools) 's Twitter Profile Photo

#iOSdev tool alert! 🚨 iOS Security Suite by Wojciech Reguła is an advanced and easy-to-use platform security & anti-tampering library written in pure Swift. The ISS can be used to detect jailbreak, detect or/and deny attached debugger & many more. github.com/securing/IOSSe…

#iOSdev tool alert! 🚨

iOS Security Suite by <a href="/_r3ggi/">Wojciech Reguła</a> is an advanced and easy-to-use platform security &amp; anti-tampering library written in pure Swift.

The ISS can be used to detect jailbreak, detect or/and deny attached debugger &amp; many more.

github.com/securing/IOSSe…
Csaba Fitzl (@theevilbit) 's Twitter Profile Photo

🍎🪳My latest blogpost Kandji about the Dock Tile Plugin vulnerability I found. It allowed someone to escalate privileges, and also perform a guest to host VM escape - unfortunately that part turned out to be less exciting than I initially thought. blog.kandji.io/dock-tile-plug…

Tony Gorez (@tonygo_) 's Twitter Profile Photo

You'll probably like this tool if you are interested in #Apple #macOS #ReverseEngineering. I face some issues in having a stable version of it; feel free to jump in if you think you can help: github.com/tony-go/snixpc

Brandon Dalton (@partyd0lphin) 's Twitter Profile Photo

Turns out you can enumerate individual clients connected to Endpoint Security by looking at the I/O Registry's `IOService` plane under: `IOService:/IOResources/EndpointSecurityDriver`. You can use: `ioreg -r -c EndpointSecurityExternalClient` swiftly-detecting.notion.site/Listing-Connec…

Turns out you can enumerate individual clients connected to Endpoint Security by looking at the I/O Registry's `IOService` plane under: `IOService:/IOResources/EndpointSecurityDriver`.

You can use: `ioreg -r -c EndpointSecurityExternalClient`

swiftly-detecting.notion.site/Listing-Connec…
Tielei (@wangtielei) 's Twitter Profile Photo

Looking for universal, backward-compatible kernel read and write primitives for both ARM and Intel-based macOS systems? No problem! Check it out at: github.com/wangtielei/POC…. The PoC uses only existing kernel mechanisms and does not require complex memory manipulation techniques.

Zhongquan Li (@guluisacat) 's Twitter Profile Photo

#BHUSA Black Hat My Black Hat USA 2024 presentation is finished. Thank you all for coming. In my presentation, I disclosed some methods to achieve SBX and LPE. Many of them require launching an app, so in an attack scenario, the user may notice an app icon briefly

Alexandre Borges (@ale_sp_brazil) 's Twitter Profile Photo

So far, I have written 706 pages to help the security community. My goal will be writing new articles of the Exploiting Reversing Series (ERS), which is focused on security research. However, I am planning to write one or two additional articles of my previous series MAS (Malware

So far, I have written 706 pages to help the security community. My goal will be writing new articles of the Exploiting Reversing Series (ERS), which is focused on security research. However, I am planning to write one or two additional articles of my previous series MAS (Malware
Stuart Ashenbrenner 🇺🇸 🇨🇦 (@stuartjash) 's Twitter Profile Photo

Publishing some of the notes I've amassed over my years in #macOS security. There's lots, so I'm publishing them as I collate them into something structured and readable. My first few are available, and the rest will be as I finish them. notes.crashsecurity.io/notes

Gergely Kalman (@gergely_kalman) 's Twitter Profile Photo

Are any of you guys interested in the 44 slides about file API security that I had to cut from my new presentation? It has all the fan favourites like union mounts, POSIX ACLs and other unhinged insanity

Are any of you guys interested in the 44 slides about file API security that I had to cut from my new presentation?
It has all the fan favourites like union mounts, POSIX ACLs and other unhinged insanity
Objective-See Foundation (@objective_see) 's Twitter Profile Photo

#OBTS v7 talks have been announced: objectivebythesea.org/v7/talks.html 🤗 With over 20 talks (from many of the world's top researchers), covering macOS/iOS bugs & exploits, malware, internals, tools, and much more, this is a can't miss event! Which talks are you most excited about?

Wojciech Reguła (@_r3ggi) 's Twitter Profile Photo

iOS friends- do you have any solution for purchasing&downloading apps from the AppStore from CLI? `ipatools` does not work anymore for purchasing 😢

Wojciech Reguła (@_r3ggi) 's Twitter Profile Photo

On my way to NSSpain XII #NSSpain2024 Tomorrow I’m giving a talk about apps isolation that I think will be interesting to Apple apps developers 🍎👩‍💻🧑‍💻

On my way to <a href="/NSSpain/">NSSpain XII</a> #NSSpain2024 
Tomorrow I’m giving a talk about apps isolation that I think will be interesting to Apple apps developers 🍎👩‍💻🧑‍💻