Oh, one more thing… our new website is live! 🌐 https://t.co/RtbbfxjTNJ
Still lots in the works - from our research blog to other initiatives - but here’s a nice sneak peek for now 👀
Another newcomer is sponsoring us this year: @prdgmshift!
@prdgmshift is an independent European EU leader in cybersecurity research. With a team of world-class researchers, we uncover critical zero-days and deliver state-of-the-art research to keep our partners one step ahead.
Here are the slides from my & @__gsch's & q3k's 0x41con 2025 talk - "1,000 bugs in your pocket"
It's about non-iOS iPod hacking
https://t.co/D2wKoOMp8G
Amazing as always! Thanks to the organizers and attendees!
I had honor to present my & @__gsch’s & q3k’s talk titled “1,000 bugs in your pocket”
We’ll likely publish the slides soon
@b_nnett Not for now. The bootrom exploit (S5Late) is tethered, and there's no driver for its NAND yet. I'm running from an NFS. In the future when proper driver support is in place it could be made untethered by using the ipod_sun exploit. Cool to hear it's gaining some interest :)
Getting some earlyprintk going for the iPod Nano7 after I managed to get USB working on U-Boot. Also figured enough of the LCD controller to draw on the screen.
This is all thanks to previous work by q3k :)
Turns out you could access DiagShell in iPod Nano7 without any exploit by just sending the diag image after WTF. And memrw works so you can read/write anywhere 🙃
After working together with q3k, wInd3x now supports iPod Nano 7G by using S5Late. That makes decrypting and running custom binaries very straightforward.
https://t.co/xhKnOd16bf
iPod shuffle 4 (S5L8443) is now also O B L I T E R A T E D by virtue of @__gsch's S5Late bug
(Yes, the ROM is so similar to S5L8723, that they didn't even bother changing serial number string)
Here is my preliminary iPod nano 6 (S5L8723) port of the new bootrom exploit by @__gsch - S5Late
As usual, be careful with this and etc.
https://t.co/lHf3Ad4cL6