<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>IOS on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/ios/</link>
    <description>Recent content in IOS on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 15 Apr 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/ios/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>MDMs – The Mobile Device “Magic” Solutions – Expectations and Reality</title>
      <link>https://insinuator.net/2019/04/mdms-the-mobile-device-magic-solutions-expectations-and-reality/</link>
      <pubDate>Mon, 15 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/mdms-the-mobile-device-magic-solutions-expectations-and-reality/</guid>
      <description>&lt;p&gt;When you are working in the area of mobile security, you sooner or later receive requests from clients asking you to test specific ‘Mobile Device Management’ (MDM) solutions which they (plan to) use, the corresponding mobile apps, as well as different environment setups and device policy sets.&lt;br&gt;&#xA;The expectations are often high, not only for the MDM solutions ability to massively reduce the administrative workload of keeping track, updating and managing the often hundreds or thousands of devices within a company but also regarding the improvements towards the level of security that an MDM solution is regularly advertised to provide.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review about the System and Security Info iOS App from SektionEins GmbH</title>
      <link>https://insinuator.net/2016/05/review-about-the-system-and-security-info-ios-app-from-sektioneins-gmbh/</link>
      <pubDate>Wed, 18 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/review-about-the-system-and-security-info-ios-app-from-sektioneins-gmbh/</guid>
      <description>&lt;p&gt;Dear readers of Insinuator,&lt;/p&gt;&#xA;&lt;p&gt;Today I want to give a little review about the latest app released by SektionEins called “System and Security Info” due to its recent media appearance. So first of all the app can be obtained via the Apple App store for 0,99€ at the time this article was written. This article will try to answer two basic questions: for whom (or “which groups of people”) is this app helpful, and which security features does this app actually has. The design of the app is straight forward and pretty minimalistic with a clean and modern design. The first page of the Application called “Overview” provides nothing more than the current CPU usage of the device, with detailed subdivision in User, Idle, Total and Load. The next section provides an overview about the used RAM divided into Wire, Active RAM usage, Inactive RAM usage, “other”, free and the total amount of the device’s ram. The next option shows the used and unused part of the devices available storage, with “used”, “free” and total amount of space. While these features can be handled with several other (free and open source) applications I won’t write a comment wether it  these components make sense.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New iOS Version – New Lockscreen Bypass</title>
      <link>https://insinuator.net/2015/09/new-ios-version-new-lockscreen-bypass/</link>
      <pubDate>Sun, 27 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/new-ios-version-new-lockscreen-bypass/</guid>
      <description>&lt;p&gt;At the 16th of September Apple released its new version of the mobile operating system iOS 9. As several versions before, this new iteration suffers from a weakness that makes it possible to bypass the lockscreen without entering the respective PIN code. Exploiting this flaw requires Siri to be enabled and phyiscal access to the phone. A successful exploitation results in a major loss of confidentiality as all photos and contacts in the phonebook can be accessed by the attacker. The following steps lead to the lockscreen bypass:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple iOS PIN Bruteforce</title>
      <link>https://insinuator.net/2015/04/apple-ios-pin-bruteforce/</link>
      <pubDate>Tue, 07 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/apple-ios-pin-bruteforce/</guid>
      <description>&lt;p&gt;Over the past few weeks, multiple news sites have covered some mystical approach to bruteforce PINs on Apple iOS devices. All articles cover a black box called IP Box, the fact that PINs can be broken and that sometimes the automatic wipe after 10 failed tries can be circumvented. Sadly, as often, the what is described but not the how……&lt;/p&gt;&#xA;&lt;h2&gt;&lt;/h2&gt;&#xA;&lt;p&gt;This blog post will give you a simple overview of both the practical attacks and the vulnerabilities behind them. Although the Headings don’t quite give away the content, the post starts with a simple PIN bruteforce against iOS 7.x and then goes over to a more advanced attack on iOS 8.x and a few technical details on the “black box”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple iOS and the history of a workin’ lockscreen… NOT</title>
      <link>https://insinuator.net/2013/02/apple-ios-and-the-history-of-a-workin-lockscreen-not/</link>
      <pubDate>Sun, 17 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/apple-ios-and-the-history-of-a-workin-lockscreen-not/</guid>
      <description>&lt;p&gt;Once again a vulnerability in Apples mobile operating system iOS was found by some guys of the Jailbreak Nation. The newest version of this operating system suffers from a weakness that makes it possible to unlock the lockscreen of all iPhones that use iOS version 6.1. In this case it does not matter whether a PIN or a password is used to unlock the phone. After successful exploitation an attacker is able to see and edit contact-information, to add new contacts to the phonebook, to view all pictures, to call the inbox or any of the contacts and to see and delete the list of recent calls or parts of it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mobile Application Testing</title>
      <link>https://insinuator.net/2013/02/mobile-application-testing/</link>
      <pubDate>Thu, 14 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/mobile-application-testing/</guid>
      <description>&lt;p&gt;Our new &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-mobile-application-testing/index.html&#34;&gt;workshop about mobile application testing&lt;/a&gt;, held for the 1st time at the Troopers conference 2013, is coming closer. So I would like to take the opportunity and post an appetizer for those who are still undetermined if they should attend the workshop ;-).&lt;/p&gt;&#xA;&lt;p&gt;While the topic of mobile application testing is a wide field that may contain reverse engineering, secure storage analysis, vulnerability research, network traffic analysis and so forth, in the end of the day you have to answer one question: Can I trust this application and run it on my enterprise devices? So first you have to define some criteria, which kind of behavior and characteristics of an application you regard as trustworthy (or not). Let us peek at malware … besides harming your devices and data, malware is typically:&lt;/p&gt;</description>
    </item>
    <item>
      <title>iOS 5, S/MIME, and Digital Certificate Management</title>
      <link>https://insinuator.net/2011/11/ios-5-s/mime-and-digital-certificate-management/</link>
      <pubDate>Fri, 04 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/ios-5-s/mime-and-digital-certificate-management/</guid>
      <description>&lt;p&gt;As a follow-up to &lt;a href=&#34;http://www.insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/&#34;&gt;this post&lt;/a&gt; somebody pointed us to &lt;a href=&#34;http://www.css-security.com/blog/ios-5-smime-and-digital-certificate-management/&#34;&gt;this interesting article&lt;/a&gt; on S/MIME support and associated certificate mgmt in iOS 5. Nice read which some of you may find worthwhile.&lt;/p&gt;&#xA;&lt;p&gt;On a related note: if anyone is aware of an easy way/good (3rd party) solution for pushing certs to iOS devices (besides SCEP) we would be very interested in that one. In that case pls leave a comment or shoot us an email.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
