Reading List
FORCEDENTRY Sandbox Escape via NSExpression from Michael Tsai RSS feed.
FORCEDENTRY Sandbox Escape via NSExpression
Ian Beer and Samuel Groß (back in March): It’s clearly a serialized NSKeyedArchiver. Definitely not what you’d expect to see in a JBIG2Bitmap object. Running strings we see plenty of interesting things[…][…]NSPredicates using the FUNCTION keyword are effectively Objective-C scripts. With some tricks it’s possible to build nested function calls which can do almost anything […]