The evad3rsare probably one of the hottest tickets around right now on the mobile security circuit. The four hackers were able to overcome Apple’s highly regarded security systems in iOS 6, to provide us with theevasi0n jailbreak.

Well good news for those of you that will be in Amsterdam between the dates of April 8 – 11. The team will be giving a presentation at theHack in the Box Security Conferencein the country, at the Okura Hotel. More details after the fold…

evad3rs logo

That’s right,MuscleNerd,pod2g,planetbeingand pimskeks will all be on hand at HITBSecConf2013 to talk about their latest jailbreak, and how they managed to break through iOS 6’s security. Here’s a brief overview of their presentation.

“The Apple product security team did an impressive job raising the resilience of the iOS 6 kernel to well known attacks: Kernel ASLR was added, code pages of the kernel protected, and heap structures reinforced to harden the exploitability of heap overflows. Also, numerous directory traversals and vulnerabilities in iOS lockdown services have been fixed silently in the road from 5.1.1 to 6.0, burning all building blocks we already prepared.

Web

For the iOS 6 public jailbreak, we started from scratch, and found successively a total of 8 vulnerabilities in a few months.

In our presentation, we will paint a big picture of the iOS 6 security, and how the Mandatory Code Signing requirement is enforced which is the target of all jailbreak tools. Afterwards, we will present different ideas, vulnerabilities and exploits that lead to the iOS 6 jailbreak. We will start by discussing the injection of the payload, which involves new and clever approaches to the problem, then explain how userland code is triggered, untethered, and finally discuss how the kernel has been successfully exploited.”

With over 1.7 million downloads in thefirst 24 hours, and more than7 million downloadsin the first four days, evasi0n is billed as the most popular jailbreak ever. It’s also been described as one of themost complex ever, utilizing several exploits.

For those that won’t be able to make it to Amsterdam, don’t worry. We imagine there will either be a live stream of the evad3rs’ presentation, or a video uploaded after the fact. At least, this was the case withthe Dream Teamat last year’s HITB.