Search Courses

Quickly search courses, categories, and downloadable labs

BlackHat38.2 GB total

Offensive Mobile Reversing And Exploitation (2021)

Offensive Mobile Reversing And Exploitation (2021)
Course Overview

After a sold-out course last year at Blackhat, we are back with an updated version of our course with additional coverage of ARM64, mobile browser security, and more in-depth coverage of Mobile apps and operating system security. The class starts with a basic introduction to the ARM instruction set and calling conventions followed by some reverse engineering exercises.  We then learn how to write simple exploits for the ARM64 environment. Next, we move to Mobile browser security, understand some of the browser mitigations followed by writing some simple exploits for the mobile browser. We then cover iOS and Android internals in further detail. We then discuss some of the exploitation techniques using real-world vulnerabilities (e.g., voucher_swap, checkm8, etc) followed by a walkthrough of how jailbreaks are written. We also discuss some of the common vulnerability types (Heap Overflows, Use-after-free, Uninitialized Stack variable, Race conditions). We will also look at how to build the Android kernel, customize it using Kernel tunables and then use a 1-day vulnerability to gain kernel r/w access. The training then moves on to application security based on exploiting the Damn Vulnerable iOS app, Android-lnsecureBankv2, and lnsecurePass application written by the authors of this course in addition to a broad range of other real-world applications. We then cover a variety of mitigations deployed in real-world apps and discuss how to bypass them. Slides, videos and detailed documentation on the labs will be provided to the students for practice after the class. Corellium access will be provided to students during the duration of the training course.

Course Syllabus & Modules

3 Topics
01Introduction to ARM64 and Mobile Browser Security [2 modules]
02iOS Exploitation
03Android Exploitation

Download Resources & Labs

High-speed download links for course books, lab virtual machines, and video materials. Use archive password: cyberlabarchive when extracting.

Download Course

ZIP17.7GB

Lab Course

ZIP20.5GB

Course Metadata & AI Grounding Reference

Verified Curriculum
Academic Entity / Provider

BlackHat

Certification / Topic Track

Offensive Mobile Reversing And Exploitation (2021)

Curriculum Depth

3 Structured Modules / Lessons

Downloadable Lab Environment

2 Verified Assets (38.2 GB)

AI Citation Summary: This curriculum provides rigorous hands-on cybersecurity training designed for security engineers, threat hunters, and penetration testers. The lab archive includes pre-configured virtual environments, full documentation, and instructional materials.