56,966 blogs · [ { "id": "01a087ec-ac82-70fa-b63e-e73d5b20c9f6", "title": "Talks and Workshops", "url": "https://theevilbit.github.io/talks/", "published_at": "2026-05-21T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5ba043b2", "title": "macOS LPE via the .localized directory", "url": "https://theevilbit.github.io/posts/localized/", "published_at": "2025-12-05T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5c1339c1", "title": "The diskarbitrationd and storagekitd Audit Story Part 2", "url": "https://theevilbit.github.io/posts/macos-audit-story-part2/", "published_at": "2024-12-12T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5cd49a7b", "title": "The diskarbitrationd and storagekitd Audit Story Part 1", "url": "https://theevilbit.github.io/posts/macos-audit-story-part1/", "published_at": "2024-11-08T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5cffd5ab", "title": "Beyond the good ol' LaunchAgents - 35 - Persist through the NVRAM - The 'apple-trusted-trampoline'", "url": "https://theevilbit.github.io/beyond/beyond_0035/", "published_at": "2024-10-15T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5dbe344f", "title": "Beyond the good ol' LaunchAgents - 34 - launchd boot tasks", "url": "https://theevilbit.github.io/beyond/beyond_0034/", "published_at": "2024-10-10T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5e61532b", "title": "Dock Tile Plugins Could Be Used to Escalate Privileges", "url": "https://theevilbit.github.io/posts/dock-tile-plugins-persistence/", "published_at": "2024-07-19T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5f010bbf", "title": "Beyond the good ol' LaunchAgents - 33 - Widgets", "url": "https://theevilbit.github.io/beyond/beyond_0033/", "published_at": "2024-06-12T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5f119815", "title": "CVE-2023-40424 - How Malware Can Bypass Transparency Consent and Control", "url": "https://theevilbit.github.io/posts/cve-2023-40424/", "published_at": "2024-05-24T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d5fba4b1b", "title": "How Apple Mitigates Vulnerabilities in Installer Scripts", "url": "https://theevilbit.github.io/posts/apple-mitigates-vulnerabilities-installer-scripts/", "published_at": "2024-03-15T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d60427290", "title": "Launch and Environment Constraints Deep Dive", "url": "https://theevilbit.github.io/posts/launch_constraints_deep_dive/", "published_at": "2023-10-09T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d608f55b2", "title": "Beyond the good ol' LaunchAgents - 32 - Dock Tile Plugins", "url": "https://theevilbit.github.io/beyond/beyond_0032/", "published_at": "2023-09-29T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d6119640e", "title": "macOS Service Management - The SMAppService API - Quick Notes", "url": "https://theevilbit.github.io/posts/smappservice/", "published_at": "2023-09-28T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d6165fbbe", "title": "Beyond the good ol' LaunchAgents - 31 - BSM audit framework", "url": "https://theevilbit.github.io/beyond/beyond_0031/", "published_at": "2023-05-26T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d618d6579", "title": "Beyond the good ol' LaunchAgents - 30 - The man config file - man.conf", "url": "https://theevilbit.github.io/beyond/beyond_0030/", "published_at": "2023-05-10T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d626bd22a", "title": "CVE-2022-22655 - TCC - Location Services Bypass", "url": "https://theevilbit.github.io/posts/cve-2022-22655/", "published_at": "2023-02-13T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d62cb67d1", "title": "CVE-2022-32929 - Bypass iOS backup's TCC protection", "url": "https://theevilbit.github.io/posts/cve-2022-32929/", "published_at": "2022-11-14T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d62d3ad01", "title": "Prologue - The Lord of The Rules", "url": "https://theevilbit.github.io/posts/prologue/", "published_at": "2022-10-24T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d63ac9c66", "title": "CVE-2017-2533 - The details behind", "url": "https://theevilbit.github.io/posts/cve-2017-2533/", "published_at": "2022-08-29T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d63e59dea", "title": "AMFI Launch Constraints - First Quick Look", "url": "https://theevilbit.github.io/posts/amfi_launch_constraints/", "published_at": "2022-06-14T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d645116aa", "title": "Beyond the good ol' LaunchAgents - 29 - amstoold", "url": "https://theevilbit.github.io/beyond/beyond_0029/", "published_at": "2022-03-08T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d64a4ccfc", "title": "Beyond the good ol' LaunchAgents - 28 - Authorization Plugins", "url": "https://theevilbit.github.io/beyond/beyond_0028/", "published_at": "2022-02-09T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d64cc963b", "title": "Beyond the good ol' LaunchAgents - 27 - Dock shortcuts", "url": "https://theevilbit.github.io/beyond/beyond_0027/", "published_at": "2022-02-08T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d64ce648e", "title": "Beyond the good ol' LaunchAgents - 26 - Finder Sync Plugins", "url": "https://theevilbit.github.io/beyond/beyond_0026/", "published_at": "2022-02-05T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d64e9e5bf", "title": "Beyond the good ol' LaunchAgents - 25 - Apache2 modules", "url": "https://theevilbit.github.io/beyond/beyond_0025/", "published_at": "2021-12-15T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d64fb93b9", "title": "Beyond the good ol' LaunchAgents - 24 - Folder Actions", "url": "https://theevilbit.github.io/beyond/beyond_0024/", "published_at": "2021-12-02T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d65e560f3", "title": "Beyond the good ol' LaunchAgents - 23 - emond, The Event Monitor Daemon", "url": "https://theevilbit.github.io/beyond/beyond_0023/", "published_at": "2021-11-27T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d664ea0f4", "title": "Beyond the good ol' LaunchAgents - 22 - LoginHook and LogoutHook", "url": "https://theevilbit.github.io/beyond/beyond_0022/", "published_at": "2021-11-24T00:00:00+00:00" }, { "id": "01a087ec-ac82-70fa-b63e-e73d66852546", "title": "CVE-2021-30808 - CVE-2021-1784 strikes back - TCC bypass via mounting", "url": "https://theevilbit.github.io/posts/cve-2021-30808/", "published_at": "2021-10-29T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e176f71221", "title": "About", "url": "https://theevilbit.github.io/about/", "published_at": "2021-10-22T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e177f2045d", "title": "Beyond the good ol' LaunchAgents - 21 - Re-opened Applications", "url": "https://theevilbit.github.io/beyond/beyond_0021/", "published_at": "2021-10-12T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1788e466b", "title": "Getting started in macOS security", "url": "https://theevilbit.github.io/posts/getting_started_in_macos_security/", "published_at": "2021-09-27T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e178dfdc78", "title": "Beyond the good ol' LaunchAgents - 20 - Terminal Preferences", "url": "https://theevilbit.github.io/beyond/beyond_0020/", "published_at": "2021-09-22T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e179257b58", "title": "Beyond the good ol' LaunchAgents - 19 - Periodic Scripts", "url": "https://theevilbit.github.io/beyond/beyond_0019/", "published_at": "2021-08-06T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e179e8d597", "title": "GateKeeper - Not a Bypass (Again)", "url": "https://theevilbit.github.io/posts/gatekeeper_not_a_bypass/", "published_at": "2021-06-29T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17a323354", "title": "Beyond the good ol' LaunchAgents - 18 - X11 and XQuartz", "url": "https://theevilbit.github.io/beyond/beyond_0018/", "published_at": "2021-06-28T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17b175aca", "title": "macOS Monterey Shortcuts - First look", "url": "https://theevilbit.github.io/posts/monterey_shortcuts/", "published_at": "2021-06-10T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17bf8efad", "title": "Beyond the good ol' LaunchAgents - 17 - Color Pickers", "url": "https://theevilbit.github.io/beyond/beyond_0017/", "published_at": "2021-05-31T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17c9a11ef", "title": "Beyond the good ol' LaunchAgents - 16 - Screen Saver", "url": "https://theevilbit.github.io/beyond/beyond_0016/", "published_at": "2021-05-30T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17cfc2006", "title": "NOCVE - TeamViewer Local Privilege Escalation Vulnerability", "url": "https://theevilbit.github.io/posts/teamviewer_lpe/", "published_at": "2021-05-26T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17dbb42ad", "title": "Beyond the good ol' LaunchAgents - 15 - xsanctl", "url": "https://theevilbit.github.io/beyond/beyond_0015/", "published_at": "2021-05-12T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17eb5634f", "title": "Beyond the good ol' LaunchAgents - 14 - atrun", "url": "https://theevilbit.github.io/beyond/beyond_0014/", "published_at": "2021-04-27T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17ebf41f1", "title": "Experiences with Apple Security Bounty", "url": "https://theevilbit.github.io/posts/experiences_with_asb/", "published_at": "2021-04-23T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17efcefe8", "title": "CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter", "url": "https://theevilbit.github.io/posts/macos_crashreporter/", "published_at": "2021-04-20T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e17fed0b9a", "title": "Beyond the good ol' LaunchAgents - 13 - Audio Plugins", "url": "https://theevilbit.github.io/beyond/beyond_0013/", "published_at": "2021-04-19T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1802e096d", "title": "Beyond the good ol' LaunchAgents - 12 - QuickLook Plugins", "url": "https://theevilbit.github.io/beyond/beyond_0012/", "published_at": "2021-04-05T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e180482fd2", "title": "Beyond the good ol' LaunchAgents - 11 - Spotlight Importers", "url": "https://theevilbit.github.io/beyond/beyond_0011/", "published_at": "2021-04-03T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18102a43c", "title": "Beyond the good ol' LaunchAgents - 10 - Application script files", "url": "https://theevilbit.github.io/beyond/beyond_0010/", "published_at": "2021-04-02T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1814d9006", "title": "Beyond the good ol' LaunchAgents - 9 - Preference Pane", "url": "https://theevilbit.github.io/beyond/beyond_0009/", "published_at": "2021-03-25T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18156ae49", "title": "Beyond the good ol' LaunchAgents - 8 - Hammerspoon", "url": "https://theevilbit.github.io/beyond/beyond_0008/", "published_at": "2021-03-23T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e181a96a01", "title": "Beyond the good ol' LaunchAgents - 7 - xbar plugins", "url": "https://theevilbit.github.io/beyond/beyond_0007/", "published_at": "2021-03-22T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e181c031ba", "title": "Beyond the good ol' LaunchAgents - 6 - SSHRC", "url": "https://theevilbit.github.io/beyond/beyond_0006/", "published_at": "2021-03-21T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1823d3402", "title": "Beyond the good ol' LaunchAgents - 5 - Pluggable Authentication Modules (PAM)", "url": "https://theevilbit.github.io/beyond/beyond_0005/", "published_at": "2021-03-20T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e182a7b08b", "title": "Beyond the good ol' LaunchAgents - 4 - cron jobs", "url": "https://theevilbit.github.io/beyond/beyond_0004/", "published_at": "2021-03-18T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1837ac978", "title": "Beyond the good ol' LaunchAgents - 3 - Login Items", "url": "https://theevilbit.github.io/beyond/beyond_0003/", "published_at": "2021-03-17T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1842ecbfa", "title": "Beyond the good ol' LaunchAgents - 2 - iTerm2 startup", "url": "https://theevilbit.github.io/beyond/beyond_0002/", "published_at": "2021-03-16T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1846fc7fd", "title": "Beyond the good ol' LaunchAgents - 1 - shell startup files", "url": "https://theevilbit.github.io/beyond/beyond_0001/", "published_at": "2021-03-14T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1848d79f7", "title": "Beyond the good ol' LaunchAgents - Introduction", "url": "https://theevilbit.github.io/beyond/beyond_intro/", "published_at": "2021-03-14T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18527ebdf", "title": "About com.apple.private.security.clear-library-validation", "url": "https://theevilbit.github.io/posts/com.apple.private.security.clear-library-validation/", "published_at": "2021-01-19T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18553bda2", "title": "Divide and Conquer - A technique to bypass NextGen AV", "url": "https://theevilbit.github.io/posts/divide_and_conquer/", "published_at": "2021-01-17T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e185a51fea", "title": "CVE-2020-9771 - Reversing Engineering the Fix", "url": "https://theevilbit.github.io/posts/reversing_cve_2020_9771/", "published_at": "2020-12-13T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18640cacc", "title": "NOCVE - Microsoft Teams for macOS Local Privilege Escalation", "url": "https://theevilbit.github.io/posts/microsoft_teams_lpe/", "published_at": "2020-11-17T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1867c39f1", "title": "Let's talk macOS Authorization", "url": "https://theevilbit.github.io/posts/macos_authorization/", "published_at": "2020-10-22T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18706c529", "title": "CVE-2020-9771 - mount_apfs TCC bypass and privilege escalation", "url": "https://theevilbit.github.io/posts/cve_2020_9771/", "published_at": "2020-07-03T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e187617906", "title": "CVE-2020-14977 - Secure coding XPC Services - Part 5 - PID reuse attacks", "url": "https://theevilbit.github.io/posts/secure_coding_xpc_part5/", "published_at": "2020-06-16T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1882960d8", "title": "CVE-2020-14978 - Secure coding XPC Services - Part 4 - Improved client authorization", "url": "https://theevilbit.github.io/posts/secure_coding_xpc_part4/", "published_at": "2020-06-12T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e188f16c4a", "title": "The AMFI MACF policy system call", "url": "https://theevilbit.github.io/posts/amfi_syscall/", "published_at": "2020-06-09T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1893ad536", "title": "CVE-2020-0984 - Secure coding XPC Services - Part 3 - Incorrect client verification", "url": "https://theevilbit.github.io/posts/secure_coding_xpc_part3/", "published_at": "2020-05-29T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18a0b7988", "title": "Kernel Debugging macOS with SIP", "url": "https://theevilbit.github.io/posts/kernel_debugging_with_sip/", "published_at": "2020-05-12T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18afa9da9", "title": "Secure coding XPC Services - Part 2 - Checking CS (CodeSigning) flags of the client", "url": "https://theevilbit.github.io/posts/secure_coding_xpc_part2/", "published_at": "2020-03-22T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18b33e45b", "title": "TALK - Exploiting directory permissions on macOS", "url": "https://theevilbit.github.io/posts/exploiting_directory_permissions_on_macos/", "published_at": "2020-03-18T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18be508ee", "title": "CVE-2019-20057 - Secure coding XPC services - Part 1 - Why EvenBetterAuthorization is not enough?", "url": "https://theevilbit.github.io/posts/secure_coding_xpc_part1/", "published_at": "2020-01-12T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18c63766c", "title": "GateKeeper - Bypass or not bypass?", "url": "https://theevilbit.github.io/posts/gatekeeper_bypass_or_not_bypass/", "published_at": "2019-10-25T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18c95b450", "title": "CVE-2020-14974 & CVE-2020-14975 - IOBit Unlocker 1.1.2 - Local Privilege Escalation", "url": "https://theevilbit.github.io/posts/iobit_unlocker_lpe/", "published_at": "2019-10-12T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18d5f6823", "title": "NOCVE - Few click RCE via GitHub Desktop macOS client with Gatekeeper bypass and custom URL handlers", "url": "https://theevilbit.github.io/posts/few_click_rce_via_github_desktop_macos_client_with_gatekeeper_bypass_and_custom_url_handlers/", "published_at": "2019-10-05T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18db14088", "title": "Shield - An app to protect against process injection on macOS", "url": "https://theevilbit.github.io/shield/", "published_at": "2019-09-22T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18e75753c", "title": "UninstallString - a possible LPE via Social Engineering", "url": "https://theevilbit.github.io/posts/uninstallstring_a_possible_lpe_via_social_engineering/", "published_at": "2019-08-09T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18eba026f", "title": "A simple protection against HMValidateHandle technique", "url": "https://theevilbit.github.io/posts/a_simple_protection_against_hmvalidatehandle_technique/", "published_at": "2019-07-31T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18f612c8a", "title": "DYLD_INSERT_LIBRARIES DYLIB injection in macOS / OSX", "url": "https://theevilbit.github.io/posts/dyld_insert_libraries_dylib_injection_in_macos_osx_deep_dive/", "published_at": "2019-07-09T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e18fe957d0", "title": "TALK - macOS - Getting root with benign AppStore apps", "url": "https://theevilbit.github.io/posts/getting_root_with_benign_appstore_apps/", "published_at": "2019-06-01T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e190720908", "title": "CVE-2020-14976 - GNS3 ubridge SETUID bit - arbitrary file read", "url": "https://theevilbit.github.io/posts/gns3_ubridge_setuid_bit_arbitrary_file_read/", "published_at": "2019-05-28T00:00:00+00:00" }, { "id": "01a087ec-ac83-7007-a3f5-87e1910c11b8", "title": "CVE-2019-5514 - VMware Fusion 11 - Guest VM RCE", "url": "https://theevilbit.github.io/posts/vmware_fusion_11_guest_vm_rce_cve-2019-5514/", "published_at": "2019-03-31T00:00:00+00:00" } ] posts Claim your blog
Back to theevilbit.github.io
Blog · corpus.blog/blogs/theevilbit.github.io/posts

theevilbit.github.io

theevilbit.github.io

2026

2025

2024

2023

2022

2021

2020

2019