|
Most rootings/jailbreaks that have been widely released use software vulnerabilities to escalate privilege. If instead you had access to the hardware of a device, and could make any reasonable modification or intervention, how would you approach this? What techniques are used for this class of attacks? (Reasonable modifications might be things like soldering extra components, removing ICs, using oscilloscopes and data loggers - but not, say, decapping chips and imaging them in an electron microscope as presumably those resources are a lot more limited.) More practically, how might you do this on recent devices such as latest, flagship iOS, Android, or Windows Phone handsets? Are there any good, educational examples of this? |
That should give you a little bit of a feel for it. Its a fun rabbit hole to spend a few years down.