| The iPhone Wiki is no longer updated. Visit this article on The Apple Wiki for current information. | 
Difference between revisions of "MobileBackup Copy Exploit"
|  (New page: BackupAgent normally restricts files to be restored to a specific set of directories ("domains").  It even has a check to ensure that ".." isn't in the path:      Path contains sneaky dots...) | m (Added to "Exploits" category.) | ||
| Line 6: | Line 6: | ||
|     Library/Preferences/SystemConfiguration/../../../../../var/db/launchd.db/com.apple.launchd/overrides.plist |     Library/Preferences/SystemConfiguration/../../../../../var/db/launchd.db/com.apple.launchd/overrides.plist | ||
| + | |||
| + | [[Category:Exploits]] | ||
Revision as of 02:58, 15 July 2010
BackupAgent normally restricts files to be restored to a specific set of directories ("domains"). It even has a check to ensure that ".." isn't in the path:
Path contains sneaky dots to traverse up outside of the domain: %@
However, for some reason, this check isn't applied when taking alternate code paths for special handling of certain files. For example, a restore to HomeDomain with a path starting with Library/Preferences/SystemConfiguration/ is migrated to the new directory for system configuration, /var/preferences/SystemConfiguration. This bypasses the sneaky dots check, so spirit is able to restore to this path:
Library/Preferences/SystemConfiguration/../../../../../var/db/launchd.db/com.apple.launchd/overrides.plist
