skip to main content
10.1145/2857546.2857555acmconferencesArticle/Chapter ViewAbstractPublication PagesicuimcConference Proceedingsconference-collections
research-article

HTML and PDF fuzzing methodology in iOS

Published: 04 January 2016 Publication History

Abstract

iOS is well-known operating system which is strong in security. However, many attacking methods of iOS have recently been published which are called "Masque Attack", "Null Dereference" and "Italy Hacking Team's RCS". Therefore, security and safety is not suitable word to iOS. In addition, many security researchers have a problem to analyze iOS because the iOS is difficult to debug because of closed source. So, we propose a new security testing method for iOS. At first, we perform to fuzz iOS's web browser called MobileSafari. The MobileSafari is possible to express HTML, PDF and mp4, etc. We perform test abnormal HTML and PDF using our fuzzing method. We hope that our research can be helpful to iOS's security and safety.

References

[1]
Collin Mulliner, Charlie Miller. 2009. Fuzzing the Phone in your Phone, Black Hat USA 2009
[2]
Chen Xiaobo, Xu Hao, 2012. Find Your Own iOS Kernel Bug, Power of Community 2012
[3]
Nam Daehyeon, 2014, Making iOS MobileSafari Fuzzer and Fuzzing, CodeEngn Conference 11
[4]
Je-gyeong Jo, Jae-cheol Ryou, 2015, Method of Fuzzing Document Application Based on Android Devices, Vol 25, Feb. 2015, 31-37, Journal of The Korea Institute of Information Security & Cryptology
[5]
maintained by Martin Szulecki, Libimobiledevice, http://www.libimobiledevice.org/
[6]
Fuzz Testing, https://en.wikipedia.org/wiki/Fuzz_testing
[7]
Header Field Definitions, http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html
[8]
Isa56, OpenJailbreak, fuzzyDuck & iOS fuzzing, Nov. 2013, http://www.isa56k.com/2013/11/openjailbreak-fuzzyduck-ios-fuzzing.html

Index Terms

  1. HTML and PDF fuzzing methodology in iOS

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Conferences
    IMCOM '16: Proceedings of the 10th International Conference on Ubiquitous Information Management and Communication
    January 2016
    658 pages
    ISBN:9781450341424
    DOI:10.1145/2857546
    © 2016 Association for Computing Machinery. ACM acknowledges that this contribution was authored or co-authored by an employee, contractor or affiliate of a national government. As such, the Government retains a nonexclusive, royalty-free right to publish or reproduce this article, or to allow others to do so, for Government purposes only.

    Sponsors

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 04 January 2016

    Permissions

    Request permissions for this article.

    Check for updates

    Author Tags

    1. Fuzzing
    2. HTML
    3. Jailbreak
    4. MobileSafari
    5. PDF
    6. iOS

    Qualifiers

    • Research-article
    • Research
    • Refereed limited

    Funding Sources

    Conference

    IMCOM '16
    Sponsor:

    Acceptance Rates

    Overall Acceptance Rate 213 of 621 submissions, 34%

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • 0
      Total Citations
    • 221
      Total Downloads
    • Downloads (Last 12 months)6
    • Downloads (Last 6 weeks)0
    Reflects downloads up to 28 Feb 2025

    Other Metrics

    Citations

    View Options

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Figures

    Tables

    Media

    Share

    Share

    Share this Publication link

    Share on social media