Meet NowSecure at r2con2024: Exploring Mobile App Security Innovations
Posted by NowSecure Marketing
The brightest minds in reverse engineering, security research and mobile app security testing will convene in Barcelona next month to explore the latest advancements in Radare2 (r2). As proud contributors to the open-source community, NowSecure experts look forward to presenting groundbreaking talks on mobile security, Frida techniques and innovative ways to enhance r2 capabilities.
About r2con2024
r2con is the premier annual conference dedicated to gathering developers of Radare2 (r2), the most popular open-source framework for reverse engineering and analyzing binaries. From Nov. 8 – 9, 2024, developers, researchers and security experts from around the globe will gather in Barcelona for r2con2024, a weekend of binary hacking know-how, education, discussion, experiments, competitions and coding.
NowSecure at r2con2024
NowSecure was founded by technology leaders in mobile cybersecurity and brings together industry-leading mobile security experts, including the creators of the Radare and Frida projects and the co-chair of the OWASP Mobile Application Security Project. Our engineers actively participate and contribute to the OSS and standards communities. Several of our top-tier researchers will present at r2con to share their knowledge (see a list of our talks below).
Additionally, if you’re interested in meeting with our team in Barcelona, we have a limited number of free guest passes to the conference. If you’d like to learn from our mobile security researchers in person, send us a message and we’ll get back to you to set up time to discuss.
As r2con2024 approaches, our team is excited to join the community to explore the latest innovations, share our knowledge and drive advancements in mobile application security.
NowSecure Presentations at r2con2024
Check out the r2con site for up-to-date schedule and agenda. Below are talks from NowSecure researchers and engineers.
- Scripting to automate and extend radare2
Presented by Pancake, NowSecure Research Engineer and Creator of Radare2
Attendees will learn how to use Python and JavaScript with radare2 to automate tasks and support new architecture, file formats, commands and io backends via plugins. We will also cover the high level and idiomatic r2papi library for easier scripting, as well as tips to make our scripts run faster.
- Frida hooking tricks for non-jailbroken iOS
Presented by Francesco Tamagni, NowSecure iOS Security Research Engineer
After removing the jailbreak superpowers, what options remain for placing Frida hooks in the context of an app process on iOS? A survey of “jailed” Frida hooking techniques and their trade-offs in terms of depth and requirements, with step-by-step practical examples where Radare2 and its dyld cache-exploring capabilities will be leveraged heavily.
- A Hitchhikers Guide for Unity: Reversing iOS games
Presented by Alex Soler, NowSecure Research Manager
This presentation will teach how to reverse engineer Unity applications on iOS. Alex Soler (Murphy) will show how to sideload the associated metadata, use r2 capabilities to symbolicate the application and decompile the code back into C#. Our main goal is to recover as much as possible of the original code and understand the game’s logic as the developer would. This will help us analyze essential parts of the app and identify critical parts, allowing us to manipulate its behavior using r2frida dynamically.
- Hack-proof your mobile apps
Presented by Carlos Holguera, NowSecure Principal Mobile Security Research Engineer
Learn how to design hack-proof apps and identify security or privacy issues in production apps for iOS and Android by using static and dynamic analysis techniques to improve your mobile app security skills. Presented by the OWASP Mobile App Security project leader, attendees will be introduced to the new Mobile Application Security Weakness Enumeration (MASWE) and dive into several practical demos.
- Combining frida-trace with radare2
Presented by Ole André Vadla Ravnås, NowSecure Security Researcher
This talk introduces the new browser-based UI in Frida-Trace, featuring Radare2 WebAssembly integration. Attendees will learn how to use a custom I/O plugin to connect with remote Frida agents, all within the browser. We’ll cover practical examples of how this setup simplifies dynamic analysis and enhances workflows, making it easier to debug and trace applications efficiently.
As r2con2024 approaches, our team is excited to join the community to explore the latest innovations, share our knowledge and drive advancements in mobile application security. Whether you’re attending talks or meeting with our researchers, we look forward to connecting and collaborating in Barcelona.