DEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security Flaws @HackersOnBoard
DEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security Flaws  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 2 days ago
We are hackers, we won't do as you expect or play by your rules, and we certainly don't trust you. JAR files are really ZIPs…unzip them! So are Microsoft's DOCX, XLSX, PPTX, etc. Let's open them up! macOS applications (.app "files") are really directories you can browse?! Sweet, let's do that.

Less well known but similarly prevalent are Flat Package Mac OS X Installer (.pkg) files. These are actually XAR archives that, among other things, contain many plaintext files (including shell, Perl, and Python scripts) as cpio files compressed using gzip.

In this presentation I'll walk you through extracting the contents of these installer packages, understanding their structure, and seeing how they work while highlighting where security issues can come up. To drive the point home of what can go wrong, I'll include examples of serious security issues I've seen in the wild and show you how they can be exploited to elevate privileges and gain code/command execution.

After this talk, .pkg files will no longer be opaque blobs to you. You'll walk away knowing tools and techniques to tear them open, understand how to evaluate what they're really doing on your computer, and a methodology for finding bugs in them. As a final bonus, I'll include a subtle trick or two that can be used on red teams.


Talk by Andy Grant
DEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security FlawsBlack Hat USA 2018 - Dissecting Non Malicious Artifacts One IP at a TimeDEF CON 27 - Brent Stone - Reverse Engineering 17 plus Cars in Less Than 10 MinutesDEF CON 27 - Bruce Schneier - Information Security in the Public InterestDEF CON 27 - Brad Dixon - Cheating in eSports How to Cheat at Virtual Cycling Using USB HacksBlack Hat USA 2018 - Hardening Hyper V through Offensive Security ResearchDEF CON 27 - Daniel ufurnace Crowley - Practical Key Search Attacks Against Modern Symmetric CiphersBlack Hat USA 2018 - How can Someone with Autism Specifically Enhance the Cyber Security WorkforceDEF CON 27 - Xiling Gong - Exploiting Qualcomm WLAN and Modem Over The AirBlack Hat USA 2018 - Automating Exploit Generation for Arbitrary Types of Kernel VulnerabilitiesBlack Hat USA 2018 - Another Flip in the RowDEF CON 27 - g richter - Reverse-Engineering 4g Hotspots for Fun Bugs and Net Financial Loss
HackersOnBoard |

DEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security Flaws

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER