#development

1 messages · Page 93 of 1

torn oriole
#

Sandboxes thishowitis

faint stag
#

sometimes you gotta let some sand escape the box

indigo peak
#

@primal perch how do i find offset for class in ida

#

nvm

#

we good

#

i think

native orbit
#

wayback time

radiant idol
#

so true

quaint wagon
#

So i know adobe makes a drag and drop kinda software to make websites like dreamweaver but is there anything else software not web that can do the same thing?

visual meadow
#

any binary signed with platform-application on ios can spawn binaries right

visual meadow
#

Just to be sure

frail cedar
visual meadow
frail cedar
#

?

#

use that to spawn

visual meadow
#

Im just saying, can binaries with platform-application spawn

#

Im trying to brainstorm ideas for trollstore install method

frail cedar
#

i believe they used to

#

but not anymore?

#

unsure

visual meadow
#

Yk

timid furnace
#

Already tried looking at that when a previous exploit came out

#

nothing you can use

faint stag
spare stone
#

hi im trying to run this unity ios game on mac with PlayCover, but it crashes when it tries to download the game assets

it tries to load a file that doesn't exist, does that mean my decrypted IPA is fucked up something?

if anyone knows about reversing unity ios games pls help

faint stag
#

i mean if it works on ios and not a mac then it's probably doing something that's intended to work on ios only

spare stone
#

i haven't tested it on IOS i don't have a jailbroken phone atm

#

could my IPA be missing files though since I didn't get it directly from my phone

faint stag
#

possibly? idk

spare stone
#

hmmm ok

#

thank u

#

do u know of a way I can pull a decrypted IPA off my non jailbroken iphone?

#

lol i have no friends Sadge

#

can you dump the app CarX Street for me? Prayge

faint stag
#

oh wait ios is just lying to me

#

smh

spare stone
wheat grotto
#

dick

sonic totem
#

To spawn as mobile even

timid furnace
#

Yea no posix_spawn without unsandboxing

#

persona-mgmt wont help you either, must be unsandboxed to posix_spawn at all

sonic totem
#

persona-mgmt is just for spawning them as root

dull stone
#

hello everyone, i have a theos project but i want to make it work on Rootless Dopamine. I tried adding THEOS_PACKAGE_SCHEME = rootless and make it but it doesn't work while Rootfull works fine, what is the reason?

native dune
#

What doesn’t work

#

If you have hard coded paths you need to use ROOT_PATH_NS from rootless.h

sonic totem
#

Thinking of writing another blog post - how interesting/appreciated would a post on the actual ‘signing’ part of code signing?

harsh junco
#

Sounds fun

sonic totem
#

Like it would explain how the entire code signature is structured, how the signature is generated, and then probably how we use it in the CoreTrust bypass.

#

I mean it would probably be a series of posts but it would be useful to dump all my knowledge anyway

radiant idol
#

If you're up for it, more documentation is always good lol

sonic totem
#

I was just thinking documentation on the actual “signing” part would have been so useful for me

#

Ended up having to read the CMS spec for one part

radiant idol
#

I think it's wise to do some documentation on that

wooden yarrow
sonic totem
#

I think it would be more of a “how to generate your own valid signature” kinda thing

#

So yeah, you can use OpenSSL, but it’s more of how to use it

wooden yarrow
#

ah alright

#

cool yeah i think that'll be a nice blog post

sonic totem
#

Well I’ll try and get the first one done over the next few days at least 😄

ocean raptor
ocean raptor
#

Also figure out how codesign decides whether or not to scatter so that I can add that to ldid

#

(I hate codesigning so much)

#

Also execSeg makes no sense

sonic totem
ocean raptor
sonic totem
sonic totem
#

To prevent trickery

indigo peak
#

@sonic totem i looked into JIT in gamepigeon more, and it turns out that getppid returns 1 when ran on MessagesExtension (where all the actual games are: the app inside imessage), and TrollStoreJitEnabler only runs ptrace me if getppid() != 1

sonic totem
#

How is it getting the PID of launchd supershocked

indigo peak
#

idk maybe iOS handles the launch of imessage extensions special or smth

#

idk

#

yeah cocoatop also says ppid is 1

#

tf

sonic totem
#

What??

#

Is this the same for any iMessage app?

indigo peak
#

idk lemme check

#

@sonic totem im getting 1 for legit every app on jb ios

granite frigate
sonic totem
#

BeReal installed via TrollStore?

indigo peak
#

no appstore

faint stag
indigo peak
visual meadow
indigo peak
#

im so confused

#

bc ptrace never gets called

#

yk

visual meadow
#

it fails on posix_spawnp

#

because sandbox thinks its forking

#

which is

#

weird

indigo peak
#

nathan eta kid

restive ether
#

6s

faint stag
visual meadow
#

tried both

#

but ellekit thing might just sidestep all of this entirely

elder scaffold
#

@visual meadow wen eta

native orbit
native orbit
#

crazy

native orbit
#

real

#

why people making whole ass copies of system apps to just get some janky tweak injection 💀

radiant idol
visual meadow
#

my phone bootlooped

#

well springboard was crashing you could say

#

it was kinda a bootloop i guess

#

but i had to update

radiant idol
#

rip

visual meadow
#

that was when i had an xr

native orbit
#

some many people gonna bootloop cuz those devs dont know what they doing

visual meadow
#

whenever i get trollstore on my 14pm tho

visual meadow
#

imma implement screendump into a app

hasty ruin
#

and opainject*

native orbit
hasty ruin
#

fr

radiant idol
#

people always ask how is swiftui but they never ask why is swiftui

native orbit
#

true

hasty ruin
#

yeah why was it made

native orbit
#

uikit will always clear

radiant idol
#

pov trying to hook an ivar in a swift object:

naive kraken
native orbit
#

pov hooking a string troll

naive kraken
#

other than that, no clue

visual meadow
hasty ruin
#

some apple dude: "hm, uikit is getting too easy... let's replace it with something that lacks features and is littered in bugs"

visual meadow
#

its posix_spawn lol

radiant idol
#

funni

native orbit
#

(runtime one)

radiant idol
#

ya

#

but still

#

scary stuff

visual meadow
#

you guys think i could do some funny stuff with this to get trollstore? 💀💀

radiant idol
#

now fix the static one đŸ”«

native orbit
#

s0n

heavy pebble
#

Alguien me puede ayudar? Compre carbridge y no se como instalarlo, y en el correo dice que primero tengo que hacer un jailbreak

radiant idol
visual meadow
#

ptsd iphone xr

granite frigate
#

trollstore need

radiant idol
heavy pebble
#

iPhone 15 pro Max y 17.2

indigo peak
radiant idol
sonic totem
#

So code slot hashes are correct for an encrypted binary, so what’s the process of running such a binary? Validate encrypted pages -> decrypt binary -> load into memory?

radiant idol
#

necesitas un jailbreak para usar CarBridge

radiant idol
heavy pebble
radiant idol
#

no puedes hacer jailbreak. Tu teléfono es muy nuevo y también tiene una versión actualizada de iOS. no puedes hacer jailbreak a ese dispositivo

heavy pebble
#

No pues entonces no sirviĂł la compra, gracias por ayudarme

radiant idol
#

ningĂșn problema

heavy pebble
#

De casualidad sabrĂĄs cĂłmo puedo ver youtube en mi coche con este celular?

radiant idol
#

No lo sé. No creo que sea posible hacer eso sin jailbreak.

heavy pebble
#

Gracias

topaz yew
#

offsets offsets offsets...

slender glade
#

the other ur talking english

#

and now spanish

#

he think everything a fucking game

radiant idol
cloud yacht
#

If so maybe you could get that one app that one dude made working in it

#

This ^

indigo peak
#

and if it’s possible to keep it alive

#

like is it “Game Pack”

#

or is it some service that iMessage uses to spawn MessagesExtension

naive kraken
#

the point of the JIT enabler is, you spawn some process and that does ptrace

indigo peak
naive kraken
#

and ptrace sets debugging flags on both parent and itself

#

like pkd sends request to launchd and launchd spawns process

#

that's also how apps are spawned

indigo peak
naive kraken
#

posix_spawn some process, that process does that attach myself thingy with ptrace

#

both processes get debug flags

indigo peak
#

hmmmm

#

I wonder

#

If the reason why

#

posix_spawnp doesn’t work

#

Is because it’s a message extension

#

and they can’t be launched thay way

#

yk

#

or am I just slow

sonic totem
visual meadow
sonic totem
#

So that I don’t need to use SideStore

timid furnace
sonic totem
#

So I don’t understand why resigning an encrypted binary doesn’t work

#

Like if you install with TrollStore

#

And bypass installd all together

#

What’s the issue?

timid furnace
#

Do you have the fairplay data alongside it

sonic totem
#

I’m not sure

#

It’s not a specific binary

#

Just a general question

#

Is FairPlay tied to the code signature?

timid furnace
#

No

#

Apple binaries are signed by the same certificate and stuff

#

But in order for decryption to work you need the fairplay data, and that's tied by account

sonic totem
#

Where is that FairPlay data stored?

#

Is it just fetched from the App Store when you download the app?

timid furnace
#

SC_Info

#

Yes

#

I believe it is bundled with the ipa

sonic totem
#

Ohhh right

#

So what if you preserve the original SC_Info and then re-sign with the bypass?

timid furnace
#

No clue

#

try it

sonic totem
#

Another time 😅

frank fossil
indigo peak
frank fossil
indigo peak
fluid lintel
primal perch
#

@hasty ruin

harsh junco
#

Developers Developers Developers Developers

primal perch
#

Developers Developers Developers Developers

native dune
#

Yorn

primal perch
#

Yorn

blazing warren
#

Yorn

indigo peak
#

@naive kraken hypothetically:
so if ptrace me debugs the child AND the parent process

wouldn’t it theoretically be possible to
make a root helper that calls ptraceme
spawnRoot the ptrace root helper
and then since MessagesExtension is the parent process to ptracerh, it should be debugged

naive kraken
#

That's also what is being done for apps

indigo peak
#

it doesn’t need any special checks or anything

#

just needs get-task-allow and sandbox entitlements

indigo peak
# naive kraken that's what I said

root helper:

int main(int argc, char **argv) {
    ptrace(PT_TRACE_ME, 0, 0, 0);
    return 0;
}

tweak:

%ctor {
  int ret = spawnRoot([[NSBundle mainBundle] pathForResource:@"TrollStoreJitEnabler" ofType:nil], @[], &stdOut, &stdErr);
  NSLog(@"[ptrace] %d", ret);
  NSLog(@"[ptrace] %@", stdOut);
  NSLog(@"[ptrace] %@", stdErr);
}

logs

kernel    Sandbox: MessagesExtension(22433) deny(1) process-fork
MessagesExtension    posix_spawn error 1
MessagesExtension    [ptrace] 1
MessagesExtension    [ptrace] (null)
MessagesExtension    [ptrace] (null)
faint timber
#

congradjulate the non swift dev

faint timber
#

unless you are snapchat

torn oriole
#

hes jealous

faint timber
#

used to spam fork on unc0ver

#

froze device

slender glade
slender glade
#

I see y'all aren't actually part of the #antoine squad...

dull stone
#

Hello everyone, how to compress binary font file to C format?

sonic totem
slender glade
gaunt helm
gaunt helm
#

how much is it

slender glade
#

1.50

#

it had like 200 downloads everyday before I made it paid

gaunt helm
#

@thin valley ayo are u here

slender glade
#

that shit is ZERO now

slender glade
thin valley
#

What’s up

gaunt helm
#

gm

thin valley
#

Gm!

gaunt helm
#

can i get a 5 copies of antoine giveaway

slender glade
#

WHAT

thin valley
#

You can

#

Coming up!

gaunt helm
#

that would be awesome thank u

slender glade
#

HAH

#

😭 wtf

#

thank u both sm

gaunt helm
#

u deserve it

thin valley
#

How long?

gaunt helm
#

1 day ig?

thin valley
#

Bet

gaunt helm
#

đŸ€

slender glade
steady nest
slender glade
#

actually i'm not sure abt that lol

acoustic imp
#

Is there a way I can make these thing pop up ? Like make my own ?

#

Or does anyone know of a tweak that does this and is open source?

slender glade
#

starts with a B

#

lemme find it

acoustic imp
#

K thx

#

Can like regular apps use it ?

gaunt helm
#

@lime pivot

slender glade
gaunt helm
#

i assume not since it's not bound to your account

slender glade
gaunt helm
slender glade
#

I appreciate it sm đŸ«¶

gaunt helm
#

give it a bit i'm sure the sales will start coming soon

hasty ruin
#

fixed btw

acoustic imp
slender glade
#

BannerKit

#

@indigo kraken knows more about it

acoustic imp
#

ok thanks

cloud yacht
brazen timber
#

@primal perch @hasty ruin average rust users be like

#

this is marked as an error btw

cloud yacht
#

Really?

brazen timber
#

the java class and mach-o magic bytes are a bit too âœšđŸ’â€â™€ïžđŸ’… __problematic__đŸ’…đŸ’â€â™€ïžâœš

cloud yacht
#

That's crazy

#

What problems does it cause

brazen timber
indigo peak
# naive kraken you're too sandboxed

which process, game pigeon?

I gave MessagesExtension the entitlements to disable sandbox

I wonder if that’s because it’s inside of iMessage

topaz yew
#

why does trash take so long to open on macos fr

brazen timber
primal perch
#

fr

#

linux + windows gigachad gigachad

slender glade
brazen timber
slender glade
#

that's none of the compiler's business

brazen timber
#

cringe authoritarian rustc vs chad libertarian clang

visual meadow
slender glade
#

you sent a photo showing that you are too sandboxed

visual meadow
slender glade
#

i dunno

slender glade
#

if you use that const

#

or any of those

#

will it not compile

brazen timber
#

so you can't compile cargo or the standard library with those numbers

#

or anything else in the rust project

#

not as bad as you think lol

native orbit
visual meadow
#

please help

slender glade
#

Result too large

brazen timber
#

i prefer 0xCAFEBABE

native orbit
#

all the macho ones kinda hit ngl

hasty ruin
#

isnt cafebabe java classes too

visual meadow
#

yes

native orbit
#

fuck java

visual meadow
#

yes

radiant idol
#

so true

brazen timber
native orbit
#

hm

radiant idol
#

system dot out dot print line me some money

cloud yacht
brazen timber
#

I can't understand that

#

babe is gendered so we can't have it any of the code bases guys

native orbit
radiant idol
#

true

brazen timber
indigo peak
#

@visual meadow i just tried to access a file in /var/mobile/Documents/ and it wouldn't work

brazen timber
#

cafe babes unite!

indigo peak
#

error: Error Domain=NSCocoaErrorDomain Code=257 "The file “Tokens.log” couldn’t be opened because you don’t have permission to view it." UserInfo={NSFilePath=/var/mobile/Documents/Tokens.log, NSUnderlyingError=0x282aca5b0 {Error Domain=NSPOSIXErrorDomain Code=1 "Operation not permitted"}}

visual meadow
#

Classic Tokens.log

radiant idol
indigo peak
visual meadow
#

yes

#

idkm

radiant idol
#

#

hasty ruin
#

petition to remove dev role from all swiftui users

native orbit
#

C#

visual meadow
#

maybe its because of blastdoor shit????

radiant idol
native orbit
radiant idol
native orbit
#

real

radiant idol
#

you literally added raw pointers to swift

indigo peak
brazen timber
radiant idol
native orbit
#

swift assembler uhhsweat

slender glade
hasty ruin
hasty ruin
#

yes we are

radiant idol
native orbit
slender glade
radiant idol
#

objc >>>

brazen timber
slender glade
radiant idol
#

this is swift

brazen timber
#

that is

native orbit
#

lmao

brazen timber
#

not

#

valid c++

#

.

native orbit
#

that pure swift

slender glade
#

This is not swift

hasty ruin
#

almost 2024 and doesnt know what c++ is

radiant idol
slender glade
#

oh I didn’t see the var keyword

#

my b in re

hasty ruin
indigo peak
brazen timber
#

you cannot use ->
or var it's auto

#

or do cringe: type

radiant idol
#
func main() -> Int {
    var joe: Int = 420;
    printf("joe: %d\n", joe);
    joe++;

    printf("joe: %d\n", *(&&joe));
    return 0;
}
#

swift

slender glade
brazen timber
#

&& is that place is not valid c++

slender glade
#

and the last

#

don’t blame me blud.

native orbit
#

variadic haxx

radiant idol
#

swift trying to not make everything into pure crap challenge

brazen timber
slender glade
radiant idol
#

looks like it

native orbit
#

no

slender glade
radiant idol
#

oh

#

L

brazen timber
native orbit
#

va bridge will forever be broken

#

you have to generate asm code at runtime for it

radiant idol
#

swift is built on bridges
swift is a bridge

native orbit
#

map it

#

and call it

hasty ruin
radiant idol
#

statur seems like he enjoys assembly

#

đŸ€ą

native orbit
#

its wonderful

hasty ruin
#

better than sw*ft

brazen timber
#

imagine not enjoying assembly

brazen timber
radiant idol
#

if its so wonderful why is someone avoiding macho

#

trol

brazen timber
#

not a hard bar to cross

radiant idol
#

nah im kidding

native orbit
#

stock swift mids

radiant idol
#

cmon icraze

#

after all this time

#

you should know this by now

radiant idol
#

shtu up

#

shut

hasty ruin
#

shtu

brazen timber
radiant idol
#

youre literally british

#

as i have stated many times

native orbit
#

gottem

hasty ruin
#

wtf couch emoji new

#

đŸ›‹ïž

radiant idol
#

youre a couch

visual meadow
#

đŸ›‹ïž

radiant idol
#

take that

native orbit
#

reminder

radiant idol
visual meadow
#

call me the

native orbit
hasty ruin
#

@torn oriole nightwind is ABUSING PERMS

radiant idol
#

stop spamming logs icraze

hasty ruin
torn oriole
#

Racist

radiant idol
#

its not nice

elder scaffold
radiant idol
#

so true

hasty ruin
#

thanks x

native orbit
#

imagine if apple just blocked objc from working after swift dropped

hasty ruin
#

end of apple

native orbit
#

ong

radiant idol
#

jailbreak the compiler

#

to allow objc

native orbit
#

compile by hand

radiant idol
#

write the asm by hand

hasty ruin
#

what if they remove the runtime

radiant idol
#

hm

#

fish one out of an old device and reverse enginner it

#

reverse engineer the entire objc runtime

hasty ruin
native orbit
#

just write a new lang galaxybrain

radiant idol
hasty ruin
#

some american ate them

radiant idol
radiant idol
cloud yacht
brazen timber
radiant idol
#

js is fine

#

if you do things "properly"

cloud yacht
#

I don't

#

But I have fun

#

So that's fun

radiant idol
#

real

proper reef
#

Isn’t swift a bastardized version of objc?

#

Anyways I want to get back in to iOS development - there’s just one problem

proper reef
cloud yacht
#

Like no idea, as in you don't have any idea of what to make, or your not sure where to start?

visual meadow
#

will you give them Zefram source

native orbit
#

infiniboard intjpray

visual meadow
#

ok

topaz yew
#

zefram malware

visual meadow
#

owe you what

radiant idol
#

why do you want it so bad

native orbit
#

cuz its god tier

topaz yew
#

with kfd you can only overwrite files in var right

radiant idol
#

anything capt wants

#

is horrible

#

you should know this by now

turbid fjord
#

You are a strange creature

visual meadow
#

does anyone here know a alternative to MSHookMemory that doesn't need jit

native dune
#

i dont think there is one

visual meadow
#

death

#

surely there is 😭

native orbit
#

what you trying to even hook

visual meadow
#

its the extend lines thing in 8 ball

#

im trying to find a way to yk

#

not need jit

#

its fiores thing but im looking too lol

native orbit
#

is the line length dynamic?

visual meadow
visual meadow
native orbit
#

the game installed with TS right?

visual meadow
native orbit
#

just patch the bytes and resign, then install again

visual meadow
#

like

#

that would just make it forced

#

lol

#

cant turn it off

native orbit
#

could patch it to reference a value in rw mem that you change then

visual meadow
#

that'd be annoying to do lol

indigo peak
#

0x52a9cdc8

native orbit
#

send the bin

#

ill do some hax

#

im bored

visual meadow
native orbit
#

how install this to test lol

visual meadow
native orbit
#

might be easier yeah

visual meadow
#

I can test it
what are you changing anyways

native orbit
#

not sure yet, ida loading

visual meadow
native orbit
#

@indigo peak whats the stock value for it

visual meadow
#

Idk

visual meadow
#

O

indigo peak
#

0x1000e4e18

native orbit
#

thats a better addr lol

native dune
#

nerd chat

indigo peak
#

ida_kernwin.jumpto((0x1000e45b8 + 0x860))

lime pivot
indigo peak
#

0x1000e45b8 is mMove start
0x860 is the offset

lime pivot
native orbit
indigo peak
#

yeah ik

native orbit
#

ieee754 moment

ocean raptor
timid furnace
#

why are you getting a DRAMless SSD

native dune
#

yeah get one with a dram cache

#

and why ryzen

ocean raptor
#

Fixed

native orbit
#

ryzen better Shrugg

native dune
#

yeah the p5 plus is better

ocean raptor
#

I like crucial

native dune
timid furnace
#

does the PSU make sense idk

#

idk how much wattage CPUs and GPUs use these days

native dune
#

you can probably get away with a 650 W but 750 is fine

timid furnace
#

so 4070 is not a power sucker like the other ones right

native dune
#

idk

ocean raptor
indigo peak
#

@native orbit @visual meadow

#

tf did I do

visual meadow
#

lol what did you do

native orbit
#

what u set it to 💀

native dune
#

what about a liquid cooler

timid furnace
#

yea 750W should be fine

indigo peak
lime pivot
native dune
#

id make some changes to this list but im currently editing a list and i dont want to lose it lmao

radiant idol
native orbit
#

cwift

radiant idol
native dune
native orbit
radiant idol
#

English doesn’t work like that I’m afraid

timid furnace
radiant idol
#

This one is tolerable

native orbit
#

swift++

radiant idol
#

Swift except with :: everywhere*

timid furnace
#

well it's a mini itx case

#

i presume they want smol pc

ocean raptor
#

So it’s small

ocean raptor
#

My desk isn’t that big


native dune
#

ok

lime pivot
#

oh and NR200

#

bro’s onto a winner

native dune
#

yeah it seems like a nice setup

lime pivot
#

just make sure the cooler will have enough clearance in the case, I just bought that Thermalright so I can find out for you if you’re curious lol

pearl sail
ocean raptor
hasty ruin
raven maple
#

Hey everyone! Maybe someone can help me. I discovered that after I did login -fp mobile (like NewTerm3 does to open a shell) pseudo whoami always returns mobile. pseudo is this GitHub project. And to be clear I use an iPhone 11 with iOS 15.6RC2. Any idea?

ocean raptor
#

Any 27” 4k monitor recommendations?

proper reef
#

time to attempt to set up a decent development environment

#

Aaand I can’t jb my phone

primal perch
indigo peak
#

so what about LHPatchMemory/MSHookMemory breaks codesign- like what part of it fucks it up

primal perch
#

the fact that it’s runtime code modification

ocean raptor
primal perch
#

for me easily

proper reef
#

For me not at all

primal perch
#

realistically there’s no gain if you don’t play games but it’s smoother

proper reef
#

It’s whether you personally think it’s worth it

indigo peak
primal perch
#

the same reason is for both

#

mshookfunction is on principle basically mshookmemory reskinned just with some orig convenience

indigo peak
#

but then how does fishhook allow for c hooking without fucking it up

primal perch
#

idk

#

magic or some shit

#

anything off rtings is pretty legit

#

s2722qc or s2721qs are solid for cheap

proper reef
#

Time to figure out how to develop tweaks without a jb

ocean raptor
#

That way I can get 2 and stay in my budget

topaz yew
#

how do you make a symlink vnode

brazen timber
ocean raptor
granite frigate
ocean raptor
pearl sail
#

You were like 5 years old shut up

gentle grove
#

since new gen is out

ocean raptor
gentle grove
#

its like the same price as 7950x3d it looks

#

and like $30 more than the 13900k

#

idk if the 7950x3d and 14900k are very different

ocean raptor
#

Oh, I was looking at something different

#

Don’t remember what now

#

i9-14900k has 24 cores


#

vs 16 of 7950x3d

gentle grove
#

is that 40 threads on the 14900k

#

oh no

#

i cant count

#

no i can count but i cant read

pearl sail
#

Yes

gentle grove
#

i would probably pick the 14900k, especially because ddr5 might not be great on amd

#

but idk

native orbit
#

maybe its just zefram trol

ocean raptor
#

Did some changes

#

Using a 240 AIO and got 3 case fans

granite frigate
#

hi everyone what are your thoughts on this guy? he has shown flex, springboard actually responding, and the camera bump + dynamic island and serial number https://vxtwitter.com/lfy_trav/status/1736595789382619197 unless i’m being blind or something he’s proven it’s not fake

@_AppleiOS @alfiecg_dev Flex injects into springboard as well✅ but it’s very buggy and causes device to crash when scrolling through ui. Still a work in progress

💖 0

▶ Play video
radiant idol
#

Looks pretty legit


granite frigate
#

yeah i also thought it was fake

#

but the new video shows its pretty legit

ocean raptor
#

They’re always fake

#

Faking the version shown in settings is so easy

granite frigate
radiant idol
radiant idol
ocean raptor
#

What is DI?

granite frigate
#

Dynamic Island

radiant idol
#

Dynamic island

ocean raptor
#

iOS 15 didn’t have Dynamic Island?

radiant idol
#

No

#

See

#

You can’t fake hardware

#

No notch

ocean raptor
#

Screen record, video edit, play video

radiant idol
#

Maybe

#

But idk

granite frigate
#

Gotta be really convincing to fake gestures

radiant idol
#

Yeah

topaz yew
#

def fake

radiant idol
#

thats the thing

#

it looks pretty legit

granite frigate
#

it’s legit

#

I checked the serial

radiant idol
#

yes

#

it also does match with an older screenshot he posted

granite frigate
granite frigate
radiant idol
ashen birch
ocean raptor
#

I don’t know anything

topaz yew
#

hmm

radiant idol
#

lets see what the guy says when he finishes typing in #jailbreak

granite frigate
#

oh he’s typing

#

ok cool

radiant idol
#

hmm he stopped

indigo peak
radiant idol
#

jk ily fiore

indigo peak
granite frigate
cloud yacht
granite frigate
#

yeah the video isn’t super long

cloud yacht
#

Also the settings app launches weirdly

#

Maybe it's some kind of fake springboard

torn oriole
#

Look when he tries to exist the fuckin hierarchy tree

#

Looks like the input should have hit but it just doesn’t

granite frigate
#

Prolly yeah

#

That’s the most obvious explanation

timid furnace
#

Just ask them for technical proof lmao

#

Something to test whether they actually know enough in order to pull things off

granite frigate
dull tiger
#

lol

slender glade
granite frigate
#

Huh ok

slender glade
restive ether
#

your mom can be faked

granite frigate
# slender glade Proven?

The second one was just a screenshot of springboard, the first one could have just been a recording

native dune
slender glade
#

@granite frigate this is fake as fuck man

granite frigate
#

how man

#

im blind

slender glade
#

everything abt this is just kinda

#

like

#

open this dude's profile

granite frigate
#

yeah I know

#

he’s so sus

slender glade
#

dog

granite frigate
#

but idk how it’s faked

slender glade
#

this is like

#

if gordon ramsey became the president tomorrow

#

like that shit just cannot happen man

granite frigate
#

fr

slender glade
#

is he here

#

@tepid olivey_trav

restive ether
#

anyone who moves that much while recording a video is clearly hiding something

hasty ruin
#

He also said he had tweak injection like 3 weeks ago

#

(He literally just installed apps manager via trollstore)

radiant idol
slender glade
#

okay this is just fake then

pearl sail
#

Nah it is real

#

Y’all more fake than this jailbreak

summer zealot
#

Gm

west bloom
#

But how can this be faked?

ashen birch
#

sup cornballs

#

how yall doin

radiant idol
#

hello adam

west bloom
radiant idol
#

it isnt injected into the photos app

#

it is injected into springboard

west bloom
#

Ohhhh

#

So then is this fake?

#

I am so confused

radiant idol
#

SpringBoard is the homescreen

#

so no

#

unless this was faked some other way

#

it isnt fake

west bloom
#

So a random guy found a way to inject tweaks on 16.5 with iPhone 14 pro max

radiant idol
#

lol

#

I am quite confused myself

west bloom
#

I was the person that got him test atria

#

3 weeks ago he said it safe moded him

#

So then the other videos wasn’t fake or?

radiant idol
#

no

#

the other two

#

are fake

#

this one is also probably fake but I cant think of how one would fake it

west bloom
radiant idol
#

afaik, no

#

unless he somehow made an app that is a video viewer without having those bars

#

but that's a stretch, considering the gestures he's doing

west bloom
#

Because I think if you look at the video in slow motion it’s going faster then he taps

radiant idol
#

wdym

summer zealot
#

I am confusion

radiant idol
summer zealot
west bloom
# radiant idol wdym

So the person I know says it’s a video right. And he just taps where he taps in the video

granite frigate
#

he probably moved the camera away when he fucked up the taps

#

now that i think about it

radiant idol
#

possibly

#

but why not just re record

granite frigate
#

true

#

how do you swipe up on your phone without exiting your app

#

wtf

radiant idol
#

yea

radiant idol
#

hmmmmm

summer zealot
#

Quick question, does anyone know that date that google TAG adheres to the 90 disclosure policy

radiant idol
#

21

#

afaik

granite frigate
#

oh sorry

summer zealot
#

Awesome

summer zealot
random field
#

does theos support adding frameworks with spm in the package file?

west bloom
#

In the end when he is exiting flex

summer zealot
#

As far as I understand we have a poc for two CVES patched on 17.0.1 right

#

Just missing the kern exploit ?

sonic totem
#

So anytime after December 21st we can expect the writeup

radiant idol
summer zealot
#

Alright would that be posted on google project zero or the google tag page

sonic totem
#

Well its not Project Zero

#

So it would be TAG page

summer zealot
#

👍

west bloom
#

This is so weird

radiant idol
#

Alfie, what do you think

#

is this video faked

sonic totem
sonic totem
sonic totem
#

But they went to such effort to fake the first three or wahtever

#

They must have found a way to fake this one too

radiant idol
summer zealot
radiant idol
summer zealot
#

One thanks to you 😁

west bloom
#

He wil prob be back

#

With more videos

sonic totem
radiant idol
#

yea

summer zealot
west bloom
#

Also he says in the video: please don’t crash bitch

radiant idol
#

oh what

sonic totem
#

But we only need the kernel exploit for installing TrollStore

radiant idol
#

I had it muted lol

#

lets see

west bloom
native dune
#

idk how flex would be unstable but ok

radiant idol
#

sometimes

#

on iOS 15+

west bloom
#

Crashes my phone too

#

Also why didn’t he just say that he achieved this 3 weeks ago. Why wait

summer zealot
#

@sonic totem in the past have they released just a write up or a full poc? Trying to see from a developer point of view how difficult it would be to write a poc from just a write up

west bloom
#

Ppl in another server says he is a known faker

#

They also say it’s probably a fake springboard

radiant idol
#

lol what

summer zealot
#

Fake springboard?

#

How is that possible lol

west bloom
sonic totem
sonic totem
west bloom
sonic totem
radiant idol
#

Yeah that's what I said but the gestures, idk

sonic totem
#

They've just written a fake SpringBoard in SwiftUI

west bloom
#

But why just don’t do that from the beginning

sonic totem
#

Because it was easier to fake it on an iPhone X

summer zealot
radiant idol
#

on the "SpringBoard"

native dune
#

do they have mdc

#

if so they can hide it

sonic totem
proper reef
#

Isn’t there that weird kiosk mode thing

west bloom
native dune
#

or kfd yeah

west bloom
#

They on 16.5

harsh junco
west bloom
#

They say

sonic totem
summer zealot
#

Wow

radiant idol
#

@sonic totem @native dune but it is not hidden when they enter the "Settings" app, this behavior is consistent with the regular behavior of the homebar

native dune
#

weird

summer zealot
#

Yeah I’m trying to load a kernel cache into ghirdra but I don’t know what I’m doing 😭

#

I might not have the right tools

radiant idol
harsh junco
#

homebar.gif

west bloom
summer zealot
#

😂

#

@sonic totem if you don’t mind me asking do you use ghirdra or binja?

sonic totem
granite frigate
#

is there a difference

velvet path
#

frankly why trust them if they've faked it three different times

sonic totem
#

YouTube it

#

And see

summer zealot
radiant idol
sonic totem
#

There's some good videos there

native orbit
#

just ask them some techinal question about to cofirm fr

west bloom
granite frigate
#

there is 0 things i can sus out

sonic totem
#

Entitlements, root, trustcache

#

etc.

#

But since CoreTrust is part of PPL

#

A CoreTrust bypass is technically a PPL bypass

radiant idol
#

someone's gonna take a screenshot of those messages and post them on twitter

#

good luck

#

:P

granite frigate
#

:P

sonic totem
#

TROLLSTORE DEVELOPER ALFIECG_DEV TEASES PPL BYPASS TO BE RELEASED SOON

radiant idol
#

REAL

sonic totem
#

DOPAMINE 3.0 IMMINENT

velvet path
#

all I'm saying is what's the evidence that it's not fake

#

think about it

summer zealot
#

I’m calling my next jailbreak cocaine

velvet path
#

if they've faked it before, now it's on them to prove it's legitimate

summer zealot
#

Because that what it takes

radiant idol
#

this one

#

nothing

#

it looks real

sonic totem
#

That reminds me I need to write my checkm8 jailbreak

velvet path
#

you'd be surprised by just how meticulously something can be faked

summer zealot
#

Palera1n is a thing

harsh junco
#

cocaine jailbreak

summer zealot
#

Yes

west bloom
#

Trust me

proper reef
radiant idol
#

probably

summer zealot
harsh junco
#

c0ca1ne

summer zealot
#

Even better

radiant idol
#

nah you gotta have that @ and 3 in there

summer zealot
#

c0c@1n3

radiant idol
#

or a 4 would work for "a" as well

velvet path
proper reef
#

0xc0c@1n3

harsh junco
#

0xc0c@123

velvet path
#

Most of the common fake things you see are lazy

#

this time probably isn't one of those cases

radiant idol
#

yeah

proper reef
#

Watch as they are using some sort of screen mirroring

west bloom
#

He was one of the first ppl that got sileo and terminal on ts2. I wonder if that’s faked too

sonic totem
#

I just accidentally git reset something I'd been working on for hours and I hadn't pushed to remote yet fr

native orbit
summer zealot
#

Ruby on Rails

proper reef
#

I need to get my device jailbroken to develop but I don’t want to update to iOS 16

sonic totem
#

Worst part is it was like my fifth attempt and the first working version

#

Oh well

#

Time to start a new project

radiant idol
proper reef
sonic totem
#

I wasn't able to put it onto GitHub yet

#

Unpushed TrollStore changes

harsh junco
radiant idol
#

rip

sonic totem
#

Would've had to start a new private repo and set it up with git remote