#development

1 messages · Page 98 of 1

radiant idol
#

what

#

huh

#

the tweak started working after I changed /private/var/... to /var/jb/var/

#

?????

acoustic imp
#

silly IOS

#

/private like perm restricted ?

radiant idol
#

no it should be fine

acoustic imp
#

bc i thouhgt like w file writing stuff its only /var and onward

native orbit
#

add that to the list of strings to patch

#

thats why the symlink method works then

radiant idol
# native orbit makes sense

no but dopamine is supposed to redirect paths from /var/mobile/Preferences/... to /var/jb/var/mobile/Preferences

#

it should've worked

#

or does it not account for when it is /private/var/mobile/Preferences

#

hmm

native orbit
#

its check

#

it oss

radiant idol
#

im lazzzyyyy

#

fine

#

ok lets see

acoustic imp
#

the folders not there

radiant idol
#

what

acoustic imp
native orbit
radiant idol
native orbit
#

just has a blacklist

radiant idol
#

/private/var/mobile/Preferences

radiant idol
#

so

native orbit
#

talking about cfpref hook

radiant idol
#

oh

#

yeah

native orbit
#

could patch all /private/var to /var lmao

radiant idol
#

yeah

acoustic imp
#

@radiant idol is this right?

radiant idol
#

will it work

#

I don't know if that's a good idea

native orbit
#

its not

#

just do a special case for /private/var/mobile/Preferences

radiant idol
radiant idol
#

hm

native orbit
#

maybe should fix root issue lol

radiant idol
#

since like, I don't think this is sustainable

#

another way that this could theoretically be done is to scan the user's root filesystem and add every single file outside of /var/jb to the blacklist

#

is that efficient or a good idea?

#

no

#

would it probably work? think so

native orbit
#

hmm

radiant idol
#

yea no not doing that

#

the more I think of that, the more painful it sounds

native orbit
#

true

visual meadow
#

dude

#

i bootlooped it so fucking bad a software update doesnt fix it

radiant idol
#

you're just like lemin lmao

visual meadow
#

mine did

#

i did an update not a restore

radiant idol
#

no I mean like

#

he also always gets into bootloops

#

somehow

hasty ruin
#

cowabunga

radiant idol
#

.

visual meadow
#

last time i got into bootloop was iphone xr

radiant idol
#

i never had a bootloop

hasty ruin
#

i've had one

#

(i deleted the root fs in ifile)

radiant idol
# native orbit true

ok the tweak works now. weirdly, though, the respring button still doesnt work

#

hm

native orbit
#

odd

radiant idol
#

indeed

#

I'll check with ida and see if the thing changed

visual meadow
radiant idol
#

what did you do to it

#

the app that you made that deleted random files in /var

proper reef
hasty ruin
#

IDIOT

radiant idol
#

IPHONE?

#

you are an idiot

hasty ruin
#

it was an iphone 4

#

on ios 7

radiant idol
#

oh

hasty ruin
#

hardly rare

radiant idol
#

ok fair

#

@native orbit interesting

#

dont mind the totally legit ida font

native orbit
radiant idol
#

yea

hasty ruin
native orbit
#

hmm

radiant idol
#
[*] data_buffer 0x140060000, size 103168
[*] CFString table: 0xc150
[*] original string at: 0xb8ca
[*] replacement string at: 0x18000
[*] data data at: 0x11110
[*] data data size: 480
[*] is_dylib: true
[*] patched CString entry at: 0x9350
    [original]:  adr x1, #0xb8ca (0x50012bc1)
    [patched]:   adr x1, #0x18000 (0x100c0001)
#

lemme see if this matches up with XMachOViewer

#

replacement str is correct

native orbit
#

extra hmmm

radiant idol
#

cfstr table is correct

#

original str is correct

native orbit
#

its just a global const char*

#

might not be used

#

just left in

hasty ruin
#

oh i found the issue night

radiant idol
#

data data is right

acoustic imp
#

@radiant idol does it matter if i watch guides on on python oop or does it need to be objc? bc concenpts r still there right?

native orbit
radiant idol
radiant idol
#

oop is universal

acoustic imp
#

k il ask questions after i watch this collage lecture thing

hasty ruin
#

cgrectmake python

acoustic imp
#

i get it.

#

no idont nvm

radiant idol
# radiant idol no but it isnt

there is also very well a possibility that the patcher could have corrupted the method and that's why it's not working

#

will do some testing, one sec

acoustic imp
#

i think i get somthing, like @implementions are the things/methods/functions that we (as devs) use to interact with an object... like theres a method for NSObject to set the CGRect stuff?

#

and bc of the inharitence thing, all things are NSObject so u can set the CGRect stuf on anything?

hasty ruin
#

@implementions is where method implementations go when you're making a class

hasty ruin
native orbit
#

any1 got a 4k chimera device?

hasty ruin
acoustic imp
#

ok so instead of NSObject its UIView and eveythung under that has it

hasty ruin
#

idk if its 4k

native orbit
hasty ruin
#

ok bet

#

i accidentally brought it with me

#

instead of my other 6S

native orbit
#

i fixed chimera intjpray but need more people to test

#

no more fan or 2% success rate

hasty ruin
#

it's already strapped with odyra1n

#

should be fine yeah?

native orbit
#

yeah just need rejb

hasty ruin
#

bet

native orbit
#

ill dm ipa

hasty ruin
#

ugh i need to sideload properly

#

no ts

radiant idol
#

anger

hasty ruin
#

very anger

native orbit
#

backport ts wen

radiant idol
#

make coretrust for iOS 12 and then exploit

#

fr

native orbit
#

joetrust

acoustic imp
#

use new ktrr and make/break coretrus

radiant idol
#

@native orbit interesting. this still shows as red even after patching

acoustic imp
#

question, is using the methods provided in/when a class was made, the only way to chnage its like proporties?

#

proporties being CGrect/frame thing

radiant idol
#

you could directly change them if they're readwrite

#

but if readonly then yes

acoustic imp
#

and u can like chnage it to readonly/readwrite with the .h file thing? or is that decied by ios and u cant chnage it?

radiant idol
#

lets see

radiant idol
#

idk if you can

#

well no

#

you cant change readonly -> readwrite

#

you can change readwrite -> readonly but idk why you'd want to do that

acoustic imp
#

ok

#

i have another question cooking but i need look at sm first

radiant idol
#

uh

#

where is the string

#

???

native orbit
radiant idol
#

lmfao

#

what

#

did it not send properly

acoustic imp
#

i got it

native orbit
#

the string ptr is the thing casting into const char

#

discord trash

radiant idol
#

cursed

acoustic imp
#

silly discord CDN update

radiant idol
#

hm

native orbit
#

idk the inst is right tho

radiant idol
#

how do u know

#

also why is it saying that is_dylib is true?

native orbit
#

oh

radiant idol
#

it aint a dylib afaik

#

just a macho

native orbit
#

that would fuck everything

radiant idol
#

lol

hasty ruin
#

jade dev ware

radiant idol
#

lemme run file on it

#

but it's not a dylib

#

what

native orbit
#

its prefs right?

radiant idol
#

yea

native orbit
#

then it a lib

radiant idol
#

hmmm

acoustic imp
#

how come in flex when i tap on a like CGRect thing it crashes to safe mode

radiant idol
#

it has issues idk

acoustic imp
#

night, i get why i cant do the crazy self.thing.thing.thing now

pearl sail
#

Just like your mother

acoustic imp
#

its bc the firs thing is the like thing and the thing after is the data atribute

#

so thats why u have to like do the "thing.thing.thing" seperate witht the * thing

radiant idol
#

i cant read asm

wooden yarrow
#

i've literally seen a entire function get dead code optimized out because of a single false noreturn

wooden yarrow
#

and just read asm documentation for the relevant parts

radiant idol
#

I see

wooden yarrow
radiant idol
#

I mean yeah that would be helpful

#

I'm just avoiding it as much as I possibly can lmao

#

too scared

wooden yarrow
#

ig the other thing you can do while being completely in pseudocode would be to just find out the correct function signatures and number of arguments

radiant idol
#

yeah I do that

#

I also rename funcs

#

that helps

wooden yarrow
#

cool

indigo peak
radiant idol
#

u know what

indigo peak
#

(I know what 2 instructions do)

radiant idol
#

shut up "fiore"

indigo peak
#

why did you put my name in quotes 💀

radiant idol
#

because

#

why not

wooden yarrow
wicked summit
#

"capt"

pearl sail
#

Shut your fake developer ass up

exotic spire
#

Does anyone know why JavaScript's alert() does nothing on a any WebKit based browser (iOS) ?

granite frigate
#

it… does

primal perch
exotic spire
primal perch
rigid glen
#

Like when safari used a cached web page, it won’t always trigger the alert

drifting heron
#

yay free nitro

#

@torn oriole

granite frigate
#

@torn oriole

#

luv u

drifting heron
#

I already redeemed

granite frigate
drifting heron
#

14:45 CET guys

#

😎

granite frigate
#

1 hour 40 minutes

elder scaffold
#

22:45 JST

#

MEOW

inner yoke
#

NGAOWW

mellow whale
#

ktrr bypass <t:1703684700:R> 🤑

gaunt stone
#

Was about to send that

drifting heron
gaunt stone
#

It just started 👀

ashen birch
#

gm nerds

#

anything cool from that talk yet

gaunt stone
ashen birch
#

yeah

#

unfortunate that this writing to unknown regs stuff isn’t on a17 ig

hexed knot
#

Hbd dude @exotic spire

radiant idol
#

yep KTRR bypass

radiant idol
ashen birch
#

ver shouldn’t matter

#

his vuln & whatever else was probably patched in whatever 16.x ver tho yeah

radiant idol
#

hm I see

ashen birch
#

okay so can we get KTRW for A12-A16 now

radiant idol
#

@steady nest can you explain

ashen birch
#

tr

radiant idol
#

finally spinlock panics can be fixed

granite frigate
#

This is fucking insane

steady nest
granite frigate
#

How did he even learn what the hash was

pearl sail
radiant idol
#

is the thing patchable or not

#

I’m confused

steady nest
#

yes

ashen birch
ashen birch
granite frigate
#

Wtf

radiant idol
granite frigate
#

Wait

ashen birch
granite frigate
#

Hmm

ashen birch
#

okay i haven’t seen the beginning of the talk but goddamn that exploit chain

granite frigate
#

This is fcking crazy they're speeding through everything I can't even keep up 😭

radiant idol
#

Crazy 😭

ashen birch
native orbit
#

it gets bigger lol

ashen birch
#

there’s 2 different kernel exploits in this

radiant idol
#

HOW BIG IS THIS

granite frigate
#

they wrote a kexploit

#

in js.

radiant idol
#

.

ashen birch
pearl sail
#

PDF exploits are funny

ashen birch
granite frigate
#

This is batshit insane

pearl sail
#

at least it isn't as complex as the last one

radiant idol
#

“Malware”

pearl sail
#

that dude wrote his own lang to exploit via safari

radiant idol
#

lmfao what

ashen birch
pearl sail
#

fr crazy shit

#

don't know why he went HAM for it

granite frigate
#

how do you write a exploit using font assembly
i thought the nsexpression thing was insane
this is another level

ashen birch
#

okay im gonna go take a shower @radiant idol keep me updated pls

radiant idol
#

Bet

drifting heron
#

exciting times

radiant idol
#

Half of this stuff is going over my head tho

radiant idol
granite frigate
#

previously

mellow whale
#

this is fire

steady nest
#

no wtfis cmon

elder scaffold
#

lol

radiant idol
#

Jailbreaking

native orbit
#

mfs still checking for cydia in 2023

radiant idol
#

Cydia 😭

radiant idol
granite frigate
#

How do you even check if you're running on Corellium

mellow whale
radiant idol
#

Lol

ashen birch
#

too true troll

#

tf

#

top tier troll

topaz yew
ashen birch
#

autocorrect making whole new sentences

#

wasn’t it supposed to be better in ios 17

drifting heron
#

it was a lie

timid briar
#

Key word “supposed”

pearl sail
slender glade
ashen birch
#

what in the fuck

drifting heron
radiant idol
#

for a second I was panicking that maybe it was only a PPL and PAC bypass instead of a KTRR bypass

slender glade
#

oh nice

slender glade
#

is this text to speech

#

nvm he's just german

radiant idol
#

no he’s Russian

#

i think

slender glade
#

oh

granite frigate
#

different russian accents

radiant idol
#

Yeah

pearl sail
#

cool stuff

drifting heron
#

I like the live captions feature on Windows 11

radiant idol
#

AI

#

lmao

drifting heron
#

🤯

#

damn

gaunt stone
#

Is KTRR bypass confirmed ?

#

I skipped a big part of the event

radiant idol
#

yes

gaunt stone
#

🔥

slender glade
#

CGRect *rect = [[CGRect alloc] init];

radiant idol
#

OOP

slender glade
#

😭

gaunt stone
#

🔥

night rover
#

is oop the cgrectmake

slender glade
#

he looks like he has social anxiety

drifting heron
#

triangle check tf

radiant idol
drifting heron
radiant idol
#

I feel bad for him

slender glade
#

same

pearl sail
slender glade
#

yeah all of us lol

gaunt stone
#

Triangle confirmed

radiant idol
#

Yeah I mean I don’t think they’re gonna release src

slender glade
#

that is not a fucking triangle

#

that's a

drifting heron
#

😭

gaunt stone
slender glade
#

CGRect *rect = [[CGRect alloc] init];

#

that's what it is

pearl sail
#

4 sided triangle confirmed

gaunt stone
#

Remix sucks

granite frigate
#

Fun fact

slender glade
#

😶‍🌫️

radiant idol
#

bleh

drifting heron
#

jelbrek

#

!!

mellow whale
#

yeah we will get a jb

#

son

radiant idol
#

smh

blazing warren
#

After the talk

exotic spire
#

Thank you bitch

granite frigate
#

this malware may have also been used for macOS

#

wow

#

and was in use for 10+ years

#

and the KTRR bypass has been unpatched for years

#

even after disclosure

exotic spire
gaunt stone
mellow whale
gaunt stone
#

(Fuck you autocorrect)

mellow whale
#

ktrr is cool

exotic spire
radiant idol
#

They’re saying lockdown mode may not even be able to mitigate if lol

sonic totem
#

Afaik

#

Similar bugs but not the same…?

radiant idol
#

And it’s over

#

Wow

#

What a ride

gaunt stone
#

Kernel text region write ?

sonic totem
#

It was an old bypass

#

found by bazad

granite frigate
#

not the same exploit for sure though yeah

acoustic imp
#

It’s over ?

#

It says break ik they finished but is there more ?

native orbit
#

there are other speakers

acoustic imp
#

Do they jus yapp about same thing ?

#

Or is it like in more detail ?

native orbit
#

about completely different things

acoustic imp
#

What?

#

More exploits ?

drifting heron
native orbit
#

its just a bunch of security talks

acoustic imp
#

Like methods ? On how to do thing ?

ashen birch
#

so they releasing anything or nah?

granite frigate
#

I wasn't really expecting any POC but it's still a bummer

ashen birch
#

f

drifting heron
timid briar
#

Well they said there’s that triangle check program or whatever
Did they say if that’s publicly available yet

drifting heron
#

didn't he say it's on their site

timid briar
#

O ok

drifting heron
#

maybe I misheard

radiant idol
timid briar
#

O cool

hexed knot
#

I used to use kaspersky antivirus

hasty ruin
granite frigate
#

Oh right

slender glade
radiant idol
#

so

#

what now

hasty ruin
radiant idol
#

fr

granite frigate
#

learn oop

timid briar
#

Jelbrek jelbrek = new Jelbrek() (real)

native orbit
#

had to check intjpray

radiant idol
#

staaaturrrr

#

what about the thing we were talking about yesterday

#

the /usr/bin/killall

#

still dunno why it doesnt work

native orbit
#

ill hook posix_spawn on the pref and see whats up

acoustic imp
#

maybe its likee the thing w tweaksettings how that doesnt work in it (it hink idk if it works or not)

radiant idol
#

no it doesnt work in the prefs app either

acoustic imp
#

thats what im saying, like maybe the reason it doesnt work in TS app is same reosn it dont work in settings app

radiant idol
#

prefs app = settings app

acoustic imp
#

ik

native orbit
#

tried tweaksettings just to see?

radiant idol
#

lemme try

#

lol

#

i dont think it'll make a difference

acoustic imp
#

i dont think so

#

i dont think it works even on reg jb

radiant idol
timid briar
#

And should I assume Alfie’s tweet saying “possibly A17”, means a PoC would need to be released/made + a PAC (or SPTM?) bypass to see if A17’s also affected?

elfin quarry
#

at least for <16.6

radiant idol
#

how easily can the bug be written just from their talk though?

#

I'd imagine it would take some time

#

since they haven't released the code

native orbit
#

im sure they will in time

granite frigate
#

my worst worry is that they just release the slides and nothing else

#

but considering that they've shown a screenshot i'm on copium rn

sonic totem
#

It was unclear whether it was properly patched in A17

radiant idol
#

the bug is in hardware, not software

sonic totem
#

Yes

slender glade
#

16.6

granite frigate
#

anyway does anyone know if this can be written to with PPLRW

radiant idol
#

yeah, but you also need a PPL and PAC bypass afaik

elfin quarry
radiant idol
#

or just one of them, I have no clue at this point

#

I'm so confused

ashen birch
granite frigate
#

this is for vulnerable chips, a16-

steady nest
radiant idol
#

the PPL or PAC bypass (idek at this point) was fixed in 16.6
the method of entry is patched, but the actual bug is still there. we'd probably need another PPL or PAC bypass (again, idek which one)

radiant idol
granite frigate
#

pmap-io

sonic totem
sonic totem
#

One was for A16- and one was A17

ashen birch
#

ah

granite frigate
#

Yes lol

opal ridge
#

it doesn't change ETA for iOS 17+ jb - that's all you need to care about

granite frigate
#

A17 i didn't get a screenshot of it

hasty ruin
#

eta 16.5 jb

harsh junco
#

PPL bypass + kernel exploit + KTRR bypass == jb?

sonic totem
#

But we do

#

It only affects the end result

elfin quarry
radiant idol
opal ridge
elder scaffold
#

oh

radiant idol
#

writeupppp, well kinda

#

lets go

sonic totem
#

This like the closest thing to checkm8 since checkm8

#

Dualboots maybe

opal ridge
#

but the amount of exec ram would be limited

sonic totem
#

Mhm

granite frigate
#

on iOS 8-9 it was easy to patch kernel TEXT region, why were there no dualboot tools then?

radiant idol
sonic totem
#

Didn’t you say executable range

#

Is limited

opal ridge
#

yeah

granite frigate
sonic totem
opal ridge
#

so your new kernel or linux or pongoOS or whatever have to fit inside that range

radiant idol
slender glade
#

one of them literally stalks this channel

opal ridge
#

arm64

granite frigate
#

Wtf

opal ridge
#

iOS 9 has KPP

ashen birch
ashen birch
#

i genuinely have seen none

granite frigate
#

and I have never seen any dualboot tools for ios 8

#

other than coolbooter

#

buit thats 32 bit

opal ridge
#

kloader64

ashen birch
#

not finished

granite frigate
ashen birch
#

nobody’s done a full dualboot with it

granite frigate
#

is it oss

ashen birch
#

yes

#

axi0mX wrote it

granite frigate
#

wow

ashen birch
granite frigate
#

idk what i'd need to do to update it

#

too stupid fr

slender glade
native orbit
#

bh memmem is goated

native orbit
ashen birch
sonic totem
#

Yeah I quoted it

slender glade
steady nest
#

lmao

hasty ruin
#

hang on

#

lemme find a post from yesterday

slender glade
#

@teal forge

#

u got no shame

hasty ruin
#

oh wait

#

it's the same dude

#

😭

drifting heron
#

Whatever that is tf

slender glade
granite frigate
#

whatever that is

acoustic imp
#

whatever that is

slender glade
#

whatever that is

radiant idol
#

whatever that is

hasty ruin
#

whatever that is

young meteor
#

whatever that is

sonic totem
mellow whale
#

fr

hasty ruin
#

hey you ruined the chain

ashen birch
#

mods are too busy having lots of gay sex with each other to pay attention to if posts are low effort

hasty ruin
#

yeah true

#

they do that a lot

teal forge
#

whatever that is

radiant idol
#

why

ashen birch
timid furnace
#

deleted

radiant idol
#

yea deleted

timid furnace
#

what was it

radiant idol
#

what was it

#

LOL

ashen birch
#

actual NPCs

hasty ruin
#

nightwind bruh stop copying people

radiant idol
#

this?

#

I AM SO GOOD

ashen birch
#

damn am I the NPC now

#

fuck

radiant idol
#

yep

steady nest
#

huge chin

ashen birch
#

anyways i smell cap

steady nest
#

fake

teal forge
#

huge cap

#

like the guy with his rubix cube

#

whos flipping his phone

ashen birch
#

first there’s no way they did a whole impl of that ktrr bypass THAT quickly

timid furnace
#

cap, no one makes "iPhone" a board name lmao

ashen birch
#

it hasn’t even been like 3 hours since the talk

radiant idol
#

i mean

#

there is a write up

#

but yea

acoustic imp
#

its probly just a photoshoped screen shot

ashen birch
teal forge
#

imagine its real tho

ashen birch
#

someone reply poc or gtfo

#

🧌

radiant idol
ashen birch
#

nah ill do it for you

#

don’t go posting it on reddit

teal forge
#

what

ashen birch
radiant idol
#

ah ok

acoustic imp
#

the event hadnt even started yet

timid furnace
#

also how do you go from KTRR to running ROMs

#

like i don't get it

#

you have to reboot

ashen birch
#

iirc to boot the images you have to patch them to run in EL3 instead of EL1

#

or sum like that

teal forge
#

people who dont understand memes:

timid furnace
#

like you obviously can't boot directly afaik

ashen birch
#

no you’re just loading it into memory and then jumping to the image from there (& killing the ios kernel)

timid furnace
#

ah

ashen birch
#

don’t quote me on that though

#

i’m not like deeply familiar with the kloader process

timid furnace
#

oh so i should google that

#

bet

#

explains what kloader is

acoustic imp
#

I just love windows

#

Bye bye 4 day uptime

indigo peak
harsh junco
#

is C oop

acoustic imp
#

No

harsh junco
#

@radiant idol

radiant idol
#

no

#

it isnt

harsh junco
acoustic imp
radiant idol
#

C++ is NOT the same as C

timid furnace
# acoustic imp

which is designed to be used with object-oriented programming languages such as C++

#

not really

#

it's designed to work with C

#

so you have fake OOP

radiant idol
#

structs are fun

acoustic imp
#

Sad oop

harsh junco
#

oopn’t

#

@radiant idol dm

#

(not) opp-related trol

topaz yew
radiant idol
#

@native orbit ok so it seems like the path doesn't get properly patched. I logged it and the log is empty. it doesnt even show /usr/bin/killall

#

very odd

radiant idol
#

what

harsh junco
timid furnace
#

i don't think you know the context of what they're doing

harsh junco
#

Maybe I don’t

slender glade
radiant idol
slender glade
#

nvm that does not look like Xcode

radiant idol
#

it's VS Code with clangd

slender glade
#

yeah was abt to say looks like vsc lmao

#

@radiant idol what's the issue

radiant idol
#

uh

timid furnace
radiant idol
#

str_patcher not working for const char * strs

#

cant really fix this on my own since i am a bonehead

#

so waiting for statur

slender glade
#

oh

acoustic imp
native orbit
radiant idol
#

wdym

native orbit
#

just dont work at all?

radiant idol
#

well

native orbit
#

or wrong/corrupt

radiant idol
#

it patches to null(?)

#

wrong

native orbit
#

o

radiant idol
#

lemme run strlen on it

#

and see

native orbit
#

send the log for the one part to

radiant idol
#

yeye

#

ooo

#

safe mode

radiant idol
timid furnace
#

the answer is easy

#

crash log

radiant idol
# native orbit send the log for the one part to
old -> /usr/bin/killall        new -> /var/jb/usr/bin/killall
[*] data_buffer 0x120080000, size 103520
[*] CFString table: 0xc038
[*] original string at: 0xb8a7
[*] replacement string at: 0x18000
[*] data data at: 0x11490
[*] data data size: 488
[*] is_dylib: true
[*] patched CString entry at: 0x929c
    [original]:  adr x20, #0xb8a7 (0x70013054)
    [patched]:   adr x20, #0x18000 (0x100c0014)

old -> /usr/bin/killall        new -> /var/jb/usr/bin/killall
magic: 0xfeedfacf
[*] data_buffer 0x130210000, size 103152
[*] CFString table: 0xc130
[*] original string at: 0xb8b6
[*] replacement string at: 0x18000
[*] data data at: 0x11128
[*] data data size: 480
[*] is_dylib: true
[*] patched CString entry at: 0x9234
    [original]:  adr x20, #0xb8b6 (0x50013414)
    [patched]:   adr x20, #0x18000 (0x100c0014)
timid furnace
#

look fot bad access

radiant idol
#

yes yes I'll look

#

uh

#

EXC_CRASH (SIGABRT)

#

what

radiant idol
#

its some other tweak crashing

radiant idol
#

yet

gaunt stone
radiant idol
#

no

#

shoo

#

👋

timid furnace
radiant idol
#

it was bettercc

native orbit
#

should say "patched CString ref" not entry lol

radiant idol
#

what

native orbit
#

real

radiant idol
#

?????

#

why is it yellow??

timid furnace
#

Wat

radiant idol
#

why is the background color yellow

timid furnace
#

Wtf u talking about

radiant idol
timid furnace
#

Lmao

radiant idol
# timid furnace Wtf u talking about

lol basically if the you cant access the path but the length of the str is greater than 0, it should color the bg yellow

but the length of the str is 0

#

so WHY is it yellow

timid furnace
#

Ur probably reading some garbage in mem that's changing

native orbit
#

send the bin

radiant idol
#

alr

#

one sec

radiant idol
native orbit
#

yes

#

it just reads til it finds a null byte

radiant idol
#

true

grim sparrow
#

Strings are automatically nil terminated when defined like that

radiant idol
#

im guessing the compiler just inserts a \0 at the end?

grim sparrow
#

Yes

radiant idol
#

I see

ocean raptor
#

Anyone got a windows pro license they want to sell?

radiant idol
# radiant idol

yea the addr goes to an invalid location in the bin. interesting

native orbit
#

@radiant idol try new commit

radiant idol
#

ok

#

thanks

native orbit
#

i figured it out

#

im dum

radiant idol
#

what was it

native orbit
#

i did replace addr - orig addr its suppose to be replace addr - fileoff

radiant idol
#

oh

#

frcoal

native orbit
radiant idol
#

this is truly a breaking change

native orbit
#

fr

radiant idol
#

shhh

native orbit
#

i think i just accidently added a space lol

radiant idol
#

it's certainly different

timid furnace
native orbit
#

fr

#

send log

radiant idol
#

ok

#

CENSORSHIP

hasty ruin
#

@radiant idol is OOP the CGRectMake stuff? bc i can set one the lables to hidden but its not chnaging the postiotns. OR is this a thing with the OOP and i didnt set the proporty stuff right so IOS deosnt chnage it (cant chnage it)?

radiant idol
# native orbit send log
old -> /usr/bin/killall        new -> /var/jb/usr/bin/killall
magic: 0xfeedfacf
[*] data_buffer 0x140108000, size 103520
[*] CFString table: 0xc038
[*] original string at: 0xb8a7
[*] replacement string at: 0x18000
[*] data data at: 0x11490
[*] data data size: 488
[*] is_dylib: true
[*] patched CString entry at: 0x929c
    [original]:  adr x20, #0xb8a7 (0x70013054)
    [patched]:   adr x20, #0x1a60b (0x700d3054)

old -> /usr/bin/killall        new -> /var/jb/usr/bin/killall
magic: 0xfeedfacf
[*] data_buffer 0x1300f8000, size 103152
[*] CFString table: 0xc130
[*] original string at: 0xb8b6
[*] replacement string at: 0x18000
[*] data data at: 0x11128
[*] data data size: 480
[*] is_dylib: true
[*] patched CString entry at: 0x9234
    [original]:  adr x20, #0xb8b6 (0x50013414)
    [patched]:   adr x20, #0x1a682 (0x500d3414)
woven lily
#

I need someone professional to say if ios 17.0 get jb soon or not please 😩

native orbit
#

no

radiant idol
#

no

woven lily
#

WTF 😳👍

radiant idol
#

this is by far the strangest conversation ive ever had

brazen timber
#

there needs to be a iq test to get into this channel

native orbit
#

@radiant idol new commit

radiant idol
#

bet

hasty ruin
native orbit
#

rly do tho

brazen timber
#

wtf where's my dev role

native orbit
#

u use x86 asm

hasty ruin
radiant idol
#

lets go

#

greeeen

native orbit
#

W

#

does it respring?

radiant idol
radiant idol
native orbit
#

real

hasty ruin
#

bold text for your blind ass

radiant idol
#

shut up

hasty ruin
harsh junco
radiant idol
radiant idol
#

idk

native orbit
#

so now everything should work

#

i hope

radiant idol
#

well we said that the last fifteen times

#

so

hasty ruin
#

now go convert nexus

timid furnace
#

do you want test cases

radiant idol
#

gimme

#

i literally have a folder called "test_cases"

#

frcoal

slender glade
#

@hasty ruin let your mom live to 80 or make sure nexus drm is never cracked

timid furnace
#

have you tested arm64e yet

radiant idol
#

yes

#

im doing this on arm64e

#

lemme make sure Zenith didnt break

hasty ruin
native orbit
#

inb4 these fixes break other things

slender glade
#

Fucking lier

hasty ruin
#

i still have rune so we good

slender glade
#

Die

hasty ruin
#

??

slender glade
#

I lowkey wanna make a notif logger

#

I think someone already did that tho

radiant idol
#

automatically adding oldabi to CONTROL >>

slender glade
#

well that’s not gonna stop me anyways

radiant idol
#

HA

hasty ruin
#

Litten

radiant idol
#

LMAO

slender glade
#

Yeah I think she did it

#

I’m gonna do it either way tho

native orbit
#

ida when it sees nexus drm:

radiant idol
slender glade
radiant idol
#

it's MIT

#

i think

slender glade
#

I didn’t mean that in the legal sense

native orbit
#

gpl3

slender glade
#

I still wanna do this so bad brah

hasty ruin
radiant idol
#

do it then

slender glade
#

I’m having a boner just thinking abt it

slender glade
radiant idol
#

old abi

#

.

#

ok lets see

native orbit
#

next patcher: perfectly decompile back to objc and recompile with new abi

hasty ruin
radiant idol
#

i dont know

#

it bothers me

hasty ruin
#

Which terminal

native orbit
#

vscode term?

radiant idol
#

no

#

iTerm

hasty ruin
#

L font then

radiant idol
#

true

#

yea Zenith works fine too

#

@timid furnace i need test cases

timid furnace
#

ok hold on

native orbit
radiant idol
#

so far I've tried: Barmoji, Zenith

native orbit
#

only took like 25 "this is the last commit, this will fix it 100%"

radiant idol
#

lmfaoooo

hasty ruin
radiant idol
#

perfectly

hasty ruin
native orbit
#

str_patcher goated

radiant idol
#

frfr

#

I should try Emerald

ocean raptor
#

@pseudo hazel

  1. Don't dm me
  2. Theres literally a flag to set it
hasty ruin
radiant idol
#

LQ's tweaks are goated

ocean raptor
#

HAHAHAHAHAHA

ocean raptor
radiant idol
#

cmon the poor guy died, at least have some respect

#

tweaks may have not been written the best but they're good

ocean raptor
#

he's dead 😳

radiant idol
#

yeah?

restive ether
#

si

radiant idol
#

cameron has been living under a rock

restive ether
#

point and laugh

ocean raptor
#

did not know that

radiant idol
#

yeah, the guy tragically died in a car accident from what I understand

timid furnace
#

@radiant idol @native orbit does it work on macOS or do i need to build iOS bins

radiant idol
#

macOS currently

#

and rn its specific to my setup

#

and im gonna rewrite this as an app anyway

#

so

#

ew no

#

no swiftui

#

who do you think i am

hasty ruin
#

Wtf

#

Did my deleted message just get re-sent

#

Or is it just a client bug

timid furnace
#

can it patch macOS bins

radiant idol
#

oh

#

idk

native orbit
#

it patches any arm64/e macho

radiant idol
#

probably

#

yeah

timid furnace
#

ok i will build for both

#

hold on i keep getting pinged in jailbreak

radiant idol
#

time to fix the .sh script

hasty ruin
#

Do you differentiate between Java classes and machos

#

@native orbit no disrespect

radiant idol
#

what do

#

I dont think adding each one manually is a good idea

#

since that would get out of hand

native orbit
hasty ruin
radiant idol
#

no thats the thing

hasty ruin
#

And see if it ain’t in that list

acoustic imp
radiant idol
#

I dont need to add the system ones

#

i need custom ones

#

oh i see what you mean

radiant idol
acoustic imp
native orbit
#

there a good crash log viewer or someshit for macos?

hasty ruin
#

@radiant idol patch cr4shed you won’t

radiant idol
#

mach hook is gone

hasty ruin
acoustic imp
hasty ruin
#

Oh

#

I’ve never heard of it

acoustic imp
#

its ehtn's

hasty ruin
#

LMAO

radiant idol
#

MusicBackground

hasty ruin
#

OF COURSE IT IS

acoustic imp
#

i dont think it was meant for ios 16

hasty ruin
#

gotcha

radiant idol
#

ye

acoustic imp
#

howd u know it was that?

#

like what do u search for in the log

radiant idol
#

i used OOP to find it

#

nah its right here

acoustic imp
radiant idol
#

Console

#

macOS

acoustic imp
#

oh

#

windows alternative?

radiant idol
#

dont know any

timid furnace
#

ok finally

#

it is time to cook

radiant idol
#

nice

hasty ruin
radiant idol
#

this doesn't seem to work either

#

lemme stop piping to /dev/null

#

and see

#

yea its just codesig stuff

acoustic imp
slender glade
brazen timber
radiant idol
#

my phone got stuck mid respring due to old abi

#

i am rioting

#

uhh

#

respring loop

#

hmm

native orbit
#

what on

hasty ruin
#

Jade

radiant idol
#

I think it's just me being weird with the script though

#

prob not an issue wit str_patcher

#

I'm so confused

#

oh wait I think I get it

#

yooo

timid furnace
#

@radiant idol temporarily delayed

#

i committed an rm fuckup

radiant idol
#

delayOTA'd

timid furnace