#development
1 messages · Page 98 of 1
huh
the tweak started working after I changed /private/var/... to /var/jb/var/
?????
no it should be fine
makes sense
bc i thouhgt like w file writing stuff its only /var and onward
no but dopamine is supposed to redirect paths from /var/mobile/Preferences/... to /var/jb/var/mobile/Preferences
it should've worked
or does it not account for when it is /private/var/mobile/Preferences
hmm
the folders not there
what
Like at all
should work fine as is hmm
there for me...
just has a blacklist
/private/var/mobile/Preferences
talking about cfpref hook
could patch all /private/var to /var lmao
yeah
@radiant idol is this right?
is that even a good idea though
will it work
I don't know if that's a good idea
hook the setFrame: method and pass in your new CGRect. learn oop first and then i'll help, because this is neither beneficial to me nor you
but then special cases exist when some tweaks access apple prefs from that folder
hm
maybe should fix root issue lol
since like, I don't think this is sustainable
another way that this could theoretically be done is to scan the user's root filesystem and add every single file outside of /var/jb to the blacklist
is that efficient or a good idea?
no
would it probably work? think so
hmm
true
you're just like lemin lmao
his wouldnt update
mine did
i did an update not a restore
cowabunga
.
i dont get into bootloops much
last time i got into bootloop was iphone xr
i never had a bootloop
ok the tweak works now. weirdly, though, the respring button still doesnt work
hm
odd
that was on a old device purposely
also that poor ipad
what did you do to it
the app that you made that deleted random files in /var
ifile
the classic
oh
logs say it was patched?
yea
wine
hmm
[*] data_buffer 0x140060000, size 103168
[*] CFString table: 0xc150
[*] original string at: 0xb8ca
[*] replacement string at: 0x18000
[*] data data at: 0x11110
[*] data data size: 480
[*] is_dylib: true
[*] patched CString entry at: 0x9350
[original]: adr x1, #0xb8ca (0x50012bc1)
[patched]: adr x1, #0x18000 (0x100c0001)
lemme see if this matches up with XMachOViewer
replacement str is correct
extra hmmm
oh i found the issue night
data data is right
@radiant idol does it matter if i watch guides on on python oop or does it need to be objc? bc concenpts r still there right?
nvm idk
no but it isnt
doesnt need to be objc
oop is universal
k il ask questions after i watch this collage lecture thing
cgrectmake python
there is also very well a possibility that the patcher could have corrupted the method and that's why it's not working
will do some testing, one sec
i think i get somthing, like @implementions are the things/methods/functions that we (as devs) use to interact with an object... like theres a method for NSObject to set the CGRect stuff?
and bc of the inharitence thing, all things are NSObject so u can set the CGRect stuf on anything?
@implementions is where method implementations go when you're making a class
cgrect (frame property) is for uiviews, and anything inheriting from it (subclasses)
any1 got a 4k chimera device?
iphone 6?
ok so instead of NSObject its UIView and eveythung under that has it
idk if its 4k
that will work
yeah just need rejb
bet
ill dm ipa
anger
very anger
backport ts wen
joetrust
use new ktrr and make/break coretrus
🤝
@native orbit interesting. this still shows as red even after patching
question, is using the methods provided in/when a class was made, the only way to chnage its like proporties?
proporties being CGrect/frame thing
and u can like chnage it to readonly/readwrite with the .h file thing? or is that decied by ios and u cant chnage it?
what ida saying
lets see
you shouldnt be able to change them
idk if you can
well no
you cant change readonly -> readwrite
you can change readwrite -> readonly but idk why you'd want to do that
ight
i got it
cursed
silly discord CDN update
interesting that it doesnt match up
hm
idk the inst is right tho
oh
that would fuck everything
lol
jade dev ware
its prefs right?
yea
then it a lib
hmmm
how come in flex when i tap on a like CGRect thing it crashes to safe mode
it has issues idk
night, i get why i cant do the crazy self.thing.thing.thing now
Just like your mother
its bc the firs thing is the like thing and the thing after is the data atribute
so thats why u have to like do the "thing.thing.thing" seperate witht the * thing
i cant read asm
i've literally seen a entire function get dead code optimized out because of a single false noreturn
uh you can help get pseudocode to guide you through it
and just read asm documentation for the relevant parts
I see
through linking the pseudocode and main view window
I mean yeah that would be helpful
I'm just avoiding it as much as I possibly can lmao
too scared
ig the other thing you can do while being completely in pseudocode would be to just find out the correct function signatures and number of arguments
cool
loser
u know what
(I know what 2 instructions do)
shut up "fiore"
why did you put my name in quotes 💀
"capt"
Shut your fake developer ass up
Does anyone know why JavaScript's alert() does nothing on a any WebKit based browser (iOS) ?
it… does
maybe you have popups turned off
I am on the default Safari WebKit, where do I check that

It does function less reliably than other platforms indeed
Like when safari used a cached web page, it won’t always trigger the alert
I already redeemed
does it fail 100% of the time or is it just unreliable
100%
1 hour 40 minutes
NGAOWW
ktrr bypass <t:1703684700:R> 🤑
Live streaming from the 37th Chaos Communication Congress
It just started 👀
Hbd dude @exotic spire
yep KTRR bypass
A17 never got iOS 16.5
he’s talking about hardware level stuff here
ver shouldn’t matter
his vuln & whatever else was probably patched in whatever 16.x ver tho yeah
hm I see
okay so can we get KTRW for A12-A16 now
@steady nest can you explain
tr
crazy
finally spinlock panics can be fixed
This is fucking insane
what
How did he even learn what the hash was
These old heads can be happy I guess lol
yes
reversing lol
patched in a17+ via dtree check
How did the attackers even know how to write to the mmio registers
Wtf
no no I mean via software
he said he used a similar approach exploiting sony bluray devices
Hmm
okay i haven’t seen the beginning of the talk but goddamn that exploit chain
This is fcking crazy they're speeding through everything I can't even keep up 😭
Crazy 😭
it gets bigger lol
there’s 2 different kernel exploits in this
HOW BIG IS THIS
.
iirc this isn’t new
PDF exploits are funny
This is batshit insane
at least it isn't as complex as the last one
“Malware”
that dude wrote his own lang to exploit via safari
lmfao what
what the Fuck ?
how do you write a exploit using font assembly
i thought the nsexpression thing was insane
this is another level
okay im gonna go take a shower @radiant idol keep me updated pls
Bet
exciting times
Half of this stuff is going over my head tho
I didn’t even know that NSExpression thing even existed
Project Zero made a post on this
previously
this is fire
no wtfis cmon
lol
Jailbreaking
mfs still checking for cydia in 2023
Cydia 😭
Evasion7 😭😭😭
How do you even check if you're running on Corellium
Lol
??? lmfao
Key word “supposed”
Oh my bad it was dude working for NSO he wrote his own computer arch to execute a zero click exploit
im so confused where is this from
what in the fuck
Live streaming from the 37th Chaos Communication Congress
for a second I was panicking that maybe it was only a PPL and PAC bypass instead of a KTRR bypass
oh nice
then that slide dropped
oh
different russian accents
Yeah
He made 70k instructions to basically install a spyware which bypassed everything via Imessage
cool stuff
yes
🔥
CGRect *rect = [[CGRect alloc] init];
OOP
😭
🔥
is oop the cgrectmake
he looks like he has social anxiety
triangle check 
poor guy
he just like me
I feel bad for him
same
tbf that is 99.9% of this server as well
yeah all of us lol
Yeah I mean I don’t think they’re gonna release src
😭
It is
4 sided triangle confirmed
Remix sucks
Fun fact
😶🌫️
bleh
smh
After the talk
Thank you bitch
this malware may have also been used for macOS
wow
and was in use for 10+ years
and the KTRR bypass has been unpatched for years
even after disclosure
I'll try, thx for the help
Idk opa might work on the jelbrek
prison break?
(Fuck you autocorrect)
ktrr is cool
Thank you
They’re saying lockdown mode may not even be able to mitigate if lol
They are not sure
It’s different to the KTRW one
Afaik
Similar bugs but not the same…?
same group of register sets
not the same exploit for sure though yeah
there are other speakers
about completely different things

its just a bunch of security talks
so they releasing anything or nah?
I wasn't really expecting any POC but it's still a bummer
f
What a crazy talk - looks like we have an unpatchable KTRR bypass for A12-A16 (possibly A17) as long as we have a PPL bypass. This will revolutionise jailbreaking for the next few years.
【QRT of opa334 (@opa334dev):】
'Very excited for this one! #37c3 https://t.co/YjE91y47Ru'
💖 44 🔁 9
Well they said there’s that triangle check program or whatever
Did they say if that’s publicly available yet
didn't he say it's on their site
O ok
maybe I misheard
O cool
I used to use kaspersky antivirus
existence of corelliumd
Oh right
does that daemon act like a bridge similar to CoreSimulatorBridge?
no idea
learn oop to exploit it
fr
learn oop
Jelbrek jelbrek = new Jelbrek() (real)
had to check 
staaaturrrr
what about the thing we were talking about yesterday
the /usr/bin/killall
still dunno why it doesnt work
ill hook posix_spawn on the pref and see whats up
maybe its likee the thing w tweaksettings how that doesnt work in it (it hink idk if it works or not)
no it doesnt work in the prefs app either
thats what im saying, like maybe the reason it doesnt work in TS app is same reosn it dont work in settings app
prefs app = settings app
ik
what
tried tweaksettings just to see?
yeah same issue
And should I assume Alfie’s tweet saying “possibly A17”, means a PoC would need to be released/made + a PAC (or SPTM?) bypass to see if A17’s also affected?
https://fxtwitter.com/alfiecg_dev/status/1740030381108429218
wouldn't KFD->PAC->CVE-2023-38606 work for a JB
at least for <16.6
how easily can the bug be written just from their talk though?
I'd imagine it would take some time
since they haven't released the code
im sure they will in time
my worst worry is that they just release the slides and nothing else
but considering that they've shown a screenshot i'm on copium rn
I guess
It was unclear whether it was properly patched in A17
the bug is in hardware, not software
Yes
16.6
anyway does anyone know if this can be written to with PPLRW
yeah, but you also need a PPL and PAC bypass afaik
the malware literally did that
i mean isn’t it via the dtree check they added?
the screenshot I sent was for the mitigation for the malware on 16.6 and above
this is for vulnerable chips, a16-
didn’t look too hard
the PPL or PAC bypass (idek at this point) was fixed in 16.6
the method of entry is patched, but the actual bug is still there. we'd probably need another PPL or PAC bypass (again, idek which one)
that's neat
pmap-io
It looked like there were two patches
most likely both
One was for A16- and one was A17
ah
Yes lol
A16- patch
it doesn't change ETA for iOS 17+ jb - that's all you need to care about
A17 i didn't get a screenshot of it
eta 16.5 jb
PPL bypass + kernel exploit + KTRR bypass == jb?
Yeah people seem to think this doesn’t mean we still need a full chain
But we do
It only affects the end result
Which page
i think it's from misinfo spread
end product: kexec iOS 17 kernel from iOS 16
oh
Gonna be insane
This like the closest thing to checkm8 since checkm8
Dualboots maybe
but the amount of exec ram would be limited
Mhm
on iOS 8-9 it was easy to patch kernel TEXT region, why were there no dualboot tools then?
you should probably shut up before the reddit crowd discovers that this channel exists
yeah
no arm64 dualboot tools for those
Deleting Reddit looking really powerful
so your new kernel or linux or pongoOS or whatever have to fit inside that range
unplug reddit servers 👍
Lol
one of them literally stalks this channel
There are dualboot tools for iOS 7-8
arm64
Wtf
iOS 9 has KPP
we had a kpp bypass on 10.x and nobody ever bothered to finish kloader64 with that
Pongo
No WAY
watchtower can be bypassed
and I have never seen any dualboot tools for ios 8
other than coolbooter
buit thats 32 bit
kloader64
not finished
Live streaming from the 37th Chaos Communication Congress
nobody’s done a full dualboot with it
is it oss
wow
okay.
bh memmem is goated
patchfinder32 moment
Yeah I quoted it
bro lol
lmao
Whatever that is 
SAME DUDE
whatever that is
whatever that is
whatever that is
whatever that is
whatever that is
whatever that is
Literally how does that post have any value
fr
mods are too busy having lots of gay sex with each other to pay attention to if posts are low effort
why
https://vxtwitter.com/exploit3dguy/status/1740041669129445542?s=46 this is almost certainly cap but
Failed to scan your link! This may be due to an incorrect link, private/suspended account, deleted tweet, or recent changes to Twitter's API (Thanks, Elon!).
deleted
yea deleted
what was it
actual NPCs
nightwind bruh stop copying people
I don't know if it's related but here is android recovery running on 14 Pro:
【QRT of JAPA (@mxngozz):】
'@opa334dev https://t.co/ja829oyyKF'
💖 0
this?
I AM SO GOOD
yep
huge chin
anyways i smell cap
fake
first there’s no way they did a whole impl of that ktrr bypass THAT quickly
cap, no one makes "iPhone" a board name lmao
it hasn’t even been like 3 hours since the talk
its probly just a photoshoped screen shot
wasn’t that posted simultaneously with it though
imagine its real tho
probably
what
date on it is today
ah ok
also how do you go from KTRR to running ROMs
like i don't get it
you have to reboot
iirc to boot the images you have to patch them to run in EL3 instead of EL1
or sum like that
people who dont understand memes:
i don't get it though, does that mean you have to boot iOS and then somehow use KTRR to chain to the android kernel instead??
like you obviously can't boot directly afaik
no you’re just loading it into memory and then jumping to the image from there (& killing the ios kernel)
ah
Is this OOP
No
@radiant idol
C++ is NOT the same as C
which is designed to be used with object-oriented programming languages such as C++
not really
it's designed to work with C
so you have fake OOP
structs are fun
Sad oop
i ❤️ structs
@native orbit ok so it seems like the path doesn't get properly patched. I logged it and the log is empty. it doesnt even show /usr/bin/killall
very odd
killall > /usr/bin/killall
what
Command > full path to binary
i don't think you know the context of what they're doing
Maybe I don’t
is thix Xcode? what's w this arg marker
clangd
nvm that does not look like Xcode
it's VS Code with clangd
uh
basedd
str_patcher not working for const char * strs
cant really fix this on my own since i am a bonehead
so waiting for statur
oh
Nexus moment
what issue
wdym
just dont work at all?
well
or wrong/corrupt
o
send the log for the one part to
cuz I don't think you can run strlen on null(?)
old -> /usr/bin/killall new -> /var/jb/usr/bin/killall
[*] data_buffer 0x120080000, size 103520
[*] CFString table: 0xc038
[*] original string at: 0xb8a7
[*] replacement string at: 0x18000
[*] data data at: 0x11490
[*] data data size: 488
[*] is_dylib: true
[*] patched CString entry at: 0x929c
[original]: adr x20, #0xb8a7 (0x70013054)
[patched]: adr x20, #0x18000 (0x100c0014)
old -> /usr/bin/killall new -> /var/jb/usr/bin/killall
magic: 0xfeedfacf
[*] data_buffer 0x130210000, size 103152
[*] CFString table: 0xc130
[*] original string at: 0xb8b6
[*] replacement string at: 0x18000
[*] data data at: 0x11128
[*] data data size: 480
[*] is_dylib: true
[*] patched CString entry at: 0x9234
[original]: adr x20, #0xb8b6 (0x50013414)
[patched]: adr x20, #0x18000 (0x100c0014)
look fot bad access
what are you cooking
its some other tweak crashing
i do need to know 🧌

it was bettercc
should say "patched CString ref" not entry lol
real
Wat
why is the background color yellow
Wtf u talking about
Lmao
lol basically if the you cant access the path but the length of the str is greater than 0, it should color the bg yellow
but the length of the str is 0
so WHY is it yellow
Ur probably reading some garbage in mem that's changing
send the bin
could be that
true
Strings are automatically nil terminated when defined like that
im guessing the compiler just inserts a \0 at the end?
Yes
I see
Anyone got a windows pro license they want to sell?
yea the addr goes to an invalid location in the bin. interesting
@radiant idol try new commit
what was it
i did replace addr - orig addr its suppose to be replace addr - fileoff

this is truly a breaking change
fr
shhh
i think i just accidently added a space lol

@radiant idol is OOP the CGRectMake stuff? bc i can set one the lables to hidden but its not chnaging the postiotns. OR is this a thing with the OOP and i didnt set the proporty stuff right so IOS deosnt chnage it (cant chnage it)?
old -> /usr/bin/killall new -> /var/jb/usr/bin/killall
magic: 0xfeedfacf
[*] data_buffer 0x140108000, size 103520
[*] CFString table: 0xc038
[*] original string at: 0xb8a7
[*] replacement string at: 0x18000
[*] data data at: 0x11490
[*] data data size: 488
[*] is_dylib: true
[*] patched CString entry at: 0x929c
[original]: adr x20, #0xb8a7 (0x70013054)
[patched]: adr x20, #0x1a60b (0x700d3054)
old -> /usr/bin/killall new -> /var/jb/usr/bin/killall
magic: 0xfeedfacf
[*] data_buffer 0x1300f8000, size 103152
[*] CFString table: 0xc130
[*] original string at: 0xb8b6
[*] replacement string at: 0x18000
[*] data data at: 0x11128
[*] data data size: 480
[*] is_dylib: true
[*] patched CString entry at: 0x9234
[original]: adr x20, #0xb8b6 (0x50013414)
[patched]: adr x20, #0x1a682 (0x500d3414)
yes
I need someone professional to say if ios 17.0 get jb soon or not please 😩
no
no
WTF 😳👍
this is by far the strangest conversation ive ever had
there needs to be a iq test to get into this channel
no
Rip capt
@radiant idol new commit
bet
need dev role only dev channel
rly do tho
wtf where's my dev role
u use x86 asm
lemme fix the code again and see, cuz i removed the respring stuff and replaced it with this bg stuff for testing
real
shut up

WHY BACKGROUND IS GREEN
yes
now go convert nexus
do you want test cases
@hasty ruin let your mom live to 80 or make sure nexus drm is never cracked
have you tested arm64e yet
Tbf it should work fine despite obfuscation, since it checks varjb at runtime
mother
inb4 these fixes break other things
Fucking lier
Die
??
automatically adding oldabi to CONTROL >>
well that’s not gonna stop me anyways
HA
Litten
LMAO
ida when it sees nexus drm:
I’m not opening this so I’m not accused of stealing ideas or code.
I didn’t mean that in the legal sense
gpl3
I still wanna do this so bad brah
do it then
I’m having a boner just thinking abt it
bet
next patcher: perfectly decompile back to objc and recompile with new abi
why the fuck does the emoji overlap the ]
Which terminal
vscode term?
L font then
ok hold on
lets go
so far I've tried: Barmoji, Zenith
only took like 25 "this is the last commit, this will fix it 100%"
lmfaoooo
Does it actually work on iOS 15

str_patcher goated
@pseudo hazel
- Don't dm me
- Theres literally a flag to set it

LQ's tweaks are goated
HAHAHAHAHAHA
@restive ether laugh at this guy
cmon the poor guy died, at least have some respect
tweaks may have not been written the best but they're good
he's dead 😳
yeah?
si
cameron has been living under a rock
point and laugh
did not know that
yeah, the guy tragically died in a car accident from what I understand
@radiant idol @native orbit does it work on macOS or do i need to build iOS bins
macOS currently
and rn its specific to my setup
and im gonna rewrite this as an app anyway
so
ew no
no swiftui
who do you think i am
it patches any arm64/e macho
ok lets see
what do
I dont think adding each one manually is a good idea
since that would get out of hand

Add the system ones
no thats the thing
And see if it ain’t in that list
Night can u tell me what tweak if fing my ipad into safe mode, much thanks
"MusicBackgroundLS.dylib"
thx
there a good crash log viewer or someshit for macos?
@radiant idol patch cr4shed you won’t
wont work anyway
mach hook is gone
Is that your own tweak
no
its ehtn's
LMAO
MusicBackground
OF COURSE IT IS
i dont think it was meant for ios 16
ye
what app is this?
dont know any
nice
Just use any text editor
@timid furnace any ideas?
this doesn't seem to work either
lemme stop piping to /dev/null
and see
yea its just codesig stuff
huh??
but what do i look for?
💀💀💀
yes and 
my phone got stuck mid respring due to old abi
i am rioting
uhh
respring loop
hmm
what on
Jade
Emerald
I think it's just me being weird with the script though
prob not an issue wit str_patcher
I'm so confused
oh wait I think I get it
yooo
delayOTA'd






