#development

1 messages · Page 152 of 1

sonic totem
timid briar
#

lol

sonic totem
#

Oops

#

macOS RC then

granite frigate
#

any guesses for when 17.4 release will... release

sonic totem
#

Okay time for me to do my maths homework

sonic totem
granite frigate
#

quoting you on that next tuesday

sonic totem
#

bet

granite frigate
#

"Alfie internal apple leaker"

timid briar
sonic totem
timid briar
#

I’m joking!!! Do what u want I’m just being a silly guy!!!

sonic totem
#

No haxx for you

#

Just hrtowii

timid briar
#

lol

sonic totem
#

Selling a CoreTrust bypass

#

$50

timid briar
#

Real

granite frigate
#

throw in some extra 0s in there

sonic totem
lean ermine
faint timber
#

No one be haxxing more than me

sonic totem
#

Prime Linus 🔥

slim bramble
sonic totem
#

"our"?

slim bramble
#

💀

#

fr

sonic totem
#

i'll believe it when i see it

slim bramble
#

Bypassed fr

faint stag
#

imagine decryption without having to read memory prayge

elder scaffold
#

need kok3shi9 v5.0

slim bramble
placid kraken
#

The oct in Nocturne stands for BINARY

sonic totem
#

YES!

slender glade
torn cloud
#

eta wen TSS key leak

#

i need

lyric heron
#

but imagine iboot

#

exploit

#

unpatchable

sonic totem
#

TSS key leak is unpatchable

#

iBoot exploit is very patchable

steady nest
lyric heron
#

the key is used to sign firmware ye?

sonic totem
sonic totem
lyric heron
#

ok but what if they just

#

change the key

steady nest
#

they do it, then what

#

your phone still takes the old one

lyric heron
#

why

steady nest
#

how does your phone know which key to accept

lyric heron
#

it asks apples server

#

is what i'd assume

steady nest
#

nope

#

you ask the apple server to give you an apticket, signed with the key

lyric heron
#

ohtrol

steady nest
#

if you're able to sign it locally, why'd you need the apple server?

lyric heron
#

but what about activating the device

#

nvm

steady nest
#

nothing stops you from doing it

sonic totem
#

@lyric heron key is defined in the ROM

#

So you can’t change it

sonic totem
lyric heron
#

or smt like that

#

right

sonic totem
#

Idk for sure

steady nest
#

no

restive ether
#

not that one

lyric heron
#

so that means

#

wait why is it not resistant

#

but blobs for A10+ are

sonic totem
#

Apple ask you not to disclose anything while it’s being reviewed afaik @torn cloud

#

So I wouldn’t send stuff here

torn cloud
#

my bad

torn cloud
#

or is there no need

sonic totem
#

Does it work?

torn cloud
#

i mean they can probably compile it themselves so there's no need

tepid olive
#

ok guys

#

I have a question

#

will this

#

work for tweaks

torn cloud
tepid olive
torn cloud
#

(maybe)

tepid olive
#

cool

radiant idol
torn cloud
#

shell execution bug in macOS

radiant idol
#

oh cool

torn cloud
#

currently getting reviewed

radiant idol
#

congrats

torn cloud
#

idk if it’ll get me anything

torn cloud
placid kraken
#

$20 and a kinder bueno

sonic totem
torn cloud
#

please tell me you’re joking

sonic totem
#

I’m really not

torn cloud
#

my ass cannot wait that long in anticipation

torn cloud
sonic totem
#

It either gets closed after a week or so, or stays in review for months

torn cloud
#

like is that a sign they want to give you the bounty

#

or will they pull a uno reverse at the last second and close it

sonic totem
#

No

placid kraken
#

what does the shell execution bug actually achieve

torn cloud
#

it’s a bug

sonic totem
#

They fix the issue, post security notes and then put it into bounty review

placid kraken
sonic totem
torn cloud
sonic totem
#

If it can’t do any substantial damage to a system, they won’t shell out

placid kraken
#

apple should implement a gatekeeper and sip protection system like macos but for ios

sonic totem
#

They do

torn cloud
sonic totem
#

It’s called “you can’t install IPAs from the internet”

placid kraken
#

why cant you disable it like you can on mac

sonic totem
slim bramble
#

alfie grab my free code

torn cloud
slim bramble
#

before it's too late

torn cloud
#

shouldn’t get my hopes up ig

sonic totem
#

They tend to be pretty steep unless you can provide an actual exploit for iOS/macOS

tepid olive
#

@native orbit ```
rror: undefined symbol: _sel_registerName
note: referenced by /Users/sora/Tweaks/meniscus/zig-cache/o/ec050c1003f5e17e559dc37b2094e3e1/libmeniscus.dylib.o:_sel.Sel.registerName
error: undefined symbol: _objc_getClass
note: referenced by /Users/sora/Tweaks/meniscus/zig-cache/o/ec050c1003f5e17e559dc37b2094e3e1/libmeniscus.dylib.o:_class.getClass
error: undefined symbol: _objc_msgSend

sonic totem
#

Or show that it could be used harmfully

tepid olive
slim bramble
#

L

torn cloud
hexed knot
#

Man why are u using zig

tepid olive
#

I like zig

faint timber
#

just be self taught prodigy

tepid olive
#

Trying to learn a new language

placid kraken
#

iPHONE ULTIMATE EXPLOIT 2024 FOR TODAY ROOT FLEXING ARM 💪 💪 💪 BIG VULNRERABILITY CAN HACK NEW JAILBREAK 2025 OPA334 ALIFECG R/JAILBREAK 😍 😍 😍 😍 😍 😍 😍 KERNEL READ WRITE NOT FAKE

primal perch
#

iPHONE ULTIMATE EXPLOIT 2024 FOR TODAY ROOT FLEXING ARM 💪 💪 💪 BIG VULNRERABILITY CAN HACK NEW JAILBREAK 2025 OPA334 ALIFECG R/JAILBREAK 😍 😍 😍 😍 😍 😍 😍 KERNEL READ WRITE NOT FAKE

torn cloud
orchid fulcrum
#

Is this a good idea

torn cloud
kind herald
#

erm copy pasta

#

mods ban

torn cloud
#

cy

#

pwn

#

piracy

faint timber
torn cloud
#

mods

kind herald
#

Filter bypass

#

mods ban

torn cloud
placid kraken
#

people are saying mods ban

#

mods should ban for that

orchid fulcrum
torn cloud
faint timber
#

mods should ban you

placid kraken
#

what did i do

faint timber
#

be you

placid kraken
#

oh

sonic totem
torn cloud
placid kraken
#

ive earned at least $0.99 from flora !!!!!

vivid dew
torn cloud
#

you’ve earned more than that

placid kraken
#

elon musk is giving a generous $7 to help children in need

kind herald
primal perch
#

elon musk is giving a generous $7 to help children in need

orchid fulcrum
placid kraken
torn cloud
#

flora is on the front page of havoc lol people are gonna be buying that shit

faint timber
#

more money in breaking shit apart than creation

placid kraken
#

so true

sonic totem
#

Break this IMG4 parser apart Cryptic

vivid dew
#

i'll give you 5 usd so you can buy a house with it

orchid fulcrum
#

Oof

torn cloud
orchid fulcrum
faint timber
#

no idea

frosty gale
#

REAL

sonic totem
torn cloud
sonic totem
#

An entire exploit chain + a code-signing bypass + two installd bugs

torn cloud
#

I wonder how he did it hm

sonic totem
#

At least 300k

placid kraken
sonic totem
#

Probably more

native orbit
primal perch
orchid fulcrum
frosty gale
#

Isn’t BootROM exploits like 1mill

placid kraken
torn cloud
#

other companies do

frosty gale
#

Thought I saw one cyber company buying them for 2mill

placid kraken
#

i have biology revision to get to have fun doing nerd stuff guys

sonic totem
#

Well

#

Depends on the BootROM exploit

frosty gale
#

3mill *

frosty gale
orchid fulcrum
sonic totem
#

IMG4 bug people would pay 10+ million probably

torn cloud
frosty gale
#

DANG

torn cloud
tepid olive
sonic totem
tepid olive
#
pub usingnamespace @cImport({
                   ^~~~~~~~
/Users/sora/Tweaks/meniscus/zig-cache/o/f65250e61f5993ba877ba09a113faf26/cimport.h:1:10: error: 'objc/runtime.h' file not found
#include <objc/runtime.h>
         ^
torn cloud
faint timber
#

I wonder why theres no cve's for rom/iboot

sonic totem
#

It’s fixable with a Find My restore

frosty gale
tepid olive
# tepid olive ```/Users/sora/.cache/zig/p/1220c94dbcdf5a799ce2b1571978ff3c97bab1341fe329084fcc...
lib.linkLibC();
    lib.addFrameworkPath(.{ .path = "/Applications/Xcode.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS.sdk/System/Library/Frameworks/" });
    lib.addLibraryPath(.{ .path = "/Applications/Xcode.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS.sdk/usr/lib" });
    lib.addSystemIncludePath(.{ .path = "/Applications/Xcode.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS.sdk/usr/include" });
    lib.linkSystemLibrary("objc");
    lib.linkFramework("Foundation");
    lib.root_module.addImport("objc", objc.module("objc"));```
#

not sure why tho

sonic totem
primal perch
#

gooning

torn cloud
sonic totem
#

That wasn’t even a CVE even

orchid fulcrum
frosty gale
#

How much is a untether like Fugu14

#

Which isn’t a BootROM

sonic totem
frosty gale
#

500k?

#

Ahh

sonic totem
#

No not 1mil

frosty gale
#

800k

sonic totem
#

If Fugu14 was 0click it would be 1mil

#

I’d say 400-500k

steady nest
steady nest
#

;P

frosty gale
slim bramble
sonic totem
#

Persistence + 100% success rate kernel exploit + PAC/PPL bypass

sonic totem
frosty gale
steady nest
#

i actually mean it

sonic totem
#

iCrazeWare™️

primal perch
#

iCrazeWare™️

slim bramble
steady nest
#

the chain exists and is weaponized already

sonic totem
slim bramble
#

iCrazeWare™️

sonic totem
#

I saw some demo video

frosty gale
orchid fulcrum
steady nest
orchid fulcrum
slim bramble
sonic totem
#

Did the blog post ever release

frosty gale
slim bramble
frosty gale
sonic totem
#

Uh oh…..

frosty gale
#

Uh oh……

slim bramble
#

In the precipitation I forgot to tag @acoustic imp

frosty gale
slim bramble
#

W

#

Tesla sent images

frosty gale
#

Is there an option to not have the blur?

slim bramble
#

Yes

#

It does not work for me tho

#

I have a drm test version

#

Ask @acoustic imp

frosty gale
#

Could I test?

slim bramble
#

I don’t have the build rn

#

And we have bunch of testers

frosty gale
#

Fair fair

slim bramble
#

6 testers and 2 devs

frosty gale
#

Can’t wait then, congrats though on the future release!

slim bramble
#

Thanks

frosty gale
#

Also

#

Uh oh……

slim bramble
#

Uh oh…

steady nest
young meteor
#

stop doing weird shit and just use objc or swift fr

tepid olive
#

no

kind herald
#

no swift

slim bramble
kind herald
slim bramble
tepid olive
#

@native orbit can't get it work

#

wtf

#

it works if I use the macOS SDK

primal perch
vivid dew
primal perch
hasty ruin
primal perch
#

hbd big man

young meteor
#

hbd big man

vivid dew
vivid dew
slim bramble
#

hbd big man

vivid dew
slim bramble
#

Fr

#

No

#

Wait

acoustic imp
#

wha

vivid dew
#

wtf he's really gone

slim bramble
acoustic imp
young meteor
acoustic imp
#

he just asked if he could turn off the blur

frosty gale
#

Banger

acoustic imp
#

This is what it can look like minimized

placid kraken
#

looks good

acoustic imp
acoustic imp
placid kraken
#

awaiting the 50,000,000 safemodes that will happen on release (its inevitable)

acoustic imp
#

It’s iOS 14/15

cloud yacht
placid kraken
#

im pretty sure flora has safemoded a lot less than you think

placid kraken
slim bramble
cloud yacht
placid kraken
acoustic imp
#

@hasty ruin is rune suposed to be dismissible on the LS ?

acoustic imp
slim bramble
tepid olive
#

this should be equivalent to __attribute__((constructor)) according to mach-o format

#
const __init linksection("__DATA,__mod_init_func") = init;
export fn init() void {
    const NSString = objc.getClass("NSString").?;
    var StringInst = NSString.msgSend(objc.Object, "alloc", .{});
    StringInst = StringInst.msgSend(objc.Object, "initWithUTF8String:", .{"TEST"});
}
slim bramble
#

And a lot more safer than you think

placid kraken
#

flora literally hooks UIColor what issues could that possibly cause

acoustic imp
placid kraken
#

yet here we are

cloud yacht
#
if(goingToSafeMode()) { 
  dont();
}```
placid kraken
kind herald
placid kraken
#

who knew there could be so many issues with a simple UIColor hook

#

of all things, fucking chinese handwriting keyboard crashing apps

slim bramble
#

It shouldn’t

acoustic imp
#

dissapearing now *

slim bramble
#

(iCrazeware stolen code)

slim bramble
acoustic imp
#

i got do HW 😭

placid kraken
#

can never be sure

slim bramble
cloud yacht
placid kraken
#

i believe you but consider getting people to test it on a variety of devices, ios versions, and bootstraps

#

not that i can use it anyway im on ios 16

acoustic imp
#

all on dif devices, prettymuch

slim bramble
#

And I have a few devices on different versions

placid kraken
cloud yacht
#

it should delete icrazedrm files so the nexus always bootloops

acoustic imp
slim bramble
placid kraken
kind herald
# slim bramble We have 6 testers

do you have any on iPadOS 14.8.1 with an iPad air 4 with Taurine or an iPad 5 on iPadOS 14.8 with unc0ver or an iPhone 6s on iOS 15.7.4 running dopamine

slim bramble
cloud yacht
#

if your not using procursus and your on like iOS 13+ what are you doing?

cloud yacht
#

there

acoustic imp
#

the player is completly dif anyway

slim bramble
cloud yacht
#

and ododysseyra1n

acoustic imp
#

im not the person to ask

slim bramble
radiant idol
#

z

acoustic imp
#

z

slim bramble
#

Binger is dead

kind herald
#

z

slim bramble
#

z

cloud yacht
#

yeah

lean ermine
#

is there even a non procursus strap above 14?

#

does xina not use procursus

cloud yacht
#

maybe checkra1n's stap

kind herald
slim bramble
#

Non procursus users are weird ngl

cloud yacht
#

does it go above 14?

acoustic imp
slim bramble
lean ermine
#

roothide uses procursus

slim bramble
#

EWWWWW

kind herald
#

they used to not use procursus

#

I think

slim bramble
#

Roothide goofy anyway

lean ermine
#

fork of procursus but its still procursus

cloud yacht
#

tbf I use not procursus on my iPhone 7

acoustic imp
#

#use a real JB

kind herald
#

my iPhone Xr runs unc0ver

slim bramble
#

Ewww

cloud yacht
lean ermine
#

my iphone runs ios

kind herald
#

(it’s the only jailbreak for iOS 12.4.1)

acoustic imp
#

L

cloud yacht
#

unc0ver on iOS 12 is acceptable

kind herald
#

it’s honestly good

slim bramble
#

Undecimus

kind herald
#

I have Sileo installed and the exploit doesn’t fail a lot

orchid fulcrum
#

Is there a way to get internal settings like that one misaka tweak. (Which didnt work for me at the time btw)

cloud yacht
kind herald
slim bramble
cloud yacht
kind herald
#

which is A12

orchid fulcrum
radiant idol
acoustic imp
#

ohhhh

#

onesettings mb

radiant idol
#

lol

cloud yacht
radiant idol
#

yes I figured out a way, it's in beta though @orchid fulcrum

#

not released yet

slim bramble
#

How 2 get one settings beta ?

radiant idol
#

n0

orchid fulcrum
#

Oh okay i can test if you need

slim bramble
#

@BibiFireDev on Twitter fr

acoustic imp
slim bramble
#

I have already convinced 1 Brit

orchid fulcrum
brazen timber
acoustic imp
slim bramble
#

Who makes bootloop common

acoustic imp
#

ah

#

ah

cloud yacht
#

tbhey should make procusus for 32 bit devices

kind herald
#

procursus for ios 7

cloud yacht
#

this

#

and the old apple tv

slim bramble
#

@acoustic imp can’t believe you typo’d

#

Go check Twitter

acoustic imp
#

oops

slim bramble
acoustic imp
#

yea i havnt checked yet

#

as i said, im doing HW atm

tepid olive
#

ok so

#

I have the base of my tweak

#

now what

tepid olive
#

TELL ME

#

GRR

acoustic imp
#

what

hasty ruin
#

what

tepid olive
indigo peak
hasty ruin
#

why not rune's

indigo peak
#

drop me the

#

rune drm files

#

‘sir

#

please

#

I just thought of a website to make

#

“Drop me the ____” generator

#

and it just uses Nathan’s image and just replaces the text

#

with whatever you enter fr

tepid olive
#

I need simple tweak idea

#

now

#

I'll do simple tweak

#

then complicated tweak

tepid olive
tepid olive
native dune
#

theres a tweak for that already

tepid olive
#

where

#

i need it

native dune
#

idk

tepid olive
native dune
lean ermine
#

fire tweak

tepid olive
#

remake it without looking at thr source ig

#

¯_(ツ)_/¯

lean ermine
#

it's closed source so no need

#

apparently respring isnt an action tho

#

kinda cringe

#

u can set it to open an app though and then set it to a respring app, almost works

tepid olive
tepid olive
lean ermine
#

oh you can set it to shortcuts in squidgesture

#

then just make a respring shortcut

#

ez pz

tepid olive
#

any other suggestions?

lean ermine
#

make a tweak that moves notification banners to the bottom of the screen 🔥

tepid olive
#

that sounds

#

weird

lean ermine
#

lmao

lean ermine
#

whats that

acoustic imp
#

it does exactly what u said

#

moves notif down

lean ermine
#

is it for ios 16?

acoustic imp
#

no 15>

lean ermine
#

pog

#

link?

#

cant find

acoustic imp
#

its like not what ur thinking of tho lol

lean ermine
#

lol

acoustic imp
#

16Player has peices of it in it

lean ermine
#

where it at

acoustic imp
#

LS config page troll

#

but only when media is playing

lean ermine
#

i mean like notif banners

acoustic imp
#

ohhhh

#

nvm then

lean ermine
#

so they show up at the home bar location instead of the top

tepid olive
#

oh I see what you mean

#

sure why the fuck not

#

shouldn't be too hard

lean ermine
#

it exists for ios 14 but not 15 or 16

#

ill send u 49 cents USD if u make it

tepid olive
#

nah

#

I'll just make it completely free

lean ermine
#

lolol

tepid olive
#

no hidden costs™️

acoustic imp
#

Starts playing media, thinks 16Player will show up

#

Nope

#

L drm

lean ermine
#

is there a term command to go into safemode

#

-SEGV?

acoustic imp
#

yea

lean ermine
#

thx

acoustic imp
#

-SEGV

#

i always forget

tepid olive
#

@lean ermine just send me a notification rq

#

ping me

#

or someone

#

actually

#

I canping myself

#

@tepid olive

#

that didn't work

lean ermine
#

just make notification pop up after 3 sec delay

tepid olive
#

how

lean ermine
#

one sec

#

i have one alr

tepid olive
#

figured it out

lean ermine
#

damn.. i was about to send my icloud shortcut exploit link...

tepid olive
#

lol

lean ermine
#

i believe there is an open source tweak for ios 14 that does the notif at bottom thing

acoustic imp
lean ermine
#

seems not open source

#

idk im about to leave work so im gone for like half an hour

tepid olive
#

how do I make it

#

not go away

#

when I press it

lean ermine
#

uhh

#

what

tepid olive
#

nvm

lean ermine
#

make sure ur doing the normal show notification one not the popup option or whatever the other one is

tepid olive
#

wait wdym

lean ermine
#

like this one

tepid olive
#

yeah

#

alr

#

@native orbit how do I find the selector for a method that isn't in apple's documentation

acoustic imp
#

can you dump headers of an app ?

tepid olive
#

yes

#

but I need the selector

#

the objc runtime selector

acoustic imp
#

uhh so it need tweak injection ?

tepid olive
#

???

acoustic imp
#

like the app cant have JB detection

tepid olive
#

I'm confused

#

I don't think you understood my question

acoustic imp
#

i wana dump headers for clash royal wich has a JB bypass

acoustic imp
tepid olive
#

The selector string

#

Like

#

“initWithUTF8String:”

slate isle
#

does anyone know how to build an update for trollstore that i made? i installed brew and the libarchive thing and its failing with

nroot@localhost:~/TrollStore/TrollStore$ make
> Making all for application TrollStore…
==> Copying resource directories into the application wrapper…
==> Compiling TSAppInfo.m (arm64)…
In file included from TSAppInfo.m:1:
/home/nroot/TrollStore/TrollStore/TSAppInfo.h:9:9: fatal error: 'archive.h' file not found
#import <archive.h>
        ^~~~~~~~~~~
1 error generated.
make[3]: *** [/home/nroot/theos/makefiles/instance/rules.mk:278: /home/nroot/TrollStore/TrollStore/.theos/obj/debug/arm64/TSAppInfo.m.596e176a.o] Error 1
make[2]: *** [/home/nroot/theos/makefiles/instance/application.mk:50: /home/nroot/TrollStore/TrollStore/.theos/obj/debug/arm64/TrollStore.app/TrollStore] Error 2
make[1]: *** [/home/nroot/theos/makefiles/instance/application.mk:41: internal-application-all_] Error 2
make: *** [/home/nroot/theos/makefiles/master/rules.mk:146: TrollStore.all.application.variables] Error 2
slate isle
#

@naive kraken the tutorial on your github is extremely vague could you help me out here to try and compile or maybe say how you do it?

#

i cant seem to build libarchive to get the .h file

timid furnace
#

it should build automatically if you have libarchive installed through brew

#

this is not needed

#

brew shell --prefix or something is in the makefile

#

yes

#

-I$(shell brew --prefix)/opt/libarchive/include

limpid pumice
#

Hey @grave sparrow. Do you know how to MSHookMemory / patch instructions?

faint timber
#

isn't it self explanatory

limpid pumice
#

Cool, a buddy of mine is a little frustrated with getting a bypass working. He isn't in the server right now and wanted me to ask for him but I will have him join and hit you up.

icy escarp
#

Oops that’s me I’m here now

indigo peak
#

gameseagull mshookmemory go CRAZY

limpid pumice
#

oh you could have talked to fiore @icy escarp

indigo peak
#

captgpt

#

jit trippin

orchid fulcrum
#

People be hooking memory and i still cant hook classes 😦

limpid pumice
#

me

#

the god

indigo peak
#

no you didnt

#

💀

#

it was scoob

#

i miss scoob too :c

limpid pumice
#

who scoob?

#

ultra mega cool guy?

kind herald
#

luz

indigo peak
icy escarp
#

How do I hook functions by address on rootless? Is that possible

#

I just want to patch out some memory address

#

A wee tad bit of control flow tampering

indigo peak
#

uhhhh just uh

#

find the cmp

#

and just

#

nop

icy escarp
#

Yeah it ain’t working for me

#

One sec

#

I got an example

indigo peak
#

^

#

nop conditionals master race

icy escarp
#

This worked on unc0ver

kind herald
#

unc0ver mentioned

indigo peak
kind herald
#

1984

#

skill issue

icy escarp
indigo peak
icy escarp
#

Oh no the comment is wrong it’s a different instruction whoops

#

Like I said this used to work but it doesnt

indigo peak
#

frfr

icy escarp
#

In the snippet I sent I feel like I got it? Still confused

#

It hasn’t worked on dopamine 2, tried patching several apps

indigo peak
#

@grave sparrow whats the difference in

offset + _dyld_get_image_vmaddr_slide(0);

and

(void *)((unsigned char *)_dyld_get_image_header(0) + offset);
icy escarp
#

Yes I’ve pulled addresses from ida and binja, using dopamine 2, patch was assembled using armconverter.

indigo peak
#

armconverter my beloved (not a fan of the UI change)

icy escarp
#

Hehe

indigo peak
#

mhm

#

makes sense

#

ty

#

makes sense

icy escarp
#

When I’m in binary ninja the subroutine names and addresses are static right?

indigo peak
#

just make a patch finder

icy escarp
#

Shit you’re right

icy escarp
#

Gameseagull fire

sonic totem
#

GameSeagull got open sourced?

indigo peak
#

for years

kind herald
#

I still suck at 8 ball with game seagull . would not buy 0/10

sonic totem
indigo peak
#

fym

#

cant tell if youre trolling rn

#

its been opened source since v1.0.0

#

may 8th 2021

sonic totem
#

I thought you said you didn’t want to release the binary patches

indigo peak
sonic totem
#

I see

#

Interesting

#

Omw to fork GameSeagull and release GameSeagull2 @indigo peak

indigo peak
#

gameseagull 2 technically released

sonic totem
#

Okay then GameSeagull3

gentle grove
grim sparrow
hasty ruin
#

^

brazen timber
#

fr

slate isle
# timid furnace it should build automatically if you have libarchive installed through brew

yeah that worked but now its saying this

nroot@localhost:~/TrollStore$ make -C ./TrollStore FINALPACKAGE=1
make: Entering directory '/home/nroot/TrollStore/TrollStore'
> Making all for application TrollStore…
==> Copying resource directories into the application wrapper…
==> Compiling main.m (arm64)…
==> Compiling TSAppDelegate.m (arm64)…
==> Compiling TSAppInfo.m (arm64)…
In file included from TSAppInfo.m:2:
/home/nroot/TrollStore/TrollStore/TSCommonTCCServiceNames.h:10:48: error: initializer element is not a compile-time constant
static NSDictionary* const commonTCCServices = @{
                                               ^~
1 error generated.
make[3]: *** [/home/nroot/theos/makefiles/instance/rules.mk:278: /home/nroot/TrollStore/TrollStore/.theos/obj/arm64/TSAppInfo.m.0b72d69c.o] Error 1
make[2]: *** [/home/nroot/theos/makefiles/instance/application.mk:50: /home/nroot/TrollStore/TrollStore/.theos/obj/arm64/TrollStore.app/TrollStore] Error 2
make[1]: *** [/home/nroot/theos/makefiles/instance/application.mk:41: internal-application-all_] Error 2
make: *** [/home/nroot/theos/makefiles/master/rules.mk:146: TrollStore.all.application.variables] Error 2
make: Leaving directory '/home/nroot/TrollStore/TrollStore'
naive kraken
slate isle
naive kraken
slate isle
#

apt update?

naive kraken
#

no clue

serene hawk
#

why is theos packaging my framework to /var/jb/var/jb...

kind herald
#

just for fun

hasty ruin
#

Show makefile

serene hawk
#

uhmm

#

it was this initially: ```TARGET := iphone:clang:latest:15.0
ARCHS = arm64 arm64e
PACKAGE_VERSION=1.0

include $(THEOS)/makefiles/common.mk

XCODEPROJ_NAME = Lottie

ifeq ($(THEOS_PACKAGE_SCHEME), rootless)
Lottie_XCODEFLAGS += SWIFT_ACTIVE_COMPILATION_CONDITIONS="ROOTLESS"
Lottie_XCODEFLAGS += LD_DYLIB_INSTALL_NAME=/var/jb/Library/Frameworks/Lottie.framework/Lottie
Lottie_XCODEFLAGS += DYLIB_INSTALL_NAME_BASE=/var/jb/Library/Frameworks/Lottie.framework/Lottie
else
Lottie_XCODEFLAGS += LD_DYLIB_INSTALL_NAME=/Library/Frameworks/Lottie.framework/Lottie
Lottie_XCODEFLAGS += DYLIB_INSTALL_NAME_BASE=/Library/Frameworks/Lottie.framework/Lottie
endif

Lottie_XCODEFLAGS += DWARF_DSYM_FOLDER_PATH=$(THEOS_OBJ_DIR)/dSYMs
Lottie_XCODEFLAGS += CONFIGURATION_BUILD_DIR=$(THEOS_OBJ_DIR)/

include $(THEOS)/makefiles/xcodeproj.mk

after-stage::
ifeq ($(THEOS_PACKAGE_SCHEME), rootless)
mkdir -p ./.theos//var/jb/Library/Frameworks
cp -r $(THEOS_OBJ_DIR)/Lottie.framework ./.theos/
/var/jb/Library/Frameworks/Lottie.framework
else
mkdir -p ./.theos//Library/Frameworks
cp -r $(THEOS_OBJ_DIR)/Lottie.framework ./.theos/
/Library/Frameworks/Lottie.framework
endif

before-all::
rm -rf $(THEOS_STAGING_DIR)/Library/Frameworks/
rm -rf $(THEOS_OBJ_DIR)
rm -rf $(THEOS_STAGING_DIR)/var/jb/Library/Frameworks/```

indigo peak
#

wheere it go

#

Oh

#

It back

serene hawk
#

yeah sorry i messed some things up

#

it's prob because of the after-stage, however when i remove after-stage and before-all and then run make, the deb is just empty. the theos staging dir also only contains the control file and not any other contents

slim bramble
#

It took me 1h to realise I sent requests async and that’s why I couldn’t pass the data on to the main thread 😭

hasty ruin
slim bramble
slate isle
#

now im getting

nroot@localhost:~/TrollStore$ make -C ./TrollStore FINALPACKAGE=1
make: Entering directory '/home/nroot/TrollStore/TrollStore'
> Making all for application TrollStore…
==> Copying resource directories into the application wrapper…
==> Compiling TSAppInfo.m (arm64)…
TSAppInfo.m:971:31: error: use of undeclared identifier 'commonTCCServices'; did you mean 'CommonTCCServices'?
                                                NSString* displayName = commonTCCServices[serviceID];
                                                                        ^~~~~~~~~~~~~~~~~
                                                                        CommonTCCServices
/home/nroot/TrollStore/TrollStore/TSCommonTCCServiceNames.h:3:15: note: 'CommonTCCServices' declared here
NSDictionary* CommonTCCServices() {
              ^
TSAppInfo.m:971:48: error: array subscript is not an integer
                                                NSString* displayName = commonTCCServices[serviceID];
                                                                                         ^~~~~~~~~~
2 errors generated.
make[3]: *** [/home/nroot/theos/makefiles/instance/rules.mk:278: /home/nroot/TrollStore/TrollStore/.theos/obj/arm64/TSAppInfo.m.0b72d69c.o] Error 1
make[2]: *** [/home/nroot/theos/makefiles/instance/application.mk:50: /home/nroot/TrollStore/TrollStore/.theos/obj/arm64/TrollStore.app/TrollStore] Error 2
make[1]: *** [/home/nroot/theos/makefiles/instance/application.mk:41: internal-application-all_] Error 2
make: *** [/home/nroot/theos/makefiles/master/rules.mk:146: TrollStore.all.application.variables] Error 2
make: Leaving directory '/home/nroot/TrollStore/TrollStore'

slate isle
#

@naive kraken

naive kraken
#

you modified the code in an attempt to fix the issue but did it wrong?...

slate isle
#
//
//  TSCommonTCCServiceNames.h
//  IPAInfo
//
//  Created by Luke Noble on 30.10.22.
//

#import <Foundation/Foundation.h>

NSDictionary* CommonTCCServices() {
    return @{
        @"kTCCServicePhotos": @"Photo Library",
        @"kTCCServicePhotosAdd": @"Photo Library (Add)",
        @"kTCCServiceCamera": @"Camera",
        @"kTCCServiceMicrophone": @"Microphone",
        @"kTCCServiceAddressBook": @"Contacts",
        @"kTCCServiceCalendar": @"Calendars",
        @"kTCCServiceReminders": @"Reminders",
        @"kTCCServiceWillow": @"HomeKit",
        @"kTCCServiceGameCenterFriends": @"Game Center Friends",
        @"kTCCServiceExposureNotification": @"Exposure Notifications",
        @"kTCCServiceFocusStatus": @"Focus Status",
        @"kTCCServiceUserTracking": @"User Tracking",
        @"kTCCServiceFaceID": @"Face ID",
        @"kTCCServiceMediaLibrary": @"Apple Media Library",
        @"kTCCServiceMotion": @"Motion Sensors",
        @"kTCCServiceNearbyInteraction": @"Nearby Device Interaction",
        @"kTCCServiceBluetoothAlways": @"Bluetooth (Always)",
        @"kTCCServiceBluetoothWhileInUse": @"Bluetooth (While In Use)",
        @"kTCCServiceBluetoothPeripheral": @"Bluetooth (Peripherals)",
        @"kTCCServiceLocation": @"Location"
    };
}
#

new code

#

oh i think i fixed it

#

its building so far

#

damn

#
==> Linking application TrollStore (arm64)…
Undefined symbols for architecture arm64:
  "___isOSVersionAtLeast", referenced from:
      -[TSSettingsListController viewDidLoad] in TSSettingsListController.m.0b72d69c.o
ld: symbol(s) not found for architecture arm64
clang-11: error: linker command failed with exit code 1 (use -v to see invocation)
make[3]: *** [/home/nroot/theos/makefiles/instance/application.mk:50: /home/nroot/TrollStore/TrollStore/.theos/obj/arm64/TrollStore.app/TrollStore] Error 1
make[2]: *** [/home/nroot/theos/makefiles/instance/application.mk:50: /home/nroot/TrollStore/TrollStore/.theos/obj/arm64/TrollStore.app/TrollStore] Error 2
make[1]: *** [/home/nroot/theos/makefiles/instance/application.mk:41: internal-application-all_] Error 2
make: *** [/home/nroot/theos/makefiles/master/rules.mk:146: TrollStore.all.application.variables] Error 2
make: Leaving directory '/home/nroot/TrollStore/TrollStore'
naive kraken
#

you need some additional stuff to compile availabilities on linux

#

I don't remember what it was called though

fossil umbra
#

I tried asking this question in Genius Bar but no response and I think it might be more suited for development

I want to flash a rom on a SOIC8 chip with a soic8 chip clip and wanted to know if the iPhone can interact with a ch341a programmer over lightning to usb

slate isle
slender glade
# slate isle ill ask in theos
#ifndef __APPLE__
int __isOSVersionAtLeast(int major, int minor, int patch) {
    NSOperatingSystemVersion version;
    version.majorVersion = major;
    version.minorVersion = minor;
    version.patchVersion = patch;
    return [[NSProcessInfo processInfo] isOperatingSystemAtLeastVersion:version];
}
#endif
#

add this

slender glade
#

the file

#

lo

#

lol

slate isle
gentle grove
primal perch
#

fr

#

most sane OOP head

tepid olive
#

Zig.

#

8i love zig

#

Zig is better than swift

#

It’s better than objc

placid kraken
#

(love zig) + 8i

tepid olive
#

Lmao

#

Definitely not a typo

slender glade
#

the api design is very human.

slim bramble
#

@hasty ruin

slender glade
#

No.

#

@grim sparrow minecraft launcher is electron

#

im actually gonna kms

grim sparrow
#

Fuck off

#

Surely not

#

That’s mental

slender glade
slender glade
#

electronites are actually leeches

grim sparrow
#

Writes a game in Java
Makes the launcher in electron

#

Maniacal

slender glade
#

funniest part of it all

#

could've written a nice cross platform in java

#

no they went for js

#

just insane lol

grim sparrow
#

I bet some PM went java and js must be similar

slender glade
#

this made me chuckle

grim sparrow
#

It’s quite humerous

slender glade
lean ermine
slender glade
#

i open the app

#

i press play minecraft

#

the app closes

#

no ofc i didn't notice

lean ermine
#

open the app

#

load web browser launcher

#

press play minecraft on secret web browser launcher

slender glade
#

i got real responsibilities and ur telling me abt minecraft secret web browser launcher

#

man shut up

lean ermine
#

LOL

timid briar
#

Prism launcher >

odd timber
sonic totem
#

Yes

torn cloud
#

a write-up would be helpful

sonic totem
#

The CVEs have no credits

#

Although you can guess what the bugs are from the descriptions

torn cloud
#

lol

sonic totem
#

kernel memory protections

torn cloud
sonic totem
#

Nah

#

Bigger than that

torn cloud
#

hmmm

sonic totem
#

Think about it literally

#

What protects kernel memory from being written to

sonic totem
#

It’s not KTRR no

slim bramble
torn cloud
slim bramble
#

I know :D

torn cloud
slim bramble
torn cloud
#

but i don't have a clue lol

slim bramble
#

Are you gonna try all of them

sonic totem
slate isle
# slender glade ```objc #ifndef __APPLE__ int __isOSVersionAtLeast(int major, int minor, int pat...

that worked and i got a little further

==> Signing TrollStore…
bash: line 1: ../Exploits/fastPathSign/fastPathSign: No such file or directory
make[2]: *** [/home/nroot/theos/makefiles/instance/application.mk:49: /home/nroot/TrollStore/TrollStore/.theos/obj/debug/TrollStore.app/TrollStore] Error 127
rm /home/nroot/TrollStore/TrollStore/.theos/obj/debug/TrollStore.app/TrollStore.60e94b38.unsigned
make[1]: *** [/home/nroot/theos/makefiles/instance/application.mk:41: internal-application-all_] Error 2
make: *** [/home/nroot/theos/makefiles/master/rules.mk:146: TrollStore.all.application.variables] Error 2
slim bramble
#

don't know if it's a thing

sonic totem
#

I’ve never heard of that

slim bramble
#

Same

#

probably SIP

sonic totem
#

There’s SIP on macOS?

slim bramble
#

but a ripoff

torn cloud
sonic totem
#

Anyways @torn cloud it’s PPL

slim bramble
#

:c

#

@sonic totem

#

it's a thing

tepid olive
#
    substrate.MSHookMessageEx(objc.getClass("NCNotificationShortLookView").?.value, objc.sel("viewDidLoad").value, viewDidLoadHook, &ogviewdidload);
slim bramble
#

KIP actually exists

tepid olive
#

it found the type it expected

sonic totem
#

But Apple’s name for it

slim bramble
lyric heron
#

imagine if it wouldve been a sptm bypass

#

guess im updating anyway lol

sonic totem
slim bramble
sonic totem
sonic totem
slim bramble
#

Oh

sonic totem
#

This is your best chance

slim bramble
#

you redacted me

#

And you are prob right

#

ngl

sonic totem
#

I am right

#

Because the screenshot you sent says it was introduced in A10

#

Which KTRR was

#

And KPP was A9

#

And KTRR uses the MMU/AMCC

slim bramble
#

The description of the thing made me think it's KTRR

slim bramble
sonic totem
lyric heron
sonic totem
#

I see

sonic totem
#

Editing

#

Funny

slim bramble
#

He seems very cool

sonic totem
#

Not if you ask me to

slim bramble
orchid fulcrum
#

While you guys are talking already i have a stupid af question: Is finding UaF's just as simple as detecting code where they forgot to assign null to pointers after deleting the memory ?

sonic totem
#

You have to ensure that it is actually used after it’s free’d

#

And the effects of that

#

And whether you can exploit it or even trigger it

orchid fulcrum
#

I see thx 👍

orchid fulcrum
slim bramble
#

mov r0, 0x0 ?

sonic totem
sonic totem
#

You'd have to find the free() function

#

But would probably be something like

ldr x0, my_buffer
bl _free```
#

Maybe ldr is wrong idk

#

adr maybe

slim bramble
#

I forgot what ldr is for

native orbit
#

load

slim bramble
#

I don't know my arm asm 😭

sonic totem
#

@native orbit get in here

#

LMFAO

#

Predicted

slim bramble
sonic totem
#

Anyways if I want to load addr of buffer in x0

#

Is it ldr

slim bramble
#

oh smh ldr is mov

sonic totem
#

what

slim bramble
#

Idk I've read that 🤷‍♂️

sonic totem
#

isn't adr PC-relative

native orbit
#

prob would be like

adrp  x0, #123
add   x0, x0, #1337
ldr   x0, [x0]
native orbit
#

adrp gets page aligned addr

sonic totem
#

ah right

native orbit
#

add is adding the offset from page to the buffer

sonic totem
#

why the add x0, x0, #1337

#

Oh

slim bramble
slim bramble
native orbit
#

ldr will load the buffers value (if using uint64_t)

#

ldrb if just doing bytes

sonic totem
#

I see

slim bramble
#

Interesting

#

Time to rewrite 16Player in asm ngl

#

@acoustic imp you down ?

acoustic imp
#

😭

slim bramble
acoustic imp
#

👋

#

hm when eta drm server not repsond with gargbage

slim bramble
#

if I don't take in consideration testing

acoustic imp
indigo peak
#

@hasty ruin

slim bramble
tepid olive
#

@native orbit I appear to be in a pickle

#

so

serene hawk
#

if you need help setting up drm i’d be happy to help @indigo peak

tepid olive
#

zig-objc

#

imports objc/runtime.h

slim bramble
tepid olive
#

but so does the substrate header

#

so

#

it generates the same types twice

serene hawk
indigo peak
native orbit
indigo peak
#

I just asked icraze bc his drm is bulletproof

slim bramble
tepid olive
#

but like

#

it generates the types without error

serene hawk
tepid olive
#

it's just when I try to pass the ones from zig-objc to substrate

#

it

serene hawk
#

i had a pretty secure concept

slim bramble
sonic totem
serene hawk
#

it just lacked clean code 🤠

tepid olive
#

errors like: error: expected type '?*cimport.struct_objc_class', found '?*cimport.struct_objc_class'

tepid olive
serene hawk
tepid olive
#

apparently it somehow generates the same type twice if you import the same header twice

slim bramble
tepid olive
#

except the solution they provided doesn't work in this situation

#

I mean I could just cast

#

but that's kinda cursed

acoustic imp
indigo peak
acoustic imp
#

real

#

is there an entitlemeant the app store apps have to allow in app purchases ?

marble jacinth
#

why is binary ninja not responding

sonic totem
marble jacinth
visual meadow
indigo peak
slim bramble
marble jacinth
#

(it was using 27gb of ram)

#

(its using 15gb rn)

slim bramble
marble jacinth
#

i have 80gb of ram

slim bramble
#

Oh forgot about that

#

yeah

next zenith
#

is force unwrapping in swift a bad idea

#

i just used it to calculate where and where not is a bad position to put a window

#

and uh

#

it compiled

#

so idc

kind herald