#development

1 messages · Page 266 of 1

surreal mountain
#

@tepid olive when will you shut the fuck up

gaunt mesa
#

gonna need more than that i'd imagine
@half walrus just buy new computer obviously

surreal mountain
#

honestly

gaunt mesa
lime pivot
#

I do have this

tepid olive
#

it was very laggy
@surreal mountain imagine having shit pc

half walrus
#

checkra1n a11 patch
@gaunt mesa ok so apparently the panic was manual in pongo?

tepid olive
#

/s

half walrus
#

and i didn't know this?

lime pivot
#

which is washed out for some reason

surreal mountain
#

carson my pc is better than yours

#

stfu

#

@gaunt mesa ok so apparently the panic was manual in pongo?
@half walrus yes

gaunt mesa
#

@gaunt mesa ok so apparently the panic was manual in pongo?
@half walrus yeah it would just force reboot

half walrus
#

otherwise I would've patched that out a month ago when i was talking about doing it with kirb

tepid olive
#

well if it lags with checkra1n obv its not

gaunt mesa
#

cuz without password isn't really ideal

surreal mountain
#

literally the only thing different between patched and non is the panic function returns 0 every time

tepid olive
#

yup

gaunt mesa
tepid olive
#

lol

gaunt mesa
#

that's it?

half walrus
#

deadass

surreal mountain
#

thats literally the only thing

gaunt mesa
#

bruh moment

lime pivot
#

I forgot that it was even us doing the reboot until yesterday lmao

half walrus
#

i've been stuck with iSH

#

for a month

tepid olive
#

static int shouldPanic() {
return 0;
}

half walrus
#

had to port dragon to ish cat_cry

gaunt mesa
#

static

surreal mountain
#

patched vs unpatched

half walrus
#

that theme looks like

#

binaryninja or w/e it is

gaunt mesa
#

i need windows

surreal mountain
#

pretty sure thats just ida dark

gaunt mesa
#

so i can get IDA 7.3

tepid olive
#

i need windows
@gaunt mesa you have windows, no??

surreal mountain
#

@gaunt mesa cryptic has ida 7.3 on his site

gaunt mesa
#

@gaunt mesa you have windows, no??
@tepid olive no?

surreal mountain
gaunt mesa
#

why would i have windows?

tepid olive
#

@tepid olive no?
@gaunt mesa at one point you def had windows

half walrus
#

how good is your pc

gaunt mesa
#

well

tepid olive
#

why would i have windows?
@gaunt mesa for playing games

gaunt mesa
#

its a 6th gen i7

half walrus
#

and are you on macos

gaunt mesa
#

i use my macbook

#

mostly cuz i can sit in bed

#

and watch netflix instaed

half walrus
#

get VMWare Fusion

gaunt mesa
#

of getting shit done

half walrus
#

you can find it fairly easy on the usual sites

gaunt mesa
#

is there something like parallels but it remotes into my PC?

#

or is that what fusion does

half walrus
#

this is better

lime pivot
#

ah yes I forgot every second time I compile now, a cocoapod says it can’t find a symbol in another cocoapod and I have to nuke derived data and rebuild

gaunt mesa
lime pivot
#

today is really not my day

gaunt mesa
#

go ahead krit

half walrus
#

let me show you

surreal mountain
#

why so many orange names

gaunt mesa
#

but its a VM

surreal mountain
#

im breaking the cjhain

gaunt mesa
#

my macbook will 100% crash

tepid olive
#

bruh

gaunt mesa
#

ah

#

ah

#

ahhhhhhhhhhhhh

half walrus
#

that sounds cool

surreal mountain
#

u have to pay for that

#

lol

half walrus
#

yeah saas

gaunt mesa
#

fuck saas

surreal mountain
#

literally use windows server

half walrus
#

servers cost money

surreal mountain
#

it has all of that

gaunt mesa
#

bro

half walrus
#

yeah just run a vnc on windows

gaunt mesa
#

my PC is currently linux

surreal mountain
#

ok and

half walrus
#

then run a vnc on linux

surreal mountain
#

does your school use microsoft at all @gaunt mesa

gaunt mesa
#

please tell me how to transfer scarlett to VM and how bad overhead is

surreal mountain
#

like office 365 or anything

gaunt mesa
#

then run a vnc on linux
@half walrus server

half walrus
#

yes

gaunt mesa
#

cba to use UI

half walrus
#

yes

gaunt mesa
#

winux obviously

half walrus
gaunt mesa
#

im not switching back to WSL tho so ill probably do what quiprr does

#

linux VM and windows server

half walrus
#

its 2 commands

#

ok what

gaunt mesa
#

does your school use microsoft at all @gaunt mesa
@surreal mountain no

half walrus
#

what is your machine

surreal mountain
#

@surreal mountain no
@gaunt mesa F

#

u need to pay lots for windows server

#

i can lend you a key

gaunt mesa
surreal mountain
#

you want a windows server 2019 standard, essentials, windows server 2016 standard, essentials, or datacenter key

#

i recommend datacenter so you can have infinite vms with hyper-v

gaunt mesa
#

@half walrus i still want to be able to use windows tho

#

do u have any suggestions to be able to use all 3 OSes without using like 5 million computers

half walrus
#

what I do is vmware fusion + win vm + WSL

gaunt mesa
#

ah WSL

half walrus
#

or

gaunt mesa
#

is WSL 2.0 actually good tho?

half walrus
#

vmware fusion also lets you run a headless vm to ssh into

surreal mountain
#

renai

gaunt mesa
#

also how does the whole docker situation work with WSL

surreal mountain
#

what is your end goal

#

one pc to run linux and mac and windows?

gaunt mesa
#

no

#

macbook is for macOS

#

and then be able to access windows and linux both

#

without switching OS on machine

#

like rebooting

surreal mountain
#

ok so

#

get windows 10 standard and use your preferred way of not paying

#

install hyper-v

gaunt mesa
#

i already have pro

surreal mountain
#

ok

gaunt mesa
#

wtf why hyper-v why not just WSL

surreal mountain
#

thats good

gaunt mesa
#

docker even has WSL mode apparently

surreal mountain
#

wsl is just shit

#

any virtualization software that isnt wsl is better imo

gaunt mesa
#

what I do is vmware fusion + win vm + WSL
@half walrus ill probably try this but the thing where isntead of a VM it does the window splitting with an actual windows machine

surreal mountain
#

wsl is not fun and bad

gaunt mesa
#

im not making tweaks on WSL

#

its only for typescript stuff

surreal mountain
#

ok

tepid olive
#

I have vmware

gaunt mesa
#

i do want a way to SSH straight into the linux tho if i need to

tepid olive
#

what are the cool things about VMware pro

gaunt mesa
#

nothing

half walrus
gaunt mesa
#

jesus

#

how powerful is ur mac

restive ether
#

kritana bad dragon cat

surreal mountain
#

powerlevel uhh

#

spaceship or starship good

restive ether
#

p10k good

gaunt mesa
#

p10k is fine

surreal mountain
#

eh

gaunt mesa
#

wait wtf

surreal mountain
#

p10k

gaunt mesa
#

how do u have mac windows and windows windows overlapping

half walrus
#

vmware fusion

gaunt mesa
#

so it does the thing parallels does

#

why isn't there a non VM solutino for this

half walrus
#

because every other solution sucks

gaunt mesa
surreal mountain
#

wtf how

gaunt mesa
#

can u get rid of that start menu tho

#

looks ugly ngl

half walrus
#

on mine?

gaunt mesa
#

yeah

half walrus
#

yeah i just threw that there to make it clear what was going on

gaunt mesa
#

ah

#

i wish my macbook didn't suck

half walrus
#

yeah i kinda upgraded this machine specifically for VMs

surreal mountain
#

dman

gaunt mesa
#

that's around the shit of my PC

half walrus
#

oh yeah if you have boot camp on your macbook vmware fusion can boot it

gaunt mesa
#

parallels RAS is $100/y

#

the issue with other RDS or VNC clients is that it doesn't do the thing that fusion or parallels do

#

whatever its called where it splits the windows and adds them to ur mac dock

half walrus
#

i mean if i need <x> os that bad i just reboot lol

gaunt mesa
#

what is that feature even called

#

where it does that

half walrus
#

called 'unity' in fusion

#

i'd just call it host window server compatibility

#

¯_(ツ)_/¯

gaunt mesa
#

google moment: vnc for windows with unity feature

half walrus
#

alright time to close the window on this 9gb ida db

half walrus
#

oh yeah

#

i found sshing into my windows VM was more effective than running linux vms

#

and just using WSL2 there

gaunt mesa
#

i might use hyper-v for linux

#

so i can ssh directly when using code server and stuff

surreal mountain
#

those all only have one vcpu

half walrus
#

alright time to close the window on this 9gb ida db
and now my pc is unusable

#

oop there it went thank god

surreal mountain
#

pihole constantly serving dns, quiprr.dev serving packages and shit, merlin kinda idle, draco never goes above 3 ish even when compiling

gaunt mesa
#

apparently tightvnc has something

surreal mountain
#

interesting why its always at 0

#

what else should i virtualize

gaunt mesa
#

but can u use windows server as a normal OS

surreal mountain
#

what is ur goal

#

i use windows server because its good and i have free keys for it

#

legitimate copies

gaunt mesa
#

how different is windows server from regular windows

#

im assuming a lot of shit is cut out

surreal mountain
#

uh i mean

#

yeah

#

a good amount of shit will just fucking die

half walrus
#

but can u use windows server as a normal OS
@gaunt mesa ye but dont

surreal mountain
#

good for server purposes but not good for daily use

gaunt mesa
#

does 10 pro have hyper-v

half walrus
#

if you've ever installed a window server to a VPS and vnc'ed in

surreal mountain
#

does 10 pro have hyper-v
@gaunt mesa yes

gaunt mesa
#

virtual display manager

#

damn what are these things

surreal mountain
#

wtf is i64

half walrus
#

is that IDA

surreal mountain
#

yes

half walrus
#

did you save the database

gaunt mesa
#

the .i64 file

surreal mountain
#

oh

half walrus
#

idb

#

i64 is a 64 bit idb

surreal mountain
#

i didnt save the database

#

but i can

#

which one you want

gaunt mesa
surreal mountain
#

please dont say both fr

half walrus
surreal mountain
#

ok

#

what arch do u want

half walrus
#

I was just wanting to see which function got patched

surreal mountain
#

oh

#

whatever the panic one is lol

half walrus
#

did you have to pull out pongo or was this in the main binary

surreal mountain
#

this is in pongo but its in the binary iirc

#

cryptic is the one that told me that but ik the dude was just distributing a binary

gaunt mesa
#

@half walrus might use this with my PC

#

so i can just switch between windows and linux with no effort

#

i don't technically need them at the same time

half walrus
#

mm

#

i'd suggest clover

gaunt mesa
#

can u change the booted OS from within the OS?

#

ie

surreal mountain
#

alright i will be taking a break while ida does its thing

gaunt mesa
#

if im in linux can i switch to windows from ssh

#

and then from windows switch to lunix

half walrus
#

not easily, didn't know that was a requirement

#

should be a way to edit the nvram and tell clover to boot <x> when it starts up

gaunt mesa
#

like for example

#

lets say im sshed into linux

half walrus
#

which is what that thing is doing

gaunt mesa
#

i can just type something like 'boot-to-windows' and it'll reboot into windows ig

half walrus
#

can any tool do that?

gaunt mesa
#

idk

#

hate it here woeis

half walrus
#

You could automate it yourself w/ clover

gaunt mesa
#

yeah u said its an NVRAM thing to decide which OS to boot right?

half walrus
#

that was out of my ass bc i dont actually know

gaunt mesa
#

lol

#

so its either that or virtualize something

primal perch
#

hey have you heard of opencore go get it btw im an arch user arch best lmao your using windows spyware LMAO

half walrus
#

swap.sh

mount /efidrive blah
cat efidrive/EFI/CLOVER/config.plist | s/driveuuid1/driveuuid2/g > efidrive/EFI/CLOVER/config.plist
reboot
#

ezpz

gaunt mesa
#

i would use windows and WSL if there was something like unity mode for a physical windows thing

half walrus
#

and have the config boot default drive with a timeout of 1s

gaunt mesa
#

cuz docker even has WSL support

half walrus
#

lol docker is broken as shit on macos

gaunt mesa
#

yeah

#

which is why ive sworn to never run it on here again

#

that and mongodb

half walrus
#

oh yeah fusion supports windows taskbar icons too 😛

gaunt mesa
#

BROO

surreal mountain
#

damn

#

that is sick af

gaunt mesa
#

need this for non virtual fucking woe

half walrus
#

it's not do-able without a VM running somewhere

#

windows being able to boot a linux kernel is nuts already

#

nuts

gaunt mesa
#

windows 10 pro, but get this: i run a windows 10 vm

#

then i can profit intjallah

surreal mountain
#

renai

#

use your build server

#

put ws on it

#

virtualize w10

#

virtualize sashimi

#

profit

#

just use vmware to virtualize

gaunt mesa
#

vspehere is saas

surreal mountain
#

ok

gaunt mesa
#

i literally just need the application virtualization thing

#

and im good

#

wait

#

App-V exists

half walrus
gaunt mesa
#

i wish i had two monitors

half walrus
#

good lord that's so compressed wtf

#

ok anyways i dont use unity much

gaunt mesa
#

woe

half walrus
#

make multiple desktops on both screens then

#

set top left to mission control

#

drag mouse to top left i need to use 2nd monitor for non windows, otherwise it's fullscreen

#

macOS window server is unbeatable

gaunt mesa
#

is it possible to ssh into WSL

half walrus
#

yeh one sec

gaunt mesa
#

for vscode-server

#

VBoxManager createvm

#

oh god

half walrus
#

install openssh-server via package manager (or equivalent ), ifconfig | grep -A1 eth0: | grep inet | sed -e 's/\s\+inet \(.*\) netmask.*/\1/'

gaunt mesa
#

wait i just realized one more alternaitve

half walrus
#

ssh to that

#

trying to fix up my arch wsl install my mirrors are borked

gaunt mesa
#

i could do a windows VM using kvm

#

couldn't i?

#

and then just VNC into the virtual windows for windows only shit

half walrus
#

that sounds a bit painful unless you have >100mb/s <10 ping

gaunt mesa
#

1.5gbps intjbruh

#

the computer in question is next to my legs rn

#

under my desk

half walrus
#

ah

gaunt mesa
#

and since i don't really need windows for heavy shit and if im gonna play games then just boot into an actual windows dummy that i install

half walrus
#

i was gonna say if you had that download speed

gaunt mesa
#

shadow nfr

half walrus
#

I got to try the beta

#

right when that came out

gaunt mesa
#

is it nice?

#

i didn't like geforce now that much

half walrus
#

how fast is your internet

#

it was

gaunt mesa
#

lemme find the bell package

half walrus
#

it was worth it on my laptop when I had 30mb/s 50 ping to it

#

it wasn't worth it here on my 2MB/s

gaunt mesa
#

bell website is slow

half walrus
#

so instead i just melted my iGPU mcatDab

gaunt mesa
#

LMAO

half walrus
#

did u know u can crank an intel HD 630 up to 15x

#

with The Ritual™️

#

+30mv to cpus, +150mv to iGPU

#

underclock cpu to 5% performance

#

cool laptop to 60F

gaunt mesa
#

bro im trynan show u the plan

#

but bell sucks

half walrus
#

incriment from 11x up to 15x in .5x incriments

#

100FPS in tf2 on integrated graphics

gaunt mesa
#

wtf

#

anyways yeah i have 1.5gbps/900

#

or sm

half walrus
#

oh yeah and once it's at 15x you can then undervolt your cpu and turn on turbo boost

gaunt mesa
#

isn't it dangerous to undervolt

half walrus
#

poor fucking laptop ran at 90º C for hours

#

isn't it dangerous to undervolt
on the contrary i'd reccomend it

#

uses less power

#

makes less heat

#

stable as fuck on windows with throttlestop

#

can do -150mv there

gaunt mesa
#

wtf

half walrus
#

-75 on macos with volta which runs like a Packix $1 tweak

#

i've bought it 3 times bc the drm is broken

#

and i ended up having to pirate it anyways because it's just fucked

gaunt mesa
half walrus
#

but it's the only program that can undervolt and enable turbo on macos

narrow mason
#

fr
@gaunt mesa

gaunt mesa
#

jlues

half walrus
#

need a 3rd monitor ffs

#

wait i have an ipad air

gaunt mesa
#

i need monitors

half walrus
#

Not Charging

#

screw u appl

gaunt mesa
#

it always says that

half walrus
#

bc my keyboard only puts out 1a

#

have a spliced usb hub somewhere 1 sec

gaunt mesa
#

i need a good setup

#

i hate the fact that i do a lot of docker stuff and my macbook just can't handle it

half walrus
#

someday i'll move to canada

gaunt mesa
#

are you canadian frcyclops
@vivid dew uhhclops

half walrus
#

mcat better hire my dumb ass eventually

gaunt mesa
#

frnod

half walrus
tepid olive
#

i'm really not that good but i mean i could try

half walrus
#

do you dev i cant remember

tepid olive
#

has been a while i touched objc

half walrus
#

just grab flex

tepid olive
#

i did make one thing but wasn't really advanced

half walrus
#

and dick around

#

that's the stage i'm at rn

gaunt mesa
#

does windows server run windows VMs well

tepid olive
#

@half walrus burrit0z made some progress on that

#

interesting

half walrus
#

@tepid olive

tepid olive
#

would need a little more than basic passcode, would be really nice to have some sort of security layer?

half walrus
#

that's the goal here

tepid olive
#

yeah

#

also what stops you from just.. you know.. rebooting lol

#

wonder if it would be possible to make it auto enable passcode before rebooting, or implementing a mechanism there

#

highly doubt it tho

#

sep is pain.

#

nah it just kps if you try

#

so passcode is 100% stored in sep right

upper mountain
#

ayy welcome back krit

half walrus
tepid olive
#

Please don't promote hacked pongo builds :/

half walrus
#

i'm frustrated enough with the fact it was a manual panic in pongo and that wasn't disclosed to tweet it out (with a disclaimer ofc)

#

i've been stuck with iSH and sshing into a VPS from my phone to unzip files for a month

tepid olive
#

oh yes files app

half walrus
#

requiring bsdiff and having no usage instructions on the github is enough of a barrier to entry

#

if it took me 5 minutes to get it to work, hopefully most of the 'special' users won't be able to

tepid olive
#

@half walrus so when booted on 14 with no sep vuln anything enabling sep panics it right

half walrus
#

dont know

#

SEP isn't in my area

#

not very interested in hopping into it

tepid olive
#

alright

half walrus
#

well

#

on iOS 14's SEPOS, when you send the SEP a request to decrypt the user partition, it checks if (something? a few registers i believe?) have been brought up, and if so, the device was booted from DFU, so it panics the device

surreal mountain
#

yeah that basically

tepid olive
#

couldn't the key for the registers be bruteforced or it's timed

half walrus
#

here's tihmstar triggering the panic, i think I got this about a week earlier

surreal mountain
#

krit

#

help with ida

#

so i want to go to the panic function

#

how do i find it

tepid olive
#

go to string view, search for either "killing task" or "due to crash" or "FAR_EL1" etc

#

xref the steing and you should land in panic

#

also you can look at pongo source online to aid

half walrus
#

no desire to deal with their obfuscation today

surreal mountain
#

obfuscation is so annoying

#

like

#

i opened an obfuscated dylib of my own tweak and realized just how bad it was

tepid olive
#

currently dealing with a null pointer dereference and I have no idea where its coming from smolhappy

half walrus
#

it's not hard to get an unobf pongo but it's not what i want to spend my time on rn

surreal mountain
half walrus
#

still waiting

twilit jungle
#

publish the jailbreak as my own
fr

half walrus
#

lmfaoo

tepid olive
#

krit what compelled you to return

surreal mountain
#

me

#

fuck

half walrus
#

krit what compelled you to return
@tepid olive a11 i14 patch

#

is why i'm in the server rn

#

also irc is dead

tepid olive
#

are you going to leave again peepoCry

half walrus
surreal mountain
#

what irc sus

half walrus
#

saurik's

#

probably gonna make my own tonight while I wait on IDA

tepid olive
#

sp3 👀

half walrus
#

are u

#

oh yeah you paid

#

what's in sp3

tepid olive
#

dunno lol but every time I get an email from hex rays it's like christmas when you're 10

half walrus
#

ikr

#

Key highlights:

  • improved macOS11 kernel debugging with VMware Fusion 12;
  • improved symbolication of MH_FILESET kernelcaches;
  • fixed some potential crash situations and enhance IDA performance by fixing minor errors.
#

IDAPython: ida_bytes.bin_search documentation was lacking

#

fucking lol

tepid olive
#

🤣🤣

half walrus
#

i specifically remember trying to figure that one out

tepid olive
#

bruh, most documentation is lacking. It's so ridiculous. Like you can get the next typedef in a typedef chain but that returns a string and not an object so you can't get the typedef after that one

#

but then there's the times where idapython "just works" and it's amazing

half walrus
#

all of the docs are fucked

#

this is what i ended up using for bin search

tepid olive
#

nice

#

sometimes ida just magically fails with get_type

#

other times it works fine

half walrus
tepid olive
#

so annoying when you're trying to demangle and parse c++ fxns

half walrus
#

lol that embed icon has been cached for over a month gg discord

#

goal with this ibootloader is to have complete coverage and 50% symbolication of all (64 bit, most likely) securerom dumps

tepid olive
#

WHY does McDonalds have jb detection

half walrus
#

lol right

tepid olive
#

Literally all I want to see is if I can get a free burger when I make a new account

half walrus
#

well

#

that's why right there lmfaO

tepid olive
#

That's what I was able to do with burger king last week and got a whopper for free

#

no like actually legit

#

I have never used the mcd app

half walrus
#

dont think they have deals like that

surreal mountain
#

liberty lite beta works on mcds btw

half walrus
#

but the regular deals are really good on there

surreal mountain
#

krit make ur own irc ill join

tepid olive
#

i'm gonna shove this into ida and it's gonna be a 500 mb OLLVM bin lmfao

half walrus
#

lol

#

more like 500MB of frameworks

tepid olive
#

loool

half walrus
#

the sonic app is

#

i actually want to check right now

tepid olive
#

yo sonic

half walrus
#

i think it's native

#

but it looks like a shitty web app

#

it's impressive

tepid olive
#

I should check for new acct deals there

half walrus
#

nah

#

they patched those

tepid olive
#

bk app seems like a shitty web app also

#

@tepid olive
@half walrus ?

#

No I'm trying to do this legit

#

bk app makes my phone unbeliveably hot

half walrus
#

scroll up on that msg @tepid olive

tepid olive
#

Oh

#

Passcode thing

half walrus
#

yoy

tepid olive
#

Lol yeah I’m working on that

half walrus
#

what'd you figure out

#

i had this idea a month ago i wanna do it

tepid olive
#

Well I got it to the point where I can fake the passcode screen, I just need to find the right way to present it and block unlocking of the device

I’m not going for a full passcode replace I don’t think, probably just a unlock passcode

#

Lemme find the video

half walrus
#

ok so my goal is

#

figure out how to trigger it at the lowest level

#

no encryption stuff ofc

#

just to see how much can be fixed

tepid olive
#

Yeah rn I’m still at surface level passcode because that’s all that really matters to me

tepid olive
#

But ultimately hooking whatever determines if passcode is on, and then intercepting the call to check hash via sep is the goal

#

Ok I read

half walrus
#

yep

#

yeah u nailed it right there

#

makes me giddy watching ppl independently having the exact same ideas i did with this problem

tepid olive
#

Iirc I did find a useful class that could have told springboard whether a passcode was set but I forget

#

I’ll have to look on my test device tomorrow, I always take screenshots of classes in Flex to remind myself

half walrus
#

need a new twitch username

#

hm

surreal mountain
#

cockmeister6969

tepid olive
#

What about face id devices

#

@tepid olive

#

oh wait nvm

half walrus
#

what abt em

tepid olive
#

I forgot you could have an actual passcode lol

#

Yeah im not tryna fuck with Face ID if that’s what you are getting at

#

May as well rewrite springboard

surreal mountain
#

you literally made cock id stfu

tepid olive
#

SHUT

half walrus
#

when

tepid olive
#

when what

half walrus
#

cock id when

tepid olive
#

Oh it already exists

half walrus
#

omg the boomer is streaming

tepid olive
#

Ok

surreal mountain
#

who

#

is the boomer

half walrus
#

i was browsing twitch at 2 am

#

tf2 section bc there's a ton of 0-3 viewer streams

#

where you can really just chat with the streamers

noble rover
#

So does reapplying a passcode after booting the modified checkra1n panic?

half walrus
#

and i found this like 50 year old dude streaming tf2

tepid olive
#

No

half walrus
#

@noble rover yes

tepid olive
#

Wait

#

Yes

#

It does

noble rover
#

Figured

tepid olive
#

I thought you were asking if it panicked after rebooting

#

I didn’t read sorry

noble rover
#

Because that is triggering the SEP

#

I’m trying to figure all of it out

tepid olive
#

SEP doesn’t permanently get fucked

noble rover
#

How exactly is the patch working

tepid olive
#

The patch is not really a patch

surreal mountain
#

stops panic

half walrus
#

pongo was panicking

tepid olive
#

Panic --> nop lol

surreal mountain
#

thats all it does

half walrus
#

on its own

tepid olive
#

so stupid

half walrus
#

manually

#

it's stupid that that was put in

tepid olive
#

It patches out the kernel panic that pongo put in to save SEP

surreal mountain
#

^ why?

#

yeah my thoughts exactly

#

why is that a thing

tepid olive
#

To stop people from using it without SEP

half walrus
#

^

noble rover
#

Makes sense

tepid olive
#

because... the checkrain team is probably finding the best way to approach the issue?

noble rover
#

^

surreal mountain
#

cock are u gonna release cock id

half walrus
tepid olive
#

Disabling SEP - It’s just not a good idea for anyone who cares about what’s on their device

half walrus
#

i like how i can participate in this conversation solely using screenshots of a chat from a month ago

tepid olive
#

and shitty patched pongo floating around isnt ideal

surreal mountain
#

because... the checkrain team is probably finding the best way to approach the issue?
@tepid olive sir this existed before 0.11.0 im 99% sure

noble rover
#

I don’t care about the data on this device. Its my test one I use betas on

tepid olive
#

?

noble rover
#

I don’t have anything personal on it

half walrus
#

@tepid olive arbitrarily limiting the capabilities of something typically results in those limits being patched out :)

#

see: ios

noble rover
#

Hhahahahah

#

Good point

tepid olive
#

Side question: if I reboot can mcd still detect jb

#

cock are u gonna release cock id
@surreal mountain no

half walrus
#

i think so yes

noble rover
#

IOS itself is a good example of that

surreal mountain
#

@surreal mountain no
@tepid olive why not

tepid olive
#

@half walrus yea I guess but it was still shitty of the guy to do that

half walrus
#

disagree

#

don't like the dude actually, but i'm very grateful he did this

tepid olive
#

There are too many false positives with cock ID, my algorithm has a hard time determining the difference between two cocks (yes I tested) @surreal mountain

surreal mountain
#

bro?????????????????????

tepid olive
#

now you have a shit pongo floating around, and then checkrain team is gonna get a bunch of nonsense questions about "why doesnt this work??"

#

And having a stranger be able to pull out their cock and unlock your phone isn’t good

tepid olive
#

and when they finally drop the update for a10 and a11 it'll still be out there

surreal mountain
#

And having a stranger be able to pull out their cock and unlock your phone isn’t good
@tepid olive yeah but how they gonna know

tepid olive
#

Well

#

and inevitably stupid people will be still using patched pongo creating an influx of stupid questions

half walrus
#

If they didn't want this to happen they should've made it possible to disable their own arbitrary limitations

lethal kayak
#

Yeah this sucks for the checkra1n team and it will suck for geniuses to help with especially once the actual official version comes out

half walrus
#

reminds me of people shitting on coolstar for patching substrate

surreal mountain
#

its a 13 year old kid he doesnt know any better lmao

half walrus
#

like ok, saurik wasn't doing it so why the fuck is it an issue

#

if you fight hard to be the singular service a community uses, dont be surprised when people patch it to work after you abandon it

tepid olive
#

@surreal mountain would you like to help improve Cock ID by providing us with data we can use to train AI and increase the accuracy?

#

Maybe the limitation was there so they could figure out the best way to approach the problem of the sep without degrading the quality of release builds?

surreal mountain
#

@tepid olive is there a size requirement

tepid olive
#

Well it must be large enough to be visible

surreal mountain
#

shit

half walrus
#

Maybe the limitation was there so they could figure out the best way to approach the problem of the sep without degrading the quality of release builds?
would've been nice to at least disclose

tepid olive
#

So that might be a problem for you

#

Yeah

#

creator of Pongo Patched is 13? Lolwait

surreal mountain
#

yes

half walrus
#

even without instructions on how to fix it

tepid olive
#

Another issue with cock ID - what if you get a boner

surreal mountain
#

what part of the cock

#

does it scan

half walrus
#

"you want to jb your ipX on 14 you patch it yourself" would be perfect

tepid olive
#

It’s cock ID not Nut ID

lethal kayak
#

Another issue with cock ID - what if you get a boner
@tepid olive Setup Alternate Appearance

surreal mountain
#

yes but

#

there are multiple parts of a cock

tepid olive
#

yea but then that's pretty much inviting unlegit patches to float around

surreal mountain
#

creator of Pongo Patched is 13? Lolwait
@tepid olive yes

tepid olive
#

there are multiple parts of a cock
@surreal mountain yes but there is only one cock (I hope)

surreal mountain
#

yes but

#

what part

tepid olive
#

THE COCK

#

THE ENTIRE COCK

#

reminds me of when I was 14 and started releasing hax and doing stupid things

half walrus
#

yea but then that's pretty much inviting unlegit patches to float around
sounds familiar to a certain mobile operating system

tepid olive
#

NOW CAN YOU PLEASE JUST SUMBIT YOUR DICK PICS @surreal mountain

#

I’m not gay

surreal mountain
#

give me source code please

tepid olive
#

Source code is shit code rn ngl

#

I need to fix it

surreal mountain
#

give me repo access

#

ill clean it up

tepid olive
#

Too much maths

#

ill clean it up
@surreal mountain clean up Cock ID

surreal mountain
#

yes

#

i will

tepid olive
surreal mountain
#

do it

tepid olive
#

On

surreal mountain
#

i need to do math homework

tepid olive
#

yea but checkrain doesn't even compare to the sheer scale of ios. It's managed by a small group and control is the key to sanity when providing such a tool

surreal mountain
#

due at 10 am tomorrow

tepid olive
#

Allah

#

Ok I dm

surreal mountain
#

ok

half walrus
#

yea but checkrain doesn't even compare to the sheer scale of ios. It's managed by a small group and control is the key to sanity when providing such a tool
normally i'd say it was rude to drop that patch, and i'm annoyed at the fact that it's being promoted as user-ready by jailbreak grifters

#

but it was kinda brought on themselves

#

had i not been told by someone on the team that the panic was in SEPOS instead of pongo, i would've done this myself a month ago

#

:p

tepid olive
#

🤔 there mustve been a good reason to ship pongo with the panic, but idk. Just doesn't sit right with me fully

half walrus
#

I understand why they did it

#

100%

#

it would've just been cool to know

lethal kayak
#

By putting it in checkra1n they would imply that it’s user ready so

#

Even if they stated it

#

People don’t read or don’t care

surreal mountain
#

had i not been told by someone on the team that the panic was in SEPOS instead of pongo, i would've done this myself a month ago
@half walrus yeah this is stupid af

#

that someone actually said that

half walrus
#

because this is nowhere near user ready and it's against their entire mission of a secure jailbreak and what they've been promoting for years

#

@surreal mountain it was a mistake on their part

#

misassumption

tepid olive
#

Ok well I’m going to bed, krit if you actually are interested in faking passcode I’ll just be doing some digging in the morning during my study hall, so I can let you know if there’s anything of importance

half walrus
#

been interested for a month lesgo mcatDab

tepid olive
half walrus
#

if you want to do a colab tweak i'm down

tepid olive
twilit jungle
#

Except when other devs release products (aPES_Cough fake passcodes aPES_Cough) on top of “nowhere near user ready” product, the users see that as its user ready.

surreal mountain
#

allah

half walrus
#

yep, thought a lot about how it needs to be marketed

#

a la "insecure" being in the name of the tweak

#

"Insecure Passcode" or something along those lines

surreal mountain
#

Not-A-Passcode

tepid olive
#

OpenGate is the name of my drm

sofuckingfunny sofuckingfunny sofuckingfunny

surreal mountain
#

derived from

half walrus
surreal mountain
#

the boring company's Not A Flamethrower

tepid olive
#

Lmao

surreal mountain
#

which was actually a flamethrower

#

@half walrus when eta we do collab tweak

#

that isnt insecure passcode

half walrus
#

OpenGate is the name of my drm
@tepid olive mine is dire zoop

noble rover
#

Question

#

Abt Checkm8

twilit jungle
#

And you think people read names of shit they download?

gaunt mesa
#

co

#

gg

tepid olive
#

Tbh it’s kinda hard to call what I have a DRM

gaunt mesa
#

er

noble rover
#

The exploit exists in A12 correct?

surreal mountain
#

Abt Checkm8
@noble rover what

half walrus
#

@twilit jungle here's the thing

surreal mountain
#

uh

#

the bug does

gaunt mesa
#

smh not using calypso drm

tepid olive
#

@noble rover yes

surreal mountain
#

the exploit doesnt

tepid olive
#

the bug does

noble rover
#

What abt A13

tepid olive
#

no

surreal mountain
#

no

half walrus
#

if someone grabs my phone and there's no passcode, they get in right now

surreal mountain
#

smh not using calypso drm
@gaunt mesa what is its name

#

that isnt calypso drm

#

cuz

tepid olive
#

I walked around campus today with a phone with no passcode on it fr

noble rover
#

So A12 didn’t fully patch it but A13 did

surreal mountain
#

calypso is name of multipurpose api

half walrus
#

nobody gets usb access to my phone

tepid olive
#

@noble rover yea

#

If I had annoying friends I would have been fucked over

surreal mountain
#

yeah i wont be upgrading for a while

half walrus
#

i have nothing illegal enough to warrant me being worried about encryption

noble rover
#

No one ever touches my phone

half walrus
#

and anything i do need encrypted is in a removable encrypted drive on my pc

#

but

surreal mountain
#

@gaunt mesa will i need to switch lx endpoint since calypso go bye bye

upper mountain
#

enough

tepid olive
#

Encryption ShrekBruh

#

every time I would hand anyone my phone I would get anxious they would tap discord or photos thank goodness for bioprotect

gaunt mesa
#

@gaunt mesa will i need to switch lx endpoint since calypso go bye bye
@surreal mountain for what

surreal mountain
#

dm

lethal kayak
#

@tepid olive what was the reason the bug couldn’t be exploited on A12 again

half walrus
#

i want a passcode on my phone to prevent non-XxHackerMan420-types from getting into it

#

and most users aren't concerned about encryption either

twilit jungle
#

Yes except thats the problem, you shouldn’t have gotten the device to that point in the first place. Like you can live on the edge all you want, just keep in mind users aren’t always going to have the same mindset as you. They aren’t going to be informed about how much risk they are at.

half walrus
#

and they're going to install a bunch of pirate tweaks and fuck their phone anyways

tepid olive
#

@lethal kayak No bootrom memory leak I am 80% sure

lethal kayak
#

@lethal kayak No bootrom memory leak I am 80% sure
@tepid olive ah ok

half walrus
#

i'm not going to sit on a product useful for 10 people because 100 people are going to use it wrong, that's a waste

surreal mountain
#

@lethal kayak No bootrom memory leak I am 80% sure
@tepid olive per siguza you are correct

half walrus
#

^

#

we need a memory leak on a12

tepid olive
noble rover
#

I have another question. Blackbird. Why is it needed? And why are the checkra1n ppl using it. Didn’t they say they didn’t necessarily need it?

tepid olive
#

I need

#

I need

surreal mountain
#

ok

tepid olive
#

I need my battery to last all day

surreal mountain
#

blackbird is a sep exploit

half walrus
#

I have another question. Blackbird. Why is it needed? And why are the checkra1n ppl using it. Didn’t they say they didn’t necessarily need it?
@noble rover they do on 14

tepid olive
half walrus
#

it gets code execution in SEP (well, arbitrary SEPROM loading)

surreal mountain
#

the sep is not decrypting the partition(??) when it is told to when it boots from dfu

gaunt mesa
#

allah

surreal mountain
#

checkra1n does that

#

and needs to boot from dfu

lethal kayak
#

I have another question. Blackbird. Why is it needed? And why are the checkra1n ppl using it. Didn’t they say they didn’t necessarily need it?
@noble rover the SEP panics if you boot from DFU mode. You can’t patch this via checkm8 because there’s a separate SEPROM that you can’t modify, and it checks validity of the SEPOS

surreal mountain
#

but sep doesnt allow that

half walrus
#

this means they can just patch out the code that panics the device when booted from DFU

tepid olive
#

Shit I woke up at 5 am today, I need to sleep

surreal mountain
#

and disable sep @half walrus

noble rover
#

So if Apple patches blackbird

surreal mountain
#

they cant

lethal kayak
#

They can’t

tepid olive
#

They can’t

#

Not by software

noble rover
#

They can’t?

surreal mountain
#

^

primal perch
#

a9 and a10 are actually done now

half walrus
#

it's an SEPROM bug

noble rover
#

I mean that’s awesome

surreal mountain
#

not really

half walrus
#

but it doesn't work on 64 bit seprom

lethal kayak
#

Blackbird exists in the seprom like checkm8 exists in the securerom/bootrom

surreal mountain
#

from sec standpoint its terrible

#

lol

pure tree
#

@upbeat wyvern do you know why this error on python3.7 when installing PyQt5?

ERROR: Failed building wheel for sip
  Failed to build sip
  ERROR: Could not build wheels for sip which use PEP 517 and cannot be installed directly
surreal mountain
pure tree
noble rover
#

Which devices use 64bit seprom

half walrus
#

from sec standpoint its terrible
@surreal mountain yeah of all the jailbreak bugs exploited blackbird is actually horrifying

noble rover
#

A11?

lethal kayak
#

A11 and higher

tepid olive
#

A11

#

Yes

primal perch
#

a69

lethal kayak
#

True

noble rover
#

Ahhhh so that’s why it doesn’t work on A11

tepid olive
#

@primal perch

twilit jungle
#

Except those 10 people that it would have been helpful to should/would know what they are doing to have other security measures in place.

surreal mountain
#

but it doesn't work on 64 bit seprom
@half walrus pretty sure its been exploited

#

at some point

tepid olive
#

Wait

#

Bruh

surreal mountain
#

just difficult

#

is what clarity said

half walrus
#

Except those 10 people that it would have been helpful to should/would know what they are doing to have other security measures in place.
i want a passcode so my girl cant grab my phone and look through it

surreal mountain
#

and im 99% sure hes been doing it on his own time

half walrus
#

i also want to jailbreak my phone

lethal kayak
#

Due to AMCC? I believe

half walrus
#

right now i cant do both

surreal mountain
#

what is amcc

half walrus
#

i develop tweaks, so i can accomplish that

tepid olive
#

Imagine having a girlfriend sadCat

surreal mountain
#

i develop tweaks, so i can accomplish that
@half walrus true

#

Imagine having a girlfriend sadCat
@tepid olive sofuckingfunny

twilit jungle
#

Like I said you can live on the edge all you want, just don't release something that is going to harm more than it does good.

surreal mountain
#

sucks

#

literally

half walrus
surreal mountain
#

wait wtf

tepid olive
#

Wtf

surreal mountain
#

you planned it

tepid olive
#

A planned breakup uhh

surreal mountain
#

my brother did that

#

when he went to college

tepid olive
#

Bruh

half walrus
#

i mean

surreal mountain
#

his girlfriend was a junior

tepid olive
#

Lmaoo

half walrus
#

are you supposed to just randomly decide it and randomly drop it out of nowhere

tepid olive
#

No

lethal kayak
#

what is amcc
@surreal mountain like KTRR but KTRR doesn’t make sense to say in the context of sep

surreal mountain
#

does she know

half walrus
#

no

surreal mountain
#

oh ok

#

yeah ive done that

tepid olive
#

But “hey bro how about we break up on Saturday”

half walrus
#

i feel awful about that lol

tepid olive
#

Lol

surreal mountain
#

i thought it was like mutual

#

lol

half walrus
#

But “hey bro how about we break up on Saturday”
lol my last girl basically did this

surreal mountain
#

maybe this isnt a lol moment

half walrus
#

u ever have to help someone break up with u bc they're not able to handle it

tepid olive
#

Hello bro I’ve been thinking and I need new guy. Ok bye, thanks

surreal mountain
#

im basically a child

#

so

lethal kayak
#

Imagine if ktrr didn’t exist Sadge

surreal mountain
#

negative

tepid olive
#

im basically a child
@surreal mountain I’m 14 uhh uhh uhh uhh

half walrus
#

i'm surrounded by child help

lethal kayak
tepid olive
#

Don’t worry I leave

#

And sleep

#

Maybe

#

If KTRR didn't exist I could make my own executable pages Angerycry

lethal kayak
#

ye sad

tepid olive
#

Ok now I swear I go sleep

lethal kayak
#

kinda crazy how kaslr didn’t even exist until iOS 6

tepid olive
#

Bruh imagine no aslr

#

NOW I SLEEP

faint timber
#

its a force panic

#

pongo panics

#

not xnu

half walrus
#

yeap

faint timber
#

I already have custom kpf + pongo

#

can do everything except blackbird so far

half walrus
#

too lazy to write kpf

faint timber
#

I didn't

#

I just patch the checkra1n one

half walrus
#

any good patches/additions?

#

about to start digging into passcode shit woo

surreal mountain
#

mfw krit dont follow me

#

intjsad

#

krit would love my twitter bio

#

@gaunt mesa

gaunt mesa
half walrus
surreal mountain
#

allah

#

im one of those

half walrus
#

my top tweet is that one negative one

lethal kayak
#

I don’t care about jailbreaking for the tweaks anymore I just care about it for the sole purpose of achieving it

#

Lol

half walrus
#

i just need a shell

#

all i need in life

lethal kayak
#

True

half walrus
#

iSH is nice but also i586

lethal kayak
#

Also filza is convenient

half walrus
#

boy

#

is there

#

another screenshot program for macos

#

preview crashes 40% of the time i open it

#
$ echo $PWD
~/ios/tweaks/HomePlus/HomePlus/HomePlus
lethal kayak
#

Make one

half walrus
#

modding existing things > making new ones

lethal kayak
#

there’s ShareX

#

True

#

ShareX good

faint timber
#

I'm a low level dev shits way better than userland

lethal kayak
#

Also open source

half walrus
#

amen @ cryptic

faint timber
#

need to write a xor string script for adrp which is a big pita

half walrus
#

when your IDA finishes analyzing in 10 seconds bc iboot is smol

lethal kayak
#

I like low level but it’s much more difficult to find resources to get into it than userland stuff

half walrus
#

I like low level but it’s much more difficult to find resources to get into it than userland stuff
have ranted about this somewhere

lethal kayak
#

lol the analyzation time of iBoot vs kernel

faint timber
#

once checkra1n becomes full oss

#

thats all the resources we need

#

for the next decade

half walrus
#

• very difficult for new researchers to get involved
• Existing efforts are kept private
• Community research efforts are dying or dead
• objc_direct will alienate beginner devs
• the toxic community will bully the rest out
• App store apps have replaced the need for most

#

• leaked content is hoarded or sold for highly inflated values
• lower level research is hoarded and kept private
• getting into the scene involves already having friends in it, or knowing who to pay hundreds to get tools and dumps
• open source jailbreaks continue to fail.

faint timber
#

I guess I'm in my little group of low level

#

#LowLevelClique

half walrus
#

yep pretty much lol

lethal kayak
#

It’s like

faint timber
#

4 members but only 2 are really active

#

cough ultra cough

half walrus
#

only reason i have a symbolicated watchos SROM is because i have the right friends who know the right stuff and have the right leaks

lethal kayak
#

cough ultra cough
@faint timber true

#

While yes I know aarch64 assembly there’s a difference between knowing it and knowing how a C function is structured in assembly and being able to disassemble something

faint timber
#

I'm really interested in syscfg nand stuff rn

#

but can't get the dscd stuff to communicate with kanzi

#

guess its different?

half walrus
#

knowing assembly vs knowing how to read disassembly

lethal kayak
#

Ye

half walrus
#

latter is easier but once you learn how to write it it's all easy is cake

faint timber
#

ftdi can't find my kanzi even given the correct vendor/product

half walrus
#

and you become a god at debugging userland stuff Kek

faint timber
#

I can debug restoremode kernel

#

sep in the way of full demoted userland debug

half walrus
#

world out here sleeping on public srom symbols smh

faint timber
#

I still need watch psychic paper

#

need to grab my ecid

tepid olive
#

You should write a bootrom patchfinder to symbolize all roms

half walrus
#

i should do that

#

i should name it iBootLoader

tepid olive
#

patchfinders are very easy to understand once you get over the conceptual barrier

half walrus
#

and i should upload this patchfinder named iBootLoader to my github

faint timber
#

Poll:

Should I make checkra1n RE resources public?

Y|N

gaunt mesa
#

gm

half walrus
tepid olive
#

does memset still have that 0x0101010101010101 immediate MOV in bootrom?

#

@faint timber no

gaunt mesa
#

krit i got hyper-v setup btw

faint timber
#

@tepid olive all I need is a reason to sway a side

tepid olive
#

wdym?

faint timber
#

would like an argument for no vs yes

half walrus
#

You should write a bootrom patchfinder to symbolize all roms
i did 3 months ago and like 3 people noticed it lol

tepid olive
#

Oh cool

#

@faint timber no: disrespectful

faint timber
#

I wish there was astris for a11

half walrus
#

it's an IDA loader, not a patchfinder

faint timber
#

no a11 product in astris

#

only a10 d10

#

and d11

half walrus
#

@faint timber no: disrespectful
@tepid olive someone else blogged about their RE on ch1 and got complimented by the team

#

so

#

¯_(ツ)_/¯

tepid olive
#

I am pretty sure that was pongo

faint timber
#

@half walrus that was for 0.9.8 prior to improved hikari so its ancient

#

march

lethal kayak
#

March

half walrus
#

i mean just ask them