#development
1 messages · Page 346 of 1
since yall are somewhat smart and know arm
should i post this firmware here
never got it to post
white screen memory overflow
no ui
its a non retail os
nano 3rd gen could be dead nand or something, it bootloops on apple logo and just fails to restore firmware on win or mac
use dfu restore
on them
or u could use the jank code i made out of a dfu exploit for a iphone to upload a dfu to the ipod
XD
think I did? is center + menu just recovery not DFU?
man please don't tell me the iPhone DFU sequence works on an iPod lmao that'd be amazing
my god I need to try this
lemme grab the code
well its similar to iphones
tho the .dfu files are non existant
so i ripped a few off apples server for people to use
XD
hah, ok I see
not sure how the mods feel about it but honestly it's been 15 years, I'd doubt Apple cares unless it has IP secrets like unobfuscated/non-stripped codecs
ones they could be sued over I guess
all of ipod 5.5 and 5g are not encrypted
aside the aupd has a rc4 key
for the header
no clue whats in it kirb
its meant for apple techs
to scan the ipods for faults
that makes sense
could be that it hangs on white screen waiting for an external diagnostic accessory?
probably
tbh
like i document
everything
@lime pivot i just dont have the code knowledge on how to apply them
@lime pivot u want to know more about ipods ?
https://github.com/Xlinka/iPodReverseEngineering some nice files on my github
unfortunately I'm probably not the guy who could put something together either
but I'm definitely curious
slowly been gathering datasheets
damn hard to get hold of them
ngl i dont feel like i belong here with you lot but @faint timber seems very smart compared to me XD
like this server is mostly iphones
im probs the only one that cares about these
@lime pivot ngl if i couldnt find anyone to help i was going to desolder my ram chip and put it on a daughter board
and solder a memory reader to it
but thats my last resort
damn
like i dont even know how i got 1.3 to patch i just did process of elimination
while looking at patched 1.2.1
and tried to find a similar pattern in 1.3
@faint timber would u know how to get the aes keys out of the ipods XD
for the firmware on the samsung ones
Prob
cus thats been the issue for years
Which iPod
the classics or nanos
s5l8702 based
the problem with them is that so far we have used a seperate bootloader and loaded that into ram over pwnage 2.0
no one botherd to decrypt the original
or find the keys
so we can patch its firmware
so the classics and nanos this whole time have had no themes for them or cracked games
2 sec if your willing to help i got some files that might help u
wait should i send u the files in dm ?
incase
@faint timber

Kind of not really
Now i see what u guys were talking about holy fuck. Ghidra ugly asf
ghidra has nice tools terrible ui
Damn only if it looked like hopper
if only
The way its built is trash. Do they even update this shit?
ghidra is a tool the nsa built
it was discontiuned
obviously they have something nicer now
@burnt niche
Damn they probably do
you need to find aes_crypto_cmd and feed it the encrypted keybag
it’s in either the rom or iboot
Doesn’t ipod nano have something called rockbox?
ah yes
the rockbox
not nano 3g no on botherd to port it
uhh the thing about that it uses a custom bootloader for it
custom made
Nice
to load the .rockbox into the boot address
but the custom bootloader was encrypted by just uploading it to the ipod and letting the ipod do it
no one knows the key
That shots confusing
well you gotta write a new payload then
and its been the same bootloader since 2007 never updated as the person who made the ipod encrypt it has dissapeard completly
Would you use hopper or ghidra if u had to pick
i use ida
Latest?
Windows?
Lol
but yeh im on windows
but like
im using LFS
XD
my pc is running two kernals in parallel to one another
its complicated and annoying
@edgy cape did u pay for ida pro or is it redacted
uhh

How do you do that?
its buggy but u basically just tell it to ignore the sign in thing and nop out the key check completly
I wish i could get it on a mac.🤕
so it just loads the start of the program
instead of the other things
but it does lead to some bugs
replying to this wdym find that line
in where
If u had hopper paid. Would you use that instead?
honestly i have no clue what im looking for
rom in your case
this is the bootrom
?
he said its the bootrom
the file im looking at
Bruh las vegas is so fuckin dope
yes, it’s in the bootrom
Im in a hotel rn i can see the entire strip from the bed
yeh no aes_crypto_cmd
obviously not symbolicated 😛
which one
aes decrypt
just poking around
this is for the Classic 6th gen
@steady nest u want it to have a poke at ?
@edgy cape kinda wanna try reversing a firmware, do you know where i could get a nano 3 dump?
lol
yeah i saw the wiki stuff briefly
how do you dump it?
i got it from someone 
no clue how he got
said something about soldering
and removing chips
and sent me all the fials
oh that's efi firmware
is the actual os available
no
im confused
oh they use ipsw
but theres only a bin file
no dmg
not like iphones
its all hidden
XD
that's what i wanna reverse, or try
these motherfuckers are more secure than iphones and it botthers me
interesting
@tepid olive the ipsw only contains visual elements inside resources/ui/silvver blah blah bin
but if u dump the nor u get stuff like this
since these images arnt in the silver file
mhm
so the recovery firmware updates or not
the recovery is basically a dfu
couldn't you do a dfu restore on the iPod and intercept the files
ok nvm
it's https anyways
lol
i think the 6th gen uses same one
since rockbox isn't there i couldn't find a way to get click wheel games
bummer
iQuiz and Vortex are getting old
oh yeah thats a decrypted dfu...
oh well
it lists all supported devices
@tepid olive vortex and iquiz was dumped in 2007
u can play them on patched firmware
i know, i have them
what happened to coherent sentences, is sending lots of messages with 3 words max the new way to communicate
really wanna get a 3rd gen since they're my favorite model
and i kinda find the 5th gen ugly
i mean i don’t really have a problem with that it’s just very atrocious to read if anyone wants to follow the conversation along.
honestly. i make no sense as it is.
I guess if that’s your perception then you probably shouldn’t message at all as logical conclusion until you “make sense”
what do
you mean?
it is very
easy to follow
cause it was spaced out in a way that broke the flow of the sentence
😏
LMAO
someone is selling a 7th gen classic for 400 bucks
😩
😩
and someone else is selling a 6th gen touch for 45 bucks
h o w
i blame dankpods for the price skyrocket
yea it's locally
found a 1st gen touch for 20 bucks
i'd cop but idk
kinda wanna experience iOS 1, 2 and 3
and have a good mp3 player
😩
wtf
did the 1G even have signing
sus
choice between 4 and 5
not like it matters, it has a bootrom exploit
No
It didn't get added until 3GS
But with both 3G and 2G (original iPhone) you gotta restore it with iTunes while in pwnedDFU
But with 3G at least it's very difficult to enter pwnedDFU cause iTunes will kick it into WTF mode
At one point I got my 3G downgraded to iOS 2 and then it bootlooped
And it's got a broken home button so I can't unbootloop it
can’t u tear the glass out and just press it manually
or worst case pull out the cable and use a pair of tweezers to bridge the contacts idk
Uh, yeah I guess, I never thought about that tbh
only truly borked home button is on the 7/8 cuz they’re software
Ok, time to get cracking on uikittools, I need a better way to determine if an app is removable
what are u doing rn
@interface LSApplicationProxy : LSBundleProxy
-(BOOL)isRemoveableSystemApp;
@end
but it doesnt seem to work, if I do com.apple.tips it says it isnt removeable
i mean isn't it not removable
i'm 90% sure they stay pre-loaded
despite being cosmetically removable
Look for isDeletable
ooh
I think that’s what you want
thank you
my mouse died 
not seeing this in LSApplicationProxy
in flex or headers
@property (getter=isDeletable,nonatomic,readonly) BOOL deletable;
it's not there on 14
L
really?
there's -(BOOL)isDeletableIgnoringRestrictions; tho
yeah i saw that
jury not back on what restrictions are

see if isNotRemovable returns what you want
I dont see isNotRemovable
wonderful world of version specific apis
there's still a deletable property on 14
but it's just nil on every object
no getter/setter
isNotRemovable returns properly on the Health app
hm, yeah isDeletable def isnt on 14
k it returns the same thing for the Spotlight app
so nvm on that one
well
SBApplication has an uninstallSupported property
isDeletable is working on 14 and does what I want
Is it working on
12
iPhone:~ mobile% uicache -i org.coolstar.SileoStore
Name: Sileo
BundleID: org.coolstar.SileoStore
Path: /Applications/Sileo.app
Container: /var/mobile
VendorName: (null)
TeamID: 0000000000
Type: System
Removeable: 0
URLScheme: sileo
URLScheme: cydia
iPhone:~ mobile% uicache -i com.apple.podcasts
Name: Podcasts
BundleID: com.apple.podcasts
Path: /private/var/containers/Bundle/Application/99D00799-FD75-4537-9845-20B6B94AC89B/Podcasts.app
Container: /private/var/mobile/Containers/Data/Application/FD3A361A-0970-41BB-BE4D-3031C58A20B4
VendorName: (null)
TeamID: 243LU875E5
Type: System
Removeable: 1
URLScheme: itms-podcasts
URLScheme: itms-pcast
URLScheme: pcast
URLScheme: podcast
URLScheme: podcasts
URLScheme: itms-podcast
URLScheme: itms-pcasts
probably
test phone is boutta die, fuck
so u basically just moved appinfo into uicache and then added more stuff to it
just gotta format it as true/false instead of 1/0
Hes been working on this since before appinfo 
but i had the idea a while ago
woeis
i need to finish this
some shit broke
fuckin C
sneeze on the buffer wrong and stdout goes nuts
if that stuff gets pushed across common jailbreaks i may just switch to it so i can get the decryptor running again
ok, its all done now
if sbingner follows suit, which based on his earlier statements he will
wait, you made an appinfo too...
oh did someone else make one

and he said he might add it to uikittools which made me remember this idea 
holy shit lol
@upbeat wyvern https://github.com/DragonBuild/appinfo/blob/main/appinfo.mm
same idea different times
mine was written in november
it seems like a while ago
prepare to tweet angrily
i didnt steal your code
i didnt even know you made an appinfo
doesn't matter in this community anymore

dmca means i win u lose
add a license 
there are no negative repercussions to this behavior
tf you doing with unlicensed code
it's licensed afaik
no
True
well, its copyrighted
Copyright law type beat
Unlicensed means ARR
not quite, publishing on github gives the right to fork, even if copyrighted
which means absolutely nothing yes
i have the right to download your profile image, and to redistribute it for parody / where it's covered by fair use, but in terms of copyright law that's as far as i can go
here's ur license
dragon license
using it in uikittools would essentially exempt it from any copyright restrictions
as it constitutes a project larger than just my own code
i dont want your code anyway 😤
why is the quoted part properly capitalized but the rest isn't
cuz i did it that way
quoted part doesn't matter
its just there so i can try and explain the basics of the license
it's incredibly permissive but doesn't seem like it at first read
its a good license
I've grown partial to FreeBSD license
the file says
// creative commons blah blah
CC isn't well suited for code anyway
this is just bsd 2 clause with my own exemptions written in pretty much
as in
if you grupi my code, the name of your project should indicate so

if you take my project and expand on it i still get credited
if you take my project and shove parts or all of it into something like UIKitTools, ur good
take a whole file and it needs to maintain any copyright header
which i rarely have lol
you cant do monospace in the PR title 
-L
@tepid olive what ios versions did you test
14
Test on 12
If you have one
i dont have a 12 i dont think
who has 12 anymore
i'd spin up corellium but
In a drawer
sadcat
True
he's gonna return to crush ur puny pull request
My 12 phone
[$200] light scratches still works
maybe it's not
don't know how u can tell with that screen
miracle that mf still works
My iOS 13 phone
do you live in an entirely hardwood floored house
after it got cracked water got poured on it too
none of those were mine 
the ipad was my brothers, he dropped it on the driveway
the 6 fell out of a pocket in an airport bathroom
like i carry my laptop like a dumbass but i hold onto it for dear life
wtf did you do
the 6s was my cousins, and if you know her thats enough explanation
how are you mfers literally destroying your devices

bro he literally
like that's not even a 'scroll up' its right there
he just told u
least concerning thing in that message
Apple clang version 11.0.3 (clang-1103.0.32.62)```

The only phone I've broken 😔, i forgot it was in my lap and stood up
better
lol i need a 13.x 11 pro
Same
"ur tweak is broken on arm64e"
True
i gave my brother my xr because i bought an 11 pro
and i mean
so much better
totally worth it
oled screen alone was worth it
My Xr is good, it's got one little chip on the back cause it fell of the counter on to tile
actually my x got shit on now that i think about it
it was originally my dads but i took it because he didn't want it

the entire status bar is just
gone
removed
Wtf
not literally
like
its obliterated
its still physically there
limd isn't detecting my 6 that's in recovery
what is limd

Not sure if most people remember but there was an old project I was loosely working on w/ nep + siguza + others
regarding brute forcing ECID
got to the point where we needed more (fresh) data on the pool of valid ECIDs which requires basically asking people to give their data
and everyone got too preoccupied at the time to get around to writing the device+server side implementation of that
well you could setup a simple webfront with an input form which validates the ecid by sending a request to apple’s warranty checker and seeing if it responds with 200 or not
easiest way to pool ecids with consent
How many ECIDs do you need?
literally as many as possible
this should be a maximum 10 minute job though
doesn't the warranty checker have a capatcha
yeah but you can easily circumvent that
if they're from tsssaver we already have those
Nah, I don't save blobs for most of my devices
Cause I'm lazy
And most of the time they're useless
wdym you “already have those” btw
I used to save OTA blobs for my ATV4K even though it's basically useless
saving blobs 
didn’t realize people actually do that
i may be completely wrong cuz this is in july
blobs only came in handy one time but even then I could have just updated to 13.5 while it was signed because u0 0day 
i can't even remember if i had a list or the validation code
just decided to wait a bit because of Odyssey
and it was probably the latter

can you publicly access arbitrary blobs on tsssaver
if you know the ECID I guess?
u0 0day

wel aktualy its not a zero day cuz it is a reGression ha 

granted tsssaver’s layout I’m somewhat confused if that’s a undisclosed privacy breach or not since tsssaver saves them as <ecid>/<blobs> and having access to that information without anyone knowing seems worrying
wasn't a privacy breech
that might’ve been the wrong wording but the point I was trying to make is did the public know some people apart from TSS maintainers have access to the ecid lot

given none of the one person (myself) have that data anymore, no, nor do i see reason for that to really be an issue
I’m usually not someone that concerned about privacy but it’s still other people’s private device data you have / had access to which wasn’t publicly disclosed, which morally might be wrong but i guess that just depends
Hello fellow developers, what are we developing today
in terms of personally identifyable data, you already need root to see it, it's not even close to udid
which even udid isn't even a breach of privacy
Gdpr would disagree with you since ecids are unique to the device afaik and thus the owner of said device
it's a hex number that could've been found by brute forcing the online gateway or reversing the validation code we already have
so i mean how far does it go
does github display repos in order of most commits? 
brute forcing the number is different to having straightforward access to the data, neither being really ok
Art 6 section 1 (f) might got you covered on that though i guess
impact of your ecid leaking being...
STOP EXPOSING ME!
it’s unique to the device which makes it fall under gdpr’s regulation of personal unique data

I had mc.procurs.us A record point to my public ip for a couple days 
ik you did
i looked
So a simple dig would tell you my ip
yes it did

I have it redirecting through my VPS with socat now though
what did you do now
oh
get the whole thing you're saying
which idk if their privacy policy covered it at the time
socat TCP4-LISTEN:25565 TPC4:xxx.xxxx.xxx.xxx:25565 or something like that, one for TCP one for UDP
Then an nginx setup to redirect http stuff to the disc invite
but how far do you push it when it's a pool of numbers shared between two researchers to test a validation script for development of a public-use tool
Well granted TSS staff by definition see your ecid which excludes them but their site doesn’t list a policy for 3rd parties to access said data which is the concerning bit in the bigger picture, to which I take a conservative stance since if things are being developed for the community even as PoCs they have a right to know
doesn’t matter who you identify as, to TSSSaver you’re 3rd parties unless you’re staff
that's true
¯_(ツ)_/¯
hello
can't remember if i even saw the data fwiw
just that a lot of it was trash
which is why the whole new 'gib data' thing was the next step
people should know putting their ECID in tsssaver could let others have it?
and do what?
"says this in a public channel"
doubt it honestly
didn’t mean to slam dunk hard on that point but I just find it very contradictory in this community at times that data and secrets get shared around without anyone knowing and it’s just tiresome that shit never changes. Yet the same people love to complain the community never moves forward
haven't i complained about that multiple times tho
the jailbreak community can start drama off anything
well there's more to the community not moving forward than just that
correct
how hard it is to do research for ios shit w/o having the right friends
true
Pretty alright if you’re dedicated enough to be fair
no one’s born a genius
you dig and work
still waiting for apple product security to reply to my email ._.
no it's not something that would lead to a jb
just bootloops devices 
i mean i'm agreeing with ur earlier point so
you know those fake cydia profiles
imagine they got a hold of the bootloop profile

true
@lime pivot can't believe you complain about apple business practices but yet u use iphone
adam doesn't sleep
for one i wholeheartedly wish we’d get rid if the skiddies and fake jailbreak “devs”
Fine. I'll leave
shit’s been around so long it’s not even a funny meme anymore
hey guys check out my jailbreak
definetely not a fork of unc0ver
very original best stability guaranteed!
lmao not you, people like chris or whatever his name is who make permanent fake jailbreak projects and lead people on
hate that so much
clout chasers
(That's a joke, u0 dark was actually good)
at least that had a feature
u0 dark had sileo
idk if this is directed at me but you can ask a few people who've repeatedly had to convince me to not leak shit cuz i don't like the whole 'secret circles' thing
Bro, Chris has had like 5 "jailbreaks"
all "WIP" I completely forgot about him
there's reasons you cant just put certain shit out there
tbh i don't think the skiddies is as bad as the bigger issues here
No it’s not directly towards you but if you’re in the target then you can feel it directed towards you
work on elixir with plank but plank doesn't deactivate challenge
mostly the fight between centralization and freedom
idk who it's directed at lol
Lmao skiddies are a major issue, half the rjb followers are barely able to pull longs from their devices, if someone yells “jelbrek A12+ 14+” they’ll come flying to suck your dick
Keep on hitting the filter 
TRUE
and that causes unnecessary uproar and tumults
the biggest issue tho is the radicalization of both sides of this community
of the community
in my opinion
the biggest issue in the jb community is people who think they understand the biggest issue in the jb community
hot take
bullying /s
I wonder if they'll unsign 14.2 finally or not yet
kinda wanted fugu to take off properly
lmao there are definitely very apparent reasons but there is no helping 9 year old john wanting to hack subway surfers for them spicy coins
ask 10 people get 10 opinions
and going to hyi or whatever
ask 20 get 20 opinions
cuz it's a complex community
80% of it doesn't speak english
TRUE
It’s very simple if you boil it down to the basics
Dude, fugu and checkra1n are gonna die, there's no avoiding that
i believe another major jailbreak is just gonna lead to more fragmentation
It doesn't have the footing to take off

the real complexity is interpreting that rjb was different and thus giving the people a layer of complexity and individualism which isn’t there
you know it’s the same old
true, but fugu would have been cool to fullfill its open source checkm8 jb goal
i hope checkra1n gets open sourced soon
oh fuck i have an hour to eat and go back to class
i mean at its essence
adios
when it comes to devs vs users
lmao
Look how bad checkra1n team messed up 14, what do you thinks gonna happen with 15? 16? The checkra1n team doesn't even really care about their users
when it comes to devs vs users, devs are robots that aren't allowed to have feelings and rights 
regulated entirely by public opinion
And what are users?
the problem is the userbase in most cases, they’ll harass you to death if you don’t provide and someone else does, you suddenly turn into the asshole
^^ ok yeah
if u listen to the wrong people yeah
namely reddit
which is just
do not miss that sub for a second
twitter isn’t different, the replies on some posts/ release posts is disgusting
@half walrus lol same name even
Yeah
false
!
bingner died 3 years ago

RIP
i remember when
was new
@tardy narwhal i'm going through logs and i didn't even have the files myself
now its probably the most used emote in every jailbreak server
just the validation script + about 30 pooled from our own actual devices
and i can't even find those rn lol
gdi
remember when
was used a ton
lmao all good, again was just saying in general if it were the case and implications from my side
yep, tricky situation there ig but in terms of people who'd actually object to that
the only ones who would care are uninformed people told to be mad by someone starting drama
Well if I’d known I’d have tweeted it out to get attention to it because it’s unacceptable
or yeah, people who pick really random things to be super firm on while ignoring the rest of the similar situations they encounter
@tardy narwhal would u mind if i hosted an instance of https://headers.saadat.dev/ myself
cuz i see the github repo doesn't have a license
are you sure there’s no license
there is, just no license file so github doesn't detect it
"THIS PROJECT IS LICENSED UNDER THE AGPLv3"
oh lmao, ggwp
oh u mentioned it in the readme
at the bottom
but didn't include an actual license file

alright that works tho
Whats the difference between internally and externally?
<small><small><small>this project is licensed under the agplv3</small></small></small>
small small
yeah sure if you want to go ahead though, it’s Open sauce so people can host it themselves if they want to and improve on.
I’m revamping most of the project currently, so you can update later to a faster variant as well👍🏽😊
in what scope
you might consult a dictionary
Ones internal other external
ooh
The website doesn't work 
yeah its been down for a while
How dose external tweaks work on ios?
i host a local version myself
I’m not sure if it’s just a petty counter argument or not but I’ll have you know that for my part I do report instances of privacy related issues.
but i wasn't sure if i was allowed to make a public facing instance of it
yeah it’s been down because i switched hosts and haven’t finished a rewrite just yet
Give an example of an "external tweak" I do not understand what you mean
but please do make mirrors and do as you please, it’s open sauce so all good!
@gaunt mesa
Lmao idk anymore these kids been telling me they are making external tweak
just remember to later update to the faster alternative, got major speed improvements coming

 apparently it runs in background
A daemon?
thanks saadat
np
yeah ill make a public one that'll have all of my patched SDKs for people
cuz the limneos one is fine its just a bit slow
yeah that was my reason as well to make the clone lmao
i did like his logify thingy, that’s coming as well
breh said its on springboard reading apps memory
yeah the logify thing is cool
He's just talking out of his ass, I don't really care


that would probably be my horrendous product lmao
Do you just cock your head to the side in all you pfp's?
lol the jarvis dev pushed an update saying: lowers device heat
Lol
Tilt head left

jarvis clown
i mean have u ever seen someone with their head perfectly straight
in a pfp
that sounds horrifying
yes, I really have no other way to take pfp’s
some person is currently mentioning how good it is on reddit
like I just don’t know how selfies work
mood
and i have 1 angle that i look good in lmao
But he's in the exact same pose in both pics I just thought it was funny
i’m visually impaired and one eye is stronger than the other so i’ve always cocked my head to the side
i’m like a fucking bird
don't call me out like this pls
it’s automagically done bro
Mirroring picture time 

@tepid olive i can hit you with a duckface pic doe
why tf was i tryna figure out how to
get udid/etc code
cc @gaunt mesa who understands why i just wasted 30 minutes of my life

Bruh can i share a Twitter post?
LOL mood
you can click the share icon and click <copy link> to share it

if ur asking permission, nobody is in charge here
when i took my macbook to the genius bar yesterday it was burning
how
i opened it and it turned out i left 2 simulators running
twitter is so bad
lmao
why genius bar
and it was running code that i hadn't put the release statements in yet
i needed to get my screen replaces
hot take man
tf
LMAO i see you sir @twilit jungle
you broke it
gm
yeah i have applecare+
i mean their opinions
but that doesn't cover it
and this discord isn't?
most people don’t express their shitty opinions on discord
so
I don't have opinions, cause everything I say is fact
bought my mac in 5 minutes due to covid, can confirm they can’t be slow
twitter is more opinion based than discord
they don’t have to give their opinions
what
the whoosh
is strong
no
what does that even mean
i didn’t get filtered
they are saying its false that there was no fraud in the election even tho there was

all social platforms pretty much run on opinions


when u post troll emoji after saying something dumb
please no politics

is there a wind emoji
there was
here there is some info sharing and helping each other but twitter has none of that
🌀
🌬️
:dash:
this channel 🌬️
u 
wtf
bet
BRUH
LMAO BRO
WHO
chill
we saw that
@tepid olive rip
well
big F
ima go get coffee
ima go eat

u all have fun

except for cameron
let me find the ban hammer
true homie just gave you 100pts
Fuck
and that hot mute
zoop
zoooop
agreed
i love you rick😂
Ily too my man
if u get 500 they give u a prize
If I went by the Rule 2 youd be banned fam
@inner quail gib points pls /s
Thank you
np!
CameronToday at Timefuck that one image.png
i remember ragequitting the server cuz ppl were spamming ntwerk in this channel
which i was being a cock but i stand by the fact that was fuckin annoying






