#development
1 messages · Page 413 of 1
It hurts still
@grim sparrow bri ish rap culture
listening to some flame bri ish rn
hold tight
Mans Not Hot performed by Big Shaq (Michael Dapaah)
Available to Buy & Stream NOW! - https://bigshaq.lnk.to/MansNotHotID
Directed & Edited By Marv Brown
Instagram - @MarvBrownFilms - https://www.instagram.com/MarvBrownFilms/
Video Produced By Michael Dapaah:
Instagram - @MichaelDapaah_ - https://www.instagram.com/MichaelDapaah_/
Twitter - @Mi...
Id rather listen to bladee
Big Shaq is just a different breed

The brits should just stick to chocolate and indie music
Those are the only good things they make
we also make fantastic pencils
No you don’t america makes the best ones
Have you
guess
Tf
There was a lot of ww2 stuff too
There’s a museum for everything these days
@tepid olive checkout hella sketchy and convolk
Y’all stole those pencils too
And how advanced pencils are now
I mean where they would put maps inside the pencil
and shit
The fuck
ngl this song is a banger
which
the one im listening to
oh i c
since when did aaron make music
Niko B is a solid guy too
damn bro
@tardy narwhal damn bro
L
L
lol
also check out lund @tepid olive
dyld: could not use '/usr/local/bin/screencapture' because it was built for a different platform
rip
Damn
recompile
They’re massive wtf
233m listens
where's screencapture source even
Legit never heard of them
lund is so flame
I’m just into Mac Miller and shit
damn rip mac, sketchy, peep, juice, and x
they do be mass1ve
@tepid olive damn they even got this feature
i will murder you like shmoo
Man wtf
the only shit I listen to is underrated arists
Peep still has posthumous shit releasing
@tepid olive yes, and I know whats coming I have all the leaks
unreleased shit is legendary
Rip tr1
or did you use your mass1ve power to kill him
another underrated artist is brennan savage
guys I deleted a furry
I clicked his name then he disappeared
the entire gbc is underated but make good music
CorelliumError: Invalid TOTP.
gotta love undocumented features
the documentation doesn't explain how to pass TOTP code to the API
gonna take a wild guess and try totp
lol
@tepid olive blood orange is basically tame impala
Somewhat ye
But more British
another one is lil happy lil sad
Can I get developer role
I made this
I’m a big developer
I found out why my phone and computer were generating different TOTP codes
the time was not synchronized
Windows said "last synchronized 2021-01-27"
interesting
Corellium accepted it because usually most sites accept +/-30 seconds
so 3 TOTP codes are valid at any given time
sooo, that didn't work
opened an issue
@faint timber do you get "cannot connect to app store" too
That won’t work
No keybags and stuff
I’m referring to running sideloaded AppStore apps
lmao

Probably cause you can't activate a fake phone 
what if you are tho
I’m 9.4% British according to 23andMe
lol

And 14% Italian
L
0.00001%

Cam is British by logic
Cameren
En = England
England = British so 
true
@river hamlet manjaro is alright
Pretty lightweight and gets everything done for me
Also EwPM will get a new feature 
If you can guess what it is I’ll give you nothing
Manjaro is less stable than arch though
so Corellium runs from AWS, interesting
Interesting
@tardy narwhal @grim sparrow

Big shaq is truly a different breed
true
🆒
Is that my IP
Wait nvm
I saw Columbus Ohio and I was like


(That’s my city and state if you don’t get it)
Anyways ihhh
Does anyone know a file format that allows me to
no I got it lol
Like
Uhh
Idk how to phrase it
Ok so let’s say I extract a gz file right
If it has more than 2 dirs in the gz, it’ll create a main dir instead of just moving those files
Is there a good format that allows me to do that
My only other option is to force devs to create hooks to install their packages
Properly
And I don’t want to do that

uh wdym any archive format like zip or tar will allow you to create a top level directory inside it if you don't want them just dumped into the current directory when extracting
I mean like
Lets say I have a tgz file
It has 2 dirs in it for files to go to, such as /etc/test.txt and /tmp/test.txt
And I extract it to root
Instead it creates a main dir
And doesn’t move those files to those directories
oh so you want the opposite
wouldn't tar -czf foo.tar etc tmp work
like don't tar up a directory that has etc and tmp but do them directly
Wait nvm
I just want to preserve paths
Lol

Just another tutorial on how to use Google.
You Suck at Coding: https://www.youtube.com/playlist?list=PLN3n1USn4xllZEdX7a7GQul2GWrag_XAy
#benawad #google
Checkout my side projects:
If you're into cooking: https://www.mysaffronapp.com/
Join the Discord: https://discord.gg/Vehs99V
Patreon: https://www.patreon.com/benawad
---...

EwPM will now include hooks 🚨 🚨 ⚠️ ⚠️
Your cursed JS package manager just got better.

Best part is
After I get hooks working
And installed package list working
EwPM will be officially finished
Wait nvm
I need to figure out a way to get 3rd party repos working
is there any reason dyld refuses to load an intact dynamic library with no error being logged or returned?
what's not working about it
Haven’t created it
Yet
But yeah
I’m actually happy how far EwPM has came
It went from being a shitpost
To now being close enough to being a fully fledged one
Well not fully fledged
But
if you send proper headers free tweaks will work with most repos, idk how to do authentication yet though
You get what I mean
EwPM will be available on procures
Procursus
nice
Inb4 Hayden actually allows it lol
that reminds me, for some repo I tried to download from User-Agent: APT was enough to get Packages.gz, but to actually download a deb I needed to find the proper user agent (User-Agent: Telesphoreo APT-HTTP/1.0.592) 
@tardy narwhal hello
why wouldnt i
Idk
It’s just a bland package manager
congrats on genius, well deserved
ty
fine by me if you can compile it without xcode
Oh it can
then you got it
Pog
i need opinions please
When EwPM is finished I’ll get it on procursus
why is iPhone 12 mini so laggy in Corellium
darwin-arm64e or macos-arm64e
leaning towards darwin
Darwin
Seems more universal tbh
Isn’t Darwin usable on every platform ?
i mean not on iphones for our own fault lol
Darwin
Def
after using homebrew on m1 for a day
we are so gonna fuck them up

EwPM+procursus collab wen???
bro that doesnt look like an m1 mac to me
Actually surprisingly
that's an iPhone 12 mini
EwPM is pretty quick
It’s just very bloated because it’s a js script
Compiled into a binary

Bruh
EwPM my beloved <3
I like hanging out here
Too bad it’s dead
And I mainly talk about my nodejs package manager while everyone else talks about tweaks and shit

is there any reason dyld refuses to load an intact dynamic library with no error being logged or returned?
it just doesn't load
did u ask this question?
yes
im asking it
did you link or dlopen
slopen
dlopen
and you confirmed it didnt open with the uhhh
fprintf(stderr, "Error: %s\n", dlerror());
return EXIT_FAILURE;
}```
i can see it should be able to be loaded, both ida and otool count it as fine
yeah it didnt error
well that means its loaded. are the symbols you need hidden?
no
no
tru
are u using dlysm for the functions u need?
no im just dlopening for use elsewhere
oh
how do u know for sure its not loaded
dyld get image count functions and loop thorugh the images
*through
sounds like a real moment right there
good luck
a real moment

even file can be read and written to, the process has full permissions over it
nfr
:nfrdiamondmine:
Created my own vmware mac os install disk using basesystem from apple servers
Yo, I made a Shake2Toggle like tweak but for the ringer switch. And I need to create a table in settings to choose the action for the switch, like this
https://cdn.discordapp.com/attachments/705873943395041430/808747641508593685/image0.png

has anyone done this so I could steal borrow their code
ok so macports isn't actually bad
its surprisingly good
@tepid olive can u send ur nvim config rq
it takes like 2 minutes to do
Just look at the specifiers page on iphonedevwiki
AH
I see
I was looking at that last night, but I was kinda brain dead so I must have missed it
hello
@tardy narwhal hello
hello




Yes
true
because even if the code is airtight the implementation and idea behind it could be flawed
humans are still monkey brain
the code is only as good as the idea



square
squircle
frog
what’s the best repo to submit a tweak to


i hate prefs
Hello jailbreakers!
Are we hacking apple
Today
well, if I can't log in to ReProvision on Corellium at least I should still be able to test if my tweak installs properly and replaces the apple.pem as expected
cock
ok
I came up with an idea
who?
How about a tweak for iOS that turns the whites
L
To a darker version
And change the text to white
ok saying n word now
God shut up burrit0z
Shut up!
true
I hate burritoz
@tepid olive stfu you
L
f

Ban

did he get banned?
@burrit0z#7777 
L
wtf who said dumbass laugh
!jumbo 
ok
cumote
!jumbo 
you can only do that with servers that are on discovery or public
or that you already have
lol
You’re not getting the emote then
fucker




Not bothered 
burrit0z when edition again
@tepid olive it's not even in neko hypehouse lmao
Gtg
Does anyone know of any tweak to record screen interaction like something some people use for Pokémon go ?
i never said it was
K
I actually honestly have high hopes for EwPM
I’d prob get procursus working tbh
Procursus EwPM repo
Getting build/install/uninstall hooks working would make it greatly usable
@grave sparrow become kernel hacker with me

sure you are
its alot of work and practice
kernel hacker 
capt dont you know asm already
kernal hacker ez
is there a better way to replace a file that another package also contains instead of a postinst hook
postinst hook bruh
if I just have it install to the location directly dpkg will yell at me
dpkg hook


ik
and it's cuz my dumbass managed to lose both of the USBs i had for it
and i don't wanna go all the way to canada to get the other 2
i am hackerbro
i cant tell if its patched, or if the poc just doesnt work

gendered moment
im about to create a vital, very important issue. It'll fix that comment to change it from he to it
why is my theos makefile creating a forkbomb
I found a better solution than my original
dpkg-divert
pog
@tepid olive cydia
yes bc this is Corellium
and I'm lazy
it has a "jailbroken" option and that just comes with Cydia out of the box
nfr
@tepid olive patch the kernel please
how
corellium is a seriously impressive product
Just patch the kernel
Mfer investigate @grave sparrow
Be the smart dev you are and figure it out!!
Hmm
@grave sparrow what device are you running
Wait nvm
Ok
It’s prob a bug
don't
Why
https://opensource.apple.com/source/xnu/xnu-4570.1.46/bsd/netinet/mptcp.c
you don't gender everything?
/s
well, the whole point here is to replace a file
because I'm making a tweak that fixes ReProvision
MPTCP looks weird
dpkg-divert works nicely
According to Ian beer it shows signs of unaudited code
@grave sparrow not really
what even is MPTCP
Multi_Path TCP
multi path tcp

When using your app on an iOS device, users are likely to move in and out of range of Wi-Fi, switching to cellular networks and back again.
Multipath TCP improves the performance of your app when a user is in a location with limited Wi-Fi and while their device is transitioning to and from cellular data usage. In its default configuration, a URL session uses a single radio for a network call, preferring Wi-Fi over cellular. However, with Multipath TCP enabled, the URL session initiates the request on both radios and selects the more responsive of the two with a preference for Wi-Fi.
paid account why?
ok that's less bad as a reason
@grave sparrow Siri uses MPTCP
still not a big fan, hah, but probably the only way to do it
Hence why it required disabling it
Since it messed with the exploitation flow
trueee
other than forking it and people going "reprovision ios 14 eta wen"
MPTCP is an interesting part of the kernel to look into for auditing
also too lazy to compile it
ive been using ida so much recently
compiling my tweak is much easier, it doesn't even need any binaries
its very helpful
I don’t want to develop tweaks
I just want to do security research and kernel dev
especially since ive been doing lower level crap with mach object files n shit
tweak devs 🤡
multipath TCP feels like an unusual solution to a problem lol
kinda makes sense
still feels weird
If it works it works™️
multipath support on nsurslsession is weird. why doesn't the system handle that automatically?
file a Feedback™
odds i get shit on if i open up a random port for RDC?
would be nice for accessing pc from school
i need windows for some things
definitely use a VPN for it or something
they'll respond to you in about 3 years' time to say well we didn't read your bug report but it's been a while so we're closing it, if it's still an issue, file it again?
my friend's server had RDP open and people kept flooding it so much it led to a DoS of the RDP
so even he wasn't able to log in with a legit account
RDP attacks have gone mad since covid
even when I changed RDP from the default to another port they didn't stop
I even set up a RD gateway thingy and blocked normal access but that didn't help either
goal is to guess the password and install ransomware
so VPN is best
not that it helps any more, but change your ssh port
yeah I always change SSH port on Linux servers
you'll at least get less wasteful traffic
and SSH key only auth
and use fail2ban
yep I use fail2ban too
and yes key auth so there isn't even the slightest possibility of anyone getting in
and i use key only even locally
I wonder, if I install a VPN on a Corellium device will ReProvision be able to log in 
how many years it's been and I still have to reiterate this advice cause ssh + distros just refuse to have a default secure ssh setup
yeahhh
hahah, I also ran a web server on 443 so I had this sweet ass tool called sslh or something
is there software to control jailbroken iPhones from a mac
what the fuck
wym control
'control'
that is vague
af
yeah I didn't bother splitting it back then, I just had webserver on port 80
but ofc now I have HTTPS
correllium style
yeah my TLD only accepts https so
quicktime is only video
??????????????????????????????????????
there's no touch stuff i think
so you want the arm simulator
no
and little snitch
it figures out from the initial packets whether you're an http or ssh client, and routes you to the appropriate port on the local machine
very cool
and ssh
i want to use a normal iphone remotely
yeah I think .app only accepts HTTPS too (I have https://iconthemer.app/)
my first instinct was to set up letsencrypt anyway
yeah i use cloudflare and .dev
needed the cert for profile signing as well
wonder how school felt about my ip just being a humble web server when they accessed it
hmm
i wonder why going to 192.168.1.237 (quiprr.dev local ip) goes straight to my api?
maybe it's the default for your web server if there's no Host header


1.1.1.1 moment
I don't think TestFlight works on Corellium if the App Store doesn't
:nfrL
i love when termius resets itself
and deletes every host i have
shitty ass app
oh right
no
i have their testflight
best instructions ever

:vibeok:
ios markup tutorial
6 packages are going to be removed. 161 new packages are going to be
installed. 644 packages are going to be upgraded.
You have to download a total of 488 M. This download will take about
1 hour 2 minutes with a 1Mbit DSL connection and about 18 hours with
a 56k modem.```

LOLLLL
they’re probably necessary
filtered, big loss
man they really filtered that
that's a thing? 
@primal perch i didn’t even know about that 

Windows? Disgusting
unfortunate
True
dumbass im in the car
Literally no reason to ever use ubuntu server


ok wow this is actually going to take 20 hours
me when the screen recording won't stop on Corellium
18 hours might cost you a bit on your phone bill 

pacman is so fast
anyway 1.1.1.1 won't add the VPN configuration rip
AppSync probably didn't sign the app extensions properly
true
it does that when i want to six out into my amp
aux
stupid ios

what computer I didn't even connect via usbfluxd 
Sorry I was connecting to it
Can you trust it pls

Trust it
I want to install spyware
i don’t think they considered people aren’t always using airpods lol
it should at least ask what you were doing

Can that ass fart tho
yea
this mf uses snap
who gave him dev role
wow
using a proxy worked for ReProvision
idek what it is tbh
==> Modified (by you or by a script) since installation.
==> Package distributor has shipped an updated version.
What would you like to do about it ? Your options are:
Y or I : install the package maintainer's version
N or O : keep your currently-installed version
D : show the differences between the versions
Z : start a shell to examine the situation
The default action is to keep your current version.``` oh yeah lemme just enter Y
also every program you install with snap requires yiou to add a systemd service
meaning the more snaps you have, the longer your boot time, even if they aren';t running
that also makes snap require systemd
nice
unsigned repo moment
loss
# ideviceinfo
ERROR: Could not connect to lockdownd: Invalid HostID (-21)
what
ok it works now
had to do idevicepair pair
ideviceinstaller works too nice
do I really have to pair again every time I ldrestart 
ERROR: Install failed. Got error "ApplicationVerificationFailed" with code 0xe8008018: Failed to verify code signature of /private/var/installd/Library/Caches/com.apple.mobile.installd.staging/temp.noLygv/extracted/Payload/Odyssey.app : 0xe8008018 (The identity used to sign the executable is no longer valid.)
is jailbreaks.app revoked
oh yeah
L
I wonder if I can add a fake device's UDID to my developer account
lol it shows up as an iPod
lmao it works
with the fake device's UDID registered in my developer account the app installs and launches fine
bruh resigning still crashes
does anyone here know if the ipsw.me api updates as soon as apple stops signing something
It’s kinda slow
I have my script checking 14.3 RC like every 5 mins atm
with tsschecker
ok ReProvision keeps crashing on 13.7
gonna try 13.3
it updates like every 5 minutes
I've always just followed other tweaks I find on this, but what are the proper sizes for tweak icons?
also, the settings icon. Every tweak I find seems to have a different size for it 
look at the anemone wiki for sizes
is that still relevant on modern ios
iirc it hasn’t been updated since 10
Hello jailbreakers
I am sad to announce that I am no longer a pogchamp developer
Loss
Loss
yeah, most of the things haven’t changed
it polls TSS by periodically sending fake signing requests for each version + device model and just seeing if it succeeds or fails, so it’s not instant
package icon: 60x60pt, best to just go @3x on that, so 180x180
settings icon: 29x29pt as @2x @3x (1x only needed for iOS 9 or older)
thanks!
That pain of Big Sur
More like delete both your drive volume and then update
more like throw your computer out the window
yes

anyone know how to present the app switcher
been looking around for a while and haven't found anything
Let's write a compiler in python
Okay, that's something that we should not do
actually
import compiler
def main():
compiler.compile("code.c").run()
there you go

@vivid dew fucking square


lmao this reminds me of a video I watched of how to build a keylogger in python
and it’s basically just import keylogger
lol
python Hello World be like
import __hello__
hold tight, i gotchu sir
#include <hello.h>
int main() {
hello_world();
}
should I make this a thing
libhello
Thats one way to make hello world more challenging
import ast
def insert_returns(self, body):
if isinstance(body[-1], ast.Expr):
body[-1] = ast.Return(body[-1].value)
ast.fix_missing_locations(body[-1])
if isinstance(body[-1], ast.If):
self.insert_returns(body[-1].body)
self.insert_returns(body[-1].orelse)
if isinstance(body[-1], ast.With):
self.insert_returns(body[-1].body)
def parse_and_exec(fnstr):
fn_name = "_eval_expr"
cmd = fnstr.strip("` ")
cmd = "\n".join(f" {i}" for i in cmd.splitlines())
body = f"def {fn_name}():\n{cmd}"
parsed = ast.parse(body)
body = parsed.body[0].body
self.insert_returns(body)
env = {
'__import__': __import__
}
exec(compile(parsed, filename="<ast>", mode="exec"), env)
result = (eval(f"{fn_name}()", env))
@tepid olive here you go, “compile”/ interpret python code string & exec it
indenting might be fucked, on mobile rn

Python Hello World ^
(
(
lambda __, ___, ____, _____: getattr(
__builtins__,
().__class__.__name__[__ << __]
+ ().__iter__().__class__.__name__[(__).__rmul__(-1)]
+ [].__class__.__name__[____ % ___]
+ chr(_____)
+ ().__class__.__name__[__ >> __],
)
)(
(lambda _: _).__code__.co_nlocals,
(lambda _, __: _ | __).__code__.co_nlocals,
(lambda _, __, ___: _ | __ | ___).__code__.co_nlocals,
(
(lambda _, __, ___: _ & __ & ___).__code__.co_nlocals.__rmul__(
(lambda _, __, ___: _ | __ | ___).__code__.co_nlocals
)
+ (True.__rmul__((lambda _, __: _ | __).__code__.co_nlocals))
).__rmul__(
(
lambda _, __, ___, ____, _____, ______, _______, ________, _________, __________:
_
).__code__.co_nlocals
),
)
)(
(
lambda __, ___, ____, _____, ______: hex.__class__.__name__[
___.__rmul__(____ * _____) - ______
].upper()
+ hex.__class__.__name__[___.__rmul__(____ * _____) - _____ - ______]
+ hex.__class__.__name__[___] * 2
+ hex.__class__.__name__[___.__rmul__(____ * _____)]
+ chr(__.__rmul__(___) + _____)
+ Warning.__qualname__[______ - True]
+ hex.__class__.__name__[___.__rmul__(____ * _____)]
+ Warning.__qualname__[_____]
+ ().__class__.__name__[___]
+ {}.__class__.__name__[______ - True]
+ chr(__.__rmul__(___) + ___)
)(
(
lambda _, __, ___, ____, _____, ______, _______, ________, _________, __________: (
_
)
).__code__.co_nlocals,
(lambda _, __, ___: _).__code__.co_nlocals,
(lambda _, __, ___, ____: _).__code__.co_nlocals,
(lambda _, __: _).__code__.co_nlocals,
(lambda _: _).__code__.co_nlocals,
)
)

I'm shocked and in awe at what you wrote
SOMEONE PIN THIS
shutju@pc apoyan incorporated
ok
is it against rule 1 to tell someone to kill them selves?
tbh could just kill myself then wouldn’t have to see shit like this again

ghost
boba

cute ghost
.
ok opening
should I include a basic rundown of handles or just summarize it to “fuck you win32 owns you anyway”
option two it is, i’ll pr

my sincerest condolences
it’ll be worth it, trust in win32 and lack of brevity in favor of beauties like LPVOID & LPCTSTR
when nvim
@gaunt mesa are you up
what
the
fuck
do u want
@burnt niche
its 3am
u better have a compelling reason
Play
to bother me
Oh shit

ok so im creating a mach voucher
nvm
yall prob dont care 
but im def looking into making a POC for this race
i hope this is the bug mentioned in the patch logs
Reminder that every bug will not be related to Mach vouchers
@faint timber ok but this one is

Idk how to explain it but it’s a race condition in ipc_voucher
That definitely use mach_swap writeup
Yeah
Im also using extra recipe as a reference
I’m also reading the exploited in the wild chain 5
Which is pretty much the same bug as mach_swap
Yeah it’s the same bug definitely
Pretty much my end goal here is to make a working POC tho
So I can get a better understanding of the vuln
And help others out
Understand how pid_for_task primitive works
Ok
I think I understand it thanks to s0rrymybad’s write up
But Im still a long way to go
It’s explained well in Mach_swap
Alright thanks
Petition to rename regex to regflex
petition to rename UIEdgeInsets to UIEdgeInsects 🐜
lol
And Swift to Slow

yay everything is working now
repo tested on Cydia, Sileo, Zebra, Installer
ReProvisionFix tested on Elucubratus and Procursus
14 votes and 0 comments so far on Reddit
what was the point when you can just install mybloxx 
installing the mybloxx tweak doesn't even install the mybloxx profile itself so you can use other shit
can someone help me with gh pages
pls
i am braindead i think
it just
wont work
@gentle crescent
you
i choose you to help me (im not entitled)
SAME
gh pages poggers
okay so bascially github pages is not difficult and you suck so you should leave
you are welcome for the help
@heavy kernel hi ok ill show what i have now
static website moment
i did
then wait
oke then ur fine
That reminds me
is ur CNAME file in the repo pointing to ur domain?
how to develop a tweak
ok so I installed theos and it did not build me a tweak
Try reinstalling
Works on my machine
http://map.mc.anamy.gay moment
dynmap is so bad
@heavy kernel
ik
@tepid olive it works for me
we were using it but it got too laggy for the server
Lovely
wait hwat
refresh ur cache
@grim sparrow hahahahahahahah ur gay!!!
Shift F5
it doesnt work on my wifi
GAY
wtf
banned for hate speech
view in incognito
temmy moment
@heavy kernel hahahaha another gay!!!
it works on 4g
rule 1 infraction

you will now die

just give time for everything to update
aight
best website https://cfw.gay/
lmao
How much did cfw.gay cost you
BRUH
?
i went to buy it and
@heavy kernel it doesnt work for dutch people lool
that's how much it was
https://github.com/ModernPwner/cicuta_virosa hacker man
propagatioklsdngfkjdsnigkfdnsg
tale.me dropped from $650 to $400





















