#development
1 messages · Page 414 of 1
it works for you and other british people
interesting
but not for dutch people
i want it the other way
propagation? nah i'm all about that propa ratio
amy i hope u appreciate that i pronounce ur domain as anime
rip
yes that's the point

true it works
Stage 1: race for voucher ivace uaf
perform_user_data_element_uaf_race: success on 50 iteration
uafed_voucher: 23963
Stage 2: leak task port address and overlapped index
Got fake element dump!
Overlapped index: 419
Next spray index: 11
task_port: 0xffffffe1aa325998
Stage 3: Convert uaf into pktopts uaf
Respray fake user_data_element
Destroy uafed voucher...
Established custom r/w primitives!
Stage 4 (DEMO): pwn kernel
task PAC: 0xe3b90261a9e9d900
PAC decrypt: 0xe3b90261a9e9d900 -> 0xffffffe1a9e9d900
proc PAC: 0xb9b7c661a0ff9920
PAC decrypt: 0xb9b7c661a0ff9920 -> 0xffffffe1a0ff9920
ucred PAC: 0xa9d8d1e1a9d22130
PAC decrypt: 0xa9d8d1e1a9d22130 -> 0xffffffe1a9d22130
Overwriting kernel credentials :)
getuid() returns 0
whoami: root
Out.```
true
I can do that
printf("Overwriting kernel credentials :)")
printf("getuid() returns 0")
printf("whoami: root)
wtf
hacker
i will
i need to reboot tho
pov me after making jailbreak 
LETS FUCKING GOOOOO
so much for me having to make a POC


lol
anyone here british

@tepid olive

Who the hell are these people
Jesus
They’re just decked out and dropping shit for no reason
Also hate to be a negative Nancy
But this name dumb af
testing now guys

ok that’s great and all but
Go ahead
Say who asked
Ok update: my cock exploded
I would not recommend running this exploit on your cock!
True
Don’t run it on your cock
ugh imagine having to reboot
exploit has been 100% success tho
in my about 5 runs

so ModernPwner is a “dumb af” name but we’re not wondering about “cheesecakeufo”
are you fr
ModernPwner 
@tardy narwhal cheesecakeufo is badass
man my name is food as well
Cheesecake is good

And UFOs are cool
cheesecakeufo >>
yea it’s like being named mass1ve_nut
Ran it 7 times, worked 7 times 
modernpwner sounds like someone who just downloaded a hacked client for cod

true
british moment
oke
looks like every other one i see in that there’s mach_* everywhere and idk what’s going on
Funny thing is
be afraid of spinlocks

I was reading up on mach_swap
And it looks a little similar to that
And extra_recipe
oh no my kernel panic
So based
Odyssey best jailbreak
yea i love those random black screens
nfr
why does google dark mode buttons look so desaturated
teacher: use this video as the only source for the lesson because i’m lazy af
oh also the school network blocks it and ur fucked lmao

nfr
rfn
ok exploit worked second time
ok why can i do a lot of shit
except html and css
im just tryna make a aboutme page

@tepid olive 

html and css is literally the easiest thing
ik lmfao
look what i made
its very cool
damn
well that’s does it for me, might as well remove my dev role at this point
give it to this man
well you certainly scream backend dev

BACKEND DEV
@heavy kernel https://quin.codes/index.html
Back-end developer
dont mind the backend dev
im changing thast
but look i added icons

Backend dev 

i develop in c++ and c#
how is that called
@tepid olive
and js
i was about to say something
but i realized that it was in the name user_data_get_value()
@primal perch how do i call my self
i do c++ c# js
and some other stuff
mostly for game hacking
person who uses c++ c# js for game hacking
true
u don't need to include index.html in the url

that mf has full cloudflare under attack mode on 

@tepid olive https://quiprr.dev
High school student and full-stack developer.
if u want inspiration
High school student and full-stack developer.
GitHub Twitter Keybase.io
What I do:
Discord Bot Developer
Full Stack Web Developer
Developer for Asset Entities
iOS Runtime Modification Developer
What I'm working on:
Notatio, an upload tweak like ShareX for iOS
Sectro, a lightweight Discord pay-for-role service
Console, a cross-platform drop-in replacement for macOS Console.app
Yeha true @primal perch
shlorp 💎🤲Today at 8:19 AM
High school student and full-stack developer.
GitHub Twitter Keybase.io
What I do:
Discord Bot Developer
Full Stack Web Developer
Developer for Asset Entities
iOS Runtime Modification Developer
What I'm working on:
Notatio, an upload tweak like ShareX for iOS
Sectro, a lightweight Discord pay-for-role service
Console, a cross-platform drop-in replacement for macOS Console.app

@primal perch u like my favicon
idk i can’t see it

.

Epic 6.5k cock
what
pretty color 🙂

dude you need to have those imported
it worked fine before
but adding #include <sys/wait.h> worked
literally says so
now make is hanging 
it literally fucking tells you what to do
L
stfu
true
it told me to "import", took me a while to realize I can translate that to an include
so many hoes are mad here
like damn bro you were in that same place not that long ago@here
here
nfr
fr

burrit0z banned

he almost like the other burrito now 


KaylaDev moment

L
Sooo.... due to there probably being a new jailbreak for iOS 14 with arm64e support soon, I was wondering if there is a somewhat convenient way by now, to include both slices for arm64e?
working on a solution
i think what it is rn is lipoing two dylibs together
TL/DR: You have to race twice to exploit the bug, the PoC is at the end or there.
EDIT: Well it seems that @ModernPwner just published an exploit for this vulnerability, racing us by few hours! Congrats to them! You can find their exploit here.

fr
wait for theos update, profit??
except i dont wanna update theos bc of stupid shit it shows
update make 
i did
🚀🚀🚀
loss
I haven't really noticed a speed difference tbh
ok
🌕
LMAO
@restive ether what fw are you chilling on
14.3 RC1
true

i got cucked by FR
FR failed like 3 times
f
rip
when i was updating to .3
so i just used RC
that dude has Pac bypass and exploit for 14.5 though
true
true

yeah
@tepid olive Whats wrong/the error with reprovision on iOS 14? (asked here, cause the #jailbreak channel is being spammed with wen eta whiners).
not sure but I think it doesn't sign apps at all there
Hmm, thank you, once I am done getting my mac vm up, I might take a look at why.
how should i get started with tweak development? I’d like to start making my own but not sure what to do
Depends on the path you want to take, the struggle path (making tweak sooner) or the long con (proper tweak development)
🖐️🤲💎🖐️🤲💎🖐️🤲💎🖐️🤲

:frbruh:

Yes buy in now, sell in a week 
damn is it not possible to enter recovery mode on Corellium
# ideviceenterrecovery 2b9dc25c99342ab14a4030888c4bdb637e6cf676
Telling device with udid 2b9dc25c99342ab14a4030888c4bdb637e6cf676 to enter recovery mode.
Device is successfully switching to recovery mode.
it just boots back to normal mode
wanted to see if I could restore a newer ipsw than 14.3 
ret, rdrand
ret x4
hi, total noob here. i appreciate any resources for using dragon to dip my toes into tweak development. i am getting mixed messages on the dragonbuild repo regarding whether or not to learn it

if you are just starting, use theos
better yet just use theos
i dont actually know theos either though; im a web developer mainly, but i want to start hacking callKit similar to the call hacks from limneos, except for a different purpose-- i want to bridge the calls through jitsi
theos currently has more documentation as well as examples (since nearly everyone uses it)
dragon and theos literally are just scripts 
ok im in the right place then obviously. thank you. i have some old obj-c dev experience but not from a jb perspective so i am looking for pointers to get started
yea it's okayish... reason i looked at dragon is the closest thing to what im trying to make was made by this guy here https://github.com/michaelnew/matrix-iosbridge-imessage and he said he gave up because theos was really painful to work with and that he recommends i use dragon to build it
sounds like gme is on the moon
0x3A28213A, 0x6339392C, 0x7363682E
funny
so that's why i was looking at dragon, but what do you recommend as educational material to get up to speed sufficiently to finish his work?
i laughed
lol thanks for the pointers
i figured i would ask in here generally before pestering the particular author of that project myself
but if it's just sorta figure it out then i dunno
refresh on objc and you’re good to go
i felt as though this https://iphonedevwiki.net/index.php/DragonBuild was pretty good but still lacking in terms of "here's how you get a basic app going from start to finish" .. my dragon setup throws silly errors on linux and mac , and ya'll saying dont even worry about dragon so forgiive me for being a bit unsure where to go from here
honestly im fresh on it, im just not clear on how to get stuff TO my jailbreak phone
just use theos and their templates to get started with something barebone
ok yea that sounds like what i am looking for.[ is there some barebones project template or resource that you recommend that is well documented for a noob like me ? i was reading about theos and saw notes that it was recently taken over due to previous dev getting busy so i wasnt sure how that affected future trajectory if at all too
this looked good https://ish.app/ and i saw the maker of dragon has a fork of it but again i got confused and overwhelmed
the question at this stage would be if you’re understanding the idea behind a tweak

the idea i have of it is you can make a .xm file whose purpose is to monkeypatch private functions
me @grim sparrow ? sorry ill change it
sounds about right, yeah: Writing fancy extension/ patches.
if you roll with it you’re probably realizing there’s no real template to base your stuff around. You can look at OSS projects (filter on github by logos) and try to follow how it’s done for certain applications/ frameworks
hi; yeah like i said im a total noob but i have a lot of programming experience. just not the hardcore intelligence stuff it takes to really do jailbreaks; more like "consumer developer" for 10 years... i can do things if it's documented for idiots
lol
Nah dw jailbreaking isn’t any different than “consumer development”
it’s just writing funny looking C
true
cool yea i was searching logos on sourcegraph in fact. appreciate the tip
not sure WHY i was , but iw as lol
obj-c headers is all the documentation you need
ok cool i was looking at this https://developer.limneos.net/index.php?ios=13.1.3&framework=DataDetectorsUI.framework&header=DDCallKitAction.h
np, good luck on your ventures. Be sure to document your progress along the way, make use of headers if available and definitely acquire the skill to debug
figured i can make .xm that hacks into calls or whatever via patching some of that
any great example projects to link me to ?
or beginner docs, just anything i can work on today?
i’m personally unbiased towards any but skitty has lovely tweaks
but you’re lowkey relying on the fact of docs which isn’t necessarily available. It’s mostly trial & error if no one did it before
ok awesome well i appreciate all your advice those who have been giving it. thanks; knowing that it's just trial and error and not to seek so much guidance/template/docs helps a lot to just keep smashing til i get somewhere. i like the simple UIAlertController idea as a first step.
if i get somewhere ill definitely document it so people like me arent lost. i really have looked at jailbreak community for years and never realized why i dont understand how to play here... but i can play just fine in other dev cultures. never figured it out. but hey better late than never i guess
well granted everywhere unknown the first approach is to seek docs or resort to good ol’ trial and error
but yeah welcome aboard, just be sure to follow ya headers
And remember there is no such thing as go-to approach/solution/method

PATRICK JB ETA SON

the fact i wasted time in class on a literal ui is sad
needs more round
is theos the best for developing tweaks on linux?
GOODBYE I GTG
It doesn't really matter
and does it matter if I use any ios sdk cuz the theos githubs latest one is like 10.3
i think it matters more if you know objective c
lol
im new lol allow it
then you shouldn’t do tweak development
ok will do
”will do” as in you’ll completely ignore the advice and proceed to listen to what you want to hear or genuinely try and approach it correctly @serene hull

you can use the standard script to create sdks

[Question] Install Cydia alongside exploit
Hi, in light of Circuta_Virosa, I wanted to try to make my own private jailbreak.
Yes I know the risks and such, I have 3 testing phones for that matter.
I was looking in how to use the exploit and was wondering on how to install a package manager(preferably cydia) once the exploit has been run.
I was thinking that is was a separate executable or extension to the exploit that would install it, but I don’t know how to go about that.
Any help is appreciated and please no need for excessive sarcasm or trolling
yea ok
you've asked me to do a lot with it
and I'm lazy
I'll add my modified nearfield and co headers soon
I did yeah
Not much
I think there were a few missing imports and like 2 syntax errors
@grave sparrow use the one on his repo, it's more updated afaik
he has mac builds on github

wait
I have no idea

Classdumb-dyld is updated
Wtf
Like a year ago
I’ve been using dsdump that capt put me on. And it doesn’t work like i want it to
how
i had to manually make /etc/init.d/uwsgi
i dont remember doing that the first time
but now it just 502s
im gonna dm you
ok
every kid on the block gon be tryna make his own jb
😩

You have to sacrifice a newborn to jay saurik
And watch as he sucks the adrenochrome out of the fetus in front of you
In order to get cydia to install
how to install exploit???
holy crap stage 3 takes forever, please someone smart fix this
@tepid olive find a way to get around the sanity check 
what even is the sanity check
Glad unc0ver gets fucked from not being able to use the exploit
pwn20wnd would have released a jb today
tbh still will, just gonna obfuscate the exploit until it is unrecognizable
wonder why
Look at that for loop

You could prob figure out a way to make it smaller by doing some calculations or something idk
i have
what exactly is the sanity check tho
i havent looked into the exploit deeply enough
ok
lmfao
@tepid olive do you mind explaining why the loop is needed
i want to learn
kill

@vivid dew true
literally not true
literally so true bro
literally pwn20wnd already has working jb he just needs to get exploit

😤


no












paypal donations 📉
drank in croatia
Lmao
Tb when i was a pwn fanboy
Dark days those were
Glad im on the winning team now
pwn is down bad

imagine getting the access to an exploit removed
true
it’s not like he cant use it
more like he won’t
sfwtwerk
i dont fucking care who makes the jb tbh
i just don't want it to fucking suck
ok and who asked
ok
give what

Don't need jailbreak if you got the full source
Ah so you have finally finished RE all of iOS?



@twilit jungle wen eta i
S 15
.
burrit0z dev again 
Unfortunately
would it fuck things up if I spoofed a Corellium device's UDID to be the same as a real device 🤔
Succesfully hooked discord
Tapping view inserts current pasteboard item to the text
Now make it so that it doesn't lag on iOS 12
Lmao

remove the gift button and you get $1
I could do that
When i get home
@restive ether i was making this to make a nitroless tweak for fun
Private
Lol

nitroless tweak?
how hard is it to hook discord and when you try sending an emote, the hook replaces the emote text with the link to the emote image
thus displaying the emote
could do some resizing though
just use NQN in all your servers loser
True
@restive ether sorry for doubting
you guys wanna hear something my Java teacher deadass said today
she said Java does not have multiple inheritance
but she believes that C does
not C++
C

she believes in void*
void *
= malloc(sizeof(dgh0st_cock));

time to memcpy dgh0st cock
fatal: Out of memory, malloc failed
Can you bestow some of that power upon me
jewish power
TIL you can use emoji in the name your variables
how effective/not effective at all is adding tweaks as conflicts?
e.g. unnamed pirating tweaks
You would be revealing the repo names
I mean afaik package managers don't show all the conflicts
people would have to go out of their way to check it with apt or download the deb / Packages file
What
ask karen
Conflicts: *cydo*
Conflicts: *
wait is that actually what happens cause i wouldn’t put it past cydia
yeah seems so
oh besides bootloop

here i am paying a company $5 a month just to post a mini gif of a black man twerking
if you spoof iOS 15.0 the Cydia UI will turn into Sileo
ok
and?
me when you literally have us your udid

me when it's a Corellium device
haha time to download tweaks with this udid!!! 
ok
and?
still going to download paid tweaks with this
I haven't bought any tweaks on this so unless you're incredibly lucky and somehow the same UDID has been used by a real device... 
0% chance 
nice
I fucked with SystemVersion.plist it went to the restore screen somehow
sad!
8 votes and 11 comments so far on Reddit
what’s the point of checking each character in a reply against a list

try:
#hex
device["ecid"] = int(answer.content, 16)
except ValueError:
#not hex
device["ecid"] = answer.content
``` probably use try except
easy dub


valueerror is thrown if it cant create a hex int out of it
so the exception is not hex
console looks nice
because it is valid hex too
you can change UDID on Corellium but not ECID 🤔
Damn discord do be lagging when you hook it
imagine kernel panicking
impossible for the udids to be the same

i can’t even see the image cause discord won’t let me click to it on mobile
mobile gay
for newer devices the ecid would have to be the same too
shut up
how
it doesn’t jump, that’s how
and for older (<=A11) udid is the sha1 hash of serial + ecid + mac + btmac
True
true
else
well i spent all day looking at this exploit even though i’ve literally never done anything exploit related before and now i have 6 hours of homework to do 
commit die

main instead of master
no cap main is less to type than master
and ive always spelled master wrong
like there have been so many times ive had the main branch be msater
or masetr
just call it cock
can you name a branch HEAD

subversion deez nuts
subversion the fuck out of here

Uhh I am sure you can murder a child with just 2 fingers
but can u murder a child and write an HSWidgets update at the same time?
yeah i thought so
Yeah HSWidgets updates itself so definitely doable

i use 8 fingers
Yeah... other people experience the same events as you. Meaning you are the protagonist of this simulation.
9 fingmerts
close enough
hey cuties
ive been MIA for about 24hrs
is there anything ive missed i should hear

hope he died in surgery
Interesting take
I very much agree
very true
pwn masters narcissism excellently i see
wait one can do that?

true
pin limit?
nah it worked for a few seconds
mfw geniuses can't pin messages in #development
can we unpin a fr emote
yes

This cannot be unpinned
im gonna pin you
true

true
hayden bra
very ironic picture, thats why its so good
hayden in a bra is quality development content
without that all of our development workflows are incomplete
true
why do u always say true
true
also why do u have developer role althio
excellent question
did u make a tweak?

yes, it was junk
andrew
very true
doesn't thatmake u an advanced developer then
yes posix sh is advanced developer level
six
sh
advanced moron
if u don't use
sh shell u have issues
how do i get uhhsh shell
uhsh?
where do i acquire
sh
yes
true
society if
i searched uhhsh
if cum
ghostpp
ghostpp:
when_nitwerk_was_young
not ath one

ntwerk
LMAO
uhhsh on facebook
go ahead ping emma
it’s actually hard to get warned in dev
the only mods that come here are me and jules
@heavy kernel
@ancient imp vim is better
and neither of us care
julian gonzales

what are you attempting to accomplish
besides getting yourself warned
again
being a dick
gotcha
Unscramble UHHSH. Unscrambling uhhsh we found 22 valid Scrabble words and scores. 22 words unscrambled with the word unscrambler.
watch emma warn me and not boba
why would she warn boba
n word
h
this is not a slur
you are a slur
ok then remove 100 of my warn points
how
do they still have an alert for ntwerk
not the 500 clones i bet
true
no you were stupid and knew it was against the rules for those like 3 moronic hours
normally i’m too focused on the sexy beast in the foreground
so it’s not against rules anymore?
no

but if you spam it i’ll just mute you 
again?
so basically the admins just wanted to warn me so they made it against the rules for 3 hours
no only the idiot mods warn me
it wasn’t something i was ever consulted on.
or asked about.
and it’s not like you were the only person lol
me when mods filter two letters :extremelyoffensivebobby
burrit0z, time for your monthly mute dear!
just temmy and me pretty much
*daily
custom probably
true

cool i just ran ps aux in my iphone over ssh for the first time 
it should be daily
ok
imagine having >50 warn points
i got 0 
Points: 50
Reason: is mod now
Moderator: Patrick#8888
Warned on: December 11, 2019, 04:21 AM UTC
Points: 100
Reason: context
Moderator: Patrick#8888
Warned on: November 23, 2019, 05:34 AM UTC
Points: 50
Reason: n word
Moderator: max#0009
Warned on: July 23, 2019, 06:38 AM UTC
Points: 100
Reason: nword
Moderator: Patrick#8888
Warned on: July 23, 2019, 05:18 AM UTC
true
the way i got 50 was really funny
@restive ether n
word

WTF
me when ni twerk was young
yay kill -9 Spingboard did what i expected lol

true
you know there’s sbreload
amogus ass
ok thank you no i am total noob tbh. learning right now
If you could just punch people through the screen you would have half of these would people never get in front of a computer

sbreload worked, awesome
i’d knock all you tf out
stop ur making fun of me
:(
I would take that bet
true
anyways time to hop on my alt (aka temmy) and go spam n word hard r in multiple servers
@restive ether wtf you attack me????? wtf
yes i would have been traumatized w a face punch to my 6 year old face from irc people in the 90s and never touched a computer again

i hate discord
i hate you
what’s another one gonna do LMAO
i came in asking to learn how to hack they told me go get laid i didnt kno what it meant tho. sorry if TMI
LOL
Lmfao
lmfao
the official t shirt of jailbreak developers
https://www.redbubble.com/i/t-shirt/IDA-Pro-Pirate-by-security-sucks/46832662.FB110
true tbh
Lmao
I gotta ask how many people in this chat have a legit license for IDA
2
but only 1 actively talks here that i know
schmoo and krit iirc
ok make that 3
jiang ying, what a man
the king 👑
the world never needed hackers
we can do just fine going and picking berries and hitting rabbits with rocks for food
This makes me feel alot better 
7.2 or what version? I use v7.2 cracked, pweas don't ban me, I can't afford ida 
mac users crying rn in 7.0
unless 7.2 is cracked idek
Only on windows v7.2 is cracked with debuggers. v7.3 is cracked on windows too but is without debuggers so its pretty much useless.
LOL
true
.
@restive ether Pweas don't ban me, I can't afford ida
. (saw you typing).
ok'
there is probably one thing i don’t care about
and it’s IDA
Somebody did legit crack v7.5 with debuggers (the latest release if I am correct) on windows but then they added malware to it, so it technically never got cracked/legit. 
me when ida 7.0 perfectly decompiles this and gives me psuedocode i can compile and turn into a binary that does the same thing as the original

Is ida a tough subject I'm guessing here just because its way to expensive?
yes
nobody really gives a shit
its wrong to pirate 0.99$ tweaks though
unironically facts
Yep




















