#futurerestore-help

1 messages · Page 139 of 1

green onyx
#

strange af

low summit
#

Maybe they skip rc?

green onyx
#

why

low summit
#

Who knows 14.5 out next week anyways

#

If 14.5 gets jb then rc blobs will be available on tss

zealous bridge
#

@lilac wren still can't get it to match

zealous bridge
#

interesting

celest basalt
low summit
#

Xcode is gonna make ur mom mad lol

celest basalt
#

huh, apparently you can't OTA from 9.3.5 or lower to 14.6+ anymore

#

Users still running older versions of iOS (up to 9.3.5) are now presented with a dummy update file, and are instructed to use iTunes to install software updates.

#

that's fine, this is only 14.6+ and only from 9.3.5-

#

for the delayed OTA you need to be on 11.3+ anyway

#

well they can until 14.5 is unsigned

celest basalt
#

it is with MITM

#

but at that point just use iTunes

#

unless you want to do this on an Apple TV 4K

zealous bridge
#

no

#

only latest

#

you can use delayed ota

#

and MDM

#

also MITM yes

#

but for average user no

#

but bear in mind that ota signing and ipsw signing is not synchronous

#

not time wise

#

if a version is signed for ipsw

#

it may not be signed for ota

#

and vice versa

green onyx
#

hello

#

anything new

#

or anybody need help?

#

ah

valid adder
#

There’s an app that says what’s taking up storage lol

#

You may need to delete apfs snapshot backups

lilac wren
#

Daisy Disk

green onyx
#

LMAO

#

is there windirstat for macos

#

lol

#

huh

#

try this

lilac wren
#

Daisy Disk is a lifesaver

#

idk if there's anything as good for free, but you should look

celest basalt
#

Finallyyyy I successfully updated to ios 14.3

low summit
#

Using Ota?

celest basalt
#
Sending TSS request attempt 1... futurerestore: failed with exception:
[exception]:
what=SEP firmware is NOT being signed!
#

I'm an idiot

#

I used 14.4.1 instead of 14.4.2 fr

#

hmm, if I use OTA SEP it won't even work

#

just messing with pwndfu

#

oh fuck I used 14.4 blobs instead of 14.3

low summit
#

Any success?

#

Wish you luck lol

celest basalt
#

no

#

still panicked

low summit
#

Fdr is ass

zealous bridge
#

why succession crashing

green onyx
zealous bridge
#

Yeah

green onyx
#

what does it crash on

#

what step

zealous bridge
#

Extracting .dmg from IPSW

green onyx
#

uh

#

never had that issue on 14.3

zealous bridge
#

it stays there for like 5 minutes

#

and then crashes

green onyx
#

open succession

#

go to settings

#

and check version #

zealous bridge
#

1.4.16~b4

green onyx
#

damn

#

disable tweak injection?

#

into succession

zealous bridge
#

its my mums phone i just jailbroke it

#

no tweaks

zealous bridge
#

also theres no restore system button

low summit
#

I could jb my parents

zealous bridge
#

in checkra1n loader app

low summit
#

And they wouldn't even know lol

green onyx
zealous bridge
#

how do i fix this in 5 minutes help

low summit
#

They want cercube lol

#

I kinda want to do it

zealous bridge
#

stupid banking apps istg

green onyx
#

the home page

zealous bridge
#

lol i gave the phone back to my mum but it said 14.1 iPhone9,3

low summit
#

She wanted a jb?

green onyx
#

i dont need that

#

i need to see what it says at the bottom

#

@zealous bridge ask for phone back

zealous bridge
#

Download clean filesystem

#

And settings

green onyx
#

the ipsw is in wrong directory

#

or theres a corrupt ipsw

zealous bridge
#

when i press download it says

#

ipsw found

#

do you want to use it

green onyx
#

remove that ipsw

#

in filza

zealous bridge
#

or get a new one

green onyx
#

and then start succession again

zealous bridge
#

ok

green onyx
#

also when u run succession, dont close phone or let it dim

#

set autolock to never or get nolowpowerautolock from sparkdev

zealous bridge
#

it doesnt turn off anyway

#

probably have autolock set to never already then

#

ok its downloaded

#

unzipping now

#

crashed

#

will try again

celest basalt
#

uhh wtf

#

my phone keeps looping between Apple logo and recovery screen

zealous bridge
#

@green onyx same shit

green onyx
#

what happened during download

celest basalt
#

ok nvm irecovery -n booted it up fine

green onyx
#

bruh

zealous bridge
#

crashed at exactly the same time as before

#

lol

green onyx
zealous bridge
#

no

green onyx
#

did download go fine?

zealous bridge
#

it went downloading, unzipping (crashed here once, reopened), verifying ipsw, extracting filesystem from dmg (crashes here consistently)

green onyx
#

ye unzipping isnt suppose to crash

#

the whole process isnt suppose to crash except at the end, when it crashes and reboots

zealous bridge
#

i cant even restore rootfs wow

green onyx
#

why doesnt she have a root fs

zealous bridge
#

checkra1n didnt make one for some reason

green onyx
#

reboot

#

and rejailbreak

#

have u tried that?

zealous bridge
#

yeah even safe mode

#

I might try with unc0ver

green onyx
lilac wren
#

Just reboot

zealous bridge
#

i did get cydia

#

and i need to get rid of jb detection

#

so rebooting changes nothing

lilac wren
#

Oh so that's why your successioning

zealous bridge
#

If theres a sepnonce in there

#

It’s known

#

Actually i’m not sure whether it was shsh host or tsssaver

#

Try both

#

Rip then

#

Imagine we could set APNonce directly

#

Without having to mess with the generator

#

Lol true

#

Because it’s signed? Lol

#

Thats like saying

#

Why cant we just change the ios version number of the blobs

#

And make it whatever version we want

stiff hazel
#

@zealous bridge @zinc moon I forget what happened when we tried beta profile + method

#

iCraze is wondering if we could do that and somehow pull shit like 14.4b1

#

And see if that works with cicuta_virosa

zealous bridge
#

What are you talking about

#

@zinc moon ez

#

imma check with img4tool hol up

#

ok the sep nonce is called snon

stiff hazel
zealous bridge
#

hm

#

i dont think delayed updates work for betas

#

but try still

#

yeah doing it rn

#

ur sepnonce is 9796144df599b7e508817569add430640ac87026

#

it came up in tss saver too lol

celest basalt
#

but maybe you could get beta blobs with the BCert because it's only tied to ProductMarketingVersion

#

but then you either need pwndfu or need to MITM it in a way that you can keep the same SepNonce because it changes on every request

celest basalt
#

smh Discord not rendering the emoji properly

zealous bridge
#

18D5030e

celest basalt
#

idk how to fix it on desktop but I need to reinstall emojiport on iOS

lilac wren
#

I'm on 14.3, when was it supposed to be added?

celest basalt
#

14.5

#

I think

lilac wren
#

Oh ok makes sense

#

🏳️‍⚧️ wait am I dumb or is this it?

#

But I'm on 14.3

#

O_o

#

Not even

#

Maybe yeah

#

Idk why discord breaks it then

#

Bc I can't see it in your username

zealous bridge
#

i also have this one

#

wait see what

celest basalt
#

hmm yeah it's still broken even with emojiport

#

Sloopie 🏳⚧

zealous bridge
#

still needs a jailbreak and supervision

#

might as well use otadisabler at that point lol

lilac wren
#

Rip

#

Wow doesn’t work for me either

celest basalt
#

🏳️‍⚧️

#

testing

lilac wren
#

It’s def discord’s fault

celest basalt
#

yeah Discord fucks it up I guess

lilac wren
#

Test

#

Wow discord seems to break all those joined emojis

zealous bridge
#

and without the beta profile?

lilac wren
#

Oh no 14.3 is gone now? :(

zealous bridge
#

wait what rly

#

loss

lilac wren
#

Oops

zealous bridge
#

lmao

celest basalt
#

it will fail if you spoof systemversion

#

oh

#

anyway Filza keeps failing to edit that file for me so I have to use the terminal

zealous bridge
#

we still got 11 hours left bois

#

makes sense

#

as long as you have the delay profile

#

it'll still show 14.3

lilac wren
#

Let's sniff that

#

I want to see what the request was

zealous bridge
#

are you sure it's final

#

lol

lilac wren
#

I think you should sniff the request and response, it'll probably answer your questions

zealous bridge
#

yeah tbh

#

if we can sniff the response it'll tell us the build number

#

nah from pallas

#

tss is way later

lilac wren
#

Well if you block tss you never have to risk it

zealous bridge
#

nah you dont even need to download it tbh

celest basalt
#

this is weird, I spoofed to 18C65 and I'm not getting any update with the profile

zealous bridge
#

the first request and response should be enough

celest basalt
#

either block the gs.apple.com response with a proxy (no SSL) or just have an SSH session open with reboot pretyped

zealous bridge
#

yeah and get rid of the pinning

#

[[SSL Kill Switch]]

mystic axleBOT
#
SSL Kill Switch 2 (iOS 13)

Blackbox tool to disable SSL certificate validation and pinning

Author

julioverne, Alban Diquet

Version

0.14c

Price

Free

Repo
Add Repo
More Info
celest basalt
#

gs.apple.com doesn't use SSL in the first place so no need if you just want the TSS request/response

zealous bridge
#

i think we want mesu more than TSS

#

would be easier

celest basalt
#

while we're MITMing someone should get a BCert bc I want to see if it will work for the next 3 days beyond April 26

#

IIRC someone managed to just force restart at the verifying screen to stop the update even, but SSH open and hitting enter on reboot (make sure to be root) is easier

#

or that yeah

zealous bridge
#

im trying to see if 14.3 will show up rn hold on

lilac wren
celest basalt
#

idk I can try to MITM it

#

14.4.1-14.4.2 has same SEP as 14.4

zealous bridge
#

uhhh

#

guys

#

preboard is filling up the whole thing

#

is that supposed to happen

celest basalt
#

yeah for some reason it didn't work

lilac wren
#

What's it say

celest basalt
#

even 14.4->14.4

zealous bridge
#

uh what is preboard doing

#

im scared

#

this thing is updating

#

oh shit

lilac wren
#

Lol berry what did you even do

zealous bridge
#

nvm

lilac wren
#

Are you sure it's updating

celest basalt
#

yeah but the SEP is the same... maybe there's something telling it that "this SEP was installed with a 14.4.2 BuildManifest"

zealous bridge
#

preboard just took rly rly long

#

it filled up halfway

celest basalt
#

you know @sacred estuary the weird thing is a few days ago I got my 14.4 SEP to generate a BCert for 14.3 but TSS rejected it with error 94

#

and someone else after also reported failed to verify (not downgrade) on iPhone10,6

lilac wren
#

Happened to the 12.4.9 ipad and did the whole "press home to upgrade" and Apple logo progresd bar, when it was done it was still on 12.4.9

celest basalt
#

so maybe Apple unsigned it for this device only idk

#

like A14

lilac wren
#

What was the issue with A14 for OTA again

zealous bridge
#

@celest basalt i'm getting 14.3

celest basalt
#

I went to test it after that and 14.3-14.4.1 all gave me a BCert but TSS error 94

#

and then 14.4.2 managed update went through and since then I'm not able to get a BCert again

zealous bridge
lilac wren
#

Ah ok

celest basalt
#

yeah, TSS just rejects even the managed request for A14

zealous bridge
#

spoofing 18C65

celest basalt
#

weird

#

I even used OTAEnabler

zealous bridge
#

watch taurine kp

#

like it always does

celest basalt
#

yeah

zealous bridge
#

yeah

celest basalt
#

works on iOS 14

zealous bridge
#

then get a proxy like charles or mitmproxy

lilac wren
#

Proxyman

zealous bridge
#

or that

celest basalt
#

I prefer Fiddler

zealous bridge
#

i keep getting mixed up

celest basalt
#

still annoyed that I updated to 14.4.2 and now both pwndfu and OTA methods are failing to go back lol

zealous bridge
#

ikr

celest basalt
#

the thing that gives me consolation is:

  • I can at least still JB, even if without passcode
  • eventually when a new exploit drops 14.3 will become irrelevant because I plan to update when Taurine gets updated for new versions anyway
zealous bridge
#

if pwndfu did get fixed would you go back then

#

its at like 201

celest basalt
#

I manually compiled Cryptic's branch and it goes through everything and enters restore mode but then SEP panic

celest basalt
#

what happened to testing pwndfu on A10 yesterday?

zealous bridge
#

failed

#

because enterpwnrecovery

celest basalt
#

what was the last error exactly bc there are a few that are solved by retrying but I guess it failed even after multiple retries

zealous bridge
#

^

celest basalt
#

someone could test on A9 too, I only have A11

zealous bridge
#

a9 has to be mac only

celest basalt
#

right because of the sigcheck removal stuff not working on Linux

#

it could if they wanted to bc checkra1n does it

zealous bridge
#

yeah you need eclipsa

#

you need to userspace reboot after this btw

#

nah just capture the response

#

and check what the build id is

#

yeah

#

should be in json format

#

then you did something wrong

#

oh im stupid

lilac wren
#

You have to block gdmf first

zealous bridge
#

gdmf

#

not mesu

lilac wren
#

Mesu is fallback

zealous bridge
#

it should be the only one there

#

so whatever you have

#

exit and enter the softwares update page again and just check the new one that pops up

#

do you have the beta profile

celest basalt
#

same error I get on A11, running futurerestore again before DFU times out fixes it for me

#

either that or create an empty file (e.g. junk.txt) and then irecovery -f junk.txt before starting FR

zealous bridge
#

@sacred estuary was that the request or response

celest basalt
#

although that should only be required for iPhone X according to checkm8-nonce-setter

zealous bridge
#

yep

#

thats not it

#

lol

#

unless its b64

#

Yeah it is b64

#

nope thats final

#

9.9.14.4

celest basalt
zealous bridge
#

Build version is 18D52

#

which is final

#

has anyone actually tested if cicuta works on b1

lilac wren
#

I think that's the full response

celest basalt
#

the only beta blobs I have are for 14.5

thin marsh
#

I have blobs for 14.4.2

zealous bridge
#

do i have b1 blobs

#

hmm

celest basalt
#

test it on Corellium troll

#

if only their custom IPSW upload actually worked...

zealous bridge
#

no lol

#

lmfao

thin marsh
#

Ok

zealous bridge
#

rip

#

lol

#

spoof kernel version

#

ez

thin marsh
#

Blobs for what device

#

Ok

lilac wren
#

I think the reason it's not a delta is because iOS14PublicSeed doesn't have deltas for stable -> "beta" (even final)

thin marsh
#

Whenever I can I always download every blob I can for safe keeping

#

Yep

#

I know

zealous bridge
#

@lilac wren do you think we can MDM and RequestedProductVersion it

lilac wren
#

What are you trying to do

zealous bridge
#

taurine has to reboot

lilac wren
#

We can always request product version even after 90 day

zealous bridge
lilac wren
#

Oh I see

low summit
#

Morning

zealous bridge
#

Oh yeahhhh

lilac wren
#

Idk how that would work because 14.4 beta 1 isn't a normal version number

zealous bridge
#

we can do 14.4 then edit the build id

lilac wren
#

There's no requested product buildid though

celest basalt
#

yeah could test the BCert theory I had because it's only tied to ProductMarketingVersion and not BuildID

zealous bridge
#

Hm it’s worth a try

#

@sacred estuary tether boot would work then

celest basalt
#

sure

zealous bridge
#

ffs

#

but isnt already jailbroken stage 2

#

as long as we can race for the voucher

#

we’ll know it works

#

what about restore rootfs?

#

that still runs the exploit

#

i think

#

Oh

#

Just do that with taurine then

lilac wren
#

Guys didn't we already solve this

zealous bridge
#

oh

lilac wren
#

Download update while jailbroken then mdm install only

zealous bridge
#

Lol

#

i dont think thats what we're tryna do lol

lilac wren
#

Oh ok I'll read again

celest basalt
#

post exploit on Odyssey won't work properly on iOS 14 though

zealous bridge
#

all we need is race for voucher

lilac wren
#

Oh ok

zealous bridge
#

i dont think we even need the converting part

#

ask someone who knows swift lol

#

lemme take a look at it

#

@sacred estuary weeeee

#

so we just edit the version i think

celest basalt
#

why does it say 13.7.1

zealous bridge
#

@sacred estuary

#

go figure

#

all mentions of it

#

the code is nice

#

just change the false to true

#

that should work in theory

celest basalt
#

oh wait it says 13.7.1 because that's the condition for being unsupported

zealous bridge
#

lol

celest basalt
#

could make it 14.0 though because 13.7.1 will never happen

zealous bridge
#

best of luck

lilac wren
#

Although idk if it will actually work that easily

zealous bridge
#

xcode i think

#

i have never used xcode before in my life

#

@lilac wren pls halp

#

lol i really tried this:

"RequestedProductVersion": "14.4",
"RequestedBuildVersion": "1818D5030e",

#

i got 200 OK

#

but

#

18D52

#

oh wait

thin marsh
#

you found it

zealous bridge
#

link beta profile pls @sacred estuary

#

did you try compiling that one thing

thin marsh
#

Umm.......................

zealous bridge
#

you need the whole app i think

#

uh

lilac wren
zealous bridge
#

i have 200 OK

#

so

#

maybe i just need the profile

lilac wren
#

It just ignores that key right

green onyx
#

why are u guys compiling odyssey?

#

ah

#

just change version checks

#

and i think theres a reason why CS didnt allow rejailbreak

zealous bridge
#

^

green onyx
#

i do

#

i also have more

zealous bridge
#

weeeeeeeeeeeeeeeeeeeeeee

green onyx
#

i have every blob

#

im always prepped

#

im A11 too

zealous bridge
#

i am here bruh

green onyx
#

can u get the ipa to compile?

#

if so, sure

#

wait why

lilac wren
#

I only have A12 and A7? I think it's a7

green onyx
#

taurine isnt OSS and does version checks

zealous bridge
#

yeah

#

just spoof

#

version

#

wait

green onyx
zealous bridge
#

yeah

#

then reboot

#

and do taurine

green onyx
#

will that work?

#

i dont need -u lmao

#

i have itunes backups

zealous bridge
#

@sacred estuary how did you get 14.4 beta profile lol

green onyx
#

is there a time frame?

#

bc i have class soon

#

i take ap calc

#

alr

#

ill try it after dinner

zealous bridge
#

14.6 one?

green onyx
#

hopefully u guys arent asleep by 7pm EST

#

but i think tanbeer sleeps at 6pm EST

zealous bridge
#

7am your time is like

#

1am

#

for me

#

idk

#

what is est

green onyx
zealous bridge
#

gmt what

green onyx
#

im in canada lol

zealous bridge
#

so 4pm my time

#

ok

thin marsh
#

I am utc+2

zealous bridge
#

19:00 Sunday, Eastern Time (ET) is
00:00 Monday, British Summer Time (BST)
oh no

green onyx
#

pog, see you tmr

#

sleep well

zealous bridge
#

eh i'll be awake until 4 anyway

#

ramadan vibe

#

focus on getting the ipa to compile for now

#

oh right

green onyx
#

what conclusions are u trying to make from this

#

to see if circuta works on 14.4 beta 1?

zealous bridge
#

yes

#

and i am checking

#

if we can ota to 14.4b1

green onyx
#

alr, i can test beta 2 KEKW

#

lol

#

oh yes

#

it should work

zealous bridge
#

nice ecid

thin marsh
#

Oh fu*k

green onyx
#

no like i have beta 1 and beta 2 blobs

zealous bridge
#

folky really saving this

green onyx
zealous bridge
#

@sacred estuary 14.4 first try lmfao

green onyx
#

A11 gang with blobs

#

best device ever

zealous bridge
#

can confirm

#

tim apple uses a11

green onyx
#

true, i can mess around how hard i want

#

i could delete /var and still be fine

#

I AM INVINCIBLE lol

zealous bridge
#

noooooo

celest basalt
#

unless you only have OTA blobs like me

#

I can't figure out why SEP panics for pwned restores

#

that was because of interrupting checkra1n I think

green onyx
#

oh wait, since tdy is the last day for otas and btickets expire after 3 days, can someone try getting one? and try using it tmr?

celest basalt
#

last one was just failed to send iBSS

green onyx
#

or does it not work like that

celest basalt
#

yeah

zealous bridge
#

wef

#

oeuf

#

just delete PreBoard.app

#

ez

#

ahh i cant get ota to work

#

i cant request a beta build

#

lol what

#

thats so weird

#

with beta profiles

#

even if i spoof 14.5

#

14.4 comes up

#

wen eta downgrade

#

ldrestart didnt work

celest basalt
#

yeah I got the same weird

zealous bridge
#

then

#

need to reboot

#

lol

#

did you reboot

#

nyu

#

just try rebooting

#

it worked 4 me

low summit
#

Is this more research on spoofing ota?

green onyx
#

no, this is testing if 14.4 beta 1 is vuln to circuta

#

lol

low summit
#

Taurine for beta 1 lol?

green onyx
#

well beta 1 was released before 14.3 came out

low summit
#

Who has blobs tho lol?

#

Nyu?

zealous bridge
#

the person you are talking to

green onyx
low summit
#

99 percent it is LMAOOO

green onyx
#

for 14.4 beta 1 and 14.4 beta 2 lol

green onyx
low summit
#

Apple don't patch shit

#

In beta

green onyx
#

hopefully beta 1 and beta 2 work

lilac wren
#

How are you going to make taurine not unsupported for 14.4 beta again

green onyx
#

also, froggy, why u looking at my reddit acc /s

low summit
#

Go to the firmware spoof version

zealous bridge
#

yeah i cannot get the beta to show up

#

hold on

low summit
#

And see if it work lol

zealous bridge
#

what if i sniff regular

low summit
#

So u guys spoofed 14.3 on 14.4beta?

green onyx
#

but that wont work

#

bc tfp0

#

odyssey is probably trying to get tfp0, which doesnt exist on 14

low summit
#

Lol remember the spoofer guy

#

Tho that was a great idea

lilac wren
#

ok

low summit
#

That's what I said lol

zealous bridge
#

@lilac wren OMG

low summit
#

Folklore say it won't work

zealous bridge
#

beta profiles

#

have

green onyx
#

is systemversion.plist in root or var?

zealous bridge
#

RequestedProductVersion

#

lmfao

#

thats jokes

lilac wren
#

wait in a profile??

zealous bridge
#

no in the request

lilac wren
#

nice so how do they request a beta version

#

or they don't

zealous bridge
lilac wren
#

ah

zealous bridge
#

im onto something

green onyx
#

also, to make this work, im getting Ora1n, not checkra1n right?

zealous bridge
#

does it matter

low summit
#

Tell coolstar to make a version uncheck for taurine @green onyx lol?

low summit
#

Imagine

#

Easy

green onyx
#

it does

zealous bridge
#

@lilac wren the difference is

green onyx
#

bc if i jb with taurine

zealous bridge
#

mesu's base URL

green onyx
#

bootstrap mismatch

#

im going to get fucked

lilac wren
#

yeah so we can't request a specific beta still

green onyx
#

i need filza and a package manager to change plist

lilac wren
#

I guess it just determines 14.5 vs 14.6

low summit
#

@zinc moon u have beta one blobs?

green onyx
#

oh i see

#

so i just swipe up on taurine after i get voucher

low summit
#

14.4

zealous bridge
low summit
#

Then how u trying lol

#

They trying to see if taurine works on 14.4 beta 1 @zinc moon

#

Because it's out before 14.3

#

Lol

#

It definitely is supported lol

green onyx
#

pog @zinc moon is mem edition

#

congrats!

low summit
#

Oh yea congratulations

#

Remember when pangu support 8.2 beta one and not 8.1.3 LMAOOO?

#

Tether boot lol

zealous bridge
#

i may have a way

low summit
#

Sloopie got it lol

#

The tether boot

#

Lol GG

#

Lol

#

Lol

#

Succession?

#

Lol

#

It's online lol

#

Let's go

#

Lol

zealous bridge
#

lmfao

#

DABEZT

#

CONGRATS

low summit
#

I'm next lol

#

Or I think

#

A berry u mean

zealous bridge
#

whyyyyy

lilac wren
#

Congrats!!!

low summit
#

No more weird berries?

green onyx
#

*tanberry

low summit
#

Bro folklore load 14.4 beta lol

#

Try it

zealous bridge
#

@lilac wren public seed also gives me 14.6

#

wtf

low summit
#

Do you need a mac for tethered boot?

#

Odyssen1x?

lilac wren
#

Does this mean exploit failed

Stage 1: race for voucher ivace uaf
perform_user_data_element_uaf_race: success on 288 iteration
uafed_voucher: 16931
Stage 2: leak task port address and overlapped index
Bad fake element dump!
perform_user_data_element_uaf_race: success on 437 iteration
uafed_voucher: 40615
Stage 2: leak task port address and overlapped index
Got fake element dump!
Overlapped index: 0
Cannot find next spray entry
#

wait

#

it's still running

#

nvm

green onyx
#

i have class

zealous bridge
#

lol

zealous bridge
lilac wren
#
perform_user_data_element_uaf_race: success on 54 iteration
uafed_voucher: 25967
Stage 2: leak task port address and overlapped index
Got fake element dump!
Overlapped index: 0
Next spray index: 36
task_port: 0xffffffe19d4200a8
Stage 3: Convert uaf into pktopts uaf
zealous bridge
#

and got the tfp

#

yep

#

thats a success

lilac wren
#

ooh ok

#

that was easy

low summit
#

Lght I'm doing tether boot lol

zealous bridge
#

pls share ipa now

#

lol

lilac wren
#

ok lol

#

it's stuck on this stage 3 though

zealous bridge
#

that takes ages

#

lol

low summit
#

Ur already doing taurine?

zealous bridge
#

you still on 14.3?

thin marsh
#

I am

green onyx
low summit
#

Oh u guys modifying taurine?

#

Lmao

lilac wren
#

no 14.3, wanted to test if I could have it work

#

it finished!

#
Respray fake user_data_element
Destroy uafed voucher...
Established custom r/w primitives!
Stage 4 (DEMO): pwn kernel
task PAC: 0xfade4561a18e4000
PAC decrypt: 0xfade4561a18e4000 -> 0xffffffe1a18e4000
proc PAC: 0x5ca939e1a0801d50
PAC decrypt: 0x5ca939e1a0801d50 -> 0xffffffe1a0801d50
ucred PAC: 0xb6eaed61a13926d0
PAC decrypt: 0xb6eaed61a13926d0 -> 0xffffffe1a13926d0
Overwriting kernel credentials :)
getuid() returns 0
whoami: root
Out.
zealous bridge
#

root

green onyx
#

yes

zealous bridge
#

you are root

lilac wren
#

this was in an already jb'en state

low summit
green onyx
#

no

#

wait

#

it works?

zealous bridge
#

yes

low summit
#

Yes

green onyx
#

pog

low summit
#

Of course it works

#

Lol

lilac wren
#

yes rejailbreak would seem to work

#

at least the exploit works

#

not sure if odyssey is meant to rejb however

green onyx
low summit
#

what about u0

#

lol

green onyx
#

no

#

pls no

low summit
#

yes

green onyx
#

its not OS

zealous bridge
#

@lilac wren interesting

low summit
#

why not lol

#

lol

green onyx
#

thats even better

#

we can check if 14.4 beta 1 kernel = 14.3

#

if so, it would work

low summit
#

so taurine can fool it?

#

or u still need to modify?

green onyx
#

thats why chimera works on 12.5.2 without an update

celest basalt
#

AllowSameBuildVersion 🤔

low summit
#

but u0 works too

#

on 12.5.2

green onyx
#

kernel check > version check

low summit
#

u0 works too lmao

green onyx
#

u0 sucks

#

bootloop incoming

#

lol

zealous bridge
low summit
#

lol

green onyx
low summit
#

not true

green onyx
#

at that aspect, yes

low summit
#

14.4 beta 1 is stable?

#

lol

celest basalt
#

u0's check is shit anyway, it only checks kernel version for detecting support, not for exploit selection

green onyx
#

lol

celest basalt
#

no

low summit
#

damn lol

#

tho ur out of 14.4 for good

celest basalt
#

kernel can't be the same bc they blocked JIT in 14.4b1, but idk if they patched cicuta_virosa

low summit
#

8.2 beta had exploits that 8.1.3 doesnt

celest basalt
#

nice

green onyx
#

bcert

low summit
#

whats that

green onyx
#

expires after 3 days

#

saving them tdy

low summit
#

extending ota?

zealous bridge
#

OMGH

green onyx
#

and seeing if we can use them to ota tmr

zealous bridge
#

YES

#

I FOUND IT

green onyx
#

?

#

tanberry clutch

zealous bridge
low summit
#

found the cert?

zealous bridge
#

ITS THAT

green onyx
#

difference between delta and full ota?

zealous bridge
#

CYAMOONN

#

need to re-add the profile

low summit
#

is this a new profile for prolonging ota

lilac wren
zealous bridge
#

well

#

let's see

green onyx
#

pog

zealous bridge
#

its a check

#

a request

#

right when

low summit
#

bruh how

zealous bridge
#

you install the profile

celest basalt
#

Validity: From
Sat Apr 24 2021 16:36:55 GMT+0200 (Central European Summer Time)

To
Tue Apr 27 2021 16:36:55 GMT+0200 (Central European Summer Time)

#

blank
for the BCert

low summit
#

lmk if it works lol

#

not for checkra1n devices?

zealous bridge
#

bruh wheres the request gone

low summit
#

can i save blobs for 14.4 beta on a 7 tho

green onyx
#

KEKW ota blobs

#

lol

low summit
#

ota blobs dont work lmao

#

useless af

green onyx
#

it doesnt work for now

#

it will work for A11-

low summit
#

ota or ipsw

#

wont work until pwndfu yea lmao

green onyx
#

pwndfu is broken rn

zealous bridge
#

nooo its not giving me the request back

low summit
#

its too good to be true

zealous bridge
#

apple stop fucking up

#

lemme try 89#

celest basalt
#

it's not just that I think, mine enters restore mode fine but then panics

low summit
#

how likely is a 14.4 jb tho? wouldnt they wait for ios 15

celest basalt
#

nah

#

13.7 JB happened months before 14.3 too

zealous bridge
#

oh i know how to get it back

#

an error occurred nooo

#

what did i do

#

oh wait

#

is it in the public seed or dev seed

green onyx
#

^

#

that

#

no

#

this would help those who dont have 14.3 blobs but 14.4 beta 1 blobs

#

but that shouldnt happen anyways since 14.3 ota still works

#

true

low summit
#

So it's still pretty useless

green onyx
#

14.4b1? no

low summit
#

Who has blobs tho

green onyx
#

¯_(ツ)_/¯

zealous bridge
#

ugh why is it encrypted

#

@sacred estuary you might as well use cicuta by itself at this point

#

compile that into an app of your own

#

omg

#

yeah that has a .xcodeproj

#

so just git clone

#

ugh i cant figure this out without getting a request from someone who requested .4 dev beta 1

#

one sec

#

lol no idea then

#

oh shit i need a build id

celest basalt
#

!t successionbeta

mystic axleBOT
# celest basalt !t successionbeta
successionbeta

You can get the beta version of Succession for iOS 14 here: https://samgisaninja.github.io/test/

This should only be used as a last resort, since it's no longer maintained. Usually you can restore rootfs and then erase all contents and settings to achieve the same effect.

celest basalt
#

I've linked this before but this seems to be the only documentation on the BAA stuff delayed OTAs use, and it only mentions Activation Lock... I wish there was more documentation on it
https://support.apple.com/guide/security/localpolicy-signing-key-creation-management-sec1f90fbad1/web

zealous bridge
#

i feel like it's hard-coded into SEP

celest basalt
#

but I still don't understand how my device managed to generate a BCert with 14.4 SEP suddenly but it still got rejected

#

I don't see anything in the request about the source version

zealous bridge
#

bruh

#

idk why this doesnt work

celest basalt
#

like I saw the managed TSS request in the log but error 94

zealous bridge
#

the only thing that changes is docID

celest basalt
#

14.3 update showed up after a rejb btw

zealous bridge
#

told you

celest basalt
#

ldrestart isn't always enough I guess

low summit
#

works on beta

#

so is CC patched on beta 1 or nah?

zealous bridge
#

xcode app signer?

celest basalt
#

you can't downgrade below 14.0

low summit
#

because sep isnt signed

celest basalt
#

now my X is again not even generating the BCert for the delayed OTA, I have no idea how it worked that one time but I shouldn't have let the 14.4.2 OTA go through, that broke it...

zealous bridge
#

Well I just made a new OTA blocker

celest basalt
#

wasn't there a new version that doesn't need offsets

zealous bridge
#

With just a .xml file

low summit
#

u cant rn

ornate yacht
#

what are you installing?

zealous bridge
#

You need to compile the external folders too

#

Somehow

#

idk how

green onyx
#

try using modernpwners

#

and see if u can get ssh working

low summit
#

Yes unless you have 14.3 blobs

green onyx
#

ik for a fact that modernpwner's can compile

#

i remember a lot of ppl on twitter screenshotting ssh with modernpwner's cicuta

#

what ios version are u

low summit
#

Any other 14 blobs

#

?

green onyx
#

?

#

L

low summit
#

U only have 13 blobs

#

?

celest basalt
#

AMAuthInstallHttpRequestBaaCertificate
this sounds like it's requesting the BCert from a server 🤔

lilac wren
#

I got you give me like 10 minutes

green onyx
#

whats in patternf's readme

#

@celest basalt do u know how?

celest basalt
#

no idea

zealous bridge
#

@coral falcon well my device just panicked in the middle of an ota update and it put me back in the existing OS

#

sooo

#

idk

lilac wren
#

uh

#

did I just bootloop

zealous bridge
#

yes

low summit
lilac wren
#

hold on time to stare at the apple logo

zealous bridge
#

what did you do

low summit
#

U have blobs?

lilac wren
#

phew im fine

low summit
#

Lol

zealous bridge
#

XR

low summit
#

Scared us

lilac wren
#

It took 2 minutes to reboot

zealous bridge
#

so cant use blobs

lilac wren
#

and i thought it looped

low summit
#

Just realized

lilac wren
#

@sacred estuary do you want an iPA or xcodeproj

zealous bridge
#

ipa probably

low summit
#

2 min is normal lol

lilac wren
#

ok doing some final tests

low summit
#

Yay

green onyx
#

uh

zealous bridge
#

bruh

#

what arr you doing

green onyx
zealous bridge
#

just get the static binary

#

lol

green onyx
#

@wheat lagoon why are u compiling it manually

#

use the gui

#

it can grab a compiled version

celest basalt
#

just use the static build

green onyx
#

^

celest basalt
#

compiling futurerestore is a pain, Cryptic has a script and I have a Docker image but that's for Linux only

lilac wren
#

darn it, this is the one time I would prefer unc0ver to taurine

#

xcode

low summit
#

That's what I said lol

#

Use u0

celest basalt
#

yeah Cryptic's script is for Linux static builds

#

and I made a Dockerfile based on it (haven't published it yet but I can)

low summit
#

@coral falcon what happened with the snapshot

#

U figured it out?

#

What's the conclusion

#

So it restores ur previous snapshot?

zealous bridge
#

yay i have a BCert

#

oh its a 14.4.2 one

#

rip

#

OMG

#

OTA UPDATES ARE BROKEN

#

LMFAI

low summit
#

Didn't take too long to boot

#

BTW

zealous bridge
#

ota has just completely broken on me

lilac wren
lilac wren
low summit
#

Odyssey?

#

Lol

lilac wren
#

no it's just the exploit wrapped in swiftui lol

low summit
#

Lol

#

Nice

celest basalt
#

why does my phone always want me to log in to my Apple ID again after I spoof systemversion

lilac wren
#

it's an ipa

green onyx
#

an ipa to exploit circuta right?

lilac wren
green onyx
#

@lilac wren is this patternf's or modernpwners?

low summit
#

Folklore only one with blobs lol

thin marsh
#

I can

low summit
#

How u tether boot

#

Give me steps

zealous bridge
#

dont do it

celest basalt
#

nice device name

zealous bridge
#

unless you want nosep

low summit
zealous bridge
#

in case you fuck up

lilac wren
#

Lol

#

You're lucky it errored out early

green onyx
#

alr

#

im just going to see if dabezt can get it to work

lilac wren
#

@wheat lagoon No iOS 13 versions are compatible with latest baseband / SEP

#

if you're using FutureRestore you need to go to iOS 14.0 or later

green onyx
#

u cant

#

bruh

lilac wren
#

I think this error means you need more space on your computer—but don't try it going to iOS 13, you'll bootloop

green onyx
#

^

#

just dont

thin marsh
#

The exploit is running

zealous bridge
#

pog

low summit
#

Ip7 can't tether boot?

#

No sep?

zealous bridge
#

it can

low summit
#

I tho we just trying the ipa lol

green onyx
low summit
#

Oh shit

thin marsh
#

Yep

zealous bridge
#

are we sure this guys on b1

green onyx
#

^

thin marsh
#

wait a sec

low summit
#

No idea

green onyx
#

screenshot systemversion.plist

lilac wren
#

just because it's running doesn't mean it works... lol

zealous bridge
#

screenshot about section

green onyx
#

^

#

yes

low summit
green onyx
#

how do we get legitimate proof

zealous bridge
#

screenshare

low summit
#

U can't

lilac wren
low summit
lilac wren
low summit
#

No ssh lol

#

Just exploit

lilac wren
#

Console.app doesn't need ssh

zealous bridge
#

thats all we need

low summit
#

OK cool

zealous bridge
#

the exploit

#

lol

#

nah for android

low summit
#

14.4beta

thin marsh
#

Yes but its running it does not finish in 1 second

low summit
#

U sure ur on 14.4 b1

#

To sign with repro

zealous bridge
#

🤦‍♂️

low summit
#

Lol

lilac wren
#

Lmho

low summit
#

Tanbeer stop trolling

thin marsh
#

Yep so don't ask if it woorks in 1 second

#

Yep i need to update that

low summit
#

?

zealous bridge
#

lol we need someone competent testing

low summit
#

Is this guy legit?