#futurerestore-help

1 messages · Page 144 of 1

celest basalt
#

refreshing (im)patiently

lilac wren
#

Username: Rebel
Password: 123

low summit
#

not secure tf

green onyx
#

im on pc too

stable rapids
lilac wren
#

imaging not having a script

low summit
#

i cant log in

lilac wren
zealous bridge
lilac wren
#

let me make a new acc

low summit
#

maybe chrome is stupid

mild mural
lilac wren
#

edit this I was just lazy

celest basalt
#

true I tend to do that too except a Pushover notification

#

and I just grep for 14.5

#

too lazy atm bc on phone

mild mural
#

Same except discord webhook

shadow meteor
#

software update is still stuck on "preparing update" I will wait longer

green onyx
#

just wait

#

im surprised ppl didnt do this earlier

shadow meteor
#

I haven't been in a jb scene for a while. I just checked reddit yesterday and everyone is saying last day

#

😂

green onyx
#

well it's suppose to be

#

bro, how slow is apple on CVEs

#

there better be a lot

low summit
#

got 14.5 lmao

green onyx
#

u updated to 14.5?

#

bruh

shadow meteor
#

Even I know better not to update to these versions

low summit
#

no

royal flint
#

@celest basalt still signed?

green onyx
celest basalt
#

yes

zealous bridge
#

Signed for me too

royal flint
#

im on windows so cant be bothered to check

low summit
#

its showing 14.5

green onyx
#

ah

low summit
#

but 2 gb

celest basalt
#

probably a delta

zealous bridge
#

Just get tsschecker from procursus

#

You can check from phone

#

ez

celest basalt
green onyx
#

ew

#

tvos

zealous bridge
#

tvOS

green onyx
#

wtf

#

how did u get tvos

#

mine doesnt have tvos after refresh

#

YO

#

SIGUZA

lilac wren
#

LOL

celest basalt
#

I got the link from checkra1n server

zealous bridge
#

CVE-2021-1816: Tielei Wang of Pangu Lab

#

Lol

#

Siguza wtf

green onyx
#

siguza big boi

low summit
#

pangu lab lol

#

nice untethered

royal flint
green onyx
#

YO

lilac wren
#

ooh

green onyx
#

@zealous bridge

#

@celest basalt

lilac wren
#

@zealous bridge

green onyx
#

bro

#

this guy

#

has 2 kernel exploits

zealous bridge
#

Pattern f

#

2nd one aint even a proper vuln ngl

green onyx
#

patternf

#

bro

#

hes a legend

low summit
#

well that was fun lol

green onyx
#

patternf has 2

lilac wren
#

3?

#

or do the first 2 count as 1

celest basalt
#

nice

zealous bridge
#

cve

#

promising?

green onyx
#

hopefully patternf or modernpwner can release

shadow meteor
zealous bridge
#

modern’s doesn’t look to be here

zealous bridge
#

After jan 26

shadow meteor
#

Yes

green onyx
#

pattern f has a third

low summit
zealous bridge
low summit
#

just keep trying

shadow meteor
#

Thanks Tanbeer and Froggy

green onyx
#

thats why

low summit
#

oh lol unable to verify

#

yea thats sep

zealous bridge
shadow meteor
#

Gonna remove mdm profile. Appreciate all your help

zealous bridge
#

They said they’d wait

#

till apple patch

low summit
#

14.5 is actually pissing me off lol

green onyx
low summit
#

lol so jb coming soon?

green onyx
#

modern pwners for 14.4:

#

it was anon

low summit
#

time to ota to 14.4 lol

lilac wren
#

@low summit someone else is downloading 14.3 rn so it's just you

green onyx
low summit
#

lmao

#

fkkk

#

why tf it shows 14.5

pseudo stump
celest basalt
#

yes

#

it's called Hack Different

green onyx
#

this is the big boi

#

if it gets released

celest basalt
#

not hard to find but sure

green onyx
#

probably jb soon

low summit
#

do u have another mdm to try?

lilac wren
#

Intune :P

low summit
#

lets try it lol

#

that one more success

lilac wren
#

I just finished school and I kinda wanna eat a snack

#

maybe later

low summit
#

lol

#

👌

stiff hazel
#

So we got:

  • 2 useful kernel vulns patched
  • 1 potential webkit patched
  • some other WebKit thing that was used in the wild

@green onyx yeah I think honestly 14.4-14.4.2 may happen soon

green onyx
#

if they release

stiff hazel
#

Probably not the modernpwner thing

green onyx
#

this guy

pseudo stump
green onyx
stiff hazel
#

@green onyx could Siguza or that guy maybe release? Cause there’s no reason to hold it if it’s already patched in my thought process, right?

green onyx
#

siguza doesnt know what it is

#

siguza's cve isnt kernel

#

^this is the real gem

stiff hazel
low summit
#

u0 coming soon lmao?

pseudo stump
#

whats that apple neural engine one

#

isnt that one useful for A11+ devices

stiff hazel
#

@green onyx so I was looking through older security notes and I noticed you can also use cicuta_virosa on Apple TV

#

(tvOS 14.3-)

stiff hazel
#

and does shit use it

#

or no

green onyx
#

nah

#

not yet

lilac wren
#

well the only uncheckm8 tv

#

will probably not have 14.3

low summit
#

jtv would know

#

omg ur back

#

14.5 is out

zealous bridge
#

Lol

low summit
#

same build as rc tho lol

zealous bridge
#

Also CVE out

low summit
#

wait ur grounded?

zealous bridge
#

Theres a lot

zealous bridge
#

Is the big one

low summit
#

time for me to catch up in xp lmao

green onyx
stiff hazel
#

your sister did something so you’re being impacted by it... huh

low summit
#

tf is cve again

#

hence his fam issues

#

no wonder ur mom is mad yesterday

#

ik what it is lol

#

they just showed it

#

results are like apple patched alot of shit

stiff hazel
#

I think this likely means the new iPad Pro won’t have any jailbreakability

#

We’ll see

#

Maybe they accidentally started with 14.4.2 on launch models

zealous bridge
#

Yeah

zealous bridge
#

Cause it’s useless

#

no

low summit
#

any ipsw blobs

#

i think

#

i use the 0x111 one

#

didnt try the other one

#

using the shortcut i cant set for the one thats not 0x111

zealous bridge
#

They all have generators

#

One is 0x111111...

low summit
#

does the other one work with fr too?

zealous bridge
#

One is 0xbd34a880be0b53f3

#

yes

low summit
#

oh yea that ^

#

the shortcut has issues with the 0xbd one tho

zealous bridge
#

Does it?

low summit
#

setting nonce yes

#

says failed to verify

#

ap

zealous bridge
#

I thought I fixed that

low summit
#

0x111 works tho

zealous bridge
#

Bd34 should work too

low summit
#

not using ur latest shortcut just the one u gave me

#

that day

#

i believe on my X both work

zealous bridge
#

Oh ok

low summit
#

but my 7 only 0x111 works

#

works fine with X

#

any blob

#

we tried on some guy yesterday and his ssh wont connect

#

that was weird

zealous bridge
#

Yeah

#

u0 or checkra1n

low summit
#

checkra1n

#

i think he has that

zealous bridge
#

I can already auto-detect the jailbreak

low summit
#

he did that already

#

still wont connect

zealous bridge
#

And I already have the warnings

#

lol

low summit
#

respring like 2 times too

#

my ipad is fked up

#

mdm dont work

zealous bridge
#

I want another u0 or checkra1n tester

#

Before release

low summit
#

ill do my ipad

#

lol

#

or do u need a completely new person?

zealous bridge
#

Just need a fresh jb

low summit
#

once i figure out this 14.3 mdm thing on ipad

vivid nova
#

14.5 & 14.6 beta 1 SEP/BB are compatible

zealous bridge
#

everyone knew that

green onyx
#

check pins

vivid nova
#

dunno why this is pinned

#

it's common knowledge

low summit
#

we been pinned tho

covert lily
#

The form does not accept 14.4.2 as an answer for i(Pad)OS version.

celest basalt
#

lol because it's a number field instead of text

#

just put 14.42 or something ig

muted nova
#

is futurerestore a one time thing or can you do it multiple times

lilac wren
#

multiple times

muted nova
#

alr

low summit
#

ok froggy is a real bro

#

ios 14.3 coming

shadow meteor
#

gz

low summit
#

really dont want u0 tho lmao

#

lol preparing takes a whole 20 min

lilac wren
#

ikr

#

takes longer than the download

low summit
#

omg it just moved soon as u said that lol

lilac wren
#

lol

shadow meteor
#

man I wish I didn't use futurerestore to 14.2. I was that use case where I did not save 14.3 but 14.2

low summit
#

imagine this gets signed all the way thru to ios 15

shadow meteor
#

Could have gotten 14.3 but oh well

low summit
#

still better than 14.4 lol

lilac wren
#

14.2 isn't bad

low summit
#

rip dabezt lol gone again

vivid nova
low summit
#

oh

lilac wren
#

and yet "updating" down from 14.5 loops you

vivid nova
#

wdym?

low summit
#

updating down lol

#

new meta

lilac wren
# vivid nova wdym?

@celest basalt is this still present on the final? you said build numbers are the same so I assume so?

low summit
#

jtv invented a brand new term

vivid nova
#

downdate?

low summit
#

14.5rc and stable is most likely the exact same

celest basalt
#

if you try to Shift+Update in iTunes or futurerestore -u down from 14.5, it will most likely recovery loop you

lilac wren
low summit
lilac wren
#

although you'll probably go to jail if they're underage

low summit
#

preparing stuck again lol

celest basalt
low summit
#

i think 14.5 might have patched modernpwner

#

is there any confirmation?

celest basalt
#

nothing about modernpwner in CVE notes but there was pattern-f

low summit
#

honestly if its patched it aint too bad. jb coming soon then

vivid nova
#

imagine an untether being released but it requires no passcode and only works for beta versions

low summit
#

ill take it

#

untethered better than sep ngl

vivid nova
#

bruh.. a buggy OS with zero protection.. pass

#

unless you've got a tester

low summit
#

i remember when untethered broke bluetooth

#

that was like 4.2.1

vivid nova
#

no-one uses bluetooth as much imo.. it's all wifi

shadow meteor
#

Untethered was nice. I remember my ipod touch 4g waay back then

low summit
#

use to never use bluetooth but now airpods lol

shadow meteor
#

I must be in high school at that point lol

lilac wren
#

we should make checkra1n untethered, open up the phone and put in some tiny rpi, when the phone turns on to DFU power is sent to the rpi and it boots checkn1x and just does it immediately

#

well untethered so long as you enter DFU when unjailbroken

#

you know what that's semi untether

low summit
#

yea

#

lol

#

miss pangu 9 untethered

vivid nova
#

i would love webra1n with the ability to connect via ota from another users' pc on a proxy server to inject the code

low summit
#

imagine a semi untether jb but ran thru a website

#

like jbme

shadow meteor
#

imagine going to the apple store to jailbreak demo devices

#

good times

low summit
#

they stop that now lol

#

i did it once with pangu lmao

shadow meteor
#

they blocked via dns i'm assuming

low summit
#

i install that pangu semi untether

vivid nova
#

i'd have a proxy server set up.. you just to webra1n -c ota -p <url:1234>

low summit
#

and u could delete var in the process lol

vivid nova
low summit
#

who did it with jbme

shadow meteor
#

Yeah I know, I've done it on 4.x

low summit
#

i did it on ios 9

vivid nova
#

and 10.3.3

low summit
#

i would put u0 on all demo phone

#

just to troll

green onyx
#

@lilac wren is vmware better than virtual box?

green onyx
#

alr

#

i need a windows vm

lilac wren
#

VMWare is 1000000x better

#

remember my rants lol

green onyx
#

yes

low summit
#

vmware is better yea lol

vivid nova
#

*that moment when peeps think 'I wasn't talking to the TV.. but i'll consider it anyways'

lilac wren
shadow meteor
#

kvm is best but I'm assuming not everyone is a sweaty nerd

#

so vmware 🙂

vivid nova
#

kvm is too much work imo

low summit
#

preparing is so slowwwww lol

celest basalt
vivid nova
zealous bridge
#

rogue SEP

vivid nova
#

rogue mom

green onyx
#

rogue ATV

low summit
#

another success lol

#

ipad on 14.3

green onyx
#

pog

zealous bridge
#

still signed...

green onyx
#

@lilac wren is there any way to transfer clipboard from host to vm?

shadow meteor
#

I think you have to install vmware tools

zealous bridge
#

yeah virtualbox and vmware have options for that

green onyx
#

hm

green onyx
zealous bridge
#

its in the VM settings

green onyx
#

but i dont know where i can enable it

green onyx
lilac wren
#

Helping 2 people at once, both people see 14.5 instead of 14.3..... hope apple didn't make a dumb change

zealous bridge
#

froggy got a lot on his hands

#

lol

green onyx
#

true

#

imma stop bothering him

lilac wren
#

lol

zealous bridge
#

i'll check for you

lilac wren
#

you're fine

#

14.3 says it's signed

zealous bridge
#

yeah it is

lilac wren
#

it also shows 14.3 in pvm

zealous bridge
#

rpv?

lilac wren
#

14.4 doesnt work either

#

only shows 14.5 what's going on lol

zealous bridge
#

hold on

lilac wren
#

@dreamy shard is the user with the issue

royal flint
#

what's the issue

lilac wren
#

We push 14.3, only 14.5 shows up

#

and starts downloading

zealous bridge
#

push 14.3 via MDM?

lilac wren
#

^ note that

zealous bridge
#

or

#

pallas

lilac wren
#

14.3 via MDM yes

zealous bridge
#

oh

lilac wren
#

14.5 starts downloading, so it did receive the MDM's request

zealous bridge
#

i thought you meant requestedproductversion

lilac wren
#

just decides to update to 14.5 instead of 14.3

royal flint
#

fuck

#

I just spilled water on my keyboard

lilac wren
#

Welp

zealous bridge
#

oh god

#

lmao

pale plank
#

How to jailbreak my device?

lilac wren
#

good question

#

aren't we all jailbroken at heart

zealous bridge
#

yeah theoretically we're not in jail

#

so we're jailbroken

#

ez

pale plank
#

I just joined this server just to know how to jailbreak my device lol

zealous bridge
#

can you see the massive channel name that says #jailbreak ?

pale plank
#

I have seen a lot of people having their device jailbroken and it is so good

lilac wren
royal flint
#

ok it appears to be fine

zealous bridge
#

you tried MDM?

low summit
#

taurine time lol

royal flint
#

meant my kb

zealous bridge
#

oh

#

lol

royal flint
#

Pallas is returning the right thing

zealous bridge
#

he's got a lot on his hands rn dabezt... maybe ask him later lol

#

helping like 5 people at once

low summit
#

i got to 14.3

zealous bridge
#

it's MDM

low summit
#

on ipad

#

lol

zealous bridge
#

so needs to be a bit private

#

lol

#

yeah

lilac wren
#

switch for sure

low summit
#

taurine just shit on me lol

#

need to rfs

#

i wish i could help with all this pushing mdm lol

#

seems like mad work

green onyx
#

but idk how it works

#

nor do i do mdm

valid adder
#

What y’all doing

zealous bridge
#

new pfp finally

#

uh just MDMing

#

cause 14.3 still signed

valid adder
#

It is?

zealous bridge
#

yep

lilac wren
#

Is this the same person Cryptic lol

#

Little peep

#

or something

celest basalt
zealous bridge
#

lil peep

valid adder
#

Yes

#

So let’s figure out bcert

celest basalt
#

would be epic if you could use A10 SEP hax to generate it

#

idk if it would let you just change ChipID to 0x8015 though or if it uses a different key for A11

zealous bridge
#

can someone on A11 not check

celest basalt
#

check what

celest basalt
#

not that simple

#

would need to figure out how to use A10 SEP as a signing oracle first

#

you can't just change values inside the actual generated BCert after the fact, that would invalidate it

shrewd wraith
#

Hey guys, I’m stuck on FDR 0xXXXXXXXX waiting for message... and it keeps timing out

zealous bridge
#

what device and ios are you restoring too

shrewd wraith
#

iPhone 11 from 13.5 to 14.3

zealous bridge
#

weird

shrewd wraith
#

It just started going again

#

Took like 10 min

zealous bridge
#

oh ok

celest basalt
#

I had that on my X when restoring to 14.4, just took forever but worked

lilac wren
#

imagine FDR error all you had to do was wait

valid adder
#

It instead it’s

#

Exits

#

Instaexits

shrewd wraith
celest basalt
#

I mean

#

all you have to do is wait

#

a billion years

#

for TSS to be cracked

dreamy shard
#

rats. still just showing 14.5

zealous bridge
#

we can get lucky and manage it in one year troll

unique bolt
#

will be cracked before a billion years pass 😄 just gotta wait for quantum computers 😄

celest basalt
#

apparently A10+ is SHA384-RSA4096

#

not 1024 like theiphonewiki says

hearty willow
celest basalt
#

yes

green onyx
#

@lilac wren how is it going

#

how many ppl are u helping at once rn?

lilac wren
#

3.5

#

I told the .5 to wait while I figure out if it's an issue with everyone or just them

zealous bridge
#

we had any success with MDM?

#

oh

#

i could try rn

#

have to go soon tho

lilac wren
#

ok go ahead

low summit
#

OK I'm back up

zealous bridge
#

got 20 minutes to try

low summit
#

Thanks to froggy

zealous bridge
#

see if internet speed will let me down

shadow meteor
#

I am interested to see if this method works with jamf pro

#

I have access to it as I am an IT admin

zealous bridge
#

it probably does

lilac wren
#

probably

zealous bridge
#

just need to locate the install already downloaded update thing

shadow meteor
#

I'll dig around. but don't want to push profiles to strangers in production

green onyx
#

im pretty sure tanbeer did it

#

@zealous bridge remember the guy with 3 apple corp accs?

zealous bridge
#

but i do remember it being there

green onyx
#

lol

celest basalt
lilac wren
#

we already have a profile for 90 day lol

celest basalt
#

I'm not talking about the profile

#

a blueprint is a set of MDM configurations that can be applied to one or more selected devices

zealous bridge
#

@lilac wren i cant even download it from pallas for some reason

#

it errors instantly

lilac wren
#

oh

#

that's probably the issue then

low summit
#

A10X is pretty good tf

#

No difference on ios 14

zealous bridge
#

@lilac wren fixed it, forgot i still needed the delay profile

celest basalt
#

14.3 was removed from gdmf

zealous bridge
#

nvm

#

i didnt

lilac wren
#

for real

#

so it's over?

zealous bridge
#

it's here for me

#

idk whats going on

lilac wren
#

I get it in pallas

zealous bridge
#

i just cant download it

celest basalt
#

TSS still signed

lilac wren
#

just the file doesn't download

#

access denied

zealous bridge
#

oh

#

thats the issue

#

fuck

low summit
#

Is there a way to make apple id without 2 factor?

celest basalt
#

yes, create it in iTunes

low summit
#

Lol fk I did it in browser

#

Now I can't turn off lol

lilac wren
#

still access denied

#

I think 14.3 is over

zealous bridge
#

yeah

#

they nuked it

#

but

#

how

#

did i get

#

14.2

low summit
#

Omg lol

zealous bridge
#

before

low summit
#

Last update?

#

For me?

celest basalt
#

TSS still accepting it so doesn't that mean we could somehow trick it still

lilac wren
#

you can still get 14.2 to show up and download lol

#

OH YOURE RIGHT

#

Map local

zealous bridge
#

with what file

#

who can download it

lilac wren
#

oh no

#

siguza

zealous bridge
#

that was my inital thought

lilac wren
#

@royal flint

shadow meteor
#

Welp jamf cannot update to 14.3

zealous bridge
#

uh

#

isnt it specific for each device

#

?

lilac wren
zealous bridge
#

or is there just one 14.2 ota

lilac wren
#

14.3 is GONE

zealous bridge
#

OGG

lilac wren
zealous bridge
#

oh no

celest basalt
#

it was there earlier today

lilac wren
#
"SupportedDevices": [
        "iPhone12,1",
        "iPhone11,8"
      ],
zealous bridge
#

lol

lilac wren
#

fine maybe not lol

lilac wren
zealous bridge
#

oh

shadow meteor
celest basalt
#

only Jamf Now

green onyx
#

wait what

#

14.3 is gone?

shadow meteor
#

Supposedly

green onyx
#

OH WAIT

#

IT IS

zealous bridge
#

its gone

#

rip

green onyx
#

FROM GDMF

#

GG

#

OTA is dead

lilac wren
#

ripp

royal flint
#

wat

zealous bridge
#

update the post

shadow meteor
royal flint
#

the fuck y'all blabbing

zealous bridge
#

tf

zealous bridge
#

how

royal flint
#

mdm only is dead, you have to use mitm now

#

wait

#

yea

zealous bridge
#

?

royal flint
#

you have to use the install only method now

#

although you should probably check if it's still signed

zealous bridge
#

the OTA zip's are pulled

lilac wren
#

mitm wont work

zealous bridge
#

yeah

lilac wren
#

apple actually nuked 14.3

zealous bridge
#

access denited

green onyx
#

gg

zealous bridge
#

lol

green onyx
zealous bridge
#

still signed via TSS

lilac wren
#

instead of turning off TSS they just turned off the actually OTA file

zealous bridge
#

how are you getting the ota file @royal flint

green onyx
#

for 14.3

royal flint
#

i just started downloading it

#

the link you sent is for the folder

zealous bridge
#

oh true

#

but

#

the device

#

doesnt install it

#

either

royal flint
#

you used RequestedProductVersion?

celest basalt
#

for iPhone10,6

zealous bridge
#

wait can we still map local then

celest basalt
#

link still up

#

ipsw.me and theiphonewiki has all the OTAs

royal flint
#

can get links that work for iPhone10,4 too

green onyx
green onyx
#

wait

zealous bridge
#

this is broken

green onyx
#

can u download the ota

zealous bridge
#

we can still map local

green onyx
#

and place it in the dir?

zealous bridge
#

with the otas

lilac wren
#

that one is denied

zealous bridge
#

12,1

royal flint
#

board?

zealous bridge
#

n104ap

green onyx
#

bro

#

since schools and corps dont need 14.3

#

apple is free to fuck us

red sleet
#

RIP

green onyx
#

this is what they're doing

#

we got nuked

celest basalt
#

So it’s intentional

#

Damn

green onyx
#

yes

red sleet
#

wouldn't be surprised

#

they know what we're doing 02LUL

celest basalt
#

sounds apple tbh

green onyx
#

gg

#

it was fun while it lasted

celest basalt
#

Wouldn’t even be surprised if some apple employees were here

red sleet
#

they 100% are

green onyx
#

ye

zealous bridge
#

oh i got it

green onyx
#

@split torrent

shadow meteor
#

apple is the fun guy at parties

zealous bridge
#

i got the ZIP

#

yay

royal flint
#

the fuck

#

i dont get that link

red sleet
#

was the case with nintendo so i wouldn't be surprised

#

lol

shadow meteor
#

Samsung gang

zealous bridge
royal flint
red sleet
#

actually @quick stag is an apple employee

#

they definitely are here

royal flint
zealous bridge
#

yes

royal flint
quick stag
#

whatd i do

royal flint
#

not the actual ota link

red sleet
#

ur here to gather intelligence

green onyx
zealous bridge
red sleet
#

and report back to tim apple

celest basalt
#

yes

#

get out of here mr steve jobs

quick stag
#

I mean this server's already being monitored

#

so

celest basalt
#

Big Steve

red sleet
#

yes

royal flint
red sleet
#

by u

lilac wren
green onyx
#

@zealous bridge can u download the ota and save it to the ota dir? and then use that to upgrade?

celest basalt
quick stag
#

who tf is big steve

#

i keep hearing it

celest basalt
#

U

red sleet
#

steve is head monitor

royal flint
#

@lilac wren has anyone confirmed RequestedProductVersion is dead?

quick stag
#

nein

celest basalt
#

yes

royal flint
#

because i can get the links just fine with that.

celest basalt
#

big S

zealous bridge
green onyx
celest basalt
#

Stevie

zealous bridge
#

that doesnt work

royal flint
red sleet
#

okay guys ping me when i should put the announcement saying it's dead salute

quick stag
lilac wren
#

yep don't put it yet

zealous bridge
quick stag
#

this will help you with futurerestore

royal flint
red sleet
#

i don't think many people saw it in the <90 seconds it was up

royal flint
#

@zealous bridge same device?

zealous bridge
#

12,1 n104ap

celest basalt
royal flint
#

cannot reproduce i get the working link i sent

zealous bridge
#

the one that works?

green onyx
zealous bridge
#

idk then

#

wtf is my device doing

celest basalt
#

ok I can’t help in this chat not smart enough

green onyx
#

i can try

royal flint
#

link for what

#

what are you gonna do with a downloaded OTA lol, map local?

green onyx
#

the link that tanbeer has trouble with

royal flint
#

you can't just pick out whatever link you want to use

lilac wren
#

yeah why aren't we doing map local

green onyx
royal flint
lilac wren
#

then why isn't it working for anyone lol

royal flint
#

i have no clue wtf you guys are doing

green onyx
#

same

royal flint
#

can someone give a coherent account of what you are following

zealous bridge
#

bruh my device is still giving the wrong link

green onyx
#

what are u doing with the ota file?

royal flint
green onyx
#

how are u going to load that ondevice?

zealous bridge
royal flint
#

bruh

#

that's docs

zealous bridge
#

oh

#

shite

royal flint
#

dumbass

green onyx
#

lol

zealous bridge
#

bruh

#

the device isnt even downloading it then

stiff hazel
#

So is it dead is it alive what’s the status what

green onyx
royal flint
#

MDM only is dead

#

you now need MITM + MDM

green onyx
#

but what dhinakG and tanbeer and froggy is testing if mitm works

#

is mitm still alive?

royal flint
#

as long as TSS is alive

green onyx
#

ah, so as long as its signed

royal flint
#

@celest basalt @lilac wren TSS still alive?

zealous bridge
#

<Error>
<Code>AccessDenied</Code>
<Message>Access Denied</Message>
<RequestId>EGJTMEQKF2PMGJNR</RequestId>
<HostId>bnQRHCAvHomdfYo7u7kGF+1wLKH30wUwENqAmx80l+cT7pcm1Rm4mBdxSKKTwRPalsZUYrDsLdk=</HostId>
</Error>

#

tss is still signing

#

yes

stiff hazel
#

So if it’s still signing then it’s not completely dead

green onyx
#

apple is going to take action soon tho

lilac wren
#

tester trying rn

green onyx
#

i mean, gdmf doesnt have 14.3

#

not sure mitm works

zealous bridge
#

@royal flint is the device supposed to download from the folder or the zip

low summit
#

It's dead?

royal flint
#

bro

low summit
#

Like dead dead?

royal flint
#

who the fuck is saying gdmf doesnt have 14.3

#

it has it

stiff hazel
#

@red sleet status:

  • MDM is definitely dead
  • MITM may/may not be dead
royal flint
#

i literally checked 2 different devices

low summit
#

Still works lol?

green onyx
royal flint
royal flint
green onyx
#

check now

zealous bridge
royal flint
#

still there

zealous bridge
#

and getting access denied

green onyx
#

strange

green onyx
#

bc i dont have it

royal flint
#

what are you using

#

proxyman?

royal flint
zealous bridge
#

charles

lilac wren
#

GDMF gives me a valid file for XR

green onyx
#

hm

royal flint
#

are you MITMing?

green onyx
#

im wrong then

#

nvm

lilac wren
#

no I just did a GDMF request

green onyx
#

ignore me, im a dumbass

zealous bridge
#

look wtf its doing

royal flint
#

expand the folder

green onyx
#

@lilac wren u should probably update ur post

royal flint
#

the fuck is your phone doing

zealous bridge
#

exactly

#

all i did was rpv

royal flint
#

uhhhh are you using ssl killer

zealous bridge
#

yes

royal flint
#

send pallas request

zealous bridge
#

i have ssl proxying

#
    "TrainName": "AzulC",
    "SessionId": "BED7F580-D37C-4338-A137-8FBF7F87F5DE",
    "ProductType": "iPhone12,1",
    "AssetType": "com.apple.MobileAsset.SoftwareUpdate",
    "ProductVersion": "14.3",
    "DeviceClass": 1,
    "DeviceVariant": "B",
    "SigningFuse": "true",
    "DelayPeriod": 90,
    "ClientData": {
        "AllowXmlFallback": "false",
        "DeviceAccessClient": "softwareupdateservicesd"
    },
    "Nonce": "132CFE93-F625-4573-BA37-C0753920E7FD",
    "Supervised": "true",
    "ProductName": "iPhone OS",
    "NoFallback": "true",
    "BaseUrl": "https:\/\/mesu.apple.com\/assets\/",
    "AssetAudience": "01c1d682-6e8f-4908-b724-5501fe3f5e5c",
    "BuildVersion": "18C65",
    "ClientVersion": 2,
    "InternalBuild": "false",
    "AllowSameBuildVersion": "false",
"RequestedProductVersion": "14.3",
    "BuildID": "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
    "IsUIBuild": "true",
    "HWModelStr": "N104AP",
    "DeviceOSData": {
        "SystemImageID": "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
        "BuildVersion": "18C65",
        "DeviceVariant": "B",
        "ProductType": "iPhone12,1",
        "BuildID": "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
        "HWModelStr": "N104AP",
        "DeviceName": "iPhone",
        "ProductName": "iPhone OS",
        "ProductVersion": "14.3"
    },
    "SystemImageID": "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
    "DelayRequested": "true",
    "DeviceCheck": "Foreground",
    "CertIssuanceDay": "2020-09-29",
    "DeviceName": "iPhone"
}```
lilac wren
#

what if you do product version 0

zealous bridge
#

trying

zealous bridge
#

ffs charles 30 mins my ass

green onyx
#

lol

stiff hazel
royal flint
#

yes their device is smashing together directory for update with file name for docs

lilac wren
#

working for iPad Pro 3 wifi

#

with tester

#

MDM

#

downloading 14.3 rn

stiff hazel
#

MDM is working?

lilac wren
#

MDM yes

green onyx
lilac wren
#

no MITM

green onyx
#

with mdm?

#

also pog

lilac wren
#

yes with MDM

green onyx
#

cryptic typing

shadow meteor
#

Weird how my jamf instance does not show 14.3

royal flint
valid adder
#

You need to inject ssl pin disable into com.apple.Security Security means it will inject into every process

royal flint
lilac wren
#

VMWare refreshed to show 14.5

#

in the past 30 min

green onyx
lilac wren
#

dunno why they didn't remove 14.3...

green onyx
#

its not immediate

#

ah i see

royal flint
stiff hazel
#

So once that happens only mitm will work

royal flint
#

or otherwise they're doing this manually lmfao

valid adder
#

@zealous bridge

green onyx
stiff hazel
#

remember when JTV tried to say 14.1 -> 14.3 was downgrading

zealous bridge
#

hm

lilac wren
#

lol poor jtv

zealous bridge
#

wonder if its something to do with SoftwareUpdateDocumentation too

#

for some reasons its requesting that every time

#

before it only used to be once

zealous bridge
#

yeah no this is still drugs

celest basalt
green onyx
zealous bridge
zealous bridge
#

maybe cause i'm mdmed

green onyx
zealous bridge
#

trying rn

#

are you kidding me

stiff hazel
#

did it die or

zealous bridge
#

im gonna jump out my window

stiff hazel
zealous bridge
#

ok hold on

#

updatebrain wtf are you doing

#

PSA: 14.3 still signed

green onyx
#

tanbeer, u good?

zealous bridge
#

ok so far so good

#

need to know where this goes wrong

#

"__RelativePath":"com_apple_MobileAsset_MobileSoftwareUpdate_UpdateBrain/31092a11930cc4358245113295fb4e8666430563.zip","__BaseURL":"http://updates-http.cdn-apple.com/2020WinterFCS/patches/001-88018/F88B8B75-7EDE-4D7C-9C0C-566448BD9470/"}],"AssetSetId":"09e92bc9-533d-4b04-a87d-18ce0042a28c"}

#

@royal flint can you try an updatebrain request

#

i think thats where it fucks up

lilac wren
#

please backtick that

zealous bridge
#

sorry

low summit
#

ok whats the status

royal flint
low summit
#

is it completely dead?

zealous bridge
#

one sec

royal flint
low summit
#

ah nice

royal flint
#

mdm only will die soon™️ once airwatch refreshes

zealous bridge
#
    "TrainName": "AzulC",
    "RequestedProductVersion": "14.3",
    "SessionId": "E543C1EF-C57C-4AA7-9F9C-3C94EC59C89F",
    "ProductType": "iPhone12,1",
    "AssetType": "com.apple.MobileAsset.MobileSoftwareUpdate.UpdateBrain",
    "ProductVersion": "14.3",
    "DeviceClass": 1,
    "DeviceVariant": "B",
    "SigningFuse": "true",
    "CompatibilityVersion": "20",
    "ClientData": {
        "AllowXmlFallback": "false",
        "DeviceAccessClient": "softwareupdated"
    },
    "Nonce": "68E6D42D-6289-4945-80D2-3778A3EBE928",
    "Supervised": "true",
    "ProductName": "iPhone OS",
    "NoFallback": "true",
    "BaseUrl": "https:\/\/mesu.apple.com\/assets\/",
    "AssetAudience": "01c1d682-6e8f-4908-b724-5501fe3f5e5c",
    "BuildVersion": "18C65",
    "ClientVersion": 2,
    "InternalBuild": "false",
    "BuildID": "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
    "IsUIBuild": "true",
    "HWModelStr": "N104AP",
    "DeviceOSData": {
        "SystemImageID": "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
        "BuildVersion": "18C65",
        "DeviceVariant": "B",
        "ProductType": "iPhone12,1",
        "BuildID": "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
        "HWModelStr": "N104AP",
        "DeviceName": "iPhone",
        "ProductName": "iPhone OS",
        "ProductVersion": "14.3"
    },
    "SystemImageID": "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
    "DelayRequested": "false",
    "CertIssuanceDay": "2020-09-29",
    "DeviceName": "iPhone"
}```
lilac wren
#

tester 2, iPad Pro 4th gen (2020), sending 14.3 gives them 14.5

royal flint
#

huh no TargetBuildVersionArray weird

zealous bridge
#

this is update brain

#

so no rpv

royal flint
#

wait i can force 18C66 with UpdateBrain

#

ok then

zealous bridge
#

delayrequested = false i think is normal with UB

#

oh wait there was an RPV

#

but i didnt put that in

#

automatic

royal flint
#

can confirm that request

zealous bridge
#

gives you the weird url?

royal flint
#
{
            "__BaseURL": "http://updates-http.cdn-apple.com/2020WinterFCS/patches/001-88018/F88B8B75-7EDE-4D7C-9C0C-566448BD9470/",
            "__RelativePath": "com_apple_MobileAsset_MobileSoftwareUpdate_UpdateBrain/31092a11930cc4358245113295fb4e8666430563.zip"
}
zealous bridge
#

thought so

#

i dont think its a device issue lol

royal flint
#

same exact thing you sent

#

just now

zealous bridge
#

but why

royal flint
#

i can check pallas

#

one sec

lilac wren
#

yeah that's what i was going to do

zealous bridge
#

guess i'll be going back to 18C66

lilac wren
#

iPad8,9 btw

royal flint
#

o

lilac wren
#

@royal flint

royal flint
#

ok

zealous bridge
#

@royal flint same thing with 14.4

zealous bridge
#

AND 14.5

royal flint
zealous bridge
#

I JUST PERMA BRICKED UPDATES

lilac wren
royal flint
#

same

stiff hazel
zealous bridge
#

wasnt on purpose

#

but

low summit
#

how bro

zealous bridge
#

my device does not know what updates are now

lilac wren
#

oh i forgot model thing

low summit
#

per brick ota or itunes too?

royal flint
#

just block tss

zealous bridge
#

still same thing

#

im gonna try reverting the spoof

lilac wren
#

how do I get the boardid of this ipad >:(

zealous bridge
lilac wren
#

doesn't seem to have 4th gen pros

zealous bridge
#

system info?

lilac wren
#

ooh yeah

#

no jailbreaking though

#

gestalt shortcut

zealous bridge
#

yeah

#

going back to delta fixes the block

#

@royal flint

royal flint
#

weird

#

man i really wanna get hired at apple to see their infrastructure for this now

#

after seeing all the shit that goes on with pallas and catalogs

zealous bridge
#

lol imagine getting a peak at the source code

royal flint
#

board and model?

lilac wren
#

t8027 is board I think

#

iPad8,9

royal flint
#

uhhh

#

"iPad8,9": {"ProductType": "iPad8,9", "HWModelStr": "J417AP"}

lilac wren
#

oh

#

yeah it

#

's J417AP

celest basalt
lilac wren
#

"HWModelStr": "J417AP",
"HardwarePlatform": "t8027",

royal flint
#

HardwarePlatform is useless

zealous bridge
#

its just chip id

zealous bridge
#

....

lilac wren
#

why is it still different

#

my request has a lot of junk

royal flint
#

that looks what tanbeer got

#

so uh

#

what are you using to test?

lilac wren
#
{
  "TrainName" : "AzulC",
  "ProductType" : "iPad8,9",
  "AssetType" : "com.apple.MobileAsset.SoftwareUpdate",
  "ProductVersion" : "0",
  "DeviceClass" : 1,
  "DeviceVariant" : "A",
  "SigningFuse" : "true",
  "ClientData" : {
    "AllowXmlFallback" : "false",
    "DeviceAccessClient" : "softwareupdateservicesd"
  },
  "Nonce" : "HI",
  "Supervised" : "true",
  "RequestedProductVersion": "14.3",
  "ProductName" : "iPhone OS",
  "NoFallback" : "true",
  "BaseUrl" : "https:\/\/mesu.apple.com\/assets\/",
  "AssetAudience" : "01c1d682-6e8f-4908-b724-5501fe3f5e5c",
  "BuildVersion" : "0",
  "ClientVersion" : 2,
  "InternalBuild" : "false",
  "AllowSameBuildVersion" : "false",
  "BuildID" : "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
  "IsUIBuild" : "true",
  "HWModelStr" : "J417AP",
  "DeviceOSData" : {
    "SystemImageID" : "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
    "BuildVersion" : "0",
    "DeviceVariant" : "A",
    "ProductType" : "iPad8,9",
    "BuildID" : "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
    "HWModelStr" : "J417AP",
    "DeviceName" : "iPhone",
    "ProductName" : "iPhone OS",
    "ProductVersion" : "0"
  },
  "SystemImageID" : "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
  "DelayRequested" : "false",
  "DeviceCheck" : "Foreground",
  "CertIssuanceDay" : "2020-09-29",
  "DeviceName" : "iPhone"
}
#

iPhone OS

#

do i change that to iPad OS

royal flint
#

no

#

hold on

zealous bridge
#

deviceosdata you said was useless right

royal flint
#

yes

zealous bridge
#

oh its outside too

royal flint
#

@lilac wren however you're sending is botched

lilac wren
#

it's just curl

royal flint
#

i copied your request and i get what i got before

#

make sure you saved your request if you're feeding it to curl from a file or something or something

lilac wren
#
curl -H 'Host: gdmf.apple.com' -H 'Content-Type: application/json' -H 'User-Agent: $%7BPRODUCT_NAME%7D/$%28CURRENT_PROJECT_VERSION%29 CFNetwork/1209 Darwin/20.2.0' -H 'Accept: application/json' -H 'Accept-Language: en-us' -H 'Cache-Control: no-cache' --data-binary '{
  "TrainName" : "AzulC",
  "ProductType" : "iPad8,9",
  "AssetType" : "com.apple.MobileAsset.SoftwareUpdate",
  "ProductVersion" : "0",
  "DeviceClass" : 1,
  "DeviceVariant" : "A",
  "SigningFuse" : "true",
  "ClientData" : {
    "AllowXmlFallback" : "false",
    "DeviceAccessClient" : "softwareupdateservicesd"
  },
  "Nonce" : "HI",
  "Supervised" : "true",
  "RequestedProductVersion": "14.3",
  "ProductName" : "iPhone OS",
  "NoFallback" : "true",
  "BaseUrl" : "https:\/\/mesu.apple.com\/assets\/",
  "AssetAudience" : "01c1d682-6e8f-4908-b724-5501fe3f5e5c",
  "BuildVersion" : "0",
  "ClientVersion" : 2,
  "InternalBuild" : "false",
  "AllowSameBuildVersion" : "false",
  "BuildID" : "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
  "IsUIBuild" : "true",
  "HWModelStr" : "J417AP",
  "DeviceOSData" : {
    "SystemImageID" : "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
    "BuildVersion" : "0",
    "DeviceVariant" : "A",
    "ProductType" : "iPad8,9",
    "BuildID" : "238D3D4C-3940-11EB-8D33-A61B81E77CB1",
    "HWModelStr" : "J417AP",
    "DeviceName" : "iPhone",
    "ProductName" : "iPhone OS",
    "ProductVersion" : "0"
  },
  "SystemImageID" : "5AD8BD31-B8BD-4FD6-9C4C-90645CA26AE1",
  "DelayRequested" : "false",
  "DeviceCheck" : "Foreground",
  "CertIssuanceDay" : "2020-09-29",
  "DeviceName" : "iPhone"
}' --compressed 'https://gdmf.apple.com/v2/assets'
#

oh

celest basalt
#

add a -k to bypass cert validation

lilac wren
#

fixed

#

just pasted it in terminal instead

#

weird bc the file was saved

#

wait the link is working though

#

yet MDM doesn't work

royal flint
#

wow OTAs really download fast if you use multiple connections

lilac wren
#

iPad tester 1 in restore mode for 14.3

royal flint
#

oh

#

so what's the conclusion @zealous bridge @lilac wren

lilac wren
#

Not dead