#futurerestore-help
1 messages · Page 158 of 1
does it show a little syncing swirl at the top in the status bar
I've seen it had blobs that didn't work yes
how, the blobs are straight from apple lol
Are you talking about the img4tool bug
It can sometimes pass off invalid blobs as valid
Thats what sent us into that whole onboard frenzy
Yeah
Maybe he’s talking about OTA blobs?
no clue
those would definitely be marked as “invalid” but img4tool wouldnt stop futurerestore
that bug still hasnt been patched yet if you can use ota onboards
so it'd send filesystem and just not boot for OTA?
that's not an img4tool bug, it's FR ignoring the blobs being invalid
well, they're valid, but only for OTAs
that's why it becomes invalid with an IPSW
can you still boot with checkra1n then if it's just bad signatures
the RestoreRamDisk's checksum mismatches
that's the idea with pwndfu to skip the sigcheck on the ramdisk but it's broken rn
generally parts of blob missing
ah I see
so it won't start the restore?
tsschecker has to craft the request to apple correctly
“Device can’t enter to restore mode”
yeah it doesn't even enter restore mode
ok that's fine
@lilac wren i reconnected the ipad and tried again and now its restoring
ok nice
Is it still possible to downgrade to 14.3 if I have blobs? Are 14.5 BaseBand and SEP compatible with it?
yes
yes
and futurerestore saying it's invalid would also count as it being messed up if tsschecker didn't fail imo
On a11 and below (a11 only 14.3, rest can go down to 14.0)
i think you’re talking about an older version of tsschecker
anyways we have img4tool now and a lot of the websites use it to verify blobs now
Perfect, I'm using an iPhone X :) do I need to use 14.5 specifically or will the latest ones work fine?
latest works fine
Awesome, thanks
damn sbingner is here?
it's on test.apt.bingner.com and installs and runs now anyway
what is this comment
@lilac wren and the Model is still iPad4,1 on itunes, despite being a cellular one
I had that issue but then it activated anyway
How?
idk it just did
I don't own a SIM with data, guess I'll have to look to a place where I can find one. Isn't there a way to bypass this?
yes but you'll get banned from this server lol
if it is unlocked, I dont think they would need to activate it
Don't need that, thx xD
I just don't have a SIM that "big"on me right now
Unlocked, by carrier?
yes
I don't recall it (I'm not from the US), but I think it is
I'll try to find one, have to think where
Do I need to put the iPad on DFU or something?
Before doing this?
No
Ty
@celest basalt dumb question: could we potentially mitm to try and pull 14.4.1 through delayed OTA? I mean 14.4.1 vs 14.4.2 is kinda meaningless but still
not with the profile, with MDM maybe
We could try RequestedProductVersion
but the big if is if it’s signed
no...
all encrypted my guy
you could to that request by hooking things but you can't really do the OTA update while jailbroken
but it wouldn't match what's on the phone later on
probably a good bootloop strategy
it's not on Pallas pmv, but I do see it in MDM
so someone may manually be doing MDM signature checking lol
ever heard of keybags? lmfao
I mean I've done an OTA update while jailbroken, 14.3->14.3
no I mean you can tell TSS that the sep is lower sure
it worked fine, just had to restore rootfs after
right
yeah, it doesn't even get to TSS yet
its albert
tanberrt
i put it in the writeup
..
what writeup?
ota writeup
All I’ve heard of was Dhinak’s to be honest
for what?
Compression? Sometimes when installing dpkgs with the control files in a zst it just fails
zstd doesn't belong in dpkg files afaik
you just need to run firmware.sh again
it's just a pseudopackage to provide the current firmware version to stuff
but if you deleted it from cydia it probably also deleted a shitload of packages
no that's essential
it was based off telesphoreo but it took my like 6 months to get it going originally probably? idk
but I've been working on it for years now
I updated so much stuff in the process of getting it ported to 64bit
yes
thank you for your work <3
well electra if you count what I was using to make it
u0 didn't exist yet then
it never used it because I also supported u0
@zealous bridge @zinc moon did you guys ever get the shortcut thing to work on Elu or no?
we can now
i think it worked
i’m on 14.4 now so this shit gonna be hard lol
and what was the issue
of course
@tiny pine i know this is a bit much but can you port img4tool to elu
Lillys-iPad:~ root# apt-get install tsschecker
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following additional packages will be installed:
curl libfragmentzip libgeneral libirecovery3 libnghttp2-14 libssh2 libusb-1.0-0 libzip
The following NEW packages will be installed:
curl libfragmentzip libgeneral libirecovery3 libnghttp2-14 libssh2 libusb-1.0-0 libzip tsschecker
0 upgraded, 9 newly installed, 0 to remove and 1 not upgraded.
Need to get 611 kB of archives.
After this operation, 4874 kB of additional disk space will be used.
Do you want to continue? [Y/n]
or at least show me how to do it
@zealous bridge img4tool should be easy
I'll do it, one sec here
need to find the right upstream git, you got it?
yes
it might just be tihms actually
yep it’s just https://github.com/tihmstar/img4tool
Sorry to bother again, but can I use the SIM card from my phone on it?
https://github.com/tihmstar/img4tool/issues/51 watch out for this tho
do you have a dpkg control file for it already?
I usually just copy debian descriptions and stuff
uh i can get one for you
you should try
one sec
Ok, I'll try. It should display something if detected, right?
i think so, try activating once it's in
Connected to the data from the SIM? Or can I use Wi-Fi?
wifi should work
(and sorry to all here for disrupting your work with my doubts)
Ty, I'll let you know if it worked
never appreciated how hard file management is without a jb goddamn
you can't even change extensions of files
you have to make some shortcut
files app is awful
this one is in .zst as well
Still getting this...
what about on device activation
Still restoring, but the iTunes information still displays this
Air* xD
Yes, w/cellular
Got it
Is it supposed to appear some icon for the data?
yes I thought at the top right/left but maybe im wrong
Is it possible that since it is identified as a Wi-Fi one, the cellular part is not working?
@tiny pine bearing in mind when i tried installing this on elu i required libplist2 for some reason, anyways this is the one with the least dependencies and just edit the architecture it works on all arm64 devices
have to update libgeneral too of cours4e
editing the architecture for the deb and installing the libplist2 dylib to /usr/lib works on elu
huh
libplist is already there
you don't need to do that
oh it links the strangely named version is all
yeah
@lilac wren didn't work, maybe I'll try an store with costumer service to understand what is going on. Thanks for all the patience and sorry for all the trouble
well you dont even need someone to give you the role if you know what i'm referring to 😉
i'm sure you can get lucky twice...
since when did capri sun start using paper straws
lol
@zealous bridge why didn't somebody tag me instead of doing stuff like that? lol
lol we were just testing stuff out at that point, you were pinged once i believe tho lol
Lillys-iPad:~ root# apt-get install img4tool
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following additional packages will be installed:
libgeneral
The following NEW packages will be installed:
img4tool
The following packages will be upgraded:
libgeneral
1 upgraded, 1 newly installed, 0 to remove and 1 not upgraded.
Need to get 60.2 kB of archives.
After this operation, 655 kB of additional disk space will be used.
Do you want to continue? [Y/n]
Get:1 https://test.apt.bingner.com ./ libgeneral 54-1 [11.2 kB]
Get:2 https://test.apt.bingner.com ./ img4tool 197-1 [49.0 kB]
Fetched 60.2 kB in 1s (77.3 kB/s)
(Reading database ... 6276 files and directories currently installed.)
Preparing to unpack .../libgeneral_54-1_iphoneos-arm.deb ...
Unpacking libgeneral (54-1) over (26-1) ...
Selecting previously unselected package img4tool.
Preparing to unpack .../img4tool_197-1_iphoneos-arm.deb ...
Unpacking img4tool (197-1) ...
Setting up libgeneral (54-1) ...
Setting up img4tool (197-1) ...
Lillys-iPad:~ root# img4tool
img4tool version: 0.1218-d49e4e4ab18073d8f2e25cae49459c597b4be704
Compiled with plist: YES
Usage: img4tool [OPTIONS] FILE
Parses img4, im4p, im4m files
also on test.apt.bingner.com now
version is screwed, I'll fix that now
lol
Lol was gonna say
I’ll start working on it again tomorrow since i need someone with a jb to test
but tbh i dont have to change much
/s
6:32PM
@tiny pine do you know why your openssh doesnt include localhost ssh to 2222 by default?
gn
openssh settings ez
gn
Always tag bingner when your Capri sun spills
fuck paper straws
because that opens up your device to literally every app on your phone
I can add an "insecure openssh localhost listener" package or something but I think lots of people have 2222 listener packages already?
what do you mean?
I have a port 22 only localhost listener already
"OpenSSH Localhost Listener"
don't say openssh
that installs the global listener
[[OpenSSH Localhost Listener]]
this will allow you to ssh over USB but not from apps on your phone
yeah
that will install the server but not the global listener
idk what that is
if it's a jailbroken unsandboxed thing it'll be fine
if its not you have to have it open to sandboxed apps
sandboxed apps can only access localhost on ports above 1023
I can add a openssh-insecure-local-listener for port 2222?
@zinc moon probably?
but if you're doing that and having them connect from localhost only should still not install the global port 22 listener
maybe openssh-sandbox-listener
idk
i mean i dont see anything wrong with getting both
True
so unless they will use ssh they shouldn't be installed imo
yeah you could check for the hash
lol when their password is “123” and that doesnt get detected but “alpine” does
lol tanbeer is still awake
would probably need two different hashes for elu and procursus
So you just gonna store it as plain text
huh no, hash comes from apple in the image
actually nvm
procursus still uses DES or whatever for the default password
only changes it to a more secure hash if you change the password
If you want security
Is it possible to update from iOS 13.2 to 14.3 iPhone 11 Pro
You shouldnt be storing it as texr
elu sould be more secure when you change it too, unless my libs are more out of date than I thought
Do you have blobs
or configured differently
alpine hash in /etc/master.passwd:
root:/smx7MYTQIi2M:0:0::0:0:System Administrator:/var/root:/usr/bin/zsh
elu will ignore everything except the first 8 characters
How do you check 😂
A variable thats either hashed or not shown in the shortcut
You’ll know if you have
if you set MySuperSecurePassword it will become MySupers but it will also accept MySuperSecurePassword or MySupers123 or anything else like that when logging in
Oof 😅
@primal quarry your best chance will be to wait for 14.4-14.4.2 to get something then delay OTA to it more than likely
hashes is a sum of a bit of data
the output it always the same length but the input can be different
👌
each input always produces the same output
you cant decode hashes
without bruteforcing
lol
otherwise we could all be chilling on ios 10 now
No just keep saving blobs, it takes one tap
[[TSS Saver]]
hmm might be the wrong hash algo still or something
Hash it when it’s shown to the user in the shortcut
if you know where it needs updating let me know 😉
Keep it as a variable elsewhere
I don't see any reason to use anything else as default
How are you going to log into ssh with just the hash though
i have a theory but its stupid
i’ll test it tomorrow
So there is a way or na
@zinc moon I don't care about those things for default, I care about reliability
🤷♂️
you can always install non-default package managers
I'm the one maintaining cydia right now....
lol
yeah it might be more than it should be considering it's just a side thing that doesn't make me money lol
yeah and a lot of people are grateful for it, for any decent person that should hold as much value as wealth
i said it before idk how devs cope with the stress that they have from whats expected from them
you cant make people happy anyways and they just expect you to finish something as soon as humanly possible
can’t win 🤷
@celest basalt is there a way to use an input as SSH key in shortcuts? Weird that it's some generated one that you can never specify
You can do it for Import Questions but thats only for one i think
Oh what you cant even
You can only choose the type
Thats stupid
yeah with import question you can let users use key auth but not a specific input key
what do they think we’re gonna do hack into someones server with our own private key
wait shortcuts actually has a built-in ssh client?
you didn’t know?
I assumed you were using it to execute an external ssh client
interesting
@zealous bridge did you fix the loop
Futurerestore
Oh nonce works?
I had my nonce set from jb
Then why can't you go back to 14.3
Dont have blobs
Oh lol
you can't now after a restore to 14.4 even if you did have blobs
Yeah nonce is destroyed
yes
tsschecker resolved yet?
@zealous bridge non-checkra1n device? 😦
doh
joe
no
Joe
doh
mama
poor tanbeer don't bully him more than we do to JTV lol
More like jtv bully us
I think it's hilarious that Dhinak went to 14.4 on his main by accident, now Tanbeer... please I better not be next
Wait since when why
true
Well I'm about to be on stock too Idk for how long on my iPad
he was testing OTA GDMF, interected TSS response and instead of blocking the connection he allowed it to go through lol. so it just OTA'd to 14.4
first we need a released 14.4 exploit
hey wanna run this shortcut https://www.icloud.com/shortcuts/ea1ff46494fd4891b956bf37faecd6b5
This is bootlooping 101 shortcut isn't it
well it doesn't teach you lol
just does it
download it though, nothing seems wrong with it right
But my grandma's ip bootloop yesterday for no reason unjailbroken
Hello, I was looking for SEP compatibility but not sure if I can futurerrstore ipad mini 5 from 14.2 to 13.3.1 or 13.x with saved shsh2?
it would work on 13.4+ and only on an iPad
and it has to be wifi only
@weary merlin
Thank so much bro
no problem, I just hope you have a 13.4-13.7 blob saved
@weary merlin when using futurerestore though select no baseband
Yep sir
Hi, may I ask a question regarding futureRestore for an iPad 5 WIFI? (currently on 12.1.1 -> want to get to 12.4.1 blops valid!)
on test.apt.bingner.com just apt-get install img4tool
echo deb https://test.apt.bingner.com/ ./ > /etc/apt/sources.list.d/test.list
no
what you did must have been something else lol
well you also need to run apt-get update
not unless you have an awful lot of sources added lol
or one source that's stupidly slow
yes except for commandline, in cydia it stores the database under ~mobile
yes
rm /etc/apt/sources.list.d/test.list to remove the source later
huh
you can't use that with procursus
huh
no
once we validate it works I'll put the packages on the main repo 😒
I assume he also called it img4tool
so then all you need is apt-get update && apt-get install img4tool
yes
because it will always be added
no reason it should be different for any other main repo
does just passing ios version to it not work?
tsschecker whatever--ios 14.5 etc
oh I see
14.0.1 😐
you didn't get 14.3?
yeah but you could have saved 14.3 when it was out I mean
14.3 is better but I don't think the jailbreak is different
need to gompile checkra1n for iphones then you can use checkra1n between devices 😛
compile
not far off with the arm64 slice, except that slice is missing
iphones
yeah
yes
I think it should be possible, I just haven't had time to play with it
just updated libfragmentzip since it had screwy versions thanks to the git scripts too
yes
and people have run checkm8 that way
so no reason it shouldn't be doable that I know of
Guys
What is the old passwd for passwd mobile
I rebooted and got new term again
For the first one alone worked
When i typed passwd mobile
And then alpine
It said sorry
Wait the old one is sill working
From my last jailbreaking?
Yesterday i changed the password for both
Then i restored re jail broke and tried changing now
Yup
Ok listen
When you restore root fs
Do the passwords also get restored
Or they remain same
Can you guys tell me some repos to add pls
- Is the only one that could hurt
The rest will just give an error
It doesn’t do that in the middle
I don’t think it’s in the middle of the process is what I’m saying
I assume so
Something like that it’s been a while since I FR
Well like a month
That all happens before starting the restore
Checking the SEP?
Yes
Oh you meant just applying it? @sacred estuary
Fetching and checking is before, applying is during
But you’re not at anymore risk of that failing than the restore itself since they’re hand in hand
It’s the same as updating in iTunes
I meant the method not the actual restore itself
If check worked on A12+ I probably never would’ve went to taurine
Hi, somebody here to help with a futureRestore problem for my iPad 5 WiFi?
u cant go to ios 13 btw
No, want to stay on 12.x
even worse
But there's a problem with the blop and Firmware
u cant futurerestore to ios 12
ah, ok. - I'm on 12.1.1 but want to get a bit higher.
nope
So in this case, no chance
yes
That explains everything, thanks
wait whats the chipset
ye no
to 13 would be possible? just in case?
no
saved on shsh.host
u can go to 14.3
if u want
yes from bingner repo
nah
just dimentio
they have tfp0
thanks, but not for now. I have some old software, running on 12.x only. That's why I want to stay. Upgrading, I wanted just to make altstore work. It does not under 12.1.1
ah
It's always a pain, to install unc0ver 5. Need to run Xcode, ... for signing, and certificates....
Anytime I'll do that, I need hours, until I get a working ipa
iPad 5 WiFI
I think the problem is the lack of knowledge about "provisioning, signing, and so on..."
If I woul understand, what I'm doing, it would be easier. But I don't.
Have about 5 Apple ID's now, and it gets more confusing everytime I try to install unc0ver
The certificates only remain 7 days.
Even with resigning with ReProvision may work, but at the end, the App doesn't start at all
So I'll have to re-install it. And therefore it must be signed and buit "well".
really annoying
No, Altstore is not compatible with 12.1.1
That's why I'm trying to update iOS 12
But as Folklore said: no chance.
What's the ReProvison fix?
I used ReProvision so far. And the signing goes well. But even if fresh sigend (6days 23 hours remaining)... and I do a restart, unc0ver won't open. just crash.
That's why I have this trouble every few weeks...
(When I reboot or when I DFU)
reprovision reborn works perfectly after reboots
reborn?
yeah
I just intalled the fix from the sorce mentioned
ah and that worked?
Is "reprovision reborn" an own tweak?
yes
I didn't resart
source for reprovision reborn?
(just in case, the fix doesn't fix....)
@hybrid mango it's on packix
found! Thanks.
To use this, I probably have to uninstall the old ReProvision, right?
yes
Pah - In trouble again.... unc0ver deleted on attempt to sign
try to sign it again
And this Preprovision crashes on revolking certificates
reborn or normal?
so resigning doesn't work?
no
try reinstalling repro
probably, because I installed it with a different certificate
yeah probably
I did already. - But with another ID
you can try revoking all certificates
try if altstore works
No, 12.1.1 is not comapatible with Altstore
Should
but in fact, after serval weeks (and a few resignings) the unc0ver doesn't start
very strange
what device?
iPad 5 wifi
if you want you can just delayed OTA to 14.4.2 and wait for an exploit to come out
in class rn
no, thanks. Stay on 12
busy
they have 14.3 blobs
sudo means super user do
su keeps you logged in as super user
it should
yes but you need to set it up
it doesn't work by default
install sudo and add mobile to sudoers
that's the same thing as su
ssh root@localhost has the same effect as su
it's gonna be a whole other guide to set up sudo
su
dimentio 0x1111111111111111```
or su -c 'dimentio 0x1111111111111111'
ooh, i didn't know that was possible
ok
that's wrong
that will try to run the command 0x1111111111111111 as user dimentio 
that's an illegal option
procursus version
on device? i dont think so
that works
lmao
FutureRestore you to upgrade/downgrade/restore to unsigned iOS versions if you meet certain requirements.
[Tutorial](#futurerestore-help message)
GUI
!t fr
unless downgrading from 14.5+ to 14.4.2- it should be ok, but better to restore rootfs first
gm
gm!
gm
looks like 14.4.2 died
yep
probably the last 2
yes
lol the shell is that script for launching universal on any linux
IntelliJ has a designer built in
I'll do it for you after I eat if you want lol
I'll show you as well
It's done in the "main" method though before it even creates the instance of the MainMenu()
I think the method is called "prepareDark" or something
why
Actually I might have gotten rid of that method in 1.70
Dang woke up to this
Did all the 14.5 betas get unsigned as well?
Then why didn't shsh.host save them :(
Oh weird
what are u guys doing
Yes
Probably not shsh.host
It might just be unsigned
And host hasn't updated it to remove the option for those
ye thats what i think
the betas are unsigned
yeah i have them as well
I mean the betas won't matter unless they do matter
14.4's betas are not useful
since cicuta_virosa was patched in beta 1
ye
yep...
Daily reminder apple is a dumb fuck an not pushing 14.4.1 is kinda stupid because it means 14.4 is available through delay OTA for even longer
yeah it only makes it easier for us
also gives more window in the event 14.4 webkit comes around
FutureRestore you to upgrade/downgrade/restore to unsigned iOS versions if you meet certain requirements.
[Tutorial](#futurerestore-help message)
GUI
lol
no it's there
just run again
if the device is actually in recovery
FRGUI will do it automatically
which
header lvl 3
just make your own website then lol
I would but I always like latest jbable version
some people say "i wish i had stayed on iOS 12" and I never get that
He cant update right
idk
Because sep isn’t compatible
yes it is?
a
idfk how that works
if you want you can go to 14.3 rc right now, and probably at least for the next month
some people say it had an iMessage notification bug
copy tweak list and do it all manually
it is fine
screenshot
no
Not really
ok well i kinda wanna stay on 13.5
but at the sametime i feel like im shooting myself in the foot, in the long run
The futurerestore could fail
lol
then what? @celest basalt
I dunno heard it doesnt always work
@icy laurel what did u use to save blobs
Never done it
email lol
??
i emailed myself the blob

how did u save it in the first place
yes
It does
on A12+
Yes
on A11- it doesn't fetch ap nonce, it just uses 0x1111 + ecid + known 0x1111 nonce
!futurerestore
⚫
⚫
🟢
!t futurerestore
futurerestore allows you to upgrade/downgrade/restore to unsigned iOS versions if you meet certain requirements.
[Tutorial](#futurerestore-help message)
GUI
When*?
For what
well i wanna know if her tweaks still work
or at least the mirror
i need the location faker
Some of them yes

I used Relocate recently on iOS 14.3 on my XR and it worked
ok
Nah it’ll take a month or so probably
any video or help on how i should upodate?
from what repo
im using relocate reborn currently
I just linked it
where?
Do 14.3
14.3RC
14.1 is ass
it doesn't
Jose
ok
use ios.cfw.guide's one
though you can just download 14.3RC ipsw
yes ofc
from https://ipsw.dev
Download developer beta versions of Apple's iOS, iPadOS and tvOS firmware.
@icy laurel what device
so i can just restore to 14.3?
14.3 rc*
Yes they do
no 14.3 is unsigned
ok
It was unsigned long ago
hold the phone bruh
u need the ipsw for fr
yall confusing
.
lol
its the same link
true
The blob is just a token of the signature
ok
The ipsw is the firmware
but how do we get this going?
Open it in notepad
ik what ur talking about
it does use 0x1111111111111 if you havent set it or it can't get it
if the current nonce set is like 0x3223524124, it uses 0x3223524124
if its 0x1212497912, it uses 0x1212497912
ok
Search for generator
yes
finna take like 15 mins
Pretty quick actually
so i'll brb when its done
It’s like 5gbs
you can get the generator from the blob so you can get that while you wait
open the blob in notepad and search for generator
im on the notepad
yeah
Search for generator
it should look like 0x<some characters>
and under that its the 0x(Characters)
We also gotta find out if his blobs support -u right
yes that's it
you can just type it over
Or just send it here
it's just 16 characters
And copy it on the phone
ok this isn't some like sensitive info?
send it here
The generator
yes
ok
the blob is sensitive but the generator isn't
No you arent
ok
inb4 apnonce mismatch
Sure
ok
hello
ok hold up
Oh
im not tryna do something if no one ever done it
Hi tanbeer
a13
even better @zealous bridge lol
ok so should i open that i cloud short cut on my phone i assume?
Yes
LOL tanbeer wellknown
cause im using my PC for disc rn
Yes
Wait
odyssey is on ios 14?
no
or am i using U0?
taurine is 14
Transfer the blob to your phone too
odyssey is called taurine on ios 14
You’ll need it
ok i see
ugh i hate 14.4
Allow them
settings > shortcuts > allow untrusted
What he said
huge oof
shortcut like any app?
@zinc moon what were you and binger talking about when i was going to school in the morning
@icy laurel
just run any of these
*bingner
thats what i did
lol
imma wait until theres another guy who needs fr
@icy laurel did it work
probably some tweak
nothing
normally rebooting was fine
userspace reboot just fucked
at least i proved
now what
This version is outdated
proved what?
update it

how do i update this?
routine hub
if your nonce was set and you bootloop, you can use fr
even if you recovery loop
just add it again?
true, so u werent in a bootloop
wait
i recovery looped quite a few times
damn so u did the impossible
true
select "set nonce"
ok wait
tell us the result first
yep
Ye

