#tvos-jailbreaks

1 messages · Page 8 of 1

vale yoke
#

Let me just break out my 100k collection of vintage arcade machines in my basement and dump them all to use for myself in MAME lol

ionic copper
#

If kodi disabled outside sources, it wouldn't.

ionic copper
stone crescent
#

Owning legal copies is no problem for me 🙂

vale yoke
#

Wtf

#

I wish I had room for all that 😫

#

And money

stone crescent
#

Not all of it. Demopods/arcades are on the other side

ionic copper
#

Ya know.. You'd make a fortune on eBay..

stone crescent
vale yoke
#

Why use emulators if you have the originals in the first place tho. It’s always more fun playing the real thing.

ionic copper
#

Nobody in 2024 is going to whip out the n64, plug in the cables, blow on the cartridge when you can just point and click

stone crescent
vale yoke
ionic copper
#

Unless you have a gameshark

stone crescent
vale yoke
#

but anyway

ionic copper
vale yoke
stone crescent
#

Lol nope

#

Married

#

Teacher

earnest grotto
stone crescent
#

🙂

ionic copper
stone crescent
#

But in the eu teaching is kinda a good paying job

ionic copper
stone crescent
#

Haha lol

vale yoke
#

I work in IT and make 50k a year, I’m barely affording a 1 bedroom apartment to rent rn 😞

stone crescent
#

Don’t think that would be very successful

ionic copper
stone crescent
vale yoke
#

I’m a network admin and server admin and a bunch of other roles at once

#

For about 800 people

#

🤷‍♂️

vale yoke
#

ya

stone crescent
#

In Eu you would be considered high level payment. With what somebody in your position is payed in eu

ionic copper
vale yoke
#

I’ve been considering modifying an AI image generator to generate pics of feet and sell them on OF

#

But it gets the toes wrong 😫

ionic copper
#

Nah, ai images are easy to tell fake

vale yoke
#

most of them can’t tell the difference 🤦‍♂️

ionic copper
#

Chatgpt making on par with Google ngl

#

Kids buying a bot to answer dumb qs

storm ridge
#

I don't have cables so for the 4k is Xcode the only way to install Misaka?

stone crescent
#

Sideloady

ionic copper
#

😉

storm ridge
#

@stone crescent
4k doesn't have USB

stone crescent
ionic copper
stone crescent
#

I just used sideloady on mac

ionic copper
stone crescent
#

But my appltv was connected with xcode before

storm ridge
#

@ionic copper
I'm still on Mojave will Apple Configuator 2.7.1 work?

ionic copper
#

Any Apple Configurator will work

storm ridge
#

@ionic copper
Tutorial somewhere I can follow?

ionic copper
#

I'm still using the original on high Sierra

ionic copper
#

You do have to go to settings, remotes and devices and stay on that screen on tvOS

#

To initiate the 4K to be discoverable

bitter gull
#

damn i just got notified by someone that trollstore working on tvos

ionic copper
vale yoke
#

They would be correct

bitter gull
ionic copper
#

Apple stocks going up for apple tv now

ionic copper
#

What tvOS are you even on?

bitter gull
#

i already have misaka on tvos 16.6. just blocking updates. 4k gen 1

storm ridge
#

@ionic copper
I'm already paired to my MacBook, what next?

ionic copper
vale yoke
#

You need it install “Apple Developer” from the App Store first though to use as the helper

bitter gull
ionic copper
vale yoke
#

Install that ipa under assets

vale yoke
ionic copper
vale yoke
#

Well it has to be an app developed by Apple right because those run with higher privileges? Or does tvOS work differently then iOS?

ionic copper
vale yoke
#

Oh. Interesting.

ionic copper
#

The developer app doesn't have higher privileges

#

We tried to edit the system apps, but because of the new security mitigations, it reverts the snapshot on reboot

#

Only way it would work is with code injection

vale yoke
bitter gull
#

TrollStore success on tvOS 16.6 AppleTV 4K gen 1

#

some notes: I had to restart the AppleTV through system menu after Misaka injected Trollstore helper into Apple Developer app. Apple Developer app would not show Trollstore helper without restarting.

#

Also, I had to use Misaka tvOS from here: https://github.com/straight-tamago/misaka-tvOS/releases

The latest Misaka tvOS release is not on the regular Misaka github: https://github.com/straight-tamago/misaka/releases

GitHub

Contribute to straight-tamago/misaka-tvOS development by creating an account on GitHub.

GitHub

iOS & tvOS customisation tool for KFD & MDC. Contribute to straight-tamago/misaka development by creating an account on GitHub.

vale yoke
ionic copper
#

Needs an exploit to work

#

Hence why misaka @vale yoke

storm ridge
#

So got Misaka and TrollStore installed. Have had 2 update nags by Apple within 1 hour (not seen that before) and I accidentally hit download but pulled the plug. I really can't wait to get this block working now.

I'm reading the instructions to install the block which says "After pairing with the iOS version of misaka, place this file in this path from the file manager". Is that correct? I've got Misaka on my iPhone too but see nowhere to "pair".

vale yoke
#

There should be a button that says Apple TV Connect

#

Then you can switch to the file manager tab. I have found it’s more reliable if you pair with the TV first and then kopen. For some reason, if you kopen open first and then try to connect everything will just freeze up.

#

I think the newest misaka has a built-in OTA block function, though

storm ridge
vale yoke
#

Loaded the file into the Apple TV?

#

Once it’s in the right directory, that’s it. Just reboot.

storm ridge
#

Can I just delete Misaka 5.0b and sideload 5.1 over? The old method is very cryptic

vale yoke
#

Ya

golden marsh
golden marsh
#

The repository has been moved.

vale yoke
#

OMG OUR GOD HAS ARRIVED

storm ridge
#

@vale yoke
ok got 5.1 installed... where can I find the OTA block. It looks identical to the old one

storm ridge
storm ridge
#

and I have 5.1 installed

golden marsh
#

Try uninstalling it once and then reinstalling it.

storm ridge
#

Uninstall what?

golden marsh
#

misaka tv

storm ridge
#

I just did

storm ridge
#

I removed 5.0b and installed 5.1

golden marsh
#

ok open

#

Wait, you're installing it using TrollStore, right?

storm ridge
#

I already have TrollStore installed using 5.0b

golden marsh
#

no

storm ridge
#

and switched to 5.1 Misaka but no OTA block

vale yoke
#

Did you install Misaka with Trollstore? Or sideload it?

storm ridge
#

sideload

vale yoke
#

Install the misaka IPA with TrollStore

golden marsh
#

To use the ota blocker you need to reinstall Misaka using ts

#

I should have added that description to the app

storm ridge
#

vunderbar!

#

Question, I've got 3 other 4k's to do this on. Will sideloadly allow me to use the same appleID or will I have to use another one due to app limits.

vale yoke
#

I was able to sideload 4 apps in one day before on the free account so probably 🤷‍♂️

ionic copper
storm ridge
#

@ionic copper
Got it working with Misaka and tested successfully. Finally, no more nags and today I got 3 within the hour of doing all these installs. Incredible how Apple keeps pushing this on us.

ionic copper
storm ridge
ionic copper
#

Any.. 4th gen and higher

#

Only issues, HD only works with MDC

#

Reason being: kfd hates A8

vale yoke
ionic copper
vale yoke
#

I tried that, but there was no lock button

ionic copper
vale yoke
#

Hmm i’ll try that when I get home. I didn’t want to just go mashing random buttons to find it because with the luck I have, I would accidentally delete a directory and brick that thing lmao

sleek moss
#

I'm on 17.0 can i downgrade

vale yoke
#

Which Apple TV?

sleek moss
#

it says a1625

#

32gb

vale yoke
#

That’s an Apple TV HD

#

You could go to 13.4.8 or 10.2.2 lol

sleek moss
#

ok

vale yoke
sleek moss
#

ok thank you so much

vale yoke
#

Trollstore doesn’t work on either of those, but I believe they have full jailbreaks anyway

sleek moss
#

what can i do with the jailbreaks

#

which jailbreaks

ionic copper
ionic copper
#

Computer required

storm ridge
#

Think I found a bug in Misaka 5.2... won't block OTA but 5.1 does. I am on 16.5

sleek moss
#

but idk what happened last time

ionic copper
sleek moss
ionic copper
vale yoke
#

Oh

sleek moss
#

i can try again

#

steps

ionic copper
vale yoke
#

wait how I get in the beta

sleek moss
#

yeah

ionic copper
storm ridge
sleek moss
#

i mean i have a laptop

#

and another pc

vale yoke
ionic copper
sleek moss
#

@ionic copper yeah the other pc is intel

ionic copper
#

Inb4 usb issues

#

You can still try

sleek moss
#

lets go can i have the steps again

ionic copper
#

Steps: flash Odysseyn1x to a usb

#

Boot Odysseyn1x

#

Run checkra1n. Don't install the bootstrap

sleek moss
#

links please

storm ridge
#

@vale yoke
Just to update... I had to switch to another Apple ID to sideload Misaka on my second 4k. As I thought, I must have used up the 2 free slots on my everyday AppleID by first installing Misaka 5.0b then 5.1. I have a few spare Apple IDs so won't need to wait 7 days to finish up sideloading to all my 4k's

#

I don't think this board has been this busy in years lol.

bitter gull
vale yoke
#

Woo just snagged ANOTHER 4K 3rd gen from marketplace on 16.4.1 lmao

#

idk what Im gonna do with all these…

ionic copper
#

I don't get why you're needing more than 2 apple tv's

#

Unless you plan to hack em, then flip em

vale yoke
#

before tvOS 16 becomes impossible to find

#

All these people are selling them for like $80-$100 as well. I don’t know why people are selling Apple TV for $60 less than retail lol

ionic copper
#

The issue I see is, in 2 years, apps are going to require 17.x

vale yoke
#

Well that’s a problem for another day 🤷‍♂️

#

Hopefully by then a full jb will be out and we can patch out the version check and keep using the old versions of the apps

ionic copper
storm ridge
# ionic copper Doubt it, nitoTV retires at 17

He's done great work, would be sad to lose another developer to the community. The Apple walled garden still has cracks and we can be thankful for any developer who takes their free time to let us noobs get behind that wall but it's getting harder with each new OS.

prisma zodiac
#

I just want to permasign Kodi

ionic copper
prisma zodiac
prisma zodiac
prisma zodiac
#

So do I use Troll Store helper to install on Apple TV?

prisma zodiac
ionic copper
#

Using misaka on iOS

prisma zodiac
#

I’m on 17.0 14plus. Can I get misaka?

prisma zodiac
#

I also have a Mac

prisma zodiac
#

how do i put the MIsaka on there?

bitter gull
#

AppleTV 4k gen 3 tvOS 16.6 TrollStore success. Also used Misaka TVOS 5.2. but the OTA blocker won't work

#

Okay I ended up using the manual method (plist file) for 4K gen 3. Works. Don't know why the OTA blocker within Misaka 5.2 didn't work for me. But it's not needed with the plist method available

prisma zodiac
prisma zodiac
#

lol i need a guide,

somber prawn
#

trollstore on apple tv? how

#

how do you even install stuff on it beside the app store

#

it doesn’t even have safari

prisma zodiac
#

Ok, i got misaka on there. TVOS 14.6 and now running MDC mode, its buffering

#

but it keeps crashing

vale yoke
somber prawn
#

yes but what do I use to sideload?

#

i had mine on tvOS 14 for a really long time, but you can’t plug it in from anywhere

vale yoke
#

Sideloadly on your mac

#

Over Wi-Fi

somber prawn
#

i’ll try that tomorrow

#

whats the last tvOS version trollstore will work on?

vale yoke
#

17.0. But there is currently no installation method for Apple TV 4K gen 2 and 3, so 16.6 right now

ionic copper
vale yoke
#

Do share it

vale yoke
#

I installed this that was posted earlier, which was a newer version than what I had but still no luck. What version are you on?

ionic copper
#

OMG my theory worked!!!

vale yoke
#

OK well now you have to share

#

What theory and what worked lol

ionic copper
#

Hello trollstore on tvOS 17!

vale yoke
#

1st gen 4K?

ionic copper
#

it can be

vale yoke
#

you install with the SSH RAMDISK?

ionic copper
#

i gotta implement this in misaka

vale yoke
#

Nice

ionic copper
#

Hey.. I wonder...

#

hold on.. Imma try something

uneven wraith
#

if you're on 14.0-14.5(?) it's broken due to swiftUI bugs, i'm trying to find the root cause but so far no luck

vale yoke
#

No I’m on 16.5

#

with TS

stoic crown
#

It should be theoretically possible to install TS on an HD with checkm8, right?

#

Also I read above somebody said kfd hates A8? Is that just on Apple TV?

ionic copper
stoic crown
#

Oh nice. I thought MDC only worked up to 16.1.2

vale yoke
#

I thought it was fixed in 16.2?

ionic copper
stoic crown
#

You said MDC would work on tvOS 16 and up so I was confused

ionic copper
analog elk
#

where is the jailbreak guide?

vale yoke
#

For what device? What version are you on? Need to be more specific lol

ionic copper
#

there's no jailbreak

stoic crown
#

@ionic copper Do you have an SSH ramdisk version that works with AppleTV?

stoic crown
#

Can I have it?

ionic copper
stoic crown
#

HD

ionic copper
stoic crown
#

Why couldn't I manually overwrite the persistenceHelper_Embedded in Developer using ramdisk?

lucid falcon
#

Quick question, if I can downgrade to 13.4.8 can I upgrade to whatever version I want? (Apple TV 4/HD)

unreal sand
#

no

lucid falcon
#

thanks

ionic copper
bitter gull
#

is there any advantage in getting apple tv 4k gen 2 on tvos 15 over a gen 3 on tvos 16? I'm guessing no, just wanted to check

bitter gull
trim wagon
#

technically it should be possible to go to 16.6 from 13.4 via beta updates

#

but I'm just trying to do that and the update keeps failing for me

trim wagon
#

yea doesn't work, tried like 5 times

#

it always ends up failing, apple seems to have fucked something up

earnest grotto
#

just to confirm, there's no way to downgrade to 16.6 any more right on an HD?

trim wagon
#

wondering about the same

ionic copper
#

The only thing you cannot do with an HD is downgrade to 10.2.2

earnest grotto
ionic copper
#

Because of SEP

ionic copper
earnest grotto
#

i believe it’s on 17.2 but we’ll see when it gets here monday

#

i was hoping to be able to dump and decrypt an app that requires 14.0 but i guess i won’t be doing that

ionic copper
#

Don't need trollstore to decrypt when checkra1n works

earnest grotto
#

i have several people that can decrypt it for me, i was just hoping to mess around with it myself

#

i’m assuming there aren’t any checkm8 based tvOS 17 jailbreaks out yet?

trim wagon
#

nope

ionic copper
#

To get code signing

#

But still need kernel rw to gain root

trim wagon
#

misaka doesn't seem to work for me on atv4 16.6, anyone any ideas what I'm doing wrong?

#

i press 'kopen' and it doesn't seem to be able to exploit

crisp crater
#

keep trying, it might take a few attempts

trim wagon
#

do I just let it run

#

or close the app and retry?

trim wagon
#

yea

bitter gull
# trim wagon yea

I've had to restart the Apple TV through system settings everytime Misaka failed. It eventually worked after several restarts (Apple TV 4K gen 1 and gen 3)

trim wagon
#

i don't think it's working with ATV4

bitter gull
ionic copper
#

so for those wondering, tvos 14 - 17.0 (including 17.0 betas) are all compatible with trollstore

#

this is confirmed on the HD and /should/ also be for the other 4k devices as well

#

sad part: you can't selectively downgrade with the 4k second or third gens. You CAN however, build an ipsw for the 1st gen, but to downgrade requires a modified version of checkm8 etc etc

#

IF you do find a device on 15, 16, 17.0, theoretically you CAN trollstore

vale yoke
#

But there’s currently no way to install Trollstore on 17.0 on 4K 2nd and 3rd gen yet, because KFD doesn’t work. right?

ionic copper
vale yoke
#

So same situation we are in with the iPhones on 17.0. Dang

sharp monolith
#

shoud've been obvious

stoic crown
#

@trim wagon I’m having the same issue with the Apple TV HD not working.

ionic copper
#

saving such would be ESSENTIAL to get trollstore working as of now

stoic crown
#

I have some blobs, yes. I’m on 16.6 currently.

ionic copper
#

what blobs?

#

if you have anything from 14 - 17.0, then you'd get trollstore no problem

stoic crown
#

What would be the process?

#

I’ve got 14.0.1, 16.1, 16.3.1, and 16.3.2. Didn’t you say it’s possible to retrieve current blobs off device as well?

ionic copper
#

i can give you the script i have that'll download the apple tv firmware, patch them and will grant you ssh access

#

from there, you can dump the raw image then convert it to a blob

stoic crown
#

What's the method of installing trollstore if I have blobs?

ionic copper
#

you will need to set the nonce, which a mac is highly recommended

#

I use Ramiel

#

if you don't have a mac, you may downgrade to 13.4.8 using windows (it's signed) or use linux idevicerestore

#

and checkra1n with installed linux or use a live-boot method

stoic crown
#

Ok so here's what I'm thinking... save 16.6 blobs off device. Downgrade to 16.1, install trollstrore with mdc, upgrade back up to 16.6?

ionic copper
stoic crown
#

I've got a mac

ionic copper
#

even better.

stoic crown
#

Can you send me that blob script you mentioned? Also, where can I find ramiel?

ionic copper
#

easy to find

#

you will need to fix up ramiel to set the nonce which is easy to do.

#

took me like 5 mins

#

requires zero compiling

stoic crown
#

To make it compatible with appletv, yes? (Since it looks like it's just working for iOS/iPadOS

stoic crown
#

Yes

ionic copper
#

it works with apple tv out of the box

#

it just has an issue with setting the generator

stoic crown
#

Ok, what are you saying I will need to "fix up ramiel"

#

oh ok

ionic copper
#

it worked fine before, then apple updated 😛

stoic crown
#

Wouldn't I just be able to use SSH access to manually patch the Developer app with the PersistenceHelper_Embedded?

ionic copper
stoic crown
ionic copper
vale yoke
#

Oh

#

So how does misaka install it then

#

I thought it was just replacing the file lol

trim wagon
ionic copper
gritty hamlet
#

cause meowbrek2 works fine on A8(X) devices, and it makes sense that this issue wouldn’t be accounted for (since iOS 16 only supports A9(X) and later devices)

brazen surge
#

installed trollstore on appletv how can i block ota updates?

green basalt
#

Also if anyone is having trouble installing Kodi via Trollstore I got it working, it was a little involved.

brazen surge
green basalt
# brazen surge can you share the kodi ipa i need it too

I'll need to figure out how to share that, its a little tricky because if you jsut build an ipa from the deb it doesnt work. There is a workaround but you have to remove a folder inside the ipa and repackage it to get it to work for versions above 18.9. Since tvOS didnt get releases before 19.0 there are no working files available that I know of. It sounds like it's an issue involving the switch to python 3.

#

For myself I hosted it on my personal dropbox and then pointed trollstore to that, I need to look into how secure that is to share that link around, but if it seems legit I can pass it along

brazen surge
#

ok thanks

#

Is there an app like Filezilla for Apple TV to access the file system?

green basalt
#

spartan

#

going the manual route?

#

I'm working on doing that right now

#

supposedly you can do it using the misaka IOS app paired with the tvOS version, but that's not working for me

#

as a tip, if you host ipa's in a drop box in order to get the ipa to work for me with trollstore i had to copy the share link and then change the 0 at the end after "dl=" to a 1, that has been working consistantly for me.

stoic crown
green basalt
brazen surge
green basalt
green basalt
green basalt
# brazen surge no what must i do?

make an IPA from a deb following the instructions from the kodi wiki i posted. but before you creat the zip from the folder named Payload in step 7, follow the steps in the top comment on the reddit post i linked above. Basically you need to show the contents of the app, go in and remove a folder. then finish following the steps in the kodi wiki.

#

It worked for me using the 20.3 release

green basalt
brazen surge
#

do you try it with misika does it work for you?

green basalt
green basalt
#

then the option will appear in the settings menu in misaka

#

I turned it on, and restarted as instructed. My aTV now shows up to date when i go into the settings app.

brazen surge
green basalt
#

ahhh yes i get what you were saying now, I misread your earlier response. That's all i had to do, and it worked fine for me, make sure you are pointing to the misaka for tvos ipa not the ios version.

brazen surge
#

What I need is YouTube ad blocker for appletv 👀

green basalt
#

Couldn’t agree more. I hear yattee works but it’s a little ugly and you can’t sign in. That said I’m gonna try it anyways since the frequency and length of the ads on YouTube has gotten ridiculous.

stone crescent
#

Any working kodi ipa with trollstore ?

green basalt
#

@stone crescent Yes but you’ll need to build it, take a look at my post above in response to ravika

stiff stone
pine kiln
#

is there any way to get 16-16.6? im jb on 13.4.8 hd 4th gen

vale yoke
#

Do you have blobs

pine kiln
#

for 16? no but i can make 13.4.8 rightt

vale yoke
#

without 16.6 blobs you can’t get to 16.6

pine kiln
#

pardon if im stupid, but you cant share blobs correct?

vale yoke
#

No, you cannot unfortunately

#

they are specific to each device

stiff stone
#

I'm on 16.6 latest model

vale yoke
green basalt
#

Maybe I’ll reach out to the owner of the iOS one and see if they can setup a subsection for tvOS

ionic copper
ionic copper
earnest grotto
#

Ok I found an HD on 16.4 that I can get for cheap, any reason I shouldn't get it instead of one on 16.6?

#

Also, if we erase it via settings will it update?

vale yoke
#

There’s a button for erase or erase and update

#

As long as you don’t hit erase and update, no it won’t

earnest grotto
#

perfect

#

I'll get this one then

vale yoke
#

Here it is on mine lol

earnest grotto
#

perfect, I couldn't remember if that was the case or not

#

thanks!

vale yoke
#

The fact that Apple still has the option to reset without doing a firmware update is quite surprising tbh

green basalt
# ionic copper And yet why they haven't been taken down for dmca is beyond me

Ya that was one of the things I was gonna look into, not sure how that works with all of the different licenses that things are released with. But even if there was a central place that linked to original files that wouldn’t suck. In the past with proper package managers this was mostly not an issue since most things were organized into a few good repo’s, but with trollstore it’s just less organized.

green basalt
earnest grotto
#

then I can downgrade to 16.4 in the future if I ever update

#

also Palera1n

#

it's been forever since I've been in the jailbreak scene, if it's not obvious

oak island
#

I can’t seem to get Misaka to install TrollStore. I’m jailbroken with Checkra1n on tvOS 14.6. When I open Misaka it will almost immediately crash. If I run ldrestart I can get to the point where I can actually click the mdc mode button which fails to grab free pages goal through the krkw helper. It seems like this whole misaka landa exploit process should be totally unnecessary considering I already have root access. Is there a way to install TrollStore without Misaka?

green basalt
#

Best as I know misaka support doesn’t extend below 15.0, so I’m not surprised that isn’t working. But TrollStore for tvOS says it’s good down to 14.0, though it isn’t clear how you install it as the linked guide is for iOS.

#

Have you tried just sideloading troll store? Since you’re jailbroken already I could see it possibly working, though admittedly I could be way off on that.

mortal tusk
# vale yoke

How did you do it? Is there a step-by-step tutorial?

stoic crown
#

@oak island ^

oak island
#

@stoic crown I’ve thought of that. However the Tips app is installable through AppStore (if it isn’t already installed) whereas the Developer app on tvOS is not. If I replace the developer app binary with the persistence_helper, Im not sure how I would then be able to launch the developer app as it wouldn’t be present on Home Screen (Pineboard)

earnest grotto
#

what would tips vs developer gain you?

#

i'm trying to understand how trollstore/misaka work

oak island
#

@earnest grotto Tips app isn’t available on Apple TV therefore the percentage_helper needs another system app (Developer) in order to exploit the core trust bug which tricks the device into thinking your sideloaded app is a system app as opposed to a user app and persist on your home screen through uicache, reboots, etc…

earnest grotto
#

gotcha, didn't realize Tips wasn't on Apple TV

oak island
#

@green basalt I’m guessing sideloading a TrollStore .ipa would work however I don’t think one exists for tvOS. I can’t find a .deb file either which would be easily installable through nitoTV (Apple TV package manager)

ionic copper
earnest grotto
#

ah

#

you've made the modifications already though, right?

#

would you mind sharing that?

stoic crown
oak island
#

@stoic crown Your right! I was confusing Developer with the diagnostics app. My bad. I’ll try this. I was also thinking about the ssh ramdisk method for checkm8 devices

marsh rune
#

and if so, for what os?

earnest grotto
#

i thought it was, but i think I was mistaken

marsh rune
#

oh okay lmao

#

hey, i have some blobs for 16.4.1, but i think i didn't specify the apnonce nor generator, is there something i can do with them? im assming this because i keep getting the "Device ApNonce doesn't match APTicket nonce" on futurerestore

#

is there somethinmg i can do

green basalt
#

I remember when it was announced that the only susceptible devices that were continuing to receive OS updates were iPads and Apple tv’s there was an announcement from the team that they were going to continue iPad support for now, and that they intended to bring palera1n to the HD and 4k 1st gen, but I haven’t seen or heard anything else about that since.

trim wagon
#

it's only for A11+ or so

#

so what u do when using futurerestore is just entering the apnonce that u can find in the shs2 blob

marsh rune
#

I haven’t seen any field to enter the apnonce on futurerestoregui

unreal sand
#

not apnonce, but nonce generator value

#

if you don't remember it, you'll need to do a pwned restore and enable the set nonce button (but don't type anything in)

marsh rune
uneven wraith
marsh rune
#

yeah ik i was confused because cobre said so

uneven wraith
#

Currently it fails while trying to load stuff before PineBoard loads - I would have logs by now but I bought the wrong debug cable

half socket
#

Anyone got a certified certificate

marsh rune
#

what am i doing wrong? i just keep getting an "assure failed" error when i try to downgrade my apple tv 4 to 16.4.1 with futurerestore
https://justpaste.it/fea63

ionic copper
marsh rune
#

yes, it is on an hd, but im doing a pwned restore because the nonce generators dont match between the atv and the blob

#

the ecids match tho

marsh rune
#

yep

ionic copper
#

You can use Ramiel to set the nonce

#

Just need to edit Ramiel

marsh rune
#

Just that?

ionic copper
#

Yes

marsh rune
#

Ok ill give it a try, thanks!

marsh rune
ionic copper
marsh rune
#

yes i already did it

#

let me do it again

ionic copper
marsh rune
#

i changed the nonce generator on ramiel

ionic copper
#

I'm talking the app itself

marsh rune
#

Sorry but i dont understand

#

How do i edit the app?

ionic copper
marsh rune
#

on the app store?

#

okay i have the app what do i do now?

ionic copper
marsh rune
#

okay

ionic copper
#

navigate to Contents/MacOS/Ramiel

#

open the Ramiel file inside hex fiend

#

inside hex field, press command F

#

it'll bring up the find strings

#

look for com.apple.System and click "next" until you find setenv com.apple.System-boot.nonce

#

change it from com.apple.System-boot.nonce to com.apple.System.boot-nonce

#

click save, then ramiel should work

marsh rune
#

alright

#

im going to try it

#

it doesnt want to open now lol

ionic copper
marsh rune
#

14.1

ionic copper
#

what happens when you try to open it

marsh rune
marsh rune
#

it opens and suddenly closes

ionic copper
marsh rune
#

i just edited the string on the right

ionic copper
#

but did you delete the whole thing?

#

then copy/paste?

marsh rune
#

yep

#

do i have to change the setenv part too?

ionic copper
marsh rune
#

nono

#

i mean

ionic copper
#

it's literally one dot change

marsh rune
#

i wrote the thing

#

i didnt copy/paste

ionic copper
#

hold on, I'll see about something

marsh rune
marsh rune
ionic copper
#

maybe that's why.. System Integrity Protection: enabled

marsh rune
#

lol maybe

ionic copper
#

you can disable it

marsh rune
#

yes i am doing that rn

#

okay it seems to work now

ionic copper
marsh rune
#

yes

#

what do i do now with this?

ionic copper
#

well, if it works, you can use it

marsh rune
#

just to change the nonce right?

ionic copper
#

yes

marsh rune
#

because i tried to load an ipsw file and it just crashed

#

dont know for what it is meant lol

ionic copper
#

ramiel does it for you

marsh rune
ionic copper
#

it's never worked for me

#

i just /path/to/futurerestore -t /ticket.shsh2 --latest-sep --latest-baseband /path/to/ipsw.ipsw --no-baseband

#

works every time

#

nothing special

marsh rune
#

okay it works now

#

thank you so much dude

ionic copper
#

np

marsh rune
#

ive been trying everything for three days now lol

ionic copper
#

i should recompile ramiel to update

#

that way you don't need to disable sip

marsh rune
#

yeah that would be awesome

ionic copper
#

because granted this bandaid works, it's not viable for everyone

ionic copper
marsh rune
#

yes

#

it worked with the gui too which is amazing lol

#

im just trying to exploit the atv with misaka

ionic copper
#

problem with the gui I find is too many toggles to play with

ionic copper
marsh rune
#

16.4.1

ionic copper
#

go to 16.0

#

if you can

#

then use MDC

marsh rune
#

i cant

ionic copper
#

cause kfd won't work

marsh rune
#

i dont have blobs for that version

marsh rune
ionic copper
#

what versions do you have bobs for?

ionic copper
marsh rune
ionic copper
#

oof.. until misaka updates kfd or if kfd improves..

marsh rune
#

maybe i can use other blob from a different atv?

ionic copper
#

blobs are device-specific

marsh rune
#

so i cant use it at all?

ionic copper
ionic copper
#

maybe you'll get lucky?

marsh rune
#

ill let it run for a while and see

#

and what do the parameters in settings mean?

ionic copper
marsh rune
#

like landa, sem_open and all the numbers

ionic copper
#

the numbers are how many pages

#

the others are kernel read/write primitive options

#

landa/sock puppet etc are the exploits used

marsh rune
ionic copper
#

your odds are best winning the lottery

#

by that time, we'd still be exploiting a8

#

but at least you have the capability of downgrading which is a plus

marsh rune
#

Well fuck me then

#

I did it for nothing lol

ionic copper
marsh rune
#

Do you think there will be a fix to this?

ionic copper
#

there's always room for improvement

ionic copper
marsh rune
#

Oh okay then

#

Wait

#

Does this happen too with older misaka versions?

ionic copper
#

best thing that works for a8 is mdc

#

but it works up to 16.1.2 afaik

#

it IS possible to tether boot

#

then simply trollstore, then update to 17.0

#

or 16.4.1

marsh rune
#

but i don't have the blobs for it

ionic copper
marsh rune
#

what's that?

ionic copper
#

boot tethered

#

needing a computer to boot

marsh rune
#

oh i see

#

and how can i try to do it?

ionic copper
#

well I'd need to fix the script to do so

marsh rune
#

theres no quick fix for it?

stoic crown
# marsh rune Do you think there will be a fix to this?

@gritty hamlet said earlier that a8 devices can be supported with kfd because meowbrek2 works on a8 devices. I feel like Misaka could be updated to properly support kfd on HD Apple TVs between 16.1.2-16.6 but I don’t know enough about it to say that with confidence. I’m still holding out hope.

stoic crown
#

Oh, except meowbrek2 doesn’t support 16.x…. So maybe that’s wrong info? Idk.

gritty hamlet
stoic crown
#

Ah. But is meowbrek using kfd or mdc?

gritty hamlet
#

kfd?

#

mdc can’t achieve kernel r/w and was also patched in 15.7.2 anyways

storm ridge
#

Darn developers... what's the incentive to up the minimum OS requirement on apps so quickly? Tubi is a free streaming app and now requires 17.0. What's so special about that app that it requires the latest update?

vale yoke
#

Does tvOS let you install the last compatible version like iOS does? I haven’t tried lol

earnest grotto
#

it should, though you may have to get it from the Purchased tab

vale yoke
#

Hmm. What if I haven’t downloaded it before?

earnest grotto
#

maybe try downloading it on an iPhone, i think that should sync your purchases

vale yoke
#

Oh good idea i’ll try that. I just heard about Tubi recently and was thinking of trying it, but I didn’t realize it required 17 already 😫

earnest grotto
ionic copper
earnest grotto
#

that would be brilliant

ionic copper
#

although the ramdisk doesn't do much good other than block ota when 17 tends to restore root fs upon reboot

#

i think 16 does that too?

earnest grotto
#

All I'm wanting to do is dump blobs for 16.4

ionic copper
earnest grotto
#

I don't have my hands on the tv yet, but i'm trying to gather all the tools I need so that in a few days when I get it I'll be good to go

#

I plan to install TS though

ionic copper
#

is it an HD?

earnest grotto
#

HD on 16.4 yes

ionic copper
#

yeah, you're not getting trollstore on it

earnest grotto
#

it would be amazing if the github would actually say that

#

so what can I do with it?

ionic copper
#

i do understand what the github states

#

but kfd doesn't work with 16.4 on a8

#

which is what the HD has

earnest grotto
#

alright

#

so what are my options, am I out of luck for everything?

#

My end goal was to be able to dump and decrypt IPAs, but that may not be possible ig

ionic copper
#

afaik, you could just wait until misaka gets updated

#

we're working on it

#

so far, the best bet is to downgrade, but I doubt that device has blobs

earnest grotto
#

it doesn't

#

so in the meantime, can I use your modified script to dump the 16.4 blobs?

#

or no

ionic copper
earnest grotto
#

what do you mean by back and forth?

ionic copper
#

from 16 to 17 back to 16

earnest grotto
#

ah, you can’t use them to go from 13 to 16?

ionic copper
#

you can, seeing as 13 is signed forever

earnest grotto
#

that’s fine then

ionic copper
#

hold on.. i have an idea

earnest grotto
#

i’ll just dump them as soon as i get my hands on the tv and your script, and then once I confirm that those blobs are valid I’ll probably go down to 13 for a bit until Misaka/Trollstore are updated

#

anyway ping me when you have a chance to upload the script for dumping blobs, thanks for the clarification!

oak island
#

@stoic crown No, the Developer App just immediately crashes when I open it. Thought about trying to compile TrollHelper from straight-tomago’s repo, adding the persistence helper and packaging it as a Deb file which I can install by airdropping it to NitoTV

ionic copper
golden geyser
golden geyser
storm ridge
ionic copper
#

requires macOS 13.0.0 or higher

golden geyser
earnest grotto
#

it's amazing how much conflicting information there is

ionic copper
#

15 - 17

golden geyser
ionic copper
#

you just can't install it the official way

#

@gritty hamlet trollstore can be installed via checkra1n and/or sshrd

#

works for all CT-compatible versions

#

(a8)

earnest grotto
#

is there a guide out there on how to do that, or would we be on our own?

ionic copper
#

a10 is possible if goldeneye/dcsd was conducted

ionic copper
#

I'll quickly post it

#

How to install TrollStore on any Apple TV HD:

This covers firmwares of tvOS 14.0 beta 2 - 14.8.1, 15.7.2 - 15.8.1 and 16.2 - 17.0. Reason why for these specific firmwares is because KFD may or may not work at the moment. If you're on tvOS 15.0 - 15.7.1 or 16.0 - 16.1.2, you may use MDC to install. For the others, there are 2 methods of installing..

Method 1: if you have blobs saved on tvOS 14 - 17.0 then you may downgrade to 13.4.8 (this firmware is signed forever). From there, you can SSH in via checkra1n and overwrite the apps binary with PersistenceHelper from this link https://github.com/straight-tamago/TrollStore-tvOS/releases/download/2.0.11.v3/PersistenceHelper_Embedded on any sideloaded/AppStore app.

(For ex) the Developer app, use the command find / -name Developer.app to find the location of the app, from there I then used scp -P 44 /location/of/PersistenceHelper root@Apple_TV_IP_Address:/location/of/Developer.app/Developer If this is too complicated, you can also use winSCP, Cyberduck and log in as well with the settings of: Protocol:SCP Port:44 Server:Apple TV IP Address Login:root Password:alpine and find the app, then overwrite.

After that, you may use futurerestore -u -t /location/of/blob.shsh2 --latest-sep --latest-baseband /location/of/ipsw.ipsw --no-baseband with any of the blobs between 14 - 17 to selectively update to. After that, click "uninstall TrollStore" inside the sideloaded/AppStore app you chose, then reinstall TrollStore. It should then work.

If you get "Apnonce no match" or anything of that sort in futurerestore, you'll need to set your generator. You can do so after using checkra1n with the following commands: nvram com.apple.System.boot-nonce=GENERATOR The "GENERATOR" is the number inside your blob file. That code is usually 0x1111111111111111

Method 2: if you DO NOT have blobs saved, you can use SSHRD to install the PersistenceHelper on any sideloaded/AppStore app and it will still work.

#

For A10, it may be possible to use a ramdisk and overwrite said files (Apple TV 4K 1st gen) but requires Goldeneye cable and DCSD.

#

hope that helps @earnest grotto

earnest grotto
#

brilliant, I'll give it a go once my HD arrives

#

thank you!

#

I'm assuming there aren't any special instructions for using SSHRD to do things like dump blobs, just follow the GitHub instructions?

earnest grotto
#

perfect

ionic copper
#

it does cover j42dap and t7000

#

which is apple tv HD's specifically

earnest grotto
#

cool, appreciate the help!

gritty hamlet
elfin haven
elfin haven
#

Like what can we do on tvos

#

Exploit wise

golden geyser
ionic copper
#

rest of it is trollstore and kfp for palera1n

marsh rune
trim wagon
marsh rune
bitter gull
ionic copper
#

checkra1n just makes it easier

ionic copper
#

it's only if you're on the latest

ionic copper
verbal condor
#

What are the supported Apple TV’s and OS?

marsh rune
marsh rune
#

Is it enough to just do the scp thing and leave it like that or do i have to delete files?

ionic copper
verbal condor
#

Got the 4k one Gen 4 I think? What’s the newest one?

marsh rune
#

@ionic copper how is an sshrd made on an atv?

ionic copper
marsh rune
#

The github script doesnt work for me

ionic copper
#

Error?

marsh rune
#

something about sigpatches

ionic copper
#

.. What's the error

marsh rune
#

wait

marsh rune
ionic copper
#

I'd give you the ramdisk but I think it's against the rules

marsh rune
ionic copper
#

Good

marsh rune
#

but the atv doesnt show any image

ionic copper
#

You can now use iproxy

#

Set up a port with 44

#

So iproxy 2235 44

#

Then ssh in to said port

#

ssh -p 2235 root@localhost

#

After typing in the password and logging in, use mount_filesystem

marsh rune
#

done

#

its stuck on rsep nonce

#

is that normal?

ionic copper
#

Yes

#

You should still get some kind of line to type in

marsh rune
#

yes

#

what do i type?

ionic copper
#

Well.. what’s mentioned above

ionic copper
oak island
# ionic copper you don't need to.

Any chance you might be able to post a trollhelper Deb for tvOS on your NitoTV repo? Would make installation a beeeze. Also , your instructions on ssh’ing in and replacing random.app binary with the persistence helper, does that only work with the SCP protocol? I did the same exact thing only via SFTP and the app crashes immediately when I try to open it.

ionic copper
oak island
#

@ionic copper 14.6

ionic copper
oak island
# ionic copper The app probably needs to be refreshed or the device rebooted

Tried that, I’m thinking it had something to do with me opening the persistence_helper to take a look around and then not resigning it with ldid after. Would that make sense? Also one other unrelated question…If I have a tvOS .tipa file that I wanted to use as a regular tvOS .ipa file and say airdrop it to be installed ReProvision, is converting it as easy as just renaming the file extension to .ipa?

ionic copper
#

@gritty hamlet could you add a picture to the assets inside cfw website?

#

that way the guide can see it

gritty hamlet
ionic copper
gritty hamlet
earnest grotto
#

I realize that's (hopefully) a temporary thing, but you should put a notice there for now imo

golden geyser
earnest grotto
marsh rune
#

any idea why troll store doesn’t work?

#

I’m trying to install Kodi

ionic copper
golden geyser
golden geyser
marsh rune
#

Wtf it just worked

#

I tried installing mame and it worked

marsh rune
#

It gets stuck on the installing screen

ionic copper
#

Because the new Kodi has different builds, you can use older versions

bitter gull
ionic copper
marsh rune
#

That version is obsolete

#

And there are little to no plugins available for that version too

oak island
ionic copper
oak island
# ionic copper Yup

Just an idea, but for the ios.cfw.guide would it maybe be easier for begginers to replace the instruction of first downloading the PersistenceHelper_Embedded with downloading the .tar and getting the PersistenceHelper binary directly from TrollStore.app?

ionic copper
#

Just need to implement it

cyan veldt
#

trying to reinstall misaka through trollstore for the ota blocker but it has no icon and doesn't launch

#

have refreshed app registrations and restarted

#

is it a common bug?

ionic copper
cyan veldt
#

was my bad, I accidentally pasted the iOS ipa in trollstore

#

all good now

oak island
#

@ionic copper Any idea why this is happening?

ionic copper
oak island
ionic copper
oak island
green basalt
marsh rune
#

Nvm it did work

#

Thank you so much! @green basalt

#

Does removing that folder remove any functionality?

fading fossil
#

hi guys, I installed misaka and ran the summa developer mode on my Appletv.... but how do I install trollstore now? thanks to who helps me

storm ridge
# fading fossil

I would not use 5.2, it does not block OTA properly. I had to go back to using 5.1 but since then 5.3 has been released and is suppose to fix the issue.

fading fossil
storm ridge
# fading fossil thak for your reply man , ok but after the misaka installation , what i have to...

I installed Misaka/TrollStore on four ATV 4's (16.5) and I documented my success as I went along. This was mine, yours may differ slightly...

Misaka/TrollStore for ATV
Note currently Misaka 5.1 or 5.3+ works for OTA blocking (5.2 does not)

  1. Make sure Macbook is paired to ATV with Apple Configurator (any version). If not, go into ATV Settings>Remotes and Devices>Remote App and Devices. Need to have the Remote App and Devices page visible in order to pair in Apple Conifigurator.
  2. On ATV, download Apple Developer app. Open then quit it completely (Misaka will use this app later to install TrollStore)
  3. Keep Apple Configurator open and launch Sideloadly. Load Misaka IPA and use an AppleID that has free signing slots then click Start. When done, quit all apps on Macbook.
  4. On ATV open Misaka>Settings makes sure Landa is set by default (for tvOS 16.5). Back on main screen click "kopen". If it crashes, quit app from app switcher & run this step again.
  5. Click Install TrollStore and on the popup screen click "Developer". If get an error, quit Misaka from app switcher, reboot ATV and try Step 4-5 again.
  6. Open Developer app and click "Install TrollStore". ATV will automatically reboot. Open Developer app again, click "Register Persistence Helper".
  7. Delete the sideloaded Misaka app. Open TrollStore, click link icon on the right and enter the URL of the Misaka app then install.
  8. Open Misaka>Settings and click Block to block OTA updates. Reboot (not respring) and check if updates are now blocked.
  9. Use TrollStore to install any other apps
fading fossil
#

I have tvOS 16.2

ionic copper
#

oh wait, you have HD.. use sshrd

fading fossil
earnest grotto
#

Looking at the SSHRD readme, do you have to specify tvOS vs iOS?

The iOS version doesn't have to be the version you're currently on, but it should be close enough, and SEP has to be compatible
If you're on Linux, you will not be able to make a ramdisk for 16.1+, please use something lower instead, like 16.0
This is due to ramdisks switching to APFS over HFS+, and another dmg library would have to be used```
ionic copper
earnest grotto
#

ah, you just specify the IPSW

#

perfect

#

and does that version have to match the currently installed version (15.4 in this case)?

ionic copper
#

no

earnest grotto
#

ok thanks

ionic copper
#

15.4 works in conjunction with 15 - 17.3

earnest grotto
#

perfect

fading fossil
ionic copper
earnest grotto
fading fossil
ionic copper
earnest grotto
#

you can make a live boot linux disk pretty easily, might be the best option

fading fossil
#

i have already a virtual machine whit Linux kali 😛

ionic copper
#

needs to be a native installation

fading fossil
#

ok, i try to make a live usb bootable whit linux , and after that what i have to do ?

ionic copper
#
sudo apt-get update
sudo apt-get install -y git
git clone --recursive https://github.com/verygenericname/SSHRD_Script.git```
fading fossil
#

but this install somethink in the apple tv in this way ? i dont understand sshrd what si for

ionic copper
#

this then, installs trollstore

#

misaka uses an exploit to install trollstore but...
This covers firmwares of tvOS 14.0 beta 2 - 14.8.1, 15.7.2 - 15.8.1 and 16.2 - 17.0. Reason why for these specific firmwares is because KFD may or may not work at the moment.

earnest grotto
ionic copper
#

which uses checkm8 as the exploit instead of kfd

fading fossil
ionic copper
#

usb-c required

#

the above command is just to install sshrd to your linux machine

fading fossil
ionic copper
earnest grotto
#

and in DFU mode if i’m not mistaken

fading fossil
#

how to put the atv in dfu mode ?

#

maybe the most speedest way is tu update my ATV on 16.4 ?

ionic copper
#

then release

#

must be connected via usb during

earnest grotto
#

any ideas what this means?

[*] Getting device info and pwning... this may take a second
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f
Compiled with plist: YES
Saved IM4M to work/IM4M
Version: 9bfdde2b2456181045f74631683fba491d8bf4f2 - 38
libfragmentzip version: 0.64-aaf6fae83a0aa6f7aae1c94721857076d04a14e8-RELEASE
init pzb: null
Error init failed
[-] An error occurred```
ionic copper
#

i think the one included has issues, so brew install might work best

#

then you can copy it from cp /usr/local/bin/pzb to SSHRD_SCRIPT/Darwin/

earnest grotto
#

i'll try

#
[*] Getting device info and pwning... this may take a second
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f
Compiled with plist: YES
Saved IM4M to work/IM4M
dyld[91036]: Library not loaded: /usr/local/opt/libzip/lib/libzip.5.dylib
  Referenced from: <91881431-321F-3074-9F25-86772E6FD1D2> /Users/cobre/Downloads/SSHRD_Script/Darwin/pzb
  Reason: tried: '/usr/local/opt/libzip/lib/libzip.5.dylib' (no such file), '/System/Volumes/Preboot/Cryptexes/OS/usr/local/opt/libzip/lib/libzip.5.dylib' (no such file), '/usr/local/opt/libzip/lib/libzip.5.dylib' (no such file), '/usr/local/lib/libzip.5.dylib' (no such file), '/usr/lib/libzip.5.dylib' (no such file, not in dyld cache)
./sshrd.sh: line 213: 91036 Abort trap: 6           ../"$oscheck"/pzb -g BuildManifest.plist "$ipswurl"
[-] An error occurred```
I think I can figure out how to fix this
#

something about libzip not being installed in the right location

ionic copper
earnest grotto
#

both are installed

#

i'm on mac btw

ionic copper
#

or if you can find / -name libzip then use that location to cp to /System/Volumes/Preboot/Cryptexes/OS/usr/local/opt/libzip/

#

or /usr/local/opt/libzip/lib/

ionic copper
#

seeing as brew isn't viable on linux

earnest grotto
#

fair haha

#

I found it, i'm copying it now

#

thanks

ionic copper
#

although i don't know why you have stuff linked to preboot...

earnest grotto
#

hmm, still getting dyld[95171]: Library not loaded: /usr/local/opt/libzip/lib/libzip.5.dylib even though /usr/local/opt/libzip/lib/ contains libzip.5.dylib

earnest grotto
earnest grotto
#

14.1.2

#

I can pull out a Linux install and try it

ionic copper
#

although /usr/local/opt is a procursus link...

earnest grotto
#

I'm going to see what Linux does, just a minute

ionic copper
#

linux would probably be better

#

seeing as macos gets fussy about running dylibs in odd locations

earnest grotto
#

yeah

#

ugh, still getting the pzb error:

[*] Getting device info and pwning... this may take a second
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f-RELEASE
Compiled with plist: YES
Saved IM4M to work/IM4M
Version: 3fc8c093f4660f6c6e07c0c9214618733da01ffc - 36
libfragmentzip version: 0.60-120447d0f410dffb49948fa155467fc5d91ca3c8
init pzb: null
Error init failed
[-] An error occurred```

Even though `./Darwin/pzb` works fine: 
```Version: 3fc8c093f4660f6c6e07c0c9214618733da01ffc - 36
libfragmentzip version: 0.60-120447d0f410dffb49948fa155467fc5d91ca3c8
Error url parameter required!
Usage: ./Darwin/pzb [parameter] <url to zip>
Browse and download files and directories from remote zip
Specifying no parameter starts an interactive console

Usage: parameter <required argument> [optional argument]
Following parameter are avaliable:
  -l                             shows contents and subdirectories of zip
      --list=[path]              shows contents and subdirectories of [path] in zip
      --nosubdirs                don't show subdirectories. Does nothing without -l or --list
  -c, --create-directories       download files with it' directories and subdirectories
  -h, --help                     shows this help
  -g, --get       <path>         downloads remote file
  -d, --directory                download remote directory recursively instead of sindle file
                                 use this with -g (--get)
  -o, --output    <path>         specify dst filename when downloading
  -k, --insecure                 disable ssl validation
  -u, --user[:password]          authenticate to webserver```
#

(I replaced ./Darwin/pzb with the latest from tihmstar's github)

ionic copper
#

wait.. what ipsw are you using?

#

because the ipsw is supposed to be the url

ionic copper
#

no, pzb grabs the url

#

😛

#

no wonder it didn't work

#

skill issue

earnest grotto
ionic copper
earnest grotto
#

i see, so ./sshrd.sh https://updates.cdn-apple.com/2022FCSWinter/fullrestores/071-05901/6C60FB17-938B-4FD6-8E67-1FD2C2F0E3C7/AppleTV5,3_15.4_19L440_Restore.ipsw?

ionic copper
#

https://updates.cdn-apple.com/2022FCSWinter/fullrestores/071-05901/6C60FB17-938B-4FD6-8E67-1FD2C2F0E3C7/AppleTV5,3_15.4_19L440_Restore.ipsw

#

yes

#

then it'll go brrrrrrrr

earnest grotto
#

same issue unfortunately

#
[*] Getting device info and pwning... this may take a second
img4tool version: 0.197-aca6cf005c94caf135023263cbb5c61a0081804f-RELEASE
Compiled with plist: YES
Saved IM4M to work/IM4M
Version: 3fc8c093f4660f6c6e07c0c9214618733da01ffc - 36
libfragmentzip version: 0.60-120447d0f410dffb49948fa155467fc5d91ca3c8
init pzb: null
Error init failed
[-] An error occurred```
#

changing ipswurl=... in the script to the actual url seems to have worked

#

now I have to figure out why ssh isn't working

Creating listening port 2222 for device port 22
bind(): Address in use
Error creating socket for listen port 2222: Address in use
New connection for 2222->22, fd = 5
waiting for connection
No connected device found, terminating.
kex_exchange_identification: read: Connection reset by peer
Connection reset by 127.0.0.1 port 2222
[-] An error occurred```
ionic copper
#

very odd

#

don't use port 2222

earnest grotto
#

(i can probably figure this out, I'm only posting here to document things)

ionic copper
#

I use port 2234

#

2222 is so common, everything uses it

#

so i change it to a random number

earnest grotto
#

how do you specify the port?

#

i'm just trying ./sshrd.sh ssh

ionic copper
#

in the script.. look for 2222

earnest grotto
#

alright

ionic copper
#

then edit to any 4-digit number

earnest grotto
#
❯ ./sshrd.sh ssh
Creating listening port 2243 for device port 22
waiting for connection
New connection for 2243->22, fd = 5
waiting for connection
No connected device found, terminating.
kex_exchange_identification: Connection closed by remote host
Connection closed by 127.0.0.1 port 2243
[-] An error occurred```
ionic copper
#

you don't need to do ssh

#

just iproxy 2243 22

#

then log in via ssh -p 2243 root@localhost

earnest grotto
#
Connection reset by 127.0.0.1 port 2243
ionic copper
#

once you've made the ramdisk via script, use ./sshrd.sh boot

#

then you can log in

earnest grotto
#

yeah, I've booted

#

it showed the sshrd logo and verbose text for a second

ionic copper
#

you can also try iproxy 2243 44

#

that one /should/ work

earnest grotto
#

and the same ssh -p 2243 root@localhost command?

ionic copper
#

yes

earnest grotto
#

still didn't work, same error

ionic copper
#

No connected device found, terminating.

#

that's your issue

earnest grotto
#

yep

ionic copper
#

maybe unplug usb, replug

#

if still not, you might need libusb

#

you could do the same on the mac

#

just copy the script over

#

mac might find the device much easier

fading fossil
earnest grotto
#
Warning: Permanently added '[localhost]:2243' (ECDSA) to the list of known hosts.
localhost:~ root#

boom, done

ionic copper
#

it's literally the path to the url

earnest grotto
# fading fossil 😅😅😅😅

if you're wanting to use the 15.4 ipsw for apple tv hd, it should be ./sshrd.sh https://updates.cdn-apple.com/2022FCSWinter/fullrestores/071-05901/6C60FB17-938B-4FD6-8E67-1FD2C2F0E3C7/AppleTV5,3_15.4_19L440_Restore.ipsw

fading fossil
#

in my atv is running 16.2

earnest grotto
#

that's alright

#

it'll still work

ionic copper
#

may as well run cat /dev/rdisk1 | dd of=dump.raw bs=256 count=$((0x4000)) then scp -P 2243 root@localhost:/path/to/dump.raw ~/Desktop

#

@earnest grotto

#

then you can convert to shsh2

#

get your on-board blobs

earnest grotto
#

I've run mount_filesystems but this is giving me:

dd: dump.raw: Read-only file system```
fading fossil
earnest grotto
#

have you cloned the sshrd repo

ionic copper
#

root is writeable

fading fossil
earnest grotto
ionic copper