From 4f8fbad36de740a9a13597e4e1fca44e9f3e0add Mon Sep 17 00:00:00 2001 From: Pwn20wnd Date: Sat, 24 Jun 2017 12:23:44 -0700 Subject: [PATCH 1/4] Update --- extra_recipe/dex.plist | 489 +++++++++++++++++++++++++++++++++++++---- 1 file changed, 450 insertions(+), 39 deletions(-) diff --git a/extra_recipe/dex.plist b/extra_recipe/dex.plist index 9a028a7..ed974b3 100644 --- a/extra_recipe/dex.plist +++ b/extra_recipe/dex.plist @@ -2,7 +2,6 @@ - hw @@ -16,23 +15,14 @@ 10.1 10.1.1 - offsets - 0xfffffff006f83d38 - 0xfffffff00747ad9c - 0xfffffff0074916b4 - 0xfffffff00749ca6c - 0xfffffff0075f0178 - 0xfffffff00757c898 - 0xfffffff006337e10 @@ -61,8 +51,6 @@ 0xfffffff00633fe10 - - hw @@ -75,7 +63,7 @@ offsets - 0xfffffff006f9b950 + 0xfffffff006f9b950 0xfffffff00743755c 0xfffffff00744df5c 0xfffffff007459378 @@ -84,10 +72,50 @@ 0xfffffff0063cfe10 - - - - + + hw + + iPhone8,1 + iPhone8,2 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006f9e1f8 + 0xfffffff0074331ec + 0xfffffff007449b04 + 0xfffffff007454e6c + 0xfffffff0075a8148 + 0xfffffff007534898 + 0xfffffff0063d3e10 + + + + hw + + iPhone8,1 + iPhone8,2 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006f9e038 + 0xfffffff007431d04 + 0xfffffff00744860c + 0xfffffff007453974 + 0xfffffff0075a8148 + 0xfffffff007534898 + 0xfffffff0063dbe12 + + hw @@ -99,7 +127,7 @@ offsets - 0xfffffff006fa7e90 + 0xfffffff006fa7e90 0xfffffff00743755c 0xfffffff00744df5c 0xfffffff007459378 @@ -108,8 +136,48 @@ 0xfffffff0063ebe10 - - + + hw + + iPhone8,4 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006fa83f8 + 0xfffffff0074331ec + 0xfffffff007449b04 + 0xfffffff007454e6c + 0xfffffff0075a8148 + 0xfffffff007534898 + 0Xfffffff0063f3e10 + + + + hw + + iPhone8,4 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006fa8238 + 0xfffffff007431d04 + 0xfffffff00744860c + 0xfffffff007453974 + 0xfffffff0075a8148 + 0xfffffff007534898 + 0xfffffff0063f7e10 + + hw @@ -133,6 +201,30 @@ 0xfffffff006413e10 + + hw + + iPhone7,1 + iPhone7,2 + + ios + + 10.0.2 + 10.0.1 + + nports + 15000 + offsets + + 0xfffffff006f9b6b8 + 0xfffffff00743eed8 + 0xfffffff0074557e0 + 0xfffffff007460b48 + 0xfffffff0075b4168 + 0xfffffff007540898 + 0xfffffff00641be10 + + hw @@ -142,9 +234,10 @@ ios 10.1.1 + 10.1 nports - 15000 + 15000 offsets 0xfffffff006f9b878 @@ -156,8 +249,6 @@ 0xfffffff006417e10 - - hw @@ -188,6 +279,7 @@ ios 10.1.1 + 10.1 offsets @@ -209,6 +301,7 @@ ios 10.0.2 + 10.0.1 offsets @@ -221,8 +314,6 @@ 0xfffffff00648be10 - - hw @@ -244,8 +335,50 @@ 0xfffffff0063bfe10 - - + + hw + + iPad5,3 + iPad5,4 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006f85878 + 0xfffffff0074405c4 + 0xfffffff007456edc + 0xfffffff007462244 + 0xfffffff0075b8228 + 0xfffffff007544898 + 0xfffffff0063c7e10 + + + + hw + + iPad5,3 + iPad5,4 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006f856b8 + 0xfffffff00743f0fc + 0xfffffff007455a04 + 0xfffffff007460d6c + 0xfffffff0075b4228 + 0xfffffff007540898 + 0xfffffff0063cbe10 + + hw @@ -267,8 +400,50 @@ 0xfffffff00628be10 - - + + hw + + iPad6,3 + iPad6,4 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006f7e778 + 0xfffffff0074331ec + 0xfffffff007449b04 + 0xfffffff007454e6c + 0xfffffff0075a8148 + 0xfffffff007534898 + 0xfffffff00628fe10 + + + + hw + + iPad6,3 + iPad6,4 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006f7e5f8 + 0xfffffff007431d04 + 0xfffffff00744860c + 0xfffffff007453974 + 0xfffffff0075a8148 + 0xfffffff007534898 + 0xfffffff006297e10 + + hw @@ -290,8 +465,50 @@ 0xfffffff0062bfe10 - - + + hw + + iPad6,7 + iPad6,8 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006f8dc38 + 0xfffffff0074331ec + 0xfffffff007449b04 + 0xfffffff007454e6c + 0xfffffff0075a8148 + 0xfffffff007534898 + 0xfffffff0062c7e10 + + + + hw + + iPad6,7 + iPad6,8 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006f8da78 + 0xfffffff007431d04 + 0xfffffff00744860c + 0Xfffffff007453974 + 0xfffffff0075a8148 + 0xfffffff007534898 + 0Xfffffff0062cbe10 + + hw @@ -314,8 +531,52 @@ 0xfffffff00645be10 - - + + hw + + iPad4,1 + iPad4,2 + iPad4,3 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006fb2278 + 0xfffffff007434110 + 0xfffffff00744aa28 + 0xfffffff007455d90 + 0xfffffff0075a8128 + 0xfffffff007534898 + 0xfffffff006463e10 + + + + hw + + iPad4,1 + iPad4,2 + iPad4,3 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006fb20f8 + 0xfffffff007432c48 + 0xfffffff007449550 + 0xfffffff0074548b8 + 0xfffffff0075a8128 + 0xfffffff007534898 + 0xfffffff006463e10 + + hw @@ -338,6 +599,29 @@ 0xfffffff00645be10 + + hw + + iPad4,4 + iPad4,5 + iPad4,6 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006fb18b8 + 0xfffffff007434110 + 0xfffffff00744aa28 + 0xfffffff007455d90 + 0xfffffff0075a8128 + 0xfffffff007534898 + 0xfffffff00645fe10 + + hw @@ -348,6 +632,7 @@ ios 10.0.2 + 10.0.1 offsets @@ -360,8 +645,6 @@ 0xfffffff006463e10 - - hw @@ -384,8 +667,52 @@ 0xfffffff00641be10 - - + + hw + + iPad4,7 + iPad4,8 + iPad4,9 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006faf8f8 + 0xfffffff007434110 + 0xfffffff00744aa28 + 0xfffffff007455d90 + 0xfffffff0075a8128 + 0xfffffff007534898 + 0xfffffff00641be10 + + + + hw + + iPad4,7 + iPad4,8 + iPad4,9 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006faf738 + 0xfffffff007432c48 + 0xfffffff007449550 + 0xfffffff0074548b8 + 0xfffffff0075a8128 + 0xfffffff007534898 + 0xfffffff006427e10 + + hw @@ -407,8 +734,50 @@ 0xfffffff0063b7e10 - - + + hw + + iPad5,1 + iPad5,2 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006f875f8 + 0xfffffff0074403a0 + 0xfffffff007456cb8 + 0xfffffff007462020 + 0xfffffff0075b8168 + 0xfffffff007544898 + 0xfffffff0063bfe10 + + + + hw + + iPad5,1 + iPad5,2 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006f87438 + 0xfffffff00743eed8 + 0xfffffff0074557e0 + 0xfffffff007460b48 + 0xfffffff0075b4168 + 0xfffffff0063c3e10 + 0xfffffff0063bfe10 + + hw @@ -429,5 +798,47 @@ 0xfffffff006477e10 + + hw + + iPod7,1 + + ios + + 10.1.1 + 10.1 + + offsets + + 0xfffffff006fa3078 + 0xfffffff0074403a0 + 0xfffffff007456cb8 + 0xfffffff007462020 + 0xfffffff0075b8168 + 0xfffffff007544898 + 0xfffffff00647fe10 + + + + hw + + iPod7,1 + + ios + + 10.0.2 + 10.0.1 + + offsets + + 0xfffffff006fa2ef8 + 0xfffffff00743eed8 + 0xfffffff0074557e0 + 0xfffffff007460b48 + 0xfffffff0075b4168 + 0xfffffff007540898 + 0xfffffff00647fe10 + + From a99756c62de0df3ed79e224a0cb060693b28ea52 Mon Sep 17 00:00:00 2001 From: Pwn20wnd Date: Sat, 24 Jun 2017 12:25:45 -0700 Subject: [PATCH 2/4] Update --- README.md | 25 +++++++++++++------------ 1 file changed, 13 insertions(+), 12 deletions(-) diff --git a/README.md b/README.md index 9c06044..6645888 100644 --- a/README.md +++ b/README.md @@ -10,20 +10,21 @@ If it says "failed, reboot" you should really reboot. Re-trying the same app wi | Device | Version | |---------|----------| | iPhone 7/+ | iOS 10.0.1 -> iOS 10.1.1 | -| iPhone 6S/+ (TSMC) | iOS 10.2 | -| iPhone SE (TSMC) | iOS 10.2 | -| iPhone 6/+ | iOS 10.1.1 & 10.2 | -| iPhone 5S | iOS 10.0.2, 10.1.1 & 10.2 | -| iPad Air 2 | iOS 10.2 | -| iPad Pro 9.7 | iOS 10.2 | -| iPad Pro 12.9 | iOS 10.2 | -| iPad Air | iOS 10.2 | -| iPad Mini 2 | iOS 10.0.2 & 10.2 | -| iPad Mini 3 | iOS 10.2 | -| iPad Mini 4 | iOS 10.2 | -| iPod Touch 6th Gen. | iOS 10.2 | +| iPhone 6S/+ (TSMC) | iOS 10.0.1 -> iOS 10.1.1 | +| iPhone SE (TSMC) | iOS 10.0.1 -> iOS 10.1.1 | +| iPhone 6/+ | iOS 10.0.1 -> iOS 10.1.1 | +| iPhone 5S | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Air 2 | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Pro 9.7 | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Pro 12.9 | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Air | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Mini 2 | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Mini 3 | iOS 10.0.1 -> iOS 10.1.1 | +| iPad Mini 4 | iOS 10.0.1 -> iOS 10.1.1 | +| iPod Touch 6th Gen. | iOS 10.0.1 -> iOS 10.1.1 | ##### Credits: * Ian Beer for the amazingly simple, yet awesome, kernel exploit * @qwertyoruiop for the amazingly complicated, yet effective, memprot bypass +* @Pwn20wnd for the offsets From 0dd16406c91a26f1f39c06e7fa6857b9e8af5eec Mon Sep 17 00:00:00 2001 From: Pwn20wnd Date: Sat, 24 Jun 2017 12:26:58 -0700 Subject: [PATCH 3/4] Update --- README.md | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/README.md b/README.md index 6645888..b7b98bd 100644 --- a/README.md +++ b/README.md @@ -10,18 +10,18 @@ If it says "failed, reboot" you should really reboot. Re-trying the same app wi | Device | Version | |---------|----------| | iPhone 7/+ | iOS 10.0.1 -> iOS 10.1.1 | -| iPhone 6S/+ (TSMC) | iOS 10.0.1 -> iOS 10.1.1 | -| iPhone SE (TSMC) | iOS 10.0.1 -> iOS 10.1.1 | -| iPhone 6/+ | iOS 10.0.1 -> iOS 10.1.1 | -| iPhone 5S | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Air 2 | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Pro 9.7 | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Pro 12.9 | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Air | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Mini 2 | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Mini 3 | iOS 10.0.1 -> iOS 10.1.1 | -| iPad Mini 4 | iOS 10.0.1 -> iOS 10.1.1 | -| iPod Touch 6th Gen. | iOS 10.0.1 -> iOS 10.1.1 | +| iPhone 6S/+ (TSMC) | iOS 10.0.1 -> iOS 10.2 | +| iPhone SE (TSMC) | iOS 10.0.1 -> iOS 10.2 | +| iPhone 6/+ | iOS 10.0.1 -> iOS 10.2 | +| iPhone 5S | iOS 10.0.1 -> iOS 10.2 | +| iPad Air 2 | iOS 10.0.1 -> iOS 10.2 | +| iPad Pro 9.7 | iOS 10.0.1 -> iOS 10.2 | +| iPad Pro 12.9 | iOS 10.0.1 -> iOS 10.2 | +| iPad Air | iOS 10.0.1 -> iOS 10.2 | +| iPad Mini 2 | iOS 10.0.1 -> iOS 10.2 | +| iPad Mini 3 | iOS 10.0.1 -> iOS 10.2 | +| iPad Mini 4 | iOS 10.0.1 -> iOS 10.2 | +| iPod Touch 6th Gen. | iOS 10.0.1 -> iOS 10.2 | ##### Credits: From 37f28a50a76f16ba0bb0024270f6c79b26b27552 Mon Sep 17 00:00:00 2001 From: Pwn20wnd Date: Sat, 24 Jun 2017 12:30:51 -0700 Subject: [PATCH 4/4] Update --- extra_recipe/Base.lproj/Main.storyboard | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra_recipe/Base.lproj/Main.storyboard b/extra_recipe/Base.lproj/Main.storyboard index 8f042e0..02d329d 100644 --- a/extra_recipe/Base.lproj/Main.storyboard +++ b/extra_recipe/Base.lproj/Main.storyboard @@ -37,7 +37,7 @@ ianbeer & qwertyoruiop & xerub