synackuk

1.1K posts

synackuk

synackuk

@synackuk

The Gateway of Last Resort, casual interest in computer security and maths.

127.0.0.1 Katılım Ekim 2018
266 Takip Edilen2.4K Takipçiler
Sabitlenmiş Tweet
synackuk
synackuk@synackuk·
Here's n1ghtshade 1.0 Fixes all the known bugs as far as I'm aware. Note you MUST restore again if you wish to update to this version. Have fun, and let me know of any bugs. github.com/synackuk/n1ght…
English
8
3
27
0
synackuk
synackuk@synackuk·
@Vyce_Merculous @dora2ios Yeah I’ll write it up. To be honest the process doesn’t change though. I did use my own tooling though
English
0
0
1
107
Merculous
Merculous@Vyce_Merculous·
@synackuk @dora2ios Could you make a writeup/guide on how to port DRA to other versions? I'm too much a noob to figure this stuff out.
English
1
0
0
118
synackuk
synackuk@synackuk·
De Rebus Antiquis on iOS 6.1.6 (iPod touch 4G)! Thanks to @dora2ios, I’ll release this at some point if anyone’s interested.
English
10
16
153
13.5K
pwnerblu
pwnerblu@pwnerblu·
@synackuk @dora2ios This is interesting! Maybe iOS 7 iPod touch 4 can be untethered some time in the future…
English
1
0
3
317
synackuk
synackuk@synackuk·
@Pingzi610 @dora2ios For nettoyeur I used an iBoot payload for the diff rather than kdumper. Not sure about r0, I may play about with the iPhone 4S at some point soon.
English
1
0
1
152
Pingzi
Pingzi@Pingzi610·
@synackuk @dora2ios Umm I have a problem running kdumper and it won’t dump a correct iBoot on iPhone 4s 6.1.3. And don’t know how to control r0 I’m using iloader
English
1
0
0
116
Pingzi
Pingzi@Pingzi610·
@synackuk @dora2ios Great work!I’m still doing iPhone 4s’ work,I haven't find a good hierarchy yet,do you have any advice?
English
1
0
0
395
synackuk
synackuk@synackuk·
@dedbeddedbed @dora2ios I will, but I want to integrate it back into n1ghtshade, and also put out a write up on the tools I built for this work (since I didn’t use iloader..). So will take some time.
English
1
0
3
64
Pingzi
Pingzi@Pingzi610·
@synackuk @ShadowLee19 @xerub not iloader.o,nettoyeur.o is,open with binary editor and you can find the correct version of arm-none-eabi-gcc
English
1
0
0
23
synackuk
synackuk@synackuk·
@Pingzi610 @ShadowLee19 @xerub I have code execution, but am having problems getting iBoot to restart correctly. Not sure if you have any advice on creating nettoyeur? I just ran kdumper and diffed it with my decrypted iBoot..
English
1
0
0
65
Pingzi
Pingzi@Pingzi610·
@synackuk @ShadowLee19 @xerub I haven’t add any breakpoints or debugging _memalign. Just only can make iloader running and let readp() work.
English
1
0
0
33
synackuk
synackuk@synackuk·
@Pingzi610 @ShadowLee19 @xerub Can we DM? I didn’t manage to get iloader working, but have been playing about with patching breakpoints into an iBoot image and booting it to achieve the same thing, would be good to compare notes?
English
2
0
0
81
Pingzi
Pingzi@Pingzi610·
@synackuk @ShadowLee19 @xerub I can fake-run iBoot 1537-9.55(iOS 6.1.3)using iloader,but I have no idea utilizing the exploit since I can’t control r0. I can send you the modified iloader if you need.
English
1
0
0
72
synackuk retweetledi
Joshua Hill
Joshua Hill@p0sixninja·
Still searching for my next project!! Really struggling to even land any interviews
English
2
2
9
6.1K
synackuk
synackuk@synackuk·
@p0sixninja @ShadowLee19 Are the slides or similar from that training available anywhere? I thought I remembered seeing it years ago, but I can't find it now...
English
1
0
0
69
synackuk retweetledi
john
john@nyan_satan·
SundanceInH2A (rev2) brings ability to create bundles with jailbreak applied Please note that it needs a different kernelcache - more info in README github.com/NyanSatan/Sund…
john tweet media
English
4
14
112
9.4K
synackuk
synackuk@synackuk·
@nyan_satan Ah after finishing the article I can see you're way ahead of me :) I remember @p0sixninja saying that in the talk where he demoed the iBoot exploit you're using here he actually leaked multiple iBoot bugs. I wonder if any of them were left unpatched
English
0
0
2
320
synackuk
synackuk@synackuk·
@nyan_satan Hmm.. I bet that iOS 6 on the iPad 1st gen would be plausible with a similar method
English
2
0
8
1.5K
synackuk retweetledi
john
john@nyan_satan·
Just released my little tool that generates iOS 6 restore bundle for iPod touch 3! USE THIS STRICTLY ON YOUR OWN RISK github.com/NyanSatan/Sund…
English
10
25
157
55.7K
synackuk retweetledi
john
john@nyan_satan·
It's been a long time since I published a write-up, so... Here's my little article about log strings obfuscation in modern iBoot and 2 methods I found to (partially) deobfuscate them Read on your own risk! nyansatan.github.io/iboot-log-deob…
john tweet media
English
2
27
291
19.7K
eri
eri@eepyeri·
@snwy_me checkm8 itself does, checkrain is only for 64bit
English
2
0
4
323
eri
eri@eepyeri·
i need some help I've recently got this iphone 5c (fmi on), managed to get to the home screen but because it's not activated i can't sideload anything. is there any possible way to jailbreak the thing without sideloading any apps?
eri tweet media
English
5
0
42
8.5K