VMLite Inc
182 posts


@Manumalware @MudSplasherdev You setup an environment, tell Gemini how to flash the device, give access to the ipsw, the tools, such as img4, img4tool, idevicerestore, etc. then write a product plan on what to do, what is the goal. Gemini CLI will do the work, you just keep hitting Yes to proceed.
English

@vmlite @MudSplasherdev And what prompt will we have to type on gemini ? Pls ?
English

@MudSplasherdev You can try to use Gemini cli, I didn’t write code, Gemini did it
English

@MudSplasherdev I know this host redirection. I made my own tss server too, can work all the way up to libimage4 without any patching of code. I am using it to play with vphone firmware
English

@vmlite Just change your hosts file to redirect gs.apple.com to localhost (The TSS server is coming from localhost)
English

@MudSplasherdev The leaf certificate is very important, but at about 95%, restore would fail, without patching, libimage4.dylib is tough to pass with restored_external
English

@_inside One more question, again, if you don’t mind, are you using the restore RAM disk from vresearch ipsw or iOS 26.2 ipsw ? Thank you
English

@matteyeux Ok, I found the strings in DeviceTree.vphone600ap.im4p, thank you
English

@matteyeux Which firmware did you see this iPhone VRE? I downloaded a few from “pccvre release download”, but couldn’t find it. Thanks
English

@matteyeux Very much appreciated! I downloaded it a few days ago, and unzipped it, but couldn’t find the strings you mentioned. Which file did you do bd the strings? There are two DeviceTree im4p files
English

@_inside If you don’t mind, can you tell which release of assets downloaded by pccvre are you using?
English

@nyan_satan Hi, anyway to try or buy your iOS virtualization on arm Mac? I’d like to see if can virtualize iOS26.
English

Here is my little article with technical details behind the iOS 6 on iPod touch 3 bring-up
nyansatan.github.io/run-unsupporte…

English

@nyan_satan Nice work! I also watched your YouTube video on iOS vm running ok macOS with virtualization. Framework, even more impressive
English

@whati001 @nyan_satan iOS supports a special host node lightning connector, which is different from the regular lightning cable we use every day. If you use usb analyzer, it does have iAP traffic, starting with 0x55. You can use a regular lightning cable to switch iOS to host mode by control transfer
English

@nyan_satan Thank you very much for your research. Also did some research to Haywire and Nero protocol running on it.
But I have not managed yet to understand how Haywire puts the Apple Device into USB host mode without iAP. Do you have a hint for me?
guess some resistor network...
English

@nyan_satan @a1exdandy Ok, thanks. I just tried one lightning female to micro usb male adapter, you are right. It does NOT work with AV adapter, it seems have to try the breakout boards as you mentioned. I used the firmware to reverse engineered the usb mirroring protocol, mainly thru static analysis.
English

@vmlite @a1exdandy There’s no such thing as “Lightning female adapter” on the market afaik. You need either breakout boards, or butcher an extension cable
Speaking of host - not sure at this point. It might be that modern Mac HW/SW won’t work out-of-box with that fork
English

@nyan_satan Hi, your research on haywire firmware is impressive! I was curious if you have found a way to decrypt the kernel? Thanks
English

@nyan_satan @a1exdandy Ok, thanks. I just tried one lightning female to micro usb male adapter, you are right. It does NOT work with AV adapter, it seems have to try the breakout boards as you mentioned. I used the firmware to reverse engineered the usb mirroring protocol, mainly thru static analysis.
English

@nyan_satan @a1exdandy Thank you for the quick response. From reading the doc, it seems that I first need to buy a lightning female adapter to connect Apple AV adapter to a MacBook then run the ipwnfu program on MacBook, right? This is really new to me.
English

@nyan_satan @a1exdandy Ok, thanks. I just tried one lightning female to micro usb male adapter, you are right. It does NOT work with AV adapter, it seems have to try the breakout boards as you mentioned. I used the firmware to reverse engineered the usb mirroring protocol, mainly thru static analysis.
English

@vmlite Sure, that’s easy. @a1exdandy ported checkm8 to that thing, so now you can do it
twitter.com/a1exdandy/stat…
Alexey Kovrizhnykh@a1exdandy
#checkm8 for Haywire Only a memory dump is checked, there may be problems with other functionality SecureROM of Haywire also in repo, enjoy! github.com/a1exdandy/ipwn… Thanks to @nyan_satan for usefull thread about Haywire
English




