Skip to content

Instantly share code, notes, and snippets.

View rickmark's full-sized avatar
🔬
Decoding iOS Formats

Rick Mark rickmark

🔬
Decoding iOS Formats
View GitHub Profile
@rickmark
rickmark / modules.txt
Created February 28, 2025 09:54
UI Recovery Tampered Modules
# Aliases extracted from modules themselves.
alias fs-squashfs squashfs
alias crypto-crc32c-generic crc32c_generic
alias crc32c-generic crc32c_generic
alias crypto-crc32c crc32c_generic
alias crc32c crc32c_generic
alias devname:loop-control loop
alias char-major-10-237 loop
alias block-major-7-* loop
alias md-level--1 linear
{
"interfaces": [
{
"identification": {
"id": "lo",
"type": "loopback"
},
"status": {
"enabled": true,
"mtu": 65536
#!/bin/sh
exec >> /tmp/syswrapper.log
exec 2>&1
echo "$(date) {$@}"
. /usr/bin/platdep_funcs.sh
. /usr/bin/state_lock_funcs.sh
. /usr/bin/unifi_util_funcs.sh
[ 0.000000] Booting Linux on physical CPU 0x0000000000 [0x410fd490]
[ 0.000000] Linux version 5.15.72-ui-cn10k (bdd@builder) (aarch64-linux-gnu-gcc (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU Binutils for Debian) 2.35.2) #5.15.72 SMP PREEMPT Tue Aug 20 15:24:52 CST 2024
[ 0.000000] Machine model: Marvell CN103XX board
[ 0.000000] earlycon: pl11 at MMIO 0x000087e028000000 (options '')
[ 0.000000] printk: bootconsole [pl11] enabled
[ 0.000000] efi: UEFI not found.
[ 0.000000] [Firmware Bug]: Kernel image misaligned at boot, please fix your bootloader!
[ 0.000000] NUMA: NODE_DATA [mem 0x7faa7dd00-0x7faa7ffff]
[ 0.000000] Zone ranges:
[ 0.000000] DMA [mem 0x0000000004000000-0x00000000ffffffff]
@rickmark
rickmark / apsctl.log
Created January 3, 2025 22:14
apsctl
daemon status: Running
startup time: Dec 30, 2024 at 12:30:24 AM (394954.96 seconds ago)
certificate status: Provisioned, using existing certificate
app refresh activity: No
connection environment: development
connection status: No
enabled: Yes
noncellular connected: No
wwan connected: No
keep alive proxying: Enabled
@rickmark
rickmark / Lockdowns.crash
Created October 11, 2024 02:01
Yet another no touch pwn
{"is_simulated":1,"app_name":"lockdownd","timestamp":"2024-10-05 10:49:18.00 -0700","app_version":"","slice_uuid":"0bd1fc85-7ee7-3656-b180-7da793ba7c81","build_version":"","platform":2,"share_with_app_devs":0,"is_first_party":1,"bug_type":"308","os_version":"iPhone OS 18.0.1 (22A3370)","roots_installed":0,"incident_id":"B4884BEE-FA38-428C-8E76-364C3B461CA4","name":"lockdownd"}
{
"uptime" : 16,
"procRole" : "Unspecified",
"version" : 2,
"userID" : 0,
"deployVersion" : 210,
"modelCode" : "iPhone17,2",
"coalitionID" : 111,
"osVersion" : {
2024-02-02T06:36:41.9751935Z Current runner version: '2.312.0'
2024-02-02T06:36:41.9775842Z ##[group]Operating System
2024-02-02T06:36:41.9776482Z Ubuntu
2024-02-02T06:36:41.9776951Z 22.04.3
2024-02-02T06:36:41.9777275Z LTS
2024-02-02T06:36:41.9777600Z ##[endgroup]
2024-02-02T06:36:41.9778009Z ##[group]Runner Image
2024-02-02T06:36:41.9778498Z Image: ubuntu-22.04
2024-02-02T06:36:41.9778891Z Version: 20240126.1.0
2024-02-02T06:36:41.9779955Z Included Software: https://github.com/actions/runner-images/blob/ubuntu22/20240126.1/images/ubuntu/Ubuntu2204-Readme.md
@rickmark
rickmark / joined.tbd
Created March 12, 2024 07:03
TBD Entries
This file has been truncated, but you can view the full file.
--- !tapi-tbd
tbd-version: 4
targets: [ x86_64-macos, arm64-macos, arm64e-macos ]
install-name: '/usr/lib/ACIPCBTLib.dylib'
exports:
- targets: [ x86_64-macos, arm64-macos, arm64e-macos ]
symbols: [ __ZN12ACIPCBTClass10writeAsyncEPKvjPFvPviS2_ES2_, __ZN12ACIPCBTClass12readRegisterEjPvPj,
__ZN12ACIPCBTClass14clearIteratorsEv, __ZN12ACIPCBTClass14sendImageAsyncEPKvjPFvPviS2_S2_ES2_,
__ZN12ACIPCBTClass16interfaceMatchedEPvj, __ZN12ACIPCBTClass17abortChannelAsyncE14acipcDirectionPFvPviES1_,
@rickmark
rickmark / fixup.txt
Created March 5, 2024 02:55
dyld symbolic fixup
/usr/lib/dyld [arm64e]:
-symbolic_fixups:
0x00098000 __DATA_CONST __auth_ptr
+0x98000 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
+0x98008 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
+0x98010 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
+0x98018 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
+0x98020 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
+0x98028 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
+0x98030 rebase pointer ___chkstk_darwin (div=0x0000 ad=0 key=IA)
@rickmark
rickmark / TargetList.txt
Created March 5, 2024 02:46
TargetedAppList
__ZN5dyld4L27dataConstApps_iOS14_5_arm64E:
+0x0000 rebase pointer "WeChat"
+0x0008 rebase pointer "True Skate"
+0x0010 rebase pointer "imeituan"
+0x0018 rebase pointer "DPScope"
+0x0020 rebase pointer "PCDBank"
+0x0028 rebase pointer "AirChina"
+0x0030 rebase pointer "ceair_iOS_branch"
+0x0038 rebase pointer "WeRead"
+0x0040 rebase pointer "osee2unifiedRelease"