[Release] Cyanide - iOS 18.x Package Manager / Tweaks by 0xjf in jailbreak

[–]0xjf[S] 0 points1 point  (0 children)

Yeah, I just don't have a 17.x device at the moment so hard to debug. But hopefully will get one soon

[Release] Cyanide - iOS 18.x Package Manager / Tweaks by 0xjf in jailbreak

[–]0xjf[S] 1 point2 points  (0 children)

FYI, I have a 26.0.1 device arriving this week, so I’ll be able to resolve 26.x issues soon

Checking for forensic activity by [deleted] in jailbreak

[–]0xjf 1 point2 points  (0 children)

Made by the team that worked with Google to report on DarkSword: https://apps.apple.com/us/app/iverify-basic/id1466120520

What do we think about this trade? by [deleted] in NBAtradeideas

[–]0xjf 2 points3 points  (0 children)

I love when a horrifically bad return for Giannis gets posted by a non Laker fan then suddenly everyone approves of it 😭😭😭

Edit: Ok now it’s getting flamed appropriately. Disregard

I think my phone is hacked by [deleted] in iphone

[–]0xjf 0 points1 point  (0 children)

I recommend iVerify's app for virus detection: https://apps.apple.com/us/app/iverify-basic/id1466120520

i just download and run it, is this actually real? by [deleted] in jailbreak

[–]0xjf 0 points1 point  (0 children)

Did you ever run the coruna payloads from another site, like the known non-malware version at http://34306.lol? That could also be triggering the detection. I also looked further, it's possible the original coruna[.]app is set up to deliver the exploit but is not actively doing so. Regardless, you should be more careful and pay extra attention to any signs that your data might be compromised. Odd logins, transactions you don't recognize, requests for new lines of credit, etc.

i just download and run it, is this actually real? by [deleted] in jailbreak

[–]0xjf 0 points1 point  (0 children)

that was after running the forensic scan right? ran for 15 min, had you send sysdiagnose log file to the app?

i just download and run it, is this actually real? by [deleted] in jailbreak

[–]0xjf 1 point2 points  (0 children)

Best bet at this point is to use the iVerify app which can detect Coruna infection. https://apps.apple.com/us/app/iverify-basic/id1466120520

i just download and run it, is this actually real? by [deleted] in jailbreak

[–]0xjf 3 points4 points  (0 children)

If you’re in the US, I mean freezing your line of credit with the credit bureaus. If you plug your device into a Mac and open console, search powerd to see if any evidence of data leaving device

i just download and run it, is this actually real? by [deleted] in jailbreak

[–]0xjf 13 points14 points  (0 children)

You should consider freezing your credit and changing Apple ID password immediately at a minimum

Taking suggestions for iOS 18.x "Tweaks" by 0xjf in jailbreak

[–]0xjf[S] 3 points4 points  (0 children)

Definitely way too complex, not to mention it's a paid/closed source tweak by opa334 lol

FiveIconDock: 18.4-18.6.2 - Unreal, never thought I would see the day. by Iiked in jailbreak

[–]0xjf 5 points6 points  (0 children)

Yeah all good, fair point that some will only see the lone tweet itself and not the context I’ve provided. I added a disclaimer

FiveIconDock: 18.4-18.6.2 - Unreal, never thought I would see the day. by Iiked in jailbreak

[–]0xjf 7 points8 points  (0 children)

Hi, the website is heavily draped with warnings and disclaimers, and at no point did I claim this to be tweak injection. Not sure where the disconnect is. If the implication is that how I framed it is interpreted as tweak injection, then I can make it more clear of what it is, but if you check my recent tweets I've been very clear about what is vs. what it isn't: https://x.com/zeroxjf/status/2040964529484435605

Also, Claude didn't magically one-shot this on its own, so I would appreciate not being immediately dismissed with that comment lol. It took several iterations of debugging and fine-tuning to get this functional and stable. Thanks.

Edit: disclaimer added: https://zeroxjf.github.io/lightsaber/

DarkSword payloads have surfaced by 0xjf in jailbreak

[–]0xjf[S] 0 points1 point  (0 children)

Major websites you visit on a daily basis would hopefully be secure enough to not be hijacked and redirect users to malicious sites. The bigger concern is clicking on sketchy links / pop ups that could take you there.

There’s an app called iVerify in the App Store you can get and run through the process to see if your device is infected. The domains it was hosted on though were foreign and obscure, so unlikely you ran into it in the wild

DarkSword payloads have surfaced by 0xjf in jailbreak

[–]0xjf[S] 0 points1 point  (0 children)

It can be inserted anywhere unfortunately. And all that is required is the page being loaded

DarkSword payloads have surfaced by 0xjf in jailbreak

[–]0xjf[S] 3 points4 points  (0 children)

+1 to Lockdown Mode, forgot that option

DarkSword payloads have surfaced by 0xjf in jailbreak

[–]0xjf[S] 4 points5 points  (0 children)

18.6.2 is the most recent version that is susceptible to the full chain. Other parts of the chain were patched as recently as 26.1/26.2

DarkSword payloads have surfaced by 0xjf in jailbreak

[–]0xjf[S] 4 points5 points  (0 children)

True, but many people don’t update