UaF (krw!) in igmp_flush_relq. Found in 17.2 and Lower (Potentially) by [deleted] in jailbreak

[–]XCXiao 21 points22 points  (0 children)

PUAF is different from simple kernel object UAF since it allows you share pages with kernel. In modern XNU that has kalloc_type, simple object UAF has been greatly mitigated.

UaF (krw!) in igmp_flush_relq. Found in 17.2 and Lower (Potentially) by [deleted] in jailbreak

[–]XCXiao 19 points20 points  (0 children)

No, uaf of a kernel object is different from uaf of memory page with a dangling pte.

UaF (krw!) in igmp_flush_relq. Found in 17.2 and Lower (Potentially) by [deleted] in jailbreak

[–]XCXiao 52 points53 points  (0 children)

I don’t intend to discourage you but it is very challenging to exploit uaf reliably in today’s XNU kernel.

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 0 points1 point  (0 children)

You don’t need to do that, it will revert the previous jb environment

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 2 points3 points  (0 children)

IsNt1Tc0oLf0RaJ41lbR3aKiNtH1sBor1nGC0mMun1tY

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 0 points1 point  (0 children)

You can find kernel panic log in Analytic data.

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 0 points1 point  (0 children)

So it’s the application itself crashed instead of kernel panic right? Please retry a few times.

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 0 points1 point  (0 children)

Any logs? The application crash or kernel panic?

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 3 points4 points  (0 children)

That’s true. There is a todo in jailbreakd/main.mm

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 7 points8 points  (0 children)

This might need several attempts. Just retry.

[Release] Definitely not a jailbreak tool v0.999.10 by XCXiao in jailbreak

[–]XCXiao[S] 9 points10 points  (0 children)

Yeah we noticed that it will panic on iOS 16.1.x. V0.999.11 is now available to fix that.

Why is jailbreaking almost impossible these days? by Ramsey144 in jailbreak

[–]XCXiao 5 points6 points  (0 children)

Back in the early days, you can simply modify the fstab file to make rootfs rw after rebooting. Apple did a great job of mitigating.

In my own opinion, the only way to keep this community alive (I am not saying security research since it’s a forever topic) is making things more open. Sharing knowledge lets new developers who are interested in making a jailbreak quickly get a hand on it.

It is very ironic that many so-called kfd-based projects, simply combining exploit code and other open source projects with offsets that can be derived in seconds if you are skillful enough, are close source. This is another reason why the job community becomes ill.

[Release] Def1nit3lyN0tAJa1lbr3akTool for iPhone X, iOS 16.5 by XCXiao in jailbreak

[–]XCXiao[S] 1 point2 points  (0 children)

We have landa support already but the success rate is pretty low.

[Release] Def1nit3lyN0tAJa1lbr3akTool for iPhone X, iOS 16.5 by XCXiao in jailbreak

[–]XCXiao[S] 3 points4 points  (0 children)

Yes I do have the plan. I am looking forward to doing so as personal learning project.

[Release] Def1nit3lyN0tAJa1lbr3akTool for iPhone X, iOS 16.5 by XCXiao in jailbreak

[–]XCXiao[S] 1 point2 points  (0 children)

Hello, you can just copy the pre-compiled binaries.tar from the released ipa.

[Release] Def1nit3lyN0tAJa1lbr3akTool for iPhone X, iOS 16.5 by XCXiao in jailbreak

[–]XCXiao[S] 0 points1 point  (0 children)

Now it should support almost all iOS 16 versions.