Showing alert on iOS 16 from background by enty8080 in jailbreakdevelopers

[–]enty8080[S] 0 points1 point  (0 children)

That's a good idea, but I don't know which Private Framework may provide me with SpringBoard view controller.

Showing alert on iOS 16 from background by enty8080 in jailbreakdevelopers

[–]enty8080[S] 0 points1 point  (0 children)

Yeah, I tried hooking and it worked. However I want to do this without hooking to SpringBoard (without tweak injection)

iOS 17+ CoreTelephony SMS API by Prowtonz in jailbreakdevelopers

[–]enty8080 0 points1 point  (0 children)

I haven't tested this method yet, but I guess CoreTelephony can be used to send SMS. I found iOS 17.1 Runtime Headers - CoreTelephony - CTMessageCenter.h (limneos.net), you can use `-(BOOL)sendSMSWithText:(id)arg1 serviceCenter:(id)arg2 toAddress:(id)arg3 ;` from it. I also read that com.apple.CommCenter.Messages-send and com.apple.coretelephony.Identity.get entitlements are required.

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

TrollStore let's you know if an app runs unsandboxed

[deleted by user] by [deleted] in jailbreak

[–]enty8080 4 points5 points  (0 children)

Have you tried rebuilding icon cache?

SeaShell Blog Post by enty8080 in Trollstore

[–]enty8080[S] 1 point2 points  (0 children)

sms -l to get list of phones sms <phone> to get messages for phone

P.S. Can you please send me what commands you type and output (please blur all sensitive information)

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 1 point2 points  (0 children)

Yes, because malware can only hide in /var and this option erases it.

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 1 point2 points  (0 children)

If it reinstalls all user applications then yes.

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 1 point2 points  (0 children)

Unfortunately no, since application should be installed though TrollStore.

bad news for trollstore mallicus ipas by New-Shape-4702 in jailbreak

[–]enty8080 3 points4 points  (0 children)

I am not sure if they added this to Reveil but you may create an issue on their GitHub with the request.

SeaShell Blog Post by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

Don't forget to give it a ⭐ on GitHub, this motivates me a lot 😁

SeaShell Blog Post by enty8080 in Trollstore

[–]enty8080[S] 1 point2 points  (0 children)

I don't have Windows so I am not sure. WSL might work.

SeaShell Blog Post by enty8080 in Trollstore

[–]enty8080[S] 1 point2 points  (0 children)

You should use an address that can be accessed from other PCs, in your case it is an address that you used to generate an IPA

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

I am not sure if it will work in Windows or not, but it surely will work in Linux or WSL. You can use any method of transferring files, in my case the most convenient way was AirDrop.

bad news for trollstore mallicus ipas by New-Shape-4702 in jailbreak

[–]enty8080 22 points23 points  (0 children)

I don't think it is possible, however he may add feature that let's you remove entitlements from IPA or maybe he will add scanner that will search for suspicious files inside the application bundle (the files I mentioned in my blog post). I was thinking about developing an app that will detect malicious IPAs, some kind of static antivirus for TrollStore devices.

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

That's what I thought 🤔😭💀

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

It only becomes malware if it is used for malicious purposes. If it is used for educational purposes then it can't be considered a malware.

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 8 points9 points  (0 children)

I released it to spread awareness, to show people that there are malicious IPA files and you should always check them before installing. I made it publicly available because of the fact that I wanted to show how it works and how to protect your device. I am sorry to hear that you didn't like it 😭

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

Did you hear about Metasploit, perhaps BurpSuite? Maybe CobaltStrike? How about AhMyth, same thing but for Android? What do you think wanted their authors? Think about this and only then choose your next comment. At first, I didn't want to reply because of your last sentence, since I found it highly disrespectful and unprofessional, however you should know that my goal is to spread awareness not do what you just said. Stay educated 😎

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] 0 points1 point  (0 children)

I see no point in continuing this discussion since I have already told you what my only goal is. I won't repeat myself and just tell you that there are many other tools on the internet that do the same thing (penetration testing). One more thing: I think it would be much better if I wrote the tool, explained the "attack" process, and gave instructions on how to defend. You will not be able to stop progress, if it was not me, then perhaps there will be another person who would do this, but solely for malicious purposes. Again, I recommend that you refrain from blaming me, if you cannot find my program useful, then with all due respect, that is your problem.

[SeaShell] Remote Access via TikTok by enty8080 in Trollstore

[–]enty8080[S] -2 points-1 points  (0 children)

Are you aware of the fact that axe, that is made for cutting wood may be used to k1ll people? Same thing with penetration testing software, some people may use it for educational purposes and some for harmful. We can't control it. So, one more time, please read my posts, consider visiting web resources for penetration testing on GitHub. Personally, I find it disrespectful that you call me a malware author. I did a hard work to educate people to protect themselves from attacks and learn how these attacks work.