-
Posts
291 -
Joined
-
Last visited
Everything posted by Elreys
-
Help/Support Best iOS Setup to work with LLDB and IDA
Elreys replied to Elreys's topic in Help & Support
Hi DiDa thanks, you mean ldid -s i tried also your online tool thin and remove aslr, but every time i try to start the app , the crash? I forget to tell you my Ipad ist Air 1. I see the explanation shows 2 Method with ldid -s are they big difference? -
Hi Guys So I like to understand exactly what us happen with the new App debug technic , first my Technical info: iOS 8.3/4 Debugserver iosgods Lldb iosgods Appsync unified LinkEditor aslr tool jack I can tell you with my old System I create successfully I tweak for the Spider-Man Game , Ida address works fine, with lldb and removing ASLR also without problem. So now my questions? Why it's impossible to remove ASLR with the new GameApp ? IDA address are completely different, I know if I thin the app sometimes works fine. But generally please help me to understand what changed really, I'm a little bit confuse with Armv7 and arm64 ? Are all App 64 if they are downloaded and installed to IPad e.x? I hope you can follow me question Thanks ELREYS
-
Big Issues Guys, after i downgrade the Substrate i have probelm to attach my Game, with LLDB segment fault 11, how i can do a rollback?
-
hi
-
Hi Guys, 1. I see a lot of Games they are impossible to disable the ASLR without a crash, so i read one post about a rebase method in IDA, how i can do that in IDA, did you have a tutorial or more information about this, 2. I read also that exists on method to find the right offset if i subtract GG address, but how i can do that, did you have again a tutorial or more information. Thanks Guys Have a good Hack days;)
-
Help/Support Disassembled code in IDA does not match that in GDB/LLDB
Elreys replied to infernusdoleo's topic in Help & Support
Hey infernusdoleo , how you did a rebase in IDA Pro? I have the same problem on my Reversed App, wrong offset and wrong llldb address please if you have time write me back, Thanks ELREYS -
ok
-
thks
-
good
-
????
-
thanks
-
thks
-
thks
-
Hi Guys, Yesterday i tried to crack a new game named Space Marshals, first with Clutch and Rasticrack but in booth tool the game was not listed, after this a decide to download the ipa from appaddict site. The installation was succesfull on my Ipad 2 and my Iphone 6 Plus, I used GamePlayer i found the Ammo adress i changed, with and works fine, but the gm adress was the wrong in IDA, so i thinked ASLR enabled after this i tried to disable the ASLR with HackJack Tool but unsuccesfully, i tried also python script from [http://sskaje.me] the scripts works he disabled correct all the PIE, but after this the game wont start .... So now i need you HELP GUYS:) Thanks for your Support
-
Hi Guys, i think its good if we can create a list with all server side Game, or better, a list with specification what are point that we need to check to know if a game is a server side or not, it will help us to dont wast a lot of time, with server side Game, what you think ? @@DiDA its this possible or not ? Thanks ELREYS
-
Help/Support [THEOS] Preference Bundle Code Injection Not Working?
Elreys replied to Elreys's topic in Help & Support
Hi DiDA i check the folde avery single file, i found one interesting differetnt beetween my Plist struct and this of Zahir Folder, but this are generate auotmatically from $THEOS. and an other difference are in the structure, he has one folder more there as me. http://imgur.com/4xLEkPz My Plist content: dungeon.plist { Filter = { Bundles = ( "com.orca.dungeonm" ); }; } Zahir Plist content: dh4.plist <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Filter</key> <dict> <key>Bundles</key> <array> <string>com.gameloft.DungeonHunter4</string> </array> </dict> </dict> </plist>