Jump to content

TRCiOS

Newbie
  • Posts

    3
  • Joined

  • Last visited

Profile Information

  • iDevice
    iPhone 6
  • iOS Version
    8
  • Jailbroken
    No

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

TRCiOS's Achievements

Newbie

Newbie (1/14)

  • 2 Years In
  • One Year In
  • One Month Later
  • Week One Done
  • First Post

Recent Badges

1

Reputation

  1. nope, it's an older exploit for 13.4.1 and below. You can find the writeup here https://blog.siguza.net/psychicpaper/#3-the-exploit . It allows for a sandbox escape and any arbitrary entitlements. I'm exploiting 8.x 64 bits and my Kernel Exploit needs a sandbox escape, this one is perfect, but Sideloadly overwrites the "exploited" entitlements I gave it before signing. The new exploit is a Coretrust exploit (a counterpart of AMFI) and it's not _yet_ exploitable through sideloading means.
  2. Thanks for answering. I currently reproduce the exploit with a free cert and a mobileprovision I extracted from XCode (7 days signing, free account, whatever random XCode ents uses) then I use codesign with custom entitlements (codesign -f -s “cert” —entitlements=psychicpaperents.plist app.app and finally install with ideviceinstaller. Psychic paper gives you arbitrary entitlements due to different entitlement parsers in iOS. I understand this is pretty niche, but would be very helpful for legacy exploitation, since asking non-savvy users to do all of this just for a sandbox escape isn’t very friendly.
  3. @Rook Would it be possible to add a function to specify custom entitlements? Trying to exploit Psychic Paper and the IPA doesn't retain the exploited entitlements from ldid before using sideloadly (unless I'm doing something wrong?)
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines