Jump to content
  • Sky
  • Mint
  • Azure
  • Indigo
  • Blueberry
  • Blackcurrant
  • Watermelon
  • Strawberry
  • Pomegranate
  • Ruby Red
  • Orange
  • Banana
  • Apple
  • Emerald
  • Teal
  • Chocolate
  • Slate
  • Midnight
  • Maastricht
  • Charcoal
  • Matte Black
Sign in to follow this  
ZAROS

General Discussion about Checkm8 bootrom exploit & Checkra1n

6 posts in this topic

Recommended Posts

Hello guys,

 

I'd like to share some thoughts on the upcoming jailbreak (most-likely Checkra1n) based on the Checkm8 bootrom exploit affecting A7-A11 devices.

First of all, from my researches I've found some information stating that Checkra1n will be a thetered jailbreak, for those who do not know, this mean you'll need a computer every time you need to reboot your iDevice.

And from some articles, it mentions that we'll be able to downgrade or upgrade to different iOS versions without requiring Shsh Blobs, kind of an digital signature from Apple.

 

I've been thinking, and this is where I'd like some opinions and thoughts from the community,

Since Checkra1n will most-likely be a thetered jailbreak, but should allow you to switch to another iOS version, 

Do you guys think it'd be possible to jailbreak using Checkra1n, switch to the iOS version to iOS 12.4 and then jailbreak with Unc0ver, in the goal of achieving a semi-unthetered jailbreak?

 

I'd like some thoughts on this topic which aren't mine!

 

Thank you all.

 

 

  • Like 1

Share this post


Link to post
Share on other sites

Tbh this whole situation is astonishing. Know that we’ll have more freedom with our devices & being able to accomplish anything we want within it is hard to believe but yet it’s near!

Share this post


Link to post
Share on other sites

 

10 minutes ago, ZAROS said:

Do you guys think it'd be possible to jailbreak using Checkra1n, switch to the iOS version to iOS 12.4 and then jailbreak with Unc0ver, in the goal of achieving a semi-unthetered jailbreak?

I think you would still need to have your PC in order to boot up your device since you downgraded with Checkm8 and not via official Apple methods.

  • Like 1

Share this post


Link to post
Share on other sites
6 minutes ago, DADi said:

 

I think you would still need to have your PC in order to boot up your device since you downgraded with Checkm8 and not via official Apple methods.

I’ve considered that possibility, but since we’d have been to switch iOS versions without shsh restrictions I really wonder if whether or not it’d remain without the exploit. But then, will we be able to reboot the device normally without the exploit once it has been done for a first time and thus, without resetting it?...

Share this post


Link to post
Share on other sites
Just now, ZAROS said:

I’ve considered that possibility, but since we’d have been to switch iOS versions without shsh restrictions I really wonder if whether or not it’d remain without the exploit. But then, will we be able to reboot the device normally without the exploit once it has been done for a first time and thus, without resetting it?...

Another thing I have heard is that you could potentially dual boot two iOS versions on the same device. Meaning you can have one Jailbroken and the other not which could potentially mean if you ever needed to reboot into the normal iOS without a PC, you perhaps could.

I'm not really informed about Checkm8 so don't take everything I say as true.

Share this post


Link to post
Share on other sites

UPDATE: I've found an article posted by X site (not going to source or link as to not break the forum rules), but I've found an interesting dialogue between axi0mX and two other persons. He shares some more insights concerning the Checkm8 exploit and it has answered my questions nicely. I'll share the dialogues in spoilers.

 

Here's the main part; answers to my questions.

Spoiler

Thomas Reed (Malwarebytes): Can this be used to install any other code, any other programs that you wanted, with root-level permissions, so that you could install malware through this?

axi0mX: The correct answer is "It depends." When you decide to jailbreak your phone using this exploit, you can customize what Apple is doing. Apple has some advanced protections. A lot of their system is set up so that you don't have malware running. If you decide to jailbreak, you're going to get rid of some of the protections. Some people might make a jailbreak that keeps a lot of those protections, but it also allows you to remove protections. Other people might remove all protections altogether.

The jailbreak that you can make with this exploit always requires you to exploit the device fresh after reboot. So if you don't use the exploit, your device will only boot to a clean install [version] of iOS. It's not like you can install malware once and then have it stay forever if you're not using the exploit because iOS has protections against that.

More about persistence

Dan Goodin (Ars): Somebody could use Checkm8 to install a keylogger on a fully up-to-date iOS device, but the second that they rebooted the phone, that keylogger would be gone, right?

axi0mX: Correct. Or it wouldn't work. They left the keylogger there, but iOS would just say: "This app is not authorized to run on this phone, so I'm not going to run it."

 

Here's the full "interview"

Spoiler

Often, when new iOS jailbreaks become public, the event is bittersweet. The exploit allowing people to bypass restrictions Apple puts into the mobile operating system allows hobbyists and researchers to customize their devices and gain valuable insights that may be peeking under the covers. That benefit is countered by the threat that the same jailbreak will give hackers a new way to install malware or unlock iPhones that are lost, stolen, or confiscated by unscrupulous authorities.

Friday saw the release of Checkm8. Unlike just about every jailbreak exploit released in the past nine years, it targets the iOS bootrom, which contains the very first code that's executed when an iDevice is turned on. Because the bootrom is contained in read-only memory inside a chip, jailbreak vulnerabilities that reside there can't be patched.

Checkm8 was developed by a hacker who uses the handle axi0mX. He's the developer of another jailbreak-enabling exploit called alloc8 that was released in 2017. Because it was the first known iOS bootrom exploit in seven years, it was of intense interest to researchers, but it worked only on the iPhone 3GS, which was seven years old by the time alloc8 went public. The limitation gave the exploit little practical application.

 

Checkm8 is different. It works on 11 generations of iPhones, from the 4S to the X. While it doesn't work on newer devices, Checkm8 can jailbreak hundreds of millions of devices in use today. And because the bootrom can't be updated after the device is manufactured, Checkm8 will be able to jailbreak in perpetuity.

I wanted to learn how Checkm8 will shape the iPhone experience—particularly as it relates to security—so I spoke at length with axi0mX on Friday. Thomas Reed, director of Mac offerings at security firm Malwarebytes, joined me. The takeaways from the long-ranging interview are:

  • Checkm8 requires physical access to the phone. It can't be remotely executed, even if combined with other exploits
  • The exploit allows only tethered jailbreaks, meaning it lacks persistence. The exploit must be run each time an iDevice boots.
  • Checkm8 doesn't bypass the protections offered by the Secure Enclave and Touch ID.
  • All of the above means people will be able to use Checkm8 to install malware only under very limited circumstances. The above also means that Checkm8 is unlikely to make it easier for people who find, steal or confiscate a vulnerable iPhone, but don't have the unlock PIN, to access the data stored on it.
  • Checkm8 is going to benefit researchers, hobbyists, and hackers by providing a way not seen in almost a decade to access the lowest levels of iDevices.

Read on to find out, in axi0mX's own words, why he believes this is the case:

Dan Goodin (Ars): Can we start with the broad details? Can you describe at a high level what Checkm8 is, or what it is not?

axi0mX: It is an exploit, and that means it can get around the protection that Apple built into the bootrom of most recent iPhones and iPads. It can compromise it so that you can execute any code at the bootrom level that you want. That is something that used to be common years ago, during the days of the first iPhone and iPhone 3G and iPhone 4. There were bootrom exploits [then] so that people could jailbreak their phone through the bootrom and that later would not be possible.

The last bootrom exploit that was released was for iPhone 4 back in 2010, I believe by Geohot. After that, it was not possible to exploit an iPhone at this level. All the jailbreaks [that] were done later on [happened] once the operating system boots. The reason that bootrom is special is it's part of the chip that Apple made for the phone. So whatever code is put there in the factory is going to be there for the rest of its life. So if there is any vulnerability inside the bootrom, it cannot be patched.

Persistence and Secure Enclave

Dan Goodin (Ars): When we talk about things that aren't patchable, we're talking about the bug. What about the change to the device itself? Is that permanent, or once the phone is rebooted, does it go back to its original state?

axi0mX: This exploit works only in memory, so it doesn't have anything that persists after reboot. Once you reboot the phone... then your phone is back to an unexploited state. That doesn't mean that you can't do other things because you have full control of the device that would modify things. But the exploit itself does not actually perform any changes. It's all until you reboot the device.

Dan Goodin (Ars): In a scenario where either police or a thief obtains a vulnerable phone but doesn't have an unlock PIN, are they going to be helped in any way by this exploit? Does this exploit allow them to access parts of this phone or do things with this phone that they couldn't otherwise do?

axi0mX: The answer is "It depends." Before Apple introduced the Secure Enclave and Touch ID in 2013, you didn't have advanced security protections. So, for example, the [San Bernardino gun man's] phone that was famously unlocked [by the FBI]—the iPhone 5c— that didn't have Secure Enclave. So in that case, this vulnerability would allow you to very quickly get the PIN and get access to all the data. But for pretty much all current phones, from iPhone 6 to iPhone 8, there is a Secure Enclave that protects your data if you don't have the PIN.

My exploit does not affect the Secure Enclave at all. It only allows you to get code execution on the device. It doesn't help you boot towards the PIN because that is protected by a separate system. But for older devices, which have been deprecated for a while now, for those devices like the iPhone 5, there is not a separate system, so in that case you could be able to [access data] quickly [without an unlock PIN].

Dan Goodin (Ars): So this exploit isn't going to be of much benefit to a person who has that device [with Secure Enclave] but does not have the PIN, right?

axi0mX: If by benefit you mean accessing your data, then yes, that is correct. But it's still possible they might have other goals than accessing your data, and in that case, it's possible they would get some benefit.

Dan Goodin (Ars): Are you talking about creating some sort of backdoor that once the owner puts in a PIN it would get sent to the attacker, or a scenario like that?

axi0mX: If, say, for example, you leave your phone in a hotel room, it's possible that someone did something to your phone that causes it to send all of the information to some bad actor's computer.

Dan Goodin (Ars): And that would happen after the legitimate owner returned and entered their PIN?

axi0mX: Yes, but that's not really a scenario that I would worry much about, because attackers at that level… would be more likely to get you to go to a bad webpage or connect to a bad Wi-Fi hotspot in a remote exploit scenario. Attackers don't like to be close. They want to be in the distance and hidden.

In this case [involving Checkm8], they would have to physically hold your device in their hand and would have to connect a cable to it. It requires access that most attackers would like to avoid.

This attack does not work remotely

Dan Goodin (Ars): How likely or feasible is it for an attacker to chain Checkm8 to some other exploit to devise remote attacks?

axi0mX: It's impossible. This attack does not work remotely. You have to have a cable connected to your device and put your device into DFU mode, and that requires you to hold buttons for a couple seconds in a correct way. It's something that most people have never used. There is no feasible scenario where someone would be able to use this attack remotely.

If you want to talk [about] really hypothetical situations, if you're a jailbreaker and you're trying to use your exploit on your own computer and somehow your computer is compromised, it's possible someone on your computer is going to deliver a different version of the exploit that does more stuff than what you want to do. But that is not a scenario that's going to apply to most people. That is a scenario that is simply not practical.

Thomas Reed (Malwarebytes): Does the bootrom code that's loaded into RAM get modified by the exploit, or is that not a requirement? Through this vulnerability, would you need to make modifications to the bootrom code that's loaded into RAM, or would that not be a factor? Would that not be involved in the way the exploit works? I'm under the assumption that some of the code from the bootrom is loaded into RAM when it's executed. Maybe I'm wrong about that.

axi0mX: The correct answer is that it's complicated. The code that is used by the bootrom is all in read-only memory. It doesn't need to get copied in order for it to be used. In order for my device to be able to do what I want, I want to also inject some custom code. In that case, I can't write my code into the read-only memory, so my only option is to write it into RAM or, in this case, SRAM—which is the low-level memory that is used by the bootrom—and then have my injected code live in this small space. But the actual bootrom code itself does not get copied in there. It's only the things that I added to my exploit.

Thomas Reed (Malwarebytes): Can this be used to install any other code, any other programs that you wanted, with root-level permissions, so that you could install malware through this?

axi0mX: The correct answer is "It depends." When you decide to jailbreak your phone using this exploit, you can customize what Apple is doing. Apple has some advanced protections. A lot of their system is set up so that you don't have malware running. If you decide to jailbreak, you're going to get rid of some of the protections. Some people might make a jailbreak that keeps a lot of those protections, but it also allows you to remove protections. Other people might remove all protections altogether.

The jailbreak that you can make with this exploit always requires you to exploit the device fresh after reboot. So if you don't use the exploit, your device will only boot to a clean install [version] of iOS. It's not like you can install malware once and then have it stay forever if you're not using the exploit because iOS has protections against that.

More about persistence

Dan Goodin (Ars): Somebody could use Checkm8 to install a keylogger on a fully up-to-date iOS device, but the second that they rebooted the phone, that keylogger would be gone, right?

axi0mX: Correct. Or it wouldn't work. They left the keylogger there, but iOS would just say: "This app is not authorized to run on this phone, so I'm not going to run it."

iOS devices have what's called a secure bootchain. Starting from the bootrom, every single step is checked by the previous stage so that it is trusted. It always has a signature verified so that the phone only allows you to run software that is meant to be running. If you choose to break that chain of trust and run software that you want to run, then exactly what you do will determine what else can happen. If you choose to not break the chain of trust and you simply use your phone the way that Apple wants you to use it, without jailbreaking it, then this chain of trust is secure. So malware will not be able to get around it the next time you boot your phone, because you are relying on the chain of trust.

You cannot actually persist using this exploit. The only way that you can break the chain of trust is if you manually do it every boot. So you have to be in DFU mode when you boot, and then you have to connect a cable to your phone, and then you have to run the exploit in order to jailbreak your phone. At that point you can do whatever you want. But in no case will that be the case if you… just boot normally. In that sense, it is not persistent.

Thomas Reed (Malwarebytes): In the case of a company like Cellebrite or Greyshift getting your device and they want to capture data from it, as I understand it if you don't have the key—which you wouldn't because it's in the Secure Enclave—a lot of the data is going to be encrypted, and it's not going to be accessible. It sounds like Checkm8 really wouldn't be of much use to them. Is that correct, or would there be some things that they could do with it?

 

axi0mX: As a standalone exploit, the answer is "No, they can't do much with it." But it's possible, perhaps likely, that they would use more than one exploit—they have an exploit chain—in order to do what they want to do. And in that case, they could use this one instead of another one that they have because maybe it's faster, maybe they don't have to worry about protecting it. So it's possible that this could serve as a step that they take in order to crack the PIN code.

This does not give them anything that would directly be able to guess the PIN code without other exploits. I don't know what they have. It's possible that they just have one thing that they use, and in that case, they probably would not use this in any way. But it's also possible that this could replace one of the bugs that they use in order to do whatever they're doing.

Thomas Reed (Malwarebytes): I think the appeal of that would be that it's something that Apple can't patch. If they had an exploit chain that would give them access to a lot of devices.

Dan Goodin (Ars): So this is more of an incremental development [for Cellebrite and Grayshift] as opposed to a game changer?

axi0mX: I don't think that they can do anything today with Checkm8 that they couldn't do yesterday [without Checkm8]. It's just that yesterday maybe they would do it a slightly different way. I don't think they gain anything from this release.

Dan Goodin (Ars): What is it about the newer chipsets that prevents Checkm8 from working? Is it possible someone could tweak Checkm8 to make it work on these newer chipsets?

axi0mX: I think it's unlikely. There were changes to make [newer chipsets] not exploitable. All I know is I can't get it to work. For me, it's not something that I can do. What I do involves using multiple bugs. Some that are not serious might be required to access other bugs that are more serious. Because Apple patched some bugs in the newer phones, it can no longer be exploited as far as I know.

Dan Goodin (Ars): So you don't see much chance that somebody is going to chain Checkm8 to something else and be able to achieve the same result with newer iPhones?

axi0mX: I can't say it's impossible, and there are some really good hackers out there. It's always possible. I think it's unlikely. I know I couldn't do it. The chance is always there, but I think it's very unlikely.

A jailbreaking renaissance

axi0mX: If you have a few minutes, I have more things that you may find interesting:

Apple has been making jailbreaks very difficult. Things were much better a couple years ago. Before about 2016 there were regular jailbreaks that worked well and a lot of people could jailbreak your phone. That changed with iOS 9, and jailbreaks no longer had persistence, and they were not even reliable. So you would have to try a couple of steps before the jailbreak worked. Jailbreaking became inaccessible to people because you couldn't get a phone, even an older phone, and jailbreak it, and customize it, and make software that changes things about the phone. People were saying "jailbreaking is dead" because it's not what it used to be.

Now, the reason [Checkm8] is so great for iOS jailbreakers is people will be able to just get an iPhone X and then be able to jailbreak it on any [iOS] version. That is great because that means anyone can decide to jailbreak and sit down at their computer, connect their phone, and be jailbroken in not much time.

Now, what I released today doesn't allow you to jailbreak your phone completely with Cydia and other things you would expect from a jailbreak, but that will come soon. And you will be able to jailbreak your phone pretty much anytime you want and on the latest version. And that latest version part is also important, because in the past when people were jailbreaking phones, they had to stay on an older version of the operating system in order for it to have the vulnerabilities that they were using to jailbreak.

Fun and safe

axi0mX: But now, with this technique, you will be able to use the latest version of iOS and still jailbreak your phone because you can run any version of iOS you want, so you can always have the latest security patches. You don't have to stay on an older version that has security vulnerabilities just so you can jailbreak, and you won't have to wait until a jailbreak is available. This is going to make jailbreaking a lot more accessible and a lot safer for everyone. That is one of the reasons I am very excited about this work.

A small group of people enjoy jailbreaking, and they do it for fun because they like to tinker with their phone, or change the way it looks, or hack it. But there's another group of people where, say, there's an incident where you believe your email was hacked and you want to find out what happened. In that case you want to be able to look at the storage on your phone and see what kind of artifact do you get, and what kind of log files, and analyze what's there to see if you can identify what happened. And if you were, say, the victim of an attempted hack, or maybe if the hack was successful, in order to get this forensic copy you need to be able to access the storage on a low level that's not possible unless you jailbreak your phone.

In the past couple years, you couldn't just jailbreak the phone on the latest version of iOS if you needed to for any reason. You would have to let the phone sit until it was finally jailbreakable and only then would you be able to do it. That changes now. If you need to see what's happening on your phone, you can just jailbreak it one time with Checkm8 and then get a full forensic copy of your data and your log files and history. That's one scenario.

Monitoring in real time

axi0mX: The other scenario is sometimes people want to look for attackers or things happening in real time. Say you go to a website [and] your phone will send traffic to various webservers and various webservers will send back files. If you are doing tracking in real time, you can see what's happening. If you want to, say, explore what happens when your phone goes to a website, you can't do that if you don't have a jailbreak because Apple doesn't give you the specific permissions that you need to see things happening at such a low level on your phone.

Now, anytime you want, you will be able to jailbreak your phone, either one time or every single time, you will be able to analyze what's happening in real time. Say you have traffic that is connecting to your phone from some country you don't think should be connecting, like Russia, then you would know that something is happening right away. And you would be able to see it and block it. For people who do research… it was impossible to do that on iOS. You would need to have your own custom jailbreak, or you would have to have an old version of iOS, or you would have to wait until a jailbreak is available.

The things I just mentioned are things that I'm quite excited about, because the iOS jailbreak community is great and they're going to benefit from this. It's also going to help people who want to research either the security of iOS or the security of apps they're using. All of that is going to benefit for the next couple of years.

 

If anyone digs a minimum on Google, they might find themselves successful at finding the original blog, but this is pretty much the whole content of the conversation.

I hope you guys enjoy it as much as I have!

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic... Posting Guidelines

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Sign in to follow this  

  • Our picks

    • Metal Slug Infinity: Idle Game v1.4.5 - [ Gold Increase & More ]
      Modded/Hacked App: Metal Slug Infinity: Idle Game By ekkorr
      Bundle ID: com.ekkorr.msf
      iTunes Store Link: https://itunes.apple.com/us/app/metal-slug-infinity-idle-game/id1394394348?mt=8&uo=4&at=1010lce4
       

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate (from Cydia).
      - PreferenceLoader (from Cydia).


      Hack Features:
      - Gold Increase
      - No Skills CoolDown
      - x3 Battle Speed
      - x5 Battle Speed

      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app. This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Non-Jailbroken & No Jailbreak required hack(s): 


      Hack Download Link:

      Hidden Content

      Download Hack








      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above.
      STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice.
      STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it.
      STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen.
      STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game.
      STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @DanYal


      Cheat Video/Screenshots:

      N/A
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 564 replies
    • Boxing Star v1.9.4 - [ x Player Damage & God Mode ]
      Modded/Hacked App: Boxing Star By Four Thirty Three
      Bundle ID: com.ftt.boxingstar.gl.ios
      iTunes Store Link: https://itunes.apple.com/us/app/boxing-star/id1241887528?mt=8&uo=4&at=1010lce4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate (from Cydia).
      - PreferenceLoader (from Cydia).


      Hack Features:
      - x Player Damage - x1 - 1000
      - God Mode

      All features are unlinked and only for player, you!
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 1,086 replies
    • Kingdom Story: Brave Legion v2.47.0 - [ x Player Damage & Defense ]
      Modded/Hacked App: Kingdom Story: Brave Legion By NHN Corp.
      Bundle ID: com.nhnent.SK10392
      iTunes Store Link: https://apps.apple.com/us/app/kingdom-story-brave-legion/id1159292704?uo=4&at=1010lce4

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate or Substitute.
      - PreferenceLoader (from Cydia or Sileo).


      Hack Features:
      - x Player Damage - x1 - 20
      - x Player Defense - x1 - 20

      All features are unlinked and only for player, you!

      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app. This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      iOS Hack Download Link:

      Hidden Content
      Download Hack







      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above.
      STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice.
      STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it.
      STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen.
      STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game.
      STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @DanYal


      Cheat Video/Screenshots:

      N/A
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 275 replies
    • ELCHRONICLE v1.8.6 - [ x Player Damage & Defense ]
      Modded/Hacked App: ELCHRONICLE By Cravemob Co.,Ltd
      Bundle ID: net.cravemob.elc.rel
      iTunes Store Link: https://apps.apple.com/us/app/elchronicle/id1303380370?uo=4&at=1010lce4

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate or Substitute.
      - PreferenceLoader (from Cydia or Sileo).


      Hack Features:
      - x Player Damage - x1 - 100
      - x Player Defense - x1 - 100

      All features are unlinked and only for player, you!

      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app. This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      iOS Hack Download Link:

      Hidden Content
      Download Hack







      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above.
      STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice.
      STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it.
      STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen.
      STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game.
      STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @QTuTi
      - @DanYal

       


      Cheat Video/Screenshots:

      N/A
        • Winner
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 193 replies
    • Last Day Rules: Survival v1.2 - [ No Recoil & More ]
      Modded/Hacked App: Last Day Rules: Survival By HK HERO ENTERTAINMENT CO.
      Bundle ID: com.herogame.ios.lastdayrules
      iTunes Store Link: https://apps.apple.com/us/app/last-day-rules-survival/id1463021419?uo=4&at=1010lce4

      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.


      Hack Features:
      - No Recoil
      - Walk Under Water
      - Hide Tree
      - Hide Grass

      This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Jailbreak required hack(s): https://iosgods.com/topic/117660-last-day-rules-survival-v12-no-recoil-more/


      iOS Hack Download Link:

      Hidden Content
      Download iOSGods App







      PC Installation Instructions:
      STEP 1: If necessary, uninstall the app if you have it installed on your iDevice. Some hacked IPAs will install as a duplicate app. Make sure to back it up so you don't lose your progress.
      STEP 2: Download the pre-hacked .IPA file from the link above to your computer.
      STEP 3: Download Cydia Impactor and extract the archive.
      STEP 4: Open/Run Cydia Impactor on your computer then connect your iOS Device and wait until your device name shows up on Cydia Impactor.
      STEP 5: Once your iDevice appears, drag the modded .IPA file you downloaded and drop it inside the Cydia Impactor application.
      STEP 6: You will now be asked to enter your iTunes/Apple ID email login & then your password. Go ahead and enter the required information..
      STEP 7: Wait for Cydia Impactor to finish sideloading/installing the hacked IPA.
      STEP 8: Once the installation is complete and you see the app on your Home Screen, you will now need to go to Settings -> General -> Profiles & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 9: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.
      NOTE: For free Apple Developer accounts you will need to repeat this process every 7 days. Using a disposable Apple ID for this process is suggested but not required. Jailbroken iDevices can skip using Cydia Impactor and just install the IPA mod with AppSync & IPA Installer (or alternatives) from Cydia. If you have any questions or problems, read our Cydia Impactor topic and if you don't find a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @DADi


      Cheat Video/Screenshots:

      N/A
        • Winner
        • Agree
        • Thanks
        • Like
      • 9 replies
    • Angry Birds Transformers v1.49.6 - Unlimited Currencies & More ]
      Modded/Hacked App: Angry Birds Transformers By Rovio Entertainment Oyj
      Bundle ID: com.rovio.angrybirdstransformers
      iTunes Store Link: https://apps.apple.com/us/app/angry-birds-transformers/id869231055?uo=4&at=1010lce4

      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.


      Hack Features:
      - Coin Multiplier - Destory materials to trigger the multiplier.
      - Pig Multiplier - Kill pigs to trigger the multiplier.
      - No Revive Cost
      - Free Instant Upgrades - Instantly upgrading a transformer will cost 0 gems.
      - Buy Missing Coins for Free
      - Buy Missing Pigs for Free
      - Buy Missing Tokens for Free
      - Buy Missing Materials for Free
      - Free Skipping
      - Achievement Reward Hack - Earn 65k gems from collecting an achievement.

      This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.
        • Like
      • 4 replies
    • Last Cloudia ラストクラウディア v1.2.18 - [ God Mode & Unlimited MP ]
      Modded/Hacked App: ラストクラウディア By AIDIS Inc.
      Bundle ID: com.aidis.lastcloudiajpn
      iTunes Store Link: https://apps.apple.com/jp/app/ラストクラウディア/id1439772862?uo=4&at=1010lce4

      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.


      Hack Features:
      - God Mode
      - Unlimited MP

      This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Jailbreak required hack(s): https://iosgods.com/topic/115192-last-cloudia-japan-ラストクラウディア-v1216-x-player-damage-defense/?tab=comments#comment-3534612


      iOS Hack Download Link:

      Hidden Content
      Download iOSGods App







      PC Installation Instructions:
      STEP 1: If necessary, uninstall the app if you have it installed on your iDevice. Some hacked IPAs will install as a duplicate app. Make sure to back it up so you don't lose your progress.
      STEP 2: Download the pre-hacked .IPA file from the link above to your computer.
      STEP 3: Download Cydia Impactor and extract the archive.
      STEP 4: Open/Run Cydia Impactor on your computer then connect your iOS Device and wait until your device name shows up on Cydia Impactor.
      STEP 5: Once your iDevice appears, drag the modded .IPA file you downloaded and drop it inside the Cydia Impactor application.
      STEP 6: You will now be asked to enter your iTunes/Apple ID email login & then your password. Go ahead and enter the required information..
      STEP 7: Wait for Cydia Impactor to finish sideloading/installing the hacked IPA.
      STEP 8: Once the installation is complete and you see the app on your Home Screen, you will now need to go to Settings -> General -> Profiles & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 9: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.
      NOTE: For free Apple Developer accounts you will need to repeat this process every 7 days. Using a disposable Apple ID for this process is suggested but not required. Jailbroken iDevices can skip using Cydia Impactor and just install the IPA mod with AppSync & IPA Installer (or alternatives) from Cydia. If you have any questions or problems, read our Cydia Impactor topic and if you don't find a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @DanYal


      Cheat Video/Screenshots:

      N/A
        • Thanks
        • Like
      • 15 replies
    • DomiNations Global v8.815.815  - [  Crowns, Gold, Food Freeze & More ]
      Modded/Hacked App: DomiNations By NEXON M Inc.
      Bundle ID: com.nexonm.dominations
      iTunes Link: https://itunes.apple.com/us/app/dominations/id922558758?mt=8&uo=4&at=1010lce4


      Hack Features:
      - Freeze Crowns
      - Freeze Oil
      - Freeze Food
      - Freeze Gold
      - No Citizens Cost
      - 0 Crown Cost Peace

      This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Jailbroken version of this hack: https://iosgods.com/topic/50401-ultrahack-dominations-v5580580-40-cheats-iosgods-exclusive/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/20-dominations-club/
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 1,689 replies
    • DomiNation Asia By NEXON Company v8.815.815 - [ Crowns, Gold, Food Freezer ]
      Modded/Hacked App: ドミネーションズ -文明創造- (DomiNations) By NEXON Company
      Bundle ID: com.nexon.dominations.asia
      iTunes Store Link: https://itunes.apple.com/jp/app/ドミネーションズ-文明創造-dominations/id1012778321?mt=8&uo=4&at=1010lce4
       

      Mod Requirements:
      - Jailbroken or Non-Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.


      Hack Features:
      - Freeze Crowns
      - Freeze Oil
      - Freeze Food
      - Freeze Gold
      - No Citizens Cost
      - 0 Crown Cost Peace

      This hack only works on x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 1,300 replies
    • Last Day Rules: Survival v1.2 - [ No Recoil & More ]
      Modded/Hacked App: Last Day Rules: Survival By HK HERO ENTERTAINMENT CO.
      Bundle ID: com.herogame.ios.lastdayrules
      iTunes Store Link: https://apps.apple.com/us/app/last-day-rules-survival/id1463021419?uo=4&at=1010lce4

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate or Substitute.
      - PreferenceLoader (from Cydia or Sileo).


      Hack Features:
      - No Recoil
      - Walk Under Water
      - Hide Tree
      - Hide Grass

      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app. This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Non-Jailbroken & No Jailbreak required hack(s): 


      iOS Hack Download Link:

      Hidden Content
      Download Hack







      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above.
      STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice.
      STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it.
      STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen.
      STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game.
      STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @DanYal


      Cheat Video/Screenshots:

      N/A
        • Winner
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 42 replies
    • Love Sick: Interactive Stories v1.35.0 +2 Cheats [Unlimited Currencies]
      Modded/Hacked App: Love Sick: Interactive Stories by SVEG MASHA, OOO
      Bundle ID: com.swagmasha.genres
      iTunes Store Link: https://itunes.apple.com/us/app/love-sick-interactive-stories/id1450264153?mt=8&uo=4&at=1010lce4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate (from Cydia).
      - PreferenceLoader (from Cydia).


      Hack Features:
      - Unlimited Keys - Will increase instead of decrease.
      - Unlimited Diamonds - Will increase instead of decrease.
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 152 replies
    • Crash Fever v4.3.4 +2 Cheats
      Modded/Hacked App: Crash Fever by WonderPlanet Inc.
      Bundle ID: com.wonderplanet.CrashFever
      iTunes Store Link: https://itunes.apple.com/us/app/crash-fever/id1146722894?mt=8&uo=4&at=1010lce4

       

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate (from Cydia).
      - PreferenceLoader (from Cydia).


      Hack Features:
      - God Mode (Low Enemy Damage)
      - High Damage 
      * Quest only


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/


      Hack Download Link:

      Hidden Content

      Download Hack








      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above.
      STEP 2: Copy the file over to your iDevice using any of the file managers mentioned above or skip this step if you're downloading from your iDevice.
      STEP 3: Using iFile or Filza, browse to where you saved the downloaded .deb file and tap on it.
      STEP 4: Once you tap on the file, you will then need to press on 'Installer' or 'Install' from the options on your screen.
      STEP 5: Let iFile / Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 6: Now open your iDevice settings and scroll down until you see the settings for this cheat and tap on it. If the hack is a Mod Menu, the cheat features can be toggled in-game.
      STEP 7: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @ZahirSher


      Cheat Video/Screenshots:

      N/A

       
        • Winner
        • Informative
        • Agree
        • Upvote
        • Haha
        • Thanks
        • Like
      • 141 replies
  • Recently Browsing   0 members

    No registered users viewing this page.


    • Administrator |
    • Special Rank |
    • ViP Plus |
    • ViP Jailed |
    • ViP |
    • Cheater  |
    • Modder  |
    • Novice Cheater |
    • Rookie Modder |
    • Contributor |
    • Senior Member |
    • Member |
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy - Guidelines