Jump to content

[Windows/macOS] Introducing Sideloadly! - Working Cydia Impactor & AltStore Alternative!


10,521 posts in this topic

Recommended Posts

Posted
11 hours ago, BarberRo said:

El viejo problema está de vuelta:

ERROR: Meditación del gurú da8d42@132 : 556260@120 : 556260@392 : 0db732@894 : 0db732@1068 : 0db732@1044 : 0db732@592 : 0db732@245 :3aea77 Error de inicio de sesión (-224 no se pudo completar): . Intentar otra vez.

ese error está desde mayo y siguen sin solucionarlo se supone que nosotros los ios son los que debemos tener prioridad y nada mas no lo reparan ya estoy harto

Posted

@Rook Would it be possible to add a function to specify custom entitlements?

Trying to exploit Psychic Paper and the IPA doesn't retain the exploited entitlements from ldid before using sideloadly (unless I'm doing something wrong?)

Posted
1 hour ago, TRCiOS said:

@Rook Would it be possible to add a function to specify custom entitlements?

Trying to exploit Psychic Paper and the IPA doesn't retain the exploited entitlements from ldid before using sideloadly (unless I'm doing something wrong?)

Custom entitlements only seems possible on paid Apple IDs.

Posted (edited)
17 minutes ago, Rook said:

Custom entitlements only seems possible on paid Apple IDs.

Thanks for answering.

I currently reproduce the exploit with a free cert and a mobileprovision I extracted from XCode (7 days signing, free account, whatever random XCode ents uses) then I use codesign with custom entitlements (codesign -f -s “cert” —entitlements=psychicpaperents.plist app.app and finally install with ideviceinstaller.

Psychic paper gives you arbitrary entitlements due to different entitlement parsers in iOS.

I understand this is pretty niche, but would be very helpful for legacy exploitation, since asking non-savvy users to do all of this just for a sandbox escape isn’t very friendly.

Updated by TRCiOS
Posted
9 minutes ago, TRCiOS said:

Thanks for answering.

I currently reproduce the exploit with a free cert and a mobileprovision I extracted from XCode (7 days signing, free account, whatever random XCode ents uses) then I use codesign with custom entitlements (codesign -f -s “cert” —entitlements=psychicpaperents.plist app.app and finally install with ideviceinstaller.

Psychic paper gives you arbitrary entitlements due to different entitlement parsers in iOS.

I understand this is pretty niche, but would be very helpful for legacy exploitation, since asking non-savvy users to do all of this just for a sandbox escape isn’t very friendly.

Is this the new exploit that people are talking about?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines