Jump to content

Hack without subtracting the ASLR Address against the Finder Address


9 posts in this topic

Recommended Posts

Updated (edited)

Please note, I will not cover from ground up. This tutorial assume you already know how to use LLDB and searching for addresses.

If you're looking for a beginner tutorial, please refer to 

 

 

For this tutorial I will be using Dino Cap 3.

1. Load the games on your iDevice.

2. Using iGameGod to search for the handgun ammo. You can search as soon as the stage loaded. Waste some bullet then do your next search. Test to make sure the remain address works. For me, this is the Finder Address for my ammo:

0x280275B14

Note that Finder address.

3. On your Mac/PC; load up two terminal to connect so we can use LLDB.

4. Set the Watchpoint for the Finder Address then continue.

 

Vl1kwM.jpg

5. Waste an ammo and LLDB should break. Here we landed on the Base Address: 0x1045DD448. On the noob friendly tutorial; we use the command 'Image List [application name]' to get the ASLR address so we can subtract the address against the Base Address. However, I will teach you a shortcut that takes you directly to the address you need in IDA without subtracting the address. Run this command on LLDB: image lookup -a [Base Address]

Example:

 

HrkefX.jpg

The second line: Address: Dino Cap 3[0x0000000100039448] ; The bolded address there is your IDA Address

6. Open IDA and jump to the IDA Address. You will landed on the LDR X0, [X19, #0xc8] assemble structure. If you look above it; you will see the SUBS W8, W8, #1. If you NOP it on the Live Offset Patcher for the SUBS address. You now find it that you have infinite ammo. 

 

9edWIE.jpg

 

I've tested a couple games and all took me to the right place. I hope you learn something today and Enjoy!

 

Update:

For those who learn by visual; check out King and our Channel at:

Updated by asianqueen
Added video tutorials
  • Like 6
  • Winner 3
  • Agree 2
  • Informative 1
Posted
3 hours ago, Hvfhbvgjvfhj said:

Any chance of updating your HelloTalk hack? I’m happy to donate! 

what's that

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines