Jump to content

4 posts in this topic

Recommended Posts

Posted

Hello everyone! I am having an issue when analyzing the Mach-O executable for the IOS Application: Subway Surfers inside of Ghidra. I will lay out the thread with the steps I have successfully taken, and outline where the issue that I am facing occurs. Any insight into why this issue could be occurring would be greatly appreciated, I'm here to learn, and if there are things that I am doing incorrectly, or could be doing differently, please let me know.

 

Steps Taken So Far:

  1. Extracted the IPA File:

    • I have successfully extracted the Subway Surfers IPA to locate the key files, including the Mach-O executable and global-metadata.dat.
  2. Confirmed Global-Metadata.dat:

    • Located the global-metadata.dat file in the Metadata folder, which is crucial for dumping the IL2CPP structures.
  3. Dumped IL2CPP:

    • Used IL2CPP Dumper on both the Mach-O executable and global-metadata.dat to extract the dump.cs and script.json files.
    • These files include critical information about game methods, classes, and offsets, including the ColliderEnable property.
  4. Imported the Mach-O Executable into Ghidra:

    • I have imported the Subway Surfers Mach-O executable into Ghidra for analysis. I set the processor language to AARCH64: AppleSilicon (default) and used the Mac OS X Mach-O format for import.
  5. Attempted to Locate the Function Offset:

    • Based on the dump.cs output, I attempted to find the ColliderEnable function using its RVA (Relative Virtual Address) from IL2CPP Dumper:
      • get_ColliderEnable: RVA = 0x29E60
      • set_ColliderEnable: RVA = 0x29E80
    • I calculated the absolute memory address by adding the base address of 0x100000000 (as determined from the Memory Map in Ghidra) to these RVAs:
      • get_ColliderEnable: 0x100029E60
      • set_ColliderEnable: 0x100029E80
    • However, when using Ghidra’s “Go To” function to navigate to these addresses, we consistently receive a “no results” error.
  6. Reanalyzed the Mach-O Executable:

    • I reanalyzed the file in Ghidra, enabling all necessary analysis passes (function identification, instruction decoding, etc.).
    • I also attempted to search for function names and program text (e.g., ColliderEnable) manually, but the function still could not be found.
  7. Encountered Swift Demangler Issues:

    • Ghidra reported an error about missing Swift demangling tools, leading to the possibility that Ghidra is struggling with sections of the binary related to Swift. I considered that Swift dependencies might interfere with the analysis process and installed Swift onto my machine.

The Issue I am Facing in Ghidra:

  • Despite importing the Mach-O binary correctly and reanalyzing the file, Ghidra is unable to locate the function offsets or names for ColliderEnable (or other related methods) based on the RVAs provided by IL2CPP Dumper.
  • I have already verified that the base address and RVA calculation are correct (using the memory map), but Ghidra still returns “no results” when navigating to the calculated addresses.
  • The Swift demangler error may be preventing full analysis or proper resolution of some sections of the binary, but the specific connection to this issue is unclear.

What I Need Help With:

  • Understanding why Ghidra can’t find the function offset even though the base address and RVAs seem correct.
  • Determining if the Swift-related errors could be affecting our ability to locate the function.
  • Identifying any potential additional steps or configurations in Ghidra to resolve this issue (or if another tool might handle this better - I don't have IDA).

I appreciate any insight into why this issue could be occurring. If there is something that I am overlooking, I would greatly appreciate any additional information so that I can learn how to resolve this.

Posted

You do not need to add 0x1000000 if the executable is the Frameworks

Just go to that RVA offset

  • Like 1
Posted (edited)
6 minutes ago, Laxus said:

You do not need to add 0x1000000 if the executable is the Frameworks

Just go to that RVA offset

Interesting, I wasn't aware of this. I will give this a try. Thanks.

Edit: The issue still persists, I could only imagine that I am somehow importing the Mach-O for analyzation incorrectly.

Updated by Game Sphere
Update Result (Issue Persistence)
Posted

Bumping this as I still haven't been able to solve this issue. I'm a bit dumbfounded. For anyone that has read my original post, I have also tried importing the Mach-O Executable into Hopper, Ghidra, and Cutter. All of which I am having the same issues with. It leaves me with the thoughts that I must be importing incorrectly, or something along those lines, but any input would be appreciated as I'm stumped.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • The Battle Cats Cheats v15.0.2 +2
      Modded/Hacked App: The Battle Cats by ponos corporation
      Bundle ID: jp.co.ponos.battlecatsen
      iTunes Store Link: https://apps.apple.com/us/app/the-battle-cats/id850057092?uo=4&at=1010lce4


      Hack Features:
      - Infinite Cash
      - OHK Linked

      NOTE: Please don't ask me for currencies hack since this is the best I can do


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/124447-arm64-the-battle-cats-v940-jailed-cheats-2/


      iOS Hack Download Link: https://iosgods.com/topic/124448-arm64-the-battle-cats-cheats-v950-2/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 928 replies
    • SimCity BuildIt Cheats v1.73.1 +1 [ Freeze Currencies ]
      Modded/Hacked App: SimCity BuildIt By EA Swiss Sarl
      Bundle ID: com.ea.simcitymobile.bv
      iTunes Store Link: https://apps.apple.com/us/app/simcity-buildit/id913292932?uo=4


      Hack Features:
      - Infinite Currencies


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/124792-arm64-simcity-buildit-v1412-jailed-cheats-1/


      iOS Hack Download Link: https://iosgods.com/topic/157687-simcity-buildit-cheats-v1415-1/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 718 replies
    • Cooking Craze: Restaurant Game Cheats v2.11.0 +1
      Modded/Hacked App: Cooking Craze: Restaurant Game By Big Fish Games, Inc
      Bundle ID: com.bigfishgames.cookingempireuniversalf2p
      iTunes Store Link: https://apps.apple.com/us/app/cooking-craze-restaurant-game/id1029094059?uo=4

       

      🔧 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Cydia, Sileo or Zebra).

       

      🚀 Hack Features

      - Free Store (not Free iAP)


      🍏 For Non-Jailbroken & No Jailbreak required hacks: https://iosgods.com/topic/191693-cooking-craze-restaurant-game-v240-jailed-cheats-1/

       

      📥 iOS Hack Download Link: https://iosgods.com/topic/191694-cooking-craze-restaurant-game-cheats-v250-1/
        • Agree
        • Like
      • 10 replies
    • [ GrandChase TW] 永恆冒險 Cheats v1.97.2 +3
      Modded/Hacked App: 永恆冒險 By HaoPlay Limited
      Bundle ID: tw.txwy.ios.grandchase
      iTunes Store Link: https://apps.apple.com/tw/app/%E6%B0%B8%E6%81%86%E5%86%92%E9%9A%AA/id1434266148?uo=4


      Hack Features:
      - Multiply Attack
      - Multiply Defense
      - Instant Skills
      - Weak Enemies


      ViP Non-Jailbroken Hack: https://iosgods.com/topic/167594-grandchase-tw-%E6%B0%B8%E6%81%86%E5%86%92%E9%9A%AA-v1744-jailed-cheats-2/


      iOS Hack Download Link: https://iosgods.com/topic/144913-grandchase-tw-%E6%B0%B8%E6%81%86%E5%86%92%E9%9A%AA-cheats-v1812-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 155 replies
    • Prison Empire Tycoon-Idle Game Cheats v4.25 +2
      Modded/Hacked App: Prison Empire Tycoon-Idle Game by Digital Things Sociedad Limitada
      Bundle ID: com.codigames.idle.prison.empire.manager.tycoon
      iTunes Store Link: https://apps.apple.com/us/app/prison-empire-tycoon-idle-game/id1508490923?uo=4&at=1010lce4


      Hack Features:
      - Infinite Cash
      - No Ads


      Non-Jailbroken & No Jailbreak required hack(s):  https://iosgods.com/topic/128324-arm64-prison-empire-tycoon%EF%BC%8Didle-game-v102-jailed-cheats-2/

       
      iOS Hack Download Link: https://iosgods.com/topic/128322-arm64-prison-empire-tycoon%EF%BC%8Didle-game-cheats-all-versions-2/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,167 replies
    • GrandChase Cheats v1.97.2 +4 [ Multiply Attack & More ]
      Modded/Hacked App: GrandChase By KOG co., Ltd
      Bundle ID: com.kog.grandchaseglobal
      iTunes Store Link: https://itunes.apple.com/us/app/grandchase/id1385904294?mt=8&uo=4&at=1010lce4

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate or Substitute.
      - PreferenceLoader (from Cydia or Sileo).


      Hack Features:
      - x Player Damage - x1 - 100
      - x Player HP - x1 - 100
      - Auto-Win
      - Unlimited Skills

      All features are unlinked and only for player, you!

      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app. This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,508 replies
    • Rick and Morty: Pocket Mortys v2.40.5 Jailed Cheats +1
      Modded/Hacked App: Rick and Morty: Pocket Mortys by Turner Broadcasting System, Inc.
      Bundle ID: com.turner.pocketmorties
      iTunes Store Link: https://itunes.apple.com/us/app/rick-and-morty-pocket-mortys/id992640880?mt=8&uo=4&at=1010lce4



      Hack Features:
      - Infinite Schmeckles
      - Infinite Coupons


      Hack Download Link: https://iosgods.com/topic/86695-arm64-rick-and-morty-pocket-mortys-v271-jailed-cheats-2/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 450 replies
    • Stick War: Legacy v2025.1.227 Jailed Cheats +3
      Modded/Hacked App: Stick War: Legacy by 1004319 Alberta Ltd
      Bundle ID: com.stickpage.stickwar
      iTunes Store Link: https://apps.apple.com/us/app/stick-war-legacy/id1001780528?uo=4&at=1010lce4


      Hack Features:
      - Infinite Gold
      - Infinite Gem
      - Fast Build


      Jailbreak required hack(s):  https://iosgods.com/topic/96769-stick-war-legacy-v20235701-jailed-cheats-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 435 replies
    • BitLife - Life Simulator Cheats v3.22.1 +2
      Modded/Hacked App: BitLife - Life Simulator by Candywriter, LLC
      Bundle ID: com.wtfapps.apollo16
      iTunes Store Link: https://apps.apple.com/us/app/bitlife-life-simulator/id1374403536?uo=4&at=1010lce4


      Hack Features:
      - Infinite Cash
      - Free Bitizen Purchase (Press Cancle) - Work for All Versions


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/84167-arm64-bitlife-life-simulator-v1412-jailed-cheats-2/


      Hack Download Link: https://iosgods.com/topic/84223-arm64-bitlife-life-simulator-cheats-all-versions-2/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 3,912 replies
    • Tap Tap Fish - AbyssRium Cheats (Auto Update) +1
      Modded/Hacked App: Tap Tap Fish - AbyssRium By SangHeon Kim
      Bundle ID: com.idleif.abyssrium
      iTunes Store Link: https://itunes.apple.com/us/app/tap-tap-fish-abyssrium/id1068366937?mt=8&uo=4&at=1010lce4



      Hack Features:
      - Infinite Vitality, Gem, etc ... (Increase When Used) / Untested with Pearl
       

      Hack Download Link: https://iosgods.com/topic/81337-arm64-tap-tap-fish-abyssrium-cheats-v179-1/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 374 replies
    • Defense Legend 5 Pro v1.0.3 [ +15 Cheats ] Currency Max
      Modded/Hacked App: Defense Legend 5 Pro By GCENTER VIET NAM TECHNOLOGY JOINT STOCK COMPANY
      Bundle ID: com.Gcenter.DefenseLegend.TowerDefense.TD.survivor.V5.Pro
      App Store Link: https://apps.apple.com/us/app/defense-legend-5-pro/id6744385350?uo=4

      🤩 Hack Features

      - ADS NO / Rewards Free
      - Unlimited Gems
      - Unlimited Energy
      - Unlimited Stars
      - Legendary Hero Pices
      - InfernoCore Currency
      - Unlimited Battle Items
      - Heroes Unlocked
      - Skin Unlocked
      - Gun Unlocked
      - Unlimited Skill Point
      - Premium Pass Active
      - Premium Pass / Claim Unlimited
      - Free Pass / Claim Unlimited
      - Battle Cash / Sell Tower 
        • Informative
        • Agree
        • Winner
        • Like
      • 8 replies
    • Defense Legend 5 Pro v1.0.3 [ +15 Jailed ] Currency Max
      Modded/Hacked App: Defense Legend 5 Pro By GCENTER VIET NAM TECHNOLOGY JOINT STOCK COMPANY
      Bundle ID: com.Gcenter.DefenseLegend.TowerDefense.TD.survivor.V5.Pro
      App Store Link: https://apps.apple.com/us/app/defense-legend-5-pro/id6744385350?uo=4

      🤩 Hack Features

      - ADS NO / Rewards Free
      - Unlimited Gems
      - Unlimited Energy
      - Unlimited Stars
      - Legendary Hero Pices
      - InfernoCore Currency
      - Unlimited Battle Items
      - Heroes Unlocked
      - Skin Unlocked
      - Gun Unlocked
      - Unlimited Skill Point
      - Premium Pass Active
      - Premium Pass / Claim Unlimited
      - Free Pass / Claim Unlimited
      - Battle Cash / Sell Tower 
        • Informative
        • Agree
        • Haha
        • Winner
        • Like
      • 10 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines