Jump to content

4 posts in this topic

Recommended Posts

Hello everyone! I am having an issue when analyzing the Mach-O executable for the IOS Application: Subway Surfers inside of Ghidra. I will lay out the thread with the steps I have successfully taken, and outline where the issue that I am facing occurs. Any insight into why this issue could be occurring would be greatly appreciated, I'm here to learn, and if there are things that I am doing incorrectly, or could be doing differently, please let me know.

 

Steps Taken So Far:

  1. Extracted the IPA File:

    • I have successfully extracted the Subway Surfers IPA to locate the key files, including the Mach-O executable and global-metadata.dat.
  2. Confirmed Global-Metadata.dat:

    • Located the global-metadata.dat file in the Metadata folder, which is crucial for dumping the IL2CPP structures.
  3. Dumped IL2CPP:

    • Used IL2CPP Dumper on both the Mach-O executable and global-metadata.dat to extract the dump.cs and script.json files.
    • These files include critical information about game methods, classes, and offsets, including the ColliderEnable property.
  4. Imported the Mach-O Executable into Ghidra:

    • I have imported the Subway Surfers Mach-O executable into Ghidra for analysis. I set the processor language to AARCH64: AppleSilicon (default) and used the Mac OS X Mach-O format for import.
  5. Attempted to Locate the Function Offset:

    • Based on the dump.cs output, I attempted to find the ColliderEnable function using its RVA (Relative Virtual Address) from IL2CPP Dumper:
      • get_ColliderEnable: RVA = 0x29E60
      • set_ColliderEnable: RVA = 0x29E80
    • I calculated the absolute memory address by adding the base address of 0x100000000 (as determined from the Memory Map in Ghidra) to these RVAs:
      • get_ColliderEnable: 0x100029E60
      • set_ColliderEnable: 0x100029E80
    • However, when using Ghidra’s “Go To” function to navigate to these addresses, we consistently receive a “no results” error.
  6. Reanalyzed the Mach-O Executable:

    • I reanalyzed the file in Ghidra, enabling all necessary analysis passes (function identification, instruction decoding, etc.).
    • I also attempted to search for function names and program text (e.g., ColliderEnable) manually, but the function still could not be found.
  7. Encountered Swift Demangler Issues:

    • Ghidra reported an error about missing Swift demangling tools, leading to the possibility that Ghidra is struggling with sections of the binary related to Swift. I considered that Swift dependencies might interfere with the analysis process and installed Swift onto my machine.

The Issue I am Facing in Ghidra:

  • Despite importing the Mach-O binary correctly and reanalyzing the file, Ghidra is unable to locate the function offsets or names for ColliderEnable (or other related methods) based on the RVAs provided by IL2CPP Dumper.
  • I have already verified that the base address and RVA calculation are correct (using the memory map), but Ghidra still returns “no results” when navigating to the calculated addresses.
  • The Swift demangler error may be preventing full analysis or proper resolution of some sections of the binary, but the specific connection to this issue is unclear.

What I Need Help With:

  • Understanding why Ghidra can’t find the function offset even though the base address and RVAs seem correct.
  • Determining if the Swift-related errors could be affecting our ability to locate the function.
  • Identifying any potential additional steps or configurations in Ghidra to resolve this issue (or if another tool might handle this better - I don't have IDA).

I appreciate any insight into why this issue could be occurring. If there is something that I am overlooking, I would greatly appreciate any additional information so that I can learn how to resolve this.

6 minutes ago, Laxus said:

You do not need to add 0x1000000 if the executable is the Frameworks

Just go to that RVA offset

Interesting, I wasn't aware of this. I will give this a try. Thanks.

Edit: The issue still persists, I could only imagine that I am somehow importing the Mach-O for analyzation incorrectly.

Updated by Game Sphere
Update Result (Issue Persistence)

Bumping this as I still haven't been able to solve this issue. I'm a bit dumbfounded. For anyone that has read my original post, I have also tried importing the Mach-O Executable into Hopper, Ghidra, and Cutter. All of which I am having the same issues with. It leaves me with the thoughts that I must be importing incorrectly, or something along those lines, but any input would be appreciated as I'm stumped.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below. For more information, please read our Posting Guidelines.
Reply to this topic... Posting Guidelines

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Our picks

    • Prison Empire Tycoon-Idle Game Cheats v3.1 +2
      Modded/Hacked App: Prison Empire Tycoon-Idle Game by Digital Things Sociedad Limitada
      Bundle ID: com.codigames.idle.prison.empire.manager.tycoon
      iTunes Store Link: https://apps.apple.com/us/app/prison-empire-tycoon-idle-game/id1508490923?uo=4&at=1010lce4


      Hack Features:
      - Infinite Cash
      - No Ads


      Non-Jailbroken & No Jailbreak required hack(s):  https://iosgods.com/topic/128324-arm64-prison-empire-tycoon%EF%BC%8Didle-game-v102-jailed-cheats-2/

       
      iOS Hack Download Link: https://iosgods.com/topic/128322-arm64-prison-empire-tycoon%EF%BC%8Didle-game-cheats-all-versions-2/
        • Like
      • 1,144 replies
    • Strongest Knight Cheats v1.10 +4
      Modded/Hacked App: Strongest Knight By Superlink Ltd.
      Bundle ID: com.idlemaster.hero
      iTunes Store Link: https://apps.apple.com/us/app/strongest-knight/id6738113239?uo=4


      Hack Features:
      - Multiply Attack
      - Multiply Defense
      - Freeze Currencies
      - No Ads (Don't use the deb cheat unless you complete tutorial -- Finish use 4 ads boost quest)
       


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/190406-strongest-knight-v106-jailed-cheats-4/


      iOS Hack Download Link: https://iosgods.com/topic/190404-strongest-knight-cheats-v106-4/
      • 23 replies
    • Gran Saga Idle:KNIGHTSxKNIGHTS Cheats v1.24.3 +2
      Modded/Hacked App: Gran Saga Idle:KNIGHTSxKNIGHTS By Kakao Games Corp.
      Bundle ID: com.piedpixels.gransagaidle
      iTunes Store Link: https://apps.apple.com/us/app/gran-saga-idle-knightsxknights/id6482985104?uo=4


      Hack Features:
      - Multiply Attack
      - Multiply Defense


      iOS Hack Download Link: https://iosgods.com/topic/182761-gran-saga-idleknightsxknights-cheats-v101-2/
        • Winner
      • 252 replies
    • Archero Cheats v6.9.4 +5 [ God Mode & More ]
      Modded/Hacked App: Archero by HABBY PTE. LTD.
      Bundle ID: com.habby.archero
      iTunes Store Link: https://apps.apple.com/us/app/archero/id1453651052?uo=4&at=1010lce4



      Hack Features:
      - Multiply Defense to
      - Multiply Damage to
      - God Mode
      - OHK (Must use with God Mode)
      - Freeze Enemies

      NOTE: If you want to use god mode and ohk turn off multiply damage and defense first. I added multiply damage and defense there to avoid ban


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/100710-archero-v210-enemies-dont-attack-x30-attack/


      Hack Download Link: https://iosgods.com/topic/96783-arm64-archero-cheats-v220-5/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 15,777 replies
    • Virtual Families 3 v2.3.4 +3 Jailed Cheats [ Coins + More ]
      Modded/Hacked App: Virtual Families 3 By LDW Software, LLC
      Bundle ID: com.ldw.vf3
      iTunes Store Link: https://apps.apple.com/us/app/virtual-families-3/id1159846171?uo=4

       
       

      Hack Features

      - Unlimited Coins*
      - Unlimited Food*
      - Unlimited Pet Food*

      * - Head into Settings and toggle the Help button. Only enable 1 feature at a time.


      Jailbreak required iOS hacks: [Mod Menu Hack] Virtual Families 3 v2.3.4 +3 Cheats [ Coins + More ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APKs: https://iosgods.com/forum/68-android-section/
      • 0 replies
    • Virtual Families 3 v2.3.4 +3 Cheats [ Coins + More ]
      Modded/Hacked App: Virtual Families 3 By LDW Software, LLC
      Bundle ID: com.ldw.vf3
      iTunes Store Link: https://apps.apple.com/us/app/virtual-families-3/id1159846171?uo=4

       
       

      Hack Features

      - Unlimited Coins*
      - Unlimited Food*
      - Unlimited Pet Food*

      * - Head into Settings and toggle the Help button. Only enable 1 feature at a time.


      For Non-Jailbroken & No Jailbreak required hacks: [IPA Mod Menu] Virtual Families 3 v2.3.4 +3 Jailed Cheats [ Coins + More ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      • 0 replies
    • Virtual Villagers 6 v1.3.23 +100 Jailed Cheats [ Cheats Menu ]
      Modded/Hacked App: Virtual Villagers 6 By LDW Software, LLC
      Bundle ID: com.ldw.vv6
      iTunes Store Link: https://apps.apple.com/us/app/virtual-villagers-6/id6566193928?uo=4

       
       

      Hack Features

      - Cheats Menu -> Head into Settings, toggle the Help button, close settings then re-open to show a Cheats button.*
      - Unlimited Food*
      - Unlimited Wood*
      - Unlimited Stone*
      - Unlimited Tech Points*
      - Unlimited Lavastone*

      * - Head into Settings and toggle the Help button. Only enable 1 feature at a time.


      Jailbreak required iOS hacks: [Mod Menu Hack] Virtual Villagers 6 v1.3.23 +100 Cheats [ Cheats Menu ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APKs: https://iosgods.com/forum/68-android-section/
      • 0 replies
    • Virtual Villagers 6 v1.3.23 +100 Cheats [ Cheats Menu ]
      Modded/Hacked App: Virtual Villagers 6 By LDW Software, LLC
      Bundle ID: com.ldw.vv6
      iTunes Store Link: https://apps.apple.com/us/app/virtual-villagers-6/id6566193928?uo=4

       


      Hack Features

      - Cheats Menu -> Head into Settings, toggle the Help button, close settings then re-open to show a Cheats button.*
      - Unlimited Food*
      - Unlimited Wood*
      - Unlimited Stone*
      - Unlimited Tech Points*
      - Unlimited Lavastone*

      * - Head into Settings and toggle the Help button. Only enable 1 feature at a time.


      For Non-Jailbroken & No Jailbreak required hacks: [IPA Mod Menu] Virtual Villagers 6 v1.3.23 +100 Jailed Cheats [ Cheats Menu ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      • 0 replies
    • All in Hole v3.8.2 +3 Jailed Cheats [ Coins + More ]
      Modded/Hacked App: All in Hole By HOMA GAMES
      Bundle ID: com.homagames.studio.allinhole
      iTunes Store Link: https://apps.apple.com/us/app/all-in-hole/id6503284107?uo=4

       


      Hack Features

      - Add Coins
      - Add Lives
      - Auto Win


      Jailbreak required iOS hacks: [Mod Menu Hack] All in Hole v3.8.2 +3 Cheats [ Coins + More] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APKs: https://iosgods.com/forum/68-android-section/
      • 1 reply
    • All in Hole v3.8.2 +3 Cheats [ Coins + More]
      Modded/Hacked App: All in Hole By HOMA GAMES
      Bundle ID: com.homagames.studio.allinhole
      iTunes Store Link: https://apps.apple.com/us/app/all-in-hole/id6503284107?uo=4

       


      Hack Features

      - Add Coins
      - Add Lives
      - Auto Win


      For Non-Jailbroken & No Jailbreak required hacks: [IPA Mod Menu] All in Hole v3.8.2 +3 Jailed Cheats [ Coins + More ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      • 1 reply
    • Summoners War Cheats v8.6.1 +7
      Hacked App: Summoners War By Com2uS Corp.
      iTunes Link: https://itunes.apple.com/us/app/summoners-war/id852912420?mt=8&uo=4&at=1010lce4
      Bundle ID: com.com2us.smon.normal.freefull.apple.kr.ios.universal

      Hack Features:
      - Damage Multiplier 
      - Godmode
      - Monster Count Unlink
      - Max Accuracy
      - No Skill Cooldown
      - First Turn
      - Build buildings without having required level
      - Antiban
        • Informative
        • Agree
        • Haha
        • Winner
        • Like
      • 6,823 replies
    • Anna's Monster Farm : BEGINS Cheats v1.7.0 +3
      Modded/Hacked App: Anna's Monster Farm : BEGINS By Dalmoon Co.,Ltd.
      Bundle ID: com.zzoo.ios.monsterfarm
      iTunes Store Link: https://apps.apple.com/us/app/annas-monster-farm-begins/id6482291449?uo=4
       

      Hack Features

      - Freeze Currencies
      - God Mode
      - Multiply Attack


      For Non-Jailbroken & No Jailbreak required hacks: https://iosgods.com/forum/79-no-jailbreak-section/


      iOS Hack Download Link https://iosgods.com/topic/191165-annas-monster-farm-begins-cheats-v170-3/
      • 15 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines