Jump to content

4 posts in this topic

Recommended Posts

Posted

Hello everyone! I am having an issue when analyzing the Mach-O executable for the IOS Application: Subway Surfers inside of Ghidra. I will lay out the thread with the steps I have successfully taken, and outline where the issue that I am facing occurs. Any insight into why this issue could be occurring would be greatly appreciated, I'm here to learn, and if there are things that I am doing incorrectly, or could be doing differently, please let me know.

 

Steps Taken So Far:

  1. Extracted the IPA File:

    • I have successfully extracted the Subway Surfers IPA to locate the key files, including the Mach-O executable and global-metadata.dat.
  2. Confirmed Global-Metadata.dat:

    • Located the global-metadata.dat file in the Metadata folder, which is crucial for dumping the IL2CPP structures.
  3. Dumped IL2CPP:

    • Used IL2CPP Dumper on both the Mach-O executable and global-metadata.dat to extract the dump.cs and script.json files.
    • These files include critical information about game methods, classes, and offsets, including the ColliderEnable property.
  4. Imported the Mach-O Executable into Ghidra:

    • I have imported the Subway Surfers Mach-O executable into Ghidra for analysis. I set the processor language to AARCH64: AppleSilicon (default) and used the Mac OS X Mach-O format for import.
  5. Attempted to Locate the Function Offset:

    • Based on the dump.cs output, I attempted to find the ColliderEnable function using its RVA (Relative Virtual Address) from IL2CPP Dumper:
      • get_ColliderEnable: RVA = 0x29E60
      • set_ColliderEnable: RVA = 0x29E80
    • I calculated the absolute memory address by adding the base address of 0x100000000 (as determined from the Memory Map in Ghidra) to these RVAs:
      • get_ColliderEnable: 0x100029E60
      • set_ColliderEnable: 0x100029E80
    • However, when using Ghidra’s “Go To” function to navigate to these addresses, we consistently receive a “no results” error.
  6. Reanalyzed the Mach-O Executable:

    • I reanalyzed the file in Ghidra, enabling all necessary analysis passes (function identification, instruction decoding, etc.).
    • I also attempted to search for function names and program text (e.g., ColliderEnable) manually, but the function still could not be found.
  7. Encountered Swift Demangler Issues:

    • Ghidra reported an error about missing Swift demangling tools, leading to the possibility that Ghidra is struggling with sections of the binary related to Swift. I considered that Swift dependencies might interfere with the analysis process and installed Swift onto my machine.

The Issue I am Facing in Ghidra:

  • Despite importing the Mach-O binary correctly and reanalyzing the file, Ghidra is unable to locate the function offsets or names for ColliderEnable (or other related methods) based on the RVAs provided by IL2CPP Dumper.
  • I have already verified that the base address and RVA calculation are correct (using the memory map), but Ghidra still returns “no results” when navigating to the calculated addresses.
  • The Swift demangler error may be preventing full analysis or proper resolution of some sections of the binary, but the specific connection to this issue is unclear.

What I Need Help With:

  • Understanding why Ghidra can’t find the function offset even though the base address and RVAs seem correct.
  • Determining if the Swift-related errors could be affecting our ability to locate the function.
  • Identifying any potential additional steps or configurations in Ghidra to resolve this issue (or if another tool might handle this better - I don't have IDA).

I appreciate any insight into why this issue could be occurring. If there is something that I am overlooking, I would greatly appreciate any additional information so that I can learn how to resolve this.

Posted

You do not need to add 0x1000000 if the executable is the Frameworks

Just go to that RVA offset

  • Like 1
Posted (edited)
6 minutes ago, Laxus said:

You do not need to add 0x1000000 if the executable is the Frameworks

Just go to that RVA offset

Interesting, I wasn't aware of this. I will give this a try. Thanks.

Edit: The issue still persists, I could only imagine that I am somehow importing the Mach-O for analyzation incorrectly.

Updated by Game Sphere
Update Result (Issue Persistence)
Posted

Bumping this as I still haven't been able to solve this issue. I'm a bit dumbfounded. For anyone that has read my original post, I have also tried importing the Mach-O Executable into Hopper, Ghidra, and Cutter. All of which I am having the same issues with. It leaves me with the thoughts that I must be importing incorrectly, or something along those lines, but any input would be appreciated as I'm stumped.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Animal Mafia v1.2.0 [ +20 Cheats ] Currency Max
      Modded/Hacked App: Animal Mafia By IGNITION M CO., LTD.
      Bundle ID: com.ignm.animalmafia
      App Store Link: https://apps.apple.com/us/app/animal-mafia/id6741849079?uo=4

      🤩 Hack Features

      - Premium Active
      - Premium Claim Unlimited
      - Premium Unlimited Rewards
      - Normal Unlimited Rewards
      - Unlimited Gems
      - Unlimited Gold
      - Unlimited Energy
      - Unlimited Soul Can
      - Unlimited Sprout Keys + Voucher
      - Unlimited Grilled Fish + Voucher
      - Unlimited Enhancement Crystal + Voucher
      - Unlimited Animal Cookie
      - Unlimited Bloom Key
      - Unlimited Adventure Medal
      - Offline Rewards / Unlimited Gold
      - Offline Rewards / Unlimited Gummy
      - Gacha / Earn Gold
      - Gacha / Earn Gummy
      - ATK / Hero Upgrade
      - HP / Hero Upgrade
        • Winner
        • Like
      • 14 replies
    • Animal Mafia v1.2.0 [ +20 Jailed ] Currency Max
      Modded/Hacked App: Animal Mafia By IGNITION M CO., LTD.
      Bundle ID: com.ignm.animalmafia
      App Store Link: https://apps.apple.com/us/app/animal-mafia/id6741849079?uo=4

      🤩 Hack Features

      - Premium Active
      - Premium Claim Unlimited
      - Premium Unlimited Rewards
      - Normal Unlimited Rewards
      - Unlimited Gems
      - Unlimited Gold
      - Unlimited Energy
      - Unlimited Soul Can
      - Unlimited Sprout Keys + Voucher
      - Unlimited Grilled Fish + Voucher
      - Unlimited Enhancement Crystal + Voucher
      - Unlimited Animal Cookie
      - Unlimited Bloom Key
      - Unlimited Adventure Medal
      - Offline Rewards / Unlimited Gold
      - Offline Rewards / Unlimited Gummy
      - Gacha / Earn Gold
      - Gacha / Earn Gummy
      - ATK / Hero Upgrade
      - HP / Hero Upgrade
        • Winner
        • Like
      • 13 replies
    • Merge Cats: Catopia Puzzle v1.5.2 [ +3 Cheats ] Currency Max
      Modded/Hacked App: Merge Cats: Catopia Puzzle By Sticky Hands Inc.
      Bundle ID: com.stickyhands.mergecats
      App Store Link: https://apps.apple.com/us/app/merge-cats-catopia-puzzle/id6746182545?uo=4

      🤩 Hack Features

      - Unlimited Cash
      - Unlimited Gold
      - Unlimited Energy
      • 2 replies
    • Merge Cats: Catopia Puzzle v1.5.2 [ +3 Jailed ] Currency Max
      Modded/Hacked App: Merge Cats: Catopia Puzzle By Sticky Hands Inc.
      Bundle ID: com.stickyhands.mergecats
      App Store Link: https://apps.apple.com/us/app/merge-cats-catopia-puzzle/id6746182545?uo=4
      🤩 Hack Features

      - Unlimited Cash
      - Unlimited Gold
      - Unlimited Energy
        • Like
      • 2 replies
    • 32 Heroes: Retro RPG +4 Jailed Cheats
      Modded/Hacked App: 32 Heroes: Retro RPG By Lunosoft Inc.
      Bundle ID: com.lunosoft.ttheroes
      App Store Link: https://apps.apple.com/us/app/32-heroes-retro-rpg/id6737118316?uo=4

       

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier
      - Freeze Currencies
      - Claim Pass Rewards

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Informative
        • Agree
        • Thanks
        • Like
      • 21 replies
    • Cult of Medjed +4 Jailed Cheats
      Modded/Hacked App: メジェ教団 - [洗脳型]放置系RPG By FUNDOSHI PARADE K.K.
      Bundle ID: com.fundoshiparade.cult
      iTunes Store Link: https://apps.apple.com/jp/app/%E3%83%A1%E3%82%B8%E3%82%A7%E6%95%99%E5%9B%A3-%E6%B4%97%E8%84%B3%E5%9E%8B-%E6%94%BE%E7%BD%AE%E7%B3%BBrpg/id6447676258?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Never Die
      - No SP Consume
      - Unlimited Curreniec → Spend/Gain
      - Unlimited EXP → Spend/Gain
      - Freeze Currencies

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Informative
        • Like
      • 23 replies
    • (Colopl Rune Story Japan) 白猫プロジェクト +6 Jailed Cheats
      Modded/Hacked App: 白猫プロジェクト By COLOPL, Inc.
      Bundle ID: jp.colopl.wcat
      iTunes Store Link: https://apps.apple.com/jp/app/%E7%99%BD%E7%8C%AB%E3%83%97%E3%83%AD%E3%82%B8%E3%82%A7%E3%82%AF%E3%83%88/id895687962?uo=4

       

      Mod Requirements:
      - Jailbroken or Non-Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.





      Hack Features:
      - Loot Multiplier - x1 - 100
      - Damage Multiplier
      - Never Die
      - Custom Damage
      - Unlimited SP
      - Move Speed Multiplier


      Jailbreak required hack(s): 


      Hack Download Link:

      Hidden Content
      React or reply to this topic to see the <a href='https://iosgods.com/topic/3762-info-how-to-unlockview-the-hidden-content-on-iosgods/?do=findComment&comment=78119'>hidden content & download link</a>.








      Installation Instructions:
      STEP 1: If necessary, uninstall the app if you have it installed on your iDevice. Some hacked IPAs will install as a duplicate app. Make sure to back it up so you don't lose your progress.
      STEP 2: Download the pre-hacked .IPA file from the link above to your computer.
      STEP 3: Download Cydia Impactor and extract the archive.
      STEP 4: Open/Run Cydia Impactor on your computer then connect your iOS Device and wait until your device name shows up on Cydia Impactor.
      STEP 5: Once your iDevice appears, drag the modded .IPA file you downloaded and drop it inside the Cydia Impactor application.
      STEP 6: You will now be asked to enter your iTunes/Apple ID email login & then your password. Go ahead and enter the required information..
      STEP 7: Wait for Cydia Impactor to finish sideloading/installing the hacked IPA.
      STEP 8: Once the installation is complete and you see the app on your Home Screen, you will now need to go to your Settings -> General -> Profiles & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 9: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further instructions inside the hack's popup in-game.

      NOTE: For free Apple Developer accounts you will need to repeat this process every 7 days. Using a disposable Apple ID for this process is suggested but not required. Jailbroken iDevices can skip using Cydia Impactor and just install the IPA mod with AppSync & IPA Installer (or alternatives) from Cydia. If you have any questions or problems, read our Cydia Impactor topic and if you don't find a solution, post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - @Zahir


      Cheat Video/Screenshots:

       
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 537 replies
    • Animal Mafia +2 Jailed Cheats
      Modded/Hacked App: Animal Mafia By IGNITION M CO., LTD.
      Bundle ID: com.ignm.animalmafia
      App Store Link: https://apps.apple.com/us/app/animal-mafia/id6741849079?uo=4

       

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Winner
        • Like
      • 5 replies
    • My Perfect Casino +3 Jailed Cheats
      Modded/Hacked App: My Perfect Casino By BoomBit, Inc.
      Bundle ID: com.SmyrnaGames.MyPerfectCasino
      App Store Link: https://apps.apple.com/us/app/my-perfect-casino/id6744884477?uo=4

       

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Add Chips → Settings → Manage Consent
      - Add Diamonds → Settings → Manage Consent
      - Add Cash → Settings → Manage Consent

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Agree
        • Thanks
        • Like
      • 23 replies
    • DEAD TARGET: FPS Zombie Games v6.166.0 +5 Jailed Cheats
      Modded/Hacked App: DEAD TARGET: Zombie By Trung Nguyen
      Bundle ID: com.vng.g6.a.zombie
      iTunes Store Link: https://itunes.apple.com/us/app/dead-target-zombie/id901793885?mt=8&uo=4&at=1010lce4

      Hack Features:
      - Unlimited Gold
      - Unlimited Cash
      - Unlimited Grenades
      - Unlimited MedKits
      - Unlimited Ammo
      - High Accuracy
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 199 replies
    • E.D.E.N : The Last Line +5 Jailed Cheats
      Modded/Hacked App: E.D.E.N : The Last Line By Game Duo Co.,Ltd.
      Bundle ID: net.gameduo.dfd
      App Store Link: https://apps.apple.com/us/app/e-d-e-n-the-last-line/id6754559095?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Always Win → Quit
      - Game Speed Multiplier
      - Unlimited Currencies → Spend/Gain
      - Premium Pass

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Agree
        • Thanks
        • Like
      • 19 replies
    • Element War : Merge Games v1.0.3 [ +1 Cheats ] Currency Max
      Modded/Hacked App: Element War : Merge Games By Gamify Studio FZ-LLC
      Bundle ID: com.gamifystudio.elementalbattle
      App Store Link: https://apps.apple.com/nz/app/element-war-merge-games/id6753741421?uo=4

      🤩 Hack Features

      - Unlimited Coins
        • Winner
      • 3 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines