Jump to content

4 posts in this topic

Recommended Posts

Hello everyone! I am having an issue when analyzing the Mach-O executable for the IOS Application: Subway Surfers inside of Ghidra. I will lay out the thread with the steps I have successfully taken, and outline where the issue that I am facing occurs. Any insight into why this issue could be occurring would be greatly appreciated, I'm here to learn, and if there are things that I am doing incorrectly, or could be doing differently, please let me know.

 

Steps Taken So Far:

  1. Extracted the IPA File:

    • I have successfully extracted the Subway Surfers IPA to locate the key files, including the Mach-O executable and global-metadata.dat.
  2. Confirmed Global-Metadata.dat:

    • Located the global-metadata.dat file in the Metadata folder, which is crucial for dumping the IL2CPP structures.
  3. Dumped IL2CPP:

    • Used IL2CPP Dumper on both the Mach-O executable and global-metadata.dat to extract the dump.cs and script.json files.
    • These files include critical information about game methods, classes, and offsets, including the ColliderEnable property.
  4. Imported the Mach-O Executable into Ghidra:

    • I have imported the Subway Surfers Mach-O executable into Ghidra for analysis. I set the processor language to AARCH64: AppleSilicon (default) and used the Mac OS X Mach-O format for import.
  5. Attempted to Locate the Function Offset:

    • Based on the dump.cs output, I attempted to find the ColliderEnable function using its RVA (Relative Virtual Address) from IL2CPP Dumper:
      • get_ColliderEnable: RVA = 0x29E60
      • set_ColliderEnable: RVA = 0x29E80
    • I calculated the absolute memory address by adding the base address of 0x100000000 (as determined from the Memory Map in Ghidra) to these RVAs:
      • get_ColliderEnable: 0x100029E60
      • set_ColliderEnable: 0x100029E80
    • However, when using Ghidra’s “Go To” function to navigate to these addresses, we consistently receive a “no results” error.
  6. Reanalyzed the Mach-O Executable:

    • I reanalyzed the file in Ghidra, enabling all necessary analysis passes (function identification, instruction decoding, etc.).
    • I also attempted to search for function names and program text (e.g., ColliderEnable) manually, but the function still could not be found.
  7. Encountered Swift Demangler Issues:

    • Ghidra reported an error about missing Swift demangling tools, leading to the possibility that Ghidra is struggling with sections of the binary related to Swift. I considered that Swift dependencies might interfere with the analysis process and installed Swift onto my machine.

The Issue I am Facing in Ghidra:

  • Despite importing the Mach-O binary correctly and reanalyzing the file, Ghidra is unable to locate the function offsets or names for ColliderEnable (or other related methods) based on the RVAs provided by IL2CPP Dumper.
  • I have already verified that the base address and RVA calculation are correct (using the memory map), but Ghidra still returns “no results” when navigating to the calculated addresses.
  • The Swift demangler error may be preventing full analysis or proper resolution of some sections of the binary, but the specific connection to this issue is unclear.

What I Need Help With:

  • Understanding why Ghidra can’t find the function offset even though the base address and RVAs seem correct.
  • Determining if the Swift-related errors could be affecting our ability to locate the function.
  • Identifying any potential additional steps or configurations in Ghidra to resolve this issue (or if another tool might handle this better - I don't have IDA).

I appreciate any insight into why this issue could be occurring. If there is something that I am overlooking, I would greatly appreciate any additional information so that I can learn how to resolve this.

6 minutes ago, Laxus said:

You do not need to add 0x1000000 if the executable is the Frameworks

Just go to that RVA offset

Interesting, I wasn't aware of this. I will give this a try. Thanks.

Edit: The issue still persists, I could only imagine that I am somehow importing the Mach-O for analyzation incorrectly.

Updated by Game Sphere
Update Result (Issue Persistence)

Bumping this as I still haven't been able to solve this issue. I'm a bit dumbfounded. For anyone that has read my original post, I have also tried importing the Mach-O Executable into Hopper, Ghidra, and Cutter. All of which I am having the same issues with. It leaves me with the thoughts that I must be importing incorrectly, or something along those lines, but any input would be appreciated as I'm stumped.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below. For more information, please read our Posting Guidelines.
Reply to this topic... Posting Guidelines

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Our picks

    • Slayer Legend Cheats v600.0.1 +3
      Modded/Hacked App: Slayer Legend By GEAR2
      Bundle ID: com.gear2.growslayer
      iTunes Store Link: https://apps.apple.com/us/app/slayer-legend/id1635712706?uo=4


      Hack Features:
      - Multiply Attack
      - Multiply Defense
      - Freeze Currencies


      iOS Hack Download Link: https://iosgods.com/topic/186299-slayer-legend-cheats-v50084-3/
      • 56 replies
    • Rent Please! Landlord Sim Cheats v1.5.1 +2
      Modded/Hacked App: Rent Please! Landlord Sim By Shimmer Games Co., Ltd.
      Bundle ID: com.shimmergames.tenants.gb.en
      iTunes Store Link: https://apps.apple.com/us/app/rent-please-landlord-sim/id1645842987?uo=4


      Hack Features:
      - Infinite Currencies
      - No Ads


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/168311-rent-please-landlord-sim-v111-jailed-cheats-2/


      iOS Hack Download Link: https://iosgods.com/topic/168312-rent-please-landlord-sim-cheats-v111-2/
      • 120 replies
    • Battle Legion - Mass Battler Cheats v4.1.0 +4
      Modded/Hacked App: Battle Legion - Mass Battler By Traplight Ltd.
      Bundle ID: com.traplight.battleslides
      iTunes Store Link: https://apps.apple.com/us/app/battle-legion-mass-battler/id1435133042?uo=4&at=1010lce4


      Hack Features:
      - Multiply Attack
      - Multiply Defense
      - Instant Win
      - Enemies Don't Move
      - Enemies Don't Attack

      NOTE: This cheat will auto update itself so it work for all version. For Instant Win feature it will update in-game so it will freeze your game for few sec, just wait for it you only need to do this once. DO NOT QUIT THE GAME

      NOTE 2: I recommended turn on each features for each attack so the cheat can update itself smoothly


      iOS Hack Download Link: https://iosgods.com/topic/129669-battle-legion-mass-battler-cheats-all-versions-x-player-damage-more/
      • 513 replies
    • AdVenture Capitalist Cheats v9.5.0 +1
      Modded/Hacked App: AdVenture Capitalist By Hyper Hippo Publishing Ltd.
      Bundle ID: com.kongregate.mobile.adventurecapitalist
      iTunes Store Link: https://apps.apple.com/us/app/adventure-capitalist/id927006017?uo=4


      Hack Features:
      - Freeze Currencies

       
      Free Non-Jailbroken Hack:  https://iosgods.com/topic/82751-adventure-capitalist-v940-jailed-cheats-1/


      Hack Download Link: https://iosgods.com/topic/78370-adventure-capitalist-cheats-v940-1/
      • 1,171 replies
    • Travel Town - Merge Adventure Cheats v2.12.810 +1
      Modded/Hacked App: Travel Town By Magmatic Games Ltd
      Bundle ID: io.randomco.travel
      iTunes Store Link: https://apps.apple.com/us/app/travel-town/id1521236603?uo=4


      Hack Features:
      - Infinite Currencies


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/148953-travel-town-v231-jailed-cheats-1/

      iOS Hack Download Link: https://iosgods.com/topic/148951-travel-town-cheats-all-versions-1/
      • 116 replies
    • FarmVille 2: Country Escape Cheats v27.0 +1
      Modded/Hacked App: FarmVille 2: Country Escape by Zynga Inc.
      Bundle ID: com.zynga.FarmVille2CountryEscape
      iTunes Store Link: https://apps.apple.com/us/app/farmville-2-country-escape/id824318267?uo=4&at=1010lce4


      Hack Features:
      - Freeze Key


      iOS Hack Download Link: https://iosgods.com/topic/101607-arm64-farmville-2-country-escape-cheats-v1263984-1/
      • 1,959 replies
    • BitLife - Life Simulator Cheats v3.16.2 +2
      Modded/Hacked App: BitLife - Life Simulator by Candywriter, LLC
      Bundle ID: com.wtfapps.apollo16
      iTunes Store Link: https://apps.apple.com/us/app/bitlife-life-simulator/id1374403536?uo=4&at=1010lce4


      Hack Features:
      - Infinite Cash
      - Free Bitizen Purchase (Press Cancle) - Work for All Versions


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/84167-arm64-bitlife-life-simulator-v1412-jailed-cheats-2/


      Hack Download Link: https://iosgods.com/topic/84223-arm64-bitlife-life-simulator-cheats-all-versions-2/
      • 3,280 replies
    • Bloons TD 6 v45.3 +24 MEGA Cheats + [Free Paid IPA]
      Modded/Hacked App: Bloons TD 6 By Ninja Kiwi Limited
      Bundle ID: com.ninjakiwi.bloonstd6
      iTunes Store Link: https://apps.apple.com/us/app/bloons-td-6/id1118115766?uo=4


      Hack Features:
      - God Mode -updated- Clear Bloons -new
      - Auto Win Game -new
      - Set Round -new
      - Restart Game -new
      - Add Cash - new
      - Place towers anywhere
      - Multiple God Towers
      - Infinite Cash
      - Infinite Monkey Money
      - Infinite Powers
      - Unlock all Heros
      - Unlock all Knoledge
      - Unlock all towers
      - Unlock all upgrades 
      - Can unlock map (click locked map)
      - Skip tutorial (load the games first tutorial then exit app and start it. should skip tutorial) -new
      • 1,640 replies
    • Cat Snack Bar Cheats v1.0.148 +1
      Modded/Hacked App: Cat Snack Bar By treeplla Inc.
      Bundle ID: com.tree.idle.catsnackbar
      iTunes Store Link: https://apps.apple.com/us/app/cat-snack-bar/id6443895159?uo=4


      Hack Features:
      - Freeze Currencies


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/170232-cat-snack-bar-v1036-jailed-cheats-1/


      iOS Hack Download Link: https://iosgods.com/topic/170233-cat-snack-bar-cheats-v1036-1/
      • 64 replies
    • Temple Run 2 Cheats v1.116.0 +8
      Modded/Hacked App: Temple Run 2 by Imangi Studios, LLC
      Bundle ID: com.imangi.templerun2
      iTunes Store Link: https://apps.apple.com/us/app/temple-run-2/id572395608?uo=4&at=1010lce4


      Hack Features:
      - No Ads Enabled
      - x2 Coin Enabled
      - Infinite Coin (Spend some)
      - Infinite Gem (Spend some)
      - All Characters Unlocked
      - Free iAP (Turn off all iap hacks before using this, also if itunes popup don't show then run ldrestart in terminal -- This is an issue with the jailbreak not the hack)
      - Auto Run
      - Coin Magnet


      iOS Hack Download Link: https://iosgods.com/topic/132609-arm64-temple-run-2-cheats-v1691-8/
      • 289 replies
    • Eatventure v1.26.1 Jailed Cheats +2
      Modded/Hacked App: Eatventure By Lessmore UG haftungsbeschraenkt
      Bundle ID: com.hwqgrhhjfd.idlefastfood
      iTunes Store Link: https://apps.apple.com/us/app/eatventure/id1600871388?uo=4


      Hack Features:
      - Freeze Currencies
      - Free iAP (Turn on inside iOSGods Mod Menu first)


      Jailbreak required hack(s): https://iosgods.com/topic/168170-eatventure-cheats-all-versions-1/


      iOS Hack Download IPA Link: https://iosgods.com/topic/168169-eatventure-v110-jailed-cheats-2/
      • 278 replies
    • Heavenly Demon IDLE RPG v1.052 +2 Jailed Cheats
      Modded/Hacked App: Heavenly Demon IDLE RPG By StandEgg Co., Ltd
      Bundle ID: com.standegg.glcheonma
      iTunes Store Link: https://apps.apple.com/us/app/heavenly-demon-idle-rpg/id6504672068?uo=4


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Never Die
      - Reward Multiplier


      Jailbreak required hack(s): 


      iOS Hack Download IPA Link:

      Hidden Content

      Download via the iOSGods App








      PC Installation Instructions:
      STEP 1: If necessary, uninstall the app if you have it installed on your iDevice. Some hacked IPAs will install as a duplicate app. Make sure to back it up so you don't lose your progress.
      STEP 2: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see this tutorial topic.
      STEP 3: Download Sideloadly and install it on your PC.
      STEP 4: Open/Run Sideloadly on your computer, connect your iOS Device, and wait until your device name shows up.
      STEP 5: Once your iDevice appears, drag the modded .IPA file you downloaded and drop it inside the Sideloadly application.
      STEP 6: You will now have to enter your iTunes/Apple ID email login, press "Start" & then you will be asked to enter your password. Go ahead and enter the required information.
      STEP 7: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 8: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles/VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 9: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. Jailbroken iDevices can also use Sideloadly/Filza/IPA Installer to normally install the IPA with AppSync. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - AlyssaX64


      Cheat Video/Screenshots:

      N/A
      • 65 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines