Jump to content
Sign in to follow this  

TuT [Tutorial] How to use IDA to hack iOS Apps

7 posts in this topic

Recommended Posts

Hacking a Binary has never been easy for me. Well I don't know for you, because I am gonna be sharing some of my knowledge about IDA. Which you might find it hard to do because I am your trainer. So I am gonna start now.


When using IDA always remember that when Always choose the processor type to ARM Little Endian And

DO NOT open the Binary as Binary File open it as what your phone supports For example my phone supports ARMv7 or ARMv7s



After opening the Binary wait for it to load. You will know that it is fully loaded when the Bar on top is Blue.


And if hacking always search for the Fuction Name. For example Bucks. Use the little window on the left that is labeled "Function Name". And press Alt + T to search for the functions.


Then after you have found the Function its time to edit the instruction. The instructions are the things that makes the Function a Function. An example of an instruction is:

MOV R0, R7
ADD R0, R1, R0

And many more.


So now let's really start.


For example the instruction that I will edit is:

 LDRD.W          R0, R1, [R0,#0x334] (in hex: D0 E9 CD 01 - Which is 4 bytes)

And As I said that I will hack the bucks so that is the Loader. Loader, this thing loads the value into a register.


To hack this you must edit this to

MOV R0, R7 (in hex: 381C - Which is 2 bytes)

Changing it to MOV is not just changing it's name, you must edit it's hex.

After changing the hex. Save it, then the binary is hacked!


But if you're hacking the Buy price for example:

SUBS            R1, R0, R1

You could null, or instead of your money decreasing it will give you millions! This is how to do it.

The original instruction is

SUBS R1, R0, R1 (in hex: 41 1A - 2 bytes)

to null it you must make it to

NOP (in hex: C0 46 - 2 bytes)


change the SUBS R1, R0, R1

Hex to C0 46 to make it Free!!


or make it

MOV R0, R7 (in hex: 38 1C - 2 Bytes)

And if it's just a simple BOOL, it's instruction is

MOV R0, #1   -    TRUE

MOV R0, #0   -    False

I am not sure on everything that I have posted because I am just really a beginner at IDA, this is just a little tut that might help you.










I just summarized it.


And @Salman1700 here it is.

Edited by --Techarmor--
  • Like 1
  • Upvote 3

Share this post

Link to post
Share on other sites

 i forgot to say if you want to know if the binary is fully loaded just see this circle




if it green then the binary is fully loaded




sorry because i forgot :lol:


Edited by ITz_kser

Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

Sign in to follow this  

  • Similar Content

    • By AnotherLurker
      What is Theos?
      "Theos is a cross-platform suite of development tools for managing, developing, and deploying iOS software without the use of Xcode. It is an important tool for people building extensions (tweaks) for Jailbroken iOS Devices"
      ~ iPhoneDevWiki

      Theos essentially gives Developers a simple way to create and manage different types of projects, based off makefiles. Theos also includes Logos, a preprocessor that allows you to easily hook Objective-C classes and methods.

      In this tutorial, I will show you how to setup Theos on Windows to do exactly that

      - 5 to 10 minutes of your time (Depends on your internet speed & luck)

      Hidden Content
      React or reply to this topic to see the hidden content. More info

      Theos has now been installed and setup on your Windows machine.
      If you have any questions about this, or any issues you're facing, Post it here and I'll be glad to help out. If you're experiencing errors regarding LZMA, see this post.
    • By Pro
      Cheaters, are you tired of having to use the same old credit pop-ups in your tweaks/patchers? Today, I'm going to show you how to go from this

      to this

      iFile/iFilza/Whatever (I prefer iFile for this)
      Knowledge on making a tweak
      RKDropdownAlert files
      1. Download the files for RKDropdownAlert here: https://www.dropbox.com/s/6i04lvg9tea18ls/RKDropdownAlert.zip?dl=0
      2. Have a project made from Theos. This can be a new/old one; it won't matter. In my case, I will be making a new project, using the template found here: https://iosgods.com/topic/6289-update-13template-custom-cscsci-nictheos-template/
      3. Take the files you downloaded, unarchive them, and copy them into your project folder. Your project folder should look like this after doing so if you use the template provided above:
      4. Remove everything that's in the Tweak.xm, unless you plan on making a tweak with the project that you have. If that's the case, please have
      5. Now that you have everything you want removed, add this to the top of your Tweak.xm
      #import "RKDropdownAlert.h"   @interface AppDelegate : NSObject <RKDropdownAlertDelegate> @end   @implementation AppDelegate   -(BOOL)dropdownAlertWasDismissed { return YES; }   -(BOOL)dropdownAlertWasTapped:(RKDropdownAlert*)alert; {     return true; } @end Change "AppDelegate" to whatever class you're using for your credits pop-up.
      6. Go add eveything else you want in your tweak, features for some hack, whatever. After you're done with that (if you even did anything), add this to the bottom of your Tweak.xm
      %hook AppDelegate -(void)applicationDidBecomeActive:(id)argument {   [RKDropdownAlert title:@"RKDropdownAlert Test" message:@"Isn't this better than UIAlertView?" backgroundColor:[UIColor yellowColor] textColor:[UIColor orangeColor] time:10];   return %orig; }   %end     You can change the text by simply changing what's inside the quotations. I will leave it for now. You can also change the colors of the background and text of the view. Where it says [uIColor yellowColor] as well as orange, there is a list of default colors found here: http://foobarpig.com/iphone/uicolor-cheatsheet-color-list-conversion-from-and-to-rgb-values.html. With that, you can change yellow and orange to whatever's on there, except for clear, otherwise you won't see your view/text!   7. In your Makefile, find the line that says ProjectName_FILES = Tweak.xm, and add RKDropdownAlert.m (ProjectName is of course the name of the project you made) After you've done this, this is what your Makefile should look like, if you've used the template:     8. After that, you can compile it and test it on whatever app you use it on!     Credits: @Pro (Me) for showing this to you guys @DiDA for showing this to me and having me make this tut @0xBL4Z3R He pretty much started it all
    • By Amuyea 
      For Education Purpose only
      Jailbroken Device
      Rasticrac from repo.xarold.com
      iFile or Filza File Manager
      Mobileterminal (ios7)  for ios 7 and 8
      iFunbox to share ipa/hack binary etc
      Note: red text means that it can be different from the screenshots
      Open iFile and go to the path /usr/bin ... scroll down until you see the file r30c5.sh  or rc.sh

      PRESS on the blue arrow to the right of the file name to rename the file, you should get this window.

      RENAME the file. I would recommend renaming it to rasticrac
      The name you give it will be the command to bring up rasticrac in terminal.

      After you are done, go to Terminal app
      Type this in
      su root It will ask for your root password, if you have never changed it please enter
      alpine Then type and enter
      rasticrac –m It will show you the list of the apps in letter order
      type a letter then press enter
      Plug in your Device to PC/Laptop
      Open iFunbox
      Go to Raw File System
      Path to cracked ipa:
      /var/root/Documents/Cracked Credits: iChr0niX (orginal post in appaddict forum)
    • By The Epic Gamer
      Hello everyone, today I'm going to show you how to get Add-Ons Studio for Minecraft for free!
      App name: Add-Ons Studio for Minecraft
      App icon:

      Version: 1.0 (newest version at the time of posting this tutorial)
      iTunes link: https://itunes.apple.com/us/app/add-ons-studio-for-minecraft/id1187279979?mt=8
      1. Jailbroken idevice
      2.App Cake
      3.App Sync
      1.Open one of the links below (Safari is recommended)
      2.Wait 5 seconds then press Skip Ad
      3.It will redirect you to the website
      4.Press download and wait for it to finish
      5.Press open with App Cake
      6.Press install and wait for the installation
      7.You're done!
      Important! If the app crashes when opening it, try to install it with Cydia Impactor, if this doesn't work then it will not work unfortunately, try to look over the Internet for a fix 

      Hidden Content
      React or reply to this topic to see the hidden content. More info  
      Credit goes to 75Digital Ltd and the author
    • By Fadexz
      Here's how to install iGameGuardian without "Initialisation Error". I figured I would make a tutorial because there isn't much out there.

      Hidden Content
      React or reply to this topic to see the hidden content. More info
  • Recently Browsing   0 members

    No registered users viewing this page.

    • Administrator |
    • Global Moderator  |
    • Moderator  |
    • ViP Plus |
    • ViP |
    • Cheater |
    • Modder  |
    • Novice Cheater |
    • Rookie Modder |
    • Contributor |
    • Senior Member |
    • Member |

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.