Jump to content

Help with disabling _syscall


Guest

36 posts in this topic

Recommended Posts

  • Replies 35
  • Created
  • Last Reply

I know that already, this is one of the first forums I've signed up with. I know how to use GDB to find offsets in IDA and I know how to patch a binary. My first hack was a savegame for COD: BOZ for v1.3.3, I already learned MS, MSHook, and I'm doing IDA and code inject (writeData) right now and I'm working on Dead Trigger 2 but decided to take a break and do this because I get angry very easily lol

 

so im not really a beginner ;)

 

@ 

@

sorry u were new thats why i thought that! ok then keep it up bro

haha worked for me in bia3 too :p

hack it or i will :p

Link to comment
Share on other sites

I'm using a 5S by the way

 

I've never worked with disabling _syscall and _dlsym before so this is pretty hard, and I can't figure this out. I know that NOP'ing a BLX or any branch would result in a crash, so I stayed away from that. I xref'ed to operand for _dlsym and it gave me this:

 

__text:00648B04 loc_648B04                              ; CODE XREF: sub_648A04+D8j

__text:00648B04                 LDR             R0, [sP,#0x70+var_1C]
__text:00648B06                 BL              sub_649168
__text:00648B0A                 MOVS            R2, #1
__text:00648B10                 MOV             R1, #(_objc_msgSend_ptr - 0x648B1C)
__text:00648B18                 ADD             R1, PC ; _objc_msgSend_ptr
__text:00648B1A                 LDR             R1, [R1] ; __imp__objc_msgSend
__text:00648B1C                 MOV             R3, #(selRef_cStringUsingEncoding_ - 0x648B28)
__text:00648B24                 ADD             R3, PC ; selRef_cStringUsingEncoding_
__text:00648B26                 STR             R0, [sP,#0x70+var_2C]
__text:00648B28                 LDR             R0, [sP,#0x70+var_2C]
__text:00648B2A                 LDR.W           R9, [sP,#0x70+var_20]
__text:00648B2E                 LDR             R3, [R3] ; "cStringUsingEncoding:"
__text:00648B30                 STR             R0, [sP,#0x70+handle]
__text:00648B32                 MOV             R0, R9
__text:00648B34                 STR             R1, [sP,#0x70+var_50]
__text:00648B36                 MOV             R1, R3
__text:00648B38                 LDR             R3, [sP,#0x70+var_50]
__text:00648B3A                 BLX             R3
__text:00648B3C                 LDR             R1, [sP,#0x70+handle]
__text:00648B3E                 STR             R0, [sP,#0x70+symbol]
__text:00648B40                 MOV             R0, R1  ; handle 
__text:00648B42                 LDR             R1, [sP,#0x70+symbol] ; symbol
__text:00648B44                 BLX             _dlsym
__text:00648B48                 MOV             R1, #(_objc_msgSend_ptr - 0x648B54)
__text:00648B50                 ADD             R1, PC ; _objc_msgSend_ptr
__text:00648B52                 LDR             R1, [R1] ; __imp__objc_msgSend
__text:00648B54                 MOV             R2, R1
__text:00648B56                 MOV             R3, #(selRef_setObject_forKey_ - 0x648B62)
__text:00648B5E                 ADD             R3, PC ; selRef_setObject_forKey_
__text:00648B60                 MOV             R9, #(selRef_valueWithPointer_ - 0x648B6C)
__text:00648B68                 ADD             R9, PC ; selRef_valueWithPointer_
__text:00648B6A                 MOV             R12, #(classRef_NSValue - 0x648B76)
__text:00648B72                 ADD             R12, PC ; classRef_NSValue
__text:00648B74                 MOV             LR, #(dword_B062A4 - 0x648B80)
__text:00648B7C                 ADD             LR, PC ; dword_B062A4
__text:00648B7E                 STR             R0, [sP,#0x70+var_30]
__text:00648B80                 LDR.W           R0, [LR]
__text:00648B84                 LDR.W           R12, [R12] ; _OBJC_CLASS_$_NSValue
__text:00648B88                 LDR.W           LR, [sP,#0x70+var_30]
__text:00648B8C                 LDR.W           R9, [R9] ; "valueWithPointer:"
__text:00648B90                 STR             R0, [sP,#0x70+var_58]
__text:00648B92                 MOV             R0, R12
__text:00648B94                 STR             R1, [sP,#0x70+var_5C]
__text:00648B96                 MOV             R1, R9
__text:00648B98                 STR             R2, [sP,#0x70+var_60]
__text:00648B9A                 MOV             R2, LR
__text:00648B9C                 LDR.W           R9, [sP,#0x70+var_5C]
__text:00648BA0                 STR             R3, [sP,#0x70+var_64]
__text:00648BA2                 BLX             R9
__text:00648BA4                 LDR             R1, [sP,#0x70+var_24]
__text:00648BA6                 LDR             R2, [sP,#0x70+var_64]
__text:00648BA8                 LDR             R3, [R2]
__text:00648BAA                 LDR.W           R9, [sP,#0x70+var_58]
__text:00648BAE                 STR             R0, [sP,#0x70+var_68]
__text:00648BB0                 MOV             R0, R9
__text:00648BB2                 STR             R1, [sP,#0x70+var_6C]
__text:00648BB4                 MOV             R1, R3
__text:00648BB6                 LDR             R2, [sP,#0x70+var_68]
__text:00648BB8                 LDR             R3, [sP,#0x70+var_6C]
__text:00648BBA                 LDR.W           R9, [sP,#0x70+var_60]
__text:00648BBE                 BLX             R9
__text:00648BC0                 LDR             R0, [sP,#0x70+var_30]
__text:00648BC2                 STR             R0, [sP,#0x70+var_18]
 
And I was not really sure about what to do with any of this. I feel like changing these four lines would do the trick, but I really have no idea what to change them to.
 
__text:00648B3C                 LDR             R1, [sP,#0x70+handle]
__text:00648B3E                 STR             R0, [sP,#0x70+symbol]
__text:00648B40                 MOV             R0, R1  ; handle 
__text:00648B42                 LDR             R1, [sP,#0x70+symbol] ; symbol
__text:00648B44                 BLX             _dlsym ----> I wouldn't change this, I just put it there for clarity.
 
So, not knowing really what to do there I xref'ed to operand loc_648B04 and got this:
 
__text:00648A50 loc_648A50                              ; CODE XREF: sub_648A04+1Ej
__text:00648A50                                         ; sub_648A04:loc_648A4Ej
__text:00648A50                 MOVS            R0, #0
__text:00648A56                 MOV             R1, #(_objc_msgSend_ptr - 0x648A62)
__text:00648A5E                 ADD             R1, PC ; _objc_msgSend_ptr
__text:00648A60                 LDR             R1, [R1] ; __imp__objc_msgSend
__text:00648A62                 MOV             R2, R1
__text:00648A64                 MOV             R3, #(selRef_objectForKey_ - 0x648A70)
__text:00648A6C                 ADD             R3, PC ; selRef_objectForKey_
__text:00648A6E                 MOV             R9, #(dword_B062A4 - 0x648A7A)
__text:00648A76                 ADD             R9, PC ; dword_B062A4
__text:00648A78                 MOV             R12, #(stru_AE58E0 - 0x648A84) ; "%@:%@"
__text:00648A80                 ADD             R12, PC ; "%@:%@"
__text:00648A82                 MOV             LR, #(selRef_stringWithFormat_ - 0x648A8E)
__text:00648A8A                 ADD             LR, PC ; selRef_stringWithFormat_
__text:00648A8C                 MOV             R4, #(classRef_NSString - 0x648A98)
__text:00648A94                 ADD             R4, PC ; classRef_NSString
__text:00648A96                 LDR             R4, [R4] ; _OBJC_CLASS_$_NSString
__text:00648A98                 LDR             R5, [sP,#0x70+var_1C]
__text:00648A9A                 LDR             R6, [sP,#0x70+var_20]
__text:00648A9C                 LDR.W           LR, [LR] ; "stringWithFormat:"
__text:00648AA0                 STR             R0, [sP,#0x70+var_34]
__text:00648AA2                 MOV             R0, R4
__text:00648AA4                 STR             R1, [sP,#0x70+var_38]
__text:00648AA6                 MOV             R1, LR
__text:00648AA8                 STR             R2, [sP,#0x70+var_3C]
__text:00648AAA                 MOV             R2, R12
__text:00648AAC                 STR             R3, [sP,#0x70+var_40]
__text:00648AAE                 MOV             R3, R5
__text:00648AB0                 STR             R6, [sP,#0x70+var_70]
__text:00648AB2                 LDR.W           R12, [sP,#0x70+var_38]
__text:00648AB6                 STR.W           R9, [sP,#0x70+var_44]
__text:00648ABA                 BLX             R12
__text:00648ABC                 STR             R0, [sP,#0x70+var_24]
__text:00648ABE                 LDR             R0, [sP,#0x70+var_44]
__text:00648AC0                 LDR             R1, [R0]
__text:00648AC2                 LDR             R2, [sP,#0x70+var_24]
__text:00648AC4                 LDR             R3, [sP,#0x70+var_40]
__text:00648AC6                 LDR.W           R9, [R3]
__text:00648ACA                 MOV             R0, R1
__text:00648ACC                 MOV             R1, R9
__text:00648ACE                 LDR.W           R9, [sP,#0x70+var_3C]
__text:00648AD2                 BLX             R9
__text:00648AD4                 STR             R0, [sP,#0x70+var_28]
__text:00648AD6                 LDR             R0, [sP,#0x70+var_28]
__text:00648AD8                 LDR             R1, [sP,#0x70+var_34]
__text:00648ADA                 CMP             R0, R1
__text:00648ADC                 BEQ             loc_648B04
__text:00648ADE                 MOV             R0, #(_objc_msgSend_ptr - 0x648AEA)
__text:00648AE6                 ADD             R0, PC ; _objc_msgSend_ptr
__text:00648AE8                 LDR             R0, [R0] ; __imp__objc_msgSend
__text:00648AEA                 MOV             R1, #(selRef_pointerValue - 0x648AF6)
__text:00648AF2                 ADD             R1, PC ; selRef_pointerValue
__text:00648AF4                 LDR             R2, [sP,#0x70+var_28]
__text:00648AF6                 LDR             R1, [R1] ; "pointerValue"
__text:00648AF8                 STR             R0, [sP,#0x70+var_48]
__text:00648AFA                 MOV             R0, R2
__text:00648AFC                 LDR             R2, [sP,#0x70+var_48]
__text:00648AFE                 BLX             R2
__text:00648B00                 STR             R0, [sP,#0x70+var_18]
__text:00648B02                 B               loc_648BC4
 

I'm pretty sure that these lines mean to

 

__text:00648AD4                 STR             R0, [sP,#0x70+var_28] ----> store the value of R0 into SP+70+var_28

__text:00648AD6                 LDR             R0, [sP,#0x70+var_28] ----> load SP+70+var_28 into R0
__text:00648AD8                 LDR             R1, [sP,#0x70+var_34] ----> load SP+70+var_34 into R1
__text:00648ADA                 CMP             R0, R1 ----> compare R1 with R0
__text:00648ADC                 BEQ             loc_648B04 ----> branch if equal to loc_648B04
 
I changed CMP R0, R1 to CMP R0, #0 to at least try to make it false and CMP R0, R7 because I know it would never be equal to 800 million. I'm used to having to set MOVS R1, #0x1F to MOVS R1, #0x00 to make this work, not all of this stuff.
 
@@Laxus you said that you got it to work, would you be able to send me a binary with all of this stuff disabled? And I have a 5S, would that affect anything?
 
Thanks everyone for trying to help, I really appreciate it :)
Link to comment
Share on other sites

 

I'm using a 5S by the way

 

I've never worked with disabling _syscall and _dlsym before so this is pretty hard, and I can't figure this out. I know that NOP'ing a BLX or any branch would result in a crash, so I stayed away from that. I xref'ed to operand for _dlsym and it gave me this:

 

__text:00648B04 loc_648B04 ; CODE XREF: sub_648A04+D8j

__text:00648B04 LDR R0, [sP,#0x70+var_1C]

__text:00648B06 BL sub_649168

__text:00648B0A MOVS R2, #1

__text:00648B10 MOV R1, #(_objc_msgSend_ptr - 0x648B1C)

__text:00648B18 ADD R1, PC ; _objc_msgSend_ptr

__text:00648B1A LDR R1, [R1] ; __imp__objc_msgSend

__text:00648B1C MOV R3, #(selRef_cStringUsingEncoding_ - 0x648B28)

__text:00648B24 ADD R3, PC ; selRef_cStringUsingEncoding_

__text:00648B26 STR R0, [sP,#0x70+var_2C]

__text:00648B28 LDR R0, [sP,#0x70+var_2C]

__text:00648B2A LDR.W R9, [sP,#0x70+var_20]

__text:00648B2E LDR R3, [R3] ; "cStringUsingEncoding:"

__text:00648B30 STR R0, [sP,#0x70+handle]

__text:00648B32 MOV R0, R9

__text:00648B34 STR R1, [sP,#0x70+var_50]

__text:00648B36 MOV R1, R3

__text:00648B38 LDR R3, [sP,#0x70+var_50]

__text:00648B3A BLX R3

__text:00648B3C LDR R1, [sP,#0x70+handle]

__text:00648B3E STR R0, [sP,#0x70+symbol]

__text:00648B40 MOV R0, R1 ; handle

__text:00648B42 LDR R1, [sP,#0x70+symbol] ; symbol

__text:00648B44 BLX _dlsym

__text:00648B48 MOV R1, #(_objc_msgSend_ptr - 0x648B54)

__text:00648B50 ADD R1, PC ; _objc_msgSend_ptr

__text:00648B52 LDR R1, [R1] ; __imp__objc_msgSend

__text:00648B54 MOV R2, R1

__text:00648B56 MOV R3, #(selRef_setObject_forKey_ - 0x648B62)

__text:00648B5E ADD R3, PC ; selRef_setObject_forKey_

__text:00648B60 MOV R9, #(selRef_valueWithPointer_ - 0x648B6C)

__text:00648B68 ADD R9, PC ; selRef_valueWithPointer_

__text:00648B6A MOV R12, #(classRef_NSValue - 0x648B76)

__text:00648B72 ADD R12, PC ; classRef_NSValue

__text:00648B74 MOV LR, #(dword_B062A4 - 0x648B80)

__text:00648B7C ADD LR, PC ; dword_B062A4

__text:00648B7E STR R0, [sP,#0x70+var_30]

__text:00648B80 LDR.W R0, [LR]

__text:00648B84 LDR.W R12, [R12] ; _OBJC_CLASS_$_NSValue

__text:00648B88 LDR.W LR, [sP,#0x70+var_30]

__text:00648B8C LDR.W R9, [R9] ; "valueWithPointer:"

__text:00648B90 STR R0, [sP,#0x70+var_58]

__text:00648B92 MOV R0, R12

__text:00648B94 STR R1, [sP,#0x70+var_5C]

__text:00648B96 MOV R1, R9

__text:00648B98 STR R2, [sP,#0x70+var_60]

__text:00648B9A MOV R2, LR

__text:00648B9C LDR.W R9, [sP,#0x70+var_5C]

__text:00648BA0 STR R3, [sP,#0x70+var_64]

__text:00648BA2 BLX R9

__text:00648BA4 LDR R1, [sP,#0x70+var_24]

__text:00648BA6 LDR R2, [sP,#0x70+var_64]

__text:00648BA8 LDR R3, [R2]

__text:00648BAA LDR.W R9, [sP,#0x70+var_58]

__text:00648BAE STR R0, [sP,#0x70+var_68]

__text:00648BB0 MOV R0, R9

__text:00648BB2 STR R1, [sP,#0x70+var_6C]

__text:00648BB4 MOV R1, R3

__text:00648BB6 LDR R2, [sP,#0x70+var_68]

__text:00648BB8 LDR R3, [sP,#0x70+var_6C]

__text:00648BBA LDR.W R9, [sP,#0x70+var_60]

__text:00648BBE BLX R9

__text:00648BC0 LDR R0, [sP,#0x70+var_30]

__text:00648BC2 STR R0, [sP,#0x70+var_18]

 

And I was not really sure about what to do with any of this. I feel like changing these four lines would do the trick, but I really have no idea what to change them to.

 

__text:00648B3C LDR R1, [sP,#0x70+handle]

__text:00648B3E STR R0, [sP,#0x70+symbol]

__text:00648B40 MOV R0, R1 ; handle

__text:00648B42 LDR R1, [sP,#0x70+symbol] ; symbol

__text:00648B44 BLX _dlsym ----> I wouldn't change this, I just put it there for clarity.

 

So, not knowing really what to do there I xref'ed to operand loc_648B04 and got this:

 

__text:00648A50 loc_648A50 ; CODE XREF: sub_648A04+1Ej

__text:00648A50 ; sub_648A04:loc_648A4Ej

__text:00648A50 MOVS R0, #0

__text:00648A56 MOV R1, #(_objc_msgSend_ptr - 0x648A62)

__text:00648A5E ADD R1, PC ; _objc_msgSend_ptr

__text:00648A60 LDR R1, [R1] ; __imp__objc_msgSend

__text:00648A62 MOV R2, R1

__text:00648A64 MOV R3, #(selRef_objectForKey_ - 0x648A70)

__text:00648A6C ADD R3, PC ; selRef_objectForKey_

__text:00648A6E MOV R9, #(dword_B062A4 - 0x648A7A)

__text:00648A76 ADD R9, PC ; dword_B062A4

__text:00648A78 MOV R12, #(stru_AE58E0 - 0x648A84) ; "%@:%@"

__text:00648A80 ADD R12, PC ; "%@:%@"

__text:00648A82 MOV LR, #(selRef_stringWithFormat_ - 0x648A8E)

__text:00648A8A ADD LR, PC ; selRef_stringWithFormat_

__text:00648A8C MOV R4, #(classRef_NSString - 0x648A98)

__text:00648A94 ADD R4, PC ; classRef_NSString

__text:00648A96 LDR R4, [R4] ; _OBJC_CLASS_$_NSString

__text:00648A98 LDR R5, [sP,#0x70+var_1C]

__text:00648A9A LDR R6, [sP,#0x70+var_20]

__text:00648A9C LDR.W LR, [LR] ; "stringWithFormat:"

__text:00648AA0 STR R0, [sP,#0x70+var_34]

__text:00648AA2 MOV R0, R4

__text:00648AA4 STR R1, [sP,#0x70+var_38]

__text:00648AA6 MOV R1, LR

__text:00648AA8 STR R2, [sP,#0x70+var_3C]

__text:00648AAA MOV R2, R12

__text:00648AAC STR R3, [sP,#0x70+var_40]

__text:00648AAE MOV R3, R5

__text:00648AB0 STR R6, [sP,#0x70+var_70]

__text:00648AB2 LDR.W R12, [sP,#0x70+var_38]

__text:00648AB6 STR.W R9, [sP,#0x70+var_44]

__text:00648ABA BLX R12

__text:00648ABC STR R0, [sP,#0x70+var_24]

__text:00648ABE LDR R0, [sP,#0x70+var_44]

__text:00648AC0 LDR R1, [R0]

__text:00648AC2 LDR R2, [sP,#0x70+var_24]

__text:00648AC4 LDR R3, [sP,#0x70+var_40]

__text:00648AC6 LDR.W R9, [R3]

__text:00648ACA MOV R0, R1

__text:00648ACC MOV R1, R9

__text:00648ACE LDR.W R9, [sP,#0x70+var_3C]

__text:00648AD2 BLX R9

__text:00648AD4 STR R0, [sP,#0x70+var_28]

__text:00648AD6 LDR R0, [sP,#0x70+var_28]

__text:00648AD8 LDR R1, [sP,#0x70+var_34]

__text:00648ADA CMP R0, R1

__text:00648ADC BEQ loc_648B04

__text:00648ADE MOV R0, #(_objc_msgSend_ptr - 0x648AEA)

__text:00648AE6 ADD R0, PC ; _objc_msgSend_ptr

__text:00648AE8 LDR R0, [R0] ; __imp__objc_msgSend

__text:00648AEA MOV R1, #(selRef_pointerValue - 0x648AF6)

__text:00648AF2 ADD R1, PC ; selRef_pointerValue

__text:00648AF4 LDR R2, [sP,#0x70+var_28]

__text:00648AF6 LDR R1, [R1] ; "pointerValue"

__text:00648AF8 STR R0, [sP,#0x70+var_48]

__text:00648AFA MOV R0, R2

__text:00648AFC LDR R2, [sP,#0x70+var_48]

__text:00648AFE BLX R2

__text:00648B00 STR R0, [sP,#0x70+var_18]

__text:00648B02 B loc_648BC4

 

I'm pretty sure that these lines mean to

 

__text:00648AD4 STR R0, [sP,#0x70+var_28] ----> store the value of R0 into SP+70+var_28

__text:00648AD6 LDR R0, [sP,#0x70+var_28] ----> load SP+70+var_28 into R0

__text:00648AD8 LDR R1, [sP,#0x70+var_34] ----> load SP+70+var_34 into R1

__text:00648ADA CMP R0, R1 ----> compare R1 with R0

__text:00648ADC BEQ loc_648B04 ----> branch if equal to loc_648B04

 

I changed CMP R0, R1 to CMP R0, #0 to at least try to make it false and CMP R0, R7 because I know it would never be equal to 800 million. I'm used to having to set MOVS R1, #0x1F to MOVS R1, #0x00 to make this work, not all of this stuff.

 

@@Laxus you said that you got it to work, would you be able to send me a binary with all of this stuff disabled? And I have a 5S, would that affect anything?

 

Thanks everyone for trying to help, I really appreciate it :)

Nop try this C046C046 done :)

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Our picks

    • Jurassic World Alive v3.5.29 - [ Dino Don't Move & More ]
      Modded/Hacked App: Jurassic World Alive By Ludia
      Bundle ID: com.ludia.jw2
      iTunes Store Link: https://apps.apple.com/us/app/jurassic-world-alive/id1231085864

      Hack Features:
      - Dino Don't Move
      - Inf.Battery
      - VIP Enabled

      This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Jailbreak required hack(s): https://iosgods.com/topic/103431-jurassic-world-alive-v1829-dino-dont-move-more/?tab=comments#comment-3107135
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,527 replies
    • Jurassic World Alive v3.5.29 - [ Dino Don't Move & More ]
      Modded/Hacked App: Jurassic World Alive By Ludia
      Bundle ID: com.ludia.jw2
      iTunes Store Link: https://apps.apple.com/us/app/jurassic-world-alive/id1231085864


      Hack Features:
      - Dino Don't Move
      - Inf. Battery
      - VIP Enabled

      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app. This hack works on the latest x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,462 replies
    • Idle Cinema Empire: Idle Games v2.13.01 +3 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Idle Cinema Empire: Idle Games By 书涛 刘
      Bundle ID: com.idle.cinema.empire.sim.tycoon
      iTunes Store Link: https://apps.apple.com/us/app/idle-cinema-empire-idle-games/id1660507282?uo=4


      Hack Features:
      - Unlimited Cash -> Earn some.
      - Unlimited Gold Coins -> Earn some.
      - Unlimited Diamonds -> Earn some.


      Jailbreak required hack(s): [Mod Menu Hack] Idle Cinema Empire: Idle Games ( All Versions ) +3 Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Haha
        • Thanks
        • Winner
        • Like
      • 42 replies
    • Idle Cinema Empire: Idle Games ( All Versions ) +3 Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Idle Cinema Empire: Idle Games By 书涛 刘
      Bundle ID: com.idle.cinema.empire.sim.tycoon
      iTunes Store Link: https://apps.apple.com/us/app/idle-cinema-empire-idle-games/id1660507282?uo=4


      Hack Features:
      - Unlimited Cash -> Earn some.
      - Unlimited Gold Coins -> Earn some.
      - Unlimited Diamonds -> Earn some.


      Non-Jailbroken & No Jailbreak required hack(s): [Non-Jailbroken Hack] Idle Cinema Empire: Idle Games v2.11.03 +3 Jailed Cheats [ Unlimited Currencies ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Agree
        • Thanks
        • Like
      • 12 replies
    • Dark Slayer : AFK RPG v1.1.4 +2 Cheats [ God Mode ]
      Modded/Hacked App: Dark Slayer : AFK RPG By Gamepub CO., LTD
      Bundle ID: com.gamepub.zhteam
      iTunes Store Link: https://apps.apple.com/us/app/dark-slayer-afk-rpg/id6446265751?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - God Mode
      - Attack Speed Multiplier
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 170 replies
    • Longleaf Valley: Merge & Plant v1.15.58 +1++ Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Longleaf Valley: Merge & Plant By TreesPlease Games Ltd
      Bundle ID: com.treespleasegames.merge1
      iTunes Store Link: https://apps.apple.com/us/app/longleaf-valley-merge-plant/id1573565989?uo=4


      Hack Features:
      - Unlimited Currencies -> Will increase instead of decrease.


      Jailbreak required hack(s): [Mod Menu Hack] Longleaf Valley: Merge & Plant ( All Versions ) +1++ Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Haha
        • Winner
        • Like
      • 15 replies
    • Longleaf Valley: Merge & Plant ( All Versions ) +1++ Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Longleaf Valley: Merge & Plant By TreesPlease Games Ltd
      Bundle ID: com.treespleasegames.merge1
      iTunes Store Link: https://apps.apple.com/us/app/longleaf-valley-merge-plant/id1573565989?uo=4


      Hack Features:
      - Unlimited Currencies -> Will increase instead of decrease.


      Non-Jailbroken & No Jailbreak required hack(s): [Non-Jailbroken Hack] Longleaf Valley: Merge & Plant v1.10.48 +1++ Jailed Cheats [ Unlimited Currencies ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Haha
        • Winner
        • Like
      • 3 replies
    • Idle Mushroom Hero : AFK RPG v1.02.067 +4 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Idle Mushroom Hero : AFK RPG By Ndolphin Connect
      Bundle ID: com.nextall.mushroomhero.apple
      iTunes Store Link: https://apps.apple.com/us/app/idle-mushroom-hero-afk-rpg/id6475755018?uo=4


      Hack Features:
      - God Mode
      - One-Hit Kill
      - Unlimited Gold -> Will increase instead of decrease.
      - Unlimited Diamonds -> Spend some.


      Jailbreak required hack(s): [Mod Menu Hack] Idle Mushroom Hero : AFK RPG v1.02.066 +5 Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Haha
        • Winner
        • Like
      • 17 replies
    • Idle Mushroom Hero : AFK RPG v1.02.067 +5 Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Idle Mushroom Hero : AFK RPG By Ndolphin Connect
      Bundle ID: com.nextall.mushroomhero.apple
      iTunes Store Link: https://apps.apple.com/us/app/idle-mushroom-hero-afk-rpg/id6475755018?uo=4


      Hack Features:
      - God Mode
      - One-Hit Kill
      - Unlimited Gold -> Will increase instead of decrease.
      - Unlimited Diamonds -> Spend some.
      - Auto Win


      Non-Jailbroken & No Jailbreak required hack(s): [Non-Jailbroken Hack] Idle Mushroom Hero : AFK RPG v1.02.066 +4 Jailed Cheats [ Unlimited Currencies ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Haha
        • Thanks
        • Winner
        • Like
      • 38 replies
    • Good Pizza, Great Pizza v5.8.1 +2 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Good Pizza, Great Pizza By TAPBLAZE, LLC
      Bundle ID: com.tapblaze.pizzabusiness
      iTunes Store Link: https://apps.apple.com/us/app/good-pizza-great-pizza/id911121200?uo=4


      Hack Features:
      - Unlimited Cash
      - Unlimited Diamonds


      Jailbreak required hack(s): [Mod Menu Hack] Good Pizza, Great Pizza v5.5.6 +2 Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Thanks
        • Winner
        • Like
      • 24 replies
    • Good Pizza, Great Pizza v5.8.1 +2 Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Good Pizza, Great Pizza By TAPBLAZE, LLC
      Bundle ID: com.tapblaze.pizzabusiness
      iTunes Store Link: https://apps.apple.com/us/app/good-pizza-great-pizza/id911121200?uo=4


      Hack Features:
      - Unlimited Cash
      - Unlimited Diamonds


      Non-Jailbroken & No Jailbreak required hack(s): [Non-Jailbroken Hack] Good Pizza, Great Pizza v5.5.6 +2 Jailed Cheats [ Unlimited Currencies ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Haha
        • Winner
        • Like
      • 16 replies
    • Merge Lion v2.2.0 +8 Jailed Cheats [ Unlimited Everything ]
      Modded/Hacked App: Merge Lion By GOMBLE GAMES PTE. LTD.
      Bundle ID: com.gomble.ios.mergelion
      iTunes Store Link: https://apps.apple.com/us/app/merge-lion/id6472009816?uo=4


      Hack Features:
      - Unlimited Gold
      - Unlimited Lives
      - Unlimited Boosters
      - Unlimited In-Game Boosters
      - Unlimited Bingo Lions
      - Unlimited Energy
      - Unlimited Pushes
      - Unlimited Capsules


      Jailbreak required hack(s): [Mod Menu Hack] Merge Lion v2.1.9 +9 Cheats [ Unlimited Everything ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Agree
        • Thanks
        • Like
      • 7 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines