Jump to content

Hooking functions from IDA into Mobile Substrate


Swagter123

15 posts in this topic

Recommended Posts

Requirements:

-Theos

-iPhone SDK
-IDA
-an iDevice 
 

So, enough speaking and lets start explaining:
Before starting, let me say that its better if you follow the guid on your computer and ssh to your device rather than using ifile.
 
Step 1.
You should first create a new project as so:

 


su

alpine

$THEOS/bin/nic.pl
hw0jv9.png
If you changed your root pass, change alpine to it.
 
Then type 5 for Tweaks or 6 if you added Iosgods patcher template.
and type in the info you want until you reach the filter bundle question; there you type in your game's bundle "com.GAMECOMPANY.GAME" which is usually found in:
"/var/mobile/Applications/"Game's Number"/Game.app/info.plist"
10gb5v8.png
 

Step 2.
 
Important Note: Please Don't Close The MobileTerminal/Putty/etc... We Will Use It Later
 
Open the Tweak.xm file and make sure that the following imports are used (if some aren't, add them):
 

[list=1][*][b]#import <CoreFoundation/CoreFoundation.h>[/b] [*][b]#import <substrate.h>[/b] (just in case) [*][b]#import <Foundation/Foundation.h>[/b](just in case as well) [/list]
Now, at the bottom of your code, either add:

__attribute__((constructor)) void DylibMain(){ }

Or

%ctor{ }

Inside either one of those two, add this:

MSHookFunction((( *)MSFindSymbol(NULL, "")),( *)$,( **)&old );
this code is missing vital parts that you will add in later
Don't worry if that confuses you, it will be explained
2449kwy.png
MSHookFunction: This is part of Mobile Substrate that allows you to hook many functions that you can see in IDA (sort of like %hook)
MSFindSymbol: This allows your tweak to find the function you want to edit
 
Step 3:
Open the game binary you want in IDA; in this tutorial, we'll be using the TempleRun binary which will be provided in the "Links" part.
nq8uc3.png
 
Search the function you want to hack (press alt+t)... In this case we will search "hasAngel".
vfwjnq.png
 
Then double click on "hasAngelWings".
2hpo8zq.png
 
Then copy and paste the function's symbolic name... In this case its "__ZNK7cPlayer13hasAngelWingsEv"
25usgmq.png
From here later, __ZNK7cPlayer13hasAngelWingsEv will be named as yourSymbolicFunction
Go back to Tweaks.xm and change

MSHookFunction((( *)MSFindSymbol(NULL, "")),( *)$,( **)&old );
With this:

MSHookFunction(((return type of function*)MSFindSymbol(NULL, "yourSymbolicFunction")),(return type of function*)$yourSymbolicFunction,(return type of function**)&oldyourSymbolicFunction );
In our case, it looks like so:

MSHookFunction(((bool*)MSFindSymbol(NULL, "__ZNK7cPlayer13hasAngelWingsEv")),(bool*)$__ZNK7cPlayer13hasAngelWingsEv,(bool**)&old__ZNK7cPlayer13hasAngelWingsEv);
18ln3q.png
To find out the return type of the function you have to look at what it's called and decide for yourself
 
if it is called something like "CanShoot" then it is probably a bool because you either can shoot or you can't
if it is called something like "GetMoney" then it is probably an int because it is getting your money value
if it is called something like "DoLevelUp" then it is probably a void bacuase it is "doing" something (this probably has an int argument though
like "Player::DoLevelUp(int)" where the int is either your new level or what gets added to your current level
 
Step 4:
Add the following code to the beginning of the Tweak.xm file:

return type of function (*oldyourSymbolicFunction)();

In our case it looks like this:

bool (*old__ZNK7cPlayer13hasAngelWingsEv)();
2ni4oip.png
 
Then, add this after the statement we wrote earlier and before the dylib part:

return type of function $yourSymbolicFunction(){//Hack code you want.}
In our case, we want to have unlimited wings, so this is what we write:

bool $__ZNK7cPlayer13hasAngelWingsEv(){    return true;}
2wqh5rn.png
 
Info: the above code can be very complex like so:

bool $__ZNK7cPlayer13hasAngelWingsEv(){ if(ida_hack2) {    return true; } else {    return old__ZNK7cPlayer13hasAngelWingsEv(); }}
or even more, but make sure you usually write the hack in c++ though default_wink.png .
 
Part 5: Testing
Before continuing, please find your game's MainDelegate (which contains a function such as "applicationDidBecomeActive") if you want to add a UIAlertView.
From now on, this header file, will be named "APPDELEGATE".
A good thing to do is to add an alert view telling you the hack is activated. If it appears, the hack is working, else its not.
So add this code under all the other code you've got:

%hook APPDELEGATE- (void)applicationDidBecomeActive:(id)fp8{%orig();UIAlertView *alert = [[UIAlertView alloc]initWithTitle:@"Hack is Working" message:@"Hack Successfully Attached. This hack was made By Infamous-Ash" delegate:nil cancelButtonTitle:@"Cool" otherButtonTitles:nil];[alert show];[alert release];}%end
107m4r6.png
 
If you add the code above, be sure to add this code in your Makefile under "TempleRunHackTut_FILES = Tweak.xm":
TempleRunHackTut_FRAMEWORKS = UIKit
To test the hack save your tweak.xm in your project folder and type "make package" to compile. This not only makes your dylib but also puts it in a deb for you.
Then, just install and run the game.

 

VERY IMPORTANT NOTE:

There are some games that can't run UIAlertViews so they cause the game to crash. Such games are like Bejeweled. So, the problem isn't in the code, but rather in the game.

 

Credit:

Alsafa7 and Kamizoom

Archived

This topic is now archived and is closed to further replies.

  • Our picks

    • Zooba: Zoo Battle Royale Game v4.73.1 Jailed Cheats +2
      Modded/Hacked App: Zooba: Zoo Battle Royale Games By Wildlife Studios Limited
      Bundle ID: com.fungames.battleroyale
      iTunes Store Link: https://apps.apple.com/us/app/zooba-zoo-battle-royale-games/id1459402952?uo=4


      Hack Features:
      - Map Hacks
      - Allow Shoot in Water


      Jailbreak required hack(s): https://iosgods.com/topic/131104-arm64-zooba-zoo-battle-royale-game-cheats-all-versions-2/


      iOS Hack Download Link: https://iosgods.com/topic/131134-arm64-zooba-zoo-battle-royale-game-v320-jailed-cheats-2/
      • 1,230 replies
    • Hunt Royale: Action RPG Battle v3.3.1 +3 Jailed Cheats [ Damage & Defence ]
      Modded/Hacked App: Hunt Royale: Action RPG Battle By BoomBit, Inc.
      Bundle ID: com.hunt.royale
      iTunes Store Link: https://apps.apple.com/us/app/hunt-royale-action-rpg-battle/id1537379121?uo=4

       
       

      🚀 Hack Features

      - Dumb Enemies

      VIP
      - Damage Multiplier
      - Defence Multiplier


      🍏 Jailbreak iOS hacks: [Mod Menu Hack] Hunt Royale: Action RPG Battle v3.2.7 +3 Cheats [ Damage & Defence ] - Free Jailbroken Cydia Cheats - iOSGods
      🤖 Modded Android APKs: https://iosgods.com/forum/68-android-section/
      • 28 replies
    • Hunt Royale: Action RPG Battle v3.3.1 +3 Cheats [ Damage & Defence ]
      Modded/Hacked App: Hunt Royale: Action RPG Battle By BoomBit, Inc.
      Bundle ID: com.hunt.royale
      iTunes Store Link: https://apps.apple.com/us/app/hunt-royale-action-rpg-battle/id1537379121?uo=4

       
       

      🚀 Hack Features

      - Dumb Enemies

      VIP
      - Damage Multiplier
      - Defence Multiplier


      🍏 For Non-Jailbroken & No Jailbreak required hacks: [IPA Mod Menu] Hunt Royale: Action RPG Battle v3.2.7 +3 Jailed Cheats [ Damage & Defence ] - Free Non-Jailbroken IPA Cheats - iOSGods
      🤖 Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      • 24 replies
    • Loot Heroes v1.3.4 +8 Jailed Cheats [ Unlimited Currencies + More ]
      Modded/Hacked App: Loot Heroes: Fantasy RPG Games By BoomBit, Inc.
      Bundle ID: com.bbp.lootheroes
      iTunes Store Link: https://apps.apple.com/us/app/loot-heroes-fantasy-rpg-games/id6642699678?uo=4


      Hack Features:
      - Freeze Currencies
      - Unlimited Currencies [ VIP ]
      - God Mode -> Traps still cause damage.
      - One-Hit Kill
      - All Heroes Unlocked
      - Auto Win [ VIP ]
      - Battle Pass Unlocked [ VIP ]


      Jailbreak required hack(s): [Mod Menu Hack] Loot Heroes v1.1.5 +8 Cheats [ Unlimited Currencies + More ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 39 replies
    • Loot Heroes v1.3.4 +8 Cheats [ Unlimited Currencies + More ]
      Modded/Hacked App: Loot Heroes By BoomBit, Inc.
      Bundle ID: com.bbp.lootheroes
      iTunes Store Link: https://apps.apple.com/us/app/loot-heroes/id6642699678?uo=4


      Hack Features:
      - Freeze Currencies
      - Unlimited Currencies [ VIP ]
      - God Mode -> Traps still cause damage.
      - One-Hit Kill
      - All Heroes Unlocked
      - Auto Win [ VIP ]
      - Battle Pass Unlocked [ VIP ]


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 158 replies
    • Good Coffee, Great Coffee v1.0.1 +2 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Good Coffee, Great Coffee By TAPBLAZE, LLC
      Bundle ID: com.tapblaze.coffeebusiness
      iTunes Store Link: https://apps.apple.com/us/app/good-coffee-great-coffee/id1603584945?uo=4
       
       

      🤩 Hack Features

      - Unlimited Cash
      - Unlimited Gems
      • 3 replies
    • Good Coffee, Great Coffee v1.0.1 +2 Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Good Coffee, Great Coffee By TAPBLAZE, LLC
      Bundle ID: com.tapblaze.coffeebusiness
      iTunes Store Link: https://apps.apple.com/us/app/good-coffee-great-coffee/id1603584945?uo=4

       
       

      🤩 Hack Features

      - Unlimited Cash
      - Unlimited Gems
      • 11 replies
    • Smashero.io - Hack N Slash RPG v1.13.0 +2 Jailed Cheats [ God / O-HK ]
      Modded/Hacked App: Smashero.io - Hack N Slash RPG By CANNON CRACKER, Inc.
      Bundle ID: com.cc.Smashero
      iTunes Store Link: https://apps.apple.com/us/app/smashero-io-hack-n-slash-rpg/id6505129091?uo=4


      Hack Features:
      - God Mode
      - One-Hit Kill


      Jailbreak required hack(s): [Mod Menu Hack] Smashero.io - Hack N Slash RPG v3.3 +2 Cheats [ God / O-HK ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 19 replies
    • Smashero.io - Hack N Slash RPG v1.13.0 +2 Cheats [ God / O-HK ]
      Modded/Hacked App: Smashero.io - Hack N Slash RPG By CANNON CRACKER, Inc.
      Bundle ID: com.cc.Smashero
      iTunes Store Link: https://apps.apple.com/us/app/smashero-io-hack-n-slash-rpg/id6505129091?uo=4


      Hack Features:
      - God Mode
      - One-Hit Kill


      Non-Jailbroken & No Jailbreak required hack(s): [No Jailbreak Required] Smashero.io - Hack N Slash RPG v3.3 +2 Jailed Cheats [ God / O-HK ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Like
      • 49 replies
    • Modded/Hacked App: Hexapolis - Civilization game By NOXGAMES s.r.o.
      Bundle ID: com.noxgames.hex.polis.civilization.empire
      iTunes Store Link: https://apps.apple.com/us/app/hexapolis-civilization-game/id1559236448?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - IAP FREE [ Buy Anything Gems Gold ]

      - Max DMG [ Upgrade Trop ]

      - Max HP [ Upgrade Trop ]

      - Max DEF [ Upgrade Trop ]

      - ATK Range

      - Max Population

      - Silver Coins [ End Turn ]

      - No Fogg Map [ Just Move Trop ]

      - XP Reward + NO LVL POPUP [ Win Battle ]


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 31 replies
    • Hexapolis - Civilization game V2.3.0 [ +9 Jailed ] DMG
      Modded/Hacked App: Hexapolis - Civilization game By NOXGAMES s.r.o.
      Bundle ID: com.noxgames.hex.polis.civilization.empire
      iTunes Store Link: https://apps.apple.com/us/app/hexapolis-civilization-game/id1559236448?uo=4

       

       

      🔧 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🚀 Hack Features

      - IAP FREE [ Buy Anything Gems Gold ]

      - Max DMG [ Upgrade Trop ]

      - Max HP [ Upgrade Trop ]

      - Max DEF [ Upgrade Trop ]

      - ATK Range

      - Max Population

      - Silver Coins [ End Turn ]

      - No Fogg Map [ Just Move Trop ]

      - XP Reward + NO LVL POPUP [ Win Battle ]


      🍏 Jailbreak iOS hacks: https://iosgods.com/forum/5-game-cheats-hack-requests/
      🤖 Modded Android APKs: https://iosgods.com/forum/68-android-section/
      • 8 replies
    • Modded/Hacked App: Lollipop 3: Match 3 Puzzles By Puzzle1Studio,inc.
      Bundle ID: com.puzzle1studio.ap.lollipopsweetheroesmatch3
      iTunes Store Link: https://apps.apple.com/us/app/lollipop-3-match-3-puzzles/id1634326372?uo=4

       

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - Coins

      - Lives

      - Booster

      - Moves

      - Auto Win 

       

      ⬇️ iOS Hack Download Link


      Hidden Content

      Download Hack
      • 0 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines