Jump to content

10 posts in this topic

Recommended Posts

Posted (edited)

Hi guys,

So here we go. I installed SW FA from itunes and did the following
 

su
Password  
rc.sh -m
Chose the binary

//No errors,  all good

Go to /var/root/, get the cracked binary thin it with

lipo starwars -thin armv7 -o starwars2

Took the output file, used armconverter.com to remove aslr, signed with
 

ldid -s starwars2

Renamed and replaced in the app, permissions set to 777. App works fine.

Connect to Mac (and windows), open terminal, start app, find offset in iGG (and GP)
 

gdb
att pid
watch *0xOffsetfromGP/iGG

When i set a watchpoint it shows a very huge value as compared to the value which im hacking (shows something like 40880308 or so and value should be at max 10)

In iGG it still shows the same value


Checked for ASLR with
 

info address _mh_execute_header

Which returns 0x4000. According to @fahadxmb (as far as i remember) that meant aslr was gone.

I did get a warning about

Possible section anti debug trick detected at segment_Dirty or so (a few hundred times) but thats also fine apparently.

Any ideas what the error is?

Btw, when i use LLDB (debugserver was thinned for arm64) i get the correct value but when i search in IDA the code isnt there (something entirely different is there)

 

Added log from PuTTy

 

http://pastebin.com/gZ1HCRNW

Updated by Archangel04
Posted

did u remove syscall?

 

if not u have to

Theres no syscall but I did find sysctl. I checked imports, strings but no syscall.

 

When i NOP any BLX _sysctl, it crashes the game. If i BX LR or NOP the branch it kills the game. What should i do then

don't know about lldb~ pass by~

The post is about gdb and if you cant contribute there is no need to comment on this. If you want to increase your post count please dont do so here. Do it in spam city or something

Posted (edited)

Theres no syscall but I did find sysctl. I checked imports, strings but no syscall.

When i NOP any BLX _sysctl, it crashes the game. If i BX LR or NOP the branch it kills the game. What should i do then

 

The post is about gdb and if you cant contribute there is no need to comment on this. If you want to increase your post count please dont do so here. Do it in spam city or something

Chill he was just trying to help

Updated by Naeemjr
Posted

Chill he was just trying to help

 

TBH, Doesnt seem so. Anyways, moving on,

 

According to another post (multiple posts), I need to find a place where there is _sysctl, _getpid and _memset. I didnt find that, but i did get _getpid and _sysctl

 

 

                 PUSH              {R4,R7,LR}
                 ADD                 R7, SP, #4
                 SUB.W            SP, SP, #0x20C ; void *
                 MOVW             R4, #(:lower16:(___stack_chk_guard_ptr - 0x173AD7A))
                 MOV.W            R0, #0x1EC
                 MOVT.W          R4, #(:upper16:(___stack_chk_guard_ptr - 0x173AD7A))
                 MOVS             R1, #0xE
                 ADD                R4, PC ; ___stack_chk_guard_ptr
                 LDR                R4, [R4] ; ___stack_chk_guard
                 LDR                R4, [R4]
                 STR                R4, [SP,#0x210+var_8]
                 STR                R0, [SP,#0x210+var_208]
                 MOVS             R0, #1
                 STR                R0, [SP,#0x210+var_204]
                 STRD.W         R1, R0, [SP,#0x10]
                 BLX                _getpid
                 STR               R0, [SP,#0x210+var_1F8]
                 MOVS            R0, #0
                 STRD.W        R0, R0, [SP]
                 ADD               R0, SP, #0x210+var_204 ; int *
                 ADD               R2, SP, #0x210+var_1F4 ; void *
                 ADD               R3, SP, #0x210+var_208 ; size_t *
                MOVS             R1, #4  ; u_int
                 BLX                _sysctl
                 CMP.W           R0, #0xFFFFFFFF
                 BEQ               loc_173ADB6
                 MOV              R0, #(byte_1FCB108 - 0x173ADB2)
                 ADD               R0, PC ; byte_1FCB108
                LDRB              R0, [R0]
                CBNZ              R0, loc_173AE0E
                B                     loc_173ADF6

If I NOP, then it crashes (as far as i remember, il have to check later)

Posted

NOPed sysctl and the function below it. I can getbin if I use a slow net otherwise it crashes. Debugging witj gdb still gives wrong value

Have u tired adding repo.xarold repo in Cydia

And installing ptrace pwner it will automatically disable syscall

Posted

Done

 

Have u tired adding repo.xarold repo in Cydia
And installing ptrace pwner it will automatically disable syscall

 

It still shows a super huge value (and yes my iGG offset is correct, i checked)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Cat Game - The Cats Collector! v1.98.29 Jailed Cheats +2
      Modded/Hacked App: Cat Game - The Cats Collector! By MinoMonsters Inc.
      Bundle ID: com.minogames.cats.beta
      App Store Link: https://apps.apple.com/us/app/cat-game-the-cats-collector/id1125011102?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Infinite Currencies

       

      Jailbroken Hack: https://iosgods.com/topic/105377-cat-game-the-cats-collector-cheats-auto-update-1/

       

      ⬇️ iOS Hack Download IPA Link: https://iosgods.com/topic/105379-cat-game-the-cats-collector-v19829-jailed-cheats-2/
      • 126 replies
    • [ ReDive TW ] 超異域公主連結!Re:Dive Cheats v5.5.0 +2
      Modded/Hacked App: 超異域公主連結!Re:Dive By So-net Entertainment Taiwan Limited
      Bundle ID: tw.sonet.princessconnect
      iTunes Store Link: https://apps.apple.com/tw/app/%E8%B6%85%E7%95%B0%E5%9F%9F%E5%85%AC%E4%B8%BB%E9%80%A3%E7%B5%90-re-dive/id1390473317?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - Multiply Attack
      - Multiply Defense

       

      Non-Jailbroken Hack: https://iosgods.com/topic/186660-redive-tw-%E8%B6%85%E7%95%B0%E5%9F%9F%E5%85%AC%E4%B8%BB%E9%80%A3%E7%B5%90%EF%BC%81redive-hack/

       

      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/134431-redive-tw-%E8%B6%85%E7%95%B0%E5%9F%9F%E5%85%AC%E4%B8%BB%E9%80%A3%E7%B5%90%EF%BC%81redive-cheats-v500-3/
        • Thanks
      • 285 replies
    • Match Factory! v1.59.46 +3 Jailed Cheats [ Unlimited Everything ]
      Modded/Hacked App: Match Factory! By Peak Games
      Bundle ID: net.peakgames.match
      iTunes Store Link: https://apps.apple.com/gb/app/match-factory/id6449094229?uo=4


      Hack Features:
      - Unlimited Everything -> Will increase instead of decrease. Use coins for energy.
      - Auto Win -> Pick up an item.
      - Unlimited Time -> Will not decrease.
      • 73 replies
    • Good Pizza, Great Pizza v5.43.0 +8 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Good Pizza, Great Pizza By TAPBLAZE, LLC
      Bundle ID: com.tapblaze.pizzabusiness
      iTunes Store Link: https://apps.apple.com/us/app/good-pizza-great-pizza/id911121200?uo=4


      Hack Features:
      - Unlimited Cash
      - Unlimited Diamonds
      - Unlimited Ad Tickets

      VIP
      -̶ ̶U̶n̶l̶i̶m̶i̶t̶e̶d̶ ̶P̶i̶z̶z̶a̶ ̶P̶a̶s̶s̶ ̶T̶o̶k̶e̶n̶s̶
      ̶-̶ ̶C̶h̶e̶f̶ ̶P̶a̶s̶s̶ ̶U̶n̶l̶o̶c̶k̶e̶d̶
      ̶-̶ ̶M̶a̶x̶ ̶P̶i̶z̶z̶a̶ ̶P̶a̶s̶s̶ ̶L̶e̶v̶e̶l̶
       ̶-̶ ̶S̶t̶a̶r̶t̶e̶r̶ ̶B̶u̶n̶d̶l̶e̶ ̶U̶n̶l̶o̶c̶k̶e̶d̶
      - Unlimited Paint Tickets
      - Unlimited Event Currency
      - Max Event Level
      - Unlimited Event Score
      - All Achievements Completed
      • 453 replies
    • Disney Emoji Blitz Game v74.0.0 +1++ Jailed Cheat [ Unlimited Currencies ]
      Modded/Hacked App: Disney Emoji Blitz Game By Jam City, Inc.
      Bundle ID: com.disney.emojimatch
      iTunes Store Link: https://apps.apple.com/us/app/disney-emoji-blitz-game/id1017551780
       

      Hack Features:
      - Unlimited Currencies -> Earn some.


      Jailbreak required hack(s): https://iosgods.com/topic/168886-disney-emoji-blitz-game-all-versions-1-cheats-unlimited-currencies/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 224 replies
    • Tsukuyomi: The Divine Hunter v1.1.3 +3 Jailed Cheats [ Damage & Defence ]
      Modded/Hacked App: Tsukuyomi: The Divine Hunter By COLOPL, Inc.
      Bundle ID: jp.colopl.mask
      App Store Link: https://apps.apple.com/us/app/tsukuyomi-the-divine-hunter/id6505051119?uo=4

       
       

      🤩 Hack Features

      - Damage Multiplier
      - Defence Multiplier
      - God Mode
      • 12 replies
    • EverMerge: Merge & Match Game v1.67.5 +30 Jailed Cheats [ Cheat Menu ]
      Modded/Hacked App: EverMerge: Merge & Match Game By Big Fish Games, Inc
      Bundle ID: com.bigfishgames.mergetalesios
      iTunes Store Link: https://apps.apple.com/us/app/evermerge-merge-match-game/id1446344746?uo=4

       


      🚀 Hack Features

      - Cheat Menu -> Head into Settings and toggle the Support button.
      • 9 replies
    • Dungeon's Call: Into the Abyss v1.0.7 +4 Jailed Cheats [ Damage & Defence ]
      Modded/Hacked App: Dungeon's Call: Into the Abyss By Satoshi Masui
      Bundle ID: com.seg-soft.dungeonscall
      iTunes Store Link: https://apps.apple.com/us/app/dungeons-call-into-the-abyss/id6739310989?uo=4

       


      🤩 Hack Features

      - Damage Multiplier
      - Defence Multiplier
      - Unlimited Gold -> Will increase instead of decrease.
      - Unlimited Gems -> Will increase instead of decrease.
      • 8 replies
    • Arcane Knight : Idle RPG v1.0.45 +6 Jailed Cheats [ Damage & Defence ]
      Modded/Hacked App: Arcane Knight : Idle RPG By DongSik Moon
      Bundle ID: com.eastmoon.gk2live
      App Store Link: https://apps.apple.com/us/app/arcane-knight-idle-rpg/id6744289685?uo=4

       


      🤩 Hack Features

      - Damage Multiplier
      - Defence Multiplier
      - God Mode
      - Move Speed Multiplier
      - Freeze Coins
      - Freeze Gems
      • 14 replies
    • Super Marine Defense v1.4.0 +1 Jailed Cheat [ Damage ]
      Modded/Hacked App: Super Marine Defense By Game Duo Co.,Ltd.
      Bundle ID: net.gameduo.smd
      App Store Link: https://apps.apple.com/us/app/super-marine-defense/id6749679878?uo=4

       


      🤩 Hack Features

      - Damage Multiplier
      • 2 replies
    • OnceWorld v1.2.1 +2 Jailed Cheats [ Damage + More ]
      Modded/Hacked App: OnceWorld By PONIX LLC
      Bundle ID: work.ponix.onceworld
      App Store Link: https://apps.apple.com/us/app/onceworld/id6753948618?uo=4

       


      🤩 Hack Features

      - Damage Multiplier
      - God Mode
      • 35 replies
    • (18+) Eros Raiders v1.2.66 +2 Cheats
      Mod APK Game Name: Eros Raiders By EroLabs
      Rooted Device: Not Required.
      Google Play Store Link: https://18game.ero-labs.club/game.html?id=132

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Muliplier

       

      ⬇️ Android Mod APK Download Link


      Hidden Content

      Download Modded APK







       

      📖 Android Installation Instructions

      STEP 1: Download the modded APK file from the link above using your preferred Android browser or download manager.
      STEP 2: Once the download is complete, open your file manager and locate the downloaded .apk file (usually in the Downloads folder).
      STEP 3: Tap the APK file, then select Install. If prompted, enable Install from Unknown Sources in your device settings.
      STEP 3A: If the mod includes an OBB file, extract it if it’s inside an archive. Then move the folder to: /Android/obb/
      STEP 3B: If the mod includes a DATA file, extract it if it’s archived. Then move the folder to: /Android/data/
      STEP 4: Once installed, open the game and toggle your desired cheats & features through the APK mod menu. Enjoy!

       

      NOTE: If you have any questions or issues, read our Frequently Asked Questions topic. If you still need help, post your issue below and we’ll assist you as soon as possible. If the mod works for you, please share your feedback to help other members!

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A

       

       iOS & iPadOS App Hacks
      If you’re looking for Non-Jailbroken & No Jailbreak required iOS IPA hacks, visit the iOS Game Cheats & Hacks or the iOSGods App for a variety of modded games and apps for non-jailbroken iOS devices.
      • 2 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines