Jump to content

Searching heap memory with lldb


tanis

5 posts in this topic

Recommended Posts

Posted
15 minutes ago, Ted2 said:

There's a memory read command if that's what you mean

Yes, I know about

mem find -s "mystring" -- 0x000000010216b000 0x000000010295f000

but you need to find out the addresses of the memory arenas that have been allocated by malloc and friends which is not obvious.

You can get a list of memory sections with 

image dump sections

but those are the allocations made when the executable is being launched and memory allocated statically. All the memory allocation functions do not end up in that list and I'm not aware of any easy way to track them down.

Posted
5 hours ago, tanis said:

Yes, I know about


mem find -s "mystring" -- 0x000000010216b000 0x000000010295f000

but you need to find out the addresses of the memory arenas that have been allocated by malloc and friends which is not obvious.

You can get a list of memory sections with 


image dump sections

but those are the allocations made when the executable is being launched and memory allocated statically. All the memory allocation functions do not end up in that list and I'm not aware of any easy way to track them down.

cfQKxv4.png

 

See this page here:

https://lldb.llvm.org/lldb-gdb.html

Posted

That's fine if you know the address. But in my case I don't know the address of what I'm looking for so I need to find out the virtual address space assigned to the process and read the list of regions in there to scan each of them.

I stumbled upon lldbinit https://github.com/gdbinit/lldbinit and it's got a findmem command that seems to work with malloc-ed memory as well (notice the MALLOC_SMALL):

(lldbinit) findmem -s ciao
Found at : 0000000100000F74 base : 0000000100000000 off : 00000F74 __TEXT
Found at : 0000000101000000 base : 0000000100800000 off : 00800000 MALLOC_SMALL
Found at : 00007FFFC9D3FF74 base : 00007FFFC1F04000 off : 07E3BF74 __LINKEDIT
Found at : 00007FFFC9D4165F                         off : 07E3D65F __LINKEDIT

This pretty much solves most of my problems.

Archived

This topic is now archived and is closed to further replies.

  • Our picks

    • RiftCraft v2.44.30 [ +4 Cheats ] Auto Win
      Modded/Hacked App: RiftCraft By Sneaky Panda LTD
      Bundle ID: com.sneakypanda.riftcraft
      App Store Link: https://apps.apple.com/us/app/riftcraft/id6744392381?uo=4 

      🤩 Hack Features

      - Auto Win [ PvP & Stage ]
      - ADS [ Rewards Free ]
      - Gems
      - Tokens
      • 7 replies
    • Undead Slayer: Horde Survivor V3.36.02 [ +14 Cheats ] Currency Max
      Modded/Hacked App: Undead Slayer: Horde Survivor By Enigma Publishing Limited
      Bundle ID: com.undeadslayer.athree.epl.as
      App Store Link: https://apps.apple.com/ph/app/undead-slayer-horde-survivor/id6746744005?uo=4


      🤩 Hack Features

      - ADS NO [ Rewards Free ]

      - Gems

      - Soul Coins

      - Abyss Key

      - Rune Key

      - Gold Key

      - Red Dust

      - Blue Dust

      - Master Coin

      - Daily Star

      - HP [ Weapon Upgrade Then Equip ]

      - ATK [ Weapon Upgrade Then Equip ]
      • 4 replies
    • Undead Slayer: Horde Survivor V3.36.02 [ +14 Jailed ] Currency Max
      Modded/Hacked App: Undead Slayer: Horde Survivor By Enigma Publishing Limited
      Bundle ID: com.undeadslayer.athree.epl.as
      App Store Link: https://apps.apple.com/ph/app/undead-slayer-horde-survivor/id6746744005?uo=4
       

      🤩 Hack Features

      - ADS NO [ Rewards Free ]

      - Gems

      - Soul Coins

      - Abyss Key

      - Rune Key

      - Gold Key

      - Red Dust

      - Blue Dust

      - Master Coin

      - Daily Star

      - HP [ Weapon Upgrade Then Equip ]

      - ATK [ Weapon Upgrade Then Equip ]
      • 3 replies
    • Paradise Paws: Merge Animals v1.0.7 [ +9 Cheats ] Currency Max
      Modded/Hacked App: Animal Sanctuary By Wildlife Studios, Inc
      Bundle ID: com.wildlifestudios.merge.animal.sanctuary
      App Store Link: https://apps.apple.com/us/app/animal-sanctuary/id6741805691?uo=4
       

      🤩 Hack Features

      - Gems

      - Coins

      - Heart

      - Spin

      - LvL

      - Exp

      - Fog Auto Remove [ Linked With LvL ]

      - Premum Lands Unlocked [ Just Tap ]

      - Store Free [ IAP Not ]

      Note:- Game Close After Currency Hack Don't Worry
        • Agree
      • 23 replies
    • Paradise Paws: Merge Animals v1.0.7 [ +9 Jailed ] Currency Max
      Modded/Hacked App: Animal Sanctuary By Wildlife Studios, Inc
      Bundle ID: com.wildlifestudios.merge.animal.sanctuary
      App Store Link: https://apps.apple.com/us/app/animal-sanctuary/id6741805691?uo=4


      🤩 Hack Features

      - Gems

      - Coins

      - Heart

      - Spin

      - LvL

      - Exp

      - Fog Auto Remove [ Linked With LvL ]

      - Premum Lands Unlocked [ Just Tap ]

      - Store Free [ IAP Not ]

      Note:- Game Close After Currency Hack Don't Worry
      • 18 replies
    • Shiba Story Go! RPG Idle Game v1.1.13 [ +12 Jailed ] Always Win
      Modded/Hacked App: Shiba Story Go! RPG Idle Game By Proof of Play, Inc.
      Bundle ID: com.proofofplay.shibastorygo
      App Store Link: https://apps.apple.com/ph/app/shiba-story-go-rpg-idle-game/id6749783343?uo=4 

      🤩 Hack Features

      - Gems

      - Gold

      - Energy

      - Keys+3

      - Enhance Items

      - Pet Egg

      - Chest Max [ Server Error Show Some Time But Works ]

      - Fast Travel Energy Cost 1

      - Enemy Easy Kill [ Both Of Linked ] Server Error Show Some Time

      - Alway My Turn

      - HP [ Enemy Easy Kill + Alway My Turn ] Disable Then Use This Feature

      - ATK

      - DEF
      • 4 replies
    • Shiba Story Go! RPG Idle Game v1.1.13 [ +12 Cheats ] Always Win
      Modded/Hacked App: Shiba Story Go! RPG Idle Game By Proof of Play, Inc.
      Bundle ID: com.proofofplay.shibastorygo
      App Store Link: https://apps.apple.com/ph/app/shiba-story-go-rpg-idle-game/id6749783343?uo=4

      🤩 Hack Features

      - Gems

      - Gold

      - Energy

      - Keys+3

      - Enhance Items

      - Pet Egg

      - Chest Max [ Server Error Show Some Time But Works ]

      - Fast Travel Energy Cost 1

      - Enemy Easy Kill [ Both Of Linked ] Server Error Show Some Time

      - Alway My Turn

      - HP [ Enemy Easy Kill + Alway My Turn ] Disable Then Use This Feature

      - ATK

      - DEF
      • 5 replies
    • Arena Heroes: Online RPG v1.15.10 [ +2 Cheats ] Skill CD
      Modded/Hacked App: Arena Heroes: Online RPG By INFUSION GAMES OU
      Bundle ID: com.infusiongames.fighting.rpg.adventure.multiplayer.wars.pvp.battles.arena.heroes
      iTunes Store Link: https://apps.apple.com/us/app/arena-heroes-online-rpg/id6448993010?uo=4
       

      🤩 Hack Features

      - DMG [ When Enemy Turn Disable ]
      - Skill CD



      DMG Not Tested With Dungeon & Arena 
      • 28 replies
    • Arena Heroes: Online RPG v1.15.10 [ +2 Jailed ] Skill CD
      Modded/Hacked App: Arena Heroes: Online RPG By INFUSION GAMES OU
      Bundle ID: com.infusiongames.fighting.rpg.adventure.multiplayer.wars.pvp.battles.arena.heroes
      iTunes Store Link: https://apps.apple.com/us/app/arena-heroes-online-rpg/id6448993010?uo=4


      🤩 Hack Features

      - DMG [ When Enemy Turn Disable ]
      - Skill CD



      DMG Not Tested With Dungeon & Arena 
      • 27 replies
    • Fairyland - Merge & Match v1.6.5 [ +4 Cheats ] Auto Win
      Modded/Hacked App: Fairyland - Merge & Match By 程程 姚
      Bundle ID: com.mergematch.fairyland
      App Store Link: https://apps.apple.com/us/app/fairyland-merge-match/id6740663230?uo=4
       

      🤩 Hack Features

      - Auto Win
      - Gems
      - Coins
      - Moves 99
      • 5 replies
    • Fairyland - Merge & Match v1.6.5 [ +4 Jailed ] Auto Win
      Modded/Hacked App: Fairyland - Merge & Match By 程程 姚
      Bundle ID: com.mergematch.fairyland
      App Store Link: https://apps.apple.com/us/app/fairyland-merge-match/id6740663230?uo=4


      🤩 Hack Features

      - Auto Win
      - Gems
      - Coins
      - Moves 99
      • 5 replies
    • Pop Island v1.1.9 [ +1 Jailed ] Coins Max
      Modded/Hacked App: Pop Island By HISTAR INTERACTIVE PTE. LTD.
      Bundle ID: com.hmbdgames.match
      iTunes Store Link: https://apps.apple.com/us/app/pop-island/id6505047210?uo=4


      🤩 Hack Features

      - Coins [ Win Match Disable After Hack ]


      • 21 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines