-
Notifications
You must be signed in to change notification settings - Fork 27
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
ip7+ 10.2 "Failed to leak realport address", "Invalid shift mask" or restart automatically #53
Comments
Why OFFSET_ROP_ADD_X0_X0_0x10 and OFFSET_ROP_LDR_X0_X0_0x10 are 32 bits? $ r2 -q -e scr.color=true -c ""/a add x0, x0, 0x10; ret"" kernelcache 2> /dev/null $ r2 -q -e scr.color=true -c ""/a ldr x0, [x0, 0x10]; ret"" kernelcache 2> /dev/null |
2018-03-02 09:22:24.677041 v0rtexNonce[246:6322] uid isn't 0
2018-03-02 09:22:27.976314 v0rtexNonce[246:6322] Darwin Kernel Version 16.3.0: Tue Nov 29 21:40:08 PST 2016; root:xnu-3789.32.1~4/RELEASE_ARM64_T8010
2018-03-02 09:22:27.976487 v0rtexNonce[246:6322] loading offsets for iPhone9,2 - 14C92
2018-03-02 09:22:27.976565 v0rtexNonce[246:6322] test offset x0x0x10gadget: b592b8
2018-03-02 09:22:27.976928 v0rtexNonce[246:6322] service: 5d0b
2018-03-02 09:22:27.977261 v0rtexNonce[246:6322] client: 5e0b, (os/kern) successful
2018-03-02 09:22:27.978078 v0rtexNonce[246:6322] newSurface: (os/kern) successful
2018-03-02 09:22:27.978305 v0rtexNonce[246:6322] realport: 5f03, (os/kern) successful
2018-03-02 09:22:28.006642 v0rtexNonce[246:6322] port: 106003
2018-03-02 09:22:28.007610 v0rtexNonce[246:6322] mach_port_insert_right: (os/kern) successful
2018-03-02 09:22:28.008615 v0rtexNonce[246:6322] mach_ports_register: (os/kern) successful
2018-03-02 09:22:28.008776 v0rtexNonce[246:6322] herp derp
2018-03-02 09:22:28.110803 v0rtexNonce[246:6322] mach_ports_register: (os/kern) successful
2018-03-02 09:22:28.448730 v0rtexNonce[246:6322] mach_port_get_context: 0x300000a100000011, (os/kern) successful
2018-03-02 09:22:28.449064 v0rtexNonce[246:6322] reallocate_buf: (os/kern) successful
2018-03-02 09:22:28.449113 v0rtexNonce[246:6322] mach_port_request_notification(realport): 0, (os/kern) successful
2018-03-02 09:22:28.449215 v0rtexNonce[246:6322] getValue(161): 0x1010 bytes, (os/kern) successful
2018-03-02 09:22:28.449232 v0rtexNonce[246:6322] Failed to leak realport address
2018-03-02 09:22:28.456102 v0rtexNonce[246:6322] Failed to get kernel task
2018-03-02 09:22:28.489822 v0rtexNonce[246:6322] Reading var failed
2018-03-02 09:22:28.489888 v0rtexNonce[246:6322] current generator:
2018-03-02 10:16:39.810735 v0rtexNonce[217:4344] uid isn't 0
2018-03-02 10:16:39.813292 v0rtexNonce[217:4344] Darwin Kernel Version 16.3.0: Tue Nov 29 21:40:08 PST 2016; root:xnu-3789.32.1~4/RELEASE_ARM64_T8010
2018-03-02 10:16:39.813345 v0rtexNonce[217:4344] loading offsets for iPhone9,2 - 14C92
2018-03-02 10:16:39.813369 v0rtexNonce[217:4344] test offset x0x0x10gadget: b592b8
2018-03-02 10:16:39.813462 v0rtexNonce[217:4344] service: 5d0b
2018-03-02 10:16:39.813581 v0rtexNonce[217:4344] client: 5e0b, (os/kern) successful
2018-03-02 10:16:39.813882 v0rtexNonce[217:4344] newSurface: (os/kern) successful
2018-03-02 10:16:39.813943 v0rtexNonce[217:4344] realport: 5f03, (os/kern) successful
2018-03-02 10:16:39.830728 v0rtexNonce[217:4344] port: 106003
2018-03-02 10:16:39.830891 v0rtexNonce[217:4344] mach_port_insert_right: (os/kern) successful
2018-03-02 10:16:39.830954 v0rtexNonce[217:4344] mach_ports_register: (os/kern) successful
2018-03-02 10:16:39.831011 v0rtexNonce[217:4344] herp derp
2018-03-02 10:16:39.941308 v0rtexNonce[217:4344] mach_ports_register: (os/kern) successful
2018-03-02 10:16:40.453699 v0rtexNonce[217:4344] mach_port_get_context: 0x0000000000000011, (os/kern) successful
2018-03-02 10:16:40.453769 v0rtexNonce[217:4344] Invalid shift mask.
2018-03-02 10:16:40.465956 v0rtexNonce[217:4344] Failed to get kernel task
2018-03-02 10:16:40.512669 v0rtexNonce[217:4344] Reading var failed
2018-03-02 10:16:40.512767 v0rtexNonce[217:4344] current generator:
2018-03-02 09:24:43.394738 v0rtexNonce[236:5176] uid isn't 0
2018-03-02 09:24:43.396583 v0rtexNonce[236:5176] Darwin Kernel Version 16.3.0: Tue Nov 29 21:40:08 PST 2016; root:xnu-3789.32.1~4/RELEASE_ARM64_T8010
2018-03-02 09:24:43.396620 v0rtexNonce[236:5176] loading offsets for iPhone9,2 - 14C92
2018-03-02 09:24:43.396636 v0rtexNonce[236:5176] test offset x0x0x10gadget: b592b8
2018-03-02 09:24:43.396704 v0rtexNonce[236:5176] service: 5d0b
2018-03-02 09:24:43.396786 v0rtexNonce[236:5176] client: 5e0b, (os/kern) successful
2018-03-02 09:24:43.396918 v0rtexNonce[236:5176] newSurface: (os/kern) successful
2018-03-02 09:24:43.396947 v0rtexNonce[236:5176] realport: 5f03, (os/kern) successful
2018-03-02 09:24:43.401767 v0rtexNonce[236:5176] port: 106003
2018-03-02 09:24:43.401816 v0rtexNonce[236:5176] mach_port_insert_right: (os/kern) successful
2018-03-02 09:24:43.401848 v0rtexNonce[236:5176] mach_ports_register: (os/kern) successful
2018-03-02 09:24:43.401876 v0rtexNonce[236:5176] herp derp
2018-03-02 09:24:43.502946 v0rtexNonce[236:5176] mach_ports_register: (os/kern) successful
2018-03-02 09:24:43.731182 v0rtexNonce[236:5176] mach_port_get_context: 0x1000008c00000000, (os/kern) successful
restart ...
2018-03-02 09:29:43.891386 v0rtexNonce[219:3861] uid isn't 0
2018-03-02 09:29:43.896480 v0rtexNonce[219:3861] Darwin Kernel Version 16.3.0: Tue Nov 29 21:40:08 PST 2016; root:xnu-3789.32.1~4/RELEASE_ARM64_T8010
2018-03-02 09:29:43.897003 v0rtexNonce[219:3861] loading offsets for iPhone9,2 - 14C92
2018-03-02 09:29:43.897204 v0rtexNonce[219:3861] test offset x0x0x10gadget: b592b8
2018-03-02 09:29:43.897792 v0rtexNonce[219:3861] service: 5d0b
2018-03-02 09:29:43.898018 v0rtexNonce[219:3861] client: 5e0b, (os/kern) successful
2018-03-02 09:29:43.898263 v0rtexNonce[219:3861] newSurface: (os/kern) successful
2018-03-02 09:29:43.898396 v0rtexNonce[219:3861] realport: 5f03, (os/kern) successful
2018-03-02 09:29:43.920022 v0rtexNonce[219:3861] port: 106003
2018-03-02 09:29:43.920791 v0rtexNonce[219:3861] mach_port_insert_right: (os/kern) successful
2018-03-02 09:29:43.921034 v0rtexNonce[219:3861] mach_ports_register: (os/kern) successful
2018-03-02 09:29:43.921262 v0rtexNonce[219:3861] herp derp
2018-03-02 09:29:44.037376 v0rtexNonce[219:3861] mach_ports_register: (os/kern) successful
2018-03-02 09:29:44.344575 v0rtexNonce[219:3861] mach_port_get_context: 0x200000ac00000000, (os/kern) successful
2018-03-02 09:29:44.354845 v0rtexNonce[219:3861] reallocate_buf: (os/kern) successful
restart ...
2018-03-02 09:55:05.965573 v0rtexNonce[222:3927] uid isn't 0
2018-03-02 09:55:05.967786 v0rtexNonce[222:3927] Darwin Kernel Version 16.3.0: Tue Nov 29 21:40:08 PST 2016; root:xnu-3789.32.1~4/RELEASE_ARM64_T8010
2018-03-02 09:55:05.967838 v0rtexNonce[222:3927] loading offsets for iPhone9,2 - 14C92
2018-03-02 09:55:05.967887 v0rtexNonce[222:3927] test offset x0x0x10gadget: b592b8
2018-03-02 09:55:05.967985 v0rtexNonce[222:3927] service: 5d0b
2018-03-02 09:55:05.968106 v0rtexNonce[222:3927] client: 5e0b, (os/kern) successful
2018-03-02 09:55:05.968233 v0rtexNonce[222:3927] newSurface: (os/kern) successful
2018-03-02 09:55:05.968278 v0rtexNonce[222:3927] realport: 5f03, (os/kern) successful
2018-03-02 09:55:05.989664 v0rtexNonce[222:3927] port: 106003
2018-03-02 09:55:05.989742 v0rtexNonce[222:3927] mach_port_insert_right: (os/kern) successful
2018-03-02 09:55:05.989795 v0rtexNonce[222:3927] mach_ports_register: (os/kern) successful
2018-03-02 09:55:05.989839 v0rtexNonce[222:3927] herp derp
2018-03-02 09:55:06.100897 v0rtexNonce[222:3927] mach_ports_register: (os/kern) successful
2018-03-02 09:55:06.518535 v0rtexNonce[222:3927] mach_port_get_context: 0x300000a300000011, (os/kern) successful
2018-03-02 09:55:06.528810 v0rtexNonce[222:3927] reallocate_buf: (os/kern) successful
2018-03-02 09:55:06.528918 v0rtexNonce[222:3927] mach_port_request_notification(realport): 0, (os/kern) successful
2018-03-02 09:55:06.529059 v0rtexNonce[222:3927] getValue(163): 0x1010 bytes, (os/kern) successful
2018-03-02 09:55:06.529092 v0rtexNonce[222:3927] realport addr: 0xffffffe0041bdae8
2018-03-02 09:55:06.529128 v0rtexNonce[222:3927] mach_port_request_notification(fakeport): 6007, (os/kern) successful
2018-03-02 09:55:06.529252 v0rtexNonce[222:3927] getValue(163): 0x1010 bytes, (os/kern) successful
2018-03-02 09:55:06.529276 v0rtexNonce[222:3927] fakeport addr: 0xffffffe00445e178
2018-03-02 09:55:06.539468 v0rtexNonce[222:3927] reallocate_buf: (os/kern) successful
2018-03-02 09:55:06.539570 v0rtexNonce[222:3927] itk_space: 0xffffffe000545cb0
2018-03-02 09:55:06.539605 v0rtexNonce[222:3927] self_task: 0xffffffe001409540
2018-03-02 09:55:06.539637 v0rtexNonce[222:3927] IOSurfaceRootUserClient port: 0xffffffe0046a9260
2018-03-02 09:55:06.539711 v0rtexNonce[222:3927] IOSurfaceRootUserClient addr: 0xffffffe002606600
2018-03-02 09:55:06.539744 v0rtexNonce[222:3927] IOSurfaceRootUserClient vtab: 0xfffffff01d4521e0
2018-03-02 09:55:06.539762 v0rtexNonce[222:3927] slide: 0x0000000016600000
2018-03-02 09:55:06.539789 v0rtexNonce[222:3927] mach_ports_register: (os/kern) successful
2018-03-02 09:55:06.539824 v0rtexNonce[222:3927] zone_map: 0x0000000014000000
restart ...
The text was updated successfully, but these errors were encountered: