Advertisement
Guest User

Errno: 17

a guest
Mar 22nd, 2019
114
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.15 KB | None | 0 0
  1. [*] unc0ver Version: 3.0.0~b46
  2. [*] Darwin Kernel Version 18.2.0: Mon Nov 12 20:31:59 PST 2018; root:xnu-4903.232.2~1/RELEASE_ARM64_S5L8960X
  3. [*] Bundled Resources Version: 1.0~b6
  4. [*] STATUS: Jailbreak
  5. [*] STATUS: Exploiting (1/37)
  6. [*] Loading preferences...
  7. [*] Successfully loaded preferences.
  8. [*] STATUS: Exploiting (2/37)
  9. [*] Exploiting kernel_task...
  10. [*] page size: 0x1000, (os/kern) successful
  11. [*] client: 5b0f, (os/kern) successful
  12. [*] surface ID: 0x1a
  13. [*] fakeport: 0x10507c000
  14. [*] got gc at 5 -- breaking
  15. [*] port: 225f17
  16. [*] WE REALLY POSTED UP ON THIS BLOCK
  17. [*] faketask: 0x101801e00
  18. [*] got ikmq_base: 0xfffffff057058900
  19. [*] ikm_header: 0xfffffff057058988
  20. [*] port_addr: 0xfffffff05994b760
  21. [*] itk_space: 0xfffffff056eb9850
  22. [*] ourtask: 0xfffffff058d4c000
  23. [*] found kernel_base: 0xfffffff00f004000
  24. [*] kernel slide: 0x8000000
  25. [*] kernel base: 0xfffffff00f004000
  26. [*] read kernel base value: feedfacf
  27. [*] got ikmq_base: 0xfffffff057058900
  28. [*] ikm_next: 0xfffffff05759b400
  29. [*] ikm_header: 0xfffffff05759b488
  30. [*] port_addr: 0xfffffff055a258f0
  31. [*] realhost: 0xfffffff010870778
  32. [*] got ourproc: 0xfffffff057777000
  33. [*] got kernproc: 0xfffffff0108b5b00
  34. [*] got kerntask: 0xfffffff055a3d840
  35. [*] got kernel vm map: 0xfffffff05464c6b0
  36. [*] ipc_space_kernel: 0xfffffff055a20fc0
  37. [*] got kernel base: 100000cfeedfacf
  38. [*] kernel_task_buf: 0xfffffff008ee1000
  39. [*] kernel_port_buf: 0xfffffff008f17000
  40. [*] orig_ucred: 0xfffffff056ea9d00
  41. [*] kern_ucred: 0xfffffff055d19560
  42. [*] setuid: 0, uid: 0
  43. [*] setuid: 0, uid: 501
  44. [*] tfp0: 0x203b0b
  45. [*] kernel_base: 0xfffffff00f004000
  46. [*] kernel_slide: 0x0000000008000000
  47. [*] Successfully exploited kernel_task.
  48. [*] STATUS: Exploiting (3/37)
  49. [*] Initializing patchfinder64...
  50. [*] Detected monolithic kernel.
  51. [*] Successfully initialized patchfinder64.
  52. [*] STATUS: Exploiting (4/37)
  53. [*] Finding offsets...
  54. [*] trustcache = 0xfffffff0088f6068 + 0x0000000008000000
  55. [*] OSBoolean_True = 0xfffffff0088ff9a0 + 0x0000000008000000
  56. [*] osunserializexml = 0xfffffff007bf5f48 + 0x0000000008000000
  57. [*] smalloc = 0xfffffff00856bb28 + 0x0000000008000000
  58. [*] add_x0_x0_0x40_ret = 0xfffffff007a4a39c + 0x0000000008000000
  59. [*] zone_map_ref = 0xfffffff008872948 + 0x0000000008000000
  60. [*] vfs_context_current = 0xfffffff0077b7358 + 0x0000000008000000
  61. [*] vnode_lookup = 0xfffffff007788390 + 0x0000000008000000
  62. [*] vnode_put = 0xfffffff00777f0e4 + 0x0000000008000000
  63. [*] kernel_task = 0xfffffff008872200 + 0x0000000008000000
  64. [*] shenanigans = 0xfffffff008903ce0 + 0x0000000008000000
  65. [*] lck_mtx_lock = 0xfffffff00773e698 + 0x0000000008000000
  66. [*] lck_mtx_unlock = 0xfffffff00773ef3c + 0x0000000008000000
  67. [*] vnode_get_snapshot = 0xfffffff0077ada44 + 0x0000000008000000
  68. [*] fs_lookup_snapshot_metadata_by_name_and_return_name = 0xfffffff0084594f0 + 0x0000000008000000
  69. [*] apfs_jhash_getvnode = 0xfffffff00849a4ac + 0x0000000008000000
  70. [*] Successfully found offsets.
  71. [*] STATUS: Exploiting (5/37)
  72. [*] Deinitializing patchfinder64...
  73. [*] Successfully deinitialized patchfinder64.
  74. [*] STATUS: Exploiting (6/37)
  75. [*] Escaping Sandbox...
  76. [*] kCFCoreFoundationVersionNumber: 1561.000000
  77. [*] offsets selected for iOS 12.0 or above
  78. [*] kernproc = 0xfffffff0108b5b00
  79. [*] myProcAddr = 0xfffffff057777000
  80. [*] kernel_proc_struct_addr = 0xfffffff0108b5b00
  81. [*] kernel_ucred_struct_addr = 0xfffffff055d19560
  82. [*] kernelCredAddr = 0xfffffff055d19560
  83. [*] Shenanigans = 0xfffffff055d19560
  84. [*] orig_creds = 0xfffffff056ea9d00
  85. [*] myOriginalCredAddr = 0xfffffff056ea9d00
  86. [*] task_struct_addr = 0xfffffff058d4c000
  87. [*] Successfully escaped Sandbox.
  88. [*] STATUS: Exploiting (7/37)
  89. [*] Setting HSP4 as TFP0...
  90. [*] kernel_task_kaddr = 0xfffffff055a3d840
  91. [*] proc_struct_addr = 0xfffffff057777000
  92. [*] task_addr = 0xfffffff058d4c000
  93. [*] itk_space = 0xfffffff056eb9850
  94. [*] is_table = 0xfffffff0af01f000
  95. [*] port_addr = 0xfffffff057447b90
  96. [*] task self: 0xfffffff057447b90
  97. [*] port_addr = 0xfffffff059949000
  98. [*] port_addr = 0xfffffff0599491f8
  99. [*] remapped_task_addr = 0xfffffff0586b9840
  100. [*] port_addr = 0xfffffff008f17000
  101. [*] port_kaddr = 0xfffffff008f17000
  102. [*] port_addr = 0xfffffff008f17000
  103. [*] port_addr = 0xfffffff055a25998
  104. [*] Will set all_image_info_addr to: 0xfffffff00f004000
  105. [*] Setting all_image_info_addr...
  106. [*] Will set all_image_info_size to: 0x0000000008000000
  107. [*] Setting all_image_info_size...
  108. [*] Successfully set HSP4 as TFP0.
  109. [*] STATUS: Exploiting (8/37)
  110. [*] Unexporting kernel task port...
  111. [*] port_addr = 0xfffffff055a258f0
  112. [*] old host type: 0x80000003
  113. [*] Successfully unexported kernel task port.
  114. [*] STATUS: Exploiting (9/37)
  115. [*] Writing a test file to UserFS...
  116. [*] Successfully wrote a test file to UserFS.
  117. [*] STATUS: Exploiting (10/37)
  118. [*] Initializing kexecute...
  119. [*] got user client: 0x203307
  120. [*] port_addr = 0xfffffff05994bd48
  121. [*] Successfully initialized kexecute.
  122. [*] STATUS: Exploiting (11/37)
  123. [*] STATUS: Exploiting (12/37)
  124. [*] Unlocking nvram...
  125. [*] port_addr = 0xfffffff056f758b0
  126. [*] IODTNVRAM obj at 0xfffffff055a08720
  127. [*] vm_kernel_page_size: 1000
  128. [*] allocated address: fffffff0af103000
  129. [*] address to wire: fffffff0af104000
  130. [*] port_addr = 0xfffffff055a25998
  131. [*] port_addr = 0xfffffff0599492a0
  132. [*] Unlocked nvram
  133. [*] Successfully unlocked nvram.
  134. [*] runCommandv(1151) command: /usr/sbin/nvram "-p"
  135. [*] runCommandv(1151): com.apple.System.tz0-size 0x600000
  136. [*] runCommandv(1151): boot-args
  137. [*] runCommandv(1151): obliteration handle_message: Obliteration Complete%0a
  138. [*] runCommandv(1151): backlight-level 1556
  139. [*] runCommandv(1151): com.apple.System.boot-nonce 0x1111111111111111
  140. [*] runCommandv(1151): com.apple.System.sep.art 0%82%01%01%02%01%000%81%d9%02%03%06%ab%90%04%14C%befh;%cb%9e%1f%f8c%92%83%8ekw 8%ab%a6o%04%14%1a%e6E%c1/3%f7%bd%feLQ%99>%d9%81L%84%14w%b9%04%001%81%a3%c0%03%03L%d4%c2%03%03.~%c3%03%03%1d%0f%c8%05f%b4%80%b80%c9%05$%aaV5q%ca%05HlNgW%cb%06%00%99%96%cb%90y%cc%06%00%dc%caW%fb%86%cd%05[%bb%f7%adj%ce%06%00%8fU;%83%c7%cf%05x+U;%0b%d0%05%19%c5%f7%a4G%d1%05)S%d5%08%91%d2%06%00%802%fd?G%d3%06%00%fdih%b0R%d4%06%00%d6%aa%d4%dd%8c%d5%05pilu%b5%d6%05c%0e%e0%d2%89%d7%06%00%b2$%b4%a9U%d8%05B%a6%0e%cc%c5%d9%06%00%b1%fa%8e%1c%82%da%06%00%8a%c1p%f6%fc%db%04%012%072%04 %82{%16l%fb%1cB%be%19%ca9_6%1df%b8Z%18%83%fdYg%a8%d6E%f3*%dd%e5%11%a7%97
  141. [*] runCommandv(1151): com.apple.System.fp-state %00%00%00%00R%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00
  142. [*] runCommandv(1151): auto-boot true
  143. [*] runCommandv(1151): oblit-begins OblitType: ObliterateDataPartition. Reason: unknown
  144. [*] runCommandv(1151) completed with exit status 0
  145. [*] runCommandv(1152) command: /usr/sbin/nvram "com.apple.System.boot-nonce"
  146. [*] runCommandv(1152): com.apple.System.boot-nonce 0x1111111111111111
  147. [*] runCommandv(1152) completed with exit status 0
  148. [*] runCommandv(1153) command: /usr/sbin/nvram "-p"
  149. [*] runCommandv(1153): com.apple.System.tz0-size 0x600000
  150. [*] runCommandv(1153): boot-args
  151. [*] runCommandv(1153): obliteration handle_message: Obliteration Complete%0a
  152. [*] runCommandv(1153): backlight-level 1556
  153. [*] runCommandv(1153): com.apple.System.boot-nonce 0x1111111111111111
  154. [*] runCommandv(1153): com.apple.System.sep.art 0%82%01%01%02%01%000%81%d9%02%03%06%ab%90%04%14C%befh;%cb%9e%1f%f8c%92%83%8ekw 8%ab%a6o%04%14%1a%e6E%c1/3%f7%bd%feLQ%99>%d9%81L%84%14w%b9%04%001%81%a3%c0%03%03L%d4%c2%03%03.~%c3%03%03%1d%0f%c8%05f%b4%80%b80%c9%05$%aaV5q%ca%05HlNgW%cb%06%00%99%96%cb%90y%cc%06%00%dc%caW%fb%86%cd%05[%bb%f7%adj%ce%06%00%8fU;%83%c7%cf%05x+U;%0b%d0%05%19%c5%f7%a4G%d1%05)S%d5%08%91%d2%06%00%802%fd?G%d3%06%00%fdih%b0R%d4%06%00%d6%aa%d4%dd%8c%d5%05pilu%b5%d6%05c%0e%e0%d2%89%d7%06%00%b2$%b4%a9U%d8%05B%a6%0e%cc%c5%d9%06%00%b1%fa%8e%1c%82%da%06%00%8a%c1p%f6%fc%db%04%012%072%04 %82{%16l%fb%1cB%be%19%ca9_6%1df%b8Z%18%83%fdYg%a8%d6E%f3*%dd%e5%11%a7%97
  155. [*] runCommandv(1153): com.apple.System.fp-state %00%00%00%00R%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00
  156. [*] runCommandv(1153): auto-boot true
  157. [*] runCommandv(1153): oblit-begins OblitType: ObliterateDataPartition. Reason: unknown
  158. [*] runCommandv(1153) completed with exit status 0
  159. [*] Locking nvram...
  160. [*] Locked nvram
  161. [*] Successfully locked nvram.
  162. [*] STATUS: Exploiting (13/37)
  163. [*] Logging slide...
  164. [*] Successfully logged slide.
  165. [*] STATUS: Exploiting (14/37)
  166. [*] Logging ECID...
  167. [*] modifyPlist: Will modify plist: /var/mobile/Containers/Data/Application/38CA42F0-17E7-4B48-B4A0-CC0C8B5152BF/Library/Preferences/science.xnu.undecimus.plist
  168. [*] modifyPlist: Success
  169. [*] Successfully logged ECID.
  170. [*] STATUS: Exploiting (15/37)
  171. [*] Enabling Auto Updates...
  172. [*] modifyPlist: Will modify plist: /var/mobile/Library/Preferences/com.apple.Preferences.plist
  173. [*] modifyPlist: Writing to file: /var/mobile/Library/Preferences/com.apple.Preferences.plist
  174. [*] modifyPlist: Success
  175. [*] STATUS: Exploiting (16/37)
  176. [*] Remounting RootFS...
  177. fs_snapshot_list: Invalid argument
  178. [*] runCommandv(1154) command: /sbin/mount
  179. [*] runCommandv(1154): com.apple.os.update-43BE66683BCB9E1FF86392838E6B772038ABA66F@/dev/disk0s1s1 on / (apfs, local, nosuid, read-only, journaled, noatime)
  180. [*] runCommandv(1154): devfs on /dev (devfs, local, nosuid, nobrowse)
  181. [*] runCommandv(1154): /dev/disk0s1s2 on /private/var (apfs, local, nodev, nosuid, journaled, noatime, protect)
  182. [*] runCommandv(1154) completed with exit status 0
  183. [*] Clearing dev vnode's si_flags...
  184. [*] zone_map_ref: fffffff010872948
  185. [*] zone_map: fffffff05464c598
  186. [*] zm_range: 0xfffffff055800000 - 0xfffffff06b02d000 (read 0x20, exp 0x20)
  187. [*] devVnode = 0xfffffff056233960
  188. [*] v_specinfo = 0xfffffff056235128
  189. [*] si_flags = 0x0
  190. [*] Successfully cleared dev vnode's si_flags.
  191. [*] Mounting RootFS...
  192. [*] runCommandv(1155) command: /sbin/mount_apfs "/dev/disk0s1s1" "/private/var/tmp/jb/mnt1"
  193. [*] procStructAddr = 0xfffffff056dcd3f8
  194. [*] orig_creds = 0xfffffff056ea9520
  195. [*] runCommandv(1155) completed with exit status 0
  196. [*] runCommandv(1156) command: /sbin/mount
  197. [*] runCommandv(1156): com.apple.os.update-43BE66683BCB9E1FF86392838E6B772038ABA66F@/dev/disk0s1s1 on / (apfs, local, nosuid, read-only, journaled, noatime)
  198. [*] runCommandv(1156): devfs on /dev (devfs, local, nosuid, nobrowse)
  199. [*] runCommandv(1156): /dev/disk0s1s2 on /private/var (apfs, local, nodev, nosuid, journaled, noatime, protect)
  200. [*] runCommandv(1156): /dev/disk0s1s1 on /private/var/tmp/jb/mnt1 (apfs, local, nosuid, journaled, noatime)
  201. [*] runCommandv(1156) completed with exit status 0
  202. [*] Successfully mounted RootFS.
  203. [*] Renaming system snapshot...
  204. [*] Snapshots on newly mounted RootFS:
  205. [*] orig-fs
  206. [*] com.apple.os.update-43BE66683BCB9E1FF86392838E6B772038ABA66F
  207. [*] rvpp_ptr = 0xfffffff009ada000
  208. [*] sdvpp_ptr = 0xfffffff009adc000
  209. [*] ndp_buf = 0xfffffff009aef000
  210. [*] vfs_context = 0xfffffff059052288
  211. [*] sdvpp = 0xfffffff057506b40
  212. [*] sdvpp_v_mount = 0xfffffff055f16400
  213. [*] sdvpp_v_mount_mnt_data = 0xfffffff000ada000
  214. [*] snap_meta_ptr = 0xfffffff009af0000
  215. [*] old_name_ptr = 0xfffffff009f7b000
  216. [*] ndp_old_name_len = 0x3c
  217. [*] ndp_old_name = 0xfffffff009aef048
  218. [*] snap_meta = 0xfffffff059af3700
  219. [*] snap_vnode = 0xfffffff057944a50
  220. [*] system_snapshot_vnode = 0xfffffff057944a50
  221. [*] system_snapshot_vnode_v_data = 0xfffffff058447780
  222. [*] system_snapshot_vnode_v_data_flag = 0x40
  223. [*] __assert(17:fs_snapshot_rename(rootfd, systemSnapshot, origfs, 0) == ERR_SUCCESS)@JailbreakViewController.m:1177[jailbreak]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement