SHARE
TWEET
Untitled
a guest
Dec 17th, 2017
186
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
- // iPhone 6s Plus - 10.3.1
- #define FEEDFACF 0x1B5
- #define OFFSET_ZONE_MAP 0xFFFFFFF007548478 // search string \"zone_init: kmem_suballoc failed\" then xref twice
- #define OFFSET_KERNEL_MAP 0xFFFFFFF0075A4050 // _kernel_map (exports)
- #define OFFSET_KERNEL_TASK 0xFFFFFFF0075A4048 // _kernel_task (exports)
- #define OFFSET_REALHOST 0xFFFFFFF00752ABA0 // qword to right of _host_priv_self (add x0,x0)
- #define OFFSET_BZERO 0xFFFFFFF007081F80 // _bzero (exports)
- #define OFFSET_BCOPY 0xFFFFFFF007081DC0 // _obvcopy (exports)
- #define OFFSET_COPYIN 0xFFFFFFF007180720 // _copyin (exports)
- #define OFFSET_COPYOUT 0xFFFFFFF007180914 // _copyout (exports)
- #define OFFSET_IPC_PORT_ALLOC_SPECIAL 0xFFFFFFF007099EFC //string \"ipc_host_init\" then xref twice (1st sub)
- #define OFFSET_IPC_KOBJECT_SET 0xFFFFFFF0070AD154 //string \"ipc_host_init\" then xref twice (2nd sub)
- #define OFFSET_IPC_PORT_MAKE_SEND 0xFFFFFFF007099A20 //string \"ipc_host_init\" then xref twice (3rd sub)
- #define OFFSET_IOSURFACEROOTUSERCLIENT_VTAB 0xFFFFFFF0060740F2 // (IOSurface + 0x1030) (use radare2)
- #define OFFSET_ROP_ADD_X0_X0_0x10 0xfffffff006465174 //rop gadget (use radare2)
- // iPhone 6 Plus - 10.3.1
- #define FEEDFACF 0x1B5
- #define OFFSET_ZONE_MAP 0xFFFFFFF007558478 // search string \"zone_init: kmem_suballoc failed\" then xref twice
- #define OFFSET_KERNEL_MAP 0xFFFFFFF0075B4050 // _kernel_map (exports)
- #define OFFSET_KERNEL_TASK 0xFFFFFFF0075B4048 // _kernel_task (exports)
- #define OFFSET_REALHOST 0xFFFFFFF00753ABA0 // qword to right of _host_priv_self (add x0,x0)
- #define OFFSET_BZERO 0xFFFFFFF00708DF80 // _bzero (exports)
- #define OFFSET_BCOPY 0xFFFFFFF00708DDC0 // _obvcopy (exports)
- #define OFFSET_COPYIN 0xFFFFFFF00718D3A8 // _copyin (exports)
- #define OFFSET_COPYOUT 0xFFFFFFF00718D59C // _copyout (exports)
- #define OFFSET_IPC_PORT_ALLOC_SPECIAL 0xFFFFFFF0070A611C //string \"ipc_host_init\" then xref twice (1st sub)
- #define OFFSET_IPC_KOBJECT_SET 0xFFFFFFF0070B9374 //string \"ipc_host_init\" then xref twice (2nd sub)
- #define OFFSET_IPC_PORT_MAKE_SEND 0xFFFFFFF0070A5C40 //string \"ipc_host_init\" then xref twice (3rd sub)
- #define OFFSET_IOSURFACEROOTUSERCLIENT_VTAB 0xFFFFFFF006EEE1B8 // (IOSurface + 0x1030) (use radare2)
- #define OFFSET_ROP_ADD_X0_X0_0x10 0xfffffff0064b5174 //rop gadget (use radare2)
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy.
