Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2019-02-16 11:34:39.575251+0900 voucher_swap[315:8931] Unknown class TitleLabel in Interface Builder file.
- 2019-02-16 11:34:42.807173+0900 voucher_swap[315:8931] [MC] System group container for systemgroup.com.apple.configurationprofiles path is /private/var/containers/Shared/SystemGroup/systemgroup.com.apple.configurationprofiles
- 2019-02-16 11:34:42.808893+0900 voucher_swap[315:8931] [MC] Reading from public effective user settings.
- 2019-02-16 11:34:44.093393+0900 voucher_swap[315:8931] [Snapshotting] Snapshotting a view (0x101402ed0, _UIReplicantView) that has not been rendered at least once requires afterScreenUpdates:YES.
- 2019-02-16 11:34:45.311559+0900 voucher_swap[315:8931] [Snapshotting] Snapshotting a view (0x10143a6a0, _UIReplicantView) that has not been rendered at least once requires afterScreenUpdates:YES.
- 4K device //<- detects 4K devices and show this.
- Exploit selected: v3ntex. //<- selected v3ntex and starts exploit.
- kern=Darwin Kernel Version 18.0.0: Tue Aug 14 22:07:17 PDT 2018; root:xnu-4903.202.2~1/RELEASE_ARM64_T7000
- real pipecnt=0x500
- service: 5a03
- client: 14827, (os/kern) successful
- newSurface: (os/kern) successful
- stuffport: 7807, (os/kern) successful
- mach_port_insert_right: (os/kern) successful
- mach_msg: (os/kern) successful
- herp derp
- task_swap_mach_voucher: (os/kern) successful
- port_address=0xfffffff07b964c38
- fake_voucher_idx=6314
- fake_voucher_jdx=22
- Shifted Port!
- kport.ip_kobject=0xfffffff07ba64700
- sprayed pipecnt=0x500
- targetVoucher->iv_port=0xfffffff07ba64000
- final buf realloc :o
- reallocate_buf: (os/kern) successful
- replacing real_port_to_fake_voucher...
- old real_port_to_fake_voucher=4220419
- new real_port_to_fake_voucher=4483843
- p->ip_srights=100
- gfakeport_idx=121
- useport_addr=0xfffffff07b964b90
- Attempting read
- test=0x6580000002
- realport_addr=0xfffffff072bfca00
- itk_space=0xfffffff072ad2c00
- self_task=0xfffffff0739642a0
- IOSurfaceRootUserClient_port=0xfffffff07266e370
- IOSurfaceRootUserClient_addr=0xfffffff0752691c0
- IOSurfaceRootUserClient_vtab=0xfffffff017754d40
- Kernel base: 0xfffffff017204000
- Kernel Magic: 0xfeedfacf
- Kernel slide: 0x10200000
- Our task port: 0xfffffff074c7b7e0
- Kernel vm_map: 0xfffffff070b7e7c8
- Our ip_receiver: 0xfffffff071a10030
- Updating port for tfp0...
- Did we get tfp0?
- Attempting kalloc
- Allocated? 0xfffffff000890000
- Attempting write
- Read back: 0x4141414141414141
- Building safer tfp0
- fake_kernel_task_kaddr: fffffff000890000
- read fake_task_refs: d00d
- about to test new tfp0
- kernel read via second tfp0 port worked?
- 0x0000000000420000
- 0x0000000000000000
- 0xfffffff070b888e0
- 0xfffffff070b88840
- Built safer tfp0: 446a03!
- Cleaning up...
- some kernel:
- CF FA ED FE 0C 00 00 01 00 00 00 00 02 00 00 00 | ................
- 16 00 00 00 58 11 00 00 01 00 20 00 00 00 00 00 | ....X..... .....
- 19 00 00 00 28 02 00 00 5F 5F 54 45 58 54 00 00 | ....(...__TEXT..
- 00 00 00 00 00 00 00 00 00 40 20 17 F0 FF FF FF | .........@ .....
- 00 80 49 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..I.............
- 00 80 49 00 00 00 00 00 05 00 00 00 05 00 00 00 | ..I.............
- 06 00 00 00 00 00 00 00 5F 5F 63 6F 6E 73 74 00 | ........__const.
- 00 00 00 00 00 00 00 00 5F 5F 54 45 58 54 00 00 | ........__TEXT..
- 00 00 00 00 00 00 00 00 E0 5A 20 17 F0 FF FF FF | .........Z .....
- 88 CD 21 00 00 00 00 00 E0 1A 00 00 05 00 00 00 | ..!.............
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 63 73 74 72 69 6E | ........__cstrin
- 67 00 00 00 00 00 00 00 5F 5F 54 45 58 54 00 00 | g.......__TEXT..
- 00 00 00 00 00 00 00 00 68 28 42 17 F0 FF FF FF | ........h(B.....
- 2F 82 24 00 00 00 00 00 68 E8 21 00 00 00 00 00 | /.$.....h.!.....
- 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 6F 73 5F 6C 6F 67 | ........__os_log
- 00 00 00 00 00 00 00 00 5F 5F 54 45 58 54 00 00 | ........__TEXT..
- 00 00 00 00 00 00 00 00 97 AA 66 17 F0 FF FF FF | ..........f.....
- FF 0D 03 00 00 00 00 00 97 6A 46 00 00 00 00 00 | .........jF.....
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 66 69 70 73 5F 68 | ........__fips_h
- 6D 61 63 73 00 00 00 00 5F 5F 54 45 58 54 00 00 | macs....__TEXT..
- 00 00 00 00 00 00 00 00 96 B8 69 17 F0 FF FF FF | ..........i.....
- 20 00 00 00 00 00 00 00 96 78 49 00 00 00 00 00 | ........xI.....
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 69 6E 66 6F 5F 70 | ........__info_p
- 6C 69 73 74 00 00 00 00 5F 5F 54 45 58 54 00 00 | list....__TEXT..
- 00 00 00 00 00 00 00 00 B6 B8 69 17 F0 FF FF FF | ..........i.....
- ED 04 00 00 00 00 00 00 B6 78 49 00 00 00 00 00 | .........xI.....
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 74 68 72 65 61 64 | ........__thread
- 5F 73 74 61 72 74 73 00 5F 5F 54 45 58 54 00 00 | _starts.__TEXT..
- 00 00 00 00 00 00 00 00 A4 BD 69 17 F0 FF FF FF | ..........i.....
- 58 02 00 00 00 00 00 00 A4 7D 49 00 02 00 00 00 | X........}I.....
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 38 01 00 00 | ............8...
- 5F 5F 44 41 54 41 5F 43 4F 4E 53 54 00 00 00 00 | __DATA_CONST....
- 00 C0 69 17 F0 FF FF FF 00 80 1D 00 00 00 00 00 | ..i.............
- 00 80 49 00 00 00 00 00 00 80 1D 00 00 00 00 00 | ..I.............
- 03 00 00 00 03 00 00 00 03 00 00 00 00 00 00 00 | ................
- 5F 5F 6D 6F 64 5F 69 6E 69 74 5F 66 75 6E 63 00 | __mod_init_func.
- 5F 5F 44 41 54 41 5F 43 4F 4E 53 54 00 00 00 00 | __DATA_CONST....
- 00 C0 69 17 F0 FF FF FF 20 02 00 00 00 00 00 00 | ..i..... .......
- 00 80 49 00 03 00 00 00 00 00 00 00 00 00 00 00 | ..I.............
- 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 6D 6F 64 5F 74 65 72 6D 5F 66 75 6E 63 00 | __mod_term_func.
- 5F 5F 44 41 54 41 5F 43 4F 4E 53 54 00 00 00 00 | __DATA_CONST....
- 20 C2 69 17 F0 FF FF FF 18 02 00 00 00 00 00 00 | .i.............
- 20 82 49 00 03 00 00 00 00 00 00 00 00 00 00 00 | .I.............
- 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 63 6F 6E 73 74 00 00 00 00 00 00 00 00 00 | __const.........
- 5F 5F 44 41 54 41 5F 43 4F 4E 53 54 00 00 00 00 | __DATA_CONST....
- 40 C4 69 17 F0 FF FF FF C0 76 1D 00 00 00 00 00 | @.i......v......
- 40 84 49 00 04 00 00 00 00 00 00 00 00 00 00 00 | @.I.............
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 E8 00 00 00 5F 5F 54 45 58 54 5F 45 | ........__TEXT_E
- 58 45 43 00 00 00 00 00 00 40 87 17 F0 FF FF FF | XEC......@......
- 00 C0 27 01 00 00 00 00 00 00 67 00 00 00 00 00 | ..'.......g.....
- 00 C0 27 01 00 00 00 00 05 00 00 00 05 00 00 00 | ..'.............
- 02 00 00 00 00 00 00 00 5F 5F 74 65 78 74 00 00 | ........__text..
- 00 00 00 00 00 00 00 00 5F 5F 54 45 58 54 5F 45 | ........__TEXT_E
- 58 45 43 00 00 00 00 00 00 40 87 17 F0 FF FF FF | XEC......@......
- 48 84 27 01 00 00 00 00 00 00 67 00 0E 00 00 00 | H.'.......g.....
- 00 00 00 00 00 00 00 00 00 04 00 80 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 69 6E 69 74 63 6F 64 65 | ........initcode
- 00 00 00 00 00 00 00 00 5F 5F 54 45 58 54 5F 45 | ........__TEXT_E
- 58 45 43 00 00 00 00 00 48 C4 AE 18 F0 FF FF FF | XEC.....H.......
- 8C 07 00 00 00 00 00 00 48 84 8E 01 02 00 00 00 | ........H.......
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 E8 00 00 00 | ................
- 5F 5F 4C 41 53 54 00 00 00 00 00 00 00 00 00 00 | __LAST..........
- 00 00 AF 18 F0 FF FF FF 00 40 00 00 00 00 00 00 | .........@......
- 00 C0 8E 01 00 00 00 00 00 40 00 00 00 00 00 00 | .........@......
- 03 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 | ................
- 5F 5F 6D 6F 64 5F 69 6E 69 74 5F 66 75 6E 63 00 | __mod_init_func.
- 5F 5F 4C 41 53 54 00 00 00 00 00 00 00 00 00 00 | __LAST..........
- 00 00 AF 18 F0 FF FF FF 08 00 00 00 00 00 00 00 | ................
- 00 C0 8E 01 03 00 00 00 00 00 00 00 00 00 00 00 | ................
- 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 6C 61 73 74 00 00 00 00 00 00 00 00 00 00 | __last..........
- 5F 5F 4C 41 53 54 00 00 00 00 00 00 00 00 00 00 | __LAST..........
- 08 00 AF 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 28 02 00 00 5F 5F 4B 4C 44 00 00 00 | ....(...__KLD...
- 00 00 00 00 00 00 00 00 00 40 AF 18 F0 FF FF FF | .........@......
- 00 40 00 00 00 00 00 00 00 00 8F 01 00 00 00 00 | .@..............
- 00 40 00 00 00 00 00 00 03 00 00 00 03 00 00 00 | .@..............
- 06 00 00 00 00 00 00 00 5F 5F 74 65 78 74 00 00 | ........__text..
- 00 00 00 00 00 00 00 00 5F 5F 4B 4C 44 00 00 00 | ........__KLD...
- 00 00 00 00 00 00 00 00 00 40 AF 18 F0 FF FF FF | .........@......
- CC 17 00 00 00 00 00 00 00 00 8F 01 02 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 04 00 80 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 63 73 74 72 69 6E | ........__cstrin
- 67 00 00 00 00 00 00 00 5F 5F 4B 4C 44 00 00 00 | g.......__KLD...
- 00 00 00 00 00 00 00 00 CC 57 AF 18 F0 FF FF FF | .........W......
- DB 07 00 00 00 00 00 00 CC 17 8F 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 02 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 63 6F 6E 73 74 00 | ........__const.
- 00 00 00 00 00 00 00 00 5F 5F 4B 4C 44 00 00 00 | ........__KLD...
- 00 00 00 00 00 00 00 00 A8 5F AF 18 F0 FF FF FF | ........._......
- 68 00 00 00 00 00 00 00 A8 1F 8F 01 03 00 00 00 | h...............
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 6D 6F 64 5F 69 6E | ........__mod_in
- 69 74 5F 66 75 6E 63 00 5F 5F 4B 4C 44 00 00 00 | it_func.__KLD...
- 00 00 00 00 00 00 00 00 10 60 AF 18 F0 FF FF FF | .........`......
- 08 00 00 00 00 00 00 00 10 20 8F 01 03 00 00 00 | ......... ......
- 00 00 00 00 00 00 00 00 09 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 6D 6F 64 5F 74 65 | ........__mod_te
- 72 6D 5F 66 75 6E 63 00 5F 5F 4B 4C 44 00 00 00 | rm_func.__KLD...
- 00 00 00 00 00 00 00 00 18 60 AF 18 F0 FF FF FF | .........`......
- 08 00 00 00 00 00 00 00 18 20 8F 01 03 00 00 00 | ......... ......
- 00 00 00 00 00 00 00 00 0A 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 5F 5F 62 73 73 00 00 00 | ........__bss...
- 00 00 00 00 00 00 00 00 5F 5F 4B 4C 44 00 00 00 | ........__KLD...
- 00 00 00 00 00 00 00 00 20 60 AF 18 F0 FF FF FF | ........ `......
- 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 78 02 00 00 | ............x...
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 00 80 AF 18 F0 FF FF FF 00 80 18 00 00 00 00 00 | ................
- 00 40 8F 01 00 00 00 00 00 40 0F 00 00 00 00 00 | .@.......@......
- 03 00 00 00 03 00 00 00 07 00 00 00 00 00 00 00 | ................
- 5F 5F 6B 6D 6F 64 5F 69 6E 69 74 00 00 00 00 00 | __kmod_init.....
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 00 80 AF 18 F0 FF FF FF 30 26 00 00 00 00 00 00 | ........0&......
- 00 40 8F 01 03 00 00 00 00 00 00 00 00 00 00 00 | .@..............
- 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 6B 6D 6F 64 5F 74 65 72 6D 00 00 00 00 00 | __kmod_term.....
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 30 A6 AF 18 F0 FF FF FF C0 25 00 00 00 00 00 00 | 0........%......
- 30 66 8F 01 03 00 00 00 00 00 00 00 00 00 00 00 | 0f..............
- 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 64 61 74 61 00 00 00 00 00 00 00 00 00 00 | __data..........
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 00 00 B0 18 F0 FF FF FF A0 E9 06 00 00 00 00 00 | ................
- 00 C0 8F 01 0E 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 73 79 73 63 74 6C 5F 73 65 74 00 00 00 00 | __sysctl_set....
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- A0 E9 B6 18 F0 FF FF FF D8 24 00 00 00 00 00 00 | .........$......
- A0 A9 96 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 66 69 72 6D 77 61 72 65 00 00 00 00 00 00 | __firmware......
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 00 10 B7 18 F0 FF FF FF D0 87 07 00 00 00 00 00 | ................
- 00 D0 96 01 0C 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 63 6F 6D 6D 6F 6E 00 00 00 00 00 00 00 00 | __common........
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 00 A0 BE 18 F0 FF FF FF 98 65 06 00 00 00 00 00 | .........e......
- 00 00 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 | ................
- 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 62 73 73 00 00 00 00 00 00 00 00 00 00 00 | __bss...........
- 5F 5F 44 41 54 41 00 00 00 00 00 00 00 00 00 00 | __DATA..........
- 00 10 C5 18 F0 FF FF FF 98 EF 02 00 00 00 00 00 | ................
- 00 00 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 | ................
- 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 98 00 00 00 5F 5F 42 4F 4F 54 44 41 | ........__BOOTDA
- 54 41 00 00 00 00 00 00 00 00 C8 18 F0 FF FF FF | TA..............
- 00 80 01 00 00 00 00 00 00 80 9E 01 00 00 00 00 | ................
- 00 80 01 00 00 00 00 00 03 00 00 00 03 00 00 00 | ................
- 01 00 00 00 00 00 00 00 5F 5F 64 61 74 61 00 00 | ........__data..
- 00 00 00 00 00 00 00 00 5F 5F 42 4F 4F 54 44 41 | ........__BOOTDA
- 54 41 00 00 00 00 00 00 00 00 C8 18 F0 FF FF FF | TA..............
- 00 80 01 00 00 00 00 00 00 80 9E 01 0E 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 38 01 00 00 | ............8...
- 5F 5F 50 52 45 4C 49 4E 4B 5F 49 4E 46 4F 00 00 | __PRELINK_INFO..
- 00 80 C9 18 F0 FF FF FF 00 00 0B 00 00 00 00 00 | ................
- 00 00 A0 01 00 00 00 00 00 00 0B 00 00 00 00 00 | ................
- 03 00 00 00 03 00 00 00 03 00 00 00 00 00 00 00 | ................
- 5F 5F 6B 6D 6F 64 5F 69 6E 66 6F 00 00 00 00 00 | __kmod_info.....
- 5F 5F 50 52 45 4C 49 4E 4B 5F 49 4E 46 4F 00 00 | __PRELINK_INFO..
- 00 80 C9 18 F0 FF FF FF 98 05 00 00 00 00 00 00 | ................
- 00 00 A0 01 03 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 6B 6D 6F 64 5F 73 74 61 72 74 00 00 00 00 | __kmod_start....
- 5F 5F 50 52 45 4C 49 4E 4B 5F 49 4E 46 4F 00 00 | __PRELINK_INFO..
- 98 85 C9 18 F0 FF FF FF A0 05 00 00 00 00 00 00 | ................
- 98 05 A0 01 03 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 5F 5F 69 6E 66 6F 00 00 00 00 00 00 00 00 00 00 | __info..........
- 5F 5F 50 52 45 4C 49 4E 4B 5F 49 4E 46 4F 00 00 | __PRELINK_INFO..
- 38 8B C9 18 F0 FF FF FF 9B E9 0A 00 00 00 00 00 | 8...............
- 38 0B A0 01 00 00 00 00 00 00 00 00 00 00 00 00 | 8...............
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 98 00 00 00 5F 5F 50 52 45 4C 49 4E | ........__PRELIN
- 4B 5F 54 45 58 54 00 00 00 40 20 14 F0 FF FF FF | K_TEXT...@ .....
- 00 00 00 00 00 00 00 00 00 00 AB 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 03 00 00 00 03 00 00 00 | ................
- 01 00 00 00 04 00 00 00 5F 5F 74 65 78 74 00 00 | ........__text..
- 00 00 00 00 00 00 00 00 5F 5F 50 52 45 4C 49 4E | ........__PRELIN
- 4B 5F 54 45 58 54 00 00 00 40 20 14 F0 FF FF FF | K_TEXT...@ .....
- 00 00 00 00 00 00 00 00 00 00 AB 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 98 00 00 00 | ................
- 5F 5F 50 4C 4B 5F 54 45 58 54 5F 45 58 45 43 00 | __PLK_TEXT_EXEC.
- 00 80 D4 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 AB 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 03 00 00 00 03 00 00 00 01 00 00 00 04 00 00 00 | ................
- 5F 5F 74 65 78 74 00 00 00 00 00 00 00 00 00 00 | __text..........
- 5F 5F 50 4C 4B 5F 54 45 58 54 5F 45 58 45 43 00 | __PLK_TEXT_EXEC.
- 00 80 D4 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 AB 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 98 00 00 00 5F 5F 50 52 45 4C 49 4E | ........__PRELIN
- 4B 5F 44 41 54 41 00 00 00 80 D4 18 F0 FF FF FF | K_DATA..........
- 00 00 00 00 00 00 00 00 00 00 AB 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 03 00 00 00 03 00 00 00 | ................
- 01 00 00 00 04 00 00 00 5F 5F 64 61 74 61 00 00 | ........__data..
- 00 00 00 00 00 00 00 00 5F 5F 50 52 45 4C 49 4E | ........__PRELIN
- 4B 5F 44 41 54 41 00 00 00 80 D4 18 F0 FF FF FF | K_DATA..........
- 00 00 00 00 00 00 00 00 00 00 AB 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 98 00 00 00 | ................
- 5F 5F 50 4C 4B 5F 44 41 54 41 5F 43 4F 4E 53 54 | __PLK_DATA_CONST
- 00 80 D4 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 AB 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 03 00 00 00 03 00 00 00 01 00 00 00 04 00 00 00 | ................
- 5F 5F 64 61 74 61 00 00 00 00 00 00 00 00 00 00 | __data..........
- 5F 5F 50 4C 4B 5F 44 41 54 41 5F 43 4F 4E 53 54 | __PLK_DATA_CONST
- 00 80 D4 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 AB 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 98 00 00 00 5F 5F 50 4C 4B 5F 4C 4C | ........__PLK_LL
- 56 4D 5F 43 4F 56 00 00 00 80 D4 18 F0 FF FF FF | VM_COV..........
- 00 00 00 00 00 00 00 00 00 00 AB 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 03 00 00 00 03 00 00 00 | ................
- 01 00 00 00 04 00 00 00 5F 5F 6C 6C 76 6D 5F 63 | ........__llvm_c
- 6F 76 6D 61 70 00 00 00 5F 5F 50 4C 4B 5F 4C 4C | ovmap...__PLK_LL
- 56 4D 5F 43 4F 56 00 00 00 80 D4 18 F0 FF FF FF | VM_COV..........
- 00 00 00 00 00 00 00 00 00 00 AB 01 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 19 00 00 00 98 00 00 00 | ................
- 5F 5F 50 4C 4B 5F 4C 49 4E 4B 45 44 49 54 00 00 | __PLK_LINKEDIT..
- 00 80 D4 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 AB 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 03 00 00 00 03 00 00 00 01 00 00 00 04 00 00 00 | ................
- 5F 5F 64 61 74 61 00 00 00 00 00 00 00 00 00 00 | __data..........
- 5F 5F 50 4C 4B 5F 4C 49 4E 4B 45 44 49 54 00 00 | __PLK_LINKEDIT..
- 00 80 D4 18 F0 FF FF FF 00 00 00 00 00 00 00 00 | ................
- 00 00 AB 01 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 19 00 00 00 48 00 00 00 5F 5F 4C 49 4E 4B 45 44 | ....H...__LINKED
- 49 54 00 00 00 00 00 00 00 80 D4 18 F0 FF FF FF | IT..............
- 78 6F 01 00 00 00 00 00 00 00 AB 01 00 00 00 00 | xo..............
- 78 6F 01 00 00 00 00 00 01 00 00 00 01 00 00 00 | xo..............
- 00 00 00 00 00 00 00 00 02 00 00 00 18 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 0B 00 00 00 50 00 00 00 00 00 00 00 00 00 00 00 | ....P...........
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................
- lol //Exploit succeed
- Getting root... //tons of errors
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x0000000000000000
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x00000000000000f7
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x0000000000000027
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x000000000000002f
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x0000000000000017
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x000000000000001b
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x000000000000001f
- [+] Overwritten UID to 0 for proc 0xffffffffffffffff
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x00000000000000f7
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x000000000000002b
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x0000000000000033
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x0000000000000067
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x000000000000006b
- [+] Overwritten GID to 0 for proc 0xffffffffffffffff
- UID: 501 //<- It needs to be "UID: 0"
- Unsandboxing... //tons of errors
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x0000000000000000
- [+] Unsandboxed proc 0xffffffffffffffff
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x00000000000000f7
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x0000000000000077
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x000000000000000f
- [-] mach_vm_write returned 268435459: (ipc/send) invalid destination port
- [-] could not write address 0x000000000000000f
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x0000000000000000
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x00000000000000f7
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x0000000000000077
- [-] mach_vm_read_overwrite returned 268435459: (ipc/send) invalid destination port
- [-] could not read address 0x000000000000000f
- Unsandboxed: 0 //<- It needs to be "Unsandboxed: 1"
- Success! //<-Ignore this, This always show up.
- Failed to make a backup checker //<- This because failed to unsandbox.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement