
Exécution de code haxx untethered + non sandboxée en tant que root sur iOS 14 - iOS 14.8.1.
Exécution de code haxx sans attache et non sandboxée en tant que root sur iOS 14 - iOS 14.8.1.
Basé sur CoreTrustDemo, veuillez également noter que les certificats ne sont pas protégés par le droit d'auteur.
Remarque : nécessite macOS + un jailbreak existant
Cette méthode fonctionne sur 14.0-14.6. 14.7 (14.7b1)-14.8.1 nécessite le remplacement de launchd (voir launchd.c), ce qui est moins sûr.
make pour compiler. Si vous n'êtes pas sur macOS, spécifiez TARGET_SYSROOT/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd vers /System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd.back/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd par /usr/bin/fileproviderctl/private/var/haxx, le mode doit être 0777fileproviderctl_internal et haxx générés par la compilation vers /usr/local/bin sur l'appareil, le mode doit être 0755.Après avoir effectué les étapes ci-dessus, fileproviderctl sera cassé. Pour le réparer, suivez les étapes suivantes
/usr/bin/fileproviderctl sur votre appareil vers votre Macgsed -i 's|/usr/local/bin/fileproviderctl_internal|/usr/local/bin/fileproviderctl_XXXXXXXX|g' fileproviderctlcodesign -s "Worth Doing Badly iPhone OS Application Signing" --preserve-metadata=entitlements --force fileproviderctlPour supprimer l'installation, suivez les étapes suivantes
/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd vers /usr/bin/fileproviderctl/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd.back vers /System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd/var/haxx, /usr/local/bin/fileproviderctl_internal ainsi que /usr/local/bin/haxx