Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
ABrake27 — iOS 27 kernelcache RE: SEP 디스패치 맵, AMFI diff, Ghidra 워크플로우 | Kitploit
도구/GitHubGitHub/vvirei333/abrake27
iOS SecurityVulnerability AnalysisExploitationMobile App PentestingReverse EngineeringMobile SecurityBinary AnalysisPapers & ResearchLearning & EducationPayload DevelopmentFirmware Analysis
341일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHub
vvirei333/abrake27

ABrake27

iOS 27 kernelcache RE: SEP 디스패치 맵, AMFI diff, Ghidra 워크플로우

저장소 보기

ABrake27

iOS AMFI 개발자 모드 활성화를 위한 Linux 네이티브 크로스 컴파일러 + PoC (arm64/arm64e)

Platform Build Arch

연구용 툴킷. iOS 27.0.1과 27.2 펌웨어를 비교하고, AMFI IOUserClient 디스패치 테이블을 리버스 엔지니어링하며, Linux에서 베어메탈 IOKit PoC를 크로스 컴파일하고 — Xcode가 필요 없습니다 — 순정 Apple lockdown 프로토콜을 통해 iOS 27.0.1에서 개발자 모드를 활성화합니다 (커널 레벨에서 영구 지속성 검증 완료).


이것은 무엇인가

  • IPS 펌웨어 비교 — iOS 27.0.1과 27.2 (iPhone 14,5) 간의 kernelcache, kexts, sandbox, entitlements.
  • AMFI 디스패치 테이블 리버스 엔지니어링 — 모든 IOExternalMethodDispatch 슬롯을 매핑하고 selector 11 = armSecurityBootMode를 식별했습니다.
  • 독립 실행형 C PoC — poc/poc.c는 AppleMobileFileIntegrity/AppleCredentialManager를 열고 armSecurityBootMode를 호출한 뒤 결과를 로깅합니다. Foundation/UIKit 부풀림 없음 — 순수 C + IOKit.
  • Linux 크로스 컴파일러 — poc/build_ipa.sh는 CachyOS/Arch에서 clang + ld64.lld + ldid를 사용하여 서명된 .ipa를 생성합니다. Apple/Xcode 의존성 제로.

iOS 27.0.1에서 개발자 모드를 활성화하는 방법 (탈옥 없음, 서명되지 않은 코드 없음)

iOS 개발자 모드 토글 체인은 전적으로 순정 Apple lockdown 프로토콜 (com.apple.amfi.lockdown)을 통해 구동할 수 있습니다. 탈옥도, IPA도, entitlement 위조도 필요 없습니다 — Linux에서 pymobiledevice3만 있으면 됩니다.

검증 완료: 아래 체인을 실행한 후 mounter query-developer-mode-status → true가 되었고 DeveloperDiskImage가 /System/Developer에 마운트되었으며 — 둘 모두 독립적인 재부팅 후에도 유지되었습니다 (동일한 검사가 이전에는 다시 false로 돌아갔으므로, 지속성이 진정한 증거입니다; FINDINGS_LOCK.md 참조).

사전 요구 사항

암호를 제거하세요 (설정 → Face ID 및 암호 → 암호 끄기). 암호가 설정되어 있으면 AMFI는 action=1/action=2에 대해 Device has a passcode set으로 응답합니다.

단계

# 1) enable → action=1 → REBOOT #1
flatpak-spawn --host python3 -m pymobiledevice3 amfi enable-developer-mode

# 2) after the device boots: post-restart accept → action=2 → REBOOT #2
#    (the CLI has no separate accept command — call the service method directly,
#     e.g. via poc/verify_now2.py)

# 3) reveal the Settings toggle → action=0
flatpak-spawn --host python3 -m pymobiledevice3 amfi reveal-developer-mode

검증 (커널 레벨, AMFI 서비스와 독립적)

flatpak-spawn --host python3 -m pymobiledevice3 mounter query-developer-mode-status   # → true
flatpak-spawn --host python3 -m pymobiledevice3 mounter list                           # → IsMounted: true, /System/Developer
flatpak-spawn --host python3 -m pymobiledevice3 mounter auto-mount                    # → DeveloperDiskImage mounted successfully

프로토콜 요약

action의미효과
0reveal설정에 개발자 모드 토글을 표시
1enable플래그를 설정하고 기기를 재부팅
2accept재시작 후 확인, 다시 재부팅

⚠️ pymobiledevice3는 단락 처리합니다: 상태가 이미 true이면 enable-developer-mode는 *"Developer mode is already enabled"*만 로깅하고 아무것도 전송하지 않습니다. 두 번의 재부팅은 Apple 프로토콜의 일부이며 부수적인 것이 아닙니다.


빠른 시작 (Linux → iPhone 4분 만에)

사전 요구 사항 (CachyOS / Arch)

sudo pacman -S clang lld zip          # compiler + Mach-O linker
yay -S ldid                           # entitlement injector (AUR)
# iOS SDK:
mkdir -p poc/SDK
git clone https://github.com/theos/sdks poc/tmp && mv poc/tmp/iPhoneOS*.sdk poc/SDK/iPhoneOS.sdk

빌드

cd poc
IOS_SDK=/path/to/iPhoneOS.sdk ./build_ipa.sh
# Output: EnableAMFIDevMode.ipa

iPhone에 설치

# Via ideviceinstaller (libimobiledevice):
ideviceinstaller --install EnableAMFIDevMode.ipa

# Via TrollStore (if jailbroken/CT-bypass device):
# → TrollStore app → "+" → pick EnableAMFIDevMode.ipa

# Via SideStore/AltStore:
# → Add to SideStore → sign with your Apple ID

실행

# On device (SSH / NewTerm):
./EnableAMFIDevMode 1
cat /tmp/amfi_devmode_poc.log
# Then REBOOT to activate Developer Mode

대안: Linux에서 CoreDevice / DVT 실행 (run_dvt.sh)

두 번째, IPA 없는 경로가 존재합니다: Linux에서 독립 실행형 IOKit 바이너리를 크로스 컴파일하고 iOS 17+ CoreDevice / RSD 터널을 통해 기기로 푸시한 다음, DVT 프로세스 제어 서비스로 실행합니다 (App Sandbox 외부 — installd 없음, 무료 서명 IPA 없음).

./run_dvt.sh enable      # build (clang + ld64.lld) → deploy → `dvt launch --stream`

run_dvt.sh는 전체 체인을 자동화합니다:

  1. usbmuxd를 시작/확인하고 ideviceinfo (libimobiledevice)로 기기를 확인합니다;
  2. poc/poc.c를 베어 arm64 Mach-O로 크로스 컴파일합니다 (Apple 툴체인 없음): clang -c → ld64.lld -platform_version ios … -syslibroot … -undefined dynamic_lookup; SDK 버전은 plistlib를 통해 바이너리 SDKSettings.plist에서 읽습니다;
  3. 사용자 공간 RSD 터널 (pymobiledevice3)을 열고 dvt launch --stream을 호출합니다.

상태: Linux 크로스 컴파일은 작동합니다 (실제 arm64 Mach-O가 생성됨). 온디바이스 배포 단계는 아직 WIP입니다 — HANDOFF.md «Сессия 12» 참조. 또한 PoC의 IOKit 경로 (AppleMobileFileIntegrity selector 11)는 플랫폼 제한 entitlement com.apple.private.amfi.developer-mode-control을 요구하므로, Apple 서명이 없는 바이너리는 DVT를 통해 실행되더라도 userclient에 의해 거부됩니다 — 개발자 모드를 활성화하는 지원되는 방법은 위에 문서화된 lockdown 프로토콜입니다.


작동 방식

아키텍처 슬라이스당 두 가지 깔끔한 단계 (ld64.lld에 위임할 때 clang 드라이버가 -arch/-platform_version을 삼키는 것을 방지):

  1. clang -c — Mach-O 오브젝트, 링크 없음
  2. ld64.lld — 명시적 -arch arm64 -platform_version ios <min> <sdk>로 실행 파일 생성

clang-20...15, ld64.lld/lld, llvm-lipo, ldid를 자동 감지합니다. 우아한 폴백: 툴체인이 ptrauth 지원이 없으면 arm64e → arm64.


저장소 구조

.
├── ipsws/                   # iOS firmware images (NOT versioned — multi-GB)
├── kernelcaches/            # Extracted kernelcaches (arm64e Mach-O)
├── extracted/               # RootFS dumps + entitlements scan
├── diff_output/             # Full markdown diff reports (KEXTS, DYLIBS, SANDBOX...)
├── research/                # CVE analysis, XNU source excerpts
├── docs/WHITEPAPER.md       # Full AMFI binary-diff whitepaper (iOS 27.0.1 → 27.2)
├── poc/                     # ★ PoC source + Linux build system
│   ├── poc.c                #   AMFI + ACM IOKit client (C99)
│   ├── stubs/iokit_stub.h   #   Minimal IOKit header for Linux syntax check
│   ├── entitlements.plist   #   Required entitlements for armSecurityBootMode
│   ├── build_ipa.sh         #   ★ Linux cross-compiler (clang + ld64.lld + ldid)
│   ├── syntax_check_linux.sh
│   ├── lockdown_devmode.py  #   Session 9: lockdown/AMFI dev-mode probes
│   ├── action_probe.py      #   ★ Real AMFI protocol {"action": N}
│   ├── state_check.py       #   ★ Full kernel-level status + mounter query
│   ├── verify_now2.py       #   Post-restart accept (action=2) + verification
│   ├── semantics_probe.py   #   lockbot KV-store semantics (set_value dead-end)
│   ├── spoof_test.py        #   DeveloperModeStatus spoof attempt (failed)
│   ├── probe_amfi_service.py
│   ├── final_verify.py
│   └── verify_now.py
├── run_dvt.sh               # ★ CoreDevice/DVT deploy (build + usbmuxd + RSD tunnel + launch)
├── tools/macho_tool.py      #   stdlib-only Mach-O arm64e disassembler (kernelcache RE)
├── HANDOFF.md               # Full session log (Russian + English)
└── README.md                # You are here

심층 분석

📄 전체 백서 → docs/WHITEPAPER.md — vnode_check_signature의 바이너리 비교, 강제 활성화된 디버그 브리지, IOExternalMethodDispatch 테이블 디코드, 그리고 CVE-2025-43520 (DarkSword) VFS 레이스 분석.


환경 변수 재정의

도구 다운로드