在 iOS 14 - iOS 14.8.1 上以 root 权限实现未绑定 + 未沙盒化的代码执行 haxx。
基于 CoreTrustDemo,另外请注意证书不受版权保护。
注意:需要 macOS + 已越狱设备
此方法适用于 14.0-14.6。14.7 (14.7b1)-14.8.1 需要替换 launchd(参见 launchd.c),安全性较低。
make 构建。如果你不在 macOS 上,请指定 TARGET_SYSROOT。/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd 复制为 /System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd.back。/usr/bin/fileproviderctl 替换 /System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd。/private/var/haxx,权限应为 0777。fileproviderctl_internal 和 haxx 复制到设备上的 /usr/local/bin,权限应为 0755。完成上述步骤后,fileproviderctl 将无法正常工作,请按以下步骤修复:
/usr/bin/fileproviderctl 的副本到你的 Mac。gsed -i 's|/usr/local/bin/fileproviderctl_internal|/usr/local/bin/fileproviderctl_XXXXXXXX|g' fileproviderctl。codesign -s "Worth Doing Badly iPhone OS Application Signing" --preserve-metadata=entitlements --force fileproviderctl。要移除安装,请执行以下步骤:
/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd 复制为 /usr/bin/fileproviderctl。/System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd.back 移回 /System/Library/PrivateFrameworks/CoreAnalytics.framework/Support/analyticsd。/var/haxx、/usr/local/bin/fileproviderctl_internal 以及 /usr/local/bin/haxx。