Tool to patch the ASLR slide generation in the kernel to disable user-land ASLR on 32-bit iOS
☆31Dec 6, 2020Updated 5 years ago
Alternatives and similar repositories for aslr-kernel-patch
Users that are interested in aslr-kernel-patch are comparing it to the libraries listed below
Sorting:
- Writes to nand_llb and triggers the Image3 SHSH overlap bug☆14Dec 2, 2023Updated 2 years ago
- some research results of sep☆20Apr 9, 2021Updated 4 years ago
- CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same networ…☆73Sep 23, 2020Updated 5 years ago
- crappy "debugger"-like memory reader, to inspect 32bit ios kernel after it paniced☆16Jan 12, 2019Updated 7 years ago
- Binary Ninja loader for A12 SEP firmware☆29Feb 4, 2021Updated 5 years ago
- Plugin for loading MachO kernelcache and dSYM files to Binary Ninja☆40Mar 23, 2025Updated 11 months ago
- iBoot/SecureROM Loader☆34Feb 24, 2023Updated 3 years ago
- ☆25May 19, 2022Updated 3 years ago
- My collection of PoCs☆26Nov 9, 2023Updated 2 years ago
- Extract iOS firmware keys using on-device AES engine☆41Jul 6, 2022Updated 3 years ago
- Proof-of-concept and write-up for the CVE-2022-32832 vulnerability patched in iOS 15.6☆96Jul 21, 2022Updated 3 years ago
- Hopefully an insightful XPC tracer that helps vulerability research by tracing server and client call stacks☆20Jul 19, 2022Updated 3 years ago
- An IDAPython module for enhancing c++ support on top of ida_kernelcache☆140May 15, 2025Updated 9 months ago
- ☆15Oct 27, 2022Updated 3 years ago
- Repository for sharing knowledge about Apple system internals and low-level exploitation☆10Feb 13, 2019Updated 7 years ago
- Binary View plugin for reverse engineering iBoot like binaries with Binary Ninja☆54Jan 25, 2024Updated 2 years ago
- ☆11Aug 11, 2012Updated 13 years ago
- ☆14Mar 27, 2023Updated 2 years ago
- UPDATED: All the action is at https://github.com/xsscx/srd☆12Jul 12, 2021Updated 4 years ago
- ☆149Oct 11, 2021Updated 4 years ago
- ☆22May 31, 2023Updated 2 years ago
- ☆39Feb 10, 2021Updated 5 years ago
- `ipsw` symbolication signatures☆85Dec 16, 2025Updated 2 months ago
- iBoot-1145.3 Image3/heap stack RE (+unholy tools)☆84Feb 10, 2024Updated 2 years ago
- 32/64 bit SecureROM/iBoot loader for IDA Pro. Also supports loading and decrypting encrypted .im4ps within IDA.☆73Mar 2, 2022Updated 3 years ago
- Structures, function definitions, and code reversed from old iBoot☆17Oct 25, 2018Updated 7 years ago
- IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter☆161Nov 2, 2024Updated last year
- A custom shellcode hook for checkra1n 0.1337 written in c!☆35Dec 20, 2023Updated 2 years ago
- A tool to write text to the iOS screen by directly modifying the pixel information in the framebuffer☆90Jun 28, 2020Updated 5 years ago
- Dev tools for probing IOKit☆200Sep 23, 2023Updated 2 years ago
- xnu_gym is a pongoOS module that patches XNU to reintroduce previously known and patched vulnerabilities. This is an easy way to practice…☆57Jun 17, 2021Updated 4 years ago
- ANE kernel r/w exploit for iOS 15 and macOS 12☆302Nov 20, 2022Updated 3 years ago
- A collection of MacOS jailbreak applications, IPA, and JailbreakMe websites.☆36Jun 20, 2024Updated last year
- Patch the iBoot64 with generic patches.☆52Mar 19, 2024Updated last year
- Dumped entitlements☆17Nov 28, 2021Updated 4 years ago
- Binary Ninja plugin & workflow to help analyze Objective-C code☆84Jul 11, 2022Updated 3 years ago
- a Ghidra framework for iOS kernelcache reverse engineering☆363Nov 6, 2022Updated 3 years ago
- Exploit for CVE-2021-30807☆132Nov 29, 2021Updated 4 years ago
- Segment-accurate iBoot/SecureROM loader for Binary Ninja & IDA Pro☆45Jan 14, 2026Updated last month