nick-botticelli / vma2pwn
Scripts + patches to pwn vma2 (Virtualization.framework) macOS virtual machines
☆55Updated 10 months ago
Alternatives and similar repositories for vma2pwn:
Users that are interested in vma2pwn are comparing it to the libraries listed below
- tart, but with custom AVPBooter ROM, serial I/O, DFU mode, GDB debugging (port 8000), and panic halting. See help menus for `tart create`…☆43Updated last year
- Interact with trustcaches☆41Updated 2 years ago
- Ghidra CI/CD to build and host a universal macOS Ghidra.app☆38Updated 2 weeks ago
- Guessed headers of non-public Apple SDK☆40Updated 4 months ago
- Translate and patch arm64e binaries or macOS arm64 binaries to run on an arm64 iPhone at runtime.☆51Updated 2 years ago
- A tool to parse Apple's binary device tree format.☆55Updated 5 years ago
- Extract iOS firmware keys using on-device AES engine☆36Updated 2 years ago
- Insecurity as an IOService☆88Updated last month
- Boot arbitrary iBoot via ipwndfu's custom protocol on some cursed platforms and more☆54Updated 3 months ago
- An open source implemention of Apple's `launchctl(1)`☆82Updated 4 months ago
- DeviceTree☆80Updated 6 months ago
- XPC sniffer using LLDB☆44Updated 7 months ago
- CLI frontend for com.apple.decmpfs / AppleFSCompression.framework☆31Updated 2 years ago
- 32/64 bit SecureROM/iBoot loader for IDA Pro. Also supports loading and decrypting encrypted .im4ps within IDA.☆74Updated 3 years ago
- AEA metadata dumper☆46Updated 9 months ago
- iPod nano 6 (S5L8723) implementation of S5Late bootrom exploit. Now also iPod shuffle 4 (S5L8443)☆18Updated 4 months ago
- Patch the iBoot64 with generic patches.☆52Updated last year
- Apple Silicon NOR dumper☆48Updated last year
- Tool for conversion between iBoot images and PNG.☆37Updated last year
- A working busybox for iOS and macOS☆32Updated 2 years ago
- iBoot/SEPOS decryption kit for JTAGgable iOS device prototypes☆105Updated 2 months ago
- Fork of PongoOS which can be run in QEMU☆66Updated 3 years ago
- ☆21Updated last year
- Transform any ARM macho executable to a dynamic library☆42Updated last month
- Extract Binaries from Apple's DYLD Shared Cache☆18Updated last year
- Sniff XPC communication using Frida and Go☆130Updated 2 weeks ago
- A custom shellcode hook for checkra1n 0.1337 written in c!☆38Updated last year
- Failed experiment for running command line macOS tools on jailbroken iOS. There's nothing useful here.☆42Updated 3 years ago
- macOS Sandbox Profile Language (SBPL) Interpreter☆53Updated 4 years ago
- Experimentation environment for checkm8-vulnerable devices☆53Updated last year