New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
iOS rootless jailbreak package #2288
Comments
+1 |
me 2 |
+1 |
@oleavr Could you take a look, recently, IOS 15.0-15.1 rootless jail break has been tested. I also encountered this problem. Thank you in advance. |
You can set |
Have you solved it? |
@oleavr |
Hi there :)
I suppose this is the Build Config that would need to be adjusted? |
Hi everyone! I created a Gist where you can find the build instructions to compile your frida version. @tmm1 confirmed to me that it works like a charm on iOS 16+ jailbroken with palera1n rootless. But there are some feature doesn't work with Dopamine on iOS 15:
|
So is it possible to use frida on dopamine with your repo? I got confused by your response |
Yes, but there are two limitations: @tmm1 supposed that these limitations depend on iOS version indeed it seems that they are present on palera1n rootless and iOS 15. |
|
Did you use my fork: https://github.com/miticollo/frida-ios-dump? |
no,use your build frida for arm64e |
|
I know there is this problem (see above) if you use Dopamibe. |
yes It's okay to use iPhone8 rootful |
I have just updated my fork. So Then:
If you prefer you can use an iDevice with rootfull JB. |
phone reboot and app Stuck etc. |
|
Hello,
iOS devices with bootrom vulnerable to the checkm8 exploit can be jailbroken up to version 15.7 by using palera1n rootless.
This jailbreak requires applications to be installed in
/var/jb/
(which is a symbolic link).I managed to install Frida by :
dpkg --vextract ./frida*.deb /var/jb ; chmod go+rx /var/jb/
/var/jb/Library/LaunchDaemons/re.frida.server.plist
to have the proper references to/var/jb/…
launchctl load /var/jb/Library/LaunchDaemons/re.frida.server.plist
I can contact the
frida-server
deamon with e.g.frida-ps -U
, but trying to hook an application results in the following error :Which happens because the
frida-agent.dylib
file is in the/var/jb/
directory too.Can you provide a Frida version for "rootless" jailbreaks on the iOS repo ?
According to the palera1n documentation, the architecture for these packages should be
iphoneos-arm64
(as opposed to the currentiphoneos-arm
)The text was updated successfully, but these errors were encountered: