As a sidenote: you can use a De Bruijn sequence to find the offset to the saved instruction pointer on the stack with ragg2: For generating the pattern: "ragg2 -P 300 -r", for getting the offset from the buffer to the saved instruction ptr: "ragg2 -q 0x41416241" (or whatever the instruction ptr was jumping to)
Hello @ZygoSec, Just following up on my previous comment. I am curious about the twitter app that you are using in the video, Could you please share the name of the app on OSX menu bar?
As a sidenote: you can use a De Bruijn sequence to find the offset to the saved instruction pointer on the stack with ragg2: For generating the pattern: "ragg2 -P 300 -r", for getting the offset from the buffer to the saved instruction ptr: "ragg2 -q 0x41416241" (or whatever the instruction ptr was jumping to)
@ZygoSec Which is the twitter app that you are using on the OSX menu bar?
Hello @ZygoSec, Just following up on my previous comment. I am curious about the twitter app that you are using in the video, Could you please share the name of the app on OSX menu bar?
Wait so you caused an error on your iphone or your computer
On the iPhone - I am simply connecting to the iPhone from the Mac
Can you use hopper instead of radare2
awesome tutorial, thanks!
was radare2 featured at 33c3? i think i saw it there...
yes it was :)
cannot execute binary file: Operation not permitted
Where do you get the crash log?
download CrashReporter from Cydia and every time the program crashes, CrashReporter will produce a new crash log for you
rip s0n1c_dev 2:50
what the video for grab passworld on icloud
Moar plzzzzz