add a readme
This commit is contained in:
parent
840664fd70
commit
1ab4a46705
26
README
26
README
@ -4,3 +4,29 @@ git clone git@github.com:comex/data.git
|
||||
make NATIVE=1
|
||||
./make_kernel_patchfile /path/to/kernelcache /tmp/patchfile
|
||||
./apply_patchfile /path/to/kernelcache /tmp/patchfile /output/patched/kernelcache
|
||||
|
||||
Patchfile format:
|
||||
|
||||
field length
|
||||
--------------------
|
||||
namelen 4
|
||||
name namelen
|
||||
addr 4
|
||||
datalen 4
|
||||
data datalen
|
||||
|
||||
- If you're patching the kernel after it has already booted, you can (but need not) skip patches with names starting with "-".
|
||||
|
||||
- apply_patchfile patches the kernel to start /sbin/lunchd instead of launchd. You can remove that, but the idea is that the filesystem looks like this:
|
||||
|
||||
/sbin/launchd: untether exploit that execs /sbin/lunchd
|
||||
/sbin/lunchd: a script that execs /sbin/launchd.real with DYLD_INSERT_LIBRARIES set to the dylibs in /Library/LaunchExtensions; this may be used in the future by MobileSubstrate
|
||||
/sbin/launchd.real: the original /sbin/launchd
|
||||
|
||||
This is the lunchd script:
|
||||
|
||||
#!/bin/bash
|
||||
shopt -s nullglob
|
||||
dylibs=$(for dylib in /Library/LaunchExtensions/*.dylib; do echo -n "$dylib:"; done)
|
||||
export DYLD_INSERT_LIBRARIES=${dylibs%:}
|
||||
exec -a /sbin/launchd /sbin/launchd.real
|
||||
|
@ -36,6 +36,8 @@ int main(int argc, char **argv) {
|
||||
assert(read(patchfd, stuff, size) == (ssize_t) size);
|
||||
|
||||
if(addr == 0) goto skip;
|
||||
// Patches starting with "+" only make sense to apply after the kernel has already booted.
|
||||
// They may be in BSS.
|
||||
if(name[0] == '+') goto skip;
|
||||
|
||||
if(argv[4] && !strcmp(argv[4], "-i")) {
|
||||
|
Loading…
Reference in New Issue
Block a user