arx8x / v0rtexNonce

set generator for iOS 10.3 with v0rtex exploit by siguza
73 stars 27 forks source link

update offsets #19

Closed ghost closed 6 years ago

ghost commented 6 years ago

offsets for iPhone SE iOS 10.3.1

OFFSET_ZONE_MAP = 0xfffffff007548478; OFFSET_KERNEL_MAP = 0xfffffff0075a4050; OFFSET_KERNEL_TASK = 0xfffffff0075a4048; OFFSET_REALHOST = 0xfffffff00752aba0; OFFSET_BZERO = 0xfffffff007081f80; OFFSET_BCOPY = 0xfffffff007081dc0; OFFSET_COPYIN = 0xfffffff007180720; OFFSET_COPYOUT = 0xfffffff007180914; OFFSET_IPC_PORT_ALLOC_SPECIAL = 0xfffffff007099efc; OFFSET_IPC_KOBJECT_SET = 0xfffffff0070ad154; OFFSET_IPC_PORT_MAKE_SEND = 0xfffffff007099a20; OFFSET_IOSURFACEROOTUSERCLIENT_VTAB = 0xfffffff006e83af8; OFFSET_ROP_ADD_X0_X0_0x10 = 0xfffffff006481174;

arx8x commented 6 years ago

Added Thank you

BuIlDaLiBlE commented 6 years ago

These offsets slightly differ from what find_offsets.sh finds:

OFFSET_ZONE_MAP                             = 0xfffffff007548478;
OFFSET_KERNEL_MAP                           = 0xfffffff0075a4050;
OFFSET_KERNEL_TASK                          = 0xfffffff0075a4048;
OFFSET_REALHOST                             = 0xfffffff00752aba0;
OFFSET_BZERO                                = 0xfffffff007081f80;
OFFSET_BCOPY                                = 0xfffffff007081dc0;
OFFSET_COPYIN                               = 0xfffffff007180720;
OFFSET_COPYOUT                              = 0xfffffff007180914;
OFFSET_IPC_PORT_ALLOC_SPECIAL               = 0xfffffff007099efc;
OFFSET_IPC_KOBJECT_SET                      = 0xfffffff0070ad154;
OFFSET_IPC_PORT_MAKE_SEND                   = 0xfffffff007099a20;
OFFSET_IOSURFACEROOTUSERCLIENT_VTAB         = 0xfffffff006e849f8;
OFFSET_ROP_ADD_X0_X0_0x10                   = 0xfffffff006481178;

(the last two)