Closed ghost closed 6 years ago
Added Thank you
These offsets slightly differ from what find_offsets.sh finds:
OFFSET_ZONE_MAP = 0xfffffff007548478;
OFFSET_KERNEL_MAP = 0xfffffff0075a4050;
OFFSET_KERNEL_TASK = 0xfffffff0075a4048;
OFFSET_REALHOST = 0xfffffff00752aba0;
OFFSET_BZERO = 0xfffffff007081f80;
OFFSET_BCOPY = 0xfffffff007081dc0;
OFFSET_COPYIN = 0xfffffff007180720;
OFFSET_COPYOUT = 0xfffffff007180914;
OFFSET_IPC_PORT_ALLOC_SPECIAL = 0xfffffff007099efc;
OFFSET_IPC_KOBJECT_SET = 0xfffffff0070ad154;
OFFSET_IPC_PORT_MAKE_SEND = 0xfffffff007099a20;
OFFSET_IOSURFACEROOTUSERCLIENT_VTAB = 0xfffffff006e849f8;
OFFSET_ROP_ADD_X0_X0_0x10 = 0xfffffff006481178;
(the last two)
offsets for iPhone SE iOS 10.3.1
OFFSET_ZONE_MAP = 0xfffffff007548478; OFFSET_KERNEL_MAP = 0xfffffff0075a4050; OFFSET_KERNEL_TASK = 0xfffffff0075a4048; OFFSET_REALHOST = 0xfffffff00752aba0; OFFSET_BZERO = 0xfffffff007081f80; OFFSET_BCOPY = 0xfffffff007081dc0; OFFSET_COPYIN = 0xfffffff007180720; OFFSET_COPYOUT = 0xfffffff007180914; OFFSET_IPC_PORT_ALLOC_SPECIAL = 0xfffffff007099efc; OFFSET_IPC_KOBJECT_SET = 0xfffffff0070ad154; OFFSET_IPC_PORT_MAKE_SEND = 0xfffffff007099a20; OFFSET_IOSURFACEROOTUSERCLIENT_VTAB = 0xfffffff006e83af8; OFFSET_ROP_ADD_X0_X0_0x10 = 0xfffffff006481174;