arx8x / v0rtexNonce

set generator for iOS 10.3 with v0rtex exploit by siguza
73 stars 27 forks source link

iPhone 7, 10.3.2 not working #35

Closed xsamuraislayerx closed 6 years ago

xsamuraislayerx commented 6 years ago

iPhone 7 on iOS 10.3.2 getting kernel panics when launching v0rtexnonce here's the log

2017-12-25 14:44:21.227053-0600 v0rtexNonce[209:4092] uid isn't 0 2017-12-25 14:44:21.227444-0600 v0rtexNonce[209:4092] Darwin Kernel Version 16.6.0: Mon Apr 17 17:33:35 PDT 2017; root:xnu-3789.60.24~24/RELEASE_ARM64_T8010 2017-12-25 14:44:21.227477-0600 v0rtexNonce[209:4092] loading offsets for iPhone9,3 - 14F89 2017-12-25 14:44:21.227491-0600 v0rtexNonce[209:4092] test offset x0x0x10gadget: fffffff0065000a8 2017-12-25 14:44:21.227567-0600 v0rtexNonce[209:4092] service: 650b 2017-12-25 14:44:21.227659-0600 v0rtexNonce[209:4092] client: 660b, (os/kern) successful 2017-12-25 14:44:21.227791-0600 v0rtexNonce[209:4092] newSurface: (os/kern) successful 2017-12-25 14:44:21.232977-0600 v0rtexNonce[209:4092] realport: 6703 2017-12-25 14:44:21.233021-0600 v0rtexNonce[209:4092] port: 106803 2017-12-25 14:44:21.233059-0600 v0rtexNonce[209:4092] mach_port_insert_right: (os/kern) successful 2017-12-25 14:44:21.233091-0600 v0rtexNonce[209:4092] mach_ports_register: (os/kern) successful 2017-12-25 14:44:21.233122-0600 v0rtexNonce[209:4092] herp derp 2017-12-25 14:44:21.334270-0600 v0rtexNonce[209:4092] mach_ports_register: (os/kern) successful 2017-12-25 14:44:21.548205-0600 v0rtexNonce[209:4092] mach_port_get_context: 0x100001c300000000, (os/kern) successful

also getting exploit failed here's that log:

2017-12-25 14:47:11.141735-0600 v0rtexNonce[214:5312] uid isn't 0 2017-12-25 14:47:11.142490-0600 v0rtexNonce[214:5312] Darwin Kernel Version 16.6.0: Mon Apr 17 17:33:35 PDT 2017; root:xnu-3789.60.24~24/RELEASE_ARM64_T8010 2017-12-25 14:47:11.142523-0600 v0rtexNonce[214:5312] loading offsets for iPhone9,3 - 14F89 2017-12-25 14:47:11.142559-0600 v0rtexNonce[214:5312] test offset x0x0x10gadget: fffffff0065000a8 2017-12-25 14:47:11.142657-0600 v0rtexNonce[214:5312] service: 650b 2017-12-25 14:47:11.142839-0600 v0rtexNonce[214:5312] client: 660b, (os/kern) successful 2017-12-25 14:47:11.142965-0600 v0rtexNonce[214:5312] newSurface: (os/kern) successful 2017-12-25 14:47:11.146511-0600 v0rtexNonce[214:5312] realport: 6703 2017-12-25 14:47:11.146773-0600 v0rtexNonce[214:5312] port: 106803 2017-12-25 14:47:11.146814-0600 v0rtexNonce[214:5312] mach_port_insert_right: (os/kern) successful 2017-12-25 14:47:11.146927-0600 v0rtexNonce[214:5312] mach_ports_register: (os/kern) successful 2017-12-25 14:47:11.146961-0600 v0rtexNonce[214:5312] herp derp 2017-12-25 14:47:11.248212-0600 v0rtexNonce[214:5312] mach_ports_register: (os/kern) successful 2017-12-25 14:47:11.434770-0600 v0rtexNonce[214:5312] mach_port_get_context: 0x0000000000000011, (os/kern) successful 2017-12-25 14:47:11.434813-0600 v0rtexNonce[214:5312] Invalid shift mask. 2017-12-25 14:47:11.440605-0600 v0rtexNonce[214:5312] Failed to get kernel task 2017-12-25 14:47:11.483425-0600 v0rtexNonce[214:5312] Reading var failed 2017-12-25 14:47:11.483495-0600 v0rtexNonce[214:5312] current generator:

if there is anymore info I can provide to you just let me know. Thank you for making this and putting so much work into it.

xsamuraislayerx commented 6 years ago

just to add I got a white screen freeze log as follows:

2017-12-25 15:03:11.627304-0600 v0rtexNonce[210:3943] uid isn't 0 2017-12-25 15:03:11.627843-0600 v0rtexNonce[210:3943] Darwin Kernel Version 16.6.0: Mon Apr 17 17:33:35 PDT 2017; root:xnu-3789.60.24~24/RELEASE_ARM64_T8010 2017-12-25 15:03:11.627878-0600 v0rtexNonce[210:3943] loading offsets for iPhone9,3 - 14F89 2017-12-25 15:03:11.627897-0600 v0rtexNonce[210:3943] test offset x0x0x10gadget: fffffff0065000a8 2017-12-25 15:03:11.628007-0600 v0rtexNonce[210:3943] service: 650b 2017-12-25 15:03:11.628160-0600 v0rtexNonce[210:3943] client: 660b, (os/kern) successful 2017-12-25 15:03:11.628375-0600 v0rtexNonce[210:3943] newSurface: (os/kern) successful 2017-12-25 15:03:11.634813-0600 v0rtexNonce[210:3943] realport: 6703 2017-12-25 15:03:11.634873-0600 v0rtexNonce[210:3943] port: 106803 2017-12-25 15:03:11.634932-0600 v0rtexNonce[210:3943] mach_port_insert_right: (os/kern) successful 2017-12-25 15:03:11.634976-0600 v0rtexNonce[210:3943] mach_ports_register: (os/kern) successful 2017-12-25 15:03:11.635014-0600 v0rtexNonce[210:3943] herp derp 2017-12-25 15:03:11.736269-0600 v0rtexNonce[210:3943] mach_ports_register: (os/kern) successful 2017-12-25 15:03:12.018916-0600 v0rtexNonce[210:3943] mach_port_get_context: 0x1000015f00000000, (os/kern) successful 2017-12-25 15:03:12.019217-0600 v0rtexNonce[210:3943] setValue(351): (os/kern) successful 2017-12-25 15:03:12.019265-0600 v0rtexNonce[210:3943] mach_port_request_notification: 0, (os/kern) successful 2017-12-25 15:03:12.019309-0600 v0rtexNonce[210:3943] getValue(351): 0x1010 bytes, (os/kern) successful 2017-12-25 15:03:12.019320-0600 v0rtexNonce[210:3943] realport addr: 0xffffffe003a78690 2017-12-25 15:03:12.019389-0600 v0rtexNonce[210:3943] setValue(351): (os/kern) successful 2017-12-25 15:03:12.019409-0600 v0rtexNonce[210:3943] itk_space: 0xffffffe0002dc510 2017-12-25 15:03:12.019418-0600 v0rtexNonce[210:3943] self_task: 0xffffffe001237520 2017-12-25 15:03:12.019425-0600 v0rtexNonce[210:3943] IOSurfaceRootUserClient port: 0xffffffe003a7a028 2017-12-25 15:03:12.019433-0600 v0rtexNonce[210:3943] IOSurfaceRootUserClient addr: 0xffffffe005629800 2017-12-25 15:03:12.019441-0600 v0rtexNonce[210:3943] IOSurfaceRootUserClient vtab: 0xfffffff00d64a238 2017-12-25 15:03:12.019448-0600 v0rtexNonce[210:3943] slide: 0x0000000006800000 2017-12-25 15:03:12.019458-0600 v0rtexNonce[210:3943] mach_ports_register: (os/kern) successful 2017-12-25 15:03:12.020019-0600 v0rtexNonce[210:3943] setValue(351): (os/kern) successful

heywong1123 commented 6 years ago

Same situation here with iPhone 9,1 10.3

u-C-m commented 6 years ago

how do you get those logs?

xsamuraislayerx commented 6 years ago

@u-C-m in Xcode, in debug.

arx8x commented 6 years ago

Offsets have been updated. Please try and let me know.

Once again : it takes a lot of tries