checkra1n / BugTracker

checkra1n bug tracker
726 stars 105 forks source link

SSH password resetting to alpine each jailbreak. Possibly a bug? #407

Open yur1xpp opened 4 years ago

yur1xpp commented 4 years ago

What device + iOS version are you on? iPhone X, iOS 13.2.2

What checkra1n version are you using? 0.9.5

What are the steps to reproduce the issue?

  1. Change your root password
  2. Reboot and rejailbreak
  3. Password is reset back to alpine ...

What do you expect, and what is happening instead? Changed password stay intact

Any other info, error logs, screenshots, ...?

Thanks guys!

WesternIcelander commented 4 years ago

Locally running unsandboxed code could escalate privileges through su or login if the password is alpine and reset to alpine at every reboot.

kpwn commented 4 years ago

It should not reset to alpine at every reboot. Is this on a bootstrapped device or do you only have the initial ssh mode?

Halo-Michael commented 4 years ago

Seem like he is try to icloud bypass a phone but without rename snapshot.

yur1xpp commented 4 years ago

I did try rejailbreak several times using the 0.9.5 and when I try to SSH, I couldn't login using my previously changed password, but alpine works. Bootstrapped device here means when it's upgraded to newer version of checkra1n (0.9.3.2 -> 0.9.5)? If yes, then yes.

And no, this has nothing to do with iCloud bypass whatsoever.

kpwn commented 4 years ago

a bootstrapped device is a device where you installed cydia. until you do that, we leave / read only, so that might be the reason.