mirror of
https://github.com/NohamR/Tweaks.git
synced 2026-08-26 10:12:32 +00:00
Compare commits
17 Commits
OqeePlus-t
...
58990b8ecc
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
58990b8ecc | ||
|
|
24dc5267ca | ||
|
|
a4dc5a9968 | ||
|
|
79f9e5cf0c | ||
|
|
4d51a6eccf | ||
|
|
58dd5db8fd | ||
|
|
4e040791c1 | ||
|
|
965bfcdeff | ||
|
|
ec1b0a17f0 | ||
|
|
81ab62324c | ||
|
|
238f92ce01 | ||
|
|
214ab9d08a | ||
|
|
db4f414902 | ||
|
|
29578e8aff | ||
|
|
43431e4916 | ||
|
|
dee3024d26 | ||
|
|
e41d8f7279 |
30
.github/workflows/build.yml
vendored
30
.github/workflows/build.yml
vendored
@@ -28,6 +28,14 @@ jobs:
|
||||
with:
|
||||
ref: ${{ inputs.branch || github.ref }}
|
||||
|
||||
- name: Cache Homebrew packages
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: ~/Library/Caches/Homebrew
|
||||
key: brew-${{ runner.os }}-make-ldid
|
||||
restore-keys: |
|
||||
brew-${{ runner.os }}-
|
||||
|
||||
- name: Install dependencies
|
||||
run: brew install make ldid
|
||||
|
||||
@@ -36,8 +44,7 @@ jobs:
|
||||
echo "$(brew --prefix make)/libexec/gnubin" >> $GITHUB_PATH
|
||||
echo "THEOS=${{ github.workspace }}/theos" >> $GITHUB_ENV
|
||||
|
||||
# Original from YTweaks
|
||||
- name: Get Theos commit
|
||||
- name: Get Theos and dependencies commit
|
||||
run: |
|
||||
get_commit_hash() {
|
||||
local repo_url=$1
|
||||
@@ -51,13 +58,18 @@ jobs:
|
||||
fi
|
||||
echo "THEOS_REPO=$THEOS_URL" >> $GITHUB_ENV
|
||||
echo "THEOS_COMMIT=$(get_commit_hash "$THEOS_URL")" >> $GITHUB_ENV
|
||||
echo "PSHEADER_COMMIT=$(get_commit_hash "https://github.com/PoomSmart/PSHeader.git")" >> $GITHUB_ENV
|
||||
echo "SDK_COMMIT=$(get_commit_hash "https://github.com/Tonwalter888/iOS-SDKs.git")" >> $GITHUB_ENV
|
||||
|
||||
- name: Cache Theos
|
||||
id: cache-theos
|
||||
uses: actions/cache@v5
|
||||
uses: actions/cache@v4
|
||||
with:
|
||||
path: theos
|
||||
key: Tweak-18.6-SDK-${{ env.THEOS_COMMIT }}
|
||||
key: Theos-${{ env.THEOS_COMMIT }}-SDK-${{ env.SDK_COMMIT }}-PSHeader-${{ env.PSHEADER_COMMIT }}
|
||||
restore-keys: |
|
||||
Theos-${{ env.THEOS_COMMIT }}-SDK-${{ env.SDK_COMMIT }}-
|
||||
Theos-${{ env.THEOS_COMMIT }}-
|
||||
|
||||
- name: Setup Theos
|
||||
if: ${{ steps.cache-theos.outputs.cache-hit != 'true' }}
|
||||
@@ -68,16 +80,8 @@ jobs:
|
||||
git sparse-checkout set --no-cone iPhoneOS18.6.sdk
|
||||
git checkout --quiet
|
||||
mv *.sdk "$THEOS/sdks"
|
||||
|
||||
- name: Clone headers
|
||||
run: |
|
||||
if [ ! -d "$THEOS/include/PSHeader" ]; then
|
||||
git clone --quiet --depth=1 https://github.com/PoomSmart/PSHeader.git "$THEOS/include/PSHeader"
|
||||
else
|
||||
cd $THEOS/include/PSHeader
|
||||
git pull --quiet --force
|
||||
cd ${{ github.workspace }}
|
||||
fi
|
||||
git clone --quiet --depth=1 https://github.com/PoomSmart/PSHeader.git "$THEOS/include/PSHeader"
|
||||
|
||||
- name: Build Tweak
|
||||
run: |
|
||||
|
||||
8
.gitignore
vendored
8
.gitignore
vendored
@@ -1,2 +1,10 @@
|
||||
.DS_Store
|
||||
Build.md
|
||||
/RedditPatch
|
||||
/PineHeartsUnlock
|
||||
/App
|
||||
/GoodnotesPro
|
||||
/StravaPremium
|
||||
scripts/build_install_loop.sh
|
||||
CanardDumper/Tweak.x.bak
|
||||
CanardDumper/Tweak_POC.x
|
||||
|
||||
7
CanardDumper/CanardDumper.plist
Normal file
7
CanardDumper/CanardDumper.plist
Normal file
@@ -0,0 +1,7 @@
|
||||
{
|
||||
Filter = {
|
||||
Bundles = (
|
||||
"fr.lecanardenchaine.app",
|
||||
);
|
||||
};
|
||||
}
|
||||
14
CanardDumper/Makefile
Normal file
14
CanardDumper/Makefile
Normal file
@@ -0,0 +1,14 @@
|
||||
TARGET = iphone:latest:15.0
|
||||
ARCHS = arm64 arm64e
|
||||
INSTALL_TARGET_PROCESSES = fr.lecanardenchaine.app
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = CanardDumper
|
||||
CanardDumper_FILES = Tweak.x
|
||||
CanardDumper_CFLAGS = -fobjc-arc -Wno-deprecated-declarations -std=c++11 -x objective-c++
|
||||
CanardDumper_CXXFLAGS = -std=c++11
|
||||
CanardDumper_FRAMEWORKS = Foundation UIKit
|
||||
CanardDumper_LDFLAGS = -lstdc++
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
153
CanardDumper/Tweak.x
Normal file
153
CanardDumper/Tweak.x
Normal file
@@ -0,0 +1,153 @@
|
||||
#import <substrate.h>
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <UIKit/UIKit.h>
|
||||
|
||||
#pragma mark - Constants
|
||||
|
||||
static NSString *const kCanardLogTag = @"[CanardDumper]";
|
||||
static NSString *const kCanardDumpDirectoryName = @"CanardDumps";
|
||||
|
||||
#pragma mark - State
|
||||
|
||||
static NSString *CanardArchivePassword;
|
||||
static int CanardLastSavedReadSize = -1;
|
||||
|
||||
#pragma mark - UI Helpers
|
||||
|
||||
static UIViewController *CanardTopViewController(UIViewController *viewController) {
|
||||
if (!viewController) return nil;
|
||||
|
||||
if (viewController.presentedViewController) {
|
||||
return CanardTopViewController(viewController.presentedViewController);
|
||||
}
|
||||
if ([viewController isKindOfClass:[UINavigationController class]]) {
|
||||
return CanardTopViewController([(UINavigationController *)viewController visibleViewController]);
|
||||
}
|
||||
if ([viewController isKindOfClass:[UITabBarController class]]) {
|
||||
return CanardTopViewController([(UITabBarController *)viewController selectedViewController]);
|
||||
}
|
||||
return viewController;
|
||||
}
|
||||
|
||||
static void CanardPresentShareSheet(NSString *filePath) {
|
||||
dispatch_async(dispatch_get_main_queue(), ^{
|
||||
UIWindow *keyWindow = nil;
|
||||
for (UIWindow *window in [UIApplication sharedApplication].windows) {
|
||||
if (window.isKeyWindow) {
|
||||
keyWindow = window;
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
UIViewController *topVC = CanardTopViewController(keyWindow.rootViewController);
|
||||
if (!topVC) {
|
||||
NSLog(@"%@ Unable to present share sheet", kCanardLogTag);
|
||||
return;
|
||||
}
|
||||
|
||||
NSURL *fileURL = [NSURL fileURLWithPath:filePath];
|
||||
UIActivityViewController *shareController = [[UIActivityViewController alloc] initWithActivityItems:@[fileURL] applicationActivities:nil];
|
||||
shareController.popoverPresentationController.sourceView = topVC.view;
|
||||
shareController.popoverPresentationController.sourceRect = CGRectMake(
|
||||
CGRectGetMidX(topVC.view.bounds),
|
||||
CGRectGetMidY(topVC.view.bounds),
|
||||
0, 0
|
||||
);
|
||||
[topVC presentViewController:shareController animated:YES completion:nil];
|
||||
});
|
||||
}
|
||||
|
||||
#pragma mark - File Helpers
|
||||
|
||||
static NSString *CanardSanitizedFilename(NSString *password) {
|
||||
if (password.length == 0) return @"unknown";
|
||||
|
||||
NSCharacterSet *invalidChars = [NSCharacterSet characterSetWithCharactersInString:@"/:\\?%*|\"<>\n\r\t"];
|
||||
NSString *sanitized = [[password componentsSeparatedByCharactersInSet:invalidChars] componentsJoinedByString:@"_"];
|
||||
return sanitized.length > 0 ? sanitized : @"unknown";
|
||||
}
|
||||
|
||||
static NSString *CanardDumpDirectory() {
|
||||
NSString *docsPath = [NSSearchPathForDirectoriesInDomains(NSDocumentDirectory, NSUserDomainMask, YES) firstObject];
|
||||
return [docsPath stringByAppendingPathComponent:kCanardDumpDirectoryName];
|
||||
}
|
||||
|
||||
static bool CanardSaveData(NSData *data, NSString *password) {
|
||||
NSFileManager *fm = [NSFileManager defaultManager];
|
||||
NSString *dumpDir = CanardDumpDirectory();
|
||||
|
||||
if (![fm fileExistsAtPath:dumpDir]) {
|
||||
[fm createDirectoryAtPath:dumpDir withIntermediateDirectories:YES attributes:nil error:nil];
|
||||
}
|
||||
|
||||
NSString *fileName = [NSString stringWithFormat:@"file_%@.pdf", CanardSanitizedFilename(password)];
|
||||
NSString *filePath = [dumpDir stringByAppendingPathComponent:fileName];
|
||||
|
||||
if ([data writeToFile:filePath atomically:YES]) {
|
||||
NSLog(@"%@ Saved to %@ (%lu bytes)", kCanardLogTag, filePath, (unsigned long)data.length);
|
||||
CanardPresentShareSheet(filePath);
|
||||
return YES;
|
||||
}
|
||||
|
||||
NSLog(@"%@ Failed to save to %@", kCanardLogTag, filePath);
|
||||
return NO;
|
||||
}
|
||||
|
||||
#pragma mark - DlyArchiveReader Hooks
|
||||
|
||||
%hook DlyArchiveReader
|
||||
|
||||
- (bool)setUpArchiveError:(id *)error {
|
||||
NSLog(@"%@ setUpArchiveError: %p", kCanardLogTag, error);
|
||||
return %orig;
|
||||
}
|
||||
|
||||
- (NSString *)password {
|
||||
NSString *pwd = %orig;
|
||||
CanardArchivePassword = [pwd copy];
|
||||
NSLog(@"%@ password: %@", kCanardLogTag, pwd);
|
||||
return pwd;
|
||||
}
|
||||
|
||||
- (int)getDocumentSize {
|
||||
int size = %orig;
|
||||
NSLog(@"%@ getDocumentSize: %d", kCanardLogTag, size);
|
||||
return size;
|
||||
}
|
||||
|
||||
- (NSData *)readDataAt:(int)offset withSize:(int)size {
|
||||
NSLog(@"%@ readDataAt: offset=%d size=%d", kCanardLogTag, offset, size);
|
||||
NSLog(@"%@ %@", kCanardLogTag, [[NSThread callStackSymbols] componentsJoinedByString:@"\n"]);
|
||||
|
||||
NSData *data = %orig;
|
||||
|
||||
if (data.length > 0 && size != CanardLastSavedReadSize) {
|
||||
CanardLastSavedReadSize = size;
|
||||
CanardSaveData(data, CanardArchivePassword);
|
||||
}
|
||||
|
||||
return data;
|
||||
}
|
||||
|
||||
%end
|
||||
|
||||
#pragma mark - DlyCoreArchive Hooks
|
||||
|
||||
%hook DlyCoreArchive
|
||||
|
||||
- (instancetype)initWithArchivePath:(NSString *)path error:(NSError **)error {
|
||||
NSLog(@"%@ initWithArchivePath: %@ error:%p", kCanardLogTag, path, error);
|
||||
return %orig;
|
||||
}
|
||||
|
||||
+ (instancetype)newWithArchivePath:(NSString *)path error:(NSError **)error {
|
||||
NSLog(@"%@ newWithArchivePath: %@ error:%p", kCanardLogTag, path, error);
|
||||
return %orig;
|
||||
}
|
||||
|
||||
- (bool)openArchiveWithType:(NSUInteger)type error:(id *)error {
|
||||
NSLog(@"%@ openArchiveWithType: %lu error:%p", kCanardLogTag, (unsigned long)type, error);
|
||||
return %orig;
|
||||
}
|
||||
|
||||
%end
|
||||
9
CanardDumper/control
Normal file
9
CanardDumper/control
Normal file
@@ -0,0 +1,9 @@
|
||||
Package: xyz.nohamr.canarddumper
|
||||
Name: CanardDumper
|
||||
Version: 1.0.0
|
||||
Architecture: iphoneos-arm
|
||||
Description: Dumps extracted files from DlyCore DlyArchiveFile::GetFile to Documents/CanardDumps for Le Canard Enchaîné app analysis
|
||||
Maintainer: NohamR
|
||||
Author: NohamR
|
||||
Section: Tweaks
|
||||
Depends: mobilesubstrate (>= 0.9.5000)
|
||||
0
CanardDumper/index.md
Normal file
0
CanardDumper/index.md
Normal file
3
CloudQuit/.gitignore
vendored
Normal file
3
CloudQuit/.gitignore
vendored
Normal file
@@ -0,0 +1,3 @@
|
||||
.theos/
|
||||
packages/
|
||||
.DS_Store
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
Filter = {
|
||||
Bundles = (
|
||||
"tech.baye.servercat",
|
||||
"com.example.cloudquit",
|
||||
);
|
||||
};
|
||||
}
|
||||
13
CloudQuit/Makefile
Normal file
13
CloudQuit/Makefile
Normal file
@@ -0,0 +1,13 @@
|
||||
TARGET = iphone:latest:14.0
|
||||
INSTALL_TARGET_PROCESSES = com.example.cloudquit
|
||||
ARCHS = arm64
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = CloudQuit
|
||||
|
||||
CloudQuit_FILES = Tweak.x
|
||||
CloudQuit_CFLAGS = -fobjc-arc
|
||||
CloudQuit_FRAMEWORKS = Foundation
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
12
CloudQuit/Tweak.x
Normal file
12
CloudQuit/Tweak.x
Normal file
@@ -0,0 +1,12 @@
|
||||
#import <substrate.h>
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
// iOS 16+ Crash Fix
|
||||
%hook CKContainer
|
||||
+ (id)defaultContainer {
|
||||
return nil;
|
||||
}
|
||||
+ (id)containerWithIdentifier:(id) arg1 {
|
||||
return nil;
|
||||
}
|
||||
%end
|
||||
9
CloudQuit/control
Normal file
9
CloudQuit/control
Normal file
@@ -0,0 +1,9 @@
|
||||
Package: xyz.nohamr.cloudquit
|
||||
Name: CloudQuit
|
||||
Version: 1.0.0
|
||||
Architecture: iphoneos-arm
|
||||
Description: Fixes iOS 16+ CloudKit crashes by returning nil from CKContainer methods.
|
||||
Maintainer: NohamR
|
||||
Author: NohamR
|
||||
Section: Tweaks
|
||||
Depends: mobilesubstrate (>= 0.9.5000)
|
||||
3
GPXViewer2/.gitignore
vendored
Normal file
3
GPXViewer2/.gitignore
vendored
Normal file
@@ -0,0 +1,3 @@
|
||||
.theos/
|
||||
packages/
|
||||
.DS_Store
|
||||
7
GPXViewer2/GPXViewer2.plist
Normal file
7
GPXViewer2/GPXViewer2.plist
Normal file
@@ -0,0 +1,7 @@
|
||||
{
|
||||
Filter = {
|
||||
Bundles = (
|
||||
"family.gander.gpxviewer2",
|
||||
);
|
||||
};
|
||||
}
|
||||
13
GPXViewer2/Makefile
Normal file
13
GPXViewer2/Makefile
Normal file
@@ -0,0 +1,13 @@
|
||||
TARGET = iphone:latest:14.0
|
||||
INSTALL_TARGET_PROCESSES = gpxviewer2
|
||||
ARCHS = arm64
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = GPXViewer2
|
||||
|
||||
GPXViewer2_FILES = Tweak.x
|
||||
GPXViewer2_CFLAGS = -fobjc-arc
|
||||
GPXViewer2_FRAMEWORKS = Foundation UIKit
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
53
GPXViewer2/Tweak.x
Normal file
53
GPXViewer2/Tweak.x
Normal file
@@ -0,0 +1,53 @@
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <UIKit/UIKit.h>
|
||||
#import <CommonCrypto/CommonCrypto.h>
|
||||
#import <CloudKit/CloudKit.h>
|
||||
#import <mach-o/dyld.h>
|
||||
#import <string.h>
|
||||
|
||||
%hook CKContainer
|
||||
+ (id)defaultContainer { return nil; }
|
||||
+ (id)containerWithIdentifier:(id)arg1 { return nil; }
|
||||
%end
|
||||
|
||||
%ctor {
|
||||
@autoreleasepool {
|
||||
// Device UUID
|
||||
NSString *deviceUUID = [[[UIDevice currentDevice] identifierForVendor] UUIDString];
|
||||
if (!deviceUUID) deviceUUID = @"<no-device-uuid>";
|
||||
|
||||
// Compute SHA256 hashes for all product keys
|
||||
NSString *salt = @"-gpxviewerbyjg-";
|
||||
NSArray *productKeys = @[
|
||||
// @"family.gander.gpxviewer2.iap.nc.coffee",
|
||||
// @"family.gander.gpxviewer2.iap.nc.hikingsnack",
|
||||
@"family.gander.gpxviewer2.iap.nc.hikingmeal",
|
||||
// @"family.gander.gpxviewer2.easteregg.secret.access",
|
||||
// @"family.gander.gpxviewer2.iap.nc.level1",
|
||||
// @"family.gander.gpxviewer2.iap.nc.level2",
|
||||
// @"family.gander.gpxviewer2.iap.nc.level3",
|
||||
];
|
||||
|
||||
NSMutableArray *hashes = [NSMutableArray array];
|
||||
for (NSString *key in productKeys) {
|
||||
NSString *input = [NSString stringWithFormat:@"%@%@%@", deviceUUID, salt, key];
|
||||
const char *cstr = [input UTF8String];
|
||||
unsigned char digest[CC_SHA256_DIGEST_LENGTH];
|
||||
CC_SHA256(cstr, (CC_LONG)strlen(cstr), digest);
|
||||
NSMutableString *hex = [NSMutableString stringWithCapacity:CC_SHA256_DIGEST_LENGTH * 2];
|
||||
for (NSUInteger i = 0; i < CC_SHA256_DIGEST_LENGTH; i++) {
|
||||
[hex appendFormat:@"%02x", digest[i]];
|
||||
}
|
||||
[hashes addObject:hex];
|
||||
}
|
||||
|
||||
// // empty hashes array
|
||||
// NSMutableArray *hashes = [NSMutableArray array];
|
||||
|
||||
[[NSUserDefaults standardUserDefaults] setObject:hashes
|
||||
forKey:@"proversionmanager.storage.purchasedproducts"];
|
||||
[[NSUserDefaults standardUserDefaults] synchronize];
|
||||
|
||||
NSLog(@"[GPXViewer2] Injected %lu product hashes", (unsigned long)[hashes count]);
|
||||
}
|
||||
}
|
||||
9
GPXViewer2/control
Normal file
9
GPXViewer2/control
Normal file
@@ -0,0 +1,9 @@
|
||||
Package: com.rev.gpxviewer2unlock
|
||||
Name: GPXViewer2 Unlock
|
||||
Version: 1.0
|
||||
Architecture: iphoneos-arm
|
||||
Description: Unlock all IAP products and easter egg in GPXViewer 2
|
||||
Maintainer: rev
|
||||
Author: rev
|
||||
Section: Tweaks
|
||||
Depends: firmware (>= 14.0)
|
||||
3
HatchDragons/.gitignore
vendored
Normal file
3
HatchDragons/.gitignore
vendored
Normal file
@@ -0,0 +1,3 @@
|
||||
.theos/
|
||||
packages/
|
||||
.DS_Store
|
||||
7
HatchDragons/HatchDragons.plist
Normal file
7
HatchDragons/HatchDragons.plist
Normal file
@@ -0,0 +1,7 @@
|
||||
{
|
||||
Filter = {
|
||||
Bundles = (
|
||||
"com.runawayplay.dragons",
|
||||
);
|
||||
};
|
||||
}
|
||||
13
HatchDragons/Makefile
Normal file
13
HatchDragons/Makefile
Normal file
@@ -0,0 +1,13 @@
|
||||
TARGET = iphone:latest:14.0
|
||||
INSTALL_TARGET_PROCESSES = com.runawayplay.dragons
|
||||
ARCHS = arm64 arm64e
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = HatchDragons
|
||||
|
||||
HatchDragons_FILES = Tweak.x
|
||||
HatchDragons_CFLAGS = -fobjc-arc
|
||||
HatchDragons_FRAMEWORKS = Foundation
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
156
HatchDragons/Tweak.x
Normal file
156
HatchDragons/Tweak.x
Normal file
@@ -0,0 +1,156 @@
|
||||
// log stream --predicate 'process == "HatchDragons" AND eventMessage contains "HGH" ' --level default --style compact
|
||||
|
||||
#import <substrate.h>
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <mach-o/dyld.h>
|
||||
|
||||
#define LOG(fmt, ...) NSLog(@"[HGH] " fmt, ##__VA_ARGS__)
|
||||
|
||||
#pragma mark - IL2CPP String Layout
|
||||
|
||||
#define IL2CPP_STRING_LENGTH_OFFSET 0x10
|
||||
#define IL2CPP_STRING_CHARS_OFFSET 0x14
|
||||
#define IL2CPP_DICT_ENTRIES_OFFSET 0x18
|
||||
#define IL2CPP_DICT_COUNT_OFFSET 0x20
|
||||
#define IL2CPP_ARRAY_CAPACITY_OFFSET 0x18
|
||||
#define IL2CPP_ARRAY_DATA_OFFSET 0x20
|
||||
#define IL2CPP_DICT_ENTRY_SIZE 24
|
||||
#define IL2CPP_STRING_MAX_LENGTH (1 << 16)
|
||||
|
||||
#pragma mark - Helpers
|
||||
|
||||
static uintptr_t getImageBase(void) {
|
||||
uint32_t count = _dyld_image_count();
|
||||
for (uint32_t i = 0; i < count; i++) {
|
||||
const char *name = _dyld_get_image_name(i);
|
||||
if (name && strstr(name, "UnityFramework")) {
|
||||
return (uintptr_t)_dyld_get_image_header(i);
|
||||
}
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int requestCount = 0;
|
||||
|
||||
static NSString *timestampString(void) {
|
||||
static NSDateFormatter *fmt;
|
||||
static dispatch_once_t onceToken;
|
||||
dispatch_once(&onceToken, ^{
|
||||
fmt = [[NSDateFormatter alloc] init];
|
||||
fmt.dateFormat = @"HH:mm:ss.SSS";
|
||||
});
|
||||
return [fmt stringFromDate:[NSDate date]];
|
||||
}
|
||||
|
||||
static NSString *il2cppString(void *str) {
|
||||
if (!str) return nil;
|
||||
uint32_t len = *(uint32_t *)((char *)str + IL2CPP_STRING_LENGTH_OFFSET);
|
||||
if (len == 0 || len > IL2CPP_STRING_MAX_LENGTH) return @"(empty?)";
|
||||
NSString *s = [[NSString alloc] initWithBytes:((char *)str + IL2CPP_STRING_CHARS_OFFSET)
|
||||
length:len * 2
|
||||
encoding:NSUTF16LittleEndianStringEncoding];
|
||||
return s ?: @"(unparseable)";
|
||||
}
|
||||
|
||||
static NSString *il2cppHeaders(void *dict) {
|
||||
if (!dict) return @"(nil)";
|
||||
|
||||
void *entriesArr = *(void **)((char *)dict + IL2CPP_DICT_ENTRIES_OFFSET);
|
||||
if (!entriesArr) return @"(empty)";
|
||||
|
||||
uint64_t cap = *(uint64_t *)((char *)entriesArr + IL2CPP_ARRAY_CAPACITY_OFFSET);
|
||||
if (cap == 0) return @"(empty)";
|
||||
|
||||
NSMutableString *out = [NSMutableString string];
|
||||
uint32_t used = 0;
|
||||
char *data = (char *)entriesArr + IL2CPP_ARRAY_DATA_OFFSET;
|
||||
|
||||
for (uint64_t i = 0; i < cap; i++) {
|
||||
char *e = data + i * IL2CPP_DICT_ENTRY_SIZE;
|
||||
int32_t hashCode = *(int32_t *)e;
|
||||
void *key = *(void **)(e + 8);
|
||||
void *value = *(void **)(e + 16);
|
||||
|
||||
if (hashCode < 0 || !key) continue;
|
||||
[out appendFormat:@"\n %@: %@", il2cppString(key),
|
||||
value ? il2cppString(value) : @"(null)"];
|
||||
used++;
|
||||
}
|
||||
|
||||
return used ? out : @"(empty)";
|
||||
}
|
||||
|
||||
static void logRequest(NSString *method, void *self, NSString *body) {
|
||||
requestCount++;
|
||||
NSString *uri = il2cppString(*(void **)((char *)self + 0x10));
|
||||
NSString *platform = il2cppString(*(void **)((char *)self + 0x20));
|
||||
void *hdrs = *(void **)((char *)self + 0x18);
|
||||
|
||||
NSMutableString *msg = [NSMutableString stringWithFormat:
|
||||
@"[%@] ▶ %@ #%d self=%p\n URI: %@\n Headers:%@\n Platform: %@",
|
||||
timestampString(), method, requestCount, self, uri, il2cppHeaders(hdrs), platform];
|
||||
|
||||
if (body) {
|
||||
[msg appendFormat:@"\n Body: %@", body];
|
||||
}
|
||||
|
||||
LOG(@"%@", msg);
|
||||
}
|
||||
|
||||
#pragma mark - CI.HttpClient.RequestHandler Hooks
|
||||
|
||||
static void (*orig_performGet)(void *, void *);
|
||||
static void (*orig_postJson)(void *, void *, void *);
|
||||
|
||||
static void hooked_performGet(void *self, void *handler) {
|
||||
logRequest(@"CI.GET", self, nil);
|
||||
orig_performGet(self, handler);
|
||||
}
|
||||
|
||||
static void hooked_postJson(void *self, void *payload, void *handler) {
|
||||
logRequest(@"CI.POST", self, payload ? il2cppString(payload) : nil);
|
||||
orig_postJson(self, payload, handler);
|
||||
}
|
||||
|
||||
#pragma mark - PlayerInventory Currency Hooks
|
||||
|
||||
static void (*orig_modifyHC)(void *, long, void *, int);
|
||||
static void (*orig_modifySC)(void *, long, void *);
|
||||
|
||||
static void hooked_modifyHC(void *self, long amount, void *info, int quantity) {
|
||||
if (amount < 0) {
|
||||
LOG(@"ModifyHC %ld → %ld (negated)", amount, -amount);
|
||||
amount = -amount;
|
||||
}
|
||||
orig_modifyHC(self, amount, info, quantity);
|
||||
}
|
||||
|
||||
static void hooked_modifySC(void *self, long amount, void *info) {
|
||||
if (amount < 0) {
|
||||
LOG(@"ModifySC %ld → %ld (negated)", amount, -amount);
|
||||
amount = -amount;
|
||||
}
|
||||
orig_modifySC(self, amount, info);
|
||||
}
|
||||
|
||||
#pragma mark - Hook Installation
|
||||
|
||||
#define HOOK(base, rva, hook, orig) \
|
||||
MSHookFunction((void *)((base) + (rva)), (void *)(hook), (void **)&(orig))
|
||||
|
||||
%ctor {
|
||||
uintptr_t base = getImageBase();
|
||||
if (!base) {
|
||||
LOG(@"UnityFramework not found, aborting");
|
||||
return;
|
||||
}
|
||||
|
||||
LOG(@"UnityFramework base = 0x%lx", (unsigned long)base);
|
||||
|
||||
HOOK(base, 0x58FE798, hooked_performGet, orig_performGet);
|
||||
HOOK(base, 0x58FED8C, hooked_postJson, orig_postJson);
|
||||
HOOK(base, 0x57DC6EC, hooked_modifyHC, orig_modifyHC);
|
||||
HOOK(base, 0x57E4978, hooked_modifySC, orig_modifySC);
|
||||
|
||||
LOG(@"All hooks installed");
|
||||
}
|
||||
9
HatchDragons/control
Normal file
9
HatchDragons/control
Normal file
@@ -0,0 +1,9 @@
|
||||
Package: xyz.nohamr.hatchdragons
|
||||
Name: HatchDragons
|
||||
Version: 1.0.0
|
||||
Architecture: iphoneos-arm
|
||||
Description: Logs CI.HttpClient requests (PerformGet/PostJson) from the HatchDragons Unity (il2cpp) game to the console.
|
||||
Maintainer: NohamR
|
||||
Author: NohamR
|
||||
Section: Tweaks
|
||||
Depends: mobilesubstrate (>= 0.9.5000)
|
||||
22
HatchDragons/index.md
Normal file
22
HatchDragons/index.md
Normal file
@@ -0,0 +1,22 @@
|
||||
# HatchDragons
|
||||
|
||||
Logs HTTP requests and negates currency deductions in HatchDragons so spending hard/soft currency instead adds it to the player's balance.
|
||||
|
||||
- **App**: [HatchDragons](https://apps.apple.com/us/app/hatch-dragons/id6746389113)
|
||||
- **Latest version**: 1.2.1
|
||||
- **Tested on**: iOS 18.3
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
|
||||
```
|
||||
|
||||
## Inject
|
||||
|
||||
```sh
|
||||
cyan -i com.runawayplay.dragons_1.2.1.ipa \
|
||||
-o com.runawayplay.dragons_1.2.1_patched.ipa \
|
||||
-f xyz.nohamr.hatchdragons_1.0.0_iphoneos-arm.deb \
|
||||
-u
|
||||
```
|
||||
@@ -79,3 +79,45 @@
|
||||
return nil;
|
||||
}
|
||||
%end
|
||||
|
||||
%hook NSFileManager
|
||||
- (NSURL *)containerURLForSecurityApplicationGroupIdentifier:(NSString *)groupIdentifier {
|
||||
NSString *homeDirectory = NSHomeDirectory();
|
||||
NSString *containerBasePath = [homeDirectory stringByAppendingPathComponent:@"Documents/ApplicationGroupContainers"];
|
||||
NSURL *baseURL = [NSURL fileURLWithPath:containerBasePath isDirectory:YES];
|
||||
NSURL *containerURL = [baseURL URLByAppendingPathComponent:groupIdentifier];
|
||||
|
||||
NSFileManager *fileManager = [NSFileManager defaultManager];
|
||||
NSString *containerPath = [containerURL path];
|
||||
BOOL containerExists = [fileManager fileExistsAtPath:containerPath];
|
||||
|
||||
if (!containerExists) {
|
||||
NSError *error = nil;
|
||||
|
||||
[fileManager createDirectoryAtURL:containerURL
|
||||
withIntermediateDirectories:YES
|
||||
attributes:nil
|
||||
error:&error];
|
||||
|
||||
NSURL *appSupportURL = [containerURL URLByAppendingPathComponent:@"Library/Application Support"];
|
||||
[fileManager createDirectoryAtURL:appSupportURL
|
||||
withIntermediateDirectories:YES
|
||||
attributes:nil
|
||||
error:&error];
|
||||
|
||||
NSURL *cachesURL = [containerURL URLByAppendingPathComponent:@"Library/Caches"];
|
||||
[fileManager createDirectoryAtURL:cachesURL
|
||||
withIntermediateDirectories:YES
|
||||
attributes:nil
|
||||
error:&error];
|
||||
|
||||
NSURL *preferencesURL = [containerURL URLByAppendingPathComponent:@"Library/Preferences"];
|
||||
[fileManager createDirectoryAtURL:preferencesURL
|
||||
withIntermediateDirectories:YES
|
||||
attributes:nil
|
||||
error:&error];
|
||||
}
|
||||
|
||||
return containerURL;
|
||||
}
|
||||
%end
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
Filter = {
|
||||
Bundles = (
|
||||
"com.firecore.infuse",
|
||||
Executables = (
|
||||
infuse,
|
||||
);
|
||||
};
|
||||
}
|
||||
@@ -1,7 +1,6 @@
|
||||
TARGET = appletv:latest:18.3
|
||||
ARCHS = arm64
|
||||
ARCHS = arm64 arm64e
|
||||
INSTALL_TARGET_PROCESSES = infuse
|
||||
THEOS_PACKAGE_SCHEME = rootless
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
@@ -10,8 +9,6 @@ TWEAK_NAME = Infuse
|
||||
Infuse_FILES = Tweak.x
|
||||
Infuse_CFLAGS = -fobjc-arc
|
||||
Infuse_FRAMEWORKS = Foundation UIKit
|
||||
Infuse_LDFLAGS += $(THEOS)/vendor/lib/appletv/CydiaSubstrate.framework/CydiaSubstrate.tbd
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
test-print:
|
||||
@echo "ARCH is $(THEOS_PACKAGE_ARCH)"
|
||||
@echo "CONTROL is $(_THEOS_DEB_PACKAGE_CONTROL_PATH)"
|
||||
|
||||
@@ -56,17 +56,33 @@
|
||||
%end
|
||||
|
||||
// Add credits
|
||||
@interface FCVersionView : UIView
|
||||
@property (nonatomic, strong) UILabel *label;
|
||||
@interface FCTVSettingsController : UITableViewController
|
||||
- (UITableView *)tableView;
|
||||
@end
|
||||
|
||||
%hook FCVersionView
|
||||
- (void)awakeFromNib {
|
||||
%hook FCTVSettingsController
|
||||
- (void)setUpAppVersionLabel {
|
||||
%orig;
|
||||
UILabel *label = (UILabel *)[self valueForKey:@"label"];
|
||||
if ([label.text containsString:@"Infuse Pro"] && ![label.text hasPrefix:@"Infuse Team •"]) {
|
||||
label.text = [NSString stringWithFormat:@"Infuse Team • %@", label.text];
|
||||
}
|
||||
|
||||
UITableView *tv = [self tableView];
|
||||
UILabel *footer = (UILabel *)tv.tableFooterView;
|
||||
|
||||
// Guard: footer is nil/not a UILabel
|
||||
if (![footer isKindOfClass:[UILabel class]]) return;
|
||||
|
||||
NSAttributedString *current = footer.attributedText;
|
||||
if (!current.length) return;
|
||||
|
||||
// Handles repeated calls
|
||||
if ([current.string hasPrefix:@"Infuse Team •"]) return;
|
||||
|
||||
NSDictionary *attrs = [current attributesAtIndex:0 effectiveRange:nil];
|
||||
NSMutableAttributedString *mas = [current mutableCopy];
|
||||
NSAttributedString *prefix = [[NSAttributedString alloc]
|
||||
initWithString:@"Infuse Team • "
|
||||
attributes:attrs];
|
||||
[mas insertAttributedString:prefix atIndex:0];
|
||||
footer.attributedText = mas;
|
||||
}
|
||||
%end
|
||||
|
||||
@@ -79,3 +95,41 @@
|
||||
return nil;
|
||||
}
|
||||
%end
|
||||
|
||||
%hook NSPersistentCloudKitContainerOptions
|
||||
- (id)initWithContainerIdentifier:(id)arg1 {
|
||||
return nil;
|
||||
}
|
||||
%end
|
||||
|
||||
%hook CKRecordID
|
||||
- (id)initWithRecordName:(id)arg1 {
|
||||
return nil;
|
||||
}
|
||||
- (id)initWithRecordName:(id)arg1 zoneID:(id)arg2 {
|
||||
return nil;
|
||||
}
|
||||
%end
|
||||
|
||||
%hook CKSystemSharingUIObserver
|
||||
- (id)initWithContainer:(id)arg1 {
|
||||
return nil;
|
||||
}
|
||||
%end
|
||||
|
||||
%hook NSFileManager
|
||||
- (id)ubiquityIdentityToken {
|
||||
return nil;
|
||||
}
|
||||
- (NSURL *)containerURLForSecurityApplicationGroupIdentifier:(NSString *)groupIdentifier {
|
||||
NSString *docPath = [NSSearchPathForDirectoriesInDomains(NSDocumentDirectory, NSUserDomainMask, YES) firstObject];
|
||||
NSString *path = [docPath stringByAppendingPathComponent:groupIdentifier];
|
||||
NSURL *url = [NSURL fileURLWithPath:path];
|
||||
|
||||
if (![[NSFileManager defaultManager] fileExistsAtPath:[url path]]) {
|
||||
[[NSFileManager defaultManager] createDirectoryAtURL:url withIntermediateDirectories:YES attributes:nil error:nil];
|
||||
}
|
||||
|
||||
return url;
|
||||
}
|
||||
%end
|
||||
@@ -1,6 +1,6 @@
|
||||
Package: io.infuseteam.infuserootless
|
||||
Name: Infuse (Rootless)
|
||||
Version: 2.0
|
||||
Version: 2.3
|
||||
Architecture: appletvos-arm64
|
||||
Description: Unlock the full potential of Infuse
|
||||
Maintainer: Infuse Team
|
||||
|
||||
3
NetworkLogger/.gitignore
vendored
Normal file
3
NetworkLogger/.gitignore
vendored
Normal file
@@ -0,0 +1,3 @@
|
||||
.theos/
|
||||
packages/
|
||||
.DS_Store
|
||||
13
NetworkLogger/Makefile
Normal file
13
NetworkLogger/Makefile
Normal file
@@ -0,0 +1,13 @@
|
||||
TARGET = iphone:latest:14.0
|
||||
INSTALL_TARGET_PROCESSES = *
|
||||
ARCHS = arm64 arm64e
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = NetworkLogger
|
||||
|
||||
NetworkLogger_FILES = Tweak.x
|
||||
NetworkLogger_CFLAGS = -fobjc-arc
|
||||
NetworkLogger_FRAMEWORKS = Foundation
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
2
NetworkLogger/NetworkLogger.plist
Normal file
2
NetworkLogger/NetworkLogger.plist
Normal file
@@ -0,0 +1,2 @@
|
||||
{
|
||||
}
|
||||
156
NetworkLogger/Tweak.x
Normal file
156
NetworkLogger/Tweak.x
Normal file
@@ -0,0 +1,156 @@
|
||||
#import <substrate.h>
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
#define LOG(fmt, ...) NSLog(@"[NetworkLogger] " fmt, ##__VA_ARGS__)
|
||||
#define MAX_BODY_LOG 2048
|
||||
|
||||
#pragma mark - Helpers
|
||||
|
||||
static int requestCount = 0;
|
||||
|
||||
static NSString *timestamp(void) {
|
||||
static NSDateFormatter *fmt;
|
||||
static dispatch_once_t once;
|
||||
dispatch_once(&once, ^{
|
||||
fmt = [NSDateFormatter new];
|
||||
fmt.dateFormat = @"HH:mm:ss.SSS";
|
||||
});
|
||||
return [fmt stringFromDate:[NSDate date]];
|
||||
}
|
||||
|
||||
static NSString *method(NSURLRequest *req) {
|
||||
return req.HTTPMethod.length ? req.HTTPMethod : @"GET";
|
||||
}
|
||||
|
||||
static NSString *url(NSURLRequest *req) {
|
||||
return req.URL.absoluteString;
|
||||
}
|
||||
|
||||
static NSString *formatHeaders(NSDictionary *hdrs) {
|
||||
if (!hdrs.count) return @"(none)";
|
||||
NSMutableString *s = [NSMutableString string];
|
||||
[hdrs enumerateKeysAndObjectsUsingBlock:^(NSString *k, NSString *v, BOOL *_) {
|
||||
[s appendFormat:@"\n %@: %@", k, v];
|
||||
}];
|
||||
return s.copy;
|
||||
}
|
||||
|
||||
static NSString *formatBody(NSData *data) {
|
||||
if (!data.length) return @"(empty)";
|
||||
NSString *str = [[NSString alloc] initWithData:data encoding:NSUTF8StringEncoding];
|
||||
if (str) return str.length > MAX_BODY_LOG ? [str substringToIndex:MAX_BODY_LOG] : str;
|
||||
return [NSString stringWithFormat:@"<binary %lu bytes>", (unsigned long)data.length];
|
||||
}
|
||||
|
||||
static NSString *formatResponse(NSHTTPURLResponse *resp, NSData *body) {
|
||||
NSMutableString *s = [NSMutableString stringWithFormat:@"HTTP %ld", (long)resp.statusCode];
|
||||
[resp.allHeaderFields enumerateKeysAndObjectsUsingBlock:^(NSString *k, NSString *v, BOOL *_) {
|
||||
[s appendFormat:@"\n %@: %@", k, v];
|
||||
}];
|
||||
if (body) [s appendFormat:@"\n Body: %@", formatBody(body)];
|
||||
return s.copy;
|
||||
}
|
||||
|
||||
static void logDataResponse(int num, NSURLRequest *req, NSData *data, NSURLResponse *resp, NSError *err) {
|
||||
if (err) {
|
||||
LOG(@"[%@] ◀ #%d %@ %@\n Error: %@", timestamp(), num, method(req), url(req), err.localizedDescription);
|
||||
} else if ([resp isKindOfClass:[NSHTTPURLResponse class]]) {
|
||||
LOG(@"[%@] ◀ #%d %@ %@\n%@", timestamp(), num, method(req), url(req), formatResponse((NSHTTPURLResponse *)resp, data));
|
||||
} else {
|
||||
LOG(@"[%@] ◀ #%d %@ %@\n (non-HTTP)", timestamp(), num, method(req), url(req));
|
||||
}
|
||||
}
|
||||
|
||||
#define LOG_REQUEST(req, extra) \
|
||||
LOG(@"[%@] ▶ #%d %@ %@\n Headers:%@%@", timestamp(), ++requestCount, method(req), url(req), formatHeaders(req.allHTTPHeaderFields), extra)
|
||||
|
||||
#define WRAP_DATA_HANDLER(orig, self, _cmd, req, handler, ...) \
|
||||
void (^wrapped)(NSData *, NSURLResponse *, NSError *) = ^(NSData *d, NSURLResponse *r, NSError *e) { \
|
||||
logDataResponse(requestCount, req, d, r, e); \
|
||||
if (handler) handler(d, r, e); \
|
||||
}; \
|
||||
return orig(self, _cmd, req, ##__VA_ARGS__, wrapped)
|
||||
|
||||
#pragma mark - NSURLSession Hooks
|
||||
|
||||
static NSURLSessionDataTask *(*orig_dataTaskReq)(NSURLSession *, SEL, NSURLRequest *, void (^)(NSData *, NSURLResponse *, NSError *));
|
||||
|
||||
static NSURLSessionDataTask *hooked_dataTaskReq(NSURLSession *self, SEL _cmd, NSURLRequest *req, void (^handler)(NSData *, NSURLResponse *, NSError *)) {
|
||||
NSString *bodyLog = req.HTTPBody ? [NSString stringWithFormat:@"\n Body: %@", formatBody(req.HTTPBody)] : @"";
|
||||
LOG_REQUEST(req, bodyLog);
|
||||
WRAP_DATA_HANDLER(orig_dataTaskReq, self, _cmd, req, handler);
|
||||
}
|
||||
|
||||
static NSURLSessionDataTask *(*orig_dataTaskURL)(NSURLSession *, SEL, NSURL *, void (^)(NSData *, NSURLResponse *, NSError *));
|
||||
|
||||
static NSURLSessionDataTask *hooked_dataTaskURL(NSURLSession *self, SEL _cmd, NSURL *u, void (^handler)(NSData *, NSURLResponse *, NSError *)) {
|
||||
return hooked_dataTaskReq(self, _cmd, [NSURLRequest requestWithURL:u], handler);
|
||||
}
|
||||
|
||||
static NSURLSessionUploadTask *(*orig_uploadTask)(NSURLSession *, SEL, NSURLRequest *, NSData *, void (^)(NSData *, NSURLResponse *, NSError *));
|
||||
|
||||
static NSURLSessionUploadTask *hooked_uploadTask(NSURLSession *self, SEL _cmd, NSURLRequest *req, NSData *body, void (^handler)(NSData *, NSURLResponse *, NSError *)) {
|
||||
LOG_REQUEST(req, [NSString stringWithFormat:@"\n Body: %@", formatBody(body)]);
|
||||
WRAP_DATA_HANDLER(orig_uploadTask, self, _cmd, req, handler, body);
|
||||
}
|
||||
|
||||
static NSURLSessionDownloadTask *(*orig_downloadTask)(NSURLSession *, SEL, NSURLRequest *, void (^)(NSURL *, NSURLResponse *, NSError *));
|
||||
|
||||
static NSURLSessionDownloadTask *hooked_downloadTask(NSURLSession *self, SEL _cmd, NSURLRequest *req, void (^handler)(NSURL *, NSURLResponse *, NSError *)) {
|
||||
LOG_REQUEST(req, @"");
|
||||
int num = requestCount;
|
||||
void (^wrapped)(NSURL *, NSURLResponse *, NSError *) = ^(NSURL *loc, NSURLResponse *resp, NSError *err) {
|
||||
if (err) {
|
||||
LOG(@"[%@] ◀ #%d %@ %@\n Error: %@", timestamp(), num, method(req), url(req), err.localizedDescription);
|
||||
} else if ([resp isKindOfClass:[NSHTTPURLResponse class]]) {
|
||||
LOG(@"[%@] ◀ #%d %@ %@\n (saved to %@)\n%@", timestamp(), num, method(req), url(req), loc.path, formatResponse((NSHTTPURLResponse *)resp, nil));
|
||||
}
|
||||
if (handler) handler(loc, resp, err);
|
||||
};
|
||||
return orig_downloadTask(self, _cmd, req, wrapped);
|
||||
}
|
||||
|
||||
static void (*orig_resume)(NSURLSessionTask *, SEL);
|
||||
|
||||
static void hooked_resume(NSURLSessionTask *self, SEL _cmd) {
|
||||
LOG(@"[%@] ▶ RESUME %@ %@", timestamp(), method(self.currentRequest), url(self.currentRequest));
|
||||
orig_resume(self, _cmd);
|
||||
}
|
||||
|
||||
#pragma mark - NSURLConnection (Legacy)
|
||||
|
||||
static void (*orig_asyncSend)(NSURLConnection *, SEL, NSURLRequest *, NSOperationQueue *, void (^)(NSURLResponse *, NSData *, NSError *));
|
||||
|
||||
static void hooked_asyncSend(NSURLConnection *self, SEL _cmd, NSURLRequest *req, NSOperationQueue *queue, void (^handler)(NSURLResponse *, NSData *, NSError *)) {
|
||||
LOG_REQUEST(req, @" (legacy)");
|
||||
void (^wrapped)(NSURLResponse *, NSData *, NSError *) = ^(NSURLResponse *r, NSData *d, NSError *e) {
|
||||
logDataResponse(requestCount, req, d, r, e);
|
||||
if (handler) handler(r, d, e);
|
||||
};
|
||||
orig_asyncSend(self, _cmd, req, queue, wrapped);
|
||||
}
|
||||
|
||||
#pragma mark - Constructor
|
||||
|
||||
#define HOOK_MSG(cls, sel, hook, orig) \
|
||||
MSHookMessageEx(cls, @selector(sel), (IMP)hook, (IMP *)&orig)
|
||||
|
||||
%ctor {
|
||||
LOG(@"=== tweak loaded ===");
|
||||
|
||||
Class session = NSClassFromString(@"NSURLSession");
|
||||
if (session) {
|
||||
HOOK_MSG(session, dataTaskWithRequest:completionHandler:, hooked_dataTaskReq, orig_dataTaskReq);
|
||||
HOOK_MSG(session, dataTaskWithURL:completionHandler:, hooked_dataTaskURL, orig_dataTaskURL);
|
||||
HOOK_MSG(session, uploadTaskWithRequest:fromData:completionHandler:, hooked_uploadTask, orig_uploadTask);
|
||||
HOOK_MSG(session, downloadTaskWithRequest:completionHandler:, hooked_downloadTask, orig_downloadTask);
|
||||
}
|
||||
|
||||
Class task = NSClassFromString(@"__NSCFLocalDataTask") ?: NSClassFromString(@"NSURLSessionDataTask");
|
||||
if (task) HOOK_MSG(task, resume, hooked_resume, orig_resume);
|
||||
|
||||
Class conn = NSClassFromString(@"NSURLConnection");
|
||||
if (conn) HOOK_MSG(conn, sendAsynchronousRequest:queue:completionHandler:, hooked_asyncSend, orig_asyncSend);
|
||||
|
||||
LOG(@"=== all hooks installed ===");
|
||||
}
|
||||
9
NetworkLogger/control
Normal file
9
NetworkLogger/control
Normal file
@@ -0,0 +1,9 @@
|
||||
Package: xyz.noham.networklogger
|
||||
Name: NetworkLogger
|
||||
Version: 1.0.0
|
||||
Architecture: iphoneos-arm
|
||||
Description: Logs every network request and response to the console via os_log.
|
||||
Maintainer: NohamR
|
||||
Author: NohamR
|
||||
Section: Tweaks
|
||||
Depends: mobilesubstrate (>= 0.9.5000)
|
||||
44
NetworkLogger/index.md
Normal file
44
NetworkLogger/index.md
Normal file
@@ -0,0 +1,44 @@
|
||||
# NetworkLogger
|
||||
|
||||
Logs every network request and response to the console via `os_log`. Useful for debugging API calls, reverse-engineering endpoints, and understanding how an app communicates with its backend.
|
||||
|
||||
## What it hooks
|
||||
|
||||
- `NSURLSession` task creation (`dataTaskWithRequest:`, `dataTaskWithURL:`, `uploadTaskWithRequest:fromData:`, `downloadTaskWithRequest:`)
|
||||
- `NSURLSessionTask resume`
|
||||
- `NSURLConnection sendAsynchronousRequest:queue:completionHandler:` (legacy)
|
||||
|
||||
## Output format
|
||||
|
||||
```
|
||||
[NetworkLogger] ▶ REQUEST GET https://platform.runawayplay.com/dragons/api/mailbox
|
||||
Headers:
|
||||
Authorization: Bearer <token>
|
||||
X-Client-Platform: ios
|
||||
Body: (none)
|
||||
[NetworkLogger] ◀ RESPONSE GET https://platform.runawayplay.com/dragons/api/mailbox
|
||||
HTTP 200
|
||||
Content-Type: application/json
|
||||
...
|
||||
Body: {"mailItems": [...]}
|
||||
```
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
make clean && make package THEOS_PACKAGE_SCHEME=rootless
|
||||
```
|
||||
|
||||
## Inject
|
||||
|
||||
```sh
|
||||
cyan -i <input.ipa> -o <output_patched.ipa> -f <tweak.deb> -u
|
||||
```
|
||||
|
||||
## Viewing logs
|
||||
|
||||
```sh
|
||||
log stream --predicate 'eventMessage contains "NetworkLogger"' --level debug
|
||||
```
|
||||
|
||||
Or view in Console.app filtering for `NetworkLogger`.
|
||||
@@ -1,7 +1,6 @@
|
||||
TARGET = appletv:latest:18.3
|
||||
ARCHS = arm64
|
||||
INSTALL_TARGET_PROCESSES = Oqee
|
||||
THEOS_PACKAGE_SCHEME = rootless
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
@@ -9,5 +8,6 @@ TWEAK_NAME = OqeePlus
|
||||
|
||||
OqeePlus_FILES = Tweak.x
|
||||
OqeePlus_CFLAGS = -fobjc-arc
|
||||
OqeePlus_LDFLAGS += $(THEOS)/vendor/lib/appletv/CydiaSubstrate.framework/CydiaSubstrate.tbd
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
Package: xyz.nohamr.oqeeplus
|
||||
Name: Oqee+ (tvOS)
|
||||
Version: 1.0
|
||||
Version: 1.1
|
||||
Architecture: appletvos-arm64
|
||||
Description: Oqee+ Ads blocker hook for tvOS
|
||||
Maintainer: NohamR
|
||||
|
||||
@@ -5,9 +5,8 @@ iOS tweaks built with [Theos](https://theos.dev), injected into IPAs via [cyan](
|
||||
## Tweaks
|
||||
|
||||
| Tweak | App | Target |
|
||||
| ------------------------------------------------------- | ---------------- | ---------- |
|
||||
| [ServerCatPremium](ServerCatPremium/index.md) | ServerCat 1.30.0 | iOS 17+ |
|
||||
| [ServerCatPremium (legacy)](ServerCatPremium_/index.md) | ServerCat 1.6.4 | iOS 15 |
|
||||
| -------------------------------------------------- | ------------------------ | ----------- |
|
||||
| [ServerCatPremium](ServerCatPremium/index.md) | ServerCat 1.30.0 / 1.6.4 | iOS 15+ |
|
||||
| [TextasticPro](TextasticPro/index.md) | Textastic 10.9.2 | iOS 18+ |
|
||||
| [BusinessJB](BusinessJB/index.md) | Business 2.3.000 | iOS 15 |
|
||||
| [CreditAgricoleJB](CreditAgricoleJB/index.md) | Ma Banque 47.0.0 | iOS 15.8.6 |
|
||||
@@ -17,6 +16,10 @@ iOS tweaks built with [Theos](https://theos.dev), injected into IPAs via [cyan](
|
||||
| [TF1+ (iOS)](TF1Plus/TF1Plus-iOS/index.md) | TF1+ 11.36.0 | iOS 14+ |
|
||||
| [OqeePlus (tvOS)](OqeePlus/OqeePlus-tvOS/index.md) | Oqee 2.40 | tvOS 18.3 |
|
||||
| [OqeePlus (iOS)](OqeePlus/OqeePlus-iOS/index.md) | Oqee 2.40 | iOS 18+ |
|
||||
| [VolkswagenJB](VolkswagenJB/index.md) | Volkswagen 2.72.0 | iOS 16.7.15 |
|
||||
| [GPXViewer2](GPXViewer2) | GPXViewer 2 | iOS 14+ |
|
||||
| [RMHook](RMHook/index.md) | reMarkable | iOS |
|
||||
| [HatchDragons](HatchDragons/index.md) | HatchDragons 1.2.1 | iOS 18+ |
|
||||
|
||||
## Build
|
||||
|
||||
|
||||
@@ -5,7 +5,16 @@
|
||||
|
||||
#define TARGET_MODULE "ServerCat"
|
||||
#define IDA_BASE 0x100000000
|
||||
#define ADDR_IS_PREMIUM 0x10009CD24 // Address of "isPremiumActive" in IDA (adjust if needed)
|
||||
|
||||
/*
|
||||
* EDIT THE HOOK ADDRESS OFFSET ACCORDING TO THE APP VERSION USED:
|
||||
*
|
||||
* ServerCat 1.30.0 (latest) -> 0x10009CD24
|
||||
* ServerCat 1.6.4 (legacy) -> 0x100454D70
|
||||
*
|
||||
* Find the address of `isPremiumActive` in IDA and set it below.
|
||||
*/
|
||||
#define ADDR_IS_PREMIUM 0x10009CD24
|
||||
|
||||
static int (*orig_isPremiumActive)(void);
|
||||
|
||||
@@ -26,7 +35,7 @@ static int hook_isPremiumActive(void) {
|
||||
}
|
||||
}
|
||||
|
||||
// iOS 16 Crash Fix
|
||||
// iOS 16+ Crash Fix
|
||||
%hook CKContainer
|
||||
+ (id)defaultContainer {
|
||||
return nil;
|
||||
|
||||
@@ -1,9 +1,13 @@
|
||||
# ServerCatPremium
|
||||
|
||||
Unlocks premium features in ServerCat by forcing `isPremiumActive` (`sub_10009CD24`) to always return `1`.
|
||||
Unlocks premium features in ServerCat by forcing `isPremiumActive` to always return `1`.
|
||||
|
||||
- **App**: [ServerCat – SSH Terminal](https://apps.apple.com/us/app/servercat-ssh-terminal/id1501532023)
|
||||
- **Tested on**: ServerCat 1.30.0 (600), iOS 18.3
|
||||
- **Tested on**: ServerCat 1.30.0 (iOS 18.3) and ServerCat 1.6.4 (iOS 15.8.6)
|
||||
|
||||
Hook address offsets (edit in `Tweak.x`):
|
||||
- `0x10009CD24` — ServerCat 1.30.0
|
||||
- `0x100454D70` — ServerCat 1.6.4
|
||||
|
||||
## Build
|
||||
|
||||
@@ -14,10 +18,7 @@ make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
|
||||
## Inject
|
||||
|
||||
```sh
|
||||
cyan -i tech.baye.servercat-1.30.0.ipa \
|
||||
-o tech.baye.servercat-1.30.0_patched.ipa \
|
||||
-f xyz.nohamr_1.0.0-1_iphoneos-arm64.deb \
|
||||
-u
|
||||
cyan -i <input.ipa> -o <output_patched.ipa> -f xyz.nohamr_1.0.0-1_iphoneos-arm64.deb -u
|
||||
```
|
||||
|
||||
## Screenshots
|
||||
|
||||
@@ -1,13 +0,0 @@
|
||||
TARGET = iphone:latest:14.0
|
||||
INSTALL_TARGET_PROCESSES = ServerCat
|
||||
ARCHS = arm64 arm64e
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = ServerCatPremium
|
||||
|
||||
ServerCatPremium_FILES = Tweak.x
|
||||
ServerCatPremium_CFLAGS = -fobjc-arc
|
||||
ServerCatPremium_FRAMEWORKS = Foundation
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
@@ -1,27 +0,0 @@
|
||||
#import <substrate.h>
|
||||
#import <mach-o/dyld.h>
|
||||
#import <string.h>
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
#define TARGET_MODULE "ServerCat"
|
||||
#define IDA_BASE 0x100000000
|
||||
#define ADDR_IS_PREMIUM 0x100454D70 // Address of "isPremiumActive" in IDA (adjust if needed)
|
||||
|
||||
static int (*orig_isPremiumActive)(void);
|
||||
|
||||
static int hook_isPremiumActive(void) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
%ctor {
|
||||
for (uint32_t i = 0; i < _dyld_image_count(); i++) {
|
||||
const char *name = _dyld_get_image_name(i);
|
||||
if (name && strstr(name, TARGET_MODULE)) {
|
||||
uintptr_t base = (uintptr_t)_dyld_get_image_header(i);
|
||||
uintptr_t addr = base + (ADDR_IS_PREMIUM - IDA_BASE);
|
||||
MSHookFunction((void *)addr, (void *)hook_isPremiumActive, (void **)&orig_isPremiumActive);
|
||||
NSLog(@"[ServerCatPremium] Hooked isPremiumActive at 0x%lx", addr);
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,26 +0,0 @@
|
||||
# ServerCatPremium (legacy — iOS 15)
|
||||
|
||||
Unlocks premium features in ServerCat by forcing `isPremiumActive` (`sub_100454D70`) to always return `1`.
|
||||
|
||||
- **App**: [ServerCat – SSH Terminal](https://apps.apple.com/us/app/servercat-ssh-terminal/id1501532023)
|
||||
- **Tested on**: ServerCat 1.6.4, iOS 15.8.6
|
||||
- **Note**: ServerCat 1.6.4 is the last version supporting iOS 15. Latest requires iOS 17+.
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
|
||||
```
|
||||
|
||||
## Inject
|
||||
|
||||
```sh
|
||||
cyan -i tech.baye.servercat-1.6.4.ipa \
|
||||
-o tech.baye.servercat-1.6.4_patched.ipa \
|
||||
-f xyz.nohamr_1.0.0-1_iphoneos-arm64.deb \
|
||||
-u
|
||||
```
|
||||
|
||||
## Screenshots
|
||||

|
||||

|
||||
@@ -1,7 +1,6 @@
|
||||
TARGET = appletv:latest:18.3
|
||||
ARCHS = arm64
|
||||
INSTALL_TARGET_PROCESSES = mytf1
|
||||
THEOS_PACKAGE_SCHEME = rootless
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
@@ -9,5 +8,6 @@ TWEAK_NAME = TF1Plus
|
||||
|
||||
TF1Plus_FILES = Tweak.x
|
||||
TF1Plus_CFLAGS = -fobjc-arc
|
||||
TF1Plus_LDFLAGS += $(THEOS)/vendor/lib/appletv/CydiaSubstrate.framework/CydiaSubstrate.tbd
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
Package: xyz.nohamr.tf1plus
|
||||
Name: TF1+ (Rootless)
|
||||
Version: 1.0
|
||||
Name: TF1+ (Rootful)
|
||||
Version: 1.1
|
||||
Architecture: appletvos-arm64
|
||||
Description: TF1+ Ads blocker hook
|
||||
Maintainer: NohamR
|
||||
|
||||
3
VolkswagenJB/.gitignore
vendored
Normal file
3
VolkswagenJB/.gitignore
vendored
Normal file
@@ -0,0 +1,3 @@
|
||||
.theos/
|
||||
packages/
|
||||
.DS_Store
|
||||
13
VolkswagenJB/Makefile
Normal file
13
VolkswagenJB/Makefile
Normal file
@@ -0,0 +1,13 @@
|
||||
TARGET = iphone:latest:14.0
|
||||
INSTALL_TARGET_PROCESSES = Volkswagen
|
||||
ARCHS = arm64
|
||||
|
||||
include $(THEOS)/makefiles/common.mk
|
||||
|
||||
TWEAK_NAME = VolkswagenJB
|
||||
|
||||
VolkswagenJB_FILES = Tweak.x
|
||||
VolkswagenJB_CFLAGS = -fobjc-arc
|
||||
VolkswagenJB_FRAMEWORKS = Foundation
|
||||
|
||||
include $(THEOS_MAKE_PATH)/tweak.mk
|
||||
98
VolkswagenJB/Tweak.x
Normal file
98
VolkswagenJB/Tweak.x
Normal file
@@ -0,0 +1,98 @@
|
||||
#import <substrate.h>
|
||||
#import <mach-o/dyld.h>
|
||||
#import <string.h>
|
||||
#import <Foundation/Foundation.h>
|
||||
|
||||
#define TARGET_MODULE "Volkswagen"
|
||||
#define IDA_BASE 0x100000000
|
||||
|
||||
// sysctl P_TRACED check : always return 0 (no debugger)
|
||||
#define ADDR_SYSCTL_DEBUG_CHECK 0x10081D5A4
|
||||
|
||||
// ptrace(PT_DENY_ATTACH) + FishHook installer : NOP the whole thing
|
||||
#define ADDR_PTRACE_FISHHOOK 0x10081D704
|
||||
|
||||
// JailbreakDetection orchestrator (8 checks) : always return 1 (clean)
|
||||
#define ADDR_JB_ORCHESTRATOR 0x100824E9C
|
||||
|
||||
// Individual JB sub-checks : each returns 1 (no jailbreak found)
|
||||
#define ADDR_JB_FILE_EXIST 0x100823E38 // type 1: stat/access
|
||||
#define ADDR_JB_FILE_READABLE 0x100824238 // type 2: fopen/isReadable
|
||||
#define ADDR_JB_SANDBOX_ESCAPE 0x1008245FC // type 3: write test + fork
|
||||
#define ADDR_JB_SYMLINK 0x100824A14 // type 5: symlink resolve
|
||||
#define ADDR_JB_DYLIB_NAMES 0x100824C7C // type 6: _dyld_get_image_name scan
|
||||
|
||||
#define ADDR_SECURITY_CHECK_BFC 0x100828BFC // sub_100828BFC(v10) & 1
|
||||
#define ADDR_SECURITY_CHECK_D20 0x100828D20 // sub_100828D20() & 1
|
||||
#define ADDR_SECURITY_CHECK_CD4 0x100828CD4 // sub_100828CD4() : bool
|
||||
|
||||
|
||||
static void *(*orig_sysctl_debug)(void);
|
||||
static void *hooked_sysctl_debug(void) { NSLog(@"[VWTweak] hooked_sysctl_debug called"); return 0; }
|
||||
|
||||
static void (*orig_ptrace_fishhook)(void);
|
||||
static void hooked_ptrace_fishhook(void) { NSLog(@"[VWTweak] hooked_ptrace_fishhook called"); return; }
|
||||
|
||||
static uint64_t (*orig_jb_orchestrator)(void);
|
||||
static uint64_t hooked_jb_orchestrator(void) { NSLog(@"[VWTweak] hooked_jb_orchestrator called"); return 1; }
|
||||
|
||||
// static uint64_t (*orig_jb_file_exist)(void);
|
||||
// static uint64_t hooked_jb_file_exist(void) { NSLog(@"[VWTweak] hooked_jb_file_exist called"); return 1; }
|
||||
|
||||
// static uint64_t (*orig_jb_file_readable)(void);
|
||||
// static uint64_t hooked_jb_file_readable(void) { NSLog(@"[VWTweak] hooked_jb_file_readable called"); return 1; }
|
||||
|
||||
// static uint64_t (*orig_jb_sandbox_escape)(void);
|
||||
// static uint64_t hooked_jb_sandbox_escape(void) { NSLog(@"[VWTweak] hooked_jb_sandbox_escape called"); return 1; }
|
||||
|
||||
// static uint64_t (*orig_jb_symlink)(void);
|
||||
// static uint64_t hooked_jb_symlink(void) { NSLog(@"[VWTweak] hooked_jb_symlink called"); return 1; }
|
||||
|
||||
// static uint64_t (*orig_jb_dylib_names)(void);
|
||||
// static uint64_t hooked_jb_dylib_names(void) { NSLog(@"[VWTweak] hooked_jb_dylib_names called"); return 1; }
|
||||
|
||||
static uint64_t (*orig_security_check_bfc)(uint64_t);
|
||||
static uint64_t hooked_security_check_bfc(uint64_t arg) { NSLog(@"[VWTweak] hooked_security_check_bfc(%llu) called", arg); return 0; }
|
||||
|
||||
static uint64_t (*orig_security_check_d20)(void);
|
||||
static uint64_t hooked_security_check_d20(void) { NSLog(@"[VWTweak] hooked_security_check_d20 called"); return 0; }
|
||||
|
||||
static uint64_t (*orig_security_check_cd4)(void);
|
||||
static uint64_t hooked_security_check_cd4(void) { NSLog(@"[VWTweak] hooked_security_check_cd4 called"); return 0; }
|
||||
|
||||
|
||||
static void hookAt(uintptr_t base, uintptr_t ida_addr, void *hook, void **orig) {
|
||||
uintptr_t real = base + (ida_addr - IDA_BASE);
|
||||
MSHookFunction((void *)real, hook, orig);
|
||||
NSLog(@"[VWTweak] Hooked 0x%lx (slide base 0x%lx)", real, base);
|
||||
}
|
||||
|
||||
%ctor {
|
||||
for (uint32_t i = 0; i < _dyld_image_count(); i++) {
|
||||
const char *name = _dyld_get_image_name(i);
|
||||
if (!name || !strstr(name, TARGET_MODULE))
|
||||
continue;
|
||||
|
||||
uintptr_t base = (uintptr_t)_dyld_get_image_header(i);
|
||||
NSLog(@"[VWTweak] Found %s at base 0x%lx", name, base);
|
||||
|
||||
hookAt(base, ADDR_SYSCTL_DEBUG_CHECK, (void *)hooked_sysctl_debug, (void **)&orig_sysctl_debug);
|
||||
hookAt(base, ADDR_PTRACE_FISHHOOK, (void *)hooked_ptrace_fishhook, (void **)&orig_ptrace_fishhook);
|
||||
|
||||
hookAt(base, ADDR_JB_ORCHESTRATOR, (void *)hooked_jb_orchestrator, (void **)&orig_jb_orchestrator);
|
||||
|
||||
// hookAt(base, ADDR_JB_FILE_EXIST, (void *)hooked_jb_file_exist, (void **)&orig_jb_file_exist);
|
||||
// hookAt(base, ADDR_JB_FILE_READABLE, (void *)hooked_jb_file_readable, (void **)&orig_jb_file_readable);
|
||||
// hookAt(base, ADDR_JB_SANDBOX_ESCAPE, (void *)hooked_jb_sandbox_escape,(void **)&orig_jb_sandbox_escape);
|
||||
// hookAt(base, ADDR_JB_SYMLINK, (void *)hooked_jb_symlink, (void **)&orig_jb_symlink);
|
||||
// hookAt(base, ADDR_JB_DYLIB_NAMES, (void *)hooked_jb_dylib_names, (void **)&orig_jb_dylib_names);
|
||||
|
||||
hookAt(base, ADDR_SECURITY_CHECK_BFC, (void *)hooked_security_check_bfc,(void **)&orig_security_check_bfc);
|
||||
hookAt(base, ADDR_SECURITY_CHECK_D20, (void *)hooked_security_check_d20,(void **)&orig_security_check_d20);
|
||||
hookAt(base, ADDR_SECURITY_CHECK_CD4, (void *)hooked_security_check_cd4,(void **)&orig_security_check_cd4);
|
||||
|
||||
return;
|
||||
}
|
||||
|
||||
NSLog(@"[VWTweak] Target module '%s' not found in dyld image list", TARGET_MODULE);
|
||||
}
|
||||
7
VolkswagenJB/VolkswagenJB.plist
Normal file
7
VolkswagenJB/VolkswagenJB.plist
Normal file
@@ -0,0 +1,7 @@
|
||||
{
|
||||
Filter = {
|
||||
Bundles = (
|
||||
"com.volkswagen.WeConnect.production",
|
||||
);
|
||||
};
|
||||
}
|
||||
@@ -1,8 +1,8 @@
|
||||
Package: xyz.nohamr.servercatpremiumlegacy
|
||||
Name: ServerCatPremium (Legacy)
|
||||
Package: xyz.nohamr.volkswagenjb
|
||||
Name: VolkswagenJB (Rootless)
|
||||
Version: 1.0.0
|
||||
Architecture: iphoneos-arm
|
||||
Description: Unlocks premium features in ServerCat app.
|
||||
Description: Bypass jailbreak detection in Volkswagen app
|
||||
Maintainer: NohamR
|
||||
Author: NohamR
|
||||
Section: Tweaks
|
||||
26
VolkswagenJB/index.md
Normal file
26
VolkswagenJB/index.md
Normal file
@@ -0,0 +1,26 @@
|
||||
# VolkswagenJB
|
||||
|
||||
Disables jailbreak detection in Volkswagen.
|
||||
|
||||
- **App**: [Volkswagen](https://apps.apple.com/fr/app/volkswagen/id1517566572)
|
||||
- **Latest version**: 2.72.0
|
||||
- **Tested on**: iOS 16.7.15
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
|
||||
```
|
||||
|
||||
## Inject
|
||||
|
||||
```sh
|
||||
cyan -i com.volkswagen.WeConnect.production_2.72.0.ipa \
|
||||
-o com.volkswagen.WeConnect.production_2.72.0_patched.ipa \
|
||||
-f xyz.nohamr.volkswagenjb_1.0.0-1_iphoneos-arm64.deb \
|
||||
-u
|
||||
```
|
||||
|
||||
## Screenshots
|
||||
|
||||

|
||||
6
scripts/patch-tvos.sh
Executable file
6
scripts/patch-tvos.sh
Executable file
@@ -0,0 +1,6 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
||||
"$SCRIPT_DIR/patch.sh" --tv "$@"
|
||||
74
scripts/patch.sh
Executable file
74
scripts/patch.sh
Executable file
@@ -0,0 +1,74 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
usage() {
|
||||
echo "Usage: $0 [--tv] [-o <output.ipa> | --output <output.ipa>] <file.ipa> <file.deb>"
|
||||
exit 1
|
||||
}
|
||||
|
||||
TV=0
|
||||
IPA=""
|
||||
DEB=""
|
||||
OUTPUT_IPA=""
|
||||
OUTPUT_SPECIFIED=0
|
||||
|
||||
while [ "$#" -gt 0 ]; do
|
||||
case "$1" in
|
||||
-o|--output)
|
||||
if [ -z "$2" ]; then
|
||||
echo "Error: $1 requires an argument."
|
||||
exit 1
|
||||
fi
|
||||
OUTPUT_IPA="$2"
|
||||
OUTPUT_SPECIFIED=1
|
||||
shift 2
|
||||
;;
|
||||
-o=*|--output=*)
|
||||
OUTPUT_IPA="${1#*=}"
|
||||
OUTPUT_SPECIFIED=1
|
||||
shift
|
||||
;;
|
||||
--tv)
|
||||
TV=1
|
||||
shift
|
||||
;;
|
||||
*.ipa)
|
||||
IPA="$1"
|
||||
shift
|
||||
;;
|
||||
*.deb)
|
||||
DEB="$1"
|
||||
shift
|
||||
;;
|
||||
*)
|
||||
echo "Unknown argument: $1"
|
||||
usage
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [ -z "$IPA" ] || [ -z "$DEB" ]; then
|
||||
echo "You must provide one .ipa and one .deb file."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ -z "$OUTPUT_IPA" ]; then
|
||||
OUTPUT_IPA="/tmp/ipa_patched/$(basename "$IPA")"
|
||||
mkdir -p "$(dirname "$OUTPUT_IPA")"
|
||||
fi
|
||||
|
||||
CYAN_ARGS=(-i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite -c 9)
|
||||
if [ "$TV" -eq 1 ]; then
|
||||
CYAN_ARGS+=(--tv)
|
||||
fi
|
||||
|
||||
echo "[+] Patching IPA with cyan..."
|
||||
cyan "${CYAN_ARGS[@]}"
|
||||
echo "[+] Patch complete."
|
||||
|
||||
if [ "$OUTPUT_SPECIFIED" -eq 0 ]; then
|
||||
PATCHED_IPA="$(dirname "$IPA")/$(basename "$IPA" .ipa)_patched.ipa"
|
||||
cp "$OUTPUT_IPA" "$PATCHED_IPA"
|
||||
echo "[+] Patched IPA saved as: $PATCHED_IPA"
|
||||
fi
|
||||
@@ -38,7 +38,8 @@ IPA_NAME=$(basename "$IPA")
|
||||
OUTPUT_IPA="$OUT_DIR/$IPA_NAME"
|
||||
|
||||
echo "[+] Patching IPA with cyan..."
|
||||
cyan -i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite
|
||||
# cyan -i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite -c 0
|
||||
cyan -i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite -c 9
|
||||
echo "[+] Patch complete."
|
||||
|
||||
LOCAL_IP=$(ipconfig getifaddr en0 2>/dev/null)
|
||||
|
||||
Reference in New Issue
Block a user