24 Commits

Author SHA1 Message Date
√(noham)²
79f9e5cf0c Add NetworkLogger utility 2026-08-20 16:28:02 +02:00
√(noham)²
4d51a6eccf Add HatchDragons tweak documentation 2026-08-20 16:23:19 +02:00
√(noham)²
58dd5db8fd Clean implementation 2026-08-20 16:16:55 +02:00
√(noham)²
4e040791c1 HatchDragons PoC 2026-08-20 16:08:03 +02:00
√(noham)²
965bfcdeff cloudquit 2026-08-20 16:07:05 +02:00
√(noham)²
ec1b0a17f0 Unify patch scripts and add output options 2026-08-01 14:15:04 +02:00
√(noham)²
81ab62324c Merge legacy and latest 2026-06-30 17:31:36 +02:00
√(noham)²
238f92ce01 Add GPXViewer2 2026-06-30 17:28:21 +02:00
√(noham)²
214ab9d08a Add VW anti-anti-JB 2026-06-24 17:35:37 +02:00
√(noham)²
db4f414902 update 2026-06-24 16:41:57 +02:00
√(noham)²
29578e8aff Cache Homebrew and Theos dependencies 2026-05-28 13:33:50 +02:00
√(noham)²
43431e4916 Switch for rootful tvOS builds 2026-05-28 13:27:28 +02:00
√(noham)²
dee3024d26 Infuse-tvOS: add executable, support arm64e, bump version 2026-05-28 11:51:35 +02:00
√(noham)²
e41d8f7279 Prepend 'Infuse Team' to footer and bump version 2026-05-28 00:13:58 +02:00
√(noham)²
4475f596d5 Add OqeePlus 2026-05-24 15:11:41 +02:00
√(noham)²
75f7add11f Add IPA patch/watch scripts and RMHook doc 2026-05-15 22:22:40 +02:00
√(noham)²
0fa7d613d8 Block subscription set and update executables 2026-05-11 00:55:20 +02:00
√(noham)²
432eafeb77 Select tvOS Theos repo and remove YouTubeHeader 2026-05-03 17:31:36 +02:00
√(noham)²
5a068bf71a Add iOS .gitignore and TF1Plus.plist 2026-05-03 16:11:20 +02:00
√(noham)²
9c7f571e8f Support tweak subpaths and tvOS builds 2026-05-03 16:08:25 +02:00
√(noham)²
6c5c90f060 Add TF1+ iOS tweak and build files 2026-05-03 16:08:08 +02:00
√(noham)²
d1af7d7a12 Add Build Tweak GitHub Actions workflow
Add a new GitHub Actions workflow (.github/workflows/build.yml) to build iOS tweaks.
2026-05-03 16:03:09 +02:00
√(noham)²
f69c20fb2c Add TF1+ tvOS tweak and docs 2026-04-10 21:06:13 +02:00
√(noham)²
2e08be66c0 Add Infuse rootless tweaks for iOS/tvOS 2026-04-09 21:45:44 +02:00
83 changed files with 2092 additions and 125 deletions

122
.github/workflows/build.yml vendored Normal file
View File

@@ -0,0 +1,122 @@
name: Build Tweak
on:
workflow_dispatch:
inputs:
tweak:
description: 'Tweak folder to build (e.g., BusinessJB, CreditAgricoleJB, Infuse-iOS, TF1Plus/TF1Plus-tvOS)'
required: false
default: 'BusinessJB'
branch:
description: 'Branch to build from'
required: false
default: 'main'
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}-${{ inputs.tweak || 'BusinessJB' }}
cancel-in-progress: true
jobs:
build:
name: Build ${{ inputs.tweak || 'BusinessJB' }}
runs-on: macos-latest
permissions:
contents: write
steps:
- name: Checkout repository
uses: actions/checkout@v6
with:
ref: ${{ inputs.branch || github.ref }}
- name: Cache Homebrew packages
uses: actions/cache@v4
with:
path: ~/Library/Caches/Homebrew
key: brew-${{ runner.os }}-make-ldid
restore-keys: |
brew-${{ runner.os }}-
- name: Install dependencies
run: brew install make ldid
- name: Set PATH environment variables
run: |
echo "$(brew --prefix make)/libexec/gnubin" >> $GITHUB_PATH
echo "THEOS=${{ github.workspace }}/theos" >> $GITHUB_ENV
- name: Get Theos and dependencies commit
run: |
get_commit_hash() {
local repo_url=$1
git ls-remote "$repo_url" HEAD | awk '{print substr($1,1,7)}'
}
TWEAK_PATH="${{ inputs.tweak || 'BusinessJB' }}"
if [[ "$TWEAK_PATH" == *"tvOS"* || "$TWEAK_PATH" == *"TVOS"* ]]; then
THEOS_URL="https://github.com/NohamR/theos-tvOS"
else
THEOS_URL="https://github.com/roothide/theos"
fi
echo "THEOS_REPO=$THEOS_URL" >> $GITHUB_ENV
echo "THEOS_COMMIT=$(get_commit_hash "$THEOS_URL")" >> $GITHUB_ENV
echo "PSHEADER_COMMIT=$(get_commit_hash "https://github.com/PoomSmart/PSHeader.git")" >> $GITHUB_ENV
echo "SDK_COMMIT=$(get_commit_hash "https://github.com/Tonwalter888/iOS-SDKs.git")" >> $GITHUB_ENV
- name: Cache Theos
id: cache-theos
uses: actions/cache@v4
with:
path: theos
key: Theos-${{ env.THEOS_COMMIT }}-SDK-${{ env.SDK_COMMIT }}-PSHeader-${{ env.PSHEADER_COMMIT }}
restore-keys: |
Theos-${{ env.THEOS_COMMIT }}-SDK-${{ env.SDK_COMMIT }}-
Theos-${{ env.THEOS_COMMIT }}-
- name: Setup Theos
if: ${{ steps.cache-theos.outputs.cache-hit != 'true' }}
run: |
git clone --quiet --depth=1 --recurse-submodules ${{ env.THEOS_REPO }}.git theos
git clone --quiet --depth=1 -n --filter=tree:0 https://github.com/Tonwalter888/iOS-SDKs.git
cd iOS-SDKs
git sparse-checkout set --no-cone iPhoneOS18.6.sdk
git checkout --quiet
mv *.sdk "$THEOS/sdks"
cd ${{ github.workspace }}
git clone --quiet --depth=1 https://github.com/PoomSmart/PSHeader.git "$THEOS/include/PSHeader"
- name: Build Tweak
run: |
TWEAK_PATH="${{ inputs.tweak || 'BusinessJB' }}"
TWEAK_NAME=$(basename "$TWEAK_PATH")
cd "$TWEAK_PATH"
echo "TWEAK_VERSION=$(grep '^Version:' control | cut -d ' ' -f2)" >> $GITHUB_ENV
echo "TWEAK_NAME=$TWEAK_NAME" >> $GITHUB_ENV
# Check if this is a tvOS tweak
if grep -q "TARGET.*appletv" Makefile; then
# tvOS tweaks don't use rootless/roothide schemes
make clean package DEBUG=0 FINALPACKAGE=1
else
# iOS tweaks build with multiple schemes
make clean package DEBUG=0 FINALPACKAGE=1
make clean package DEBUG=0 FINALPACKAGE=1 THEOS_PACKAGE_SCHEME=rootless
make clean package DEBUG=0 FINALPACKAGE=1 THEOS_PACKAGE_SCHEME=roothide
fi
mv packages/*.deb ${{ github.workspace }}
- name: Upload the tweak .deb(s)
uses: actions/upload-artifact@v7
with:
name: ${{ env.TWEAK_NAME }} v${{ env.TWEAK_VERSION }}
path: ${{ github.workspace }}/*.deb
if-no-files-found: error
overwrite: true
- name: Create a draft release
uses: softprops/action-gh-release@v3
with:
tag_name: ${{ env.TWEAK_NAME }}-v${{ env.TWEAK_VERSION }}
name: ${{ env.TWEAK_NAME }} v${{ env.TWEAK_VERSION }}
files: ${{ github.workspace }}/*.deb
draft: true

8
.gitignore vendored
View File

@@ -1,5 +1,7 @@
.DS_Store
/CreditAgricoleTweak
/RMHook
/rootless
Build.md
/RedditPatch
/PineHeartsUnlock
/App
/GoodnotesPro
/StravaPremium

View File

@@ -1,7 +1,7 @@
{
Filter = {
Bundles = (
"tech.baye.servercat",
"com.example.cloudquit",
);
};
}

13
CloudQuit/Makefile Normal file
View File

@@ -0,0 +1,13 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = com.example.cloudquit
ARCHS = arm64
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = CloudQuit
CloudQuit_FILES = Tweak.x
CloudQuit_CFLAGS = -fobjc-arc
CloudQuit_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

12
CloudQuit/Tweak.x Normal file
View File

@@ -0,0 +1,12 @@
#import <substrate.h>
#import <Foundation/Foundation.h>
// iOS 16+ Crash Fix
%hook CKContainer
+ (id)defaultContainer {
return nil;
}
+ (id)containerWithIdentifier:(id) arg1 {
return nil;
}
%end

9
CloudQuit/control Normal file
View File

@@ -0,0 +1,9 @@
Package: xyz.nohamr.cloudquit
Name: CloudQuit
Version: 1.0.0
Architecture: iphoneos-arm
Description: Fixes iOS 16+ CloudKit crashes by returning nil from CKContainer methods.
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

View File

@@ -0,0 +1,7 @@
{
Filter = {
Bundles = (
"family.gander.gpxviewer2",
);
};
}

13
GPXViewer2/Makefile Normal file
View File

@@ -0,0 +1,13 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = gpxviewer2
ARCHS = arm64
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = GPXViewer2
GPXViewer2_FILES = Tweak.x
GPXViewer2_CFLAGS = -fobjc-arc
GPXViewer2_FRAMEWORKS = Foundation UIKit
include $(THEOS_MAKE_PATH)/tweak.mk

53
GPXViewer2/Tweak.x Normal file
View File

@@ -0,0 +1,53 @@
#import <Foundation/Foundation.h>
#import <UIKit/UIKit.h>
#import <CommonCrypto/CommonCrypto.h>
#import <CloudKit/CloudKit.h>
#import <mach-o/dyld.h>
#import <string.h>
%hook CKContainer
+ (id)defaultContainer { return nil; }
+ (id)containerWithIdentifier:(id)arg1 { return nil; }
%end
%ctor {
@autoreleasepool {
// Device UUID
NSString *deviceUUID = [[[UIDevice currentDevice] identifierForVendor] UUIDString];
if (!deviceUUID) deviceUUID = @"<no-device-uuid>";
// Compute SHA256 hashes for all product keys
NSString *salt = @"-gpxviewerbyjg-";
NSArray *productKeys = @[
// @"family.gander.gpxviewer2.iap.nc.coffee",
// @"family.gander.gpxviewer2.iap.nc.hikingsnack",
@"family.gander.gpxviewer2.iap.nc.hikingmeal",
// @"family.gander.gpxviewer2.easteregg.secret.access",
// @"family.gander.gpxviewer2.iap.nc.level1",
// @"family.gander.gpxviewer2.iap.nc.level2",
// @"family.gander.gpxviewer2.iap.nc.level3",
];
NSMutableArray *hashes = [NSMutableArray array];
for (NSString *key in productKeys) {
NSString *input = [NSString stringWithFormat:@"%@%@%@", deviceUUID, salt, key];
const char *cstr = [input UTF8String];
unsigned char digest[CC_SHA256_DIGEST_LENGTH];
CC_SHA256(cstr, (CC_LONG)strlen(cstr), digest);
NSMutableString *hex = [NSMutableString stringWithCapacity:CC_SHA256_DIGEST_LENGTH * 2];
for (NSUInteger i = 0; i < CC_SHA256_DIGEST_LENGTH; i++) {
[hex appendFormat:@"%02x", digest[i]];
}
[hashes addObject:hex];
}
// // empty hashes array
// NSMutableArray *hashes = [NSMutableArray array];
[[NSUserDefaults standardUserDefaults] setObject:hashes
forKey:@"proversionmanager.storage.purchasedproducts"];
[[NSUserDefaults standardUserDefaults] synchronize];
NSLog(@"[GPXViewer2] Injected %lu product hashes", (unsigned long)[hashes count]);
}
}

9
GPXViewer2/control Normal file
View File

@@ -0,0 +1,9 @@
Package: com.rev.gpxviewer2unlock
Name: GPXViewer2 Unlock
Version: 1.0
Architecture: iphoneos-arm
Description: Unlock all IAP products and easter egg in GPXViewer 2
Maintainer: rev
Author: rev
Section: Tweaks
Depends: firmware (>= 14.0)

3
HatchDragons/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -0,0 +1,7 @@
{
Filter = {
Bundles = (
"com.runawayplay.dragons",
);
};
}

13
HatchDragons/Makefile Normal file
View File

@@ -0,0 +1,13 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = com.runawayplay.dragons
ARCHS = arm64 arm64e
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = HatchDragons
HatchDragons_FILES = Tweak.x
HatchDragons_CFLAGS = -fobjc-arc
HatchDragons_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

156
HatchDragons/Tweak.x Normal file
View File

@@ -0,0 +1,156 @@
// log stream --predicate 'process == "HatchDragons" AND eventMessage contains "HGH" ' --level default --style compact
#import <substrate.h>
#import <Foundation/Foundation.h>
#import <mach-o/dyld.h>
#define LOG(fmt, ...) NSLog(@"[HGH] " fmt, ##__VA_ARGS__)
#pragma mark - IL2CPP String Layout
#define IL2CPP_STRING_LENGTH_OFFSET 0x10
#define IL2CPP_STRING_CHARS_OFFSET 0x14
#define IL2CPP_DICT_ENTRIES_OFFSET 0x18
#define IL2CPP_DICT_COUNT_OFFSET 0x20
#define IL2CPP_ARRAY_CAPACITY_OFFSET 0x18
#define IL2CPP_ARRAY_DATA_OFFSET 0x20
#define IL2CPP_DICT_ENTRY_SIZE 24
#define IL2CPP_STRING_MAX_LENGTH (1 << 16)
#pragma mark - Helpers
static uintptr_t getImageBase(void) {
uint32_t count = _dyld_image_count();
for (uint32_t i = 0; i < count; i++) {
const char *name = _dyld_get_image_name(i);
if (name && strstr(name, "UnityFramework")) {
return (uintptr_t)_dyld_get_image_header(i);
}
}
return 0;
}
static int requestCount = 0;
static NSString *timestampString(void) {
static NSDateFormatter *fmt;
static dispatch_once_t onceToken;
dispatch_once(&onceToken, ^{
fmt = [[NSDateFormatter alloc] init];
fmt.dateFormat = @"HH:mm:ss.SSS";
});
return [fmt stringFromDate:[NSDate date]];
}
static NSString *il2cppString(void *str) {
if (!str) return nil;
uint32_t len = *(uint32_t *)((char *)str + IL2CPP_STRING_LENGTH_OFFSET);
if (len == 0 || len > IL2CPP_STRING_MAX_LENGTH) return @"(empty?)";
NSString *s = [[NSString alloc] initWithBytes:((char *)str + IL2CPP_STRING_CHARS_OFFSET)
length:len * 2
encoding:NSUTF16LittleEndianStringEncoding];
return s ?: @"(unparseable)";
}
static NSString *il2cppHeaders(void *dict) {
if (!dict) return @"(nil)";
void *entriesArr = *(void **)((char *)dict + IL2CPP_DICT_ENTRIES_OFFSET);
if (!entriesArr) return @"(empty)";
uint64_t cap = *(uint64_t *)((char *)entriesArr + IL2CPP_ARRAY_CAPACITY_OFFSET);
if (cap == 0) return @"(empty)";
NSMutableString *out = [NSMutableString string];
uint32_t used = 0;
char *data = (char *)entriesArr + IL2CPP_ARRAY_DATA_OFFSET;
for (uint64_t i = 0; i < cap; i++) {
char *e = data + i * IL2CPP_DICT_ENTRY_SIZE;
int32_t hashCode = *(int32_t *)e;
void *key = *(void **)(e + 8);
void *value = *(void **)(e + 16);
if (hashCode < 0 || !key) continue;
[out appendFormat:@"\n %@: %@", il2cppString(key),
value ? il2cppString(value) : @"(null)"];
used++;
}
return used ? out : @"(empty)";
}
static void logRequest(NSString *method, void *self, NSString *body) {
requestCount++;
NSString *uri = il2cppString(*(void **)((char *)self + 0x10));
NSString *platform = il2cppString(*(void **)((char *)self + 0x20));
void *hdrs = *(void **)((char *)self + 0x18);
NSMutableString *msg = [NSMutableString stringWithFormat:
@"[%@] ▶ %@ #%d self=%p\n URI: %@\n Headers:%@\n Platform: %@",
timestampString(), method, requestCount, self, uri, il2cppHeaders(hdrs), platform];
if (body) {
[msg appendFormat:@"\n Body: %@", body];
}
LOG(@"%@", msg);
}
#pragma mark - CI.HttpClient.RequestHandler Hooks
static void (*orig_performGet)(void *, void *);
static void (*orig_postJson)(void *, void *, void *);
static void hooked_performGet(void *self, void *handler) {
logRequest(@"CI.GET", self, nil);
orig_performGet(self, handler);
}
static void hooked_postJson(void *self, void *payload, void *handler) {
logRequest(@"CI.POST", self, payload ? il2cppString(payload) : nil);
orig_postJson(self, payload, handler);
}
#pragma mark - PlayerInventory Currency Hooks
static void (*orig_modifyHC)(void *, long, void *, int);
static void (*orig_modifySC)(void *, long, void *);
static void hooked_modifyHC(void *self, long amount, void *info, int quantity) {
if (amount < 0) {
LOG(@"ModifyHC %ld → %ld (negated)", amount, -amount);
amount = -amount;
}
orig_modifyHC(self, amount, info, quantity);
}
static void hooked_modifySC(void *self, long amount, void *info) {
if (amount < 0) {
LOG(@"ModifySC %ld → %ld (negated)", amount, -amount);
amount = -amount;
}
orig_modifySC(self, amount, info);
}
#pragma mark - Hook Installation
#define HOOK(base, rva, hook, orig) \
MSHookFunction((void *)((base) + (rva)), (void *)(hook), (void **)&(orig))
%ctor {
uintptr_t base = getImageBase();
if (!base) {
LOG(@"UnityFramework not found, aborting");
return;
}
LOG(@"UnityFramework base = 0x%lx", (unsigned long)base);
HOOK(base, 0x58FE798, hooked_performGet, orig_performGet);
HOOK(base, 0x58FED8C, hooked_postJson, orig_postJson);
HOOK(base, 0x57DC6EC, hooked_modifyHC, orig_modifyHC);
HOOK(base, 0x57E4978, hooked_modifySC, orig_modifySC);
LOG(@"All hooks installed");
}

9
HatchDragons/control Normal file
View File

@@ -0,0 +1,9 @@
Package: xyz.nohamr.hatchdragons
Name: HatchDragons
Version: 1.0.0
Architecture: iphoneos-arm
Description: Logs CI.HttpClient requests (PerformGet/PostJson) from the HatchDragons Unity (il2cpp) game to the console.
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

22
HatchDragons/index.md Normal file
View File

@@ -0,0 +1,22 @@
# HatchDragons
Logs HTTP requests and negates currency deductions in HatchDragons so spending hard/soft currency instead adds it to the player's balance.
- **App**: [HatchDragons](https://apps.apple.com/us/app/hatch-dragons/id6746389113)
- **Latest version**: 1.2.1
- **Tested on**: iOS 18.3
## Build
```sh
make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
```
## Inject
```sh
cyan -i com.runawayplay.dragons_1.2.1.ipa \
-o com.runawayplay.dragons_1.2.1_patched.ipa \
-f xyz.nohamr.hatchdragons_1.0.0_iphoneos-arm.deb \
-u
```

3
Infuse/Infuse-iOS/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -1,7 +1,7 @@
{
Filter = {
Bundles = (
"dk.simonbs.Jayson",
"com.firecore.infuse",
);
};
}

View File

@@ -0,0 +1,13 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = infuse
ARCHS = arm64 arm64e
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = Infuse
Infuse_FILES = Tweak.x
Infuse_CFLAGS = -fobjc-arc
Infuse_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

123
Infuse/Infuse-iOS/Tweak.x Normal file
View File

@@ -0,0 +1,123 @@
// changes : FCInAppPurchaseServiceFreemium block deleted, FCTraktIAPManager block deleted, layoutSubviews -> awakeFromNib on FCVersionView, and the dead return %orig lines after return statements cleaned up (they were unreachable in the old version too)
#import <substrate.h>
#import <Foundation/Foundation.h>
#import <UIKit/UIKit.h>
%hook FCIAPGUIHelper
+(bool) isProAvailable {
return TRUE;
}
+(bool) isSubscriptionBought {
return TRUE;
}
%end
%hook FCInAppPurchaseServiceBase
- (bool)isFeaturePurchased:(long long)arg1 tillDate:(id*)arg2 {
return 1;
}
- (bool)isFeaturePurchased:(long long)arg1 {
return 1;
}
%end
%hook FCInAppPurchaseServiceDummy
- (bool)isFeaturePurchased:(long long)arg1 tillDate:(id*)arg2 {
return 1;
}
%end
// REMOVED: FCInAppPurchaseServiceFreemium (class gone from binary, replaced by SK2)
// SK2 IAP backend
%hook _TtC6infuse31InAppPurchaseServiceFreemiumSK2
- (bool)isFeaturePurchased:(long long)arg1 tillDate:(id*)arg2 {
return 1;
}
- (long long)iapVersionStatus {
// FCUpgradeToProViewController.featureHasBought checks iapVersionStatus > 0
return 1;
}
%end
%hook FCProductCollectionCell
-(bool) featurePurchased {
return TRUE;
}
%end
// REMOVED: FCTraktIAPManager (class gone from binary)
%hook FCUpgradeToProViewController
-(bool) featureHasBought {
return TRUE;
}
%end
// Add credits
@interface FCVersionView : UIView
@property (nonatomic, strong) UILabel *label;
@end
%hook FCVersionView
- (void)awakeFromNib {
%orig;
UILabel *label = (UILabel *)[self valueForKey:@"label"];
if ([label.text containsString:@"Infuse Pro"] && ![label.text hasPrefix:@"Infuse Team •"]) {
label.text = [NSString stringWithFormat:@"Infuse Team • %@", label.text];
}
}
%end
// iOS 16 Crash Fix
%hook CKContainer
+ (id)defaultContainer {
return nil;
}
+ (id)containerWithIdentifier:(id)arg1 {
return nil;
}
%end
%hook NSFileManager
- (NSURL *)containerURLForSecurityApplicationGroupIdentifier:(NSString *)groupIdentifier {
NSString *homeDirectory = NSHomeDirectory();
NSString *containerBasePath = [homeDirectory stringByAppendingPathComponent:@"Documents/ApplicationGroupContainers"];
NSURL *baseURL = [NSURL fileURLWithPath:containerBasePath isDirectory:YES];
NSURL *containerURL = [baseURL URLByAppendingPathComponent:groupIdentifier];
NSFileManager *fileManager = [NSFileManager defaultManager];
NSString *containerPath = [containerURL path];
BOOL containerExists = [fileManager fileExistsAtPath:containerPath];
if (!containerExists) {
NSError *error = nil;
[fileManager createDirectoryAtURL:containerURL
withIntermediateDirectories:YES
attributes:nil
error:&error];
NSURL *appSupportURL = [containerURL URLByAppendingPathComponent:@"Library/Application Support"];
[fileManager createDirectoryAtURL:appSupportURL
withIntermediateDirectories:YES
attributes:nil
error:&error];
NSURL *cachesURL = [containerURL URLByAppendingPathComponent:@"Library/Caches"];
[fileManager createDirectoryAtURL:cachesURL
withIntermediateDirectories:YES
attributes:nil
error:&error];
NSURL *preferencesURL = [containerURL URLByAppendingPathComponent:@"Library/Preferences"];
[fileManager createDirectoryAtURL:preferencesURL
withIntermediateDirectories:YES
attributes:nil
error:&error];
}
return containerURL;
}
%end

10
Infuse/Infuse-iOS/control Normal file
View File

@@ -0,0 +1,10 @@
Package: io.infuseteam.infuserootless
Name: Infuse (Rootless)
Version: 2.0
Architecture: iphoneos-arm
Description: Unlock the full potential of Infuse
Maintainer: Infuse Team
Author: Infuse Team
Section: Tweaks
Depends: firmware (>= 18.3)
Conflicts: io.infuseteam.infuse, io.infuseteam.infuseroothide, io.infuseteam.infuselegacy, xyz.eshaydev.ignition, com.ippteam.infuse, com.strejda603.infuse6pro, xyz.eshaydev.infuse

View File

@@ -0,0 +1,26 @@
# Infuse (iOS)
Unlock the full potential of Infuse.
- **App**: [Infuse](https://apps.apple.com/fr/app/infuse/id1136220934)
- **Tested version**: 8.4.2
- **Target**: iOS 18+ (tested on iOS 18.7.1 using LiveContainer)
## Build
```sh
make package FINALPACKAGE=1
```
## Inject
```sh
cyan -i infuse-8.4.2.ipa \
-o infuse-8.4.2_patched.ipa \
-f io.infuseteam.infuserootless_2.0_iphoneos-arm.deb \
-u
```
## Screenshots
![mobile.png](../../docs/screens/Infuse/mobile.png)

3
Infuse/Infuse-tvOS/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -0,0 +1,7 @@
{
Filter = {
Executables = (
infuse,
);
};
}

View File

@@ -0,0 +1,14 @@
TARGET = appletv:latest:18.3
ARCHS = arm64 arm64e
INSTALL_TARGET_PROCESSES = infuse
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = Infuse
Infuse_FILES = Tweak.x
Infuse_CFLAGS = -fobjc-arc
Infuse_FRAMEWORKS = Foundation UIKit
Infuse_LDFLAGS += $(THEOS)/vendor/lib/appletv/CydiaSubstrate.framework/CydiaSubstrate.tbd
include $(THEOS_MAKE_PATH)/tweak.mk

135
Infuse/Infuse-tvOS/Tweak.x Normal file
View File

@@ -0,0 +1,135 @@
// changes : FCInAppPurchaseServiceFreemium block deleted, FCTraktIAPManager block deleted, layoutSubviews -> awakeFromNib on FCVersionView, and the dead return %orig lines after return statements cleaned up (they were unreachable in the old version too)
#import <substrate.h>
#import <Foundation/Foundation.h>
#import <UIKit/UIKit.h>
%hook FCIAPGUIHelper
+(bool) isProAvailable {
return TRUE;
}
+(bool) isSubscriptionBought {
return TRUE;
}
%end
%hook FCInAppPurchaseServiceBase
- (bool)isFeaturePurchased:(long long)arg1 tillDate:(id*)arg2 {
return 1;
}
- (bool)isFeaturePurchased:(long long)arg1 {
return 1;
}
%end
%hook FCInAppPurchaseServiceDummy
- (bool)isFeaturePurchased:(long long)arg1 tillDate:(id*)arg2 {
return 1;
}
%end
// REMOVED: FCInAppPurchaseServiceFreemium (class gone from binary, replaced by SK2)
// SK2 IAP backend
%hook _TtC6infuse31InAppPurchaseServiceFreemiumSK2
- (bool)isFeaturePurchased:(long long)arg1 tillDate:(id*)arg2 {
return 1;
}
- (long long)iapVersionStatus {
// FCUpgradeToProViewController.featureHasBought checks iapVersionStatus > 0
return 1;
}
%end
%hook FCProductCollectionCell
-(bool) featurePurchased {
return TRUE;
}
%end
// REMOVED: FCTraktIAPManager (class gone from binary)
%hook FCUpgradeToProViewController
-(bool) featureHasBought {
return TRUE;
}
%end
// Add credits
@interface FCTVSettingsController : UITableViewController
- (UITableView *)tableView;
@end
%hook FCTVSettingsController
- (void)setUpAppVersionLabel {
%orig;
UITableView *tv = [self tableView];
UILabel *footer = (UILabel *)tv.tableFooterView;
// Guard: footer is nil/not a UILabel
if (![footer isKindOfClass:[UILabel class]]) return;
NSAttributedString *current = footer.attributedText;
if (!current.length) return;
// Handles repeated calls
if ([current.string hasPrefix:@"Infuse Team •"]) return;
NSDictionary *attrs = [current attributesAtIndex:0 effectiveRange:nil];
NSMutableAttributedString *mas = [current mutableCopy];
NSAttributedString *prefix = [[NSAttributedString alloc]
initWithString:@"Infuse Team • "
attributes:attrs];
[mas insertAttributedString:prefix atIndex:0];
footer.attributedText = mas;
}
%end
// iOS 16 Crash Fix
%hook CKContainer
+ (id)defaultContainer {
return nil;
}
+ (id)containerWithIdentifier:(id)arg1 {
return nil;
}
%end
%hook NSPersistentCloudKitContainerOptions
- (id)initWithContainerIdentifier:(id)arg1 {
return nil;
}
%end
%hook CKRecordID
- (id)initWithRecordName:(id)arg1 {
return nil;
}
- (id)initWithRecordName:(id)arg1 zoneID:(id)arg2 {
return nil;
}
%end
%hook CKSystemSharingUIObserver
- (id)initWithContainer:(id)arg1 {
return nil;
}
%end
%hook NSFileManager
- (id)ubiquityIdentityToken {
return nil;
}
- (NSURL *)containerURLForSecurityApplicationGroupIdentifier:(NSString *)groupIdentifier {
NSString *docPath = [NSSearchPathForDirectoriesInDomains(NSDocumentDirectory, NSUserDomainMask, YES) firstObject];
NSString *path = [docPath stringByAppendingPathComponent:groupIdentifier];
NSURL *url = [NSURL fileURLWithPath:path];
if (![[NSFileManager defaultManager] fileExistsAtPath:[url path]]) {
[[NSFileManager defaultManager] createDirectoryAtURL:url withIntermediateDirectories:YES attributes:nil error:nil];
}
return url;
}
%end

View File

@@ -0,0 +1,10 @@
Package: io.infuseteam.infuserootless
Name: Infuse (Rootless)
Version: 2.3
Architecture: appletvos-arm64
Description: Unlock the full potential of Infuse
Maintainer: Infuse Team
Author: Infuse Team
Section: Tweaks
Depends: firmware
Conflicts: io.infuseteam.infuse, io.infuseteam.infuseroothide, io.infuseteam.infuselegacy, xyz.eshaydev.ignition, com.ippteam.infuse, com.strejda603.infuse6pro, xyz.eshaydev.infuse

View File

@@ -0,0 +1,26 @@
# Infuse tvOS
Unlock pro features in Infuse.
- **App**: [Infuse](https://apps.apple.com/fr/app/infuse/id1136220934)
- **Tested version**: 8.2.4
- **Target**: tvOS 18.3 (tested on tvOS 18.3)
## Build
```sh
make package FINALPACKAGE=1
```
## Inject
```sh
cyan -i infuse-8.2.4.ipa \
-o infuse-8.2.4_patched.ipa \
-f io.infuseteam.infuserootless_2.0_tvos-arm64.deb \
-u
```
## Screenshots
![../docs/screens/Infuse/settings.png](../docs/screens/Infuse/settings.png)

View File

@@ -1,13 +0,0 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = Jayson
ARCHS = arm64 arm64e
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = JaysonPlus
JaysonPlus_FILES = Tweak.x
JaysonPlus_CFLAGS = -fobjc-arc
JaysonPlus_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -1,11 +0,0 @@
#import <substrate.h>
%hook UnlockEverythingManager
- (BOOL)haveUnlockedEverything {
return TRUE;
}
- (void)setHaveUnlockedEverything:(BOOL)unlocked {
%orig(YES);
}
%end

3
NetworkLogger/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

13
NetworkLogger/Makefile Normal file
View File

@@ -0,0 +1,13 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = *
ARCHS = arm64 arm64e
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = NetworkLogger
NetworkLogger_FILES = Tweak.x
NetworkLogger_CFLAGS = -fobjc-arc
NetworkLogger_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -0,0 +1,2 @@
{
}

156
NetworkLogger/Tweak.x Normal file
View File

@@ -0,0 +1,156 @@
#import <substrate.h>
#import <Foundation/Foundation.h>
#define LOG(fmt, ...) NSLog(@"[NetworkLogger] " fmt, ##__VA_ARGS__)
#define MAX_BODY_LOG 2048
#pragma mark - Helpers
static int requestCount = 0;
static NSString *timestamp(void) {
static NSDateFormatter *fmt;
static dispatch_once_t once;
dispatch_once(&once, ^{
fmt = [NSDateFormatter new];
fmt.dateFormat = @"HH:mm:ss.SSS";
});
return [fmt stringFromDate:[NSDate date]];
}
static NSString *method(NSURLRequest *req) {
return req.HTTPMethod.length ? req.HTTPMethod : @"GET";
}
static NSString *url(NSURLRequest *req) {
return req.URL.absoluteString;
}
static NSString *formatHeaders(NSDictionary *hdrs) {
if (!hdrs.count) return @"(none)";
NSMutableString *s = [NSMutableString string];
[hdrs enumerateKeysAndObjectsUsingBlock:^(NSString *k, NSString *v, BOOL *_) {
[s appendFormat:@"\n %@: %@", k, v];
}];
return s.copy;
}
static NSString *formatBody(NSData *data) {
if (!data.length) return @"(empty)";
NSString *str = [[NSString alloc] initWithData:data encoding:NSUTF8StringEncoding];
if (str) return str.length > MAX_BODY_LOG ? [str substringToIndex:MAX_BODY_LOG] : str;
return [NSString stringWithFormat:@"<binary %lu bytes>", (unsigned long)data.length];
}
static NSString *formatResponse(NSHTTPURLResponse *resp, NSData *body) {
NSMutableString *s = [NSMutableString stringWithFormat:@"HTTP %ld", (long)resp.statusCode];
[resp.allHeaderFields enumerateKeysAndObjectsUsingBlock:^(NSString *k, NSString *v, BOOL *_) {
[s appendFormat:@"\n %@: %@", k, v];
}];
if (body) [s appendFormat:@"\n Body: %@", formatBody(body)];
return s.copy;
}
static void logDataResponse(int num, NSURLRequest *req, NSData *data, NSURLResponse *resp, NSError *err) {
if (err) {
LOG(@"[%@] ◀ #%d %@ %@\n Error: %@", timestamp(), num, method(req), url(req), err.localizedDescription);
} else if ([resp isKindOfClass:[NSHTTPURLResponse class]]) {
LOG(@"[%@] ◀ #%d %@ %@\n%@", timestamp(), num, method(req), url(req), formatResponse((NSHTTPURLResponse *)resp, data));
} else {
LOG(@"[%@] ◀ #%d %@ %@\n (non-HTTP)", timestamp(), num, method(req), url(req));
}
}
#define LOG_REQUEST(req, extra) \
LOG(@"[%@] ▶ #%d %@ %@\n Headers:%@%@", timestamp(), ++requestCount, method(req), url(req), formatHeaders(req.allHTTPHeaderFields), extra)
#define WRAP_DATA_HANDLER(orig, self, _cmd, req, handler, ...) \
void (^wrapped)(NSData *, NSURLResponse *, NSError *) = ^(NSData *d, NSURLResponse *r, NSError *e) { \
logDataResponse(requestCount, req, d, r, e); \
if (handler) handler(d, r, e); \
}; \
return orig(self, _cmd, req, ##__VA_ARGS__, wrapped)
#pragma mark - NSURLSession Hooks
static NSURLSessionDataTask *(*orig_dataTaskReq)(NSURLSession *, SEL, NSURLRequest *, void (^)(NSData *, NSURLResponse *, NSError *));
static NSURLSessionDataTask *hooked_dataTaskReq(NSURLSession *self, SEL _cmd, NSURLRequest *req, void (^handler)(NSData *, NSURLResponse *, NSError *)) {
NSString *bodyLog = req.HTTPBody ? [NSString stringWithFormat:@"\n Body: %@", formatBody(req.HTTPBody)] : @"";
LOG_REQUEST(req, bodyLog);
WRAP_DATA_HANDLER(orig_dataTaskReq, self, _cmd, req, handler);
}
static NSURLSessionDataTask *(*orig_dataTaskURL)(NSURLSession *, SEL, NSURL *, void (^)(NSData *, NSURLResponse *, NSError *));
static NSURLSessionDataTask *hooked_dataTaskURL(NSURLSession *self, SEL _cmd, NSURL *u, void (^handler)(NSData *, NSURLResponse *, NSError *)) {
return hooked_dataTaskReq(self, _cmd, [NSURLRequest requestWithURL:u], handler);
}
static NSURLSessionUploadTask *(*orig_uploadTask)(NSURLSession *, SEL, NSURLRequest *, NSData *, void (^)(NSData *, NSURLResponse *, NSError *));
static NSURLSessionUploadTask *hooked_uploadTask(NSURLSession *self, SEL _cmd, NSURLRequest *req, NSData *body, void (^handler)(NSData *, NSURLResponse *, NSError *)) {
LOG_REQUEST(req, [NSString stringWithFormat:@"\n Body: %@", formatBody(body)]);
WRAP_DATA_HANDLER(orig_uploadTask, self, _cmd, req, handler, body);
}
static NSURLSessionDownloadTask *(*orig_downloadTask)(NSURLSession *, SEL, NSURLRequest *, void (^)(NSURL *, NSURLResponse *, NSError *));
static NSURLSessionDownloadTask *hooked_downloadTask(NSURLSession *self, SEL _cmd, NSURLRequest *req, void (^handler)(NSURL *, NSURLResponse *, NSError *)) {
LOG_REQUEST(req, @"");
int num = requestCount;
void (^wrapped)(NSURL *, NSURLResponse *, NSError *) = ^(NSURL *loc, NSURLResponse *resp, NSError *err) {
if (err) {
LOG(@"[%@] ◀ #%d %@ %@\n Error: %@", timestamp(), num, method(req), url(req), err.localizedDescription);
} else if ([resp isKindOfClass:[NSHTTPURLResponse class]]) {
LOG(@"[%@] ◀ #%d %@ %@\n (saved to %@)\n%@", timestamp(), num, method(req), url(req), loc.path, formatResponse((NSHTTPURLResponse *)resp, nil));
}
if (handler) handler(loc, resp, err);
};
return orig_downloadTask(self, _cmd, req, wrapped);
}
static void (*orig_resume)(NSURLSessionTask *, SEL);
static void hooked_resume(NSURLSessionTask *self, SEL _cmd) {
LOG(@"[%@] ▶ RESUME %@ %@", timestamp(), method(self.currentRequest), url(self.currentRequest));
orig_resume(self, _cmd);
}
#pragma mark - NSURLConnection (Legacy)
static void (*orig_asyncSend)(NSURLConnection *, SEL, NSURLRequest *, NSOperationQueue *, void (^)(NSURLResponse *, NSData *, NSError *));
static void hooked_asyncSend(NSURLConnection *self, SEL _cmd, NSURLRequest *req, NSOperationQueue *queue, void (^handler)(NSURLResponse *, NSData *, NSError *)) {
LOG_REQUEST(req, @" (legacy)");
void (^wrapped)(NSURLResponse *, NSData *, NSError *) = ^(NSURLResponse *r, NSData *d, NSError *e) {
logDataResponse(requestCount, req, d, r, e);
if (handler) handler(r, d, e);
};
orig_asyncSend(self, _cmd, req, queue, wrapped);
}
#pragma mark - Constructor
#define HOOK_MSG(cls, sel, hook, orig) \
MSHookMessageEx(cls, @selector(sel), (IMP)hook, (IMP *)&orig)
%ctor {
LOG(@"=== tweak loaded ===");
Class session = NSClassFromString(@"NSURLSession");
if (session) {
HOOK_MSG(session, dataTaskWithRequest:completionHandler:, hooked_dataTaskReq, orig_dataTaskReq);
HOOK_MSG(session, dataTaskWithURL:completionHandler:, hooked_dataTaskURL, orig_dataTaskURL);
HOOK_MSG(session, uploadTaskWithRequest:fromData:completionHandler:, hooked_uploadTask, orig_uploadTask);
HOOK_MSG(session, downloadTaskWithRequest:completionHandler:, hooked_downloadTask, orig_downloadTask);
}
Class task = NSClassFromString(@"__NSCFLocalDataTask") ?: NSClassFromString(@"NSURLSessionDataTask");
if (task) HOOK_MSG(task, resume, hooked_resume, orig_resume);
Class conn = NSClassFromString(@"NSURLConnection");
if (conn) HOOK_MSG(conn, sendAsynchronousRequest:queue:completionHandler:, hooked_asyncSend, orig_asyncSend);
LOG(@"=== all hooks installed ===");
}

9
NetworkLogger/control Normal file
View File

@@ -0,0 +1,9 @@
Package: xyz.noham.networklogger
Name: NetworkLogger
Version: 1.0.0
Architecture: iphoneos-arm
Description: Logs every network request and response to the console via os_log.
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

44
NetworkLogger/index.md Normal file
View File

@@ -0,0 +1,44 @@
# NetworkLogger
Logs every network request and response to the console via `os_log`. Useful for debugging API calls, reverse-engineering endpoints, and understanding how an app communicates with its backend.
## What it hooks
- `NSURLSession` task creation (`dataTaskWithRequest:`, `dataTaskWithURL:`, `uploadTaskWithRequest:fromData:`, `downloadTaskWithRequest:`)
- `NSURLSessionTask resume`
- `NSURLConnection sendAsynchronousRequest:queue:completionHandler:` (legacy)
## Output format
```
[NetworkLogger] ▶ REQUEST GET https://platform.runawayplay.com/dragons/api/mailbox
Headers:
Authorization: Bearer <token>
X-Client-Platform: ios
Body: (none)
[NetworkLogger] ◀ RESPONSE GET https://platform.runawayplay.com/dragons/api/mailbox
HTTP 200
Content-Type: application/json
...
Body: {"mailItems": [...]}
```
## Build
```sh
make clean && make package THEOS_PACKAGE_SCHEME=rootless
```
## Inject
```sh
cyan -i <input.ipa> -o <output_patched.ipa> -f <tweak.deb> -u
```
## Viewing logs
```sh
log stream --predicate 'eventMessage contains "NetworkLogger"' --level debug
```
Or view in Console.app filtering for `NetworkLogger`.

3
OqeePlus/OqeePlus-iOS/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -0,0 +1,12 @@
TARGET = iphone:latest:14.0
ARCHS = arm64
INSTALL_TARGET_PROCESSES = Oqee
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = OqeePlus
OqeePlus_FILES = Tweak.x
OqeePlus_CFLAGS = -fobjc-arc
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -0,0 +1,10 @@
{
Filter = {
Bundles = (
"net.oqee.appleos",
);
Executables = (
App,
);
};
}

View File

@@ -0,0 +1,143 @@
#import <substrate.h>
#import <UIKit/UIKit.h>
#import <AVFoundation/AVFoundation.h>
#import <Foundation/Foundation.h>
#include <mach-o/dyld.h>
#include <string.h>
#include <stdint.h>
#define TAG @"[OQAdsLogger]"
%hook IMAAdsRequest
- (instancetype)initWithAdsResponse:(NSString *)adsResponse
adDisplayContainer:(id)adDisplayContainer
avPlayerVideoDisplay:(id)avPlayerVideoDisplay
pictureInPictureProxy:(id)pipProxy
userContext:(id)userContext {
NSLog(@"%@-[IMAAdsRequest init] [PiP path]", TAG);
NSLog(@"%@ adDisplayContainer = %@", TAG, adDisplayContainer);
NSLog(@"%@ avPlayerVideoDisplay = %@", TAG, avPlayerVideoDisplay);
NSLog(@"%@ pictureInPictureProxy = %@", TAG, pipProxy);
NSLog(@"%@ VMAP payload (%lu bytes):\n%@",
TAG, (unsigned long)adsResponse.length, adsResponse);
id result = %orig;
NSLog(@"%@ -> IMAAdsRequest = %p", TAG, result);
return result;
}
// - (instancetype)initWithAdsResponse:(NSString *)adsResponse
// adDisplayContainer:(id)adDisplayContainer
// contentPlayhead:(id)contentPlayhead
// userContext:(id)userContext {
// NSLog(@"%@-[IMAAdsRequest init] [non-PiP path]", TAG);
// NSLog(@"%@ adDisplayContainer = %@", TAG, adDisplayContainer);
// NSLog(@"%@ contentPlayhead = %@", TAG, contentPlayhead);
// NSLog(@"%@ VMAP payload (%lu bytes):\n%@",
// TAG, (unsigned long)adsResponse.length, adsResponse);
// id result = %orig;
// NSLog(@"%@ -> IMAAdsRequest = %p", TAG, result);
// return result;
// }
// - (instancetype)initWithAdsResponse:(NSString *)adsResponse
// adDisplayContainer:(id)adDisplayContainer
// contentPlayhead:(id)contentPlayhead
// userContext:(id)userContext {
// NSString *tweakedVMAP = @"<?xml version='1.0' encoding='utf-8'?>\n"
// @"<vmap:VMAP\n"
// @" xmlns:vmap=\"http://www.iab.net/vmap-1.0\" version=\"1.0\">\n"
// @" <vmap:AdBreak breakId=\"pre-roll-intro\" breakType=\"linear\" timeOffset=\"start\">\n"
// @" <vmap:AdSource allowMultipleAds=\"false\" followRedirects=\"true\" id=\"1\">\n"
// @" <vmap:VASTAdData>\n"
// @" <VAST\n"
// @" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" version=\"3.0\" xsi:noNamespaceSchemaLocation=\"vast.xsd\">\n"
// @" <Ad id=\"breakIntro\" sequence=\"1\">\n"
// @" <InLine>\n"
// @" <AdSystem>VizChoice</AdSystem>\n"
// @" <AdTitle>Oqee Cine Break Intro</AdTitle>\n"
// @" <Creatives>\n"
// @" <Creative>\n"
// @" <Linear>\n"
// @" <Duration>00:00:03</Duration>\n"
// @" <MediaFiles>\n"
// @" <MediaFile delivery=\"progressive\" width=\"1920\" height=\"1080\" type=\"video/mp4\">https://noh.am/rick.mp4</MediaFile>\n"
// @" <MediaFile delivery=\"streaming\" width=\"1920\" height=\"1080\" type=\"application/dash+xml\">https://replay-01.bzn.oqee.net/oqee-static/barkers/oqee-cine/2025-10-21/adaptative/playlist_214c3e5132137e02.mpd</MediaFile>\n"
// @" <MediaFile delivery=\"streaming\" width=\"1920\" height=\"1080\" type=\"application/x-mpegURL\">https://replay-01.bzn.oqee.net/oqee-static/barkers/oqee-cine/2025-10-21/adaptative/playlist_214c3e5132137e02.m3u8</MediaFile>\n"
// @" </MediaFiles>\n"
// @" </Linear>\n"
// @" </Creative>\n"
// @" </Creatives>\n"
// @" </InLine>\n"
// @" </Ad>\n"
// @" </VAST>\n"
// @" </vmap:VASTAdData>\n"
// @" </vmap:AdSource>\n"
// @" </vmap:AdBreak>\n"
// @"</vmap:VMAP>\n";
// NSLog(@"%@ Replaced VMAP (%lu bytes) with tweaked document", TAG, adsResponse.length);
// return %orig(tweakedVMAP, adDisplayContainer, contentPlayhead, userContext);
// }
- (instancetype)initWithAdsResponse:(NSString *)adsResponse
adDisplayContainer:(id)adDisplayContainer
contentPlayhead:(id)contentPlayhead
userContext:(id)userContext {
// Replace the VMAP with an empty document
NSString *emptyVMAP = @"<?xml version='1.0' encoding='utf-8'?>"
@"<vmap:VMAP xmlns:vmap=\"http://www.iab.net/vmap-1.0\" version=\"1.0\"/>";
NSLog(@"%@ Replaced VMAP (%lu bytes) with empty document", TAG, adsResponse.length);
return %orig(emptyVMAP, adDisplayContainer, contentPlayhead, userContext);
}
%end
// IMAAdsLoader — confirms dispatch to IMA SDK
//
// Called from OQPlayerAdsLoader.requestAds(_:loader:) (sub_10008FC08)
// after Swift dynamic-cast guards pass. This is the point of no return —
// the IMA SDK takes ownership of the request and starts network I/O.
%hook IMAAdsLoader
- (void)requestAdsWithRequest:(id)request {
NSLog(@"%@ -[IMAAdsLoader requestAdsWithRequest:]", TAG);
NSLog(@"%@ loader = %@", TAG, self);
NSLog(@"%@ request = %@", TAG, [request debugDescription]);
%orig;
NSLog(@"%@ requestAdsWithRequest dispatched ✓", TAG);
}
%end
// IMAAdsManager — SDK parsed the VMAP, breaks are scheduled
//
// Called from the IMAAdsLoaderDelegate callback in OQImaManager
// At this point the IMA SDK has parsed the VMAP and knows all ad break
// positions. Passing nil for renderingSettings means OQEE uses defaults.
%hook IMAAdsManager
- (void)initializeWithAdsRenderingSettings:(id)renderingSettings {
NSLog(@"%@ -[IMAAdsManager initializeWithAdsRenderingSettings:]", TAG);
NSLog(@"%@ adsManager = %@", TAG, self);
NSLog(@"%@ renderingSettings = %@", TAG, renderingSettings ?: @"(nil — default)");
%orig;
NSLog(@"%@ VMAP parsed, ad breaks scheduled ✓", TAG);
}
%end
%hook VSSubscriptionRegistrationCenter
- (void)setCurrentSubscription:(id)subscription
{
NSLog(@"Blocked VSSubscriptionRegistrationCenter");
NSLog(@"Subscription: %@", subscription);
return;
}
%end
%ctor {
// activate dev mode
NSUserDefaults *defaults = [NSUserDefaults standardUserDefaults];
[defaults setBool:YES forKey:@"tv.oqee.devModeEnabled"];
}

View File

@@ -0,0 +1,9 @@
Package: xyz.nohamr.oqeeplus
Name: Oqee+ (iOS)
Version: 1.0
Architecture: iphoneos-arm64
Description: Oqee+ Ads blocker hook for iOS
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

View File

@@ -0,0 +1,22 @@
# OqeePlus iOS
Block ads initialization on Oqee.
- **App**: [OqeePlus : Streaming, TV en Direct](https://apps.apple.com/fr/app/free-tv/id1542614107)
- **Tested version**: 2.40
- **Target**: iOS
## Build
```sh
make package FINALPACKAGE=1
```
## Inject
```sh
cyan -i oqeeplus.ipa \
-o oqeeplus_patched.ipa \
-f xyz.nohamr.oqeeplus_1.0_iphoneos-arm64.deb \
-u
```

3
OqeePlus/OqeePlus-tvOS/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -0,0 +1,13 @@
TARGET = appletv:latest:18.3
ARCHS = arm64
INSTALL_TARGET_PROCESSES = Oqee
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = OqeePlus
OqeePlus_FILES = Tweak.x
OqeePlus_CFLAGS = -fobjc-arc
OqeePlus_LDFLAGS += $(THEOS)/vendor/lib/appletv/CydiaSubstrate.framework/CydiaSubstrate.tbd
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -0,0 +1,10 @@
{
Filter = {
Bundles = (
"net.oqee.appleos",
);
Executables = (
App,
);
};
}

View File

@@ -0,0 +1,88 @@
#import <substrate.h>
#import <UIKit/UIKit.h>
#import <AVFoundation/AVFoundation.h>
#import <Foundation/Foundation.h>
#include <mach-o/dyld.h>
#include <string.h>
#include <stdint.h>
#define TAG @"[OQAdsLogger]"
%hook IMAAdsRequest
- (instancetype)initWithAdsResponse:(NSString *)adsResponse
adDisplayContainer:(id)adDisplayContainer
avPlayerVideoDisplay:(id)avPlayerVideoDisplay
pictureInPictureProxy:(id)pipProxy
userContext:(id)userContext {
NSLog(@"%@-[IMAAdsRequest init] [PiP path]", TAG);
NSLog(@"%@ adDisplayContainer = %@", TAG, adDisplayContainer);
NSLog(@"%@ avPlayerVideoDisplay = %@", TAG, avPlayerVideoDisplay);
NSLog(@"%@ pictureInPictureProxy = %@", TAG, pipProxy);
NSLog(@"%@ VMAP payload (%lu bytes):\n%@",
TAG, (unsigned long)adsResponse.length, adsResponse);
id result = %orig;
NSLog(@"%@ -> IMAAdsRequest = %p", TAG, result);
return result;
}
- (instancetype)initWithAdsResponse:(NSString *)adsResponse
adDisplayContainer:(id)adDisplayContainer
contentPlayhead:(id)contentPlayhead
userContext:(id)userContext {
// Replace the VMAP with an empty document
NSString *emptyVMAP = @"<?xml version='1.0' encoding='utf-8'?>"
@"<vmap:VMAP xmlns:vmap=\"http://www.iab.net/vmap-1.0\" version=\"1.0\"/>";
NSLog(@"%@ Replaced VMAP (%lu bytes) with empty document", TAG, adsResponse.length);
return %orig(emptyVMAP, adDisplayContainer, contentPlayhead, userContext);
}
%end
// IMAAdsLoader — confirms dispatch to IMA SDK
//
// Called from OQPlayerAdsLoader.requestAds(_:loader:) (sub_10008FC08)
// after Swift dynamic-cast guards pass. This is the point of no return —
// the IMA SDK takes ownership of the request and starts network I/O.
%hook IMAAdsLoader
- (void)requestAdsWithRequest:(id)request {
NSLog(@"%@ -[IMAAdsLoader requestAdsWithRequest:]", TAG);
NSLog(@"%@ loader = %@", TAG, self);
NSLog(@"%@ request = %@", TAG, [request debugDescription]);
%orig;
NSLog(@"%@ requestAdsWithRequest dispatched ✓", TAG);
}
%end
// IMAAdsManager — SDK parsed the VMAP, breaks are scheduled
//
// Called from the IMAAdsLoaderDelegate callback in OQImaManager
// At this point the IMA SDK has parsed the VMAP and knows all ad break
// positions. Passing nil for renderingSettings means OQEE uses defaults.
%hook IMAAdsManager
- (void)initializeWithAdsRenderingSettings:(id)renderingSettings {
NSLog(@"%@ -[IMAAdsManager initializeWithAdsRenderingSettings:]", TAG);
NSLog(@"%@ adsManager = %@", TAG, self);
NSLog(@"%@ renderingSettings = %@", TAG, renderingSettings ?: @"(nil — default)");
%orig;
NSLog(@"%@ VMAP parsed, ad breaks scheduled ✓", TAG);
}
%end
%hook VSSubscriptionRegistrationCenter
- (void)setCurrentSubscription:(id)subscription
{
NSLog(@"Blocked VSSubscriptionRegistrationCenter");
NSLog(@"Subscription: %@", subscription);
return;
}
%end
%ctor {
// activate dev mode
NSUserDefaults *defaults = [NSUserDefaults standardUserDefaults];
[defaults setBool:YES forKey:@"tv.oqee.devModeEnabled"];
}

View File

@@ -0,0 +1,9 @@
Package: xyz.nohamr.oqeeplus
Name: Oqee+ (tvOS)
Version: 1.1
Architecture: appletvos-arm64
Description: Oqee+ Ads blocker hook for tvOS
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

View File

@@ -0,0 +1,22 @@
# OqeePlus tvOS
Block ads initialization on Oqee.
- **App**: [OqeePlus : Streaming, TV en Direct](https://apps.apple.com/fr/app/free-tv/id1542614107)
- **Tested version**: 2.40
- **Target**: tvOS
## Build
```sh
make package FINALPACKAGE=1
```
## Inject
```sh
cyan -i oqeeplus.ipa \
-o oqeeplus_patched.ipa \
-f xyz.nohamr.oqeeplus_1.0_appletvos-arm64.deb \
-u
```

View File

@@ -4,13 +4,22 @@ iOS tweaks built with [Theos](https://theos.dev), injected into IPAs via [cyan](
## Tweaks
| Tweak | App | Target |
| ------------------------------------------------------- | ---------------- | ---------- |
| [ServerCatPremium](ServerCatPremium/index.md) | ServerCat 1.30.0 | iOS 17+ |
| [ServerCatPremium (legacy)](ServerCatPremium_/index.md) | ServerCat 1.6.4 | iOS 15 |
| [TextasticPro](TextasticPro/index.md) | Textastic 10.9.2 | iOS 18+ |
| [BusinessJB](BusinessJB/index.md) | Business 2.3.000 | iOS 15 |
| [CreditAgricoleJB](CreditAgricoleJB/index.md) | Ma Banque 47.0.0 | iOS 15.8.6 |
| Tweak | App | Target |
| -------------------------------------------------- | ------------------------ | ----------- |
| [ServerCatPremium](ServerCatPremium/index.md) | ServerCat 1.30.0 / 1.6.4 | iOS 15+ |
| [TextasticPro](TextasticPro/index.md) | Textastic 10.9.2 | iOS 18+ |
| [BusinessJB](BusinessJB/index.md) | Business 2.3.000 | iOS 15 |
| [CreditAgricoleJB](CreditAgricoleJB/index.md) | Ma Banque 47.0.0 | iOS 15.8.6 |
| [Infuse](Infuse/Infuse-tvOS/index.md) | Infuse 8.2.4 | tvOS 18.3 |
| [Infuse (iOS)](Infuse/Infuse-iOS/index.md) | Infuse 8.4.2 | iOS 18+ |
| [TF1+ (tvOS)](TF1Plus/TF1Plus-tvOS/index.md) | TF1+ 11.36.0 | tvOS |
| [TF1+ (iOS)](TF1Plus/TF1Plus-iOS/index.md) | TF1+ 11.36.0 | iOS 14+ |
| [OqeePlus (tvOS)](OqeePlus/OqeePlus-tvOS/index.md) | Oqee 2.40 | tvOS 18.3 |
| [OqeePlus (iOS)](OqeePlus/OqeePlus-iOS/index.md) | Oqee 2.40 | iOS 18+ |
| [VolkswagenJB](VolkswagenJB/index.md) | Volkswagen 2.72.0 | iOS 16.7.15 |
| [GPXViewer2](GPXViewer2) | GPXViewer 2 | iOS 14+ |
| [RMHook](RMHook/index.md) | reMarkable | iOS |
| [HatchDragons](HatchDragons/index.md) | HatchDragons 1.2.1 | iOS 18+ |
## Build

5
RMHook/index.md Normal file
View File

@@ -0,0 +1,5 @@
# RMHook-iOS
A dynamic library injection tweak for the reMarkable iOS app, enabling connection to self-hosted [rmfakecloud](https://github.com/ddvk/rmfakecloud) servers.
See the [GitHub Repository](https://github.com/NohamR/RMHook-iOS) for full details, building instructions, and credits.

View File

@@ -5,7 +5,16 @@
#define TARGET_MODULE "ServerCat"
#define IDA_BASE 0x100000000
#define ADDR_IS_PREMIUM 0x10009CD24 // Address of "isPremiumActive" in IDA (adjust if needed)
/*
* EDIT THE HOOK ADDRESS OFFSET ACCORDING TO THE APP VERSION USED:
*
* ServerCat 1.30.0 (latest) -> 0x10009CD24
* ServerCat 1.6.4 (legacy) -> 0x100454D70
*
* Find the address of `isPremiumActive` in IDA and set it below.
*/
#define ADDR_IS_PREMIUM 0x10009CD24
static int (*orig_isPremiumActive)(void);
@@ -26,7 +35,7 @@ static int hook_isPremiumActive(void) {
}
}
// iOS 16 Crash Fix
// iOS 16+ Crash Fix
%hook CKContainer
+ (id)defaultContainer {
return nil;
@@ -34,4 +43,4 @@ static int hook_isPremiumActive(void) {
+ (id)containerWithIdentifier:(id) arg1 {
return nil;
}
%end
%end

View File

@@ -1,9 +1,13 @@
# ServerCatPremium
Unlocks premium features in ServerCat by forcing `isPremiumActive` (`sub_10009CD24`) to always return `1`.
Unlocks premium features in ServerCat by forcing `isPremiumActive` to always return `1`.
- **App**: [ServerCat SSH Terminal](https://apps.apple.com/us/app/servercat-ssh-terminal/id1501532023)
- **Tested on**: ServerCat 1.30.0 (600), iOS 18.3
- **Tested on**: ServerCat 1.30.0 (iOS 18.3) and ServerCat 1.6.4 (iOS 15.8.6)
Hook address offsets (edit in `Tweak.x`):
- `0x10009CD24` — ServerCat 1.30.0
- `0x100454D70` — ServerCat 1.6.4
## Build
@@ -14,12 +18,9 @@ make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
## Inject
```sh
cyan -i tech.baye.servercat-1.30.0.ipa \
-o tech.baye.servercat-1.30.0_patched.ipa \
-f xyz.nohamr_1.0.0-1_iphoneos-arm64.deb \
-u
cyan -i <input.ipa> -o <output_patched.ipa> -f xyz.nohamr_1.0.0-1_iphoneos-arm64.deb -u
```
## Screenshots
![../docs/screens/ServerCatPremium/menu.png](../docs/screens/ServerCatPremium/menu.png)
![../docs/screens/ServerCatPremium/menu2.png](../docs/screens/ServerCatPremium/menu2.png)
![../docs/screens/ServerCatPremium/menu2.png](../docs/screens/ServerCatPremium/menu2.png)

View File

@@ -1,13 +0,0 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = ServerCat
ARCHS = arm64 arm64e
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = ServerCatPremium
ServerCatPremium_FILES = Tweak.x
ServerCatPremium_CFLAGS = -fobjc-arc
ServerCatPremium_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -1,27 +0,0 @@
#import <substrate.h>
#import <mach-o/dyld.h>
#import <string.h>
#import <Foundation/Foundation.h>
#define TARGET_MODULE "ServerCat"
#define IDA_BASE 0x100000000
#define ADDR_IS_PREMIUM 0x100454D70 // Address of "isPremiumActive" in IDA (adjust if needed)
static int (*orig_isPremiumActive)(void);
static int hook_isPremiumActive(void) {
return 1;
}
%ctor {
for (uint32_t i = 0; i < _dyld_image_count(); i++) {
const char *name = _dyld_get_image_name(i);
if (name && strstr(name, TARGET_MODULE)) {
uintptr_t base = (uintptr_t)_dyld_get_image_header(i);
uintptr_t addr = base + (ADDR_IS_PREMIUM - IDA_BASE);
MSHookFunction((void *)addr, (void *)hook_isPremiumActive, (void **)&orig_isPremiumActive);
NSLog(@"[ServerCatPremium] Hooked isPremiumActive at 0x%lx", addr);
return;
}
}
}

View File

@@ -1,9 +0,0 @@
Package: xyz.nohamr.servercatpremiumlegacy
Name: ServerCatPremium (Legacy)
Version: 1.0.0
Architecture: iphoneos-arm
Description: Unlocks premium features in ServerCat app.
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

View File

@@ -1,26 +0,0 @@
# ServerCatPremium (legacy — iOS 15)
Unlocks premium features in ServerCat by forcing `isPremiumActive` (`sub_100454D70`) to always return `1`.
- **App**: [ServerCat SSH Terminal](https://apps.apple.com/us/app/servercat-ssh-terminal/id1501532023)
- **Tested on**: ServerCat 1.6.4, iOS 15.8.6
- **Note**: ServerCat 1.6.4 is the last version supporting iOS 15. Latest requires iOS 17+.
## Build
```sh
make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
```
## Inject
```sh
cyan -i tech.baye.servercat-1.6.4.ipa \
-o tech.baye.servercat-1.6.4_patched.ipa \
-f xyz.nohamr_1.0.0-1_iphoneos-arm64.deb \
-u
```
## Screenshots
![../docs/screens/ServerCatPremium_/menu.png](../docs/screens/ServerCatPremium_/menu.png)
![../docs/screens/ServerCatPremium_/menu2.png](../docs/screens/ServerCatPremium_/menu2.png)

3
TF1Plus/TF1Plus-iOS/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -0,0 +1,12 @@
TARGET = iphone:latest:14.0
ARCHS = arm64 arm64e
INSTALL_TARGET_PROCESSES = mytf1
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = TF1Plus
TF1Plus_FILES = Tweak.x
TF1Plus_CFLAGS = -fobjc-arc
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -0,0 +1,10 @@
{
Filter = {
Bundles = (
"com.tf1.applitf1",
);
Executables = (
App,
);
};
}

View File

@@ -0,0 +1,16 @@
#import <Foundation/Foundation.h>
%hook FWRequestConfiguration
- (id)initWithServerURL:(id)arg1 playerProfile:(id)arg2 {
return self;
}
%end
%hook VSSubscriptionRegistrationCenter
- (void)setCurrentSubscription:(id)subscription
{
NSLog(@"Blocked VSSubscriptionRegistrationCenter");
NSLog(@"Subscription: %@", subscription);
return;
}
%end

View File

@@ -0,0 +1,9 @@
Package: xyz.nohamr.tf1plus
Name: TF1+ (iOS)
Version: 1.0
Architecture: iphoneos-arm64
Description: TF1+ Ads blocker hook for iOS
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: mobilesubstrate (>= 0.9.5000)

View File

@@ -0,0 +1,22 @@
# TF1+ iOS
Block ads initialization on TF1+.
- **App**: [TF1+ : Streaming, TV en Direct](https://apps.apple.com/fr/app/tf1-streaming-tv-en-direct/id407248490)
- **Tested version**: 23.3.1
- **Target**: iOS
## Build
```sh
make package FINALPACKAGE=1
```
## Inject
```sh
cyan -i tf1plus.ipa \
-o tf1plus_patched.ipa \
-f xyz.nohamr.tf1plus_1.0_iphoneos-arm64.deb \
-u
```

3
TF1Plus/TF1Plus-tvOS/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

View File

@@ -0,0 +1,13 @@
TARGET = appletv:latest:18.3
ARCHS = arm64
INSTALL_TARGET_PROCESSES = mytf1
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = TF1Plus
TF1Plus_FILES = Tweak.x
TF1Plus_CFLAGS = -fobjc-arc
TF1Plus_LDFLAGS += $(THEOS)/vendor/lib/appletv/CydiaSubstrate.framework/CydiaSubstrate.tbd
include $(THEOS_MAKE_PATH)/tweak.mk

View File

@@ -0,0 +1,10 @@
{
Filter = {
Bundles = (
"com.tf1.applitf1",
);
Executables = (
mytf1,
);
};
}

View File

@@ -0,0 +1,7 @@
#import <Foundation/Foundation.h>
%hook FWRequestConfiguration
- (id)initWithServerURL:(id)arg1 playerProfile:(id)arg2 {
return self;
}
%end

View File

@@ -0,0 +1,9 @@
Package: xyz.nohamr.tf1plus
Name: TF1+ (Rootful)
Version: 1.1
Architecture: appletvos-arm64
Description: TF1+ Ads blocker hook
Maintainer: NohamR
Author: NohamR
Section: Tweaks
Depends: firmware

View File

@@ -0,0 +1,22 @@
# TF1+ tvOS
Block ads initialization on TF1+.
- **App**: [TF1+ : Streaming, TV en Direct](https://apps.apple.com/fr/app/tf1-streaming-tv-en-direct/id407248490)
- **Tested version**: 11.36.0
- **Target**: tvOS
## Build
```sh
make package FINALPACKAGE=1
```
## Inject
```sh
cyan -i tf1plus.ipa \
-o tf1plus_patched.ipa \
-f com.yourname.tf1plus_1.0_tvos-arm64.deb \
-u
```

3
VolkswagenJB/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
.theos/
packages/
.DS_Store

13
VolkswagenJB/Makefile Normal file
View File

@@ -0,0 +1,13 @@
TARGET = iphone:latest:14.0
INSTALL_TARGET_PROCESSES = Volkswagen
ARCHS = arm64
include $(THEOS)/makefiles/common.mk
TWEAK_NAME = VolkswagenJB
VolkswagenJB_FILES = Tweak.x
VolkswagenJB_CFLAGS = -fobjc-arc
VolkswagenJB_FRAMEWORKS = Foundation
include $(THEOS_MAKE_PATH)/tweak.mk

98
VolkswagenJB/Tweak.x Normal file
View File

@@ -0,0 +1,98 @@
#import <substrate.h>
#import <mach-o/dyld.h>
#import <string.h>
#import <Foundation/Foundation.h>
#define TARGET_MODULE "Volkswagen"
#define IDA_BASE 0x100000000
// sysctl P_TRACED check : always return 0 (no debugger)
#define ADDR_SYSCTL_DEBUG_CHECK 0x10081D5A4
// ptrace(PT_DENY_ATTACH) + FishHook installer : NOP the whole thing
#define ADDR_PTRACE_FISHHOOK 0x10081D704
// JailbreakDetection orchestrator (8 checks) : always return 1 (clean)
#define ADDR_JB_ORCHESTRATOR 0x100824E9C
// Individual JB sub-checks : each returns 1 (no jailbreak found)
#define ADDR_JB_FILE_EXIST 0x100823E38 // type 1: stat/access
#define ADDR_JB_FILE_READABLE 0x100824238 // type 2: fopen/isReadable
#define ADDR_JB_SANDBOX_ESCAPE 0x1008245FC // type 3: write test + fork
#define ADDR_JB_SYMLINK 0x100824A14 // type 5: symlink resolve
#define ADDR_JB_DYLIB_NAMES 0x100824C7C // type 6: _dyld_get_image_name scan
#define ADDR_SECURITY_CHECK_BFC 0x100828BFC // sub_100828BFC(v10) & 1
#define ADDR_SECURITY_CHECK_D20 0x100828D20 // sub_100828D20() & 1
#define ADDR_SECURITY_CHECK_CD4 0x100828CD4 // sub_100828CD4() : bool
static void *(*orig_sysctl_debug)(void);
static void *hooked_sysctl_debug(void) { NSLog(@"[VWTweak] hooked_sysctl_debug called"); return 0; }
static void (*orig_ptrace_fishhook)(void);
static void hooked_ptrace_fishhook(void) { NSLog(@"[VWTweak] hooked_ptrace_fishhook called"); return; }
static uint64_t (*orig_jb_orchestrator)(void);
static uint64_t hooked_jb_orchestrator(void) { NSLog(@"[VWTweak] hooked_jb_orchestrator called"); return 1; }
// static uint64_t (*orig_jb_file_exist)(void);
// static uint64_t hooked_jb_file_exist(void) { NSLog(@"[VWTweak] hooked_jb_file_exist called"); return 1; }
// static uint64_t (*orig_jb_file_readable)(void);
// static uint64_t hooked_jb_file_readable(void) { NSLog(@"[VWTweak] hooked_jb_file_readable called"); return 1; }
// static uint64_t (*orig_jb_sandbox_escape)(void);
// static uint64_t hooked_jb_sandbox_escape(void) { NSLog(@"[VWTweak] hooked_jb_sandbox_escape called"); return 1; }
// static uint64_t (*orig_jb_symlink)(void);
// static uint64_t hooked_jb_symlink(void) { NSLog(@"[VWTweak] hooked_jb_symlink called"); return 1; }
// static uint64_t (*orig_jb_dylib_names)(void);
// static uint64_t hooked_jb_dylib_names(void) { NSLog(@"[VWTweak] hooked_jb_dylib_names called"); return 1; }
static uint64_t (*orig_security_check_bfc)(uint64_t);
static uint64_t hooked_security_check_bfc(uint64_t arg) { NSLog(@"[VWTweak] hooked_security_check_bfc(%llu) called", arg); return 0; }
static uint64_t (*orig_security_check_d20)(void);
static uint64_t hooked_security_check_d20(void) { NSLog(@"[VWTweak] hooked_security_check_d20 called"); return 0; }
static uint64_t (*orig_security_check_cd4)(void);
static uint64_t hooked_security_check_cd4(void) { NSLog(@"[VWTweak] hooked_security_check_cd4 called"); return 0; }
static void hookAt(uintptr_t base, uintptr_t ida_addr, void *hook, void **orig) {
uintptr_t real = base + (ida_addr - IDA_BASE);
MSHookFunction((void *)real, hook, orig);
NSLog(@"[VWTweak] Hooked 0x%lx (slide base 0x%lx)", real, base);
}
%ctor {
for (uint32_t i = 0; i < _dyld_image_count(); i++) {
const char *name = _dyld_get_image_name(i);
if (!name || !strstr(name, TARGET_MODULE))
continue;
uintptr_t base = (uintptr_t)_dyld_get_image_header(i);
NSLog(@"[VWTweak] Found %s at base 0x%lx", name, base);
hookAt(base, ADDR_SYSCTL_DEBUG_CHECK, (void *)hooked_sysctl_debug, (void **)&orig_sysctl_debug);
hookAt(base, ADDR_PTRACE_FISHHOOK, (void *)hooked_ptrace_fishhook, (void **)&orig_ptrace_fishhook);
hookAt(base, ADDR_JB_ORCHESTRATOR, (void *)hooked_jb_orchestrator, (void **)&orig_jb_orchestrator);
// hookAt(base, ADDR_JB_FILE_EXIST, (void *)hooked_jb_file_exist, (void **)&orig_jb_file_exist);
// hookAt(base, ADDR_JB_FILE_READABLE, (void *)hooked_jb_file_readable, (void **)&orig_jb_file_readable);
// hookAt(base, ADDR_JB_SANDBOX_ESCAPE, (void *)hooked_jb_sandbox_escape,(void **)&orig_jb_sandbox_escape);
// hookAt(base, ADDR_JB_SYMLINK, (void *)hooked_jb_symlink, (void **)&orig_jb_symlink);
// hookAt(base, ADDR_JB_DYLIB_NAMES, (void *)hooked_jb_dylib_names, (void **)&orig_jb_dylib_names);
hookAt(base, ADDR_SECURITY_CHECK_BFC, (void *)hooked_security_check_bfc,(void **)&orig_security_check_bfc);
hookAt(base, ADDR_SECURITY_CHECK_D20, (void *)hooked_security_check_d20,(void **)&orig_security_check_d20);
hookAt(base, ADDR_SECURITY_CHECK_CD4, (void *)hooked_security_check_cd4,(void **)&orig_security_check_cd4);
return;
}
NSLog(@"[VWTweak] Target module '%s' not found in dyld image list", TARGET_MODULE);
}

View File

@@ -0,0 +1,7 @@
{
Filter = {
Bundles = (
"com.volkswagen.WeConnect.production",
);
};
}

View File

@@ -1,8 +1,8 @@
Package: xyz.nohamr.jaysonplus
Name: JaysonPlus
Package: xyz.nohamr.volkswagenjb
Name: VolkswagenJB (Rootless)
Version: 1.0.0
Architecture: iphoneos-arm
Description: Unlocks everything in the Jayson app.
Description: Bypass jailbreak detection in Volkswagen app
Maintainer: NohamR
Author: NohamR
Section: Tweaks

26
VolkswagenJB/index.md Normal file
View File

@@ -0,0 +1,26 @@
# VolkswagenJB
Disables jailbreak detection in Volkswagen.
- **App**: [Volkswagen](https://apps.apple.com/fr/app/volkswagen/id1517566572)
- **Latest version**: 2.72.0
- **Tested on**: iOS 16.7.15
## Build
```sh
make clean && make package THEOS_PACKAGE_SCHEME=rootless DEBUG=0
```
## Inject
```sh
cyan -i com.volkswagen.WeConnect.production_2.72.0.ipa \
-o com.volkswagen.WeConnect.production_2.72.0_patched.ipa \
-f xyz.nohamr.volkswagenjb_1.0.0-1_iphoneos-arm64.deb \
-u
```
## Screenshots
![../docs/screens/VolkswagenJB/undetected.png](../docs/screens/VolkswagenJB/undetected.png)

Binary file not shown.

After

Width:  |  Height:  |  Size: 232 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

6
scripts/patch-tvos.sh Executable file
View File

@@ -0,0 +1,6 @@
#!/bin/bash
set -e
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
"$SCRIPT_DIR/patch.sh" --tv "$@"

74
scripts/patch.sh Executable file
View File

@@ -0,0 +1,74 @@
#!/bin/bash
set -e
usage() {
echo "Usage: $0 [--tv] [-o <output.ipa> | --output <output.ipa>] <file.ipa> <file.deb>"
exit 1
}
TV=0
IPA=""
DEB=""
OUTPUT_IPA=""
OUTPUT_SPECIFIED=0
while [ "$#" -gt 0 ]; do
case "$1" in
-o|--output)
if [ -z "$2" ]; then
echo "Error: $1 requires an argument."
exit 1
fi
OUTPUT_IPA="$2"
OUTPUT_SPECIFIED=1
shift 2
;;
-o=*|--output=*)
OUTPUT_IPA="${1#*=}"
OUTPUT_SPECIFIED=1
shift
;;
--tv)
TV=1
shift
;;
*.ipa)
IPA="$1"
shift
;;
*.deb)
DEB="$1"
shift
;;
*)
echo "Unknown argument: $1"
usage
;;
esac
done
if [ -z "$IPA" ] || [ -z "$DEB" ]; then
echo "You must provide one .ipa and one .deb file."
exit 1
fi
if [ -z "$OUTPUT_IPA" ]; then
OUTPUT_IPA="/tmp/ipa_patched/$(basename "$IPA")"
mkdir -p "$(dirname "$OUTPUT_IPA")"
fi
CYAN_ARGS=(-i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite -c 9)
if [ "$TV" -eq 1 ]; then
CYAN_ARGS+=(--tv)
fi
echo "[+] Patching IPA with cyan..."
cyan "${CYAN_ARGS[@]}"
echo "[+] Patch complete."
if [ "$OUTPUT_SPECIFIED" -eq 0 ]; then
PATCHED_IPA="$(dirname "$IPA")/$(basename "$IPA" .ipa)_patched.ipa"
cp "$OUTPUT_IPA" "$PATCHED_IPA"
echo "[+] Patched IPA saved as: $PATCHED_IPA"
fi

View File

@@ -38,7 +38,8 @@ IPA_NAME=$(basename "$IPA")
OUTPUT_IPA="$OUT_DIR/$IPA_NAME"
echo "[+] Patching IPA with cyan..."
cyan -i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite
# cyan -i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite -c 0
cyan -i "$IPA" -o "$OUTPUT_IPA" -f "$DEB" -u --overwrite -c 9
echo "[+] Patch complete."
LOCAL_IP=$(ipconfig getifaddr en0 2>/dev/null)

128
scripts/patch_and_server.py Normal file
View File

@@ -0,0 +1,128 @@
#!/usr/bin/env python3
import sys
import os
import subprocess
import shutil
import socket
def get_local_ip():
try:
# Try macOS command
output = subprocess.check_output(
["ipconfig", "getifaddr", "en0"], stderr=subprocess.DEVNULL
)
return output.decode("utf-8").strip()
except subprocess.CalledProcessError:
try:
# Try Linux command
output = subprocess.check_output(
["hostname", "-I"], stderr=subprocess.DEVNULL
)
return output.decode("utf-8").split()[0].strip()
except (subprocess.CalledProcessError, IndexError):
pass
# Fallback to socket method
try:
s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
s.connect(("8.8.8.8", 80))
ip = s.getsockname()[0]
s.close()
return ip
except Exception:
return None
def main():
if len(sys.argv) != 3:
print(f"Usage: {os.path.basename(sys.argv[0])} <file.ipa> <file.deb>")
sys.exit(1)
ipa_file = None
deb_file = None
for arg in sys.argv[1:]:
if arg.endswith(".ipa"):
ipa_file = arg
elif arg.endswith(".deb"):
deb_file = arg
else:
print(f"Unknown file type: {arg}")
sys.exit(1)
if not ipa_file or not deb_file:
print("You must provide one .ipa and one .deb file.")
sys.exit(1)
out_dir = "/tmp/ipa_patched"
os.makedirs(out_dir, exist_ok=True)
ipa_name = os.path.basename(ipa_file)
output_ipa = os.path.join(out_dir, ipa_name)
print("[+] Patching IPA with cyan...")
try:
subprocess.run(
[
"cyan",
"-i",
ipa_file,
"-o",
output_ipa,
"-f",
deb_file,
"-u",
"--overwrite",
],
check=True,
)
except subprocess.CalledProcessError:
print("[-] Patch failed.")
sys.exit(1)
except FileNotFoundError:
print(
"[-] 'cyan' command not found. Please ensure it is installed and in your PATH."
)
sys.exit(1)
print("[+] Patch complete.")
local_ip = get_local_ip()
if not local_ip:
print("Could not detect local IP automatically.")
local_ip = "YOUR_IP"
download_link = f"http://{local_ip}:8000/{ipa_name}"
print()
print("==========================================")
print("Download link:")
print(download_link)
print("==========================================")
print()
# Try to copy to clipboard using pbcopy on macOS
try:
if shutil.which("pbcopy"):
subprocess.run(["pbcopy"], input=download_link.encode("utf-8"), check=True)
print("[+] Download link copied to clipboard.")
except Exception:
pass
print("[+] Starting HTTP server...")
print("Press Ctrl+C to stop.")
print()
# Start python HTTP server
try:
subprocess.run(
[sys.executable, "-m", "http.server", "8000", "--directory", out_dir]
)
except KeyboardInterrupt:
print("\nStopping HTTP server...")
if __name__ == "__main__":
main()

159
scripts/watch_and_server.py Normal file
View File

@@ -0,0 +1,159 @@
#!/usr/bin/env python3
import sys
import os
import subprocess
import shutil
import socket
import time
import glob
import threading
def get_local_ip():
try:
output = subprocess.check_output(
["ipconfig", "getifaddr", "en0"], stderr=subprocess.DEVNULL
)
return output.decode("utf-8").strip()
except subprocess.CalledProcessError:
try:
output = subprocess.check_output(
["hostname", "-I"], stderr=subprocess.DEVNULL
)
return output.decode("utf-8").split()[0].strip()
except (subprocess.CalledProcessError, IndexError):
pass
try:
s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
s.connect(("8.8.8.8", 80))
ip = s.getsockname()[0]
s.close()
return ip
except Exception:
return None
def patch_ipa(ipa_file, deb_file, output_ipa):
print(f"\n[+] Patching IPA with cyan using {os.path.basename(deb_file)}...")
try:
subprocess.run(
[
"cyan",
"-i",
ipa_file,
"-o",
output_ipa,
"-f",
deb_file,
"-u",
"--overwrite",
],
check=True,
)
print("[+] Patch complete.")
return True
except subprocess.CalledProcessError:
print("[-] Patch failed.")
return False
except FileNotFoundError:
print(
"[-] 'cyan' command not found. Please ensure it is installed and in your PATH."
)
return False
def get_newest_deb(directory):
deb_files = glob.glob(os.path.join(directory, "*.deb"))
if not deb_files:
return None
return max(deb_files, key=os.path.getmtime)
def start_server(out_dir):
server_process = subprocess.Popen(
[sys.executable, "-m", "http.server", "8000", "--directory", out_dir]
)
return server_process
def main():
if len(sys.argv) != 3:
print(f"Usage: {os.path.basename(sys.argv[0])} <file.ipa> <file.deb>")
sys.exit(1)
ipa_file = None
initial_deb_file = None
for arg in sys.argv[1:]:
if arg.endswith(".ipa"):
ipa_file = arg
elif arg.endswith(".deb"):
initial_deb_file = arg
else:
print(f"Unknown file type: {arg}")
sys.exit(1)
if not ipa_file or not initial_deb_file:
print("You must provide one .ipa and one .deb file.")
sys.exit(1)
out_dir = "/tmp/ipa_patched"
os.makedirs(out_dir, exist_ok=True)
ipa_name = os.path.basename(ipa_file)
output_ipa = os.path.join(out_dir, ipa_name)
deb_dir = os.path.dirname(os.path.abspath(initial_deb_file))
current_deb_file = get_newest_deb(deb_dir) or initial_deb_file
last_mtime = (
os.path.getmtime(current_deb_file) if os.path.exists(current_deb_file) else 0
)
if not patch_ipa(ipa_file, current_deb_file, output_ipa):
sys.exit(1)
local_ip = get_local_ip() or "YOUR_IP"
download_link = f"http://{local_ip}:8000/{ipa_name}"
print()
print("==========================================")
print("Download link:")
print(download_link)
print("==========================================")
print()
try:
if shutil.which("pbcopy"):
subprocess.run(["pbcopy"], input=download_link.encode("utf-8"), check=True)
print("[+] Download link copied to clipboard.")
except Exception:
pass
print("[+] Starting HTTP server...")
server_process = start_server(out_dir)
print(f"[+] Watching for new .deb files in {deb_dir} every 2 seconds...")
print("Press Ctrl+C to stop.")
try:
while True:
time.sleep(2)
newest_deb = get_newest_deb(deb_dir)
if newest_deb:
current_mtime = os.path.getmtime(newest_deb)
if current_mtime > last_mtime:
print(
f"\n[*] Detected new/updated .deb file: {os.path.basename(newest_deb)}"
)
patch_ipa(ipa_file, newest_deb, output_ipa)
last_mtime = current_mtime
except KeyboardInterrupt:
print("\nStopping HTTP server and watcher...")
server_process.terminate()
server_process.wait()
if __name__ == "__main__":
main()