mirror of
https://github.com/NohamR/pyzule-rw.git
synced 2026-10-11 02:49:40 +00:00
Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
edd34f6713 | ||
|
|
c1c0b2294e | ||
|
|
2d16015c78 | ||
|
|
4c979a91e7 | ||
|
|
b4aa6c9b69 | ||
|
|
246f6ace80 | ||
|
|
511cb4bbe3 |
22
.github/ISSUE_TEMPLATE/bug.yaml
vendored
Normal file
22
.github/ISSUE_TEMPLATE/bug.yaml
vendored
Normal file
@@ -0,0 +1,22 @@
|
||||
# thanks to uYouEnhanced for the issue template:
|
||||
# https://github.com/arichornlover/uYouEnhanced/blob/main/.github/ISSUE_TEMPLATE/bug.yaml?plain=1
|
||||
|
||||
name: bug
|
||||
description: report a bug in cyan
|
||||
title: "[bug] "
|
||||
labels: bug
|
||||
body:
|
||||
- type: checkboxes
|
||||
attributes:
|
||||
label: have you searched the existing issues?
|
||||
options:
|
||||
- label: this is a unique issue. i agree that if this isn't a unique issue, i'll be BLOCKED from the cyan repo
|
||||
required: true
|
||||
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: describe the bug.
|
||||
description: attach videos or screenshots if possible
|
||||
validations:
|
||||
required: true
|
||||
|
||||
22
.github/ISSUE_TEMPLATE/feature_request.yaml
vendored
Normal file
22
.github/ISSUE_TEMPLATE/feature_request.yaml
vendored
Normal file
@@ -0,0 +1,22 @@
|
||||
# thanks to uYouEnhanced for the issue template:
|
||||
# https://github.com/arichornlover/uYouEnhanced/blob/main/.github/ISSUE_TEMPLATE/bug.yaml?plain=1
|
||||
|
||||
name: feature request
|
||||
description: request a feature to be added to cyan
|
||||
title: "[feature request] "
|
||||
labels: enhancement
|
||||
body:
|
||||
- type: checkboxes
|
||||
attributes:
|
||||
label: have you searched the existing issues?
|
||||
options:
|
||||
- label: this is a unique feature request. i agree that if this isn't a unique request, i'll be BLOCKED from the cyan repo
|
||||
required: true
|
||||
|
||||
- type: textarea
|
||||
attributes:
|
||||
label: describe the feature request.
|
||||
description: what exactly are you requesting? can you provide an example where this would be useful?
|
||||
validations:
|
||||
required: true
|
||||
|
||||
@@ -4,7 +4,7 @@ a rewrite of [pyzule](https://github.com/asdfzxcvbn/pyzule) that doesn't (comple
|
||||
|
||||
## features
|
||||
|
||||
you can open an issue to request a feature :D !!
|
||||
you can open an issue to request a feature :D !! also see my [recommended flags](https://github.com/asdfzxcvbn/pyzule-rw/wiki/recommended-flags)
|
||||
|
||||
- generate and use shareable .cyan files to configure IPAs!
|
||||
- inject deb, dylib, framework, bundle, and appex files/folders
|
||||
@@ -15,6 +15,7 @@ you can open an issue to request a feature :D !!
|
||||
- remove watch app
|
||||
- change the app icon
|
||||
- fakesign the output ipa/app
|
||||
- add custom entitlements to the main executable
|
||||
- thin all binaries to arm64, it can LARGELY reduce app size sometimes!
|
||||
- remove all app extensions (or just encrypted ones!)
|
||||
|
||||
@@ -26,6 +27,8 @@ first, make sure you have [ar](https://command-not-found.com/ar) and [tar](https
|
||||
|
||||
also obviously install python, version 3.9 or greater is required
|
||||
|
||||
the `zip` and `unzip` commands are *optional* dependencies, they may [fix issues when extracting certain IPAs with chinese characters](https://github.com/asdfzxcvbn/pyzule-rw/wiki/file-does-not-exist-(executable)-%3F), etc
|
||||
|
||||
<details>
|
||||
<summary><b>linux/WSL/macOS instructions</b></summary>
|
||||
<br/>
|
||||
|
||||
@@ -50,6 +50,10 @@ def main() -> None:
|
||||
"-k", metavar="icon",
|
||||
help="modify the app's icon"
|
||||
)
|
||||
parser.add_argument(
|
||||
"-x", metavar="entitlements",
|
||||
help="add or modify entitlements to the main binary"
|
||||
)
|
||||
|
||||
parser.add_argument(
|
||||
"-u", "--remove-supported-devices", action="store_true",
|
||||
@@ -95,7 +99,7 @@ def main() -> None:
|
||||
)
|
||||
|
||||
parser.add_argument(
|
||||
"--version", action="version", version="cyan v1.1.5"
|
||||
"--version", action="version", version="cyan v1.2"
|
||||
)
|
||||
|
||||
from cyan import logic
|
||||
|
||||
@@ -4,24 +4,34 @@
|
||||
<dict>
|
||||
<key>CFBundleDevelopmentRegion</key>
|
||||
<string>English</string>
|
||||
|
||||
<key>CFBundleExecutable</key>
|
||||
<string>Cephei</string>
|
||||
|
||||
<key>CFBundleIdentifier</key>
|
||||
<string>ws.hbang.common</string>
|
||||
|
||||
<key>CFBundleInfoDictionaryVersion</key>
|
||||
<string>6.0</string>
|
||||
|
||||
<key>CFBundleName</key>
|
||||
<string>Cephei</string>
|
||||
|
||||
<key>CFBundlePackageType</key>
|
||||
<string>BNDL</string>
|
||||
|
||||
<key>CFBundleShortVersionString</key>
|
||||
<string>1.0.0</string>
|
||||
|
||||
<key>CFBundleSignature</key>
|
||||
<string>????</string>
|
||||
|
||||
<key>CFBundleVersion</key>
|
||||
<string>1.0</string>
|
||||
|
||||
<key>DTPlatformName</key>
|
||||
<string>iphoneos</string>
|
||||
|
||||
<key>HBPackageIdentifier</key>
|
||||
<string>ws.hbang.common</string>
|
||||
</dict>
|
||||
|
||||
@@ -4,26 +4,37 @@
|
||||
<dict>
|
||||
<key>CFBundleDevelopmentRegion</key>
|
||||
<string>English</string>
|
||||
|
||||
<key>CFBundleExecutable</key>
|
||||
<string>CepheiPrefs</string>
|
||||
|
||||
<key>CFBundleIdentifier</key>
|
||||
<string>ws.hbang.common.prefs</string>
|
||||
|
||||
<key>CFBundleInfoDictionaryVersion</key>
|
||||
<string>6.0</string>
|
||||
|
||||
<key>CFBundleName</key>
|
||||
<string>Cephei</string>
|
||||
|
||||
<key>CFBundlePackageType</key>
|
||||
<string>BNDL</string>
|
||||
|
||||
<key>CFBundleShortVersionString</key>
|
||||
<string>1.0.0</string>
|
||||
|
||||
<key>CFBundleSignature</key>
|
||||
<string>????</string>
|
||||
|
||||
<key>CFBundleVersion</key>
|
||||
<string>1.0</string>
|
||||
|
||||
<key>DTPlatformName</key>
|
||||
<string>iphoneos</string>
|
||||
|
||||
<key>HBPackageIdentifier</key>
|
||||
<string>ws.hbang.common</string>
|
||||
|
||||
<key>NSPrincipalClass</key>
|
||||
<string>HBDemoRootListController</string>
|
||||
</dict>
|
||||
|
||||
Binary file not shown.
@@ -61,6 +61,8 @@ def main(parser: ArgumentParser) -> None:
|
||||
app.plist.change_minimum_version(args.m)
|
||||
if args.k is not None:
|
||||
app.change_icon(args.k, tmpdir)
|
||||
if args.x is not None: # `validate_inputs()` made it a dict
|
||||
app.executable.merge_entitlements(args.x, tmpdir)
|
||||
|
||||
if args.remove_supported_devices:
|
||||
app.plist.remove_uisd()
|
||||
|
||||
@@ -1,12 +1,14 @@
|
||||
from .app_bundle import AppBundle
|
||||
from .executable import Executable
|
||||
from .leaving_cm import LeavingCM
|
||||
from .main_executable import MainExecutable
|
||||
from .plist import Plist
|
||||
|
||||
__all__ = [
|
||||
"AppBundle",
|
||||
"Executable",
|
||||
"LeavingCM",
|
||||
"MainExecutable",
|
||||
"Plist"
|
||||
]
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@ from uuid import uuid4
|
||||
from typing import Optional, Literal
|
||||
|
||||
from .executable import Executable
|
||||
from .main_executable import MainExecutable
|
||||
from .plist import Plist
|
||||
|
||||
class AppBundle:
|
||||
@@ -12,7 +13,7 @@ class AppBundle:
|
||||
self.path = path
|
||||
self.plist = Plist(f"{path}/Info.plist", path)
|
||||
|
||||
self.executable = Executable(
|
||||
self.executable = MainExecutable(
|
||||
f"{path}/{self.plist['CFBundleExecutable']}",
|
||||
path
|
||||
)
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import os
|
||||
import sys
|
||||
import shutil
|
||||
import subprocess
|
||||
from typing import Optional
|
||||
|
||||
@@ -33,12 +32,16 @@ class Executable:
|
||||
"CepheiPrefs.framework": "CepheiPrefs.framework"
|
||||
}
|
||||
|
||||
def __init__(self, path: str, bundle_path: Optional[str] = None):
|
||||
def __init__(self, path: str):
|
||||
if not os.path.isfile(path):
|
||||
sys.exit(f"[!] {path} does not exist (executable)")
|
||||
print(f"[!] {path} does not exist (executable)", file=sys.stderr)
|
||||
sys.exit(
|
||||
"[?] check the wiki for info: "
|
||||
"https://github.com/asdfzxcvbn/pyzule-rw/wiki/"
|
||||
"file-does-not-exist-(executable)-%3F"
|
||||
)
|
||||
|
||||
self.path = path
|
||||
self.bundle_path = bundle_path
|
||||
|
||||
self.bn = os.path.basename(path)
|
||||
self.inj: Optional = None # type: ignore
|
||||
@@ -56,16 +59,14 @@ class Executable:
|
||||
|
||||
return b"cryptid 1" in proc.stdout
|
||||
|
||||
def inject(self, tweaks: dict[str, str], tmpdir: str) -> None:
|
||||
# we only inject into the main executable
|
||||
assert self.bundle_path is not None
|
||||
def remove_signature(self) -> None:
|
||||
subprocess.run([self.ldid, "-R", self.path], stderr=subprocess.DEVNULL)
|
||||
|
||||
has_entitlements = False
|
||||
ENT_PATH = f"{self.bundle_path}/cyan.entitlements"
|
||||
PLUGINS_DIR = f"{self.bundle_path}/PlugIns"
|
||||
FRAMEWORKS_DIR = f"{self.bundle_path}/Frameworks"
|
||||
def fakesign(self) -> bool:
|
||||
return subprocess.run([self.ldid, "-S", "-M", self.path]).returncode == 0
|
||||
|
||||
with open(ENT_PATH, "wb") as entf:
|
||||
def write_entitlements(self, output: str) -> bool:
|
||||
with open(output, "wb") as entf:
|
||||
proc = subprocess.run(
|
||||
[self.ldid, "-e", self.path],
|
||||
capture_output=True
|
||||
@@ -73,98 +74,7 @@ class Executable:
|
||||
|
||||
entf.write(proc.stdout)
|
||||
|
||||
if os.path.getsize(ENT_PATH) > 0:
|
||||
has_entitlements = True
|
||||
|
||||
# iirc, injecting doesnt work (sometimes) if the file isn't signed
|
||||
self.remove_signature()
|
||||
|
||||
if any(t.endswith(".appex") for t in tweaks):
|
||||
os.makedirs(PLUGINS_DIR, exist_ok=True)
|
||||
|
||||
if any(
|
||||
t.endswith(k)
|
||||
for t in tweaks
|
||||
for k in (".deb", ".dylib", ".framework")
|
||||
):
|
||||
os.makedirs(FRAMEWORKS_DIR, exist_ok=True)
|
||||
|
||||
# some apps really dont have this lol
|
||||
subprocess.run(
|
||||
[self.nt, "-add_rpath", "@executable_path/Frameworks", self.path],
|
||||
stderr=subprocess.DEVNULL
|
||||
)
|
||||
|
||||
# `extract_deb()` will modify `tweaks`, which is why we make a copy
|
||||
cwd = os.getcwd()
|
||||
for bn, path in dict(tweaks).items():
|
||||
if bn.endswith(".deb"):
|
||||
tbhutils.extract_deb(path, tweaks, tmpdir)
|
||||
continue
|
||||
os.chdir(cwd) # i fucking hate jailbroken iOS utils.
|
||||
|
||||
needed: set[str] = set()
|
||||
for bn, path in tweaks.items():
|
||||
if bn.endswith(".appex"):
|
||||
fpath = f"{PLUGINS_DIR}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
shutil.copytree(path, fpath)
|
||||
elif bn.endswith(".dylib"):
|
||||
path = shutil.copy2(path, tmpdir)
|
||||
Executable(path).fix_dependencies(tweaks, needed)
|
||||
|
||||
fpath = f"{FRAMEWORKS_DIR}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
self.inj_func(f"@rpath/{bn}")
|
||||
shutil.move(path, FRAMEWORKS_DIR)
|
||||
elif bn.endswith(".framework"):
|
||||
fpath = f"{FRAMEWORKS_DIR}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
self.inj_func(f"@rpath/{bn}/{bn[:-10]}")
|
||||
shutil.copytree(path, fpath)
|
||||
else:
|
||||
fpath = f"{self.bundle_path}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
try:
|
||||
shutil.copytree(path, fpath)
|
||||
except NotADirectoryError:
|
||||
shutil.copy2(path, self.bundle_path)
|
||||
|
||||
if not existed:
|
||||
print(f"[*] injected {bn}")
|
||||
|
||||
# orion has a *weak* dependency to substrate,
|
||||
# but will still crash without it. nice !!!!!!!!!!!
|
||||
if "Orion.framework" in needed:
|
||||
needed.add("CydiaSubstrate.framework")
|
||||
|
||||
for missing in needed:
|
||||
real = self.common[missing] # "real" name, thanks substrate!
|
||||
ip = f"{FRAMEWORKS_DIR}/{real}"
|
||||
existed = tbhutils.delete_if_exists(ip, real)
|
||||
shutil.copytree(f"{self.install_dir}/extras/{real}", ip)
|
||||
|
||||
if not existed:
|
||||
print(f"[*] auto-injected {real}")
|
||||
|
||||
# FINALLY !!
|
||||
if self.inj is not None: # type: ignore
|
||||
self.inj.write(self.path) # type: ignore
|
||||
|
||||
if has_entitlements:
|
||||
subprocess.run([self.ldid, f"-S{ENT_PATH}", self.path])
|
||||
print("[*] restored entitlements")
|
||||
|
||||
def remove_signature(self) -> None:
|
||||
subprocess.run([self.ldid, "-R", self.path], stderr=subprocess.DEVNULL)
|
||||
|
||||
def fakesign(self, keep_entitlements: bool = True) -> bool:
|
||||
cmd = [self.ldid, "-S"]
|
||||
if keep_entitlements:
|
||||
cmd.append("-M")
|
||||
|
||||
subprocess.run(cmd + [self.path])
|
||||
return True
|
||||
return os.path.getsize(output) > 0
|
||||
|
||||
def thin(self) -> bool:
|
||||
return subprocess.run(
|
||||
|
||||
124
cyan/tbhtypes/main_executable.py
Normal file
124
cyan/tbhtypes/main_executable.py
Normal file
@@ -0,0 +1,124 @@
|
||||
import os
|
||||
import shutil
|
||||
import plistlib
|
||||
import subprocess
|
||||
from typing import Any
|
||||
from plistlib import dump as pdump
|
||||
|
||||
from cyan import tbhutils
|
||||
from .executable import Executable
|
||||
|
||||
class MainExecutable(Executable):
|
||||
def __init__(self, path: str, bundle_path: str):
|
||||
super().__init__(path)
|
||||
self.bundle_path = bundle_path
|
||||
|
||||
def inject(self, tweaks: dict[str, str], tmpdir: str) -> None:
|
||||
ENT_PATH = f"{self.bundle_path}/cyan.entitlements"
|
||||
PLUGINS_DIR = f"{self.bundle_path}/PlugIns"
|
||||
FRAMEWORKS_DIR = f"{self.bundle_path}/Frameworks"
|
||||
has_entitlements = self.write_entitlements(ENT_PATH)
|
||||
|
||||
# iirc, injecting doesnt work (sometimes) if the file isn't signed
|
||||
self.remove_signature()
|
||||
|
||||
if any(t.endswith(".appex") for t in tweaks):
|
||||
os.makedirs(PLUGINS_DIR, exist_ok=True)
|
||||
|
||||
if any(
|
||||
t.endswith(k)
|
||||
for t in tweaks
|
||||
for k in (".deb", ".dylib", ".framework")
|
||||
):
|
||||
os.makedirs(FRAMEWORKS_DIR, exist_ok=True)
|
||||
|
||||
# some apps really dont have this lol
|
||||
subprocess.run(
|
||||
[self.nt, "-add_rpath", "@executable_path/Frameworks", self.path],
|
||||
stderr=subprocess.DEVNULL
|
||||
)
|
||||
|
||||
# `extract_deb()` will modify `tweaks`, which is why we make a copy
|
||||
cwd = os.getcwd()
|
||||
for bn, path in dict(tweaks).items():
|
||||
if bn.endswith(".deb"):
|
||||
tbhutils.extract_deb(path, tweaks, tmpdir)
|
||||
continue
|
||||
os.chdir(cwd) # i fucking hate jailbroken iOS utils.
|
||||
|
||||
needed: set[str] = set()
|
||||
for bn, path in tweaks.items():
|
||||
if bn.endswith(".appex"):
|
||||
fpath = f"{PLUGINS_DIR}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
shutil.copytree(path, fpath)
|
||||
elif bn.endswith(".dylib"):
|
||||
path = shutil.copy2(path, tmpdir)
|
||||
Executable(path).fix_dependencies(tweaks, needed)
|
||||
|
||||
fpath = f"{FRAMEWORKS_DIR}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
self.inj_func(f"@rpath/{bn}")
|
||||
shutil.move(path, FRAMEWORKS_DIR)
|
||||
elif bn.endswith(".framework"):
|
||||
fpath = f"{FRAMEWORKS_DIR}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
self.inj_func(f"@rpath/{bn}/{bn[:-10]}")
|
||||
shutil.copytree(path, fpath)
|
||||
else:
|
||||
fpath = f"{self.bundle_path}/{bn}"
|
||||
existed = tbhutils.delete_if_exists(fpath, bn)
|
||||
try:
|
||||
shutil.copytree(path, fpath)
|
||||
except NotADirectoryError:
|
||||
shutil.copy2(path, self.bundle_path)
|
||||
|
||||
if not existed:
|
||||
print(f"[*] injected {bn}")
|
||||
|
||||
# orion has a *weak* dependency to substrate,
|
||||
# but will still crash without it. nice !!!!!!!!!!!
|
||||
if "Orion.framework" in needed:
|
||||
needed.add("CydiaSubstrate.framework")
|
||||
|
||||
for missing in needed:
|
||||
real = self.common[missing] # "real" name, thanks substrate!
|
||||
ip = f"{FRAMEWORKS_DIR}/{real}"
|
||||
existed = tbhutils.delete_if_exists(ip, real)
|
||||
shutil.copytree(f"{self.install_dir}/extras/{real}", ip)
|
||||
|
||||
if not existed:
|
||||
print(f"[*] auto-injected {real}")
|
||||
|
||||
# FINALLY !!
|
||||
if self.inj is not None: # type: ignore
|
||||
self.inj.write(self.path) # type: ignore
|
||||
|
||||
if has_entitlements:
|
||||
self.sign_with_entitlements(ENT_PATH)
|
||||
print("[*] restored entitlements")
|
||||
|
||||
def merge_entitlements(
|
||||
self, entitlements: dict[str, Any], tmpdir: str
|
||||
) -> None:
|
||||
ENT_PATH = f"{tmpdir}/new.entitlements"
|
||||
existing: dict[str, Any]
|
||||
|
||||
if self.write_entitlements(ENT_PATH): # has entitlements
|
||||
with open(ENT_PATH, "rb") as f:
|
||||
existing = plistlib.load(f)
|
||||
else:
|
||||
existing = {}
|
||||
|
||||
new = existing | entitlements
|
||||
with open(ENT_PATH, "wb") as f2:
|
||||
pdump(new, f2)
|
||||
|
||||
self.sign_with_entitlements(ENT_PATH)
|
||||
print("[*] modified entitlement keys:", ", ".join(entitlements))
|
||||
|
||||
def sign_with_entitlements(self, entitlements: str) -> bool:
|
||||
return subprocess.run(
|
||||
[self.ldid, f"-S{entitlements}", self.path]
|
||||
).returncode == 0
|
||||
|
||||
@@ -9,6 +9,10 @@ from uuid import uuid4
|
||||
from glob import glob, iglob
|
||||
from argparse import Namespace
|
||||
from typing import Optional, Any
|
||||
from plistlib import load as pload
|
||||
|
||||
HAS_ZIP = shutil.which("zip") is not None
|
||||
HAS_UNZIP = shutil.which("unzip") is not None
|
||||
|
||||
|
||||
def validate_inputs(args: Namespace) -> Optional[str]:
|
||||
@@ -65,6 +69,16 @@ def validate_inputs(args: Namespace) -> Optional[str]:
|
||||
if args.cyan is not None and not os.path.isfile(args.cyan):
|
||||
sys.exit(f"[!] {args.cyan} does not exist")
|
||||
|
||||
if args.x is not None:
|
||||
if not os.path.isfile(args.x):
|
||||
sys.exit(f"[!] {args.x} does not exist")
|
||||
|
||||
try:
|
||||
with open(args.x, "rb") as f:
|
||||
args.x = pload(f)
|
||||
except Exception:
|
||||
sys.exit("[!] couldn't parse given entitlements file")
|
||||
|
||||
|
||||
def get_app(path: str, tmpdir: str, is_ipa: bool) -> str:
|
||||
payload = f"{tmpdir}/Payload"
|
||||
@@ -81,7 +95,15 @@ def get_app(path: str, tmpdir: str, is_ipa: bool) -> str:
|
||||
elif not any(name.endswith(".app/Info.plist") for name in names):
|
||||
sys.exit("[!] no Info.plist, invalid app")
|
||||
|
||||
# using unzip fixes extraction errors in ipas with chinese chars, etc
|
||||
if HAS_UNZIP:
|
||||
subprocess.run(
|
||||
["unzip", path, "-d", tmpdir],
|
||||
stdout=subprocess.DEVNULL
|
||||
)
|
||||
else:
|
||||
ipa.extractall(tmpdir)
|
||||
|
||||
app = glob(f"{payload}/*.app")[0]
|
||||
except (KeyError, IndexError):
|
||||
sys.exit("[!] couldn't find either Payload or app folder, invalid ipa")
|
||||
@@ -180,6 +202,17 @@ def make_ipa(tmpdir: str, output: str, level: int) -> None:
|
||||
os.chdir(tmpdir)
|
||||
weird = 0
|
||||
|
||||
if HAS_ZIP:
|
||||
try:
|
||||
os.remove(output) # zip command updates zipfiles by default
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
|
||||
subprocess.run(
|
||||
["zip", f"-{level}", "-r", output, "Payload"],
|
||||
stdout=subprocess.DEVNULL
|
||||
)
|
||||
else:
|
||||
with zipfile.ZipFile(
|
||||
output, "w", zipfile.ZIP_DEFLATED, compresslevel=level
|
||||
) as zf:
|
||||
|
||||
Reference in New Issue
Block a user