matteyeux Profile Banner
matteyeux Profile
matteyeux

@matteyeux

Followers
10K
Following
8K
Media
3K
Statuses
28K

https://t.co/RanRs3b58V

Joined April 2011
Don't wanna be here? Send us removal request.
@matteyeux
matteyeux
5 years
Here is an iPhone 7 booting Android !
181
2K
5K
@matteyeux
matteyeux
1 year
Looks like someone dropped a Linux kernel 0day .
Tweet media one
39
504
3K
@matteyeux
matteyeux
3 months
Changed IDA icons to make it feel a bit more modern
Tweet media one
32
98
1K
@matteyeux
matteyeux
2 years
I still find this funny that Apple keeps adding this stop sign on some rkos fw even on the Vision Pro one
Tweet media one
8
94
946
@matteyeux
matteyeux
7 years
@nixcraft Reminds me this comic from @CommitStrip
6
219
665
@matteyeux
matteyeux
5 years
Patched version of checkra1n + working KPF on iPhone 7/14.0 (no sep stuff)
Tweet media one
55
92
634
@matteyeux
matteyeux
4 years
Pangu Team showed iOS 15 beta 4 jailbreak on iPhone 11 Pro at MOSEC.
41
55
450
@matteyeux
matteyeux
5 years
Attack Secure Boot of SEP.
Tweet media one
4
117
378
@matteyeux
matteyeux
6 years
George Hotz | Programming | Exploring checkm8: a brand new iOS bootrom exploit by axi0mX.
1
78
382
@matteyeux
matteyeux
1 year
Seems like someone pushed a bunch of iBoot symbols to Hexrays's Lumina server
Tweet media one
9
56
384
@matteyeux
matteyeux
4 years
Nice, this 14.3 exploit works on A13 without any changes
Tweet media one
17
36
335
@matteyeux
matteyeux
3 years
Another checkm8 exploit 😄.
19
74
323
@matteyeux
matteyeux
5 years
iPhone 11(Pro) SecureROM
Tweet media one
13
39
317
@matteyeux
matteyeux
4 years
A15 SecureROM exploit .
Tweet media one
15
55
308
@matteyeux
matteyeux
5 years
Jailbreaks Never Die: Exploiting iOS 13.7 (slides).
8
72
293
@matteyeux
matteyeux
4 years
Linux kernel source tree for Apple M1 .
1
65
287
@matteyeux
matteyeux
1 year
Well, a decryption tool is now available .
@matteyeux
matteyeux
1 year
It looks like iOS 18 OTA firmware images are now encrypted
Tweet media one
0
62
291
@matteyeux
matteyeux
4 years
How to decompress iOS 14.3 sep-firmware for A10 :.1. decrypt file.2. extract compressed part : dd if=sep-firmware.d10.RELEASE.im4p.dec of=sep.compressed skip=65536 bs=1.3. decompress with lzvn : ./lzvn -d sep.compressed sep.bin
Tweet media one
5
78
274
@matteyeux
matteyeux
4 years
Emmutaler: Fuzzing the iOS Boot Loader.
2
76
271
@matteyeux
matteyeux
6 years
SSD Advisory – iOS Jailbreak via Sandbox Escape and Kernel R/W leading to RCE.
5
90
251
@matteyeux
matteyeux
6 years
iOS 11.3.1 exploit.
3
95
238
@matteyeux
matteyeux
3 months
Looks like someone got a 0day burned ?
Tweet media one
@zerozenxlabs
ZeroZenX
3 months
🚨 $1,000,000 Bounty for iOS Zero-Day! 🚨. ZeroZenX is offering a $1M reward for a working zero-day exploit that bypasses USB Restricted Mode on the latest version of iOS. If you’re a top-tier security researcher and have a reliable exploit, we want to hear from you!. 💰.
2
24
253
@matteyeux
matteyeux
5 years
Fugu
Tweet media one
16
23
219
@matteyeux
matteyeux
6 years
PoC tool for setting nonce without triggering KPP/KTRR/PAC. (requires tfp0).
7
58
234
@matteyeux
matteyeux
3 years
[Slides] The hitchhacker’s guide to.iPhone Lightning & JTAG hacking.
6
80
241
@matteyeux
matteyeux
7 years
CVE-2018-4280: Mach port replacement vulnerability in launchd on iOS 11.2.6 leading to sandbox escape, privilege escalation, and codesigning bypass.
2
74
230
@matteyeux
matteyeux
5 years
also A11 on 14.2b2
Tweet media one
19
37
210
@matteyeux
matteyeux
4 years
Reverse Engineering the M1.
6
68
223
@matteyeux
matteyeux
4 years
iOS 15 (19A5261w) .iBoot : iBoot-7429.0.72.112.2.Kernel : Darwin Kernel Version 21.0.0: Sat May 22 02:37:35 PDT 2021; root:xnu-7938.0.0.112.1~5/RELEASE_ARM64_T8030.
7
19
201
@matteyeux
matteyeux
6 years
Recreating an iOS 0-day jailbreak out of Apple’s security patches.
2
53
212
@matteyeux
matteyeux
8 years
Wipe and reinstall a running Linux system via SSH, without rebooting. You know you want to.
4
83
199
@matteyeux
matteyeux
5 years
Spotted that iPhone prototype ? :P
Tweet media one
13
31
196
@matteyeux
matteyeux
6 years
Wen ETA Redsn0w for iPhone X.
9
19
186
@matteyeux
matteyeux
4 years
Exploiting checkm8 with unknown SecureROM for the T2 chip.
4
67
205
@matteyeux
matteyeux
5 years
Here is checkra1n web interface
Tweet media one
9
25
191
@matteyeux
matteyeux
7 years
The making of an iOS 11 jailbreak - Kiddie to kernel hacker in 14 sleepless nights .
1
92
201
@matteyeux
matteyeux
5 years
I don't even know how to use an Android phone.
8
5
199
@matteyeux
matteyeux
4 years
iOS 15.0 RC (19A344) iBoot d53g .f616222bda5f10aadc5dd206c4cfb9dd9f287480e05bb40a61f6b6220412e7b01a7358245838fe2ce2dcce179341bbe3
Tweet media one
1
31
197
@matteyeux
matteyeux
11 months
Unstripped SPTM found in the wild👀
Tweet media one
10
27
203
@matteyeux
matteyeux
5 years
Checkra1n command line version
Tweet media one
4
30
186
@matteyeux
matteyeux
2 years
wInd3x, the iPod Bootrom exploit 10 years too late
6
61
193
@matteyeux
matteyeux
5 years
@RazMashat From mosec account on Weibo.
Tweet media one
5
47
189
@matteyeux
matteyeux
5 years
iOS 13.3.1. (17D6050) Homepod iBoot. bae48ea04ae32b1cb8c17c9b4120ef332b7aa58fae9a0f4393f3698799b02a4de497b0ca369b450c2ab27e7fa2d1701c
Tweet media one
7
27
193
@matteyeux
matteyeux
6 years
get tfp0 on iOS 11.2 - 12.1.2.
2
42
180
@matteyeux
matteyeux
6 years
A bunch of links related to VMware escape exploits.
1
109
188
@matteyeux
matteyeux
1 year
It looks like iOS 18 OTA firmware images are now encrypted
Tweet media one
7
12
188
@matteyeux
matteyeux
5 years
Accelerating iOS on QEMU with hardware virtualization (KVM).
1
63
183
@matteyeux
matteyeux
5 years
Since checkra1n 0.9.8.1 you can access AES engine from userland to decrypt kbags. I updated autodecrypt to grab keys from a device
Tweet media one
7
25
178
@matteyeux
matteyeux
5 years
Here is a script to split 64 bits Mach-O files from a decrypted sep-firmware (A11+).
Tweet media one
5
39
184
@matteyeux
matteyeux
4 years
Apple added firebloom 🔥🌸 in A12 (except TV) and A12X iBoot in iOS 14.5
Tweet media one
5
27
166
@matteyeux
matteyeux
5 years
So the vulnerability announced at #MOSEC2020 is in SEPROM. It can't be patched.
5
32
172
@matteyeux
matteyeux
3 years
Mandatory step: open twitter[.]com and brag about Linux on Apple, because internet
Tweet media one
3
9
168
@matteyeux
matteyeux
2 years
Rootful version of Fugu15.
10
47
173
@matteyeux
matteyeux
1 year
Apple Security Research Device Picture Gallery.
Tweet media one
4
17
166
@matteyeux
matteyeux
5 years
To decrypt sep kbag with checkra1n 0.12.0 :.- sep auto.- sep decrypt <kbag>
Tweet media one
6
27
166
@matteyeux
matteyeux
4 years
Another iBoot/SecureROM loader for IDA Pro.
2
31
169
@matteyeux
matteyeux
4 years
checkra1n does not work on iOS 15.0/iPhone 7
Tweet media one
7
20
158
@matteyeux
matteyeux
4 years
Nice to see that A14 SecureROM and SEPROM available on !
Tweet media one
4
32
165
@matteyeux
matteyeux
5 years
@blue_kanikama @jon_prosser iPhone SDKs have always been named iPhoneOS
Tweet media one
2
18
161
@matteyeux
matteyeux
7 years
6
21
161
@matteyeux
matteyeux
7 years
Here we are, thanks @tihmstar my iPhone 5C is now jailbroken for life
Tweet media one
Tweet media two
9
10
153
@matteyeux
matteyeux
2 years
I finally have a working setup with the Raspberry Pico and the tamarin fw
Tweet media one
11
16
159
@matteyeux
matteyeux
4 years
Security Research Device Cohort .
Tweet media one
4
24
157
@matteyeux
matteyeux
5 years
iOS Dual Booting Demystified.
0
37
150
@matteyeux
matteyeux
5 years
MagicCFG working without DCSD ✅
Tweet media one
27
31
137
@matteyeux
matteyeux
7 years
PoC for the iOS 11.4.1 and MacOS 10.13 kernel vulnerability in lio_listio.
12
69
150
@matteyeux
matteyeux
5 years
@YellowDinouse Malware.
8
5
145
@matteyeux
matteyeux
6 years
No, you can't get tfp0 with the FaceTime bug.
7
16
139
@matteyeux
matteyeux
7 years
Is jailbreak still dying ? This month we got : .- Houdini.- v0rtex.- Ian Beer's tfp0 + kdbg.- JailbreakMe for 32bits devices.
7
39
143
@matteyeux
matteyeux
4 years
Replay of the iPhone 13 remote jailbreak demo by Pangu .
Tweet media one
1
31
145
@matteyeux
matteyeux
3 months
iPhone 16e IPSW firmware is available for download. C1 firmware : Firmware/c4000v59/Release/patched/ftab.bin. Uses cL4 kernel as expected
Tweet media one
3
14
152
@matteyeux
matteyeux
3 years
The qemu fork by @ntrung03 is pretty cool ! It's also possible to debug the A9 SecureROM in IDA 😁.
Tweet media one
1
31
146
@matteyeux
matteyeux
5 years
New blog post by Pangu Team .
5
40
146
@matteyeux
matteyeux
5 years
iOS 5 iBoot bug.
2
26
133
@matteyeux
matteyeux
3 years
So it's possible to boot Ubuntu initrd on iPhone 7
Tweet media one
7
7
143
@matteyeux
matteyeux
5 years
checkm8 PoC for macOS (T7000 only for now).
2
37
134
@matteyeux
matteyeux
7 years
iOS 11.2 kernel pointer disclosure introduced by Apple's Meltdown mitigation.
7
62
141
@matteyeux
matteyeux
3 years
My iPhone 14 Pro in DFU is detected as "Debug USB" 🤨
Tweet media one
9
9
136
@matteyeux
matteyeux
3 years
An iOS Kernel Patchfinder, supporting iOS 15. Used by Fugu15.
3
21
129
@matteyeux
matteyeux
3 years
iOS 16.0 - 20A5283p.iBoot-8419.0.42.112.1.Darwin Kernel Version 22.0.0: Thu May 26 20:49:02 PDT 2022; root:xnu-8792.0.50.112.3~4/RELEASE_ARM64_T8020.
4
17
132
@matteyeux
matteyeux
7 years
CVE-2017-13868: A fun XNU infoleak.
3
68
134
@matteyeux
matteyeux
6 years
Recreating An iOS 0-Day Jailbreak Out Of Apple's Security Updates.
1
34
132
@matteyeux
matteyeux
5 years
DEV iBoot + Diags with menu on iPhone 8
Tweet media one
Tweet media two
Tweet media three
8
16
126
@matteyeux
matteyeux
5 years
FYI : checkra1n does not support yet iOS 14 :P
Tweet media one
Tweet media two
7
19
130
@matteyeux
matteyeux
5 years
Based on @haiyuidesu's sephelper I made a SEPROM loader for Binary Ninja.
Tweet media one
9
29
130
@matteyeux
matteyeux
6 years
KTRR bypass analysis (in French) 😁
Tweet media one
7
12
127
@matteyeux
matteyeux
7 years
Was able to build multi_path last night (without dev cert)
Tweet media one
5
29
122
@matteyeux
matteyeux
6 years
Accessing physical memory on iOS.
3
28
120
@matteyeux
matteyeux
4 years
Demo exploit code for CVE-2020-27904, a tfp0 bug.
2
38
123
@matteyeux
matteyeux
7 years
iOS 11.4.1 unstripped kernels.
4
39
115
@matteyeux
matteyeux
2 years
iBoot* for n301 (Apple Vision Pro). 1.0 - 21N5165g. e93c560966ad2d584c5fb86f7c32ab2e003739b11d51fdddc3a76eed70ae05422419d89983a4b796d3b68f9ec82c0370. *iBEC.n301.RELEASE.im4p
Tweet media one
0
17
119
@matteyeux
matteyeux
7 years
A tool for analyzing and find vulnerabilities in macOS and iOS kernel drivers.
1
41
120
@matteyeux
matteyeux
5 years
Real question is : can we use checkra1n for Linux on an iPhone running Linux.
Linux on T8010 via PongoOS :) /cc @CorelliumHQ @never_released
Tweet media one
Tweet media two
4
3
108
@matteyeux
matteyeux
5 years
checkm8 port for S5L8940X/S5L8942X/S5L8945X.
6
27
112
@matteyeux
matteyeux
8 years
An iOS kernel exploit designated to work on all iOS devices <= 10.3.1.
4
72
122
@matteyeux
matteyeux
7 months
Interesting talk about ITW exploit chains caught by Google TAG. No surprise, they use Google's internal resources and Chrome crash dumps to catch exploits.
0
36
120
@matteyeux
matteyeux
6 years
Technical analysis of the checkm8 exploit
1
33
112
@matteyeux
matteyeux
6 years
Mapping physical memory to user space (EL0) on iOS. (+ AES PoC)
3
31
111
@matteyeux
matteyeux
5 years
Twitter does not allow anymore to tweet hashes. So it's not possible to publish iOS bootloader keys here ¯\_(ツ)_/¯
Tweet media one
5
4
113
@matteyeux
matteyeux
2 years
CVE-2023-4863: Heap buffer overflow in WebP. Reported by Apple SEAR and CitizenLab. Seems to be one of the bugs in ImageIO exploited in the latest iMessage exploit chain (BLASTPASS).
2
30
115