
john
@nyan_satan
Followers
17K
Following
1K
Media
425
Statuses
4K
demonic beast from another era (with F20.0) | https://t.co/W7w9FmL4Fd
Joined October 2015
@DylangerDaly No, it’s much easier and at the same time much darker - I have got some prototype Apple devices that have unlocked JTAG.
2
4
343
There's a bug in A6 SecureROM in Image3 parser, that allows both tethered and untethered code execution. @iH8sn0w found it back in 2015. I tried to find it too, decompiled most of the Image3 stack in that ROM, but couldn't find anything useful, only memory leak and other nonsense.
4
38
222
USB-C Diagnostic Doom. 4 bytes patch, 32 bits CRC fix, 0 hardware modifications, same result
I recently found that it is possible to convert the Apple "USB-C Diagnostic Tool" (available for any AASP to purchase) into the device it's based on, the "Chimp" USB-C debugging probe! Here's a quick video on what needs to be done. #appleinternal
4
17
193
checkm8_bootkit - a little program of mine that allows booting an iBSS on some cursed platforms with no patch to ipwndfu:. S5L8747X - Haywire.S5L8947X - Apple TV 3 (3,2). If anyone needs this, I can publish with minor improvements. (thanks to @1nsane_dev for this *insane* iBSS!)
8
23
157
Flashing iOS 6.1.3 bootchain over iOS 9.3.5’ on n94ap — untethered, without restore. Might be useful for #derebusantiquis
7
22
145
The absolutely best device ever!. N78 PROTO1. Produced in the very beginning of 2012. Runs Sundance10A219.iPodtouchFactoryOS (iBoot-1470). Apparently has a faulty Tristar, but still I managed to get USB and charging. Huge thanks to @MrWhite128 for providing me with this unit!
2
13
144
Created a little kit to decrypt KBAGs with JTAGable prototype devices (newer ones - A12+) in easy and fast manner:. Basically, you need JTAG only for initial setup and after that it's plain USB. SEP eta son. Thanks to @axi0mX for the idea of replacing handle_interface_request()!
8
22
120
N18EVTa - iPod touch 3 with an unreleased camera. It has an early revision of the SoC with an early version of SecureROM - iBoot-359.4 - which still has 24kpwn and alloc8 bugs, though they are not exploitable on this device. Huge thanks to @1nsane_dev for gifting this unit!
3
8
125
Finally managed to fix my old 1st-gen Kong (all-white)!. From a useless cable with a dead FW to a fully working probe that can provide power, USB, UART and SWD. Wouldn't be possible without help from @iRazGAr and @chiptunext . If anyone's interested, I can make an article/thread
13
8
104