Pinned Repositories
brutenonce
An OpenCL implementation of the SHA-1 for brute forcing iBoot's cryptographic nonce.
dimentio
Tool for getting and setting nonce without triggering KPP/KTRR/PAC.
eclipsa
Checkm8 PoC tool for A8, A8X and A9 devices that allows you to boot untrusted images (macOS only, credits: checkra1n team).
gaster
Checkm8 experiment to understand AP/SEP internals.
golb
Mapping physical memory to user space (EL0) on iOS.
iBootMaybeDumper
See https://github.com/0x7ff/iBootMaybeDumper/issues/1#issuecomment-426731516 for more info.
kextract
A tool for extracting kernel extensions from the iOS 12's new kernelcache format.
maphys
Accessing physical memory on iOS.
vtable
A tool for reversing IOKit classes from the iOS 12's new kernelcache format.
xpcy
A tool for listing/reversing XPC services inside container sandbox. Reference: https://www.blackhat.com/docs/us-15/materials/us-15-Wang-Review-And-Exploit-Neglected-Attack-Surface-In-iOS-8.pdf
0x7ff's Repositories
0x7ff/gaster
Checkm8 experiment to understand AP/SEP internals.
0x7ff/dimentio
Tool for getting and setting nonce without triggering KPP/KTRR/PAC.
0x7ff/eclipsa
Checkm8 PoC tool for A8, A8X and A9 devices that allows you to boot untrusted images (macOS only, credits: checkra1n team).
0x7ff/golb
Mapping physical memory to user space (EL0) on iOS.
0x7ff/maphys
Accessing physical memory on iOS.
0x7ff/vtable
A tool for reversing IOKit classes from the iOS 12's new kernelcache format.
0x7ff/xpcy
A tool for listing/reversing XPC services inside container sandbox. Reference: https://www.blackhat.com/docs/us-15/materials/us-15-Wang-Review-And-Exploit-Neglected-Attack-Surface-In-iOS-8.pdf
0x7ff/iBootMaybeDumper
See https://github.com/0x7ff/iBootMaybeDumper/issues/1#issuecomment-426731516 for more info.
0x7ff/kextract
A tool for extracting kernel extensions from the iOS 12's new kernelcache format.
0x7ff/brutenonce
An OpenCL implementation of the SHA-1 for brute forcing iBoot's cryptographic nonce.
0x7ff/sandy
A WIP program for reversing iOS 10+ binary sandbox profiles.
0x7ff/bitamin