This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
/** | |
* bling.js | |
*/ | |
window.$ = document.querySelectorAll.bind(document); | |
window.$id = document.getElementById.bind(document); | |
Array.prototype.each = Array.prototype.forEach; | |
NodeList.prototype.__proto__ = Array.prototype; | |
NodeList.prototype.on = function(name, delegate, fn) { |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
[ | |
{ | |
"idYear": "11", | |
"idBase": 249, | |
"zdiId": "ZDI-11-249", | |
"zdiCan": "ZDI-CAN-1159", | |
"affectedVendors": "Microsoft", | |
"cve": "CVE-2011-1347", | |
"publishDate": "2011-08-09", | |
"lastUpdate": "", |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
LOCAL_PATH := $(call my-dir) | |
include $(CLEAR_VARS) | |
LOCAL_MODULE := loader | |
LOCAL_MODULE_TAGS := optional | |
LOCAL_SRC_FILES := loader.c | |
LOCAL_CPPFLAGS := -std=gnu++0x -Wall | |
LOCAL_LDLIBS := -L$(SYSROOT)/usr/lib -llog -pie -fPIE |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
WITH RECURSIVE | |
unhex(str, val, weight) AS ( | |
SELECT 'deadbeef', 0, 1 | |
UNION ALL | |
SELECT | |
substr(str, 1, length(str) - 1), | |
val + (instr('0123456789ABCDEF', substr(str, length(str), 1)) - 1) * weight, | |
weight * 16 | |
FROM unhex WHERE length(str) > 0 | |
) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
/** | |
* requires node.js with ES6 support, or babel | |
*/ | |
'use strict'; | |
const vm = require('vm'); | |
const fs = require('fs'); | |
const __loggers__ = {}; | |
function log(tag) { |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
// to speed up, I removed all data validation | |
function MemoryBuffer(address, size) { | |
this.base = address | |
if (!size) { | |
// const range = Process.findRangeByAddress(address) | |
// if (!range) | |
// throw new Error('invalid address: ' + address) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/usr/bin/env python3 | |
import struct | |
import lief | |
from lief.MachO import LOAD_COMMAND_TYPES, HEADER_FLAGS | |
def check(filename): | |
macho = lief.parse(filename) | |
# check this? |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import os | |
# preinstalled python is python2 | |
filename = '/'.join(map(os.environ.get, ('TARGET_TEMP_DIR', 'FULL_PRODUCT_NAME'))) + '.xcent' | |
evil = ''' | |
<!---><!--> | |
<key>platform-application</key> | |
<true/> | |
<key>com.apple.private.security.no-container</key> | |
<true/> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
// frida -U --attach-frontmost -l awake.js | |
ObjC.schedule(ObjC.mainQueue, () => { | |
try { | |
ObjC.classes.UIApplication.sharedApplication().setIdleTimerDisabled_(ptr(1)) | |
} finally { | |
} | |
}) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import asyncio | |
import concurrent.futures | |
import frida | |
pool = concurrent.futures.ThreadPoolExecutor(max_workers=4) | |
def make_handler(dev: frida.core.Device, port:int, buffer_size=4096): | |
async def handler(reader, writer): |
NewerOlder