Skip to content

Instantly share code, notes, and snippets.

@sharklatan
sharklatan / untether.txt
Created September 24, 2021 18:32 — forked from spacepilotAV/untether.txt
better release tomorrow, but for now, i'll release part of the method.
i'll do a better release tomorrow or something, but to keep my promise, here's a gist
bug2:
platform-application bypass,
/usr/bin/fileproviderctl is a binary with a purpose i'm not sure of, however, it executes /usr/local/bin/fileproviderctl_internal when run
make /usr/local/bin/fileproviderctl_internal a symlink to your code to execute, and replace a daemon with /usr/bin/fileproviderctl
recommended to use wifiFirmwareLoader, and SUID fileproviderctl with mobile:mobile (if it runs as root containermanagerd has a seizure)
boom, BFU code exec on >11.xish -> 14.xish
bug3:
platform-application bypass,

Keybase proof

I hereby claim:

  • I am sharklatan on github.
  • I am sharklatan (https://keybase.io/sharklatan) on keybase.
  • I have a public key ASBrk3NDhOzX6cLLPhNFrsnqyMnYPReZhsrm3JZk3CmxNAo

To claim this, I am signing this object: