Difference between revisions of "User:Aker"

From The iPhone Wiki
Jump to: navigation, search
(Exploits which are used in order to jailbreak 8.x: DDI RC)
(Jailbreak Exploits: iOS 5)
Line 1: Line 1:
 
= Jailbreak Exploits =
 
= Jailbreak Exploits =
  +
  +
== Missing ==
  +
* UnthreadedJB
  +
  +
== Exploits which are used in order to jailbreak different versions of iOS ==
  +
* [[limera1n]]'s bootrom exploit + [[0x24000 Segment Overflow]] (together for [[untethered jailbreak]] on [[n88ap|iPhone 3GS]] with [[Bootrom 359.3|old bootrom]])
  +
* [[limera1n]]'s bootrom exploit (Tethered jailbreak) on [[n88ap|iPhone 3GS]] with [[Bootrom 359.3.2|new bootrom]], [[n18ap|iPod touch 3G]], [[k48ap|iPad]], [[iPhone 4]], and [[n81ap|iPod touch 4G]])
  +
  +
== Exploits which are used in order to jailbreak 5.x ==
  +
=== [[Absinthe]] (5.0 [[n94ap|iPhone 4S]] only / 5.0.1 [[iPad 2]] and [[iPhone 4S]]) ===
  +
* [[Racoon String Format Overflow Exploit]] (used both for payload injection and untether)
  +
* [[HFS Heap Overflow]]
  +
  +
=== [[Corona|Corona Untether]] (5.0.1) ===
  +
* [[Racoon String Format Overflow Exploit]]
  +
* [[HFS Heap Overflow]]
  +
  +
=== [[Absinthe|Absinthe 2.0]] (5.1.1) ===
  +
{{Section Stub}}
  +
* [[Rocky Racoon]]
  +
   
 
== Exploits which are used in order to jailbreak 6.x ==
 
== Exploits which are used in order to jailbreak 6.x ==

Revision as of 19:04, 2 December 2014

Jailbreak Exploits

Missing

  • UnthreadedJB

Exploits which are used in order to jailbreak different versions of iOS

Exploits which are used in order to jailbreak 5.x

Absinthe (5.0 iPhone 4S only / 5.0.1 iPad 2 and iPhone 4S)

Corona Untether (5.0.1)

Absinthe 2.0 (5.1.1)

This section is a stub; it is incomplete. Please add more content to this section and remove this tag.


Exploits which are used in order to jailbreak 6.x

evasi0n (6.0 / 6.0.1 / 6.0.2 / 6.1 / 6.1.1 / 6.1.2)

p0sixspwn (6.1.3 / 6.1.4 / 6.1.5 / 6.1.6)


Exploits which are used in order to jailbreak 7.x

This section is a stub; it is incomplete. Please add more content to this section and remove this tag.

evasi0n7 (7.0 / 7.0.1 / 7.0.2 / 7.0.3 / 7.0.4 / 7.0.5 / 7.0.6)

Geeksn0w (7.1 / 7.1.1 / 7.1.2)

Pangu (7.1 / 7.1.1 / 7.1.2)

  • i0n1c's Infoleak vulnerability (Pangu v1.0.0)
  • break_early_random (by i0n1c and Tarjei Mandt of Azimuth) (Pangu v1.1.0)
  • LightSensor / ProxALSSensor kernel exploit (Pangu 1.0.0)
  • TempSensor kernel exploit (Pangu 1.1.0)
  • "syslogd chown" vulnerability
  • enterprise certificate (no real exploit, used for initial "unsigned" code execution)
  • "foo_extracted" symlink vulnerability (used to write to /var)
  • /tmp/bigfile (a big file for improvement of the reliability of a race condition)
  • VoIP backgrounding trick (used to auto restart the app)
  • hidden segment attack


Exploits which are used in order to jailbreak 8.x

This section is a stub; it is incomplete. Please add more content to this section and remove this tag.

Pangu8 (8.0 / 8.0.1 / 8.0.2 / 8.1)

  • an exploit for a bug in /usr/libexec/neagent (source @iH8sn0w)
  • enterprise certificate (inside the IPA)
  • a kind of dylib injection into a system process (see IPA)
  • a dmg mount command (looks like the Developer DMG) (syslog while jailbreaking)
  • a sandboxing problem in debugserver (CVE-2014-4457)
  • the same/a similar kernel exploit as used in Pangu (CVE-2014-4461) (source @iH8sn0w)
  • enable-dylibs-to-override-cache
  • CVE-2014-4455

TaiG (8.0 / 8.0.1 / 8.0.2 / 8.1 / 8.1.1)