本文共 929 字,大约阅读时间需要 3 分钟。
1.写测试代码。
#include#include int main(int argc,char* argv[]){ printf("testios\n"); return 1;}
2.编译。
xcrun -sdk iphoneos clang -arch arm64 main.c -o testhook3.签名我这里直接用自己的(做逆向时不要用自己的防被吊销)file testhook $testhook: Mach-O 64-bit executable arm644.查找证书。haidragondeMacBook-Air:~ haidragon$ file testhook testhook: Mach-O 64-bit executable arm64haidragondeMacBook-Air:~ haidragon$ security find-identity -v -p codesigning 1) 3EBAD7EE1C26691217CF3D1E4485E6C44D15E52A "xxxxxxxxxxxxxxxxx" 2) E6EBDA70B2F2FD24AC69657B4ACE009E17C66BFB "xxxxxxxxxxxxxxxxx" 2 valid identities foundhaidragondeMacBook-Air:~ haidragon$ codesign --force --verify --verbose --sign "xxxxxxxxxxxxxxxxx" ./testhook5.端口转发。iproxy 4567 22发到手机上 ssh -p 4567 root@127.0.0.1修改成777 运行。
iPhone:/var root# chmod 777 ./testhook iPhone:/var root# ./testhook testiosiPhone:/var root#
转载于:https://blog.51cto.com/haidragon/2398212