Debugging an Undebuggable App
bryce.co
bryce.co
I'm pretty new to RE though this kind of videos are super interesting for me
It's pretty easy to grab an app, decompile and disassembly it, find what you need to change and then patch the smali and recompile.
It's been a long time since I looked at that stuff, but I think I used to use apktool and smali / baksmali from memory.
I remember something like dex2jar also, which gave you a jar you could use in any java decompiler, like jdgui, procyon etc. Easier to find what you are looking for in the decompiled java and then patch the smali. Lots of android apps are obfuscated, but you can do stuff like add logs to the smali etc, probably remote debugging etc.
It has been a while, so that info might be woefully out of date now.
https://github.com/skylot/jadx is very handy for that nowadays. It also supports interactive variable/method/class name renaming to make the decomplied code easier to read. The decompiler isn't perfect, but I guess all available Java decompilers have their limitations with more complex bytecode…
How easy it is for the user to have control over what apps do is inversely related to how user-hostile the platform is. PT_DENY_ATTACH seems like a feature specifically invented for the purpose of serving the latter. Of course on the Windows side, which I believe doesn't have such a feature, the trick is to make the app attach to itself instead:
https://www.x86matthew.com/view_post?id=selfdebug
https://anti-debug.checkpoint.com/techniques/interactive.htm...
You're exactly right. It was literally invented by Apple for iTunes as part of its DRM solution back in the day.
Similarly I'm wondering why the author here searched through the code for `mov w16, #26` instead of searching for `svc 0x80`.
But also thanks for providing a written version too, it's very nice ;)
(would have added this ages ago if I knew this existed; not a CSS expert, just seeing it now by checking if web has an equivalent of iOS' `UIAccessibility.isReduceMotionEnabled`. neat!)
It's your site, you can do what you want; it's my browser, I will close tabs that annoy me with extreme prejudice.
I've seen some rumors of that device not supporting iPadOS 19, so I'm not really sure what the plan is if that's true. Maybe everyone starts forking money over to Corellium.
Few questions for the author: do you think the most popular commercial tool (guardsquare if im not wrong) brings anything new to the table which prevents an easy disassembly like this? Was TopWidgets protected by something similar or was it rather a local effort?
Seems like a lot of effort to go to otherwise
There were some interesting things in the binary still. At one point I was trying to figure out why I was looking at code that looked like it was downloading a Windows .iso; turns out it was, and it was used for a network speed test widget!
CoolWidgets.app: Your heft tests the network speed.
BillGates.iso: Oh my god.
And of course, you can't really know if a loop is infinite because of the halting problem.
There's also the harderer mode, which I did on macOS a while back - patch the kernel to make PT_DENY_ATTACH do nothing. Macs actually make it fairly easy to run a patched kernel, but I guess on iOS it'd be a lot more trouble (KTRR etc.)
Although XNU is technically open-source, I found it easier to apply my patch with a hexeditor rather than recompiling.
Report it to the store as malware? Crashing the phone is obviously the behavior of malware, but you also have to wonder what other malicious behavior they're trying to hide.
I thought preventing this kind of crap was the supposed reason for apple's walled garden?
But that's besides the point, isn't it? The fact that your phone happens to be jailbroken doesn't say anything about the rest of apple's store, and they clearly allow malware to be distributed.
In this case it's probably additional subterfuge in case somebody examines all notifications posted and sees apple and thus ignores it.
appleid https://zemnmez.medium.com/how-to-hack-apple-id-f3cc9b483a41 steam https://hackerone.com/reports/409850
For example, after being kicked off the App Store by sanctions, Russian banks have used "trojan apps" that show different apps inside Russia: https://appleinsider.com/articles/24/02/12/how-russian-banks...
Draconian anti-hacking laws for device owners, but not for corporate malware makers.