Skip to content

4rmi0s/Little_taskfinder

 
 

Repository files navigation

Little_taskfinder

execute in iPhone 6, ios12.5.7

Usage

kernel base

iPhone:~ root# kinfo -b
fffffff00e404000

task list

/usr/bin/expose_kernel_task -k 0xfffffff00e404000 -l
[DEBUG] host_get_special_port(4): kr=0, tfp0=0x0
[DEBUG] host_get_host_priv_port: kr=0, host_priv=0x1303
[DEBUG] host_get_special_port(4) with host_priv: kr=0, tfp0=0x0
Got kernel task port via task_for_pid(0)! (port=0xa03)
[libkrw] loaded successfully!
Manual kernel base: 0xfffffff00e404000 (slide: 0x7400000)
[patchfinder] Reading kernel header from 0xfffffff00e404000...
[patchfinder] kernel_read returned 1, magic=0xfeedfacf
[patchfinder] Found __TEXT_EXEC: base=0xfffffff00ea68000 size=0x12ac000
[patchfinder] kernel_size=0x1b9f208, kerndumpbase=0xfffffff00e404000
[patchfinder] xnucore_base=0x664000, xnucore_size=0x12ac000
[patchfinder] cstring_base=0x2039d0, cstring_size=0x24fadc
[patchfinder] Reading full kernel...
[patchfinder] Kernel read successful!
[find_task] Finding kern_proc for pid 606...
[find_task] kern_proc pointer at 0xfffffff00fe53a20
[find_task] kernel_proc = 0xfffffff00fe53628
[find_task] Traversing proc list for pid 606...
[find_task] [0] proc=0xfffffff00fe53628 pid=0
[find_task] [1] proc=0xfffffff0740c7be8 pid=1
[find_task] [2] proc=0xfffffff07450c3f8 pid=26
[find_task] [3] proc=0xfffffff07450c000 pid=28
[find_task] [4] proc=0xfffffff07450cbe8 pid=29
[find_task] [5] proc=0xfffffff0745b3be8 pid=32
[find_task] [6] proc=0xfffffff0745b3000 pid=33
[find_task] [7] proc=0xfffffff0745c43f8 pid=34
[find_task] [8] proc=0xfffffff0745c47f0 pid=35
[find_task] [9] proc=0xfffffff0745c4000 pid=37
[find_task] [10] proc=0xfffffff0745df7f0 pid=38
[find_task] [11] proc=0xfffffff0745dfbe8 pid=39
[find_task] [12] proc=0xfffffff0745df3f8 pid=40
[find_task] [13] proc=0xfffffff0745df000 pid=41
[find_task] [14] proc=0xfffffff0746017f0 pid=42
[find_task] [15] proc=0xfffffff0746013f8 pid=43
[find_task] [16] proc=0xfffffff074601be8 pid=44
[find_task] [17] proc=0xfffffff0746123f8 pid=46
[find_task] [18] proc=0xfffffff0746127f0 pid=47
[find_task] [19] proc=0xfffffff074612be8 pid=49
[find_task] FOUND pid 606 at 0xfffffff074b763f8!
found task with pid 606 at kaddress 0xfffffff074764680successfully found current_task kaddr
[find_task] Using cached kern_proc for pid 0
[find_task] kernel_task = 0xfffffff073a31760
successfully found kernel_task k_addr

PID    NAME                             PROC_ADDR
--------------------------------------------------------------
0      kernel_task                      0xfffffff00fe53628
1      launchd                          0xfffffff0740c7be8
26     payload                          0xfffffff07450c3f8
28     syslogd                          0xfffffff07450c000
29     assistantd                       0xfffffff07450cbe8
32     fseventsd                        0xfffffff0745b3be8
33     mediaserverd                     0xfffffff0745b3000
34     coreauthd                        0xfffffff0745c43f8
35     mediaremoted                     0xfffffff0745c47f0
37     routined                         0xfffffff0745c4000
38     misd                             0xfffffff0745df7f0
39     configd                          0xfffffff0745dfbe8
40     healthd                          0xfffffff0745df3f8
41     wifivelocityd                    0xfffffff0745df000
42     powerd                           0xfffffff0746017f0
43     atc                              0xfffffff0746013f8
44     WirelessRadioManagerd            0xfffffff074601be8
46     keybagd                          0xfffffff0746123f8
47     familynotificationd              0xfffffff0746127f0
49     wifid                            0xfffffff074612be8
50     logd                             0xfffffff07462a3f8
52     installd                         0xfffffff07462abe8
53     mobiletimerd                     0xfffffff07462a000
54     softwareupdated                  0xfffffff07463d7f0
55     seld                             0xfffffff07463d3f8
56     identityservicesd                0xfffffff07463d000
58     wcd                              0xfffffff07465d3f8
59     SpringBoard                      0xfffffff07465d7f0
61     askpermissiond                   0xfffffff07465d000
62     wirelessproxd                    0xfffffff07466e3f8
63     backboardd                       0xfffffff07466e7f0
64     sharingd                         0xfffffff07466e000
65     timed                            0xfffffff07466ebe8
66     locationd                        0xfffffff074686be8
67     containermanagerd                0xfffffff0746867f0
68     imagent                          0xfffffff0746863f8
69     assertiond                       0xfffffff074686000
72     mobilewatchdog                   0xfffffff0746a0000
73     UserEventAgent                   0xfffffff0746a0be8
74     lockdownd                        0xfffffff0746ba7f0
75     aggregated                       0xfffffff0746ba3f8
77     AppleCredentialManagerDaemon     0xfffffff0746babe8
78     ptpd                             0xfffffff0746d13f8
79     navd                             0xfffffff0746d1000
80     budd                             0xfffffff0746d17f0
81     rapportd                         0xfffffff0746d1be8
83     bluetoothd                       0xfffffff0746e8be8
84     fairplayd.H2                     0xfffffff0746e83f8
85     CommCenter                       0xfffffff0746e8000
86     notifyd                          0xfffffff0748007f0
88     cfprefsd                         0xfffffff074800000
89     nfcd                             0xfffffff074800be8
90     distnoted                        0xfffffff07450c7f0
91     lsd                              0xfffffff0746e87f0
92     dmd                              0xfffffff07465dbe8
93     awdd                             0xfffffff074d3a000
94     nehelper                         0xfffffff074d3a3f8
95     securityd                        0xfffffff074d3a7f0
96     mobileassetd                     0xfffffff074d3abe8
97     nsurlsessiond                    0xfffffff074f8a7f0
98     dasd                             0xfffffff074f8a3f8
99     pfd                              0xfffffff074f8abe8
100    nanoregistryd                    0xfffffff074f8a000
101    AssetCacheLocatorService         0xfffffff0745b33f8
102    CloudKeychainProxy               0xfffffff0752f07f0
103    coreduetd                        0xfffffff0752f0be8
104    com.apple.MobileInstallationHelp 0xfffffff0752f03f8
105    profiled                         0xfffffff0752f0000
106    ContextService                   0xfffffff0754833f8
107    carkitd                          0xfffffff0754837f0
108    MTLCompilerService               0xfffffff075483000
109    MTLCompilerService               0xfffffff075483be8
110    contextstored                    0xfffffff0756567f0
112    itunesstored                     0xfffffff075656000
113    OTATaskingAgent                  0xfffffff075656be8
114    apsd                             0xfffffff075a737f0
115    mobileactivationd                0xfffffff075a733f8
117    accountsd                        0xfffffff075a73be8
118    biometrickitd                    0xfffffff075b91000
119    trustd                           0xfffffff075b913f8
120    geod                             0xfffffff075b917f0
121    BlueTool                         0xfffffff075b91be8
122    tccd                             0xfffffff075c3c000
123    ctkd                             0xfffffff075c3c3f8
124    pkd                              0xfffffff075c3c7f0
125    medialibraryd                    0xfffffff075c3cbe8
126    nsurlstoraged                    0xfffffff075da7be8
127    setoken                          0xfffffff075da77f0
128    misagent                         0xfffffff075da73f8
129    MobileStorageMounter             0xfffffff075da7000
130    cloudd                           0xfffffff075f607f0
131    analyticsd                       0xfffffff075f603f8
132    mDNSResponder                    0xfffffff075f60000
134    callservicesd                    0xfffffff074458000
135    AGXCompilerService               0xfffffff0744583f8
136    symptomsd                        0xfffffff0744587f0
139    IMDPersistenceAgent              0xfffffff0762ae7f0
140    MTLCompilerService               0xfffffff0762ae3f8
141    MTLCompilerService               0xfffffff0762ae000
142    duetexpertd                      0xfffffff07634ebe8
143    passd                            0xfffffff07634e7f0
144    calaccessd                       0xfffffff07634e3f8
145    MobileGestaltHelper              0xfffffff07634e000
146    mDNSResponderHelper              0xfffffff0765633f8
147    followupd                        0xfffffff0765637f0
148    useractivityd                    0xfffffff076563000
149    lsdiconservice                   0xfffffff076563be8
150    softwareupdateservicesd          0xfffffff0740c73f8
151    parsecd                          0xfffffff0769cc3f8
152    rtcreportingd                    0xfffffff0769cc7f0
153    deleted                          0xfffffff0769ccbe8
154    captiveagent                     0xfffffff0769cc000
155    companion_proxy                  0xfffffff076a893f8
156    notification_proxy               0xfffffff076a89000
157    afcd                             0xfffffff076a897f0
158    com.apple.StreamingUnzipService  0xfffffff076a89be8
159    akd                              0xfffffff076ca47f0
160    adid                             0xfffffff076ca4be8
163    voiced                           0xfffffff076ca4000
164    aslmanager                       0xfffffff076f4a3f8
165    sshd                             0xfffffff076f4a7f0
166    vmd                              0xfffffff076f4abe8
168    com.apple.CallKit.CallDirectoryM 0xfffffff076f4a000
169    appstored                        0xfffffff076fb73f8
170    bookassetd                       0xfffffff076fb77f0
171    fmfd                             0xfffffff076fb7000
172    installcoordinationd             0xfffffff076fb7be8
173    searchd                          0xfffffff076cbf7f0
174    bash                             0xfffffff076cbf3f8
183    familycircled                    0xfffffff076cbf000
184    suggestd                         0xfffffff076cbfbe8
185    networkserviceproxy              0xfffffff07725f000
186    AGXCompilerService               0xfffffff07725f3f8
187    BTLEServer                       0xfffffff07725f7f0
188    bash                             0xfffffff07725fbe8
189    accessoryd                       0xfffffff0774fb3f8
190    oscard                           0xfffffff0774fb000
193    CMFSyncAgent                     0xfffffff0774fb7f0
194    findmydeviced                    0xfffffff0774fbbe8
196    coresymbolicationd               0xfffffff07591c7f0
197    MTLCompilerService               0xfffffff07591cbe8
198    MTLCompilerService               0xfffffff07591c3f8
209    bird                             0xfffffff074812000
211    com.apple.MobileSoftwareUpdate.C 0xfffffff07786f7f0
212    nanoregistrylaunchd              0xfffffff07786fbe8
220    itunescloudd                     0xfffffff075f60be8
221    siriactionsd                     0xfffffff076ca43f8
222    videosubscriptionsd              0xfffffff07463dbe8
223    TVRemoteConnectionService        0xfffffff0762aebe8
224    swcd                             0xfffffff07786f3f8
225    assetsd                          0xfffffff07786f000
226    online-auth-agent                0xfffffff074612000
227    mobile_installation_proxy        0xfffffff074601000
228    ProtectedCloudKeySyncing         0xfffffff0748127f0
230    cloudphotod                      0xfffffff0745b37f0
231    filecoordinationd                0xfffffff0740c7000
232    ContainerMetadataExtractor       0xfffffff0740c77f0
233    fileproviderd                    0xfffffff0748003f8
234    com.apple.CloudDocs.MobileDocume 0xfffffff0756563f8
493    pasted                           0xfffffff074812be8
497    adprivacyd                       0xfffffff074458be8
498    com.apple.accessibility.Accessib 0xfffffff07591c000
499    fmflocatord                      0xfffffff0748123f8
500    diagnosticextensionsd            0xfffffff07462a7f0
501    SafariBookmarksSyncAgent         0xfffffff0746ba000
588    tipsd                            0xfffffff0746a07f0
589    ndoagent                         0xfffffff0746a03f8
592    LocalStorageFileProvider         0xfffffff0749c17f0
593    dprivacyd                        0xfffffff0749c13f8
594    ind                              0xfffffff0749c1be8
595    webbookmarksd                    0xfffffff0749c1000
597    absd                             0xfffffff074b107f0
600    homed                            0xfffffff074b10be8
601    progressd                        0xfffffff074b76be8
602    remotemanagementd                0xfffffff074b767f0
606    expose_kernel_task               0xfffffff074b763f8
0      I��                          0xfffffff00fe546e8
--------------------------------------------------------------
Total: 177 processes

About

A simple tool to play around with the kernel read/write primitive on iOS 12.5.7

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C 97.6%
  • Objective-C 2.0%
  • Makefile 0.4%