Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That’s correct. iOS applications have their binaries encrypted by Apple when they are uploaded to the App Store, and a special memory mapper in iOS is used to copy those pages from disk and decrypt it into RAM so I can run. You can guess the obvious workaround for this: if you can read the memory of a process other than your own, just dump its memory and reconstruct the binary without encryption. This project allows this to happen on a device that isn’t jailbroken by using the PsychicPaper exploit, which allows applications to sign themselves with arbitrary “entitlements”, one of which is “I want to be able to dump memory from other processes”.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: