-
-
[原创]iOS Write Up
-
2015-10-20 01:08 2608
-
赞赏
|
|
---|---|
|
Level3:
The key length is 15. Patched the sysctl debugger check (via lldb python script). Filtered the instructions. [+] bp set 100038a00 [+] bp set 100038820 [+] bp set 100038844 [+] bp set 100038a24 [+] bp set 1000389e8 [+] bp set 10003882c [+] bp set 100038850 [+] bp set 100038a0c [+] bp set 100038868 [+] bp set 100038a30 [+] bp set 1000389b8 [+] bp set 1000389d0 [+] bp set 100038a18 [+] bp set 1000389f4 [+] bp set 1000389ac [+] bp set 10003885c 0x10002ca18:strlen (char *) $0 = 0x000000017028ba20 "Yyyuuuuuuuuuuuu" [+] 0x100023f18 Process 533 stopped 15 0x10002c9b8:memset [+] 0x100022940 Process 533 stopped 6171856848 0x10002ca18:strlen (char *) $3 = 0x000000017028ba20 "Yyyuuuuuuuuuuuu" [+] 0x100022a2c Process 533 stopped 6171856592 0x10002c9b8:memset [+] 0x100016ae8 Process 533 stopped 6171857376 0x10002ca24:sysctl [+] sysctl arg2:16fdf11e0 arg1:4, arg3: 16fdf0dc0 0x16fdf11d0: 0x0000000e00000001 0x0000021500000001 0x16fdf11e0: 0x0000000000000000 0x0000000000000000 [+] 0x10001c6b0 Process 533 stopped <nil> [+] cmd: x/16xw 16fdf11e0 0x16fdf11e0: 0x56217885 0x00000000 0x000c1ae8 0x00000000 0x16fdf11f0: 0x00000000 0x00000000 0x00000000 0x00000000 0x16fdf1200: 0x00004804 0x00000002 0x00000215 0x00000001 0x16fdf1210: 0x00000000 0x00000000 0x6fdf4000 0x00000001 [+] cmd: x/16xw 16fdf11e0 0x16fdf11e0: 0x56217885 0x00000000 0x000c1ae8 0x00000000 0x16fdf11f0: 0x00000000 0x00000000 0x00000000 0x00000000 0x16fdf1200: 0x00000000 0x00000002 0x00000215 0x00000001 0x16fdf1210: 0x00000000 0x00000000 0x6fdf4000 0x00000001 [+] start trace instruction [+]: 13: iOS3[0x10001c6dc]: movz w8, #62284, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 27: iOS3[0x10001c72c]: movk w8, #52869 : ___lldb_unnamed_function373$$iOS3 [+]: 41: iOS3[0x10001c710]: movz w9, #17191, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 42: iOS3[0x10001c714]: movk w9, #4046 : ___lldb_unnamed_function373$$iOS3 [+]: 56: iOS3[0x10001c6f4]: cmp w0, #0 : ___lldb_unnamed_function373$$iOS3 [+]: 57: iOS3[0x10001c6f8]: csel w8, w8, w9, eq : ___lldb_unnamed_function373$$iOS3 [+]: 71: iOS3[0x10001c6c4]: str w8, [sp, #1372] : ___lldb_unnamed_function373$$iOS3 [+]: 85: iOS3[0x10001dfc0]: str w0, [sp, #1340] : ___lldb_unnamed_function373$$iOS3 [+]: 99: iOS3[0x10001c674]: b 0x100017f2c : ___lldb_unnamed_function373$$iOS3 [+]: 100: iOS3[0x100017f2c]: b 0x100022a58 : ___lldb_unnamed_function373$$iOS3 [+]: 101: iOS3[0x100022a58]: ldr w8, [sp, #1372] : ___lldb_unnamed_function373$$iOS3 [+]: 102: iOS3[0x100022a5c]: mov x9, x8 : ___lldb_unnamed_function373$$iOS3 [+]: 116: iOS3[0x1000229d8]: movz w10, #31840, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 117: iOS3[0x1000229dc]: movk w10, #41435 : ___lldb_unnamed_function373$$iOS3 [+]: 131: iOS3[0x100022e48]: subs w8, w8, w10 : ___lldb_unnamed_function373$$iOS3 [+]: 145: iOS3[0x100022e7c]: str w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 159: iOS3[0x100022ecc]: str w8, [sp, #1136] : ___lldb_unnamed_function373$$iOS3 [+]: 173: iOS3[0x100022e60]: b.gt 0x1000175c0 : ___lldb_unnamed_function373$$iOS3 [+]: 174: iOS3[0x100022e64]: b 0x100022e30 : ___lldb_unnamed_function373$$iOS3 [+]: 175: iOS3[0x100022e30]: movz w8, #33778, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 189: iOS3[0x1000229bc]: movk w8, #1186 : ___lldb_unnamed_function373$$iOS3 [+]: 190: iOS3[0x1000229c0]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 204: iOS3[0x100022d60]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 205: iOS3[0x100022d64]: str w8, [sp, #1132] : ___lldb_unnamed_function373$$iOS3 [+]: 219: iOS3[0x100022d44]: b.gt 0x100022fd4 : ___lldb_unnamed_function373$$iOS3 [+]: 220: iOS3[0x100022fd4]: movz w8, #35503, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 234: iOS3[0x100023154]: movk w8, #1962 : ___lldb_unnamed_function373$$iOS3 [+]: 235: iOS3[0x100023158]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 249: iOS3[0x100023170]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 263: iOS3[0x10002313c]: str w8, [sp, #1124] : ___lldb_unnamed_function373$$iOS3 [+]: 277: iOS3[0x100023120]: b.gt 0x100023360 : ___lldb_unnamed_function373$$iOS3 [+]: 278: iOS3[0x100023360]: movz w8, #35962, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 292: iOS3[0x100023378]: movk w8, #62321 : ___lldb_unnamed_function373$$iOS3 [+]: 293: iOS3[0x10002337c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 307: iOS3[0x1000230bc]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 321: iOS3[0x1000232ac]: str w8, [sp, #1116] : ___lldb_unnamed_function373$$iOS3 [+]: 335: iOS3[0x1000232e0]: b.gt 0x1000230a4 : ___lldb_unnamed_function373$$iOS3 [+]: 336: iOS3[0x1000230a4]: movz w8, #38284, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 350: iOS3[0x10002324c]: movk w8, #27755 : ___lldb_unnamed_function373$$iOS3 [+]: 364: iOS3[0x100023294]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 378: iOS3[0x10002327c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 392: iOS3[0x100023264]: str w8, [sp, #1108] : ___lldb_unnamed_function373$$iOS3 [+]: 406: iOS3[0x100022fb4]: b.gt 0x100023024 : ___lldb_unnamed_function373$$iOS3 [+]: 407: iOS3[0x100023024]: movz w8, #41571, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 421: iOS3[0x1000231b8]: movk w8, #21081 : ___lldb_unnamed_function373$$iOS3 [+]: 435: iOS3[0x100023200]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 436: iOS3[0x100023204]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 450: iOS3[0x100023234]: str w8, [sp, #1100] : ___lldb_unnamed_function373$$iOS3 [+]: 464: iOS3[0x10002321c]: b.gt 0x100022f6c : ___lldb_unnamed_function373$$iOS3 [+]: 465: iOS3[0x100022f6c]: movz w8, #42468, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 479: iOS3[0x100022f4c]: movk w8, #35769 : ___lldb_unnamed_function373$$iOS3 [+]: 480: iOS3[0x100022f50]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 494: iOS3[0x10002286c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 508: iOS3[0x1000228d4]: str w8, [sp, #1092] : ___lldb_unnamed_function373$$iOS3 [+]: 522: iOS3[0x1000228a0]: b.gt 0x100022b28 : ___lldb_unnamed_function373$$iOS3 [+]: 523: iOS3[0x100022b28]: movz w8, #44677, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 537: iOS3[0x100022b0c]: movk w8, #36693 : ___lldb_unnamed_function373$$iOS3 [+]: 538: iOS3[0x100022b10]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 552: iOS3[0x100022f00]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 566: iOS3[0x100022f18]: str w8, [sp, #1084] : ___lldb_unnamed_function373$$iOS3 [+]: 580: iOS3[0x100022ee4]: b.gt 0x100022de8 : ___lldb_unnamed_function373$$iOS3 [+]: 581: iOS3[0x100022de8]: movz w8, #46208, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 595: iOS3[0x100022e18]: movk w8, #51949 : ___lldb_unnamed_function373$$iOS3 [+]: 609: iOS3[0x100022e00]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 623: iOS3[0x100022d94]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 624: iOS3[0x100022d98]: str w8, [sp, #1076] : ___lldb_unnamed_function373$$iOS3 [+]: 638: iOS3[0x100022dcc]: b.gt 0x100016920 : ___lldb_unnamed_function373$$iOS3 [+]: 639: iOS3[0x100016920]: movz w8, #47260, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 640: iOS3[0x100016924]: movk w8, #30677 : ___lldb_unnamed_function373$$iOS3 [+]: 654: iOS3[0x10001693c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 668: iOS3[0x10001696c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 682: iOS3[0x1000169bc]: str w8, [sp, #1068] : ___lldb_unnamed_function373$$iOS3 [+]: 696: iOS3[0x100016954]: b.gt 0x100016df4 : ___lldb_unnamed_function373$$iOS3 [+]: 697: iOS3[0x100016df4]: movz w8, #47746, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 698: iOS3[0x100016df8]: movk w8, #26180 : ___lldb_unnamed_function373$$iOS3 [+]: 712: iOS3[0x100018248]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 713: iOS3[0x10001824c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 727: iOS3[0x100016908]: str w8, [sp, #1060] : ___lldb_unnamed_function373$$iOS3 [+]: 741: iOS3[0x1000168f0]: b.gt 0x10001720c : ___lldb_unnamed_function373$$iOS3 [+]: 742: iOS3[0x10001720c]: movz w8, #48143, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 756: iOS3[0x10001723c]: movk w8, #33687 : ___lldb_unnamed_function373$$iOS3 [+]: 757: iOS3[0x100017240]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 771: iOS3[0x100017224]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 785: iOS3[0x1000172f4]: str w8, [sp, #1052] : ___lldb_unnamed_function373$$iOS3 [+]: 799: iOS3[0x100016870]: b.gt 0x100017bb0 : ___lldb_unnamed_function373$$iOS3 [+]: 800: iOS3[0x100017bb0]: movz w8, #49836, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 801: iOS3[0x100017bb4]: movk w8, #31244 : ___lldb_unnamed_function373$$iOS3 [+]: 815: iOS3[0x100017c6c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 829: iOS3[0x100017b98]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 843: iOS3[0x100017b7c]: str w8, [sp, #1044] : ___lldb_unnamed_function373$$iOS3 [+]: 844: iOS3[0x100017b80]: b.gt 0x10001a2fc : ___lldb_unnamed_function373$$iOS3 [+]: 845: iOS3[0x10001a2fc]: movz w8, #50453, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 846: iOS3[0x10001a300]: movk w8, #21164 : ___lldb_unnamed_function373$$iOS3 [+]: 860: iOS3[0x10001a2ac]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 861: iOS3[0x10001a2b0]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 875: iOS3[0x10001ac9c]: str w8, [sp, #1036] : ___lldb_unnamed_function373$$iOS3 [+]: 876: iOS3[0x10001aca0]: b.gt 0x100018e14 : ___lldb_unnamed_function373$$iOS3 [+]: 877: iOS3[0x100018e14]: movz w8, #50791, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 878: iOS3[0x100018e18]: movk w8, #6028 : ___lldb_unnamed_function373$$iOS3 [+]: 892: iOS3[0x100017b2c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 893: iOS3[0x100017b30]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 907: iOS3[0x100017c50]: str w8, [sp, #1028] : ___lldb_unnamed_function373$$iOS3 [+]: 908: iOS3[0x100017c54]: b.gt 0x1000179ac : ___lldb_unnamed_function373$$iOS3 [+]: 909: iOS3[0x1000179ac]: movz w8, #51177, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 910: iOS3[0x1000179b0]: movk w8, #49064 : ___lldb_unnamed_function373$$iOS3 [+]: 924: iOS3[0x100017a28]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 925: iOS3[0x100017a2c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 939: iOS3[0x100017a44]: str w8, [sp, #1020] : ___lldb_unnamed_function373$$iOS3 [+]: 940: iOS3[0x100017a48]: b.gt 0x100017a60 : ___lldb_unnamed_function373$$iOS3 [+]: 941: iOS3[0x100017a60]: movz w8, #51438, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 955: iOS3[0x100017a10]: movk w8, #34285 : ___lldb_unnamed_function373$$iOS3 [+]: 969: iOS3[0x100017c1c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 970: iOS3[0x100017c20]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 984: iOS3[0x1000179f8]: str w8, [sp, #1012] : ___lldb_unnamed_function373$$iOS3 [+]: 998: iOS3[0x1000190d8]: b.gt 0x10001915c : ___lldb_unnamed_function373$$iOS3 [+]: 999: iOS3[0x10001915c]: movz w8, #51647, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1013: iOS3[0x1000191f4]: movk w8, #22474 : ___lldb_unnamed_function373$$iOS3 [+]: 1027: iOS3[0x1000190f0]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1028: iOS3[0x1000190f4]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1042: iOS3[0x10001ac1c]: str w8, [sp, #1004] : ___lldb_unnamed_function373$$iOS3 [+]: 1043: iOS3[0x10001ac20]: b.gt 0x10001d614 : ___lldb_unnamed_function373$$iOS3 [+]: 1044: iOS3[0x10001d614]: movz w8, #52595, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1045: iOS3[0x10001d618]: movk w8, #13211 : ___lldb_unnamed_function373$$iOS3 [+]: 1059: iOS3[0x10001d648]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1073: iOS3[0x10001d630]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1087: iOS3[0x10001d5a8]: str w8, [sp, #996] : ___lldb_unnamed_function373$$iOS3 [+]: 1088: iOS3[0x10001d5ac]: b.gt 0x10001af44 : ___lldb_unnamed_function373$$iOS3 [+]: 1089: iOS3[0x10001af44]: movz w8, #29409, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1103: iOS3[0x10001d348]: movk w8, #56594 : ___lldb_unnamed_function373$$iOS3 [+]: 1117: iOS3[0x10001abd4]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1131: iOS3[0x10001d040]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1132: iOS3[0x10001d044]: str w8, [sp, #988] : ___lldb_unnamed_function373$$iOS3 [+]: 1146: iOS3[0x10001d024]: b.gt 0x10001c220 : ___lldb_unnamed_function373$$iOS3 [+]: 1147: iOS3[0x10001d028]: b 0x10001d078 : ___lldb_unnamed_function373$$iOS3 [+]: 1148: iOS3[0x10001d078]: movz w8, #29319, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1162: iOS3[0x1000190bc]: movk w8, #44983 : ___lldb_unnamed_function373$$iOS3 [+]: 1163: iOS3[0x1000190c0]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1177: iOS3[0x1000179c8]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1191: iOS3[0x100019088]: str w8, [sp, #984] : ___lldb_unnamed_function373$$iOS3 [+]: 1205: iOS3[0x100017990]: b.gt 0x100016a28 : ___lldb_unnamed_function373$$iOS3 [+]: 1206: iOS3[0x100017994]: b 0x100017ed8 : ___lldb_unnamed_function373$$iOS3 [+]: 1207: iOS3[0x100017ed8]: movz w8, #28496, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1208: iOS3[0x100017edc]: movk w8, #10094 : ___lldb_unnamed_function373$$iOS3 [+]: 1222: iOS3[0x100017ec0]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1236: iOS3[0x10001991c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1250: iOS3[0x100017e74]: str w8, [sp, #980] : ___lldb_unnamed_function373$$iOS3 [+]: 1251: iOS3[0x100017e78]: b.gt 0x10001b90c : ___lldb_unnamed_function373$$iOS3 [+]: 1265: iOS3[0x1000197c8]: b 0x1000197fc : ___lldb_unnamed_function373$$iOS3 [+]: 1266: iOS3[0x1000197fc]: movz w8, #27802, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1280: iOS3[0x100017e58]: movk w8, #40214 : ___lldb_unnamed_function373$$iOS3 [+]: 1281: iOS3[0x100017e5c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1295: iOS3[0x10001683c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1309: iOS3[0x100016a5c]: str w8, [sp, #976] : ___lldb_unnamed_function373$$iOS3 [+]: 1323: iOS3[0x100016a74]: b.gt 0x10001b96c : ___lldb_unnamed_function373$$iOS3 [+]: 1324: iOS3[0x100016a78]: b 0x100016ac4 : ___lldb_unnamed_function373$$iOS3 [+]: 1325: iOS3[0x100016ac4]: movz w8, #27435, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1326: iOS3[0x100016ac8]: movk w8, #25064 : ___lldb_unnamed_function373$$iOS3 [+]: 1340: iOS3[0x100016aa8]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1341: iOS3[0x100016aac]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1355: iOS3[0x100016a90]: str w8, [sp, #972] : ___lldb_unnamed_function373$$iOS3 [+]: 1369: iOS3[0x100016a40]: b.gt 0x10001b9d8 : ___lldb_unnamed_function373$$iOS3 [+]: 1370: iOS3[0x100016a44]: b 0x100017d90 : ___lldb_unnamed_function373$$iOS3 [+]: 1371: iOS3[0x100017d90]: movz w8, #26697, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1385: iOS3[0x100017d24]: movk w8, #19287 : ___lldb_unnamed_function373$$iOS3 [+]: 1399: iOS3[0x100017cf0]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1400: iOS3[0x100017cf4]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1414: iOS3[0x10001920c]: str w8, [sp, #968] : ___lldb_unnamed_function373$$iOS3 [+]: 1415: iOS3[0x100019210]: b.gt 0x10001b8bc : ___lldb_unnamed_function373$$iOS3 [+]: 1429: iOS3[0x100019258]: b 0x1000192a8 : ___lldb_unnamed_function373$$iOS3 [+]: 1430: iOS3[0x1000192a8]: movz w8, #26471, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1444: iOS3[0x100019240]: movk w8, #61153 : ___lldb_unnamed_function373$$iOS3 [+]: 1458: iOS3[0x10001cda8]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1472: iOS3[0x100019228]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1486: iOS3[0x10001c938]: str w8, [sp, #964] : ___lldb_unnamed_function373$$iOS3 [+]: 1487: iOS3[0x10001c93c]: b.gt 0x10001e204 : ___lldb_unnamed_function373$$iOS3 [+]: 1501: iOS3[0x10001c96c]: b 0x10001c9b8 : ___lldb_unnamed_function373$$iOS3 [+]: 1502: iOS3[0x10001c9b8]: movz w8, #22233, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1516: iOS3[0x10001c984]: movk w8, #49707 : ___lldb_unnamed_function373$$iOS3 [+]: 1530: iOS3[0x10001c99c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1531: iOS3[0x10001c9a0]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1545: iOS3[0x10001c954]: str w8, [sp, #960] : ___lldb_unnamed_function373$$iOS3 [+]: 1559: iOS3[0x10001e9a8]: b.gt 0x10001b4ec : ___lldb_unnamed_function373$$iOS3 [+]: 1560: iOS3[0x10001e9ac]: b 0x10001c91c : ___lldb_unnamed_function373$$iOS3 [+]: 1561: iOS3[0x10001c91c]: movz w8, #21607, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1562: iOS3[0x10001c920]: movk w8, #25489 : ___lldb_unnamed_function373$$iOS3 [+]: 1576: iOS3[0x10001c904]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1590: iOS3[0x10001ef68]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1591: iOS3[0x10001ef6c]: str w8, [sp, #956] : ___lldb_unnamed_function373$$iOS3 [+]: 1605: iOS3[0x10001f004]: b.gt 0x10001b584 : ___lldb_unnamed_function373$$iOS3 [+]: 1619: iOS3[0x10001efec]: b 0x10001efa0 : ___lldb_unnamed_function373$$iOS3 [+]: 1620: iOS3[0x10001efa0]: movz w8, #20400, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1621: iOS3[0x10001efa4]: movk w8, #65108 : ___lldb_unnamed_function373$$iOS3 [+]: 1635: iOS3[0x1000202b8]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1636: iOS3[0x1000202bc]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1650: iOS3[0x10002024c]: str w8, [sp, #952] : ___lldb_unnamed_function373$$iOS3 [+]: 1651: iOS3[0x100020250]: b.gt 0x10001b600 : ___lldb_unnamed_function373$$iOS3 [+]: 1665: iOS3[0x10002029c]: b 0x1000202a0 : ___lldb_unnamed_function373$$iOS3 [+]: 1666: iOS3[0x1000202a0]: movz w8, #20200, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1680: iOS3[0x100020280]: movk w8, #24317 : ___lldb_unnamed_function373$$iOS3 [+]: 1681: iOS3[0x100020284]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1695: iOS3[0x100021900]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1696: iOS3[0x100021904]: str w8, [sp, #948] : ___lldb_unnamed_function373$$iOS3 [+]: 1710: iOS3[0x1000218e4]: b.gt 0x10001b524 : ___lldb_unnamed_function373$$iOS3 [+]: 1711: iOS3[0x1000218e8]: b 0x100020268 : ___lldb_unnamed_function373$$iOS3 [+]: 1712: iOS3[0x100020268]: movz w8, #19729, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1726: iOS3[0x10002199c]: movk w8, #53698 : ___lldb_unnamed_function373$$iOS3 [+]: 1727: iOS3[0x1000219a0]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1741: iOS3[0x100021980]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1742: iOS3[0x100021984]: str w8, [sp, #944] : ___lldb_unnamed_function373$$iOS3 [+]: 1756: iOS3[0x100021a20]: b.gt 0x1000192f0 : ___lldb_unnamed_function373$$iOS3 [+]: 1770: iOS3[0x100021964]: b 0x100021968 : ___lldb_unnamed_function373$$iOS3 [+]: 1771: iOS3[0x100021968]: movz w8, #18034, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1785: iOS3[0x10001ef84]: movk w8, #25798 : ___lldb_unnamed_function373$$iOS3 [+]: 1786: iOS3[0x10001ef88]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1800: iOS3[0x100020984]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1801: iOS3[0x100020988]: str w8, [sp, #940] : ___lldb_unnamed_function373$$iOS3 [+]: 1815: iOS3[0x1000209a0]: b.gt 0x100019370 : ___lldb_unnamed_function373$$iOS3 [+]: 1829: iOS3[0x1000209b8]: b 0x10002096c : ___lldb_unnamed_function373$$iOS3 [+]: 1830: iOS3[0x10002096c]: movz w8, #17803, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1844: iOS3[0x100021680]: movk w8, #9709 : ___lldb_unnamed_function373$$iOS3 [+]: 1858: iOS3[0x100021698]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1859: iOS3[0x10002169c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1873: iOS3[0x1000217b4]: str w8, [sp, #936] : ___lldb_unnamed_function373$$iOS3 [+]: 1887: iOS3[0x10002179c]: b.gt 0x1000193a8 : ___lldb_unnamed_function373$$iOS3 [+]: 1901: iOS3[0x100021704]: b 0x100021708 : ___lldb_unnamed_function373$$iOS3 [+]: 1902: iOS3[0x100021708]: movz w8, #17191, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1916: iOS3[0x100021784]: movk w8, #4045 : ___lldb_unnamed_function373$$iOS3 [+]: 1930: iOS3[0x100021768]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 1931: iOS3[0x10002176c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 1945: iOS3[0x100021830]: str w8, [sp, #932] : ___lldb_unnamed_function373$$iOS3 [+]: 1946: iOS3[0x100021834]: b.gt 0x1000196f8 : ___lldb_unnamed_function373$$iOS3 [+]: 1960: iOS3[0x100021750]: b 0x100021738 : ___lldb_unnamed_function373$$iOS3 [+]: 1961: iOS3[0x100021738]: movz w8, #14867, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 1975: iOS3[0x100021de0]: movk w8, #10514 : ___lldb_unnamed_function373$$iOS3 [+]: 1989: iOS3[0x100021720]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2003: iOS3[0x100021ee0]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2004: iOS3[0x100021ee4]: str w8, [sp, #928] : ___lldb_unnamed_function373$$iOS3 [+]: 2018: iOS3[0x100021f14]: b.gt 0x10001ba58 : ___lldb_unnamed_function373$$iOS3 [+]: 2032: iOS3[0x100021f80]: b 0x1000216b4 : ___lldb_unnamed_function373$$iOS3 [+]: 2033: iOS3[0x1000216b4]: movz w8, #14472, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2034: iOS3[0x1000216b8]: movk w8, #24667 : ___lldb_unnamed_function373$$iOS3 [+]: 2048: iOS3[0x1000216e8]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2049: iOS3[0x1000216ec]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2063: iOS3[0x1000216d0]: str w8, [sp, #924] : ___lldb_unnamed_function373$$iOS3 [+]: 2077: iOS3[0x100021efc]: b.gt 0x10001e73c : ___lldb_unnamed_function373$$iOS3 [+]: 2091: iOS3[0x100021ec8]: b 0x100021e94 : ___lldb_unnamed_function373$$iOS3 [+]: 2092: iOS3[0x100021e94]: movz w8, #13442, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2093: iOS3[0x100021e98]: movk w8, #38100 : ___lldb_unnamed_function373$$iOS3 [+]: 2107: iOS3[0x1000220e4]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2121: iOS3[0x100022114]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2135: iOS3[0x100022148]: str w8, [sp, #920] : ___lldb_unnamed_function373$$iOS3 [+]: 2149: iOS3[0x1000220fc]: b.gt 0x10002152c : ___lldb_unnamed_function373$$iOS3 [+]: 2163: iOS3[0x100022160]: b 0x10001c8ec : ___lldb_unnamed_function373$$iOS3 [+]: 2164: iOS3[0x10001c8ec]: movz w8, #13190, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2178: iOS3[0x10001ca3c]: movk w8, #12517 : ___lldb_unnamed_function373$$iOS3 [+]: 2192: iOS3[0x10001ca08]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2206: iOS3[0x10001c9ec]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2207: iOS3[0x10001c9f0]: str w8, [sp, #916] : ___lldb_unnamed_function373$$iOS3 [+]: 2221: iOS3[0x10001c9d0]: b.gt 0x1000215b0 : ___lldb_unnamed_function373$$iOS3 [+]: 2222: iOS3[0x10001c9d4]: b 0x10001cb38 : ___lldb_unnamed_function373$$iOS3 [+]: 2223: iOS3[0x10001cb38]: movz w8, #11896, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2237: iOS3[0x10001cb50]: movk w8, #32226 : ___lldb_unnamed_function373$$iOS3 [+]: 2238: iOS3[0x10001cb54]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2252: iOS3[0x10001c8d0]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2253: iOS3[0x10001c8d4]: str w8, [sp, #912] : ___lldb_unnamed_function373$$iOS3 [+]: 2267: iOS3[0x10001c8b4]: b.gt 0x1000214e0 : ___lldb_unnamed_function373$$iOS3 [+]: 2268: iOS3[0x10001c8b8]: b 0x10001eb50 : ___lldb_unnamed_function373$$iOS3 [+]: 2269: iOS3[0x10001eb50]: movz w8, #11608, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2283: iOS3[0x10001eb00]: movk w8, #58903 : ___lldb_unnamed_function373$$iOS3 [+]: 2284: iOS3[0x10001eb04]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2298: iOS3[0x100020768]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2312: iOS3[0x100020750]: str w8, [sp, #908] : ___lldb_unnamed_function373$$iOS3 [+]: 2326: iOS3[0x100020738]: b.gt 0x100021430 : ___lldb_unnamed_function373$$iOS3 [+]: 2340: iOS3[0x1000210e4]: b 0x100021164 : ___lldb_unnamed_function373$$iOS3 [+]: 2341: iOS3[0x100021164]: movz w8, #11077, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2355: iOS3[0x100021130]: movk w8, #33934 : ___lldb_unnamed_function373$$iOS3 [+]: 2369: iOS3[0x100021114]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2370: iOS3[0x100021118]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2384: iOS3[0x100021d94]: str w8, [sp, #904] : ___lldb_unnamed_function373$$iOS3 [+]: 2398: iOS3[0x100021dac]: b.gt 0x10001fcd0 : ___lldb_unnamed_function373$$iOS3 [+]: 2412: iOS3[0x100021d78]: b 0x100021d7c : ___lldb_unnamed_function373$$iOS3 [+]: 2413: iOS3[0x100021d7c]: movz w8, #10089, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2427: iOS3[0x1000210fc]: movk w8, #17226 : ___lldb_unnamed_function373$$iOS3 [+]: 2441: iOS3[0x100021218]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2455: iOS3[0x100021194]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2456: iOS3[0x100021198]: str w8, [sp, #900] : ___lldb_unnamed_function373$$iOS3 [+]: 2470: iOS3[0x10002071c]: b.gt 0x100020c6c : ___lldb_unnamed_function373$$iOS3 [+]: 2471: iOS3[0x100020720]: b 0x1000209d0 : ___lldb_unnamed_function373$$iOS3 [+]: 2472: iOS3[0x1000209d0]: movz w8, #9878, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2486: iOS3[0x100020a00]: movk w8, #44943 : ___lldb_unnamed_function373$$iOS3 [+]: 2500: iOS3[0x100020a18]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2514: iOS3[0x100020a7c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2528: iOS3[0x100020a94]: str w8, [sp, #896] : ___lldb_unnamed_function373$$iOS3 [+]: 2529: iOS3[0x100020a98]: b.gt 0x10001fc04 : ___lldb_unnamed_function373$$iOS3 [+]: 2543: iOS3[0x100020ab0]: b 0x100020a64 : ___lldb_unnamed_function373$$iOS3 [+]: 2544: iOS3[0x100020a64]: movz w8, #9599, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2558: iOS3[0x100021aa4]: movk w8, #5420 : ___lldb_unnamed_function373$$iOS3 [+]: 2559: iOS3[0x100021aa8]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2573: iOS3[0x100020a4c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2587: iOS3[0x100020a30]: str w8, [sp, #892] : ___lldb_unnamed_function373$$iOS3 [+]: 2588: iOS3[0x100020a34]: b.gt 0x10001e414 : ___lldb_unnamed_function373$$iOS3 [+]: 2602: iOS3[0x1000209e8]: b 0x10001c87c : ___lldb_unnamed_function373$$iOS3 [+]: 2603: iOS3[0x10001c87c]: movz w8, #9021, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2604: iOS3[0x10001c880]: movk w8, #13039 : ___lldb_unnamed_function373$$iOS3 [+]: 2618: iOS3[0x10001c898]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2619: iOS3[0x10001c89c]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2633: iOS3[0x10001c860]: str w8, [sp, #888] : ___lldb_unnamed_function373$$iOS3 [+]: 2634: iOS3[0x10001c864]: b.gt 0x10001e480 : ___lldb_unnamed_function373$$iOS3 [+]: 2648: iOS3[0x10001cb6c]: b 0x10001cb70 : ___lldb_unnamed_function373$$iOS3 [+]: 2649: iOS3[0x10001cb70]: movz w8, #8188, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2663: iOS3[0x10001cba0]: movk w8, #43962 : ___lldb_unnamed_function373$$iOS3 [+]: 2664: iOS3[0x10001cba4]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2678: iOS3[0x10001cbd4]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2692: iOS3[0x10001cbec]: str w8, [sp, #884] : ___lldb_unnamed_function373$$iOS3 [+]: 2693: iOS3[0x10001cbf0]: b.gt 0x10001db84 : ___lldb_unnamed_function373$$iOS3 [+]: 2707: iOS3[0x10001cbbc]: b 0x10001c82c : ___lldb_unnamed_function373$$iOS3 [+]: 2708: iOS3[0x10001c82c]: movz w8, #6210, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2709: iOS3[0x10001c830]: movk w8, #27383 : ___lldb_unnamed_function373$$iOS3 [+]: 2723: iOS3[0x10001c810]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2724: iOS3[0x10001c814]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2738: iOS3[0x10001d1a4]: str w8, [sp, #880] : ___lldb_unnamed_function373$$iOS3 [+]: 2739: iOS3[0x10001d1a8]: b.gt 0x10001bae0 : ___lldb_unnamed_function373$$iOS3 [+]: 2753: iOS3[0x10001d1d8]: b 0x10001d1dc : ___lldb_unnamed_function373$$iOS3 [+]: 2754: iOS3[0x10001d1dc]: movz w8, #2737, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2768: iOS3[0x10001d1c0]: movk w8, #52331 : ___lldb_unnamed_function373$$iOS3 [+]: 2782: iOS3[0x10001e198]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2796: iOS3[0x1000191d8]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2797: iOS3[0x1000191dc]: str w8, [sp, #876] : ___lldb_unnamed_function373$$iOS3 [+]: 2811: iOS3[0x10001943c]: b.gt 0x10001bb34 : ___lldb_unnamed_function373$$iOS3 [+]: 2825: iOS3[0x10001946c]: b 0x100019628 : ___lldb_unnamed_function373$$iOS3 [+]: 2826: iOS3[0x100019628]: movz w8, #2185, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2840: iOS3[0x100019610]: movk w8, #47184 : ___lldb_unnamed_function373$$iOS3 [+]: 2854: iOS3[0x1000195f4]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2855: iOS3[0x1000195f8]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2869: iOS3[0x100019a98]: str w8, [sp, #872] : ___lldb_unnamed_function373$$iOS3 [+]: 2870: iOS3[0x100019a9c]: b.gt 0x100019484 : ___lldb_unnamed_function373$$iOS3 [+]: 2884: iOS3[0x100019a80]: b 0x10001c424 : ___lldb_unnamed_function373$$iOS3 [+]: 2885: iOS3[0x10001c424]: movz w8, #1924, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2899: iOS3[0x1000195d8]: movk w8, #34685 : ___lldb_unnamed_function373$$iOS3 [+]: 2900: iOS3[0x1000195dc]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2914: iOS3[0x100019a00]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 [+]: 2928: iOS3[0x100019a18]: str w8, [sp, #868] : ___lldb_unnamed_function373$$iOS3 [+]: 2929: iOS3[0x100019a1c]: b.gt 0x10001c088 : ___lldb_unnamed_function373$$iOS3 [+]: 2943: iOS3[0x100019a68]: b 0x100019a4c : ___lldb_unnamed_function373$$iOS3 [+]: 2944: iOS3[0x100019a4c]: movz w8, #65479, lsl #16 : ___lldb_unnamed_function373$$iOS3 [+]: 2945: iOS3[0x100019a50]: movk w8, #17495 : ___lldb_unnamed_function373$$iOS3 [+]: 2959: iOS3[0x10001a09c]: ldr w9, [sp, #1140] : ___lldb_unnamed_function373$$iOS3 [+]: 2960: iOS3[0x10001a0a0]: subs w8, w9, w8 : ___lldb_unnamed_function373$$iOS3 ..... |
他的文章
[原创]iOS Write Up
2609
看原图