首页
社区
课程
招聘
[分享] ida pro 9.0 BETA arm macos
发表于: 2024-8-10 17:16 12756

[分享] ida pro 9.0 BETA arm macos

2024-8-10 17:16
12756

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
cd /Applications/IDA Professional 9.0.app/Contents/MacOS
 
python3 sigpayload.py
 
mv libida.dylib.patched libida.dylib
 
mv libida64.dylib.patched libida64.dylib
 
cp ~/Downloads/arm_mac_user64.dylib /Applications/IDA Professional 9.0.app/Contents/MacOS/plugin
 
sudo codesign --remove-signature libida.dylib && sudo codesign -f -s - --timestamp=none --all-architectures --deep libida.dylib && sudo xattr -cr libida.dylib
 
sudo codesign --remove-signature libida64.dylib && sudo codesign -f -s - --timestamp=none --all-architectures --deep libida64.dylib && sudo xattr -cr libida64.dylib
 
cd plugin
 
sudo codesign --remove-signature arm_mac_user64.dylib && sudo codesign -f -s - --timestamp=none --all-architectures --deep arm_mac_user64.dylib && sudo xattr -cr arm_mac_user64.dylib

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

最后于 2024-8-11 09:40 被YiW编辑 ,原因: 修正
注:下载本附件需支付 10雪币(note:10 points for downloading this attachment)
上传的附件:
收藏
免费 1
支持
分享
最新回复 (21)
雪    币: 8138
活跃值: (4939)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
手速真快
2024-8-10 22:40
0
雪    币: 190
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
3
操作了一下 未成功
提示 Could not load licenses: Signature decryption failed with code: -2
2024-8-11 00:30
0
雪    币: 6876
活跃值: (557)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
YiW
4
mb_ylluoota 操作了一下 未成功 提示 Could not load licenses: Signature decryption failed with code: -2
python那步会产生两个后缀为.patch的文件,要用这两个替换掉原来的。我写步骤时候写漏了
2024-8-11 08:44
0
雪    币: 6876
活跃值: (557)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
YiW
5
修正了
2024-8-11 09:40
0
雪    币: 915
活跃值: (1635)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
YiW 修正了

每次打开总crash如何解决

/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib' (mach-o file, but is an incompatible architecture (have (arm64), need (x86_64h)))

/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib: can't load file  每次打开新的so都报这个错


2024-8-13 01:00
0
雪    币: 6876
活跃值: (557)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
YiW
7
你是intel吧?!
2024-8-13 07:52
0
雪    币: 190
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
8
cp ~/Downloads/signpayload.py /Applications/IDA\ Professional\ 9.0.app/Contents/MacOS

cp ~/Downloads/arm_mac_user64.dylib /Applications/IDA\ Professional\ 9.0.app/Contents/MacOS/plugins

cd /Applications/IDA\ Professional\ 9.0.app/Contents/MacOS
 
python3 sigpayload.py
 
mv libida.dylib.patched libida.dylib
 
mv libida64.dylib.patched libida64.dylib
 
sudo codesign --remove-signature libida.dylib && sudo codesign -f -s - --timestamp=none --all-architectures --deep libida.dylib && sudo xattr -cr libida.dylib
 
sudo codesign --remove-signature libida64.dylib && sudo codesign -f -s - --timestamp=none --all-architectures --deep libida64.dylib && sudo xattr -cr libida64.dylib
 
cd ./plugins
 
sudo codesign --remove-signature arm_mac_user64.dylib && sudo codesign -f -s - --timestamp=none --all-architectures --deep arm_mac_user64.dylib && sudo xattr -cr arm_mac_user64.dylib


2024-8-13 10:50
0
雪    币: 27
活跃值: (1823)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
支持优秀内容
2024-8-13 11:18
0
雪    币: 915
活跃值: (1635)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
YiW 你是intel吧?!

我擦 还真是!intel的破解用哪个啊 大佬?

最后于 2024-8-13 11:52 被hacker521编辑 ,原因:
2024-8-13 11:26
0
雪    币: 6876
活跃值: (557)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
YiW
11
hacker521 YiW 你是intel吧?! 我擦 还真是!intel的破解用哪个啊 大佬?
https://gofile.io/d/cqczRc
用这个。如果还是signum11的话,用 idapyswitch切换下python版本
2024-8-13 12:23
0
雪    币: 344
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
12
ida
2024-8-13 18:30
0
雪    币: 344
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
13

2

最后于 2024-8-14 10:06 被Damn7Kx编辑 ,原因:
2024-8-13 18:32
0
雪    币: 344
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
14
Kernel Triage:
VM - (arg = 0x0) A memory corruption was found in executable text


Thread 0 Crashed::  Dispatch queue: com.apple.main-thread
0   arm_mac_user64.dylib          	       0x10cfaf060 0x10cf8c000 + 143456
1   arm_mac_user64.dylib          	       0x10cf90010 0x10cf8c000 + 16400
2   dyld                          	       0x190737328 invocation function for block in dyld3::MachOAnalyzer::forEachInitializer(Diagnostics&, dyld3::MachOAnalyzer::VMAddrConverter const&, void (unsigned int) block_pointer, void const*) const + 340
3   dyld                          	       0x19072a668 invocation function for block in dyld3::MachOFile::forEachSection(void (dyld3::MachOFile::SectionInfo const&, bool, bool&) block_pointer) const + 496
4   dyld                          	       0x1906d12fc dyld3::MachOFile::forEachLoadCommand(Diagnostics&, void (load_command const*, bool&) block_pointer) const + 300
5   dyld                          	       0x1907296a0 dyld3::MachOFile::forEachSection(void (dyld3::MachOFile::SectionInfo const&, bool, bool&) block_pointer) const + 192
6   dyld                          	       0x190736e3c dyld3::MachOAnalyzer::forEachInitializer(Diagnostics&, dyld3::MachOAnalyzer::VMAddrConverter const&, void (unsigned int) block_pointer, void const*) const + 516
7   dyld                          	       0x1906edb38 dyld4::Loader::findAndRunAllInitializers(dyld4::RuntimeState&) const + 524
8   dyld                          	       0x1906f3f70 dyld4::JustInTimeLoader::runInitializers(dyld4::RuntimeState&) const + 36
9   dyld                          	       0x1906edf24 dyld4::Loader::runInitializersBottomUp(dyld4::RuntimeState&, dyld3::Array<dyld4::Loader const*>&) const + 220
10  dyld                          	       0x1906f1ab0 dyld4::Loader::runInitializersBottomUpPlusUpwardLinks(dyld4::RuntimeState&) const::$_1::operator()() const + 112
11  dyld                          	       0x1906ee0f0 dyld4::Loader::runInitializersBottomUpPlusUpwardLinks(dyld4::RuntimeState&) const + 380
12  dyld                          	       0x19070c7ac dyld4::APIs::dlopen_from(char const*, int, void*) + 1576
13  libida64.dylib                	       0x107754300 0x10751c000 + 2327296

Thread 1:
0   libsystem_pthread.dylib       	       0x190a4be28 start_wqthread + 0

Thread 2:
0   libsystem_pthread.dylib       	       0x190a4be28 start_wqthread + 0

Thread 3:
0   libsystem_kernel.dylib        	       0x190a10848 semaphore_timedwait_trap + 8
1   libida64.dylib                	       0x1078a3524 qsem_wait + 104
2   libsystem_pthread.dylib       	       0x190a4be3c thread_start + 8

Thread 4:
0   libsystem_pthread.dylib       	       0x190a4be28 start_wqthread + 0

Thread 5:
0   libsystem_pthread.dylib       	       0x190a4be28 start_wqthread + 0


Thread 0 crashed with ARM Thread State (64-bit):
    x0: 0x000000010cfc0f90   x1: 0x000000000000000d   x2: 0x000000016b493b70   x3: 0x000000016b493bd8
    x4: 0x00000001e70a85e0   x5: 0x0000000000000000   x6: 0x0000000000000000   x7: 0x0000000000000400
    x8: 0x83cae22314290032   x9: 0x0000000105291910  x10: 0x000000016b491ca8  x11: 0x0000000000030000
   x12: 0x0000000000000002  x13: 0x0000000000000000  x14: 0x000000000002fffc  x15: 0x000000000000005f
   x16: 0x0000000000000000  x17: 0x000000010cf8f470  x18: 0x0000000000000000  x19: 0x000000010cfc0f90
   x20: 0x000000016b491db8  x21: 0x000000000000000d  x22: 0x000000010cfb0dc8  x23: 0x000000010cf8c2e8
   x24: 0x000000010cf8c158  x25: 0x000000010cf8c810  x26: 0x000000016b491ad0  x27: 0x000000010cf8c2e8
   x28: 0x0000000000000000   fp: 0x000000016b491920   lr: 0x000000010cf90010
    sp: 0x000000016b4917b0   pc: 0x000000010cfaf060 cpsr: 0x20001000
   far: 0x000000010cfaf060  esr: 0x82000007 (Instruction Abort) Translation fault

Binary Images:
       0x10cf8c000 -        0x10cfbbfff arm_mac_user64.dylib (*) <3231b8ef-4f7b-31de-b17b-057db4ebb122> /Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib
       0x105cb0000 -        0x105cb7fff libqsvgicon.dylib (*) <978537ff-55a0-3610-891b-c8b8aa7c2488> /Applications/IDA Professional 9.0.app/Contents/PlugIns/iconengines/libqsvgicon.dylib
       0x106ca0000 -        0x106cabfff libobjc-trampolines.dylib (*) <c9ce7923-2f2d-31eb-a6e4-0f3b7a78f895> /usr/lib/libobjc-trampolines.dylib
       0x105994000 -        0x10599bfff libqsvg.dylib (*) <def6d7da-0fff-3723-acaf-29df0100eb89> /Applications/IDA Professional 9.0.app/Contents/PlugIns/imageformats/libqsvg.dylib
       0x105c00000 -        0x105c3bfff libqjpeg.dylib (*) <286b1613-f8c1-3363-acd9-7c516d4b71f7> /Applications/IDA Professional 9.0.app/Contents/PlugIns/imageformats/libqjpeg.dylib
       0x1055e4000 -        0x1055ebfff libqico.dylib (*) <0c313142-3da9-3e5a-88c2-1856e578944b> /Applications/IDA Professional 9.0.app/Contents/PlugIns/imageformats/libqico.dylib
       0x1055d0000 -        0x1055d7fff libqgif.dylib (*) <d96e3f1e-9e00-3110-a881-0fef04cc3f07> /Applications/IDA Professional 9.0.app/Contents/PlugIns/imageformats/libqgif.dylib
       0x105958000 -        0x10597bfff libqmacstyle.dylib (*) <5465b53a-336e-31c6-b559-1b739429c11d> /Applications/IDA Professional 9.0.app/Contents/PlugIns/styles/libqmacstyle.dylib
       0x1050bc000 -        0x105207fff libqcocoa.dylib (*) <3c20074e-2c3f-3023-8901-44f4ad1c9415> /Applications/IDA Professional 9.0.app/Contents/PlugIns/platforms/libqcocoa.dylib
       0x1054b8000 -        0x10551bfff org.qt-project.QtDBus (5.15) <0a66f247-2bf1-366d-af44-5942ea040987> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtDBus.framework/Versions/5/QtDBus
       0x10534c000 -        0x105377fff org.qt-project.QtPrintSupport (5.15) <617624c3-4185-35fb-9a8e-309124fe74c4> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtPrintSupport.framework/Versions/5/QtPrintSupport
       0x10543c000 -        0x105473fff org.qt-project.QtSvg (5.15) <e8b0bd53-c871-3dca-ab24-1da0a14be1fa> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtSvg.framework/Versions/5/QtSvg
       0x105cc4000 -        0x1060dffff org.qt-project.QtWidgets (5.15) <dfceb1e2-84d0-3edd-9818-5745c2c43b25> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtWidgets.framework/Versions/5/QtWidgets
       0x1052f8000 -        0x105303fff org.qt-project.QtMacExtras (5.15) <3de854e8-89dc-3542-b1ea-19c1a0d5b865> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtMacExtras.framework/Versions/5/QtMacExtras
       0x106cf4000 -        0x10717ffff org.qt-project.QtGui (5.15) <edf279ff-55e4-3b74-b42b-e9ebcae7fc2a> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtGui.framework/Versions/5/QtGui
       0x1064d4000 -        0x1069bffff org.qt-project.QtCore (5.15) <8261e18f-e59f-3bcb-9a93-500a011b0311> /Applications/IDA Professional 9.0.app/Contents/Frameworks/QtCore.framework/Versions/5/QtCore
       0x10751c000 -        0x1079effff libida64.dylib (*) <afdcd0b6-f4dc-3af5-8a7f-de92451eaf0a> /Applications/IDA Professional 9.0.app/Contents/MacOS/libida64.dylib
       0x10496c000 -        0x104ddbfff com.hexrays.ida64 (9.0.240807) <76d1f663-edb6-3ba1-91b3-b0d5ea1d505e> /Applications/IDA Professional 9.0.app/Contents/MacOS/ida64
       0x1906cf000 -        0x190763317 dyld (*) <ec7a3ba0-f9bf-3ab8-a0f4-8622e5606b20> /usr/lib/dyld
               0x0 - 0xffffffffffffffff ??? (*) <00000000-0000-0000-0000-000000000000> ???
       0x190a4a000 -        0x190a56ff3 libsystem_pthread.dylib (*) <daf95373-5de6-39a1-a6ce-d87f3f0629cc> /usr/lib/system/libsystem_pthread.dylib
       0x190a0f000 -        0x190a49fef libsystem_kernel.dylib (*) <b7751381-1442-30b5-91b9-ad7be461bebe> /usr/lib/system/libsystem_kernel.dylib

External Modification Summary:
  Calls made by other processes targeting this process:
    task_for_pid: 0
    thread_create: 0
    thread_set_state: 0
  Calls made by this process:
    task_for_pid: 0
    thread_create: 0
    thread_set_state: 0
  Calls made by all processes on this machine:
    task_for_pid: 0
    thread_create: 0
    thread_set_state: 0

VM Region Summary:
ReadOnly portion of Libraries: Total=1.2G resident=0K(0%) swapped_out_or_unallocated=1.2G(100%)
Writable regions: Total=1.1G written=0K(0%) resident=0K(0%) swapped_out=0K(0%) unallocated=1.1G(100%)


2024-8-13 19:51
0
雪    币: 344
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
15
Damn7Kx Kernel&nbsp;Triage: VM&nbsp;-&nbsp;(arg&nbsp;=&nbsp;0x0)&nbsp;A&nbsp;me ...
macos m1 删除 arm_mac_user64.dylib,正常
2024-8-14 10:05
1
雪    币: 0
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
16
Damn7Kx macos m1 删除 arm_mac_user64.dylib,正常
他这个调试器本地启动两次就崩溃了,老哥有没有遇到这个情况
2024-8-14 11:57
0
雪    币: 344
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
17
mb_zglezcov 他这个调试器本地启动两次就崩溃了,老哥有没有遇到这个情况
你是指哪个调试器,动态调试so?
2024-8-15 16:53
0
雪    币: 344
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
18
mb_zglezcov 他这个调试器本地启动两次就崩溃了,老哥有没有遇到这个情况
确实不行

IDA Android 64-bit remote debug server(ST) v9.0.30. Hex-Rays (c) 2004-2024
2024-08-15 18:20:49 Listening on 0.0.0.0:22233...
Error: Oops! internal error 30016 occurred.
got signal #-1, terminating
2024-8-15 18:29
0
雪    币: 277
活跃值: (2131)
能力值: ( LV6,RANK:90 )
在线值:
发帖
回帖
粉丝
19

我按 https://www.52pojie.cn/forum.php?mod=viewthread&tid=1953431&highlight=ida 修改后, 出现

IDA Mac OS X 64-bit remote debug server(MT) v9.0.30. Hex-Rays (c) 2004-2024
2024-08-15 16:52:14 Listening on 0.0.0.0:23946 (my ip 192.168.1.41)...
2024-08-15 16:52:29 [1] Accepting connection from 127.0.0.1...
2024-08-15 16:52:29 [1] [1] Incompatible IDA version
2024-08-15 16:52:29 [1] Closing connection from 127.0.0.1...

最后于 2024-8-15 18:34 被gjianbo编辑 ,原因:
2024-8-15 18:34
0
雪    币: 687
活跃值: (2204)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
20
python3 idapyswitch                                                                                                         ─╯
SyntaxError: Non-UTF-8 code starting with '\xcf' in file /Applications/IDA Professional 9.0.app/Contents/MacOS/idapyswitch on line 1, but no encoding declared; see http://python.org/dev/peps/pep-0263/ for details
2024-9-4 09:11
0
雪    币: 10
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
21
dlopen(/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib): dlopen(/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib, 0x0002): Library not loaded: @rpath/libida64.dylib
  Referenced from: <3231B8EF-4F7B-31DE-B17B-057DB4EBB122> /Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib
  Reason: tried: '/Applications/IDA Professional 9.0.app/Contents/MacOS/libida64.dylib' (no such file), '/Applications/IDA Professional 9.0.app/Contents/MacOS/libida64.dylib' (no such file), '/Applications/IDA Professional 9.0.app/Contents/Frameworks/libida64.dylib' (no such file)
/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/arm_mac_user64.dylib: can't load file
IDA Feeds plugin (/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/ida_feeds/ida_feeds.py) was not loaded due to a missing dependency: rpyc.
IDA Feeds plugin (/Applications/IDA Professional 9.0.app/Contents/MacOS/plugins/ida_feeds/ida_feeds.py) terminated.
2024-10-17 18:18
0
雪    币: 0
能力值: ( LV1,RANK:0 )
在线值:
发帖
回帖
粉丝
22
大佬,能不能给我发一份文件试试啊,甩个github链接呀
5天前
0
游客
登录 | 注册 方可回帖
返回
//