Slave-in-the-Magic-Mirror
Slave-in-the-Magic-Mirror copied to clipboard
Newer firmware
Have you tried using newer Apple TV firmware? It looks like we can decrypt Sochi 11D258, though the airtunesd file is only 10KB...
In recent versions the airplay functionality was moved out to AirPlayReceiver.framework
I use that ancient airtunesd because it's the only one that doesn't use any thumb mode instructions (which aren't implemented in the emulator yet).
Note that as far as I know so far the authentication is version independent - we could implement newer revisions of the protocol while still using the old airtunesd for authentication, so it's not a big priority.
How to get "airtunesd" from firmware the "get_airtunesd.py" cannot run on my computer
@espes can you share your method how to find below address 0x435B4 0xEB00C 0xEB964 self.fp_initsap = 0x435B4 self.fp_challenge = 0xEB00C self.fp_decryptkey = 0xEB964
Too bad there is no like button!