xnuspy icon indicating copy to clipboard operation
xnuspy copied to clipboard

How to determine an offset for a kernel method?

Open YiYiZheng opened this issue 2 years ago • 1 comments

Is there a doc showing how to determine?

For example, iPhone X 14.4.2, open1 method

Not sure if the code snippet below will hook open1 method? ret = syscall(SYS_xnuspy_ctl, XNUSPY_INSTALL_HOOK, 0xfffffff007d574f4, open1, &open1_orig);

Just do not understand the difference between sysctlbyname and syscall...

  1. Could you help me to find offset of necp_send_network_denied_event method in iPhone X 14.4.2

YiYiZheng avatar May 26 '22 14:05 YiYiZheng

Take a look at this: https://github.com/jsherman212/xnuspy/issues/3

gr3atest avatar May 31 '22 14:05 gr3atest