Halo Michael Profile
Halo Michael

@halo_michael

Followers
2,974
Following
150
Media
446
Statuses
2,761
Explore trending content on Musk Viewer
Pinned Tweet
@halo_michael
Halo Michael
9 months
Tweet media one
@halo_michael
Halo Michael
1 year
It's time to 16.5👽
Tweet media one
1
0
8
3
0
21
@halo_michael
Halo Michael
5 years
Very nice job! I used #Unc0ver by @Pwn20wnd remounted rootfs on iPhoneXS iOS12.4 and replaced the system font successful.
Tweet media one
39
51
582
@halo_michael
Halo Michael
7 months
New iOS17.2 kernel exploit by @Nyaaaaa_ovo
Tweet media one
51
98
613
@halo_michael
Halo Michael
5 years
Android10 on iPhone7 🔥🔥🔥
Tweet media one
49
86
550
@halo_michael
Halo Michael
4 years
Also 14.0.1
Tweet media one
Tweet media two
13
24
263
@halo_michael
Halo Michael
5 years
In iOS13.3.1, Apple added a new mechanism. Unless launchd_missing_exec_no_panic = 1 is added to boot-args, if you try to control launchd to load a launchdaemon file that does not exist in the corresponding executable, it will cause panic.
5
20
207
@halo_michael
Halo Michael
2 years
So, I wrote two exploit demo app here: if anyone wants test it :P flow_divert support <= 15.4.1 ipc_kmsgs support <= 15.3.1 enjoy!
Tweet media one
Tweet media two
48
49
193
@halo_michael
Halo Michael
4 years
Successfully futurerestored from iOS 13.5 -> iOS 14.3 using iOS 14.4’s SEP/Baseband on my iPhoneSE2 (A13)! Thanks to @marijuanARM @Cryptiiiic everyone who took the risk to test futurerestore before me... and anyone else I missed!
Tweet media one
16
15
148
@halo_michael
Halo Michael
3 years
Untethered jailbreak, which is very valuable! so there is a high probability that it will not be released within ten years. But still excited me!
@LinusHenze
Linus Henze
3 years
Demo of CVE-2021-30740, CVE-2021-30768, CVE-2021-30769, CVE-2021-30770 and CVE-2021-30773 on iOS 14.5.1, iPhone 12 Pro Max
218
687
3K
5
18
140
@halo_michael
Halo Michael
5 years
[Release]: Generator Auto Setter Auto set your generator when jailbreaking! Only Support Checkra1n. (Because other jailbreak tool doesn't need that.) It's on my repo NOW:
Tweet media one
17
37
137
@halo_michael
Halo Michael
7 months
😈
Tweet media one
@halo_michael
Halo Michael
7 months
#CVE -2024-23208 You need unsandbox first to allow fork()
Tweet media one
5
16
118
25
20
138
@halo_michael
Halo Michael
9 months
Apple removed -(BOOL)setUsagePoliciesForBundle:(id)arg1 cellular:(BOOL)arg2 wifi:(BOOL)arg3 ; in PSAppDataUsagePolicyCache, that's why TrollStore installed apps can't access network in Chinese models.
Tweet media one
Tweet media two
7
10
134
@halo_michael
Halo Michael
7 months
#CVE -2024-23208 You need unsandbox first to allow fork()
Tweet media one
5
16
118
@halo_michael
Halo Michael
2 years
If anyone wanna set resolution: *TrollStore request⚠️ *Resolution value verify✅ *Reboot revert resolution✅ So it’s 100% safe Have fun!😈
Tweet media one
23
21
101
@halo_michael
Halo Michael
2 years
So, that's how I made palera1n semi-tethered: 1. Create a partition: newfs_apfs -A -v System -e /dev/disk0s1 that will be disk0s1s8 2. Copy root file system to disk0s1s8 3. add rd=disk0s1s8 to boot-args (1/2)
@halo_michael
Halo Michael
2 years
😼
Tweet media one
1
1
21
6
12
102
@halo_michael
Halo Michael
5 years
Checkra1n users may be able to delete /System/Library/LaunchDaemons/com.apple.MobileFileIntegrity.plist to completely disable amfid. And this will not have any impact on using the device in a non-jailbroken state.
10
14
86
@halo_michael
Halo Michael
9 months
So… iOS17 mount disk1s2 as /var/mobile and mount disk1s8(a new created partition) as /var now💩
Tweet media one
5
10
84
@halo_michael
Halo Michael
6 years
Thanks the tool "multi_path" from @Jakeashacks ,now I can half jailbreak my iPhone7 on iOS11.3.1,and I can use dropbear to connect my phone.
19
10
72
@halo_michael
Halo Michael
6 years
Hello World!Thank you! @Jakeashacks
Tweet media one
5
5
73
@halo_michael
Halo Michael
4 years
Ummm
Tweet media one
6
6
72
@halo_michael
Halo Michael
4 years
#unc0ver 6.1.0 added supports for libkrw! Upgrade now! @ichitaso
Tweet media one
8
4
72
@halo_michael
Halo Michael
5 years
For easy to switch between #unc0ver and #checkra1n without manually install Cydia Substrate, you can install [Unc0ver Support Package] from my repo: .
7
15
66
@halo_michael
Halo Michael
1 year
Hey guys, I guess that's what you want:
Tweet media one
Tweet media two
Tweet media three
Tweet media four
9
10
74
@halo_michael
Halo Michael
6 years
Does anyone like it? It is my favorite.: )Thanks Thanks Thanks you @Jakeashacks
13
8
68
@halo_michael
Halo Michael
5 years
Tether downgrade to 13.2.3 with kernel version 19.2.0 on 6s+
4
9
66
@halo_michael
Halo Michael
5 years
[Tutorial] Set generator in any iOS version by using checkm8
0
20
65
@halo_michael
Halo Michael
9 months
Networkfixer App for all TrollStore users released here: Fix network permission for apps in Chinese models This fix will also included in next release of TrollStore😈
11
8
71
@halo_michael
Halo Michael
3 years
14.3 users with unc0ver jailbroken: You can now get untether without restore rootfs!🥳
@halo_michael
Halo Michael
3 years
👀
Tweet media one
Tweet media two
0
0
2
8
8
59
@halo_michael
Halo Michael
5 years
Unc0ver work fine on 12.2🥴 thanks @Pwn20wnd 🤗
Tweet media one
Tweet media two
16
4
56
@halo_michael
Halo Michael
9 months
Have both TrollStore and Standby😈
7
3
63
@halo_michael
Halo Michael
6 years
Tweaks does not show up in the settings?Now it's fixed. : ) @Jakeashacks
10
1
54
@halo_michael
Halo Michael
2 years
You guys can install tvos16 profile as a replacement If can't install, open with Safari.
@halo_michael
Halo Michael
2 years
Anyone also have tvos15 profile auto removed?
8
1
13
7
22
61
@halo_michael
Halo Michael
6 years
Thanks for @Jakeashacks ,AFC2 works on my iPhone7 iOS11.3.1 perfect now! :P
Tweet media one
15
5
52
@halo_michael
Halo Michael
5 years
iOS13.3 is VERY buggy.
@halo_michael
Halo Michael
5 years
iOS13.3 is VERY safe.
0
1
17
8
3
58
@halo_michael
Halo Michael
4 years
TIPS: a tfp0 exploit demo always shows tfp0 on the last line, not the first line.
0
4
52
@halo_michael
Halo Michael
8 months
Add entitlement .DiagnosticReports to access /var/containers/Shared/SystemGroup/systemgroup.com.apple.osanalytics/DiagnosticReports (New system crash log path).
Tweet media one
1
3
56
@halo_michael
Halo Michael
9 months
Due to iOS17 fixed xpc_crasher bug, Resolution Setter App now updated to 1.3.0 to support iOS17, enjoy!
@Jovibobo
Bon Jovi
9 months
@halo_michael 大佬你好~resolution setter巨魔应用您能更新支持iOS17吗?谢谢
0
0
1
5
8
53
@halo_michael
Halo Michael
7 months
Also it only effect devices which have ApplePMP, not ApplePMPv2, which means < A15 (not included)
@halo_michael
Halo Michael
7 months
New iOS17.2 kernel exploit by @Nyaaaaa_ovo
Tweet media one
51
98
613
7
5
50
@halo_michael
Halo Michael
5 years
@coolstarorg Did you really feel that nothing was wrong when you clicked the send button in Twitter?
2
0
47
@halo_michael
Halo Michael
5 years
How to set generator via Unc0ver on A12 (12.1.3~12.4). I just downgrade an iPhoneXR from 12.4 to 12.1.1b3 (And closed the password).
Tweet media one
9
14
49
@halo_michael
Halo Michael
4 years
Ok, so... Anyone wants to test it? TimeMachine on iOS, now have a preferenceloader bundle! Enjoy it ;)
Tweet media one
Tweet media two
8
7
48
@halo_michael
Halo Michael
5 years
iPhone11,2 @Pwn20wnd
Tweet media one
4
4
46
@halo_michael
Halo Michael
9 months
It’s time to iOS17😈 Legal Notices: That’s only for me
Tweet media one
@opa334dev
opa334
9 months
So just to be 100% clear Before OTA update: Make sure TrollStore is open in app switcher After OTA update: Start TrollStore through app switcher and immediately install the persistence helper into a system app
24
15
212
9
6
49
@halo_michael
Halo Michael
7 months
Sorry, someone told me it only effect to iOS 17.1🤯. Can someone test it?
@halo_michael
Halo Michael
7 months
New iOS17.2 kernel exploit by @Nyaaaaa_ovo
Tweet media one
51
98
613
7
3
45
@halo_michael
Halo Michael
1 year
Finally, join the kfd party👽
4
2
45
@halo_michael
Halo Michael
5 years
Tweet media one
5
4
40
@halo_michael
Halo Michael
5 years
zsh on iOS! Jesus!😋 Thanks @sbingner bring it to iOS😋
2
3
39
@halo_michael
Halo Michael
5 years
Wow, nice job! Thank you! @CorelliumHQ
Tweet media one
2
2
39
@halo_michael
Halo Michael
7 months
Must have entitlements: <key>.private.pmp.performance-spi</key> <true/> <key>.exception.iokit-user-client-class</key> <array> <string>ApplePMPUserClient</string> </array> first, so must find other exploit to work with.
3
1
38
@halo_michael
Halo Michael
4 years
Offsets:
Tweet media one
3
3
38
@halo_michael
Halo Michael
4 years
Remount rootfs as rw on Big Sur Big Sur mounted a snapshot on rootfs as iOS11.3.
Tweet media one
1
4
39
@halo_michael
Halo Michael
5 years
(Need free space: 4GB)
@halo_michael
Halo Michael
5 years
Android10 on iPhone7 🔥🔥🔥
Tweet media one
49
86
550
5
2
37
@halo_michael
Halo Michael
2 years
😼
Tweet media one
3
4
39
@halo_michael
Halo Michael
4 years
First jailbreak for iPhoneSE2!🔥 Thanks @Pwn20wnd #unc0ver #FreeTheSandbox
Tweet media one
Tweet media two
0
3
38
@halo_michael
Halo Michael
4 years
iPhone9,1 14.3
Tweet media one
@ModernPwner
ModernPwner
4 years
cicuta_virosa - iOS 14.3 kernel LPE for ALL devices. @FCE365 @RazMashat @CStar_OW please share it across jailbreak community. We are Anonymous. We are Legion.
87
369
1K
1
5
37
@halo_michael
Halo Michael
5 years
Finally, oob_timestamp can fully work on arm64 devices like on arm64e deivces now. Thanks for @0x36b :P
1
2
36
@halo_michael
Halo Michael
4 years
OK, test it success. Will release an "exploited" PPSSPP as soon as possible.
New blog post: "Psychic Paper" The story of the best. Sandbox escape. Ever.
71
568
2K
6
8
36
@halo_michael
Halo Michael
4 years
Checkra1n on sandcastle linux...
Tweet media one
Tweet media two
1
3
34
@halo_michael
Halo Michael
1 year
🐛
Tweet media one
@_p0up0u_
p0up0u
1 year
kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices:
31
123
457
3
8
37
@halo_michael
Halo Michael
5 years
Exploit demo of ipv6_pathmtu and cuck00 is out on my repo (both killed in iOS13.3.1). Enjoy. (Before use them, please check the notes first.)
2
4
32
@halo_michael
Halo Michael
7 months
Seems Dopamine’s forkfix request a real jb to do something, I stuck in dispatch_atfork_parent() anyway.
2
1
33
@halo_michael
Halo Michael
2 years
I can confirm it works; but I guess AltStore tethered itself so you can’t install more apps via AltStore hah @altstoreio Can your team fix it?
Tweet media one
@zhuowei
Zhuowei Zhang
2 years
Made an app that removes the three app limit for free provisioning. Hit "Go" just before installing apps. Should work on iOS 16.1.2 and below / iOS 15.7.1 and below. Thanks to XsF1re for figuring out the methods to patch:
65
139
550
5
3
31
@halo_michael
Halo Michael
5 years
"panicString" : "panic(cpu 1 caller 0xfffffff00dc589a4): \"userspace panic: File Radar to: [ launchd | missing executable ]. Set boot-arg launchd_missing_exec_no_panic=1 to work around.
0
4
33
@halo_michael
Halo Michael
4 years
Hey devs, don't compile your tweaks for arm64e with Xcode12. Otherwise you needs to change the machine specifier to the right value 0x2.
Tweet media one
4
2
33
@halo_michael
Halo Michael
6 years
[Release]:TimeMachine on iOS v0.1.0 update notes: Make TimeMachine looks "more open source" So there need a file named "Makefile" Simplify the way of system version checking Now support for iOS 11.4.x and above (iOS12).
1
7
33
@halo_michael
Halo Michael
5 years
Still can't get unc0ver work on my iPhone7... Respring loop then reboot after jailbreak.
20
1
33
@halo_michael
Halo Michael
5 years
@pwn30wnd @coolstarorg Coolstar: Great! Just bootloooped my last chimera/electra user.🤭
1
0
28
@halo_michael
Halo Michael
4 years
OHHHHHHHHHHHHHHHHHHHH
Tweet media one
4
2
31
@halo_michael
Halo Michael
2 years
Open source now:
@halo_michael
Halo Michael
2 years
If anyone wanna set resolution: *TrollStore request⚠️ *Resolution value verify✅ *Reboot revert resolution✅ So it’s 100% safe Have fun!😈
Tweet media one
23
21
101
6
5
29
@halo_michael
Halo Michael
7 months
You know, we have TrollStore already so😎
3
1
31
@halo_michael
Halo Michael
1 year
It's really too many offsets needs hardcode🫠 That's the the only things I can got, I don't know how to get others (only for SE2 16.1.2)
Tweet media one
6
0
32
@halo_michael
Halo Michael
3 years
Why the arm64 device does not need to read the apnonce beforehand to save blobs: Because arm64 device uses a deterministic algorithm to calculate apnonce from generator, you can use these codes to calculate it on any computer.
1
7
30
@halo_michael
Halo Michael
5 years
Some Tips: 1. OTA/iTunes upgrade will clean all snapshots on rootfs/varfs. 2. Starting with iOS 13, iOS has added a new detection mechanism. If the rootfs was modified, the OTA can only download the full package. (1/2)
1
5
30
@halo_michael
Halo Michael
4 years
I hope you like it :)
1
2
26
@halo_michael
Halo Michael
4 years
Just pushed an update for neofetch :)
Tweet media one
3
4
28
@halo_michael
Halo Michael
4 years
Anyone have already tested checkra1n 0.10.0 with iOS13.4.5b1?
7
2
27
@halo_michael
Halo Michael
4 years
Checkra1n's nvram_unlock patch finder seems is broken on 14.2b3.
1
3
26
@halo_michael
Halo Michael
8 months
👽
Tweet media one
4
3
27
@halo_michael
Halo Michael
5 years
@mild_tsunami @pwn30wnd @coolstarorg I can tell you responsibly that due to incorrect file checking and poor snapshot management, chimera does bootlooped some people’s device.
2
0
26
@halo_michael
Halo Michael
5 years
For anyone who wants to test oob_timestamp and get some panic logs:
3
1
25
@halo_michael
Halo Michael
4 years
Now I prefer to talk about some jailbreaking techniques not related to checkm8 because now my main device is iPhoneSE2.
6
2
27
@halo_michael
Halo Michael
4 years
nvram .System.boot-nonce=0x1111111111111111 nvram IONVRAM-FORCESYNCNOW-PROPERTY=.System.boot-nonce
1
4
26
@halo_michael
Halo Michael
5 years
Tweet media one
4
4
25
@halo_michael
Halo Michael
3 years
Two points I guess: 1.Doesn't work on A14 2.Can't verify update if you are using higher version of sep/baseband If you have sufficient evidence to break one of the above points, please leave a message
6
6
26
@halo_michael
Halo Michael
2 years
So, when I'm not boot with palera1n, my rootfs normal and sealed so I can boot as unjailbroken. And when I boot with palera1n, iBoot will read my boot-args and mount disk0s1s8 as rootfs, so it's jailbroken. Have fun!🕺
2
0
23
@halo_michael
Halo Michael
5 years
It seems that EmojPort conflicts with Safari Plus. But this happens only when the Rocketbootstrap version is 1.0.7~beta3, and it will not appear if you downgrade it to 1.0.6. @opa334dev @PoomSmart @rpetrich
Tweet media one
7
2
23
@halo_michael
Halo Michael
4 years
RIP @s0uthwes .... Your life is meaningful You will be missed RIP
0
2
25
@halo_michael
Halo Michael
4 years
Well, about CVE-2020-27932
Tweet media one
1
0
23
@halo_michael
Halo Michael
4 years
WTF? I don't even know there is zsh on iOS.
Tweet media one
2
2
26
@halo_michael
Halo Michael
2 years
CVE-2022-26757,fixed in iOS15.5
@ProjectZeroBugs
Project Zero Bugs
2 years
XNU: Flow Divert Race Condition Use After Free
2
18
61
1
4
21
@halo_michael
Halo Michael
4 years
Ok done, everything works fine.
Tweet media one
1
4
23
@halo_michael
Halo Michael
2 years
Resolution changed && substitute loaded🕺
Tweet media one
@halo_michael
Halo Michael
2 years
😼
Tweet media one
3
4
39
2
2
23
@halo_michael
Halo Michael
6 years
For those who want rename your snapshot on iOS12: Warning: It’s ONLY for DEVELOPER TEST!
2
6
22
@halo_michael
Halo Michael
5 years
A fully oob_timestamp exploit without finding memory addresses manually?
@_bazad
Brandon Azad
5 years
Tweet media one
45
91
628
1
3
22
@halo_michael
Halo Michael
8 months
Write into ppl protected address.
@xina520
朱心浪
8 months
ml_dbgwrap_halt_cpu new value: 800000ff dma_ctrl_1 new value: 8000000000070e01 kernel_addr phys_addr: fffffff14eca99d0 91db959d0 dma_ctrl_1 old value: 70e00 fffffff14eca99d0 : 4141414141414141
98
120
534
0
0
23
@halo_michael
Halo Michael
5 years
This is an App named " #Shelly " and you can download it from AppStore. when you done this, setting like that: (password is alpine)
Tweet media one
6
0
20
@halo_michael
Halo Michael
5 years
echo "/jb/usr/local/bin/dropbear -R -E --shell /jb/bin/bash -p 2222 > /dev/null 2>&1" > /jb/etc/rc.d/localdropbear && chmod 0755 /jb/etc/rc.d/localdropbear && /jb/etc/rc.d/localdropbear (2/2)
4
3
21
@halo_michael
Halo Michael
9 months
Wait, that's real! Also unbanned in iOS17👽
3
0
20
@halo_michael
Halo Michael
4 years
Failed
Tweet media one
Tweet media two
@halo_michael
Halo Michael
4 years
Will test if futurerestore is working on iOS14 or not(use iPhoneSE1 which only I can test).
4
0
7
4
5
20