越獄簡(jiǎn)單,不寫,越獄后,進(jìn)行一些運(yùn)行時(shí)操作。
項(xiàng)目代碼:http://git.oschina.net/lishangkai/reverseproject
這是一些用到的軟件或語(yǔ)言:
Openssh:連接手機(jī)(在cydia中搜索下載即可)
iproxy:修改映射
Cycript:一款腳本語(yǔ)言,是混合了objective-c與javascript語(yǔ)法的一個(gè)工具,讓開(kāi)發(fā)者在命令行下和應(yīng)用交互,在運(yùn)行時(shí)查看和修改應(yīng)用
手機(jī)cydia搜索即可安裝
電腦安裝教程

一些命令:
ssh 登錄
ssh root@192.168.x.x
密碼alpine
ssh root@iPhone ip 終端卡住,啥反應(yīng)都沒(méi)有。解決辦法如下
1、卸載open ssh
2、添加源:?http://cydia.ichitaso.com/,cydia中搜索Dropbear并安裝(已經(jīng)失效,請(qǐng)查找其他dropbear安裝方法參考)
3、重新安裝open ssh
然后重試ssh root@iPhone ip,就可以了
要是還不行,參考這篇文章(http://www.itdecent.cn/p/91e0c22a6ea7),我是用這個(gè)辦法連上的:
USB連接:先安裝brew($ ruby -e"$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/master/install)")
再安裝usbmuxd,$ brew install usbmuxd
再鍵入$ iproxy? 2222? 22
waiting for connection
(不要關(guān)閉這個(gè)終端)
新建終端,$ssh -p 2222 root@localhost?
Cycript
lishangkaide-iPhone:~ root# cycript -p SpringBoard
cy# UIApp
cy# alert =[[UIAlertView alloc]initWithTitle:'di yi ge ni xiang' message:'di y ci lai ni xiang' delegate: nil cancelButtonTitle:'OK' otherButtonTitles:nil]
#">"
cy#[alert show]
cy#[#0x17ea7980 show]
cy# var shot =[SBScreenShotter sharedInstance]
#""
cy#[shot saveScreenshot:YES]
cy# UIApp
#""
cy# #0x16d3ff00.keyWindow#";layer = >"
cy# sb = #0x16fde9f0
#";layer = >"
cy# sb.alpha = 0.5
0.5
cy# sb.hidden = YES
true
cy# sb.hidden = NO
false
cy# sb.backgroundColor =[UIColor redColor]

lishangkaide-iPhone4:~ root#ps aux查看進(jìn)程
lishangkaide-iPhone4:~ root#ps -e
lishangkaide-iPhone4:~ root# cycript -p 1288
cy# UIApp
cy# #0x16575230.keyWindow
#";layer = >"
cy# #0x16575230.keyWindow.rootViewController
#""
cy# #0x165f8770.visibleViewControllew
#""
cy# #0x16584ce0.view
#">"
cy# view = #0x16555f60
#">"
cy# *view
{isa:UIView,_layer:#"",_gestureInfo:null,_gestureRecognizers:null,_subviewCache:@[#">",#">",#">",#">"],_charge:0,_tag:0,_viewDelegate:#"",_backgroundColorSystemColorName:@"orangeColor",_countOfMotionEffectsInSubtree:0,_viewFlags:@error,_retainCount:6,_tintAdjustmentDimmingCount:0,_shouldArchiveUIAppearanceTags:0,_interactionTintColor:null,_layoutEngine:null,_boundsWidthVariable:null,_boundsHeightVariable:null,_minXVariable:null,_minYVariable:null,_internalConstraints:null,_constraintsExceptingSubviewAutoresizingConstraints:null}
cy# view0 = #0x16555de0
#">"
cy# label0 = #0x16555c40
#">"
cy# label1 = #0x16555000
#">"
cy# view1 = #0x16554e70
#">"
cy# view1.backgroundColor =[UIColor redColor];
#"UIDeviceRGBColorSpace 1 0 0 1"
cy#[view frame]
{0:{0:0,1:0},1:{0:320,1:480}}
cy#[view setFrame:{0:{0:55,1:75},1:{0:250,1:90}}]
cy# label1.text
@"20"
cy# label1.text = 'haha'
"haha"
詳情請(qǐng)參考百度云