1. 写测试代码.
- #include<stdlib.h>
- #include<stdio.h>
- int main(int argc,char* argv[]){
- printf("testios\n");
- return 1;
- }
2. 编译.
xcrun -sdk iphoneos clang -arch arm64 main.c -o testhook
3. 签名我这里直接用自己的 (做逆向时不要用自己的防被吊销)
- file testhook
- $testhook: Mach-O 64-bit executable arm64
4. 查找证书.
- haidragondeMacBook-Air:~ haidragon$ file testhook
- testhook: Mach-O 64-bit executable arm64
- haidragondeMacBook-Air:~ haidragon$ security find-identity -v -p codesigning
- 1) 3EBAD7EE1C26691217CF3D1E4485E6C44D15E52A "xxxxxxxxxxxxxxxxx"
- 2) E6EBDA70B2F2FD24AC69657B4ACE009E17C66BFB "xxxxxxxxxxxxxxxxx"
- 2 valid identities found
- haidragondeMacBook-Air:~ haidragon$ codesign --force --verify --verbose --sign "xxxxxxxxxxxxxxxxx" ./testhook
5. 端口转发.
iproxy 4567 22
发到手机上 SSH -p 4567 [email protected]
修改成 777 运行.
- iPhone:/var root# chmod 777 ./testhook
- iPhone:/var root# ./testhook
- testios
- iPhone:/var root#
来源: http://www.bubuko.com/infodetail-3067537.html