# apt-get install com.ericasadun.utilities gdb gawk zip ldid odcctools ps
# cd /var/mobile/Applications/?ID
# otool -l ./[application name].app/[application name] | grep crypt
cryptoff (numeric)
cryptsize (numeric) - CHECK!
cryptid (numeric)
* cryptsize+cryptoff
excute application for iphone.
# ps ax | grep [application name]
* PID CHECK!
# gdb -p [PID]
(gdb) dump memory dump.bin 0x2000 0x[cryptsize+cryptoff]
(gdb) quit
* Modify Application
start address is cryptoffset+1000h, overwrite from dump file.
find cryptid for Dump file cryptsize+0x10
modify value 0x01 to 0x00, for 0x01 of after of find value
* cryptoffset: # otool -f /var/mobile/Applications/?ID/[application name].app/[application name]
offset of architecture1
# cd /var/mobile/Applications/?ID
# otool -l ./[application name].app/[application name] | grep crypt
cryptoff (numeric)
cryptsize (numeric) - CHECK!
cryptid (numeric)
* cryptsize+cryptoff
excute application for iphone.
# ps ax | grep [application name]
* PID CHECK!
# gdb -p [PID]
(gdb) dump memory dump.bin 0x2000 0x[cryptsize+cryptoff]
(gdb) quit
* Modify Application
start address is cryptoffset+1000h, overwrite from dump file.
find cryptid for Dump file cryptsize+0x10
modify value 0x01 to 0x00, for 0x01 of after of find value
* cryptoffset: # otool -f /var/mobile/Applications/?ID/[application name].app/[application name]
offset of architecture1




