<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jailbreak &#8211; Gary&#039;s &#8230;Lasamia</title>
	<atom:link href="https://garynil.tw/tag/jailbreak/feed/" rel="self" type="application/rss+xml" />
	<link>https://garynil.tw</link>
	<description>🍎 📱 🖥 🔨 😄</description>
	<lastBuildDate>Sat, 07 Jul 2018 13:50:30 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://i0.wp.com/garynil.tw/wp-content/uploads/2017/01/cropped-Gary_v3.0.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>Jailbreak &#8211; Gary&#039;s &#8230;Lasamia</title>
	<link>https://garynil.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">147732124</site>	<item>
		<title>[Tutorial / 教學] Get Electra (Multipath TCP) installed on iOS 11.2~11.3.1 / 安裝開發者版本的 Electra (iOS 11.2~11.3.1)</title>
		<link>https://garynil.tw/2018/07/814/tutorial-get-electra-multipath-tcp-installed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tutorial-get-electra-multipath-tcp-installed</link>
					<comments>https://garynil.tw/2018/07/814/tutorial-get-electra-multipath-tcp-installed/#respond</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Sat, 07 Jul 2018 07:34:57 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Electra]]></category>
		<category><![CDATA[ios11]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[越獄]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=814</guid>

					<description><![CDATA[<p>CoolStar just released Electra for iOS 11.2-11.3.1 today (2018.07.07). Electra for iOS 11.2-11.3.1 is now available! https://t.co/YxbYAmMkVK Note: First run will require rebooting. Make sure to re-run electra after the first reboot to continue jailbreak. — CoolStar (@coolstarorg) 2018年7月6日 This tutorial shows how to install Electra IPA (Multipath TCP version) on your device with paid Apple develop...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2018/07/814/tutorial-get-electra-multipath-tcp-installed/">[Tutorial / 教學] Get Electra (Multipath TCP) installed on iOS 11.2~11.3.1 / 安裝開發者版本的 Electra (iOS 11.2~11.3.1)</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="aligncenter size-full" src="https://i0.wp.com/img.garynil.tw/images/2018/07/ANW.png?resize=700%2C394&#038;ssl=1" width="700" height="394" /></p>
<p><a href="https://twitter.com/coolstarorg/status/1015369667542564865">CoolStar</a> just released Electra for iOS 11.2-11.3.1 today (2018.07.07).</p>
<blockquote class="twitter-tweet" data-lang="zh-tw">
<p dir="ltr" lang="en">Electra for iOS 11.2-11.3.1 is now available! <a href="https://t.co/YxbYAmMkVK">https://t.co/YxbYAmMkVK</a><br />
<span id="more-814"></span></p>
<p>Note: First run will require rebooting. Make sure to re-run electra after the first reboot to continue jailbreak.</p>
<p>— CoolStar (@coolstarorg) <a href="https://twitter.com/coolstarorg/status/1015369667542564865?ref_src=twsrc%5Etfw">2018年7月6日</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p>This tutorial shows how to install Electra IPA (Multipath TCP version) on your device with paid Apple developer account. Make sure you have basic knowledge for this tutorial, you are fully doing this at your own risk, I’m not responsible for any damage or data losing&#8230; etc.<br />
此教學是教你安裝 iOS 11.2~11.3.1 的越獄工具 &#8211; Electra，前提是你擁有「付費的」開發者帳號及基本知識，意思是說手機爆炸我不管。</p>
<h2>1st. What you need / 必備工具</h2>
<ul>
<li><a href="https://coolstar.org/electra/">Electra ipa (Multipath TCP version)</a></li>
<li><a href="https://developer.apple.com/account/">Apple developer account</a>，you should login your Apple Developer account into Xcode first.</li>
<li>Resign tool，recommend <a href="https://dantheman827.github.io/ios-app-signer/">IOS Appsigner</a></li>
<li>ipa install tool, such as iFunbox..etc<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/L7G.png?w=700&#038;ssl=1" alt="L7G.png" /></li>
</ul>
<p>And we start!</p>
<h2>2nd. Create a provision file only for Electra</h2>
<p>For supporting the requirement of Electra dev version &#8211; Multipath TCP service, you need to create a provision file with multipath TCP service enabled in your developer account.<br />
此次 Electra 開發者版本是使用 Multipath TCP 漏洞，因此我們需要使用一組開啟 Multipath TCP 功能的 provision profile。</p>
<p>Remind to add your device UDID to your account before you create provision file. You can check this <a href="https://www.wikihow.com/Add-a-New-Device-to-Your-Apple-Developer-Portal">Tutorial</a> if you don&#8217;t know how to add your device into your account.<br />
再開始之前，記得先將你的裝置 UDID 註冊到你的開發者帳號，可以參考<a href="https://www.wikihow.com/Add-a-New-Device-to-Your-Apple-Developer-Portal">教學</a></p>
<h3>2-1. Registering a new App ID in App ID page of Identifier section</h3>
<p>進入開發者帳號頁面後，我們選擇右側 Identifier → AppID → 並註冊一組新的 App ID<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/S77.png?w=700&#038;ssl=1" alt="S77.png" /></p>
<h3>2-2. Fill in your custom bundle ID, for example, I used <code>tw.garynil.Electra1131</code></h3>
<p>填入 Bundle ID，建議用「你常用的名稱」+ Electra1131，例如我是 <code>tw.garynil.Electra1131</code><br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/X3C.png?w=700&#038;ssl=1" alt="X3C.png" /></p>
<h3>2-3. Enable Multipath TCP serivce for your provision file</h3>
<p>為此組 App ID 開啟 Multipath TCP 服務<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/ed2.png?w=700&#038;ssl=1" alt="ed2.png" /></p>
<p>完成後，我們便創立了一組只為此次 JB 使用並有 Multipath TCP 服務的 AppID</p>
<h2>2-4. Then get into the Provision Profile section and create new iOS Provision Profile</h2>
<p>接下來我們將建立剛剛創立的 App ID 的 Provision Profile，我們先進入右側 Provision Profile 區塊並按+號<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/iFJ.png?w=700&#038;ssl=1" alt="iFJ.png" /></p>
<h2>2-5. Choose the App ID we create previously.</h2>
<p>我們為此組欲建立的 Provision Profile 選擇剛剛創立的 App ID<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/j5M.png?w=700&#038;ssl=1" alt="j5M.png" /></p>
<h2>2-6. Choose devices you would like to install.</h2>
<p>選擇你要適用的裝置<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/ICH.png?w=700&#038;ssl=1" alt="ICH.png" /></p>
<h2>2-6. Finally, we can download the Provision Profile we created.</h2>
<p>將剛剛建立的 Provision Profile 下載至你的電腦<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/kk6.png?w=700&#038;ssl=1" alt="kk6.png" /></p>
<h2>3rd. Extract resigned Electra ipa / 重簽名 ipa</h2>
<p>We open the Resign tool <a href="https://dantheman827.github.io/ios-app-signer/">IOS Appsigner</a> and selected：<br />
&#8211; Input file：the newest Electra ipa / 最新版 Electra ipa<br />
&#8211; Signing Certificate：Your iPhone Developer Certificate / 你的開發者帳號憑證，記得先於 Xcode 登入它才抓的到<br />
&#8211; Provisioning Profile：Download from apple developer page we created on last step. / 剛剛製作並下載的 Provisioning Profile<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/Tu3.png?w=700&#038;ssl=1" alt="Tu3.png" /><br />
Press start then it will resign and extract the ipa for you.<br />
按下開始他便依照你的設定重簽名了</p>
<p>註：如果出現錯誤，檢查你的 ipa 內的 <code>Payload/Electra1131.app/embedded.mobileprovision</code> 是否有 multipath 這行，以及你的裝置的 udid。<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/c1X.png?w=700&#038;ssl=1" alt="c1X.png" /></p>
<h2>4th. Install on your device / 在裝置上安裝 Electra ipa</h2>
<p>After these steps, you can install this ipa on your device by tools such as <a href="https://support.apple.com/zh-tw/apple-configurator">Apple Configurator</a>、<a href="http://www.i-funbox.com/">iFunbox</a>&#8230;etc<br />
用 <a href="https://support.apple.com/zh-tw/apple-configurator">Apple Configurator</a>、<a href="http://www.i-funbox.com/">iFunbox</a> 等工具安裝你剛剛建立的 ipa 吧！<br />
<img data-recalc-dims="1" decoding="async" src="https://i0.wp.com/img.garynil.tw/images/2018/07/KX8.png?w=700&#038;ssl=1" alt="KX8.png" /></p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2018/07/814/tutorial-get-electra-multipath-tcp-installed/">[Tutorial / 教學] Get Electra (Multipath TCP) installed on iOS 11.2~11.3.1 / 安裝開發者版本的 Electra (iOS 11.2~11.3.1)</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2018/07/814/tutorial-get-electra-multipath-tcp-installed/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">814</post-id>	</item>
		<item>
		<title>[Tutorial] How to build Electra ( iOS 11 Jailbreak app ) with ldid2</title>
		<link>https://garynil.tw/2018/01/691/tutorial-build-electra-ios-11-jailbreak-app-ldid2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=tutorial-build-electra-ios-11-jailbreak-app-ldid2</link>
					<comments>https://garynil.tw/2018/01/691/tutorial-build-electra-ios-11-jailbreak-app-ldid2/#comments</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Fri, 26 Jan 2018 07:20:35 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[build]]></category>
		<category><![CDATA[Electra]]></category>
		<category><![CDATA[ios11]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Xcode]]></category>
		<category><![CDATA[越獄]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=691</guid>

					<description><![CDATA[<p>Coolstar has released a new beta version of Electra jailbreak toolkit for iOS 11 – iOS 11.1.2. The author also release the source code of the jailbreak toolkit on Github. I would like to try to find out how the toolkit work by building it on my own. So I wrote this guide for people (who may be a developer) can follow instructions and build Electra toolkit successfully. The most important of all, b...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2018/01/691/tutorial-build-electra-ios-11-jailbreak-app-ldid2/">[Tutorial] How to build Electra ( iOS 11 Jailbreak app ) with ldid2</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p><a href="https://twitter.com/coolstarorg">Coolstar</a> has released a new beta version of <a href="https://coolstar.org/electra/">Electra</a> jailbreak toolkit for iOS 11 – iOS 11.1.2. The author also release the source code of the jailbreak toolkit on <a href="https://github.com/coolstar/electra">Github</a>. I would like to try to find out how the toolkit work by building it on my own. So I wrote this guide for people (who may be a developer) can follow instructions and build Electra toolkit successfully.</p>
<p><img decoding="async" src="https://i0.wp.com/lh3.googleusercontent.com/LUQPFWITqe-Tm6oW6rmpTgrB1KbOkKQhDWCJiPrHEVrmlMUAIwdvAvHk6P8" width="1600" height="1427" class="aligncenter size-full" /></p>
<p>The most important of all, before you start to read this guide, make sure you have the ability to handle the problem you meet. You are fully doing this at your own risk, I&#8217;m not responsible for any damage caused.</p>
<p>If you don&#8217;t know what this article is doing, you can download the released ipa on the author <a href="https://coolstar.org/electra/">website</a> resign by tools such as <a href="https://github.com/maciekish/iReSign">iResign</a> and install it to your iPhone without building it youself.</p>
<p><span id="more-691"></span></p>
<h4>Advantage of build the toolkit yourself</h4>
<ol>
<li>Know the structure of the code</li>
<li>Preventing if there were malicious code in toolkit.</li>
<li>Remove unused features. For example, in this toolkit, it will install Anemone tweak after you jailbreak. The last part in this tutorial will told you how to do it.</li>
<li>Keep the latest version, you can pull the latest version from Github and build it yourself.</li>
<li>You need to turn the SIP off of macOS before you did these instructions.</li>
</ol>
<h2>Clone repo</h2>
<p>You can access the Electra repo on <a href="https://github.com/coolstar/electra">Github</a>, which contain a Xcode project.<br />
Clone it to your ~/Desktop or any other path you like to work with.</p>
<p></p><pre class="urvanov-syntax-highlighter-plain-tag">git clone https://github.com/coolstar/electra.git</pre><p></p>
<p><a href="//i0.wp.com/lh3.googleusercontent.com/MjLpIWf3lGmh1pvhgDYZ3OSh2Up386AFRXHHF7ejUmnksTJDXGJGT63B1zI" data-featherlight="image"><img decoding="async" alt="Array" src="//i0.wp.com/lh3.googleusercontent.com/MjLpIWf3lGmh1pvhgDYZ3OSh2Up386AFRXHHF7ejUmnksTJDXGJGT63B1zI" width="811" height="600" scale="2"></a></p>
<h2>Build Xcode project</h2>
<p>Open the Xcode project then build. You will meet some error with the clean Xcode environment.</p>
<h2>ldid2 error</h2>
<p>After you build the project, you will meet a error. You will see this error:</p>
<p><a href="//i0.wp.com/lh5.googleusercontent.com/vZU-gDoh2jhgFA8eBncA2CFIBVkgO3Shf3kJ1iVUzIpYQE9CpgunWAQ7y0Y" data-featherlight="image"><img loading="lazy" decoding="async" alt="Array" src="//i0.wp.com/lh5.googleusercontent.com/vZU-gDoh2jhgFA8eBncA2CFIBVkgO3Shf3kJ1iVUzIpYQE9CpgunWAQ7y0Y" width="875" height="600" scale="2"></a></p>
<p>At the first test, I tried install ldid original version by</p>
<p></p><pre class="urvanov-syntax-highlighter-plain-tag">brew install ldid</pre><p></p>
<p>and the bin of the ldid would be at <code>/usr/local/Cellar/ldid/1.2.1</code>, then link it as ldid2 in <code>/usr/local/bin</code></p>
<p></p><pre class="urvanov-syntax-highlighter-plain-tag">ln -s /usr/local/Cellar/ldid/1.2.1/bin/ldid /usr/local/bin/ldid2</pre><p></p>
<p><a href="//i0.wp.com/lh4.googleusercontent.com/s6XTUMGfpfA7ta-e3zueDiD6E66a1I8YJ9U5yEFdcAqyEfhNWoMP0QUMg4Y" data-featherlight="image"><img loading="lazy" decoding="async" alt="Array" src="//i0.wp.com/lh4.googleusercontent.com/s6XTUMGfpfA7ta-e3zueDiD6E66a1I8YJ9U5yEFdcAqyEfhNWoMP0QUMg4Y" width="837" height="600" scale="2"></a></p>
<p>With the ldid, it can work, and you can build the toolkit into your iPhone. However, the jailbreak won&#8217;t success and block on 2/3.</p>
<p>So I tried to find the solution on Github. I found <a href="https://github.com/xerub">xerub</a> make a <a href="ldid2">ldid2</a> with SHA256 support. However, this repo is not complete. The repo are lack of make code and wasn&#8217;t build.</p>
<h2>Add ldid2 to <code>/usr/local/bin/</code></h2>
<p>I completed the ldid2 project and put the binary in release version <a href="https://github.com/GaryniL/ldid/releases/tag/0.1-2">page</a>.<br />
<a href="https://github.com/GaryniL/ldid">Project Link</a></p>
<p><a href="https://github.com/GaryniL/ldid"><img loading="lazy" decoding="async" alt="Array" src="//i0.wp.com/lh6.googleusercontent.com/oEAPtGL4HQ1iq4EKW-VjfpSVeQoTkHU_O1yJZ0XB2kEcHWc6Y2Cmu-w7JqA" width="900" height="484" scale="2"></a></p>
<p></p><pre class="urvanov-syntax-highlighter-plain-tag">curl https://raw.githubusercontent.com/GaryniL/ldid/master/ldid2 -o ldid2
sudo mv ldid2 /usr/local/bin/
chmod +x /usr/local/bin/ldid2</pre><p></p>
<p>Then rebuild the project, it will work.<br />
<a href="//i0.wp.com/lh3.googleusercontent.com/HuX8tRwjS2qGOvuRaQdHHw-_knyoBynGLGWemba1jNcauklvrsOrW5DCj-o" data-featherlight="image"><img loading="lazy" decoding="async" alt="Array" src="//i0.wp.com/lh3.googleusercontent.com/HuX8tRwjS2qGOvuRaQdHHw-_knyoBynGLGWemba1jNcauklvrsOrW5DCj-o" width="900" height="153" scale="2"></a><br />
<a href="//i0.wp.com/lh5.googleusercontent.com/B-TmX8yOe6Sd9u0HcBPzLwY_AVToPvguK0r5819RkDfBZmFoLX07xlbJjLU" data-featherlight="image"><img loading="lazy" decoding="async" alt="Array" src="//i0.wp.com/lh5.googleusercontent.com/B-TmX8yOe6Sd9u0HcBPzLwY_AVToPvguK0r5819RkDfBZmFoLX07xlbJjLU" width="277" height="600" scale="2"></a></p>
<h2>Remove Anemone</h2>
<p>Besides, you can remove the line for preventing installing Anemone tweak<br />
<a href="//i1.wp.com/lh3.googleusercontent.com/zymV2cO9wQeooRedfMGl6ceHlGRq-4KacyFSn2O3ljX6fXM0Uk1_4Y19PC4" data-featherlight="image"><img loading="lazy" decoding="async" alt="Array" src="//i1.wp.com/lh3.googleusercontent.com/zymV2cO9wQeooRedfMGl6ceHlGRq-4KacyFSn2O3ljX6fXM0Uk1_4Y19PC4" width="900" height="590" scale="2"></a></p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2018/01/691/tutorial-build-electra-ios-11-jailbreak-app-ldid2/">[Tutorial] How to build Electra ( iOS 11 Jailbreak app ) with ldid2</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2018/01/691/tutorial-build-electra-ios-11-jailbreak-app-ldid2/feed/</wfw:commentRss>
			<slash:comments>11</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">691</post-id>	</item>
		<item>
		<title>Yalu102 &#8211; App crash at launched after Jailbreak</title>
		<link>https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=yalu102-app-crash-at-launched-after-jailbreak</link>
					<comments>https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/#respond</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Fri, 27 Jan 2017 16:52:28 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 10]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[Resign]]></category>
		<category><![CDATA[Yalu]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=301</guid>

					<description><![CDATA[<p>After I use Yalu beta 1 on iOS 10.2 for jailbreaking my iPhone 6s &#38; 6s plus, as I mentioned in my previous paragraph：Yalu102 &#8211; iOS 10.2 Jailbreak, it works more stable then previous version. I tried to install some tweaks such as iFile、KeyBoard Accio and SwipeSelection to enhance the functionality of my phone. You can try to find out which tweak supported iOS 10.2 here and here I install...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/">Yalu102 &#8211; App crash at launched after Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p>After I use <a href="https://yalu.qwertyoruiop.com/" target="_blank">Yalu beta 1</a> on iOS 10.2 for jailbreaking my iPhone 6s &amp; 6s plus, as I mentioned in my previous paragraph：<a href="https://garynil.tw/2017/01/295" target="_blank">Yalu102 &#8211; iOS 10.2 Jailbreak</a>, it works more stable then previous version.</p>
<p>I tried to install some tweaks such as iFile、KeyBoard Accio and SwipeSelection to enhance the functionality of my phone.<br />
You can try to find out which tweak supported iOS 10.2 <a href="http://www.ios10tweaks.com/p/ios-102-compatible-tweaks.html" target="_blank">here</a> and <a href="https://docs.google.com/spreadsheets/d/14e9GB-PNhDJuKI799InVFWrUQc-qn-Wd3zRJHKGkKr0/pubhtml#" target="_blank">here</a></p>
<p>I installed <strong>Cydia Substrate</strong> for supporting tweaks and <strong>iFile</strong> for debugging. However, after I respring in Cydia, at the next time I start using any other apps, the apps will crash at launch..</p>
<p>Including Yalu it self&#8230;.<br />
[fve]https://youtu.be/AaaNOYl273U[/fve]</p>
<p><span id="more-301"></span></p>
<p>Although system apps can launch normally eg.Preference. But user&#8217;s apps can&#8217;t, such as apps downloaded from AppStore.</p>
<p>And it works normally after rebooting, your phone wasn&#8217;t Jailbreak then due to Yalu is a semi-untethered jailbreak.</p>
<p>[fve]https://youtu.be/fwfNP0ILuxg[/fve]</p>
<p>First, I try to find out what is the problem if it was made by installing iFile or Cydia Substrate.</p>
<p>During testing time, I restore my 6s with ipsw of 10.2 (since SHSH of iOS 10.2 is opening now, I can restore it at anytime) for the purpose of prepainge a clean environment to test.</p>
<p>After testing, I found that if I try to install Cydia Substrate with other tweaks and respring, it caused the problem.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>But the result is incorrect.</strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>In previous testing, I tried to use the <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">public version ipa</a> of Yalu which <a href="https://twitter.com/qwertyoruiopz" target="_blank">qwertyoruiop</a> released on <a href="https://yalu.qwertyoruiop.com/" target="_blank">his site</a>.</p>
<p>But at the first time I jailbreak my phone, I used the version builded by myself from the code qwertyoruiop released on <a href="https://github.com/kpwn/yalu102" target="_blank">Github</a>. Besides, I&#8217;ve tried two version of it (<a href="https://github.com/kpwn/yalu102/commit/04b574267e65c13682ecd8771cff5353732178a1" target="_blank">04b574267e65c13682ecd8771cff5353732178a1</a> &amp; <a href="https://github.com/kpwn/yalu102/commit/24723830b74aac9825d53a3cd38d53439f52ad57" target="_blank">24723830b74aac9825d53a3cd38d53439f52ad57</a>)</p>
<p>At last, I found out the problem is caused by the different version of Yalu (the recent version on Github will make apps can&#8217;t launch).</p>
<p>So here is the way to solve the problem (remove Yalu and install the previous version of Yalu102)</p>
<ul>
<li>Delete the old version of Yalu from your phone</li>
<li>Resign <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">public version ipa</a> of Yalu (<a href="https://garynil.tw/2017/01/295" target="_blank">tutorial</a>)</li>
<li>Install it into your phone then reboot</li>
<li>Jailbreak your phone again, Cydia will works normally, if not, you can solve by <a href="https://www.reddit.com/r/jailbreak/comments/5jv0ag/tutorial_how_to_rejailbreak_your_device_after/" target="_blank">this way</a></li>
<li>Done</li>
</ul>
<p>[fve]https://youtu.be/CzL70D5FTgI[/fve]</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/">Yalu102 &#8211; App crash at launched after Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2017/01/301/yalu102-app-crash-at-launched-after-jailbreak/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">301</post-id>	</item>
		<item>
		<title>Yalu102 &#8211; iOS 10.2 Jailbreak</title>
		<link>https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=yalu-ios-10-jailbreak</link>
					<comments>https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/#comments</comments>
		
		<dc:creator><![CDATA[Gary]]></dc:creator>
		<pubDate>Thu, 26 Jan 2017 14:49:18 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Cydia]]></category>
		<category><![CDATA[iOS 10]]></category>
		<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[JB]]></category>
		<category><![CDATA[Lucas]]></category>
		<category><![CDATA[qwertyoruiopz]]></category>
		<category><![CDATA[Resign]]></category>
		<category><![CDATA[Yalu]]></category>
		<guid isPermaLink="false">https://garynil.tw/?p=295</guid>

					<description><![CDATA[<p>繼上次寫了 iOS 10.1.x 越獄 &#8211; Yalu beta 3 也快過了一個月，悲觀的 Lucas 終於釋出了新的 beta 1 版本。 這裡補充一下，請大家尊重一下開發者大大們，不要去騷擾拍打、催促他完成 Jailbreak。他是沒有義務要完成這些的，這些騷擾讓他的氫碘鈉化碳碎了..，也聲稱 10.2 版本釋出之後將不會再投入研究 在新版本中， Lucas 加入了對 MobileSubstrate 的相容性 (來源) 有比較深入研究，或者再追蹤 reddit 的人應該都知道在 10.1.x 時，Lucas 釋出的版本是不支援 MobileSubstrate 的 因為目前大部分的 tweak 都依賴 MobileSubstrate，當時大部分的 tweaks 是無法使用的。 &#160; 當時也有人推出 Substrate Fix (iOS 10) Source：http:...</p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/">Yalu102 &#8211; iOS 10.2 Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></description>
										<content:encoded><![CDATA[<p>繼上次寫了 <a href="https://garynil.tw/2016/12/234" target="_blank">iOS 10.1.x 越獄 &#8211; Yalu beta 3</a> 也快過了一個月，悲觀的 <a href="https://twitter.com/qwertyoruiopz" target="_blank">Lucas</a> 終於釋出了新的 <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">beta 1</a> 版本。</p>
<p>這裡補充一下，請大家尊重一下開發者大大們，不要去騷擾<del datetime="2017-01-26T13:44:53+00:00">拍打</del>、催促他完成 Jailbreak。他是沒有義務要完成這些的，這些騷擾<del datetime="2017-01-26T15:14:31+00:00">讓他的氫碘鈉化碳碎了..</del>，也<a href="https://twitter.com/qwertyoruiopz/status/823293730857820160" target="_blank">聲稱</a> 10.2 版本釋出之後將不會再投入研究</p>
<p>在新版本中， Lucas 加入了對 MobileSubstrate 的相容性 <a href="https://twitter.com/qwertyoruiopz/status/824508945695997952" target="_blank">(來源)<br />
</a>有比較深入研究，或者再追蹤 reddit 的人應該都知道在 10.1.x 時，Lucas 釋出的版本是不支援 MobileSubstrate 的<br />
因為目前大部分的 tweak 都依賴 MobileSubstrate，當時大部分的 tweaks 是無法使用的。<br />
<span id="more-295"></span></p>
<p>&nbsp;</p>
<p>當時也有人推出 Substrate Fix (iOS 10) Source：<a href="cydia://url/https://cydia.saurik.com/api/share#?source=http://83.218.67.215/~ijapija00/cydia" target="_blank">http://83.218.67.215/~ijapija00/cydia</a><br />
但在當時我自己測試之下，是蠻不穩定的.. 不過目前 iOS 10.1.1 使用 Yalu beta 3 的人只能使用這套來支援 Cydia Substrate<br />
而使用 Yalu 102 新版的人，直接安裝 Cydia Substrate 即可，在 1 月底也有為了 iOS 10 釋出的 0.96301 的更新檔</p>
<p>&nbsp;</p>
<p>而此次 beta 1 版本，修正了這些不穩定性，就我自己使用上知道改正了以下錯誤：</p>
<ul>
<li>可以正常 Log 出錯誤訊息，NSLog 和 printf 正常使用</li>
<li>支援 MobileSubstrate</li>
<li><code>killall -9 Springboard</code> 在我的機器上是穩定的，這有待換到別的機器測試</li>
<li><code>killall -9 backboardd</code> 可以正常使用，不會讓手機重啟</li>
</ul>
<p>但透過 Yalu app 越獄失敗的情況還是存在，需要多嘗試一兩次才能成功</p>
<p><a href="https://flic.kr/p/RkDR2E"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/474/32383879132_986dccfb52_z.jpg?resize=640%2C418&#038;ssl=1" alt="螢幕快照 2017-01-26 下午7.41.25" width="640" height="418" /></a><br />
&nbsp;</p>
<p>================== 更新 ====================</p>
<p><strong>2017/02/01 更新</strong><br />
現在設備情況分為兩種：是 iPhone 7 以及非 iPhone 7 系列</p>
<ul>
<li>如果你是使用 iPhone 7 在 iOS 10.1.1 ，請使用<a href="https://garynil.tw/2016/12/234" target="_blank">這篇教學</a>配上 <a href="https://yalu.qwertyoruiop.com/mach_portal+yalu-b3.ipa" target="_blank">Yalu beta 3</a> (註：beta 4-1 作者沒有包好，也註明是損毀的，不要聽信網路傳言用 4-1 。)。</p>
</li>
<li>
<p>如果你是使用其他 64 bit 裝置並在 iOS 10，請使用 <a href="https://yalu.qwertyoruiop.com/yalu102_beta7.ipa" target="_blank">Yalu 102 beta 7</a>，詳請再參照此篇教學</a></p>
</li>
</ul>
<p><strong>2017/01/30 更新</strong><br />
推出 <a href="https://yalu.qwertyoruiop.com/yalu102_beta6.ipa" target="_blank">beta 6 版本</a><br />
現已支援所有 iOS 10 64 bit 的裝置除了 iPhone7, iPad Air 2 和 iPad Mini 4<br />
<em>fixes some issues some device/fw combos were having with the tfp0 / nonceEnabler patch</em></p>
<p>iPhone 7 可以使用 Yalu 舊版 <a href="https://yalu.qwertyoruiop.com/mach_portal+yalu-b3.ipa" target="_blank">beta 3</a></p>
<p>詳細更新項目可以參照<a href="https://yalu.qwertyoruiop.com" target="_blank">原始網頁</a></p>
<p><strong>2017/01/29 更新</strong><br />
推出 beta 5 版本<br />
<em>placebo effect</em></p>
<p><strong>2017/01/26 補充</strong><br />
我用兩台裝置 6s (iOS 10.2) 及 6s Plus (iOS 10.1.1) 做的測試<br />
在 6s Plus (iOS 10.1.1) 上使用 Yalu102 會出現幾個不能運作的情況：<br />
1.OpenSSH 無法運作，完全連不進去<br />
2.Log 失效</p>
<p>#註：後來證實是自己用 Github 上的版本 build 出來才會有問題，用官方版本是正常的</p>
<p>&nbsp;<br />
&nbsp;<br />
<del datetime="2017-02-04T14:39:21+00:00">但這些問題在 6s (iOS 10.2) 上一切正常<br />
而 OpenSSH 問題，只要透過 Yalu beta 3 就可以解決，但舊版又超不穩定..</del></p>
<p><strong>0127 補充</strong><br />
在 10.2 越獄之後，我有遇到裝完 iFile 和 Cydia Substrate 之後，除了系統 app 以外其他 app 點開馬上閃退的情況<br />
交叉測試之後發現：<br />
在第一次越獄之後，要先單獨安裝 Cydia Substrate，其他套件等此次安裝完 respring 之後在另外安裝<br />
便不會發升上述問題了<br />
&nbsp;</p>
<p>而進入文章重點，那此次 Jailbreak 要如何安裝使用呢？<br />
其實跟<a href="http://www.pangu.io" target="_blank">盤古 iOS 9 越獄</a> 一樣，是透過安裝一個 app 來觸發漏洞建立越獄環境<br />
當你每次重新啟動手機之後，是需要重新越獄的</p>
<p>而安裝 Yalu App 主要分為以下三個方法：</p>
<h3>方法1：透過 Cydia Impactor 和開發者帳號來安裝 (最簡易懶人)</h3>
<p>你需要準備的是作者編譯好的 <a href="https://yalu.qwertyoruiop.com/yalu102_alpha.ipa" target="_blank">ipa 安裝檔</a>以及 <a href="http://www.cydiaimpactor.com" target="_blank">Cydia Impactor</a><br />
然後使用 Cydia Impactor 將 ipa resign 後裝至你的手機<br />
詳細教學可以看我<a href="https://garynil.tw/2016/12/234" target="_blank">上次這篇</a></p>
<p>缺點就是因為 Apple 佛心讓大家可以成為開發者，但限制是你每 7 天要 resign 一次<br />
然後強烈建議不要使用自己的付費開發者帳號，他會將你 revoke ，之後在 Xcode 開發還要設定一次很麻煩..</p>
<h3>方法2：使用付費開發者帳號 Resign</h3>
<p>相信有付費開發者帳號的人有開發經驗會比較聰明，我也懶得截圖，就將步驟寫的簡易一點：<br />
主要的目的就是透過你的帳號將 ipa resign，</p>
<h1>以下這一小段可以略過，因為使用 Yalu 10.2 beta 1 不需要這麼做</h1>
<p>在 Yalu 第一版除了 ipa 本身以外，還要 resign 裡面的 dylib，先將 ipa 副檔名改為 zip 後打開找到以下檔案<br />
並透過 codesign指令，加上你的 iPhone Developer 描述檔及代號重新簽名<br />
這裡會發生問題有一種特殊情況，你必需要開一個在<a href="http://developer.apple.com/" target="_blank">開發者後台</a>去新增一個 APP ID 符合 ipa 的 bundle idintifier，才可以正常的 resign dylib</p>
<p></p><pre class="urvanov-syntax-highlighter-plain-tag">codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftCore.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftCoreGraphics.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftCoreImage.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftDarwin.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftDispatch.dyli
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftFoundation.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftObjectiveC.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftQuartzCore.dylib
codesign -f -s "iPhone Developer: XXX (XXXXXXXXXX)" ./Frameworks/libswiftUIKit.dylib</pre><p></p>
<p>============================================</p>
<p>而 ipa resign 的部分可以透過 <a href="http://mac.softpedia.com/get/Developer-Tools/iModSign.shtml" target="_blank">iModSign</a> 或者 <a href="https://github.com/maciekish/iReSign" target="_blank">iResign</a> 有 GUI 的簽名工具完成<br />
你只需要導入你的開發者帳號的 Provisioning Profile，可以從 Xcode 的設定來尋找，要使用 Provisioning Profile:* 的那一個<br />
路徑在：<code>~/Library/MobileDevice/Provisioning\ Profiles</code></p>
<p><a href="https://flic.kr/p/Qhz9wh"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/519/31692656164_1740abae3a_z.jpg?resize=640%2C539&#038;ssl=1" alt="螢幕快照_2017-01-26_下午10_36_47" width="640" height="539" /></a></p>
<p>之後再透過 <a href="http://www.i-funbox.com" target="_blank">iFunbox</a> 之類的工具安裝 ipa 即可完成</p>
<h3>方法3：當你擁有了原始碼</h3>
<p>因為這次作者直接<a href="https://github.com/kpwn/yalu102">公開原始碼</a>，便可以用這種特殊的形式來操作</p>
<p>以 Xcode 開啟專案，</p>
<p>這裡會有個小問題，作者的 code 中會使用到 IOKit 這個 framework，正常開啟是會顯示失敗無法 build 的，我將解決方法寫在<a href="https://garynil.tw/?p=298" target="_blank">這篇 &#8211; Import IOKit framework into Xcode project</a></p>
<p>1.直接 Archive，Export for development 匯出成擁有你簽名的 ipa ，然後安裝、結束。<br />
2.接上手機直接 build 進去<br />
這方法好處是可以隨時 pull 作者 update 的新版本，隨時 build 保持最新版～</p>
<p><a href="https://flic.kr/p/QZD9rE"><img data-recalc-dims="1" loading="lazy" decoding="async" src="https://i0.wp.com/farm1.staticflickr.com/759/32157412680_c542db0aba_z.jpg?resize=640%2C466&#038;ssl=1" alt="螢幕快照_2017-01-26_下午11_09_13" width="640" height="466" /></a></p>
<p>這篇文章 <a rel="nofollow" href="https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/">Yalu102 &#8211; iOS 10.2 Jailbreak</a> 最早出現於 <a rel="nofollow" href="https://garynil.tw">Gary&#039;s ...Lasamia</a>。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://garynil.tw/2017/01/295/yalu-ios-10-jailbreak/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">295</post-id>	</item>
	</channel>
</rss>
