Тёмный

Getting JTAG on the iPhone 15 

stacksmashing
Подписаться 215 тыс.
Просмотров 333 тыс.
50% 1

In this video we explore how to get access to the JTAG interface on the new iPhone 15!
Special thanks to aunali1 & h0m3us3r, the Asahi Linux Project and Marc Zyngier!
Sign-up to the hextree.io waiting list here: hextree.io/
Links:
- Twitter: / ghidraninja
- Patreon: / stacksmashing
- Modified Chip Scrutinizer Firmware: github.com/stacksmashing/cs-s...
- macvdmtool patched for the iPhone 15: github.com/stacksmashing/macv...
- My DEF CON talk on Tamarin Cable: • DEF CON 30 - stacksmas...
- The secrets of Apple Lightning: • The secrets of Apple L...
- Central Scrutinizer Hardware: git.kernel.org/pub/scm/linux/...
- Central Scrutinizer on Tindie (does not work with iPhone 15 without modifications): www.tindie.com/products/aaafn...

Наука

Опубликовано:

 

30 сен 2023

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 278   
@muditbatra1681
@muditbatra1681 10 месяцев назад
Working in a semiconductor company myself, it’s really nice to see how much effort you put in this with literally 0 official documentation available with you. Please do a follow up as well on your progress.
@bassyey
@bassyey 10 месяцев назад
@@shueibdahir Pay is better in software lol. I left embedded field myself.
@janossydnepthalipao4277
@janossydnepthalipao4277 10 месяцев назад
I mean, I was about to say the same to him.
@shueibdahir
@shueibdahir 10 месяцев назад
@@bassyey How about hardware? Like sysadmin or some sort of it engineer? Do they pay aswell as software?
@farawayskies
@farawayskies 9 месяцев назад
@@bassyey Did the same. Worked in embedded a couple years and switched to software. Didn't do it for the money, although I did immediately get a six figure salary.
@farawayskies
@farawayskies 9 месяцев назад
@@shueibdahir I'd argue sysadmin does not pay nearly as well as software on average. I think you'd need to be a senior sysadmin to make what an entry level software engr can make.
@SomeDork353
@SomeDork353 10 месяцев назад
It's not even been 2 weeks, give poor Tim Cook a break lmao. Very cool work!
@djispro4272
@djispro4272 10 месяцев назад
Ah yes, Tim Cook is poor!
@Adolf1Extra
@Adolf1Extra 10 месяцев назад
Mr Tim Apple is merely an expendable pawn partaking in techno-feudalism to please his anti-capitalist shareholder lords.
@JPS13Laptop
@JPS13Laptop 10 месяцев назад
@@djispro4272 It's a figure of speech...
@Corei14
@Corei14 10 месяцев назад
*Tim Apple
@HyperVectra
@HyperVectra 10 месяцев назад
@@Corei14 lol you beat me too it!
@r.g.thesecond
@r.g.thesecond 10 месяцев назад
Amazing! Kudos to Asahi project as well for their dedication. Have a happy and productive hacking time!
@realcartoongirl
@realcartoongirl 10 месяцев назад
can you speak regular people language
@xanderplayz3446
@xanderplayz3446 18 дней назад
@@realcartoongirlThat is regular people language.
@aettic
@aettic 10 месяцев назад
Interesting stuff. It's always so cool to me to see folks who have specialized knowledge in the areas where hardware and software meet. Even just reading those notes from the documentation (From the Texas team, if I understood correctly?) about the 206 maybe being SWD is so cool to see: Playing around with hardware and probing it for signs of how it might work. Very cool.
@crusher70
@crusher70 10 месяцев назад
Fascinating work, well done getting this far. Can’t wait to see how far you can go. Good luck
@stacksmashing
@stacksmashing 10 месяцев назад
Thank you! :)
@crusher70
@crusher70 10 месяцев назад
@@stacksmashingI feel a visit to DigiKey is imminent 😂
@CyReVolt
@CyReVolt 10 месяцев назад
Well done! 🥳 It's so cool to see the community succeed together. Also I know that today is a holiday. I expect a breakthrough later tonight. :D Cheers ausm Pott! :)
@csbluechip
@csbluechip 10 месяцев назад
There seems to be virtually zero courses on hardware hacking and reversing. I really hope your hextree project changes this :)
@stacksmashing
@stacksmashing 10 месяцев назад
We hope so too! :)
@prakharmishra3000
@prakharmishra3000 10 месяцев назад
its actually pretty diverse depending on what you want to hack, so its difficult to make a generalised tutorial for hardware hacking and most people just learn it themselves
@jameshatton4211
@jameshatton4211 10 месяцев назад
Yes I agree. I think that's the highlight of this video actually, not the iPhone 15 hacking itself (which is still awesome)
@phr3ui559
@phr3ui559 10 месяцев назад
yes
@mattmurphy7030
@mattmurphy7030 10 месяцев назад
There are entire university degrees dedicated to embedded engineering lol
@majdps995
@majdps995 10 месяцев назад
Very well put video, straight to the point and no music. +1 sub.
@saschakaupp
@saschakaupp 10 месяцев назад
Now I want a new iPhone, just to be able to use JTAG via USB-C. No clue what to do with it, though.
@fffUUUUUU
@fffUUUUUU 10 месяцев назад
But maaaam!😢 It's for the homework!
@alfaxgo
@alfaxgo 10 месяцев назад
It's for getting some of the Android features without having to wait for Apple to announce the same features as great improvements on iPhone 17.
@a17waysJackinn
@a17waysJackinn 10 месяцев назад
idk im noob too no idea what hes talking, but "jailbreak" control hardware and overclocking chips or smth I GUESS..
@charon7320
@charon7320 9 месяцев назад
u are doing amazing work with so little documentation, literally a tech detective.
@blackhorseteck8381
@blackhorseteck8381 9 месяцев назад
Man, you brought me back memories of JTAG on the PS2 and X360, cool video though!
@duckydude20
@duckydude20 10 месяцев назад
so facinated by you guys. its my dream to do something like this someday. but i lack so much in everything...
@StormBurnX
@StormBurnX 10 месяцев назад
Excellent work. I was curious how long it would be, since the Macbooks and iPads are M1/etc rather than A-series chips. Quite interesting all the same!
@TheTarrMan
@TheTarrMan 10 месяцев назад
Awesome work you guys are doing.
@rickoneill4343
@rickoneill4343 10 месяцев назад
Just joined the channel. Can't wait to see what you have been up to!
@bekircandal3528
@bekircandal3528 10 месяцев назад
dude that was awesome. cant wait for another videos!
@pikniknyok9203
@pikniknyok9203 10 месяцев назад
omg i never think usb c so complex like this 😮 thanks mate for the video
@f.d.9326
@f.d.9326 10 месяцев назад
Insane stuff man! I wonder how one can know so much!
@Eaton.
@Eaton. 10 месяцев назад
i barely understand this stuff but im forever interested and grateful for the work you put in discovering these things.
@vassoharalambous5982
@vassoharalambous5982 10 месяцев назад
This is brilliant work!! Bravoo
@deez6005
@deez6005 10 месяцев назад
I love your channel. Keep up the good work
@thomasandrews9355
@thomasandrews9355 10 месяцев назад
LOL lot of comments which seem to have the "oh iphone owned" vibe... great work as Always
@justHeisen
@justHeisen 10 месяцев назад
I am very interested in these kinds of videos.
@nicknorthcutt7680
@nicknorthcutt7680 5 месяцев назад
Wow you are seriously talented, very interesting man!
@user-lo4er8wy9l
@user-lo4er8wy9l 10 месяцев назад
fantastic work.
@NeverGiveUpYo
@NeverGiveUpYo 10 месяцев назад
Yes! What a video! Thanks for this!!
@imawesome580
@imawesome580 10 месяцев назад
I jtaged my xbox off youtube tuttorials so this is extremely interesting and I hope you get the Jtag!
@v1x4z
@v1x4z 10 месяцев назад
Pretty neat stuff!
@sneauxburrow
@sneauxburrow Месяц назад
Great video, thank you 🙏
@prateekSpace
@prateekSpace 10 месяцев назад
very in-depth video! get new subscriber 🎉
@betogamer08
@betogamer08 9 месяцев назад
Good work!
@lucasimark7992
@lucasimark7992 10 месяцев назад
Oh wow, that was nice!
@hyperkiko
@hyperkiko 10 месяцев назад
FINALLY, a new video!!!!
@RazgrizDuTTA
@RazgrizDuTTA 10 месяцев назад
Hardware hacking is so fun! I have never done things that complex but even small hacks are fun!
@randallbro6749
@randallbro6749 10 месяцев назад
Nice didn't think it was possible
@jsandppr
@jsandppr 10 месяцев назад
Love the Zappa reference!
@stacksmashing
@stacksmashing 10 месяцев назад
Which one? 😅
@xenozelda0102
@xenozelda0102 10 месяцев назад
Awesome man!
@BAAAM101
@BAAAM101 9 месяцев назад
Amazing work. I’d like to see if youre able to jtag the new iPad with usb c. It offers more features with the usb port than the iPhone so you just might get a different result
@MediaCollection
@MediaCollection 10 месяцев назад
Love the zappa reference👌🏼
@stacksmashing
@stacksmashing 10 месяцев назад
Which Zappa reference? 😅 you are the second person mentioning it
@MediaCollection
@MediaCollection 10 месяцев назад
@@stacksmashing “The Central Scrutinizer”
@stacksmashing
@stacksmashing 10 месяцев назад
Ahhhhh thank you
@WhoaMykey
@WhoaMykey 10 месяцев назад
Tim Cook is filthy rich and needs no breaks! This needs to happen for research and repair purposes! To the people! Bless you for your hard work! I thank you 🙏
@Unbaguettable
@Unbaguettable 9 месяцев назад
I understood absolutely nothing but looked interesting, cool video
@dhruvgulati1667
@dhruvgulati1667 10 месяцев назад
Hey could you please explain more about debugging and exploiting.
@vxrlorxnxrreal
@vxrlorxnxrreal 10 месяцев назад
sehr interessantes video!
@iamfinky
@iamfinky 10 месяцев назад
Very exciting! I'd be interested to know what is possible with JTAG.
@csbluechip
@csbluechip 10 месяцев назад
JTAG generally: You get direct control of the CPU, so your imagination is the limit... Specifically here: Who knows how open/crippled it is yet ;)
@ACiDFiRE
@ACiDFiRE 9 месяцев назад
Cool keep grinding lad
@ArthurKhazbs
@ArthurKhazbs 10 месяцев назад
Good luck exploring the possibilities hidden inside the fruits of this corporation!
@johnnykernel4557
@johnnykernel4557 10 месяцев назад
Amazing work done!
@hammers_sq
@hammers_sq 24 дня назад
Hi, where can I find the target configuration file you used to run openocd? Because I can find one only for iphone until iphone 11..
@Magnom365
@Magnom365 10 месяцев назад
You are quick!
@SneakyCaleb
@SneakyCaleb 10 месяцев назад
What does this allow you to do ? I only know the word jtag from the 360 days.
@piholino
@piholino 10 месяцев назад
I have no idea what the hell you are doing but it was interesting to watch.
@hanspeter24
@hanspeter24 10 месяцев назад
stacksmashing the best!!!
@kwiky5643
@kwiky5643 10 месяцев назад
Great stuff
@kritikusi-666
@kritikusi-666 10 месяцев назад
this is awesome.
@jarredallen
@jarredallen 10 месяцев назад
its not uncommon ( for my line of work) to see a jtag locked physically. maybe this is the case right here. some pull up resistor to some pads might be needed.
@stacksmashing
@stacksmashing 10 месяцев назад
Ah in this case it's a bit more complicated - you can read up on the demotion of the iPhone X using checkm8 :)
@jameshatton4211
@jameshatton4211 10 месяцев назад
I see you've done this with the iPhone 15, but I'm curious if JTAG can be found a similar way on Samsung Galaxy devices and if one could possibly access the KNOX e-fuse data store on a galaxy device? So essentially if the Knox bit has been tripped; that section in the boot loader can be reversed? This is currently the only thing stopping me from going to GraphineOS and being able to support encryption and have as much support with the boot loader security as say a supported Pixel device?
@trevorgray3681
@trevorgray3681 10 месяцев назад
I don't remember much about it and doubt it's relevant anymore, but I remember being able to not trip knox on my s6 edge. I'm sure whatever exploit was there has been fixed though.
@jameshatton4211
@jameshatton4211 10 месяцев назад
@@trevorgray3681 I would like to reverse the boot loader and how it trips the Knox because it's an implementation that's still in practice today? I've built ROMs and custom firmware for Android and have bucket loads of tools for just about any kind i of hacking and reversing software known? I've also got experiencing dumping binaries by direct chip reading and FlashROM using raspberry Pi SPI interface + voltage changer and read from diagnostic ports on MacBooks etc. Then Hex hacking the dumped binary and then writing my own stuff back on it to unblock a forgotten password? I can find out the voltages etc but if I could possibly talk between his created device and using USB-C then I can certainly attempt to play around? Have a little snoop & sniff and see what's up yo? See it could mean I could possibly make any Samsung a private phone like the Google Pixel with GrapheneOS. I can already rebuild and change the GrapheneOS to work on my Samsung or any Samsung even if the firmware doesn't support it? I know what partitions to write to, I can build a custom recovery. I can impart binaries etc etc and get what ever I need working? It's the being able to support encryption from recovery that is the most important? So it's worth sniffing even if not for Knox? It's just more enticing to offer should anyone be interested in using their Samsung as a private phone without needing to purchase a Pixel to so? In Australia Pixels are for fanatics and people who purchased it outright with money and not on a plan? That's a very very tiny slice of the Australian market unfortunately? Sorry but I figured I may as well spew my thoughts all over the RU-vid comments cause I'm Autistic as fuck and have narcolepsy and you've got me on a medication is working don't know where to stop moment? So sucks to you if you've read this far 😛
@atinder2006
@atinder2006 10 месяцев назад
When they added usb c and controller embedded into cpu i had feeling they are already worried about security.
@nilsmertens6253
@nilsmertens6253 10 месяцев назад
Nice, keep going
@jerromerro9405
@jerromerro9405 9 месяцев назад
I have a Short question , i Hope for an answer . The iPhone15 has 5g Right? Can i use this for sniffing 5g packets like osmocombb for gsm??
@ErtugrulOzdemir-mf1gl
@ErtugrulOzdemir-mf1gl 10 месяцев назад
really cool!
@Freedom-of-Thought
@Freedom-of-Thought 10 месяцев назад
Can you teach how to jailbreak iOS 17? Thank you
@NewGroup78
@NewGroup78 10 месяцев назад
How and where do we learn hardware hacking and all these things?? please tell me.
@bloodaid
@bloodaid 9 месяцев назад
Is it possible to send data from an app to the JTAG with this?
@jameshatton4211
@jameshatton4211 10 месяцев назад
This is so awesome. I would really like to be able to use hardware hacking as a business? So if you can get JTAG to iPhone 15, does that mean that the boot loader can be reverse engineered and the iPhone could essentially run non-apple or customised firmware?
@sol_xz
@sol_xz 10 месяцев назад
imagine this on ipad with windows for arm
@overPowerPenguin
@overPowerPenguin 10 месяцев назад
​​@@sol_xzthis is not how it works. You need Windows drivers and a lot of patches to make everything run, even if you can load an custom EFI boot. It's insane amount of work and don't worth it, because, in the end, it's cheaper and faster to buy an Windows tablet that probably supports also Linux.
@bameninghong-chan
@bameninghong-chan 9 месяцев назад
Do you have a cheap way to read and Write Bricked android, it has 11 UFS debug pins but no public layout, it is surface duo with an SDR855 and there is no public EDl loaders available
@limebulls
@limebulls 9 месяцев назад
What do you recommend for beginners to start learning electronics?
@filipenicoli_
@filipenicoli_ 10 месяцев назад
Amazing!
@Marvinzock34
@Marvinzock34 10 месяцев назад
YOOOO NEW VIDEO
@gamerstar8311
@gamerstar8311 10 месяцев назад
Cool stuff
@DMONSKULL
@DMONSKULL 10 месяцев назад
amazing work
@ishdemon_
@ishdemon_ 10 месяцев назад
man's voice evolved around 6:48 lmao
@dcfix35
@dcfix35 10 месяцев назад
Excellent ✅✅
@HoZyVN
@HoZyVN 10 месяцев назад
Amazing
@2.7petabytes
@2.7petabytes 10 месяцев назад
Zappa would be proud 😂
@shortgrowinchannel101
@shortgrowinchannel101 10 месяцев назад
My dream iphone😊
@jerm_
@jerm_ 10 месяцев назад
so whats possible with JTAG? is it similar to jailbreak?
@aacc8466
@aacc8466 9 месяцев назад
is this a way to retrieve a lost password/iCloud ? asking for a friend
@jerromerro9405
@jerromerro9405 10 месяцев назад
Good to know that you didnt finish the work , i have to know that checkm8 didnt work on the “newer“ iphones But i thought for the Usb-c “problem“ on the TamarinCable FW where only changing the cables and changing some code .. ok Its Not so easy But on iPhone 15 swd is Open i think thats a good Start ..
@JonMasters
@JonMasters 10 месяцев назад
Excellent
@robertclarkguitar
@robertclarkguitar 9 месяцев назад
Nice. ❤😮
@mattsold1267
@mattsold1267 10 месяцев назад
What do you need to study to learn all this stuff? The automotive field is heavy on this type technology and I want to get be able to heavily study these systems but there isn’t enough info online?? Some pls respond
@elbert5208
@elbert5208 9 месяцев назад
It's a secretive field
@hydro5168
@hydro5168 9 месяцев назад
will this let me get a mod menu for Black Ops 2?
@bankruptsee
@bankruptsee 10 месяцев назад
Ok can I host 10th prestige challenge lobbies on my iPhone now?
@XCTDEV
@XCTDEV 10 месяцев назад
Already knew it! but may brick after flash Jtag
@javierxcod
@javierxcod 9 месяцев назад
The way you say macbook is the same as the "city people" episode in south park 😂😂😂
@stacksmashing
@stacksmashing 9 месяцев назад
Bahahaha 🤣
@ajmalaboobacker5110
@ajmalaboobacker5110 9 месяцев назад
Is he tree available for sign up?
@kipchickensout
@kipchickensout 9 месяцев назад
Will 0xT have a free trial?
@cleardd
@cleardd 10 месяцев назад
Very cool
@KpFriendly
@KpFriendly 9 месяцев назад
It’s so simple I’m completely able to follow this with 5 years of experience Jk This stuff seems really complicated but interesting, as someone getting into cyber security, you definitely got me more interested in the hardware side of it all, I learned alot from this video!
@Sulphur_67
@Sulphur_67 10 месяцев назад
could this mean jailbreaking is possible?
@H8RSAPPRECIATE
@H8RSAPPRECIATE 9 месяцев назад
I know you said it’s not a exploit but I realized once they switched to USB C I assumed it might make it easier for someone to find a exploit that way and since you can connect to more devices than with a lightning cable ( not saying I know anything or claiming to be a expert)
@jtw-r
@jtw-r 10 месяцев назад
I heard initial rumours (months before apple confirmed the USB C port), that they were going to REMOVE the charging port entirely. I rolled my eyes at that - am I correct in assuming some physical port is always required for JTAG or whatever diagnostics apple uses? For device security, it seems like you’d always want that to be a physical connection-right?
@stacksmashing
@stacksmashing 10 месяцев назад
I think on some of the newer Apple Watches they use some very high-frequency communication instead of contacts - so potentially they can get rid of it. But it would kill low-latency audio, high-speed storage etc
@saschakaupp
@saschakaupp 10 месяцев назад
I think at least the pro models will have USB-C for a long time, as they can now record video to external SSDs.
@ameliabuns4058
@ameliabuns4058 10 месяцев назад
It's certainly possible but it'd suck. Plus they could have contact pins on the phone I guess? But I highly doubt it'll happen on the pro models
@saschakaupp
@saschakaupp 10 месяцев назад
@@ameliabuns4058 As long as the contact pins are inside a USB-C socket, I'm happy. :)
@phr3ui559
@phr3ui559 10 месяцев назад
@@stacksmashing oh
@NieuNotNew
@NieuNotNew 10 месяцев назад
thats huge, the central scrutinizer. that pcbs purpose is to enforce all the laws that havent been passed yet
@inwerp
@inwerp 10 месяцев назад
Have you ever heard of J137 / banana cable for T2 Macs / EDWIN course of T2 repair which was clearly done before T2 macbooks were even released? i have one and maybe it would be interesting information to share.
@stacksmashing
@stacksmashing 10 месяцев назад
I have not! :) To be honest I have not looked a lot at the hardware side of MacBooks before this! Sounds interesting!
@inwerp
@inwerp 10 месяцев назад
@@stacksmashing sent you an email to the addresse listed in YT
@gabriledyt
@gabriledyt 10 месяцев назад
Maybe a new full jailbreak after this?
@b_1337
@b_1337 9 месяцев назад
You’re awesome
@zackaria
@zackaria 10 месяцев назад
This is really intresting to see. Do you think you can do TMSC For JTAG?
@stacksmashing
@stacksmashing 10 месяцев назад
SWD doesn't need TMSC - or what do you mean?
@zackaria
@zackaria 10 месяцев назад
@@stacksmashing I thought the reduced JTAG wire uses a wire for TMSC?
@stacksmashing
@stacksmashing 10 месяцев назад
@@zackariaNah, just clock and IO :)
@zackaria
@zackaria 10 месяцев назад
@@stacksmashing Oh alright
@zackaria
@zackaria 10 месяцев назад
@@stacksmashing Dang it i just realized that too
@PepsiMan42069
@PepsiMan42069 10 месяцев назад
if/when you can achieve JTAG, what can you do with it?
@eyesoffloraandfauna8728
@eyesoffloraandfauna8728 9 месяцев назад
Make videos for best sideload method
@SF-eg3fq
@SF-eg3fq 10 месяцев назад
yo sup hope u read my comment, the hardware world is really confusing to me. I always stuggle to know how to start, I'll be glad if u can give me your ardvice on this, thanks.
Далее
How the Apple AirTags were hacked
8:38
Просмотров 1,6 млн
Why 111-1111111 is a valid Windows 95 key
6:26
Просмотров 1,9 млн
IQ Level: 10000
00:10
Просмотров 2,9 млн
Вопрос Ребром - Субо
49:41
Просмотров 1,1 млн
Bringing homebrew to the Game & Watch
6:13
Просмотров 271 тыс.
The secrets of Apple Lightning - Part 1
9:45
Просмотров 823 тыс.
Mining Bitcoin on the Game Boy
8:35
Просмотров 1,2 млн
Online Multiplayer on the Game Boy
8:12
Просмотров 206 тыс.
DOOM on the Game and Watch
6:00
Просмотров 405 тыс.
Hacking the Game Boy with a Silver Play Button
4:41
Просмотров 35 тыс.
iPhone 16 - 20+ КРУТЫХ ИЗМЕНЕНИЙ
5:20
$1 vs $100,000 Slow Motion Camera!
0:44
Просмотров 28 млн
Новые iPhone 16 и 16 Pro Max
0:42
Просмотров 2,1 млн