R00tkitSMM

Advanced
@R00tkitSMM

CVE-2024-27804. POC for CVE-2024-27804

138

Pishi. Pishi is a code coverage tool like kcov for macOS.

76

R00tkitSMM.github.io. HTML

9

h264fuzzer. Objective-C

7

TinyInstLibfuzzer. C++

6

MacRootKit. macOS RootKit that can fuzz binaries/drivers, do kernel r/w, hook kernel and userspace functions, set custom breakpoints, GDB stub (in progress), match KDK kernels with DWARF debug symbols to release kernels, MachOs of all kinds, dyld shared caches, Objective C/Swift metadata, dump libraries, library injection (e.g. cycript), and crawl iOS apps

3

apple-fuzz-poc. I will provide details and pocs for some bugs I found.

3

xnuspy. an iOS kernel function hooking framework for checkra1n'able devices

3

KextFuzz. Code of KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting Mitigations (USENIX Security'23)

3

macosvm. Tool for running macOS guest virtual machines in macOS 12 host or higher on M1 arm64 Macs

2

RouterOS. Overview of router OS and some reversing.

2

iOS-SDKs. iOS 9 - iOS 16 SDK including symbols for private frameworks.

2

bookmarks. A personal list of various resources for those who are interested in learning about infosec and hacking and keeping themselves up to date. This is by no means a complete nor fresh list, but I occasionally add entries to lists.

2

desc_race. iOS 15.1 kernel exploit POC for CVE-2021-30955

2

Win32k-heap-sanitizer. win32k.sys heap memory sanitizer.

2

fsfuzzer. C++

2

Apple-Sample-Code. Apple Sample Codes

1

VirtualApple. Work with macOS VMs using Virtualization

1

VmDeviceFuzz. inprocess userspace driver hardware interface analysis

1

iOSRyuk. Forked from original @bxl1989 who then was forked by @userlandkernel

1

Vulnerability-analyze. Vulnerability analyze QEMU

1

haiku. The Haiku operating system. (Pull requests will be ignored; patches may be sent to https://review.haiku-os.org).

1

ViDeZZo. ViDeZZo source code.

1

fairplay_research. load kext into user mode

1

darwin-xnu-build. XNU kernel, Kernel Collection and CodeQL build scripts

1

webdavfs. C

1

arm-trusted-firmware. Read-only mirror of Trusted Firmware-A

1

iokit-utils. Dev tools for probing IOKit

1

TQ-pre-jailbreak. Hello from pattern-f.

1

vpwn. xnu local privilege escalation via cve-2015-1140 IOHIDSecurePromptClient injectStringGated heap overflow | poc||gtfo

1

iomfb-exploit. Exploit for CVE-2021-30807

1

acrn-hypervisor. Project ACRN hypervisor

1

HelloSilicon. An introduction to ARM64 assembly on Apple Silicon Macs

1

openqnx. mirror of git://git.code.sf.net/p/monartis/openqnx

1

VirtioCrash. C++

1
35
Apply