iPhone 5唔記密碼 好急!!!

2013-06-02 2:41 am
我唔記密碼唔想出去街解(冇曬啲嘢咁有咩辦法
我上網揾到堆句解鎖句但唔明咩意思
可唔可以幫我解釋清楚我唔識電腦啲嘢
iPhone Passcode Easily Defeated
I had a request come in tonight from an agency in NZ, looking to perform forensics on a drug dealer's iPhone. The iPhone happened to be passcode protected which, to my surprise, actually presented a problem for iLiberty+. I quickly hacked together a simple solution, and am simply posting this as a warning to anyone who thinks their data is safe because they have a passcode. The iPhone's passcode is quite simple to circumvent, and the latest versions of my forensic toolkit and manual now cover a simple three-step process to do it. While I'm not about to make the files themselves publicly available, this method can be easily adapted to crack the passcode by simply deleting a property list file. What a shame, that Apple went to the trouble of storing the passcode in the keychain, and yet the switch to turn it on and off is sitting in a little property list you can delete.
Step 1: Prepare a custom iPhone RAM disk. There are numerous How-To's out there to do this. I hex-edited the one that came with iLiberty+ and added my own shell intructions where the credits used to be. Your custom RAM disk should mount /dev/rdisk0s2 (say, /mnt) and simply delete the file /mnt/mobile/Library/Preferences/com.apple.springboard.plist. This is the config file that tells springboard "passcode: on". In one case, I had to move the entire preferences folder out of the way - this was on an iPhone that had been "permanently" disabled by several failed passcode attempts. Opened it up like a charm.
Step 2: The iPhone must be placed into recovery mode, but with a clean shutdown. You can either use the iPhone Utility Client to place the device into recovery mode, or "Slide to Power off", then force it into recovery on next boot... then boot the RAM disk using something like:
(iPHUC Recovery) #: filecopytophone Bypass_Passcode.bin
(iPHUC Recovery) #: cmd setenv\ boot-args\ rd=md0\ -x\ -s\ pmd0=0x9340000.0xA00000

回答 (1)

2013-06-02 6:33 pm
✔ 最佳答案
鬆擊敗iPhone的密碼
我已經請求今晚在新西蘭的代理,找一個毒販的iPhone上進行取證。的iPhone發生密碼保護,讓我吃驚,實際上提出了一個問題為iLiberty +。我趕緊一起砍死一個簡單的解決方案,只是簡單地張貼這是一個警告,任何人認為他們的數據是安全的,因為他們有一個密碼。 iPhone的密碼是很簡單的規避,現在我的法醫工具包和手冊的最新版本包括一個簡單的過程分為三個步驟來做到這一點。雖然我不是文件本身的公開,可以很容易地適應這種方法破解密碼,通過簡單地刪除屬性列表文件。有什麼丟人的,即蘋果去存儲在鑰匙串密碼的麻煩,但開關將其打開和關閉是坐在在一點點的屬性列表,您可以刪除。
步驟1:準備一個定制的iPhone RAM磁盤。有許多如何做到這一點。我一個十六進制編輯附帶iLiberty的+和補充我自己的殼intructions抵用。您的自定義RAM磁盤安裝/ dev/rdisk0s2,(比如說,/ mnt)中,只需刪除該文件/ MNT /移動/資源庫/ Preferences / com.apple.springboard.plist的。這是配置文件,告訴跳板“密碼:”。在一個案例中,我不得不將整個Preferences文件夾的方式 - 這是在iPhone上已被“永久”禁用幾個密碼嘗試失敗。打開它就像一個魅力。
第2步:iPhone必須放在進入恢復模式,但用乾淨關機。您可以使用iPhone實用工具,客戶端設備進入恢復模式,或者“移動滑塊來關機”,然後迫使它在下次開機進入恢復...然後引導RAM磁盤使用類似:
(iPHUC恢復)#:filecopytophone Bypass_Passcode.bin
(iPHUC恢復)#:CMD SETENV \啟動參數\ RD = MD0 \ X \ \ PMD0 = 0x9340000.0xA00000

(iPHUC恢復)#:CMD saveenv
(iPHUC恢復)#:CMD BootX的

步驟3:在您的自定義RAM磁盤吹走跳板配置,重新啟動手機和密碼將被繞過,因為跳板的默認值是“沒有密碼”。
參考: me


收錄日期: 2021-04-13 19:30:50
原文連結 [永久失效]:
https://hk.answers.yahoo.com/question/index?qid=20130601000051KK00303

檢視 Wayback Machine 備份