, 10 tweets, 5 min read Read on Twitter
@axi0mX’s #checkm8 is out and let’s you debug your device (up to A11).

But how is this done?
Here is a little thread on dumping the bootrom (SecureROM) on demoted devices with Apple’s official tools.

1/ connect the cable using the correct lighting orientation and launch astris
2/ select the CPU you want to work on (in this case, we’ll select CPU0) and halt it.

As result, astris will provide the output containing the selected CPU’s registers with their content.
We can now use the debugger to copy the content from the memory region
3/ use the command ‘save’ followed by the destination filename on the host, the address of the SecureROM and the size of the desired region to be copied (512kb are enough)
4/ you should now have your file saved into the destination you entered in the command.
Note, in case you didn’t specify a path along with the filename, astris will save the file into your currently working directory. Find it and open it (HEX) and you should see it as follows:
5/ You can easily find Probes and software on Twitter. As a reference, you can check this post for Apple’s official softwares (which work only with their own probes). Otherwise check bonobo as an alternative.

6/ Debugger like Kong and Kanzi (as well as SNR, with some little patching on an astris daemon) can work absolutely good for any supported lightning device. I recommend to install Tigris Tools (15A) from the previous link if you have one of these.

7/ You can find useful informations about this technology in this thread below. For what my little experience makes possible, feel free to ask any detail and I’ll do my best to help you out.

8/ I used a development device to dump the SecureROM as an example of astris usage, note that the probe is not required to achieve this with the exploit publicly released, as you can use a normal lightning cable.
9/ here is an example of astris view before and after demotion. #checkm8 enabled successfully the debugging and the devices now expose AP to JTAG
10/ (and final) if you are looking for refurbished probes for an accessible price feel free to DM me
#checkm8
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Giulio Zompetti
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!