/private/var/mobile/Media/coronaWhich is using exploit called racoon. racoon-exploit.conf layout:
sainfo address ::1 icmp6 address ::1 icmp6 { my_identifier user_fqdn "%243u%619$hhn"; my_identifier user_fqdn "%11u%625$hhn"; my_identifier user_fqdn "%244u%619$hhn"; my_identifier user_fqdn "%217u%625$hhn"; my_identifier user_fqdn "%245u%619$hhn"; my_identifier user_fqdn "%186u%625$hhn"; my_identifier user_fqdn "%246u%619$hhn"; my_identifier user_fqdn "%10u%625$hhn";Here is the comment by pod2g: Using a fuzzer, I found after some hours of work that there's a format string vulnerability in theracoon configuration parsing code! racoon is the IPsec IKE daemon (http://ipsec-tools.sourceforge.net/). It comes by default with iOS and is started when you setup an IPsec connection. Now you got it, Corona is an anagram of racoon :-) . By the way, the exploitation of the format string vulnerability is different than what was done in 2001, check it out if you're interested ! For the jailbreak to be applied at boot, racoon is started by a launchd plist file, executing the command : racoon -f racoon-exploit.conf is a large configuration file exploiting the format string bug to get the unsigned code started. The format string bug is utilized to copy the ROP bootstrap payload to the memory and to execute it by overwriting a saved LR in the racoon stack by a stack pivot gadget. The ROP bootstrap payload copies the ROP exploit payload from the payload file which is distributed with Corona then stack pivot to it. The idea is to escape from format strings as fast as possible, because they are CPU time consuming. The ROP exploit payload triggers the kernel exploit.
Download Corona Payload
To download payload use our github source forked from iOnic. Open terminal and type: git clone git://github.com/LetsUnlockiPhone/Corona-A5-Exploit-Absinthe-Jailbreak.git Happy code engineering.Recent Blog
Ultimate Guide: How to turn Off Restricted Mode on iPhone?
Automate Apple GSX check result obtaining?
iRemove Unlock iPhone 5S, 5C, 5, SE, 4S/4 Software
MacOS High Sierra Features: Set Up Websites in Safari on Mac
How to Enable iOS 11 Mail Reply Notification on iPhone 7
How to Bypass Apple Watch Passcode Problem
LetsUnlock Services List
iPhone & iPad Activation Lock Bypass
Use LetsUnlock iCloud Tool to bypass Activation Lock Screen on iPhone and iPad running on iOS version up to 14.6.
Read MoreUnlock Passcode Disabled iPhone or iPad
LetsUnlock iCloud Tool is ready to remove Find My and unlock your passcode disable device running on iOS 13.x.x in one click!
Read MoreMacOS iCloud Activation Lock Bypass
The LetsUnlock Mac iCloud Activation Lock Bypass Tool will help you to remove Activation Lock on an iCloud locked Mac which is stuck on Activation Lock Screen with no need to enter the correct Apple ID and password.
Read MoreMac EFI Firmware Passcode Bypass
The LetsUnlock EFI Bypass Tool is a one button solution, which you click to start the EFI Unlock process. Bypass EFI with out password! Everything else does the software.
Read MoreMacOS iCloud System PIN Bypass
The LetsUnlock MacOS iCloud System PIN Bypass Tool was designed to bypass iCloud PIN lock on macOS without passcode!
Read More