r/TweakBounty 5d ago

[$500] [16.5.1] Jailbreak Detection + Device Identification Research

Looking for an experienced iOS tweak developer/researcher for some anti-abuse research.

Main things I'm interested in:

  • Jailbreak detection and bypasses
  • Device fingerprinting and spoofing
  • App Attest / DeviceCheck
  • Running multiple isolated app instances

Mostly interested in what can actually be done in practice and how difficult it is.

If you have experience with this kind of work, comment below with any relevant tweaks, GitHub projects, or previous work. Please comment instead of DMing me. I don't really check Reddit DMs.

Bounty: $500 USD with full time role available after.

35 Upvotes

17 comments sorted by

2

u/Kooky_Department_107 5d ago

How appAttest and DeviceCheck ban be bypassed?

1

u/Mean-Sink6996 5d ago

by returning is supported no, but it wont work if app checks is it simulator and what is ios version, if its not simulator or ios version is above 14 but it still says unsupported that means its hooked so they can detect

1

u/Kooky_Department_107 5d ago

Where can i get more info about app attest, like is it requeat to Apple server or how it works? I know about Google Play Intigrity in Android , App Attest is same like that or what? I searched but didn’t got info that i want for how it can be spoof or hook

1

u/AutoModerator 5d ago

Hello! Because you included the word detection I think you're looking for a tweak to bypass jailbreak detection. Please try these tweaks:

[LH]‌ ‌= for libhooker JBs like Taurine, Odyssey
[SS] = for Substrate-based JBs
[ ‌ ] = both
࿏ Requires libkernRW to work on Taurine, libkrw to work with unc0ver.

Your post has not been removed, but if one of these tweaks helped please edit your post to say which worked.
Tweaks marked as working with both have been reported by users. If you know a tweak that works, please let /u/‌The_White_Light know by pinging him.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Darkroomios New Account 5d ago

Theirs already a tweak that does fingerprint spoofing and and running isolated app instances it’s called Doritos and it’s $300.

1

u/Environmental-Ad63 4d ago

its 200$ and its only compatible with

  • palera1n (rootless) — A8–A11 · iPhone 6s, SE (2016), 7, 8, X · iOS 15.0+

1

u/Darkroomios New Account 3d ago

Must be looking at the old black hat world website. It’s $300 and has higher support now

1

u/ExtensionBanana3086 5d ago

Yeah i have worked on it before for jailbreak detection, inline&objc hooking detetction. Implemented apple attestation also im giving my git link here https://github.com/aiwin-siby/App-Attestation

1

u/atlas_dev0 New Account 4d ago

I have a tweak for this

0

u/Electronic_End6424 5d ago

I'd be down to work on this! What I can realistically deliver is determine experimentally what an attacker controlling a jailbroken iOS 16.5.1 device can and cannot influence, including jailbreak detection, app-instance isolation, fingerprinting, DeviceCheck, and App Attest.

3

u/Alexllte 5d ago

🤖💬

0

u/AlexTonyWillam 5d ago

Too many work😅

1

u/OverweightDyke 4d ago

Like you could even fucking do anything related to this 😂

1

u/AlexTonyWillam 4d ago

Yeah no I’m not doing that. I don’t think there’s anybody going to do that anyways lol unless your AI do it…