Uploaded April 2024 | Updated September 2026, 4 days ago
This is a demo of a complete De Rebus Antiquis iBoot exploit setup running on iPad 4 (P102AP). Once iBoot re-runs after the exploitation, it mounts a secondary HFS+ volume that contains a new bootloader image and executes it. In this demo, I simply used the same iBoot as the signed one, except running unsigned with custom patches and verbose boot enabled.
I'm currently working on a complete write-up about De Rebus Antiquis iBoot exploit. Once it will be released, you should get most of the necessary knowledge to implement what you see in this video. See my personal blog here, pmbonneau.com for more details.
Many thanks to @dora2ios (Twitter) for help with some issues I had while debugging.
This is a demo of a complete De Rebus Antiquis iBoot exploit setup running on iPad 4 (P102AP). Once iBoot re-runs after the exploitation, it mounts a secondary HFS+ volume that contains a new bootloader image and executes it. In this demo, I simply used the same iBoot as the signed one, except running unsigned with custom patches and verbose boot enabled.
I'm currently working on a complete write-up about De Rebus Antiquis iBoot exploit. Once it will be released, you should get most of the necessary knowledge to implement what you see in this video. See my personal blog here, pmbonneau.com for more details.
Many thanks to @dora2ios (Twitter) for help with some issues I had while debugging.
![HFS+ Heap Buffer Overflow - iPad 2 (K94AP) iOS 5.x iBoot Exploit [Demo]
This is a post-exploitation demo of an HFS+ heap buffer overflow in iOS 5.x iBoot, running on iPad 2nd (K94AP). One particular use case of an iBoot exploit such as this one is the ability to downgrade or upgrade the device to any iOS version as long as it can run on it. This iPad 2nd is downgraded to iOS 5.x using previously saved SHSH blobs, so when powered-on, the signed iOS 5.x iBoot is executed. An HFS+ volume is specifically crafted to trigger an heap buffer overflow when iBoot attempts to mount it. Then, we get control over the PC register and eventually execute a custom payload which jumps to a completely new patched iBoot image. From there, additional unsigned bootchain images are executed and so, to fully boot iOS. In this video, iPad start up with the iOS 5.0.1 signed bootchain, exploit is triggered, then jumps to an iOS 7.1.2 bootchain.
See the complete write-up I did about this iBoot exploit on my personal blog here, https://www.pmbonneau.com/ios5-iboot-hfs-hbo/
This video was originally posted on X (Twitter) here, https://x.com/ShadowLee19/status/1074533504610918400?s=20 HFS+ Heap Buffer Overflow - iPad 2 (K94AP) iOS 5.x iBoot Exploit [Demo]](https://i.ytimg.com/vi/dJbakxWSy18/mqdefault.jpg)







![iPhone 4 (N90AP) iOS 7.1.2 Pangu Jailbreak - Cydia Applications Stashing Fail
I was prepearing a video about how to jailbreak iOS 7.1.2 on iPhone 4 (N90AP) using Pangu 7, but it seems that Cydia had some problems during the application stashing process. This step is also known as Prepearing the FileSystem, after opening Cydia for the first time. When jailbreaking your iOS device, the most important thing to do before is to backup important data before doing the process. Using iTunes for backup usually do a good work.
In technical details, Application Stashing is the process where Cydia moves /Applications folder from the first partition (/dev/disk0s1s1) to /var/stash/[random string]/Applications, which is on the second partition (/dev/disk0s1s2). After moving applications, a Unix symlink refeering /Applications folder to /var/stash/[random string]/Applications is made to trick the iOS system. The goal of Application Stashing is to free up disk space on the system partition (/dev/disk0s1s1) for Cydia packages, some iOS system tweaking and so.
I now have to restore (again) that N90AP. iPhone 4 (N90AP) iOS 7.1.2 Pangu Jailbreak - Cydia Applications Stashing Fail](https://i.ytimg.com/vi/nhku20ETHCU/mqdefault.jpg)
![Futurama - Holophonor Sonnet for Leela [Piano]
Here is a piano arrangment of the holophonor song played by Fry for Leela in the Parasite Lost (S03E04) episode of Futurama.
There are five softwares used in the making of this arrangement.
1 - Nero Recode (probably, I dont remember exactly): To extract the audio from the original video. Then, I cut all the audio except the holophonor part and exported to WAV format using audacity.
2 - AnthemScore: To reverse the song. This software allows me to see a visual representation of the actual song and guess notes, plus it uses an IA to automatically do a part of this work. The final product is a sheet music in MusicXML file format.
3 - MuseScore: To re-encode the MusicXML output of AnthemScore to a more versatile MusicXML format. I dont know why, but using AnthemScores MusicXML output in Synthesia doesnt work well, the BPM isnt the right one. Converting the file with Musescore will produce a MusicXML file that will be better with Synthesia.
4 - Synthesia: To get this nice piano roll and also to practice the song on a real piano.
Album : N/A
Title : Holophonor Sonnet for Leela
Arrangment type : Reversed from soundtrack
Download sheet music from my blog here : https://www.pmbonneau.com/music/arrangements/ Futurama - Holophonor Sonnet for Leela [Piano]](https://i.ytimg.com/vi/nnynLpZVWno/mqdefault.jpg)
