Skip to content

iPad Air Cellular 1st gen, iOS 12.5.8 works, but... #27

Description

@mksy

...
You need to add -o HostKeyAlgorithms=+ssh-rsa -o PubkeyAcceptedAlgorithms=+ssh-rsa for ssh and scp commands in scripts executed on Ubuntu, otherwise the error Unable to negotiate with 127.0.0.1 port 2222: no matching host key type found. Their offer: ssh-rsa will appear.

Also, scripts do not run directly on the iPad, resulting in the error /bin/bash: bad interpreter: No such file or directory, so I executed the commands from scripts manually in an SSH session on the iPad and it worked without errors.
Here is log:
terminal 1

mksy@ubuntu:$ cd iOS_ActivationBypass/
mksy@ubuntu:
/iOS_ActivationBypass$ nano transfer_files.sh
mksy@ubuntu:~/iOS_ActivationBypass$ ./transfer_files.sh

iOS Activation Bypass - File Transfer

[] This script will transfer files to the jailbroken device
[
] Make sure iproxy is running in another terminal!

Prerequisites:

  • iproxy running (use ./setup_proxy.sh)
  • Device jailbroken with Checkra1n
  • Device at WiFi selection screen

Press Enter to continue or Ctrl+C to cancel...

[*] Using sshpass for automated transfer

Step 1: Transferring bypass scripts...

[] Transferring bypass_device.sh to /var/root/bypass_device.sh...
[✓] bypass_device.sh transferred successfully
[
] Transferring finalize_bypass.sh to /var/root/finalize_bypass.sh...
[✓] finalize_bypass.sh transferred successfully

Step 2: Making scripts executable...

[✓] Scripts made executable

==========================================
✓ Phase 1 Complete!

NEXT STEPS:

  1. SSH into the device:
    ssh root@127.0.0.1 -p 2222
    (Password: alpine)

  2. Run the bypass script:
    cd /var/root
    ./bypass_device.sh

  3. Transfer the patched file:
    (On your host machine, in a new terminal)
    ./transfer_patch.sh

  4. Finalize the bypass:
    (Back in the SSH session)
    ./finalize_bypass.sh

  5. On the device, tap 'Connect to iTunes'

mksy@ubuntu:/iOS_ActivationBypass$ nano transfer_patch.sh
mksy@ubuntu:
/iOS_ActivationBypass$ ./transfer_patch.sh

Transferring Patched Activation File

[*] Transferring patched mobileactivationd...
Source: ./mobileactivationd
Destination: /usr/libexec/mobileactivationd

[*] Using sshpass for automated transfer

==========================================
✓ Patch File Transferred Successfully!

NEXT STEP:
Go back to your SSH session and run:
./finalize_bypass.sh

terminal 2

mksy@ubuntu:$ cd iOS_ActivationBypass/
mksy@ubuntu:
/iOS_ActivationBypass$ ./transfer_files.sh

iOS Activation Bypass - File Transfer

[] This script will transfer files to the jailbroken device
[
] Make sure iproxy is running in another terminal!

Prerequisites:

  • iproxy running (use ./setup_proxy.sh)
  • Device jailbroken with Checkra1n
  • Device at WiFi selection screen

Press Enter to continue or Ctrl+C to cancel...

[*] Using sshpass for automated transfer

Step 1: Transferring bypass scripts...

[*] Transferring bypass_device.sh to /var/root/bypass_device.sh...
Unable to negotiate with 127.0.0.1 port 2222: no matching host key type found. Their offer: ssh-rsa
lost connection
[✗] Failed to transfer bypass_device.sh

mksy@ubuntu:~/iOS_ActivationBypass$ ssh -p 2222 -o HostKeyAlgorithms=+ssh-rsa -o PubkeyAcceptedAlgorithms=+ssh-rsa root@127.0.0.1
The authenticity of host '[127.0.0.1]:2222 ([127.0.0.1]:2222)' can't be established.
RSA key fingerprint is SHA256:bXOVUdGs/9kl9eP16x8wfND9vPXwRl3pyhmmjItQKvw.
This key is not known by any other names
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '[127.0.0.1]:2222' (RSA) to the list of known hosts.
root@127.0.0.1's password:
-bash-3.2# cd /var/root && ./bypass_device.sh
-bash: ./bypass_device.sh: No such file or directory
-bash-3.2# ls
.aks_migrate .aks_whitelist .bootstrapped Library bypass_device.sh finalize_bypass.sh
-bash-3.2# ./bypass_device.sh
-bash: ./bypass_device.sh: /bin/bash: bad interpreter: No such file or directory
-bash-3.2# bash
bash-3.2# /bin/bash
bash: /bin/bash: No such file or directory
bash-3.2# ls /bin
df ps
bash-3.2# ls /
.HFS+ Private Directory Data? .file Applications System dev sbin var
.Trashes .fseventsd Developer bin etc tmp
.ba .mb Library cores private usr
bash-3.2# ls /sbin
fsck fsck_apfs fsck_exfat fsck_hfs fsck_msdos launchd mount mount_apfs mount_hfs newfs_apfs newfs_hfs pfctl
bash-3.2# ls /usr
bin include lib libexec local sbin share standalone
bash-3.2# ls /usr/bin
DumpBasebandCrash abmlite footprint hpmdiagnose powerlogHelperd tailspin vm_stat
PerfPowerServicesExtended brctl hidutil kbdebug sysdiagnose taskinfo zprint

bash-3.2# mount -o rw,union,update /
bash-3.2# launchctl unload /System/Library/LaunchDaemons/com.apple.mobileactivationd.plist
bash-3.2# rm /usr/libexec/mobileactivationd
bash-3.2# uicache --all
bash-3.2# ./finalize_bypass.sh
bash: ./finalize_bypass.sh: /bin/bash: bad interpreter: No such file or directory
bash-3.2# ls /usr/libexec/
BackupAgent companion_proxy lskdd rtcreportingd
BackupAgent2 configd lskdmsed safarifetcherd
CrashHousekeeping corecaptured magicswitchd security-sysdiagnose
DataDetectorsSourceAccess coreduetd mc_mobile_tunnel securityd
FSTaskScheduler coreidvd microstackshot securityuploadd
FinishRestoreFromBackup crash_mover misagent seputil
IOAccelMemoryInfoCollector dasd misd sharingd
IOMFB_bics_daemon demod mmaintenanced signpost_reporter
MobileGestaltHelper demod_helper mobile_assertion_agent silhouette
MobileStorageMounter dhcpd mobile_diagnostics_relay siriknowledged
NANDTaskScheduler diagnosticd mobile_house_arrest smcDiagnose
OTATaskingAgent diagnosticextensionsd mobile_installation_proxy splashboardd
PowerUIAgent dmd mobile_obliterator springboardservicesrelay
PreboardService dprivacyd mobile_storage_proxy streaming_zip_conduit
ProxiedCrashCopier dtrace mobileactivationd studentd
PurpleReverseProxy duetexpertd mobileassetd swcd
ReportMemoryException fdrhelper mobilewatchdog symptomsd
SafariCloudHistoryPushAgent findmydeviced mtmergeprops symptomsd-helper
SidecarRelay finish_demo_restore neagent sysdiagnose_helper
SyncAgent fmfd nehelper sysstatuscheck
UserEventAgent fmflocatord nesessionmanager tailspind
adid fseventsd networkserviceproxy timed
adprivacyd ftp-proxy nlcd tipsd
adservicesd gamecontrollerd notification_proxy topicsmap.db
afcd gamed nsurlsessiond transitd
airtunesd hangreporter nsurlstoraged trustd
amfid hangtracerd online-auth-agent tzd
asd heartbeatd oscard tzinit
assertiond hostapd pcapd tzlinkd
atc idamd pcsstatus videosubscriptionsd
atwakeup init_data_protection pfd wapic
backboardd installd pipelined webbookmarksd
bootpd ioupsd pkd webinspectord
bubbled keybagd pkreporter wifiFirmwareLoaderLegacy
captiveagent languageassetd ptpd wifivelocityd
cc_fips_test locationd rapportd xpcproxy
checkpointd lockdownd replayd xpcroleaccountd
cloudpaird logd rolld
com.apple.automation.defaultslockdownserviced lsd routined
bash-3.2# chmod 755 /usr/libexec/mobileactivationd
bash-3.2# launchctl load /System/Library/LaunchDaemons/com.apple.mobileactivationd.plist
bash-3.2#

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions