Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bypass Every Methods #43

Open
marcotrumpet opened this issue Jan 24, 2023 · 7 comments
Open

Bypass Every Methods #43

marcotrumpet opened this issue Jan 24, 2023 · 7 comments
Labels
to be fixed This issue will be fixed in the future

Comments

@marcotrumpet
Copy link

Hi,

I created a new flutter project to test freerasp capabilities and found out that jailbreak detection could be bypass using hopper and NOP region.
I'm also aware that anti tampering protection and other methods are still valid (didn't test to bypass them yet) so even if someone bypass jb detection the framework should still be able to inform the app about that.

So I'm just opening this one to let you know what you probably already know.

Feel free to close this if you think that jb detection bypass is not a big deal and thanks for your amazing framework.

@msikyna
Copy link
Member

msikyna commented Jan 27, 2023

Hello @marcotrumpet ,

thank you for reporting the issue. The jailbreak detection bypass using Hopper and NOP region is quite advanced and will not be a problem in our businessRASP (https://github.com/orgs/talsec/discussions/5). However, we might look if we can help to prevent it in the freeRASP version as well.

Kind regards,
Matúš, Talsec developer

@marcotrumpet
Copy link
Author

Thanks a lot for the clarification!

@marcotrumpet
Copy link
Author

Hi,
reopening this for different reasons. The previous issue was regarding using NOP in you native talsecruntime framework (so it's a technique valid for nativa iOS and all other platform you support).

Now I want to point out that I'm able to bypass all your methods in the flutter package simply swapping hexadecimal. I used hopper but it should be possible also to do that with vim and no payed license in hopper.

@marcotrumpet marcotrumpet reopened this Feb 13, 2023
@marcotrumpet marcotrumpet changed the title Jailbreak Detection Bypass Jailbreak Detection Bypass (now bypass every methods) Feb 13, 2023
@marcotrumpet marcotrumpet changed the title Jailbreak Detection Bypass (now bypass every methods) Bypass Every Methods Feb 15, 2023
@syakymchuk syakymchuk added the to be fixed This issue will be fixed in the future label Mar 9, 2023
@syakymchuk
Copy link
Contributor

Plan to be solved in the next release of freeRASP

@marcotrumpet
Copy link
Author

Awesome! Thank you guys

@reyesmfabian
Copy link

Hi, I'm just wondering if this will be in the new version of the plugin.

@msikyna
Copy link
Member

msikyna commented May 9, 2023

Hello @reyesmfabian ,
it is not yet in the new version of the plugin.

The new version will be mainly about better developer experience, solving the debug vs release integration issues, removing HMS dependencies and enhancing root detection capabilities.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
to be fixed This issue will be fixed in the future
Projects
None yet
Development

No branches or pull requests

4 participants