查看ASLR偏移
(lldb) image list -o -f
[ 0] 0x00035000 /private/var/db/stash/_.29LMeZ/Applications/MobileNotes.app/MobileNotes(0x0000000000039000)
[ 1] 0x00197000 /Library/MobileSubstrate/MobileSubstrate.dylib (0x0000000000197000)
[ 2] 0x06db3000 /Users/snakeninny/Library/Developer/Xcode/iOS DeviceSupport/8.1 (12B411)/Symbols/System/Library/Frameworks/QuickLook.framework/QuickLook
……
設(shè)置斷點
b function
br s –a address
br s –a 'ASLROffset+address'
(lldb) br s -a 0x4BE70
Breakpoint 1: where = MobileNotes`___lldb_unnamed_function382$$MobileNotes, address = 0x0004be70
當(dāng)進(jìn)程停下來之后看靠,可以用“c”命令讓進(jìn)程繼續(xù)運行擒权。
斷點處運行指令
(lldb) br com add 1
執(zhí)行這條命令后非凌,LLDB會要求我們設(shè)置一系列指令,以“DONE”結(jié)束,如下:
Enter your debugger command(s). Type 'DONE' to end.
> po [$r0 class]
> p (char *)$r1
> c
> DONE