<?xml version="1.0" encoding="UTF-8"?>

<rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel>

<title>OS X and iOS Internals - The RSS Feed</title>
<link>http://www.newosxbook.com/</link>
<description>Additional code samples, articles, and downloads for OS X and iOS kernel enthusiasts</description>
<language>en-us</language>
<copyright>© Jonathan Levin</copyright>
<pubDate>Tue, 08 May 2012 22:36:42 EDT</pubDate>

<ttl>5</ttl>
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.newosxbook.com/rss.php" /><feedburner:info uri="/rss.php" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" />



<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/bonus/vol1AppA.html</guid>
<title>Bonus chapter from Volume I - Software Images</title>

<description>Bonus chapter from Vol1 v1.3 - Appendix on Software Images - free, as promised</description>
<pubDate>Wed, 19 Jun 2019 07:23:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/CasaDePPL.html?rss</guid>
<title>La Casa De PPL</title>
<description>Reverse Engineering Apple's iOS12/A12 Page Protection Layer</description>
<pubDate>Sun, 03 Mar 2019 17:01:00 EDT</pubDate>
</item>






<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewforum.php?f=15</guid>
<title>QiLin toolkit updated for 12.1.2</title>
<description>Bring your own exploit. Presently different file (qilin12.o) for 12 due to different structures. Working on making this universal. Stay tuned</description>
<pubDate>Sun, 03 Feb 2019 17:56:00 EDT</pubDate>
</item>





<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/bonus/vol1ch16.html</guid>
<title>Bonus chapter from Volume I - Networking</title>

<description>Bonus chapter from Vol1 - Networking - free, as promised</description>
<pubDate>Fri, 04 Jan 2019 13:41:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=19577&amp;p=23792#p23792</guid>
<title>JTool2 now does IOKit Classes!</title>
<description>
.. but I need help testing this!
</description>
<pubDate>Thu, 14 Jan 2019 23:14:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/iOSBinaries.html</guid>
<title>The iOS binpack is now a single multifunction binary</title>
<description>
I've updated the binpack for Darwin 18.1 (MacOS 14.1 sources), and while at it collapsed it into a single multipurpose binary. Better for forensics, and for dealing with that annoying CoreTrust). 70 utilities folded so far into a 1.2MB binary.
</description>
<pubDate>Thu, 03 Jan 2019 12:15:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=19610</guid>
<title>Updates about Books: Vol1 (major update), Vol2 (delayed)</title>

<description>
Volume I expanded with a new chapter on networking, and more detail on thread policies, and remote XPC. Volume II is delayed because AAPL are mean to me.

</description>

<pubDate>Sat, 08 Dec 2018 19:49:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=19577&amp;p=23629#p23629</guid>
<title>JTool2 alpha build - please help test</title>

<description>
JTool2 is a radical rewrite of jtool to make it more featureful and extensible, and less buggy. This is your chance to help out!

</description>
<pubDate>Sat, 22 Sep 2018 14:30:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=11&amp;t=19557&amp;p=23623#p23623</guid>
<title>Update to Volume 1 - v1.1</title>

<description>
I put the updates in the ChangeLog, and made a couple of the pages (pertaining to PAC and the new Mach-O architectures) available in the forum.
</description>
<pubDate>Thu, 20 Sep 2018 14:46:00 EDT</pubDate>
</item>





<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://www.newosxbook.com/forum/viewtopic.php?f=10&amp;t=19566</guid>
<title>Hardcover poll</title>

<description>
I could use your help as I try to work towards combining the trilogy into one, colorful and hardcover format.
</description>
<pubDate>Sun, 15 Sep 2018 23:40:00 EST</pubDate>
</item>





<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://www.newosxbook.com/forum/viewtopic.php?f=8&amp;t=19565&amp;ref=rss</guid>
<title>"1469" kernelcaches</title>

<description>
Quick glimpse from Volume II to summarize differences between normal iOS 10 and later kernelcaches and the new "1469" format. I figured this is something that needs to get out there, before the book (which is still on track, thank you for asking :-)
</description>
<pubDate>Sun, 15 Sep 2018 22:49:00 EST</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=11&amp;t=19557&amp;ref=rss</guid>
<title>iPhone Xs, Xr... and, one more thing..</title>

<description>
Things AAPL didn't mention about the iPhone 11's A12.
</description>
<pubDate>Wed, 12 Sep 2018 22:59:00 GMT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=11&amp;t=19534</guid>
<title>Announcing the XNU XRef on NewOSXBook..</title>
<description>
I've been using find . -type f | xargs grep .... on the XNU sources for so long I figured I might as well make it a bit easier for me and give it a web interface. Thus is born http://newosxbook.com/xxr . I'm not linking it yet from main page because it might not be ready for the world.

Please try it out and provide feedback!


</description>
<pubDate>Wed, 08 Aug 2018 21:57:00 PDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=11&amp;t=19527&amp;etc</guid>
<title>More updates coming soon..</title>
<description>
Still alive, and working on a couple of things - jtool2, Fsleuth with APFS and new version of Joker, and Liber* JBs - among others. Just busy with actual work in Singapore, too.. Stay tuned, folks. :-)

</description>
<pubDate>Sat, Jul 21 2018 04:04:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/?xx</guid>
<title>Registration enabled once more</title>
<description>
Captcha was broken, and I wanted to detach from anything remotely GOOGL. So we're back to simple image + admin verification. That way spambots won't be able to get in.

</description>
<pubDate>Sat, Aug 18 2018 15:35:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=11&amp;t=19527</guid>
<title>RSS enabled once more</title>
<description>
I got so used to Twitter that I abandoned this medium. Now that I'm on indefinite leave from the former, time to get this alive again.

</description>
<pubDate>Fri, Jul 06 2018 15:42:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/supraudit.html</guid>
<title>SUpraudit</title>
<description>
Enhanced praudit(1) for MacOS, enabling agent mode, filters, colors, and more.
</description>
<pubDate>Fri, Oct 06 2017 15:03:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewforum.php?f=12</guid>
<title>TvOS &lt; 10.1.1 Jailbreak released :-)</title>
<description>
All Done! #LiberTV - #tvOS #jailbreak for 10.0-10.1: Free at last! http://NewOSXBook.com/libertv/libertv.ipa But please RTFM @ http://newosxbook.com/forum/viewforum.php?f=12 first!
</description>
<pubDate>Fri, Mar 03 2017 01:03:00 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/ent.jl</guid>
<title>MacOS/iOS Entitlement Database updated!</title>
<description>
Now full with all MacOS 10.12(.2) and iOS 10.2
</description>
<pubDate>Wed, Jan 18 2017 22:02:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/jtool.html</guid>
<title>Happy New Year, people!</title>
<description>
Somewhat belated, but - I bring Significant jtool improvements!
Better SLC handling (now works and resolves symbols so you don't really need to extract), decompilation (-D) and even ARMv7k under the hood :-) Plenty more to come, so stay tuned!
</description>

<pubDate>Sat, Jan 08 2017 21:24:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/nuwashi.pdf</guid>
<title>Chapter 21 (Pangu 9.3.3) available</title>
<description>
I published the very small but detailed Chapter 21, dealing with Pangu's 9.3.3 jailbreak, for free. This way if you got the initial version you can get the PDF as well. Anybody ordering the book as of today will get this built-in .</description>
<pubDate>Wed, Nov 16 2016 11:12:00 EDT</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/hfsleuth.html</guid>
<title>HFSleuth improvements</title>
<description>
HFSLeuth for HFS+ partition/DMG forensics/mounting/debugging under *OS/Linux, now supports file compression, xattr. http://newosxbook.com/tools/hfsleuth.html</description>
<pubDate>Mon, Nov 14 2016 00:17:00 EDT</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/ojtool.html</guid>

<title>OJTool - Putting the J into otool(1)</title>
<pubDate>Sun, Nov 06 2016 00:17:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=16750&amp;p=17996#p17996</guid>

<title>Stack snapshot for 10.11/iOS 9 and later</title>
<pubDate>Thu, Nov 02 2016 22:24:00 EDT</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/</guid>
<title>Wow. It's been a while</title>
<description>I've been out and about and neglecting the site a bit. Hopefully updates will be more frequent as of now! Anyway - MOXiI Vol. III is on sale. Already went through its first (minor) revision, adding a bit more content. </description>
<pubDate>Wed, Nov 02 2016 12:18:00 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/articles/OTA4.html</guid>
<title>OTA (IV) - A new hope</title>
<description>Something I should have implemented LONG ago for in-OTA searches!</description>
<pubDate>Wed, Sep 07 2016 21:37:00 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/articles/hitsb.html</guid>
<title>Hack in the (Sand)box presentation</title>
<description>Plus a nifty little sandbox inspection tool.</description>
<pubDate>Thu, Aug 25 2016 19:35:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/2ndUpdate.html</guid>
<title>MOX*I.. I mean... *OS Internals, volume III</title>
<description>Yep. You read right. I've been cooking this quietly for months, and it's almost ready. </description>
<pubDate>Fri, Jul 01 2016 13:57:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/filemon.html?r</guid>
<title>FileMon 2.0</title>
<description>FileMon gets some active capabilities, and its own about page :-)</description>
<pubDate>Mon, Jun 06 2016 20:43:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/2ndUpdate.html?r</guid>
<title>Updated Release date announcement for MOXiI II</title>
<description>Nuff Said</description>
<pubDate>Thu, Mar 10 2016 07:43:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/articles/TvOS.html?r</guid>
<title>Notes from TvOS 9.0</title>
<description>Summary notes from Apple TV, 4th Gen</description>
<pubDate>Sat, Mar 05 2016 02:11:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/procexp.html?color</guid>
<title>Updated Process Explorer</title>
<description>ProcExp now correctly displays Mach/XPC ports for all port types (U and M). And -- colors!</description>

<pubDate>Sun 28 Feb 2016, 20:11:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/ent.jl</guid>
<title>Entitlement Database</title>
<description>A searchable database of iOS entitlements</description>
<pubDate>Tue 23 Feb 2016, 01:20:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/src.jl?tree=listings&amp;file=ls.m</guid>
<title>LSDTrip - A LaunchServices (LSD) client for OS X and iOS </title>
<description>Just a simple, but rather useful utilty for inspecting apps in both OSes. I cover the internals of this in MOXiI 2. Stay tuned</description>

<pubDate>Tue 16 Feb 2016, 23:16:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/iOSBinaries.html?u1</guid>
<title>More Darwin Binaries - compiled for ARM64 and ARMv7 - fixes, id, date, fs_usage</title>

<description>I keep adding more and more binaries and fixing a few which were malsigned by me. screen, vim should now work, ls now has full color (well, "full".. you know, terminal capability..), and fs_usage (useful!) is now added to the bunchm, as well</description>

<pubDate>Fri 12 Feb 2016, 22:36:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/iOSBinaries.html</guid>
<title>Darwin Binaries - compiled for ARM64 and ARMv7</title>
<description>IMHO, a far better alternative to Cydia's old and all-too-often binaries. Recompiled by yours truly from scratch.</description>

<pubDate>Fri 05 Feb 2016, 10:02:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/jtool.html#darncool</guid>
<title>Loud update to jtool</title>
<description>JTool now auto-detects and auto symbolicates MIG tables when you dump __DATA.__const. Check it out! Unbelievably useful for reversing!</description>
<pubDate>Wed 03 Feb 2016, 23:27:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/jtool.tar?s1</guid>
<title>Silent update to jtool</title>
<description>Fixes disass/decomp (esp in fat files) as well as a few bugs I introduced by mistake in the process of refactoring.. Also updates Linux version to be in line with OSX/iOS[32/64] (thanks Billy!)</description>
<pubDate>Sat, 30 Jan 2016, 23:55:15 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/tools/procexp.html?1-e</guid>
<title>Process Explorer now does Mach ports!</title>
<description>Much, much needed functionality :-)</description>
<pubDate>Tue, 26 Jan 2015, 12:00:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<title>jtool updated</title>
<guid>http://NewOSXBook.com/tools/jtool.html?r</guid>
<description>Massive improvements. Too many to list here. Read the html..</description>
<pubDate>Sun, 20 Dec 2015, 10:10:00 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<title>jlaunchctl updated</title>
<guid>http://NewOSXBook.com/articles/jlaunchctl.html?1.1</guid>
<description>jlaunchctl now supports more commands, and a bonus XPC Man-in-the-Middle Library which you can use (via interposing) to print XPC messages</description>
<pubDate>Fri, 13 Nov 2015, 22:20:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/files/jtool.tar?r0.98</guid>
<title>Jtool - silent but important update</title>
<description>RADICALLY improved jtool now handles code signature faking, better objective C, and many other features - Checks WhatsNew in tar file..</description>
<pubDate>Thu, 12 Nov 2015, 20:00:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/files/procexp.tgz?r099</guid>
<title>New version of Process Explorer sports customizable perspectives and fan speeds (at least on my macbook air..)</title>
<pubDate>Thu, 12 Nov 2015, 20:00:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://NewOSXBook.com/TOC2-2.html?r</guid>
<title>ToC for Volume II (Kernel mode) now out</title>
<pubDate>Tue, 10 Nov 2015, 00:00:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/jlaunchctl.html?r</guid>
<title>launchctl - open sourced</title>
<description>Your comments and feedback on this are really appreciated.  </description>
<pubDate>Tue, 09 Nov 2015, 00:00:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/OTA2.html?r</guid>
<title>OTA Updates - the followup article</title>
<pubDate>Thu, 24 Sep 2015, 00:00:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/HIDeAndSeek.html?r</guid>
<title>TaiG v2 exploit analysis - Part II</title>
<pubDate>Tue, 25 Jul 2015, 00:00:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/disarm.html?r</guid>
<title>DisARM - A simple command line ARM64 disassembly/opcode utility for iOS (but also Android)</title>
<description> ..  </description>
<pubDate>Mon, 17 Aug 2015, 08:00:00 PDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/tools/joker.html?r</guid>
<title>Joker updated to support 64-bit kernel dumps!</title>
<description>.. and integration with Jtool companion files as well. Q.v. the new joker page</description>
<pubDate>Fri, 07 Aug 2015, 12:00:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/28DaysLater.html?r</guid>
<title>TaiG v2 exploit analysis</title>
<pubDate>Fri, 24 Jul 2015, 07:50:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=16580</guid>
<title>Process Explorer Update</title>
<description>Process Explorer (0.56) now updated to symbolicate user threads, supports iOS9/OSX 10.11 
</description>
<pubDate>Fri, 10 Jul 2015, 00:15:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/9-10.11.html?0.1rs</guid>
<title>Notes on iOS 9/OS X 10.11 DP - Updates</title>
<description>Observations on the new 10.11 DP1 and XCode w/iOS 9.0b  kernel
</description>
<pubDate>Tue, 09 Jun 2015, 19:15:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/src.jl?r=1&amp;tree=listings&amp;file=inject.c</guid>
<title>Code Injection example now updated for ARM64</title>
<description>You know. Just in case you want it :-)</description>
<pubDate>Mon, 01 June 2015, 00:01:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/guesstalt.html?r</guid>
<title>Reversing MobileGestalt</title>
<description>MobileGestalt is Apple's library which provides support for system configuration data. As part of MOXiI 2, I've reversed it. Findings are herein</description>
<pubDate>Sat, 23 May 2015, 20:01:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/2ndKickoff.html?r</guid>
<title>I know some of you have been waiting for this... :-)</title>
<description>The 2nd Edition is my baby again!</description>
<pubDate>Tue, 05 May 2015, 17:36:00 EDT</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/CodeSigning.pdf?r</guid>
<title>Code Signing presentation from RSA 2015</title>
<description>The full slides of my talk</description>
<pubDate>Tue, 28 Apr 2015, 20:02:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/joker.tar?r</guid>
<title>Joker updates</title>
<description>Joker now supports iOS 8, and allows for kext extraction</description>
<pubDate>Mon, 20 Apr 2015, 21:26:00 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/procexp.tar?05</guid>
<title>WiFi SSID/RSSI support added to Process Explorer v0.5</title>
<description>'nuff said</description>
<pubDate>Mon, 13 Apr 2015, 16:13:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/11208ellpA.html?r</guid>
<title>Apple80211.framework, reversed - Part I</title>
<description>'nuff said</description>
<pubDate>Wed, 08 Apr 2015, 20:15:00 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/TaiG2.html</guid>
<title>TaiG (iOS 8.1.2 JB) exploit writeup - part II</title>
<description>..</description>
<pubDate>Sun, 15 Feb 2015, 04:32:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/TaiG.html</guid>
<title>TaiG (iOS 8.1.2 JB) exploit writeup - Part I</title>
<description>..</description>
<pubDate>Sun, 08 Feb 2015, 04:32:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/filemon.tgz?r</guid>
<title>FileMon updated for 10.10 and iOS 8 - And tidied up!</title>
<description>Why didn't I do this before? The previous version that was on the site was an utter mess, and crashed. This one produces human readable output, is grep friendly, and should be rock solid!</description>
<pubDate>Tue, 09 Nov 2014, 03:25:00 EDT</pubDate>

</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/TOC2.html</guid>
<title>Table of Contents for 2nd Ed - Part I - now out - your requests are appreciated!</title>
<description>'Nuff said! Please check out the TOC, and let me know if I've missed anything</description>
<pubDate>Tue, 04 Nov 2014, 16:38:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/8-10.10.html?0.4rs</guid>
<title>Notes on iOS 8/OS X 10.10 DP - Updates</title>
<description>More observations on the new 10.10 DP8 and XCode w/iOS 8 full filesystem image
</description>
<pubDate>Sun, 21 Sep 2014, 20:54:00 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=10&amp;t=16552&amp;2</guid>
<title>2nd Edition - We have liftoff!</title>
<description>
Wiley and I have reached an understanding. The second edition is underway. Expect *many* updates - by Early 2015!
</description>

<pubDate>Wed, 30 Jul 2014, 09:37:00 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=10&amp;t=16552</guid>
<title>2nd Edition - Call for Requests</title>
<description>
1.5 years after the book has been out, many changes have been afoot. OS X has advanced by almost three operating system versions , with 10.10 and iOS 8 around the corner. Also, I've got some pretty constructive (and sometime less than constructive) feedback on more topics to cover.

The new book will follow in the general path of the Android book, meaning far less source code snippets, and lots more diagrams and illustrations, which will allow for more coverage of important topics.

Your requests are welcome - this is your chance to get all your questions about undocumented stuff answered!
</description>

<pubDate>Wed, 02 Jul 2014, 09:37:00 EDT</pubDate>

</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/procexp.tar?v032</guid>
<title>Process Explorer v0.3.2</title>
<description>New version of Process Explorer - now handles kernel symbols! Select any process and press "T" to view kernel and user stacks. Symbolication on kernel works (tested on ML, Y) - will symbolicate user stacks soon
</description>
<pubDate>Fri, 13 Jun 2014, 00:59:00 EDT</pubDate>

</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/8-10.10.html?rs</guid>
<title>Notes on iOS 8/OS X 10.10 DP</title>
<description>Preliminary notes on the new 10.10 DP1 and XCode w/iOS 8 SDK
</description>
<pubDate>Thu, 05 Jun 2014, 12:43:00 EDT</pubDate>

</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/GCD.html?rs</guid>
<title>GCD Internals explained</title>
<description>An exploration of Grand Central Dispatcher and Apple's modifications to Pthread
</description>
<pubDate>Sat, 22 Feb 2014, 12:43:00 EDT</pubDate>

</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/src.jl?tree=listings&amp;r=1&amp;file=inject.c</guid>
<title>OS X dylib injector code made available</title>
<description>The coreruption tool is still closed source, but I've made an important part of it - the dylib injector - open. And I've fully annotated it, too.
</description>
<pubDate>Wed, 05 Feb 2014, 01:43:11 EDT</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/hfsleuth.tar?v022</guid>
<title>HFSleuth fixes and mods</title>
<description>HFSleuth in new version with bug fixes, and full Linux support for BZ2 DMGs. Useful for opening HFS+ volumes for raw access, as well as DMG files on Linux - pure user mode, no driver or kernel interaction required.
</description>
<pubDate>Tue, 21 Jan 2014, 23:51:11 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/procexp.tar?v027</guid>
<title>.. and procexp also has network statistics</title>
<description>The last thing that top(1) may have had on ProcExp is now gone - updated procexp to have network statistics. Working on debugging *per-process* statistics, but that will wait for next release...</description>
<pubDate>Mon, 20 Jan 2014, 01:22:24 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/procexp.tar?v025</guid>
<title>ProcExp now has integrated vmmap functionality</title>
<description>v0.25 now has vmmap(1) functionality built-in - try "procexp pid regions". Also tested on Armv8</description>
<pubDate>Sun, 19 Jan 2014, 13:09:52 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/EveningWithMobileObliterator.html</guid>
<title>An evening with Mobile Obliterator</title>
<description>Back after a long leave of absence.. with an article on iOS and its entitlement model. Happy New Year, everyone!</description>
<pubDate>Tue, 31 Dec 2013, 14:42:11 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/articles/MemoryPressure.html</guid>
<title>Memory Pressure and Jetsam (iOS) explained</title>
<description>Another long flight to the far east, and to pass the time - I wrote a short article explaining OS X's memorystatus, iOS's Jetsam, and memory pressure handling in both OSes</description>
<pubDate>Sun, 03 Nov 2013, 10:29:44 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/procexp.tar?v24</guid>
<title>Process Explorer 0.24 - with memory pressure, CPU stat</title>
<description>Process Explorer updated (v0.24) for Mavericks and iOS7, with memory pressure, per CPU statistics, file descriptors, and more. Also includes preliminary support for delta mode (highlighting changed table cells)
</description>
<pubDate>Thu, 24 Oct 2013 14:53:10 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/files/procexp.universal?v21</guid>
<title>Process Explorer - now updated for Mavericks and iOS7</title>
<description>Process Explorer updated (v0.21) for Mavericks and iOS7, with more details (such as memory compression statistics). This is A FAR better tool than OS X's top (closer and modeled after Linux top). Bugs fixed, color added, man page created.
</description>
<pubDate>Thu, 10 Oct 2013 14:53:10 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>blah</guid>
<title>Back to the Drawing Board</title>
<description>Just as I was getting a handle on ARM32 and Thumb, A7 starts using ARM64.. *Sigh* Now revising jtool accordingly...
</description>
<pubDate>Sun, 22 Sep 2013 20:59:10 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=16543</guid>
<title>And, speaking of Process Explorer..</title>
<description>
I never really got a chance to post this. Think SysInternals, but for OS X/iOS - and in text mode. Downloadable via the forum. Preliminary Alpha version, but works pretty well.</description>

<pubDate>Sun, 08 Sep 2013 13:54:12 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/">
<guid>http://www.newosxbook.com/src.jl?tree=listings&amp;file=bat.c</guid>
<title>Sample code for battery stats, using IOPowerSources</title>
<description>
Someone pointed out to me that I refer (in Chapter 19) to IOPowerSources in the book, but don't really have a demonstration of how to do so. I use that in Process Explorer (my top replacement, demonstrating proc_info (syscall #336), and now I posted the (really simple) code
</description>
<pubDate>Sun, 08 Sep 2013 13:30:12 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Joker now handles xnu 2423 (iOS7)</title>
<guid>http://newosxbook.com/files/joker?7</guid>
<description>
The joker tool can now handle iOS7 betas, as well. Apple has changed the system and mach table structures (and added 10 new syscalls!), but now the signatures are updated. I'm also rewriting the tool to be a lot more elegant (use machlib). You're welcome to download and try.
</description>
<pubDate>Tue, 27 Aug 2013 09:28:14 EDT</pubDate>

</item>
<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Errata now available in forum</title>
<guid>http://newosxbook.com/forum/viewforum.php?f=9</guid>
<description>
Following comments from readers Emmanuel and Brian, I've started a sub-forum to handle all errata. If you have any comments on any factual inaccuracies in the book (or, alas, typos), please share them here. This would prove valuable to all readers, past, present and future.

</description>
<pubDate>Fri, 16 Aug 2013 23:59:03 EDT</pubDate>

</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>More updates to jtool</title>
<guid>http://newosxbook.com/files/jtool.tar?x</guid>
<description>
JTool now supports more load commands, including LC_LOAD_UPWARD_DYLIB and others you're never likely to see anywhere... More importantly, the symbol display command (jtool -S -v) now works for 64-bit and fat binaries too. DWARF support is almost done, so creating .dSYM files and injecting symbols is right around the corner. Stay tuned.

</description>
<pubDate>Fri, 16 Aug 2013 21:04:03 EDT</pubDate>

</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>DYLD - Detayled</title>
<guid>http://newosxbook.com/articles/DYLD.html</guid>
<description>
A detailed description of DYLD's internals and the poorly documented __LINKEDIT segment, picking up where the book left off. Also provides some good usage examples of Jtool.
</description>
<pubDate>Wed, 07 Aug 2013 21:04:03 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >

<title>Apple's Private MobileDevice.framework exposed</title>
<guid>http://newosxbook.com/src.jl?tree=listings&amp;file=jurpleConsole.c</guid>
<description>Another long flight from PVG to LAX, and with nothing else to do I set out to reverse engineer the (surprisingly simple) purple_console tool, from Apple's "RestoreTools.pkg" floating around the Internet. The result is a 1:1 decompilation, allowing you to see the usage of MobileDevice.framework. This will surely open up more discoveries as I dissect the framework (which is included in every Mac by default) to pieces. Stay tuned - and go ahead and download the source!  </description>
<pubDate>Sat, 27 Jul 2013 22:24:55 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>JTool enhancements!</title>
<guid >http://newosxbook.com/forum/viewtopic.php?f=3&amp;zz</guid>
<description>With nothing to do in Beijing, I've occupied myself with some serious enhancements in JTool! From the WhatsNew.txt:
  1) JTool now dumps CFStrings! If you -d an address in _cfstring section, or disassemble, and a register is detected to point to a CFString, it will be resolved to its CFString value. REALLY useful for reverse engineering.

  2) LC_FUNCTION_STARTS now processed during disassembly, so as to print function starting points. If the function addresses do not have a symbol associated with them (as, alas, is the case with most iOS binaries), jtool generates a func_xxxx name (similar to IDA). A future version will auto-symbolicate in a .dSYM file (once I figure out what the #$%#$% Mach-O Dwarf format is)

  3) Last, but by far NOT least: JTool now correctly resolves stubs in disassembly! This will show external (dylib) function calls. This puts JTool on par with otool (grrrr) and IDA. In fact, seeing as JTool resolves PC relative and neither of the other two do, it might just come a bit ahead.

</description>
<pubDate>Thu, 18 Jul 2013 22:01:04 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>More jtool options</title>
<guid >http://newosxbook.com/forum/viewtopic.php?f=3&amp;z</guid>
<description>JTool now has (partial) support for shared caches (implementing decache functionality), as well as a new option, --pages, which gives you a mapping of the Mach-O file pages to their respetive regions or load commands. Useful for inspecting __LINKEDIT.
</description>
<pubDate>Tue, 09 Jul 2013 22:01:04 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Productivity in the air</title>
<guid >http://newosxbook.com/forum/viewtopic.php?f=3&amp;y</guid>
<description>Amazing what boredom on an 11 hour flight does. JTool is (again) updated, this time with *really* useful features: -S -v: shows symbols like nm WITH libraries, -opcodes: does dyldinfo's opcode binding. Check out WhatsNew.txt in jtool.tar.
</description>
<pubDate>Sat, 29 Jun 2013 22:28:21 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>tool update - jtool</title>
<guid >http://newosxbook.com/forum/viewtopic.php?f=3&amp;x</guid>
<description>New version of JTool - with entitlement and signature support. You can now use --ent and --sig, respectively, to display the previously opaque goodies in LC_CODE_SIGNATURE. Man page updated, as are many of its options.
</description>
<pubDate>Thu, 27 Jun 2013 19:50:21 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>tool update - HFSLeuth, jtool</title>
<guid >http://newosxbook.com/forum/viewtopic.php?f=3&amp;</guid>
<description>Tools keep updating, with HFSLeuth and JTool - both as universal binaries (also for iOS) as well as ELF (Linux) - released in updated versions with minor bugfixes. Still working on the latter, but it already has more nifty features such as being able to dump C-Strings, and toggle PIE in a binary. Expect more really soon.

</description>
<pubDate>Fri, 07 Jun 2013 07:56:11 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>tool update - HFSLeuth, joker</title>
<guid>http://newosxbook.com/forum/viewtopic.php?f=3</guid>
<description>It's been a while.. :-) Thanks to a bug find by codelogic - hfsleuth now supports unmounted filesystems. Also, joker available in universal version. I'm also working on a massive update to Jtool, which incorporates all of dyldinfo(1)'s functionality into it.</description>
<pubDate>Tue, 04 Jun 2013 08:23:32 PDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Joker tool update</title>
<guid >http://newosxbook.com/forum/viewtopic.php?f=3&amp;t=376</guid>
<description>Now supporting a full dump of the kextcache, along with file offsets - q.v. forum post</description>
<pubDate>Sat, 20 Apr 2013 13:06:32 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>HFSleuth now universal - supports PPC</title>
<guid >http://newosxbook.com/files/hfsleuth.universal</guid>
<description>As per a request on the newly established forum by Daniel - HFSleuth is now released as a truly universal binary, with support for Intel (Mac), ARMv7 (iOS) and PPC (G5). There is a separate ELF version for Linux, as well. This makes HFSleuth a great replacement for Singh's "hfsdebug", which has been available only for PPC, and has disappeared with the advent of his commercial tool. HFSleuth is here to stay.
</description>
<pubDate>Wed, 17 Apr 2013 07:34:20 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>NewOSXBook.com now has a forum!</title>
<guid >http://newosxbook.com/forum</guid>
<description>Following my reviewer's excellent advice, the website now has an online forum. Currently wide open for guests - no need to register - until the first spambot finds me.. This forum will give you a chance to discuss, and ask questions, on anything related to iOS or OS X. Now waiting for the first post..</description>
<pubDate>Thu, 11 Apr 2013 13:31:20 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Joker updated to display kext load addresses</title>
<guid >http://newosxbook.com/files/joker</guid>
<description>The joker tool now displays kext load addresses, making it useful for plotting out the kernel address space. Note that KASLR still applies (i.e. these addresses will be shifted by some random value)</description>
<pubDate>Mon, 08 Apr 2013 16:51:27 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>JTool now available in an ELF version (for Linux)</title>
<guid >http://newosxbook.com/files/jtool.tar</guid>
<description>Jtool is now also available in an ELF64 version for Linux. I had to tweak the OS X headers, but it compiles (almost) neatly. You're welcome to download it and try</description>
<pubDate>Tue, 19 Mar 2013 20:27:41 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Chapter 4 available online for free</title>
<guid >http://newosxbook.com/Sample.pdf</guid>
<description>I decided to make chapter 4 available for my Harvard students as we discuss mobile operating system internals. Then I figured, why not make it public? So, enjoy</description>
<pubDate>Tue, 12 Mar 2013 09:05:10 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>HFSleuth's Unicode now better than Apple's own implementation - thanks to spammers!</title>
<guid >http://newosxbook.com/files/HFSleuth.tar</guid>
<description><![CDATA[ A peculiar spam mail from a well known pharm with pink hearts (💕) at the subject offering me some chemicals for Valentine's intrigued me - not because of the spam, but because I had no idea unicode was so damn convoluted. Turns out that UTF-16 can support "surrogate pairs" (double double byte encodings) which none but the lonely hearts (and various emoticons - like those from Skype) occupy. I tested creating a file on HFS+, and saw that it does support it, but terminal displayed it "?" when ls'ed. I quickly set to work to get HFSleuth to support those weird bytes (in UTF-8: f0 + 3 byte sequence!). And now it does. So even though the terminal displays ??, you can both see and input those totally useless (but cute) characters, as well as some quaint Chinese in the very distant character sets.]]></description>

<pubDate>Sun, 10 Mar 2013 00:32:22 EST</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Updated VMMap source code</title>
<guid >http://newosxbook.com/src.jl?tree=listings&amp;file=12-1-vmmap.c</guid>
<description> Updated vmmap for iOS and OS X - file is now a fat binary (so you can run it on iOS on OS X). Source now modified to use dyld APIs to retrieve list of Mach-O images. Not putting the two together yet (i.e. list is separate), but working on a procfs implementation for a Linux-like /proc/$$/maps on OS X. Stay tuned.
</description>

<pubDate>Sat, 09 Mar 2013 14:30:11 EST</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>A review by nekkidblogger</title>
<guid >http://nekkidblogger.com/2013/mac-os-x-and-ios-internals-to-the-apples-core-by-jonathan-levin/</guid>
<description>Another great review by Peter, a.k.a nekkidblogger. Thanks for the kind words!</description>
<pubDate>Sat, 09 Mar 2013 14:30:01 EST</pubDate>

</item>




<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Appendix A</title>
<guid >http://www.newosxbook.com/index.php?page=Appendix</guid>
<description>Following a question on LinkedIn - Appendix A (list of Mach Traps and System calls) is on the site (always has been, but with no clear link outside the RSS feed) at  http://www.newosxbook.com/index.php?page=Appendix. Clicking on file names will (usually) get you to the source tree and a quick JS hack I wrote for auto-syntax and function names. Also, as per my reviewer's recommendation, RSS feeds are now newest first.. :-) Sorry if this causes confusion for your RSS readers (hopefully it won't, since the guids have not changed)</description>

<pubDate>Mon, 04 Mar 2013 23:19:20 EST</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Documenting DMG</title>
<guid >http://newosxbook.com/DMG.html</guid>
<description>After adding support for DMGs to HFSleuth, I figured it makes sense to document the file format and process of mounting images in OS X. </description>

<pubDate>Fri, 01 Mar 2013 13:27:32 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>HFSleuth keeps evolving</title>
<guid >http://newosxbook.com/files/hfsleuth.tar&amp;new</guid>
<description>HFSleuth has been updated with a new command - "allocation", to display the allocation bitmap of the HFS filesystem inspected. Experimental output is to an HTML table, providing a clear view of fragmentation and "holes" in the filesystem.
</description>
<pubDate>Thu, 28 Feb 2013 12:53:02 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Back, with a better HFSleuth</title>
<guid >http://newosxbook.com/files/hfsleuth.tar</guid>
<description>It's been a (long) while, but I've been busy.. And now I'm back with a new version of HFSleuth. Now a fully interactive tool, able to open HFS+/HFSX partitions as well as DMGs. Available for OS X, iOS, and - Linux! All in the same tar file, along with a manual page. Even more to come soon.
</description>
<pubDate>Tue, 26 Feb 2013 12:53:02 EDT</pubDate>

</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<guid >http://macsoluciones.com/analisis/ver-todos/35-libros/948-mac-os-x-and-ios-internals-to-the-apple-s-core</guid>
<title>Spanish</title>
<description> http://macsoluciones.com/analisis/ver-todos/35-libros/948-mac-os-x-and-ios-internals-to-the-apple-s-core has a nice review of the book, in Spanish, no less.</description>
<pubDate>Wed, 20 Feb 2013 12:53:02 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>So, about that BS"D</title>
<guid isPermaLink="false">http://unix.stackexchange.com/questions/60298/what-is-bsd-in-mac-os-x-and-ios-internals/62193#62193</guid>
<description>I came across a post on StackExchange, wondering about the extra " in Chapter 13's dual title - BS"D. While yours truly is technically Jewish, it is not meant as an allusion to the Jewish roots. Close, but no cigar. Like all dual titles, though, it *is* an allusion.  BS"D is an orthodox jewish wish/blessing written on documents, short for Besyiata Deshmaya (Yiddish for "With the help of the 'name'", i.e. God). The allusion was that OS X wouldn't have gotten to where it did without the BSD core (in a sense, a greater power). And it ties in to "On the shoulders of Giants" in Chapter 3, which is an allusion to Newton (gigantum humeris insidentes). While on the subject, "E Pluribus Unum", the motto of the United States, is "One out of many", which in Chapter 2 talks about the synergy of the various technologies (Mach, BSD, IOKit, frameworks) and how they build OS X. 

In short, no, it's not a typo :-) Though my editors probably think so till this very day ;-) . 
</description>

<pubDate>Tue, 22 Jan 2013 12:53:02 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>HFSLeuth is  ready</title>
<guid isPermaLink="false">http://www.newosxbook.com/files/hfsleuth.tar</guid>
<description>Happy New Year! HFSleuth is ready! A stable version, now as an interactive tool, is ready for your consumption. Both OS X and iOS versions, as well as an experimental ELF version. *** THIS IS VERY PRELIMINARY, BUT STABLE **. I will add many more features (including shell like interface for low level file access directly over HFS) soon.
</description>

<pubDate>Tue, 08 Jan 2013 23:09:02 EDT</pubDate>
</item>




<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>HFSLeuth is (almost) ready</title>
<guid isPermaLink="false">http://www.newosxbook.com/files/not-yet</guid>
<description>For those of you wondering - HFSleuth is (almost) ready for consumption and use by the masses. It was working just fine until I recently tested it on iOS 6, wherein Apple has forced a blocksize of 8192 on the flash devices. Turns out lseek(2) still works just fine, but read(2) fails with an unknown error. Using dmesg(1), however, reveals an orphaned "alignment error" message. I'm now revising HFSleuth for the change, and will republish it soon!
</description>

<pubDate>Sat, 29 Dec 2012 21:06:02 EDT</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>FileMon</title>
<guid isPermaLink="false">http://www.newosxbook.com/files/filemon.iOS</guid>
<link>http://www.newosxbook.com/files/filemon.iOS</link>
<description>Merry Christmas! I've been bad, as work keeps on pouring.. But - due to popular demand (Boyd, Jason and others) - filemon is up. This is an iOS6-tested example of an fsevents monitor, and provides cool insight as to the behind-the-scenes of your (jailbroken) i-Device. Both source and binary are available! Please keep emails and requests coming. MUCH more will come soon (including a GUI for filemon).
</description>
<pubDate>Tue, 25 Dec 2012 18:45:01 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Back, and with a new (old) tool</title>
<guid isPermaLink="false">http://www.newosxbook.com/update2</guid>
<link>http://www.newosxbook.com/files/joker</link>
<description>Inundated with other stuff, I let the regular updates slip some.. Anyway, The source for the joker tool (which reads the decrypted iOS kernelcache and displays information about it) is now out (along with the binary, as before). Watch out for more updates as I add some of the beta functionality, like separating the kexts, editing the info, etc.
</description>
<pubDate>Fri, 30 Nov 2012 04:53:43 CST</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Amazon keeps jacking up the price..</title>
<guid isPermaLink="false">http://www.newosxbook.com/update1</guid>
<link>http://www.newosxbook.com</link>
<description>The book must be selling well - consistently in the top #8,000 still, and Amazon has twice upped the price , by some $4.9 by now (20%!). Thanks for all of you who bought so far (and kudos to those who got it at the pre-sale price). I'd love to hear from you!
Incidentally, some copies contain a bonus chapter of ASP.net. I know, because I got some of them too.. Too bad they come in place of Chapters 4-5.. It's only a limited batch, though. I'm hopeful Wiley will replace them..
</description>
<pubDate>Mon, 12 Nov 2012 22:53:12 CST</pubDate>
</item>



<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>VMMap for iOS</title>
<guid isPermaLink="false">http://www.newosxbook.com/src.jl?tree=listings&amp;file=12-vmmap.c</guid>
<link>http://www.newosxbook.com/src.jl?tree=listings&amp;file=12-1-vmmap.c</link>
<description>The vmmap(1) clone, derived from GDB's "info regions" logic. Patched to workaround iOS 6's invalidation of the task port. Used as the basis for the corerupt tool (which will be available for download once I tidy it up a little..). Thanks to Mike of Canada for pointing out the link was broken!
</description>
<pubDate>Sun, 11 Nov 2012 08:21:11 CST</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Google Books</title>
<guid isPermaLink="false">http://who.asked.google.com</guid>
<link>http://books.google.com/books?id=bzZO64m3iS0C</link>
<description>Apparently, the book is now on Google (e)Books. Somewhat peeving, since nobody asked me if I want it to be there (I'd have said no). Even though it might be tempting to buy it at $32.99, I personally think that it's worth waiting for the high quality PDF that Wiley will be putting out (sometime) soon (though the link to Google is supplied). Oh, the irony. Google making a buck off of Apple's back :-). From what I understand, btw, Amazon's price is slightly cheaper if you follow the link on this site (i.e. http://www.newosxbook.com/)

Btw, I am not an associate professor of English, or whatever Google has me at. What can you expect from a hulking yet inferior, context-free search engine?

</description>
<pubDate>Fri, 02 Nov 2012 19:56:02 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>StackShot</title>
<guid isPermaLink="false">http://newosxbook.com/src.jl?tree=listings&amp;file=stack-snapshot.</guid>
<link>http://newosxbook.com/src.jl?tree=listings&amp;file=5-2-stack-snapshot.c</link>
<description>Added the code from listing 5-2, which provides stackshot functionality (using the undocumented syscall #365) for both OS X and iOS. This enables you to get a complete thread call stack dump. In other news, the book is (incredibly) in Amazon's top #2,000(!). Who would've believed? A niche technical book! Watch out, 50 shades :-) Thank you all!
</description>
<pubDate>Fri, 02 Nov 2012 10:11:02 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Imagine tool ready</title>
<guid isPermaLink="false">http://newosxbook.com/src.jl?tree=listings&amp;file=6-bonus.c</guid>
<link>http://newosxbook.com/src.jl?tree=listings&amp;file=6-bonus.c</link>
<description>The imagine tool, shown in chapter 6 (EFI and iBoot) can be used to inspect the various IMG3 files from the iOS ipsws. In particular, it's useful to dump the device tree files. The tool is shown in output 6-6 and listing 6-7 (which should really be an output..). Oh, and - the book just climbed to the all time high of 8,247  (and #3 in Mac OS Books) on Amazon!
</description>
<pubDate>Tue, 30 Oct 2012 11:22:11 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Book is out, in print!</title>
<guid isPermaLink="false">http://newosxbook.com/</guid>
<link>http://www.amazon.com/gp/product/1118057651/ref=as_li_ss_tl?ie=UTF8&amp;camp=1789&amp;creative=390957&amp;creativeASIN=1118057651&amp;linkCode=as2&amp;tag=newosxbookcom-20</link>
<description>The book is finally in print, a few days ahead of time. Amazon is listing it as in stock, and I got my copies (all 20 of them.. if I want more to hand out, I actually have to *buy* my own book, imagine that!). Book has been consistently in the top 25,000  on Amazon so far. Quite impressive, considering it's out of 8,000,000, and not bad for a book that was yet to be published!
</description>

<pubDate>Sun, 28 Oct 2012 11:13:52 EDT</pubDate>
</item>


<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>UTUN Sample code (for OS X and iOS) ready</title>
<guid isPermaLink="false">http://newosxbook.com/src.jl?tree=listings&amp;file=17-15-utun.c</guid>
<link>http://newosxbook.com/src.jl?tree=listings&amp;file=17-15-utun.c</link>
<description>The example from Chapter 17 (networking) demonstrating usage of User mode tunnels with the UTUN mechanism. The simple example sets up a utun interface (utun1), and then dumps all the packets sent to it. Download as source for both OS X and iOS.
</description>
<pubDate>Tue, 16 Oct 2012 13:21:56 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>BPF Sample code (for OS X and iOS) ready</title>
<guid isPermaLink="false">http://newosxbook.com/src.jl?tree=listings&amp;file=17-25-bpf.c</guid>
<link>http://newosxbook.com/src.jl?tree=listings&amp;file=17-25-bpf.c</link>
<description>The example from Chapter 17 (networking) demonstrating usage of BPF filters. Download as source for both OS X and iOS.
</description>

<pubDate>Sun, 14 Oct 2012 20:11:41 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>lsock (Improved netstat with live updates) ready</title>
<guid isPermaLink="false">http://newosxbook.com/src.jl?tree=listings&amp;file=17-1-lsock.c</guid>
<link>http://newosxbook.com/src.jl?tree=listings&amp;file=17-1-lsock.c</link>
<description>The example from Chapter 17 (networking)   demonstrating the com.apple.network.statistics provider is ready! Download as source or as binaries for OS X/iOS
</description>

<pubDate>Tue, 09 Oct 2012 19:15:11 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>The book is really on Amazon! Look Inside!</title>
<guid isPermaLink="false">http://www.amazon.com/gp/reader/1118057651/ref=sib_dp_pt#reader-link</guid>
<link>http://www.amazon.com/gp/reader/1118057651/ref=sib_dp_pt#reader-link</link>
<description>Checking on the book's rank (fluctuating in the top 30,000-100,000 - not bad for a book that has yet to be published!) I just saw that Amazon uploaded the "Look Inside" previews! This is it, people! </description>

<pubDate>Thu, 04 Oct 2012 19:21:28 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Tools update</title>
<guid isPermaLink="false">http://newosxbook.com/index.php?page=Downloads</guid>
<link>http://newosxbook.com/index.php?page=Downloads</link>
<description>Tools will now feature some sample usage . This is especially important for some of the cool features, like JTool's new disassembler..</description>

<pubDate>Tue, 25 Sep 2012 14:21:28 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Appendix 1 is now online</title>
<guid isPermaLink="false">http://newosxbook.com/index.php?page=Appendix</guid>
<link>http://newosxbook.com/index.php?page=Appendix</link>
<description>Appendix I - the list of XNU's system calls and Mach traps - is now online. Some of the system calls are well known (being POSIX), but nevertheless there are a few undocumented ones whose prototype the table lists, with a short description. More detail can be found in the book. The Mach traps are entirely undocumented, and Apple keeps adding more (e.g. kernelrpc_* ones, which were introduced in iOS and have been included in Mountain Lion). I'll try to keep this as updated as I can, so check back soon.
</description>

<pubDate>Thu, 30 Aug 2012 20:51:28 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Mountain Lion Sources are out</title>
<guid isPermaLink="false">http://opensource.apple.com</guid>
<link>http://www.opensource.apple.com/release/mac-os-x-108/</link>
<description>Mountain Lion Sources (XNU 2050.7.9 and others) are officially out in the public domain, and it's great to see that the reverse engineering and educated guesses made in the book have all proved correct!</description>
<pubDate>Thu, 02 Aug 2012 00:30:25 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Content Added: Book Table of Contents</title>
<guid isPermaLink="false">http://www.newosxbook.com/index.php?page=main&amp;</guid>
<link>http://www.newosxbook.com/index.php?page=book</link>
<description>Main page edited. Added welcome message</description>
<pubDate>Fri, 08 Jun 2012 23:07:19 EDT</pubDate>
</item>
<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>Content Added: Main Page</title>
<guid isPermaLink="false">http://www.newosxbook.com/index.php?page=main</guid>
<link>http://www.newosxbook.com/index.php</link>
<description>Main page edited. Added welcome message</description>
<pubDate>Tue, 08 May 2012 23:07:19 EDT</pubDate>
</item>

<item xmlns:media="http://search.yahoo.com/mrss/" >
<title>RSS is now live, but experimental</title>
<guid isPermaLink="false">http://www.newosxbook.com/xxx/xxx/xxx</guid>
<link>http://www.newosxbook.com/index.php</link>
<description>Watch this space for more news and announcements!</description>
<pubDate>Tue, 08 May 2012 23:06:09 EDT</pubDate>
</item>








</channel>



</rss>


