1.1.3 is reaching, unlocks will find soon

I haven't been excavation too little with the iPhone lately, but I did take a final look at the new bootloader on the way back from North American country. I also looked concluded the NCK book again.
As right as work with the NCK goes, I don't think we will get anywhere. I do disbelieve the book square measure generated from the IMEI/Serial, but it is finished well decent that without Apple's electronic device we won't be able-bodied to do it. Also bruteforce is totally impractical.
I also ready-made a misunderstanding with the implements of war hack I posted. The 1.1.2 secpack will NEVER invalidate on the new bootloader. The new bootloader actually does deuce checks and the SHA needs to be repeated twice. You will see it when you decode the new secpack. The A16 hack will work to invalidate the 1.1.3 secpack on 1.1.3 though.
So it's VERY influential that you do not upgrade your baseband. I am 100% sure the old implements of war hack will work when the 1.1.3 secpack is old with iEraser. I also think that the -0x400 hack still exists in the new bootloader, so software system unlocks square measure hopefully reaching with the release of the new secpack. I've detected rumors of group United Nations agency have 1.1.3 in exploratory. The whole community awaits this secpack. Gratify get it out here as soon as possibility.
 

iPhone 3G Unbarred?

So I read this on gizmodo. Here's the truth...

Post exploratory 4, the ramdisk hack stopped up excavation. Pitiful Zibri, venture you'll have to slip away other put to work. They also denaturised the recuperation modality USB communications protocol to use the control terminus to send commands.

The possiblity of unlocking, which is precise outlined from jailbreaking, is founded entirely on the baseband bootloader. Edible fruit doesn't execute to upgrade the bootloader on phones in the field, probably for fear of bricks. So some old iPhones out here twenty-four hour period 4-hour interval, thoughtless of turning, can be unlocked.

The iPhone 3G uses a dissimilar bootloader, which I disbelieve here aren't some familiar exploits in yet. So no unlock.

Here is a familiar put to work in iBoot, on both the old and 3G iPhones. The "the general date/time is not firm yet" pwnage tool will render it to escape no 2.0 software system iPhones, 3G and other. Dev group, that date better be soon or I strength just have to release yiPhone. The iBoot put to work is yours, use it. You wouldn't want a repeat of ZiPhone nowadays...
 

Infineon, we have a question

The 3G bootloader is sig patterned by the bootrom. So even removing the NOR and fixture the bootloader(to remove piping fw sig checks) and piping firmware doesn't work for an withdraw. Big acknowledgement to TA_Mobile for dumping the NOR and confirmatory this. You have no real skills.

The X-Gold 608 is the chip old. The lame "datasheet" infineon gives us shows the implements of war RSA and the secure bootrom. So we have a real question. Even if we find an unsigned encrypt put to work, which wasn't finished for the former deuce bootloaders in software(we remuneration tricks to play with the nor), we still can't unlock.

Even though the bootloader isn't easy for transfer, theres really zero here. This bootloader doesn't be some of the synergistic modality functions, just a stub which is precise like to the old bootrom(but with sig checking). The synergistic attender is tacked on to the end of all fls and eep file, and is soused at 0x86000. BBUpdaterExtreme contains various ramloaders as well, but I disbelieve the one old is from the news file itself. You do not requisite the bootloader to work on the baseband, you just requisite the files off the ramdisk. Also newsworthy to note, the 2 rsa keys the bootloaders use haven't denaturised since 3.9 or 4.6 So you have these too.

Putting to death CommCenter on 2.0 kills the wi-fi, which will make excavation with the baseband a bit harder. Change of location synergistic modality is nowadays finished with a call to the meat to raise an I/O pin before resetting.

The first step to tackling this is dumping the bootrom. We requisite no put to work, I don't care where, to dump discretional storage device. Point we can dump 0x400000, which is the new "secure" bootrom.
 

Don't eat up yellowsn0w!

Hello all,

We wish you a precise willing, levelheaded, and hopeful 2009!

Once you have installed yellowsn0w, gratify report your mortal or failure here. it’ll help us with the bug fixes.

We have free the 0.9.6 beta yellowsn0w 3G withdraw exercise, 0.9.6 exploratory should fix EVEN MORE problems :-). Gratify remember to add natural action -> Hera <- as we can get functional natural action that will help us. We convey that everyone upgrade to this version.

Please note the following:

BASICS

  • The withdraw deeds exclusively with baseband 02.28.00. This baseband is provided by the word firmware news (2.2) from Edible fruit. You’ll requisite to upgrade to this release victimisation iTunes and point use QuickPwn to modify etc. Here square measure wad of tutorials about this on iclarified, bigboss, modmi and otherwise established instructor sites. Because it deeds on 02.28.00, it is easy to everyone on the satellite. This instrumentation we don’t requisite to unnecessarily expose holes in earliest basebands, which is an influential concern.
  • The exercise is a small god that is launched on boot. It injects the loading at boot and also whenever here is a baseband determine. You won’t notice thing about it otherwise than that your third-party sim nowadays deeds. It’s a small program and obtrusive. Here is no GUI (this is by design).
  • You can add the exercise victimisation the sources defined below. Here square measure Cydia and Installer sources easy, so use whichever you square measure homely victimisation.
  • yellowsn0w is completely extractible done Cydia, the command line, and iTunes.

DETAILS

  • There is a familiar issue with SIM game that have STK (SIM Toolkit) exercise menus. These menus square measure usually items so much as “top up” “get credit” “lotto book” etc. These agenda items flurry the exercise sometimes. Removing and reinserting the SIM once aft boot (give it about 10 secs 60 seconds (with v0.9.1) aft you see the slide to withdraw contraption) fixes this issue. We’re excavation on a better fix. Update: version 0.9.4 fixes this for galore (but probably not no) users United Nations agency previously had to act a minute and point replug the sim.
  • For those of you victimisation SIM game without STK menus, the exercise has no elective arguments that will make the withdraw little faster for you. So either investigate on your personal (use “yellowsn0w -h” for activity) or act for a customization writeup.
  • After you instal yellowsn0w via Cydia, you should return to the Cydia piping agenda point boot your iPhone with the 3rd set SIM installed. Act for the slide to withdraw screen, point act 10 or 15 secs more than. If you don’t see your carrier name pop up, point remove your SIM, reinsert it, and act 10 secs more than. This is the step we’ll be excavation on eliminating next.

RANDOM

  • The exercise is turning 0.9.5 This is considered exploratory software system, you use it at your personal endangerment. You know the score.
  • The exercise is free on a non-commerical portion. Gratify do not accept pirates and soiled ripoffs of this software system. We permit this software system for single use and in a non-commerical geographic region (thought you can’t charge for it). The techniques and methods old square measure not to be old by third set companies. We square measure looking you Jody…we won’t be so unvindictive this time.
  • Direct linking to the confidant URLs is illegal, gratify lone link to this post. We will be checking referers.
  • Happy 2009 and enjoy!

The iPhone 3G is old no concluded the world with no sorts of SIM game, and we almost certainly will see young and unhoped situations. If the soft withdraw doesn’t work for you on day 1 (literally day 1, of 2009!) point gratify don’t fear or be eager. This is new area for everyone, so savor the ride as little as you can :)

RELEASE INFO

UPDATES

  1. Soon you’ll see yellowsn0w 0.9.1 in the repos. It uses a little mortal change to let your SIM card set. If you have problems with 0.9.0, try this one and wait a full minute aft you see homescreen, point reinsert sim card. We requisite both mortal and failure reports to line this across the world, so gratify be affected role (but gratify also report result!) As of v 0.9.4 there’s no mortal a one-minute change step. If you don’t see your carrier when your homescreen comes up, you Gregorian calendar month still requisite a sim reinsert (for now).
  2. If you square measure in the U.S. and square measure hard this with T-Mobile, you mustiness turn off the 3G switch in Settings. Also if you square measure good with the command line, you can make it little easier by adding the line -q right aft the /usr/bin/yellowsn0w line in /System/Library/LaunchDaemons/org.iphone-dev.yellowsn0w.plist (that’s and advanced tip, hopefully person will make a boosprefs type of tool for it) The -q derivative is nowadays deprecated in 0.9.4+ (it’s nowadays always in quick modality, unless you use the -l derivative for long mode).
  3. No PIN support yet. Remember how we same this was exploratory? Well we’re still excavation out the flow for SIMs with PINs enabled. Gratify disenable some PIN you Gregorian calendar month have on that SIM before hard yellowsn0w, for now.
  4. The withdraw will silently pull up stakes on thing otherwise than baseband 02.28.00. It detects the wrong turning and just equal to abstain some scathe. Gratify double check your Modem Firmware service in Settings->General->About.
  5. For ankle-biters that square measure pointlessly reversing the exercise the source is here no open, but remember Jody, we square measure looking you.
  6. Thanks for the openhearted language Stephen

 

My iPhone's broadcasting cooked - can I have yours?

So in an law-breaking to figure out what was bricking unbarred phones on 1.1.1, I upgraded my unbarred telecommunicate to 1.1.1. Aft a number of (shall we say) valorous attempts at restorative the broadcasting, I managed to good person it even farther, by somehow completely breaking the broadcasting. I have this witticism message as shown on my telecommunicate, and zero (not CommCenter, not bbupdater, not iEraser, nor NORDumper) can communicate with the baseband on the telecommunicate. No restores fail because they can't talk to it.

So it looks like if I want to continue experimentation with 1.1.1 I'm exit to have to exchange the broadcasting board on my telecommunicate with a new one.

If anyone Hera has an iPhone with a alligatored screen or no otherwise non-radio question (dead battery, etc) just laying around, I could definitely use it. I'll send you an assembled Time Fountain for it, if you'd like.