Scream...

Congrats to the dev team for finding the last put to work in the S5L. We Gregorian calendar month not fit in on galore belongings, but I certainly respect your skills.

Pwnage uses an undreamed of put to work actually at the DFU level, which instrumentation it's secured into the implements of war. I have managed to regurgitate the put to work, but in no way see it. I can't act for your thinking. This is consanguine to finding a soft-exploitable put to work in the bootrom of the baseband.

Edible fruit unsuccessful to cover it up by having the new WTF downloaded as soon as iTunes sees the phone(0x1227) vs DFU(0x1222). I belief they strength be cover an put to work but point just figured they didn't want the iBoots unencrypted. Good thing dev looked closer.

Also it's unlikely they left the LLB unsigchecked in the 3G. They have no the encrypt in the DFU to sig check, they just don't call it.

This is also great tidings for iphonelinux. We'll be able-bodied to boot encrypt without the requisite for some of Apple's copyrighted software(and maybe without their cert).

Twenty-four hour period 4-hour interval is a good day for iPhone
 

Infineon, we have a question

The 3G bootloader is sig patterned by the bootrom. So even removing the NOR and fixture the bootloader(to remove piping fw sig checks) and piping firmware doesn't work for an withdraw. Big acknowledgement to TA_Mobile for dumping the NOR and confirmatory this. You have no real skills.

The X-Gold 608 is the chip old. The lame "datasheet" infineon gives us shows the implements of war RSA and the secure bootrom. So we have a real question. Even if we find an unsigned encrypt put to work, which wasn't finished for the former deuce bootloaders in software(we remuneration tricks to play with the nor), we still can't unlock.

Even though the bootloader isn't easy for transfer, theres really zero here. This bootloader doesn't be some of the synergistic modality functions, just a stub which is precise like to the old bootrom(but with sig checking). The synergistic attender is tacked on to the end of all fls and eep file, and is soused at 0x86000. BBUpdaterExtreme contains various ramloaders as well, but I disbelieve the one old is from the news file itself. You do not requisite the bootloader to work on the baseband, you just requisite the files off the ramdisk. Also newsworthy to note, the 2 rsa keys the bootloaders use haven't denaturised since 3.9 or 4.6 So you have these too.

Putting to death CommCenter on 2.0 kills the wi-fi, which will make excavation with the baseband a bit harder. Change of location synergistic modality is nowadays finished with a call to the meat to raise an I/O pin before resetting.

The first step to tackling this is dumping the bootrom. We requisite no put to work, I don't care where, to dump discretional storage device. Point we can dump 0x400000, which is the new "secure" bootrom.
 

Installer 4.0b6 and New Updated Confidant Encrypt

Hi!

Proudly presenting you the new exploratory of Installer - 4.0b6.

New and changed:
  • Search. It searches among packages from the repositories you have added, and, if you let it sit for 5 seconds, will question our participant and return packages that square measure easy from repositories you don't have added (that we know about) with an derivative to automatically add and instal. Confidant owners, upgrade to the word turning of the repo encrypt (below) to have your confidant added to the search engine.
  • Uninstall nowadays deeds correctly.
  • Fixed a lot of protection issues especially with trade HTML content pages.
  • Updated the Categories and Tasks icons so they square measure little ugly.
  • Fixed a bug with four-fold copies of Installer appearance in Installed Packages low-level no circumstances.
  • Installer will nowadays correctly check and prompt for an news of itself.

Also, to play along the Installer release, a new grouping of the Confidant encrypt is up. Grab it Hera: repo-r1114.zip

What's new in the repo code?
  • Added an derivative to ping the Installer search participant so it reindexes your confidant. The ping occurs during regenerate.php run.
  • Much better manipulation of ZIP compendium, since this is what least group had troubles with. It nowadays attempts to determine which way to use to unfasten your files (PEAR::ZipArchive, zip_open or shell_exec("unzip")). Gratify note that we didn't test zip_open piece of the encrypt as we don't have a participant with that plugin compiled in PHP.
  • DOMDocument::load() should work low-level PHP4. We hope.
  • Slightly better manipulation of the four-fold versions of the European package.
How to upgrade? Simply exchange regenerate.php with the new one, and add new conformation parameters from config.inc.default.php to your config.inc.php. Here square measure deuce: REPOSITORY_URL, that should have a full way to your repo (with a trailing slash), and ZIP_CMDLINE_PATH (lone add this if necessary). Have in mind to config.inc.default.php for the descriptions and copy-paste goodness.

Don't forget to regenerate your repositories once upgraded, and also don't forget to put 2.0.2 into POSSIBLE_FIRMWARE_VERSIONS lay out so group on the new firmware can see your packages!

Acknowledgement. :)

 

The Integrated DisAssembler(EDA)

I was hoping person would notice this clearly isn't IDA...

It's EDA, my disassembly/simulation rooms. But it isn't like some otherwise simulator around twenty-four hour period 4-hour interval. Envisage turning control in a simulator, where storage device locations square measure files, manual square measure changelists, and running is committing. You'll be able-bodied to see which didactics restricted some part of storage device, and all alteration it ready-made. Staining MMIO should be caretaker easy.

The picture is the EDA frontend, rendered in Campaign. The EDA backend also has a patch causal agent that finds locations to patch founded on their position in the encrypt, instead of hard-coding one physical object. It also allows in writing function comparisons between dissimilar versions of the code.

Sadly, it's still a work in onward motion. Maybe when its finished, I'll look for the 3G withdraw.
 

QuickGold for iPhone - Jailbroken iPhone app testimonial

This one's not one of reenforce, but an app ready-made by Zachary "zataang" Taanges really hit the spot. Victimisation the Dock 3.0 source encrypt as a reference, Zach created a aesthetical text-based app launcher known as QuickGold that runs right on top of SpringBoard.

It's easy nowadays in Cydia (hosted by Shaun "Ste" Erickson).

This thing is great, just hit the Home button spell already at the home screen and start typewriting what you want, point tap the resultant role that matches. So fast (even faster than Dock)!

Read the rest of this post