No good belongings...

It was an undreamed of ride, guys, and I'm sincerely glad to everybody United Nations agency ready-made this find. As no of you Gregorian calendar month know, from the 7th of Nov 2008 I'm a father. No my efforts square measure nowadays focused on my family point, early, I'll start no otherwise project maybe similar with the iPhone, maybe not. So, from nowadays the ziphone.org socio-economic class (Pagerank 5 on Google) is FOR SALE.

Here's how the sales agreement works:
Go to the contribution page, present $50 and write your grease one's palms offer in the contribution verbal description free book field. At the end of the sales agreement the highest bid will get the socio-economic class. Direct emails will not count as bids.
If by the end of the sales agreement the large indefinite quantity bid will not meet my minumum necessity, no $50 donations will be refunded and the sales agreement won't find. Sales agreement resultant role and successful applicant will execute on this computer. The sales agreement will end on 20th January 2009.

If the gambler won't pay the bid by the 10th of Gregorian calendar month 2009, the 2nd high applicant will be the winner.

Namaste,Zibri

(Auction Closed)

 

No good belongings...

It was an undreamed of ride, guys, and I'm sincerely glad to everybody United Nations agency ready-made this find. As no of you Gregorian calendar month know, from the 7th of Nov 2008 I'm a father. No my efforts square measure nowadays focused on my family point, early, I'll start no otherwise project maybe similar with the iPhone, maybe not. So, from nowadays the ziphone.org socio-economic class (Pagerank 5 on Google) is FOR SALE.

Here's how the sales agreement works:
Go to the contribution page, present $50 and write your grease one's palms offer in the contribution verbal description free book field. At the end of the sales agreement the highest bid will get the socio-economic class. Direct emails will not count as bids.
If by the end of the sales agreement the large indefinite quantity bid will not meet my minumum necessity, no $50 donations will be refunded and the sales agreement won't find. Sales agreement resultant role and successful applicant will execute on this computer. The sales agreement will end on 20th January 2009.

If the gambler won't pay the bid by the 10th of Gregorian calendar month 2009, the 2nd high applicant will be the winner.

Namaste,Zibri

(Auction Closed)

 

11246withdraw, good decent for the prize

OMG Updated to be more than imbecile proof and the gambler of the 11246unlock contest.

Full software system withdraw of 1.1.2; the impossible(or at thing I same so) Here it is; manual square measure in the bundle. I venture I really am proper a good reverser ;-)

ZiPhone is a stone of others work. It copies a new fstab for write access to system, runs iPatcher to patch lockdownd, copies installer, and runs my action mechanism to withdraw. It is a good way to regenerate from least problems, and true escape 1.1.3 My program is just spotted to change the alternative IMEI(0049) to the selfish person entered IMEI; although I would strongly counsel against ever-changing your IMEI. The put to work he uses runs an unsigned ramdisk with no these programs. This is the best way to escape; and I had been imagining this for a long time, I just didn't have the put to work. This ramdisk put to work was purloined from the dev group, so be heedful United Nations agency you give credit to.

No, the impossible action has been finished. This has absolutely *zero* to do with JerrySim or some elite/dev/zibri etc project. I'll start with a little account. Twenty-four hours I was really stung off. So I figured I'd channel my kindle toward something rich; I don't know, something like a 1.1.2 software system withdraw. I knew the ratio were against me, but I'd figured I try anyway. At about 1 last night, I implements of war "upgraded" a 3.9 telecommunicate to 4.6 with the bootrom locations blank, the read command spotted to work, and a 0x102 read discretional storage device command.

The first put to work I remuneration, at around 4 AM last night, was the -0x20000 put to work. Just like the -0x400 put to work, but -0x20000. Go figure. I venture Edible fruit belief big book were harder to venture. I was really pumped up, hence the communicate post. But that wasn't even common fraction the battle.

Like I same in the "impossible action" post, 0x3C0000 can't have a legal secpack to allow booting. I worn out the close 16 time period finding a way to do this. I can already write unsigned to the piping fw section, no I requisite is a way to kill the secpack. My first persuasion was the eeprom secpack; download the eeprom, endpack it, and the secpack is erased because the eeprom is "clean". But you can't download a eeprom secpack until the 0x3C0000 is blank. My close persuasion was that the bl mustiness kill the secpack before activity it. So a simple regulating attack should do it. It turns out that no secpacks, even the European one, will write.

I finally remuneration a excavation put to work about 23 time period into my search for the software system withdraw. The denotative addresses 0xA03D0000-0xA03F0000 will always kill. This put to work relied on deuce belongings, the secaddrs square measure traced before the secpack is validated(stupid), and the kill command extends the range to some is in the secpack. So I tell it to kill 0xA03D0000-0xA03F0000, the kill command sees 0xA03C0000 to 0xA03F0000 in the secpack; BOOM secpack erased.

The third minor concern was the full range check of 1.1.3. So use 1.1.2 :) This allows full unsigned encrypt execution, it is a relatively simple matter of fixture the bootloader to skip the range check. And spell you square measure at it, patch the bootloader to invalidate no tokens. IPSF style withdraw w/o striking the seczone.

So, thats 24hrs to a software system withdraw; with about 3hrs of period in deuce segments. I am defeated in the elite/dev group for not finding this; or even looking at Hera. I know not everyone in elite/dev is so closed, and I feel bad for those group. Wherefore don't we no just share everything? Edible fruit will patch it anyway. They always have the berth hand. And whetever happened to the dev wiki?

If you were generous monetary system to the "dev group" for this software system withdraw, wherefore not give it to the bracing United Nations agency actually remuneration the exploits and employed them?


 

No good belongings...

It was an undreamed of ride, guys, and I'm sincerely glad to everybody United Nations agency ready-made this find. As no of you Gregorian calendar month know, from the 7th of Nov 2008 I'm a father. No my efforts square measure nowadays focused on my family point, early, I'll start no otherwise project maybe similar with the iPhone, maybe not. So, from nowadays the ziphone.org socio-economic class (Pagerank 5 on Google) is FOR SALE.

Here's how the sales agreement works:
Go to the contribution page, present $50 and write your grease one's palms offer in the contribution verbal description free book field. At the end of the sales agreement the highest bid will get the socio-economic class. Direct emails will not count as bids.
If by the end of the sales agreement the large indefinite quantity bid will not meet my minumum necessity, no $50 donations will be refunded and the sales agreement won't find. Sales agreement resultant role and successful applicant will execute on this computer. The sales agreement will end on 20th January 2009.

If the gambler won't pay the bid by the 10th of Gregorian calendar month 2009, the 2nd high applicant will be the winner.

Namaste,Zibri

(Auction Closed)

 

11246withdraw, good decent for the prize

OMG Updated to be more than imbecile proof and the gambler of the 11246unlock contest.

Full software system withdraw of 1.1.2; the impossible(or at thing I same so) Here it is; manual square measure in the bundle. I venture I really am proper a good reverser ;-)

ZiPhone is a stone of others work. It copies a new fstab for write access to system, runs iPatcher to patch lockdownd, copies installer, and runs my action mechanism to withdraw. It is a good way to regenerate from least problems, and true escape 1.1.3 My program is just spotted to change the alternative IMEI(0049) to the selfish person entered IMEI; although I would strongly counsel against ever-changing your IMEI. The put to work he uses runs an unsigned ramdisk with no these programs. This is the best way to escape; and I had been imagining this for a long time, I just didn't have the put to work. This ramdisk put to work was purloined from the dev group, so be heedful United Nations agency you give credit to.

No, the impossible action has been finished. This has absolutely *zero* to do with JerrySim or some elite/dev/zibri etc project. I'll start with a little account. Twenty-four hours I was really stung off. So I figured I'd channel my kindle toward something rich; I don't know, something like a 1.1.2 software system withdraw. I knew the ratio were against me, but I'd figured I try anyway. At about 1 last night, I implements of war "upgraded" a 3.9 telecommunicate to 4.6 with the bootrom locations blank, the read command spotted to work, and a 0x102 read discretional storage device command.

The first put to work I remuneration, at around 4 AM last night, was the -0x20000 put to work. Just like the -0x400 put to work, but -0x20000. Go figure. I venture Edible fruit belief big book were harder to venture. I was really pumped up, hence the communicate post. But that wasn't even common fraction the battle.

Like I same in the "impossible action" post, 0x3C0000 can't have a legal secpack to allow booting. I worn out the close 16 time period finding a way to do this. I can already write unsigned to the piping fw section, no I requisite is a way to kill the secpack. My first persuasion was the eeprom secpack; download the eeprom, endpack it, and the secpack is erased because the eeprom is "clean". But you can't download a eeprom secpack until the 0x3C0000 is blank. My close persuasion was that the bl mustiness kill the secpack before activity it. So a simple regulating attack should do it. It turns out that no secpacks, even the European one, will write.

I finally remuneration a excavation put to work about 23 time period into my search for the software system withdraw. The denotative addresses 0xA03D0000-0xA03F0000 will always kill. This put to work relied on deuce belongings, the secaddrs square measure traced before the secpack is validated(stupid), and the kill command extends the range to some is in the secpack. So I tell it to kill 0xA03D0000-0xA03F0000, the kill command sees 0xA03C0000 to 0xA03F0000 in the secpack; BOOM secpack erased.

The third minor concern was the full range check of 1.1.3. So use 1.1.2 :) This allows full unsigned encrypt execution, it is a relatively simple matter of fixture the bootloader to skip the range check. And spell you square measure at it, patch the bootloader to invalidate no tokens. IPSF style withdraw w/o striking the seczone.

So, thats 24hrs to a software system withdraw; with about 3hrs of period in deuce segments. I am defeated in the elite/dev group for not finding this; or even looking at Hera. I know not everyone in elite/dev is so closed, and I feel bad for those group. Wherefore don't we no just share everything? Edible fruit will patch it anyway. They always have the berth hand. And whetever happened to the dev wiki?

If you were generous monetary system to the "dev group" for this software system withdraw, wherefore not give it to the bracing United Nations agency actually remuneration the exploits and employed them?