NCK Physical property=15

So acknowledgement to the sorcerous of an energizing someone and the model work of Videodisk Jon, I got the activation/unlock record of a European country unbarred iPhone. The field looks like

"UnlockCode" = "NO=111111111111111&";

with the 1's replaced by the encrypt. "NO" is the lock type. Here square measure fifteen digits, so I'm beautiful sure the NCK physical property is 15. This is out of range of a bruteforcer, and I mistrust, although its possibility, that the NCK's square measure founded off the IMEI/DevID. I would think Edible fruit just has a big operation table. Although some perceptible pattern would diminish the inhumane force time. So I still really requisite a.plists off judicial unbarred phones.
 

NCK Pattern: 6 So Right: No German pattern

So right I have (see title) NCK <=> IMEI combinations. I can't post them, since they square measure sore collection of the group United Nations agency were openhearted decent to extract their a.plist for me. I have conditioned that the German ones use "SP" instead of "NO". Also the deuce German NCK's I have both start with the number 3. Fortuity? Keep these a.plists flowing, could group gratify posts requests on their respective terminology iPhone forums? Also the algorithmic rule old to test the NCK on the telecommunicate is familiar and is not even close to nonreversible. Inhumane force is able at 100,000 k/s, so the letter persuasion of finding a pattern in the NCK's is to devalue the time mandatory for that inhumane force.
Also my hypothetic NCK generation system; this has no portion in thing anyone has discovered but... IMEI^d adolescent n, where d and n square measure relatively prime and n is like in size to the IMEI. If Edible fruit keeps d and n secret, they could give NCK's assumption an IMEI when no one else could.
 

1.1.3 is reaching, unlocks will find soon

I haven't been excavation too little with the iPhone lately, but I did take a final look at the new bootloader on the way back from North American country. I also looked concluded the NCK book again.
As right as work with the NCK goes, I don't think we will get anywhere. I do disbelieve the book square measure generated from the IMEI/Serial, but it is finished well decent that without Apple's electronic device we won't be able-bodied to do it. Also bruteforce is totally impractical.
I also ready-made a misunderstanding with the implements of war hack I posted. The 1.1.2 secpack will NEVER invalidate on the new bootloader. The new bootloader actually does deuce checks and the SHA needs to be repeated twice. You will see it when you decode the new secpack. The A16 hack will work to invalidate the 1.1.3 secpack on 1.1.3 though.
So it's VERY influential that you do not upgrade your baseband. I am 100% sure the old implements of war hack will work when the 1.1.3 secpack is old with iEraser. I also think that the -0x400 hack still exists in the new bootloader, so software system unlocks square measure hopefully reaching with the release of the new secpack. I've detected rumors of group United Nations agency have 1.1.3 in exploratory. The whole community awaits this secpack. Gratify get it out here as soon as possibility.
 

NCK Pattern: 6 So Right: No German pattern

So right I have (see title) NCK <=> IMEI combinations. I can't post them, since they square measure sore collection of the group United Nations agency were openhearted decent to extract their a.plist for me. I have conditioned that the German ones use "SP" instead of "NO". Also the deuce German NCK's I have both start with the number 3. Fortuity? Keep these a.plists flowing, could group gratify posts requests on their respective terminology iPhone forums? Also the algorithmic rule old to test the NCK on the telecommunicate is familiar and is not even close to nonreversible. Inhumane force is able at 100,000 k/s, so the letter persuasion of finding a pattern in the NCK's is to devalue the time mandatory for that inhumane force.
Also my hypothetic NCK generation system; this has no portion in thing anyone has discovered but... IMEI^d adolescent n, where d and n square measure relatively prime and n is like in size to the IMEI. If Edible fruit keeps d and n secret, they could give NCK's assumption an IMEI when no one else could.
 

Notes on a 1.1.2 OTB Software system Withdraw

I don't see it event anytime soon.

The old exploits aren't here anymore. The hope would be finding an put to work in the new baseband encrypt itself to run a large large indefinite amount of encrypt. But I think the bootloader is beautiful well secured down.

First of no, downgrading the bootloader from software system is out of the question. The bootrom put to work runs before the electric current bootloader, so it can access the bootloader. But when the bootloader boots, it locks down its sections of flash. So aft the bootloader runs, the bootloader can't be touched.

Secondly, the lone secpack that validates on 4.6 is >= 1.1.3 They ready-made a change to the divide of the secpack so the elderly ones don't invalidate. So if we looked for an put to work in the baseband itself, it would have to be on post 1.1.2

Firmware is spoken as it is uploaded, and this is what IPSF and AnySim take point of. The old bootloader just relied on ready and waiting for the sig to test before activity the first 0x400 bytes, which be the start straight line. The new bootloader also needs the "secpack" in 0x3c0000 to not test. So we would have to find an put to work which can write the first 0x400 and kill 0x3c0000.

The IPSF withdraw itself uses an RSA hack in bootloader 3.9 This has been thoroughly spotted in 4.6

Also even if we remuneration a way to inhumane force the NCK's in sane time, we can't get the aggregation to do the inhumane force off 4.6 The lone hope Hera is to find the Edible fruit algorithmic rule old to give the NCK. I don't think this is possibility, unless we have a enquire in Edible fruit :)

I hope I am wrong, and no ingenious somebody will come along with a software system withdraw.