Tag Archives: Pwnage Tool

[iPhone] Latest iPhone 3GS Contain New Bootloader

The latest manufactured iPhone 3GS devices seem to contain new bootloaders, which can not be compromised using the 24k bug. Although Musclenerd of the iPhone Dev Team paints a dark future, Mathieu Hervais expects that there are still ways thru the chain of trust in order to jailbreak.


Picture is courtesy of Mathieu Hervais

P.S. To find out which Bootrom your iPhone got, just get yourself a Mac and check system profiler while your iPhone is in DFU mode.

[iPhone] GeoHot Releases Jailbreak for 3.x Called BlackRa1n

Today notorious GeoHot released a standing new jailbreak tool called BlackRa1n. BlackRa1n is currently only available for Microsoft Windows. It is supposed to jailbreak any 3.x based iPhone or iPod touch. No matter if you’ve jailbroken before or not.

BlackRa1n is fairly self explaining and straight forward designed. It’ll bring your iPhone or iPod Touch automatically into Recovery Mode.

Sadly currently BlackRa1n does not hacktivate your iPhone. So you still need a valid subscription with an Apple licensed carrier or a factory unlocked iPhone.

Kudos fly out to GeoHot. Standing work again.

» Download BlackRa1n here

[iPhone] GreenPois0n to Jailbreak all iPhones and iPod Touchs

What has happened so far

Some irritation is going on in the Apple hacking community. On the one hand GeoHot today announced that there will be a tool that will allow jailbreaking all iPhones and iPod Touchs, but as he wished to perform further tests he didn’t tell anything about the procedure.

The Chronic Dev Team on the other hand who seem to have been working together with GeoHot now released the technical details about this hack. Sadly as there is no GreenPois0n tool available as of now, the technical details are most likely useless for 99,9% of all iPhone and iPod users.

Reasons are unknown why the Chronic Dev Team released the information before a tool has been finished. But it seems GeoHot is not amused by taking these steps.

Update 2009, Oct 19th: GeoHot and the Chronic Dev Team tell they have independently found the bug that allows for jailbreaking the 3.1 firmware.

Enduser compatible information

According to mFX.ch (german only) the forthcoming GreenPois0n jailbreak tool will not require to bring the iPhone into DFU mode. The GreenPois0n will be released on the PirateBay*.

External Links

» GeoHot on the universal 3.1 jailbreak
» Chronic Dev Team on 3.1. jailbreak progress
» GreenPois0n site (only dummy page atm)…
» TheiPhoneWiki with technical details

* for legal reasons here in Germany we cannot link directly to the PirateBay.

[iPhone] GeoHot releases iPhone 3Gs Jailbreak (Upd.)

Update July 5th, 2009: GeoHot now also provides a Mac OS X version of the jailbreak tool. Windows and Mac versions ready for download at purplera1n.com

That’s it with the 3.0 firmware and the iPhone jailbreaks. Apple has been beaten again. This time by GeoHot. Although the iPhone Dev Team seems to have their programs already prepared they preferred to wait with the release of an updated PwnageTool. GeoHot did not wanna wait and decided to release a Windows based jailbreak tool for the iPhone 3Gs called PurpleRa1n.

Status

All three iPhone generations can now be activated, jailbroken and unlocked with the current firmware 3.0. Currently for the iPhone 3Gs there is only a Windows version available that is under strong beta testing. Anyway you can give it a try. The security whole that gets exploited in the iPhone 3Gs is well known as the 24k bug that has been found in january in the iPod Touch 2nd generations.

After jailbreaking, the iPhone Dev Team’s UltraSn0w should unlock your baseband.

Our recommendations

By now you know we are the conservative ones. We recommend: wait a couple of days. PurpleRa1n is still beta. But can hacks ever become stable? ;-)

More information to be found here:
» GeoHot accounces jailbreak for iPhone 3Gs
» iPhone Dev Team confirm unlock of iPhone 3Gs
» Get iPhone 3Gs jailbreak tool (PurpleRa1n.exe) here

iPhone 3GS Unlock Demonstration from planetbeing on Vimeo.

[iPhone] HowTo Jailbreak and Unlock using RedSn0w

I. Abstract

The following article will show you how to install firmware 3.0 on your iPhone 2G by also allowing to jailbreak, activate and eventually to unlock (JAU process). At the moment of writing this article is for Mac OS X users with iPhone 2G’s only.

II. Who needs this article?

We suppose 50% of all 2G users around the globe. As iPhone 2G’s were sold almost everywhere with Sim-Lock enabled (besides some T-Mobile Germany or Orange France unlocked 2G’s).

III. Warning

You’d better read all of this in detail before you do anything practically! If you feel there is something you don’t understand or something you will not be able to handle, then go and ask someone who is in the know.

!!!!!!!! Otherwise your devices may be terribly screwed up! !!!!!!!

IV. Required Downloads

Download these tiny things first:

» RedSn0w for Mac OS X
» iPhone OS 3.0 for iPhone 2G
» if you are using an iPhone 2G: get Bootloader 3.9 and 4.6

RedSn0w is almost the same as QuickPwn was in the ancient days of iPhone firmware 2.x

V. Preparing for Take off

  1. you need to have iPhone OS 3.0 already installed / updated /restored via iTunes
  2. install RedSn0w
  3. start RedSn0w
  4. Browse to the downloaded restore firmware (iPhone1,1_3.0_7A341_Restore.ipsw)
  5. Wait for the firmware to be checked

  6. Click Next
  7. Wait for the firmware to be modified
  8. Select Install Cydia (and Unlock if you are using an iPhone 2G. If you are using an iPhone 3G, don’t select to unlock, since it will not work this way)
  9. Click Next
  10. Browse for the Bootloaders you downloaded
  11. Click Next
  12. Turn your iPhone off
  13. Turn iTunes off

VI. Fasten your seat belts // Get into DFU mode

  1. Click Next
  2. bring out beloved jesus phone into DFU mode
  3. RedSn0w guides you thru the required steps (anyway this may take several repetitions as this is not as easy as some people write on the net!)

VII. Ignition sequence start

  1. the uploaded modified ramdisk will do all the required stuff
  2. to indicate what is going on your iPhone will show some nice pictures like this:
  3. don’t disturb the process
  4. instead: relax and get yourself a good drink or a cigarette
  5. as this may take some minutes

VIII. Possible issues

Although we haven’t been reported any yet, this doesn’t mean there can’t go something wrong. If you run into problems, try:

  • restoring original unmodified 3.0 firmware from within iTunes 8.2
  • make sure you installed firmware 3.0 with iTunes 8.2
  • generate a custom pre-hacked ipsw using PwnageTool (find article here)

IX. Kudos

Fly out to the iPhone Dev Team. You guys should get paid by Apple…

[iPhone] HowTo Jailbreak and Unlock using PwnageTool

I. Abstract

The following article will show you how to install firmware 3.0 on your iPhone 2G by also allowing to jailbreak, activate, and eventually to unlock (JAU process). At the moment of writing this article is for Mac OS X users with iPhone 2G’s only.

II. Who needs this article?

We suppose 50% of all 2G users around the globe. As iPhone 2G’s were sold almost everywhere with Sim-Lock enabled (besides some T-Mobile Germany or Orange France unlocked 2G’s).

III. Warning

You’d better read all of this in detail before you do anything practically! If you feel there is something you don’t understand or something you will not be able to handle, then go and ask someone who is in the know.

!!!!!!!! Otherwise your devices may be terribly screwed up! !!!!!!!

IV. Required Downloads

Download these tiny things first:

» Pwnage 3.0 for Mac OS X
» iPhone OS 3.0 for iPhone 2G
» if you are using an iPhone 2G: get Bootloader 3.9 and 4.6

V. Preparing for Take off // Prepping your custom iPhone OS 3.0

  1. make sure you synced your iPhone with iTunes before to have all your current calendar and address book entries in a safe place
  2. Install PwnageTool
  3. start PwnageTool
  4. Choose Expert Mode
  5. Select iPhone
  6. Click the Next button (down right of PwnageTool window)
  7. Select (or browse for) the iPhone1,1_3.0_7A341.ipsw firmware
  8. Click the Next button
  9. You now may choose some more Cydia Packages (like SSH), but you can also safely install this later via Cydia on the iPhone. This is a matter of taste
  10. Click Create (here in german “Erstellen”)
  11. Click the Next button
  12. Select a location to save the custom firmware 3.0
  13. wait some minutes for the creation of your custom firmware 3.0
  14. you may provide your adminstrator password during creation phase, this is normal !

VI. Fasten your seat belts // Get into DFU mode

  1. in case you never pwned your iPhone before: bring it into DFU mode first.
  2. PwnageTool guides you thru the required steps (anyway this may take several repetitions as this is not as easy as some people write on the net!)

VII. Ignition sequence start // Restore

  1. start iTunes (make sure you’re using iTunes 8.2)
  2. Select your iPhone (found on the left column under devices)
  3. and hold the Alt Key and Click the Restore button (this allows browsing for your custom firmware)
  4. The iPhone software will be extracted and prepared for restoring
  5. in the meantime your iPhone will show a status bar like this:
  6. The whole process will take some minutes, don’t wonder about that

VIII. Possible issues

You may receive an “unknown error 1600”, “unknown error 2001”, “unknown error 10”, or “unknown error 20” . If this is the case you may try this:

  • restore the original unmodified iPhone firmware 3.0 first and the re-restore your custom firmware and
  • try aswell in DFU mode as in normal mode
  • if all that does not work: restore with original unmodified iPhone firmware and jailbreak with redsn0w (article here)

IX. Kudos

Fly out to the iPhone Dev Team…

[iPhone] Jailbird for Windows to Replace WinPwn

There seems to be a new kid on the block called Jailbird. Jailbird is an independent implementation of exploits the iPhone Dev Team found in order to

  • activate,
  • jailbreak and
  • sim-unlock
  • all firmware revisions 2.x

As WinPwn has not been updated for a while this is amazing news for the Windows users among us.

See Jailbird’s Website for further information…

[iPhone] HowTo Activate and Unlock using QuickPwn 2.1

I. Abstract

This is a short HowTo since all of you by now know how to use QuickPwn, don’t you? in short: QuickPwn is an Après-Tool. Means: you let iTunes 8 do the update process and use QuickPwn afterwards to “open” your device. Note:

  • 2G iPhones can be jailbroken and unlocked
  • 3G iPhones can be jailbroken, but not unlocked
  • iPod Touch 1st generation can be jailbroken
  • iPod Touch 2nd generation can not be jailbroken

Our article will not cover the iPod Touch, but the iPhone.

II. Requirements

III. Warning

Jailbreaking and unlocking is illegal to be performed with iPhone devices that are part of a current agreement (mostly 12 or 24 months). You would violate your contract by jailbreaking and unlocking! Don’t do it.

  • If you’re updating: all your Cydia and Installer.app based applications will be lost and need to be installed again!
  • Make sure you make a backup of your data!

IV. Update iPhone firmware

  • connect your iPhone with your PC
  • start iTunes 8
  • choose your iPhone (under devices)
  • hold the shift-key (on your keyboard) and do a mouse-click on the Update Button – a file-open window will pop up like this:
  • locate the downloaded firmware 2.1 (named: iPhone1,1_2.1_5F136_Restore.ipsw) and open it
  • iTunes will begin to update your iPhone automatically





  • After having updated the iPhone will reboot. If you are using an already Pwned iPhone it will remain activated and unlocked, you only need to jailbreak.

IV. QuickPwning it :-)

  • Let your iPhone plugged to your computer
  • Close iTunes
  • Start QuickPwn 2.1-1
  • You will be greeted with the Device Detection screen, click the right-arrow to proceed:
  • on the next window, click the Browse button to locate your iPhone1,1_2.1_5F136_Restore.ipsw firmware:

  • QuickPwn will check if the firmware matches the version currently running on your iPhone and will allow you to proceed (click the right-arrow):
  • the next windows allows you to select, what you want to install. We recommend to install both Cydia and Installer.app. If your iPhone has not been unlocked until now, here you can also choose to simunlock it. As we are quite conservative: we never change the boot logos, but this seems to be a matter of taste. After having selected, click the right-arrow button to proceed.
  • For safety reasons, QuickPwn will remind you to leave your iPhone plugged to your computer, click the right-arrow button to proceed
  • Read and follow the instruction on this window very carefully! QuickPwn will help you counting!
  • After that, QuickPwn will take control and perform the following actions automatically:


  • When all the tasks have been completed, QuickPwn has finished.
  • Your iPhone will perform some more actions for the next few minutes. It will show it is changing the NOR and so on and will reboot then.

After having rebooted your iPhone will be perfectly jailbroken and unlocked

V. Final words

Guys, we hope we could clarify some more things here than others did. We appreciate your comments on this. Kudos to all of you and remember to consider our sponsors, they really got the coolest offers ;-) Kudos fly out to the iPhone Dev Team! Live long and prosper, guys.

[iPhone] Apple Sells Unlocked 3G’s in Hong Kong (update)

As of today Apple sells their new iPhone 3G factory unlocked in Hong Kong. The Apple Site explicitly says:

“iPhone 3G purchased at the Apple Online Store can be activated with any wireless carrier.”

Prices will vary from 5,400HK$ for the 8GB model (695US$ or 476€) and 6,200HK$ for the 16GB model (798US$ or 547€). This obviously is the end of Apple’s strategy of exclusive carrier linking of their iPhones.

We want to remind you that import taxes will apply when shipping from Hong Kong to either the US or Europe. So this would not be a bargain. You’d better wait a couple of weeks, probably Apple will apply this new selling strategy to other markets as well in the near future. Next step should be to license visual voicemail to any carrier worldwide and make it a standard in cell phone communication.

» Find more information on the Apple Hong Kong page
» See our iPhone 3G “Factory Unlocked List” list here (update)..

[iPhone] PwnageTool and QuickPwn for Firmware 2.1 released (Updated)

The iPhone Dev Team did it again. Firmware 2.1 has been released yesterday and PwnageTool and QuickPwn are yet updated to support jailbreaking and unlocking. Nice! Besides support of firmware 2.1, the iPhone Dev Team found a way to even fool the new iTunes 8 pwnage detection (read our recent article here). Now iTunes 8 will install custom firmware compiled with PwnageTool again – no patching or modifying of iTunes 8 required…

[Update] 14th of Sept, 2008: People report issues with different errors. We are just prepping a collection of workarounds. Find them in some minutes here.

Kudos to the Dev Team !!!

» Download QuickPwn here(SHA: 0b2dcb51e224b12590793e8a758dd80c450e5b64)
» Download PwnageTool here(SHA: 92487230c66296ec1e414260b5f107e5d351923f)