Showing posts with label Untethered. Show all posts
Showing posts with label Untethered. Show all posts

Sunday, April 29, 2012

JAILBREAK COMPLETE GUIDE

As the whole tech world waits for today’s Apple Event, it seems like a good time to remind both veteran and amateur jailbreakers about the fundamental rule of jailbreaking:  Avoid firmware updates!
In all likelihood we’ll see the GM “gold master” version of 5.1 this week.  DO NOT UPDATE TO 5.1, because you may lose your jailbreak!  The rest of this post details the subtleties with this rule, but if there’s only one message to take home, it’s the overall “do not update” message!  Now for the nitty gritty exceptions:

Soon after 5.1 appears on Apple’s public servers (i.e. iTunes starts to offer it), Apple will stop signing 5.0.1 SHSH blobs.
If you have an iPhone4S, the basic rule above is really the only rule:  you cannot restore back to 5.0.1 once the 5.0.1 signing window is closed, no matter what (even if you saved your SHSH blobs).
If you have an iPad2 with saved 4.x hashes, you can in fact downgrade to that 4.x but you won’t be able to get to 5.0.1 once the 5.0.1 signing window is closed (even if you saved your 5.0.1 SHSH blobs).
If you have a device earlier than the iPad2, you can downgrade to whatever version you want, as long as you have saved SHSH blobs for that version.  You’ll need the assistance of geohot’s limera1n exploit with tools like redsn0w to get into “pwned DFU mode” and bypass the downgrade restriction.
As you can see, it really is a nuanced landscape so it’s sometimes hard to drive the message home to new jailbreakers.  But the basic rule is the simplest (and it’s better to be safe than sorry!):  If you update to 5.1 you’ll very likely lose your jailbreak, so don’t do it!  Exceptions are noted above.
Now let’s see what Apple unveils today!

Update #1:  First, please read and re-read the above warnings!  With all of that in mind, we realize that some of you non-A5 jailbreakers are itching to get to 5.1, even though there seems to be no compelling new feature there. Because of geohot’s limera1n exploit, those with devices earlier than the iPad2 can test the 5.1 jailbreak waters if they really want to, using redsn0w 0.9.10b6.  Here’s what you need to know:
This is a *tethered* 5.1 jailbreak for non-A5 devices.  You’ll need to use redsn0w to “Just Boot” your device every time it power cycles, otherwise jailbreak apps won’t work (neither will Safari).
If you use ultrasn0w for your carrier unlock, be sure to use a custom IPSW to get to 5.1 first!  Don’t ever restore to a stock Apple IPSW!  Use redsn0w’s “Custom IPSW” button to create a NO_BB_* version of the 5.1 IPSW and restore to that instead of the stock one.  (That option is available only to 3GS and iPhone4-GSM owners.)  ultrasn0w itself will be updated for 5.1 in the next few days (same baseband support, not 5.1’s baseband).
If you’re lucky enough to have an old-bootrom 3GS, this jailbreak is actually untethered (redsn0w will figure that part out automatically).
While we were at it, we added @pod2g’s steaks4uce exploit to support MC models of the iPod touch 2G (whose last firmware was 4.2.1).  So now redsn0w will auto-detect and jailbreak both MB and MC versions of that older device.
iBooks won’t work until a future update of redsn0w

Update #1b: The OS X version of redsn0w has been updated to fix an issue for those running OS X 10.5.x or earlier.

Update #2: Version 0.9.10b7 of redsn0w adds a collection of useful features:  It finally implements the corona-A5 jailbreak for iPhone4S and iPad2 devices still at 5.0.1.  It can also re-install that jailbreak for those who accidentally uninstalled the untether.  When stitching an IPSW, it can now grab your blobs directly from Cydia.   It now shows a lot more info about your device (for instance, whether your iPhone3G has the vulnerable baseband boot loader, or whether your iPhone3GS has the old exploitable bootrom.   (And the next new feature to be added will be built-in restore support, to provide an alternative to iTunes restores.)

Update #3: redsn0w 0.9.10b8 adds the ability to backup arbitrary directories or files from your device into a zip file on your Mac or PC.  The new button is Extras->Even More->Backup and it requires your device to be jailbroken with the afc2 service enabled (most jailbreaks include that).  By default it will backup your activation records from /var/root/Library/Lockdown, which is useful for everyone taking advantage of today’s SAM unlock using Loktar_Sun’s trick (more on that in a later post!).

Update #3b: The 0.9.10b8b update to redsn0w makes the zip files more compatible with the native Windows explorer (which doesn’t like leading slashes in the filenames).
Here are the redns0w download links:
redsn0w 0.9.10b8b for OS X
redsn0w 0.9.10b8b for Windows (be sure to run in Administrator mode)

Thursday, April 26, 2012

Hacker Pod2G Is Nearing Completion Of The iOS 5.0/iOS 5.0.1 Untethered Jailbreak


Hacker Pod2G seems to be doing a great job at updating the Jailbreaking community with his progress of the iOS 5.0/iOS 5.0.1 Untethered Userland Jailbreak. Today he has written yet anotherblog post with a progress update on his Untethered Jailbreak.
To summarize his blog post Pod2G has managed to test his Untethered Jailbreak on the first generation iPad (it worked) and today his goal was to test it on the iPhone 3GS. He has mentioned that he does not plan to let the public test his Untethered Userland Jailbreak for fear of a leak, likeComex’s last Userland Jailbreak. Pod2G’s upcoming tasks include finalizing the Jailbreak for older iDevices, fixing some stability issues and then packaging it for public distribution. On top of everything that Pod2G is currently working on, he will also be researching whether or not he can port his Untethered Userland Jailbreak to the iPad 2 and iPhone 4S.
This is some exciting news from Pod2G, and if all goes as planned we can expect the UntetheredUserland Jailbreak to be released within the next week or so. We will keep you updated on the progress of Pod2G’s Untethered Userland Jailbreak. 

An Update On The iPhone 4S Untethered Userland Jailbreak From Hacker Pod2G

With millions of iPhone 4S’ sold around the world, this leaves a large majority of iPhone 4S users longing for a Jailbreak. Right now the only person that we know has made progress on Jailbreaking the iPhone 4S is hacker Pod2G. In fact, he has done more than look into an iPhone 4S Jailbreak, he has created an iOS 5.0/iOS 5.0.1 Untethered Userland Jailbreak for the iPhoneiPod Touch and iPad that he is going to be releasing to the public within the coming weeks.
iPhone 4S and iPad 2G Untethered Jailbreak
few days ago we told you that hacker Pod2G purchased an iPhone 4S for testing the UntetheredUserland Jailbreak on. Now, Pod2G has updated his blog to provide a status update on how his progress of porting his Untethered Userland Jailbreak to the iPhone 4S is going.
The untether fails right now because I’m having processor cache issues.
I’m close, but I can’t figure out what happens. It certainly has something to do with the Cortex-A9 cache management.
I could sort it out quick, it’s a matter of chance.
I’ll report you my progress tomorrow.
By the sounds of it Pod2G has made some good progress on Jailbreaking the iPhone 4S. Thus, I know I am not the only one hoping the Pod2G brings us good news tomorrow when he updates us on how things are going. As always, we will keep you updated when new information becomes available. In the mean time please stay tuned to iJailbreak.com and leave any questions or thoughts in the comments section below…
UPDATE #1: Pod2G has fixed these issues and has had the help of Saurik to essentially finish theiPhone 4S Untethered Jailbreak. Click here to find out more!

iPhone 4S 5.0.1 untethered BY POD2G

My friend @DHowett made a video of an untethered 4S iPhone 4,1 running iOS 5.0.1 some days ago.

@DHowett is a famous iOS developer and a member of the Chronic Dev Team.

Only a few to wait now.

iPhone 4S and iPad 2 untether to be released real soon


iPhone 4S and iPad 2 untether to be released real soon

Hello dear readers,

I know the wait was long, too much long, but it's about to end! You'd be able to free your iPhone in some hours.

A tool named Absinthe and developped by the Chronic Dev Team will install the untether on your device. Also the iPhone Dev Team will release a CLI (command line) tool to help diagnose issues and repair things if it goes wrong.

This is a little scary I know, but the chance you break something is really small, since we made lots of tests to verify the process on different devices. But it is the first time we use the backup / restore functions of iTunes to install software, and there are maybe things we are not aware of.

As you already know, different security researchers put a lot of energy to work out the different issues we had to install the untether on new devices.

Thus, a unified PayPal account was opened so that everyone who worked on the A5 exploits will receive a fair split of your contributions. Here is the link : contribute
As usual, contributions are not needed but are appreciated by developpers. By the way, thank you very much again for everyone who already participated. This is real nice.

Here is the complete list of Absinthe supported devices :
  • iPhone 4S running iOS 5.0, 5.0.1 (9A405 and 9A406)
  • iPad 2 Wifi/GSM/CDMA running iOS 5.0.1
Also, here is MuscleNerd's which explains the whole story in a really precise way: iPhone Dev Team blog post

iPad 2 5.0.1 untethered


iPad 2 5.0.1 untethered

No more to say !

IMPORTANT LINKS FOR IOS: Absinthe update


Absinthe (iPhone 4S and iPad 2 untether installer) is out

The greenpois0n blog is under heavy load... because it's indeed out !

Here is the download link of Chronic Dev Team's Absinthe : Absinthe MacOSX (>=10.6) v0.1.2-1

Happy Cydia !


Absinthe update 0.1.2-2

Chronic Dev Team has released a new build that'll point the web clip to greenpois0n.com instead of the absinthe dedicated page.

This will handle better the workload.

Here is the modified build link : Absinthe MacOSX (>=10.6) v0.1.2-2


Absinthe v0.3

Chronic Dev Team has released a new version of the A5 jailbreak tool Absinthe.

Don't reapply if your 5.0.x device is already jailbroken as it won't change anything.

The untether payload is exactly the same, only the computer part has been improved for stability issues.

Here are the links:
Absinthe Windows v0.3
Absinthe MacOSX (>=10.6) v0.3
Absinthe Linux v0.3

A working GNU Debugger on iOS >= 4.3


A working GNU Debugger on iOS >= 4.3

People know that the gdb package coming from Cydia is broken since 4.3.

But here is a simple way to have a working gdb running on your iOS device : use the one from the Apple SDK !

Prerequisites :
- a jailbroken iOS >= 4.3 device
- OpenSSH should be installed on the iOS device and should listen for connections
- an OSX machine with the iOS SDK >= 4.3 installed

How to :
- remove the gdb package from Cydia
- do the following in the OSX terminal :

cd /tmp
cp /Developer/Platforms/iPhoneOS.platform/Developer/usr/libexec/gdb/gdb-arm-apple-darwin .
lipo -thin armv7 gdb-arm-apple-darwin -output gdb
nano entitlements.xml

- paste the following to the OSX terminal :

        com.apple.springboard.debugapplications
       
        get-task-allow
       
        task_for_pid-allow
       

- save the file by doing CTRL + X, then 'Y', then 'ENTER'

- now do the following in the OSX terminal :

ldid -Sentitlements.xml gdb
scp gdb root@:/usr/bin/

- GDB is now installed to your iOS device.

Happy debugging !

IDC script to help reverse iOS 5 binaries with IDA < 6.2


IDC script to help reverse iOS 5 binaries with IDA < 6.2


Apple is not standing still and in iOS 5 the default compiler is LLVM instead of GCC. It produces somewhat different code and IDA < 6.2 fail to resolve references which are now relative to PC.

I wrote a little IDC script to resolve those refs (I don't know if another solution exists...). Feel free to use it and modify it to your needs.

It's on github.


Here is an example of code dissasembled with IDA :

__text:00001000 MOV R4, 0x12344
__text:00001008 ADD R4, PC

After executing this IDC script :

__text:00001000 MOV R4, 0x12344
__text:00001008 ADD R4, PC ; off_13350

(if the address is named, the name will appear instead of off_xxx)

The xref is also added so that when you type X on address 0x13350 you'll see where it is used.

Hope it could help.