Just to be clear, I did not discover this exploit. I'm just the one trying to exploit it on the iphone.
Most of you will remember me from my work on the orginal Tif exploit for the PSP 2.0 and my Linux ports to sidekick2/msntv2.
Status Update
What we know so far.
- The stack is NX ( non executable )
The heap is executable (via the toolchain)
This will provide a way to activate and jailbreak.
Should work on the Touch
We managed to put code on the heap and have the tif jump to it. It still had issues executing it, So its possible Safari sets some bit on start that makes the heap NX.
There are a few other methods that we are currently working and i wanted to post so people didn't give up hope.
I will post my progress on my site
http://www.toc2rta.com and on this forum.
Please be sure to support both Toc2rta and the Dev Team.
Thanks to the following people for their help so far
Dinopio / Erica / Pumpkin / Natetrue