Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > Projects and Hacks > iPhone > iPhone "2G" (Rev. 1) > Older Software Unlock Solution

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-12-2007, 08:27 PM
n000b's Avatar
n000b
Status: Offline
Senior Member
 
Join Date: Mar 2007
Posts: 117
Rep Power: 12
n000b will become famous soon enough
Smile Here comes an experimental 1.1.2 lockdownd patch

I've made a patch for 1.1.2 lockdownd so you don't have to use the old 1.1.1 patch. This patch will put the 1.1.2 into factory activated state. If you have a SuperSim or TurboSIM, you may use it immediately after the patch.

The patched lockdownd may be downloaded from:

/*removed due to copyright */
(remove the underscores)

UPDATE:
1. I did an experiment to try the 1.1.2's brickmode, I forced my activated phone (with SilverCard in) to execute the code block at 0x5B28, syslog showed the following:
Code:
localhost lockdown[21]: lookup_baseband_info: Not the expected firmware version. Enabling brick mode
localhost lockdown[21]: Enabling brick mode on the baseband
then the phone lost signal, reboot didn't not solve it, have to do a firmware restore to return the phone to normal (the syslog said 'brick mode on the baseband', but after restore and activation, my SilverCard worked again), so I think elite team's patch at 0x4B3B is needed.

2. I've modified my patch accordingly in a slightly different manner, allows the info being logged in syslog, but skip the other opeartions.

Here's the revised patch:
Code:
Search for differences

1. G:\iPhone Stuffs\lockdownd\lockdownd_112_original\lockdownd: 996,440 bytes
2. G:\iPhone Stuffs\lockdownd\lockdownd_112_patched\lockdownd: 996,440 bytes
Offsets: hexadec.

 4B4C:	01	14
 4B4E:	A0	00
 4B4F:	E3	EA
 C5C1:	00	40
 C5C2:	54	A0
 C5C8:	04	00
 C5CA:	00	A0
 C5CB:	1A	E1
 C5CC:	01	00
 C5D4:	88	EC

10 difference(s) found.
I use it on my 1.1.2 (upgraded from 1.0.2), and it activates the phone immediately without problem, my SilverCard (16F877+24C64) works as well.

EDIT: my first try was not successful because the SilverCard didn't work. I think I might messed some system files, so I did a restore and retried, this time the SilverCard works perfectly, call in/out, sms in/out, grps all work, youtube only shows list, can't play (I'm in a country the ip is forbidden by youtube).

Last edited by n000b; 11-14-2007 at 05:47 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 11-12-2007, 09:38 PM
brasuco
Status: Offline
Senior Member
 
Join Date: Aug 2007
Posts: 312
Rep Power: 20
brasuco is on a distinguished road
Default

Quote:
Originally Posted by n000b View Post
I've made a patch for 1.1.2 lockdownd so you don't have to use the old 1.1.1 patch.

The patched lockdownd may be downloaded from:

/*removed due to copyright */
(remove the underscores)

Here's what was patched:
Code:
FileOfs    Original    Patched
C5C1:	  00	    40
C5C2:	  54	    A0
C5C8:	  04	    00
C5CA:	  00	    A0
C5CB:	  1A	    E1
C5CC:	  01	    00
C5D4:	  88	    EC
I use it on my 1.1.2 (upgraded from 1.0.2), and while it activates the phone immediately without problem, my SilverCard (16F877+24C64) still doesn't work. I'm still not sure if this is caused by the new modem or if I missed any point in the patching.
Are you sure about this? I've been looking into that and my findings are a little different.

Besides, there's something wrong about the opcodes you've provided for the original/virgin lockdownd. They don't match the ones from binary that comes with the 1.1.2 restore image.

Cheers.
__________________
brasuco
A Brazilian fellow that likes iPhone stuff.
email: brasucocarnaval@gmail.com

Last edited by sam; 11-14-2007 at 03:06 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 11-13-2007, 02:43 AM
n000b's Avatar
n000b
Status: Offline
Senior Member
 
Join Date: Mar 2007
Posts: 117
Rep Power: 12
n000b will become famous soon enough
Default

Quote:
Originally Posted by brasuco View Post
Are you sure about this? I've been looking into that and my findings are a little different.

Besides, there's something wrong about the opcodes you've provided for the original/virgin lockdownd. They don't match the ones from binary that comes with the 1.1.2 restore image.

Cheers.
I don't think the opcodes were wrong, although I fetched the lockdownd from a restored phone, not from the restore image directly. Please check the following snippets:

Before the patch:
Code:
__text:0000D5A8 B0 26 9F E5                 LDR     R2, =off_EE99C
__text:0000D5AC 06 00 A0 E1                 MOV     R0, R6
__text:0000D5B0 00 10 A0 E3                 MOV     R1, #0
__text:0000D5B4 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5B8 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5BC 01 E5 FF EB                 BL      sub_69C8
__text:0000D5C0 00 00 54 E3                 CMP     R4, #0
__text:0000D5C4 00 80 A0 E1                 MOV     R8, R0
__text:0000D5C8 04 00 00 1A                 BNE     loc_D5E0
__text:0000D5CC 01 30 A0 E3                 MOV     R3, #1
__text:0000D5D0 08 30 8D E5                 STR     R3, [SP,#0x2C+var_24]
__text:0000D5D4 88 36 9F E5                 LDR     R3, =unk_EFBE0
__text:0000D5D8 18 00 8D E8                 STMEA   SP, {R3,R4}
__text:0000D5DC CA 00 00 EA                 B       loc_D90C
After the patch:
Code:
__text:0000D5A8 B0 26 9F E5                 LDR     R2, =off_EE99C
__text:0000D5AC 06 00 A0 E1                 MOV     R0, R6
__text:0000D5B0 00 10 A0 E3                 MOV     R1, #0
__text:0000D5B4 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5B8 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5BC 01 E5 FF EB                 BL      sub_69C8
__text:0000D5C0 00 40 A0 E3                 MOV     R4, #0
__text:0000D5C4 00 80 A0 E1                 MOV     R8, R0
__text:0000D5C8 00 00 A0 E1                 NOP
__text:0000D5CC 00 30 A0 E3                 MOV     R3, #0
__text:0000D5D0 08 30 8D E5                 STR     R3, [SP,#0x2C+var_24]
__text:0000D5D4 EC 36 9F E5                 LDR     R3, =unk_EFC50
__text:0000D5D8 18 00 8D E8                 STMEA   SP, {R3,R4}
__text:0000D5DC CA 00 00 EA                 B       loc_D90C
WinHex's file compare result:
Code:
Search for differences

1. C:\iPhone\lockdownd\lockdownd_112_original\lockdownd: 996,440 bytes
2. C:\iPhone\lockdownd\lockdownd_112_patched\lockdownd: 996,440 bytes
Offsets: hexadec.

 C5C1:	00	40
 C5C2:	54	A0
 C5C8:	04	00
 C5CA:	00	A0
 C5CB:	1A	E1
 C5CC:	01	00
 C5D4:	88	EC

7 difference(s) found.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #4 (permalink)  
Old 11-13-2007, 03:09 AM
brasuco
Status: Offline
Senior Member
 
Join Date: Aug 2007
Posts: 312
Rep Power: 20
brasuco is on a distinguished road
Default

Quote:
Originally Posted by n000b View Post
I don't think the opcodes were wrong, although I fetched the lockdownd from a restored phone, not from the restore image directly. Please check the following snippets:

Before the patch:
Code:
__text:0000D5A8 B0 26 9F E5                 LDR     R2, =off_EE99C
__text:0000D5AC 06 00 A0 E1                 MOV     R0, R6
__text:0000D5B0 00 10 A0 E3                 MOV     R1, #0
__text:0000D5B4 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5B8 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5BC 01 E5 FF EB                 BL      sub_69C8
__text:0000D5C0 00 00 54 E3                 CMP     R4, #0
__text:0000D5C4 00 80 A0 E1                 MOV     R8, R0
__text:0000D5C8 04 00 00 1A                 BNE     loc_D5E0
__text:0000D5CC 01 30 A0 E3                 MOV     R3, #1
__text:0000D5D0 08 30 8D E5                 STR     R3, [SP,#0x2C+var_24]
__text:0000D5D4 88 36 9F E5                 LDR     R3, =unk_EFBE0
__text:0000D5D8 18 00 8D E8                 STMEA   SP, {R3,R4}
__text:0000D5DC CA 00 00 EA                 B       loc_D90C
After the patch:
Code:
__text:0000D5A8 B0 26 9F E5                 LDR     R2, =off_EE99C
__text:0000D5AC 06 00 A0 E1                 MOV     R0, R6
__text:0000D5B0 00 10 A0 E3                 MOV     R1, #0
__text:0000D5B4 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5B8 00 20 92 E5                 LDR     R2, [R2]
__text:0000D5BC 01 E5 FF EB                 BL      sub_69C8
__text:0000D5C0 00 40 A0 E3                 MOV     R4, #0
__text:0000D5C4 00 80 A0 E1                 MOV     R8, R0
__text:0000D5C8 00 00 A0 E1                 NOP
__text:0000D5CC 00 30 A0 E3                 MOV     R3, #0
__text:0000D5D0 08 30 8D E5                 STR     R3, [SP,#0x2C+var_24]
__text:0000D5D4 EC 36 9F E5                 LDR     R3, =unk_EFC50
__text:0000D5D8 18 00 8D E8                 STMEA   SP, {R3,R4}
__text:0000D5DC CA 00 00 EA                 B       loc_D90C
WinHex's file compare result:
Code:
Search for differences

1. C:\iPhone\lockdownd\lockdownd_112_original\lockdownd: 996,440 bytes
2. C:\iPhone\lockdownd\lockdownd_112_patched\lockdownd: 996,440 bytes
Offsets: hexadec.

 C5C1:	00	40
 C5C2:	54	A0
 C5C8:	04	00
 C5CA:	00	A0
 C5CB:	1A	E1
 C5CC:	01	00
 C5D4:	88	EC

7 difference(s) found.
It seems I forgot to subtract 0x1000 from the IDA offset, sorry (I always forget that)!

Now that you posted the code things gotten more clear. We basically have the same thing with a minor difference. As soon as you or me (or someone else) patches it nicely I'll be able to assemble a newer version of CARNAVAL. That's kindda the last thing.

I haven't been able to test my patch yet, as soon as I test it out I'll post it here.

I'll let you know what I find out.

Cheers.
__________________
brasuco
A Brazilian fellow that likes iPhone stuff.
email: brasucocarnaval@gmail.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 11-13-2007, 03:18 AM
n000b's Avatar
n000b
Status: Offline
Senior Member
 
Join Date: Mar 2007
Posts: 117
Rep Power: 12
n000b will become famous soon enough
Default

Quote:
Originally Posted by brasuco View Post
It seems I forgot to subtract 0x1000 from the IDA offset, sorry (I always forget that)!

Now that you posted the code things gotten more clear. We basically have the same thing with a minor difference. As soon as you or me (or someone else) patches it nicely I'll be able to assemble a newer version of CARNAVAL. That's kindda the last thing.

I haven't been able to test my patch yet, as soon as I test it out I'll post it here.

I'll let you know what I find out.

Cheers.
Heh, that 0x1000 thing has got me several times Waiting for yr next unlocking batch, good luck! BTW, what's its name gonna be this time?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 11-13-2007, 05:02 AM
Vger
Status: Offline
Senior Member
 
Join Date: Aug 2007
Location: Ljubljana, SI
Posts: 228
Rep Power: 16
Vger will become famous soon enough
Default

Working excellent here with TurboSIM! Thank you very much!!

Quote:
Originally Posted by n000b View Post
I use it on my 1.1.2 (upgraded from 1.0.2), and while it activates the phone immediately without problem, my SilverCard (16F877+24C64) still doesn't work. I'm still not sure if this is caused by the new modem or if I missed any point in the patching.
Check the iphone-elite Wiki!

Last edited by Vger; 11-13-2007 at 05:05 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #7 (permalink)  
Old 11-13-2007, 05:16 AM
n000b's Avatar
n000b
Status: Offline
Senior Member
 
Join Date: Mar 2007
Posts: 117
Rep Power: 12
n000b will become famous soon enough
Default

Quote:
Originally Posted by Vger View Post
Working excellent here with TurboSIM! Thank you very much!!
Check the iphone-elite Wiki!
Glad it works! Though I don't have a TurboSIM thus can't get that the first hand
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 11-13-2007, 05:19 AM
Vger
Status: Offline
Senior Member
 
Join Date: Aug 2007
Location: Ljubljana, SI
Posts: 228
Rep Power: 16
Vger will become famous soon enough
Default

Since TSIM works, SuperSim should aswell... I think.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 11-13-2007, 05:21 AM
n000b's Avatar
n000b
Status: Offline
Senior Member
 
Join Date: Mar 2007
Posts: 117
Rep Power: 12
n000b will become famous soon enough
Default

I thought so, just weird why my SilverCard not work I'll retry it later.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #10 (permalink)  
Old 11-13-2007, 05:22 AM
Vger
Status: Offline
Senior Member
 
Join Date: Aug 2007
Location: Ljubljana, SI
Posts: 228
Rep Power: 16
Vger will become famous soon enough
Default

Quote:
Originally Posted by n000b View Post
I thought so, just weird why my SilverCard not work I'll retry it later.
What's happening?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 06:23 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448