Home User CP Donate Chat Register Today!  
  Get New posts Faq / Help?
   


Go Back   Hackint0sh > Projects and Hacks > iPhone > iPhone "2G" (Rev. 1) > PwnageTool

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-22-2008, 08:56 AM
outofbreath
Status: Offline
Member
 
Join Date: Oct 2007
Posts: 46
Rep Power: 0
outofbreath is on a distinguished road
Default [Pwnage 2.0] Unpwnd iphone upgraded with pwnage ipsw firmware. WORKS !!!

Can someone explain why this works ????

I used Pwnage 2.0 to gernerate a firmware image. I selected that my iphone was never pwnd and that I am not a legit at&t user.

After the image was created the pwnagetool exited with "unable to enter DFU mode"

Since I did not know how to enter dfu mode i started itunes 7.7 and did an option-restore with the pwnd firmware image.

This Worked !!! After the restore bootneuter came up automatically.

I am sure my phone was not pre-pwnd. However, it was only 1.1.4 ipsf unlocked and Jailbroken.

I did this on a second phone.

Why does this work ??? and can I basically always use this image ???

Summary: It Appears that it is possible to shift/option-restore 1.1.4 (or earlier ?) iphones to a customized pwnd firmware with Itunes 7.7 witout the need to have the phone pre-pwnd. This should be a relatively easy path for windows users who cannot use pwnagetool 2.0 yet, if the can get their hands on a customized firmware.
XianLi gave a possible explanation: Itunes 7.7 may put the iphone in DFU instead of the "normal" restore mode when doing a restore. The Dev team already stated that it is possible to install a custom firmware on an unpwnd phone using DFU mode.
speedy523 For the sake of science. Refreshed his phone to a stock 1.1.4 jailbroke with ziphone and confirmed this upgrade path
n350z Tried doing this with a freshly installed official 2.0 firmware and it worked
Calvin Reports that Pawnage 2.0 and winpwn modyfy a file called "x12220000_4_Recovery.ipsw" in your "iTunes\Device support" that puts the iphone in dfu mode when doing a shift/option restore. This means that the reported behaviour happens only after winpwn or Pwnage 2.0 is installed & run at least once. He uploaded some links that do this without the neccessity to install pwnage or winpawn:
For Windows: http://www.megaupload.com/de/?d=FYNAHT86
For Mac: http://belgium-iphone.com/plus/DFU%2...e.com.mpkg.zip

I have not tested these files, so use at your own risk.

Last edited by outofbreath; 07-29-2008 at 07:56 PM. Reason: added a short summary
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 07-22-2008, 09:00 AM
vboyz
Status: Offline
Junior Member
 
Join Date: Oct 2007
Posts: 18
Rep Power: 0
vboyz is on a distinguished road
Default

Same here uing winpwn, open 1.1.4 then ipwner, after it done ur phone still in recovery mode right now open itune 7.7 then restore with shift key select custom image of 2.0 work fine. Done three phones no problem. save alot of time. just one time restore.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 07-22-2008, 09:03 AM
Former Bender's Avatar
Former Bender
Status: Offline
Guest
 
Join Date: Nov 1970
Posts: 3,501
Rep Power: 0
Former Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud of
Default

You've got the error message that it couldn't turn into DFU mode but in fact it did and your phone got pwned.
(if not that means it has been pwned before on 1.1.4)
You can't install a custom firmware without pwning your phone as ipsw are signed and iTunes will refuse to install them.

Restore it to original 2.0 and try to restore the custom image if you want to make sure. Obviously it won't work
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #4 (permalink)  
Old 07-22-2008, 09:07 AM
outofbreath
Status: Offline
Member
 
Join Date: Oct 2007
Posts: 46
Rep Power: 0
outofbreath is on a distinguished road
Default

Quote:
Originally Posted by XianLi View Post
You've got the error message that it couldn't turn into DFU mode but in fact it did and your phone got pwned.
I can understand that that would work for the first phone.... But why did it work for the second Phone ??? I am sure pwnagetool was never involved. I just restored a jailbroken iphone with the customized firmware image from pwnagetool.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5 (permalink)  
Old 07-22-2008, 09:11 AM
Former Bender's Avatar
Former Bender
Status: Offline
Guest
 
Join Date: Nov 1970
Posts: 3,501
Rep Power: 0
Former Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud of
Default

Ok, let me repeat it again.

You can't restore a custom ipsw image on an iPhone or iTouch that hasn't been pwned.

If you don't trust me try this:

Restore your phone with an original ipsw from Apple and try to restore the custom one after.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6 (permalink)  
Old 07-22-2008, 09:19 AM
abrasBR's Avatar
abrasBR
Status: Offline
Senior Member
 
Join Date: Sep 2007
Location: Belo Horizonte, Brasil
Posts: 502
Rep Power: 29
abrasBR is on a distinguished road
Default

Quote:
Originally Posted by XianLi View Post
Ok, let me repeat it again.

You can't restore a custom ipsw image on an iPhone or iTouch that hasn't been pwned.

If you don't trust me try this:

Restore your phone with an original ipsw from Apple and try to restore the custom one after.
Well XianLi. I think you are wrong.

My phone was pwned, but i restored it in DFU mode to Original 1.1.4 just to make sure I'd have a clean phone.
Then created a Custom 2.0 using PWNAGE 2.0.1 (selected tha my phone wasnt pwned) and restored it in DFU mode to 2.0. It worked flawlessly, and i didnt have to pwn my phone after the 1.1.4 restore. Just restoring it to pwned 2.0 did it.

The thing is,("thats what i think, not so sure") the new exploit found by Dev Team let us run anything without apple permission while in DFU mode
So thats why pwned 1.1.4fw doesnt work if you only try to restore it, but pwned2.0WORKS.
Besides that, there is a lot of people with iliberty jailbreaked 1.1.4 phones just downloading custom 2.0 and restoring with itunes, without pwning.

Abras
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #7 (permalink)  
Old 07-22-2008, 09:27 AM
Former Bender's Avatar
Former Bender
Status: Offline
Guest
 
Join Date: Nov 1970
Posts: 3,501
Rep Power: 0
Former Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud ofFormer Bender has much to be proud of
Default

Windows users who are downloading the custom ipsw need to pwn their 1.1.4 phone once with WinPwn before being able to restore the custom ipsw.

The DevTeam doesn't have the Apple private key to be able to create/sign "legit" ipsw.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8 (permalink)  
Old 07-22-2008, 09:39 AM
outofbreath
Status: Offline
Member
 
Join Date: Oct 2007
Posts: 46
Rep Power: 0
outofbreath is on a distinguished road
Default

Well this may be not neccesary, because I had a 1.1.4 Jailbroken phone that has never been pwnd. And was never connected while pwnagetool has been running. I am not making this up !!!
Why would this work ???
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9 (permalink)  
Old 07-22-2008, 10:04 AM
spaceman81
Status: Offline
Member
 
Join Date: Oct 2007
Posts: 77
Rep Power: 6
spaceman81 is on a distinguished road
Default

"Update 5: If DFU restores are giving you trouble, another route to pwned 2.0 for 1G owners is to use our first pwnage at 1.1.4. Once you are pwned there, you can do a normal recovery-mode restore to your custom 2.0 ipsw. BTW the iPhone does *not* need to be pre-pwned to be able to DFU-restore into a pwned ipsw — it needs to be pre-pwned only for normal recovery-mode restores of custom ipsw’s."

This is from the dev team's blog. From what is stated, I think he means that if you have trouble getting the iPhone into DFU mode, then you use the old pwnage to pwn the iPhone so that you may use the recovery mode to restore the new 2.0. But, if you do not have any problem getting into DFU, you can proceed to restore the new custom 2.0 in DFU mode and it will be activated and unlocked (for 1st gen phones).

It would be good if someone can clarify this with any member of the dev team.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Sponsored links Remove advertisements
Advertisement
Advertisement

  #10 (permalink)  
Old 07-22-2008, 10:13 AM
wlp5
Status: Offline
Senior Member
 
Join Date: Sep 2007
Posts: 253
Rep Power: 16
wlp5 is on a distinguished road
Default

Yeah, XianLi is wrong on this one, I've been hearing about this everywhere and devteam has in on their blog. If you enter DFU, you can use a custom firmware without ever pwning.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +2. The time now is 06:32 AM.



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.2 Ad Management by RedTyger
follow us on Twitter!

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448