Results 1 to 4 of 4
Discuss Spoof the host to install custom DMG restore ? at the General - Hackint0sh.org; I know we haven't cracked the entire .DMG image files yet, but for the ones ...
  1. #1
    Rookie Array

    Join Date
    Jul 2007
    Posts
    23
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Talking Spoof the host to install custom DMG restore ?

    I know we haven't cracked the entire .DMG image files yet, but for the ones we did crack, can't we just modify the /etc/hosts file so that :

    http://appldnld.apple.com.edgesuite....a_Restore.ipsw

    Points to:

    LOCALHOST:YourFolder/iPhone1,1_1.0_1A543a_Restore.ipsw

    Then click restore in iTunes and it will think it's getting the modified restore.ipsw file from Apple's server's when really it's getting it from the local copy on our computer? I know we can't make tons of changes until we crack the final DMG, but wouldn't this give us a chance to at least customize it a little bit?

    Then at least we copy into ramdisk > System > Library > Extensions:
    Other frameworks besides the current "IOUSBDeviceFamily.kext"


    Such as the frameworks in real Mac OS X for bluetooth, and several other things. I know that from the NSA securing Mac OS X guide, this is how they would disable USB, and bluetooth on Mac laptops by removing these .kext files for them. So logically if we copied them back into there wouldn't they work?

    I mean worse case scenario we have to go into iTunes remove the /etc/hosts modification and hit restore to "fix" the phone back to normal

    Am I way off base here? The only problem I can see is the ARM processors is not really an Intel x86 chip correct so it's probably special kernel extensions?

    On my Mac OS X (MacBook Pro) in the same directory I have ( 19 ones related to bluetooth:


    Code:
    /System/Library/Extensions/IOBluetoothFamily.kext/Contents/PlugIns/IOBluetoothA2DPAudioDriver.kext/Contents/MacOS/IOBluetoothA2DPAudioDriver
    
    /System/Library/Extensions/IOBluetoothFamily.kext/Contents/PlugIns/IOBluetoothA2DPAudioDriver.kext
    
    /System/Library/Extensions/IOBluetoothFamily.kext/Contents/PlugIns/IOBluetoothSCOAudioDriver.kext/Contents/MacOS/IOBluetoothSCOAudioDriver
    
    /System/Library/Extensions/IOBluetoothFamily.kext
    
    /System/Library/Extensions/IOBluetoothFamily.kext/Contents/MacOS/IOBluetoothFamily
    /System/Library/Extensions/IOBluetoothFamily.kext/Contents/PlugIns/IOBluetoothSerialManager.kext/Contents/MacOS/IOBluetoothSerialManager
    
    /System/Library/Extensions/IOBluetoothFamily.kext/Contents/PlugIns/IOBluetoothSerialManager.kext

    Or does the RAM disk portion just load USB ktext file first for USB charging, and then later load up any other kernel extensions for the iPhone?

    Seems like with the Leopard Bluetooth extensions above placed into the RAMdisk and put back into the DMG file we could fool the iPhone into offering full bluetooth filebrowing.

    Any thoughts?



  2. #2
    Newbie Array

    Join Date
    Aug 2006
    Posts
    7
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    20 mins ago on irc:
    <Omikron> The encrypted 39.dmg image was recently cracked, and the contents of the system files have been dumped. The files are currently being explored for additional information and possible attack vectors.

  3. #3
    Rookie Array

    Join Date
    Mar 2007
    Posts
    27
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    The kext's would need to be recompiled to work with ARM

  4. #4
    Rookie Array

    Join Date
    Jul 2007
    Posts
    23
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    woah, where are the new files? cool, so I can modify graphics at the very least and upload them correct?

    Quote Originally Posted by Virtualball View Post
    The kext's would need to be recompiled to work with ARM

 

 

Similar Threads

  1. Can't restore to custom IPSW
    By anmh in forum iOS 4.x (iPhone OS 4.x)
    Replies: 2
    Last Post: 03-28-2011, 12:56 AM
  2. Is there a way to install Snow leopard on a ESX(vmware) host?
    By dclinton02126 in forum Installation
    Replies: 0
    Last Post: 03-31-2010, 03:20 PM
  3. Trying a custom FW 3.1 restore(win xp)
    By spitphire in forum iOS 3.x (iPhone OS 3.x)
    Replies: 14
    Last Post: 09-17-2009, 07:24 PM
  4. Replies: 0
    Last Post: 07-22-2008, 03:48 PM
  5. [PWNAGE + Custom 1.1.4] DFU restore custom firmware
    By nathulal in forum PwnageTool
    Replies: 1
    Last Post: 04-15-2008, 03:38 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Powered by vBulletin®
Copyright © 2014 vBulletin Solutions, Inc. All rights reserved.
Search Engine Friendly URLs by vBSEO
(c) 2006-2012 Hackint0sh.org
All times are GMT +2. The time now is 02:26 AM.
twitter, follow us!