Page 1 of 2 12 LastLast
Results 1 to 10 of 19
Discuss George Hotz: 5.8 Exploit at the iPhone 3G - Hackint0sh.org; I've been off the iPhone scene for a while. A couple days ago, I got ...
  1. #1
    Rookie Array

    Join Date
    Apr 2008
    Posts
    29
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default George Hotz: 5.8 Exploit

    I've been off the iPhone scene for a while. A couple days ago, I got an e-mail from Chronic asking for help with the new asr. I helped out with genpass, and started reading through theiphonewiki again. Thanks so much for all the information contributed so far; it prompted me to find this.

    In bootloader 5.8 on the 3G, the loader signature validator is broken. Someone botched an if statement checking the location and length of the loader in the cert. Because of this, you can pass the run cert for the firmware you currently have on the phone instead of the loader cert, and send whatever you want as a loader.

    Here is a bspatch file to be applied to ICE2_02.28.00.fls allowing downgrades from 2.30.03 using BBUpdaterExtreme. By replacing the patched cert with your current run cert, you can downgrade from any other version.

    Unfortunately, most 3G's out there are bootloader 5.9 I was hoping, since RSA was added to the bootrom, that it would run the vulnerable ramstrapper, but I had no luck, although I didn't try that hard. I see no reason why it shouldn't work theoretically; the bootrom RSA is complicated, maybe when I finish EDA...

    And dev, since you're into hashes
    882B7B3E84B76125755A84FB0BE52B9D8E25284D

    From gehotz blog



  2. #2
    Speedy Administrator Array n350z's Avatar

    Join Date
    Nov 2007
    Location
    United Kingdom
    Posts
    3,021
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    10

    Default

    Nice to see gehotz posting on this blog again
    -
    Read the stickies and search the forum before posting!
    Did we solve your problem? +1 us above
    If you want to become a Hackint0sh supporter click here
    ----------
    Follow Hackint0sh Follow Me

  3. #3
    Professional Array doblezeta's Avatar

    Join Date
    Dec 2007
    Posts
    50
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    9

    Default

    Has anyone made this work? Meaning 2.30 downgrade to 2.28 baseband on a BootLoader 5.8 iPhone 3G?

    Weird, I would think that this news is pretty big, but no one here in hackint0sh seems to mind it?

    Anyone have additional instructions on how to apply the patch to the 2.28 BB files?

    Geohot=!CaptainObvious

  4. #4
    Rookie Array

    Join Date
    Sep 2007
    Location
    Germany Mainz
    Posts
    24
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    hey,

    i want to find out my BL version. Right now iam stood at the mobile-terminal.

    when i shut down the comcenter nothing happened...
    Ipod classic 80GIG (US-Version)
    Iphone 8 GB FW: 1.0.2 (US-Version)
    Samsung BIG LCD-TV ;-)

  5. #5
    drg
    drg is offline
    Senior Professional Array

    Join Date
    Oct 2007
    Location
    Canada
    Posts
    479
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    34

    Default

    PHaseBanDowngrader - The iPhone Wiki

    Have not tried this, but it's based on geohot's exploit.


  6. #6
    Senior Professional Array

    Join Date
    Dec 2007
    Posts
    143
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    14

    Default

    my phone is already on 2.28.0 i just want to check what bootloader do i have.
    i have already downloaded bbupdaterextreme but where do i put it cuz i dont have var/root i have private/var/root.
    iPhone 4 iOS 4.2.1
    Jailbroken and unlocked
    My website:
    -websites removed, does not comply with site rules related to signatures: see http://www.hackint0sh.org/f18/69493.htm for more details-
    Call In/Out - Yes/Yes
    SMS In/Out - Yes/Yes
    EDGE/WIFI - Yes/Yes
    YouTube - Yes
    Jailbreak-Yes

  7. #7
    Respected Professional Array

    Join Date
    Sep 2007
    Posts
    575
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    36

    Default

    will it work with 6.02 bootloader?
    didnt hear anything about this one yet.

    thanks

  8. #8
    Senior Professional Array DeCode's Avatar

    Join Date
    Oct 2007
    Location
    Greenhills,Ph
    Posts
    126
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    13

    Default

    Quote Originally Posted by drg View Post
    PHaseBanDowngrader - The iPhone Wiki

    Have not tried this, but it's based on geohot's exploit.
    I tried but sad to say my baseband stays at 2.30.03 after reboot weird

  9. #9
    Senior Professional Array

    Join Date
    Sep 2007
    Posts
    436
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    He says if we replace the cert with the firmware we are on we can send anything for the loader does that mean we can also downgrade the baseband from 3.0 if we have its cert? This could help all early adoptors with bl 5.8 (including me) to unlock their phones.

    Can anyone put the 3.0 beta cert here or a patch which we can use with the above exploit to downgrade the baseband to 2.28?
    Search before you post

    Alienware M15x

    iPhone 3GS 32Gb

  10. #10
    Senior Professional Array

    Join Date
    Dec 2007
    Posts
    143
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    14

    Default

    sorry guys i said before that there was no bootloader 6.02 but i was wrong since my iphone has 6.02.
    here is a pic,
    Last edited by ggonxhi; 04-13-2009 at 06:24 PM.
    iPhone 4 iOS 4.2.1
    Jailbroken and unlocked
    My website:
    -websites removed, does not comply with site rules related to signatures: see http://www.hackint0sh.org/f18/69493.htm for more details-
    Call In/Out - Yes/Yes
    SMS In/Out - Yes/Yes
    EDGE/WIFI - Yes/Yes
    YouTube - Yes
    Jailbreak-Yes


 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Replies: 27
    Last Post: 06-16-2008, 01:15 PM
  2. 1.1.3 OTB George Hotz unlock help!
    By skyline_2k7 in forum iPhone "2G" (Rev. 1)
    Replies: 4
    Last Post: 02-09-2008, 07:41 AM
  3. Replies: 1
    Last Post: 08-28-2007, 09:48 PM
  4. Thanks Georges Hotz !
    By SEB152030 in forum General
    Replies: 3
    Last Post: 08-26-2007, 05:42 AM
  5. George Hotz full unlocking instructions
    By sweetcaro333 in forum General
    Replies: 2
    Last Post: 08-24-2007, 10:52 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Powered by vBulletin®
Copyright © 2014 vBulletin Solutions, Inc. All rights reserved.
Search Engine Friendly URLs by vBSEO
(c) 2006-2012 Hackint0sh.org
All times are GMT +2. The time now is 10:05 AM.
twitter, follow us!