Page 4 of 8 FirstFirst 12345678 LastLast
Results 31 to 40 of 77
Discuss [Theory] Hacktivate and Unlock your Pwned and Neutered iPhone 2G at the PwnageTool - Hackint0sh.org; Originally Posted by RockfordFosgate So now I'm one step further in decrypting the 5A347 ramdisk. ...
  1. #31
    Rookie Array

    Join Date
    Jul 2008
    Posts
    22
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    Quote Originally Posted by RockfordFosgate View Post
    So now I'm one step further in decrypting the 5A347 ramdisk. Somehow it looks like the given ramdisk size does not match the actual ramdisk size. So after removing the unused parts in the old fashioned way we got some crap left at the end of the stripped .dmg - found this after painful hex editor search.

    Removed the crap - the error message changes. Before I got "not recognized" when I tried to mount the stripped .dmg, now it comes up with "no mountable filesystems" after manually removing the data which appears to be too much.

    Now it's time to find out where the filesystem information has gone - I'm not very familiar with the .dmg format, can anybody give me a hint?

    Greetz
    RF
    Hey RF-sounds like good work getting rid of all the "crap" from the ramdisk-would you mind posting this modified ramdisk up somewhere, like Rapid$hare or something? That would be great, so then we could work on extracting the DMG, patching lockdownd, etc, etc.

    Thanks.


  2. #32
    Senior Professional Array

    Join Date
    Aug 2007
    Posts
    117
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    11

    Default

    Quote Originally Posted by RockfordFosgate View Post
    So now I'm one step further in decrypting the 5A347 ramdisk. Somehow it looks like the given ramdisk size does not match the actual ramdisk size. So after removing the unused parts in the old fashioned way we got some crap left at the end of the stripped .dmg - found this after painful hex editor search.
    Nice job. You are writing that you removed the unused parts. How did you find out the unused parts? I mean how do you know how many bytes to strip? Where did you get this information from? I couldn't find nothing...

  3. #33
    Supporter Array

    Join Date
    Nov 2007
    Posts
    73
    Post Thanks / Like
    Downloads
    1
    Uploads
    0
    Rep Power
    9

    Default

    I found the crap by comparing the images:
    Beta 7 full image to Beta 7 stripped image
    Release full image to release stripped image
    Release full image to Beta 7 full image
    Release stripped image to Beta7 stripped image

    all in Hex editor

    and found that both full images contain some data at the end which is exactely the same. When stripping the Beta 7 image all of the data which is the same in the full image is removed, when stripping the release image some of these bytes remain in the output file.

    Basically you can get to my status by stripping the .dmg with

    dd if=018-3786-2.dmg of=018-3786-2.striped.dmg bs=32 skip=1 count=588544 conv=sync

    where the filesize is already adjusted from 588547 to 588544. But then it's getting tricky. I'm afraid I can't find time today to go on with this, so have fun out there and good luck!

    Greetz
    RF

    Edit: if you find another spelling mistake please feel free to keep it yours.

  4. #34
    Rookie Array

    Join Date
    Dec 2007
    Posts
    12
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default 5a347 Decryption key!

    Looks like member 11111111 has found the decryption key! see: http://hackint0sh.org/forum/showthread.php?t=46218

  5. #35
    Professional Array

    Join Date
    Oct 2007
    Location
    Netherlands
    Posts
    95
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    12

    Default

    It works, looking at the decrypted dmg now


  6. #36
    Supporter Array

    Join Date
    Nov 2007
    Posts
    73
    Post Thanks / Like
    Downloads
    1
    Uploads
    0
    Rep Power
    9

    Default

    Quote Originally Posted by pascalletje View Post
    It works, looking at the decrypted dmg now
    screenshot! encrypted with the old 8900 key please....

  7. #37
    Professional Array

    Join Date
    Oct 2007
    Location
    Netherlands
    Posts
    95
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    12

    Default

    http://img519.imageshack.us/my.php?i...cryptedpd4.jpg

    Is this what you mean? I'm not so familiar with the hacking stuff

  8. #38
    Rookie Array

    Join Date
    Jul 2008
    Posts
    22
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    0

    Default

    Quote Originally Posted by pascalletje View Post
    http://img519.imageshack.us/my.php?i...cryptedpd4.jpg

    Is this what you mean? I'm not so familiar with the hacking stuff
    Ok, so you managed to get the rootFS. Good job. I haveba question though. What was the name of the .dmg file you used, and did you use vfdecrypt to decrypt the rootFS? Thanks.

  9. #39
    Professional Array

    Join Date
    Oct 2007
    Location
    Netherlands
    Posts
    95
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    12

    Default

    The file was 018-3785-2.dmg and i used vfdecrypt...

  10. #40
    Senior Professional Array

    Join Date
    Aug 2006
    Posts
    204
    Post Thanks / Like
    Downloads
    0
    Uploads
    0
    Rep Power
    17

    Default

    wich argument have you used with vfdecryt ?
    I tried ti decrypt on osx but didnt work. I am not sure if I have well used vfdecrypt

    OK, I have it. Thanks


    ./vfdecrypt -i 018-3785-2.dmg -o 018-3785-2Dec.dmg -k 2cfca55aabb22fde7746e6a034f738b7795458be9902726002 a8341995558990f41e3755
    Last edited by lolof; 07-18-2008 at 06:11 PM.
    iPhone 3GS iBoot 359.3.2
    3.1.2 Blackra1n / Blacksn0w


 

 
Page 4 of 8 FirstFirst 12345678 LastLast

Similar Threads

  1. Hacktivate/Jailbreak/Unlock freshly restored 3g on 4.1?
    By bobbylight in forum Ultrasn0w (3G(S)/iPhone 4 unlock)
    Replies: 3
    Last Post: 11-05-2010, 05:34 AM
  2. jailbreak / hacktivate / unlock 2G iphone
    By sinanerdemir in forum Redsn0w
    Replies: 1
    Last Post: 10-21-2010, 10:17 AM
  3. True Unlock Theory
    By sezxzpqcfuy in forum iPhone "2G" (Rev. 1)
    Replies: 0
    Last Post: 03-30-2008, 05:05 AM
  4. Replies: 2
    Last Post: 09-06-2007, 08:20 PM
  5. Replies: 5
    Last Post: 08-31-2007, 06:21 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Powered by vBulletin®
Copyright © 2013 vBulletin Solutions, Inc. All rights reserved.
Search Engine Friendly URLs by vBSEO
(c) 2006-2012 Hackint0sh.org
All times are GMT +2. The time now is 11:13 AM.
twitter, follow us!