HomeStoreForumsWikiiPhone Native AppsiPhone AppsiPhone Apps modmyifone Downloadsmodmyifone Links






Go Back   ModMyiFone.com - iPhone | iPod Touch forums, news, apps, themes. > ModMyiFone > News
Register FAQ Members List READ THIS Today's Posts Mark Forums Read

News What's the latest news? Check it out here. Grab Our News RSS Feed


iPhone Optimized MMi | Browser Optimized MMi

Get more out of ModMyiFone by joining our free community. By registering you get privileges to download files from our downloads section and you may also post your questions in our forums! It's fast, free, and easy!

Opportunities at MMi | 1.1.4 Unlock|Jailbreak OS X / Win | $199 3G iPhone Releasing July 11
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-08-2008, 01:16 AM
cash7c3's Avatar
Owner / Founder - ModMyiFone
 
Join Date: May 2007
Device + Firmware: iPhone | 1.1.2 | 1.1.3
Operating System: OS X | XP | Sabayon
Posts: 2,499
Thanks: 179
Thanked 9,018 Times in 256 Posts
Send a message via AIM to cash7c3 Send a message via MSN to cash7c3 Send a message via Yahoo to cash7c3
FREE IT. Software Unlock iPhone 1.1.2 OTB and 1.1.3 OTB! (yes the 4.6 bootloader)

geohotz has discovered the secrets to unlocking 1.1.3 + 1.1.2 out of the box!!! Whats more this doesnt even destroy your seczone!!



I haven't had a chance to try it out yet but when has gehotz failed us before?

If any of you are feeling up to it give it a shot. First grab his gunlock.rar MIRROR and his instructions are as follows:

Quote:
geohot's 1.1.2 software unlock
yes, this is what you have all been waiting for

1. Download these:
gunlock and the secpack from http://iphonejtag.blogspot.com/ or the blog
the 4.02.13 fls from http://george.zjlotto.com/index.php/baseband/ MIRROR

2. Downgrade your phone to 1.0.2. See all the great tutorials online to do this.
Your baseband won't be downgraded, this is normal.
This will probably work on other versions too, but 1.1.2 doesn't lose wifi on bb access.

3. Kill CommCenter and run "gunlock secpack ICE04.02.13_G.fls"

4. Reload CommCenter. For some reason my phone was in brick mode. Use the elite team bricktool to get out.

5. Enjoy your 1.1.2 OTB unlocked iPhone

Now who'd have thought it'd be this easy

This release is no thanks to elite/dev
I wish they would share like the old days.
I don't believe everyone in the team is like this, but come on guys.

If you want to contribute to me, the person who discovered these exploits and wrote this tool
paypal geohot@gmail.com
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 6 Users Say Thank You to cash7c3 For This Useful Post:
bapiyaa (02-10-2008), Kanin (02-08-2008), mike_carter1 (02-09-2008), Polgas (02-08-2008), Samm_73 (02-10-2008), wiseone (02-08-2008)
  #2 (permalink)  
Old 02-08-2008, 01:22 AM
Green Apple
 
Join Date: Sep 2007
Posts: 54
Thanks: 5
Thanked 1 Time in 1 Post

R you sure it works on 1.1.3 OTB as well?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #3 (permalink)  
Old 02-08-2008, 01:26 AM
cosmoLV's Avatar
iPhone? More like MyPhone
 
Join Date: Oct 2007
Location: Latvia, riga
Posts: 157
Thanks: 11
Thanked 14 Times in 13 Posts
Send a message via Skype? to cosmoLV

great news, let's test
__________________
Country: Latvia
Carrier: LV LMT
Runing On FW 1.1.3 BL 3.9 [Jailbreaked/Unlocked]

iPhone Simple Things

-------------------------------------
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to cosmoLV For This Useful Post:
kee (02-09-2008)
  #4 (permalink)  
Old 02-08-2008, 01:33 AM
Green Apple
 
Join Date: Sep 2007
Posts: 42
Thanks: 3
Thanked 13 Times in 8 Posts

Its been updated now for OTB 1.1.3

these are the instructions I have been given:

its 1.1.2 otb, here is a brief noobs guide

Download these:
gunlock and the secpack from http://iphonejtag.blogspot.com/ or the blog
the 4.02.13 fls from http://george.zjlotto.com/index.php/baseband/

2. Downgrade your phone to 1.0.2.
irrespective of wher u are 1.1.1/1.1.2 otb not otb
press and hold power and home button untill u see the screen go blank , leave the power button as soon as the screen turns black, (set up the speaker volume on ur pc to high) as soon as the screen goes black u'l hear a sound, now after abt 10 secs holding down the home button u'll hear another sound , now in itunes it will say phone in recovery mode and all, in itunes, hold the shift key (alt key in mac) and downgrade sequentially to 1.1.1 if you were in 1.1.2 or from 1.1.1 to 1.02 (some will say go directly to 1.02 I prefer this) once ur on 1.02
jailbreak and activate it , use ibrickr or watever u like.
install installer.app through ibrickr or watever, update it, install
community sources,bsd subsystems,open ssh, mobile terminal, etc etc
now use win scp/ibrickr and upload all files to usr/bin
files are gunlock/secpack/fls file for 1.1.2/gunlock.c

use putty or mobile terminal to execute the following commands

launchctl unload -w /System/Library/LaunchDaemons/com.apple.CommCenter.plist

gunlock secpack ICE04.02.13_G.fls"

launchctl load -w /System/Library/LaunchDaemons/com.apple.CommCenter.plist


5. Enjoy your 1.1.2 OTB unlocked iPhone

This explains the video I was shown today of a 16 gig unlocked
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 2 Users Say Thank You to w9cae For This Useful Post:
ripaz17 (02-10-2008), wiseone (02-08-2008)
  #5 (permalink)  
Old 02-08-2008, 01:35 AM
What's Jailbreak?
 
Join Date: Oct 2007
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts

Geohost you are JEBENO Awesome (Serbin)

THANK YOU VERY MUCH !!!

GO GEOHOST BROTHER...
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #6 (permalink)  
Old 02-08-2008, 01:44 AM
jasonm253's Avatar
iPhone? More like MyPhone
 
Join Date: Dec 2007
Device + Firmware: 1.1.4. tmobile
Location: Swayside
Posts: 145
Thanks: 4
Thanked 4 Times in 4 Posts
Send a message via AIM to jasonm253

this is for bootloader 4.6 plz say yes plz say yes?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #7 (permalink)  
Old 02-08-2008, 01:47 AM
cash7c3's Avatar
Owner / Founder - ModMyiFone
 
Join Date: May 2007
Device + Firmware: iPhone | 1.1.2 | 1.1.3
Operating System: OS X | XP | Sabayon
Posts: 2,499
Thanks: 179
Thanked 9,018 Times in 256 Posts
Send a message via AIM to cash7c3 Send a message via MSN to cash7c3 Send a message via Yahoo to cash7c3

yes
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #8 (permalink)  
Old 02-08-2008, 01:51 AM
cosmoLV's Avatar
iPhone? More like MyPhone
 
Join Date: Oct 2007
Location: Latvia, riga
Posts: 157
Thanks: 11
Thanked 14 Times in 13 Posts
Send a message via Skype? to cosmoLV

Database Error for this http://george.zjlotto.com/index.php/baseband/
__________________
Country: Latvia
Carrier: LV LMT
Runing On FW 1.1.3 BL 3.9 [Jailbreaked/Unlocked]

iPhone Simple Things

-------------------------------------
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #9 (permalink)  
Old 02-08-2008, 01:59 AM
Green Apple
 
Join Date: Oct 2007
Posts: 37
Thanks: 2
Thanked 4 Times in 3 Posts

His site is down, but this is what he said:
-----------------------------------

11246unlock, good enough for the prize
OMG NOW supports 1.1.3 TOO

Full software unlock of 1.1.2; the impossible(or at least I said so) Here it is; instructions are in the package. I guess I really am becoming a good reverser ;-)

Yes, the impossible has been done. This has absolutely *nothing* to do with JerrySim or any elite/dev/zibri etc project. I'll start with a little story. Yesterday I was really pissed off. So I figured I'd channel my anger toward something productive; I don't know, something like a 1.1.2 software unlock. I knew the odds were against me, but I'd figured I try anyway. At about 1 last night, I hardware "upgraded" a 3.9 phone to 4.6 with the bootrom locations blank, the read command patched to work, and a 0x102 read arbitrary memory command.

The first exploit I found, at around 4 AM last night, was the -0x20000 exploit. Just like the -0x400 exploit, but -0x20000. Go figure. I guess Apple thought big numbers were harder to guess. I was really pumped, hence the blog post. But that wasn't even half the battle.

Like I said in the "impossible" post, 0x3C0000 can't have a valid secpack to allow booting. I spent the next 16 hours finding a way to do this. I can already write unsigned to the main fw section, all I need is a way to erase the secpack. My first idea was the eeprom secpack; upload the eeprom, endpack it, and the secpack is erased because the eeprom is "clean". But you can't upload a eeprom secpack until the 0x3C0000 is blank. My next idea was that the bl must erase the secpack before writing it. So a simple timing attack should do it. It turns out that no secpacks, even the same one, will write.

I finally found a working exploit about 23 hours into my search for the software unlock. The explict addresses 0xA03D0000-0xA03F0000 will always erase. This exploit relied on two things, the secaddrs are copied before the secpack is validated(stupid), and the erase command extends the range to whatever is in the secpack. So I tell it to erase 0xA03D0000-0xA03F0000, the erase command sees 0xA03C0000 to 0xA03F0000 in the secpack; BOOM secpack erased.

The third minor concern was the full range check of 1.1.3. So use 1.1.2 This allows full unsigned code execution, it is a relatively simple matter of patching the bootloader to skip the range check. And while you are at it, patch the bootloader to validate all tokens. IPSF style unlock w/o touching the seczone.

So, thats 24hrs to a software unlock; with about 3hrs of sleep in two segments. I am disappointed in the elite/dev team for not finding this; or even looking here. I know not everyone in elite/dev is so closed, and I feel bad for those people. Why don't we all just share everything? Apple will patch it anyway. They always have the upper hand. And whetever happened to the dev wiki?

If you were giving money to the "dev team" for this software unlock, why not give it to the guy who actually found the exploits and exploited them?



files available here: (fls file included)

http://rapidshare.com/files/90086821/gunlock.zip.html

Last edited by mopplecrump : 02-08-2008 at 02:11 AM.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to mopplecrump For This Useful Post:
wiseone (02-08-2008)
  #10 (permalink)  
Old 02-08-2008, 02:00 AM
Green Apple
 
Join Date: Nov 2007
Device + Firmware: iPhone 1.1.4
Operating System: Windows XP
Location: Singapore
Posts: 45
Thanks: 3
Thanked 3 Times in 3 Posts

woot! life is good geohotz rox!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #11 (permalink)  
Old 02-08-2008, 02:01 AM
What's Jailbreak?
 
Join Date: Nov 2007
Posts: 1
Thanks: 1
Thanked 0 Times in 0 Posts

I think we killed the second site, keep getting a database error.
Anyone run into the same problem or an alternative site to dl from?
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #12 (permalink)  
Old 02-08-2008, 02:04 AM
What's Jailbreak?
 
Join Date: Dec 2007
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts

Great news, congrats.

Found 4.02.13 fls in the second link posted so I have it all, thanks!

Last edited by carolaclavo@mac.com : 02-08-2008 at 02:08 AM.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #13 (permalink)  
Old 02-08-2008, 02:04 AM
What's Jailbreak?
 
Join Date: Oct 2007
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts

Can't download the 4.02.13 fls from the URL, it must be a broken link or something. Is there any other way to get it? Anybody knows?

thanx
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #14 (permalink)  
Old 02-08-2008, 02:09 AM
What's Jailbreak?
 
Join Date: Sep 2007
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts

I've been trying so many times. Stuck with this error. Anyone got the same problem like me? Thanks.

# gunlock secpack ICE.04.02.13_G.fls
geohot's 112 otb unlocker...
Waiting for data...
Attempt...
Attempt...
Got Header: 77 0b cc
Bootloader version: 4.6_M3S2
Increasing baud rate...
02 00 82 00 04 00 00 10 0E 00 A4 00 03 00
CFI Stage 1
CFI Stage 2
zsh: bus error gunlock secpack ICE.04.02.13_G.fls
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #15 (permalink)  
Old 02-08-2008, 02:18 AM
What's Jailbreak?
 
Join Date: Feb 2008
Posts: 2
Thanks: 0
Thanked 1 Time in 1 Post
4.02.13.fls

Maybe if more of us had it someone can help you...could someone please upload it to rapidshare or something PLEASE!!!!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
Reply

  ModMyiFone.com - iPhone | iPod Touch forums, news, apps, themes. > ModMyiFone > News


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

ModMyMoto.com - ModMyGPhone.com - ModMyiFone.com - Managed Dedicated Servers by SingleHop - iPhone Wallpapers - Contact Us - Link to us - Archive - Privacy Statement - - Top
Copyright © 2007-08 by ModMy, LLC. All rights reserved. You may not copy anything on this site unless you link to the original.
All times are GMT -6. The time now is 08:10 PM. Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC5
ModMyiFone.com is an independent publication and has not been authorized, sponsored, or otherwise approved by Apple, Inc or Cisco Systems, Inc. The information contained on this site is for educational purposes only.
Forum skin by poetic_folly