Exploit | Jailbreak iPhone, iPod Touch, iPad - Part 5 Skip to content

Jailbreak iPhone, iPod Touch, iPad

новости про джейлбрейк iPhone, iPod Touch и iPad

Archive

Tag: exploit

a5 jail 1 Saurik makes contribution towards iPad 2 and iPhone 4S untethered jailbreak

It looks like iPad 2 and iPhone 4S untethered jailbreak will truly be a team effort. Recently another hacker Saurik joined the team and made “some major contributions” yesterday.

Last week Pod2g announced that Planetbeing, MuscleNerd, and P0sixninja joined his effort to release an untethered iOS 5.0.1 jailbreak of the iPhone 4S and iPad 2 (A5 CPU devices).

Today, MuscleNerd noted that the team has received some major contributions from saurik:

props to @saurik for major contributions to the A5 version of @pod2g’s untether yesterday! (still no ETA, but moving forward)

Pod2g also thanked planetbeing for his help in escaping from the sandbox.

And greetings to @planetbeing for the coding + research. Really great stuff to escape from the sandbox.

Good news, that means that there is progress and we might see utility sometime this month.

a5 jail 2 Saurik makes contribution towards iPad 2 and iPhone 4S untethered jailbreak

UPDATE:
Pod2g has also addressed the request that the untethered jailbreak be released to developers. He previously revealed that there is a working jailbreak that requires a developer account.

Sorry, we can’t release the A5 for the developers, the exploit used have to be kept secret. I know this is unfair.

pwned Dream Team will work on untethered iPad 2 and iPhone 4S jailbreak

Pod2g has recently announced that Planetbeing, MuscleNerd, and P0sixninja have joined his effort to release an iOS 5.0.1 untethered jailbreak for the iPhone 4S and iPad 2.

@planetbeing, the legendary hacker behind iPhone Linux and lot of jailbreaks has joined the A5 research! The famous @MuscleNerd, the leader of the iPhone Dev Team, who did a lot of tests for Corona and whom integrated it and made it simple in redsn0w is willing to help also. And last, but not least @p0sixninja, the leader of the Chronic Dev Team, and my partner for years on iPhone security research has started to code and fuzz the Apple sandbox.

That means that we now have a dream team to create a public release of the A5 jailbreak.

Several day ago pod2g posted information why the A5 jailbreak had not been released yet. The key reason being that the exploit used for A4 devices (called limera1n) doesn’t work on A5 devices. The untethered iPhone 4S and iPad 2 jailbreak that we have seen on videos and photos was created relying on having a developer account.

We are sure that planetbeing, MuscleNerd, p0sixninja and pod2g is just a great team. Hopefully they will find necessary exploit and implement it fast, because Apple might release 5.0.2 or 5.1 and fix untathered.

redsn0w 099b9 325x400 RedSn0w 0.9.9b9b released: now fully supports iOS 5.0.1 and SHSH/APTickets

iPhone Dev-Team released RedSn0w 0.9.9b9 with full iOS 5.0.1 support (no need to point to iOS 5.0 any more). New version also features support for SHSH and APTickets:

  • native support for 5.0.1 (no need to point redsn0w at 5.0 IPSW or use command-line args).  Support automatically extends to all of redsn0w’s various functions: “Jailbreak”, “Just boot”, “Fetch blobs”, “Stitch blobs”, “Recovery Fix”
  • iBooks fixed in 5.0 and 5.0.1.  This is a targeted fix that doesn’t remove entire sandbox mechanism.  5.x users already using redsn0w “Just Boot” can just use the new version without redoing entire jailbreak again
  • 3GS old-bootrom owners can now create custom IPSWs without blobs
  • ultrasn0w compatability update (i.e. same baseband requirements) for 5.0.1 will be available on Cydia Monday
  • support for newer 8GB iPhone4 (which until now had problems with “Fetch blobs”).  Thanks to @JKjeepnJeff for loaning us one of these newer i4 units for testing!
  • allows Windows users (not just OS X users) to use the “Custom” button to create IPSWs without baseband updates.  (Update: please wait for 0.9.9b9b for this!)
  • accommodates APTickets in 5.x (until next Apple countermove).  APTickets are crypto-verified before submitting to Cydia, just like the main blobs.  Cydia server support for sending back the APTickets is upcoming.  For now, use stitched IPSWs for 5.x.  Due to APTickets, stitched 5.x IPSWs now require user to start in “Pwned DFU” mode
  • Support added for stitching 4.x blobs to iPad2-GSM IPSWs.  Similar to @notcom’s TinyCFW but doesn’t require lots of RAM or a TSS-assisted restore. Won’t work for iPad2 5.x blobs (or iPhone4S at all) until a bootrom-level exploit is out
  • top line now shows whether (and where) a redsn0w update is available, or if the version being run is the latest.  Uses DNS TXT record to alleviate any concerns about snooping
  • no 5.1 beta support at this time (major apps like Cydia are not yet compatible)
  • @pod2g has been doing a great job porting his 5.x untether…check his blog for updates!
  • Owners of newer 3GS iPhones must not flash the iPad baseband.  The iPad baseband will not work on 3GS iPhones built later than 2011 week 35.  You have a week 35 or later device if your serial # starts with xx135.
Update #17b: Version 0.9.9b9b enables the “Custom” button for Windows users, and make the 3GS week 35 warning a more explicit part of the process.

You can download RedSn0w 0.9.9b9b here.

UPDATE: redsn0w updated to redsn0w 0.9.9b9d.

redsn0w 099b9 2 RedSn0w 0.9.9b9b released: now fully supports iOS 5.0.1 and SHSH/APTickets

Chronic Dev Team is almost done with a much anticipated untethered jailbreak for iOS 5 and iOS 5.0.1. Team member and French hacker pod2g just released a video showing off the jailbreak. It looks to be near-complete and functioning properly. Take a look:

pod2g even created a blog, where he plans to post the most recent news about his progress:

Today I succeed in jailbreaking my iPod 3G. The exploit is user-land, rely on a user ROP payload and a kernel write anywhere exploit.

I can’t give much details right now, but here are the next steps :
- upgrade the iPod 3G to iOS 5.0.1
- do the same on iPhone 4 / iOS 5.0.1
- then iPad 1 & iPod 4G

At every step, the exploit code needs certainly to be reworked, but I really don’t know right now. Next, I’ll return to the research for iPad 2 and iPhone 4S. I don’t know if I gonna release first for other devices or not. I’ve to think about it. Feel free to give your opinion.

crashreporter Chronic Dev Team Releases CrashReporter for Windows

The Chronic Dev-Team has released CDevReporter, their new tool that lets you help find jailbreak vulnerabilities, for Windows.

You can download the Mac and Windows versions of CDevReporter here:

More information is available in our recent post “Want untethered iOS 5 jailbreak? Help hackers to find new exploits!“.

crash reporter Want untethered iOS 5 jailbreak? Help hackers to find new exploits!

Semi-tethered jailbreak is already available for some devices for both iOS 5 and iOS 5.0.1. But we all want untethered jailbreak and we want jailbreak for iPad 2 and iPhone 4S. So why not help hackers to find new exploits and vulnerabilities?

The Chronic Dev-Team has a released a tool to collect crash reports from iOS devices in order to find vulnerabilities that could lead to an untethered jailbreak.

The idea is very simple. When your iPhone, iPad or iPod Touch crashes it sends data to Apple (you can turn it this off though). Apple uses these reports to update iOS in the future. By the way, it also uses them to fix exploits found by jailbreakers. P0sixninja says that Apple closed several exploits they have found in IOS 5 beta before the final version of the software was released.

In order to find more vulnerabilities as fast as possible, the team has developed a tool which will copy the crash reports from your device and analyze them to locate potential exploits. The tool will also remove the crash reports from your device and modify your iTunes installation to prevent uploading of that diagnostic information to Apple.


Read the rest of this entry »

noupdate501 Jailbreakers and unlockers: dont update to iOS 5.0.1

Apple has recently released iOS 5.0.1. It is still tethered jailbreakable. However if you want untethered jailbreak or unlock – you should stay away from 5.0.1

Earlier this week pod2g reported that a code signing bug found in iOS 5.0 will make it easier for hackers to develop a full jailbreak for iOS 5 firmware version. That bug might have been closed in iOS 5.0.1. UPDATE: According to pod2g the bug is still present, but harder to exploit because another exploit found by Charlie Miller is fixed in iOS 5.0.1.

Also, MuscleNerd via twitter has warned iOS users that there is no downgrade from iOS 5.0.1 to iOS 5.0 yet and he recommends to wait until downgrade mechanism is available.

Jailbreakers and unlockers should avoid today’s 5.0.1 until a flow for downgrading to 5.0 is developed.

Downgrade flow needs to be modified for AP “nonce” http://is.gd/b3G0io … saved SHSH blobs are not enough to downgrade to 5.0

MyGreatFest There will be an untethered iOS 5 jailbreak

Hackers from the Chronic Dev Team recently announced that they have found 5 userland exploits in iOS 5. To us this means that it is very likely that an untethered jailbreak will be available for the upcoming firmware release.

P0sixninja made the announcement at MyGreatFest jailbreak conference held in London, England.

While this is a “record breaking number of exploits found”, userland exploits can be easily fixed via a minor software update. The exploits are kept in secret, so hopefully Apple won’t fix them before the expected iOS 5 launch next month.

The jailbreak is expected for all devices, including iPhone 3GS, iPhone 4, iPad, iPad 2, iPod Touch and even future iPhone 4S and iPhone 5.

redsn0w 098b7b 318x400 RedSn0w 0.9.8b7b: untethered 4.3.5 jailbreak for iPhone 3GS and full support for iOS 5 Beta 7

The iPhone Dev-Team has released RedSn0w 0.9.8b7b to bring two new main features:

Musclenerd posted via twitter:

New redsn0w is.gd/6eek4Y explicitly supports iOS5b7 (no need to point at b6 IPSW). Also brings back old-bootrom 3GS goodies.

This is great news for both developers and owners of old bootrom iPhone 3GS’s who accidentally updated to iOS 4.3.5.

DevTeam posted:

About 12 hours after we released redsn0w 0.9.8b7 with some improvements for iOS5b6, Apple went and released iOS5b7 (what are the odds of that?!?). Even though that redsn0w could still jailbreak iOS5b7, you needed to point it at the iOS5b6 IPSW to do so. Today’s redsn0w 0.9.8b7b lets you point redsn0w directly at the iOS5b7 IPSW instead.

We’ve also added some overall improvements for old-bootrom 3GS owners (where the 24kpwn exploit applies): on those devices, you can tell redsn0w to untether 4.3.5 and lower, or iOS5b7. Old-bootrom 3GS owners can once again choose custom logos, and/or verbose booting (for the really nerdy iPhone3GS fans out there!). And it allows 4.3.4 or 4.3.5 users to use ultrasn0w again (if they have a compatible baseband).

Last but not least, we fixed some lingering Verizon iPhone4 4.2.10 JB issues.

We will update our tutorials shortly.

You can download RedSn0w 0.9.8b7b here.

Here are links to our RedSn0w 0.9.8b7b iOS 4.3.5 jailbreak tutorials:

redsn0w 098b3 318x400 DevTeam released tethered jailbreak for iOS 4.3.4

The iPhone Dev-Team has released RedSn0w 0.9.8b3 which can perform a tethered jailbreak on iOS 4.3.4. This means that you will have to connect your device to a computer and run redsn0w each time you restart.

For the convenience of kernel hackers like @comex and @i0n1c, we have a new redsn0w 0.9.8b3 that supports a TETHERED jailbreak for iOS 4.3.4 on all devices that have 4.3.4 except the iPad2. The vast majority of people will want to stay back at 4.3.3 because that’s where the untethered jailbreak is! There are no new features in 4.3.4 – only fixes for jailbreak exploits.

Also, this is a good time to remind everyone (since we’re still seeing confusion about this): iPad2 owners with a baseband (3G or CDMA) cannot currently use saved blobs to go back to 4.3.3 once the signing window is closed. This is unlike every other device, so don’t be confused! iPad2 owners with basebands should stay away from all updates to maintain your jailbreak!

This jailbreak works with iPhone 3GS, iPhone 4, iPad 1, iPod Touch 3G and iPod Touch 4G. It does not work with iPad 2.

You can download RedSn0w 0.9.8b3 from here: (Mac, Windows)