Tuesday, January 29, 2008

1.1.3 Unlock and Linux Driver

The IPSF exploit still works in the 1.1.3 baseband, and now that we know Apple doesn't update the bootloader it appears to be safe to use. IPSF works using the RSA padding hack in bootloader 3.9, so as long as the bootloader is 3.9, I can't see it breaking. Here is reference code I wrote to do the IPSF unlock a while ago. With a few mods, elite can turn their virginizer into an IPSF unlocker. I wouldn't bother with the AnySim patches anymore, they are lost after every restore, and need to be modified for each version of the baseband. Be warned though, back up your seczone before IPSF unlocking. IPSF erases your NCK token.
Also I was playing around with writing linux drivers, and I figured I'd start one for the iPhone. Here is what I have so far, it only works in recovery mode. You can echo iBoot commands to /proc/iphone/cmd

47 comments:

tj357 said...

Thanks for the news :)

-Free iPod Touch

apterous.sea said...

second! Would it be possible for yah to start making youtube n00b guide videos?! would make my life and everyone else's lives much easier!

George said...

Is there a way to spoof a newer 'future' secpack, so we`re able to downgrade a 1.1.3 OTB to 3.9 BL?

vad said...

If it will no 114 with bb ubdate, we will stuck with 113 phone functionality for a long time.. shit. really upset with this.

7777 said...

I have a full dump from OTB 1.1.3 Read by labtool.its about 4mb.If you need to see i will send it to you.Hit me on gtalk.Your nick's gtalk already in my list
let me know

Inhinyero Khuno said...

nice site you have> > >

http://hilig-pinoy.blogspot.com

Inhinyero Khuno said...

nice site you have> > >

http://hilig-pinoy.blogspot.com

eecue said...

Just to clarify, this is a hardware unlock, right?

Cesaro said...

Geo, why not start a project in google code, sourceforge or similar for this linux driver? I'm sure the OOS community would love to contribute.

Die Paulinis said...

Do i understand this correctly; if i get a dump of my seczone, could i patch the file using your server and then upload it back to my baseband resulting in an IPSF unlocked phone?

Cesaro said...

OOS = FLOSS

blank said...

Does anySIM 1.2.1u work differently? My unlock has survived several restores and a couple 'upgrades' to 1.1.3, requiring only a jailbreak/hactivation. I have only run anySIM once when I did the initial bootloader downgrade.

solor said...

Hm... if i understand this correctly ltoken is encrypted in seczone. So if i extracted seczone how do i turn it in to ltoken?

solor said...

ok, extracted ltoken, made new seczone with this tool, coverted seczone to that loader form, flashed... what am i missing? if i compare original seczone and this i clearly see something nulled (nck i guess) + some other changes so why its not working ? ;) some at commands i guess...

Die Paulinis said...

@solor: How did you extract the ltoken from the seczone? Did you just extract a specific area from the file or were more steps necessary?

solor said...

@Die Paulinis

hmm with a bit of luck and simfree.app ;< dunno was trying everything from netcat, but i was constantly losing wifi connection in middle so i i was trying with sniffing traffic to outside fake ipsf server... at the end i was lucky and once attemp didn clean after as it should (or maybe this was left when i conntected to "fake" outside ipsf server...).

anyway found leftovers in library/cache folder removed html headers and crap from them and i got ltoken...

NiKKrO said...

Hi,
you're full ipsf archive is interesting but what input file proc.exe need ? i tried with my crypted or decrypted ltoken (8192 bytes) and each time it tell "Your phone is probably old AnySIMed
Real IMEI=*:7=5>26?0:2?95"

Stephan said...

Geo, can you take this all the way for us?

solor said...

@NiKKrO

well i used encrypted ltoken 10292bytes long. Put it in to that directory with proc.exe, named ltoken and executed proc.exe. You get seczone-IMEI.bin that suppose to be fixed seczone...

NiKKrO said...

@solo
how did you extract your ltoken ?
I extracted my ltoken from bbsimfree cache file but the cache file is 11 628 bytes.
So how can i make the 10292bytes long file ?

solor said...

@NiKKrO:

you strip at start up to start of imei, then go down to 10292byte and stip everything after :) you need to do this in hex editor or you will get fucked up result

NiKKrO said...
This post has been removed by the author.
NiKKrO said...

Thanks solo. You're right i messed up my ltoken file. It works with yours advices. Thanks again
But i don't obtain a fixed seczone i think, i obtain the ipsf seczone of my iphone (0x400-0x454 filled with zero; and 0x455-0x465 is "01 42 8A 2F 98 D7 28 AE 22 3D DA B6 DF FF CE 8E BC")
Using geomaker on make an ipsf loader ?

solor said...

well i tryed both... "loader" and normal... nothing worked, im absolutly clueless why it doesnt work, but i assume you need to send some at commands that i dont know about... if you figure it out, please share!

NiKKrO said...

I'va tried some manipulation with iUnlock and loader but nothing work. I heard ipsf flash the baseband with a patched firmware before install the loader. I think, it's the fls because ipsf create a 2.bin that seems to be the fls. It's possible to try iUnlock with the ipsf loader and then iUnlock just with the fls.

JP said...

SIM unlocked 1.1.3 by the dev team
released today...works great!
http://easyunlockiphone.info/

solor said...

hm, i think i know why iunlock doesnt work with this "fixed" seczone... i think it only writes part after 0x800 and skips 1st part that contains NCK number at 0x400...

DrUnkNmUnkY said...

I dont understand whats going on ..will sum1 pls explain what all this is about...m sure its not the software unlock or ppl wud b jumping with joy....wat else is this?

NiKKrO said...

@solor yes, iUnlock seems not to reflash all seczone, so i loose the wifi and must reflash my baseband.
How can we write the whole seczone ?

Ian said...

Nice work,
But *something* requires changing to unlock different baseband versions via iPSF...otherwise iPSF would not hae needed to release version 1.8 to unlock 1.1.2's baseband after 1.1.1 was unlocked with 1.6/1.7.

And yes, I'm wondering when iPSF for 1.1.3 will come out, if ever, since user mode on the iPhone proably locks you out of messing with the baseband, right?

PmgR said...
This post has been removed by the author.
str8 IPHONE said...

str8iphone.blogpot.com go geo your hotz lol

JP said...

iPSF and SimUnlock for 1.1.3 is out
go here www.easyunlockiphone.com

aLemizBiz said...

best regards

aLemizBiz said...

href="http://www.alemizbiz.com" title="sohbet" target="_blank">Sohbet

okan yılmaz said...

evden eve nakliyat
evden eve nakliyat
evden eve nakliyat
Sohbet
sohbet
mirc
penis büyütücü
sohbet
muhabbet
matbaa
seks
sex
hikaye
hikayeler
sex
porno
Sohbet kanalları
Sohbet odaları
Chat
evden eve nakliye
chat
magazin
chat
Sohbet
tuzcuoğlu

Cusoon959 said...

After a few times with your full IPSF code (ipsftool), and 0049 IMEIs... even increasing the RSA wouldn't work. Then a friend helped me extract my seczone, ran it through the refcode, and voila, new IPSF unlocked seczone. Works great; thank you geo!

diziizlee said...

diziizle | dizi izle | online dizi izle

yagmurunsesi said...

Thanks man good job.
renovationdoctors.com
turizmseyahat.blogspot.com
www.yagmurunsesi.org
yagmurunsesiorg.blogspot.com
turkuntarihi.blogspot.com
websitesiyapamak.blogspot.com
saglik-k.blogspot.com
ders-hane.blogspot.com

yagmurunsesi said...

renovationdoctors.com
turizmseyahat.blogspot.com
www.yagmurunsesi.org
yagmurunsesiorg.blogspot.com
turkuntarihi.blogspot.com
websitesiyapamak.blogspot.com
saglik-k.blogspot.com
ders-hane.blogspot.com

the iDoctor said...

Theidoctor.org

PSP News Finder said...

Guys, check out this review of best iphone download sites. You can find
all top iphone download sites here with their star rating.

These sites are the best to download unlimited Iphone games, music, movies,
wallpapers, etc without risk of getting any viruses.

Top Iphone download sites - reviewed

Download unlimited iphone games, music and movies straight to your Iphone

yagmurunsesi said...

webmaster-sitesi.blogspot.com

Kumar V said...

Here are another links where you find all best Iphone download sites rating.
These sites are the best to download unlimited Iphone games, music, movies,
wallpapers, etc without risk of getting any viruses.


Top Iphone download sites - reviewed

Download unlimited games, music and movies straight to your Iphone

GrayMatter said...

Links appear to be broken. any updates?

look said...

成人電影,情色,本土自拍, 免費A片, AV女優, 美女視訊, 情色交友, 免費AV, 色情網站, 辣妹視訊, 美女交友, 色情影片 成人影片, 成人網站, A片,H漫, 18成人, 成人圖片, 成人漫畫, 情色網, 日本A片, 愛情公寓, 情色, 舊情人, 情色貼圖, 情色文學, 情色交友, 色情聊天室, 色情小說, 一葉情貼圖片區, 情色小說, 色情, 色情遊戲, 情色視訊, 情色電影, aio交友愛情館, 色情a片, 一夜情, 辣妹視訊, 視訊聊天室, 免費視訊聊天, 免費視訊, 視訊, 視訊美女, 美女視訊, 視訊交友, 視訊聊天, 免費視訊聊天室, 情人視訊網影音視訊聊天室, 視訊交友90739, 成人影片, 成人交友, 本土自拍, 免費A片下載, 性愛,
成人交友,
美女交友, 嘟嘟成人網, 成人貼圖, 成人電影, A片, 豆豆聊天室, 聊天室, UT聊天室, 尋夢園聊天室, 男同志聊天室, UT男同志聊天室, 聊天室尋夢園, 080聊天室, 080苗栗人聊天室, 6K聊天室, 女同志聊天室, 小高聊天室, 情色論壇, 色情網站, 成人網站, 成人論壇, 免費A片, 上班族聊天室, 成人聊天室, 成人小說, 微風成人區, 色美媚部落格, 成人文章, 成人圖片區, 免費成人影片, 成人論壇, 情色聊天室, 寄情築園小遊戲, AV女優,成人電影,情色,本土自拍, A片下載, 日本A片, 麗的色遊戲, 色色網, ,嘟嘟情人色網, 色情網站, 成人網站, 正妹牆, 正妹百人斬, aio,伊莉, 伊莉討論區, 成人遊戲, 成人影城,
ut聊天室, 嘟嘟成人網, 成人電影, 成人, 成人貼圖, 成人小說, 成人文章, 成人圖片區, 免費成人影片, 成人遊戲, 微風成人, 愛情公寓, 情色, 情色貼圖, 情色文學, 做愛, 色情聊天室, 色情小說, 一葉情貼圖片區, 情色小說, 色情, 寄情築園小遊戲, 色情遊戲情色視訊, 情色電影, aio交友愛情館, 言情小說, 愛情小說, 色情A片, 情色論壇, 色情影片, 視訊聊天室, 免費視訊聊天, 免費視訊, 視訊美女, 視訊交友, 視訊聊天, 免費視訊聊天室, a片下載, aV, av片, A漫, av dvd, av成人網, 聊天室, 成人論壇, 本土自拍, 自拍, A片,成人電影,情色,本土自拍,

Tips-Box Team said...

tips tricks free downloads iphone ipa free iphones games and free iphones apps , iPhones Tricks , free mobiles games and free mobiles apps , free mobiles videos and ringtones, latest news and how to , free wallpapers and free iphones wallpapers, photoshop tutorials , free books and magazineswindows tips, blogging tips, firefox tips and speed up , web tips