Bypassing the Overlord
To this end, I have constructed a server that duplicates the functionality exposed by Apple's signature server, except using "on file" results rather than live requests.
All we need, then, is to make iTunes use it. Luckily, most operating systems also have the ability to locally define bypasses on specific hostnames through a file called hosts. Using this, we can redirect requests to Apple's signature server to Cydia.
So, open the file C:\Windows\System32\drivers\etc\hosts (Windows) or /etc/hosts (Mac OS X) and add the following entry to the bottom of the file.
74.208.10.249 gs.apple.com
Now, when iTunes thinks it is talking to Apple, it is talking to Cydia instead. Doing this will allow iTunes to access signatures already stored by Cydia's "on file" feature.
This server will also act as a cache for any SHSH blobs it hasn't seen, acting as an intermediary to Apple's server. This effectively registers your device with the "on file" mechanism, which means you can now enjoy the protections of being able to downgrade your firmware in the future even if you aren't jailbroken.
This point should be stressed: even if you don't jailbreak, and even if you never intend to jailbreak, you should consider using the new "on file" service.
Let's say that Apple releases an OS upgrade in the future, you take it, and they break something important. Maybe they break your e-mail account, or your todo list. Your business is now crippled.
If only you could downgrade, right? Alas, Apple won't let you anymore. That's where the new signature cache server comes in: by doing your restores through this server you secure your ability to not accept upgrades from Apple if the need is dire.
Performing the Restore
Now, one would have hoped that the process would be as easy as "restore using the 3.0 IPSW". If only we were that lucky. The first problem is that a downgrade from 3.1 to 3.0 must be initiated in DFU mode.
So, we begin: hold down the lock and menu buttons (some call these the power and home buttons) for 10 seconds, letting go of the lock button but continuing to hold menu until iTunes recognizes the device with the message: "iTunes has detected an iPhone in recovery mode. You must restore this iPhone before it can be used with iTunes.".
Note that, at this point, your iPhone's screen should be entirely black. Many people confuse "DFU" with "recovery" (and in fact, iTunes itself glosses over this), but they are quite different. If you see anything on your screen, such as the iTunes logo and a sync cable, or a cartoon of Steve Jobs swearing in Cyrillic, you are in recovery mode and need to try again. One can find videos online that may help.
At this point, you should do a "normal" restore to the 3.0 software. When doing this, remember to hold down the option key (on Mac OS X) or the shift key (Windows) while clicking the Restore button in iTunes. Select the firmware (which is probably named iPhone2,1_3.0_7A341_Restore.ipsw), and things should be on their way.
Please note that I do not have signatures for 3.0.1, only for 3.0. For some very small number of users I also have a signature for 3.0.1, but I ran out of time hitting the Wednesday deadline getting the code for this working and generalized. If you would like to try restoring to 3.0.1 with my server, therefore, to see if you have 3.0.1 keys on file you can try, but it may fail late in the process with a very weird error. All users "on file", however, have 3.0 ready to go.
Thanks
DJRaz55
Today Apple sent a press release announcing that they’ve filed a lawsuit against HTC for infringing 20 of Apple’s patents related to iPhone interface and the underlying architecture and hardware. The lawsuit was filed with U.S. International Trade Commission (ITC) and in U.S. District Court in Delaware.
“We can sit by and watch competitors steal our patented inventions, or we can do something about it. We’ve decided to do something about it,” said Steve Jobs, Apple’s CEO. “We think competition is healthy, but competitors should create their own original technology, not steal ours.”
Apple is specifically going after HTC’s phones that are running Google’s Android software rather than the phones that are running Windows Mobile. By suing HTC for using Android’s operating system, is Apple trying to scare other manufacturers from using Google’s Android operating systems on their future devices? This is what it looks like to me. Going through the boring list of patents Apple listed in their complaint, I noticed that one of the patents they complained about was the “Swipe to unlock” feature. I find it ridiculous that a company can patent these types of simple features, and hope that Apple looses this case. If you are bored you can see a list of all the patents here.
http://www.docstoc.com/docs/27230772/Apple-vs-HTC
Thanks
DJRaz55
This warning applies to owners of
3GS
iPod touch 3
iPod touch 2 with serial *MC*
Any 3g unlockers
iPhone OS 3.1.3 is now out from Apple. Supposedly it fixes some battery issues. (Doesn't every release make things faster and fix battery problems?) There are no new features. The release only stops jailbreaks. That's right. No new features.
DO NOT UPDATE YOU WILL BE SORRY.
Currently there is no jailbreak for this firmware. Unofficial sources have confirmed that they have patched up the method we used to jailbreak 3.1.2 so you will not be able to jailbreak. If you update you will lose all your jailbreak apps and will not be able to get them back. In other words, updating means you lose a lot of stuff in return for almost nothing back. In addition, there is no ETA on a jailbreak for 3.1.3. It may never be jailbroken. It is likely that they (dev team, geohot) will not waste another hole on 3.1.3. They will most likely hold it for the bigger update that will come with the release of the iPad and iPhone 4.0.
Unlockers - you cannot unlock the new baseband. This woudl apply to those 3g users that can jailbreak 3g. If you update, you will not be able to unlock.
One more thing, as of right now, Apple is still signing 3.1.2 for you 3gs users but no one knows for how much longer they will be. Make sure you *rush* into Cydia or Rock and get your keys signed on the front page if you have not. This will make certain you can always restore 3.1.2 even in the future using Saurik's server.
To summarize:
- Update adds NO NEW FEATURES, do not update.
- Update kills your jailbreak. Do not update.
- Get your 3gs 3.1.2 keys signed by Cydia/Rock now if you haven't.
- Unlock does not work on new baseband.
Thanks
DJRaz55
What is it?
A cross-platform jailbreaking, unlocking, and customizing tool for iPhones and iPod touches. Customizations include boot logos, recovery logos, and “verbose” boot. It's a standalone program that doesn't use iTunes (no custom IPSWs are involved).
The download links are at the bottom of this page (but please read the whole page anyway!).
We've been offering redsn0w in various incarnations over the years (including poorlad's Windows version of QuickPwn). The most recent release before this one was redsn0w 0.8, which targeted Apple firmware 3.0/3.0.1.
What devices, platforms, and FW versions are supported?
This release supports:
All iPhones and iPod touches (still a tethered-only JB for late-model devices though)
Apple firmware 3.0 and 3.1.2
Windows and Mac OSX (x86)
It will also soon run on the PPC OSX, and Linux platforms.
If you need a carrier unlock, redsn0w will handle iPhone 2G by itself (by installing our BootNeuter utility). For the 3G and 3GS, use Cydia after you're jailbroken to install ultrasn0w (baseband 04.26, preferred) or blacksn0w (baseband 05.11).
How is it different from PwnageTool?
redsn0w doesn't require a system restore like PwnageTool does (it doesn't even use iTunes at all). On the other hand, PwnageTool can prevent your baseband from being upgraded when you upgrade your firmware, preserving your unlock. (redsn0w doesn't touch your baseband but it doesn't help preserve it during an upgrade either).
redsn0w works by modifying your current filesystem, so your existing baseband, data and applications should remain intact.
ADVICE: DO NOT USE REDSN0W AFTER DOING A STOCK APPLE UPGRADE TO 3.1.2 IF YOU NEED A CARRIER UNLOCK AND ARE CURRENTLY USING BASEBAND 04.26 OR EARLIER. The key part of that advice is “do not do a stock Apple upgrade to 3.1.2”. You really want to keep that 04.26 baseband on there because then you can keep using ultrasn0w. Ultrasn0w doesn't have the wifi issues that some people (10-20%) report when using geohot's blacksn0w unlock on 05.11. If you are at 04.26 or earlier, use a custom IPSW from PwnageTool to update your firmware to 3.1.2, or just stay at 3.0 and use redsn0w there (redsn0w and ultrasn0w work on both 3.0 and 3.1.2, but ultrasn0w needs baseband 04.26).
How is it different from blackra1n?
It differs from blackra1n because:
It offers custom logos and verbose boot
It installs Cydia, afc2, and the IPCC tethering hack without needing separate downloads. Because they're all installed in one go, redsn0w doesn't need the multiple levels of installs that blackra1n requires. (Update: the IPCC hack was pushed off to redsn0w 0.9.3 for beta testers, links are below also).
It uses our original Pwnage bootrom exploit for iPhone 2G, iPhone 3G, and iPod 1G. (Because it's a bootrom exploit, it can't be fixed by Apple without a new hardware release.) Note that redsn0w 0.9 does use the USB exploit for iPhone 3GS and iPod 2G+3G running 3.1.2, but that exploit will be fixed in Apple's next FW release.
What if I have a late-model device?
If you have a late-model iPhone 3GS, or if you have an iPod touch 2G whose serial number begins with “MC”, or any iPod touch 3G, you can use redsn0w to jailbreak but you are currently restricted to “tethered” rebooting. That means you need to connect your device to a computer to complete the boot after a reset. Also, these devices cannot have custom logos.
redsn0w will ask you whether or not you fit in this category when used with the iPhone 3GS or iPod touch 2G+3G. If you have a late-model device and don't give redsn0w the correct answer, you will likely need to do a system restore to recover from the mistake.
To do a tethered boot after your late-model device resets for some reason, either run redsn0w again and select “Just boot tethered right now”, or run blackra1n.
What if I'm already jailbroken?
If you're already jailbroken (by whatever means), redsn0w can still be used to change your boot logos, revert back to the stock logos, or switch verbose booting on and off. By selecting “Already Pwned” you can bypass the steps normally needed to enter the jailbroken state.
What is the IPCC tethering hack?
It allows you to install cellphone Carrier Bundles that aren't officially signed by Apple. This lets you, for instance, install a Carrier Bundle that allows you to use your iPhone as a way to connect your PC to the internet (through your 3G cell connection). This hack is always installed on 3G and 3GS phones by redsn0w 0.9.3 (no selection is required). It isn't included at all in 0.9.2 (it's still in a trial phase). Note that carriers may not like you tethering behind their back so you do so at your own risk.
For some excellent info on Carrier Bundles vs. mobileconfigs, along with a great generator, see http://www.volkspost.info/ipcc_fw3 (and talk about it here). The hack itself is detailed in the 2nd topic on this page. Another generator is available at http://www.benm.at/help/help.php .
How long should it take
You should see a picture of a drive (“Downloading Jailbreak Data”) within 30 seconds of launching the jailbreak (after you've made your custom selections). It should then reboot and you should see a running pwnapple while the process is underway. It should finish within a minute or two after that, and will reboot on its own.
Is it safe?
The Windows version has been tested by small groups of volunteers on IRC and our blog since mid-January. That being said, if things go wrong you may have to do a system restore…so make sure your data and pictures are synced before trying it.
Feedback
Please send any feedback to MuscleNerd (either gmail or iphone-dev.org), or tweet with a #redsn0w tag. Please detail your device, OS, and any problem you find.
Download links
Mac OSX x86
These download links were last updated at about 8PM PST on January 31.
For those who want to beta test the version with the IPCC hack included, the 0.9.3 links are here: Mac and Windows. The IPCC hack is only useful on 3G and 3GS, and you'll need to install a mobileconfig or IPCC appropriate for your carrier to see if it works (see the question above on what the IPCC hack is).
Table of Contents
redsn0w 0.9
What is it?
What devices, platforms, and FW versions are supported?
How is it different from PwnageTool?
How is it different from blackra1n?
What if I have a late-model device?
What if I'm already jailbroken?
How long should it take
What is the IPCC tethering hack?
Is it safe?
Feedback
Download links
redsn0w 0.9
What is it?
A cross-platform jailbreaking, unlocking, and customizing tool for iPhones and iPod touches. Customizations include boot logos, recovery logos, and “verbose” boot. It's a standalone program that doesn't use iTunes (no custom IPSWs are involved).
The download links are at the bottom of this page (but please read the whole page anyway!).
We've been offering redsn0w in various incarnations over the years (including poorlad's Windows version of QuickPwn). The most recent release before this one was redsn0w 0.8, which targeted Apple firmware 3.0/3.0.1.
What devices, platforms, and FW versions are supported?
This release supports:
All iPhones and iPod touches (still a tethered-only JB for late-model devices though)
Apple firmware 3.0 and 3.1.2
Windows and Mac OSX (x86)
It will also soon run on the PPC OSX, and Linux platforms.
If you need a carrier unlock, redsn0w will handle iPhone 2G by itself (by installing our BootNeuter utility). For the 3G and 3GS, use Cydia after you're jailbroken to install ultrasn0w (baseband 04.26, preferred) or blacksn0w (baseband 05.11).
How is it different from PwnageTool?
redsn0w doesn't require a system restore like PwnageTool does (it doesn't even use iTunes at all). On the other hand, PwnageTool can prevent your baseband from being upgraded when you upgrade your firmware, preserving your unlock. (redsn0w doesn't touch your baseband but it doesn't help preserve it during an upgrade either).
redsn0w works by modifying your current filesystem, so your existing baseband, data and applications should remain intact.
ADVICE: DO NOT USE REDSN0W AFTER DOING A STOCK APPLE UPGRADE TO 3.1.2 IF YOU NEED A CARRIER UNLOCK AND ARE CURRENTLY USING BASEBAND 04.26 OR EARLIER. The key part of that advice is “do not do a stock Apple upgrade to 3.1.2”. You really want to keep that 04.26 baseband on there because then you can keep using ultrasn0w. Ultrasn0w doesn't have the wifi issues that some people (10-20%) report when using geohot's blacksn0w unlock on 05.11. If you are at 04.26 or earlier, use a custom IPSW from PwnageTool to update your firmware to 3.1.2, or just stay at 3.0 and use redsn0w there (redsn0w and ultrasn0w work on both 3.0 and 3.1.2, but ultrasn0w needs baseband 04.26).
How is it different from blackra1n?
It differs from blackra1n because:
It offers custom logos and verbose boot
It installs Cydia, afc2, and the IPCC tethering hack without needing separate downloads. Because they're all installed in one go, redsn0w doesn't need the multiple levels of installs that blackra1n requires.
It uses our original Pwnage bootrom exploit for iPhone 2G, iPhone 3G, and iPod 1G. (Because it's a bootrom exploit, it can't be fixed by Apple without a new hardware release.) Note that redsn0w 0.9 does use the USB exploit for iPhone 3GS and iPod 2G+3G running 3.1.2, but that exploit will be fixed in Apple's next FW release.
What if I have a late-model device?
If you have a late-model iPhone 3GS, or if you have an iPod touch 2G whose serial number begins with “MC”, or any iPod touch 3G, you can use redsn0w to jailbreak but you are currently restricted to “tethered” rebooting. That means you need to connect your device to a computer to complete the boot after a reset. Also, these devices cannot have custom logos.
redsn0w will ask you whether or not you fit in this category when used with the iPhone 3GS or iPod touch 2G+3G. If you have a late-model device and don't give redsn0w the correct answer, you will likely need to do a system restore to recover from the mistake.
To do a tethered boot after your late-model device resets for some reason, either run redsn0w again and select “Just boot tethered right now”, or run blackra1n.
What if I'm already jailbroken?
If you're already jailbroken (by whatever means), redsn0w can still be used to change your boot logos, revert back to the stock logos, or switch verbose booting on and off. By selecting “Already Pwned” you can bypass the steps normally needed to enter the jailbroken state.
How long should it take
You should see a picture of a drive (“Downloading Jailbreak Data”) within 30 seconds of launching the jailbreak (after you've made your custom selections). It should then reboot and you should see a running pwnapple while the process is underway. It should finish within a minute or two after that, and will reboot on its own.
What is the IPCC tethering hack?
It allows you to install cellphone Carrier Bundles that aren't officially signed by Apple. This lets you, for instance, install a Carrier Bundle that allows you to use your iPhone as a way to connect your PC to the internet (through your 3G cell connection). See the 2nd topic on this page for more. This hack is always installed on 3G and 3GS phones by redsn0w (no selection is required).
Is it safe?
The Windows version has been tested by small groups of volunteers on IRC and our blog since mid-January. That being said, if things go wrong you may have to do a system restore…so make sure your data and pictures are synced before trying the beta.
Feedback
Please send any feedback to MuscleNerd (either gmail or iphone-dev.org), or tweet with a #redsn0w tag. Please detail your device, OS, and any problem you find.
Download links
REMOVED TEMPORARILY while a bug is chased down …sorry! Be back soon..
Mac OSX x86
Windows
These downloads were last updated at about 1PM PST on January 31.
Thanks
DJRaz55
redsn0w 0.9beta3
What is it?
What devices, platforms, and FW versions are supported?
How is it different from PwnageTool?
How is it different from blackra1n?
What if I have a late-model device?
What if I'm already jailbroken?
How long should it take
Is it safe?
Beta feedback
Download links
redsn0w 0.9beta3
What is it?
A cross-platform jailbreaking, unlocking, and customizing tool for iPhones and iPod touches. Customizations include boot logos, recovery logos, and “verbose” boot. It's a standalone program that doesn't use iTunes (no custom IPSWs are involved).
The download links are at the bottom of this page (but please read the whole page anyway!).
We've been offering redsn0w in various incarnations over the years (including poorlad's Windows version of QuickPwn). The most recent release before this one was redsn0w 0.8, which targeted Apple firmware 3.0/3.0.1.
What devices, platforms, and FW versions are supported?
The beta supports:
All iPhones and iPod touches except the iPod touch 3G
Windows and Mac OSX (x86)
Apple firmware 3.0 and 3.1.2
When it's out of beta, it will support the iPod touch 3G, PPC OSX, and Linux.
If you need a carrier unlock, redsn0w will handle iPhone 2G by itself (by installing our BootNeuter utility). For the 3G and 3GS, use Cydia after you're jailbroken to install ultrasn0w (baseband 04.26, preferred) or blacksn0w (baseband 05.11).
How is it different from PwnageTool?
redsn0w doesn't require a system restore like PwnageTool does (it doesn't even use iTunes at all). On the other hand, PwnageTool can prevent your baseband from being upgraded when you upgrade your firmware, preserving your unlock. (redsn0w doesn't touch your baseband but it doesn't help preserve it during an upgrade either).
redsn0w works by modifying your current filesystem, so your existing baseband, data and applications should remain intact.
How is it different from blackra1n?
It differs from blackra1n because:
It uses our original Pwnage bootrom exploit for iPhone 2G, iPhone 3G, and iPod 1G. (Because it's a bootrom exploit, it can't be fixed by Apple without a new hardware release.) Note that redsn0w 0.9 does use the USB exploit for iPhone 3GS and iPod 2G running 3.1.2, but that exploit will be fixed in Apple's next FW release.
It offers custom logos and verbose boot
It installs Cydia without needing a separate download
It's not as fast :) (but redsn0w handles more variations :))
What if I have a late-model device?
If you have a late-model iPhone 3GS, or if you have an iPod touch 2G whose serial number begins with “MC”, you can use redsn0w to jailbreak but you are currently restricted to “tethered” rebooting. That means you need to connect your device to a computer to complete the boot after a reset. Also, these devices cannot have custom logos.
redsn0w will ask you whether or not you fit in this category when used with the iPhone 3GS or iPod touch 2G. If you have a late-model device and don't give redsn0w the correct answer, you will likely need to do a system restore to recover from the mistake.
To do a tethered boot after your late-model device resets for some reason, either run redsn0w again and select “Just boot tethered right now”, or run blackra1n.
What if I'm already jailbroken?
If you're already jailbroken (by whatever means), redsn0w can still be used to change your boot logos, revert back to the stock logos, or switch verbose booting on and off. By selecting “Already Pwned” you can bypass the steps normally needed to enter the jailbroken state.
How long should it take
You should see a picture of a drive (“Downloading Jailbreak Data”) within 30 seconds of launching the jailbreak (after you've made your custom selections). It should then reboot and you should see a running pwnapple while the process is underway. It should finish within a minute or two after that, and will reboot on its own.
Is it safe?
The Windows version has been tested by small groups of volunteers on IRC and our blog since mid-January. That being said, this is still a beta and if things go wrong you may have to do a system restore…so make sure your data and pictures are synced before trying the beta.
Beta feedback
redsn0w is in beta until we get iPod Touch 3G, PPC OSX, and Linux support added. In the meantime, please send any feedback to MuscleNerd (either gmail or iphone-dev.org), or tweet with a #redsn0w tag. Please detail your device, OS, and any problem you find.
Download links
Mac OSX x86 http://iphwn.org/redsn0w-mac_0.9beta3_gsfix.zip
Windows http://iphwn.org/redsn0w-win_0.9beta3_gsfix.zip
Thanks
DJRaz55
Well there has not been any thing new for a while but they are working on redsn0w 9. It is in beta testing at this time I will post where to down load when it is out of bata.
Thanks
DJRaz55
If you have baseband 05.11.07 you can Jailbreak & Unlock your Iphone for use on other GSM Carriers. Ultrasn0w has been updated to 0.92 it is dowanloadable via cydia must add source
http://repo666.ultrasn0w.com
GEORGE HOTZ wrote
I have an unlock for 05.11.07. I will be releasing on 11/04/09, for $0.00
First off, Jody Sanders, I am declining your $10,000. Why? Because you, and the rest of the iPhone unlock sites out there are scum. You make money selling freeware; that's not cool, and I am in no way going to legitimize it.
Seriously, the people who really lose here are the customers. These sites are full of blatant lies, claiming to have unlocks for 05.11.07 People buy them, and are told the unlock is in development, and the release date is unknown. Imagine you bought a cup of coffee and were told it's in development? Recently, many of these sites sent out e-mails saying they made major breakthroughs and the unlock will be ready 11/04/09. Coincidence that that's the release date of blacksn0w?
I'm not going to post all these scam sites here, as I don't want to give them the pagerank boost. Rather I'll give you a whitelist, two people make unlocks, me and the dev team. Every iPhone unlock site you see out there is selling our stuff, repackaged in some form or another. Same goes for jailbreaks, although ih8sn0w and chronicdev are legit. Notice what all the legit ones have in common? They are free.
Now despite rumors of the ferocity of my legal team, they actually are pretty poor lawyers. And the scum who run these websites are the type who get off on legal battles. So we have to fight them in another way, and I'm asking for everyones help on this. Our weapon is information. Get the truth out, that all iPhone unlocks and jailbreaks are free, and if you are buying something, you aren't getting anything a simple google search couldn't get you, and are probably funding someones crack habit.
This is the first time I have tried to make something simple for the end users, and it enrages me to see people selling it. Let's shut all these assholes down, and tell the iPhone owning world all they need is at blackra1n.com, including blacksn0w instructions on it's release date, 11/04/09(yes, will support hacktivation). You do your part, and I'll do mine making things as simple, reliable, and straightforward as possible.
The iPhone 3.1.2 update that Apple released last week required users of jailbroken iPhones or iPod Touches to wait for a new jailbreak software to be released before updating. There was no jailbreak available until Geohot released his new blackra1n 1 click jailbreak software. The blackra1n software is available for both Windows and Mac users, but it only supports iPhone, iPhone 3G, iPhone 3GS, and iPod Touch. blackra1n does not support the iPod Touch 3rd generation 8 GB models that have a MC in the model number. Many iPhone 3G users reported having a problem with blackra1n on iPhone 3G, if you were one of them please leave a comment telling us what problems you encountered and how you solved them. I will be making a blackra1n troubleshooting guide to help users that have any problem with it. You can jailbreak iPhone 3.1.2 with blackra1n, but you cannot unlock iPhone 3.1.2. To unlock iPhone 3.1.2, you must use PwnageTool 3.1.4 which the Dev-Team recently released.
If you want to just jailbreak iPhone 3.1.2 I recommend you use blackra1n, but if you want to unlock then you have no choice but to use PwnageTool which only works with Mac. If you haven’t already downloaded iPhone 3.1.2 or updated, the download links for it are below.
- iPhone 3.1.2 download (iPhone1,1_3.1.2_7D11_Restore.ipsw, 241 MB)
- iPhone 3G 3.1.2 download (iPhone1,2_3.1.2_7D11_Restore.ipsw, 242 MB)
- iPhone 3GS 3.1 download (iPhone2,1_3.1.2_7D11_Restore.ipsw, 306 MB)
Note: Do no’t use Safari to download iPhone 3.1.2 IPSW files, instead use another browser. Safari downloads this as a .ZIP and iTunes is not able to recognize the firmware that way.
Jailbreak iPhone 3.1.2 with blackra1n
2. Click the make it ra1n button.
3. Your iPhone or iPod Touch will reboot once blackra1n is done doing it’s thing and you should see the blackra1n icon on there. If you don’t see the blackra1n icon, go to the last page on your iDevice and you should see it.
4. Install your preferred aplication from the blackra1n app. You have the option of choosing Cydia, Icy, or Rock. I don’t recommend you to install them all at once, because that may cause problems. Install them one at a time.
Jailbreak iPhone 3.1.2 with PwnageTool
1. Download PwnageTool 3.1.4 (only works with Mac!)

