<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description></description><title>Dev-Team Blog</title><generator>Tumblr (3.0; @devteam)</generator><link>http://blog.iphone-dev.org/</link><item><title>Welcome new A5 jailbreakers!</title><description>&lt;p&gt;Here’s a quick breakdown of how many A5 owners have jailbroken their devices since Friday morning.  The numbers as of Monday afternoon are:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;491,325 new iPhone4,1 devices&lt;/li&gt;
&lt;li&gt;308,967 new iPad2 devices&lt;/li&gt;
&lt;li&gt;152,940 previously jailbroken (at 4.x) iPad2 devices&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;Total: 953,232 new A5 jailbreaks in a little over 3 days&lt;/p&gt;
&lt;p&gt;The reason these numbers can be so precise is that one of the housekeeping activities that happens when you launch Cydia is a query to @saurik’s server for the list of available SHSH blobs.  (Even if you have none on file, the query is still made).&lt;/p&gt;
&lt;p&gt;Welcome to the jailbreak family!&lt;/p&gt;
&lt;p&gt;P.S. Remember the cardinal rule of jailbreaking: &lt;strong&gt;never update your firmware &lt;/strong&gt;until a new jailbreak is available.  This is especially true for A5 owners, who currently have no way of restoring to 5.0.1 once the 5.0.1 SHSH blob signing window is closed.&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/16366982367</link><guid>http://blog.iphone-dev.org/post/16366982367</guid><pubDate>Mon, 23 Jan 2012 21:44:14 +0300</pubDate></item><item><title>Corona A5 jailbreak nearly ready to pop!</title><description>&lt;p&gt;Ever since the December release of @pod2g’s “corona” untether for iOS 5.x on A4 and earlier devices, all eyes have been on the attempts to extend it to the A5 devices: the iPhone4S and iPad2.  Due to the combined efforts of @pod2g and members of the iPhone Dev Team and Chronic Dev Team, we’re nearly ready for a general release!  All technical hurdles dealing with the underlying technique have been overcome, and it’s now all about making the jailbreak as bug free as possible.&lt;/p&gt;
&lt;p&gt;On &lt;a href="http://pod2g-ios.blogspot.com/" target="_blank"&gt;his blog&lt;/a&gt;, @pod2g playfully nicknamed the combined effort a “dream team”.  It’s an ironic name, because the past few weeks have left everyone involved with very little sleep and the opportunity to dream :) But we’re now near the final stages of testing the public version of the jailbreak.  Please allow time to clean up any remaining bugs in the jailbreak clients.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Jailbreak programs:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;To be as flexible as possible, the A5 version of the corona jailbreak will take multiple forms:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Chronic Dev have incorporated the overall flow into a GUI that runs on your Mac or PC.  The goal is for the GUI to be enough for most cases.&lt;/li&gt;
&lt;li&gt;iPhone Dev have also incorporated the exact same flow into an alternative command-line interface (CLI). This will allow us to help users through individual steps of the jailbreak manually, to both help the user and help improve the overall flow.  Although the CLI will also allow the user to perform the entire jailbreak from beginning to end, we anticipate it will be more useful in debugging the occasional errors.  The CLI currently has over 20 individual options (in addition to the single “jailbreak” option) that should be useful during debug after the GUI release.&lt;/li&gt;
&lt;li&gt;Once all the bugs in the flow are worked out, we’ll also incorporate it into the redsn0w GUI (but still leave the CLI freely available too).  In order to maximize the chances of the jailbreak working for everyone, the redsn0w GUI will use native Apple iTunes libraries — this technique is slightly different than how the Chronic Dev GUI handles communications, and should provide nice combined coverage for all the odd computer configurations out there.&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Paypal Contributions:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Because there were so many different people and teams involved in the A5 corona release, we all felt the most equitable approach to any Paypal contributions should involve a single shared account.  &lt;strong&gt;If you do feel the desire to contribute to &lt;a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=DPFUPCEAYUD4L" target="_blank"&gt;the “dream team” Paypal account&lt;/a&gt;, it will be distributed to the members according to internally agreed-upon proportions :)&lt;/strong&gt;  (Please refer to this blog post for that specific &lt;a href="http://is.gd/39YMWg" target="_blank"&gt;http://is.gd/39YMWg&lt;/a&gt; link, to avoid frauds!)  The same link will be on both the Chronic Dev and iPhone Dev versions of the GUI.  This method seemed like the fairest to everyone involved!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Firmware:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The supported firmware versions will be:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPhone4S: 5.0 (9A334), 5.0.1 (9A405) and the “other” 5.0.1 (9A406)&lt;/li&gt;
&lt;li&gt;iPad2: 5.0.1 (9A405)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;iPhone4S owners looking to maximize their chances of achieving an eventual software-based carrier unlock should be staying at 5.0.&lt;/strong&gt;  Everyone else should be at 5.0.1.  If you’re an iPhone4S owner who already updated to 5.0.1, it’s too late to go back down to 5.0, but if you’re on 9A406 it is possible to downgrade the BB by going to the 9A405 version of 5.0.1 while the window is still open.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Support:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The overall flow used by the GUI and CLI to inject the A5 corona jailbreak has never been done before, and there may be unforeseen problems once it’s released to the public.  It’s very important for you to sync your data, photos, and music before attempting any version of this jailbreak.  We’ll be watching the comments section below for signs of any widespread problems, but please be aware that you jailbreak at your own risk! &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;When:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;del&gt;As mentioned at the start of this post: when testing has shown most of the bugs have been fixed!&lt;/del&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Updates:&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&lt;strong&gt;If the Absinthe webclip shows “Error establishing a database connection”, &lt;/strong&gt;please go to Settings, turn on VPN and wait instead.         
&lt;ul&gt;&lt;li&gt;Toggle VPN only AFTER Absinthe says it’s done, or it will not work. &lt;/li&gt;
&lt;li&gt;VPN SHOULD error and then reboot soon. If it does not, rerun Absinthe!&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;If you get a strange problem, we advise you to restore your iPhone with iTunes, if you can (i.e. if you’re not on 5.0 waiting for an eventual 4S unlock).&lt;/li&gt;
&lt;li&gt;The OS X version of the CLI mentioned in the post can be downloaded &lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/cinject_0.4.3.zip?attredirects=0&amp;d=1" target="_blank"&gt;here&lt;/a&gt;.  It’s primarily to help us debug specific issues, but tinkerers might like to play around with some of its advanced options!  More info is &lt;a href="http://musclenerd.com/cinject-readme.txt" target="_blank"&gt;here&lt;/a&gt;.
&lt;ul&gt;&lt;li&gt;Version 0.4.3 adds support for Windows users.  It also makes the “-j” jailbreak option much more functional :)  See the README.txt for usage.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;&lt;strong&gt; &lt;/strong&gt;&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/16162905938</link><guid>http://blog.iphone-dev.org/post/16162905938</guid><pubDate>Fri, 20 Jan 2012 10:18:00 +0300</pubDate></item><item><title>Untethered holidays</title><description>&lt;p&gt;@pod2g has created a terrific gift for iOS fans — an untethered 5.0.1 jailbreak for non-A5 devices! &lt;/p&gt;
&lt;p&gt;Many of you have already been following @pod2g’s &lt;a href="http://pod2g-ios.blogspot.com" target="_blank"&gt;blog&lt;/a&gt; where he’s been keeping everyone up to date on his progress.  And so you know that he recently decided to push the button on a release for all devices except the new iPhone4S and iPad2.  @pod2g’s untether involves two separate exploits and a few other “tricks” — and since he’s taken the @comex approach of doing nearly everything himself, you know his plate has been full these past few months!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A few days ago, @pod2g gave the untether to both the iPhone devteam and the chronic devteam.&lt;/strong&gt;  We’ve put it into redsn0w 0.9.10 and PwnageTool, and the chronic devteam put it into a Cydia package (the same set of exploits is in all three).&lt;/p&gt;
&lt;p&gt;Here are the basic steps for how to get it:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;The untether is for iOS 5.0.1 on iPhone3GS, iPhone4, iPhone4-CDMA, iPad1, iPod touch 3G, iPod touch 4G&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;If you have one of those devices and are not on 5.0.1 yet, update now!  The SHSH window is still open for 5.0.1  &lt;strong&gt;If you unlock via ultrasn0w or gevey&lt;/strong&gt;, make sure you only get to 5.0.1 via a custom IPSW!  See the guides at places like &lt;a href="http://iclarified.com" target="_blank"&gt;iClarified.com&lt;/a&gt; if you don’t know how.  &lt;strong&gt;Once you’re at 5.0.1, use the latest redsn0w 0.9.10 to both jailbreak and untether.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;If you’re already at 5.0.1 with a tethered jailbreak, you have two choices:&lt;/strong&gt; either run redsn0w 0.9.10 over your current jailbreak (deselect “Install Cydia” if you do that), or install the Cydia package prepared by the chronic devteam.  &lt;strong&gt;The patches are the same regardless of which you choose.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Some of you are using a hybrid 5.0/5.0.1 configuration.  If so, do not attempt to install this untether over that setup!  You will most likely get into a reboot cycle.  Do a sync and fresh restore to 5.0.1 then install the jailbreak + untether.&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;As mentioned earlier, @pod2g has spent months working on all the exploits and tricks in this untether, and many of you may be wondering how you can send donations.  Although the iPhone devteam itself doesn’t take donations, we thought it was appropriate to provide a link at the end of the redsn0w run for you to more easily donate directly to @pod2g if you wish (alternatively, you can go right &lt;a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;hosted_button_id=VLSHU7DG68H52" target="_blank"&gt;here&lt;/a&gt;).  There’s a link in the Cydia package for donating to the chronic devteam for the Cydia version of @pod2g’s untether.&lt;/p&gt;
&lt;p&gt;@pod2g is now looking for a way to extend this to A5 devices.  Because those devices cannot use geohot’s limera1n exploit to inject the untether, they require exploits above and beyond those used for this release.  Keep following pod2g on &lt;a href="http://twitter.com/pod2g" target="_blank"&gt;twitter&lt;/a&gt; or his blog for any progress reports!&lt;/p&gt;
&lt;div&gt;&lt;strong&gt;Update #2: &lt;/strong&gt;The b2 version of redsn0w includes the launchctl-related fix by @planetbeing as mentioned by @saurik &lt;a href="https://twitter.com/#!/saurik/status/151831295280947202" target="_blank"&gt;here&lt;/a&gt; and &lt;a href="https://twitter.com/#!/saurik/status/151851829074989056" target="_blank"&gt;here&lt;/a&gt;.  As usual, you can just re-run redsn0w in jailbreak mode over your existing 5.0.1 jailbreak (even a PwnageTool one), making sure to de-select “Install Cydia” if you do.  Always be sure to do a controlled “slide to power off” shutdown of your device before running redsn0w.&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Update #3: &lt;/strong&gt;The b3 version of redsn0w fixes a problem where re-running redsn0w over an existing jailbreak would cause MobileSubstrate-based apps to stop running until MS was installed again.  Now you can re-run the redsn0w jailbreak step without worrying about that (but still remember to de-select the “Install Cydia” option if it’s already installed).&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Update #4: &lt;/strong&gt;The b4 version of redsn0w incorporates the 5.0.1 fix for iBooks, and also for sporadic problems with launchctl.  Thanks to @xvolks for merging the iBooks (sandbox) fix from @comex’s github into the overall corona untether from @pod2g!  &lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Update #5: &lt;/strong&gt;redsn0w version b5 incorporates yet another fix for iBooks, this time involving DRM.  @planetbeing wrote a utility called “crazeles” that overcomes jailbreak detection by iBooks that would cause about 10% of images to show incorrectly.  This fix is similar to the “hunnypot” fix that @comex wrote for the 4.x jailbreak.  As usual, you can choose to install the fix either by re-running redsn0w over your existing jailbreak (de-select Cydia if you do that), or by installing the corona package from Cydia (it’s the same set of files no matter which way you choose).&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;TIP: &lt;/strong&gt;If auto-detection fails and redsn0w tells you no identifying data was found, you can always pre-select the &lt;a href="http://theiphonewiki.com/wiki/index.php?title=Firmware" target="_blank"&gt;appropriate 5.0.1 IPSW&lt;/a&gt; using “Extras-&gt;Select IPSW”.&lt;/div&gt;
&lt;div&gt;&lt;/div&gt;
&lt;hr&gt;&lt;div&gt;Here are the redsn0w download links&lt;strong&gt;:&lt;/strong&gt;&lt;/div&gt;
&lt;div&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.10b5.zip?attredirects=0&amp;d=1" target="_blank"&gt;redsn0w 0.9.10b5 for OS X&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.10b5.zip?attredirects=0&amp;d=1" target="_blank"&gt;redsn0w 0.9.10b5 for Windows&lt;/a&gt; (be sure to run in Administrator mode)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;PwnageTool Official Bittorent Releases&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://torrents.thepiratebay.org/6915059/PwnageTool_5.0.1.dmg.6915059.TPB.torrent" target="_blank"&gt;PwnageTool_5.0.1.dmg&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;SHA1 Sum = 32e90607378988cdebb6c76d3acf8ffac6366e35&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/p&gt;
&lt;p&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must.&lt;/p&gt;
&lt;p&gt;Mirror owners should email mirrors to blog@iphone-dev.org - please ensure that they are direct dmg download links only  (no rapidshare type sites please) and that your web-server can serve DMG MIME types properly. — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;/div&gt;</description><link>http://blog.iphone-dev.org/post/14857834236</link><guid>http://blog.iphone-dev.org/post/14857834236</guid><pubDate>Tue, 27 Dec 2011 13:55:00 +0300</pubDate><category>PwnageTool</category><category>redsn0w</category></item><item><title>pre-QUALifier</title><description>&lt;p&gt;&lt;img src="http://musclenerd.com/us124.png" alt="ultrasn0w 1.2.4" width="320" height="480" align="middle"/&gt;&lt;/p&gt;
&lt;p&gt;We’ve updated ultrasn0w to be compatible with iOS5, which came out a few days ago.  While ultrasn0w 1.2.4 (available now in Cydia) doesn’t add support for any new basebands, the update is required for any ultrasn0w unlockers trying out iOS5 (it remains backwards compatible though, so you should be able to use it no matter what firmware you have).  &lt;/p&gt;
&lt;p&gt;The supported basebands for the iPhone 3G and 3GS are 04.26.08, 05.11.07, 05.12.01, 05.13.04, and 06.15.00.  The baseband supported for the iPhone4 is 01.59.00.&lt;/p&gt;
&lt;p&gt;Remember, the only way to get to iOS5 while preserving your ultrasn0w-compatible baseband is by using a custom IPSW.  redsn0w now has the ability to create such a custom IPSW for you (at least on Macs…the same capability for Windows will be coming soon).&lt;/p&gt;
&lt;p&gt;The majority of people who use ultrasn0w at iOS5 right now will probably be those with old-bootrom iPhone3GS devices, since they already have an untethered jailbreak via redsn0w.  For everyone else, the iOS5 jailbreak is currently tethered and you need to “Just boot” tethered with redsn0w every time your phone reboots.  That’s not always easy to do if your phone reboots while away from home!&lt;/p&gt;
&lt;p&gt;&lt;strike&gt;&lt;strong&gt;Note: there’s a special “trick” that iPhone3GS owners with baseband 06.15 need for iOS5.&lt;/strong&gt;  During the new setup screens you see when you start iOS5 for the first time, you’ll be asked about Location Services.  &lt;strong&gt;Be sure to select “Disable Location Services” when asked!  Later on in the setup, you’ll have the chance to turn on Location Services again&lt;/strong&gt; when asked if you want to use “Find my iPhone”.  It’s fine to turn it back on at that point, if that’s your desire (or you can always go in and enable it in Settings.app).&lt;/strike&gt;&lt;/p&gt;
&lt;p&gt;Edit: The above “trick” is no longer needed as of v0.9.9b6 of redsn0w.&lt;/p&gt;
&lt;p&gt;Also, some iPhone3GS users with the 06.15 baseband may have tried to install iOS5 using a stock IPSW (even though you should never ever try to use a stock IPSW if you’re an ultrasn0w unlocker).  If you did try this, your baseband is probably in an inconsistent state, and you’ll need to reflash the 06.15 baseband again (using redsn0w).  Be very careful if you use redsn0w to reflash the iPad baseband — don’t interrupt the process! And please avoid using stock IPSWs in the future :)  &lt;strong&gt;Unlockers should never go near stock IPSWs.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you need to use redsn0w for any of the above tasks, please make sure it’s version 0.9.9b4 or higher, which is &lt;a href="http://blog.iphone-dev.org/redsn0w-iOS5" target="_blank"&gt;available here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Enjoy!&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/11430068008</link><guid>http://blog.iphone-dev.org/post/11430068008</guid><pubDate>Fri, 14 Oct 2011 12:01:00 +0400</pubDate></item><item><title>RIP</title><description>&lt;p&gt;&lt;img height="360" width="549" alt="Steve Jobs" src="http://musclenerd.com/steve.jpg"/&gt;&lt;/p&gt;

&lt;p&gt;&lt;iframe width="420" height="315" src="http://www.youtube.com/embed/UF8uR6Z6KLc" frameborder="0"&gt;&lt;/iframe&gt;&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/11081248963</link><guid>http://blog.iphone-dev.org/post/11081248963</guid><pubDate>Thu, 06 Oct 2011 04:38:50 +0400</pubDate></item><item><title>The coolest cat</title><description>&lt;p&gt;&lt;img src="http://xs1.iphwn.org/TomJerry2_468x342.jpg" alt="The coolest cat" width="468" height="342"/&gt;&lt;/p&gt;

&lt;p&gt;We loved the chase!  &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.apple.com/pr/library/2011/08/24Letter-from-Steve-Jobs.html" target="_blank"&gt;Good luck&lt;/a&gt;, Steve.&lt;/p&gt;
&lt;p&gt;Signed,&lt;br/&gt;Jailbreakers and tinkerers everywhere.&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/9352689002</link><guid>http://blog.iphone-dev.org/post/9352689002</guid><pubDate>Thu, 25 Aug 2011 03:40:00 +0400</pubDate></item><item><title>jailbreakme times 3</title><description>&lt;p&gt;Once again, &lt;a href="http://twitter.com/comex" target="_blank"&gt;@comex&lt;/a&gt; has resurrected &lt;a href="http://www.jailbreakme.com" target="_blank"&gt;&lt;a href="http://www.jailbreakme.com" target="_blank"&gt;http://www.jailbreakme.com&lt;/a&gt;&lt;/a&gt; for your jailbreaking ease and pleasure!&lt;/p&gt;
&lt;p&gt;@comex developed what is now the third installment (and his second) of jailbreakme.com, the easiest way to jailbreak your iPhone, iPod touch, and iPad (including the iPad2!).  No computer is necessary for jbme3.0…just browse to &lt;a href="http://www.jailbreakme.com" target="_blank"&gt;http://www.jailbreakme.com&lt;/a&gt; on your device and install it from there!&lt;/p&gt;
&lt;p&gt;While @comex and others have worked hard to make this as simple as possible, some people may have questions and problems may arise.  Rather than inundate comex with any questions over twitter, please consider using either our comments section below, or visit &lt;a href="http://jbqa.me" target="_blank"&gt;http://jbqa.me&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Please read &lt;a href="http://www.jailbreakme.com/#moreinfo" target="_blank"&gt;“More Information”&lt;/a&gt; on the jbme3.0 page for some basic background information and ways you can thank @comex&lt;/strong&gt;.  Here are some additional Q&amp;As beyond that:&lt;/p&gt;
&lt;p&gt;Q: Which devices and firmware versions are supported?&lt;br/&gt;A: In this initial release, the following configurations are supported:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPad1: 4.3 through 4.3.3&lt;/li&gt;
&lt;li&gt;iPad2: 4.3.3&lt;/li&gt;
&lt;li&gt;iPhone3GS: 4.3 through 4.3.3&lt;/li&gt;
&lt;li&gt;iPhone4: 4.3 through 4.3.3&lt;/li&gt;
&lt;li&gt;iPhone4-CDMA: 4.2.6 through 4.2.8&lt;/li&gt;
&lt;li&gt;iPod touch 3g: 4.3, 4.3.2, 4.3.3&lt;/li&gt;
&lt;li&gt;iPod touch 4g: 4.3 through 4.3.3&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;Q: Do the holes discovered by @comex put my device at risk?&lt;br/&gt;A: Yes.  &lt;strong&gt;We recommend installing “PDF Patcher 2” in Cydia once you’re jailbroken&lt;/strong&gt; to eliminate this risk (any firmware version). &lt;/p&gt;
&lt;p&gt;Q: How does jbme3.0 differ from the existing jailbreaks?&lt;br/&gt;A: jbme3.0 is entirely userland-based, from start to finish.  The A5 chip in the iPad2 has no iBoot or bootrom-level exploits yet, so tools like redsn0w, PwnageTool and sn0wbreeze can’t use the limera1n bootrom exploit to inject the jailbreak.  Even for those devices where limera1n works, jbme3.0 injects the jailbreak with a userland exploit.&lt;/p&gt;
&lt;p&gt;Q: If I’m already jailbroken on the latest firmware, is there any advantage to jailbreaking again?&lt;br/&gt;A: No, but you should c&lt;strong&gt;onsider showing this to your friends!  Spread the jailbreaking fever.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Q: Are the holes exploited by jbme3.0 closed in iOS5?&lt;br/&gt;A: The holes still exist in the iOS5 betas, but they’ll almost certainly be fixed by the time iOS5 is public.  However because the iPad2 had no public jailbreak yet, it probably wasn’t worth waiting until the fall to use them.  If history repeats itself though, there will be more holes and exploits.&lt;/p&gt;
&lt;p&gt;Q: Will I permanently lose the jailbreak if I need to restore my device?&lt;br/&gt;A: For all except the iPad2, saving your SHSH blobs should let you always restore your device to iOS versions where this jailbreak works.  The iPad2 is a little more complicated.  If you have a wifi-only iPad2 and saved SHSH blobs, you’re in good shape.  But&lt;strong&gt; if you have the GSM or CDMA iPad2, you won’t be able to restore to 4.3.3 or lower once Apple stops signing its baseband&lt;/strong&gt;.  There are a few ideas that might work to get around this limitation, but for now it’s best to assume there’s no going back to 4.3.3 once 4.3.4 is out for iPad2 GSM or CDMA owners. &lt;/p&gt;
&lt;p&gt;Q: I heard this new unionfs stuff is dangerous?&lt;br/&gt;A: Define dangerous :)  Seriously though, although unionfs is a huge improvement to the install time of the jailbreak, it is brand new code and there is the possibility something will go wrong.  Just keep regular backups of your media and content and you should be fine.  If there are any problems, they should appear within the first few days, so hold off and let “everyone else” test the waters if you’d like.&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/7295551750</link><guid>http://blog.iphone-dev.org/post/7295551750</guid><pubDate>Wed, 06 Jul 2011 10:43:00 +0400</pubDate><category>jailbreakme</category></item><item><title>Blob monster</title><description>&lt;p&gt;It looks like Apple is about to aggressively combat the “replay attacks” that have until now allowed users to use iTunes to restore to previous firmware versions using saved SHSH blobs.&lt;/p&gt;
&lt;p&gt;Those of you who have been jailbreaking for a while have probably heard us periodically warn you to “save your blobs” for each firmware using either Cydia or TinyUmbrella (or even the “copy from /tmp during restore” method for advanced users).  Saving your blobs for a given firmware on your specific device allows you to restore *that* device to *that* firmware even after Apple has stopped signing it.  That’s all about to change.&lt;/p&gt;
&lt;p&gt;Starting with the iOS5 beta, the role of the “APTicket” is changing — it’s being used much like the “BBTicket” has always been used.  The LLB and iBoot stages of the boot sequence are being refined to depend on the authenticity of the APTicket, which is uniquely generated at each and every restore (in other words, it doesn’t depend merely on your ECID and firmware version…it changes every time you restore, based partly on a random number).  This APTicket authentication will happen at every boot, not just at restore time.  Because only Apple has the crypto keys to properly sign the per-restore APTicket, replayed APTickets are useless.&lt;/p&gt;
&lt;p&gt;This will only affect restores starting at iOS5 and onward, and Apple will be able to flip that switch off and on at will (by opening or closing the APTicket signing window for that firmware, like they do for the BBTicket).  geohot’s limera1n exploit occurs before any of this new checking is done, so &lt;strong&gt;tethered jailbreaks will still always be possible&lt;/strong&gt; for devices where limera1n applies.  Also, &lt;strong&gt;restoring to pre-5.0 firmwares with saved blobs will still be possible&lt;/strong&gt; (but you’ll soon start to need to use older iTunes versions for that). Note that iTunes ultimately is *not* the component that matters here..it’s the boot sequence on the device starting with the LLB.&lt;/p&gt;
&lt;p&gt;Although it’s always been just “a matter of time” before Apple started doing this (they’ve always done this with the BBTicket), it’s still a significant move on Apple’s part (and it also dovetails with certain technical requirements of their upcoming OTA “delta” updates).&lt;/p&gt;
&lt;p&gt;Note: although there may still be ways to combat this, &lt;strong&gt;a beta period is really not the time or place to discuss them&lt;/strong&gt;.  We’re just letting you know what Apple has already done in their exisiting beta releases — they’ve stepped up their game!&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/6952986620</link><guid>http://blog.iphone-dev.org/post/6952986620</guid><pubDate>Mon, 27 Jun 2011 02:57:00 +0400</pubDate></item><item><title>Tic tac toe...</title><description>&lt;p&gt;… three in a row!  Apple released iOS 4.3.3 on Wednesday, and once again the untethered jailbreak exploit that &lt;a href="http://twitter.com/i0n1c" target="_blank"&gt;@i0n1c&lt;/a&gt; created for 4.3.1 still works.  That makes it an unprecedented three firmwares where the same userland exploit works.  We’re not exactly sure why Apple hasn’t fixed the hole yet, but we’re not complaining!&lt;/p&gt;
&lt;p&gt;Today’s PwnageTool and redsn0w incorporate @i0n1c’s port to 4.3.3 (it’s ironic that such a long-lasting untether doesn’t even have an official name!).  It also of course uses geohot’s limera1n bootrom exploit to inject the jailbreak. The 4.3.3 untether works on all devices that actually support 4.3.3 except for the iPad2:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPhone3GS&lt;/li&gt;
&lt;li&gt;iPhone4 (GSM)  &lt;/li&gt;
&lt;li&gt;iPhone4 (CDMA) (4.2.8 - See update #3)&lt;/li&gt;
&lt;li&gt;iPod touch 3G&lt;/li&gt;
&lt;li&gt;iPod touch 4G&lt;/li&gt;
&lt;li&gt;iPad1&lt;/li&gt;
&lt;li&gt;AppleTV2G (v4.3 8F202…see update #2 below for the v4.3 8F305 bundle)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;Some things to note:&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&lt;strong&gt;ultrasn0w unlockers must stay away from redsn0w!  Use only a custom IPSW to update to 4.3.3, to avoid updating your baseband.&lt;/strong&gt;  There are plenty of tutorials for both redsn0w and PwnageTool at sites like &lt;a href="http://iclarified.com" target="_blank"&gt;iClarified.com&lt;/a&gt;.  Or feel free to ask away in our comments section below.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ultrasn0w has been updated to v1.2.3 to be compatible with iOS 4.3.3 and earlier (the ultrasn0w update does not include any new baseband support!).&lt;/strong&gt;  Please reboot your iPhone using the normal “slide to power off” swipe after installing ultrasn0w 1.2.3.&lt;/li&gt;
&lt;li&gt;By popular demand, redsn0w now allows you to enable multitasking gestures (although most will find it useful only on iPads).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;iPad2 update&lt;/strong&gt;:  The iPad2 jailbreak remains under development.  As you may know, the original exploit @comex developed in the first week of the iPad2 release was mysteriously fixed by Apple within days of its development.  Partly because of this, don’t expect much public discussion of the iPad2 jailbreak until it’s actually finished and ready for release (and please avoid asking about it).  In all liklihood, it will be a userland exploit like the first (unreleased) one, not dependent on bootrom dumps.  The first one can’t be released even for those with the original 4.3 firmware due to legal (distribution) reasons.&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;As always, please feel free to ask for help or advice in our comment section, with our friendly moderators Confucious, sherif_hashim, dhlizard, Frank55, and subarurider (and many other very knowledgable commenters too!)&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #1&lt;/strong&gt;: PwnageTool and redsn0w have been updated to include a fix for the iPhone3GS/i4 side switch vibration issue (&lt;strong&gt;only for 4.3.3!&lt;/strong&gt;).  Thanks to @i0n1c for tracking this down (even though he doesn’t even have an iPhone!).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you’re already jailbroken at 4.3.3 (by either redsn0w rc15 or custom IPSW), you can install this fix simply by running redsn0w rc16 over your existing 4.3.3 jailbreak.&lt;/strong&gt;  Just uncheck the “Install Cydia” option and check any other options you want.  The fix will be installed no matter what you’ve selected.  This is safe for even ultrasn0w unlockers to do (because redsn0w itself won’t update your baseband…only an iTunes stock IPSW update/restore will do that).&lt;/p&gt;
&lt;p&gt;redsn0w rc16 has a few more improvements:  &lt;strong&gt;Windows 7 and Vista users should no longer need to set their CPU affinity…just run redsn0w as Administrator in XP compatiblity mode&lt;/strong&gt;.  Also, the “verbose boot” option for old-bootrom iPhone 3GS has been fixed for 4.3.3 (remember: old-bootrom 3GS users can even have custom bootlogos that show right at power-up).  Enjoy!&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #2&lt;/strong&gt;:  Apple released a minor update to iOS 4.3 for AppleTV2G (the IPSW name still says 4.3, but the build version changed from 8F202 to 8F305).  &lt;a href="http://twitter.com/i0n1c" target="_blank"&gt;@i0n1c&lt;/a&gt; was once again able to quickly port his original 4.3.1 untether (the exploit that wouldn’t die!) to this version.  &lt;/p&gt;
&lt;p&gt;If you do feel like updating to the “new” 4.3, you’ll need to drop &lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/AppleTV2%2C1_4.3_8F305.bundle.zip?attredirects=0&amp;d=1" target="_blank"&gt;this bundle&lt;/a&gt; into the correct folder in PwnageTool.app.  If you don’t know how to do that, there are lots of tutorials on the web, and we’d be glad to help in the comments below.  &lt;/p&gt;
&lt;p&gt;Thanks once again, @i0n1c!&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #3&lt;/strong&gt;: We’ve updated redsn0w (0.9.6rc18) to also include the Verizon iPhone4-CDMA iOS version 4.2.8 untether (which uses the &lt;a href="http://blog.iphone-dev.org/post/3314130778/whats-in-a-name" target="_blank"&gt;HFS exploit&lt;/a&gt;).&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #4&lt;/strong&gt;: redsn0w has been updated to 0.9.6rc19 to include changes in the way custom bundles are handled.  Now when you use a custom bundle, most of the normal jailbreak steps (like stashing and untethering) are skipped.  This makes it easier for custom bundles like the Verizon i4 jailbreakme &lt;a href="http://a.qoid.us/verizon-iphone.html" target="_blank"&gt;fix&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;redsn0w 0.9.6rc19:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.6rc19.zip?attredirects=0&amp;d=1" target="_blank"&gt;OS X&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.6rc19.zip?attredirects=0&amp;d=1" target="_blank"&gt;Windows&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;hr&gt;&lt;p&gt;&lt;strong&gt;PwnageTool Official BitTorrent Release&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt;&lt;a href="http://torrents.thepiratebay.org/6375459/PwnageTool_4.3.3.1.dmg.6375459.TPB.torrent" target="_blank"&gt;PwnageTool_4.3.3.1.dmg.6375459.TPB.torrent&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span&gt;SHA1 Sum = &lt;/span&gt;&lt;/strong&gt;2c8b17c28ae10295b72dabde30bb4b39b0e85821&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/p&gt;
&lt;p&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must.&lt;/p&gt;
&lt;p&gt;Mirror owners should email mirrors to blog@iphone-dev.org - please ensure that they are direct dmg download links only  (no rapidshare type sites please) and that your web-server can serve DMG MIME types properly. — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://mayask.com/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://mayask.com/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://mayask.com/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://ibloo.net/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://ibloo.net/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://ibloo.net/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://m0o.eu/d/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://m0o.eu/d/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://m0o.eu/d/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://mirror.omegarazer.ca/PwnageTool/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://mirror.omegarazer.ca/PwnageTool/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://mirror.omegarazer.ca/PwnageTool/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://smotrikino.net/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://smotrikino.net/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://smotrikino.net/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://mirror.StrongRoute.com/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://mirror.StrongRoute.com/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://mirror.StrongRoute.com/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.idevice.ro/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://www.idevice.ro/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://www.idevice.ro/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://white-buy.ru/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;&lt;a href="http://white-buy.ru/PwnageTool_4.3.3.1.dmg" target="_blank"&gt;http://white-buy.ru/PwnageTool_4.3.3.1.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><link>http://blog.iphone-dev.org/post/5239805497</link><guid>http://blog.iphone-dev.org/post/5239805497</guid><pubDate>Fri, 06 May 2011 12:57:00 +0400</pubDate><category>PwnageTool</category><category>redsn0w</category><category>ultrasn0w</category></item><item><title>The untether rolls on</title><description>&lt;p&gt;Only a few weeks after the 4.3.1 untether created by &lt;a href="http://twitter.com/i0n1c" target="_blank"&gt;@i0n1c&lt;/a&gt; was released, Apple pushed out firmware 4.3.2. Thankfully, it appears Apple didn’t have a chance to fix the hole used by @i0n1c’s untether, so he ported his code over to 4.3.2’s kernel.  Today’s redsn0w has been updated to include it.&lt;/p&gt;
&lt;p&gt;The&lt;strong&gt; 4.3.2 untether&lt;/strong&gt; works on all devices that actually support 4.3.2 except for the iPad2:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPhone3GS&lt;/li&gt;
&lt;li&gt;iPhone4 (GSM)  &lt;/li&gt;
&lt;li&gt;iPod touch 3G&lt;/li&gt;
&lt;li&gt;iPod touch 4G&lt;/li&gt;
&lt;li&gt;iPad1&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;redsn0w 0.9.6rc14:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.6rc14.zip?attredirects=0&amp;d=1" target="_blank"&gt;OS X redsn0w&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.6rc14.zip?attredirects=0&amp;d=1" target="_blank"&gt;Windows redsn0w&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;As always, ultrasn0w unlockers should stay away from redsn0w and only update their firmware through a custom IPSW.&lt;/strong&gt;   See update #3 below.&lt;/p&gt;
&lt;p&gt;For any questions or problems, please use our comments section below with our ever-helpful moderators Confucious, sherif_hashim, dhlizard, Frank55, and subarurider.&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strike&gt;Update #1: Until @i0n1c has a chance to fix the i4 version, we’ve removed the i4 untether from redsn0w (making it a tethered-only JB for i4 right now).&lt;/strike&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #2: &lt;/strong&gt;redsn0w rc14 includes the fixed i4 untether from @i0n1c.  You can re-run redsn0w rc14 right over the tethered rc13b to transform the i4 JB into an untethered one.&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #3: &lt;/strong&gt;PwnageTool 4.3.2 now includes the iOS 4.3.2 untether from @i0n1c.  (And look, the PwnageTool and iOS version numbers actually match!).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note that there’s a corresponding update to ultrasn0w, which has been bumped up to v1.2.2 to get along with iOS 4.3.2 (the ultrasn0w update does not include any new baseband support!).&lt;/strong&gt;  Please reboot your iPhone using the normal “slide to power off” swipe after installing ultrasn0w 1.2.2.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PwnageTool Official BitTorrent Release&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://torrents.thepiratebay.org/6340182/PwnageTool_4.3.2.dmg.6340182.TPB.torrent" target="_blank"&gt;PwnageTool_4.3.2.dmg.6340182.TPB.torrent&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span&gt;SHA1 Sum = &lt;/span&gt;&lt;/strong&gt;fdf9d7cba7872451bbca1ccae95a82cfefb352e7&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/p&gt;
&lt;p&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must.&lt;/p&gt;
&lt;p&gt;Mirror owners should email mirrors to blog@iphone-dev.org - please ensure that they are &lt;em&gt;direct dmg download links only&lt;/em&gt;  (no rapidshare type sites please) and that your web-server can serve &lt;em&gt;DMG MIME types&lt;/em&gt; properly.  — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://public.kioskofpiracy.org/iphone-dev/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://public.kioskofpiracy.org/iphone-dev/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://public.kioskofpiracy.org/iphone-dev/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://ikeygen.com/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://ikeygen.com/PwnageTool_4.3.dmg" target="_blank"&gt;http://ikeygen.com/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.vespaonline.de/iphone/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://www.vespaonline.de/iphone/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://www.vespaonline.de/iphone/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://iphoners.org/download/PwnageTool/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://iphoners.org/download/PwnageTool/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://iphoners.org/download/PwnageTool/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.vespaforum.com/iphone/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://www.vespaforum.com/iphone/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://www.vespaforum.com/iphone/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.youritechsupport.com/apple-files/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://www.youritechsupport.com/apple-files/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://www.youritechsupport.com/apple-files/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://cool.storybro.net/dl/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://cool.storybro.net/dl/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://cool.storybro.net/dl/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://evilvibes.com/downloads/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://evilvibes.com/downloads/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://evilvibes.com/downloads/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://downloads.ulfklose.de/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://downloads.ulfklose.de/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://downloads.ulfklose.de/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://public.stuff.hu/pwnagetool/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://idea4it.com/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://idea4it.com/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://idea4it.com/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.idevice.ro/d/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://www.idevice.ro/d/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://www.idevice.ro/d/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://mirror.omegarazer.ca/pwnagetool/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://mirror.omegarazer.ca/pwnagetool/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://mirror.omegarazer.ca/pwnagetool/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.packetcollision.com/files/PwnageTool/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://www.packetcollision.com/files/PwnageTool/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://www.packetcollision.com/files/PwnageTool/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://up.iNeal.ME/PwnageTool_4.3.2.dmg" target="_blank"&gt;&lt;a href="http://up.iNeal.ME/PwnageTool_4.3.2.dmg" target="_blank"&gt;http://up.iNeal.ME/PwnageTool_4.3.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><link>http://blog.iphone-dev.org/post/4731948971</link><guid>http://blog.iphone-dev.org/post/4731948971</guid><pubDate>Tue, 19 Apr 2011 04:02:00 +0400</pubDate><category>PwnageTool</category><category>redsn0w</category><category>ultrasn0w</category></item><item><title>Three years of pwnage(tool)</title><description>&lt;p&gt;Three years ago (almost to the day!), the first version of PwnageTool was released for firmware 1.1.4.  So today we’re excited to release another edition of both PwnageTool and redsn0w to bring an untethered jailbreak for Apple’s latest firmware, FW 4.3.1.&lt;/p&gt;
&lt;p&gt;The 4.3.1 untether exploit comes courtesy of Stefan Esser (&lt;a href="http://twitter.com/i0n1c" target="_blank"&gt;@i0n1c on twitter&lt;/a&gt;), a security researcher based in Germany.  Stefan has a &lt;a href="http://www.suspekt.org" target="_blank"&gt;long history of vulnerability research&lt;/a&gt;, and ironically his first contribution to the iPhone jailbreak community was &lt;strong&gt;improved security&lt;/strong&gt; — last year he beat Apple to the punch and implemented ASLR for jailbroken iPhones with his “antid0te” framework. We’re happy to see that Stefan then turned his iPhone attention over to an untethered jailbreak exploit!&lt;/p&gt;
&lt;p&gt;The 4.3.1 untether works on all devices that actually support 4.3.1 &lt;strong&gt;except for the iPad2&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPhone3GS&lt;/li&gt;
&lt;li&gt;iPhone4 (GSM)&lt;/li&gt;
&lt;li&gt;iPod touch 3G&lt;/li&gt;
&lt;li&gt;iPod touch 4G&lt;/li&gt;
&lt;li&gt;iPad1&lt;/li&gt;
&lt;li&gt;AppleTV 2G (PwnageTool only for now)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;The reason the untether won’t work as-is on the iPad2 is that it requires a bootrom or iBoot-level exploit to install, and the iPad2 is not susceptible to either the limera1n or SHAtter bootrom exploits.&lt;/p&gt;
&lt;p&gt;&lt;strike&gt;&lt;strong&gt;WARNING WARNING — ultrasn0w users don’t update yet! &lt;/strong&gt; We need to first release an update to ultrasn0w that fixes some incompatibilities when FW 4.3.1 is used on the older basebands supported by ultrasn0w.&lt;/strike&gt;  And remember once we do fix ultrasn0w for 4.3.1 (we’ll announce it here and on twitter),&lt;strong&gt; you must only get there via a custom IPSW&lt;/strong&gt; from PwnageTool, Sn0wbreeze or xpwn!  Don’t ever try to restore or update to a stock IPSW, or you’ll lose the unlock!&lt;/p&gt;
&lt;p&gt;For everyone else, redsn0w is the easier program to use (and redsn0w runs on both Mac and Windows).  Please check out places like &lt;a href="http://www.iclarified.com" target="_blank"&gt;iClarified&lt;/a&gt; for some excellent guides on how to use both PwnageTool and redsn0w.&lt;/p&gt;
&lt;p&gt;Feel free to ask for help in our comments section.  &lt;strong&gt;Thanks once again to our fantastic moderators for volunteering their time and knowledge and keeping order: Confucious, sherif_hashim, dhlizard, Frank55, and subarurider&lt;/strong&gt;!&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strike&gt;redsn0w 0.9.6rc9:&lt;/strike&gt;&lt;br/&gt; redsn0w 0.9.6rc12 (updated to rc12..details in Update #1 below):&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.6rc12.zip?attredirects=0&amp;d=1" target="_blank"&gt;OS X redsn0w&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.6rc12.zip?attredirects=0&amp;d=1" target="_blank"&gt;Windows redsn0w&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;hr&gt;&lt;p&gt;&lt;strong&gt;PwnageTool Official Bittorent Releases&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://torrents.thepiratebay.org/6293151/PwnageTool_4.3.dmg.6293151.TPB.torrent" target="_blank"&gt;PwnageTool_4.3.dmg.6293151.TPB.torrent&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span&gt;SHA1 Sum = &lt;/span&gt;&lt;/strong&gt;9e8ce7d4eb79b5f839efa0233893ef1a6a5e3c5c&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/p&gt;
&lt;p&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must.&lt;/p&gt;
&lt;p&gt;Mirror owners should email mirrors to blog@iphone-dev.org - please ensure that they are &lt;em&gt;direct dmg download links only&lt;/em&gt;  (no rapidshare type sites please) and that your web-server can serve &lt;em&gt;DMG MIME types&lt;/em&gt; properly.  — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.idevice.ro/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://www.idevice.ro/PwnageTool_4.3.dmg" target="_blank"&gt;http://www.idevice.ro/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://iphoners.org/download/PwnageTool/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://iphoners.org/download/PwnageTool/PwnageTool_4.3.dmg" target="_blank"&gt;http://iphoners.org/download/PwnageTool/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.3.dmg" target="_blank"&gt;http://public.stuff.hu/pwnagetool/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.vespaonline.de/iphone/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://www.vespaonline.de/iphone/PwnageTool_4.3.dmg" target="_blank"&gt;http://www.vespaonline.de/iphone/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.riccardomastellone.com/files/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://www.riccardomastellone.com/files/PwnageTool_4.3.dmg" target="_blank"&gt;http://www.riccardomastellone.com/files/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://dl.crzz.co/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://dl.crzz.co/PwnageTool_4.3.dmg" target="_blank"&gt;http://dl.crzz.co/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://jailbreakzone.com/files/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://jailbreakzone.com/files/PwnageTool_4.3.dmg" target="_blank"&gt;http://jailbreakzone.com/files/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://up.iNeal.ME/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://up.iNeal.ME/PwnageTool_4.3.dmg" target="_blank"&gt;http://up.iNeal.ME/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://repairmyiphonenyc.com/vl/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://repairmyiphonenyc.com/vl/PwnageTool_4.3.dmg" target="_blank"&gt;http://repairmyiphonenyc.com/vl/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://claytonbraasch.com/downloads/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://claytonbraasch.com/downloads/PwnageTool_4.3.dmg" target="_blank"&gt;http://claytonbraasch.com/downloads/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://leimobile.com/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://leimobile.com/PwnageTool_4.3.dmg" target="_blank"&gt;http://leimobile.com/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://tpsproductions.com/downloads/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://tpsproductions.com/downloads/PwnageTool_4.3.dmg" target="_blank"&gt;http://tpsproductions.com/downloads/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://youritechsupport.com/apple-files/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://youritechsupport.com/apple-files/PwnageTool_4.3.dmg" target="_blank"&gt;http://youritechsupport.com/apple-files/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://riccardomastellone.com/files/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://riccardomastellone.com/files/PwnageTool_4.3.dmg" target="_blank"&gt;http://riccardomastellone.com/files/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.appleturk.net/PwnageTool_4.3.dmg" target="_blank"&gt;&lt;a href="http://www.appleturk.net/PwnageTool_4.3.dmg" target="_blank"&gt;http://www.appleturk.net/PwnageTool_4.3.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #1:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Those running redsn0w may have noticed we enabled too many Settings options in some versions of the jailbreak (for instance, what you want your side switch to do, even if you have no side switch because you’re not using an iPad).   Release &lt;strike&gt;rc10&lt;/strike&gt; rc12 of redsn0w corrects that (you can just run it over your existing jailbreak…be sure to de-select Cydia to avoid package conflicts).&lt;/p&gt;
&lt;p&gt;Along the way, we’ve also added the option to enable boot animations…these animations can be installed via Cydia, but be sure to select which animation to use via the Settings-&gt;Bootlogo setting after you’ve downloaded an animation (and again, you can just run &lt;strike&gt;rc10&lt;/strike&gt; rc12 over your existing jailbreak…be sure to de-select Cydia to avoid package conflicts).&lt;/p&gt;
&lt;p&gt;(The boot animation we tested against was “Android Boot Logo”.  It correctly installs all the dependencies needed to run the animation at each boot).&lt;/p&gt;
&lt;p&gt;&lt;strike&gt;redsn0w 0.9.6rc10:&lt;/strike&gt;&lt;br/&gt; redsn0w_0.9.6rc12: (rc12 should fix any lingering issues with the boot animation)&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.6rc12.zip?attredirects=0&amp;d=1" target="_blank"&gt;OS X redsn0w&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.6rc12.zip?attredirects=0&amp;d=1" target="_blank"&gt;Windows redsn0w&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #2:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We’ve pushed out the 4.3.1 compatibility fix for ultrasn0w in Cydia — it’s now at version 1.2.1.  If you’re not already at 4.3.1 and you need the unlock, &lt;strong&gt;please be sure you understand how to get to 4.3.1 using a custom IPSW that doesn’t update your baseband.&lt;/strong&gt;  There are lots of guides for this (like at &lt;a href="http://iclarified.com" target="_blank"&gt;iClarified.com&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;This isn’t a new unlock!  It’s to allow those who are already using ultrasn0w to use FW 4.3.1.&lt;/strong&gt;  It also fixes the signal bar issue for those who aren’t using the unlock but retain an older baseband intentionally.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AFTER INSTALLING ULTRASN0W 1.2.1, PLEASE REBOOT YOUR iPHONE &lt;/strong&gt;using the normal “slide to power off” swipe.  T-Mobile users in the USA also should disable 3G mode in Settings-&gt;General-&gt;Network.&lt;/p&gt;
&lt;p&gt;A big thanks to @sbingner and @ronaldsb for helping with the testing of this update!&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/4332841631</link><guid>http://blog.iphone-dev.org/post/4332841631</guid><pubDate>Mon, 04 Apr 2011 09:00:00 +0400</pubDate><category>PwnageTool</category><category>redsn0w</category><category>ultrasn0w</category></item><item><title>What's in a name?</title><description>&lt;p&gt;What’s in a name?  Well in the case of an HFS volume name on iOS, an untether exploit — as the Chronic Dev Team revealed last week with an untether for the 4.2.1 jailbreak, which had &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;previously been a tethered JB&lt;/a&gt; for most recent devices since 4.2.1’s release in November.  With their permission, we’ve incorporated their 4.2.1 “feedface” untether into today’s PwnageTool 4.2.  &lt;strong&gt;This means iPhone unlockers can safely restore to a custom 4.2.1 pre-jailbroken IPSW and retain their current baseband and unlock&lt;/strong&gt;.  PwnageTool also supports all the other 4.2.1 devices other than iPod touch 2G:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPhone3G&lt;/li&gt;
&lt;li&gt;iPhone3GS&lt;/li&gt;
&lt;li&gt;iPhone4&lt;/li&gt;
&lt;li&gt;iPhone4-Verizon&lt;/li&gt;
&lt;li&gt;iPod touch 3G&lt;/li&gt;
&lt;li&gt;iPod touch 4G&lt;/li&gt;
&lt;li&gt;iPad&lt;/li&gt;
&lt;li&gt;AppleTV 2G&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;PwnageTool also includes two very recent improvements to the 4.2.1 JB&lt;/strong&gt;:  iBooks was just fixed by @comex and @pushfix last night so that it works as intended on DRMed books, and the wifi problem on AppleTV 2G was fixed by @nitotv, @DHowett, and @saurik.  Both of these fixes will also be available in upcoming Cydia package updates, so if you’re already jailbroken you can wait for those updates rather than restore and jailbreak again.&lt;/p&gt;
&lt;p&gt;The various components to the 4.2.1 untether (including a second exploit involving Mach-o headers) were worked out by 0naj, posixninja, and pod2g, and a nice writeup by 0naj is available &lt;a href="http://theiphonewiki.com/wiki/index.php?title=Incomplete_Codesign_Exploit" target="_blank"&gt; on the wiki&lt;/a&gt;. The actual injection method uses geohot’s &lt;a href="http://blog.iphone-dev.org/post/1280823486/limera1n-surprise" target="_blank"&gt;limerain exploit&lt;/a&gt; for most devices.  And even though 4.3 is just around the corner, the exploit used has already been closed in the latest 4.3 betas, so it made sense for the 4.2.1 untether to be released when it was.  It also appears that a security researcher named @i0n1c has a &lt;a href="http://twitter.com/i0n1c/status/37431014926065664" target="_blank"&gt;4.3 untether ready&lt;/a&gt; for when Apple releases the final 4.3 FW, so it may not be a long wait at all with 4.3!&lt;/p&gt;
&lt;p&gt;Feel free to ask for help in our comments section.  &lt;strong&gt;And thanks as always to our terrific moderators Confucious, sherif_hashim, dhlizard, Frank55, and subarurider&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Official Bittorent Releases&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;PwnageTool_4.2.dmg -&gt;&lt;strong&gt; &lt;a title="PwnageTool_4.2.dmg.6176918.TPB.torrent" href="http://torrents.thepiratebay.org/6176918/PwnageTool_4.2.dmg.6176918.TPB.torrent" target="_blank"&gt;PwnageTool_4.2.dmg.6176918.TPB.torrent&lt;/a&gt;&lt;br/&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span&gt;SHA1 Sum = &lt;/span&gt;&lt;/strong&gt;af365f5de19d7ee19cbe1c67b2f226996a46b3ac&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/p&gt;
&lt;p&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must.&lt;/p&gt;
&lt;p&gt;Mirror owners should email &lt;em&gt;direct dmg download links only &lt;/em&gt;(no rapidshare type sites please and please make sure that your web-server can serve DMG MIME types) to blog@iphone-dev.org — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a title="http://www.macniouz.fr/softwares/PwnageTool_4.2.dmg" href="http://www.macniouz.fr/softwares/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://www.macniouz.fr/softwares/PwnageTool_4.2.dmg" target="_blank"&gt;http://www.macniouz.fr/softwares/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://dl.twiios.com/pwnagetool/PwnageTool_4.2.dmg" href="http://dl.twiios.com/pwnagetool/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://dl.twiios.com/pwnagetool/PwnageTool_4.2.dmg" target="_blank"&gt;http://dl.twiios.com/pwnagetool/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://public.stuff.hu/pwnagetool/PwnageTool_4.2.dmg" href="http://public.stuff.hu/pwnagetool/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.2.dmg" target="_blank"&gt;http://public.stuff.hu/pwnagetool/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://crzz.co/dl/PwnageTool_4.2.dmg" href="http://crzz.co/dl/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://crzz.co/dl/PwnageTool_4.2.dmg" target="_blank"&gt;http://crzz.co/dl/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://www.yourdailyapple.net/downloads/PwnageTool_4.2.dmg" href="http://www.yourdailyapple.net/downloads/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://www.yourdailyapple.net/downloads/PwnageTool_4.2.dmg" target="_blank"&gt;http://www.yourdailyapple.net/downloads/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://applerama.ru/pwnagetool_4.2.dmg" href="http://applerama.ru/pwnagetool_4.2.dmg" target="_blank"&gt;&lt;a href="http://applerama.ru/pwnagetool_4.2.dmg" target="_blank"&gt;http://applerama.ru/pwnagetool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://riccardomastellone.com/files/PwnageTool_4.2.dmg" href="http://riccardomastellone.com/files/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://riccardomastellone.com/files/PwnageTool_4.2.dmg" target="_blank"&gt;http://riccardomastellone.com/files/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://up.iNeal.ME/PwnageTool_4.2.dmg" href="http://up.iNeal.ME/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://up.iNeal.ME/PwnageTool_4.2.dmg" target="_blank"&gt;http://up.iNeal.ME/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://claytonbraasch.com/downloads/PwnageTool_4.2.dmg" href="http://claytonbraasch.com/downloads/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://claytonbraasch.com/downloads/PwnageTool_4.2.dmg" target="_blank"&gt;http://claytonbraasch.com/downloads/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://www.zaone.ro/PwnageTool_4.2.dmg" href="http://www.zaone.ro/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://www.zaone.ro/PwnageTool_4.2.dmg" target="_blank"&gt;http://www.zaone.ro/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://maclovr.com/PwnageTool_4.2.dmg" href="http://maclovr.com/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://maclovr.com/PwnageTool_4.2.dmg" target="_blank"&gt;http://maclovr.com/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://cdn.nspwn.com/pwnagetool/PwnageTool_4.2.dmg" href="http://cdn.nspwn.com/pwnagetool/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://cdn.nspwn.com/pwnagetool/PwnageTool_4.2.dmg" target="_blank"&gt;http://cdn.nspwn.com/pwnagetool/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://stantheripper.com/PwnageTool_4.2.dmg" href="http://stantheripper.com/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://stantheripper.com/PwnageTool_4.2.dmg" target="_blank"&gt;http://stantheripper.com/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a title="http://smotrikino.net/PwnageTool_4.2.dmg" href="http://smotrikino.net/PwnageTool_4.2.dmg" target="_blank"&gt;&lt;a href="http://smotrikino.net/PwnageTool_4.2.dmg" target="_blank"&gt;http://smotrikino.net/PwnageTool_4.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><link>http://blog.iphone-dev.org/post/3314130778</link><guid>http://blog.iphone-dev.org/post/3314130778</guid><pubDate>Wed, 16 Feb 2011 00:16:00 +0300</pubDate><category>PwnageTool</category></item><item><title>Ultra-recycle</title><description>&lt;p&gt;Today we’re pleased to announce our free carrier unlock for iPhone3G/3GS owners with a baseband later than 05.13.04.  The unlock for that baseband exploited the AT+XAPP command, thanks to a crash initially discovered by @sherif_hashim (@Oranav also found this crash).  So what hole are we exploiting today, since Apple closed that AT+XAPP hole?  Well, we’re exploiting the exact same hole!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;It turns out that the very first iPad firmware 3.2.2 has baseband version 06.15.00 still vulnerable to AT+XAPP. The iPad baseband is built for the exact same baseband chip as the iPhone3G/3GS — they’re fully compatible!&lt;/strong&gt; Some of us have been running 06.15 for weeks now on our iPhones in preparation for this release.   (And some have known about this possibility of 06.15 on the iPhones for a while — kudos to @w1kedZ and @DHowett for keeping it hush!)&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Unlockers have been reporting mixed results about GPS functionality at 06.15.00.  Until we can track down what differentiates those who retain GPS vs. those who lose it, be conservative and assume you’ll lose GPS at 06.15.00. As we work on finding the cause (and possibly a fix), please report your personal findings in our comments section.  &lt;/em&gt;&lt;em&gt;(Update: early indications are that while 06.15.00 is capable of GPS, it will require some further hacks.  But please still be conservative and assume you will lose GPS at 06.15, in case the hacks don’t work).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;SIMPLIFIED ROUTE #1 (redsn0w for OSX + Windows):&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Read and fully understand the warning below.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;span&gt;&lt;strong&gt;If you have an old-bootrom 3GS and are already unlockable but want to get to 4.2.1, please wait til we release an “unofficial” bundle for you.  Read no further.&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Use redsn0w (see update #2) for OSX or Windows.  Enable the “Install iPad baseband” option and accept the warning.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;When the redsn0w ramdisk is finished, install ultrasn0w via Cydia.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enjoy!&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;SIMPLIFIED ROUTE #2 (PwnageTool for OSX):&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Read and fully understand the warning below.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;If you have an old-bootrom 3GS and are already unlockable but want to get to 4.2.1, please wait til we release an “unofficial” bundle for you.  Read no further.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Read update #1 for an updated 3GS bundle.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Download &lt;a href="http://appldnld.apple.com/iPad/061-8801.20100811.CvfR5/iPad1,1_3.2.2_7B500_Restore.ipsw" target="_blank"&gt;this IPSW&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Run PwnageTool to create a custom 4.1 IPSW.  Tell it you want to use the iPad baseband you just downloaded.  Restore to this custom IPSW.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Install ultrasn0w through Cydia&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enjoy!&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;FULL VERSION:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Since 06.15 is a higher version than 05.14 or 05.15 (where AT+XAPP is gone), anyone stuck at those versions can simply upgrade to 06.15 to unlock again! Luckily for us, Apple *still* provides the iPad FW 3.2.2 with this vulnerable baseband right &lt;a href="http://appldnld.apple.com/iPad/061-8801.20100811.CvfR5/iPad1,1_3.2.2_7B500_Restore.ipsw" target="_blank"&gt;from their own servers&lt;/a&gt;. (Grab it now, before they take it down!)&lt;/p&gt;
&lt;p&gt;We’ve been busy updating both PwnageTool and redsn0w to make the baseband update as seamless as possible.&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;First up is “PwnageTool 4.1.3 Unlock Edition”.  It has a special dialog box which will ask you if you want to update to the iPad baseband.  You must already have the iPad 3.2.2 IPSW on your computer (see the above link)….so just point PwnageTool at it (or let it find it on its own if you’re in “simple” mode).&lt;/li&gt;
&lt;li&gt;Directly after PwnageTool 4.1.3 is available, the official ultrasn0w repo &lt;a href="http://repo666.ultrasn0w.com" target="_blank"&gt;http://repo666.ultrasn0w.com&lt;/a&gt; will be updated with ultrasn0w 1.2, which covers iPhone 4 baseband 01.59.00 and iPhone 3G/3GS basebands 04.26.08, 05.11.07, 05.12.01, 05.13.04 and now 06.15.00.&lt;/li&gt;
&lt;li&gt;Finally, we’ll release an update to redsn0w today for those without Macs and can’t run PwnageTool.  The new redsn0w will give you the option to update your baseband to 06.15 too.&lt;/li&gt;
&lt;/ol&gt;&lt;hr&gt;&lt;p&gt;&lt;strong&gt;WARNING — YOU DO THIS AT YOUR OWN RISK!  PLEASE UNDERSTAND THE CONSEQUENCES OF UPDATING TO 06.15.&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;There is no way to come back down from 06.15, and there’s no hiding the baseband version from Apple. You’ll be voiding your warranty in a very obvious way.&lt;/li&gt;
&lt;li&gt;If some future baseband comes out with a critical fix, you won’t be able to update to it if it remains down in the 05.xx sequence (then again, you wouldn’t update to it if you wanted to keep your unlock anyway).&lt;/li&gt;
&lt;li&gt;Starting with FW 4.2.1 if you have 06.15 on your iPhone you won’t ever be able to restore to stock firmware (it will fail).  You’ll need to only restore to custom IPSWs (then again, if you’re unlocker you should already be doing that).&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;&lt;em&gt;Unlockers have been reporting mixed results about GPS functionality at 06.15.00.  Until we can track down what differentiates those who retain GPS vs. those who lose it, be conservative and assume you’ll lose GPS at 06.15.00. As we work on finding the cause (and possibly a fix), please report your personal findings in our comments section.  &lt;/em&gt;&lt;em&gt;(Update: early indications are that while 06.15.00 is capable of GPS, it will require some further hacks.  But please still be conservative and assume you will lose GPS at 06.15, in case the hacks don’t work).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Certainly don’t update to 06.15 if you don’t need to!  &lt;em&gt;&lt;strong&gt;Only do this if you need the unlock and you’re stuck on 05.14 or 05.15, and you’re willing to assume the above risks.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;This PwnageTool also contains a 4.2.1 bundle for iPhone3G owners…for all else, it’s still only 4.1.   If you have an iPhone3GS with an old bootrom, use redsn0w for an untethered 4.2.1 jailbreak (it can now install the iPad baseband too).  For all other devices, the 4.2.1 jailbreak is tethered only (use redsn0w for it), until @comex can work some untethering magic.  &lt;/p&gt;
&lt;p&gt;Please feel free to use our comments section for questions.  We have some very knowledgeable and helpful moderators:  &lt;em&gt;&lt;strong&gt;angiepangie, Confucious, sherif_hashim, dhlizard, and Frank55&lt;/strong&gt;!&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Official Bittorrent Releases&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;PwnageTool 4.1.3  - &lt;a href="http://torrents.thepiratebay.org/5994102/PwnageTool_4.1.3_Unlock_Edition.dmg.5994102.TPB.torrent" target="_blank"&gt;PwnageTool_4.1.3_Unlock_Edition.dmg.5994102.TPB.torrent&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;SHA1 Sum = adda6d882dce1b5117d01586037de289407e038a&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/p&gt;
&lt;p&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://8sv.de/dl/iphone/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://8sv.de/dl/iphone/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://8sv.de/dl/iphone/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://gumballtech.com/files/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://gumballtech.com/files/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://gumballtech.com/files/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://myblack.co.cc/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://myblack.co.cc/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://myblack.co.cc/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://cloud.xtra.me.uk/dev/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://cloud.xtra.me.uk/dev/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://cloud.xtra.me.uk/dev/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://xtra.me.uk/dev/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://xtra.me.uk/dev/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://xtra.me.uk/dev/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.zaone.ro/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://www.zaone.ro/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://www.zaone.ro/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.emreunal.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://www.emreunal.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://www.emreunal.com/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.cofo.us/idevice/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://www.cofo.us/idevice/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://www.cofo.us/idevice/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://ibloo.net/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://ibloo.net/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://ibloo.net/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://jacensolo.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://jacensolo.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://jacensolo.com/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://theplacefordee.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://theplacefordee.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://theplacefordee.com/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://loloke.hu/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://loloke.hu/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://loloke.hu/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://powerfree.pl/iphone/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://powerfree.pl/iphone/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://powerfree.pl/iphone/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.accesoriigsm.net/tools/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://www.accesoriigsm.net/tools/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://www.accesoriigsm.net/tools/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://cdn.nspwn.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://cdn.nspwn.com/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://cdn.nspwn.com/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://msby.org/iphone_dev/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://msby.org/iphone_dev/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://msby.org/iphone_dev/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.tomreinartz.com/DevTeam/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;&lt;a href="http://www.tomreinartz.com/DevTeam/PwnageTool_4.1.3_Unlock_Edition.dmg" target="_blank"&gt;http://www.tomreinartz.com/DevTeam/PwnageTool_4.1.3_Unlock_Edition.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://iNeal.ME/up/pt413.dmg" target="_blank"&gt;&lt;a href="http://iNeal.ME/up/pt413.dmg" target="_blank"&gt;http://iNeal.ME/up/pt413.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Mirror owners should email direct dmg download links only (no rapidshare type sites please) to blog@iphone-dev.org&lt;/strong&gt; — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #1: &lt;/strong&gt; There’s an error in the bundle for the iPhone3GS 4.1 that prevents the new baseband from being used.  If you know your way around OSX, please &lt;a href="http://iphwn.org/iPhone2,1_4.1_8B117.bundle.zip" target="_blank"&gt;download the fixed bundle&lt;/a&gt;, and unzip it if Safari hasn’t already done so.  Then “Show Package Contents” of PwnageTool.app, navigate to Contents-&gt;Resources-&gt;FirmwareBundles and drop it there.   Otherwise, please wait for the updated PwnageTool, or the OSX version of redsn0w coming soon.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #2:  &lt;/strong&gt;The new redsn0w 0.9.6beta5 is out.  It gives both Windows and OSX users the ability to flash the iPad 06.15 baseband on iPhone3G or iPhone3GS.  It fetches the baseband files directly from Apple for now (the only IPSW you ever point it at is the stock IPSW for the FW on your iPhone right now).  There may be a long delay while it’s doing this (their servers are currently getting pounded).&lt;/p&gt;
&lt;p&gt;If you do flash your baseband via redsn0w, &lt;strong&gt;please keep it plugged into USB the whole time&lt;/strong&gt;.  You don’t want your battery to die during the flash process!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #3: &lt;/strong&gt; For those Mac users with an old-bootrom 3GS who really know what they’re doing, &lt;a href="http://iphwn.org/advanced/iPhone2,1_4.2.1_8C148a.bundle.zip" target="_blank"&gt; here’s a minimal 3GS 4.2.1 bundle&lt;/a&gt; that will get you to 4.2.1 without updating your baseband.  Be sure to uncheck “Activate the iPhone” using Expert mode.  To actually jailbreak after you’ve restored with the help of that bundle, please use redsn0w.  If you don’t know how to drop a bundle into PwnageTool.app, please hold off on 4.2.1 until it’s untethered for everyone (or wait for a nice tutorial from somewhere like &lt;a href="http://iclarified.com" target="_blank"&gt;http://iclarified.com&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #4: &lt;/strong&gt;Our terrific moderators &lt;em&gt;&lt;strong&gt;angiepangie, Confucious, sherif_hashim, dhlizard, and Frank55&lt;/strong&gt;&lt;/em&gt; have done a stupendous job moderating &lt;strong&gt;7700 comments over just the first 12 hours (that’s 10 per minute for half a day!). &lt;/strong&gt;Hats off to them, and to all of our great commenters who rack up those + points for helping total strangers jailbreak and unlock their iPhones!   That’s what makes this community great :)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #5:  &lt;/strong&gt;Unlockers have been reporting mixed results about GPS functionality at 06.15.00.  Until we can track down what differentiates those who retain GPS vs. those who lose it, be conservative and assume you’ll lose GPS at 06.15.00.  As we work on finding the cause (and possibly a fix), please report your personal findings in our comments section.  &lt;em&gt;(Update: early indications are that while 06.15.00 is capable of GPS, it will require some further hacks.  But please still be conservative and assume you will lose GPS at 06.15, in case the hacks don’t work).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #6:  &lt;/strong&gt;Developer @sbingner (author of TetherMe) has made some excellent progress devising a new hactivation method that kills two birds with one stone for all you ultrasn0w unlockers.  His tool, “Subscriber Artificial Module (SAM)” tricks your iPhone and iTunes into creating legitimate activation tickets even though you’re unlocked with ultrasn0w.  This means you get the full benefit of push applications, and your battery life increases substantially.  If you’d like to try it out, check out &lt;a href="http://www.bingner.com/SAM.html" target="_blank"&gt;http://www.bingner.com/SAM.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;To help make it easier to try out @sbingner’s tool, we’ve updated redsn0w to include a new “Deactivate” option for the 3G and 3GS.  Use this option &lt;strong&gt;&lt;em&gt;*after*&lt;/em&gt;&lt;/strong&gt; you’ve installed SAM…it will remove the normal patches made to lockdownd and let SAM take over.  (sbingner plans on making a button to do this within SAMPrefs too).  &lt;strong&gt;&lt;em&gt;Great work, @sbingner!&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The new redsn0w with the “Deactivate” option is at:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.6rc8.zip?attredirects=0&amp;d=1" target="_blank"&gt;OSX&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.6rc8.zip?attredirects=0&amp;d=1" target="_blank"&gt;Windows&lt;/a&gt;  &lt;em&gt;&lt;strong&gt;(Windows 7 and Vista users, please run redsn0w as Administrator in “XP Compatiblity Mode”)&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;</description><link>http://blog.iphone-dev.org/post/1718400992</link><guid>http://blog.iphone-dev.org/post/1718400992</guid><pubDate>Mon, 29 Nov 2010 00:24:00 +0300</pubDate><category>PwnageTool</category><category>ultrasn0w</category></item><item><title>Thanksgiving with Apple</title><description>&lt;p&gt;With Turkey Day a few days off, today Apple publicly released FW version 4.2.1.  As always, &lt;strong&gt;ultrasn0w unlockers please stay far far away from this official firmware&lt;/strong&gt; (and all official firmware).  Wait for the ability to create custom 4.2.1. IPSWs that don’t update your baseband!  If you’re not an unlocker, read on!&lt;/p&gt;
&lt;p&gt;The best news of all is for owners of iPhone3G, older iPhone3GS, and non-MC iPod touch 2G.  Due to a combination of our original pwnage2 exploit, the arm7_go exploit, 24kpwn, and limera1n, your device is “just as jailbreakable as ever.”  You reap the full benefit of an untethered 4.2.1 jailbreak.&lt;/p&gt;
&lt;p&gt;Next are the owners of all the more recent devices.  The good news there is that &lt;strong&gt;due to geohot’s limera1n exploit, all recent devices can be jailbroken&lt;/strong&gt; (this will be true until Apple released new hardware that fixes geohot’s limerain exploit in the bootrom).  The bad news is that &lt;strong&gt;right now, the 4.2.1 jailbreak is *tethered* on all of these recent devices&lt;/strong&gt;.  A tethered jailbreak means that each time your device loses battery power or needs to be rebooted, you must attach it to a PC or Mac to boot into the jailbroken state.  @comex is working hard on a method that may untether the 4.2.1 jailbreak, but it &lt;strong&gt;may&lt;/strong&gt; require you to have your 4.1 SHSH blobs in order to use it.  No word on how much more effort it will take though (please don’t bug @comex about it!).  (We also have an alternative method that may work, but @comex’s method is much more elegant.)&lt;/p&gt;
&lt;p&gt;So when does all this 4.2.1 jailbreak action happen?  &lt;strike&gt;Well if you’re a JB developer or tinkerer, you’ve already probably used the &lt;a href="http://blog.iphone-dev.org/post/1452044444/redsn0w-limera1n-fun" target="_blank"&gt;redsn0w mentioned in our last post to jailbreak 4.2.1 and at least get SSH working&lt;/a&gt;.  But beyond that, there are still some last minute issues with MobileSubstrate and comex’s kernel patches that are being fixed.  We’ll tweet and post a blog update when it’s all available (we hate to give ETAs, but barring any unforeseen problems, probably later today).&lt;/strike&gt;  It happens “now’…see Update #1.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;In the meantime, please make sure you have your 4.1 SHSH blobs&lt;/strong&gt; for all your devices.  These will be important even for firmware beyond 4.1 (using both comex’s method and our alternative, depending on how each of them turn out.)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ultrasn0w unlock:&lt;/strong&gt;  After redsn0w is officially released with the new Cydia and kernel patches, we’ll be able to assess the unlock situation.  It’s already looking very promising though, so expect the unlock for the 3G and 3GS to be coming this week.  The i4 unlock is taking more effort though, and no further concrete info is available about that yet.&lt;/p&gt;
&lt;p&gt;Feel free to ask questions in our comments section below, where we’ve got some awesome new additional moderators —&lt;strong&gt; sherif_hashim, dhlizard, and Frank55&lt;/strong&gt;!&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #1:  &lt;/strong&gt;redsn0w version 0.9.6b6 is now available for your 4.2.1 jailbreaking pleasure.  Please read all the above to understand what this jailbreak currently entails.&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #2&lt;/strong&gt;:  The notion of a “tethered” jailbreak is pretty new to many people, so here’s a quick rundown on what to expect:&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;If you’re on an iPhone3G, old-bootrom iPhone3GS, or non-MC ipt2g, life is easy. redsn0w installed an untethered jailbreak and so nothing below applies.&lt;/li&gt;
&lt;li&gt;“Tethered” does &lt;strong&gt;not&lt;/strong&gt; mean you cannot boot at all without PC/Mac assistance.  &lt;strong&gt;If you have not installed any tweaks that hook into important programs like SpringBoard or CommCenter, your device will actually boot.&lt;/strong&gt;  However, jailbreak programs like Cydia won’t work (and Cydia may still have a white icon).  Also, certain built-in apps that had to be moved by Cydia will fail (Safari being the most noticeable example).&lt;/li&gt;
&lt;li&gt;If you’ve installed MobileSubstrate tweaks that hook into SpringBoard or other important programs, your boot will actually fail (you’ll get stuck at the Apple logo).  You need to use redsn0w to “Just boot tethered right now”.&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;Remember, @comex is working on a way to untether the 4.2.1 jailbreak.  Meanwhile, the above 3 points hopefully will make it all seem less confusing :)&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;&lt;strong&gt;Update #3:  &lt;/strong&gt;We’ve updated redsn0w to include “one-click” support for those of you running the tethered 4.2.1 jailbreak.  &lt;strong&gt;Using command-line arguments, you can now bypass the screens you’d normally see&lt;/strong&gt; as you use redsn0w to “Just boot tethered for now”.&lt;/p&gt;
&lt;p&gt;The available command line arguments are:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;-j to ask redsn0w to “Just boot now tethered for now” &lt;br/&gt;-i &lt;filename&gt; to specify your reference IPSW &lt;br/&gt;-o for old-bootrom iPod touch 2G and iPhone 3GS &lt;br/&gt;-b &lt;filename&gt; to specify your own boot logo png&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For example, to get redsn0w for Mac to do a tethered boot of an iPod touch 4G jailbroken at 4.2.1:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;open ~/Desktop/redsn0w.app —args -j -i ~/Desktop/iPod4,1_4.2.1_8C148_Restore.ipsw&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This assumes both redsn0w and the IPSW are on your OS X desktop, so modify as necessary!  &lt;strong&gt;Included in the zip is an example script file that you can double click on to launch redsn0w like this (the Windows example assumes everything is in C:\).&lt;/strong&gt;  (Mac users: please remember to change the permissions of your custom *.command files to allow execution.)&lt;/p&gt;
&lt;p&gt;This should help ease the pain of the tethered jailbreak until @comex comes up with a 4.2.1 untether (or for those of you with legit access to the 4.2b3 IPSW, until the “Jailbreak Monte” untether is out of beta)!&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;em&gt;&lt;strong&gt;PLEASE UPGRADE TO iTunes 10.1 FOR BEST RESULTS&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;WINDOWS 7 USERS SHOULD RUN redsn0w IN “XP COMPATIBILITY” MODE&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;Make sure you’re using a USB 2.0 port&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_mac_0.9.6rc8.zip?attredirects=0&amp;d=1" target="_blank"&gt;OS X&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sites.google.com/a/iphone-dev.com/files/home/redsn0w_win_0.9.6rc8.zip?attredirects=0&amp;d=1" target="_blank"&gt;Windows&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><link>http://blog.iphone-dev.org/post/1652053923</link><guid>http://blog.iphone-dev.org/post/1652053923</guid><pubDate>Tue, 23 Nov 2010 01:48:00 +0300</pubDate><category>redsn0w</category></item><item><title>redsn0w+limera1n fun</title><description>&lt;p&gt;It looks like geohot’s recent limera1n exploit for iPhone3GS/iPhone4/iPad/ipt3g/ipt4g/atv2g will be very beneficial to jailbreakers and unlockers for the next few months (at least).  geohot’s limera1n program and the alternative greenpois1on program both use his same exploit (although greenpois0n refuses to tell you that, FWIW), and hopefully SHAtter can be saved for some later device.&lt;/p&gt;
&lt;p&gt;In the meantime, we’ve also incorporated the limera1n exploit into redsn0w.  But we’ve added a few extras:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;custom bootlogos for iPhone3G/iPhone3GS/iPod2G users (with qualifying bootroms)&lt;/li&gt;
&lt;li&gt;an option that implements the “DFU” button in PwnageTool.  This button (which you can use from Windows) lets you prepare your device for a custom DFU.  Even if you’re purely a Windows user, you can get a trusted friend to run PwnageTool over your IPSW to create a custom IPSW.  You can now install that custom IPSW on your own Windows box, after you run this redsn0w version.&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;This latest redsn0w is available at:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strike&gt;OS X&lt;/strike&gt;  (See &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;our latest redsn0w post&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strike&gt;Windows&lt;/strike&gt; (See &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;our latest redsn0w post&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;For Windows users who have run redsn0w and chosen “Just enter pwned DFU mode right now”, your device is now completely vulnerable.  Running iTunes and selecting a custom IPSW from PwnageTool (choose it by pressing Shift+Restore)….you’ve now convinced your device and iTunes to restore to a custom firmware.  Congratulations!&lt;/p&gt;
&lt;p&gt;If you are timid about software and running these programs…please just wait!  Don’t jeopardize your carrier unlock for a firmware upgrade.  Wait for even easier methods than this latest redsn0w release. &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #1: &lt;/strong&gt; Today Apple released to developers the GM seed for 4.2.  Tinkerers will find that yesterday’s redsn0w jailbreaks today’s 4.2 GM seed, simply by pointing redsn0w at the 4.1 IPSW (rather than the 4.2 one).   &lt;strong&gt;Right now it mostly only makes sense for JB app developers to do that&lt;/strong&gt; because many apps (including Cydia itself) need to be updated for 4.2.  However, if all you want to do is enable afc2 (to use iFunBox or other file browsers), or to tweak settings like Battery % and Homescreen wallpapers, then go for it (if you have valid paid access to the GM seed).  Be sure to uncheck the Cydia box, though!  &lt;strong&gt;Ultrasn0w unlockers should stay very far away from this!!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #2&lt;/strong&gt;:  By all accounts, we’re within a few days of Apple’s official public release of Firmware 4.2.  Here’s what you need to know:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Thanks to geohot’s limera1n exploit, and our original pwnage2 exploit, and @pod2g’s ipod2g-MC exploit, absolutely &lt;strong&gt;all&lt;/strong&gt; devices at &lt;strong&gt;all&lt;/strong&gt; iOS firmware versions are capable of being jailbroken.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;untethered&lt;/em&gt; jailbreak of those very latest FWs and latest devices depends on @comex hacks.  His hacks so far extend only to 4.1 and 4.2beta3.  He’s working on a way to extend it to 4.2 and beyond.  Just wait for him to work out his method.&lt;/li&gt;
&lt;li&gt;iPhone 3G and 3GS unlockers &lt;strong&gt;will&lt;/strong&gt; be covered by our upcoming unlock.  Stay away from any updates to Apple FW until our official release and you’ll be okay.  Just stay away from all Apple IPSWs :)&lt;/li&gt;
&lt;li&gt;iPhone4 unlockers are not left out in the cold.  @sherif_hashim has found some very promising avenues to pursue.  Those will be explored as soon as possible after all the 4.2 madness.&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;What does this mean to you?&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you’re an unlocker, just stay where you are.  &lt;strong&gt;Please, just stay where you are.&lt;/strong&gt;  Any mistakes you make now may be permanent. &lt;/li&gt;
&lt;li&gt;If you only care about the jailbreak and you’re absolutely sure you have your personalized 4.1 SHSH hashes, feel free to experiment but keep in mind that any mistakes you make may result in your losing pictures or notes or bookmarks that you’d rather keep.  Honestly unless you love living on the bleeding edge, it’s better to just wait for official updates from Cydia/redsn0w/PwnageTool.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Don’t buy or donate to any unlock or jailbreak scammers&lt;/strong&gt;.  Every legitimate solution you will find for unlocks or jailbreaks will be offered without an extended hand.  &lt;strong&gt;That’s how the iPhone jailbreak/unlock community has succeeded.  It’s about freedom to do what you want with your $300 device —  not about donations, egos, tweets, or “interviews.”&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Update #3:   &lt;/strong&gt;&lt;em&gt;(Warning: if you use the ultrasn0w unlock, please read no further…this doesn’t apply to you yet!) &lt;/em&gt;We’ve made some updates to redsn0w to make it easier for jailbreak developers (and tinkerers) to get their programs ready for 4.2.1.  As noted above, the public version of Cydia (and MobileSubstrate too!) is not 4.2.1-compatible.  redsn0w will now let you install your own custom bundles independent of Cydia (the bundle can actually &lt;strong&gt;be&lt;/strong&gt; Cydia if you’ve compiled it on your own).  These bundles can be up to 15MB in size, and should be in the form of a gzip-compressed tar file.  &lt;/p&gt;
&lt;p&gt;The new redsn0w 0.9.6b3 is available at:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strike&gt;OS X&lt;/strike&gt;  (See &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;our latest redsn0w post&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strike&gt;Windows&lt;/strike&gt; (See &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;our latest redsn0w post&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;It’s very important that you get the file permissions and ownerships right in your custom redsn0w bundles.  To give you a practical example of such a bundle, here’s one that includes OpenSSH, OpenSSL, and the basic apt installer programs:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://sites.google.com/a/iphone-dev.com/files/home/SSH2_bundle.tgz?attredirects=0&amp;d=1" target="_blank"&gt;SSH bundle v2&lt;/a&gt; &lt;em&gt;(update: v2 has fixed permissions..you can just drop this one right in even if you installed the first version)&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;redsn0w has also been updated to recognize the 4.2.1GM IPSWs.  *However*, as noted above, the 4.2.x jailbreak is not yet untethered for most devices!  &lt;strong&gt;That means until someone like @comex comes up with a way to untether it, you must use redsn0w (or a similar utility) to boot your device into a jailbroken 4.2.1 state.  &lt;/strong&gt; (The only exceptions to this are the iPhone3G, non-MC iPod touch 2G, and old-bootrom iPhone3GS.  redsn0w will jailbreak those untethered!)&lt;/p&gt;
&lt;p&gt;With the above redsn0w and SSH bundle, jailbreak developers and tinkerers can jailbreak and SSH into their 4.2.1 devices, provided they’ve done a tethered boot (using redsn0w’s “Just boot tethered right now” option).&lt;/p&gt;
&lt;p&gt;Note:  The Cydia that’s included in 0.9.6b3 is the same one as in 0.9.6b2, and so it will *not* work on 4.2.1.  &lt;strong&gt;Don’t try installing it on 4.2.1!  Instead, use the SSH bundle, or compile Cydia on your own.&lt;/strong&gt;  If you’re familiar with the apt utilities, you can use “apt-get” to install many programs from the command line.  Be sure to do “apt-get update” first to refresh your sources!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;PLEASE CONSIDER THIS AN ADVANCED TOPIC!!  &lt;/em&gt;&lt;/strong&gt;It’s not meant for the masses because it involves rather nerdy things like command lines and tar files.  But for those who know how to use this new redsn0w feature, have fun!&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/1452044444</link><guid>http://blog.iphone-dev.org/post/1452044444</guid><pubDate>Mon, 01 Nov 2010 11:35:00 +0300</pubDate><category>redsn0w</category></item><item><title>20102010 event</title><description>&lt;p&gt;We’re pleased to release PwnageTool&lt;strike&gt; 4.1&lt;/strike&gt; 4.1.2 for Mac OS X (free of charge, blog ads, and donation requests — as always!).  &lt;strong&gt;Today’s big new addition to the jailbreak family is AppleTV 2G&lt;/strong&gt;, which was &lt;a href="http://is.gd/g9OdB" target="_blank"&gt;first shown jailbroken in its release week!&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;[Update: Version 4.1.2 should fix any issues that OS X 10.5.x users were seeing.  You only need to run this version if you’re at OS X 10.5.x and were seeing Cydia errors]&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;ULTRASN0W UNLOCKERS BEWARE!!  &lt;/strong&gt;&lt;/em&gt;&lt;em&gt;&lt;strong&gt;&lt;span&gt;&lt;em&gt;&lt;strong&gt;ULTRASN0W UNLOCKERS BEWARE!!&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/em&gt;&lt;span&gt;  The biggest mistake you can make (and it is a big one!) is lettings iTunes restore to the official IPSW — you’ll lose the unlock and won’t be able to go back!  You &lt;em&gt;&lt;strong&gt;must use Option-Restore&lt;/strong&gt;&lt;/em&gt;, not just the Restore button by itself.  Then navigate to your custom IPSW — not to the stock one!  If you accidentally started a restore to the official IPSW, unplug your iPhone immediately before the restore gets to the “Updating Firmware” step!&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Through a combination of the recently released geohot &lt;a href="http://blog.iphone-dev.org/post/1280823486/limera1n-surprise" target="_blank"&gt;limera1n exploit&lt;/a&gt; , &lt;a href="http://twitter.com/comex" target="_blank"&gt;@comex’s&lt;/a&gt; recently released pf kernel exploit, and our original pwnage2 exploit, PwnageTool &lt;strike&gt;4.1&lt;/strike&gt; 4.1.2 works untethered on these devices at firmware 4.1:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;AppleTV 2G&lt;/li&gt;
&lt;li&gt;iPad (firmware 3.2.2)&lt;/li&gt;
&lt;li&gt;iPod touch 4G&lt;/li&gt;
&lt;li&gt;iPod touch 3G&lt;/li&gt;
&lt;li&gt;iPhone4&lt;/li&gt;
&lt;li&gt;iPhone 3GS&lt;/li&gt;
&lt;li&gt;iPhone 3G&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;PwnageTool allows you to restore to a custom IPSW file.  For instance, &lt;strong&gt;you can restore to a pre-jailbroken firmware while simultaneously maintaining your current baseband (and thus your ultrasn0w carrier unlock)&lt;/strong&gt;.  You can also add whatever packages you want in the “Expert” mode of PwnageTool, if you wish to pre-install Cydia packages.   iPhone 3G users get the additional benefit of selecting their own boot and recovery logos, and features like multitasking and battery charge percentage.&lt;/p&gt;
&lt;p&gt;PwnageTool’s main advantage to ramdisk-based methods (limera1n, greenpois0n, redsn0w) is for unlockers — those that need to keep their current baseband and preserve their ultrasn0w unlock.  But in this new age of both bootrom- and userland-based exploits, it’s an excellent platform for continuing the jailbreak through all future firmwares.  More on this later!  In the meantime, please enjoy this free software and please provide any usage feedback in our comment section below.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AppleTV 2G users&lt;/strong&gt;:  Welcome to the JB family!  Right now, about all you can do is command-line stuff via ssh.  You also have afc2 available, so you can use tools like ifunbox to move files around.  These are the *very* early days of AppleTV 2G jailbreaking, so it’ll take some time for JB app developers to come up with methods to use your AppleTV 2G from the remote, versus the command line.  PS: Your ssh password is “alpine”…please change it when you can :)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Expert mode: &lt;/strong&gt;By popular demand, the IPSW file selection in Expert mode is now completely manual (doesn’t use Spotlight).  Just pick your IPSW file directly instead of waiting for the Spotlight search to complete.  &lt;strong&gt;In Expert mode, the default is to hacktivate &lt;/strong&gt;(“Activate the iPhone”), so if you have a legit SIM card be sure to deselect that option in Expert mode.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DFU button&lt;/strong&gt;:  That “DFU” button in PwnageTool is more than it looks like.  It guides you through the DFU process, but then also runs the appropriate exploit to convince your device and iTunes that all is legit.   The DFU button in PwnageTool is not just your average DFU.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Official Bittorrent Releases&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;PwnageTool 4.1.2 Torrent  - &lt;a href="http://torrents.thepiratebay.org/5904259/PwnageTool_4.1.2.dmg.5904259.TPB.torrent" target="_blank"&gt;PwnageTool_4.1.2.dmg.5904259.TPB.torrent&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;SHA1 Sum = 1c0d5ea45464e336fcb38c644dc125c3a16b5493&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unofficial Mirrors&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The following links are unofficial download mirrors, you download these archives at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these files. We do not check these links and we accept no responsibility with regard to the validity of the files, the other content that these links may provide or with the content that is on the third-party linked site.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;Always check the files that you have downloaded against our published SHA1 hash.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Mirror owners should email &lt;em&gt;direct dmg download links only &lt;/em&gt;(no rapidshare type sites please) to &lt;strong&gt;blog@iphone-dev.org&lt;/strong&gt; — please don’t place mirrors in the comments as they will be deleted.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="http://iphoneroot.com/download/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://iphoneroot.com/download/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://iphoneroot.com/download/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://download.touch-time.eu/PwnageTool_4.1.2.dmg%20" target="_blank"&gt;&lt;a href="http://download.touch-time.eu/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://download.touch-time.eu/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.kuru.at/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://www.kuru.at/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://www.kuru.at/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.kuruptor.com/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://www.kuruptor.com/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://www.kuruptor.com/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://gumballtech.com/files/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://gumballtech.com/files/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://gumballtech.com/files/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://zcr.me/f/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://zcr.me/f/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://zcr.me/f/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://download.sourcekills.com/files/devteam/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://download.sourcekills.com/files/devteam/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://download.sourcekills.com/files/devteam/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://public.stuff.hu/pwnagetool/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://public.stuff.hu/pwnagetool/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://flyhq.net/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://flyhq.net/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://flyhq.net/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.d4sys.com/download/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://www.d4sys.com/download/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://www.d4sys.com/download/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://chronzz.com/dl/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://chronzz.com/dl/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://chronzz.com/dl/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://theplacefordee.com/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://theplacefordee.com/PwnageTool_4.1.2.dmg" target="_blank"&gt;http://theplacefordee.com/PwnageTool_4.1.2.dmg&lt;/a&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;&lt;a href="http://www.project" target="_blank"&gt;http://www.project&lt;/a&gt;-&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;cestlavie&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;.&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;de&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;/&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;PwnageTool&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;_4.1.2.&lt;/a&gt;&lt;a href="http://www.project-cestlavie.de/PwnageTool_4.1.2.dmg" target="_blank"&gt;dmg&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><link>http://blog.iphone-dev.org/post/1359246784</link><guid>http://blog.iphone-dev.org/post/1359246784</guid><pubDate>Wed, 20 Oct 2010 19:32:00 +0400</pubDate><category>PwnageTool</category></item><item><title>Limera1n surprise</title><description>&lt;p&gt;After a few very dramatic days in the jailbreak community, geohot has come out of nowhere to release &lt;a href="http://limera1n.com/" target="_blank"&gt;limera1n&lt;/a&gt;.  It’s a bootrom-level jailbreak that works on the iPhone3GS, iPhone4, iPod touch 3G, iPod touch 4G, the iPad, and (technically) the AppleTV 2G.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DO NOT USE LIMERA1N IF YOU USE THE ULTRASN0W CARRIER UNLOCK — wait for PwnageTool to incorporate the limera1n exploit.&lt;/strong&gt;  This is so that you can avoid updating your baseband and losing the unlock (possibly forever).&lt;/p&gt;
&lt;p&gt;Limera1n uses a different exploit than SHAtter, and in fact covers more devices.  Although some may question geohot’s dramatic and competitive style, he obviously does have considerable skill pulling this together in just over a day (although he’s had the underlying exploit for months).  Credit also goes to @comex, who provides the untethered aspect of limera1n via another one of his growing list of kernel hacks.&lt;/p&gt;
&lt;p&gt;The release of limera1n has (thankfully!) averted the burning of 2 bootrom holes at once (both his and SHAtter). Releasing &lt;a href="http://blog.iphone-dev.org/post/1197198297/shattered-ipod-touch-4g" target="_blank"&gt;SHAtter&lt;/a&gt; now would be a complete waste of a perfectly good bootrom hole in light of limera1&lt;strong&gt;n&lt;/strong&gt;, and so it can be held until Apple closes limera1n’s hole.  While there’s no guarantee that Apple won’t also close SHAtter by then, it provides a ray of hope for devices after Apple’s bootrom respin.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update #1: &lt;/strong&gt;Because the “untethered” part of this jailbreak comes from a userland hack from @comex, &lt;strong&gt;you should still backup your SHSH hashes for 4.1&lt;/strong&gt;.  Do this by either letting Cydia keep them (“make my life easier”), or using Tiny Umbrella.   This way you can always come back to an untethered, jailbreakable 4.1 on your devices after Apple has closed their 4.1 signing window (they’ll close the 4.1 window once they push out their next firmware version). If you fail to do this and ever need to restore to 4.1 again, you can still jailbreak but it will be a tethered JB (you’ll need to connect to your computer to finish the booting process, each and every time).&lt;/p&gt;
&lt;p&gt;And remember: y&lt;strong&gt;ou can backup your 4.1 SHSH hashes without even being at 4.1 or even being jailbroken&lt;/strong&gt;, by using Tiny Umbrella.&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/1280823486</link><guid>http://blog.iphone-dev.org/post/1280823486</guid><pubDate>Sun, 10 Oct 2010 07:55:00 +0400</pubDate></item><item><title>SHAttered iPod touch 4G</title><description>&lt;p&gt;Those of you with Apple’s new iPod touch 4G, or those of you who bought another recent device after the jailbreakme.com exploit was closed, have probably heard about a brand new exploit called SHAtter.  The exploit (and payload) was &lt;a href="http://twitter.com/pod2g/status/23932796062" target="_blank"&gt;developed by @pod2g&lt;/a&gt; a few months after @p0sixninja of the Chronic Dev Team discovered the crash.  That team is hard at work bringing you a brand new tool to make use of the exploit.  It’s not the sort of thing that can be developed overnight so please be patient while waiting for &lt;a href="http://twitter.com/chronicdevteam" target="_blank"&gt;any announcements from them&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In the meantime, we’ve put @pod2g’s exploit into a beta version of PwnageTool to test the waters.  The SHAtter exploit was enough to convince the iPod touch 4G to restore to our custom IPSW.  The successful result is shown below!  It’s all working: customized Preferences to show battery percentage, Cydia, root shell…the works!&lt;/p&gt;
&lt;p&gt;
&lt;object height="385" width="640"&gt;
&lt;param value="http://www.youtube.com/v/aoX1Q8ym2J8?fs=1&amp;hl=en_US&amp;rel=0" name="movie"&gt;&lt;param value="true" name="allowFullScreen"&gt;&lt;param value="always" name="allowscriptaccess"&gt;&lt;embed height="385" width="640" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" src="http://www.youtube.com/v/aoX1Q8ym2J8?fs=1&amp;hl=en_US&amp;rel=0"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;/p&gt;
&lt;p&gt;Although PwnageTool was a useful first test of a full iPod 4G jailbreak via SHAtter, it’s really overkill compared to the faster tools being developed.  Its main use in PwnageTool will be for those with iPhone4’s, to allow updates while preserving the baseband and ultrasn0w carrier unlock.  In any event, this is another exciting time for iPhone and iPod touch users…the cat and mouse game continues!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;UPDATE #1: &lt;/strong&gt; It’s looking like SHAtter is going to be the gift that keeps on giving.  Even though the new AppleTV isn’t yet in people’s homes, the firmware is available on Apple’s normal public distribution servers and SHAtter has been used to decrypt its keys!  The main filesystem (“Mojave8M89.K66OS”) key for 018-8609-066.dmg is:&lt;/p&gt;
&lt;p&gt;31c700a852f1877c88efc05bc5c63e8c7f081c4cb28d024ed7f9b0dbc98c7e1406e499c6&lt;/p&gt;
&lt;p&gt;If you’re familiar with vfdecrypt, you can use that key to decrypt the image and mount it.  If you do so, feel free to use the comments section to discuss what you discover there :)  (And of course, thanks @pod2g!)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;UPDATE #2:  &lt;/strong&gt;It’s confirmed…SHAtter can trick Apple’s new AppleTV 2G into restoring to a pre-jailbroken IPSW from PwnageTool too!   Literally the only UI application on the ATV is Lowtide.app, but now the window is open for jailbroken apps of all varieties.  (Just like the early iPhone days, the &lt;strong&gt;only&lt;/strong&gt; apps you’ll see on the AppleTV will be jailbroken ones).  In the meantime, here’s a video showing root access (via ssh) into Apple’s new product.&lt;/p&gt;
&lt;p&gt;
&lt;object width="640" height="385"&gt;
&lt;param name="movie" value="http://www.youtube.com/v/adVp-IxcDHI?fs=1&amp;hl=en_US&amp;rel=0"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/adVp-IxcDHI?fs=1&amp;hl=en_US&amp;rel=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/1197198297</link><guid>http://blog.iphone-dev.org/post/1197198297</guid><pubDate>Mon, 27 Sep 2010 10:46:00 +0400</pubDate></item><item><title>redsn0wier</title><description>&lt;p&gt;We’ve released a beta version of redsn0w for the iPhone3G and iPod Touch 2G at FW 4.1 or 4.0.  It uses the same pwnage2 DFU-mode exploit that we’ve been using since the 2.x days.  It does not include the SHAtter exploit developed by pod2g.  Nothing new is revealed to Apple with this jailbreak.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;IF YOU USE THE ULTRASN0W UNLOCK, PLEASE WAIT FOR PWNAGETOOL TO SUPPORT 4.1.  DO NOT USE REDSN0W.&lt;/strong&gt;  That’s because to use redsn0w at 4.1, you need to already have updated to official 4.1 from Apple.  If you do that, you lose the ultrasn0w unlock (possibly forever).&lt;/p&gt;
&lt;p&gt;&lt;strike&gt;The Windows version needs further testing, so for now this is available only for Mac OS X x86.  The Windows version will come as soon as the bugs are ironed out.&lt;/strike&gt;&lt;/p&gt;
&lt;p&gt;Note: if you have an “MC” model of the ipt2g, your 4.1 jailbreak will be tethered…sorry!  (Consider rolling back to a FW supported by jailbreakme.com or spiritjb.com)&lt;/p&gt;
&lt;p&gt;===== What devices, platforms, and FW versions are supported? =====&lt;/p&gt;
&lt;p&gt;This BETA release supports:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;iPhone 3G and iPod touch 2G only (for now)&lt;/li&gt;
&lt;li&gt;Mac OS X x86 and Windows only (for now)&lt;/li&gt;
&lt;li&gt;4.1 or 4.0 firmware from Apple&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;                                        &lt;img src="http://xs1.iphwn.org/rs096b1.png" width="345" height="372" align="middle"/&gt;&lt;/p&gt;
&lt;p&gt;===== How do I use it? =====&lt;/p&gt;
&lt;p&gt;If you’ve already updated your device to 4.1 or 4.0, the next steps are:&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Launch the beta redsn0w 0.9.6b1&lt;/li&gt;
&lt;li&gt;Select your stock 4.1 or 4.0 ipsw (you’ve already used this to update your device to 4.1 or  4.0)&lt;/li&gt;
&lt;li&gt;Select “Install Cydia” and any of the other options shown above, then click “Next”.  Use DFU mode to install the jailbreak.&lt;/li&gt;
&lt;/ol&gt;&lt;p&gt;Note: If you choose to “Enable battery percentage”, you actually toggle that off and on via Settings-&gt;General-&gt;Usage.&lt;/p&gt;
&lt;p&gt;===== Download links =====&lt;/p&gt;
&lt;p&gt;Please do not directly link to these URLs because they’ll be changing according to bandwidth demands.&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;strike&gt;OS X&lt;/strike&gt;  (See &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;our latest redsn0w post&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strike&gt;Windows&lt;/strike&gt; (See &lt;a href="http://blog.iphone-dev.org/post/1652053923/thanksgiving-with-apple" target="_blank"&gt;our latest redsn0w post&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;Update: Any Windows users seeing “Waiting for reboot” for too long (more than 20 seconds or so), please try “shaking” the JB process by unplugging then replugging your USB cable (while letting redsn0w continue to run).  Also, try using a USB port “closer” to your computer (as opposed to on your monitor or behind another hub).  We’re still tweaking the Windows flow and so any feedback you can provide will help!&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/1160213613</link><guid>http://blog.iphone-dev.org/post/1160213613</guid><pubDate>Tue, 21 Sep 2010 10:05:00 +0400</pubDate><category>redsn0w</category></item><item><title>It's a trap!</title><description>&lt;p&gt;Today you’ll likely start seeing iTunes innocently offer you a new version of iOS…version 4.1.  Don’t accept it…it’s a trap!&lt;/p&gt;
&lt;p&gt;
&lt;object width="480" height="385"&gt;
&lt;param name="movie" value="http://www.youtube.com/v/dddAi8FF3F4?fs=1&amp;hl=en_US"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/dddAi8FF3F4?fs=1&amp;hl=en_US" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;/p&gt;
&lt;p&gt;This time of year there are lots of new iPhone owners, and not everybody knows that accepting new iOS updates is the surest way to lose your jailbreak and/or unlock.  While those of you who have Cydia or TinyUmbrella backups of your FW hashes will always be able to get back to 4.0.1 if you make this mistake, this doesn’t hold for unlockers. &lt;strong&gt;There’s currently no known way to revert your baseband — if you update your baseband you’ll lose the ultrasn0w unlock, possible forever.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Please stay away from this 4.1 release until a safe jailbreak procedure (which also preserves ultrasn0w) is developed and released.&lt;/p&gt;
&lt;p&gt;P.S.  There are a tiny number of iPhone3G owners who can revert their basebands due to a flaw in very early bootloaders…you will already know if you fit in this category!&lt;/p&gt;</description><link>http://blog.iphone-dev.org/post/1086032828</link><guid>http://blog.iphone-dev.org/post/1086032828</guid><pubDate>Wed, 08 Sep 2010 15:12:00 +0400</pubDate></item></channel></rss>

