Forum

You must be logged in to post

 
Search Forums:


 




Dev Team mkaes two Steps toward iPhone 3G Unlock
Read original blog post

UserPost

10:32 am
October 6, 2008


Bezman

Admin

Trinidad & Tobago

posts 262

1

I have been really busy recently with life, work and everything NOT iPhone. It seems to have pissed a few people off, others sent me SMS/emails messages saying that I had obviously given up on iPhones and unlocking my 3G and I had no time for the blog etc. Well to be honest, I kind of have (had). Thankfully the Dev Team are still working on the iPhone 3G baseband Unlock and here is the latest that they have posted on their blog.

“We’ve been exploring different ideas with the 3G unlock, but this past weekend one of us hit a big snag. For whatever reason, all of our poking and prodding of the 3G baseband caused it to finally have a breakdown.   After one specific exploit run, all of a sudden our baseband stopped responding to the OS.   Even after multiple restore attempts, we were plagued with errors like this:

Somehow our software hacking had caused the baseband chip’s SPI bus to stop responding (so it looked like a hardware problem).   Even though BBUpdaterExtreme reported the correct baseband version, it failed basic tests like memtest:

If you’re familiar with the baseband revision history for the 3G iPhone, you may have noticed that the above captures were done at the original 01.45 baseband.  As dire (and hardware-related) as these messages sounded, though, there was a simple solution.  We just updated to 01.46 and then downgraded again (because we can run unsigned code on the baseband CPU) to 01.45.

We tried to recreate the problem by using the same exploit over again, but it doesn’t appear to be reproducible (which is actually disappointing, as it might have been exploitable).

Anyway, there you go…a random, technical snapshot of dev team work.”


One readers comments suggests that this may be the method that leads to a 3G baseband unlock if the Dev Team can re-create the error again and are able to upload unassigned code that can execute the unlock.

Saggy Old Man Nuts says:

You guys are geniuses!!! All you have to do at this point to recreate the exploit is to migrate in the reference file ICE2 to the CFI loader. Once you do that, the bootsector is going to change its boot mode from 0xCC to 0xFF. Which of course is going to allow you to send a flash ID to the Protocol configuration sect which ultimately will allow the core kernel to redirect and redistribute the command queue, preventing it from stalling on command 2215. Once all this is accomplished you can then run any unsigned code on the baseband. So there you go guys.
[via The DevTeam]

Read original blog post

 

About the MyTriniPhone.com forum

Currently Online:

2 Guests

Maximum Online: 18

Forums:

Groups: 6

Forums: 18

Topics: 246

Posts: 362

Members:

There are 134 members

There are 1 guests


Bezman has made 262 posts

Top Posters:

SRASC - 39

-LiNkS- - 13

hot blue - 8

modeminho - 8

g - 7

Administrator: Bezman


© Simple:Press Forum - Version 3.1.3 (Build 356)