<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=5ynt4x+3rr0r</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=5ynt4x+3rr0r"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/5ynt4x_3rr0r"/>
	<updated>2026-07-26T07:08:01Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Nonce&amp;diff=113379</id>
		<title>Nonce</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Nonce&amp;diff=113379"/>
		<updated>2021-05-05T00:08:46Z</updated>

		<summary type="html">&lt;p&gt;5ynt4x 3rr0r: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Nonce''' is a signing method that randomizes Apple's cryptographic signature hash blobs ([[SHSH]] blobs) and is used with the BBTicket (baseband signing ticket), the APTicket (firmware signing ticket), and SEP ([[Secure Enclave]]). A12 and newer use a technique known as 'Nonce Entangling' making it harder to save blobs.&lt;br /&gt;
&lt;br /&gt;
==Method==&lt;br /&gt;
The device bootloaders (baseband, firmware, and SEP) generate a random number at the restore, then send them to iTunes which sends them to Apple. Then Apple sends the APTicket / BBTicket [[SHSH]] certificate with the number generated. This level is the most critical: the number within the certificate is matched to the number generated on device, and if they match iTunes will prepare the matched certificate and finally will stitch the randomized blobs to the firmware. If the blobs don't match the restore will fail and the bootloaders will reject the certificate.&lt;br /&gt;
&lt;br /&gt;
==Usage==&lt;br /&gt;
===BBTicket===&lt;br /&gt;
*No iPod touch (or iPad Wi-Fi) has been signed with the BBTicket, since by definition it has no baseband.&lt;br /&gt;
*[[M68AP|iPhone]] (bootloaders can be neutered to cancel this signchecks). [[N82AP|iPhone 3G]], [[N88AP|iPhone 3GS]] and [[K48AP|iPad Wi-Fi+3G]] - if the baseband is higher or equal (or just higher on bootloader 3.9 on [[M68AP|iPhone]]). Some bootloaders allow downgrade of the baseband if it is still signed.&lt;br /&gt;
*[[N90AP|iPhone 4 (iPhone3,1)]], [[N92AP|iPhone 4 (iPhone3,3)]], [[N94AP|iPhone 4S]], and [[K94AP|iPad 2 (iPad2,2)]] and [[K95AP|iPad 2 (iPad2,3)]] - [[AT+XNONCE]] - restores the baseband only if Apple is still signing it. On bootloaders 2.8, 2.13, Trek and Phoenix, both the [[AT+XNONCE]] and the &amp;quot;higher or equal&amp;quot; checks happen.&lt;br /&gt;
&lt;br /&gt;
===APTicket===&lt;br /&gt;
*Devices with the [[S5L8900]] get [[SHSH]] blobs without APTicket on 4.0 - 4.2.1, even though they are not required and can be avoided with [[Pwnage]]+[[Pwnage 2.0]].&lt;br /&gt;
*Devices with the [[S5L8720]] get [[SHSH]] blobs without APTicket from 3.1.1 and on, even though [[Bootrom 240.4]] doesn't require them and they can be avoided with the [[0x24000 Segment Overflow]]&lt;br /&gt;
*Devices with the [[S5L8920]], [[S5L8922]], [[S5L8930]] and [[S5L8940]] got [[SHSH]] blobs without APTicket between 3.0 - 4.3.5, and they can not be avoided (except for the [[Bootrom 359.3]] with the 0x24000 Segment Overflow)&lt;br /&gt;
*Devices with the [[S5L8920]], [[S5L8922]], [[S5L8930]], [[S5L8940]], [[S5L8942]], [[S5L8945]], [[S5L8950]], and [[S5L8955]] get APTicket SHSH blobs on 5.0+. The SHSH requirement can not be avoided (except for the [[Bootrom 359.3]] with 0x24000 Segment Overflow), and the APTicket requirement can only be avoided on devices vulnerable to the [[limera1n Exploit]], or if the device is on iOS 5.1.1 or lower.&lt;br /&gt;
*Devices with the [[S5L8960]], [[S5L8965]], [[T7000]], [[T7001]], [[S7002]], [[S8000]], [[S8001]], [[S8003]], [[T8010]], and [[T8011]] get APTickets exclusively (with SepNonce, which also needs to match) and they cannot be avoided, but can be utilized with the prometheus method.&lt;br /&gt;
==Jailbreak difficulties==&lt;br /&gt;
With nonce signatures, signatures can't be cached, because signatures will not match if they have been reused. In other words, the widely used replay attack is no longer possible unless the nonce(s) (SepNonce + ApNonce on 64 bit, ApNonce only on 32 bit) the device generates matches the one on the APTicket.&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
*[[AT+XNONCE]]&lt;/div&gt;</summary>
		<author><name>5ynt4x 3rr0r</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:5ynt4x_3rr0r&amp;diff=112017</id>
		<title>User:5ynt4x 3rr0r</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:5ynt4x_3rr0r&amp;diff=112017"/>
		<updated>2021-04-09T02:51:37Z</updated>

		<summary type="html">&lt;p&gt;5ynt4x 3rr0r: Created page with &amp;quot;this is me.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;this is me.&lt;/div&gt;</summary>
		<author><name>5ynt4x 3rr0r</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=/private/var/containers&amp;diff=112015</id>
		<title>/private/var/containers</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=/private/var/containers&amp;diff=112015"/>
		<updated>2021-04-08T22:50:29Z</updated>

		<summary type="html">&lt;p&gt;5ynt4x 3rr0r: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;/private/var/mobile is a folder in the [[iOS]] filesystem. Inside it, the {{parent|private|var|containers|Bundle|Application|}} folder contains some app store apps, though others may be located in .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Children ==&lt;br /&gt;
&lt;br /&gt;
=== Folders ===&lt;br /&gt;
* {{ipfw|Bundle}}&lt;br /&gt;
** {{ipfw|Bundle/Application|Application}}&lt;br /&gt;
* {{ipfw|Data}}&lt;br /&gt;
* {{ipfw|Shared}}&lt;br /&gt;
* {{ipfw|Temp}}&lt;br /&gt;
&lt;br /&gt;
=== Files ===&lt;br /&gt;
(none)&lt;br /&gt;
&lt;br /&gt;
== Parents ==&lt;br /&gt;
{{parent|private|etc|}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Filesystem]]&lt;/div&gt;</summary>
		<author><name>5ynt4x 3rr0r</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=/private/var/containers&amp;diff=112014</id>
		<title>/private/var/containers</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=/private/var/containers&amp;diff=112014"/>
		<updated>2021-04-08T22:50:19Z</updated>

		<summary type="html">&lt;p&gt;5ynt4x 3rr0r: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;/private/var/mobile is a folder in the [[iOS]] filesystem. Inside it, the {{parent|private|var|containers|Bundle|Application|}} folder contains some app store apps, though others may be located in .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Children ==&lt;br /&gt;
&lt;br /&gt;
=== Folders ===&lt;br /&gt;
* {{ipfw|Bundle|}}&lt;br /&gt;
** {{ipfw|Bundle/Application|Application}}&lt;br /&gt;
* {{ipfw|Data}}&lt;br /&gt;
* {{ipfw|Shared}}&lt;br /&gt;
* {{ipfw|Temp}}&lt;br /&gt;
&lt;br /&gt;
=== Files ===&lt;br /&gt;
(none)&lt;br /&gt;
&lt;br /&gt;
== Parents ==&lt;br /&gt;
{{parent|private|etc|}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Filesystem]]&lt;/div&gt;</summary>
		<author><name>5ynt4x 3rr0r</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=/private/var/containers/Bundle/Application&amp;diff=112013</id>
		<title>/private/var/containers/Bundle/Application</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=/private/var/containers/Bundle/Application&amp;diff=112013"/>
		<updated>2021-04-08T22:47:58Z</updated>

		<summary type="html">&lt;p&gt;5ynt4x 3rr0r: Created page with &amp;quot;This folder contains some apps downloadable from the App Store. Some apps may be in {{parent|private|var|mobile|Containers}} instead.  == Folders == Folders in this folder...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This folder contains some apps downloadable from the [[App Store]]. Some apps may be in {{parent|private|var|mobile|Containers}} instead.&lt;br /&gt;
&lt;br /&gt;
== Folders ==&lt;br /&gt;
Folders in this folder will vary from system to system, as each folder is named after a unique UUID given to each app upon install.&lt;/div&gt;</summary>
		<author><name>5ynt4x 3rr0r</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=/private/var/containers&amp;diff=112012</id>
		<title>/private/var/containers</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=/private/var/containers&amp;diff=112012"/>
		<updated>2021-04-08T22:32:23Z</updated>

		<summary type="html">&lt;p&gt;5ynt4x 3rr0r: Created page with &amp;quot;/private/var/mobile is a folder in the iOS filesystem. Inside it, the {{parent|private|var|containers|Bundle|Application|}} folder contains most app store apps.   == Child...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;/private/var/mobile is a folder in the [[iOS]] filesystem. Inside it, the {{parent|private|var|containers|Bundle|Application|}} folder contains most app store apps.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Children ==&lt;br /&gt;
&lt;br /&gt;
=== Folders ===&lt;br /&gt;
{{parent|private|var|containers|Bundle|}}&lt;br /&gt;
{{parent|private|var|containers|Data}}&lt;br /&gt;
{{parent|private|var|containers|Shared}}&lt;br /&gt;
{{parent|private|var|containers|Temp}}&lt;br /&gt;
&lt;br /&gt;
=== Files ===&lt;br /&gt;
(none)&lt;br /&gt;
&lt;br /&gt;
== Parents ==&lt;br /&gt;
{{parent|private|etc|}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Filesystem]]&lt;/div&gt;</summary>
		<author><name>5ynt4x 3rr0r</name></author>
		
	</entry>
</feed>