<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Acwan</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Acwan"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/Acwan"/>
	<updated>2026-05-01T19:14:30Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=X-Gold_608_Unlock&amp;diff=5359</id>
		<title>X-Gold 608 Unlock</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=X-Gold_608_Unlock&amp;diff=5359"/>
		<updated>2009-11-04T02:01:05Z</updated>

		<summary type="html">&lt;p&gt;Acwan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Until recenlty, the 3G software [[unlock]] was the biggest missing piece of the iPhone community. It proved more difficult than the previous unlocks due to the fact that the [[Baseband_Bootloader | baseband bootloader]] is signature checked by the bootrom. [[The dev team]] has successfully unlocked baseband 04.26.08, by overriding carrier locks on-the-fly in RAM, therefore at boot the baseband bootrom can validate the bootloader, and the bootloader can validate the baseband. The unlock, code-name [[ultrasn0w]], was released to the public on 23 June 2009 for baseband 04.26.08 only [http://blog.iphone-dev.org/post/128573459/ultras-now].&lt;br /&gt;
&lt;br /&gt;
A new unlock named [[blacksn0w]], was released by [[geohot]] on 3 November 2009 for baseband 05.11.07.&lt;br /&gt;
&lt;br /&gt;
==Possible Methods==&lt;br /&gt;
===Class 1===&lt;br /&gt;
* Find an exploit in the [[Baseband Bootrom|bootrom]] to break the chain of trust. The Dev-Team successfully dumped the bootrom, but they won't release it as it's copyrighted code.&lt;br /&gt;
* Improve by several orders of magnitude the [[NCK Brute Force|NCK brute forcer]], and find a way to extract the CHIPID and NORID&lt;br /&gt;
* Find the theorized algorithm of NCK generation&lt;br /&gt;
&lt;br /&gt;
===Class 2===&lt;br /&gt;
* Use a [[SIM hacks|SIM hack]] such as the [[Unlock iPhone 3G with TurboSim|TurboSIM Unlock]]&lt;br /&gt;
* Find a way to patch running memory to &amp;quot;unlock&amp;quot; the phone on every bootup. This is how [[ultrasn0w]] works.&lt;br /&gt;
* Find an exploit in the [[Baseband Bootloader]] so you can downgrade the baseband, then use ultrasn0w. [[User:Geohot|Geohot]] and the [[iPhone Dev Team]] found (independently) an exploit in bootloader 5.8, but it isn't useful enough as only very-early (week&amp;lt;30) iPhone 3G units have bootloader 5.8.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
* Read about the [[X-Gold 608]]&lt;br /&gt;
* Read geohot's [http://iphonejtag.blogspot.com/2008/07/infineon-we-have-problem.html blog post]&lt;br /&gt;
* 25C3 presentation [http://events.ccc.de/congress/2008/Fahrplan/events/2976.en.html &amp;quot;Hacking the iPhone&amp;quot;] video [http://vimeo.com/2646755?pg=embed&amp;amp;sec=2646755 here]&lt;/div&gt;</summary>
		<author><name>Acwan</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=X-Gold_608_Unlock&amp;diff=5358</id>
		<title>X-Gold 608 Unlock</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=X-Gold_608_Unlock&amp;diff=5358"/>
		<updated>2009-11-04T02:00:25Z</updated>

		<summary type="html">&lt;p&gt;Acwan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Until recenlty, the 3G software [[unlock]] was the biggest missing piece of the iPhone community. It proved more difficult than the previous unlocks due to the fact that the [[Baseband_Bootloader | baseband bootloader]] is signature checked by the bootrom. [[The dev team]] has successfully unlocked baseband 04.26.08, by overriding carrier locks on-the-fly in RAM, therefore at boot the baseband bootrom can validate the bootloader, and the bootloader can validate the baseband. The unlock, code-name [[ultrasn0w]], was released to the public on 23 June 2009 for baseband 04.26.08 only [http://blog.iphone-dev.org/post/128573459/ultras-now].&lt;br /&gt;
&lt;br /&gt;
A new unlock named [[blacksn0w]], was released by Geohot on 3 November 2009 for baseband 05.11.07.&lt;br /&gt;
&lt;br /&gt;
==Possible Methods==&lt;br /&gt;
===Class 1===&lt;br /&gt;
* Find an exploit in the [[Baseband Bootrom|bootrom]] to break the chain of trust. The Dev-Team successfully dumped the bootrom, but they won't release it as it's copyrighted code.&lt;br /&gt;
* Improve by several orders of magnitude the [[NCK Brute Force|NCK brute forcer]], and find a way to extract the CHIPID and NORID&lt;br /&gt;
* Find the theorized algorithm of NCK generation&lt;br /&gt;
&lt;br /&gt;
===Class 2===&lt;br /&gt;
* Use a [[SIM hacks|SIM hack]] such as the [[Unlock iPhone 3G with TurboSim|TurboSIM Unlock]]&lt;br /&gt;
* Find a way to patch running memory to &amp;quot;unlock&amp;quot; the phone on every bootup. This is how [[ultrasn0w]] works.&lt;br /&gt;
* Find an exploit in the [[Baseband Bootloader]] so you can downgrade the baseband, then use ultrasn0w. [[User:Geohot|Geohot]] and the [[iPhone Dev Team]] found (independently) an exploit in bootloader 5.8, but it isn't useful enough as only very-early (week&amp;lt;30) iPhone 3G units have bootloader 5.8.&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
* Read about the [[X-Gold 608]]&lt;br /&gt;
* Read geohot's [http://iphonejtag.blogspot.com/2008/07/infineon-we-have-problem.html blog post]&lt;br /&gt;
* 25C3 presentation [http://events.ccc.de/congress/2008/Fahrplan/events/2976.en.html &amp;quot;Hacking the iPhone&amp;quot;] video [http://vimeo.com/2646755?pg=embed&amp;amp;sec=2646755 here]&lt;/div&gt;</summary>
		<author><name>Acwan</name></author>
		
	</entry>
</feed>