<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Drg</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Drg"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/Drg"/>
	<updated>2026-05-06T09:40:38Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Siri&amp;diff=22098</id>
		<title>Siri</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Siri&amp;diff=22098"/>
		<updated>2011-10-30T20:39:57Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Siri]] is a voice control feature in the [[N94ap|iPhone 4S]], one of the main selling points for this device, although still in beta. A port to iPhone 4 and late model iPod touch has been completed by [http://twitter.com/#!/stroughtonsmith stroughtonsmith] with the help of [http://twitter.com/#!/chpwn chpwn].&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [http://twitter.com/stroughtonsmith Steve on Twitter]&lt;br /&gt;
&lt;br /&gt;
{{stub|Software}}&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Siri&amp;diff=22097</id>
		<title>Siri</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Siri&amp;diff=22097"/>
		<updated>2011-10-30T20:38:34Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Siri]] is a voice control feature in the [[N94ap|iPhone 4S]], one of the main selling points for this device, although still in beta. A port to iPhone 4 and late model iPod touch has been completed by [http://twitter.com/#!/stroughtonsmith stroughtonsmith] and [http://twitter.com/#!/chpwn chpwn].&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* [http://twitter.com/stroughtonsmith Steve on Twitter]&lt;br /&gt;
&lt;br /&gt;
{{stub|Software}}&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10416</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10416"/>
		<updated>2010-10-11T04:26:49Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Exploits */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which was developed by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
Details of the [[bootrom exploit]] to follow.&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
[[limera1n]]'s [[Untethered jailbreak|untethered]] userland exploit was obtained by [[User:Geohot|geohot]] under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10415</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10415"/>
		<updated>2010-10-11T04:26:14Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Basics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which was developed by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
[[limera1n]]'s [[Untethered jailbreak|untethered]] userland exploit was obtained by [[User:Geohot|geohot]] under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10414</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10414"/>
		<updated>2010-10-11T04:25:37Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Controversy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] was developped by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
[[limera1n]]'s [[Untethered jailbreak|untethered]] userland exploit was obtained by [[User:Geohot|geohot]] under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10413</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10413"/>
		<updated>2010-10-11T04:25:20Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Controversy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] was developped by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
[[limera1n]]'s [[Untethered jailbreak|untethered]] userland exploit was obtained by [[User:Geohot|geohot]]under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10412</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10412"/>
		<updated>2010-10-11T04:24:54Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Controversy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] was developped by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
[[limera1n]]'s [[Untethered jailbreak|untethered userland exploit was obtained by [[User:Geohot|geohot]]under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10411</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10411"/>
		<updated>2010-10-11T04:24:46Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Controversy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] was developped by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[limera1n]]'s [[Untethered jailbreak|untethered userland exploit was obtained by [[User:Geohot|geohot]]under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10410</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10410"/>
		<updated>2010-10-11T04:23:38Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Basics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] was developped by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10409</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10409"/>
		<updated>2010-10-11T04:21:58Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Basics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* [[limera1n]] does not use [[SHAtter]].&lt;br /&gt;
* [[limera1n]] uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* [[limera1n]] uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] obtained under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in [[limera1n]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10408</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10408"/>
		<updated>2010-10-11T04:20:45Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Basics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* This does not use [[SHAtter]].&lt;br /&gt;
* This uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* This uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] obtained under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving approval of the exploit being included in limerain.&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10403</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10403"/>
		<updated>2010-10-11T03:23:58Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Controversy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* This does not use [[SHAtter]].&lt;br /&gt;
* This uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* This uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] obtained under questionable circumstances from [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10402</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10402"/>
		<updated>2010-10-11T03:23:27Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Controversy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction==&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex's]] [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices.&lt;br /&gt;
* [[N88ap|iPhone 3GS]] (New [[bootrom]] is now working with Beta 3)&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]] (support announced, not released)&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
[[limera1n]] beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the [[limera1n]] exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues.&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br&amp;gt;&lt;br /&gt;
released today to get chronicdev to do the right thing&amp;lt;br&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br&amp;gt;&lt;br /&gt;
Mac coming soon&amp;lt;br&amp;gt;&lt;br /&gt;
follow the instructions in the box, sadly limera1n isn't one click&amp;lt;br&amp;gt;&lt;br /&gt;
that's the price of unpatchability&amp;lt;br&amp;gt;&lt;br /&gt;
as usual, donations appreciated but not required&amp;lt;br&amp;gt;&lt;br /&gt;
still in beta, pardon my ragged edges&amp;lt;br&amp;gt;&lt;br /&gt;
AppleTV is technically supported, but theres no apps yet&amp;lt;br&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]].&lt;br /&gt;
*[[User:Comex|comex]] - [[userland exploit]] that allows [[limera1n]] to run [[untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''md5'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 2&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 3&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|RC1 beta 4&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* This does not use [[SHAtter]].&lt;br /&gt;
* This uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]].&lt;br /&gt;
* This uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which [[User:Geohot|geohot]] obtained under questionable circumstances from [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
[[limera1n]] uses an undisclosed [[bootrom exploit]].&lt;br /&gt;
&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In [[recovery1]],&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU]], it uploads a [[payload]].&lt;br /&gt;
* In [[recovery2]], it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the [[limera1n]] exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released [[limera1n]], releasing[[SHAtter]] would uselessly disclose another[[bootrom exploit]] to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the [[limera1n]] exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. Geohot observed his [[limera1n]] exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining usefull in iPhone 5 should it not be disclosed at this time.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Actual Site http://limera1n.com/]&lt;br /&gt;
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10328</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=10328"/>
		<updated>2010-10-10T02:40:19Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Basics */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Release ==&lt;br /&gt;
On the 9th of October 2010 [[Limera1n]] was released, delaying the release of [[SHAtter]]. [[Limera1n]] is now in Beta 2. It only supports Windows at the moment and a large number of devices have issues.&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
&amp;lt;!-- DO NOT CHANGE ANY LINKS! THESE ARE HERE FOR A REASON. ONLY CHANGE TO ADD YOUR OWN MIRROR LINKS! --&amp;gt;&lt;br /&gt;
{| border=3&lt;br /&gt;
|-&lt;br /&gt;
| RC1 BETA2 for Windows from the official website. &amp;lt;!-- DO NOT CHANGE THIS LINK UNLESS THE LINK ON LIMERA1N.com CHANGES! --&amp;gt;&lt;br /&gt;
| [http://limera1n.com/limera1n.exe HTTP]&lt;br /&gt;
&amp;lt;!-- A MIRROR IS NOT NEEDED. THIS ISN'T A PAGE MEANT TO ENCOURAGE LIMERA1N! --&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Background Information ==&lt;br /&gt;
Limera1n is a jailbreak by [[User:Geohot|geohot]]. It is untethered on all supported devices, which include the following (but aren't necessarily limited to):&lt;br /&gt;
* [[N88ap|iPhone 3GS]]&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad 1G]]&lt;br /&gt;
* [[K66ap|Apple TV 2G]]&lt;br /&gt;
&lt;br /&gt;
It has been demonstrated multiple times by geohot, using blog posts on his now private blog. Geohot showed off a high-res picture of Cydia on an iPhone 4. [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png Image] He displayed an [[untethered jailbreak]] that met MuscleNerd's requirements for a good video on the iPod touch 3G: [http://www.youtube.com/watch?v=__TR86PLiHw YouTube Video] In addition, he demonstrated Cydia, blackra1n, and a verbose boot on an iPad (before Spirit was released): [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg Image]&lt;br /&gt;
&lt;br /&gt;
== Technical Information ==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* This does not use [[SHAtter]].&lt;br /&gt;
* This uses a [[bootrom]] exploit (different than the [[greenpois0n]] one) to achieve the tethered jailbreak and unsigned code execution&lt;br /&gt;
* This uses a userland exploit to provide untetheredness, which [[User:Geohot|geohot]] obtained under questionable circumstances from [[User:Comex|comex]].&lt;br /&gt;
* [[Chronic Dev (team)|Chronic Dev]] knows about this exploit and has confirmed its legitimacy&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
* The pwnage-type exploit appears to reside in DFU mode of the device.&lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following:&lt;br /&gt;
1) The tool has you boot into DFU mode, where the fun starts.&lt;br /&gt;
2) Limera1n.exe appears to upload a payload to your device and execute it at this time, to pwn out the signature checks.&lt;br /&gt;
3) The device reboots and is now pwned. From here, it uploads an exploit and a ramdisk. The ramdisk installs limera1n.app and possibly the untethered part of the jailbreak.&lt;br /&gt;
4) The device shuts down and upon reboot with no computer necessary, the device is jailbroken.&lt;br /&gt;
&lt;br /&gt;
== Controversy ==&lt;br /&gt;
The release of this jailbreak is specifically designed to pressure the Chronic Dev team into implementing the exploits in limera1n into greenpois0n. Now that geohot has released limera1n, [[SHAtter]] can't be released without major negative backlash from other hackers, as this would burn a bootrom exploit.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* http://limera1n.com/&lt;br /&gt;
* http://theiphonewiki.com/limera1n (cached copy)&lt;br /&gt;
* [http://www.twitlonger.com/show/6d31jr Info from cdevwill]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Sumdin sexay]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=M68AP&amp;diff=6104</id>
		<title>M68AP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=M68AP&amp;diff=6104"/>
		<updated>2010-04-21T17:13:18Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Jailbreak/Unlock Status */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:Jailbroken.PNG|right|thumb|Homescreen of a jailbroken iPhone 3G. Note that when it comes to the [[iPhone]] and [[iPhone 3G]], the OS remains exactly the same, as does the home screen. However, this does not apply to the [[iPod Touch]]|300px]]&lt;br /&gt;
&lt;br /&gt;
This is the original [[iPhone]]. It was released on June 29, 2007, it is an internet-connected multimedia smartphone designed and manufactered by Apple Inc, with a multi-touch screen. It does not have a physical keyboard, so a virtual keyboard is rendered onto the multi-touch screen. The iPhone functions as a camera phone, a media player and an internet client. The first generation includes Quad-Band GSM with EDGE, unlike the later versions with more advanced UMTS and HSDPA.&lt;br /&gt;
==Internals==&lt;br /&gt;
&amp;lt;i&amp;gt;See: [[M68ap (Internals)]][http://maltiel-consulting.com/iPhone_Chip_Components_maltiel_semiconductor.htm]&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Baseband ==&lt;br /&gt;
The [[iPhone]] uses the [[S-Gold 2]] baseband chip&lt;br /&gt;
&lt;br /&gt;
== Application Processor ==&lt;br /&gt;
It makes use of the [[S5L8900]] application processor. At the time, the [[iPhone]], [[iPhone 3G]], and [[iPod Touch]] all use this same processor.&lt;br /&gt;
&lt;br /&gt;
== [[Bluetooth]] ==&lt;br /&gt;
&lt;br /&gt;
Uses the CSR BlueCore4 Chip (BC41B41)&lt;br /&gt;
&lt;br /&gt;
== Differences between iPhone Models ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!Device&lt;br /&gt;
!Case Material&lt;br /&gt;
!Colours&lt;br /&gt;
!Dimensions&lt;br /&gt;
!Weight&lt;br /&gt;
!Capacity&lt;br /&gt;
!Processor Speed&lt;br /&gt;
!RAM&lt;br /&gt;
!Battery Life&lt;br /&gt;
!Initial Firmware&lt;br /&gt;
!Camera&lt;br /&gt;
!Voice Controls&lt;br /&gt;
!GPS&lt;br /&gt;
|-&lt;br /&gt;
|iPhone 2G&lt;br /&gt;
|Aluminium&lt;br /&gt;
|Aluminium&lt;br /&gt;
|4.5x2.4x0.46 in.&lt;br /&gt;
|4.8oz.&lt;br /&gt;
|4*/8/16**GB&lt;br /&gt;
|412MHz&lt;br /&gt;
|128Mb&lt;br /&gt;
|24h (Music), 7h (Video)&lt;br /&gt;
|1.0 (1A543a)&lt;br /&gt;
|2MP&lt;br /&gt;
|{{no}}&lt;br /&gt;
|{{no}}&lt;br /&gt;
|-&lt;br /&gt;
|iPhone 3G&lt;br /&gt;
|Plastic&lt;br /&gt;
|Black/White***&lt;br /&gt;
|4.5x2.4x0.48 in.&lt;br /&gt;
|4.7oz.&lt;br /&gt;
|8/16GB&lt;br /&gt;
|412MHz&lt;br /&gt;
|128Mb&lt;br /&gt;
|24h (Music), 7h (Video)&lt;br /&gt;
|2.0 (5A345)&lt;br /&gt;
|2MP&lt;br /&gt;
|{{no}}&lt;br /&gt;
|{{yes}}&lt;br /&gt;
|-&lt;br /&gt;
|iPhone 3GS&lt;br /&gt;
|Plastic&lt;br /&gt;
|Black/White&lt;br /&gt;
|4.5x2.4x0.48 in.&lt;br /&gt;
|4.8oz.&lt;br /&gt;
|16/32GB&lt;br /&gt;
|620MHz&lt;br /&gt;
|256Mb&lt;br /&gt;
|30h (Music), 10h (Video)&lt;br /&gt;
|3.0 (7A341)&lt;br /&gt;
|3.2MP Auto Focus&lt;br /&gt;
|{{yes}}&lt;br /&gt;
|{{yes}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(*) Discontinued on September 5, 2007&lt;br /&gt;
(**) Introduced on February 5, 2008&lt;br /&gt;
(***) 16GB version only&lt;br /&gt;
&lt;br /&gt;
== Jailbreak/Unlock Status ==&lt;br /&gt;
Naturally, as the iPhone 2G was a first generation device, it is one of the more hack-friendly iDevices. It is susceptible to [[Pwnage 2.0]] for an [[untethered jailbreak]], and will remain that way since it is a hardware-based exploit. The iPhone 2G [[unlock]] is also available and is unfixable by Apple. The [[iPhone Dev Team]] created [[BootNeuter]] which can remove restrictions the [[Baseband Bootloader]] imposes and unlock the iPhone 2G no matter what.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
*[http://maltiel-consulting.com/iPhone_Chip_Components_maltiel_semiconductor.htm iPhone semiconductor components]&lt;br /&gt;
*[http://www.eetasia.com/ART_8800470713_499488_NT_d06c93ea.HTM Analysts crack open the iPhone, reveal chip suppliers]&lt;br /&gt;
*[http://www.anandtech.com/mac/showdoc.aspx?i=3026&amp;amp;p=1 Apple's iPhone Dissected: We did it, so you don't have to]&lt;br /&gt;
*[http://www.hardwarebook.info/IPhone Hwb iPhone]&lt;br /&gt;
*[http://ivitto.wordpress.com/ iVitto's Blog]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=M68AP&amp;diff=6103</id>
		<title>M68AP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=M68AP&amp;diff=6103"/>
		<updated>2010-04-21T17:11:46Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Differences between iPhone Models */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:Jailbroken.PNG|right|thumb|Homescreen of a jailbroken iPhone 3G. Note that when it comes to the [[iPhone]] and [[iPhone 3G]], the OS remains exactly the same, as does the home screen. However, this does not apply to the [[iPod Touch]]|300px]]&lt;br /&gt;
&lt;br /&gt;
This is the original [[iPhone]]. It was released on June 29, 2007, it is an internet-connected multimedia smartphone designed and manufactered by Apple Inc, with a multi-touch screen. It does not have a physical keyboard, so a virtual keyboard is rendered onto the multi-touch screen. The iPhone functions as a camera phone, a media player and an internet client. The first generation includes Quad-Band GSM with EDGE, unlike the later versions with more advanced UMTS and HSDPA.&lt;br /&gt;
==Internals==&lt;br /&gt;
&amp;lt;i&amp;gt;See: [[M68ap (Internals)]][http://maltiel-consulting.com/iPhone_Chip_Components_maltiel_semiconductor.htm]&amp;lt;/i&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Baseband ==&lt;br /&gt;
The [[iPhone]] uses the [[S-Gold 2]] baseband chip&lt;br /&gt;
&lt;br /&gt;
== Application Processor ==&lt;br /&gt;
It makes use of the [[S5L8900]] application processor. At the time, the [[iPhone]], [[iPhone 3G]], and [[iPod Touch]] all use this same processor.&lt;br /&gt;
&lt;br /&gt;
== [[Bluetooth]] ==&lt;br /&gt;
&lt;br /&gt;
Uses the CSR BlueCore4 Chip (BC41B41)&lt;br /&gt;
&lt;br /&gt;
== Differences between iPhone Models ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
!Device&lt;br /&gt;
!Case Material&lt;br /&gt;
!Colours&lt;br /&gt;
!Dimensions&lt;br /&gt;
!Weight&lt;br /&gt;
!Capacity&lt;br /&gt;
!Processor Speed&lt;br /&gt;
!RAM&lt;br /&gt;
!Battery Life&lt;br /&gt;
!Initial Firmware&lt;br /&gt;
!Camera&lt;br /&gt;
!Voice Controls&lt;br /&gt;
!GPS&lt;br /&gt;
|-&lt;br /&gt;
|iPhone 2G&lt;br /&gt;
|Aluminium&lt;br /&gt;
|Aluminium&lt;br /&gt;
|4.5x2.4x0.46 in.&lt;br /&gt;
|4.8oz.&lt;br /&gt;
|4*/8/16**GB&lt;br /&gt;
|412MHz&lt;br /&gt;
|128Mb&lt;br /&gt;
|24h (Music), 7h (Video)&lt;br /&gt;
|1.0 (1A543a)&lt;br /&gt;
|2MP&lt;br /&gt;
|{{no}}&lt;br /&gt;
|{{no}}&lt;br /&gt;
|-&lt;br /&gt;
|iPhone 3G&lt;br /&gt;
|Plastic&lt;br /&gt;
|Black/White***&lt;br /&gt;
|4.5x2.4x0.48 in.&lt;br /&gt;
|4.7oz.&lt;br /&gt;
|8/16GB&lt;br /&gt;
|412MHz&lt;br /&gt;
|128Mb&lt;br /&gt;
|24h (Music), 7h (Video)&lt;br /&gt;
|2.0 (5A345)&lt;br /&gt;
|2MP&lt;br /&gt;
|{{no}}&lt;br /&gt;
|{{yes}}&lt;br /&gt;
|-&lt;br /&gt;
|iPhone 3GS&lt;br /&gt;
|Plastic&lt;br /&gt;
|Black/White&lt;br /&gt;
|4.5x2.4x0.48 in.&lt;br /&gt;
|4.8oz.&lt;br /&gt;
|16/32GB&lt;br /&gt;
|620MHz&lt;br /&gt;
|256Mb&lt;br /&gt;
|30h (Music), 10h (Video)&lt;br /&gt;
|3.0 (7A341)&lt;br /&gt;
|3.2MP Auto Focus&lt;br /&gt;
|{{yes}}&lt;br /&gt;
|{{yes}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(*) Discontinued on September 5, 2007&lt;br /&gt;
(**) Introduced on February 5, 2008&lt;br /&gt;
(***) 16GB version only&lt;br /&gt;
&lt;br /&gt;
== Jailbreak/Unlock Status ==&lt;br /&gt;
Naturally, as the iPhone 2G was a first generation device, it is one of the more hack-friendly iDevices. It is susceptible to [[Pwnage 2.0]] for an [[untethered jailbreak]], and will remain that way since it is a hardware-based exploit. The iPhone 2G [[unlock]] was also defeated. The [[iPhone Dev Team]] created [[BootNeuter]] which can remove restrictions the [[Baseband Bootloader]] imposes and unlock the iPhone 2G no matter what.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
*[http://maltiel-consulting.com/iPhone_Chip_Components_maltiel_semiconductor.htm iPhone semiconductor components]&lt;br /&gt;
*[http://www.eetasia.com/ART_8800470713_499488_NT_d06c93ea.HTM Analysts crack open the iPhone, reveal chip suppliers]&lt;br /&gt;
*[http://www.anandtech.com/mac/showdoc.aspx?i=3026&amp;amp;p=1 Apple's iPhone Dissected: We did it, so you don't have to]&lt;br /&gt;
*[http://www.hardwarebook.info/IPhone Hwb iPhone]&lt;br /&gt;
*[http://ivitto.wordpress.com/ iVitto's Blog]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Blacksn0w&amp;diff=5653</id>
		<title>Blacksn0w</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Blacksn0w&amp;diff=5653"/>
		<updated>2009-11-16T18:57:47Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The runtime unlock for baseband 5.11.07 (iPhone 3G &amp;amp; 3GS) by geohot which uses the [[AT+XEMN Heap Overflow]] exploit. Blacksn0w was released November 3rd for the iPhone 3G and 3GS and can be downloaded for free together with [[blackra1n]] at http://blackra1n.com as well as through Cydia by adding the repo http://blackra1n.com/.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5342</id>
		<title>AT+XEMN Heap Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5342"/>
		<updated>2009-11-01T22:55:30Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* July 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AT+XEMN is a command on baseband 5.11.07 (pushed out with the 3.1 release), which when exploited correctly, causes a heap overflow allowing the crash to be moulded into an injection vector. This injection vector can then be used to inject an unlocking payload to provide a coveted Software SIM Unlock on the official 3.1(.2) firmware running 5.11.07&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
* '''Vulnerability''': [[User:Oranav|Oranav]] (July) and ih8sn0w (September) (discovered independently)&amp;lt;br&amp;gt;&lt;br /&gt;
* '''Exploit''': [[User:geohot|geohot]]&lt;br /&gt;
&lt;br /&gt;
== Implementation ==&lt;br /&gt;
This exploit is used in [[blacksn0w]].&lt;br /&gt;
&lt;br /&gt;
== Exception Dump == &lt;br /&gt;
 +XLOG: Exception Number: 1&lt;br /&gt;
 Trap Class:     0xDDDD  (SW GENERATED TRAP)&lt;br /&gt;
 Identification: 140 (0x008C)&lt;br /&gt;
 Date: 22.10.2009&lt;br /&gt;
 Time: 00:30&lt;br /&gt;
 File: atform/text/_malloc.c&lt;br /&gt;
 Line: 1036&lt;br /&gt;
 Logdata:&lt;br /&gt;
  2E 0C 76 ED 40 14 31 64 61 74 63 3A 31 00 64 63   ..v.@.1datc:1.dc&lt;br /&gt;
  20 44 F4 E9 20 20 20 20 20 20 20 20 20 20 20 20    D..            &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20&lt;br /&gt;
&lt;br /&gt;
== Timeline ==&lt;br /&gt;
=== July 2009 ===&lt;br /&gt;
*[[User:Oranav|Oranav]] discovers this crash and gives is to the [[iPhone Dev Team]].&lt;br /&gt;
*Upon initial investigation, The [[iPhone Dev Team]], mistakenly concludes that the crash is non-exploitable.&lt;br /&gt;
&lt;br /&gt;
=== September 2009 ===&lt;br /&gt;
*iH8sn0w discovered this command independently but kept it a secret for about a month. [http://twitter.com/iH8sn0w/status/4353547726 ]&lt;br /&gt;
&lt;br /&gt;
=== October 2009 ===&lt;br /&gt;
*When the Dev-Team stated that iH8sn0w did not have a unlock, he posted the command on Twitter. [http://twitter.com/iH8sn0w/status/4954333558]&lt;br /&gt;
*Shortly after, Oranav posted his Hash from July. [http://pastebin.ca/1485104]&lt;br /&gt;
*MuscleNerd tells iHacker that the crash was received awhile ago and is thought to be non-exploitable. [http://twitter.com/MuscleNerd/status/4978871033][http://twitter.com/iHacker/status/4978821448]&lt;br /&gt;
*[[User:Geohot|Geohot]] attempts to exploit this crash, but intially also finds it to be non-exploitable. [http://twitter.com/geohot/status/4979506974]&lt;br /&gt;
*Geohot does more investigation and discovers that this crash is indeed exploitable, and that it's a heap overflow. [http://twitter.com/geohot/status/5196861045]&lt;br /&gt;
*Geohot achieves arbitrary code execution and begins work on unlock which will be called blacksn0w. [http://iphonejtag.blogspot.com/2009/10/heap-of-trouble.html]&lt;br /&gt;
*Geohot posts a video of an unlocked 05.11.07 device. [http://www.youtube.com/watch?v=g23e9e9zOVI]&lt;br /&gt;
&lt;br /&gt;
[[Category:Baseband Exploits]]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5341</id>
		<title>AT+XEMN Heap Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5341"/>
		<updated>2009-11-01T22:54:08Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* October 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AT+XEMN is a command on baseband 5.11.07 (pushed out with the 3.1 release), which when exploited correctly, causes a heap overflow allowing the crash to be moulded into an injection vector. This injection vector can then be used to inject an unlocking payload to provide a coveted Software SIM Unlock on the official 3.1(.2) firmware running 5.11.07&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
* '''Vulnerability''': [[User:Oranav|Oranav]] (July) and ih8sn0w (September) (discovered independently)&amp;lt;br&amp;gt;&lt;br /&gt;
* '''Exploit''': [[User:geohot|geohot]]&lt;br /&gt;
&lt;br /&gt;
== Implementation ==&lt;br /&gt;
This exploit is used in [[blacksn0w]].&lt;br /&gt;
&lt;br /&gt;
== Exception Dump == &lt;br /&gt;
 +XLOG: Exception Number: 1&lt;br /&gt;
 Trap Class:     0xDDDD  (SW GENERATED TRAP)&lt;br /&gt;
 Identification: 140 (0x008C)&lt;br /&gt;
 Date: 22.10.2009&lt;br /&gt;
 Time: 00:30&lt;br /&gt;
 File: atform/text/_malloc.c&lt;br /&gt;
 Line: 1036&lt;br /&gt;
 Logdata:&lt;br /&gt;
  2E 0C 76 ED 40 14 31 64 61 74 63 3A 31 00 64 63   ..v.@.1datc:1.dc&lt;br /&gt;
  20 44 F4 E9 20 20 20 20 20 20 20 20 20 20 20 20    D..            &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20&lt;br /&gt;
&lt;br /&gt;
== Timeline ==&lt;br /&gt;
=== July 2009 ===&lt;br /&gt;
*[[User:Oranav|Oranav]] discovers this crash and gives is to the [[iPhone Dev Team]].&lt;br /&gt;
*Upon initial investigation, The [[iPhone Dev Team]], mistakenly states that the crash is non-exploitable.&lt;br /&gt;
&lt;br /&gt;
=== September 2009 ===&lt;br /&gt;
*iH8sn0w discovered this command independently but kept it a secret for about a month. [http://twitter.com/iH8sn0w/status/4353547726 ]&lt;br /&gt;
&lt;br /&gt;
=== October 2009 ===&lt;br /&gt;
*When the Dev-Team stated that iH8sn0w did not have a unlock, he posted the command on Twitter. [http://twitter.com/iH8sn0w/status/4954333558]&lt;br /&gt;
*Shortly after, Oranav posted his Hash from July. [http://pastebin.ca/1485104]&lt;br /&gt;
*MuscleNerd tells iHacker that the crash was received awhile ago and is thought to be non-exploitable. [http://twitter.com/MuscleNerd/status/4978871033][http://twitter.com/iHacker/status/4978821448]&lt;br /&gt;
*[[User:Geohot|Geohot]] attempts to exploit this crash, but intially also finds it to be non-exploitable. [http://twitter.com/geohot/status/4979506974]&lt;br /&gt;
*Geohot does more investigation and discovers that this crash is indeed exploitable, and that it's a heap overflow. [http://twitter.com/geohot/status/5196861045]&lt;br /&gt;
*Geohot achieves arbitrary code execution and begins work on unlock which will be called blacksn0w. [http://iphonejtag.blogspot.com/2009/10/heap-of-trouble.html]&lt;br /&gt;
*Geohot posts a video of an unlocked 05.11.07 device. [http://www.youtube.com/watch?v=g23e9e9zOVI]&lt;br /&gt;
&lt;br /&gt;
[[Category:Baseband Exploits]]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5340</id>
		<title>AT+XEMN Heap Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5340"/>
		<updated>2009-11-01T22:52:37Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* October 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AT+XEMN is a command on baseband 5.11.07 (pushed out with the 3.1 release), which when exploited correctly, causes a heap overflow allowing the crash to be moulded into an injection vector. This injection vector can then be used to inject an unlocking payload to provide a coveted Software SIM Unlock on the official 3.1(.2) firmware running 5.11.07&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
* '''Vulnerability''': [[User:Oranav|Oranav]] (July) and ih8sn0w (September) (discovered independently)&amp;lt;br&amp;gt;&lt;br /&gt;
* '''Exploit''': [[User:geohot|geohot]]&lt;br /&gt;
&lt;br /&gt;
== Implementation ==&lt;br /&gt;
This exploit is used in [[blacksn0w]].&lt;br /&gt;
&lt;br /&gt;
== Exception Dump == &lt;br /&gt;
 +XLOG: Exception Number: 1&lt;br /&gt;
 Trap Class:     0xDDDD  (SW GENERATED TRAP)&lt;br /&gt;
 Identification: 140 (0x008C)&lt;br /&gt;
 Date: 22.10.2009&lt;br /&gt;
 Time: 00:30&lt;br /&gt;
 File: atform/text/_malloc.c&lt;br /&gt;
 Line: 1036&lt;br /&gt;
 Logdata:&lt;br /&gt;
  2E 0C 76 ED 40 14 31 64 61 74 63 3A 31 00 64 63   ..v.@.1datc:1.dc&lt;br /&gt;
  20 44 F4 E9 20 20 20 20 20 20 20 20 20 20 20 20    D..            &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20&lt;br /&gt;
&lt;br /&gt;
== Timeline ==&lt;br /&gt;
=== July 2009 ===&lt;br /&gt;
*[[User:Oranav|Oranav]] discovers this crash and gives is to the [[iPhone Dev Team]].&lt;br /&gt;
*Upon initial investigation, The [[iPhone Dev Team]], mistakenly states that the crash is non-exploitable.&lt;br /&gt;
&lt;br /&gt;
=== September 2009 ===&lt;br /&gt;
*iH8sn0w discovered this command independently but kept it a secret for about a month. [http://twitter.com/iH8sn0w/status/4353547726 ]&lt;br /&gt;
&lt;br /&gt;
=== October 2009 ===&lt;br /&gt;
*When the Dev-Team stated that iH8sn0w did not have a unlock, he posted the command on Twitter. [http://twitter.com/iH8sn0w/status/4954333558]&lt;br /&gt;
*Shortly after, Oranav posted his Hash from July. [http://pastebin.ca/1485104]&lt;br /&gt;
*MuscleNerd tells iHacker that the crash was received awhile ago and was thought to be non-exploitable. [http://twitter.com/MuscleNerd/status/4978871033][http://twitter.com/iHacker/status/4978821448]&lt;br /&gt;
*[[User:Geohot|Geohot]] attempts to exploit this crash, but intially also finds it to be non-exploitable. [http://twitter.com/geohot/status/4979506974]&lt;br /&gt;
*Geohot does more investigation and discovers that this crash is indeed exploitable, and that it's a heap overflow. [http://twitter.com/geohot/status/5196861045]&lt;br /&gt;
*Geohot achieves arbitrary code execution and begins work on unlock which will be called blacksn0w. [http://iphonejtag.blogspot.com/2009/10/heap-of-trouble.html]&lt;br /&gt;
*Geohot posts a video of an unlocked 05.11.07 device. [http://www.youtube.com/watch?v=g23e9e9zOVI]&lt;br /&gt;
&lt;br /&gt;
[[Category:Baseband Exploits]]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5339</id>
		<title>AT+XEMN Heap Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=AT%2BXEMN_Heap_Overflow&amp;diff=5339"/>
		<updated>2009-11-01T22:51:05Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* July 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AT+XEMN is a command on baseband 5.11.07 (pushed out with the 3.1 release), which when exploited correctly, causes a heap overflow allowing the crash to be moulded into an injection vector. This injection vector can then be used to inject an unlocking payload to provide a coveted Software SIM Unlock on the official 3.1(.2) firmware running 5.11.07&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
* '''Vulnerability''': [[User:Oranav|Oranav]] (July) and ih8sn0w (September) (discovered independently)&amp;lt;br&amp;gt;&lt;br /&gt;
* '''Exploit''': [[User:geohot|geohot]]&lt;br /&gt;
&lt;br /&gt;
== Implementation ==&lt;br /&gt;
This exploit is used in [[blacksn0w]].&lt;br /&gt;
&lt;br /&gt;
== Exception Dump == &lt;br /&gt;
 +XLOG: Exception Number: 1&lt;br /&gt;
 Trap Class:     0xDDDD  (SW GENERATED TRAP)&lt;br /&gt;
 Identification: 140 (0x008C)&lt;br /&gt;
 Date: 22.10.2009&lt;br /&gt;
 Time: 00:30&lt;br /&gt;
 File: atform/text/_malloc.c&lt;br /&gt;
 Line: 1036&lt;br /&gt;
 Logdata:&lt;br /&gt;
  2E 0C 76 ED 40 14 31 64 61 74 63 3A 31 00 64 63   ..v.@.1datc:1.dc&lt;br /&gt;
  20 44 F4 E9 20 20 20 20 20 20 20 20 20 20 20 20    D..            &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20                   &lt;br /&gt;
  20 20 20 20 20 20 20 20&lt;br /&gt;
&lt;br /&gt;
== Timeline ==&lt;br /&gt;
=== July 2009 ===&lt;br /&gt;
*[[User:Oranav|Oranav]] discovers this crash and gives is to the [[iPhone Dev Team]].&lt;br /&gt;
*Upon initial investigation, The [[iPhone Dev Team]], mistakenly states that the crash is non-exploitable.&lt;br /&gt;
&lt;br /&gt;
=== September 2009 ===&lt;br /&gt;
*iH8sn0w discovered this command independently but kept it a secret for about a month. [http://twitter.com/iH8sn0w/status/4353547726 ]&lt;br /&gt;
&lt;br /&gt;
=== October 2009 ===&lt;br /&gt;
*When the Dev-Team stated that iH8sn0w did not have a unlock, he posted the command on Twitter. [http://twitter.com/iH8sn0w/status/4954333558]&lt;br /&gt;
*Shortly after, Oranav posted his Hash from July. [http://pastebin.ca/1485104]&lt;br /&gt;
*MuscleNerd tells iHacker that the crash was received awhile ago and was non-exploitable. [http://twitter.com/MuscleNerd/status/4978871033][http://twitter.com/iHacker/status/4978821448]&lt;br /&gt;
*[[User:Geohot|Geohot]] attempts to exploit this crash, but later finds out as well that it is non-exploitable. [http://twitter.com/geohot/status/4979506974]&lt;br /&gt;
*The hunt for another exploit continues as New 3G/3G[S] users join or if 3G/3G[S] users upgrade to Official Apple Firmware.&lt;br /&gt;
*Geohot does more investigation and discovers that this crash is indeed exploitable, and that it's a heap overflow. [http://twitter.com/geohot/status/5196861045]&lt;br /&gt;
*Geohot has achieved arbitrary code execution and has begun working on unlock which will be called blacksn0w. [http://iphonejtag.blogspot.com/2009/10/heap-of-trouble.html]&lt;br /&gt;
*Geohot posts a video of an unlocked 05.11.07 device. [http://www.youtube.com/watch?v=g23e9e9zOVI]&lt;br /&gt;
&lt;br /&gt;
[[Category:Baseband Exploits]]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Blacksn0w&amp;diff=5330</id>
		<title>Blacksn0w</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Blacksn0w&amp;diff=5330"/>
		<updated>2009-10-31T16:02:15Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The runtime unlock for baseband 5.11 by geohot which uses the [[AT+XEMN Heap Overflow]] exploit.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Blacksn0w&amp;diff=5329</id>
		<title>Blacksn0w</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Blacksn0w&amp;diff=5329"/>
		<updated>2009-10-31T16:00:57Z</updated>

		<summary type="html">&lt;p&gt;Drg: New page: The runtime unlock for baseband 5.11 by geohot.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The runtime unlock for baseband 5.11 by geohot.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4198</id>
		<title>Purplera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4198"/>
		<updated>2009-07-13T20:03:15Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Credit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Credit ==&lt;br /&gt;
[[geohot]]&lt;br /&gt;
&lt;br /&gt;
OSX client: AriX, and westbaer.&lt;br /&gt;
&lt;br /&gt;
== Phase 1: Signature Grabber ==&lt;br /&gt;
* '''Blog Post''': http://iphonejtag.blogspot.com/2009/06/usbdump-huh-how.html&lt;br /&gt;
&lt;br /&gt;
Allows anyone with a [[N88AP|3GS]] right now to generate a file that contains:&lt;br /&gt;
* The [[ECID|Exclusive Chip ID tag]] for your device&lt;br /&gt;
* The new RSA signature for a 3.0GM [[N88AP|iPhone 3GS]] iBSS that includes your ECID&lt;br /&gt;
&lt;br /&gt;
This way, if Apple tries to pull a fast one and disallow downgrades to earlier versions, you have a backup that can be used to still allow you to boot an older iBSS.&lt;br /&gt;
&lt;br /&gt;
Apple can not stop you from obtaining the ECID from your phone. But the webapp behind purplera1n calls the same Apple servers which are also used by iTunes for signing your personal iBSS ECID combination. So this will stop working, when&lt;br /&gt;
* a new firmware gets released and Apple does not allow downgrading any more or&lt;br /&gt;
* Apple finds a way to distinguish between requests from iTunes and purplera1n&lt;br /&gt;
&lt;br /&gt;
As purplera1n uses a distributed application hosting it is not easy for Apple to filter it using IP addresses.&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Jailbreak Tool (3.0) ==&lt;br /&gt;
* '''Web Site''': http://purplera1n.com&lt;br /&gt;
&lt;br /&gt;
One-Click, dead simple, jailbreak for the [[iPhone 3GS]]. Currently available for Windows, Mac, and Linux. It utilizes the [[iBoot Environment Variable Overflow]].&lt;br /&gt;
&lt;br /&gt;
== How purplera1n Works ==&lt;br /&gt;
&lt;br /&gt;
purplera1n is so simple, that it hides the complex work it's doing from the user. Figured I'd describe it step by step&lt;br /&gt;
* purplera1n sends the enter recovery commands using iTunesMobileDevice&lt;br /&gt;
* once in recovery(iBoot), it sends the [[IBoot Environment Variable Overflow]] exploit&lt;br /&gt;
* the exploit adds a &amp;quot;geohot&amp;quot; command to the phone which runs the payload&lt;br /&gt;
* the &amp;quot;geohot&amp;quot; command is run, control is now transferred from iboot to the payload&lt;br /&gt;
* the purplera1n client is done&lt;br /&gt;
Inside payload&lt;br /&gt;
* the payload restores the default environment variable ring buffer and saves the environment to nvram(sets auto-boot to true)&lt;br /&gt;
* it patches iBoot to load unsigned img3s and not care about the tags&lt;br /&gt;
* it loads the purplera1n picture(sent with payload)&lt;br /&gt;
* the nor patcher starts&lt;br /&gt;
* llb is decrypted, patched, and increased in size to 0x24200. this is the resident [[0x24000 Segment Overflow]] exploit&lt;br /&gt;
* a little loader code is put @ 0x20000 in the LLB to load it and fix the stack&lt;br /&gt;
* iboot is decrypted, patched&lt;br /&gt;
* everything else is read as is&lt;br /&gt;
* nor is written back, nor patcher is done&lt;br /&gt;
* kernel is loaded, decrypted, and patched&lt;br /&gt;
* ramdisk is loaded(sent with payload) and moved to ramdisk region at 0x44000000, patched kernel is tacked on to the end&lt;br /&gt;
* patched kernel is booted&lt;br /&gt;
* control is now transferred from payload to ramdisk&lt;br /&gt;
Inside ramdisk&lt;br /&gt;
* launchd is run, all stuff happens here&lt;br /&gt;
* /dev/disk0s1 is mounted&lt;br /&gt;
* fstab and services are overwritten here to allow disk0s1 writes and afc2 respectively&lt;br /&gt;
* Freeze.app is transferred and Freeze.app loader has SUID bit set&lt;br /&gt;
* patched kernel is read from end of ramdisk block device and written to filesystem&lt;br /&gt;
* ramdisk is done, rebooting...&lt;br /&gt;
Reboots as jailbroken phone&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4197</id>
		<title>Purplera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4197"/>
		<updated>2009-07-13T20:02:53Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Credit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Credit ==&lt;br /&gt;
[[geohot]]&lt;br /&gt;
OSX client: AriX, and westbaer.&lt;br /&gt;
&lt;br /&gt;
== Phase 1: Signature Grabber ==&lt;br /&gt;
* '''Blog Post''': http://iphonejtag.blogspot.com/2009/06/usbdump-huh-how.html&lt;br /&gt;
&lt;br /&gt;
Allows anyone with a [[N88AP|3GS]] right now to generate a file that contains:&lt;br /&gt;
* The [[ECID|Exclusive Chip ID tag]] for your device&lt;br /&gt;
* The new RSA signature for a 3.0GM [[N88AP|iPhone 3GS]] iBSS that includes your ECID&lt;br /&gt;
&lt;br /&gt;
This way, if Apple tries to pull a fast one and disallow downgrades to earlier versions, you have a backup that can be used to still allow you to boot an older iBSS.&lt;br /&gt;
&lt;br /&gt;
Apple can not stop you from obtaining the ECID from your phone. But the webapp behind purplera1n calls the same Apple servers which are also used by iTunes for signing your personal iBSS ECID combination. So this will stop working, when&lt;br /&gt;
* a new firmware gets released and Apple does not allow downgrading any more or&lt;br /&gt;
* Apple finds a way to distinguish between requests from iTunes and purplera1n&lt;br /&gt;
&lt;br /&gt;
As purplera1n uses a distributed application hosting it is not easy for Apple to filter it using IP addresses.&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Jailbreak Tool (3.0) ==&lt;br /&gt;
* '''Web Site''': http://purplera1n.com&lt;br /&gt;
&lt;br /&gt;
One-Click, dead simple, jailbreak for the [[iPhone 3GS]]. Currently available for Windows, Mac, and Linux. It utilizes the [[iBoot Environment Variable Overflow]].&lt;br /&gt;
&lt;br /&gt;
== How purplera1n Works ==&lt;br /&gt;
&lt;br /&gt;
purplera1n is so simple, that it hides the complex work it's doing from the user. Figured I'd describe it step by step&lt;br /&gt;
* purplera1n sends the enter recovery commands using iTunesMobileDevice&lt;br /&gt;
* once in recovery(iBoot), it sends the [[IBoot Environment Variable Overflow]] exploit&lt;br /&gt;
* the exploit adds a &amp;quot;geohot&amp;quot; command to the phone which runs the payload&lt;br /&gt;
* the &amp;quot;geohot&amp;quot; command is run, control is now transferred from iboot to the payload&lt;br /&gt;
* the purplera1n client is done&lt;br /&gt;
Inside payload&lt;br /&gt;
* the payload restores the default environment variable ring buffer and saves the environment to nvram(sets auto-boot to true)&lt;br /&gt;
* it patches iBoot to load unsigned img3s and not care about the tags&lt;br /&gt;
* it loads the purplera1n picture(sent with payload)&lt;br /&gt;
* the nor patcher starts&lt;br /&gt;
* llb is decrypted, patched, and increased in size to 0x24200. this is the resident [[0x24000 Segment Overflow]] exploit&lt;br /&gt;
* a little loader code is put @ 0x20000 in the LLB to load it and fix the stack&lt;br /&gt;
* iboot is decrypted, patched&lt;br /&gt;
* everything else is read as is&lt;br /&gt;
* nor is written back, nor patcher is done&lt;br /&gt;
* kernel is loaded, decrypted, and patched&lt;br /&gt;
* ramdisk is loaded(sent with payload) and moved to ramdisk region at 0x44000000, patched kernel is tacked on to the end&lt;br /&gt;
* patched kernel is booted&lt;br /&gt;
* control is now transferred from payload to ramdisk&lt;br /&gt;
Inside ramdisk&lt;br /&gt;
* launchd is run, all stuff happens here&lt;br /&gt;
* /dev/disk0s1 is mounted&lt;br /&gt;
* fstab and services are overwritten here to allow disk0s1 writes and afc2 respectively&lt;br /&gt;
* Freeze.app is transferred and Freeze.app loader has SUID bit set&lt;br /&gt;
* patched kernel is read from end of ramdisk block device and written to filesystem&lt;br /&gt;
* ramdisk is done, rebooting...&lt;br /&gt;
Reboots as jailbroken phone&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4104</id>
		<title>Purplera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4104"/>
		<updated>2009-07-06T04:06:41Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Phase 1: USB Dumper */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Credit ==&lt;br /&gt;
[[geohot]]&lt;br /&gt;
&lt;br /&gt;
== Phase 1: Certificate Dumper ==&lt;br /&gt;
* '''Blog Post''': http://iphonejtag.blogspot.com/2009/06/usbdump-huh-how.html&lt;br /&gt;
&lt;br /&gt;
Allows anyone with a [[N88AP|3G S]] right now to generate a file that contains:&lt;br /&gt;
* The [[ECID|Exclusive Chip ID tag]] for your device&lt;br /&gt;
* The new RSA signature for a 3.0GM [[N88AP|iPhone 3G S]] iBSS that includes your ECID&lt;br /&gt;
&lt;br /&gt;
This way, if Apple tries to pull a fast one and disallow downgrades to earlier versions, you have a backup that can be used to still allow you to boot an older iBSS.&lt;br /&gt;
&lt;br /&gt;
Apple can not stop you from obtaining the ECID from your phone. But the webapp behind purplera1n calls the same Apple servers which are also used by iTunes for signing your personal iBSS ECID combination. So this will stop working, when&lt;br /&gt;
* a new firmware gets released and Apple does not allow downdating any more or&lt;br /&gt;
* Apple finds a way to disinguish between requests from iTunes and purplera1n&lt;br /&gt;
&lt;br /&gt;
As purplera1n uses a distributed application hosting it is not easy for Apple to filter it using IP addresses.&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Jailbreak App ==&lt;br /&gt;
* '''Web Site: http://purplera1n.com&lt;br /&gt;
&lt;br /&gt;
Multiplatform one-click jailbreak for 3GS.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4103</id>
		<title>Purplera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=4103"/>
		<updated>2009-07-06T04:05:57Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Credit ==&lt;br /&gt;
[[geohot]]&lt;br /&gt;
&lt;br /&gt;
== Phase 1: USB Dumper ==&lt;br /&gt;
* '''Blog Post''': http://iphonejtag.blogspot.com/2009/06/usbdump-huh-how.html&lt;br /&gt;
&lt;br /&gt;
Allows anyone with a [[N88AP|3G S]] right now to generate a file that contains:&lt;br /&gt;
* The [[ECID|Exclusive Chip ID tag]] for your device&lt;br /&gt;
* The new RSA signature for a 3.0GM [[N88AP|iPhone 3G S]] iBSS that includes your ECID&lt;br /&gt;
&lt;br /&gt;
This way, if Apple tries to pull a fast one and disallow downgrades to earlier versions, you have a backup that can be used to still allow you to boot an older iBSS.&lt;br /&gt;
&lt;br /&gt;
Apple can not stop you from obtaining the ECID from your phone. But the webapp behind purplera1n calls the same Apple servers which are also used by iTunes for signing your personal iBSS ECID combination. So this will stop working, when&lt;br /&gt;
* a new firmware gets released and Apple does not allow downdating any more or&lt;br /&gt;
* Apple finds a way to disinguish between requests from iTunes and purplera1n&lt;br /&gt;
&lt;br /&gt;
As purplera1n uses a distributed application hosting it is not easy for Apple to filter it using IP addresses.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Phase 2: Jailbreak App ==&lt;br /&gt;
* '''Web Site: http://purplera1n.com&lt;br /&gt;
&lt;br /&gt;
Multiplatform one-click jailbreak for 3GS.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Firmware&amp;diff=4085</id>
		<title>Firmware</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Firmware&amp;diff=4085"/>
		<updated>2009-07-04T23:52:36Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the iPhone OS system the iPhone runs. Latest Apple download links can be found [http://www.itunes.com/version here].&lt;br /&gt;
&lt;br /&gt;
==Comparison of firmware versions==&lt;br /&gt;
&lt;br /&gt;
===[[iPhone]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Version&lt;br /&gt;
! Build&lt;br /&gt;
! [[Baseband]]&lt;br /&gt;
! IPSW Download URL&lt;br /&gt;
! SHA1 Hash&lt;br /&gt;
! Comments&lt;br /&gt;
! Can be [[jailbreak|jailbroken]]?&lt;br /&gt;
! Can be [[unlock|unlocked]]?&lt;br /&gt;
! File Size&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.0&lt;br /&gt;
| Heavenly 1A543a&lt;br /&gt;
| 03.12.06_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3538.20070629.B7vXa/iPhone1,1_1.0_1A543a_Restore.ipsw iPhone1,1_1.0_1A543a_Restore.ipsw]&lt;br /&gt;
| fb8bb3ee2e9a997affbb97868599f2995c78209c&lt;br /&gt;
| Initial US shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,604,348&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.1&lt;br /&gt;
| Heavenly 1C25&lt;br /&gt;
| 03.12.06_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3614.20070731.Nt6Y7/iPhone1,1_1.0.1_1C25_Restore.ipsw iPhone1,1_1.0.1_1C25_Restore.ipsw]&lt;br /&gt;
| a00b85a7a55d62a94be5fbf5effbc42fd63f3097&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,627,958&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.2&lt;br /&gt;
| Heavenly 1C28&lt;br /&gt;
| 03.14.08_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3823.20070821.vormd/iPhone1,1_1.0.2_1C28_Restore.ipsw iPhone1,1_1.0.2_1C28_Restore.ipsw]&lt;br /&gt;
| 7f5c0ff1f84a0202b75a55c3fcb362e415334d1e&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,627,324&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| Snowbird 3A109a&lt;br /&gt;
| 04.01.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3883.20070927.In76t/iPhone1,1_1.1.1_3A109a_Restore.ipsw iPhone1,1_1.1.1_3A109a_Restore.ipsw]&lt;br /&gt;
| d441dd1c71ce18f25d8fc4faa71c1e6eaa02d02c&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 159,668,150&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48a&lt;br /&gt;
| 04.02.13_G&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial Euro shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48b&lt;br /&gt;
| 04.02.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4037.20071107.5Bghn/iPhone1,1_1.1.2_3B48b_Restore.ipsw iPhone1,1_1.1.2_3B48b_Restore.ipsw]&lt;br /&gt;
| 797c02e7d660940e8d9a16cc7229ccf3f67dd8b1&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 167,927,501&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| Little Bear 4A93&lt;br /&gt;
| 04.03.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4061.20080115.4Fvn7/iPhone1,1_1.1.3_4A93_Restore.ipsw iPhone1,1_1.1.3_4A93_Restore.ipsw]&lt;br /&gt;
| b3dec7580bd00dc4faf28449d9618ef40aeacc96&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 169,950,551&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.4&lt;br /&gt;
| Little Bear 4A102&lt;br /&gt;
| 04.04.05_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4313.20080226.Sw39i/iPhone1,1_1.1.4_4A102_Restore.ipsw iPhone1,1_1.1.4_4A102_Restore.ipsw]&lt;br /&gt;
| 000811bac096011b50ebf6ec1ec2285b62fda4cb&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 169,946,442&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| Big Bear 5A347&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4956.20080710.V50OI/iPhone1,1_2.0_5A347_Restore.ipsw iPhone1,1_2.0_5A347_Restore.ipsw]&lt;br /&gt;
| 9c510a3cfce789fa5f92a8f763c231bac82ff6d4&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 228,768,637&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| Big Bear 5B108&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5135.20080729.Vfgtr/iPhone1,1_2.0.1_5B108_Restore.ipsw iPhone1,1_2.0.1_5B108_Restore.ipsw]&lt;br /&gt;
| 61de6a2bd6ceddc9ecabad1671b91a59b3824bc4&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 254,048,068&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| Big Bear 5C1&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5246.20080818.2V0hO/iPhone1,1_2.0.2_5C1_Restore.ipsw iPhone1,1_2.0.2_5C1_Restore.ipsw]&lt;br /&gt;
| b84b57bea919bdc720287ec908c1378e7d7b5e1b&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,589,000&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| Sugar Bowl 5F136&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5202.20080909.gkbEj/iPhone1,1_2.1_5F136_Restore.ipsw iPhone1,1_2.1_5F136_Restore.ipsw]&lt;br /&gt;
| 353b7745767b85932e14e262e69463620939bdf7&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 242,171,241&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| Timberline 5G77&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5779.20081120.Pt5yH/iPhone1,1_2.2_5G77_Restore.ipsw iPhone1,1_2.2_5G77_Restore.ipsw]&lt;br /&gt;
| cbfc6ff886ce89868a55547b9fb980dbf92e6418 &lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 257,576,980&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| SUTimberline 5H11&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5830.20090127.Mmni6/iPhone1,1_2.2.1_5H11_Restore.ipsw iPhone1,1_2.2.1_5H11_Restore.ipsw]&lt;br /&gt;
| 43b95ebe1e51f8d30eae916053396595c08440d3&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 257,593,705&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone)|Kirkwood 7A341]]&lt;br /&gt;
| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6580.20090617.XsP76/iPhone1,1_3.0_7A341_Restore.ipsw iPhone1,1_3.0_7A341_Restore.ipsw]&lt;br /&gt;
| 2afd3f8ede17390737f508473ed205506a0bd23f&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 240,394,111&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[iPhone 3G]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Version&lt;br /&gt;
! Build&lt;br /&gt;
! [[Baseband]]&lt;br /&gt;
! IPSW Download URL&lt;br /&gt;
! SHA1 Hash&lt;br /&gt;
! Comments&lt;br /&gt;
! Can be [[jailbreak|jailbroken]]?&lt;br /&gt;
! Can be [[unlock|unlocked]]?&lt;br /&gt;
! File Size&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| Big Bear 5A345&lt;br /&gt;
| 01.45.00&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial iPhone 3G shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| Big Bear 5A347&lt;br /&gt;
| 01.45.00&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4955.20080710.bgt53/iPhone1,2_2.0_5A347_Restore.ipsw iPhone1,2_2.0_5A347_Restore.ipsw]&lt;br /&gt;
| af9506ca0034e462674f9f59c5406f159eaf9fc1&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| 235,957,125&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| Big Bear 5B108&lt;br /&gt;
| 01.48.02&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5134.20080729.Q2W3E/iPhone1,2_2.0.1_5B108_Restore.ipsw iPhone1,2_2.0.1_5B108_Restore.ipsw]&lt;br /&gt;
| e81c7ac7e334a3e9d81b3b47894bfaa1ec495482&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| 261,224,227&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| Big Bear 5C1&lt;br /&gt;
| 02.08.01&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5241.20080818.t5Fv3/iPhone1,2_2.0.2_5C1_Restore.ipsw iPhone1,2_2.0.2_5C1_Restore.ipsw]&lt;br /&gt;
| bef7fef954293046420fbcf947379839178a195b&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| 260,761,030&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| Sugar Bowl 5F136&lt;br /&gt;
| 02.11.07&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5198.20080909.K3294/iPhone1,2_2.1_5F136_Restore.ipsw iPhone1,2_2.1_5F136_Restore.ipsw]&lt;br /&gt;
| c6957dcbf2a95ccfd6dce374a727b1b7700a9043&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| 249,341,655&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| Timberline 5G77&lt;br /&gt;
| 02.28.00&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5778.20081120.Aqw4R/iPhone1,2_2.2_5G77_Restore.ipsw iPhone1,2_2.2_5G77_Restore.ipsw]&lt;br /&gt;
| f67f8b2b842428bf89456cda0c2d5cf954d111a4&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| 258,342,348&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| SUTimberline 5H11&lt;br /&gt;
| 02.30.03&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5828.20090127.aQLi8/iPhone1,2_2.2.1_5H11_Restore.ipsw iPhone1,2_2.2.1_5H11_Restore.ipsw]&lt;br /&gt;
| e0098e6fab5c90b59e067e03ae3ccd4a7cd0f39c&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (Upgrade to 04.26.08)}}&lt;br /&gt;
| 258,359,073&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone 3G)|Kirkwood 7A341]]&lt;br /&gt;
| 04.26.08&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6578.20090617.VfgtU/iPhone1,2_3.0_7A341_Restore.ipsw iPhone1,2_3.0_7A341_Restore.ipsw]&lt;br /&gt;
| 94f1fb43de12bff0f168ce690b7e794cc6220ae3&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (with [[ultrasn0w]])}}&lt;br /&gt;
| 241,229,233&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[iPhone2,1|iPhone 3GS]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Version&lt;br /&gt;
! Build&lt;br /&gt;
! [[Baseband]]&lt;br /&gt;
! IPSW Download URL&lt;br /&gt;
! SHA1 Hash&lt;br /&gt;
! Comments&lt;br /&gt;
! Can be [[jailbreak|jailbroken]]?&lt;br /&gt;
! Can be [[unlock|unlocked]]?&lt;br /&gt;
! File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone 3G S)|Kirkwood 7A341]]&lt;br /&gt;
| 04.26.08&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6582.20090617.LlI87/iPhone2,1_3.0_7A341_Restore.ipsw iPhone2,1_3.0_7A341_Restore.ipsw] &lt;br /&gt;
| d8534408c8679c830fd0c4e36ef9762c11ef73df&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes (with [[ultrasn0w]])}}&lt;br /&gt;
| 312,292,933&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N45ap|iPod touch (1st generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Version&lt;br /&gt;
! Build&lt;br /&gt;
! IPSW Download URL&lt;br /&gt;
! SHA1 Hash&lt;br /&gt;
! Comments&lt;br /&gt;
! Can be [[jailbreak|jailbroken]]?&lt;br /&gt;
! File Size&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.0&lt;br /&gt;
| Snowbird 3A100a&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.0&lt;br /&gt;
| Snowbird 3A101a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3882.20070910.N8uyT/iPod1,1_1.1_3A101a_Restore.ipsw iPod1,1_1.1_3A101a_Restore.ipsw]&lt;br /&gt;
| 9b0d83c7f8b4328174a3f31e0e93f60e591ae143&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 157,890,186&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| Snowbird 3A110a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3932.20070927.p23dD/iPod1,1_1.1.1_3A110a_Restore.ipsw iPod1,1_1.1.1_3A110a_Restore.ipsw]&lt;br /&gt;
| 84bbc6ea8bf29745195bc9926c1874f7c2a36f32&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 157,906,686&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48b&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4036.20071107.9g3DF/iPod1,1_1.1.2_3B48b_Restore.ipsw iPod1,1_1.1.2_3B48b_Restore.ipsw]&lt;br /&gt;
| 108d8ffe9ea75e61cd5e57170ad388b7fa00d923&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 165,567,897&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| Little Bear 4A93&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/061-4060.20080115.9Iuh5/iPod1,1_1.1.3_4A93_Restore.ipsw iPod1,1_1.1.3_4A93_Restore.ipsw]&lt;br /&gt;
| 8dca23eec69d5ae58fbf3d4a23276e46cbb2e3c6&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,511,411&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.4&lt;br /&gt;
| Little Bear 4A102&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4312.20080226.Btu45/iPod1,1_1.1.4_4A102_Restore.ipsw iPod1,1_1.1.4_4A102_Restore.ipsw]&lt;br /&gt;
| c148d1eb1c979bb6434175411d4a372103a4fdd2&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,519,589&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.5&lt;br /&gt;
| Little Bear 4B1&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4841.20080714.bgy8O/iPod1,1_1.1.5_4B1_Restore.ipsw iPod1,1_1.1.5_4B1_Restore.ipsw]&lt;br /&gt;
| 1b818911316e4248ee01d3ec67f9d39afc3db240&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,519,637&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| Big Bear 5A347&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| ae82798e85f9953b0f4798bad36187cb020c9d22&lt;br /&gt;
| 2.0+ is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 233,409,573&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| Big Bear 5B108&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| a81b6e7af4b85ef436d047f9da57c0f694d8964a&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 258,660,321&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| Big Bear 5C1&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| c8b6f9fefa3f3777c56285dfe4c735b1e08a81a2&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 258,201,218&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| Sugar Bowl 5F137&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| fc7f6d0972927df502ffca47438ca75dcccffaf3&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 251,155,156&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| Timberline 5G77&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| 081a7de363230fb38d0ce092cbbe42f2a50c8a5f&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,186,851&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| SUTimberline 5H11&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| fc69be9e421bc0630567184506ab771f6b7ef68b&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,166,688&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| Kirkwood 7A341&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| dff2bd14931225908a360fb8e60a336f17d2dd6d&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 242,458,552&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N72ap|iPod touch (2nd generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Version&lt;br /&gt;
! Build&lt;br /&gt;
! IPSW Download URL&lt;br /&gt;
! SHA1 Hash&lt;br /&gt;
! Comments&lt;br /&gt;
! Can be [[jailbreak|jailbroken]]?&lt;br /&gt;
! File Size&lt;br /&gt;
|-&lt;br /&gt;
| 2.1.1&lt;br /&gt;
| [[Sugar Bowl - 5F138]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-5494.20080909.8i9o0/iPod2,1_2.1.1_5F138_Restore.ipsw iPod2,1_2.1.1_5F138_Restore.ipsw]&lt;br /&gt;
| c3c700be49ad227d1152188e7c1e46b8958fd1e4&lt;br /&gt;
|&lt;br /&gt;
| {{yes|Yes}}&lt;br /&gt;
| 282,083,944&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| Timberline - 5G77a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/061-5358.20081120.Gtghy/iPod2,1_2.2_5G77a_Restore.ipsw iPod2,1_2.2_5G77a_Restore.ipsw]&lt;br /&gt;
| 34a0a489605f34d6cc6c9954edcaaf9a050deedc&lt;br /&gt;
|&lt;br /&gt;
| {{yes|Yes}}&lt;br /&gt;
| 291,123,491&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| SUTimberline - 5H11a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5863.20090127.rt56K/iPod2,1_2.2.1_5H11a_Restore.ipsw iPod2,1_2.2.1_5H11a_Restore.ipsw]&lt;br /&gt;
| 9af5625ea34acdd8abeb6fce71a72651d0c815d5&lt;br /&gt;
|&lt;br /&gt;
| {{yes|Yes}}&lt;br /&gt;
| 291,140,244&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPod touch 2G)|Kirkwood 7A341]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| 0f7fc76d9b9aa826b5ab14be9821a315d3d9dc42&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes}}&lt;br /&gt;
| 270,315,364&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[VFDecrypt Keys]]&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
*[http://www.trejan.com/projects/ipod/ Firmware List]&lt;br /&gt;
*[http://www.iphones.ru/forum/index.php?showtopic=7115 iPhone FW's Links (Russian)]&lt;br /&gt;
*[http://www.iphones.ru/forum/index.php?showtopic=13934 iPod Touch FW's Links (Russian)]&lt;br /&gt;
*[http://pastebin.ca/1209360 A link of interest...]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=N88AP&amp;diff=4069</id>
		<title>N88AP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=N88AP&amp;diff=4069"/>
		<updated>2009-07-04T02:48:37Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:IPhone3GS.jpg|right|thumb|iPhone 3GS, back and front.]]&lt;br /&gt;
&lt;br /&gt;
This is the iPhone 3GS. It was released on June 19, 2009 with a price tag of $199 for the 16GB model and $299 for the 32GB model, in the U.S., Canada and major European countries. Prices vary depending on the mobile operator. It features the same exterior design as the [[iPhone 3G]], but has new internal features such as video recording, voice control, digital compass, faster CPU, increased RAM etc.&lt;br /&gt;
&lt;br /&gt;
== Baseband ==&lt;br /&gt;
The iPhone 3G S uses the [[X-Gold 608]] baseband chip, same as in the iPhone 3G.&lt;br /&gt;
&lt;br /&gt;
== Application Processor ==&lt;br /&gt;
It makes use of the [[S5L8920]] application processor.&lt;br /&gt;
&lt;br /&gt;
== Specifications ==&lt;br /&gt;
'''Color''': Black or white &amp;lt;br&amp;gt;&lt;br /&gt;
'''Size''': 4.5 inches (115.5 mm) (h) × 2.4 inches (62.1 mm) (w) × 0.48 inch (12.3 mm) (d) &amp;lt;br&amp;gt;&lt;br /&gt;
'''Weight''': 135 g (4.8 oz) &amp;lt;br&amp;gt;&lt;br /&gt;
'''Battery''': Up to 12 hours of 2G talk, 5 hours of 3G talk, 5 (3G) or 9 (Wi-Fi) hours of Internet use, 10 hours of video playback, and up to 30 hours of audio playback, lasting over 300 hours on standby. &amp;lt;br&amp;gt;&lt;br /&gt;
'''3G''': Broadband data speeds, supporting 7.2Mbps HSDPA &amp;lt;br&amp;gt;&lt;br /&gt;
'''Camera''': 3.15MP with Autofocus and manual focus (''Tap to focus''), supporting VGA video recording @ 30FPS&lt;br /&gt;
&lt;br /&gt;
More specifications available in [http://www.gsmarena.com/apple_iphone_3g_s-2826.php GSMArena].&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Jailbreak iPhone2,1]]&lt;br /&gt;
* [[X-Gold 608 Unlock]]&lt;br /&gt;
* [[N88AP Device Tree]]&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.anandtech.com/gadgets/showdoc.aspx?i=3579 AnandTech: The iPhone 3GS Hardware Exposed &amp;amp; Analyzed]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:IBoot_Environment_Variable_Overflow&amp;diff=4066</id>
		<title>Talk:IBoot Environment Variable Overflow</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:IBoot_Environment_Variable_Overflow&amp;diff=4066"/>
		<updated>2009-07-03T23:05:43Z</updated>

		<summary type="html">&lt;p&gt;Drg: Removing all content from page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=N88AP&amp;diff=4051</id>
		<title>N88AP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=N88AP&amp;diff=4051"/>
		<updated>2009-07-03T01:03:41Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:IPhone3GS.jpg|right|thumb|iPhone 3GS, back and front.]]&lt;br /&gt;
&lt;br /&gt;
This is the iPhone 3GS. It was released on June 19, 2009 with a price tag of $199 for the 16GB model and $299 for the 32GB model, in the U.S., Canada and major European countries. Price vary depending on the mobile operator. It features the same exterior design as the [[iPhone 3G]], but has new internal features such as video recording, voice control, digital compass, faster CPU, increased RAM etc.&lt;br /&gt;
&lt;br /&gt;
== Baseband ==&lt;br /&gt;
The iPhone 3G S uses the [[X-Gold 608]] baseband chip, same as in the iPhone 3G.&lt;br /&gt;
&lt;br /&gt;
== Application Processor ==&lt;br /&gt;
It makes use of the [[S5L8920]] application processor.&lt;br /&gt;
&lt;br /&gt;
== Specifications ==&lt;br /&gt;
'''Color''': Black or white &amp;lt;br&amp;gt;&lt;br /&gt;
'''Size''': 4.5 inches (115.5 mm) (h) × 2.4 inches (62.1 mm) (w) × 0.48 inch (12.3 mm) (d) &amp;lt;br&amp;gt;&lt;br /&gt;
'''Weight''': 135 g (4.8 oz) &amp;lt;br&amp;gt;&lt;br /&gt;
'''Battery''': Up to 12 hours of 2G talk, 5 hours of 3G talk, 5 (3G) or 9 (Wi-Fi) hours of Internet use, 10 hours of video playback, and up to 30 hours of audio playback, lasting over 300 hours on standby. &amp;lt;br&amp;gt;&lt;br /&gt;
'''3G''': Broadband data speeds, supporting 7.2Mbps HSDPA &amp;lt;br&amp;gt;&lt;br /&gt;
'''Camera''': 3.15MP with Autofocus and manual focus (''Tap to focus''), supporting VGA video recording @ 30FPS&lt;br /&gt;
&lt;br /&gt;
More specifications available in [http://www.gsmarena.com/apple_iphone_3g_s-2826.php GSMArena].&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Jailbreak iPhone2,1]]&lt;br /&gt;
* [[X-Gold 608 Unlock]]&lt;br /&gt;
* [[N88AP Device Tree]]&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.anandtech.com/gadgets/showdoc.aspx?i=3579 AnandTech: The iPhone 3GS Hardware Exposed &amp;amp; Analyzed]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=N88AP&amp;diff=4050</id>
		<title>N88AP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=N88AP&amp;diff=4050"/>
		<updated>2009-07-03T01:03:23Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:IPhone3GS.jpg|right|thumb|iPhone 3G S, back and front.]]&lt;br /&gt;
&lt;br /&gt;
This is the iPhone 3GS. It was released on June 19, 2009 with a price tag of $199 for the 16GB model and $299 for the 32GB model, in the U.S., Canada and major European countries. Price vary depending on the mobile operator. It features the same exterior design as the [[iPhone 3G]], but has new internal features such as video recording, voice control, digital compass, faster CPU, increased RAM etc.&lt;br /&gt;
&lt;br /&gt;
== Baseband ==&lt;br /&gt;
The iPhone 3G S uses the [[X-Gold 608]] baseband chip, same as in the iPhone 3G.&lt;br /&gt;
&lt;br /&gt;
== Application Processor ==&lt;br /&gt;
It makes use of the [[S5L8920]] application processor.&lt;br /&gt;
&lt;br /&gt;
== Specifications ==&lt;br /&gt;
'''Color''': Black or white &amp;lt;br&amp;gt;&lt;br /&gt;
'''Size''': 4.5 inches (115.5 mm) (h) × 2.4 inches (62.1 mm) (w) × 0.48 inch (12.3 mm) (d) &amp;lt;br&amp;gt;&lt;br /&gt;
'''Weight''': 135 g (4.8 oz) &amp;lt;br&amp;gt;&lt;br /&gt;
'''Battery''': Up to 12 hours of 2G talk, 5 hours of 3G talk, 5 (3G) or 9 (Wi-Fi) hours of Internet use, 10 hours of video playback, and up to 30 hours of audio playback, lasting over 300 hours on standby. &amp;lt;br&amp;gt;&lt;br /&gt;
'''3G''': Broadband data speeds, supporting 7.2Mbps HSDPA &amp;lt;br&amp;gt;&lt;br /&gt;
'''Camera''': 3.15MP with Autofocus and manual focus (''Tap to focus''), supporting VGA video recording @ 30FPS&lt;br /&gt;
&lt;br /&gt;
More specifications available in [http://www.gsmarena.com/apple_iphone_3g_s-2826.php GSMArena].&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Jailbreak iPhone2,1]]&lt;br /&gt;
* [[X-Gold 608 Unlock]]&lt;br /&gt;
* [[N88AP Device Tree]]&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://www.anandtech.com/gadgets/showdoc.aspx?i=3579 AnandTech: The iPhone 3GS Hardware Exposed &amp;amp; Analyzed]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=ECID&amp;diff=3984</id>
		<title>ECID</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=ECID&amp;diff=3984"/>
		<updated>2009-06-26T13:33:06Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Exclusive Chip ID''' or ECID, is a 3GS device specific numeric identifier which is sent to Apple during a restore. The ECID is included in a new, device specific, signed img3 file and sent back to iTunes for the restore process to proceed.&lt;br /&gt;
&lt;br /&gt;
The implication of this is Apple could dissallow downgrades (even via DFU) on newer devices and even on older devices once new firmware is released.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=ECID&amp;diff=3983</id>
		<title>ECID</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=ECID&amp;diff=3983"/>
		<updated>2009-06-26T13:32:45Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Exclusive Chip ID Tag''' or ECID, is a 3GS device specific numeric identifier which is sent to Apple during a restore. The ECID is included in a new, device specific, signed img3 file and sent back to iTunes for the restore process to proceed.&lt;br /&gt;
&lt;br /&gt;
The implication of this is Apple could dissallow downgrades (even via DFU) on newer devices and even on older devices once new firmware is released.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=ECID&amp;diff=3982</id>
		<title>ECID</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=ECID&amp;diff=3982"/>
		<updated>2009-06-26T13:31:58Z</updated>

		<summary type="html">&lt;p&gt;Drg: New page: The '''Exclusive Chip ID Tag''' or ECID, is a 3GS device specific numeric identifier which is sent to Apple during a restore. The ECID included in a new, device specific, signed img3 file ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Exclusive Chip ID Tag''' or ECID, is a 3GS device specific numeric identifier which is sent to Apple during a restore. The ECID included in a new, device specific, signed img3 file abd sent back to iTunes.&lt;br /&gt;
&lt;br /&gt;
The implication of this is Apple could dissallow downgrades (even via DFU) on newer devices and even on older devices once new firmware is released.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Jailbreak_(S5L8920%2B)&amp;diff=3981</id>
		<title>Jailbreak (S5L8920+)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Jailbreak_(S5L8920%2B)&amp;diff=3981"/>
		<updated>2009-06-26T13:27:31Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* ECID */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Apple did not have the time to fix the [[24kpwn]] hole in the [[S5L8920 (Bootrom)|iPhone 3G[s] Bootrom]]. Thus, the following needs to be done:&lt;br /&gt;
* '''Find [[iBoot]] exploit''' - In order to flash 24kPwned [[LLB]].&lt;br /&gt;
* '''&amp;quot;Port&amp;quot; the [[24kpwn]] exploit''' - In order to run our patched [[LLB]] and to skip the ECID checks.&lt;br /&gt;
&lt;br /&gt;
==ECID==&lt;br /&gt;
Apple added a new tag to the img3 format called ECID. The ECID is ''unique'' to each phone, and is being sigchecked. So Apple could block downgrades once newer firmware becomes available, unless you have a dump of your unique old firmware's img3 or signed certificate. Therefore, iBoot exploits won't be so useful for tethered JBs, because such exploits will be closed in new FWs. [http://iphonejtag.blogspot.com/2009/06/ecid-field-downgrades-no-dice.html].&lt;br /&gt;
&lt;br /&gt;
The issue with this is that, even with [[24kpwn]] still in bootrom, an [[iBoot]] exploit is still needed to actually flash the 24kpwned [[LLB]]. If Apple uses this ECID stuff to block downgrades, then a new [[iBoot]] exploit will be needed whenever they fix the last, so that [[24kpwn]] can be applied. This is because Apple could choose to not let you upload an older / exploitable iBEC / iBoot / iBSS to the device. 3GS owners can save a signed certificate which will always allow downgrades to 3.0 7A341 using http://purplera1n.com/ should Apple try to block this in the future.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Jailbreak_(S5L8920%2B)&amp;diff=3980</id>
		<title>Jailbreak (S5L8920+)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Jailbreak_(S5L8920%2B)&amp;diff=3980"/>
		<updated>2009-06-26T13:24:14Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* ECID */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Apple did not have the time to fix the [[24kpwn]] hole in the [[S5L8920 (Bootrom)|iPhone 3G[s] Bootrom]]. Thus, the following needs to be done:&lt;br /&gt;
* '''Find [[iBoot]] exploit''' - In order to flash 24kPwned [[LLB]].&lt;br /&gt;
* '''&amp;quot;Port&amp;quot; the [[24kpwn]] exploit''' - In order to run our patched [[LLB]] and to skip the ECID checks.&lt;br /&gt;
&lt;br /&gt;
==ECID==&lt;br /&gt;
Apple added a new tag to the img3 format called ECID. The ECID is ''unique'' to each phone, and is being sigchecked. So Apple could block downgrades once newer firmware becomes available, unless you have a dump of your unique old firmware's img3 or signed certificate. Therefore, iBoot exploits won't be so useful for tethered JBs, because such exploits will be closed in new FWs. [http://iphonejtag.blogspot.com/2009/06/ecid-field-downgrades-no-dice.html].&lt;br /&gt;
&lt;br /&gt;
The issue with this is that, even with [[24kpwn]] still in bootrom, an [[iBoot]] exploit is still needed to actually flash the 24kpwned [[LLB]]. If Apple uses this ECID stuff to block downgrades, than a new [[iBoot]] exploit will be needed whenever they fix the last, so that [[24kpwn]] can be applied. This is because Apple could choose to not let you upload an older / exploitable iBEC / iBoot / iBSS to the device. If you go to http://purplera1n.com/ now though and save the file, you will be OK.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Jailbreak_(S5L8920%2B)&amp;diff=3979</id>
		<title>Jailbreak (S5L8920+)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Jailbreak_(S5L8920%2B)&amp;diff=3979"/>
		<updated>2009-06-26T13:22:07Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Apple did not have the time to fix the [[24kpwn]] hole in the [[S5L8920 (Bootrom)|iPhone 3G[s] Bootrom]]. Thus, the following needs to be done:&lt;br /&gt;
* '''Find [[iBoot]] exploit''' - In order to flash 24kPwned [[LLB]].&lt;br /&gt;
* '''&amp;quot;Port&amp;quot; the [[24kpwn]] exploit''' - In order to run our patched [[LLB]] and to skip the ECID checks.&lt;br /&gt;
&lt;br /&gt;
==ECID==&lt;br /&gt;
Apple added a new tag to the img3 format called ECID. The ECID is ''unique'' to each phone, and is being sigchecked. So no downgrades unless you have a dump of your unique old firmware's img3. Therefore, iBoot exploits won't be so useful for tethered JBs, because such exploits will be closed in new FWs. [http://iphonejtag.blogspot.com/2009/06/ecid-field-downgrades-no-dice.html].&lt;br /&gt;
&lt;br /&gt;
The issue with this is that, even with [[24kpwn]] still in bootrom, and [[iBoot]] exploit is still needed to actually flash the 24kpwned [[LLB]]. If Apple uses this ECID stuff to block downgrades, than a new [[iBoot]] exploit will be needed whenever they fix the last, so that [[24kpwn]] can be applied. This is because Apple could choose to not let you upload an older / exploitable iBEC / iBoot / iBSS to the device. If you go to http://purplera1n.com/ now though and save the file, you will be OK.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=3963</id>
		<title>Purplera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=3963"/>
		<updated>2009-06-26T02:06:33Z</updated>

		<summary type="html">&lt;p&gt;Drg: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This appears to be the codename for geohot's 3GS jailbreak. &lt;br /&gt;
-------------&lt;br /&gt;
As of now the domain purplera1n.com will allow 3GS users to generate a unique certificate for iBSS. This will allow downgrades to 3.0 (for exploit purposes) should Apple one day stop issuing these certs.&lt;br /&gt;
http://iphonejtag.blogspot.com/2009/06/usbdump-huh-how.html&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=3962</id>
		<title>Purplera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Purplera1n&amp;diff=3962"/>
		<updated>2009-06-26T02:05:56Z</updated>

		<summary type="html">&lt;p&gt;Drg: New page:  This appears to be the codename for geohot's 3GS jailbreak. As of now the domain purplera1n.com will allow 3GS users to generate a unique certificate for iBSS. This will allow downgrades ...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
This appears to be the codename for geohot's 3GS jailbreak. As of now the domain purplera1n.com will allow 3GS users to generate a unique certificate for iBSS. This will allow downgrades to 3.0 (for exploit purposes) should Apple one day stop issuing these certs.&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Main_Page&amp;diff=3866</id>
		<title>Talk:Main Page</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Main_Page&amp;diff=3866"/>
		<updated>2009-06-18T03:49:21Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* firmware keys */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== firmware keys ==&lt;br /&gt;
We need a &amp;quot;standard&amp;quot; for firmware key posting so that we can stay organized. Who likes this method?&lt;br /&gt;
* [[Kirkwood 7A341 (iPhone 3G)]]&lt;br /&gt;
* [[Kirkwood 7A341 (iPod touch 2G)]]&lt;br /&gt;
&lt;br /&gt;
-----&lt;br /&gt;
&lt;br /&gt;
Love it. -drg&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3494</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3494"/>
		<updated>2009-04-13T14:15:04Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* About */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8. This tool will not work with BL 5.9 or the newly reported 6.0.2.&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
===Português===&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui: [[Baseband Commands]]&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
===English===&lt;br /&gt;
To run the pHaseBanDowngrader, connect to your iPhone via SSH and copy the downloaded folder (phasebandowngrader) into the &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader in lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, install minicom and run at+xgendata (see [[Baseband Commands]] for more info)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3489</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3489"/>
		<updated>2009-04-13T04:47:14Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* English */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
===Português===&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui: [[Baseband Commands]]&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
===English===&lt;br /&gt;
To run the pHaseBanDowngrader, connect to your iPhone via SSH and copy the downloaded folder (phasebandowngrader) into the &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader in lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, install minicom and run at+xgendata (see [[Baseband Commands]] for more info)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3488</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3488"/>
		<updated>2009-04-13T04:45:25Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Credits */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
===Português===&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui: [[Baseband Commands]]&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
===English===&lt;br /&gt;
To run the pHaseBanDowngrader, connect via SSH to your iPhone and copy the downloaded folder (phasebandowngrader) into the folder &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader with lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd / Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, install minicom and run at+xgendata (see [[Baseband Commands]] for more info)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3487</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3487"/>
		<updated>2009-04-13T04:45:03Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* Credits */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&lt;br /&gt;
&lt;br /&gt;
Patch Implementation: [[Geohot]]&lt;br /&gt;
&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
===Português===&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui: [[Baseband Commands]]&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
===English===&lt;br /&gt;
To run the pHaseBanDowngrader, connect via SSH to your iPhone and copy the downloaded folder (phasebandowngrader) into the folder &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader with lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd / Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, install minicom and run at+xgendata (see [[Baseband Commands]] for more info)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3482</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3482"/>
		<updated>2009-04-13T03:06:58Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* README */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
'''Português:'''&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
'''English:''' &lt;br /&gt;
&lt;br /&gt;
To run the pHaseBanDowngrader, connect via SSH to your iPhone and copy the downloaded folder (phasebandowngrader) into the folder &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader with lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd / Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, visit:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(run at+xgendata in minicom)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3481</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3481"/>
		<updated>2009-04-13T03:06:47Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* README */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
'''Português:'''&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
'''English:''' &lt;br /&gt;
To run the pHaseBanDowngrader, connect via SSH to your iPhone and copy the downloaded folder (phasebandowngrader) into the folder &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader with lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd / Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, visit:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(run at+xgendata in minicom)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3480</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3480"/>
		<updated>2009-04-13T03:05:27Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* README */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
_____________________________________________________________&lt;br /&gt;
Português:&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
_____________________________________________________________&lt;br /&gt;
English: &lt;br /&gt;
&lt;br /&gt;
To run the pHaseBanDowngrader, connect via SSH to your iPhone and copy the downloaded folder (phasebandowngrader) into the folder &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader with lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd / Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, visit:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(run at+xgendata in minicom)&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Baseband_Commands&amp;diff=3478</id>
		<title>Baseband Commands</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Baseband_Commands&amp;diff=3478"/>
		<updated>2009-04-13T02:01:06Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* How to run Baseband Commands */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
In this page, you'll find some Baseband Commands. You can use them with Minicom 2.2, that can be found on Cydia.&lt;br /&gt;
&lt;br /&gt;
==Setting up Minicom 2.2==&lt;br /&gt;
# After installing Minicom from Cydia, make sure the folder /usr/etc exists. SSH into your iPhone and then, type: ''minicom -s''.&lt;br /&gt;
# Now, select ''Serial Port Setup'' in the Menu and press Enter. Then, press &amp;quot;a&amp;quot; and set Serial Device to ''/dev/tty.debug''.&lt;br /&gt;
# Press Esc, and in the Main Menu, select ''Save setup as dfl''. Now, select &amp;quot;exit&amp;quot;.&lt;br /&gt;
# To run minicom using ssh, just run minicom -w&lt;br /&gt;
&lt;br /&gt;
==Running Minicom 2.2 from MobileTerminal==&lt;br /&gt;
'''Note''': minicom does work on MobileTerminal only on root (use su) and only after it has been configured (through the steps above).&lt;br /&gt;
# Open MobileTerminal.&lt;br /&gt;
# Run the command su, enter your root password (default alpine) and then run minicom -w.&lt;br /&gt;
# To exit minicom, slide your finger on the screen (&amp;quot;gesture&amp;quot;) to the bottom right (if you haven't changed this setting in MobileTerminal settings), then press A, X and enter.&lt;br /&gt;
&lt;br /&gt;
==How to run Baseband Commands==&lt;br /&gt;
&lt;br /&gt;
First, run Minicom. Then, type &amp;quot;at&amp;quot; and press Enter. Then, you can type the command that you want, have fun.&lt;br /&gt;
&lt;br /&gt;
==Baseband Commands==&lt;br /&gt;
===Getting Information===&lt;br /&gt;
* '''at+xgendata''': Display some baseband informations&lt;br /&gt;
* '''at&amp;amp;v''': Display the profiles in the Baseband (Active Profile, Stored Profile 0 and Stored Profile 1)&lt;br /&gt;
* '''at+clac''': Show some baseband commands&lt;br /&gt;
* '''at&amp;amp;h''': Show more Baseband Commands&lt;br /&gt;
&lt;br /&gt;
===Unlock===&lt;br /&gt;
* '''at+clck''': Traditional unlock command&lt;br /&gt;
* '''at+xlock''': Wildcard unlock&lt;br /&gt;
* '''at+xsimstate''': Print lock state (write at+xsimstate=1 to turn on, at+xsimstate=0 to turn off)&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3477</id>
		<title>PHaseBanDowngrader</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=PHaseBanDowngrader&amp;diff=3477"/>
		<updated>2009-04-13T02:00:13Z</updated>

		<summary type="html">&lt;p&gt;Drg: /* About */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==About==&lt;br /&gt;
pHaseBanDowngrader is a tool that allows the user to downgrade the [[iPhone 3G]] Baseband from 02.30.03 to 02.28.00 with the [[Baseband Bootloader]] 5.8 (This tool will not work with BL 5.9).&lt;br /&gt;
&lt;br /&gt;
==Credits==&lt;br /&gt;
Exploit: [[Geohot]] and [[iPhone Dev Team]], independently&amp;lt;br&amp;gt;&lt;br /&gt;
Patch Implementation: [[Geohot]]&amp;lt;br&amp;gt;&lt;br /&gt;
Script: pH with thanks to EvilPenguin&lt;br /&gt;
&lt;br /&gt;
==README==&lt;br /&gt;
pHaseBanDowngrader - by Pedro Henrique Cavallieri Franceschi.&lt;br /&gt;
(a.k.a. pH).&lt;br /&gt;
&lt;br /&gt;
_____________________________________________________________&lt;br /&gt;
Português:&lt;br /&gt;
&lt;br /&gt;
Para rodar o pHaseBanDowngrader, conecte via SSH ao seu iPhone e copie a pasta baixada (phasebandowngrader) para dentro da pasta &amp;quot;/Applications&amp;quot; no seu iPhone.&lt;br /&gt;
OBS: A pasta TEM que se chamar phasebandowngrader, com letras minúsculas!&lt;br /&gt;
&lt;br /&gt;
Para rodá-lo, entre no MobileTerminal e digite &amp;quot;login&amp;quot;. O usuário é &amp;quot;root&amp;quot; e a senha é &amp;quot;alpine&amp;quot; por padrão. Depois, digite: &amp;quot;cd /Applications/phasebandowngrader/&amp;quot; e, em seguida, por final, para rodar o downgrader, digite &amp;quot;./phasebandowngrader&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Para checar a versão do seu Bootloader, mais informações aqui:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(rode o at+xgendata no minicom)&lt;br /&gt;
&lt;br /&gt;
_____________________________________________________________&lt;br /&gt;
English: &lt;br /&gt;
&lt;br /&gt;
To run the pHaseBanDowngrader, connect via SSH to your iPhone and copy the downloaded folder (phasebandowngrader) into the folder &amp;quot;/Applications&amp;quot; on your iPhone. &lt;br /&gt;
Note: The folder MUST named phasebandowngrader with lowercase letters! &lt;br /&gt;
&lt;br /&gt;
To run it, open MobileTerminal and type &amp;quot;login&amp;quot;. The user is &amp;quot;root&amp;quot; and password is &amp;quot;alpine&amp;quot; by default. Then type: &amp;quot;cd / Applications/phasebandowngrader/&amp;quot;, then, to run the downgrader, type &amp;quot;./phasebandowngrader&amp;quot;&lt;br /&gt;
&lt;br /&gt;
To check your bootloader version, visit:&lt;br /&gt;
http://www.theiphonewiki.com/wiki/index.php?title=Baseband_Commands&lt;br /&gt;
&lt;br /&gt;
(run at+xgendata in minicom)&lt;br /&gt;
&lt;br /&gt;
_____________________________________________________________&lt;br /&gt;
&lt;br /&gt;
Copyright (C) - 2009&lt;br /&gt;
iBlogeek.com - Todos os direitos reservados&lt;br /&gt;
All rights reserved.&lt;br /&gt;
&lt;br /&gt;
By pH - 12/04/2009&lt;br /&gt;
&lt;br /&gt;
==Download links==&lt;br /&gt;
* [http://tinyurl.com/phasebandowngrader10 MediaFire]&lt;/div&gt;</summary>
		<author><name>Drg</name></author>
		
	</entry>
</feed>