<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Leobruh</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Leobruh"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/Leobruh"/>
	<updated>2026-05-08T15:48:33Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=JailbreakMe&amp;diff=17174</id>
		<title>JailbreakMe</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=JailbreakMe&amp;diff=17174"/>
		<updated>2011-04-02T17:29:30Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;JailbreakMe is a site that has been used multiple times to jailbreak iDevices. It is currently online with the [[Star]] Jailbreak by [[User:Comex|comex]].&lt;br /&gt;
&lt;br /&gt;
==First Incarnation (AppSnapp)==&lt;br /&gt;
Initially, [http://www.conceitedsoftware.com/ Conceited Software] utilized the [[LibTiff]] exploit with jailbreakme.com, which also went by the name &amp;quot;AppSnapp,&amp;quot; to jailbreak iOS 1.1.1. Upon the release of iOS 2.0 and the debut of the App Store, Conceited Software closed JailbreakMe, when it remained dormant for a while.&lt;br /&gt;
&lt;br /&gt;
==Second Incarnation (Star)==&lt;br /&gt;
[[User:Comex|comex]] has since repurposed the domain for [[Star]], his userland [[jailbreak]] for iOS 3.1.2 through 4.3 (comex stated that the bug used for the untethered jailbreak was there until 4.3 and was patched at 4.3.1 in order to prevent the jailbreak of the iPad 2)&lt;br /&gt;
==External Link==&lt;br /&gt;
[http://jailbreakme.com/ JailbreakME.com]&lt;br /&gt;
&lt;br /&gt;
{{stub|jailbreaking}}&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=16935</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=16935"/>
		<updated>2011-03-20T17:41:05Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. --[[User:Lilstevie|Lilstevie]] 09:45, 20 August 2010 (UTC)- lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
The baseband processor checks the signature, not the application processor. [[User:dogbert|dogbert]] 18:36, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
ahh got ya! but would my theory work though through an exploit such as AT+XAPP? instead of a payload it just changes the .plist? [[User:Leobruh|Leobruh]] 00:15, 20 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
:you would still require the valid NCK for it to process the unlock in that method, the current way the payloads work for exploits in the baseband processor are adequate --[[User:Lilstevie|Lilstevie]] 09:44, 20 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:i thought NKC was only for the iPhone 2G? 0.o [[User:Leobruh|Leobruh]] 14:47, 21 August 2010 (UTC)!&lt;br /&gt;
::NCK or Network Code Key is on any cellular device that gets locked to a carrier --[[User:Lilstevie|Lilstevie]] 14:52, 19 September 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Is there are ability to decode WildcardTicket received from Apple to see NCK or lockstate table?&lt;br /&gt;
What about unlocked by request to carrier iPhones? Is it some differences in WildcardTicket? --[[User:Requilence|Requilence]] 13:17, 20 March 2011 (UTC)&lt;br /&gt;
&lt;br /&gt;
:Decrypting is possible since the key is known. Changing the ticket is, however, not possible since it breaks the signatures. For carrier unlocked phones, Apple sends a new WildcardTicket without a lock table during sync.--[[User:Dogbert|Dogbert]] 16:43, 20 March 2011 (UTC)&lt;br /&gt;
&lt;br /&gt;
::Tell me this, if the signature is broken, what happens to the phone? DFU, Recovery...? [[User:Leobruh|Leobruh]] 17:41, 20 March 2011 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User_talk:Planetbeing&amp;diff=16581</id>
		<title>User talk:Planetbeing</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User_talk:Planetbeing&amp;diff=16581"/>
		<updated>2011-03-02T22:51:46Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Does anyone know what has happened to planetbeing? he has seem to have dropped off the rador for a while now. --[[User:Dopeyrat|Dopeyrat]] 11:50, 2 March 2011 (UTC)&lt;br /&gt;
:Planetbeing likes to go into hiding between mid-August to May. He surfaces to the iPhone Community around June to early-August. [[User:Leobruh|Leobruh]]!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:AT%2BXAPP_Vulnerability&amp;diff=16439</id>
		<title>Talk:AT+XAPP Vulnerability</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:AT%2BXAPP_Vulnerability&amp;diff=16439"/>
		<updated>2011-02-24T23:20:46Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I try to find the xapp command in the disassembly. Is it right that it is in the stack.fls file? I cant find a &amp;quot;xapp&amp;quot; string ... Can someone help me? ~chrisude&lt;br /&gt;
&lt;br /&gt;
In a more general sense I'd like to know the same. As to not being able to find the xapp string, which baseband are you looking at? I can verify that the 05.11.07 baseband does have xapp (at offset 62F5AF, 63B217, 37E4D5 (and xapp_get at 513D18, cmd_xapp.app at 632619). Which you're suppose to look at exactly I'd like to know also.&lt;br /&gt;
So if someone could please give a small intro as to how to find the AT+ commands (main) routine, please fill out. Thanks in advance! ~toomuchjames&lt;br /&gt;
&lt;br /&gt;
Anyone?&lt;br /&gt;
&lt;br /&gt;
Okay so like this can't be real can it? I know it's not relavant to this exploit but I just wanna know.&lt;br /&gt;
http://pastie.org/pastes/1568212 [[User:Leobruh|Leobruh]] 23:20, 24 February 2011 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=16010</id>
		<title>Talk:XMM6180</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=16010"/>
		<updated>2011-02-10T20:43:11Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Flash Possibility */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Flash Possibility ==&lt;br /&gt;
Okay, so hypothetically speaking, if I flashed my baseband to [[1.59.00]] from [[3.10.01]] while my phone is on 4.2.1 (ONLY 4.2.1 [[SHSH]] IS AVAILABLE), it would enter the boot loop because the baseband doesnt meet the requirements for [[iOS]] 4.2.1. I am willing to try and flash my baseband in an attempt to downgrade and use [[ultrasn0w]]. And if the downgrade was to work and I restored it to a pwned 4.2.1 fw where the baseband update would be neglected, would the boot loop occur? [[User:Leobruh|Leobruh]] 01:20, 10 February 2011 (UTC)!&lt;br /&gt;
:You can't flash baseband [[1.59.00]]; Apple's not signing it anymore. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 02:47, 10 February 2011 (UTC)&lt;br /&gt;
:Well look at [http://tysiphonehelp.com/forum/showthread.php?7908-Manually-flash-iphone-to-05.11.07-baseband this]. I don't know whether or not this could be done to the [[n90ap|iPhone 4]] but it proves that a manual flash can be used so long as you have the proper firmware ipsw available. I mean if this is possible for the [[n90ap|iPhone 4]], then I will do it without a doubt. [[User:Leobruh|Leobruh]] 04:05, 10 February 2011 (UTC)!&lt;br /&gt;
::Um, that is for the iPhone 3G/3GS basebands. That probably wont work on the [[n90ap|iPhone 4]]. For those devices, Apple didn't sign the baseband, so a manual flash was possible (going up version #'s). Downgrading required one to have the 5.8 bootloader iPhone 3G. Sorry to burst your bubble, but you are mistaken. --[[User:Gamer765|Gamer765]] 04:28, 10 February 2011 (UTC)&lt;br /&gt;
:::Word I got you bro, haha I wish it would be easier I have had an i4 for almost 2 months with the carrier lock. I will keep waiting sooner or later it will come out. [[User:Leobruh|Leobruh]] 20:43, 10 February 2011 (UTC)!&lt;br /&gt;
&lt;br /&gt;
== Device for iPhone 4 ==&lt;br /&gt;
Are we sure this is the baseband? The infineon spec-sheet says &amp;quot;HSDPA/HSUPA capabilities of 7.2Mbps/2.9Mbps&amp;quot;.  At the keynote Steve mentioned 5.8Mbps HSUPA. --[[User:Iemit737|Iemit737]] 19:26, 21 June 2010 (UTC)&lt;br /&gt;
:Running &amp;quot;string&amp;quot; on the new baseband files shows &amp;quot;XGold 618&amp;quot; multiple times. --[[User:Miketress|Miketress]] 19:35, 21 June 2010 (UTC)&lt;br /&gt;
::Ok, awesome. Thanks for finding this so quickly! [[User:Iemit737|Iemit737]] 19:50, 21 June 2010 (UTC)&lt;br /&gt;
:::Very unlikely it's the 618 after looking at the spec sheet.&lt;br /&gt;
In case anyone is interested, [http://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a39470bb00555 X-Gold 616 spec sheet], [https://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a3948dc76055b X-Gold 618 spec sheet]. --[[User:D235j|D235j]] 21:43, 22 June 2010 (UTC)&lt;br /&gt;
::::Actually, it's the XMM 6180. ebl.fls says so. --[[User:Oranav|oranav]] 21:56, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Downgrade ==&lt;br /&gt;
Anybody knows more about the bb downgrade signatures? Or how to backup them like the shsh certs? Or how to use the replay attack here? Actually this is more related to baseband firmware and not to this iPhone 4 hardware. [[User:http|http]]&lt;br /&gt;
:The baseband is signed with an [[AT+XNONCE]] which is a random string generated on every bootup. Therefore, it is not possible to cache the SHSH signatures with a replay attack. I think this info either belongs on this page because it is specific to its baseband or  in a special section on [[Baseband Firmware]]. [[User:Iemit737|Iemit737]] 18:18, 16 July 2010 (UTC)&lt;br /&gt;
::Ah, that's what [[User:MuscleNerd|MuscleNerd]] meant with [http://twitter.com/MuscleNerd/status/18667056119 &amp;quot;stricter signed&amp;quot;]. I also found [http://iphwn.org/nonce.txt this example]. And someone suggested to change iTunes to always send the same string. That would work, but BB wouldn't accept the response. My only idea would be to let BB generate (or store) the same string on every boot (I don't know how though). But even then we would have to backup the signatures at the time they were available. -- [[User:Http|http]] 23:11, 16 July 2010 (UTC)&lt;br /&gt;
:::So how does TinyUmbrella give baseband protection ? ---Whiteshinyapple&lt;br /&gt;
::::It manages to error out the signature for the baseband, that's why you get the 1004 error, not sure exactly how it's done but I'd assume that's how. ---OMEGA_RAZER&lt;br /&gt;
:::::I think there's not much to do. When hosts is pointing to Cydia, you also won't get baseband downgraded, even if it would work when pointing to real Apple server. Same should apply for upgrade. Maybe local TSS server from TinyUmbrella just handles error returns better, so that firmware up/downgrade doesn't fail - maybe it just returns an invalid certificate for the baseband, but returns 'ok'. --[[User:Http|http]] 11:08, 9 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=15993</id>
		<title>Talk:XMM6180</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=15993"/>
		<updated>2011-02-10T04:05:44Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Flash Possibility */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Flash Possibility ==&lt;br /&gt;
Okay, so hypothetically speaking, if I flashed my baseband to 1.59.00 from 3.10.01 while my phone is on 4.2.1 (ONLY 4.2.1 SHSH IS AVAILABLE), it would enter the boot loop because the baseband doesnt meet the requirements for iOS 4.2.1. I am willing to try and flash my baseband in an attempt to downgrade and use ultrasn0w. And if the downgrade was to work and I restored it to a pwned 4.2.1 fw where the baseband update would be neglected, would the boot loop occur? [[User:Leobruh|Leobruh]] 01:20, 10 February 2011 (UTC)!&lt;br /&gt;
:You can't flash baseband 1.59.00; Apple's not signing it anymore. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 02:47, 10 February 2011 (UTC)&lt;br /&gt;
&lt;br /&gt;
Well look at this, http://tysiphonehelp.com/forum/showthread.php?7908-Manually-flash-iphone-to-05.11.07-baseband . I don't know whether or not this could be done to the iPhone 4 but it proves that a manual flash can be used so long as you have the proper firmware ipsw available. I mean if this is possible for the iPhone 4, then I will do it without a doubt. [[User:Leobruh|Leobruh]] 04:05, 10 February 2011 (UTC)!&lt;br /&gt;
&lt;br /&gt;
== Device for iPhone 4 ==&lt;br /&gt;
&lt;br /&gt;
Are we sure this is the baseband? &lt;br /&gt;
&lt;br /&gt;
The infineon spec-sheet says &amp;quot;HSDPA/HSUPA capabilities of 7.2Mbps/2.9Mbps&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
At the keynote Steve mentioned 5.8Mbps HSUPA.&lt;br /&gt;
[[User:Iemit737|Iemit737]] 19:26, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Running &amp;quot;string&amp;quot; on the new baseband files shows &amp;quot;XGold 618&amp;quot; multiple times.&lt;br /&gt;
--[[User:Miketress|Miketress]] 19:35, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Ok, awesome. Thanks for finding this so quickly! [[User:Iemit737|Iemit737]] 19:50, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Very unlikely it's the 618 after looking at the spec sheet.&lt;br /&gt;
In case anyone is interested, [http://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a39470bb00555 | X-Gold 616 spec sheet], [https://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a3948dc76055b | X-Gold 618 spec sheet].&lt;br /&gt;
[[User:D235j|D235j]] 21:43, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Actually, it's the XMM 6180. ebl.fls says so. --[[User:Oranav|oranav]] 21:56, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Downgrade ==&lt;br /&gt;
&lt;br /&gt;
Anybody knows more about the bb downgrade signatures? Or how to backup them like the shsh certs? Or how to use the replay attack here? Actually this is more related to baseband firmware and not to this iPhone 4 hardware. [[User:http|http]]&lt;br /&gt;
&lt;br /&gt;
The baseband is signed with an [[AT+XNONCE]] which is a random string generated on every bootup. Therefore, it is not possible to cache the SHSH signatures with a replay attack. I think this info either belongs on this page because it is specific to its baseband or  in a special section on [[Baseband Firmware]]. [[User:Iemit737|Iemit737]] 18:18, 16 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Ah, that's what [[User:MuscleNerd|MuscleNerd]] meant with [http://twitter.com/MuscleNerd/status/18667056119 &amp;quot;stricter signed&amp;quot;]. I also found [http://iphwn.org/nonce.txt this example]. And someone suggested to change iTunes to always send the same string. That would work, but BB wouldn't accept the response. My only idea would be to let BB generate (or store) the same string on every boot (I don't know how though). But even then we would have to backup the signatures at the time they were available. -- [[User:Http|http]] 23:11, 16 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
So how does TinyUmbrella give baseband protection ? ---Whiteshinyapple&lt;br /&gt;
&lt;br /&gt;
It manages to error out the signature for the baseband, that's why you get the 1004 error, not sure exactly how it's done but I'd assume that's how. ---OMEGA_RAZER&lt;br /&gt;
&lt;br /&gt;
I think there's not much to do. When hosts is pointing to Cydia, you also won't get baseband downgraded, even if it would work when pointing to real Apple server. Same should apply for upgrade. Maybe local TSS server from TinyUmbrella just handles error returns better, so that firmware up/downgrade doesn't fail - maybe it just returns an invalid certificate for the baseband, but returns 'ok'. -- [[User:Http|http]] 11:08, 9 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=15991</id>
		<title>Talk:XMM6180</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=15991"/>
		<updated>2011-02-10T01:20:52Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Flash Possibility */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Flash Possibility ==&lt;br /&gt;
Okay, so hypothetically speaking, if I flashed my baseband to 1.59.00 from 3.10.01 while my phone is on 4.2.1 (ONLY 4.2.1 SHSH IS AVAILABLE), it would enter the boot loop because the baseband doesnt meet the requirements for iOS 4.2.1. I am willing to try and flash my baseband in an attempt to downgrade and use ultrasn0w. And if the downgrade was to work and I restored it to a pwned 4.2.1 fw where the baseband update would be neglected, would the boot loop occur? [[User:Leobruh|Leobruh]] 01:20, 10 February 2011 (UTC)!&lt;br /&gt;
&lt;br /&gt;
== Device for iPhone 4 ==&lt;br /&gt;
&lt;br /&gt;
Are we sure this is the baseband? &lt;br /&gt;
&lt;br /&gt;
The infineon spec-sheet says &amp;quot;HSDPA/HSUPA capabilities of 7.2Mbps/2.9Mbps&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
At the keynote Steve mentioned 5.8Mbps HSUPA.&lt;br /&gt;
[[User:Iemit737|Iemit737]] 19:26, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Running &amp;quot;string&amp;quot; on the new baseband files shows &amp;quot;XGold 618&amp;quot; multiple times.&lt;br /&gt;
--[[User:Miketress|Miketress]] 19:35, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Ok, awesome. Thanks for finding this so quickly! [[User:Iemit737|Iemit737]] 19:50, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Very unlikely it's the 618 after looking at the spec sheet.&lt;br /&gt;
In case anyone is interested, [http://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a39470bb00555 | X-Gold 616 spec sheet], [https://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a3948dc76055b | X-Gold 618 spec sheet].&lt;br /&gt;
[[User:D235j|D235j]] 21:43, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Actually, it's the XMM 6180. ebl.fls says so. --[[User:Oranav|oranav]] 21:56, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Downgrade ==&lt;br /&gt;
&lt;br /&gt;
Anybody knows more about the bb downgrade signatures? Or how to backup them like the shsh certs? Or how to use the replay attack here? Actually this is more related to baseband firmware and not to this iPhone 4 hardware. [[User:http|http]]&lt;br /&gt;
&lt;br /&gt;
The baseband is signed with an [[AT+XNONCE]] which is a random string generated on every bootup. Therefore, it is not possible to cache the SHSH signatures with a replay attack. I think this info either belongs on this page because it is specific to its baseband or  in a special section on [[Baseband Firmware]]. [[User:Iemit737|Iemit737]] 18:18, 16 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Ah, that's what [[User:MuscleNerd|MuscleNerd]] meant with [http://twitter.com/MuscleNerd/status/18667056119 &amp;quot;stricter signed&amp;quot;]. I also found [http://iphwn.org/nonce.txt this example]. And someone suggested to change iTunes to always send the same string. That would work, but BB wouldn't accept the response. My only idea would be to let BB generate (or store) the same string on every boot (I don't know how though). But even then we would have to backup the signatures at the time they were available. -- [[User:Http|http]] 23:11, 16 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
So how does TinyUmbrella give baseband protection ? ---Whiteshinyapple&lt;br /&gt;
&lt;br /&gt;
It manages to error out the signature for the baseband, that's why you get the 1004 error, not sure exactly how it's done but I'd assume that's how. ---OMEGA_RAZER&lt;br /&gt;
&lt;br /&gt;
I think there's not much to do. When hosts is pointing to Cydia, you also won't get baseband downgraded, even if it would work when pointing to real Apple server. Same should apply for upgrade. Maybe local TSS server from TinyUmbrella just handles error returns better, so that firmware up/downgrade doesn't fail - maybe it just returns an invalid certificate for the baseband, but returns 'ok'. -- [[User:Http|http]] 11:08, 9 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=15990</id>
		<title>Talk:XMM6180</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:XMM6180&amp;diff=15990"/>
		<updated>2011-02-10T01:20:30Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Flash Possibility ==&lt;br /&gt;
Okay, so hypothetically speaking, if I flashed my baseband to 1.59.00 from 3.10.01 while my phone is on 4.2.1 (ONLT 4.2.1 SHSH IS AVAILABLE), it would enter the boot loop because the baseband doesnt meet the requirements for iOS 4.2.1. I am willing to try and flash my baseband in an attempt to downgrade and use ultrasn0w. And if the downgrade was to work and I restored it to a pwned 4.2.1 fw where the baseband update would be neglected, would the boot loop occur? [[User:Leobruh|Leobruh]] 01:20, 10 February 2011 (UTC)!&lt;br /&gt;
&lt;br /&gt;
== Device for iPhone 4 ==&lt;br /&gt;
&lt;br /&gt;
Are we sure this is the baseband? &lt;br /&gt;
&lt;br /&gt;
The infineon spec-sheet says &amp;quot;HSDPA/HSUPA capabilities of 7.2Mbps/2.9Mbps&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
At the keynote Steve mentioned 5.8Mbps HSUPA.&lt;br /&gt;
[[User:Iemit737|Iemit737]] 19:26, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Running &amp;quot;string&amp;quot; on the new baseband files shows &amp;quot;XGold 618&amp;quot; multiple times.&lt;br /&gt;
--[[User:Miketress|Miketress]] 19:35, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Ok, awesome. Thanks for finding this so quickly! [[User:Iemit737|Iemit737]] 19:50, 21 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Very unlikely it's the 618 after looking at the spec sheet.&lt;br /&gt;
In case anyone is interested, [http://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a39470bb00555 | X-Gold 616 spec sheet], [https://www.infineon.com/cms/en/product/channel.html?channel=db3a304319c6f18c011a3948dc76055b | X-Gold 618 spec sheet].&lt;br /&gt;
[[User:D235j|D235j]] 21:43, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Actually, it's the XMM 6180. ebl.fls says so. --[[User:Oranav|oranav]] 21:56, 22 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Downgrade ==&lt;br /&gt;
&lt;br /&gt;
Anybody knows more about the bb downgrade signatures? Or how to backup them like the shsh certs? Or how to use the replay attack here? Actually this is more related to baseband firmware and not to this iPhone 4 hardware. [[User:http|http]]&lt;br /&gt;
&lt;br /&gt;
The baseband is signed with an [[AT+XNONCE]] which is a random string generated on every bootup. Therefore, it is not possible to cache the SHSH signatures with a replay attack. I think this info either belongs on this page because it is specific to its baseband or  in a special section on [[Baseband Firmware]]. [[User:Iemit737|Iemit737]] 18:18, 16 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Ah, that's what [[User:MuscleNerd|MuscleNerd]] meant with [http://twitter.com/MuscleNerd/status/18667056119 &amp;quot;stricter signed&amp;quot;]. I also found [http://iphwn.org/nonce.txt this example]. And someone suggested to change iTunes to always send the same string. That would work, but BB wouldn't accept the response. My only idea would be to let BB generate (or store) the same string on every boot (I don't know how though). But even then we would have to backup the signatures at the time they were available. -- [[User:Http|http]] 23:11, 16 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
So how does TinyUmbrella give baseband protection ? ---Whiteshinyapple&lt;br /&gt;
&lt;br /&gt;
It manages to error out the signature for the baseband, that's why you get the 1004 error, not sure exactly how it's done but I'd assume that's how. ---OMEGA_RAZER&lt;br /&gt;
&lt;br /&gt;
I think there's not much to do. When hosts is pointing to Cydia, you also won't get baseband downgraded, even if it would work when pointing to real Apple server. Same should apply for upgrade. Maybe local TSS server from TinyUmbrella just handles error returns better, so that firmware up/downgrade doesn't fail - maybe it just returns an invalid certificate for the baseband, but returns 'ok'. -- [[User:Http|http]] 11:08, 9 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Greenpois0n_(jailbreak)&amp;diff=15812</id>
		<title>Greenpois0n (jailbreak)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Greenpois0n_(jailbreak)&amp;diff=15812"/>
		<updated>2011-02-04T03:40:17Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Supported Devices */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{lowercase}}&lt;br /&gt;
[[Image:gp.png|180px|right|greenpois0n]]&lt;br /&gt;
{{other|jailbreak|toolkit|greenpois0n (toolkit)}}&lt;br /&gt;
The downloads for greenpois0n can be found on http://www.greenpois0n.com/. It is available for Windows, Mac, and Linux.&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
Greenpois0n was originally written using two exploits: SHAtter (a [[bootrom]] [[exploit]]) as well as a userland [[kernel]] [[exploit]] provided by [[User:Comex|Comex]] to make the jailbreak [[untethered jailbreak|untethered]]. A release date of 10/10/10 10:10:10 AM (GMT) was announced, as well as the list of supported devices. Due to the nature of SHAtter, only iDevices using the [[S5L8930|A4 Processor]] were supported.&lt;br /&gt;
[[user:geohot|geohot]] later released another jailbreak ([[limera1n]] using a different [[bootrom]] [[exploit]]) on 9 October 2010, which led to a delay in greenpois0n's release (to implement geohot's exploit, not SHAtter).&lt;br /&gt;
Posixninja and the rest of the Chronic-dev team released Greenpois0n RC5 on 2/3/2011 which jailbreaks 4.2.1 with an untether for newer devices. Whereabouts of the new userland exploit to untether the jailbreak are unknown. &lt;br /&gt;
&lt;br /&gt;
== Controversy ==&lt;br /&gt;
There was much controversy surrounding the sudden release of [[limera1n]] and the motives behind it. The main reasons for the [[limera1n]] release were:&lt;br /&gt;
&lt;br /&gt;
#Use an exploit that Apple already knew about (newer [[iBoot]]s shows the exploit patched) &lt;br /&gt;
#Supports more iDevices than SHAtter&lt;br /&gt;
#Hopefully save the SHAtter [[bootrom]] [[exploit]] for future iDevices&lt;br /&gt;
&lt;br /&gt;
The reason for this is [[bootrom]] [[exploit]]s are not patchable with software updates. It requires new hardware to fix the security hole. Since the [[limera1n]] hole was already discovered and patched by Apple, it benefits the community if SHAtter is saved in hopes of using it with new hardware, like the 5th generation iPhone/iPod touch and the iPad 2G.&lt;br /&gt;
&lt;br /&gt;
== Supported Devices ==&lt;br /&gt;
greenpois0n requires the device to be on either iOS 3.2.2 ([[K48ap|iPad 1G]]) or iOS 4.1 (all other devices). Of the devices that support these firmware revisions, the only one ''not'' supported is the [[N82ap|iPhone 3G]]. As of RC5, Greenpois0n, has the ability to jailbreak all newer devices on iOS 4.2.1. According to posixninja, the userland exploit in RC5 was partched in 4.3 which led to its early release to the masses.&lt;br /&gt;
&lt;br /&gt;
== Output ==&lt;br /&gt;
[[N90ap|iPhone 4]] with [[Greenpois0n (toolkit)|greenpois0n]] output (via [[iRecovery]]):&lt;br /&gt;
 Attempting to initialize greenpois0n&lt;br /&gt;
 Initializing commands&lt;br /&gt;
 Searching for cmd_ramdisk&lt;br /&gt;
 Found cmd_ramdisk string at 0x8401c7ac&lt;br /&gt;
 Found cmd_ramdisk reference at 0x84000d64&lt;br /&gt;
 Found cmd_ramdisk function at 0x84000cd1&lt;br /&gt;
 Initializing patches&lt;br /&gt;
 Initializing memory&lt;br /&gt;
 Initializing aes&lt;br /&gt;
 Searching for aes_crypto_cmd&lt;br /&gt;
 Found aes_crypto_cmd string at 0x84021a8c&lt;br /&gt;
 Found aes_crypto_cmd reference at 0x84017bb8&lt;br /&gt;
 Found aes_crypto_cmd fnction at 0x84017b51&lt;br /&gt;
 Initializing bdev&lt;br /&gt;
 Initializing image&lt;br /&gt;
 Initializing nvram&lt;br /&gt;
 Initializing kernel&lt;br /&gt;
 Greenpois0n initialized&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;br /&gt;
[[Category:greenpois0n|jailbreak]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Greenpois0n_(jailbreak)&amp;diff=15811</id>
		<title>Greenpois0n (jailbreak)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Greenpois0n_(jailbreak)&amp;diff=15811"/>
		<updated>2011-02-04T03:39:17Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Supported Devices */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{lowercase}}&lt;br /&gt;
[[Image:gp.png|180px|right|greenpois0n]]&lt;br /&gt;
{{other|jailbreak|toolkit|greenpois0n (toolkit)}}&lt;br /&gt;
The downloads for greenpois0n can be found on http://www.greenpois0n.com/. It is available for Windows, Mac, and Linux.&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
Greenpois0n was originally written using two exploits: SHAtter (a [[bootrom]] [[exploit]]) as well as a userland [[kernel]] [[exploit]] provided by [[User:Comex|Comex]] to make the jailbreak [[untethered jailbreak|untethered]]. A release date of 10/10/10 10:10:10 AM (GMT) was announced, as well as the list of supported devices. Due to the nature of SHAtter, only iDevices using the [[S5L8930|A4 Processor]] were supported.&lt;br /&gt;
[[user:geohot|geohot]] later released another jailbreak ([[limera1n]] using a different [[bootrom]] [[exploit]]) on 9 October 2010, which led to a delay in greenpois0n's release (to implement geohot's exploit, not SHAtter).&lt;br /&gt;
Posixninja and the rest of the Chronic-dev team released Greenpois0n RC5 on 2/3/2011 which jailbreaks 4.2.1 with an untether for newer devices. Whereabouts of the new userland exploit to untether the jailbreak are unknown. &lt;br /&gt;
&lt;br /&gt;
== Controversy ==&lt;br /&gt;
There was much controversy surrounding the sudden release of [[limera1n]] and the motives behind it. The main reasons for the [[limera1n]] release were:&lt;br /&gt;
&lt;br /&gt;
#Use an exploit that Apple already knew about (newer [[iBoot]]s shows the exploit patched) &lt;br /&gt;
#Supports more iDevices than SHAtter&lt;br /&gt;
#Hopefully save the SHAtter [[bootrom]] [[exploit]] for future iDevices&lt;br /&gt;
&lt;br /&gt;
The reason for this is [[bootrom]] [[exploit]]s are not patchable with software updates. It requires new hardware to fix the security hole. Since the [[limera1n]] hole was already discovered and patched by Apple, it benefits the community if SHAtter is saved in hopes of using it with new hardware, like the 5th generation iPhone/iPod touch and the iPad 2G.&lt;br /&gt;
&lt;br /&gt;
== Supported Devices ==&lt;br /&gt;
greenpois0n requires the device to be on either iOS 3.2.2 ([[K48ap|iPad 1G]]) or iOS 4.1 (all other devices). Of the devices that support these firmware revisions, the only one ''not'' supported is the [[N82ap|iPhone 3G]]. As of RC5, Greenpois0n, has the ability to jailbreak all newer devices on iOS 4.2.1.&lt;br /&gt;
&lt;br /&gt;
== Output ==&lt;br /&gt;
[[N90ap|iPhone 4]] with [[Greenpois0n (toolkit)|greenpois0n]] output (via [[iRecovery]]):&lt;br /&gt;
 Attempting to initialize greenpois0n&lt;br /&gt;
 Initializing commands&lt;br /&gt;
 Searching for cmd_ramdisk&lt;br /&gt;
 Found cmd_ramdisk string at 0x8401c7ac&lt;br /&gt;
 Found cmd_ramdisk reference at 0x84000d64&lt;br /&gt;
 Found cmd_ramdisk function at 0x84000cd1&lt;br /&gt;
 Initializing patches&lt;br /&gt;
 Initializing memory&lt;br /&gt;
 Initializing aes&lt;br /&gt;
 Searching for aes_crypto_cmd&lt;br /&gt;
 Found aes_crypto_cmd string at 0x84021a8c&lt;br /&gt;
 Found aes_crypto_cmd reference at 0x84017bb8&lt;br /&gt;
 Found aes_crypto_cmd fnction at 0x84017b51&lt;br /&gt;
 Initializing bdev&lt;br /&gt;
 Initializing image&lt;br /&gt;
 Initializing nvram&lt;br /&gt;
 Initializing kernel&lt;br /&gt;
 Greenpois0n initialized&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;br /&gt;
[[Category:greenpois0n|jailbreak]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Greenpois0n_(jailbreak)&amp;diff=15810</id>
		<title>Greenpois0n (jailbreak)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Greenpois0n_(jailbreak)&amp;diff=15810"/>
		<updated>2011-02-04T03:37:45Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: RC5&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{lowercase}}&lt;br /&gt;
[[Image:gp.png|180px|right|greenpois0n]]&lt;br /&gt;
{{other|jailbreak|toolkit|greenpois0n (toolkit)}}&lt;br /&gt;
The downloads for greenpois0n can be found on http://www.greenpois0n.com/. It is available for Windows, Mac, and Linux.&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
Greenpois0n was originally written using two exploits: SHAtter (a [[bootrom]] [[exploit]]) as well as a userland [[kernel]] [[exploit]] provided by [[User:Comex|Comex]] to make the jailbreak [[untethered jailbreak|untethered]]. A release date of 10/10/10 10:10:10 AM (GMT) was announced, as well as the list of supported devices. Due to the nature of SHAtter, only iDevices using the [[S5L8930|A4 Processor]] were supported.&lt;br /&gt;
[[user:geohot|geohot]] later released another jailbreak ([[limera1n]] using a different [[bootrom]] [[exploit]]) on 9 October 2010, which led to a delay in greenpois0n's release (to implement geohot's exploit, not SHAtter).&lt;br /&gt;
Posixninja and the rest of the Chronic-dev team released Greenpois0n RC5 on 2/3/2011 which jailbreaks 4.2.1 with an untether for newer devices. Whereabouts of the new userland exploit to untether the jailbreak are unknown. &lt;br /&gt;
&lt;br /&gt;
== Controversy ==&lt;br /&gt;
There was much controversy surrounding the sudden release of [[limera1n]] and the motives behind it. The main reasons for the [[limera1n]] release were:&lt;br /&gt;
&lt;br /&gt;
#Use an exploit that Apple already knew about (newer [[iBoot]]s shows the exploit patched) &lt;br /&gt;
#Supports more iDevices than SHAtter&lt;br /&gt;
#Hopefully save the SHAtter [[bootrom]] [[exploit]] for future iDevices&lt;br /&gt;
&lt;br /&gt;
The reason for this is [[bootrom]] [[exploit]]s are not patchable with software updates. It requires new hardware to fix the security hole. Since the [[limera1n]] hole was already discovered and patched by Apple, it benefits the community if SHAtter is saved in hopes of using it with new hardware, like the 5th generation iPhone/iPod touch and the iPad 2G.&lt;br /&gt;
&lt;br /&gt;
== Supported Devices ==&lt;br /&gt;
greenpois0n requires the device to be on either iOS 3.2.2 ([[K48ap|iPad 1G]]) or iOS 4.1 (all other devices). Of the devices that support these firmware revisions, the only one ''not'' supported is the [[N82ap|iPhone 3G]].&lt;br /&gt;
&lt;br /&gt;
== Output ==&lt;br /&gt;
[[N90ap|iPhone 4]] with [[Greenpois0n (toolkit)|greenpois0n]] output (via [[iRecovery]]):&lt;br /&gt;
 Attempting to initialize greenpois0n&lt;br /&gt;
 Initializing commands&lt;br /&gt;
 Searching for cmd_ramdisk&lt;br /&gt;
 Found cmd_ramdisk string at 0x8401c7ac&lt;br /&gt;
 Found cmd_ramdisk reference at 0x84000d64&lt;br /&gt;
 Found cmd_ramdisk function at 0x84000cd1&lt;br /&gt;
 Initializing patches&lt;br /&gt;
 Initializing memory&lt;br /&gt;
 Initializing aes&lt;br /&gt;
 Searching for aes_crypto_cmd&lt;br /&gt;
 Found aes_crypto_cmd string at 0x84021a8c&lt;br /&gt;
 Found aes_crypto_cmd reference at 0x84017bb8&lt;br /&gt;
 Found aes_crypto_cmd fnction at 0x84017b51&lt;br /&gt;
 Initializing bdev&lt;br /&gt;
 Initializing image&lt;br /&gt;
 Initializing nvram&lt;br /&gt;
 Initializing kernel&lt;br /&gt;
 Greenpois0n initialized&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;br /&gt;
[[Category:greenpois0n|jailbreak]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=15512</id>
		<title>Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Limera1n&amp;diff=15512"/>
		<updated>2011-01-29T19:01:19Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: this was annooooooooying me.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:limera1n}}&lt;br /&gt;
[[Image:Ra1ndrop.png|right]]&lt;br /&gt;
This is [[User:Geohot|geohot's]] latest [[jailbreak]] utility. It uses an undisclosed bootrom exploit and [[User:Comex|comex]]'s Packet Filter Kernel Exploit to achieve an [[untethered jailbreak]] on newer devices. The following devices are technically supported:&lt;br /&gt;
&lt;br /&gt;
* [[N88ap|iPhone 3GS]]&lt;br /&gt;
* [[N90ap|iPhone 4]]&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
* [[N81ap|iPod touch 4G]]&lt;br /&gt;
* [[K48ap|iPad]]&lt;br /&gt;
* [[K66ap|AppleTV 2G]] (creates a bare-bones jailbreak by mounting '/' as read/write in /etc/fstab)&lt;br /&gt;
&lt;br /&gt;
Limera1n has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard].&lt;br /&gt;
&lt;br /&gt;
'''Release Date:''' October 9, 2010&lt;br /&gt;
&lt;br /&gt;
'''Supported OS's:''' Mac OS X, Windows&lt;br /&gt;
&lt;br /&gt;
'''Supported Operations:''' Hacktivation, jailbreaking&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Release text==&lt;br /&gt;
&amp;lt;center&amp;gt;limera1n, 6 months in the making&amp;lt;br /&amp;gt;&lt;br /&gt;
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G&amp;lt;br /&amp;gt;&lt;br /&gt;
4.0-4.1 and beyond+++&amp;lt;br /&amp;gt;&lt;br /&gt;
limera1n is unpatchable&amp;lt;br /&amp;gt;&lt;br /&gt;
untethered thanks to jailbreakme star '''comex'''&amp;lt;br /&amp;gt;&lt;br /&gt;
brought to you by '''geohot'''&amp;lt;br /&amp;gt;&lt;br /&gt;
hacktivates&amp;lt;br /&amp;gt;&lt;br /&gt;
Mac coming in 7 years&amp;lt;br /&amp;gt;&lt;br /&gt;
donations keep support alive&amp;lt;br /&amp;gt;&lt;br /&gt;
zero pictures of my face&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Credit==&lt;br /&gt;
* '''[[User:Geohot|geohot]]''' - The program itself, and the bootrom exploit.&lt;br /&gt;
* '''[[User:Comex|comex]]''' - The userland exploit that allows limera1n to run [[untethered jailbreak|untethered]].&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;border-collapse:collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Version'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Release time'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''MD5 Hash'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|&amp;lt;center&amp;gt;'''Change comment'''&amp;lt;/center&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|BETA 1&lt;br /&gt;
|9 Oct 2010 XX:XX GMT&lt;br /&gt;
|2f2b09a6ed5c5613d5361d8a9d0696b6&lt;br /&gt;
|First release.&lt;br /&gt;
|-&lt;br /&gt;
|BETA 2&lt;br /&gt;
|10 Oct 2010 XX:XX GMT&lt;br /&gt;
|a70dccb3dfc0e505687424184dc3d1ce&lt;br /&gt;
|Fixed kernel patching magic. Rerun BETA2+ over BETA1.&lt;br /&gt;
|-&lt;br /&gt;
|BETA 3&lt;br /&gt;
|10 Oct 2010 XX:XX GMT&lt;br /&gt;
|81730090f7de1576268ee8c2407c3d35&lt;br /&gt;
|Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]])&lt;br /&gt;
|-&lt;br /&gt;
|BETA 4&lt;br /&gt;
|10 Oct 2010 XX:XX GMT&lt;br /&gt;
|d901c4b3a544983f095b0d03eb94e4db&lt;br /&gt;
|Uninstall fixed, respring fixed&lt;br /&gt;
|-&lt;br /&gt;
|RC1&lt;br /&gt;
|11 Oct 2010 XX:XX GMT&lt;br /&gt;
|0622d99ffe4c25f75c720a689853845f&lt;br /&gt;
|out of beta! afc2, reliability improvements, no reboot for cydia, 2kb smaller&lt;br /&gt;
|-&lt;br /&gt;
|RC1b&lt;br /&gt;
|11 Oct 2010 XX:XX GMT&lt;br /&gt;
|fc6f7d696a57c3baede49bdff8a7f43f&lt;br /&gt;
|addresses an install issue, mainly with iPads&lt;br /&gt;
|-&lt;br /&gt;
|Final&lt;br /&gt;
|11 Oct 2010 23:XX GMT&lt;br /&gt;
|fc6f7d696a57c3baede49bdff8a7f43f&lt;br /&gt;
|(same as RC1b)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Technical Information==&lt;br /&gt;
=== Basics ===&lt;br /&gt;
* Limera1n has nothing to do with SHAtter at all.&lt;br /&gt;
* Limera1n uses a bootrom exploit to achieve the [[tethered jailbreak]] and unsigned code execution.&lt;br /&gt;
* Limera1n uses a userland exploit to make it untethered, which was developed by [[User:Comex|comex]].&lt;br /&gt;
* Limera1n uses a hacktivation dylib to perform hacktivation.&lt;br /&gt;
&lt;br /&gt;
=== Exploits ===&lt;br /&gt;
Limera1n reuses the usb_control_msg(0x21,2) but exploits a different vulnerability.&lt;br /&gt;
 &lt;br /&gt;
=== Process ===&lt;br /&gt;
The jailbreak appears to execute something like the following (in no particular order):&lt;br /&gt;
* In recovery1,&lt;br /&gt;
 &amp;quot;setenv debug-uarts 1&lt;br /&gt;
 setenv auto-boot false&lt;br /&gt;
 saveenv&amp;quot;&lt;br /&gt;
* In [[DFU Mode]], it uploads a [[payload]].&lt;br /&gt;
* In recovery2, it uploads another [[payload]] and its [[ramdisk]].&lt;br /&gt;
 &amp;quot;setenv auto-boot true&lt;br /&gt;
  reset&lt;br /&gt;
  geohot done&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Interesting Messages ===&lt;br /&gt;
 &amp;quot;geohot black is the new purple&amp;quot;&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;blackra1n start: %d current IRQ mask is %8.8X&lt;br /&gt;
 usb irq disabled...shhh&lt;br /&gt;
 fxns found @ %8.8X %8.8X&lt;br /&gt;
 found iBoot @ %8.8X&lt;br /&gt;
 i'm back from IRQland...&lt;br /&gt;
 3g detected, kicking nor&lt;br /&gt;
 nor kicked&lt;br /&gt;
 memcpy done&lt;br /&gt;
 iBoot restored!!!&lt;br /&gt;
 found command table @ %8.8X&lt;br /&gt;
 cmd_geohot added&lt;br /&gt;
 time to pray...%8.8X&amp;quot;&lt;br /&gt;
&lt;br /&gt;
 &amp;quot;2.2X  send command(%d): %s&lt;br /&gt;
 send exploit!!!&lt;br /&gt;
 sent data to copy: %X&lt;br /&gt;
  sent shellcode: %X has real length %X&lt;br /&gt;
 never freed: %X&lt;br /&gt;
 sent fake data to timeout: %X&lt;br /&gt;
  sent exploit to heap overflow: %X&lt;br /&gt;
  sending file with length: 0x%X Mingw runtime failure:&lt;br /&gt;
   VirtualQuery failed for %d bytes at address %p      Unknown pseudo relocation protocol version %d.&lt;br /&gt;
     Unknown pseudo relocation bit size %d.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==Controversy==&lt;br /&gt;
The release of this jailbreak was specifically designed to pressure [[Chronic Dev (team)]] into not releasing SHAtter, but to instead implement the limera1n exploit into [[greenpois0n]]; after releasing limera1n, releasing SHAtter would uselessly disclose another bootrom exploit to Apple.&lt;br /&gt;
&lt;br /&gt;
[[User:Geohot|Geohot]]'s rationale is that Apple already discovered, through internal testing, the limera1n exploit, making it very likely that it will be fixed in the next bootrom revision. Because [[iBoot]] code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. [[User:Geohot|Geohot]] observed his limera1n exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining useful for an indefinite amount of time.&lt;br /&gt;
&lt;br /&gt;
Limera1n's [[Untethered jailbreak|untethered]] userland exploit for iOS 4.0 and 4.1 was obtained by [[User:Geohot|geohot]] under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|Comex]] did end up fixing the kernel patching code by beta2, so as to not break users' devices.&lt;br /&gt;
&lt;br /&gt;
== Hacktivation ==&lt;br /&gt;
Limera1n will copy hacktivation.dylib to /usr/lib and change entries to com.apple.mobile.lockdown.plist, whether it has been activated using iTunes or not. This, while helpful to many, can also be harmful to legitimate activators. For a guide on how to remove this hacktivation on iTunes activated devices, see the link below.&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action]&lt;br /&gt;
* [http://limera1n.com/ Official domain] &lt;br /&gt;
* [http://theiphonewiki.com/limera1n The iPhone Wiki Mirror]&lt;br /&gt;
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire provided by iH8sn0w.]&lt;br /&gt;
* [http://www.pastie.org/1210054 Veence's explanation for release]&lt;br /&gt;
* [http://www.cmdshft.ipwn.me/blog/?p=555 Hacktivation removal guide.]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Pod2g&amp;diff=15490</id>
		<title>User:Pod2g</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Pod2g&amp;diff=15490"/>
		<updated>2011-01-29T17:53:54Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;pod2g is an iPhone hacker who has discovered several [[bootrom]] exploits, including the [[0x24000 Segment Overflow]] and the [[usb_control_msg(0xA1, 1) Exploit]]. He was formerly part of the [[Chronic Dev (team)|Chronic Dev Team]], but left for personal reasons.&lt;br /&gt;
&lt;br /&gt;
He was the first to [https://twitter.com/pod2g/status/23932796062 tweet the IMG3 keys] for [[iBSS]] for iOS 4.0.1 on the [[N90ap|iPhone 4]], as proof of unsigned code running on the device.&lt;br /&gt;
&lt;br /&gt;
As of 1/29/2011, pod2g, has revealed to have two untether exploits. News of release have not been revealed.&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/pod2g pod2g on Twitter]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hackers]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Pod2g&amp;diff=15489</id>
		<title>User:Pod2g</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Pod2g&amp;diff=15489"/>
		<updated>2011-01-29T17:51:59Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;pod2g is an iPhone hacker who has discovered several [[bootrom]] exploits, including the [[0x24000 Segment Overflow]] and the [[usb_control_msg(0xA1, 1) Exploit]]. He was formerly part of the [[Chronic Dev (team)|Chronic Dev Team]], but left for personal reasons.&lt;br /&gt;
&lt;br /&gt;
He was the first to [https://twitter.com/pod2g/status/23932796062 tweet the IMG3 keys] for [[iBSS]] for iOS 4.0.1 on the [[N90ap|iPhone 4]], as proof of unsigned code running on the device.&lt;br /&gt;
&lt;br /&gt;
As of 1/29/2011, pod2g, has revealed to have two untether exploits. News of release have not been released.&lt;br /&gt;
&lt;br /&gt;
[https://twitter.com/pod2g pod2g on Twitter]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hackers]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=05.16.00&amp;diff=15173</id>
		<title>05.16.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=05.16.00&amp;diff=15173"/>
		<updated>2011-01-20T05:03:24Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: New page: A new iPhone 3GS baseband in iOS 4.2b1. There's no public unlock for it.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A new iPhone 3GS baseband in iOS 4.2b1. There's no public unlock for it.&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=04.09.00&amp;diff=15172</id>
		<title>04.09.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=04.09.00&amp;diff=15172"/>
		<updated>2011-01-20T05:02:47Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: New page: A new iPhone 4 baseband in iOS 4.3b2. There's no public unlock for it.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A new iPhone 4 baseband in iOS 4.3b2. There's no public unlock for it.&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=04.08.00&amp;diff=15171</id>
		<title>04.08.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=04.08.00&amp;diff=15171"/>
		<updated>2011-01-20T05:02:06Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A new iPhone 4 baseband in iOS 4.3b1. There's no public unlock for it.&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=04.08.00&amp;diff=15170</id>
		<title>04.08.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=04.08.00&amp;diff=15170"/>
		<updated>2011-01-20T05:01:45Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: New page: A new iPhone 4 baseband in iOS 4.3b2. There's no public unlock for it.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;A new iPhone 4 baseband in iOS 4.3b2. There's no public unlock for it.&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Firmware&amp;diff=14180</id>
		<title>Firmware</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Firmware&amp;diff=14180"/>
		<updated>2010-12-14T22:18:00Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* iPod touch (2nd generation) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Latest Apple download links can be found [http://www.itunes.com/version here].&lt;br /&gt;
&lt;br /&gt;
==Comparison of firmware versions==&lt;br /&gt;
&lt;br /&gt;
===[[K66ap|Apple TV (2nd generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| [[IBoot (Bootloader)|iBoot]]&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Mojave 8M89 (Apple TV 2G)|Mojave 8M89]]&lt;br /&gt;
| [[IBoot-931.44.21|931.44.21]]&lt;br /&gt;
| [http://appldnld.apple.com/AppleTV/061-8940.20100926.Tvtnz/AppleTV2,1_4.1_8M89_Restore.ipsw AppleTV2,1_4.1_8M89_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;68647d6ce163fc20891ca5bcff647c8eecc2b8d9&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,759,976&lt;br /&gt;
|-&lt;br /&gt;
| 4.2&lt;br /&gt;
| [[jasper 8C150 (Apple TV 2G)|Jasper 8C150]]&lt;br /&gt;
|&lt;br /&gt;
| [http://appldnld.apple.com/AppleTV/061-8747.20101122.Vgtr5/AppleTV2,1_4.2_8C150_Restore.ipsw AppleTV2,1_4.2_8C150_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;58f9ab479783dad3dff3834452abc2917aaef2a5&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 279,991,056&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[jasper 8C154 (Apple TV 2G)|Jasper 8C154]]&lt;br /&gt;
|&lt;br /&gt;
| [http://appldnld.apple.com/AppleTV/061-9978.20101214.gmabr/AppleTV2,1_4.2.1_8C154_Restore.ipsw AppleTV2,1_4.2.1_8C154_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c2b1adea595afa2b9caf633f0a820d3b66424dbf&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 280,052,510&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[K48ap|iPad]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[X-Gold 608#Known iPad Firmware Versions|Baseband]] (3G only)&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.2&lt;br /&gt;
| [[Wildcat 7B367 (iPad)|Wildcat 7B367]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[6.15.00]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPad/061-7987.20100403.mjiTr/iPad1,1_3.2_7B367_Restore.ipsw iPad1,1_3.2_7B367_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;172e8297af74b91971a802e6ad137c891f553099&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 478,959,325&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.1&lt;br /&gt;
| [[Wildcat 7B405 (iPad)|Wildcat 7B405]]&lt;br /&gt;
| [http://appldnld.apple.com/iPad/061-8282.20100713.vgtgh/iPad1,1_3.2.1_7B405_Restore.ipsw iPad1,1_3.2.1_7B405_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;de0a2b64cd335d48fb4abc9ed8700f5dbdf768ca&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 479,012,625&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.2&lt;br /&gt;
| [[Wildcat 7B500 (iPad)|Wildcat 7B500]]&lt;br /&gt;
| [http://appldnld.apple.com/iPad/061-8801.20100811.CvfR5/iPad1,1_3.2.2_7B500_Restore.ipsw iPad1,1_3.2.2_7B500_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;68b613f78581d36eab96aa5a007001dff142baa3&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 479,001,595&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPad)|Jasper 8C148]]&lt;br /&gt;
| [[7.10.00]]&lt;br /&gt;
| [http://appldnld.apple.com/iPad/061-9857.20101122.VGthy/iPad1,1_4.2.1_8C148_Restore.ipsw iPad1,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;8717b3bedc925b587566442ad375aa65d857e79a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 578,084,840&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[M68ap|iPhone]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[Baseband Firmware]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;91&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 1.0&lt;br /&gt;
| [[Alpine 1A420]]&lt;br /&gt;
| [http://img399.imageshack.us/i/iphone2go0.jpg/ 03.06.01_G]&lt;br /&gt;
| iphoneproto.zip&lt;br /&gt;
| &amp;lt;code&amp;gt;6e798e906c6590a7521ef89b731569be6d05b3aa&amp;lt;/code&amp;gt;&lt;br /&gt;
| Prototype; [http://forums.macrumors.com/showthread.php?t=627449 macrumors]&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 109,813,128&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.0&lt;br /&gt;
| Heavenly 1A543a&lt;br /&gt;
| 03.11.02_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3538.20070629.B7vXa/iPhone1,1_1.0_1A543a_Restore.ipsw iPhone1,1_1.0_1A543a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;fb8bb3ee2e9a997affbb97868599f2995c78209c&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial US shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,604,348&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.1&lt;br /&gt;
| Heavenly 1C25&lt;br /&gt;
| 03.12.06_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3614.20070731.Nt6Y7/iPhone1,1_1.0.1_1C25_Restore.ipsw iPhone1,1_1.0.1_1C25_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a00b85a7a55d62a94be5fbf5effbc42fd63f3097&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,627,958&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.2&lt;br /&gt;
| Heavenly 1C28&lt;br /&gt;
| 03.14.08_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3823.20070821.vormd/iPhone1,1_1.0.2_1C28_Restore.ipsw iPhone1,1_1.0.2_1C28_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;7f5c0ff1f84a0202b75a55c3fcb362e415334d1e&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,627,324&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| Snowbird 3A109a&lt;br /&gt;
| 04.01.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3883.20070927.In76t/iPhone1,1_1.1.1_3A109a_Restore.ipsw iPhone1,1_1.1.1_3A109a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;d441dd1c71ce18f25d8fc4faa71c1e6eaa02d02c&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 159,668,150&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48b&lt;br /&gt;
| 04.02.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4037.20071107.5Bghn/iPhone1,1_1.1.2_3B48b_Restore.ipsw iPhone1,1_1.1.2_3B48b_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;797c02e7d660940e8d9a16cc7229ccf3f67dd8b1&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial Euro shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 167,927,501&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| Little Bear 4A93&lt;br /&gt;
| 04.03.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4061.20080115.4Fvn7/iPhone1,1_1.1.3_4A93_Restore.ipsw iPhone1,1_1.1.3_4A93_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b3dec7580bd00dc4faf28449d9618ef40aeacc96&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 169,950,551&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.4&lt;br /&gt;
| Little Bear 4A102&lt;br /&gt;
| 04.04.05_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4313.20080226.Sw39i/iPhone1,1_1.1.4_4A102_Restore.ipsw iPhone1,1_1.1.4_4A102_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;000811bac096011b50ebf6ec1ec2285b62fda4cb&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 169,946,442&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A347 (iPhone)|Big Bear 5A347]]&lt;br /&gt;
|rowspan=&amp;quot;11&amp;quot;| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4956.20080710.V50OI/iPhone1,1_2.0_5A347_Restore.ipsw iPhone1,1_2.0_5A347_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9c510a3cfce789fa5f92a8f763c231bac82ff6d4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;11&amp;quot; {{yes|[[BootNeuter]]}}&lt;br /&gt;
| 228,768,637&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| [[Big Bear 5B108 (iPhone)|Big Bear 5B108]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5135.20080729.Vfgtr/iPhone1,1_2.0.1_5B108_Restore.ipsw iPhone1,1_2.0.1_5B108_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;61de6a2bd6ceddc9ecabad1671b91a59b3824bc4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 254,048,068&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| [[Big Bear 5C1 (iPhone)|Big Bear 5C1]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5246.20080818.2V0hO/iPhone1,1_2.0.2_5C1_Restore.ipsw iPhone1,1_2.0.2_5C1_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b84b57bea919bdc720287ec908c1378e7d7b5e1b&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,589,000&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| [[Sugar Bowl 5F136 (iPhone)|Sugar Bowl 5F136]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5202.20080909.gkbEj/iPhone1,1_2.1_5F136_Restore.ipsw iPhone1,1_2.1_5F136_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;353b7745767b85932e14e262e69463620939bdf7&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 242,171,241&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77 (iPhone)|Timberline 5G77]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5779.20081120.Pt5yH/iPhone1,1_2.2_5G77_Restore.ipsw iPhone1,1_2.2_5G77_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;cbfc6ff886ce89868a55547b9fb980dbf92e6418&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 257,576,980&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11 (iPhone)|SUTimberline 5H11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5830.20090127.Mmni6/iPhone1,1_2.2.1_5H11_Restore.ipsw iPhone1,1_2.2.1_5H11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;43b95ebe1e51f8d30eae916053396595c08440d3&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 257,593,705&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone)|Kirkwood 7A341]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6580.20090617.XsP76/iPhone1,1_3.0_7A341_Restore.ipsw iPhone1,1_3.0_7A341_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;2afd3f8ede17390737f508473ed205506a0bd23f&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 240,394,111&lt;br /&gt;
|-&lt;br /&gt;
| 3.0.1&lt;br /&gt;
| [[Kirkwood 7A400 (iPhone)|Kirkwood 7A400]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6974.20090731.Cf4Tg/iPhone1,1_3.0.1_7A400_Restore.ipsw  iPhone1,1_3.0.1_7A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;34c391fbbc7b31b159372766de39ce5c9cc26ebb&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix for an SMS exploit.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 240,439,502&lt;br /&gt;
|-&lt;br /&gt;
| 3.1&lt;br /&gt;
| [[Northstar 7C144 (iPhone)|Northstar 7C144]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6605.20090909.PQ3ws/iPhone1,1_3.1_7C144_Restore.ipsw iPhone1,1_3.1_7C144_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b7b5f436f81c6f855410e8b44a3d432ccaacd6fc&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 252,536,460&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPhone)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7268.20091008.32pNe/iPhone1,1_3.1.2_7D11_Restore.ipsw iPhone1,1_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e4a1171542dbbd3093516d9c02047b9f7e143050&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 252,515,888&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPhone)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7481.20100202.4orot/iPhone1,1_3.1.3_7E18_Restore.ipsw iPhone1,1_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;eab23a7f8d2a17cb71046c50fc5f67ec390a3c2b&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 238,319,275&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N82ap|iPhone 3G]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[X-Gold 608#Known iPhone Firmware Versions|Baseband]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;90&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A345 (iPhone 3G)|Big Bear 5A345]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[1.45.00]]&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;5&amp;quot; {{partial|Upgrade to 2.2}}&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A347 (iPhone 3G)|Big Bear 5A347]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4955.20080710.bgt53/iPhone1,2_2.0_5A347_Restore.ipsw iPhone1,2_2.0_5A347_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;af9506ca0034e462674f9f59c5406f159eaf9fc1&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 235,957,125&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| [[Big Bear 5B108 (iPhone 3G)|Big Bear 5B108]]&lt;br /&gt;
| [[1.48.02]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5134.20080729.Q2W3E/iPhone1,2_2.0.1_5B108_Restore.ipsw iPhone1,2_2.0.1_5B108_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e81c7ac7e334a3e9d81b3b47894bfaa1ec495482&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 261,224,227&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| [[Big Bear 5C1 (iPhone 3G)|Big Bear 5C1]]&lt;br /&gt;
| [[2.08.01]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5241.20080818.t5Fv3/iPhone1,2_2.0.2_5C1_Restore.ipsw iPhone1,2_2.0.2_5C1_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;bef7fef954293046420fbcf947379839178a195b&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,761,030&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| [[Sugar Bowl 5F136 (iPhone 3G)|Sugar Bowl 5F136]]&lt;br /&gt;
| [[2.11.07]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5198.20080909.K3294/iPhone1,2_2.1_5F136_Restore.ipsw iPhone1,2_2.1_5F136_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c6957dcbf2a95ccfd6dce374a727b1b7700a9043&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 249,341,655&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77 (iPhone 3G)|Timberline 5G77]]&lt;br /&gt;
| [[2.28.00]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5778.20081120.Aqw4R/iPhone1,2_2.2_5G77_Restore.ipsw iPhone1,2_2.2_5G77_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;f67f8b2b842428bf89456cda0c2d5cf954d111a4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|[[Ultrasn0w|yellowsn0w]]}}&lt;br /&gt;
| 258,342,348&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11 (iPhone 3G)|SUTimberline 5H11]]&lt;br /&gt;
| [[2.30.03]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5828.20090127.aQLi8/iPhone1,2_2.2.1_5H11_Restore.ipsw iPhone1,2_2.2.1_5H11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e0098e6fab5c90b59e067e03ae3ccd4a7cd0f39c&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{partial|Upgrade to 3.0}}&lt;br /&gt;
| 258,359,073&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone 3G)|Kirkwood 7A341]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[4.26.08]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6578.20090617.VfgtU/iPhone1,2_3.0_7A341_Restore.ipsw iPhone1,2_3.0_7A341_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;94f1fb43de12bff0f168ce690b7e794cc6220ae3&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 241,229,233&lt;br /&gt;
|-&lt;br /&gt;
| 3.0.1&lt;br /&gt;
| [[Kirkwood 7A400 (iPhone 3G)|Kirkwood 7A400]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6972.20090731.Zx3Rr/iPhone1,2_3.0.1_7A400_Restore.ipsw  iPhone1,2_3.0.1_7A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a148ff39fa4dea499e7a9dd007b63e90c4f56666&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix for an SMS exploit.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 241,274,617&lt;br /&gt;
|-&lt;br /&gt;
| 3.1&lt;br /&gt;
| [[Northstar 7C144 (iPhone 3G)|Northstar 7C144]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[5.11.07]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6600.20090909.AwndZ/iPhone1,2_3.1_7C144_Restore.ipsw iPhone1,2_3.1_7C144_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9b3b3c148170b012012278efda9ff5c38282d559&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[blacksn0w]] or [[ultrasn0w]]}}&lt;br /&gt;
| 253,361,339&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPhone 3G)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7265.20091008.Xsd32/iPhone1,2_3.1.2_7D11_Restore.ipsw iPhone1,2_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b1a6ab2771bb5da372ba75a8fa3e1d72b71359d0&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,340,786&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPhone 3G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [[5.12.01]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7468.20100202.pbnrt/iPhone1,2_3.1.3_7E18_Restore.ipsw iPhone1,2_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;f5950afca546f93e281ba3cdb08bc0cfed7f0896&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 239,139,281&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPhone 3G)|Apex 8A293]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[5.13.04]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7436.20100621.58Yt4/iPhone1,2_4.0_8A293_Restore.ipsw iPhone1,2_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;ee1eba9281b902d7ff3f24d50f9aebff0df27f92&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 306,274,631&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.1&lt;br /&gt;
| [[Apex 8A306 (iPhone 3G)|Apex 8A306]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8616.20100715.phnt4/iPhone1,2_4.0.1_8A306_Restore.ipsw iPhone1,2_4.0.1_8A306_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;940bd2b36c646f6673419eab661ac1f13248e592&amp;lt;/code&amp;gt;&lt;br /&gt;
| New formula to calculate bars. Otherwise, it's the same as 4.0.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 320,237,975&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPhone 3G)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8802.20100811.XcfpR/iPhone1,2_4.0.2_8A400_Restore.ipsw iPhone1,2_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;ee2bc74719170a7a2440b593b6f300727c930c69&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 320,216,794&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPhone 3G)|Baker 8B117]]&lt;br /&gt;
| [[5.14.02]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7932.20100908.3fgt5/iPhone1,2_4.1_8B117_Restore.ipsw iPhone1,2_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;d87bab469dd1146ab83ddcc23f03b3164d7e09d4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{Yes}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 323,137,556&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPhone 3G)|Jasper 8C148]]&lt;br /&gt;
| [[5.15.04]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9853.20101122.Vfgt5/iPhone1,2_4.2.1_8C148_Restore.ipsw iPhone1,2_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;d2ed58586e8ca2153f2e2ec585bba8afc5173378&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{Yes}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 338,579,762&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N88ap|iPhone 3GS]]===&lt;br /&gt;
Units with the new bootrom began shipping around September 2009.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[X-Gold 608#Known iPhone Firmware Versions|Baseband]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-359.3|old bootrom]])&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-359.3.2|new bootrom]])&lt;br /&gt;
!width=&amp;quot;80&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone 3GS)|Kirkwood 7A341]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[4.26.08]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6582.20090617.LlI87/iPhone2,1_3.0_7A341_Restore.ipsw iPhone2,1_3.0_7A341_Restore.ipsw] &lt;br /&gt;
| &amp;lt;code&amp;gt;d8534408c8679c830fd0c4e36ef9762c11ef73df&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{no|[[SHSH]]s unavailable at release}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 312,292,933&lt;br /&gt;
|-&lt;br /&gt;
| 3.0.1&lt;br /&gt;
| [[Kirkwood 7A400 (iPhone_3GS)|Kirkwood 7A400]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6976.20090731.Vgbt5/iPhone2,1_3.0.1_7A400_Restore.ipsw  iPhone2,1_3.0.1_7A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;30006575af931e3da0521febace005152cdb8853&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix for an SMS exploit.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 312,330,244&lt;br /&gt;
|-&lt;br /&gt;
| 3.1b&lt;br /&gt;
| [[Sierra 7C108b]]&lt;br /&gt;
| Unknown&lt;br /&gt;
| Not available to public&lt;br /&gt;
| Unknown&lt;br /&gt;
| Used for testing.&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| 3.1&lt;br /&gt;
| [[Northstar 7C144 (iPhone 3GS)|Northstar 7C144]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[5.11.07]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6609.20090909.mwws4/iPhone2,1_3.1_7C144_Restore.ipsw  iPhone2,1_3.1_7C144_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;527c74f87588afa1d69c1e2c08eedc88f113013a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[blacksn0w]] or [[ultrasn0w]]}}&lt;br /&gt;
| 321,011,474&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPhone 3GS)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7270.20091008.phn32/iPhone2,1_3.1.2_7D11_Restore.ipsw iPhone2,1_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;6998bb7d9e869b2d89a08853312f9457d070fb1f&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 321,015,700&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPhone 3GS)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [[5.12.01]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7472.20100202.8tugj/iPhone2,1_3.1.3_7E18_Restore.ipsw iPhone2,1_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;8cb3775e62c6f72059a962bf891b4e145b965052&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 305,122,343&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPhone 3GS)|Apex 8A293]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[5.13.04]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7437.20100621.5urG8/iPhone2,1_4.0_8A293_Restore.ipsw iPhone2,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e065245874c73510ceb8fa4bd9388b60d46eb252&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 396,281,280&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.1&lt;br /&gt;
| [[Apex 8A306 (iPhone 3GS)‎|Apex 8A306]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8618.20100715.Zapn4/iPhone2,1_4.0.1_8A306_Restore.ipsw iPhone2,1_4.0.1_8A306_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c2b6fb9a158547ce726baa1bf8f0558a71518fec&amp;lt;/code&amp;gt;&lt;br /&gt;
| New formula to calculate bars. Otherwise, it's the same as 4.0.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 396,322,891&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPhone 3GS)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8805.20100811.Dcr4e/iPhone2,1_4.0.2_8A400_Restore.ipsw iPhone2,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;61d21363ced6e006cc226f9a0a0e9c6ed8e048ab&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 396,310,640&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPhone 3GS)|Baker 8B117]]&lt;br /&gt;
| [[5.14.02]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7938.20100908.F3rCk/iPhone2,1_4.1_8B117_Restore.ipsw iPhone2,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;2d1657cd33ae23b8d4e79e41fe758d09d3c52e30&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 400,572,133&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148a (iPhone 3GS)|Jasper 8C148a]]&lt;br /&gt;
| [[5.15.04]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9895.20101122.Cdew2/iPhone2,1_4.2.1_8C148a_Restore.ipsw  iPhone2,1_4.2.1_8C148a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;2787bb9fbf18594279d05682e6fd16d2b9612a2a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 420,813,164&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N90ap|iPhone 4]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[XMM 6180#Known Firmware Versions|Baseband]]&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| [[IBoot (Bootloader)|iBoot]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| Inf1&lt;br /&gt;
| [[Inferno 8A2062a]]&lt;br /&gt;
| Unknown&lt;br /&gt;
| ?&lt;br /&gt;
| Not available to public&lt;br /&gt;
| Unknown&lt;br /&gt;
| Used for testing.&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
| Unknown&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPhone 4)|Apex 8A293]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[1.59.00]]&lt;br /&gt;
| ?&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7380.20100621,Vfgb5/iPhone3,1_4.0_8A293_Restore.ipsw iPhone3,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;171c2a3995fa149f2a369ccd87f82c5c30da3f88&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; {{Yes|[[ultrasn0w]]}}&lt;br /&gt;
| 607,363,121&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.1&lt;br /&gt;
| [[Apex 8A306 (iPhone 4)|Apex 8A306]]&lt;br /&gt;
| ?&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8619.20100715.4Pnsx/iPhone3,1_4.0.1_8A306_Restore.ipsw iPhone3,1_4.0.1_8A306_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a9cf20679273b7e502ab384854ba96cc2a54d532&amp;lt;/code&amp;gt;&lt;br /&gt;
| New formula to calculate bars. Otherwise, it's the same as 4.0.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 607,380,127&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPhone 4)|Apex 8A400]]&lt;br /&gt;
| ?&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8807.20100811.3Edre/iPhone3,1_4.0.2_8A400_Restore.ipsw iPhone3,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;19eb071cdb9f1601b106825d0a16b1449c6eef8c&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 607,375,880&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPhone 4)|Baker 8B117]]&lt;br /&gt;
| [[2.10.04]]&lt;br /&gt;
| [[IBoot-931.18.27|931.18.27]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7939.20100908.Lcyg3/iPhone3,1_4.1_8B117_Restore.ipsw iPhone3,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;a3f8a333ca181146b862ca6a59c9a6e7c27eba0b&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{No}}&lt;br /&gt;
| 618,501,195&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPhone 4)|Jasper 8C148]]&lt;br /&gt;
| [[3.10.01]]&lt;br /&gt;
| &lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9858.20101122.Er456/iPhone3,1_4.2.1_8C148_Restore.ipsw iPhone3,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;366b28e9c95936bd4b11a84d54fefaf079fd6411&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| {{No}}&lt;br /&gt;
| 654,550,096&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N45ap|iPod touch (1st generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 1.1&lt;br /&gt;
| Snowbird 3A100a&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{no}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| 1.1&lt;br /&gt;
| Snowbird 3A101a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3882.20070910.N8uyT/iPod1,1_1.1_3A101a_Restore.ipsw iPod1,1_1.1_3A101a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9b0d83c7f8b4328174a3f31e0e93f60e591ae143&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 157,890,186&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| Snowbird 3A110a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3932.20070927.p23dD/iPod1,1_1.1.1_3A110a_Restore.ipsw iPod1,1_1.1.1_3A110a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;84bbc6ea8bf29745195bc9926c1874f7c2a36f32&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 157,906,686&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48b&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4036.20071107.9g3DF/iPod1,1_1.1.2_3B48b_Restore.ipsw iPod1,1_1.1.2_3B48b_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;108d8ffe9ea75e61cd5e57170ad388b7fa00d923&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 165,567,897&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| Little Bear 4A93&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/061-4060.20080115.9Iuh5/iPod1,1_1.1.3_4A93_Restore.ipsw iPod1,1_1.1.3_4A93_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;8dca23eec69d5ae58fbf3d4a23276e46cbb2e3c6&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,511,411&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.4&lt;br /&gt;
| Little Bear 4A102&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4312.20080226.Btu45/iPod1,1_1.1.4_4A102_Restore.ipsw iPod1,1_1.1.4_4A102_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c148d1eb1c979bb6434175411d4a372103a4fdd2&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,519,589&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.5&lt;br /&gt;
| Little Bear 4B1&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4841.20080714.bgy8O/iPod1,1_1.1.5_4B1_Restore.ipsw iPod1,1_1.1.5_4B1_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;1b818911316e4248ee01d3ec67f9d39afc3db240&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,519,637&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A347 (iPod touch 1G)|Big Bear 5A347]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;ae82798e85f9953b0f4798bad36187cb020c9d22&amp;lt;/code&amp;gt;&lt;br /&gt;
| 2.0+ is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 233,409,573&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| [[Big Bear 5B108 (iPod touch 1G)|Big Bear 5B108]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;a81b6e7af4b85ef436d047f9da57c0f694d8964a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 258,660,321&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| [[Big Bear 5C1 (iPod touch 1G)|Big Bear 5C1]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;c8b6f9fefa3f3777c56285dfe4c735b1e08a81a2&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 258,201,218&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| [[Sugar Bowl 5F137 (iPod touch 1G)|Sugar Bowl 5F137]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;fc7f6d0972927df502ffca47438ca75dcccffaf3&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 251,155,156&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77 (iPod touch 1G)|Timberline 5G77]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;081a7de363230fb38d0ce092cbbe42f2a50c8a5f&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,186,851&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11 (iPod touch 1G)|SUTimberline 5H11]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;fc69be9e421bc0630567184506ab771f6b7ef68b&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,166,688&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPod touch 1G)|Kirkwood 7A341]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;dff2bd14931225908a360fb8e60a336f17d2dd6d&amp;lt;/code&amp;gt;&lt;br /&gt;
| 3.0+ is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 242,458,552&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C145 (iPod touch 1G)|Northstar 7C145]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;c6270780c166db4c9f4f0a7fa945754a1f9fe7e8&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 249,755,862&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPod touch 1G)|Northstar 7D11]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;7367dd9ba58a3b9777307368a0128e696fdfc9a6&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}} &lt;br /&gt;
| 249,780,497&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPod touch 1G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;5f897990f19d2f093b35e0813d7d77806404fb1f&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 235,678,189&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N72ap|iPod touch (2nd generation)]]===&lt;br /&gt;
Units with the new bootrom have model numbers that start with &amp;quot;MC.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-240.4|old bootrom]])&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-240.5.1|new bootrom]])&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 2.1.1&lt;br /&gt;
| [[Sugar Bowl 5F138 (iPod touch 2G)|Sugar Bowl 5F138]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-5494.20080909.8i9o0/iPod2,1_2.1.1_5F138_Restore.ipsw iPod2,1_2.1.1_5F138_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c3c700be49ad227d1152188e7c1e46b8958fd1e4&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|rowspan=&amp;quot;4&amp;quot; {{no|Incompatible device/&lt;br /&gt;
firmware match}}&lt;br /&gt;
| 282,083,944&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77a (iPod touch 2G)|Timberline 5G77a]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/061-5358.20081120.Gtghy/iPod2,1_2.2_5G77a_Restore.ipsw iPod2,1_2.2_5G77a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;34a0a489605f34d6cc6c9954edcaaf9a050deedc&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 291,123,491&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11a (iPod touch 2G)|SUTimberline 5H11a]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5863.20090127.rt56K/iPod2,1_2.2.1_5H11a_Restore.ipsw iPod2,1_2.2.1_5H11a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9af5625ea34acdd8abeb6fce71a72651d0c815d5&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 291,140,244&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPod touch 2G)|Kirkwood 7A341]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;0f7fc76d9b9aa826b5ab14be9821a315d3d9dc42&amp;lt;/code&amp;gt;&lt;br /&gt;
| 3.x is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 270,315,364&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C145 (iPod touch 2G)|Northstar 7C145]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;e0d8800a4fc7cc5be6976ddbceb43c2d2a7120d7&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment for units with the new bootrom.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 277,753,989&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPod touch 2G)|Northstar 7D11]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;e7c83d4a5baec0e81816ae1cd1caf9a4dc38ebf0&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 277,794,671&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPod touch 2G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;5f4f5c01eda2f811f73167e7d1f82dbeed82367b&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 263,275,211&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPod touch 2G)|Apex 8A293]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7435.20100621.tr49t/iPod2,1_4.0_8A293_Restore.ipsw iPod2,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c026c373bc535496a6f901de2ba37d4a487413bf&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 330,278,777&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPod touch 2G)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8551.20100811.Xcder/iPod2,1_4.0.2_8A400_Restore.ipsw iPod2,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;06a42297d94461264eb64d7c8640cc5d1c19edeb&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 344,248,876&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPod touch 2G)|Baker 8B117]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7937.20100908.ghj4f/iPod2,1_4.1_8B117_Restore.ipsw iPod2,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;97abde6207660bd876fd476275dd526d0dcf3d19&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{Yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 348,027,174&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPod touch 2G)|Jasper 8C148]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9855.20101122.Lrft6/iPod2,1_4.2.1_8C148_Restore.ipsw iPod2,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;b9efddc7bb4350c237a8d3846af61bbfc8a2f647&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|363,553,480&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N18ap|iPod touch (3rd generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C145 (iPod touch 3G)|Northstar 7C145]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-7163.20090909.NtstR/iPod3,1_3.1.1_7C145_Restore.ipsw iPod3,1_3.1.1_7C145_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a3eddbe2cf77858bae7087dc8b2035f0d3097e57&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
&lt;br /&gt;
| 311,702,789&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C146 (iPod touch 3G)|Northstar 7C146]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7238.20090918.23GhT/iPod3,1_3.1.1_7C146_Restore.ipsw iPod3,1_3.1.1_7C146_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;f66a7286b261137f25ddbbd84047f9a7ea181904&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 311,690,768&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPod touch 3G)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7271.20091008.Tch23/iPod3,1_3.1.2_7D11_Restore.ipsw iPod3,1_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;02dcee28d788d594a2939ab564f4f183af6ccdf2&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 311,740,034&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPod touch 3G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7473.20100202.4i44t/iPod3,1_3.1.3_7E18_Restore.ipsw iPod3,1_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;375fd469b18bfc0b74c7cfa5b4d5945197b1d106&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 295,870,806&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPod touch 3G)|Apex 8A293]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7381.20100621.AzSP9/iPod3,1_4.0_8A293_Restore.ipsw iPod3,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;36fe02b83f87d6305db572e1644841e3cd64cc7d&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 384,178,784&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPod touch 3G)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8554.20100811.Bgt54/iPod3,1_4.0.2_8A400_Restore.ipsw iPod3,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;481b21044130125b117d53207f725b70fb061855&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 384,203,993&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPod touch 3G)|Baker 8B117]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7941.20100908.sV9KE/iPod3,1_4.1_8B117_Restore.ipsw iPod3,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;3162bad4060b7a58c9942ddb483e5bd9bcc5269f&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 388,255,189&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPod touch 3G)|Jasper 8C148]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9860.20101122.Xsde3/iPod3,1_4.2.1_8C148_Restore.ipsw iPod3,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;1127a042c535f7cf0be950ff8946862d5fb05b36&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 408,118,620&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N81ap|iPod touch (4th generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPod touch 4G)|Baker 8B117]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8490.20100901.hyjtR/iPod4,1_4.1_8B117_Restore.ipsw iPod4,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a464492bf6ad25d65b378c85d8b181f973ede38a&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 608,360,672&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B118 (iPod touch 4G)|Baker 8B118]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9344.20100922.Urgt43/iPod4,1_4.1_8B118_Restore.ipsw iPod4,1_4.1_8B118_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;331fb1342f5dab8c04cead74384a1e0fc1145952&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 608,360,927&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPod touch 4G)|Jasper 8C148]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9859.20101122.$erft/iPod4,1_4.2.1_8C148_Restore.ipsw iPod4,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;6a890696126d0cb7f9ccd6b913ecb09cf2029820&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|638,177,119&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[VFDecrypt]]&lt;br /&gt;
* [[VFDecrypt Keys]]&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
*[http://www.trejan.com/projects/ipod/ Firmware List]&lt;br /&gt;
*[http://itunes.com/version Apple Firmware XML]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Firmware&amp;diff=14179</id>
		<title>Firmware</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Firmware&amp;diff=14179"/>
		<updated>2010-12-14T22:17:00Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* iPod touch (2nd generation) */  latest redsn0w tether jbs ipod touch 2g with new bootrom&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Latest Apple download links can be found [http://www.itunes.com/version here].&lt;br /&gt;
&lt;br /&gt;
==Comparison of firmware versions==&lt;br /&gt;
&lt;br /&gt;
===[[K66ap|Apple TV (2nd generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| [[IBoot (Bootloader)|iBoot]]&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Mojave 8M89 (Apple TV 2G)|Mojave 8M89]]&lt;br /&gt;
| [[IBoot-931.44.21|931.44.21]]&lt;br /&gt;
| [http://appldnld.apple.com/AppleTV/061-8940.20100926.Tvtnz/AppleTV2,1_4.1_8M89_Restore.ipsw AppleTV2,1_4.1_8M89_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;68647d6ce163fc20891ca5bcff647c8eecc2b8d9&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,759,976&lt;br /&gt;
|-&lt;br /&gt;
| 4.2&lt;br /&gt;
| [[jasper 8C150 (Apple TV 2G)|Jasper 8C150]]&lt;br /&gt;
|&lt;br /&gt;
| [http://appldnld.apple.com/AppleTV/061-8747.20101122.Vgtr5/AppleTV2,1_4.2_8C150_Restore.ipsw AppleTV2,1_4.2_8C150_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;58f9ab479783dad3dff3834452abc2917aaef2a5&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 279,991,056&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[jasper 8C154 (Apple TV 2G)|Jasper 8C154]]&lt;br /&gt;
|&lt;br /&gt;
| [http://appldnld.apple.com/AppleTV/061-9978.20101214.gmabr/AppleTV2,1_4.2.1_8C154_Restore.ipsw AppleTV2,1_4.2.1_8C154_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c2b1adea595afa2b9caf633f0a820d3b66424dbf&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 280,052,510&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[K48ap|iPad]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[X-Gold 608#Known iPad Firmware Versions|Baseband]] (3G only)&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.2&lt;br /&gt;
| [[Wildcat 7B367 (iPad)|Wildcat 7B367]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[6.15.00]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPad/061-7987.20100403.mjiTr/iPad1,1_3.2_7B367_Restore.ipsw iPad1,1_3.2_7B367_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;172e8297af74b91971a802e6ad137c891f553099&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 478,959,325&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.1&lt;br /&gt;
| [[Wildcat 7B405 (iPad)|Wildcat 7B405]]&lt;br /&gt;
| [http://appldnld.apple.com/iPad/061-8282.20100713.vgtgh/iPad1,1_3.2.1_7B405_Restore.ipsw iPad1,1_3.2.1_7B405_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;de0a2b64cd335d48fb4abc9ed8700f5dbdf768ca&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 479,012,625&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.2&lt;br /&gt;
| [[Wildcat 7B500 (iPad)|Wildcat 7B500]]&lt;br /&gt;
| [http://appldnld.apple.com/iPad/061-8801.20100811.CvfR5/iPad1,1_3.2.2_7B500_Restore.ipsw iPad1,1_3.2.2_7B500_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;68b613f78581d36eab96aa5a007001dff142baa3&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 479,001,595&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPad)|Jasper 8C148]]&lt;br /&gt;
| [[7.10.00]]&lt;br /&gt;
| [http://appldnld.apple.com/iPad/061-9857.20101122.VGthy/iPad1,1_4.2.1_8C148_Restore.ipsw iPad1,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;8717b3bedc925b587566442ad375aa65d857e79a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 578,084,840&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[M68ap|iPhone]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[Baseband Firmware]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;91&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 1.0&lt;br /&gt;
| [[Alpine 1A420]]&lt;br /&gt;
| [http://img399.imageshack.us/i/iphone2go0.jpg/ 03.06.01_G]&lt;br /&gt;
| iphoneproto.zip&lt;br /&gt;
| &amp;lt;code&amp;gt;6e798e906c6590a7521ef89b731569be6d05b3aa&amp;lt;/code&amp;gt;&lt;br /&gt;
| Prototype; [http://forums.macrumors.com/showthread.php?t=627449 macrumors]&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 109,813,128&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.0&lt;br /&gt;
| Heavenly 1A543a&lt;br /&gt;
| 03.11.02_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3538.20070629.B7vXa/iPhone1,1_1.0_1A543a_Restore.ipsw iPhone1,1_1.0_1A543a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;fb8bb3ee2e9a997affbb97868599f2995c78209c&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial US shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,604,348&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.1&lt;br /&gt;
| Heavenly 1C25&lt;br /&gt;
| 03.12.06_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3614.20070731.Nt6Y7/iPhone1,1_1.0.1_1C25_Restore.ipsw iPhone1,1_1.0.1_1C25_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a00b85a7a55d62a94be5fbf5effbc42fd63f3097&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,627,958&lt;br /&gt;
|-&lt;br /&gt;
| 1.0.2&lt;br /&gt;
| Heavenly 1C28&lt;br /&gt;
| 03.14.08_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3823.20070821.vormd/iPhone1,1_1.0.2_1C28_Restore.ipsw iPhone1,1_1.0.2_1C28_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;7f5c0ff1f84a0202b75a55c3fcb362e415334d1e&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 95,627,324&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| Snowbird 3A109a&lt;br /&gt;
| 04.01.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3883.20070927.In76t/iPhone1,1_1.1.1_3A109a_Restore.ipsw iPhone1,1_1.1.1_3A109a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;d441dd1c71ce18f25d8fc4faa71c1e6eaa02d02c&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 159,668,150&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48b&lt;br /&gt;
| 04.02.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4037.20071107.5Bghn/iPhone1,1_1.1.2_3B48b_Restore.ipsw iPhone1,1_1.1.2_3B48b_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;797c02e7d660940e8d9a16cc7229ccf3f67dd8b1&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial Euro shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 167,927,501&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| Little Bear 4A93&lt;br /&gt;
| 04.03.13_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4061.20080115.4Fvn7/iPhone1,1_1.1.3_4A93_Restore.ipsw iPhone1,1_1.1.3_4A93_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b3dec7580bd00dc4faf28449d9618ef40aeacc96&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 169,950,551&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.4&lt;br /&gt;
| Little Bear 4A102&lt;br /&gt;
| 04.04.05_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4313.20080226.Sw39i/iPhone1,1_1.1.4_4A102_Restore.ipsw iPhone1,1_1.1.4_4A102_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;000811bac096011b50ebf6ec1ec2285b62fda4cb&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 169,946,442&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A347 (iPhone)|Big Bear 5A347]]&lt;br /&gt;
|rowspan=&amp;quot;11&amp;quot;| 04.05.04_G&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4956.20080710.V50OI/iPhone1,1_2.0_5A347_Restore.ipsw iPhone1,1_2.0_5A347_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9c510a3cfce789fa5f92a8f763c231bac82ff6d4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;11&amp;quot; {{yes|[[BootNeuter]]}}&lt;br /&gt;
| 228,768,637&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| [[Big Bear 5B108 (iPhone)|Big Bear 5B108]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5135.20080729.Vfgtr/iPhone1,1_2.0.1_5B108_Restore.ipsw iPhone1,1_2.0.1_5B108_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;61de6a2bd6ceddc9ecabad1671b91a59b3824bc4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 254,048,068&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| [[Big Bear 5C1 (iPhone)|Big Bear 5C1]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5246.20080818.2V0hO/iPhone1,1_2.0.2_5C1_Restore.ipsw iPhone1,1_2.0.2_5C1_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b84b57bea919bdc720287ec908c1378e7d7b5e1b&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,589,000&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| [[Sugar Bowl 5F136 (iPhone)|Sugar Bowl 5F136]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5202.20080909.gkbEj/iPhone1,1_2.1_5F136_Restore.ipsw iPhone1,1_2.1_5F136_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;353b7745767b85932e14e262e69463620939bdf7&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 242,171,241&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77 (iPhone)|Timberline 5G77]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5779.20081120.Pt5yH/iPhone1,1_2.2_5G77_Restore.ipsw iPhone1,1_2.2_5G77_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;cbfc6ff886ce89868a55547b9fb980dbf92e6418&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 257,576,980&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11 (iPhone)|SUTimberline 5H11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5830.20090127.Mmni6/iPhone1,1_2.2.1_5H11_Restore.ipsw iPhone1,1_2.2.1_5H11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;43b95ebe1e51f8d30eae916053396595c08440d3&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 257,593,705&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone)|Kirkwood 7A341]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6580.20090617.XsP76/iPhone1,1_3.0_7A341_Restore.ipsw iPhone1,1_3.0_7A341_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;2afd3f8ede17390737f508473ed205506a0bd23f&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 240,394,111&lt;br /&gt;
|-&lt;br /&gt;
| 3.0.1&lt;br /&gt;
| [[Kirkwood 7A400 (iPhone)|Kirkwood 7A400]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6974.20090731.Cf4Tg/iPhone1,1_3.0.1_7A400_Restore.ipsw  iPhone1,1_3.0.1_7A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;34c391fbbc7b31b159372766de39ce5c9cc26ebb&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix for an SMS exploit.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 240,439,502&lt;br /&gt;
|-&lt;br /&gt;
| 3.1&lt;br /&gt;
| [[Northstar 7C144 (iPhone)|Northstar 7C144]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6605.20090909.PQ3ws/iPhone1,1_3.1_7C144_Restore.ipsw iPhone1,1_3.1_7C144_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b7b5f436f81c6f855410e8b44a3d432ccaacd6fc&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 252,536,460&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPhone)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7268.20091008.32pNe/iPhone1,1_3.1.2_7D11_Restore.ipsw iPhone1,1_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e4a1171542dbbd3093516d9c02047b9f7e143050&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 252,515,888&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPhone)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7481.20100202.4orot/iPhone1,1_3.1.3_7E18_Restore.ipsw iPhone1,1_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;eab23a7f8d2a17cb71046c50fc5f67ec390a3c2b&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 238,319,275&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N82ap|iPhone 3G]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[X-Gold 608#Known iPhone Firmware Versions|Baseband]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;90&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A345 (iPhone 3G)|Big Bear 5A345]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[1.45.00]]&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;5&amp;quot; {{partial|Upgrade to 2.2}}&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A347 (iPhone 3G)|Big Bear 5A347]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4955.20080710.bgt53/iPhone1,2_2.0_5A347_Restore.ipsw iPhone1,2_2.0_5A347_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;af9506ca0034e462674f9f59c5406f159eaf9fc1&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 235,957,125&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| [[Big Bear 5B108 (iPhone 3G)|Big Bear 5B108]]&lt;br /&gt;
| [[1.48.02]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5134.20080729.Q2W3E/iPhone1,2_2.0.1_5B108_Restore.ipsw iPhone1,2_2.0.1_5B108_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e81c7ac7e334a3e9d81b3b47894bfaa1ec495482&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 261,224,227&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| [[Big Bear 5C1 (iPhone 3G)|Big Bear 5C1]]&lt;br /&gt;
| [[2.08.01]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5241.20080818.t5Fv3/iPhone1,2_2.0.2_5C1_Restore.ipsw iPhone1,2_2.0.2_5C1_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;bef7fef954293046420fbcf947379839178a195b&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,761,030&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| [[Sugar Bowl 5F136 (iPhone 3G)|Sugar Bowl 5F136]]&lt;br /&gt;
| [[2.11.07]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5198.20080909.K3294/iPhone1,2_2.1_5F136_Restore.ipsw iPhone1,2_2.1_5F136_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c6957dcbf2a95ccfd6dce374a727b1b7700a9043&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 249,341,655&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77 (iPhone 3G)|Timberline 5G77]]&lt;br /&gt;
| [[2.28.00]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5778.20081120.Aqw4R/iPhone1,2_2.2_5G77_Restore.ipsw iPhone1,2_2.2_5G77_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;f67f8b2b842428bf89456cda0c2d5cf954d111a4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|[[Ultrasn0w|yellowsn0w]]}}&lt;br /&gt;
| 258,342,348&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11 (iPhone 3G)|SUTimberline 5H11]]&lt;br /&gt;
| [[2.30.03]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5828.20090127.aQLi8/iPhone1,2_2.2.1_5H11_Restore.ipsw iPhone1,2_2.2.1_5H11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e0098e6fab5c90b59e067e03ae3ccd4a7cd0f39c&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{partial|Upgrade to 3.0}}&lt;br /&gt;
| 258,359,073&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone 3G)|Kirkwood 7A341]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[4.26.08]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6578.20090617.VfgtU/iPhone1,2_3.0_7A341_Restore.ipsw iPhone1,2_3.0_7A341_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;94f1fb43de12bff0f168ce690b7e794cc6220ae3&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 241,229,233&lt;br /&gt;
|-&lt;br /&gt;
| 3.0.1&lt;br /&gt;
| [[Kirkwood 7A400 (iPhone 3G)|Kirkwood 7A400]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6972.20090731.Zx3Rr/iPhone1,2_3.0.1_7A400_Restore.ipsw  iPhone1,2_3.0.1_7A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a148ff39fa4dea499e7a9dd007b63e90c4f56666&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix for an SMS exploit.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 241,274,617&lt;br /&gt;
|-&lt;br /&gt;
| 3.1&lt;br /&gt;
| [[Northstar 7C144 (iPhone 3G)|Northstar 7C144]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[5.11.07]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6600.20090909.AwndZ/iPhone1,2_3.1_7C144_Restore.ipsw iPhone1,2_3.1_7C144_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9b3b3c148170b012012278efda9ff5c38282d559&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[blacksn0w]] or [[ultrasn0w]]}}&lt;br /&gt;
| 253,361,339&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPhone 3G)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7265.20091008.Xsd32/iPhone1,2_3.1.2_7D11_Restore.ipsw iPhone1,2_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;b1a6ab2771bb5da372ba75a8fa3e1d72b71359d0&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 253,340,786&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPhone 3G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [[5.12.01]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7468.20100202.pbnrt/iPhone1,2_3.1.3_7E18_Restore.ipsw iPhone1,2_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;f5950afca546f93e281ba3cdb08bc0cfed7f0896&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 239,139,281&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPhone 3G)|Apex 8A293]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[5.13.04]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7436.20100621.58Yt4/iPhone1,2_4.0_8A293_Restore.ipsw iPhone1,2_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;ee1eba9281b902d7ff3f24d50f9aebff0df27f92&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 306,274,631&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.1&lt;br /&gt;
| [[Apex 8A306 (iPhone 3G)|Apex 8A306]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8616.20100715.phnt4/iPhone1,2_4.0.1_8A306_Restore.ipsw iPhone1,2_4.0.1_8A306_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;940bd2b36c646f6673419eab661ac1f13248e592&amp;lt;/code&amp;gt;&lt;br /&gt;
| New formula to calculate bars. Otherwise, it's the same as 4.0.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 320,237,975&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPhone 3G)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8802.20100811.XcfpR/iPhone1,2_4.0.2_8A400_Restore.ipsw iPhone1,2_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;ee2bc74719170a7a2440b593b6f300727c930c69&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 320,216,794&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPhone 3G)|Baker 8B117]]&lt;br /&gt;
| [[5.14.02]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7932.20100908.3fgt5/iPhone1,2_4.1_8B117_Restore.ipsw iPhone1,2_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;d87bab469dd1146ab83ddcc23f03b3164d7e09d4&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{Yes}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 323,137,556&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPhone 3G)|Jasper 8C148]]&lt;br /&gt;
| [[5.15.04]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9853.20101122.Vfgt5/iPhone1,2_4.2.1_8C148_Restore.ipsw iPhone1,2_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;d2ed58586e8ca2153f2e2ec585bba8afc5173378&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{Yes}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 338,579,762&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N88ap|iPhone 3GS]]===&lt;br /&gt;
Units with the new bootrom began shipping around September 2009.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[X-Gold 608#Known iPhone Firmware Versions|Baseband]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-359.3|old bootrom]])&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-359.3.2|new bootrom]])&lt;br /&gt;
!width=&amp;quot;80&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPhone 3GS)|Kirkwood 7A341]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[4.26.08]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6582.20090617.LlI87/iPhone2,1_3.0_7A341_Restore.ipsw iPhone2,1_3.0_7A341_Restore.ipsw] &lt;br /&gt;
| &amp;lt;code&amp;gt;d8534408c8679c830fd0c4e36ef9762c11ef73df&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{no|[[SHSH]]s unavailable at release}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 312,292,933&lt;br /&gt;
|-&lt;br /&gt;
| 3.0.1&lt;br /&gt;
| [[Kirkwood 7A400 (iPhone_3GS)|Kirkwood 7A400]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6976.20090731.Vgbt5/iPhone2,1_3.0.1_7A400_Restore.ipsw  iPhone2,1_3.0.1_7A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;30006575af931e3da0521febace005152cdb8853&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix for an SMS exploit.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 312,330,244&lt;br /&gt;
|-&lt;br /&gt;
| 3.1b&lt;br /&gt;
| [[Sierra 7C108b]]&lt;br /&gt;
| Unknown&lt;br /&gt;
| Not available to public&lt;br /&gt;
| Unknown&lt;br /&gt;
| Used for testing.&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| 3.1&lt;br /&gt;
| [[Northstar 7C144 (iPhone 3GS)|Northstar 7C144]]&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; | [[5.11.07]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6609.20090909.mwws4/iPhone2,1_3.1_7C144_Restore.ipsw  iPhone2,1_3.1_7C144_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;527c74f87588afa1d69c1e2c08eedc88f113013a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|rowspan=&amp;quot;2&amp;quot; {{yes|[[blacksn0w]] or [[ultrasn0w]]}}&lt;br /&gt;
| 321,011,474&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPhone 3GS)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7270.20091008.phn32/iPhone2,1_3.1.2_7D11_Restore.ipsw iPhone2,1_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;6998bb7d9e869b2d89a08853312f9457d070fb1f&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 321,015,700&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPhone 3GS)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [[5.12.01]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7472.20100202.8tugj/iPhone2,1_3.1.3_7E18_Restore.ipsw iPhone2,1_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;8cb3775e62c6f72059a962bf891b4e145b965052&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 305,122,343&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPhone 3GS)|Apex 8A293]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[5.13.04]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7437.20100621.5urG8/iPhone2,1_4.0_8A293_Restore.ipsw iPhone2,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;e065245874c73510ceb8fa4bd9388b60d46eb252&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; {{yes|[[ultrasn0w]]}}&lt;br /&gt;
| 396,281,280&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.1&lt;br /&gt;
| [[Apex 8A306 (iPhone 3GS)‎|Apex 8A306]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8618.20100715.Zapn4/iPhone2,1_4.0.1_8A306_Restore.ipsw iPhone2,1_4.0.1_8A306_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c2b6fb9a158547ce726baa1bf8f0558a71518fec&amp;lt;/code&amp;gt;&lt;br /&gt;
| New formula to calculate bars. Otherwise, it's the same as 4.0.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 396,322,891&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPhone 3GS)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8805.20100811.Dcr4e/iPhone2,1_4.0.2_8A400_Restore.ipsw iPhone2,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;61d21363ced6e006cc226f9a0a0e9c6ed8e048ab&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 396,310,640&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPhone 3GS)|Baker 8B117]]&lt;br /&gt;
| [[5.14.02]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7938.20100908.F3rCk/iPhone2,1_4.1_8B117_Restore.ipsw iPhone2,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;2d1657cd33ae23b8d4e79e41fe758d09d3c52e30&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 400,572,133&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148a (iPhone 3GS)|Jasper 8C148a]]&lt;br /&gt;
| [[5.15.04]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9895.20101122.Cdew2/iPhone2,1_4.2.1_8C148a_Restore.ipsw  iPhone2,1_4.2.1_8C148a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;2787bb9fbf18594279d05682e6fd16d2b9612a2a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| {{partial|Upgrade baseband to [[6.15.00]]}}&lt;br /&gt;
| 420,813,164&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N90ap|iPhone 4]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;120&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| [[XMM 6180#Known Firmware Versions|Baseband]]&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| [[IBoot (Bootloader)|iBoot]]&lt;br /&gt;
!width=&amp;quot;210&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;140&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[unlock]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| Inf1&lt;br /&gt;
| [[Inferno 8A2062a]]&lt;br /&gt;
| Unknown&lt;br /&gt;
| ?&lt;br /&gt;
| Not available to public&lt;br /&gt;
| Unknown&lt;br /&gt;
| Used for testing.&lt;br /&gt;
| {{no}}&lt;br /&gt;
| {{no}}&lt;br /&gt;
| Unknown&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPhone 4)|Apex 8A293]]&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; | [[1.59.00]]&lt;br /&gt;
| ?&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7380.20100621,Vfgb5/iPhone3,1_4.0_8A293_Restore.ipsw iPhone3,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;171c2a3995fa149f2a369ccd87f82c5c30da3f88&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
|rowspan=&amp;quot;3&amp;quot; {{Yes|[[ultrasn0w]]}}&lt;br /&gt;
| 607,363,121&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.1&lt;br /&gt;
| [[Apex 8A306 (iPhone 4)|Apex 8A306]]&lt;br /&gt;
| ?&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8619.20100715.4Pnsx/iPhone3,1_4.0.1_8A306_Restore.ipsw iPhone3,1_4.0.1_8A306_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a9cf20679273b7e502ab384854ba96cc2a54d532&amp;lt;/code&amp;gt;&lt;br /&gt;
| New formula to calculate bars. Otherwise, it's the same as 4.0.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 607,380,127&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPhone 4)|Apex 8A400]]&lt;br /&gt;
| ?&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8807.20100811.3Edre/iPhone3,1_4.0.2_8A400_Restore.ipsw iPhone3,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;19eb071cdb9f1601b106825d0a16b1449c6eef8c&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 607,375,880&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPhone 4)|Baker 8B117]]&lt;br /&gt;
| [[2.10.04]]&lt;br /&gt;
| [[IBoot-931.18.27|931.18.27]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7939.20100908.Lcyg3/iPhone3,1_4.1_8B117_Restore.ipsw iPhone3,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;a3f8a333ca181146b862ca6a59c9a6e7c27eba0b&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{No}}&lt;br /&gt;
| 618,501,195&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPhone 4)|Jasper 8C148]]&lt;br /&gt;
| [[3.10.01]]&lt;br /&gt;
| &lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9858.20101122.Er456/iPhone3,1_4.2.1_8C148_Restore.ipsw iPhone3,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;366b28e9c95936bd4b11a84d54fefaf079fd6411&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| {{No}}&lt;br /&gt;
| 654,550,096&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N45ap|iPod touch (1st generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 1.1&lt;br /&gt;
| Snowbird 3A100a&lt;br /&gt;
| No download available&lt;br /&gt;
|&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{no}}&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| 1.1&lt;br /&gt;
| Snowbird 3A101a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3882.20070910.N8uyT/iPod1,1_1.1_3A101a_Restore.ipsw iPod1,1_1.1_3A101a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9b0d83c7f8b4328174a3f31e0e93f60e591ae143&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 157,890,186&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.1&lt;br /&gt;
| Snowbird 3A110a&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3932.20070927.p23dD/iPod1,1_1.1.1_3A110a_Restore.ipsw iPod1,1_1.1.1_3A110a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;84bbc6ea8bf29745195bc9926c1874f7c2a36f32&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 157,906,686&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.2&lt;br /&gt;
| Oktoberfest 3B48b&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4036.20071107.9g3DF/iPod1,1_1.1.2_3B48b_Restore.ipsw iPod1,1_1.1.2_3B48b_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;108d8ffe9ea75e61cd5e57170ad388b7fa00d923&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 165,567,897&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.3&lt;br /&gt;
| Little Bear 4A93&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/061-4060.20080115.9Iuh5/iPod1,1_1.1.3_4A93_Restore.ipsw iPod1,1_1.1.3_4A93_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;8dca23eec69d5ae58fbf3d4a23276e46cbb2e3c6&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,511,411&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.4&lt;br /&gt;
| Little Bear 4A102&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4312.20080226.Btu45/iPod1,1_1.1.4_4A102_Restore.ipsw iPod1,1_1.1.4_4A102_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c148d1eb1c979bb6434175411d4a372103a4fdd2&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,519,589&lt;br /&gt;
|-&lt;br /&gt;
| 1.1.5&lt;br /&gt;
| Little Bear 4B1&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4841.20080714.bgy8O/iPod1,1_1.1.5_4B1_Restore.ipsw iPod1,1_1.1.5_4B1_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;1b818911316e4248ee01d3ec67f9d39afc3db240&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 173,519,637&lt;br /&gt;
|-&lt;br /&gt;
| 2.0&lt;br /&gt;
| [[Big Bear 5A347 (iPod touch 1G)|Big Bear 5A347]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;ae82798e85f9953b0f4798bad36187cb020c9d22&amp;lt;/code&amp;gt;&lt;br /&gt;
| 2.0+ is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 233,409,573&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.1&lt;br /&gt;
| [[Big Bear 5B108 (iPod touch 1G)|Big Bear 5B108]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;a81b6e7af4b85ef436d047f9da57c0f694d8964a&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 258,660,321&lt;br /&gt;
|-&lt;br /&gt;
| 2.0.2&lt;br /&gt;
| [[Big Bear 5C1 (iPod touch 1G)|Big Bear 5C1]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;c8b6f9fefa3f3777c56285dfe4c735b1e08a81a2&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 258,201,218&lt;br /&gt;
|-&lt;br /&gt;
| 2.1&lt;br /&gt;
| [[Sugar Bowl 5F137 (iPod touch 1G)|Sugar Bowl 5F137]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;fc7f6d0972927df502ffca47438ca75dcccffaf3&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 251,155,156&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77 (iPod touch 1G)|Timberline 5G77]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;081a7de363230fb38d0ce092cbbe42f2a50c8a5f&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,186,851&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11 (iPod touch 1G)|SUTimberline 5H11]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;fc69be9e421bc0630567184506ab771f6b7ef68b&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 260,166,688&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPod touch 1G)|Kirkwood 7A341]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;dff2bd14931225908a360fb8e60a336f17d2dd6d&amp;lt;/code&amp;gt;&lt;br /&gt;
| 3.0+ is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 242,458,552&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C145 (iPod touch 1G)|Northstar 7C145]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;c6270780c166db4c9f4f0a7fa945754a1f9fe7e8&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 249,755,862&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPod touch 1G)|Northstar 7D11]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;7367dd9ba58a3b9777307368a0128e696fdfc9a6&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}} &lt;br /&gt;
| 249,780,497&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPod touch 1G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;5f897990f19d2f093b35e0813d7d77806404fb1f&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 235,678,189&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===[[N72ap|iPod touch (2nd generation)]]===&lt;br /&gt;
Units with the new bootrom have model numbers that start with &amp;quot;MC.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;95&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-240.4|old bootrom]])&lt;br /&gt;
!width=&amp;quot;100&amp;quot;| Publicly available virgin [[jailbreak]]? ([[IBoot-240.5.1|new bootrom]])&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 2.1.1&lt;br /&gt;
| [[Sugar Bowl 5F138 (iPod touch 2G)|Sugar Bowl 5F138]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-5494.20080909.8i9o0/iPod2,1_2.1.1_5F138_Restore.ipsw iPod2,1_2.1.1_5F138_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c3c700be49ad227d1152188e7c1e46b8958fd1e4&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|rowspan=&amp;quot;4&amp;quot; {{no|Incompatible device/&lt;br /&gt;
firmware match}}&lt;br /&gt;
| 282,083,944&lt;br /&gt;
|-&lt;br /&gt;
| 2.2&lt;br /&gt;
| [[Timberline 5G77a (iPod touch 2G)|Timberline 5G77a]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/061-5358.20081120.Gtghy/iPod2,1_2.2_5G77a_Restore.ipsw iPod2,1_2.2_5G77a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;34a0a489605f34d6cc6c9954edcaaf9a050deedc&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{no}}&lt;br /&gt;
| 291,123,491&lt;br /&gt;
|-&lt;br /&gt;
| 2.2.1&lt;br /&gt;
| [[SUTimberline 5H11a (iPod touch 2G)|SUTimberline 5H11a]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-5863.20090127.rt56K/iPod2,1_2.2.1_5H11a_Restore.ipsw iPod2,1_2.2.1_5H11a_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;9af5625ea34acdd8abeb6fce71a72651d0c815d5&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 291,140,244&lt;br /&gt;
|-&lt;br /&gt;
| 3.0&lt;br /&gt;
| [[Kirkwood 7A341 (iPod touch 2G)|Kirkwood 7A341]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;0f7fc76d9b9aa826b5ab14be9821a315d3d9dc42&amp;lt;/code&amp;gt;&lt;br /&gt;
| 3.x is a paid upgrade series&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 270,315,364&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C145 (iPod touch 2G)|Northstar 7C145]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;e0d8800a4fc7cc5be6976ddbceb43c2d2a7120d7&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment for units with the new bootrom.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 277,753,989&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPod touch 2G)|Northstar 7D11]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;e7c83d4a5baec0e81816ae1cd1caf9a4dc38ebf0&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 277,794,671&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPod touch 2G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| Download Link Prohibited&lt;br /&gt;
| &amp;lt;code&amp;gt;5f4f5c01eda2f811f73167e7d1f82dbeed82367b&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 263,275,211&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPod touch 2G)|Apex 8A293]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7435.20100621.tr49t/iPod2,1_4.0_8A293_Restore.ipsw iPod2,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;c026c373bc535496a6f901de2ba37d4a487413bf&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 330,278,777&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPod touch 2G)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8551.20100811.Xcder/iPod2,1_4.0.2_8A400_Restore.ipsw iPod2,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;06a42297d94461264eb64d7c8640cc5d1c19edeb&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 344,248,876&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPod touch 2G)|Baker 8B117]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7937.20100908.ghj4f/iPod2,1_4.1_8B117_Restore.ipsw iPod2,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;97abde6207660bd876fd476275dd526d0dcf3d19&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{Yes}}&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 348,027,174&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPod touch 2G)|Jasper 8C148]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9855.20101122.Lrft6/iPod2,1_4.2.1_8C148_Restore.ipsw iPod2,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;b9efddc7bb4350c237a8d3846af61bbfc8a2f647&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| {{yes^1}}&lt;br /&gt;
|363,553,480&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N18ap|iPod touch (3rd generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C145 (iPod touch 3G)|Northstar 7C145]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-7163.20090909.NtstR/iPod3,1_3.1.1_7C145_Restore.ipsw iPod3,1_3.1.1_7C145_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a3eddbe2cf77858bae7087dc8b2035f0d3097e57&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
&lt;br /&gt;
| 311,702,789&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1&lt;br /&gt;
| [[Northstar 7C146 (iPod touch 3G)|Northstar 7C146]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7238.20090918.23GhT/iPod3,1_3.1.1_7C146_Restore.ipsw iPod3,1_3.1.1_7C146_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;f66a7286b261137f25ddbbd84047f9a7ea181904&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 311,690,768&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2&lt;br /&gt;
| [[Northstar 7D11 (iPod touch 3G)|Northstar 7D11]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7271.20091008.Tch23/iPod3,1_3.1.2_7D11_Restore.ipsw iPod3,1_3.1.2_7D11_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;02dcee28d788d594a2939ab564f4f183af6ccdf2&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 311,740,034&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3&lt;br /&gt;
| [[SUNorthstarTwo 7E18 (iPod touch 3G)|SUNorthstarTwo 7E18]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-7473.20100202.4i44t/iPod3,1_3.1.3_7E18_Restore.ipsw iPod3,1_3.1.3_7E18_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;375fd469b18bfc0b74c7cfa5b4d5945197b1d106&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 295,870,806&lt;br /&gt;
|-&lt;br /&gt;
| 4.0&lt;br /&gt;
| [[Apex 8A293 (iPod touch 3G)|Apex 8A293]]&lt;br /&gt;
| [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone4/061-7381.20100621.AzSP9/iPod3,1_4.0_8A293_Restore.ipsw iPod3,1_4.0_8A293_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;36fe02b83f87d6305db572e1644841e3cd64cc7d&amp;lt;/code&amp;gt;&lt;br /&gt;
|&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 384,178,784&lt;br /&gt;
|-&lt;br /&gt;
| 4.0.2&lt;br /&gt;
| [[Apex 8A400 (iPod touch 3G)|Apex 8A400]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8554.20100811.Bgt54/iPod3,1_4.0.2_8A400_Restore.ipsw iPod3,1_4.0.2_8A400_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;481b21044130125b117d53207f725b70fb061855&amp;lt;/code&amp;gt;&lt;br /&gt;
| Hotfix to prevent malicious misuse of [[Star]]'s exploits.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 384,203,993&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPod touch 3G)|Baker 8B117]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-7941.20100908.sV9KE/iPod3,1_4.1_8B117_Restore.ipsw iPod3,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;3162bad4060b7a58c9942ddb483e5bd9bcc5269f&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 388,255,189&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPod touch 3G)|Jasper 8C148]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9860.20101122.Xsde3/iPod3,1_4.2.1_8C148_Restore.ipsw iPod3,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
|&amp;lt;code&amp;gt;1127a042c535f7cf0be950ff8946862d5fb05b36&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
| 408,118,620&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
===[[N81ap|iPod touch (4th generation)]]===&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot; style=&amp;quot;font-size: smaller; text-align: center; width: auto; table-layout: fixed; border-collapse: collapse;&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
!width=&amp;quot;40&amp;quot;| Version&lt;br /&gt;
!width=&amp;quot;168&amp;quot;| Build&lt;br /&gt;
!width=&amp;quot;200&amp;quot;| IPSW Download URL&lt;br /&gt;
!width=&amp;quot;220&amp;quot;| SHA1 Hash&lt;br /&gt;
!width=&amp;quot;150&amp;quot;| Comments&lt;br /&gt;
!width=&amp;quot;99&amp;quot;| Publicly available virgin [[jailbreak]]?&lt;br /&gt;
!width=&amp;quot;70&amp;quot;| File Size&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B117 (iPod touch 4G)|Baker 8B117]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-8490.20100901.hyjtR/iPod4,1_4.1_8B117_Restore.ipsw iPod4,1_4.1_8B117_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;a464492bf6ad25d65b378c85d8b181f973ede38a&amp;lt;/code&amp;gt;&lt;br /&gt;
| Initial shipment.&lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 608,360,672&lt;br /&gt;
|-&lt;br /&gt;
| 4.1&lt;br /&gt;
| [[Baker 8B118 (iPod touch 4G)|Baker 8B118]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9344.20100922.Urgt43/iPod4,1_4.1_8B118_Restore.ipsw iPod4,1_4.1_8B118_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;331fb1342f5dab8c04cead74384a1e0fc1145952&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes}}&lt;br /&gt;
| 608,360,927&lt;br /&gt;
|-&lt;br /&gt;
| 4.2.1&lt;br /&gt;
| [[Jasper 8C148 (iPod touch 4G)|Jasper 8C148]]&lt;br /&gt;
| [http://appldnld.apple.com/iPhone4/061-9859.20101122.$erft/iPod4,1_4.2.1_8C148_Restore.ipsw iPod4,1_4.2.1_8C148_Restore.ipsw]&lt;br /&gt;
| &amp;lt;code&amp;gt;6a890696126d0cb7f9ccd6b913ecb09cf2029820&amp;lt;/code&amp;gt;&lt;br /&gt;
| &lt;br /&gt;
| {{yes|Yes&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;}}&lt;br /&gt;
|638,177,119&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; [[Tethered jailbreak]] only.&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[VFDecrypt]]&lt;br /&gt;
* [[VFDecrypt Keys]]&lt;br /&gt;
&lt;br /&gt;
==Resources==&lt;br /&gt;
*[http://www.trejan.com/projects/ipod/ Firmware List]&lt;br /&gt;
*[http://itunes.com/version Apple Firmware XML]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13850</id>
		<title>Talk:06.15.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13850"/>
		<updated>2010-11-30T18:00:36Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Install check */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This has to be the best AppleFail yet, being able to use this on 3G/3GS... [[User:Iemit737|Iemit737]] 01:56, 29 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Install check ==&lt;br /&gt;
&lt;br /&gt;
Why can this be installed on iPhone? I thought as of iOS4.2.1 there's a check for the bb version that must match the firmware. If a wrong (in this case higher) bb version is installed, then iOS doesn't boot. Or why does it boot now? And why can an old baseband be installed at all? Because the version number is higher and before iPhone 4 there was no certificate check? --[[User:Http|http]] 00:16, 30 November 2010 (UTC)&lt;br /&gt;
:The sig check for the baseband only determines if the baseband firmware is lower than what it should correspond to the iOS firmware then it prevents a successful boot sequence. However since the 3G/3GS use the X-Gold 608 chip it can be flashed to a higher Modem Firmware. By doing so it uses the chips own programming to be exploited using the recycled AT+XAPP injection vector. This however could easily be patched. Now that I answered your question maybe you can help me with this one. Since the iPad has no lock in the baseband why is Ultrasn0w even needed? [[User:Leobruh|Leobruh]] 03:57, 30 November 2010 (UTC)!&lt;br /&gt;
::The unlock status doesn't reside in the baseband firmware; it's in the [[seczone]]. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 04:24, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::So the baseband version check does not check for correct firmware version; it checks for &amp;quot;lower than correct&amp;quot; version. #epicfail --[[User:Http|http]] 08:57, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::@Dialexio, so you still have to patch running memory with Ultrasn0w for the on-the-fly ram unlock?&lt;br /&gt;
@http, fail in it's biggest form. who knows how long we can use AT+XAPP. [[User:Leobruh|Leobruh]] 11:15, 30 November 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
Someone needs to write a baseband downgrader with this to allow normal restores again. And what really needs to be done is a bootloader downgrader, 5.8 FTW [[User:Geohot|geohot]] 16:41, 30 November 2010 (UTC)&lt;br /&gt;
:in the [[25C3_presentation_Hacking_the_iPhone]] [[User:MuscleNerd|MuscleNerd]] did say that the [[N82ap|iphone 3]]g has [[fakeblank]] but it uses a hash to verify the [[Baseband_Bootloader|bootloader]] and [[Fuzzyband_Downgrader]] does a good [[Baseband_Firmware]] downgrade --[[User:Liamchat|liamchat]] 17:08, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
@geohot, would the 5.8BL downgrade work on the 3GS because it uses X-Gold 5.8? but doesnt the bootloader get checked everytime by the baseband and vice-versa? another exploit like the one for the 3.6/4.9 for the 2G would be needed correct? [[User:Leobruh|Leobruh]] 17:59, 30 November 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13849</id>
		<title>Talk:06.15.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13849"/>
		<updated>2010-11-30T17:59:47Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Install check */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This has to be the best AppleFail yet, being able to use this on 3G/3GS... [[User:Iemit737|Iemit737]] 01:56, 29 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Install check ==&lt;br /&gt;
&lt;br /&gt;
Why can this be installed on iPhone? I thought as of iOS4.2.1 there's a check for the bb version that must match the firmware. If a wrong (in this case higher) bb version is installed, then iOS doesn't boot. Or why does it boot now? And why can an old baseband be installed at all? Because the version number is higher and before iPhone 4 there was no certificate check? --[[User:Http|http]] 00:16, 30 November 2010 (UTC)&lt;br /&gt;
:The sig check for the baseband only determines if the baseband firmware is lower than what it should correspond to the iOS firmware then it prevents a successful boot sequence. However since the 3G/3GS use the X-Gold 608 chip it can be flashed to a higher Modem Firmware. By doing so it uses the chips own programming to be exploited using the recycled AT+XAPP injection vector. This however could easily be patched. Now that I answered your question maybe you can help me with this one. Since the iPad has no lock in the baseband why is Ultrasn0w even needed? [[User:Leobruh|Leobruh]] 03:57, 30 November 2010 (UTC)!&lt;br /&gt;
::The unlock status doesn't reside in the baseband firmware; it's in the [[seczone]]. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 04:24, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::So the baseband version check does not check for correct firmware version; it checks for &amp;quot;lower than correct&amp;quot; version. #epicfail --[[User:Http|http]] 08:57, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::@Dialexio, so you still have to patch running memory with Ultrasn0w for the on-the-fly ram unlock?&lt;br /&gt;
@http, fail in it's biggest form. who knows how long we can use AT+XAPP. [[User:Leobruh|Leobruh]] 11:15, 30 November 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
Someone needs to write a baseband downgrader with this to allow normal restores again. And what really needs to be done is a bootloader downgrader, 5.8 FTW [[User:Geohot|geohot]] 16:41, 30 November 2010 (UTC)&lt;br /&gt;
:in the [[25C3_presentation_Hacking_the_iPhone]] [[User:MuscleNerd|MuscleNerd]] did say that the [[N82ap|iphone 3]]g has [[fakeblank]] but it uses a hash to verify the [[Baseband_Bootloader|bootloader]] and [[Fuzzyband_Downgrader]] does a good [[Baseband_Firmware]] downgrade --[[User:Liamchat|liamchat]] 17:08, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
@geohot, would the 5.8BL downgrade work on the 3GS because it uses X-Gold 5.8? but doesnt the bootloader get checked everytime by the baseband and vice-versa? another exploit like the one for the 3.8/4.9 for the 2G would be needed correct? [[User:Leobruh|Leobruh]] 17:59, 30 November 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13834</id>
		<title>Talk:06.15.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13834"/>
		<updated>2010-11-30T11:15:59Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This has to be the best AppleFail yet, being able to use this on 3G/3GS... [[User:Iemit737|Iemit737]] 01:56, 29 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Install check ==&lt;br /&gt;
&lt;br /&gt;
Why can this be installed on iPhone? I thought as of iOS4.2.1 there's a check for the bb version that must match the firmware. If a wrong (in this case higher) bb version is installed, then iOS doesn't boot. Or why does it boot now? And why can an old baseband be installed at all? Because the version number is higher and before iPhone 4 there was no certificate check? --[[User:Http|http]] 00:16, 30 November 2010 (UTC)&lt;br /&gt;
:The sig check for the baseband only determines if the baseband firmware is lower than what it should correspond to the iOS firmware then it prevents a successful boot sequence. However since the 3G/3GS use the X-Gold 608 chip it can be flashed to a higher Modem Firmware. By doing so it uses the chips own programming to be exploited using the recycled AT+XAPP injection vector. This however could easily be patched. Now that I answered your question maybe you can help me with this one. Since the iPad has no lock in the baseband why is Ultrasn0w even needed? [[User:Leobruh|Leobruh]] 03:57, 30 November 2010 (UTC)!&lt;br /&gt;
::The unlock status doesn't reside in the baseband firmware; it's in the [[seczone]]. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 04:24, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::So the baseband version check does not check for correct firmware version; it checks for &amp;quot;lower than correct&amp;quot; version. #epicfail --[[User:Http|http]] 08:57, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::@Dialexio, so you still have to patch running memory with Ultrasn0w for the on-the-fly ram unlock?&lt;br /&gt;
@http, fail in it's biggest form. who knows how long we can use AT+XAPP. [[User:Leobruh|Leobruh]] 11:15, 30 November 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13823</id>
		<title>Talk:06.15.00</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:06.15.00&amp;diff=13823"/>
		<updated>2010-11-30T03:57:25Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This has to be the best AppleFail yet, being able to use this on 3G/3GS... [[User:Iemit737|Iemit737]] 01:56, 29 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Install check ==&lt;br /&gt;
&lt;br /&gt;
Why can this be installed on iPhone? I thought as of iOS4.2.1 there's a check for the bb version that must match the firmware. If a wrong (in this case higher) bb version is installed, then iOS doesn't boot. Or why does it boot now? And why can an old baseband be installed at all? Because the version number is higher and before iPhone 4 there was no certificate check? --[[User:Http|http]] 00:16, 30 November 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The sig check for the baseband only determines if the baseband firmware is lower than what it should correspond to the iOS firmware then it prevents a successful boot sequence. However since the 3G/3GS use the X-Gold 608 chip it can be flashed to a higher Modem Firmware. By doing so it uses the chips own programming to be exploited using the recycled AT+XAPP injection vector. This however could easily be patched. Now that I answered your question maybe you can help me with this one. Since the iPad has no lock in the baseband why is Ultrasn0w even needed? [[User:Leobruh|Leobruh]] 03:57, 30 November 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User_talk:Ifish&amp;diff=13062</id>
		<title>User talk:Ifish</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User_talk:Ifish&amp;diff=13062"/>
		<updated>2010-11-18T10:51:20Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: New page: lacrosse pwns diving. diving is pretty chill though. Our lives are bro.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;lacrosse pwns diving. diving is pretty chill though. Our lives are bro.&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=F0recast&amp;diff=12589</id>
		<title>F0recast</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=F0recast&amp;diff=12589"/>
		<updated>2010-11-08T19:38:54Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* iPhone */ refurbished was spelled wrong&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:f0recast}}&lt;br /&gt;
== What is f0recast? ==&lt;br /&gt;
An application created by [[User:ih8sn0w|iH8sn0w]]. He created a simple application that uses Manzana to tap into [[MobileDevice Library]] inside of: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\iTunesMobileDevice.dll&lt;br /&gt;
&lt;br /&gt;
'''It grabs these functions when an iDevice is connected:'''&lt;br /&gt;
* Serial #&lt;br /&gt;
* [[Baseband Firmware|Baseband]]&lt;br /&gt;
* Bootloader Version&lt;br /&gt;
* Model&lt;br /&gt;
* ProductType&lt;br /&gt;
&lt;br /&gt;
== How does it determine if its [[unlock]]able? ==&lt;br /&gt;
When f0recast grabs the [[Baseband Firmware|baseband]] version, it checks the version against a built-in database to determine whether it is [[unlock]]able or not.&lt;br /&gt;
&lt;br /&gt;
== How does it determine if it's restricted to a [[tethered jailbreak]]? ==&lt;br /&gt;
===[[iPhone]]===&lt;br /&gt;
* When the iPhone is inserted, it first checks to see the Product type. If any device but an [[N88ap|iPhone 3GS]] is connected, it is immediately determined to be untethered. It checks the 3rd, 4th &amp;amp; 5th digit of the Serial #. &lt;br /&gt;
* If the 3 digits are below 940, it is determined to be untethered. If it is above, then it tells the owner that it could be tethered. &lt;br /&gt;
*(f0recast cannot fully tell you whether it is a [[tethered jailbreak]] because tons of refurbished models still contain the [[iBoot-359.3|old bootrom]].&lt;br /&gt;
* The only way of determining if it's limited to a [[tethered jailbreak]] is entering [[DFU Mode]] to check the [[bootrom]] version. If it contains (.2) at the end (e.g [[iBoot-359.3.2]] = Tethered). f0recast doesn't implement this is because LibUSB is required to check this.&lt;br /&gt;
* The reason LibUSB is not a smart decision is because it would cause an issue with 64-bit editions of Windows. Therefore, it can only tell you if it is [[untethered]] or if it may be tethered.&lt;br /&gt;
&lt;br /&gt;
===[[iPod touch]]===&lt;br /&gt;
* When the iPod touch is connected, f0recast only focuses on the model. If it sees that the model is either MA/MB/PB, then it will be untethered. If it is anything above, such as: MC/PC, then it will be tethered.&lt;br /&gt;
&lt;br /&gt;
== License ==&lt;br /&gt;
f0recast is freeware.&lt;br /&gt;
&lt;br /&gt;
== Resources ==&lt;br /&gt;
[http://ih8sn0w.com/index.php/products/view/f0recast.snow Download f0recast]&lt;br /&gt;
&lt;br /&gt;
[http://www.github.com/sn0wra1n/F0retell-Reb0rn Open-Source Alternative to f0recast]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Limera1n&amp;diff=10777</id>
		<title>Talk:Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Limera1n&amp;diff=10777"/>
		<updated>2010-10-19T20:20:13Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* He did it */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Drop size on image == &lt;br /&gt;
Has anyone else noticed that on the picture, the lime raindrop us bigger than the rest of them? Could be nothing but could also mean that [[User:Geohot|geohot]] has worked out [[SHAtter]] and use it on the three A4 devices that are there and just used the photos app for the [[N88ap|3GS]].&lt;br /&gt;
Also (if it's real) why is [[User:Geohot|Geohots]]  exploit not used and keep [[SHAtter]] for when there are more A4 devices around? --[[User:Shengis14|Shengis14]] 07:16, 9 October 2010 (UTC)&lt;br /&gt;
:I did see that and assume it's just the same image everywhere, but on retina display it's just smaller due to higher resolution. --[[User:Http|http]] 09:00, 9 October 2010 (UTC)&lt;br /&gt;
::I also saw that and would ask you to look at the image again. iPod Touch 4g and iPhone 4, both retina, have smaller... This could be because [[geohot]] has a problem with the program as he didn't create a @2x.png image... I believe this is a true jailbreK. [[User:Balloonhead66|Balloonhead66]] 13:57, 9 October 2010 (UTC)&lt;br /&gt;
:::In the dump, I found the lime drop and it is a 320x480 image. Therfore, when you jailbreak a retina device with a 320x480 it shrinks the image because there is no lime@2x.png file...&lt;br /&gt;
&lt;br /&gt;
== Misc. ==&lt;br /&gt;
I think some more info may be needed. What is some background on it? I thought Limera1n was a fake from the 3.x days? --[[User:OMEGA RAZER|OMEGA RAZER]] 22:09, 8 October 2010 (UTC&lt;br /&gt;
:It was never fake see [http://theiphonewiki.com/limera1n http://theiphonewiki.com/limera1n] (a cached copy). --[[User:GreySyntax|GreySyntax]] 22:45, 8 October 2010 (UTC)&lt;br /&gt;
::Thanks for the clarification. Not sure where I heard that. --[[User:OMEGA RAZER|OMEGA RAZER]] 23:09, 8 October 2010 (UTC)&lt;br /&gt;
Geohot made the web page when 3.1.3 come out but he said it used a bootrom exploit for untetherdness that he was saving for the iPhone 4 --[[User:Liamchat|liamchat]] 22:53, 8 October 2010 (UTC)&lt;br /&gt;
Anything else we should mention? :P --[[User:Dra1nerdrake|dra1nerdrake]] 23:14, 8 October 2010 (UTC)&lt;br /&gt;
:Why the insane secrecy of it? I'm not deep in the scene but this is the first I'm hearing more than the name lol. --[[User:OMEGA RAZER|OMEGA RAZER]] 23:18, 8 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Release ==&lt;br /&gt;
&lt;br /&gt;
I thought geohot had no plans to release it... [[User:Balloonhead66|Balloonhead66]] 23:22, 8 October 2010 (UTC)&lt;br /&gt;
:Correct. Read the controversy section of this page. It should answer as to why the sudden change in heart. ~Drake&lt;br /&gt;
&lt;br /&gt;
== SIGN YOUR COMMENTS ON THE TALK PAGE ==&lt;br /&gt;
Please press the button on top of the exit box or type &amp;lt;nowiki&amp;gt;~~~~&amp;lt;/nowiki&amp;gt; manually. This will give you the basic signature. It's also acceptable to just identify yourself. Just make sure we know who you are. ;P ~Drake&lt;br /&gt;
&lt;br /&gt;
== Latest edit to [[Limera1n]] ==&lt;br /&gt;
&lt;br /&gt;
How does it look like a tethered? -- Balloonhead66|23:34, October 8, 2010 (UTC)&lt;br /&gt;
:They're all plugged in with USB cables. --[[User:OMEGA RAZER|OMEGA RAZER]] 23:35, 8 October 2010 (UTC)&lt;br /&gt;
::They could just be charging and he is in  the photos app -- Balloonhead66|23:41, October 8, 2010 (UTC)&lt;br /&gt;
:::I think it's because they need to be plugged in for the ramdisk to be uploaded (hence the logo). --[[User:Palz|Palz]] 21:15, 12 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Who is John Galt? ==&lt;br /&gt;
&lt;br /&gt;
Look at the HTML source of the page. Is this comment new? [[User:Angelo|Angelo]] 23:42, 8 October 2010 (UTC)&lt;br /&gt;
:Yep. I've looked at the source of this page before and after this update. The John Galt is probably meant to throw us off. Geohot does that. :P But, yes, it's new. ~Drake&lt;br /&gt;
::Where did you see that? [[User:Balloonhead66|Balloonhead66]] 23:50, 8 October 2010 (UTC)&lt;br /&gt;
:::Type in Firefox URL bar: view-source:http://limera1n.com/ [[User:Angelo|Angelo]] 23:47, 8 October 2010 (UTC)&lt;br /&gt;
::::Or google chrome for that matter :D .  Anyway, I thought you meant the source of this page or the [[Limera1n]] page, not the website... *stupid* Thanks for explaining that! [[User:Balloonhead66|Balloonhead66]] 23:50, 8 October 2010 (UTC)&lt;br /&gt;
:::::[http://en.wikipedia.org/wiki/John_Galt Who is John Galt] Kind of funny actually when you read it and what's going on right now --[[User:alpineflip|alpineflip]]&lt;br /&gt;
:::::: yes I see why &amp;quot;learns that all of the stories have an element of truth to them.&amp;quot; maybe it will ra1n again but not today --[[User:Liamchat|liamchat]] 00:35, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Explanation ==&lt;br /&gt;
&lt;br /&gt;
So, I'm sure most, if not all, of you are confused. This Limera1n is nothing more than a plot by geohot to get the chronic dev team to incorporate the exploit used in limera1n into greenpois0n. This is not plausible because the exploit in limera1n is a bootrom level exploit, which can be used to make a jailbreak (albeit [[tethered]]) on its own. To make greenpois0n untethered, chronic dev has used a tweak by comex (in userland) to patch the kernel. The exploit in Limera1n can be used at a later date to make another untethered jailbreak, but it's better to leave the lower level exploits until later, after all, either way, it produces the same affect. To implement the limera1n exploit into greenpois0n, they'd have to rewrite the entire jailbreak, which would offset the release. This should clear up confusion. ~Drake&lt;br /&gt;
&lt;br /&gt;
I reckon it was the iphone dev teams fault if they just had to release spirit after the iphone 4 was released there would be no drama because the ipod touch 4 would hav been jailbroken via star. --[[User:Robinhood|robinhood]] &lt;br /&gt;
&lt;br /&gt;
I think Geohot told someone about his exploit and apple attempted to patch it in a4 bootrom [http://mobile.twitter.com/musclenerd/status/26801617164] --[[User:Liamchat|liamchat]] 01:54, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
===UPDATE:===&lt;br /&gt;
A [http://twitter.com/#!/p0sixninja/status/26799962302 recent tweet] from iPhone hacker p0sixninja has just confirmed that the date WILL NOT be changed. If they can implement geohot's exploit before 10/10, they will use that. If they can't they won't. --[[User:Dra1nerdrake|dra1nerdrake]] 00:53, 9 October 2010 (UTC)&lt;br /&gt;
: This has nothing to-do with Limera1n. -- [[User:Shorty|Shorty]] 01:06, 9 October 2010 (UTC)&lt;br /&gt;
::It does. If they can integrate it into GP then there's not going to be a Limera1n. If they can't in time then there will be two jailbreaks released... --[[User:OMEGA RAZER|OMEGA RAZER]] 01:11, 9 October 2010 (UTC)&lt;br /&gt;
::: This is a grand waste of a bootrom exploit though. ~Drake&lt;br /&gt;
:::: Geohot will not waste the exploit's used in limera1n but greenpois0n is using a bootrom exploit to inject a userland exploit that is odd --[[User:Liamchat|liamchat]] 01:20, 9 October 2010 (UTC)&lt;br /&gt;
:::::Yes it does limera1n will use an untetherd bootrom and iboot exploit but Why does Geohot not want us to use comex's kernel patch just for 4.1 then when 4.2 is out we can use shatter to reuse the iboot exploit --[[User:Liamchat|liamchat]] 01:20, 9 October 2010 (UTC)&lt;br /&gt;
::::::@[[User:Dra1nerdrake|dra1nerdrake]] - Sorry if I didn't make myself more clear, I was basically on about the first part, not the last bit. -- [[User:Shorty|Shorty]] 01:25, 9 October 2010 (UTC)&lt;br /&gt;
the exploit used by [[limera1n]] is a [[24kPwn]] like [[bootrom]] exploit and a [[IBoot]] exploit  ( read the second to last paragraph [http://posixninja.blogspot.com/2010/06/latest-progress-and-new-updates.html] ) --[[User:Liamchat|liamchat]] 12:55, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Image Taken Down ==&lt;br /&gt;
&lt;br /&gt;
I'm just speculating here. With all this controversy, I am on the edge of believing... Also, the image was taken down from the site... It gives you a bitly link that takes you back to the bitty link... --[[User:Balloonhead66|Balloonhead66]] 14:20, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:It is now very real [[greenpois0n]] will be cancelled (said by [[MuscleNerd]] [http://twitter.com/MuscleNerd/status/26860163077 Twitter Status]) and [[Limera1n]] will be used to jailbreak on 4.1 but [[wikipedia:Apple Inc.|Apple]] knows about both exploit's but [[Geohot]]'s has already being patched (patched in 4.2 beta 2 iboot [http://twitter.com/MuscleNerd/status/26860634891]) --[[User:Liamchat|liamchat]] 19:21, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::The exploit has not been patched though, but because of the code similarities geohot can tell his exploit will be patched anyway by iPad2,1 so he wants it to be used instead of wasted, greenpois0n and SHAtter should be kept as they will affect a larger crowd of iOS devices (assuming apple continue to use the A4 chip. --[[User:Shengis14|Shengis14]] 19:36, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:::[[Geohot]]'s exploit will be used in [[greenpois0n]] if it can be utilised in time. Otherwise both exploits will be burned. In relation to the image being taken down, it was proving to be too popular, so imageshack moved it. --[[User:Mushroom|Mushroom]]  19:47, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::::I dont think so we said a lot about [[SHAtter]] (if apple patch one of the three BSS+Heap+Stack the exploit wont work) so it may be to late to protect [[SHAtter]] but [[Geohot]]'s exploit was fixed in [[iBoot]] so [[wikipedia:Apple Inc.|Apple]] knows 100% what his exploit is --[[User:Liamchat|liamchat]] 20:06, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== He did it==&lt;br /&gt;
It's in the wild. Thoughts? ~Drake&lt;br /&gt;
:It's just BETA2 though... --[[User:Balloonhead66|Balloonhead66]] 22:28, 9 October 2010 (UTC)&lt;br /&gt;
::Has anyone being able to grab information about the exploit we need to delete shatter and name the new dfu exploit --[[User:Liamchat|liamchat]] 23:22, 9 October 2010 (UTC)&lt;br /&gt;
:::BETA2 naming means nothing. We need to delete SHAtter? Wtf? And also this exploit will either be named by Geohot or by it's technical name (like Environment Variable Overflow). [[User:Iemit737|Iemit737]] 00:03, 10 October 2010 (UTC)&lt;br /&gt;
::::I'd like to disassemble this and see what's in that exe of his. Anyone take a gander into this magical land of software yet? The payload's bound to be in there somewhere. ~Drake&lt;br /&gt;
:::::A dump has been released by ih8sn0w, see links. So much for the protection he put on it. It uses the ramdisk from purplera1n ( lulz). You'll need IDA Pro... [[User:Pwnd-v1|Pwnd-v1]] 13:12, 10 October 2010 (UTC)&lt;br /&gt;
::::::Blackra1n uses purpled1sk too :/ All it is is an exploit like arm7_go in DFU that pwns iBoot (temporarily) and applies a userland jailbreak from a ramdisk. --[[User:Palz|Palz]] 22:16, 15 October 2010 (UTC)&lt;br /&gt;
the exploit ( it is a heap overflow ) is used to create a command called geohot ( in the [[NOR_%28NVRAM%29]] same as in [[Purplera1n]] ) maybe purpled1sk is the best for the job [[iBoot]] cannot be changed it will remove [[SHSH]] preventing the device from booting  --[[User:Liamchat|liamchat]] 22:32, 15 October 2010 (UTC)&lt;br /&gt;
:do u hear urself talk? the bootrom exploit in limera1n is not a heap overflow. -__- the heap overflow is the userland exploit used to achieve an untethered status.[[User:Leobruh|Leobruh]] 20:20, 19 October 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
== Pwnage ==&lt;br /&gt;
&lt;br /&gt;
Does limera1n flash the NOR? I never managed to install a custom firmware after using limera1n.--[[User talk:Ryccardo|Ryccardo]], 11 October 2010 (UTC)&lt;br /&gt;
:Sign your posts, please. And, limera1n leaves your NOR untouched. All it does is patch the kernel (which is on your NAND). Theoretically, one might be able to restore to a custom firmware by jumping to a pwned iBSS or iBEC through the limera1n exploit and using that to trick the device into accepting the firmware, but I'm probably mistaken. --[[User:Dra1nerdrake|dra1nerdrake]] 19:28, 11 October 2010 (UTC)&lt;br /&gt;
:It leaves the NOR un-touched otherwise the signature checks would fail during boot. Hence the kernel exploit from [[User:comex|comex]] is used to patch the kernel at runtime. --[[User:GreySyntax|GreySyntax]] 19:49, 11 October 2010 (UTC)&lt;br /&gt;
::Thanks, [[http://twitter.com/iH8sn0w/statuses/27065535774 iH8Sn0w confirms.]] Sorry for the signature, I always forget to use that button. --[[User:Ryccardo|Ryccardo]] 20:43, 11 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Support ==&lt;br /&gt;
&lt;br /&gt;
I propose that appleTV should be removed from the supported list until further notice as while the exploit interacts with the bootrom, the ramdisk never executes to jailbreak the OS and leaves you in recovery mode (yet to establish if it is in a pwned state or not) --[[User:Lilstevie|Lilstevie]] 07:29, 12 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Why no ipt2g support? ==&lt;br /&gt;
&lt;br /&gt;
I have an ipt2g mc model. I currently have no 4.1 jailbreak, since sn0wbreeze is messed up and redsn0w hangs. Why doesn't this exploit work with the new bootrom touches? Have we been forgotten? --[[User:Palz|Palz]] 21:13, 12 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:It works for the ipt2g new bootrom, but geohot didn't take his time to remake anything so that it would work with our device. greenpois0n will support our devices, just takes a little while to write up everything needed. --[[User:JacobVengeance|JakeAnthraX]] 05:24, 13 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== hacktivation.dylib ==&lt;br /&gt;
&lt;br /&gt;
I added info about it and how to remove it for people who activate with iTunes. Hope no one minds. --[[User:Cmdshft|cmdshft]] 04:31, 13 October 2010 (UTC)&lt;br /&gt;
:I have my 3GS officially activated and had no problems at all with this dylib or anything else related to activation so far... I'm officially unlocked too... Should I still remove the dylib even if I had no problems?? --[[User:Luxiel|Luxiel]] 17:02, 19 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Pwn4life ==&lt;br /&gt;
&lt;br /&gt;
Is this a pwned4life?  If it is, can a restore remove it?  --[[User:Balloonhead66|Balloonhead66]] 02:10, 15 October 2010 (UTC)&lt;br /&gt;
:A DFU Mode restore will return you to a fresh and all Apple state --[[User:OMEGA RAZER|OMEGA RAZER]] 04:20, 15 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:Pwned4life isn't like permanent jailbreak on the device, just means there is an exploit that will always be there to allow jailbreaks. A restore will get rid of it simple. --[[User:JacobVengeance|JakeAnthraX]] 19:37, 19 October 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Usb_control_msg(0x21,_2)_Exploit&amp;diff=10725</id>
		<title>Talk:Usb control msg(0x21, 2) Exploit</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Usb_control_msg(0x21,_2)_Exploit&amp;diff=10725"/>
		<updated>2010-10-18T20:05:43Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This exploit isn't used in greepois0n, is it? --malontop&lt;br /&gt;
&lt;br /&gt;
nope. this exploit was used back in the 3.1.x days for a tethered jailbreak. SHAtter wont be revealed for awhile. but it is a usb exploit. [[User:Leobruh|Leobruh]] 20:05, 18 October 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9971</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9971"/>
		<updated>2010-10-06T17:52:59Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: Replacing page with 'Active wiki member with an iPhone 3GS 16gb.'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Active wiki member with an iPhone 3GS 16gb.&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9729</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9729"/>
		<updated>2010-09-29T23:12:05Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iDevice Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Sold the 8gb model to buy a 16gb.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #3. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 2G #1. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #4. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 3G #1. (Gifted to one of my cousins.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #4. (Gifted to one of my other cousins.)&lt;br /&gt;
&lt;br /&gt;
==Current iDevices==&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #2. (Needed  a 16gb model.)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=S5L8900&amp;diff=9402</id>
		<title>S5L8900</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=S5L8900&amp;diff=9402"/>
		<updated>2010-09-23T02:25:14Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: not really hacking more like editing a wiki page. bunch of losers.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Exploits ==&lt;br /&gt;
=== [[iBoot]] ===&lt;br /&gt;
'''Note''': [[iBoot]] on the S5L8720 can be downgraded, allowing any of these exploits to be used on future firmwares&lt;br /&gt;
* [[Restore Mode]] -  Works up to [[iOS]] 1.0.2&lt;br /&gt;
* [[Ramdisk Hack]] - Works up to [[iOS]] 2.0 beta 3&lt;br /&gt;
* [[diags]] - Works up to [[iOS]] 2.0 beta 5&lt;br /&gt;
* [[ARM7 Go]] - Works on [[iOS]] 2.1.1&lt;br /&gt;
* [[iBoot Environment Variable Overflow]] - Works up to [[iOS]] 3.1 beta 3&lt;br /&gt;
* [[usb_control_msg(0x21, 2) Exploit]] - Works up to [[iOS]] 3.1.2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== [[Kernel]] ===&lt;br /&gt;
* [[BPF STX Kernel Write Exploit]] - Works up to [[iOS]] 3.1.3&lt;br /&gt;
* [[IOSurface Kernel Exploit]] - Works up to [[iOS]] 4.0.1&lt;br /&gt;
&lt;br /&gt;
=== [[Userland]] ===&lt;br /&gt;
* [[Symlinks]] - Works up to [[iOS]] 1.1.1&lt;br /&gt;
* [[LibTiff]] - Works up to [[iOS]] 1.1.1&lt;br /&gt;
* [[Mknod]] - Works up to [[iOS]] 1.1.2&lt;br /&gt;
* [[Dual Boot Exploit]] - Works up to [[iOS]] 2.0 beta 3&lt;br /&gt;
* [[MobileBackup Copy Exploit]] - Works up to [[iOS]] 3.1.3&lt;br /&gt;
* [[PDF CFF Font Stack Overflow]] - Works up to [[iOS]] 4.0.1&lt;br /&gt;
&lt;br /&gt;
===Boot Chain===&lt;br /&gt;
[[VROM]]-&amp;gt;[[LLB]]-&amp;gt;[[iBoot]]-&amp;gt;[[Kernel]]-&amp;gt;[[System|System Software]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Boot Chain ====&lt;br /&gt;
[[VROM]]-&amp;gt;[[DFU]]&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9178</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9178"/>
		<updated>2010-09-12T03:43:42Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iDevice Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Sold the 8gb model to buy a 16gb.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #3. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 2G #1. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #4. (Sold.)&lt;br /&gt;
&lt;br /&gt;
==Current iDevices==&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #2. (Needed  a 16gb model.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 3G #1. (My iPod dock's bitch.)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9018</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9018"/>
		<updated>2010-09-06T01:30:05Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iDevice Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Sold the 8gb model to buy a 16gb.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #3. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 2G #1. (Sold.)&lt;br /&gt;
&lt;br /&gt;
==Current iDevices==&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #2. (Needed  a 16gb model.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #4. (Needed a 16gb model.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 3G #1. (My iPod dock's bitch.)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9017</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=9017"/>
		<updated>2010-09-06T01:28:24Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iPhone Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Sold the 8gb model to buy a 16gb.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #3. (Sold.)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 2G #1. (Sold.)&lt;br /&gt;
&lt;br /&gt;
==Current iDevices==&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #2. (Needed  a 16gb model.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #4. (Needed a 16gb model.)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User_talk:Leobruh&amp;diff=8873</id>
		<title>User talk:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User_talk:Leobruh&amp;diff=8873"/>
		<updated>2010-09-02T02:28:15Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Recent Vandalism==&lt;br /&gt;
Hi there Leobruh! I couldn't help but notice that your page was vandalized... Sorry for letting that slip under the radar. However, in retaliation, you vandalized Gamer765's page and talk page. Please don't fight fire with fire... You could always notify a sysop (me, [[User:Http|Http]], et. al.) if we inadvertently neglect such actions. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 01:57, 2 September 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
thank you sir.[[User:Leobruh|Leobruh]] 02:28, 2 September 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=8849</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=8849"/>
		<updated>2010-09-02T00:41:31Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iPhone Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Current iDevices==&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Currently using and praying for the best.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #3. (Works 100%)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 2G #1. (Works 100%)&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=8836</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=8836"/>
		<updated>2010-09-01T19:06:23Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iPhone Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
==Current iDevices==&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Currently using and praying for the best.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #3. (Works 100%)&lt;br /&gt;
&lt;br /&gt;
iPod Touch 2G #1. (Works 100%)&lt;br /&gt;
&lt;br /&gt;
I get silly I suppose :P&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User_talk:Dialexio&amp;diff=8739</id>
		<title>User talk:Dialexio</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User_talk:Dialexio&amp;diff=8739"/>
		<updated>2010-08-25T17:10:42Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Q */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Baseband Help==&lt;br /&gt;
hey i need help {{unsigned|Leobruh|03:35, March 29, 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
with...? {{unsigned|Gojohnnyboi|04:00, March 29, 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
im trying to learn how to find baseband exploits but i need some PC friendly tools to find those baseband exploits [[User:Leobruh|Leobruh]]!&lt;br /&gt;
:I can't help you there, sorry. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 15:06, 24 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Rant deletion==&lt;br /&gt;
alright i agree with what u did. [[User:Leobruh|Leobruh]] 04:39, 3 July 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
==Thanks==&lt;br /&gt;
Thanks for curating this wiki by wikifying paragraphs and adding tons of relevant, accurate, and grammatically correct info. :) [[User:Iemit737|Iemit737]] 01:00, 14 July 2010 (UTC)&lt;br /&gt;
:Thanks! You've done a pretty amazing job also. :D --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 02:50, 14 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Presentation links==&lt;br /&gt;
Thanks for adding those HQ torrent links, probably better than my FLV anyway ;) [[User:MaybachMan|MaybachMan]] 22:06, 14 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
... And once again for the Bluetooth additions. I'll shut up now ;) [[User:MaybachMan|MaybachMan]] 22:14, 14 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Beta Firmwares==&lt;br /&gt;
should we start a beta firmwares page that contains a table with release dates, baseband versions, and iboot versions but without links? It might be interesting for reference purposes, and a good way to link to the decryption keys. [[User:Iemit737|Iemit737]] 03:53, 20 July 2010 (UTC)&lt;br /&gt;
:I suppose this could be done (at [[Firmware/Beta]]?). I don't think hashes should be provided, though. A hash will probably only serve to help idiots pirate, verify, and install a beta firmware. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 04:57, 20 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Sysop Status==&lt;br /&gt;
You are now a sysop. --[[User:Geohot|geohot]] 15:32, 21 July 2010 (UTC)&lt;br /&gt;
:Thanks geohot! I'll be sure to do the best I can. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 21:48, 21 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Q==&lt;br /&gt;
idc if the link is there or not&lt;br /&gt;
u can C&amp;amp;P my paragraph to keep people informed [[User:Leobruh|Leobruh]] 05:37, 25 August 2010 (UTC)!&lt;br /&gt;
:What do you mean with Q, idc, C&amp;amp;P? Ah, and yes, I agree that he deleted the advertisement page you made. It doesn't really belong into this wiki and the page had no content except the link to your blog. -- [[User:Http|http]] 10:34, 25 August 2010 (UTC)&lt;br /&gt;
::C&amp;amp;P is copy and paste :P if i just copy my post will that be okay? [[User:Leobruh|Leobruh]] 17:10, 25 August 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User_talk:Dialexio&amp;diff=8722</id>
		<title>User talk:Dialexio</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User_talk:Dialexio&amp;diff=8722"/>
		<updated>2010-08-25T05:37:31Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Baseband Help==&lt;br /&gt;
hey i need help {{unsigned|Leobruh|03:35, March 29, 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
with...? {{unsigned|Gojohnnyboi|04:00, March 29, 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
im trying to learn how to find baseband exploits but i need some PC friendly tools to find those baseband exploits [[User:Leobruh|Leobruh]]!&lt;br /&gt;
:I can't help you there, sorry. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 15:06, 24 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Rant deletion==&lt;br /&gt;
alright i agree with what u did. [[User:Leobruh|Leobruh]] 04:39, 3 July 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
==Thanks==&lt;br /&gt;
Thanks for curating this wiki by wikifying paragraphs and adding tons of relevant, accurate, and grammatically correct info. :) [[User:Iemit737|Iemit737]] 01:00, 14 July 2010 (UTC)&lt;br /&gt;
:Thanks! You've done a pretty amazing job also. :D --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 02:50, 14 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Presentation links==&lt;br /&gt;
Thanks for adding those HQ torrent links, probably better than my FLV anyway ;) [[User:MaybachMan|MaybachMan]] 22:06, 14 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
... And once again for the Bluetooth additions. I'll shut up now ;) [[User:MaybachMan|MaybachMan]] 22:14, 14 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Beta Firmwares==&lt;br /&gt;
should we start a beta firmwares page that contains a table with release dates, baseband versions, and iboot versions but without links? It might be interesting for reference purposes, and a good way to link to the decryption keys. [[User:Iemit737|Iemit737]] 03:53, 20 July 2010 (UTC)&lt;br /&gt;
:I suppose this could be done (at [[Firmware/Beta]]?). I don't think hashes should be provided, though. A hash will probably only serve to help idiots pirate, verify, and install a beta firmware. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 04:57, 20 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Sysop Status==&lt;br /&gt;
You are now a sysop. --[[User:Geohot|geohot]] 15:32, 21 July 2010 (UTC)&lt;br /&gt;
:Thanks geohot! I'll be sure to do the best I can. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 21:48, 21 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Q==&lt;br /&gt;
idc if the link is there or not&lt;br /&gt;
u can C&amp;amp;P my paragraph to keep people informed [[User:Leobruh|Leobruh]] 05:37, 25 August 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Hacktivation&amp;diff=8642</id>
		<title>Talk:Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Hacktivation&amp;diff=8642"/>
		<updated>2010-08-23T04:22:54Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;You should write &amp;quot;Hacktivation&amp;quot; instead of &amp;quot;Hackitivation&amp;quot;. ;) -- hypn0zis&lt;br /&gt;
&lt;br /&gt;
fixed lol this page was in due need. [[User:Leobruh|Leobruh]] 04:22, 23 August 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8638</id>
		<title>Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8638"/>
		<updated>2010-08-23T03:28:40Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Methods */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hackitivation is the process of circumventing the standard Apple activation process with iTunes. As of now you can hackitivate an iPhone in a variety of ways. The most common use for hackitivation is for users of an unlock. At times some iPhones users hackitivate to use the phone as an iPod Touch with a camera.&lt;br /&gt;
&lt;br /&gt;
==Methods==&lt;br /&gt;
1. By using a valid AT&amp;amp;T sim card and connecting to iTunes. (This method will work on any iPhone. Although its not true hackitivation it can be a type of method for users without ATT.&lt;br /&gt;
&lt;br /&gt;
2. Using redsn0w and not selecting any of the options. (This will work on any iPhone compatible with the redsn0w version)&lt;br /&gt;
&lt;br /&gt;
3. If on 3.1.x you can run blackra1n. (If you have a new bootrom 3GS it will be tethered.)&lt;br /&gt;
&lt;br /&gt;
4. Restore using sn0wbreeze. (Like redsn0w this will work on any iPhone compatible with the sn0wbreeze version)&lt;br /&gt;
&lt;br /&gt;
5. By using a phonebook sim card and connecting to iTunes and syncing the phone. (Note you must sync your phone for the activation token to be signed. If you put the phonebook sim card in and take it out of the phone without syncing to iTunes, thene it will go to the &amp;quot;Connect to iTunes/Emergency Call&amp;quot; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Note that the userland jailbreak Spirit will not hackitivate because it relies on MobileSubstrate for the jailbreak. Also note that Star will never be able to hackitivate because for someone to even use it you have to have Safari access.]&lt;br /&gt;
&lt;br /&gt;
---Leobruh&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8637</id>
		<title>Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8637"/>
		<updated>2010-08-23T03:26:10Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Methods */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hackitivation is the process of circumventing the standard Apple activation process with iTunes. As of now you can hackitivate an iPhone in a variety of ways. The most common use for hackitivation is for users of an unlock. At times some iPhones users hackitivate to use the phone as an iPod Touch with a camera.&lt;br /&gt;
&lt;br /&gt;
==Methods==&lt;br /&gt;
1. By using a valid AT&amp;amp;T sim card and connecting to iTunes. (This method will work on any iPhone. Although its not true hackitivation it can be a type of method for users without ATT.&lt;br /&gt;
&lt;br /&gt;
2. Using redsn0w and not selecting any of the options. (This will work on any iPhone compatible with the redsn0w version)&lt;br /&gt;
&lt;br /&gt;
3. If on 3.1.x you can run blackra1n. (If you have a new bootrom 3GS it will be tethered.)&lt;br /&gt;
&lt;br /&gt;
4. Restore using sn0wbreeze. (Like redsn0w this will work on any iPhone compatible with the sn0wbreeze version)&lt;br /&gt;
&lt;br /&gt;
5. By using a phonebook sim card and connecting to iTunes and syncing the phone. (Note you must sync your phone for the activation token to be signed. If you put the phonebook sim card in and take it out your phone will go to the &amp;quot;Connect to iTunes/Emergency Call&amp;quot; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[Note that the userland jailbreak Spirit will not hackitivate because it relies on MobileSubstrate for the jailbreak. Also note that Star will never be able to hackitivate because for someone to even use it you have to have Safari access.]&lt;br /&gt;
&lt;br /&gt;
---Leobruh&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8636</id>
		<title>Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8636"/>
		<updated>2010-08-23T03:21:26Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hackitivation is the process of circumventing the standard Apple activation process with iTunes. As of now you can hackitivate an iPhone in a variety of ways. The most common use for hackitivation is for users of an unlock. At times some iPhones users hackitivate to use the phone as an iPod Touch with a camera.&lt;br /&gt;
&lt;br /&gt;
==Methods==&lt;br /&gt;
1. By using a valid AT&amp;amp;T sim card and connecting to iTunes. (This method will work on any iPhone. Although its not true hackitivation it can be a type of method for users without ATT.&lt;br /&gt;
&lt;br /&gt;
2. Using redsn0w and not selecting any of the options. (This will work on any iPhone compatible with the redsn0w version)&lt;br /&gt;
&lt;br /&gt;
3. If on 3.1.x you can run blackra1n.&lt;br /&gt;
&lt;br /&gt;
4. Restore using sn0wbreeze.(Like redsn0w this will work on any iPhone compatible with the sn0wbreeze version)&lt;br /&gt;
&lt;br /&gt;
5. By using a phonebook sim card and connecting to iTunes and syncing the phone.&lt;br /&gt;
&lt;br /&gt;
[Note that the userland jailbreak Spirit will not hackitivate because it relies on MobileSubstrate for the jailbreak. Also note that Star will never be able to hackitivate because for someone to even use it you have to have Safari access.]&lt;br /&gt;
&lt;br /&gt;
---Leobruh&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8635</id>
		<title>Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8635"/>
		<updated>2010-08-23T03:19:12Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Methods */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hackitivation is the process of circumventing the standard Apple activation process with iTunes. As of now you can hackitivate an iPhone in a variety of ways.&lt;br /&gt;
&lt;br /&gt;
==Methods==&lt;br /&gt;
1. By using a valid AT&amp;amp;T sim card and connecting to iTunes. (This method will work on any iPhone. Although its not true hackitivation it can be a type of method for users without ATT.&lt;br /&gt;
&lt;br /&gt;
2. Using redsn0w and not selecting any of the options. (This will work on any iPhone compatible with the redsn0w version)&lt;br /&gt;
&lt;br /&gt;
3. If on 3.1.x you can run blackra1n.&lt;br /&gt;
&lt;br /&gt;
4. Restore using sn0wbreeze.(Like redsn0w this will work on any iPhone compatible with the sn0wbreeze version)&lt;br /&gt;
&lt;br /&gt;
5. By using a phonebook sim card and connecting to iTunes and syncing the phone.&lt;br /&gt;
&lt;br /&gt;
[Note that the userland jailbreak Spirit will not hackitivate because it relies on MobileSubstrate for the jailbreak. Also note that Star will never be able to hackitivate because for someone to even use it you have to have Safari access.]&lt;br /&gt;
&lt;br /&gt;
---Leobruh&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8634</id>
		<title>Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8634"/>
		<updated>2010-08-23T03:15:47Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: /* Methods */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hackitivation is the process of circumventing the standard Apple activation process with iTunes. As of now you can hackitivate an iPhone in a variety of ways.&lt;br /&gt;
&lt;br /&gt;
==Methods==&lt;br /&gt;
1. By using a valid AT&amp;amp;T sim card and connecting to iTunes. (This method will work on any iPhone)&lt;br /&gt;
&lt;br /&gt;
2. Using redsn0w and not selecting any of the options. (This will work on any iPhone compatible with the redsn0w version)&lt;br /&gt;
&lt;br /&gt;
3. If on 3.1.x you can run blackra1n.&lt;br /&gt;
&lt;br /&gt;
4. Restore using sn0wbreeze.(Like redsn0w this will work on any iPhone compatible with the sn0wbreeze version)&lt;br /&gt;
&lt;br /&gt;
5. By using a phonebook sim card and connecting to iTunes and syncing the phone.&lt;br /&gt;
&lt;br /&gt;
[Note that the userland jailbreak Spirit will not hackitivate because it relies on MobileSubstrate for the jailbreak. Also note that Star will never be able to hackitivate because for someone to even use it you have to have Safari access.]&lt;br /&gt;
&lt;br /&gt;
---Leobruh&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8633</id>
		<title>Hacktivation</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Hacktivation&amp;diff=8633"/>
		<updated>2010-08-23T03:15:29Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: started a new page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hackitivation is the process of circumventing the standard Apple activation process with iTunes. As of now you can hackitivate an iPhone in a variety of ways.&lt;br /&gt;
&lt;br /&gt;
==Methods==&lt;br /&gt;
1. By using a valid AT&amp;amp;T sim card and connecting to iTunes. (This method will work on any iPhone)&lt;br /&gt;
2. Using redsn0w and not selecting any of the options. (This will work on any iPhone compatible with the redsn0w version)&lt;br /&gt;
3. If on 3.1.x you can run blackra1n.&lt;br /&gt;
4. Restore using sn0wbreeze.(Like redsn0w this will work on any iPhone compatible with the sn0wbreeze version)&lt;br /&gt;
5. By using a phonebook sim card and connecting to iTunes and syncing the phone.&lt;br /&gt;
&lt;br /&gt;
[Note that the userland jailbreak Spirit will not hackitivate because it relies on MobileSubstrate for the jailbreak. Also note that Star will never be able to hackitivate because for someone to even use it you have to have Safari access.]&lt;br /&gt;
&lt;br /&gt;
---Leobruh&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8552</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8552"/>
		<updated>2010-08-21T14:47:54Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. --[[User:Lilstevie|Lilstevie]] 09:45, 20 August 2010 (UTC)- lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
The baseband processor checks the signature, not the application processor. [[User:dogbert|dogbert]] 18:36, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
ahh got ya! but would my theory work though through an exploit such as AT+XAPP? instead of a payload it just changes the .plist? [[User:Leobruh|Leobruh]] 00:15, 20 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
:you would still require the valid NCK for it to process the unlock in that method, the current way the payloads work for exploits in the baseband processor are adequate --[[User:Lilstevie|Lilstevie]] 09:44, 20 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:i thought NKC was only for the iPhone 2G? 0.o [[User:Leobruh|Leobruh]] 14:47, 21 August 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8518</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8518"/>
		<updated>2010-08-20T00:15:26Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. - lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
The baseband processor checks the signature, not the application processor. [[User:dogbert|dogbert]] 18:36, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
ahh got ya! but would my theory work though through an exploit such as AT+XAPP? instead of a payload it just changes the .plist? [[User:Leobruh|Leobruh]] 00:15, 20 August 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8500</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8500"/>
		<updated>2010-08-19T18:33:13Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. - lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=8479</id>
		<title>User:Leobruh</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Leobruh&amp;diff=8479"/>
		<updated>2010-08-19T07:52:33Z</updated>

		<summary type="html">&lt;p&gt;Leobruh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===My iPhone Timeline===&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #1. (RIP from opening to swap battery. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #2. (Sold on Craigslist to buy iPhone 3G #1. WIN.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #1. (Dropped on concrete and flew off a car top after initial cracked screen fix. FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 2G #3. (Fell off a jetski. Revived 2 weeks later after laying in a bag of rice. Gave to my little brother. WIN/FAIL.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3G #2. (Bought a 16gb motherboard for more memory. Pulled the phone apart, sneezed, ripped all the bands of the LCD, Digitizer, and Speaker. FAIL.Then I sold the remaining parts on Craigslist for $50.)&lt;br /&gt;
&lt;br /&gt;
iPhone 3GS #1. (Currently using and praying for the best.)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I get silly I suppose :P&lt;/div&gt;</summary>
		<author><name>Leobruh</name></author>
		
	</entry>
</feed>