<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Lilstevie</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Lilstevie"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/Lilstevie"/>
	<updated>2026-06-09T20:57:53Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=J105aAP&amp;diff=104141</id>
		<title>J105aAP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=J105aAP&amp;diff=104141"/>
		<updated>2020-06-29T14:52:54Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Results from further research into the debug port and how it Sets USB modes&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Apple TV 4K.png|thumb|131px|Apple TV 4K]]&lt;br /&gt;
The Apple TV 4K starts at $179 for 32GB of storage, and $199 for 64GB. Its firmware identifier is AppleTV6,2. It is capable of playing 4K content.&lt;br /&gt;
&lt;br /&gt;
The Apple TV 4K was announced on 12th September 2017 and released on 22nd September 2017.&lt;br /&gt;
&lt;br /&gt;
== Application processor ==&lt;br /&gt;
The Apple TV 4K makes use of the [[T8011|Apple A10X]] processor.&lt;br /&gt;
&lt;br /&gt;
== Debug Port ==&lt;br /&gt;
&lt;br /&gt;
[[File:AppleTV4K_Debug_Ethernet.jpg|thumb|right]]&lt;br /&gt;
&lt;br /&gt;
Hidden behind a small trapdoor in the back of the Ethernet port is a debug port that includes USB access.&lt;br /&gt;
&lt;br /&gt;
Without a custom cable the easiest method of access to the port is to solder directly onto the pins. Care should be taken with the test points that are near the port as they also serve as the top of the via that connects the debug port to the rest of the Apple TV. USB access is enabled by setting the voltage on the mode pin to either USB device mode or assert force_dfu mode. While in DFU or recovery Apple's firmware does not care about the mode pin state and always enables USB. In assert force_dfu mode the Apple TV will enter DFU on every boot. &lt;br /&gt;
&lt;br /&gt;
[[File:AppleTV4K_Debug_Internal.jpg|thumb|left]]&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Pinout&lt;br /&gt;
! Pin&lt;br /&gt;
! Name&lt;br /&gt;
! Max Voltage&lt;br /&gt;
! Notes&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 1&lt;br /&gt;
| Unknown &lt;br /&gt;
| 1.8V&lt;br /&gt;
| Purpose of the pin is unknown but it is connected to the A10X near the USB pins&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 2&lt;br /&gt;
| ACC_PWR &lt;br /&gt;
| 3.3V&lt;br /&gt;
| Pin is connected to a power switch, more exploration is required to see if it is capable of outputting 5V&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 3&lt;br /&gt;
| USB_DM &lt;br /&gt;
| 3.3V&lt;br /&gt;
| Pin operates at USB logic levels.&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 4&lt;br /&gt;
| USB_DP &lt;br /&gt;
| 3.3V&lt;br /&gt;
| Pin operates at USB logic levels.&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 5&lt;br /&gt;
| GND &lt;br /&gt;
| 0V&lt;br /&gt;
| Pin is connected directly to the boards ground plane&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 6&lt;br /&gt;
| Mode Pin &lt;br /&gt;
| 1.8V&lt;br /&gt;
| Selects mode dependant on voltage&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 7&lt;br /&gt;
| Unknown&lt;br /&gt;
| 1.8V&lt;br /&gt;
| See pin 1, connected to the A10X next to pin 1&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
&amp;lt;/br&amp;gt;&lt;br /&gt;
== Mode Pin ==&lt;br /&gt;
&lt;br /&gt;
Pin 6 in the debug connector is a mode select pin. There are 4 known modes available.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Modes&lt;br /&gt;
! VMin&lt;br /&gt;
! VMax&lt;br /&gt;
! Function&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 0V&lt;br /&gt;
| 0.49V&lt;br /&gt;
| Disabled&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 0.51V&lt;br /&gt;
| 0.76V&lt;br /&gt;
| USB Device mode active&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 0.76V&lt;br /&gt;
| 0.99V&lt;br /&gt;
| Assert force_dfu&lt;br /&gt;
|- &lt;br /&gt;
! scope=row | 1.01V&lt;br /&gt;
| 1.8V&lt;br /&gt;
| Reset device&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
USB Device mode is active from 0.5-0.99V After 0.99V the device will enter a reset loop. Force_dfu is asserted with voltages above 0.76V, and will enter DFU on reboot. To trigger a reboot and enter DFU from the port alone without an external reboot requires first raising the voltage about 1.01V then dropping it no lower than 0.76V. The transition between each mode results in metastability for ±10mV from the transition point (0.50V, 0.75V, 1.00V) between modes.&lt;br /&gt;
&lt;br /&gt;
[[Category:Devices]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=J105aAP&amp;diff=98162</id>
		<title>J105aAP</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=J105aAP&amp;diff=98162"/>
		<updated>2019-11-18T07:58:11Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Add some basic information about the hidden debug port&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:Apple TV 4K.png|thumb|131px|Apple TV 4K]]&lt;br /&gt;
The Apple TV 4K starts at $179 for 32GB of storage, and $199 for 64GB. It’s firmware identifier is AppleTV6,2. It is capable of playing 4K content.&lt;br /&gt;
&lt;br /&gt;
The Apple TV 4K was announced on 12th September 2017 and released on 22nd September 2017.&lt;br /&gt;
&lt;br /&gt;
== Application processor ==&lt;br /&gt;
The Apple TV 4K makes use of the [[T8011|Apple A10X]] processor.&lt;br /&gt;
&lt;br /&gt;
== Debug Port ==&lt;br /&gt;
&lt;br /&gt;
[[File:AppleTV4K_Debug_Ethernet.jpg|thumb|right]]&lt;br /&gt;
&lt;br /&gt;
Hidden behind a small trapdoor in the back of the Ethernet port is a debug port that includes USB access.&lt;br /&gt;
&lt;br /&gt;
Without a custom cable the easiest method of access to the port is to solder directly onto the pins. Care should be taken with the test points that are near the port as they also serve as the top of the via that connects the debug port to the rest of the Apple TV. USB access is disabled in tvOS due to us not knowing how to instruct the AppleTV that a device is currently connected, but this limitation does not exist in DFU or Recovery. While the Reset pin pulls force dfu high, secureROM requires that it detects a USB connection. At this time it does not allow entry into DFU. &lt;br /&gt;
&lt;br /&gt;
[[File:AppleTV4K_Debug_Internal.jpg|thumb|left]]&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+ Pinout&lt;br /&gt;
! Pin&lt;br /&gt;
! Name&lt;br /&gt;
! Max Voltage&lt;br /&gt;
! Notes&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 1&lt;br /&gt;
| Unknown &lt;br /&gt;
| 1.8V&lt;br /&gt;
| Purpose of the pin is unknown but it is connected to the A10X near the USB pins&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 2&lt;br /&gt;
| ACC_PWR &lt;br /&gt;
| 3.3V&lt;br /&gt;
| Pin is connected to a power switch, more exploration is required to see if it is capable of outputting 5V&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 3&lt;br /&gt;
| USB_DM &lt;br /&gt;
| 3.3V&lt;br /&gt;
| Pin operates at USB logic levels.&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 4&lt;br /&gt;
| USB_DP &lt;br /&gt;
| 3.3V&lt;br /&gt;
| Pin operates at USB logic levels.&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 5&lt;br /&gt;
| GND &lt;br /&gt;
| 0V&lt;br /&gt;
| Pin is connected directly to the boards ground plane&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 6&lt;br /&gt;
| Reset &lt;br /&gt;
| 1.8V&lt;br /&gt;
| Pin is connected to a buffer which appears to be 3.3V tolerant, but caution is advised. Pin also triggers the force dfu pin to be pulled high for 20ms&lt;br /&gt;
|-&lt;br /&gt;
! scope=row | 7&lt;br /&gt;
| Unknown&lt;br /&gt;
| 1.8V&lt;br /&gt;
| See pin 1, connected to the A10X next to pin 1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:Devices]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_Debug_Internal.jpg&amp;diff=98161</id>
		<title>File:AppleTV4K Debug Internal.jpg</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_Debug_Internal.jpg&amp;diff=98161"/>
		<updated>2019-11-18T07:08:21Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: /* Summary */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Internal view of where the pins connect&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_Debug_Internal.jpg&amp;diff=98160</id>
		<title>File:AppleTV4K Debug Internal.jpg</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_Debug_Internal.jpg&amp;diff=98160"/>
		<updated>2019-11-18T07:08:07Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Internal view of where the pins connect internally&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
Internal view of where the pins connect internally&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_Debug_Ethernet.jpg&amp;diff=98159</id>
		<title>File:AppleTV4K Debug Ethernet.jpg</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_Debug_Ethernet.jpg&amp;diff=98159"/>
		<updated>2019-11-18T07:01:26Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: External View of debug port&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
External View of debug port&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_ExternalDebug.jpg&amp;diff=98158</id>
		<title>File:AppleTV4K ExternalDebug.jpg</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=File:AppleTV4K_ExternalDebug.jpg&amp;diff=98158"/>
		<updated>2019-11-18T06:54:12Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: External view of debug port&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary ==&lt;br /&gt;
External view of debug port&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=List_of_baseband_commands&amp;diff=18100</id>
		<title>List of baseband commands</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=List_of_baseband_commands&amp;diff=18100"/>
		<updated>2011-05-16T16:38:58Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Neither of those were crashes, but rather ways to turn the baseband off&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For instructions how to use these commands, please see [[Baseband Commands]].&lt;br /&gt;
&lt;br /&gt;
List compiled by [[User:keps|keps]].&lt;br /&gt;
&lt;br /&gt;
==Other==&lt;br /&gt;
*ASSIGN (Present in [[2.10.04]])&lt;br /&gt;
* AT&lt;br /&gt;
* AT@ (Present in [[2.10.04]])&lt;br /&gt;
* ATD &lt;br /&gt;
* AT&amp;amp;H (Show more baseband commands)&lt;br /&gt;
* AT&amp;amp;V (Display the profiles in the baseband)&lt;br /&gt;
* ATE (Present in [[2.10.04]])&lt;br /&gt;
* ATH (Present in [[2.10.04]])&lt;br /&gt;
* ATZ (Present in [[2.10.04]])&lt;br /&gt;
&lt;br /&gt;
==AT+A... (present in [[2.10.04]])==&lt;br /&gt;
* AT+ATA&lt;br /&gt;
* AT+ATAC&lt;br /&gt;
* AT+ATAD &lt;br /&gt;
* AT+ATAE &lt;br /&gt;
* AT+ATAF &lt;br /&gt;
* AT+ATAH &lt;br /&gt;
* AT+ATAK  &lt;br /&gt;
* AT+ATAS &lt;br /&gt;
* AT+ATAV &lt;br /&gt;
* AT+ATAW  &lt;br /&gt;
* AT+ATAY &lt;br /&gt;
* AT+ATBQ &lt;br /&gt;
* AT+ATD  &lt;br /&gt;
* AT+ATDL &lt;br /&gt;
* AT+ATDPBK &lt;br /&gt;
* AT+ATE  &lt;br /&gt;
* AT+ATH &lt;br /&gt;
* AT+ATI  &lt;br /&gt;
* AT+ATL &lt;br /&gt;
* AT+ATM &lt;br /&gt;
* AT+ATO &lt;br /&gt;
* AT+ATON &lt;br /&gt;
* AT+ATP  &lt;br /&gt;
* AT+ATQ  &lt;br /&gt;
* AT+ATSN  &lt;br /&gt;
* AT+ATT &lt;br /&gt;
* AT+ATV  &lt;br /&gt;
* AT+ATX &lt;br /&gt;
* AT+ATZ  &lt;br /&gt;
&lt;br /&gt;
==AT+B...==&lt;br /&gt;
* AT+BINP&lt;br /&gt;
* AT+BLDN&lt;br /&gt;
* AT+BRSF&lt;br /&gt;
* AT+BVRA&lt;br /&gt;
&lt;br /&gt;
==AT+C...==&lt;br /&gt;
* AT+CACM&lt;br /&gt;
* AT+CAEMLPP&lt;br /&gt;
* AT+CALA&lt;br /&gt;
* AT+CALD&lt;br /&gt;
* AT+CALM&lt;br /&gt;
* AT+CAMM (present in [[2.10.04]])&lt;br /&gt;
* AT+CAOC&lt;br /&gt;
* AT+CBC&lt;br /&gt;
* AT+CBST&lt;br /&gt;
* AT+CCFC&lt;br /&gt;
* AT+CCID&lt;br /&gt;
* AT+CCLK&lt;br /&gt;
* AT+CCUG&lt;br /&gt;
* AT+CCWA&lt;br /&gt;
* AT+CCWE&lt;br /&gt;
* AT+CDIS (present in [[2.10.04]])&lt;br /&gt;
* AT+CEER&lt;br /&gt;
* AT+CFUN&lt;br /&gt;
* AT+CGACT&lt;br /&gt;
* AT+CGANS&lt;br /&gt;
* AT+CGATT&lt;br /&gt;
* AT+CGAUTO&lt;br /&gt;
* AT+CGCLASS&lt;br /&gt;
* AT+CGCMOD&lt;br /&gt;
* AT+CGDATA&lt;br /&gt;
* AT+CGDCONT&lt;br /&gt;
* AT+CGDSCONT&lt;br /&gt;
* AT+CGED&lt;br /&gt;
* AT+CGEQMIN&lt;br /&gt;
* AT+CGEQNEG&lt;br /&gt;
* AT+CGEQREQ&lt;br /&gt;
* AT+CGEREP&lt;br /&gt;
* AT+CGMI&lt;br /&gt;
* AT+CGMM&lt;br /&gt;
* AT+CGMR&lt;br /&gt;
* AT+CGPADDR&lt;br /&gt;
* AT+CGQMIN&lt;br /&gt;
* AT+CGQREQ&lt;br /&gt;
* AT+CGREG&lt;br /&gt;
* AT+CGSMS&lt;br /&gt;
* AT+CGSN&lt;br /&gt;
* AT+CGTFT&lt;br /&gt;
* AT+CHLD&lt;br /&gt;
* AT+CHUP&lt;br /&gt;
* AT+CIMI&lt;br /&gt;
* AT+CIND&lt;br /&gt;
* AT+CKPD (Present in [[2.10.04]])&lt;br /&gt;
* AT+CLAC (Show some baseband commands.)&lt;br /&gt;
* AT+CLAN (Present in [[5.12.01]])&lt;br /&gt;
* AT+CLCC&lt;br /&gt;
* AT+CLCK (Traditional unlock method.)&lt;br /&gt;
* AT+CLIP&lt;br /&gt;
* AT+CLIR&lt;br /&gt;
* AT+CLVL&lt;br /&gt;
* AT+CMDR (Present in [[2.10.04]])&lt;br /&gt;
* AT+CMDW (Present in [[2.10.04]])&lt;br /&gt;
* AT+CMEC&lt;br /&gt;
* AT+CMEE&lt;br /&gt;
* AT+CMER&lt;br /&gt;
* AT+CMGC&lt;br /&gt;
* AT+CMGD&lt;br /&gt;
* AT+CMGF (SMS operating mode.)&lt;br /&gt;
* AT+CMGL&lt;br /&gt;
* AT+CMGR&lt;br /&gt;
* AT+CMGS (Sends SMS message.)&lt;br /&gt;
* AT+CMGW&lt;br /&gt;
* AT+CMMS&lt;br /&gt;
* AT+CMOD&lt;br /&gt;
* AT+CMSS&lt;br /&gt;
* AT+CMUT&lt;br /&gt;
* AT+CMUX&lt;br /&gt;
* AT+CNAP&lt;br /&gt;
* AT+CNMA&lt;br /&gt;
* AT+CNMI&lt;br /&gt;
* AT+CNUM&lt;br /&gt;
* AT+COLP&lt;br /&gt;
* AT+COLR&lt;br /&gt;
* AT+COPN&lt;br /&gt;
* AT+COPS&lt;br /&gt;
* AT+CPAS&lt;br /&gt;
* AT+CPBF&lt;br /&gt;
* AT+CPBR&lt;br /&gt;
* AT+CPBS&lt;br /&gt;
* AT+CPBW&lt;br /&gt;
* AT+CPGR (Present in [[2.10.04]])&lt;br /&gt;
* AT+CPIN&lt;br /&gt;
* AT+CPLS&lt;br /&gt;
* AT+CPMS (Present in [[2.10.04]])&lt;br /&gt;
* AT+CPOL&lt;br /&gt;
* AT+CPUC&lt;br /&gt;
* AT+CPWAC (Present in [[2.10.04]])&lt;br /&gt;
* AT+CPWD&lt;br /&gt;
* AT+CPWROFF&lt;br /&gt;
* AT+CR&lt;br /&gt;
* AT+CRC&lt;br /&gt;
* AT+CREG&lt;br /&gt;
* AT+CRES&lt;br /&gt;
* AT+CRLP&lt;br /&gt;
* AT+CRSL&lt;br /&gt;
* AT+CRSM&lt;br /&gt;
* AT+CSAS&lt;br /&gt;
* AT+CSCA&lt;br /&gt;
* AT+CSCB&lt;br /&gt;
* AT+CSCC (Present in [[2.10.04]])&lt;br /&gt;
* AT+CSCS&lt;br /&gt;
* AT+CSDH&lt;br /&gt;
* AT+CSGT&lt;br /&gt;
* AT+CSIM&lt;br /&gt;
* AT+CSMP&lt;br /&gt;
* AT+CSMS&lt;br /&gt;
* AT+CSQ&lt;br /&gt;
* AT+CSSN&lt;br /&gt;
* AT+CSTA&lt;br /&gt;
* AT+CSVM&lt;br /&gt;
* AT+CTFR&lt;br /&gt;
* AT+CTZR&lt;br /&gt;
* AT+CTZU&lt;br /&gt;
* AT+CUSD&lt;br /&gt;
* AT+CUUS1 (Present in [[5.12.01]])&lt;br /&gt;
* AT+CXAR (Present in [[2.10.04]])&lt;br /&gt;
* AT+CXDR (Present in [[2.10.04]])&lt;br /&gt;
* AT+CXDW (Present in [[2.10.04]])&lt;br /&gt;
* AT+CXRR (Present in [[2.10.04]])&lt;br /&gt;
&lt;br /&gt;
==AT+D... (Present in [[2.10.04]])==&lt;br /&gt;
* AT+DDLD &lt;br /&gt;
* AT+DDLE &lt;br /&gt;
* AT+DDLI&lt;br /&gt;
* AT+DDLL &lt;br /&gt;
* AT+DDLR &lt;br /&gt;
* AT+DDLS &lt;br /&gt;
* AT+DDLU&lt;br /&gt;
* AT+DDLW  &lt;br /&gt;
* AT+DS &lt;br /&gt;
&lt;br /&gt;
==AT+E... (Present in [[2.10.04]])==&lt;br /&gt;
* AT+ETBM&lt;br /&gt;
&lt;br /&gt;
==AT+F...==&lt;br /&gt;
* AT+FAA&lt;br /&gt;
* AT+FAP&lt;br /&gt;
* AT+FBO&lt;br /&gt;
* AT+FBS&lt;br /&gt;
* AT+FBU&lt;br /&gt;
* AT+FCC&lt;br /&gt;
* AT+FCLASS&lt;br /&gt;
* AT+FCQ&lt;br /&gt;
* AT+FCR&lt;br /&gt;
* AT+FCS&lt;br /&gt;
* AT+FCT&lt;br /&gt;
* AT+FDR&lt;br /&gt;
* AT+FDT&lt;br /&gt;
* AT+FEA&lt;br /&gt;
* AT+FFC&lt;br /&gt;
* AT+FFD&lt;br /&gt;
* AT+FHS&lt;br /&gt;
* AT+FIE&lt;br /&gt;
* AT+FIP&lt;br /&gt;
* AT+FIS&lt;br /&gt;
* AT+FIT&lt;br /&gt;
* AT+FKS&lt;br /&gt;
* AT+FLI&lt;br /&gt;
* AT+FLO&lt;br /&gt;
* AT+FLP&lt;br /&gt;
* AT+FMR (Present in [[5.12.01]])&lt;br /&gt;
* AT+FMS&lt;br /&gt;
* AT+FND&lt;br /&gt;
* AT+FNR&lt;br /&gt;
* [[AT+FNS]]&lt;br /&gt;
** (exploitable crash in [[4.26.08]])&lt;br /&gt;
* AT+FPA&lt;br /&gt;
* AT+FPI&lt;br /&gt;
* AT+FPP&lt;br /&gt;
* AT+FPS&lt;br /&gt;
* AT+FPW&lt;br /&gt;
* AT+FRQ&lt;br /&gt;
* AT+FRY&lt;br /&gt;
* AT+FSA&lt;br /&gt;
* AT+FSP&lt;br /&gt;
&lt;br /&gt;
==AT+G...==&lt;br /&gt;
* AT+GCAP&lt;br /&gt;
* AT+GMI&lt;br /&gt;
* AT+GMM&lt;br /&gt;
* AT+GMR&lt;br /&gt;
* AT+GSN&lt;br /&gt;
&lt;br /&gt;
==AT+I...==&lt;br /&gt;
* AT+ICF&lt;br /&gt;
* AT+IFC&lt;br /&gt;
* AT+IPR&lt;br /&gt;
&lt;br /&gt;
==AT+L... (Present in [[2.10.04]])==&lt;br /&gt;
* AT+LAST_CMD&lt;br /&gt;
* AT+LEGACY&lt;br /&gt;
&lt;br /&gt;
==AT+N...==&lt;br /&gt;
* AT+NREC&lt;br /&gt;
&lt;br /&gt;
==AT+P... (Present in [[2.10.04]])==&lt;br /&gt;
* AT+PDU_INFO&lt;br /&gt;
&lt;br /&gt;
==AT+S...==&lt;br /&gt;
* AT+SBEG (Present in [[2.10.04]])&lt;br /&gt;
* AT+SMSSRESUL (Present in [[5.12.01]])&lt;br /&gt;
* AT+STKENV&lt;br /&gt;
* AT+STKLBR&lt;br /&gt;
* AT+STKPRO&lt;br /&gt;
* [[AT+stkprof|AT+STKPROF]]&lt;br /&gt;
** (exploitable crash in [[2.28.00]])&lt;br /&gt;
* AT+STKTR&lt;br /&gt;
&lt;br /&gt;
==AT+T...==&lt;br /&gt;
* AT+TRACE&lt;br /&gt;
&lt;br /&gt;
==AT+U... (Present in [[2.10.04]])==&lt;br /&gt;
* AT+UNKNOWN &lt;br /&gt;
&lt;br /&gt;
==AT+V...==&lt;br /&gt;
* AT+VGM&lt;br /&gt;
* AT+VGR (Present in [[5.12.01]])&lt;br /&gt;
* AT+VGS&lt;br /&gt;
* AT+VGT (Present in [[5.12.01]])&lt;br /&gt;
* AT+VTD&lt;br /&gt;
* AT+VTS&lt;br /&gt;
&lt;br /&gt;
==AT+W... (Present in [[5.12.01]])==&lt;br /&gt;
* AT+WS46&lt;br /&gt;
&lt;br /&gt;
==AT+X...==&lt;br /&gt;
* AT+XADDTRACE&lt;br /&gt;
* AT+XALS&lt;br /&gt;
* AT+XALSBLOCK&lt;br /&gt;
* AT+XAPOXI&lt;br /&gt;
* [[AT+XAPP Vulnerability|AT+XAPP]]&lt;br /&gt;
** (exploitable crash in [[5.13.04]] with command &amp;quot;AT+XAPP=&amp;quot;kepskepskepskepskepskepskepskeps&amp;quot;)&lt;br /&gt;
* AT+XBANDSEL&lt;br /&gt;
* AT+XCALLREFUSE&lt;br /&gt;
* AT+XCALLSTAT&lt;br /&gt;
* AT+XCAOC&lt;br /&gt;
* AT+XCBS&lt;br /&gt;
* AT+XAT+CCBS&lt;br /&gt;
* AT+XCEER&lt;br /&gt;
* AT+XCELLINFO&lt;br /&gt;
* AT+XCFC&lt;br /&gt;
* AT+XCGCLASS&lt;br /&gt;
* AT+XCGEDPAGE (Present in [[5.12.01]])&lt;br /&gt;
* AT+XCHNSIM&lt;br /&gt;
* AT+XCIND&lt;br /&gt;
* AT+XCIPH&lt;br /&gt;
* AT+XCONFIG&lt;br /&gt;
* AT+XCOPS&lt;br /&gt;
* AT+XCRSM&lt;br /&gt;
* AT+XCSIM&lt;br /&gt;
* AT+XCSP&lt;br /&gt;
* AT+XCSPAGING&lt;br /&gt;
* AT+XCSSMS&lt;br /&gt;
* AT+XCTMDR&lt;br /&gt;
* AT+XCTMS&lt;br /&gt;
* AT+XDATACHANNEL (Present in [[5.12.01]])&lt;br /&gt;
* AT+XDEV&lt;br /&gt;
* AT+XDEVICE&lt;br /&gt;
* AT+XDIAG&lt;br /&gt;
* AT+XDNOABORT&lt;br /&gt;
* AT+XDNS&lt;br /&gt;
* AT+XDRV&lt;br /&gt;
* AT+XDTMF&lt;br /&gt;
* AT+XEMC (Present in [[5.12.01]])&lt;br /&gt;
* [[AT+XEMN Heap Overflow|AT+XEMN]] (Present in [[5.11.07]])&lt;br /&gt;
** (exploitable crash in [[5.11.07]] with lots of zeroes)&lt;br /&gt;
* AT+XEONS&lt;br /&gt;
* AT+XETFT&lt;br /&gt;
* AT+XFDOR (Present in [[5.12.01]])&lt;br /&gt;
* AT+XFDORT (Present in [[5.12.01]])&lt;br /&gt;
* AT+XGAUTH&lt;br /&gt;
* AT+XGCNTRD&lt;br /&gt;
* AT+XGCNTSET&lt;br /&gt;
* AT+XGENDATA (Displays some information about the baseband.)&lt;br /&gt;
* AT+XGENDATE (Present in [[02.10.04]])&lt;br /&gt;
* AT+XGPRSERRMAP (Present in [[5.12.01]])&lt;br /&gt;
* AT+XHANDSFREE&lt;br /&gt;
* AT+XHOMEZR&lt;br /&gt;
* AT+XHSDUPA (Present in [[5.12.01]])&lt;br /&gt;
* AT+XIA (Present in [[5.12.01]])&lt;br /&gt;
* AT+XIMS&lt;br /&gt;
* AT+XL1SET&lt;br /&gt;
* AT+XLCAPS&lt;br /&gt;
* AT+XLCK&lt;br /&gt;
* AT+XLGASSIST (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGCPL (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGINFO (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGLOGLEV (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGMODE (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGMOTIONTYPE (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGNAV (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGNMEA (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGNVRAM (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGPOS (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGSENSORDATA (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGTEST (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLGTIME (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLIN&lt;br /&gt;
* AT+XLOCK (Wildcard unlock. Present in [[5.12.01]])&lt;br /&gt;
* [[AT+XLOG Vulnerability|AT+XLOG]]&lt;br /&gt;
** (exploitable crash in [[4.26.08]] with command &amp;quot;AT+XLOG=1,&amp;quot;kepskepskepskepskepskepskepskepskepskepskepskeps&amp;quot;)&lt;br /&gt;
* AT+XLOOPBACK&lt;br /&gt;
* AT+XLQOS&lt;br /&gt;
* AT+XLRMT&lt;br /&gt;
* AT+XLRSUPL (Present in [[5.12.01]])&lt;br /&gt;
* AT+XLRTA&lt;br /&gt;
* AT+XLRV&lt;br /&gt;
* AT+XLRWAP (Present in [[2.10.04]])&lt;br /&gt;
* AT+XLSR&lt;br /&gt;
* AT+XLSRSTOP (Present in [[5.12.01]])&lt;br /&gt;
* AT+XMAGETBLOCK&lt;br /&gt;
* AT+XMAGETKEY&lt;br /&gt;
* AT+XMER&lt;br /&gt;
* AT+XMSG&lt;br /&gt;
* AT+XMULTISLOT&lt;br /&gt;
* AT+XMUX&lt;br /&gt;
* AT+XNMI&lt;br /&gt;
* [[AT+XNONCE]] (Random string generated on bootup. Present in [[5.12.01]].)&lt;br /&gt;
* AT+XPIN&lt;br /&gt;
* AT+XPINCNT&lt;br /&gt;
* AT+XPOW&lt;br /&gt;
* AT+XPPP&lt;br /&gt;
* AT+XPROGRESS&lt;br /&gt;
* AT+XQNEG&lt;br /&gt;
* AT+XRAT&lt;br /&gt;
* AT+XREDIAL&lt;br /&gt;
* AT+XREG&lt;br /&gt;
* AT+XREL&lt;br /&gt;
* AT+XRFS&lt;br /&gt;
* AT+XRLCSET&lt;br /&gt;
* AT+XRRSET&lt;br /&gt;
* AT+XSCELLLOCK (Present in [[5.12.01]])&lt;br /&gt;
* AT+XSECSTATE&lt;br /&gt;
* AT+XSELFRXSTAT&lt;br /&gt;
* AT+XSERVICE&lt;br /&gt;
* AT+XSIMCHG&lt;br /&gt;
* AT+XSIMLG&lt;br /&gt;
* AT+XSIMLOOPBACK&lt;br /&gt;
* AT+XSIMSIMUL (Present in [[2.10.04]])&lt;br /&gt;
* AT+XSIMSTATE (Reports lock state.)&lt;br /&gt;
* AT+XSIMVALID&lt;br /&gt;
* AT+XSIO&lt;br /&gt;
* AT+XSLN&lt;br /&gt;
* AT+XSMS&lt;br /&gt;
* AT+XSTK&lt;br /&gt;
* AT+XSTRESSSIM&lt;br /&gt;
* AT+XSVM&lt;br /&gt;
* AT+XSYSERR (Present in [[5.12.01]])&lt;br /&gt;
* AT+XTDEV&lt;br /&gt;
* AT+XTERM (Present in [[5.12.01]])&lt;br /&gt;
* AT+XTESM&lt;br /&gt;
* AT+XTEST (Present in [[5.12.01]])&lt;br /&gt;
* AT+XTFILTER&lt;br /&gt;
* AT+XTHUMB&lt;br /&gt;
* AT+XTOS&lt;br /&gt;
* AT+XTRACECONFIG (Present in [[5.12.01]])&lt;br /&gt;
* AT+XTRACEIP&lt;br /&gt;
* AT+XTRACESYSTIME&lt;br /&gt;
* AT+XTRANSPORTMODE&lt;br /&gt;
* AT+XUBANDSEL (Present in [[5.12.01]])&lt;br /&gt;
* AT+XUICC (Present in [[5.12.01]])&lt;br /&gt;
* AT+XUSBFLASH&lt;br /&gt;
* AT+XVTS&lt;br /&gt;
&lt;br /&gt;
[[Category:Baseband]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:List_of_baseband_commands&amp;diff=18095</id>
		<title>Talk:List of baseband commands</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:List_of_baseband_commands&amp;diff=18095"/>
		<updated>2011-05-15T10:11:22Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: discussion on baseband commands&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Merge==&lt;br /&gt;
This is the third page with baseband commands. We now have:&lt;br /&gt;
*[[Baseband Commands]]&lt;br /&gt;
*[[AT Commands]]&lt;br /&gt;
*[[List of baseband commands]]&lt;br /&gt;
I started the [[AT Commands]] page for exactly this reason, but it was incomplete of course. But in any case I would recommend a merge of [[AT Commands]] and [[List of baseband commands]] at least. The only thing missing here is a description of each command with its parameters. I'll do the merge in a few days if nobody else is faster. --[[User:Http|http]] 20:50, 4 October 2010 (UTC)&lt;br /&gt;
:Done. :) --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 21:04, 4 October 2010 (UTC)&lt;br /&gt;
::Thanks [[User:Dialexio|Dialexio]]. Currently I only have my iPhone to edit and you know how easy copy&amp;amp;pasting is there.--[[User:Http|http]] 21:41, 4 October 2010 (UTC)&lt;br /&gt;
==More infos==&lt;br /&gt;
We need to look at the old pages about the sim tool kit [http://chickenenchiladagrilledstuftburrito.info/u.htm] and this list need's more command's from [http://code.google.com/p/iphone-elite/wiki/UndocumentedATcommands] --[[User:Liamchat|liamchat]] 21:13, 4 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
I think that AT+CFUN and AT+CPWROFF should not have a note on them stating non-exploitable crash, they are not crashes but are methods to turn the baseband device off --[[User:Lilstevie|Lilstevie]] 10:11, 15 May 2011 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:IBoot_(Bootloader)&amp;diff=10982</id>
		<title>Talk:IBoot (Bootloader)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:IBoot_(Bootloader)&amp;diff=10982"/>
		<updated>2010-10-22T07:19:10Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Commands used as an exploit vector  ==&lt;br /&gt;
the armv7 go and stop do not have vectors you just point at the kernelcache and boot --[[User:Liamchat|liamchat]] 21:23, 29 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
the usb_control_msg(0x21, 2) Exploit has a vector and there may be lots of tiny write zones in iboot --[[User:Liamchat|liamchat]] 21:23, 29 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Article name ==&lt;br /&gt;
&lt;br /&gt;
I'm not a big fan of the new name, so I'd like to propose a name change to &amp;quot;iBoot (Stage 2 Bootloader).&amp;quot; Would this be fine with others? --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 00:29, 21 October 2010 (UTC)&lt;br /&gt;
:For me it was just important to separate the two iBoot's. That was very confusing. For me your suggestion would be ok. --[[User:Http|http]] 06:19, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:Sorry for making such a change without discussing first. I was excited about the fact that disambiguation pages work now and wanted these two things to separate long ago. [[Cydia Application]] is also not the ideal name. I'll discuss the next time first. --[[User:Http|http]] 06:34, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::It's fine. :) &amp;lt;del&amp;gt;I'll get to changing it now.&amp;lt;/del&amp;gt; Actually... would &amp;quot;iBoot (bootloader)&amp;quot; be a better name? The name probably doesn't need to be specific about which bootloader it is; it's mentioned in the article. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 19:38, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:::I would use uppercase for the Bootloader as it is a title. Not sure though. And yes, you can leave &amp;quot;Stage 2&amp;quot; away if there only exists one bootloader. But isn't the [[Bootrom]] the &amp;quot;Stage 1 Bootloader&amp;quot;? In that case I wouldn't leave it away. --[[User:Http|http]] 22:21, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::::The stage 1 bootloader is actually [[LLB]]. However, I still don't believe that the &amp;quot;Stage 2&amp;quot; part should be included in parentheses; putting &amp;quot;(bootloader)&amp;quot; or &amp;quot;(Bootloader)&amp;quot; is sufficient enough to differentiate between this article and the bootrom's article. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 23:08, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:::::Ok [[LLB]]. Does [[LLB]] also have versions that begin with iBoot? Or is it included in the Stage 2 part? --[[User:Http|http]] 23:17, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::::::LLB's version does indeed begin with &amp;quot;iBoot.&amp;quot; It's the same version number as iBEC/iBoot/iBSS from the same firmware. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 23:40, 21 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:::::::The Bootrom, LLB, iBEC, iBSS and iBoot all have the tag iBoot in their version numbers as they are part of the iBoot family, but iBoot(2nd stage bootloader) is the only one internally referred to as iBoot --[[User:Lilstevie|Lilstevie]] 07:19, 22 October 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=QuickPwn&amp;diff=10579</id>
		<title>QuickPwn</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=QuickPwn&amp;diff=10579"/>
		<updated>2010-10-15T11:30:15Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Undo revision 10575 by Whiteshinyapple (Talk) why was this page blanked&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:QuickPwn Mac.png|thumb]]&lt;br /&gt;
QuickPwn was a program from the [[iPhone Dev Team]] that allowed people to quickly [[jailbreak]] their devices. Initially, it was only available as a Windows CLI tool, but poorlad created a GUI shortly afterwards. Later, a Mac OS X GUI was also released.&lt;br /&gt;
&lt;br /&gt;
The name was exploited (as &amp;quot;QuickPWN&amp;quot;) by quickpwn.com, so the decision was made to discontinue QuickPwn in favor of [[redsn0w]].&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Limera1n&amp;diff=10492</id>
		<title>Talk:Limera1n</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Limera1n&amp;diff=10492"/>
		<updated>2010-10-12T07:29:44Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Drop size on image == &lt;br /&gt;
Has anyone else noticed that on the picture, the lime raindrop us bigger than the rest of them? Could be nothing but could also mean that [[User:Geohot|geohot]] has worked out [[SHAtter]] and use it on the three A4 devices that are there and just used the photos app for the [[N88ap|3GS]].&lt;br /&gt;
Also (if it's real) why is [[User:Geohot|Geohots]]  exploit not used and keep [[SHAtter]] for when there are more A4 devices around? --[[User:Shengis14|Shengis14]] 07:16, 9 October 2010 (UTC)&lt;br /&gt;
:I did see that and assume it's just the same image everywhere, but on retina display it's just smaller due to higher resolution. --[[User:Http|http]] 09:00, 9 October 2010 (UTC)&lt;br /&gt;
::I also saw that and would ask you to look at the image again. iPod Touch 4g and iPhone 4, both retina, have smaller... This could be because [[geohot]] has a problem with the program as he didn't create a @2x.png image... I believe this is a true jailbreK. [[User:Balloonhead66|Balloonhead66]] 13:57, 9 October 2010 (UTC)&lt;br /&gt;
:::In the dump, I found the lime drop and it is a 320x480 image. Therfore, when you jailbreak a retina device with a 320x480 it shrinks the image because there is no lime@2x.png file...&lt;br /&gt;
&lt;br /&gt;
== Misc. ==&lt;br /&gt;
I think some more info may be needed. What is some background on it? I thought Limera1n was a fake from the 3.x days? --[[User:OMEGA RAZER|OMEGA RAZER]] 22:09, 8 October 2010 (UTC&lt;br /&gt;
:It was never fake see [http://theiphonewiki.com/limera1n http://theiphonewiki.com/limera1n] (a cached copy). --[[User:GreySyntax|GreySyntax]] 22:45, 8 October 2010 (UTC)&lt;br /&gt;
::Thanks for the clarification. Not sure where I heard that. --[[User:OMEGA RAZER|OMEGA RAZER]] 23:09, 8 October 2010 (UTC)&lt;br /&gt;
Geohot made the web page when 3.1.3 come out but he said it used a bootrom exploit for untetherdness that he was saving for the iPhone 4 --[[User:Liamchat|liamchat]] 22:53, 8 October 2010 (UTC)&lt;br /&gt;
Anything else we should mention? :P --[[User:Dra1nerdrake|dra1nerdrake]] 23:14, 8 October 2010 (UTC)&lt;br /&gt;
:Why the insane secrecy of it? I'm not deep in the scene but this is the first I'm hearing more than the name lol. --[[User:OMEGA RAZER|OMEGA RAZER]] 23:18, 8 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Release ==&lt;br /&gt;
&lt;br /&gt;
I thought geohot had no plans to release it... [[User:Balloonhead66|Balloonhead66]] 23:22, 8 October 2010 (UTC)&lt;br /&gt;
:Correct. Read the controversy section of this page. It should answer as to why the sudden change in heart. ~Drake&lt;br /&gt;
&lt;br /&gt;
== SIGN YOUR COMMENTS ON THE TALK PAGE ==&lt;br /&gt;
Please press the button on top of the exit box or type &amp;lt;nowiki&amp;gt;~~~~&amp;lt;/nowiki&amp;gt; manually. This will give you the basic signature. It's also acceptable to just identify yourself. Just make sure we know who you are. ;P ~Drake&lt;br /&gt;
&lt;br /&gt;
== Latest edit to [[Limera1n]] ==&lt;br /&gt;
&lt;br /&gt;
How does it look like a tethered? -- Balloonhead66|23:34, October 8, 2010 (UTC)&lt;br /&gt;
:They're all plugged in with USB cables. --[[User:OMEGA RAZER|OMEGA RAZER]] 23:35, 8 October 2010 (UTC)&lt;br /&gt;
::They could just be charging and he is in  the photos app -- Balloonhead66|23:41, October 8, 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Who is John Galt? ==&lt;br /&gt;
&lt;br /&gt;
Look at the HTML source of the page. Is this comment new? [[User:Angelo|Angelo]] 23:42, 8 October 2010 (UTC)&lt;br /&gt;
:Yep. I've looked at the source of this page before and after this update. The John Galt is probably meant to throw us off. Geohot does that. :P But, yes, it's new. ~Drake&lt;br /&gt;
::Where did you see that? [[User:Balloonhead66|Balloonhead66]] 23:50, 8 October 2010 (UTC)&lt;br /&gt;
:::Type in Firefox URL bar: view-source:http://limera1n.com/ [[User:Angelo|Angelo]] 23:47, 8 October 2010 (UTC)&lt;br /&gt;
::::Or google chrome for that matter :D .  Anyway, I thought you meant the source of this page or the [[Limera1n]] page, not the website... *stupid* Thanks for explaining that! [[User:Balloonhead66|Balloonhead66]] 23:50, 8 October 2010 (UTC)&lt;br /&gt;
:::::[http://en.wikipedia.org/wiki/John_Galt Who is John Galt] Kind of funny actually when you read it and what's going on right now --[[User:alpineflip|alpineflip]]&lt;br /&gt;
:::::: yes I see why &amp;quot;learns that all of the stories have an element of truth to them.&amp;quot; maybe it will ra1n again but not today --[[User:Liamchat|liamchat]] 00:35, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Explanation ==&lt;br /&gt;
&lt;br /&gt;
So, I'm sure most, if not all, of you are confused. This Limera1n is nothing more than a plot by geohot to get the chronic dev team to incorporate the exploit used in limera1n into greenpois0n. This is not plausible because the exploit in limera1n is a bootrom level exploit, which can be used to make a jailbreak (albeit [[tethered]]) on its own. To make greenpois0n untethered, chronic dev has used a tweak by comex (in userland) to patch the kernel. The exploit in Limera1n can be used at a later date to make another untethered jailbreak, but it's better to leave the lower level exploits until later, after all, either way, it produces the same affect. To implement the limera1n exploit into greenpois0n, they'd have to rewrite the entire jailbreak, which would offset the release. This should clear up confusion. ~Drake&lt;br /&gt;
&lt;br /&gt;
I reckon it was the iphone dev teams fault if they just had to release spirit after the iphone 4 was released there would be no drama because the ipod touch 4 would hav been jailbroken via star. --[[User:Robinhood|robinhood]] &lt;br /&gt;
&lt;br /&gt;
I think Geohot told someone about his exploit and apple attempted to patch it in a4 bootrom [http://mobile.twitter.com/musclenerd/status/26801617164] --[[User:Liamchat|liamchat]] 01:54, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
===UPDATE:===&lt;br /&gt;
A [http://twitter.com/#!/p0sixninja/status/26799962302 recent tweet] from iPhone hacker p0sixninja has just confirmed that the date WILL NOT be changed. If they can implement geohot's exploit before 10/10, they will use that. If they can't they won't. --[[User:Dra1nerdrake|dra1nerdrake]] 00:53, 9 October 2010 (UTC)&lt;br /&gt;
: This has nothing to-do with Limera1n. -- [[User:Shorty|Shorty]] 01:06, 9 October 2010 (UTC)&lt;br /&gt;
::It does. If they can integrate it into GP then there's not going to be a Limera1n. If they can't in time then there will be two jailbreaks released... --[[User:OMEGA RAZER|OMEGA RAZER]] 01:11, 9 October 2010 (UTC)&lt;br /&gt;
::: This is a grand waste of a bootrom exploit though. ~Drake&lt;br /&gt;
:::: Geohot will not waste the exploit's used in limera1n but greenpois0n is using a bootrom exploit to inject a userland exploit that is odd --[[User:Liamchat|liamchat]] 01:20, 9 October 2010 (UTC)&lt;br /&gt;
:::::Yes it does limera1n will use an untetherd bootrom and iboot exploit but Why does Geohot not want us to use comex's kernel patch just for 4.1 then when 4.2 is out we can use shatter to reuse the iboot exploit --[[User:Liamchat|liamchat]] 01:20, 9 October 2010 (UTC)&lt;br /&gt;
::::::@[[User:Dra1nerdrake|dra1nerdrake]] - Sorry if I didn't make myself more clear, I was basically on about the first part, not the last bit. -- [[User:Shorty|Shorty]] 01:25, 9 October 2010 (UTC)&lt;br /&gt;
the exploit used by [[limera1n]] is a [[24kPwn]] like [[bootrom]] exploit and a [[IBoot]] exploit  ( read the second to last paragraph [http://posixninja.blogspot.com/2010/06/latest-progress-and-new-updates.html] ) --[[User:Liamchat|liamchat]] 12:55, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Image Taken Down ==&lt;br /&gt;
&lt;br /&gt;
I'm just speculating here. With all this controversy, I am on the edge of believing... Also, the image was taken down from the site... It gives you a bitly link that takes you back to the bitty link... --[[User:Balloonhead66|Balloonhead66]] 14:20, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:It is now very real [[greenpois0n]] will be cancelled (said by [[MuscleNerd]] [http://twitter.com/MuscleNerd/status/26860163077 Twitter Status]) and [[Limera1n]] will be used to jailbreak on 4.1 but [[wikipedia:Apple Inc.|Apple]] knows about both exploit's but [[Geohot]]'s has already being patched (patched in 4.2 beta 2 iboot [http://twitter.com/MuscleNerd/status/26860634891]) --[[User:Liamchat|liamchat]] 19:21, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::The exploit has not been patched though, but because of the code similarities geohot can tell his exploit will be patched anyway by iPad2,1 so he wants it to be used instead of wasted, greenpois0n and SHAtter should be kept as they will affect a larger crowd of iOS devices (assuming apple continue to use the A4 chip. --[[User:Shengis14|Shengis14]] 19:36, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:::[[Geohot]]'s exploit will be used in [[greenpois0n]] if it can be utilised in time. Otherwise both exploits will be burned. In relation to the image being taken down, it was proving to be too popular, so imageshack moved it. --[[User:Mushroom|Mushroom]]  19:47, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
::::I dont think so we said a lot about [[SHAtter]] (if apple patch one of the three BSS+Heap+Stack the exploit wont work) so it may be to late to protect [[SHAtter]] but [[Geohot]]'s exploit was fixed in [[iBoot]] so [[wikipedia:Apple Inc.|Apple]] knows 100% what his exploit is --[[User:Liamchat|liamchat]] 20:06, 9 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== He did it==&lt;br /&gt;
It's in the wild. Thoughts? ~Drake&lt;br /&gt;
:It's just BETA2 though... --[[User:Balloonhead66|Balloonhead66]] 22:28, 9 October 2010 (UTC)&lt;br /&gt;
::Has anyone being able to grab information about the exploit we need to delete shatter and name the new dfu exploit --[[User:Liamchat|liamchat]] 23:22, 9 October 2010 (UTC)&lt;br /&gt;
:::BETA2 naming means nothing. We need to delete SHAtter? Wtf? And also this exploit will either be named by Geohot or by it's technical name (like Environment Variable Overflow). [[User:Iemit737|Iemit737]] 00:03, 10 October 2010 (UTC)&lt;br /&gt;
::::I'd like to disassemble this and see what's in that exe of his. Anyone take a gander into this magical land of software yet? The payload's bound to be in there somewhere. ~Drake&lt;br /&gt;
:::::A dump has been released by ih8sn0w, see links. So much for the protection he put on it. It uses the ramdisk from purplera1n ( lulz). You'll need IDA Pro... [[User:Pwnd-v1|Pwnd-v1]] 13:12, 10 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Pwnage ==&lt;br /&gt;
&lt;br /&gt;
Does limera1n flash the NOR? I never managed to install a custom firmware after using limera1n.--[[User talk:Ryccardo|Ryccardo]], 11 October 2010 (UTC)&lt;br /&gt;
:Sign your posts, please. And, limera1n leaves your NOR untouched. All it does is patch the kernel (which is on your NAND). Theoretically, one might be able to restore to a custom firmware by jumping to a pwned iBSS or iBEC through the limera1n exploit and using that to trick the device into accepting the firmware, but I'm probably mistaken. --[[User:Dra1nerdrake|dra1nerdrake]] 19:28, 11 October 2010 (UTC)&lt;br /&gt;
:It leaves the NOR un-touched otherwise the signature checks would fail during boot. Hence the kernel exploit from [[User:comex|comex]] is used to patch the kernel at runtime. --[[User:GreySyntax|GreySyntax]] 19:49, 11 October 2010 (UTC)&lt;br /&gt;
::Thanks, [[http://twitter.com/iH8sn0w/statuses/27065535774 iH8Sn0w confirms.]] Sorry for the signature, I always forget to use that button. --[[User:Ryccardo|Ryccardo]] 20:43, 11 October 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Support ==&lt;br /&gt;
&lt;br /&gt;
I propose that appleTV should be removed from the supported list until further notice as while the exploit interacts with the bootrom, the ramdisk never executes to jailbreak the OS and leaves you in recovery mode (yet to establish if it is in a pwned state or not) --[[User:Lilstevie|Lilstevie]] 07:29, 12 October 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Malformed_CFF_Vulnerability&amp;diff=10491</id>
		<title>Malformed CFF Vulnerability</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Malformed_CFF_Vulnerability&amp;diff=10491"/>
		<updated>2010-10-12T07:26:48Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: IOService to IOSurface&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This vulnerability, along with the [[IOSurface Kernel Exploit]], was used in [[Star]]/[[JailbreakMe]] 2.0. It is a stack overflow in the handling of [[wikipedia:PostScript fonts#Compact Font Format|CFF]] opcodes. Contrary to popular belief, it is '''not''' a problem with the PDF parser, although the malformed font was placed in a PDF for exploitation.&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
[[User:Comex|comex]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Exploits]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=IREB&amp;diff=9921</id>
		<title>IREB</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=IREB&amp;diff=9921"/>
		<updated>2010-10-05T12:52:54Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:iREB_4.0.png|360px|right|iREB 4.0]] &lt;br /&gt;
{{DISPLAYTITLE:iREB}}&lt;br /&gt;
A program created by iH8sn0w, that is used for early-generation devices, which include:&lt;br /&gt;
*[[N82ap|iPhone 3G]]&lt;br /&gt;
*[[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom]])&lt;br /&gt;
&lt;br /&gt;
== What is iREB? ==&lt;br /&gt;
iREB is a GUI application that uses iTunnel. It uploads 3 pwned files, so that [[iTunes]] can accept custom [[IPSW File Format|IPSW]] firmware/downgrade to lower firmwares. For [[S5L8900]] devices, it uploads the following:&lt;br /&gt;
*  iBSS.MODEL.RELEASE.dfu&lt;br /&gt;
*  WTF.MODEL.RELEASE.dfu&lt;br /&gt;
*  WTF.s5l8900xall.RELEASE.dfu&lt;br /&gt;
&lt;br /&gt;
iREB does '''''NOT''''' jailbreak, it just disables [[iTunes]]'s ability to upload a patch to the ramdisk to block custom firmware made by [[sn0wbreeze]].&lt;br /&gt;
&lt;br /&gt;
== Why cant it work with the later-generation devices? ==&lt;br /&gt;
Those devices such as [[iPhone 3GS]] [[iPhone 4]] [[iPod Touch 3G]] require SHSH Blobs to upload iBSS to these devices, Also required is an exploit within the bootchain to execute unsigned code.&lt;br /&gt;
&lt;br /&gt;
== Current Developers ==&lt;br /&gt;
*[[User:ih8sn0w|iH8sn0w]] (Windows + Mac)&lt;br /&gt;
*w3st05 (Windows)&lt;br /&gt;
*spendl (Windows)&lt;br /&gt;
*srts (Mac)&lt;br /&gt;
*greenp0ison (Windows)&lt;br /&gt;
&lt;br /&gt;
== Compatible Operating Systems: ==&lt;br /&gt;
Windows XP/Vista/7&lt;br /&gt;
&lt;br /&gt;
== Changelog ==&lt;br /&gt;
===4.0===&lt;br /&gt;
*Changed GUI&lt;br /&gt;
*Removed Support for iPod Touch 1G and iPhone 2G&lt;br /&gt;
*Removed Umbrella SHSH Grabber&lt;br /&gt;
*Removed sn0wblower&lt;br /&gt;
*No LibUsb Required&lt;br /&gt;
*Uses iTunnel To Fix [[Recovery Mode]] Loops and bypass 1015 error.&lt;br /&gt;
&lt;br /&gt;
===3.1.2===&lt;br /&gt;
*Updated [[SHSH]] Grabber to accept the [[N72ap|iPod touch 2G]] and [[N18ap|iPod touch 3G]].&lt;br /&gt;
*Updated [[SHSH]] Grabber to grab 3.1.2 blobs.&lt;br /&gt;
*Integrated sn0wbl0wer, which uploads the following to an [[N72ap|iPod touch 2G]]:&lt;br /&gt;
**[[iBSS]] 2.1.1 (stock)&lt;br /&gt;
**[[ARM7 Go]] Exploit&lt;br /&gt;
**Pwned [[iBSS]]&lt;br /&gt;
*Removed PayPal Donate link.&lt;br /&gt;
&lt;br /&gt;
===3.1-3===&lt;br /&gt;
*Added [[N88ap|iPhone 3GS]] 3.1 SHSH Grabber&lt;br /&gt;
*More stable&lt;br /&gt;
*Added credits&lt;br /&gt;
&lt;br /&gt;
===3.1===&lt;br /&gt;
*Added GUI&lt;br /&gt;
*Added [[Recovery Mode]] loop fixer&lt;br /&gt;
*Fixed Bug from 2.2&lt;br /&gt;
*Removed popups&lt;br /&gt;
*Removed command prompts&lt;br /&gt;
&lt;br /&gt;
===2.2===&lt;br /&gt;
*Added Support for 3.1 (7C144)/3.1.1 (7C145)&lt;br /&gt;
*This version contains a bug, that will be fixed.&lt;br /&gt;
*Improved GUI (Windows)&lt;br /&gt;
*Added a bit more user-friendly GUI (Mac)&lt;br /&gt;
*Snow Leopard compatibility (Mac)&lt;br /&gt;
&lt;br /&gt;
===2.1===&lt;br /&gt;
*Added GUI&lt;br /&gt;
*All 3 supported devices are implemented.&lt;br /&gt;
&lt;br /&gt;
===2.0===&lt;br /&gt;
*No longer required to rename ipsw to ih8sn0w.ipsw (Windows)&lt;br /&gt;
*No longer required to move ipsw to C:\ (Windows)&lt;br /&gt;
&lt;br /&gt;
===1.0===&lt;br /&gt;
*Initial Release&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Sn0wbreeze&amp;diff=9920</id>
		<title>Sn0wbreeze</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Sn0wbreeze&amp;diff=9920"/>
		<updated>2010-10-05T12:18:07Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: corrected reason for being tethered&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;sn0wbreeze is a [[PwnageTool]] port to Windows, developed by [[User:ih8sn0w|iH8sn0w]], w3st05, srts, Little_Martian and LiLBush81.&lt;br /&gt;
&lt;br /&gt;
== Models Supported ==&lt;br /&gt;
* [[M68ap|iPhone 2G]]&lt;br /&gt;
* [[N45ap|iPod touch 1G]]&lt;br /&gt;
* [[N82ap|iPhone 3G]]&lt;br /&gt;
* [[N72ap|iPod touch 2G]]&lt;br /&gt;
* [[N88ap|iPhone 3GS]]&lt;br /&gt;
* [[N18ap|iPod touch 3G]]&lt;br /&gt;
&lt;br /&gt;
The [[N72ap|iPod touch 2G]] [[N18ap|iPod Touch 3G]] [[N88ap|iPhone 3GS]] need to have the signature checks disabled beforehand by having a pwned iBoot either by jailbreaking using a iBoot exploit or using the [[iBooty]] method. The [[S5L8900]] devices can enter [[DFU Mode]] and restore with [[iTunes]] without being jailbroken.&lt;br /&gt;
&lt;br /&gt;
== What about the iPhone 4 and the iPod Touch 4? ==&lt;br /&gt;
A iBoot Exploit or a bootrom exploit is required to run custom firmware.No such low level exploits has been found yet so there is no custom firmware.&lt;br /&gt;
&lt;br /&gt;
== Why is it tethered with the later-generation models? ==&lt;br /&gt;
Sn0wbreeze is tethered on later model devices due to the lack of a bootrom exploit like [[0x24000_Segment_Overflow]] or [[pwnage]].&lt;br /&gt;
&lt;br /&gt;
== Versions ==&lt;br /&gt;
sn0wbreeze was first released January 13, 2010 as a beta version. The following versions that are shown here are official, and sorted by compatibility with iOS revisions.&lt;br /&gt;
&lt;br /&gt;
=== 3.1.X ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; width=&amp;quot;100%&amp;quot; style=&amp;quot;font-size: 90%&amp;quot;&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:150px;&amp;quot; |Version&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center;&amp;quot; |Release date&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center;&amp;quot; |Changes&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== Public Beta ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | January 13, 2010&lt;br /&gt;
|&lt;br /&gt;
* Initial release&lt;br /&gt;
* Jailbreaks iOS 3.1.2&lt;br /&gt;
* Only allows you to be able to select simple mode&lt;br /&gt;
* Taken down due to copyright issues with [[XPwn]]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.0 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | January 16, 2010&lt;br /&gt;
|&lt;br /&gt;
* Official release of sn0wbreeze&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.1 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | January 19, 2010&lt;br /&gt;
|&lt;br /&gt;
* Fixes [[Cydia]] problems&lt;br /&gt;
* Fixes problems with [[NOR]] on [[S5L8900]] devices&lt;br /&gt;
* Fixes custom packages not being installed&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.2 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; |January 21, 2010&lt;br /&gt;
|&lt;br /&gt;
* GUI fixes&lt;br /&gt;
* Fixed even more [[Cydia]] problems&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.3 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | January 23, 2010&lt;br /&gt;
|&lt;br /&gt;
* fixes bug where some [[Cydia]] repositories could not be added and downloaded from&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.4 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | January 26, 2010&lt;br /&gt;
|&lt;br /&gt;
* Fixed vital bug where deb files may not be added to the right place&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.5 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | February 5, 2010&lt;br /&gt;
|&lt;br /&gt;
* Jailbreaks iOS 3.1.3&lt;br /&gt;
* Removed verbose mode support&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.5.1 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | February 7, 2010&lt;br /&gt;
|&lt;br /&gt;
* Removed [[blacksn0w]] due to CommCenter issues (fix being worked on)&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 4.X ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; width=&amp;quot;100%&amp;quot; style=&amp;quot;font-size: 90%&amp;quot;&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:150px;&amp;quot; |Version&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:175px;&amp;quot; |Release date&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center;&amp;quot; |Changes&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 1.6 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | June 24, 2010&lt;br /&gt;
|&lt;br /&gt;
* Jailbreaks iOS 4.0.&lt;br /&gt;
* Deleted [[ultrasn0w]] unlock option.&lt;br /&gt;
* Removed the option sn0wbreeze App&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.7 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | July 6, 2010&lt;br /&gt;
|&lt;br /&gt;
* Added support for new bootrooms ([[tethered jailbreak]])&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 1.8 Beta ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | July 16, 2010&lt;br /&gt;
|&lt;br /&gt;
* Added Support for iOS 4.1 beta 1.&lt;br /&gt;
* Deleted [[hacktivation]].&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 2.0 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | September 22nd, 2010&lt;br /&gt;
|&lt;br /&gt;
* Added support for &amp;quot;MC model&amp;quot; [[N72ap|iPod touch 2G]] ([[Tethered jailbreak|tethered]] using [[usb_control_msg(0xA1, 1) Exploit]])&lt;br /&gt;
* Added Support for [[N18ap|iPod touch 3G]] and [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]]) on iOS 3.1.2&lt;br /&gt;
* Simplified the GUI&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 2.0.1 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | September 22nd, 2010&lt;br /&gt;
|&lt;br /&gt;
* Fixed Error 37&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
==== 2.0.2 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | September 25th, 2010&lt;br /&gt;
|&lt;br /&gt;
* [https://twitter.com/iH8sn0w/status/25462030444 Bug fixes]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Problems==&lt;br /&gt;
There are some problems with blacksn0w because it relies on the 3.1.2 CommCenter, and needs to be updated to the 3.1.3 version. If installed it will cause your iPhone to go into a boot loop.&lt;br /&gt;
&lt;br /&gt;
== Use of xpwn ==&lt;br /&gt;
The backend of sn0wbreeze is [http://github.com/planetbeing/xpwn xpwn], an open-source custom IPSW generator created by planetbeing in parallel with [[iPhone Dev Team]] developments of techniques and tools.  xpwn runs on Windows, Mac OS X, and Linux.  Given a &amp;quot;bundle&amp;quot; of patches from either [[PwnageTool]] or sn0wbreeze, xpwn driven from the command line is able to create the same custom IPSW as either tool. All Fixes to xpwn made by iH8sn0w have been made available. [http://github.com/iH8sn0w/xpwn].&lt;br /&gt;
&lt;br /&gt;
== License ==&lt;br /&gt;
sn0wbreeze is freeware.&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[http://ih8sn0w.com/index.php/welcome.snow Download sn0wbreeze]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Firmware&amp;diff=9745</id>
		<title>Talk:Firmware</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Firmware&amp;diff=9745"/>
		<updated>2010-09-30T10:55:02Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;What do you mean by protected? iTunes has to dl it somehow&lt;br /&gt;
&lt;br /&gt;
o yea, forgot you had to pay for it :-) i wonder if the iPhone one would run easily?&lt;br /&gt;
&lt;br /&gt;
I've never had any luck myself, but I suppose anything's possible :-)&lt;br /&gt;
As for the actual word 'protected', the URLs in the XML are prefixed protected://.  Perhaps those URLs are still of value?&lt;br /&gt;
BTW, as far as I know, having a 2.0 beta installed will still allow &amp;quot;free&amp;quot; upgrades to 2.0.  --[[User:Haldo|Haldo]] 13:39, 5 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
:After reading a post on Zibri's blog today, I tested (and confirmed) that the iPod touch 2.0.1 firmware could be downloaded from Apple's servers. Should this URL be provided on this page? -[[User:Dialexio|Dialexio]] 00:29, 6 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
::That is a tough question... I may have to defer to geohot for that.  It is unfortunately very much a gray area.  Maybe we link to the file linked by Zibri? --[[User:Haldo|Haldo]] 20:47, 7 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
:::My thinking is this. If Apple sells it, no download link should be posted here. But perhaps a link to Zibri's page about it in the resources area. ~geohot&lt;br /&gt;
&lt;br /&gt;
== chex ==&lt;br /&gt;
&lt;br /&gt;
itunes probably checks to see if u bought it somehow...&lt;br /&gt;
&lt;br /&gt;
== yup ==&lt;br /&gt;
&lt;br /&gt;
funny you should mention that. my friend np1011357 got a 2.0 fw working, but I don't think people are brave enough to test any further :P&lt;br /&gt;
&lt;br /&gt;
I do know you have to be pwned for it to work though...&lt;br /&gt;
&lt;br /&gt;
== hmm ==&lt;br /&gt;
&lt;br /&gt;
well if its on apples servers, then we are not really 'hosting' warez, not could we be connected to hosting it at all, unlike if someone uploaded it to rapidshare, then there would be reason to believe we were involved. although its a community wiki, for something like this, it is geohot's call.&lt;br /&gt;
&lt;br /&gt;
== totally free :) ==&lt;br /&gt;
&lt;br /&gt;
ipod touch 1.1 (day it came out) -&amp;gt; 1.1.1 (command line jailbreak and jailbreakme.com) -&amp;gt; 1.1.2 symlink jailbreak -&amp;gt; 1.1.3 soft -&amp;gt; 1.1.3 ziphone -&amp;gt; 1.1.4 ijailbreak with jan. app pack -&amp;gt; 1.1.4 pwned and jan. app pack -&amp;gt; beta 1 and 2 pwned -&amp;gt; beta 8 -&amp;gt; 2.0 for free -&amp;gt; pwned 2.0 -&amp;gt; i downloaded 2.0.1 from itunes but i haven't updated yet&lt;br /&gt;
&lt;br /&gt;
haven't wasted a dime cuz i'm a lazy, jobless 14 year old and all my money goes to my 3g plan (only pay $55 a month with unlimted data, 300 minutes, and unlimted) texts $9 movie tickets, and girls&lt;br /&gt;
&lt;br /&gt;
== WOW ==&lt;br /&gt;
&lt;br /&gt;
ffs guys. i was hoping someone would figure this out. Anyone at all could just type 'strings iTunes' on the iTunes binary, and see that there is a link saying http://itunes.com/version, then another directly after is '?touchUpdate=yes&amp;quot;. It's not even that hard if u disassembeld it in IDA&lt;br /&gt;
&lt;br /&gt;
== Add defunct firmwares? ==&lt;br /&gt;
&lt;br /&gt;
There are some defunct firmware builds referenced in Apple's XML file (i.e.- iPhone 3A101a). Should these be added to this page, or not?&lt;br /&gt;
-[[User:Dialexio|Dialexio]] 20:05, 23 September 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Clarification of &amp;quot;Can be unlocked&amp;quot; ? ==&lt;br /&gt;
&lt;br /&gt;
I think we need a clarification what the &amp;quot;Can be unlocked?&amp;quot;-Column means. Because Northstar 7C144 on the 3G can be unlocked using pwnage (i.e. if you stay at BB 04.26.08). However if you'd upgrade to BB 05.11.07 it can't. --[[User:M2m|M2m]] 03:17, 16 September 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
Quote Oranav: &amp;quot;There's no point for an &amp;quot;unlock&amp;quot; column if we write &amp;quot;yes, stay at X&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
I totally agree on this, however the Columns also states ''&amp;quot;Yes (Upgrade to 04.26.08)&amp;quot;'' for BB 01.45.00 - 02.30.03, while technically currently a working implementation only is available for 04.26.08 (ultrasn0w - yellowsn0w is not available anymore AFAIK). Like this I would think for BB 01.45.00 - 02.30.03 it should also read ''&amp;quot;No (Though you can upgrade to 04.26.08)&amp;quot;'' - or something similar.&lt;br /&gt;
Therefore my statement/request for a clarification.&lt;br /&gt;
Regards --[[User:M2m|M2m]] 02:19, 17 September 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
I am of the opinion that if the BB that ships with the given Apple IPSW is not unlock(ed/able) then it should be marked NO. It should be made clear elsewhere that 04.26.08 is suitable for devices looking for an unlock. [[User:Haldo|Haldo]] 13:53, 17 September 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
The main difference here is that for older firmwares there's an upgrade path towards unlock. For example, if you buy a 3G phone now with 2.0 and BB 01.45.00, it can be easily upgraded to 3.0 and unlocked. On the other hand, if the phone has 3.1 and 05.11.07 pre-installed, there's no such upgrade path. --[[User:Blackbox|Blackbox]] 18:22, 17 September 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
What about changing the title of the column to say &amp;quot;Can baseband be unlocked?&amp;quot; and then only answer yes if there is an unlock available for the baseband included in that version? [[User:Rekoil|Rekoil]] 21:26, 17 September 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
I've changed it to say yes only on the rows with basebands that can be unlocked &amp;quot;OTB&amp;quot;. No one should have problems figuring out that you can upgrade to a version that can be unlocked if you're at a version below that cannot be unlocked. But maybe a clarification that you cannot downgrade basebands? --[[User:Rekoil|adriaaan]] 15:16, 14 October 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Tethered Jailbreak ==&lt;br /&gt;
at this point with ipt3g a tethered jailbreak may be the only option we have. the chances of another bootrom exploit being found are rather slim. And find an untethering exploit beyond that is stupid/pointless.  I know a tethered exploit sucks, but there's a real chance that this may be the only thing that's left!  Should we mark is as &amp;quot;yes jailbreakable&amp;quot; or not? I say take it and be happy with what you got!!&lt;br /&gt;
--[[User:Posixninja|posixninja]] 13:22, 12 October 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
I see what you mean, and I tend to agree for the most part, but a tethered jailbreak just isn't a complete jailbreak in my opinion. Plus if people keep looking I know a tether-less jailbreak will be found eventually, nothing is unhackable ;) --[[User:Rekoil|adriaaan]] 19:39, 12 October 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
I wish that was true, but most people average 1 exploit for every so many kilobytes, and bootrom really isn't very large.  Even then there's a limited number of injection vectors to exploits.  So the chances of bootrom becoming exploitable is actually a real risk!!   every exploit that is found greatly decreases the chances another exploit will be found.  Within the next 2-3 years jailbreaking on iphone will probably be extinct. 4 years max&lt;br /&gt;
--[[User:Posixninja|posixninja]] 04:36, 15 October 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
Well then in the next two years we'll &amp;quot;borrow one of nsa's super computers and extract the private signing key :D. Or get hold of a developer model and maybe there will be some interesting stuff on it.&lt;br /&gt;
&lt;br /&gt;
==Updated Bootroms==&lt;br /&gt;
How can we note on this page that for some 3gs and touch 2G users (ones after September 9) they can only have a tethered jailbreak at the moment. [[User:Iemit737|Iemit737]] 18:07, 31 October 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Easily find rare firmwares using Google. ==&lt;br /&gt;
&lt;br /&gt;
A handy way to search for firmwares, is to just search in Google using the corresponding listed SHA1 Hash (or even just the file size) as your query. Perhaps someone feels like editing the wiki so that the SHA1 strings become links to the right Google search results. Example: http://www.google.com/search?q=7367dd9ba58a3b9777307368a0128e696fdfc9a6 and http://www.google.com/search?q=249%2C780%2C497 [[User:Harlekeyn|Harlekeyn]] 22:59, 28 March 2010 (UTC)&lt;br /&gt;
:I say no. Links for some of the iPod touch firmwares are missing because [https://buy.itunes.apple.com/WebObjects/MZFinance.woa/wa/touchLandingPage Apple sells or sold them]. Not to mention, Apple's links to download them expire over time. (A third-party site hosting the firmware is copyright violation, which is a big no-no.) --[[User:Dialexio|Dialexio]] 06:51, 29 March 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Forbidden ==&lt;br /&gt;
There are some IPSW links which instead of a download link contain just the text &amp;quot;forbidden&amp;quot;. It would be good to know at least the name of this IPSW. To make sure nobody puts a working download link there instead (later), we could leave the &amp;quot;forbidden&amp;quot; text there and add a link to Google with the full name in the search query. I think that would be ok. What do you think? --[[User:Http|http]] 19:35, 13 June 2010 (UTC)&lt;br /&gt;
:I suppose supplying the firmware name would be fine, but I'm not a fan of linking to a Google search of the name as it would still promote piracy/copyright infringement. Perhaps we could use the &amp;quot;protected://&amp;quot; URL that Apple supplies in the [http://itunes.apple.com/version version XML], like how [http://www.trejan.com/projects/ipod/ Trejan] lists it. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 19:48, 13 June 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==4.0 Jailbreak==&lt;br /&gt;
&lt;br /&gt;
There is a userland exploit out there, and @comex (et al.) have verified that will likely work on iPhone 4 too. There is no such case as iPhone 4 having an exploit that an iPod touch 3G does not. Also this page displays if a jailbreak tool is available, not if a jailbreak has been demonstrated by geohot/chronic/dev-team/comex or Santa. -- [[User:Iemit737|Iemit737]] 21:55, 2 July 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
[[User:Dialexio|Dialexio]], ok it sounds better now. But you also removed the two other jailbreak possibilites for 4.0:&lt;br /&gt;
*with 3.1.2 shsh (this one is listed)&lt;br /&gt;
*if still running 3.1.2, but no shsh&lt;br /&gt;
*old bootrom&lt;br /&gt;
And what does OTB stand for?&lt;br /&gt;
-- [[User:Http|http]] 22:51, 21 July 2010 (UTC)&lt;br /&gt;
:OTB stands for &amp;quot;'''O'''ut of '''T'''he '''B'''ox.&amp;quot; I'll fix it up now. --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 23:07, 21 July 2010 (UTC)&lt;br /&gt;
::I saw that you changed it to ''virgin'', but not everywhere. Can you make it consistent? -- [[User:Http|http]] 05:18, 12 August 2010 (UTC)&lt;br /&gt;
:::Done. :) --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 05:23, 12 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Clarification of virgin jailbreak==&lt;br /&gt;
&lt;br /&gt;
2.2	 Timberline 5G77a	iPod2,1_2.2_5G77a_Restore.ipsw	34a0a489605f34d6cc6c9954edcaaf9a050deedc		 No &amp;lt;-- shouldn't this be a yes with a superscript 1 for tethered as there were no real protections against using iBSS/iBEC from 2.1.1 on a 2.2 device, infact the run rs program was adapted to chainload a 2.2 iBEC/iBSS for devices that the NAND didn't detect with 2.1.1 iBSS&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=S5L8900&amp;diff=9634</id>
		<title>S5L8900</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=S5L8900&amp;diff=9634"/>
		<updated>2010-09-28T17:56:06Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: /* iBoot */  arm7go was not an exploit on this platform, nor was 2.1.1 released for this processor type&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Processor shared between the [[M68ap|iPhone]], [[N45ap|iPod touch]], and the [[N82ap|iPhone 3G]]. Not much is known about it through official sources. This processor is not used in any of the newest devices, being replaced by the [[S5L8720]] and [[S5L8920]].&lt;br /&gt;
&lt;br /&gt;
==[[S5L File Formats|Firmware File Formats]]==&lt;br /&gt;
&lt;br /&gt;
== Exploits ==&lt;br /&gt;
=== [[iBoot]] ===&lt;br /&gt;
* [[Restore Mode]] -  Works up to [[iOS]] 1.0.2&lt;br /&gt;
* [[Ramdisk Hack]] - Works up to [[iOS]] 2.0 beta 3&lt;br /&gt;
* [[diags]] - Works up to [[iOS]] 2.0 beta 5&lt;br /&gt;
* [[iBoot Environment Variable Overflow]] - Works up to [[iOS]] 3.1 beta 3&lt;br /&gt;
* [[usb_control_msg(0x21, 2) Exploit]] - Works up to [[iOS]] 3.1.2&lt;br /&gt;
&lt;br /&gt;
===[[VROM (S5L8900)|Bootrom]]===&lt;br /&gt;
* [[pwnage|Pwnage 1.0 (Ramdisk + AppleImage2NORAccess)]]&lt;br /&gt;
* [[Pwnage 2.0|Pwnage 2.0 (DFU + Malformed Certificate)]]&lt;br /&gt;
&lt;br /&gt;
=== [[Kernel]] ===&lt;br /&gt;
* [[BPF STX Kernel Write Exploit]] - Works up to [[iOS]] 3.1.3&lt;br /&gt;
* [[IOSurface Kernel Exploit]] - Works up to [[iOS]] 4.0.1&lt;br /&gt;
&lt;br /&gt;
=== [[Userland]] ===&lt;br /&gt;
* [[Symlinks]] - Works up to [[iOS]] 1.1.1&lt;br /&gt;
* [[LibTiff]] - Works up to [[iOS]] 1.1.1&lt;br /&gt;
* [[Mknod]] - Works up to [[iOS]] 1.1.2&lt;br /&gt;
* [[Dual Boot Exploit]] - Works up to [[iOS]] 2.0 beta 3&lt;br /&gt;
* [[MobileBackup Copy Exploit]] - Works up to [[iOS]] 3.1.3&lt;br /&gt;
* [[PDF CFF Font Stack Overflow]] - Works up to [[iOS]] 4.0.1&lt;br /&gt;
&lt;br /&gt;
==Boot Chain==&lt;br /&gt;
[[VROM (S5L8900)]]-&amp;gt;[[LLB]]-&amp;gt;[[iBoot]]-&amp;gt;[[Kernel]]-&amp;gt;[[Firmware|System Software]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
One of the [[iPhoneLinux]] goals are to replace that Boot Chain after iBoot:&lt;br /&gt;
&lt;br /&gt;
[[VROM (S5L8900)]]-&amp;gt;OpeniBoot-&amp;gt;Linux Kernel-&amp;gt;X Server-&amp;gt;Window Manager&lt;br /&gt;
&lt;br /&gt;
==Upgrade Process==&lt;br /&gt;
&lt;br /&gt;
=== [[Restore Mode]] ===&lt;br /&gt;
The common upgrade process chain is [[VROM]]-&amp;gt;[[DFU Mode]]-&amp;gt;[[WTF]]-&amp;gt;[[iBoot]]-&amp;gt;[[Kernel]]-&amp;gt;[[Ramdisk]]-&amp;gt;[[Restore Mode]].&lt;br /&gt;
&lt;br /&gt;
=== [[DFU Mode]] ===&lt;br /&gt;
To flash an older version of the iPhone software you have to let your phone reside in [[DFU Mode]]. In iTunes you have to press the option key (Mac) or the shift key (Windows) when pressing 'Restore' to be able to manually chose an [[IPSW File Format|IPSW]].&lt;br /&gt;
&lt;br /&gt;
==== Boot Chain ====&lt;br /&gt;
[[VROM]]-&amp;gt;[[DFU Mode]]&lt;br /&gt;
&lt;br /&gt;
==External Links==&lt;br /&gt;
* [http://infocenter.arm.com/help/topic/com.arm.doc.ddi0301h/DDI0301H_arm1176jzfs_r0p7_trm.pdf Technical Reference Manual: ARM1176JZF-S]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:S5L8930&amp;diff=9266</id>
		<title>Talk:S5L8930</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:S5L8930&amp;diff=9266"/>
		<updated>2010-09-20T14:26:09Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Merge?==&lt;br /&gt;
Should this and the A4 page be merged? They're practically the same in content. --[[User:Dialexio|Dialexio]] 17:18, 6 April 2010 (UTC)&lt;br /&gt;
:A4 is just the public name for the s5l8930, no? I say we merge it and make A4 redirect to this page, with a /very minor/ explanation on why it redirects you to this page. ~Drake&lt;br /&gt;
::This was from when the pages were separate entities. The problem has since been resolved. :) --[[User:Dialexio|&amp;lt;span style=&amp;quot;color:#C20; font-weight:normal;&amp;quot;&amp;gt;Dialexio&amp;lt;/span&amp;gt;]] 04:13, 20 September 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Is there an iBoot exploit?==&lt;br /&gt;
&lt;br /&gt;
Geohot got the iPad to boot verbosely, and the VFDecrypt and other fun keys.&lt;br /&gt;
&lt;br /&gt;
This almost certainly means there is an iboot/llb exploit out there, no? Can the keys be gotten with just a tethered bootrom exploits?&lt;br /&gt;
&lt;br /&gt;
[[User:Iemit737|Iemit737]] 21:39, 25 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
it could be possible he found a bootrom exploit that was pwnage 2 like however the real pwnage exploits the unchecked LLB but apple could have made a mistake with the new shsh check --[[User:Liamchat|liamchat]] 19:20, 29 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Are we sure that geohot even had an untethered bootrom exploit? He had denied that &amp;quot;pwned4life&amp;quot; or whatever it was was real. [[User:LiNK|LiNK]] 02:07, 20 September 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
There /is/ a bootrom exploit. It's probably tethered (for now). It's a code-execution exploit, as you can't get keys without executing code. Nor can you boot verbosely without an untethered bootrom exploit. Hope this helps. ~Drake&lt;br /&gt;
::A bootrom exploit tethered or untethered can be used to boot verbosely, SIDEBAR: people take tethered/untethered as meaning far too much, all tethered/untethered means is you need to plug in to something to boot, it has absolutely NO bearing on any other capability --[[User:Lilstevie|Lilstevie]] 14:26, 20 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=9254</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=9254"/>
		<updated>2010-09-19T14:52:21Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. --[[User:Lilstevie|Lilstevie]] 09:45, 20 August 2010 (UTC)- lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
The baseband processor checks the signature, not the application processor. [[User:dogbert|dogbert]] 18:36, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
ahh got ya! but would my theory work though through an exploit such as AT+XAPP? instead of a payload it just changes the .plist? [[User:Leobruh|Leobruh]] 00:15, 20 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
:you would still require the valid NCK for it to process the unlock in that method, the current way the payloads work for exploits in the baseband processor are adequate --[[User:Lilstevie|Lilstevie]] 09:44, 20 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
:i thought NKC was only for the iPhone 2G? 0.o [[User:Leobruh|Leobruh]] 14:47, 21 August 2010 (UTC)!&lt;br /&gt;
::NCK or Network Code Key is on any cellular device that gets locked to a carrier --[[User:Lilstevie|Lilstevie]] 14:52, 19 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8532</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8532"/>
		<updated>2010-08-20T09:45:29Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. --[[User:Lilstevie|Lilstevie]] 09:45, 20 August 2010 (UTC)- lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
The baseband processor checks the signature, not the application processor. [[User:dogbert|dogbert]] 18:36, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
ahh got ya! but would my theory work though through an exploit such as AT+XAPP? instead of a payload it just changes the .plist? [[User:Leobruh|Leobruh]] 00:15, 20 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
:you would still require the valid NCK for it to process the unlock in that method, the current way the payloads work for exploits in the baseband processor are adequate --[[User:Lilstevie|Lilstevie]] 09:44, 20 August 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8531</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8531"/>
		<updated>2010-08-20T09:44:54Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoretically, can't we just edit the .plist? and make it into the factory unlocked IMSI Mask? -- {{unsigned|Leobruh|5:32, 19 August 2010 (UTC)}}&lt;br /&gt;
:The activation plist is signed, so to do this you require a jailbreak anyway. - lilstevie&lt;br /&gt;
&lt;br /&gt;
i realize that. but wouldnt this result in a permanent unlock? [[User:Leobruh|Leobruh]] 07:37, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
I'm guessing the ticket is handled by the baseband, which requires an exploit to get unsigned code running in the first place? [[User:Iemit737|Iemit737]] 07:41, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
The wildcard ticket is also signed - simple edits break the signature and the ticket gets rejected then. rtfm cryptography 101. [[User:dogbert|dogbert]] 16:02, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
kay but unsigned code already runs when the phone is jailbroken and has access to the filesystem. wouldnt editing the .plist be okay since the sig checks arent needed. again this is all theoretical. im jw [[User:Leobruh|Leobruh]] 18:33, 19 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
The baseband processor checks the signature, not the application processor. [[User:dogbert|dogbert]] 18:36, 19 August 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
ahh got ya! but would my theory work though through an exploit such as AT+XAPP? instead of a payload it just changes the .plist? [[User:Leobruh|Leobruh]] 00:15, 20 August 2010 (UTC)!&lt;br /&gt;
&lt;br /&gt;
 you would still require the valid NCK for it to process the unlock in that method, the current way the payloads work for exploits in the baseband processor are adequate --[[User:Lilstevie|Lilstevie]] 09:44, 20 August 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8466</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8466"/>
		<updated>2010-08-19T06:14:31Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoritically, cant we just edit the .plist? and make it into the factory unlocked IMSI Mask?&lt;br /&gt;
      The activation plist is signed, so to do this you require a jailbreak anyway. - lilstevie&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8465</id>
		<title>Talk:WildcardTicket</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:WildcardTicket&amp;diff=8465"/>
		<updated>2010-08-19T06:14:07Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Theoritically, cant we just edit the .plist? and make it into the factory unlocked IMSI Mask?&lt;br /&gt;
      - The activation plist is signed, so to do this you require a jailbreak anyway. - lilstevie&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Lilstevie&amp;diff=7953</id>
		<title>Lilstevie</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Lilstevie&amp;diff=7953"/>
		<updated>2010-08-07T10:02:08Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Lilstevie moved to User:Lilstevie: I am a user of this wiki&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[User:Lilstevie]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Lilstevie&amp;diff=7952</id>
		<title>User:Lilstevie</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Lilstevie&amp;diff=7952"/>
		<updated>2010-08-07T10:02:07Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: Lilstevie moved to User:Lilstevie: I am a user of this wiki&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;iPhone Hacker, Member of the [[Chronic Dev]]&lt;br /&gt;
[[Category:Hackers]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=IPhoneTunnel&amp;diff=4414</id>
		<title>IPhoneTunnel</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=IPhoneTunnel&amp;diff=4414"/>
		<updated>2009-07-23T09:32:45Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: corrected itunes version number&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Mac OSX Software developed by novi to open TCP connections (TCP tunnels) between your iPhone / iPod touch and Mac via USB cable. This can be used in case WiFi connection is not available. Currently not working with iPhone OS 3.0 and [[iTunes]] 8.2.x&lt;br /&gt;
&lt;br /&gt;
A MS Windows Software featuring a more or less similar functionality called iPhone Tunnel suit is available as well.&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
&lt;br /&gt;
*[http://web.me.com/novi.mad/page2/page2.html iPhoneTunnel]&lt;br /&gt;
*[http://minephone.blogspot.com/2009/03/iphone-tunnel-suit-27.html iPhone Tunnel suit]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=S5L8920&amp;diff=4292</id>
		<title>S5L8920</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=S5L8920&amp;diff=4292"/>
		<updated>2009-07-17T11:54:12Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: /* iBoot / Kernel */ adding in the info removed from S5L8720 page that was related to s5l8920&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the processor used in the [[iPhone 3GS]].&lt;br /&gt;
&lt;br /&gt;
S5L8920 using [http://www.arm.com/products/CPUs/archi-thumb2.html THUMB-2] instruction set as much as ARM and THUMB ones. So the compiled binaries are not compatible with older CPUs.&lt;br /&gt;
&lt;br /&gt;
== Exploits ==&lt;br /&gt;
=== [[iBoot]] / [[Kernel]] ===&lt;br /&gt;
* [[iBoot Environment Variable Overflow]] - Firmware 3.1b1 and below (Note: [[iBoot]] on the S5l8720 can be downgraded allowing the exploit to be used on future firmwares, but ''only if'' a backup of the device-specific Apple-signed 3.0 iBSS with unique [[ECID]] was made.)&lt;br /&gt;
&lt;br /&gt;
=== [[S5L8920 (Bootrom)|Bootrom]] ===&lt;br /&gt;
* [[0x24000 Segment Overflow]]&lt;br /&gt;
&lt;br /&gt;
== Boot Chain ==&lt;br /&gt;
[[S5L8920 (Bootrom)|Bootrom]]-&amp;gt;[[LLB]]-&amp;gt;[[iBoot]]-&amp;gt;[[Kernel]]-&amp;gt;[[System|System Software]]&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[S5L8920 (Bootrom)]]&lt;br /&gt;
* [[S5L8920 (Hardware)]]&lt;br /&gt;
* [[S5L8920 (Hardware - Quick Notes)]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=S5L8720&amp;diff=4287</id>
		<title>S5L8720</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=S5L8720&amp;diff=4287"/>
		<updated>2009-07-16T21:50:48Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: adding back in info i accidentally removed while cleaning the incorrect stuff out&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Processor used on the [[n72ap|iPod Touch 2G]].&lt;br /&gt;
&lt;br /&gt;
==Exploits==&lt;br /&gt;
===[[iBoot]] / [[Kernel]] Level===&lt;br /&gt;
* [[ARM7 Go]] - Firmware v2.1.1&lt;br /&gt;
* [[iBoot Environment Variable Overflow]] - Firmware v3.1b1 and below (Note: [[iBoot]] on the S5l8720 can be downgraded allowing the exploit to be used on future firmwares)&lt;br /&gt;
&lt;br /&gt;
===[[VROM (S5L8720)|Bootrom]]===&lt;br /&gt;
* [[0x24000 Segment Overflow]]&lt;br /&gt;
&lt;br /&gt;
==Boot Chain==&lt;br /&gt;
[[VROM (S5L8720)|VROM]]-&amp;gt;[[LLB]]-&amp;gt;[[iBoot]]-&amp;gt;[[Kernel]]-&amp;gt;[[System|System Software]]&lt;br /&gt;
&lt;br /&gt;
It is definitely worthy to note that the [[Pwnage]] exploit is fixed because the images are now flashed to the [[NOR]] in their encrypted [[IMG3]] containers, and the [[S5L8720 Bootrom|bootrom]] can properly sigcheck [[LLB]]. That being said, unsigned images can still be run using the [[0x24000 Segment Overflow]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
* [[S5L8720 (Hardware)]]&lt;br /&gt;
* [[S5L File Formats]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=S5L8720&amp;diff=4285</id>
		<title>S5L8720</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=S5L8720&amp;diff=4285"/>
		<updated>2009-07-16T21:48:23Z</updated>

		<summary type="html">&lt;p&gt;Lilstevie: /* iBoot / Kernel Level */ removed information that was for the s5l8920&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the Application Processor used on the [[n72ap|iPod Touch 2G]].&lt;br /&gt;
&lt;br /&gt;
==Exploits==&lt;br /&gt;
===[[iBoot]] / [[Kernel]] Level===&lt;br /&gt;
* [[ARM7 Go]] - Firmware v2.1.1&lt;br /&gt;
* [[iBoot Environment Variable Overflow]] - Firmware v3.1b1 and below&lt;br /&gt;
&lt;br /&gt;
===[[VROM (S5L8720)|Bootrom]]===&lt;br /&gt;
* [[0x24000 Segment Overflow]]&lt;br /&gt;
&lt;br /&gt;
==Boot Chain==&lt;br /&gt;
[[VROM (S5L8720)|VROM]]-&amp;gt;[[LLB]]-&amp;gt;[[iBoot]]-&amp;gt;[[Kernel]]-&amp;gt;[[System|System Software]]&lt;br /&gt;
&lt;br /&gt;
It is definitely worthy to note that the [[Pwnage]] exploit is fixed because the images are now flashed to the [[NOR]] in their encrypted [[IMG3]] containers, and the [[S5L8720 Bootrom|bootrom]] can properly sigcheck [[LLB]]. That being said, unsigned images can still be run using the [[0x24000 Segment Overflow]].&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
* [[S5L8720 (Hardware)]]&lt;br /&gt;
* [[S5L File Formats]]&lt;/div&gt;</summary>
		<author><name>Lilstevie</name></author>
		
	</entry>
</feed>