<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Malontop</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Malontop"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/Malontop"/>
	<updated>2026-05-19T10:12:43Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Usb_control_msg(0x21,_2)_Exploit&amp;diff=10710</id>
		<title>Talk:Usb control msg(0x21, 2) Exploit</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Usb_control_msg(0x21,_2)_Exploit&amp;diff=10710"/>
		<updated>2010-10-18T07:55:34Z</updated>

		<summary type="html">&lt;p&gt;Malontop: New page: This exploit isn't used in greepois0n, is it? --malontop&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This exploit isn't used in greepois0n, is it? --malontop&lt;/div&gt;</summary>
		<author><name>Malontop</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Redsn0w&amp;diff=10709</id>
		<title>Redsn0w</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Redsn0w&amp;diff=10709"/>
		<updated>2010-10-18T07:53:59Z</updated>

		<summary type="html">&lt;p&gt;Malontop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:Redsn0w.png|thumb|redsn0w 0.9.5-b5]]&lt;br /&gt;
redsn0w was originally called [[QuickPwn]] but due to the theft and exploitation of the name, QuickPWN by quickpwn.com, as of iOS 3.0, QuickPwn was discontinued and redsn0w (at the time, version 0.7) was converted into a [[jailbreak]]ing tool for all current devices as well as providing [[unlock]] support the [[M68ap|iPhone 2G]]. As of version 0.8, the [[N88ap|iPhone 3GS]] can also be jailbroken through redsn0w.&lt;br /&gt;
&lt;br /&gt;
Version 0.9 beta 3 was released for Windows and Mac OS X, and it allows iOS 3.0 through 3.1.2 to be jailbroken. It includes support for all devices except the [[N18ap|iPod touch 3G]], and supports a [[tethered jailbreak]] on [[N88ap|iPhone 3GS]] units and [[N72ap|iPod touch 2G]] units with new bootroms. In addition, this version supported custom boot and recovery mode logos, as well as verbose mode on bootup.&lt;br /&gt;
&lt;br /&gt;
The final release, version [http://wikee.iphwn.org/howto:rs9 0.9.2], supports jailbreaking of all iDevices (at the time) with iOS 3.0 through 3.1.2 on Windows and Mac OS X, as well as 3.1.3 on [[S5L8900]] devices. Version 0.9.3 adds support of internet tethering IPCC hack on those devices and 0.9.4 allows jailbreaking of early [[N72ap|iPod touch 2G]] with iOS 3.1.3.&lt;br /&gt;
&lt;br /&gt;
Version [http://wikee.iphwn.org/howto:rsbeta 0.9.5b5-5] supports jailbreaking the [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom]]) with iOS 4.0 on Windows and Mac OS X.&lt;br /&gt;
&lt;br /&gt;
redsn0w [http://blog.iphone-dev.org/post/1160213613 0.9.6b1] supports jailbreaking the [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] (both bootroms, although the [[iBoot-240.5.1|new bootrom]]'s jailbreak is tethered) with iOS 4.0 through 4.1 on Mac OS X and Windows.&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
[[iPhone Dev Team]]&lt;br /&gt;
&lt;br /&gt;
== Versions ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; width=&amp;quot;100%&amp;quot; style=&amp;quot;font-size: 90%&amp;quot;&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:150px;&amp;quot; |Version&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:175px;&amp;quot; |Release date&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center;&amp;quot; |Changes&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.2 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Supports 3.0-3.1.2 on all iPhones and iPod touches (still a tethered-only JB for late-model devices though)&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.3 beta ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Contains the IPCC hack to enable tethering on the iPhone 3G and 3GS.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.4 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Supports jailbreaking iOS 3.1.3 on [[M68ap|iPhone 2G]], [[N82ap|iPhone 3G]], [[N45ap|iPod touch 1G]], [[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom/MB model]])&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.5 beta 5-3 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | June 21, 2010&lt;br /&gt;
|&lt;br /&gt;
* Supports jailbreaking iOS 4.0 on [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom/MB model]])&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.5 beta 5-4 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Resolved a problem with iBooks.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.5 beta 5-5 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Supposed to fix any APN or MMS issues that users were seeing.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.6 beta 1 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | September 21, 2010&lt;br /&gt;
|&lt;br /&gt;
* Supports jailbreaking iOS 4.0/4.1 on [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] (Tethered on New Bootrom)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Exploits used ==&lt;br /&gt;
For [[N45ap|iPod touch]], [[M68ap|iPhone]] and [[N82ap|iPhone 3G]], see:&lt;br /&gt;
*[[Pwnage]]&lt;br /&gt;
*[[Pwnage 2.0]]&lt;br /&gt;
&lt;br /&gt;
For [[N72ap|iPod touch 2G]], see:&lt;br /&gt;
*[[0x24000 Segment Overflow]]&lt;br /&gt;
*[[ARM7 Go]] - was used to upload the oversized [[LLB]] required to utilize the 0x24000 Segment Overflow.&lt;br /&gt;
*[[usb_control_msg(0xA1, 1) Exploit]] - used to upload the oversized [[LLB]] to utilize the 0x24000 Segment Overflow. It is also used for a [[tethered jailbreak]] on units with the [[iBoot-240.5.1|new bootrom]].&lt;br /&gt;
&lt;br /&gt;
For [[N88ap|iPhone 3GS]], see:&lt;br /&gt;
*[[0x24000 Segment Overflow]]&lt;br /&gt;
*[[iBoot Environment Variable Overflow]] - Exploit has a different implementation from [[User:geohot|geohot]]'s implementation in [[purplera1n]].&lt;br /&gt;
*[[usb_control_msg(0x21, 2) Exploit]]&lt;br /&gt;
&lt;br /&gt;
For [[N18ap|iPod touch 3G]]&lt;br /&gt;
*[[usb_control_msg(0x21, 2) Exploit]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;/div&gt;</summary>
		<author><name>Malontop</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Redsn0w&amp;diff=10707</id>
		<title>Redsn0w</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Redsn0w&amp;diff=10707"/>
		<updated>2010-10-18T07:42:56Z</updated>

		<summary type="html">&lt;p&gt;Malontop: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:Redsn0w.png|thumb|redsn0w 0.9.5-b5]]&lt;br /&gt;
redsn0w was originally called [[QuickPwn]] but due to the theft and exploitation of the name, QuickPWN by quickpwn.com, as of iOS 3.0, QuickPwn was discontinued and redsn0w (at the time, version 0.7) was converted into a [[jailbreak]]ing tool for all current devices as well as providing [[unlock]] support the [[M68ap|iPhone 2G]]. As of version 0.8, the [[N88ap|iPhone 3GS]] can also be jailbroken through redsn0w.&lt;br /&gt;
&lt;br /&gt;
Version 0.9 beta 3 was released for Windows and Mac OS X, and it allows iOS 3.0 through 3.1.2 to be jailbroken. It includes support for all devices except the [[N18ap|iPod touch 3G]], and supports a [[tethered jailbreak]] on [[N88ap|iPhone 3GS]] units and [[N72ap|iPod touch 2G]] units with new bootroms. In addition, this version supported custom boot and recovery mode logos, as well as verbose mode on bootup.&lt;br /&gt;
&lt;br /&gt;
The final release, version [http://wikee.iphwn.org/howto:rs9 0.9.2], supports jailbreaking of all iDevices (at the time) with iOS 3.0 through 3.1.2 on Windows and Mac OS X, as well as 3.1.3 on [[S5L8900]] devices. Version 0.9.3 adds support of internet tethering IPCC hack on those devices and 0.9.4 allows jailbreaking of early [[N72ap|iPod touch 2G]] with iOS 3.1.3.&lt;br /&gt;
&lt;br /&gt;
Version [http://wikee.iphwn.org/howto:rsbeta 0.9.5b5-5] supports jailbreaking the [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom]]) with iOS 4.0 on W&lt;br /&gt;
Version 0.9.5b5-5 supports jailbreaking the iPhone 3G and iPod touch 2G (old bootrom) with iOS 4.0 on Windows and Mac OS X.&lt;br /&gt;
redsn0w 0.9.6b1 supportsindows and Mac OS X.&lt;br /&gt;
&lt;br /&gt;
redsn0w [http://blog.iphone-dev.org/post/1160213613 0.9.6b1] supporrts jailbreaking the [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] (both bootroms, although the [[iBoot-240.5.1|new bootrom]]'s jailbreak is tethered) with iOS 4.0 through 4.1 on Mac OS X.&lt;br /&gt;
&lt;br /&gt;
== Credit ==&lt;br /&gt;
[[iPhone Dev Team]]&lt;br /&gt;
&lt;br /&gt;
== Versions ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; width=&amp;quot;100%&amp;quot; style=&amp;quot;font-size: 90%&amp;quot;&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:150px;&amp;quot; |Version&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center; width:175px;&amp;quot; |Release date&lt;br /&gt;
! style=&amp;quot;background-color:#E9E9E9; text-align:center;&amp;quot; |Changes&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.2 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Supports 3.0-3.1.2 on all iPhones and iPod touches (still a tethered-only JB for late-model devices though)&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.3 beta ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Contains the IPCC hack to enable tethering on the iPhone 3G and 3GS.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.4 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Supports jailbreaking iOS 3.1.3 on [[M68ap|iPhone 2G]], [[N82ap|iPhone 3G]], [[N45ap|iPod touch 1G]], [[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom/MB model]])&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.5 beta 5-3 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | June 21, 2010&lt;br /&gt;
|&lt;br /&gt;
* Supports jailbreaking iOS 4.0 on [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] ([[iBoot-240.4|old bootrom/MB model]])&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.5 beta 5-4 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Resolved a problem with iBooks.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.5 beta 5-5 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | Unknown&lt;br /&gt;
|&lt;br /&gt;
* Supposed to fix any APN or MMS issues that users were seeing.&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;white-space: nowrap;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==== 0.9.6 beta 1 ====&lt;br /&gt;
| style=&amp;quot;white-space: nowrap;&amp;quot; | September 21, 2010&lt;br /&gt;
|&lt;br /&gt;
* Supports jailbreaking iOS 4.0/4.1 on [[N82ap|iPhone 3G]] and [[N72ap|iPod touch 2G]] (Tethered on New Bootrom)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Exploits used ==&lt;br /&gt;
For [[N45ap|iPod touch]], [[M68ap|iPhone]] and [[N82ap|iPhone 3G]], see:&lt;br /&gt;
*[[Pwnage]]&lt;br /&gt;
*[[Pwnage 2.0]]&lt;br /&gt;
&lt;br /&gt;
For [[N72ap|iPod touch 2G]], see:&lt;br /&gt;
*[[0x24000 Segment Overflow]]&lt;br /&gt;
*[[ARM7 Go]] - was used to upload the oversized [[LLB]] required to utilize the 0x24000 Segment Overflow.&lt;br /&gt;
*[[usb_control_msg(0xA1, 1) Exploit]] - used to upload the oversized [[LLB]] to utilize the 0x24000 Segment Overflow. It is also used for a [[tethered jailbreak]] on units with the [[iBoot-240.5.1|new bootrom]].&lt;br /&gt;
&lt;br /&gt;
For [[N88ap|iPhone 3GS]], see:&lt;br /&gt;
*[[0x24000 Segment Overflow]]&lt;br /&gt;
*[[iBoot Environment Variable Overflow]] - Exploit has a different implementation from [[User:geohot|geohot]]'s implementation in [[purplera1n]].&lt;br /&gt;
*[[usb_control_msg(0x21, 2) Exploit]]&lt;br /&gt;
&lt;br /&gt;
For [[N18ap|iPod touch 3G]]&lt;br /&gt;
*[[usb_control_msg(0x21, 2) Exploit]]&lt;br /&gt;
&lt;br /&gt;
[[Category:Hacking Software]]&lt;/div&gt;</summary>
		<author><name>Malontop</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Bootrom&amp;diff=9500</id>
		<title>Bootrom</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Bootrom&amp;diff=9500"/>
		<updated>2010-09-26T07:55:22Z</updated>

		<summary type="html">&lt;p&gt;Malontop: /* Check bootrom version */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Introduction / old+new==&lt;br /&gt;
The bootrom (called &amp;quot;SecureROM&amp;quot; by Apple) is the first significant code that runs on an iDevice. The bootrom is unwritable. Finding exploits in the bootrom level is a big achievement since Apple won't be able to fix it without a hardware revision.&lt;br /&gt;
&lt;br /&gt;
Often users refer to '''old bootrom''' or '''new bootrom''' devices. The '''new bootrom''' devices were released after [[Timeline#September|9 September 2009]] and have the [[0x24000 Segment Overflow]] fixed. Therefore these newer versions of the [[N72ap|iPod touch 2G]] and [[N88ap|iPhone 3GS]] are not vulnerable to this exploit and had only a [[tethered jailbreak]]/[[unlock]] until [[Spirit]] came out. Currently, these devices can be jailbroken on iOS 4.0 with [[Star]].&lt;br /&gt;
&lt;br /&gt;
Please see also [[IBoot|Apple's stage 2 bootloader]], which also uses the &amp;quot;iBoot&amp;quot; name.&lt;br /&gt;
&lt;br /&gt;
==Check bootrom version==&lt;br /&gt;
To find out if you have an old or new bootrom, the easiest way is to look at the serial number. If the 4th and 5th digits are lower than 40, then you probably have an old bootrom. If they are higher than 45, then you probably have a new bootrom. These two digits show the production week. For refurbished phones and for numbers inbetween, the result is undefined and you have to make the following exact check.&lt;br /&gt;
&lt;br /&gt;
To check your device's bootrom version, you must put your device into [[DFU Mode]]. Make sure it is '''not''' in [[Recovery Mode]], as Recovery Mode does not mention the bootrom version. If you have Mac OS X, go to System Profiler, and under the &amp;quot;Hardware&amp;quot; category, go to USB, and click on &amp;quot;Apple Mobile Device (DFU Mode).&amp;quot; If you have Windows, go to Device Manager, find USB controller, subitem Apple Mobile Device USB Driver. In Properties, Details, select Device Instance Path in the dropdown. The end of the info string will show the bootrom version.&lt;br /&gt;
&lt;br /&gt;
If you're on Linux and have a Desktop Environment setup, install gnome-device-manager and start it. Connect you're device in DFU Mode, search in the left tree-view for &amp;quot;USB Device&amp;quot; and look at Summary -&amp;gt; Model until it says &amp;quot;Apple Mobile Device (DFU Mode)&amp;quot;. If it does go to Properties (next to Summary) and search for &amp;quot;usb_device.serial&amp;quot;. The end of the String will show you the bootrom version.&lt;br /&gt;
&lt;br /&gt;
== Revisions ==&lt;br /&gt;
===[[S5L8900]], used in the [[M68ap|iPhone]], [[N45ap|iPod touch 1G]], and [[N82ap|iPhone 3G]]===&lt;br /&gt;
&lt;br /&gt;
===[[S5L8720]], used in the [[N72ap|iPod touch 2G]]===&lt;br /&gt;
* [[iBoot-240.4]] &amp;quot;old bootrom&amp;quot;&lt;br /&gt;
* [[iBoot-240.5.1]] &amp;quot;new bootrom&amp;quot;&lt;br /&gt;
&lt;br /&gt;
===[[S5L8920]], used in the [[N88ap|iPhone 3GS]]===&lt;br /&gt;
* [[iBoot-359.3]] &amp;quot;old bootrom&amp;quot;&lt;br /&gt;
* [[iBoot-359.3.2]] &amp;quot;new bootrom&amp;quot;&lt;br /&gt;
&lt;br /&gt;
===[[S5L8922]], used in the [[N18ap|iPod touch 3G]]===&lt;br /&gt;
* [[iBoot-359.5]]&lt;br /&gt;
&lt;br /&gt;
===[[S5L8930]], used in the [[K48ap|iPad]], [[N90ap|iPhone 4]], and [[N81ap|iPod touch 4G]]===&lt;br /&gt;
* [[iBoot-574.4]]&lt;/div&gt;</summary>
		<author><name>Malontop</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=User:Malontop&amp;diff=9057</id>
		<title>User:Malontop</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=User:Malontop&amp;diff=9057"/>
		<updated>2010-09-08T06:39:20Z</updated>

		<summary type="html">&lt;p&gt;Malontop: New page: I am interested in programming Linux, OS X and iOS Apps.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I am interested in programming Linux, OS X and iOS Apps.&lt;/div&gt;</summary>
		<author><name>Malontop</name></author>
		
	</entry>
</feed>