<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Shad00w</id>
	<title>The iPhone Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.theiphonewiki.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Shad00w"/>
	<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/wiki/Special:Contributions/Shad00w"/>
	<updated>2026-06-10T14:53:31Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.31.14</generator>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Apex_8A306_(iPhone3,1)&amp;diff=9108</id>
		<title>Talk:Apex 8A306 (iPhone3,1)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Apex_8A306_(iPhone3,1)&amp;diff=9108"/>
		<updated>2010-09-09T12:44:36Z</updated>

		<summary type="html">&lt;p&gt;Shad00w: Response&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Wait a sec ...'''&lt;br /&gt;
Just a quick question, how did (whoever) manage to get the keys for the iBSS ? Cheers --[[User:Shad00w|Shad00w]] 20:09, 8 September 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
: [[pod2g]] published them three hours ago: [http://twitter.com/pod2g/status/23932796062 Tweet by pod2g]. It looks like he found a new exploit. -- [[User:Http|http]] 20:31, 8 September 2010 (UTC)&lt;br /&gt;
&lt;br /&gt;
Sorry, I didn't know ! Congrats to pod2g and I can't wait to use the exploit ! &lt;br /&gt;
--[[User:Shad00w|Shad00w]] 13:44, 9 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Shad00w</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Talk:Apex_8A306_(iPhone3,1)&amp;diff=9074</id>
		<title>Talk:Apex 8A306 (iPhone3,1)</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Talk:Apex_8A306_(iPhone3,1)&amp;diff=9074"/>
		<updated>2010-09-08T20:09:28Z</updated>

		<summary type="html">&lt;p&gt;Shad00w: quick question&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Wait a sec ...]]&lt;br /&gt;
Just a quick question, how did (whoever) manage to get the keys for the iBSS ? Cheers --[[User:Shad00w|Shad00w]] 20:09, 8 September 2010 (UTC)&lt;/div&gt;</summary>
		<author><name>Shad00w</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Ramdisk_Hack&amp;diff=6882</id>
		<title>Ramdisk Hack</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Ramdisk_Hack&amp;diff=6882"/>
		<updated>2010-07-10T21:05:21Z</updated>

		<summary type="html">&lt;p&gt;Shad00w: not much&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This allows unsigned ramdisks to be booted. It was first publicized by [[ZiPhone]] &lt;br /&gt;
&lt;br /&gt;
==Exploit==&lt;br /&gt;
Passing pmd*= boot-args specifying a ramdisk in ram &amp;gt; 0x9C000000 allows any ramdisk to be booted.&lt;br /&gt;
&lt;br /&gt;
==Implementation==&lt;br /&gt;
* [[PwnageTool]]&lt;br /&gt;
* [[ZiPhone]]&lt;br /&gt;
* iPlus&lt;br /&gt;
* iLibertyX / [[iLiberty+]]&lt;br /&gt;
* iFree &lt;br /&gt;
* iPhone Forensics Toolkit&lt;br /&gt;
* iNdependence&lt;br /&gt;
* Any Jailbreak program so far&lt;br /&gt;
* iTunes&lt;br /&gt;
* Android&lt;br /&gt;
* Zune&lt;br /&gt;
* Linux&lt;br /&gt;
* Windows Mobile&lt;br /&gt;
* webOS&lt;br /&gt;
* BlackBerry OS&lt;br /&gt;
&lt;br /&gt;
== History ==&lt;br /&gt;
&lt;br /&gt;
Credit goes to the Dev Team for the discovery of the ramdisk hack. First implemented in ZiPhone, using code taken from the dev-team repository, it allowed running jailbreaks on the fly to be quicker than previous jailbreak implementations, due to the fact that at the time it was the only ramdisk hack jailbreak available.&lt;br /&gt;
&lt;br /&gt;
[[Category:Jailbreaks]]&lt;br /&gt;
[[Category:Exploits]]&lt;/div&gt;</summary>
		<author><name>Shad00w</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Unsolved_problems&amp;diff=6867</id>
		<title>Unsolved problems</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Unsolved_problems&amp;diff=6867"/>
		<updated>2010-07-10T16:31:15Z</updated>

		<summary type="html">&lt;p&gt;Shad00w: Updating link :L&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Use your imagination; what do you want?&lt;br /&gt;
&lt;br /&gt;
==Exploits Needed==&lt;br /&gt;
* [[Unlock 2.0|3G iPhone Baseband]] - Partly done ([[ultrasn0w]] uses [[AT+XLOG Vulnerability]] which is available in all versions until 04.26.08)&lt;br /&gt;
* [[Baseband Bootrom|iPhone 3G Baseband Bootrom]] (breaking the chain of trust)&lt;br /&gt;
* &amp;lt;del&amp;gt;[[S5L8720|iPod Touch 2G S5L Bootrom]] (breaking the chain of trust)&amp;lt;/del&amp;gt; - Done ([[0x24000 Segment Overflow]])&lt;br /&gt;
* [[S5L8920 (Bootrom)|iPhone 3GS Bootrom]] (breaking the chain of trust or finding a way to write LLB without using an iBoot exploit)&lt;br /&gt;
&lt;br /&gt;
==Work to be done==&lt;br /&gt;
*[[iPhoneLinux|Port Linux to the iPhone]] [http://www.iphonelinux.org/]&lt;br /&gt;
**[[Port (Google's mobile os) to the iPhone]]  [http://code.google.com/android/ Android Link]&lt;br /&gt;
*[[Increased Bluetooth Profile Support]]&lt;br /&gt;
*[[Patch iOS 4.0 to work on iPhone 2G &amp;amp; iPod Touch 1G]]&lt;br /&gt;
*IP over iTunes&lt;br /&gt;
*Getting NMEA output from the GPS&lt;br /&gt;
*IPFW kernel extension&lt;br /&gt;
*Find out how to activate the Broad-comm radio/wireless N chip&lt;br /&gt;
&lt;br /&gt;
== Investigation ==&lt;br /&gt;
*[[Research: Pwnage Patches]]&amp;lt;br&amp;gt;&lt;br /&gt;
*[[Research: Re-allowing unsigned ramdisks and boot-args with the 2.* iBoot]]&lt;br /&gt;
*[[2.0 and 1.1.4 dual boot]]&lt;/div&gt;</summary>
		<author><name>Shad00w</name></author>
		
	</entry>
	<entry>
		<id>https://www.theiphonewiki.com/w/index.php?title=Unsolved_problems&amp;diff=6863</id>
		<title>Unsolved problems</title>
		<link rel="alternate" type="text/html" href="https://www.theiphonewiki.com/w/index.php?title=Unsolved_problems&amp;diff=6863"/>
		<updated>2010-07-10T16:22:25Z</updated>

		<summary type="html">&lt;p&gt;Shad00w: Adding link for iOS 4.0 patching page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Use your imagination; what do you want?&lt;br /&gt;
&lt;br /&gt;
==Exploits Needed==&lt;br /&gt;
* [[Unlock 2.0|3G iPhone Baseband]] - Partly done ([[ultrasn0w]] uses [[AT+XLOG Vulnerability]] which is available in all versions until 04.26.08)&lt;br /&gt;
* [[Baseband Bootrom|iPhone 3G Baseband Bootrom]] (breaking the chain of trust)&lt;br /&gt;
* &amp;lt;del&amp;gt;[[S5L8720|iPod Touch 2G S5L Bootrom]] (breaking the chain of trust)&amp;lt;/del&amp;gt; - Done ([[0x24000 Segment Overflow]])&lt;br /&gt;
* [[S5L8920 (Bootrom)|iPhone 3GS Bootrom]] (breaking the chain of trust or finding a way to write LLB without using an iBoot exploit)&lt;br /&gt;
&lt;br /&gt;
==Work to be done==&lt;br /&gt;
*[[iPhoneLinux|Port Linux to the iPhone]] [http://www.iphonelinux.org/]&lt;br /&gt;
**[[Port (Google's mobile os) to the iPhone]]  [http://code.google.com/android/ Android Link]&lt;br /&gt;
*[[Increased Bluetooth Profile Support]]&lt;br /&gt;
*[[Patch iOS 4.0 to work on iPhone 2G &amp;amp; iPod Touch 1G)]]&lt;br /&gt;
*IP over iTunes&lt;br /&gt;
*Getting NMEA output from the GPS&lt;br /&gt;
*IPFW kernel extension&lt;br /&gt;
*Find out how to activate the Broad-comm radio/wireless N chip&lt;br /&gt;
&lt;br /&gt;
== Investigation ==&lt;br /&gt;
*[[Research: Pwnage Patches]]&amp;lt;br&amp;gt;&lt;br /&gt;
*[[Research: Re-allowing unsigned ramdisks and boot-args with the 2.* iBoot]]&lt;br /&gt;
*[[2.0 and 1.1.4 dual boot]]&lt;/div&gt;</summary>
		<author><name>Shad00w</name></author>
		
	</entry>
</feed>