Decrypting Firmwares

From The iPhone Wiki
Revision as of 14:09, 12 April 2009 by AriX (talk | contribs)
Jump to: navigation, search

Ramdisk on 3.x firmware (currently beta release) is a simple img3 file, that you can decrypt using img3decrypt or xpwntool. So you must download this utility. For easier access, put them in /usr/local/bin

In Terminal.app enter:

img3decrypt e restore_ramdisk.dmg restore_ramdisk_decrypted.dmg Ramdisk_IV Ramdisk_Key

Where restore_ramdisk.dmg is image of restore ramdisk (for example 3.0 beta 1 iPhone GSM firmware restore ramdisk is 018-4793-1.dmg), and restore_ramdisk_decrypted.dmg is decrypted image, that you can mount and explore from Finder. Ramdisk_IV and Ramdisk_Key is a decrypted keys that you can find in vfdecrypt page or in Info.plist from PwnageTool FirmwareBundles folder (when Dev Team include support for this firmware).