- Find a new iBoot exploit - This will allow us to decrypt the platform iBoot and other firmware files in it's IPSW, as well as dump the bootrom to examine.
- Find a new bootrom exploit - After we have the bootrom dumped, we must look for a way to make SecureROM run our patched LLB.
How to check for 0x24000 Segment Overflow exploitability (Mac)
As the device has not been released yet, and we only know of it's existance because of various references to "iPhone2,1", this might not work for it. But for previous devices, and hopefully this one too, you can do this:
- Put the device in DFU
- Open Applications/Utilities/System Profiler
- Go to "USB" on the left sidebar
- Click on "Apple Mobile Device (DFU Mode)"
- Look under "USB Serial Number". Among things like the Chip ID, there should be "iBoot Version"
- If "iBoot Version" is "iBoot-240.4", then that means it is most likely still vulnerable