Difference between revisions of "X-Gold 608 Unlock"

From The iPhone Wiki
Jump to: navigation, search
(Class 2)
Line 1: Line 1:
Currently, the 3G (software) [[unlock]] which is not baseband-dependent is the biggest missing piece of the iPhone community. It is more difficult than the previous unlocks due to the fact that the [[Baseband_Bootloader | baseband bootloader]] is signature checked. the devteam has successfully unlocked all baseband versions until 02.11.07, by a somehow patching the baseband on-the-fly (in RAM), therefore at boot the baseband bootrom can validate the bootloader, the bootloader can validate the baseband, and not until after the boot up will it be patched. The unlock is planned to be released in New Years Eve before 2009 (31.12.08). [http://blog.iphone-dev.org/post/65126957/tis-the-season-to-be-jolly]
+
Currently, the 3G (software) [[unlock]] which is not baseband-dependent is the biggest missing piece of the iPhone community. It is more difficult than the previous unlocks due to the fact that the [[Baseband_Bootloader | baseband bootloader]] is signature checked. [[The dev team]] has successfully unlocked all baseband versions until 02.11.07, by a somehow patching the baseband on-the-fly (in RAM), therefore at boot the baseband bootrom can validate the bootloader, the bootloader can validate the baseband, and not until after the boot up will it be patched. The unlock (called [[yellowsn0w]]) is planned to be released in New Years Eve before 2009 (31.12.08). [http://blog.iphone-dev.org/post/65126957/tis-the-season-to-be-jolly]
   
 
==Possible Methods==
 
==Possible Methods==
Line 8: Line 8:
 
===Class 2===
 
===Class 2===
 
* Use a [[SIM hacks|SIM hack]] such as the [[Unlock iphone-3G with TurboSim|TurboSIM Unlock]]
 
* Use a [[SIM hacks|SIM hack]] such as the [[Unlock iphone-3G with TurboSim|TurboSIM Unlock]]
* Find a way to patch running memory to "unlock" the phone on every bootup. The [[dev team]] has accomplished this for basebands 1.45 through 2.11. See [[yellowsn0w]].
+
* Find a way to patch running memory to "unlock" the phone on every bootup. The [[dev team]] has accomplished this for basebands 1.45 through 2.11.
   
 
==Resources==
 
==Resources==

Revision as of 17:09, 22 December 2008

Currently, the 3G (software) unlock which is not baseband-dependent is the biggest missing piece of the iPhone community. It is more difficult than the previous unlocks due to the fact that the baseband bootloader is signature checked. The dev team has successfully unlocked all baseband versions until 02.11.07, by a somehow patching the baseband on-the-fly (in RAM), therefore at boot the baseband bootrom can validate the bootloader, the bootloader can validate the baseband, and not until after the boot up will it be patched. The unlock (called yellowsn0w) is planned to be released in New Years Eve before 2009 (31.12.08). [1]

Possible Methods

Class 1

  • Find an exploit in the bootrom to break the chain of trust
  • Improve by several orders of magnitude the NCK brute forcer, and find a way to extract the CHIPID and NORID
  • Find the theorized algorithm of NCK generation

Class 2

  • Use a SIM hack such as the TurboSIM Unlock
  • Find a way to patch running memory to "unlock" the phone on every bootup. The dev team has accomplished this for basebands 1.45 through 2.11.

Resources