d_bug
09-02-2007, 05:59
Since iphone is unlocked from here: http://iphonejtag.blogspot.com/
i think it time to gather ideas, put it together and make thing easier for us.
first, as written by author: http://iphonejtag.blogspot.com/2007/08/some-comments-on-method.html
Thursday, August 23, 2007
Some Comments on the Method
This method is very similar to the method used to unlock the Siemens phones with the S-Gold2 chipset. The S-Gold2 has a bootrom which allows you to download a bit of unsigned code. This code is run if certain flash addresses are blank. Using a little hardware trick, which I'll explain later, we make them appear blank. Then once we have unsigned code running on the baseband, we can download a modified firmware, with the unlock patched in, to the nor flash. The signature checks only cover this region while it is being downloaded the first time. Once the code is on the NOR we can do whatever we want. So patch out the PN lock; Voila, unlocked iPhone.
Posted by George Hotz at 6:23 AM
hmmmmm......... does it sound familiar? yeah of course if your doing s-gold based siemens and papuas soft. i'm no programmer :D and i don't know how it is implemented on papuas soft but the method seems similar eventhough it is on more advance version of s-gold (s-gold2). The above method applies patched chunks onto the firmware as explained, whereas on papuas, bootpassword is calculated and unlock keys is retrieved and injected. I don't know but maybe, just maybe infineon hackers can do something similar for iphone - we're waiting.
another way could be patched firmware update, ala HTC style upgrading :D.
as said here, values that are valid:
http://iphonejtag.blogspot.com/2007/08/allowed-mccmncs.html
these are allowede values:
310 United States 150 Cingular Wireless
310 United States 170 Cingular Wireless
310 United States 410 Cingular Wireless
311 United States - 180 Cingular Wireless
310 United States 980 AT&T Wireless Services Inc
and of course 001-010 :D
if main firmware can be reversed and mcc+mnc is checked here, then work could have been easier.
please add your crazy ideas here and lets hope those experts notice this thread. :D:D:D
the race now is on permanent and SOFTWARE based unlock.
who will be the FIRST???
i think it time to gather ideas, put it together and make thing easier for us.
first, as written by author: http://iphonejtag.blogspot.com/2007/08/some-comments-on-method.html
Thursday, August 23, 2007
Some Comments on the Method
This method is very similar to the method used to unlock the Siemens phones with the S-Gold2 chipset. The S-Gold2 has a bootrom which allows you to download a bit of unsigned code. This code is run if certain flash addresses are blank. Using a little hardware trick, which I'll explain later, we make them appear blank. Then once we have unsigned code running on the baseband, we can download a modified firmware, with the unlock patched in, to the nor flash. The signature checks only cover this region while it is being downloaded the first time. Once the code is on the NOR we can do whatever we want. So patch out the PN lock; Voila, unlocked iPhone.
Posted by George Hotz at 6:23 AM
hmmmmm......... does it sound familiar? yeah of course if your doing s-gold based siemens and papuas soft. i'm no programmer :D and i don't know how it is implemented on papuas soft but the method seems similar eventhough it is on more advance version of s-gold (s-gold2). The above method applies patched chunks onto the firmware as explained, whereas on papuas, bootpassword is calculated and unlock keys is retrieved and injected. I don't know but maybe, just maybe infineon hackers can do something similar for iphone - we're waiting.
another way could be patched firmware update, ala HTC style upgrading :D.
as said here, values that are valid:
http://iphonejtag.blogspot.com/2007/08/allowed-mccmncs.html
these are allowede values:
310 United States 150 Cingular Wireless
310 United States 170 Cingular Wireless
310 United States 410 Cingular Wireless
311 United States - 180 Cingular Wireless
310 United States 980 AT&T Wireless Services Inc
and of course 001-010 :D
if main firmware can be reversed and mcc+mnc is checked here, then work could have been easier.
please add your crazy ideas here and lets hope those experts notice this thread. :D:D:D
the race now is on permanent and SOFTWARE based unlock.
who will be the FIRST???