Care Unlock  
Your online unlock store
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   GSM-Forum > GSM Mobile / Tablets Brands -Software Area- > iPhone ,iPod & iPad (Apple Inc. Products)

iPhone ,iPod & iPad (Apple Inc. Products) iPhone 2G / 3G / 3GS / 4 / 4s / 5 , iPod , iPad / II / New, Apple TV and All Apple Inc. Products goes here

Reply
 
LinkBack Thread Tools Display Modes
Old 05-07-2012, 12:21   #1 (permalink)
No Life Poster
 
iqballk's Avatar
 
Join Date: Jul 2002
Location: sri lanka
Age: 28
Posts: 1,197
Member: 13932
Status: Offline
Sonork: 100.1609876
Thanks: 40
Thanked 329 Times in 167 Posts
Lightbulb Iphone Activation Patch..!

hello ppl,

i want to share some interest information regarding iphone unlock, it means ACTIVATION PROCESS.

when we come to Activation, a file called xxx.plist created in var\root\Library\Lockdown\activation_records folder. xxx is your SIM's 19 digit ICCID.

this plist file contain encrypted activation records which identified locked or unlocked.

let me explain, i have an iphone 4 which is locked to AT&T network. its 5.01 jailbreak state. i have deactivate nd reactivate it with AT&T Sim, backup xxx.plist file via iphone folders. install SAM module. activate with my local network sim. again backup xxx.plist file. now my phone works with my local network sim.

again i deactivate nd reactivate with AT&T sim. this time, phone could not accept my local network sim. i replace xxx.plist file dt was backuped after SAM method.viola.. now iphone accept my local network sim.

may be it possible to unlock or patch activation data by decrypting this plist file.

i heared, dt plutil.exe can decrypt plist files into simple xml format. u can find plutil.exe from C:\Program Files\Common Files\Apple\Apple Application Support folder.

so.. i use this tool to convert xxx.plist file to xlm format via command line. but dt xml file contain same data as encrypted plist file. may be its only work with old ipod keychain.plist files.

its possible to unlock if we can decrypt this plist file's data.

any idea's welcome..!
  Reply With Quote
The Following 4 Users Say Thank You to iqballk For This Useful Post:
Old 05-07-2012, 13:47   #2 (permalink)
Freak Poster
 
Join Date: Jul 2010
Location: Mandaue City, Cebu, Philippine
Posts: 199
Member: 1348264
Status: Offline
Thanks: 9
Thanked 18 Times in 18 Posts
anyone tested this?can you simplify your explaination...thanks
  Reply With Quote
Old 05-07-2012, 14:26   #3 (permalink)
No Life Poster
 
iqballk's Avatar
 
Join Date: Jul 2002
Location: sri lanka
Age: 28
Posts: 1,197
Member: 13932
Status: Offline
Sonork: 100.1609876
Thanks: 40
Thanked 329 Times in 167 Posts
this is not a solution. its reversing.

plist
ICCID
Encryption
Decryption

you have to learn more to understand..,

regards..
  Reply With Quote
Old 05-07-2012, 14:48   #4 (permalink)
Freak Poster
 
Join Date: Jan 2010
Posts: 356
Member: 1198842
Status: Offline
Thanks: 5
Thanked 167 Times in 61 Posts
it is decy. with 2034 bit, if you want to use normal PC to read the code, then you need more than 1 bilion years.

unles you have the code.
  Reply With Quote
Old 05-07-2012, 15:30   #5 (permalink)
Freak Poster
 
SanjanMobile's Avatar
 
Join Date: Jul 2006
Age: 34
Posts: 245
Member: 316292
Status: Offline
Thanks: 392
Thanked 71 Times in 43 Posts
Your local sim accept, can u explain me network comes or not, if there are network, can u call by your iphone
Explain more
  Reply With Quote
Old 05-07-2012, 16:08   #6 (permalink)
Junior Member
 
Join Date: May 2012
Location: NY
Posts: 9
Member: 1756657
Status: Offline
Thanks: 0
Thanked 0 Times in 0 Posts
Quote:
Originally Posted by lbd2005 View Post
anyone tested this?can you simplify your explaination...thanks
agree
  Reply With Quote
Old 05-07-2012, 18:06   #7 (permalink)
No Life Poster
 
Join Date: Feb 2007
Location: East Or West India is the best
Posts: 973
Member: 457470
Status: Offline
Thanks: 409
Thanked 155 Times in 135 Posts
Quote:
Originally Posted by frake50 View Post
it is decy. with 2034 bit, if you want to use normal PC to read the code, then you need more than 1 bilion years.

unles you have the code.
private and public key are given too in the folder then rsa password can be cracked
  Reply With Quote
Old 05-08-2012, 05:28   #8 (permalink)
No Life Poster
 
iqballk's Avatar
 
Join Date: Jul 2002
Location: sri lanka
Age: 28
Posts: 1,197
Member: 13932
Status: Offline
Sonork: 100.1609876
Thanks: 40
Thanked 329 Times in 167 Posts
yes, have both keys.. theres no use of RSA. coz RSA depends on IMSI nd ICCID.

regards..
  Reply With Quote
Old 05-08-2012, 05:31   #9 (permalink)
No Life Poster
 
iqballk's Avatar
 
Join Date: Jul 2002
Location: sri lanka
Age: 28
Posts: 1,197
Member: 13932
Status: Offline
Sonork: 100.1609876
Thanks: 40
Thanked 329 Times in 167 Posts
Quote:
Originally Posted by satcable20055 View Post
Your local sim accept, can u explain me network comes or not, if there are network, can u call by your iphone
Explain more
yes.. it got signal too with SAM's trick (its done b4 apple close sam exploit).

regards..
  Reply With Quote
The Following User Says Thank You to iqballk For This Useful Post:
Old 05-08-2012, 10:16   #10 (permalink)
Super Moderator
 
stanner_austin's Avatar
 
Join Date: Jan 2004
Location: INDIA,Gujarat,Surat
Age: 28
Posts: 5,058
Member: 49752
Status: Offline
Sonork: 100.112446
Thanks: 104
Thanked 4,009 Times in 597 Posts
attached here decoded activationdata and activationcomplete plist from apple.
it don't use rsa or any high security in this activation stuff.
fareplay key is sign every time change on every request.
same as randomizer in both side.

really nice playing with apple activation hole till it was active.

Best Regards
Chevli
Attached Files
File Type: zip activation and reply both.zip (8.8 KB, 478 views)
  Reply With Quote
The Following 3 Users Say Thank You to stanner_austin For This Useful Post:
Old 05-08-2012, 10:26   #11 (permalink)
Junior Member
 
Join Date: May 2012
Posts: 3
Member: 1756925
Status: Offline
Thanks: 0
Thanked 0 Times in 0 Posts
if you want to use normal PC to read the code, then you need more than 1 bilion years.

http://forum.gsmhosting.com/iptch/156/Refurbished Apple iPhone 3GS (16GB) Black Color

Last edited by dangke; 05-08-2012 at 10:33.
  Reply With Quote
Old 05-08-2012, 11:55   #12 (permalink)
No Life Poster
 
iqballk's Avatar
 
Join Date: Jul 2002
Location: sri lanka
Age: 28
Posts: 1,197
Member: 13932
Status: Offline
Sonork: 100.1609876
Thanks: 40
Thanked 329 Times in 167 Posts
with a factory unlocked phone.. is still fareplay signing every request..?

nd can u confirm plist file from activation_records contain that phones lockstate table..?
  Reply With Quote
Old 05-27-2012, 11:53   #13 (permalink)
Freak Poster
 
Ta@of!k's Avatar
 
Join Date: May 2012
Location: AsanSam-inG!
Posts: 136
Member: 1754434
Status: Offline
Sonork: 100.1603928
Thanks: 191
Thanked 37 Times in 21 Posts
• Similar
message
tampering
technique
was
used
in
iPhone4
01.59.00
ultrasn0w
• Apple
started
looking
for
this
message
tampering
(although
they
have
typos
all
throughout
their
debug
strings,
calling
it
"tambering")
• A
much
more
challenging
obstacle
on
the
iPhone4
was
the
hardware-*‐based
DEP
mechanism
(“crossbar”).
• As
soon
as
you
write
to
memory,
hardware
disables
all
execution
rights
for
the
address
range
containing
it
• The
solution
@planetbeing
and
I
developed
for
ultrasn0w
to
overcome
the
crossbar
is
detailed
in
the
iOS
Hacker's
Handbook
  Reply With Quote
Old 05-28-2012, 05:36   #14 (permalink)
No Life Poster
 
iqballk's Avatar
 
Join Date: Jul 2002
Location: sri lanka
Age: 28
Posts: 1,197
Member: 13932
Status: Offline
Sonork: 100.1609876
Thanks: 40
Thanked 329 Times in 167 Posts
Nice Copy paste..

no regards..
  Reply With Quote
Old 05-28-2012, 07:23   #15 (permalink)
Freak Poster
 
Join Date: Sep 2011
Age: 33
Posts: 152
Member: 1653961
Status: Offline
Thanks: 16
Thanked 9 Times in 9 Posts
iPhone activation ticket is encrypted with TEA using iPhone hardware signature (norID, HWID and most probably unique device ID). While unique device ID is easily available through iTunes when the phone is connected, norID and HWID is bit difficult to get. You need to be good in programming.
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
thread Thread Starter Forum Replies Last Post
I have Wintesla PKD-1 dongle schematic and activation file Gsmhq Nokia Hardware & Hardware-Repair Area 3 08-20-2004 10:11
Problem with Vibrator Activator Nokia 3210 Erik Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) 1 07-12-2000 21:17
Me need activator for TDF-4 NSE13 Alexey Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) 6 04-16-2000 20:00
How to activate Netmonitor in 8110i zfrank Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) 2 08-20-1999 08:19
Anyone have idea for activate netmon on 8110? .:Shorbagy Team:. Nokia Legacy Phones ( DCT-1 , DCT-2 , DCT-3 , DCT-L ) 0 06-13-1999 05:11


All times are GMT +1. The time now is 06:01.



Powered by Searchlight © 2013 Axivo Inc.
- GSM Hosting Ltd. - 1999-2013 -
Page generated in 0.40342 seconds with 12 queries

SEO by vBSEO