GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering


GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 04-23-2011, 12:17   #1 (permalink)
No Life Poster
 
Join Date: Feb 2009
Posts: 2,370
Member: 972745
Status: Offline
Sonork: 100.1627715
Thanks Meter: 216
BruteForce iPhone NCK


Is it possible to use a similar technique in used with sl3?

can't we dump baseband and decrypt it as it may contain the nck?

flashing a modified baseband? which allows the nck to be read and lead to a permanent unlock
  Reply With Quote
The Following User Says Thank You to shak360 For This Useful Post:
Old 04-23-2011, 12:26   #2 (permalink)
No Life Poster
 
rkinfo_khan's Avatar
 
Join Date: Feb 2009
Age: 43
Posts: 838
Member: 978268
Status: Offline
Thanks Meter: 83
may be or maybe not , in future lets see
  Reply With Quote
Old 04-23-2011, 13:39   #3 (permalink)
No Life Poster
 
Join Date: Feb 2009
Posts: 2,370
Member: 972745
Status: Offline
Sonork: 100.1627715
Thanks Meter: 216
Yeah'
it would be good if some teams from mobile boxes could give a hand?
  Reply With Quote
Old 04-23-2011, 15:11   #4 (permalink)
No Life Poster
 
angel25dz's Avatar
 
Join Date: Jul 2006
Location: ..::DZ-25::..
Posts: 529
Member: 315181
Status: Offline
Sonork: 100.1593455
Thanks Meter: 301
Quote:
Originally Posted by shak360 View Post
Is it possible to use a similar technique in used with sl3?

can't we dump baseband and decrypt it as it may contain the nck?

flashing a modified baseband? which allows the nck to be read and lead to a permanent unlock
not so easy as u think, security in Iphone is much stronger than SL3, there is many common things between SL3 and Iphone : RSA1024, SHA1, Unique Value ...etc

take a look here : Dogbert's Blog: How to protect better: The Apple iPhone 2G

./br
  Reply With Quote
Old 04-23-2011, 15:23   #5 (permalink)
No Life Poster
 
Boshko_Alfa's Avatar
 
Join Date: Mar 2007
Location: Skopje, Macedonia
Age: 36
Posts: 4,244
Member: 472933
Status: Offline
Sonork: 100.1590967
Thanks Meter: 1,331
Donate money to this user
I think is not possible, b`coz iphone security is on server based :/
maybe will be in near future possible to perm. unlock, but not via codes... i think with full dumping perm. never locked iphones via jtag and wrote security in locked...

and that is puritania
  Reply With Quote
Old 04-24-2011, 02:50   #6 (permalink)
No Life Poster
 
Join Date: Mar 2009
Location: Europe Wienna
Posts: 1,269
Member: 984046
Status: Offline
Thanks Meter: 255
Some comment from Fernando (DM3) would be really interesting...

Or Bph&Co...



BR


Haltec
  Reply With Quote
Old 04-24-2011, 03:27   #7 (permalink)
No Life Poster
 
Gecko_UK's Avatar
 
Join Date: Feb 2009
Posts: 851
Member: 961957
Status: Offline
Sonork: Jabber: [email protected]
Thanks Meter: 641
to even attempt to extract NCK you need baseband exploit to dump seczone

you can't just flash modified baseband as it's sigchecked

even if you somehow, magically managed to extract and bruteforce valid NCK.. Apple can issue new wildcardticket (via itunes server) and disable the unlock, unlike other handsets such as SL3 security .(. although AFAIK you can capture this using SAM's backup auth token feature, which recently users of factory unlocks purchased unofficaly are doing

read below: see if u can see more info on this around it's not a bruteforce but would, in theory allow semi-permanent unlock without additional software

Quote:
Wildcard Ticket Unlock Guide
IF YOU PAYED FOR THIS TYPE OF UNLOCK DEMAND A REFUND!!! THIS IS FREE TO THE MASSES!!!

This guide might become obsolete soon, I will try to implement this into a GUI so that it will become faster and less risky.
FOR THE SAKE OF SANITY, MY UNLOCK USES A MINOR EDIT, NONE OF THE EXPLOITS USED ARE NEW. YOU NEED TO BE JAILBROKEN, ALL THIS DOES IS CREATE A TEMPORARY TOKEN TO UNLOCK. NOT A TRUE NCK BRUTEFORCE UNLOCK, BUT STILL MORE ADVANCED THAN ULTRASN0W.
Jailbreak for READ/WRITE ACCESS
SecZone- patch lockdown.
Baseband- deactivate.
Direct to:
0x010-0x090 Public Key (RSA Key 3)
0x80 byte
0x0 Total length of the policy table in bytes
<Policy Item>
0x0-0x2 ID
0x2-0x4 type?
0x4-0xC IMSI mask

Activate Seczone lock down patch to allow IMSI Wildcard.plist EDIT
Go to: /var/root/Library/Lockdown/activation_records/wildcard_record.plist at this point the patch should allow you to find the IMSI Mask. You need to find these values.
YOU SHOULD SEE EITHER OF THE FIRST (2) VALUES [If you have the third value (aka the unlocked value) I have one question. Why the hell are you reading this guide?]
==>AT&T USA
IMSI Mask
310150?????????
310170?????????
310410?????????
311180?????????
310980?????????
==>T-Mobile Germany
IMSI Mask
26201??????????
26201??????????
26201??????????
All restrictions should be off at this point and the SecZone should have full read/write access via Modem. Copy and Paste from plisteditor will work as long as the baseband is deactivated. So change the values to that of a factory unlocked iPhone. The NCK BruteForce method can attain the actual key to create a pseudo Factory Unlocked Device that can stay unlocked via updates, this edit method makes your iPhone think that it is unlocked via a fake sig checked activation token (NOTE: RESTORES AND SYNC RESTORES WILL DEFAULT BACK TO THE ORIGINAL CARRIER SETTINGS! YOU WILL LOSE YOUR UNLOCK!)
At this point you change the values of the IMSI Mask to that of a Factory Unlocked Device.
==> Unlocked Device
IMSI Mask
???????????????

Reactivate Baseband. Signature token will activate phone via baseband and your phone will be unlocked

Last edited by Gecko_UK; 04-24-2011 at 03:35.
  Reply With Quote
The Following 2 Users Say Thank You to Gecko_UK For This Useful Post:
Old 04-24-2011, 04:53   #8 (permalink)
Insane Poster
 
Join Date: Nov 2007
Posts: 75
Member: 636340
Status: Offline
Thanks Meter: 110
that guide is obvious BS - modifying the lock table breaks the signature so a tempered ticket will be discarded.
  Reply With Quote
Old 04-24-2011, 06:37   #9 (permalink)
Insane Poster
 
Join Date: Apr 2005
Location: Asia.canada.Usa
Posts: 81
Member: 141400
Status: Offline
Sonork: 100.1621275
Thanks Meter: 352
//no cannot
//yes can
  Reply With Quote
Old 04-24-2011, 08:16   #10 (permalink)
Cheater -Don't Deal with him-
 
::gsmcoder::'s Avatar
 
Join Date: Aug 2005
Location: /%%temp%%.;adb
Posts: 3,652
Member: 172434
Status: Offline
Sonork: 100.161280
Thanks Meter: 577
Simple theory, apple can can regenerate a new wildcard and block any nck based unlock due to alt-lo algorithm
  Reply With Quote
Old 04-24-2011, 09:24   #11 (permalink)
No Life Poster
 
yousha's Avatar
 
Join Date: Nov 2002
Age: 43
Posts: 1,503
Member: 17689
Status: Offline
Sonork: 100.72392
Thanks Meter: 737
Quote:
Originally Posted by s400py View Post
that guide is obvious BS - modifying the lock table breaks the signature so a tempered ticket will be discarded.
Correct and the biggest mystery is IPHONE-4 seczone dumper which was not working previously But Musclenerd twitted about it sometime ago that he managed to get it working and the idea behind it is

dump seczone before factroy unlock
dump seczone after factory unlock

than work for offline BF flow but there is no nck (that unique code which we think like sl3)at all in iphone factory unlocking its just legit wildcard

Wildcard=When activating an iPhone, the ticket is pulled from Apple's server and stored on the device. It contains all the information about sim-/netlocks. Factory- and carrier-unlocked devices receive a wildcard ticket with policies that permit all SIM cards.)

Similar argument i had on Twitter where people asking if i can preserve FactoryUnlock with (SAM) thing and misinterpreted my twits as SAM not working But actual thing is SAM is working for Now but if apple relock the device somehow in that case it will not work reason is same (seczone not accessible )

iphone factory unlock hit direct to seczone rewrite and save token to seczone via itune than itune just verify if imei allowed to get nck or not if got means its factory unlock and allow wildcard with imei


And i have no doubt about that in our forum we have that potential Bph&Co,DM3,DEJAN,CINEK,ZULEA,SARAS,LASER,FLORIN many other to name who can bring down the iphone protection in days (just depends on interest)

wbr
  Reply With Quote
Old 04-24-2011, 19:12   #12 (permalink)
No Life Poster
 
[Shadab_M]'s Avatar
 
Join Date: Mar 2006
Location: .: India :. Heaven on Earth
Posts: 2,496
Member: 238812
Status: Offline
Sonork: 100.1602669
Thanks Meter: 1,443
Means if we can write own signed Tickets then it will unlock permanently without any restrictions?

Br,
Shadab Ahmad
  Reply With Quote
Old 04-25-2011, 04:47   #13 (permalink)
Insane Poster
 
Join Date: Nov 2007
Posts: 75
Member: 636340
Status: Offline
Thanks Meter: 110
seczone/nck and wildcardticket are two separate unlock mechanisms. for either, you need either a private rsa key for generating a valid certificate or a hash collision for not breaking it.
dumping the seczone is trivial if the baseband is exploitable, e.g. custom code can be executed.
  Reply With Quote
Old 05-02-2011, 15:59   #14 (permalink)
No Life Poster
 
Join Date: Feb 2009
Posts: 2,370
Member: 972745
Status: Offline
Sonork: 100.1627715
Thanks Meter: 216
couldn't we use custom firmware or tiny umbrella to spoof some of this? like the unlock token? or maybe use custom firmware fkash baseband to a lower version??
  Reply With Quote
Old 05-02-2011, 19:00   #15 (permalink)
No Life Poster
 
Salami1_1's Avatar
 
Join Date: Apr 2001
Posts: 1,596
Member: 3941
Status: Offline
Thanks Meter: 636
Quote:
Originally Posted by shadab_a4u View Post
Means if we can write own signed Tickets then it will unlock permanently without any restrictions?

Br,
Shadab Ahmad
yes, only is done with 1024bit key..
  Reply With Quote
The Following 2 Users Say Thank You to Salami1_1 For This Useful Post:
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Bosh 909 - Without NCK signal Moc Various 2 10-23-2001 05:20
NCK Mambo3 help needed Blartiartfast Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 2 05-22-2001 23:25
New Siemens x35 Nck Code Generator Michel Main Sales Section 0 10-02-2000 23:41
NCK code sergioSLO Nokia Legacy Phones ( DCT-1 ,2 ,3 ,L ) 0 08-29-2000 17:45
ERICSSON NCK & NSCK code after 99W20 ptkrf Old Ericsson Phones & Sony Phones 1 06-03-1999 22:17

 



All times are GMT +1. The time now is 15:05.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.28271 seconds with 9 queries

SEO by vBSEO