Home > News > OTB 1.1.2 iPhone unlock: Bootloader exploits!

OTB 1.1.2 iPhone unlock: Bootloader exploits!

You have probably heard that the Dev Team needs a 1.1.3 firmware update
for hacking 1.1.2 OTB. This could not be the case anymore!

2 theoretical exploits have been found on the new bootloader 4.6 !!
And you know what it means! 1.1.2 OTB Software unlock coming very soon!

Geohot reported that there are 2 possible exploits, hardware and software.
The next coming days should be decisive!

In the meantime, read this great tutorial for 1.1.2 OTB activation: click here

Read about the exploits in the extended post…

Hardware exploit:

The version check reads from 0xA0021000 and 0xA0021004 to get the version
of the main firmware. It then compares the values [0xA0021000]==~[0xA0021004].
If that check fails it ignores the version check. It is also the only bootloader access
into high flash. So when A16 goes high, pull any data line high or low.
That will cause the check to fail, and hence the version check to be skipped.
And they shouldn’t be any memory accesses in the bootloader, so it’ll be fine.

Software exploit:

This exploit is in the the way the secpack signature is padded.
They did a lot to remove the really bad signature checking of the old bootloader
that IPSF exploited. Although the secpack still has 0×28 bytes of data at the end
that isn’t checked for normal secpack sigs. The secpack sig is(0×30 header/padding,
0×14 main fw sha, 0×14 secpack sha, 0×28 unchecked padding).
So by spoofing the first 0×58 of the RSA, you can set any secpack and main fw sha hash
you want. It is very easy in exponent 3 RSA cryptosystems to spoof the first 1/3 of the
message bytes. With some clever math and brute force, the whole 0×58 can be spoofed.

Those findings have been reported by Geohot.

Share this post!

http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/digg_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/reddit_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/stumbleupon_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/delicious_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/technorati_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/magnolia_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/google_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/facebook_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/yahoobuzz_48.png http://www.macgeekblog.com/wp-content/plugins/sociofluid/images/twitter_48.png

Advertise!


Earn money - Accomplish a freelance project


Freelance Jobs

Related Posts

Categories: News Tags:
  1. luis
    December 1st, 2007 at 17:18 | #1

    Great News! Maybe my iPhone will find another use rather than to be used as a super iPod touch… let’s wait and see..

  2. Tim
    December 1st, 2007 at 17:51 | #2

    How many day’s (from now).Do you think they (the hackers) need to software unlock the new bootloader 4.6, without apple their new update. So we can unlock our iphone’s without waiting for apple’s new update. So we can begin making calls.

  3. Tim
    December 1st, 2007 at 18:03 | #3

    Or weeks (I hope day’s).

  4. R
    December 2nd, 2007 at 00:10 | #4

    I will donate 50 EUR if this is happening before christmas!

    thx for all the genius work of these guys!

  5. Martin
    December 2nd, 2007 at 02:32 | #5

    I also will donate 25€ then, to the dev team.

  6. matl1990
    December 2nd, 2007 at 04:38 | #6

    YES!!!!!!!!!!!!!!!YES!!!YYEESSSSS!!!!!!!!OMG! thank you. ive been waiting for this for a long time. ill give my life for u to unlock my otb 1.1.2 iphone. please pple. im begging u

  7. December 2nd, 2007 at 20:35 | #7

    You guys want an official Apple unlock to be safe for the next coming firmware upgrades. Read this post: http://www.macgeekblog.com/blog/archive/2007/12/02/otb-1-1-2-iphone-unlock-donations-needed.html

  8. nuthinbetta2do
    December 3rd, 2007 at 21:43 | #8

    Will this method unlock U.S. phones?

  9. December 3rd, 2007 at 21:55 | #9

    The goal is to unlock OTB 1.1.2 UK/FR/DE/US iPhones.

  10. giz
    December 29th, 2007 at 04:04 | #10

    is it now possible to unlock otb 1.1.2? where can I get more info?

  1. No trackbacks yet.
You must be logged in to post a comment.
blog comments powered by Disqus