|
楼主 |
发表于 2007-10-12 09:36
|
显示全部楼层
上文中提到的一个具体的操作方法在这里...
- L5 t7 ]- N* E% _* }/ t: k( g1 d% f! r
- i7 R7 @' R) V. s: F
[size=120%]DowngradingBaseband How to Downgrade screwed up baseband 4.0 (after anySIM and 1.1.1 firmware upgrade).
# y! \# L6 a6 H& j2 t ; e3 \, ~) D: {
UNBRICKING 1.1.1 UPGRADEHere's the procedure to downgrade after you upgraded (by mistake) to firmware 1.1.1 on a anySIM unlocked iPhone.
( q6 _# [9 Y4 D9 G6 ?/ b2 b& f) a* IHOW TO0. Download iPhone 1.0.2 firmware from Apple Here * |- H& `7 _% d, Q. G/ M
1. Change ipsw to zip then unpack it.
2 ^3 \: J4 k0 V# _ f, D( f
5 H+ ]4 V" b4 J% c4 K% s; A2. Extract the ramdisk file from it by typing + Q! S$ R! t6 `8 k
dd if=009-7698-4.dmg of=ramdisk.dmg bs=512 skip=4 conv=sync9 |% M6 \% U0 G7 E" v
8 q1 d2 J( s: x' M: t* A7 Z3.Mount the ramdisk by double-clicking it (on Mac). On Windows use someHFS tools to peek inside it or get the files from someone who extractedit already. : |. W% K0 w6 _6 H4 b
1 M r) L: [( h1 U% l6 {% h4. Put your phone into DFU modeand do option-restore in iTunes. This will reflash everything to 1.0.2.You will get an error at the end because it couldnt reflash thebaseband. You will end up with a yellow triangle.
2 B: l8 H; n F3 r* |3 i: X: d
) x, V! `; ]9 C3 j5.Quit iTunes, launch iNdependence then quit it again. Now relaunchiTunes. Press the power button on the iPhone for 3-4 seconds. Afterabout 10 seconds you end up on the activation screen.
$ Z+ }) L1 r: E/ V' a/ Q: s$ v) J
% j; U3 P9 A3 X9 w0 V+ V3 k, \8 y' i6.Complete the baseband downgrade by jailbreaking/activating, installingSSH on to the iPhone etc. There are tons of wiki's about that so Iwon't repeat. (Probably also true for step 4 and 5.)
3 G$ a2 ]+ U7 J7 \) x' h7 P( g
! g- @/ P8 o. p5 c; u7. Extract the baseband firmware and EEPROM files of 3.14 from the ramdisk of firmware 1.0.2. The files are named ICE03.14.08_G.eep and ICE03.14.08_G.fls and are located under /usr/local/standalone/firmware. / @8 c4 T. l( c. `: x% H
+ F2 s) U* Q; I# ]) H" t1 c
8.Get the secpack of baseband firmware 4.0 (some people have that, I haveno idea how they got it but its needed). I can't give that one outunfortunately. Name it "secpack". * z! J" y$ A' Z
8 G! M* p+ p( U' G
9. Download iEraser2 here or from Geohot's blog. 1 m' L( |) W3 n8 \6 n1 o
# {$ {# R o+ S5 @7 \10.Install all the tools onto the iPhone (I use the location/usr/local/bin.) You need to have SSH access to the 1.0.2 firmwareiPhone and upload iEraser2, the secpack, ICE03.14.08_G.eep, ICE03.14.08_G.fls and anySIM 1.0.2.
7 U% N/ |9 ]+ s- |1 L R0 ?3 E0 L# R( C1 O: `3 n
11. SSH to the phone. Stop CommCenter by typing:
3 ^! }' s7 |4 ?# |2 Tlaunchctl remove com.apple.CommCenter12. Now run:
! Z6 {8 C W% H8 Vbbupdater -vIt will tell you you run version 4.01 of the baseband. "bbupdater" is a tool by Apple which is also on the ramdisk. 8 V/ P/ l' x% b* A- n. j
5 f4 ~) c" r( N9 A6 e- U0 ]13. run iEraser2. This will WIPE your baseband, given a file "secpack" is in the same directory and this is a version 4 secpack.
6 ?* d: o+ X% R) h$ {4 u0 z, s) N1 `% E) ~4 [
14. Run the bbupdater command again:
; C# v. t' l7 j$ D: R9 Ubbupdater -vThis time it will not find any baseband firmware
3 S/ t* \0 t% _1 d, q, a7 T; ^: I7 B- W7 _0 M' N
15. Now do: 4 h, p3 U! r I6 v) s1 P( `* ^
bbupdater -e ICE03.14.08_G.eep -f ICE03.14.08_G.flsThis will flash the 3.14.08 baseband firmware back to the iPhone.
) Z0 I5 ^3 ^- D& ]4 e6 Y& H
! I; V- K6 Y1 z% s16. Now check to make sure it worked: + s% o' I1 g" O( ^, a1 T* W
bbupdater -vIt should tell you the version is 3.14
$ B0 P! W7 w0 e! VAtthis point you will still have an IMEI number starting with 004999...and its not of use yet. So still bricked but at least downgraded toversion 3.14. $ a/ T! W d$ |' s
9 |+ L' w, ~, ^' s* j% L
17. run anySIM Version 1.0.2 (note that older versions might not be good here as 1.0.2 has a lot of fixes for this kind of stuff).
- U3 J" e8 s4 o: S. oNow you have an unlocked 3.14 baseband with IMEI being your original one!
2 o$ ]8 C5 k1 |# y3 e9 v2 uCongratulations you now fully recovered from your botched update to 1.1.1 and are back to 1.0.2. 2 j$ I: u+ O" N( S; a9 l) m' N
You can stop here if you want to remain unlocked with iPhone firmware 1.0.2 with working phone. | Do you want to completely virginize and remove all traces of anySIM?Simply do:
) J: J* g Y" M% ulaunchctl remove com.apple.CommCenterTo stop commCenter
9 A- r* D" a' i! E# {( }then do: ) m5 S0 z" O2 ?+ b9 ]
bbupdater -e ICE03.14.08_G.eep -f ICE03.14.08_G.flsThis will reflash the "locked" version of the baseband removing any sign that anySIM ever touched your phone. Enjoy! 8 s. y( T9 t* ?, b% F5 P, R
Ifyou don't want to pay for iPhoneSIMFree to have a less ...bad... unlocksolution then stay tuned as we are actively working on our own safeunlock for both 1.0.2 and 1.1.1! + O0 e% o2 t$ f0 {' F
A tool automating all this is in the workings.... $ X" V. ^6 H" r
Discuss this here: http://rdgaccess.com/iphone-elite/viewtopic.php?t=27 |
-
-
ieraser
19.11 KB, 下载次数: 654
相关的软件 ieraser2
|