|
9 \- b8 P5 d& w8 h3 e: W5 z6 B( p) H2 W! j) ~) F/ k: Y& W
UPDATED tutorial for PwnageTool 1.1. on MAC and Windows BETAThe Pwnage Tool 1.1 is OUT NOW!/ L/ H$ i; d5 n+ F& c
5 B# Y# a* O# @Mac Guide below! 1 F M! g: k- h7 t
2 f# h8 D$ l1 h2 l& I+ a: ]) P0 AWindows BETA IS OUT!6 M0 [# g- x- Y$ h* I
. Y& @0 i" R. f4 w3 J
includes FAQ now& O8 p9 X' m" a2 B
This thread is updated multiple times every day with the latest information! Latest update: Monday 21st April BST9 Q7 [/ X: Z6 U4 e7 j) D
; ^% y) V% A ?" L) Z" e7 B
* ~5 \) V( c$ d' j8 T4 N/ d1 bThis is a very simple process. Below is a detailed guideline with FAQ and solutions to possible problems.+ G2 u B- X* s! t0 U
& ~/ A* f3 K# c( p! }
At the most basic level all you have to do to make this work is:/ _3 H, z$ E9 b! \! b! a8 Y
5 S$ ^; D1 d4 Q# Z9 L3 ^% |1. Pwn your phone.1 o. n! | I( A! }5 R4 F
2. Make custom firmware.
$ _! _9 T% j, C' v( _& L3. Restore using custom firmware in iTunes.# j; H. @ o# i) X3 c& @) ?, T
http://www.youtube.com/watch?v=siuKQw6L6Rk&eurl=http://www.engadget.com/2008/03/29/video-of-the-iphone-pwned-project-in-action/
" Z' o3 i* R( C* a5 uThis took unlocks ANY firmware and activates it. 4 \. V/ m5 ]' G; B' U
# i6 w0 e! T( K( [7 _
It even allows us ALL to run the 2.0 beta (if we can find it online!)., |) r% R* h! A
& o2 ?' i' m5 p5 P- b" ] E IThis will replace all other tools such as iPlus/iLiberty+ and ZiPhone.
, s+ k" M) ~0 c4 n' o
$ u$ C9 [3 `/ ?" b$ H-----------------------------------------------------------------------------------
; [4 Q6 M5 J: C# u! I
0 a ?% _0 r2 TFAQ
0 | _+ K. `5 Y3 V- _' X/ M' d7 M6 v6 y5 X
' R3 ~) `( \/ J7 r- `: xITUNES ERROR MESSAGES - HOW TO FIX THEM - see below tutorial- M9 K8 g$ u8 f- i
4 V! a* d$ }0 t
WINDOWS BETA USERS IMPORTANT READ HERE! X: _" S" C- k' J, T% ]
3 U. B$ ]# U4 x" L- A5 I
Windows BETA version is OUT!' c9 |+ J) a: |1 g
http://www.winpwn.com/index.php/Main_Page
- h9 I+ |% b$ O; R/ l' lWhat does that mean?
5 q9 E6 @2 j! \! U; C T2 j; F- f
' z0 @. k6 a( q) i9 o& @ UBeta means that it may go wrong - it may crash - your iPhone/iPod may fail to restore or get stuck in a boot loop.
5 x2 K7 Q! m. L# W- J& ]& Y: O7 N1 O/ C$ z. k* L
Right now winpwn is MAINLY FOR JAILBREAKING and adding Installer.
8 L- X7 ? j1 |7 {2 z" n3 i
0 e; F; H8 _& wIt has disabled unlocking features to ensure further testing goes smoothly!
: Z! K3 a0 n* w8 w2 ?8 x
* ]0 i' |" z% _- iThis means you CANNOT unlock the iPhone using the windows version - However adding the installer source for BootNeuter will let you do that.
3 M! Z' p9 u' u+ `% z4 tEVERYTHING CAN BE FIXED BY RESTORING and recovery mode.8 H* X& E( T( t0 Y2 {% }: M0 o
4 t0 w* P4 ]8 }# X. ~3 h4 W- _Although it is for windows the buttons do the same and it works the same way.
w0 |- t3 t! }3 x0 C% G8 w
. X; ^$ i& S* D/ `4 _' qFollow the same steps below as on Mac (except some options will NOT be available in the beta and greyed out!: c3 v* L- C* ]3 i9 g- w- o
9 @; ?4 E* O7 Q0 u7 c$ \ E5 I9 I% A: _) Z/ h7 U3 n, k! F- b
It takes approximately 10 minutes to build the ramdisk for the "ipwner" part on Windows6 j1 I2 y% W4 ~
. d( q2 ^. u5 s7 Z9 _, H7 vIt takes approximately 15 minutes or so to build the IPSW on Windows
; \& d1 i0 K8 Z& p3 K; j( N: }/ M4 {9 w
NOTE: Once you pwn your iphone/ipod using winpwn you CAN download already made custom firmwares to install but this is not recommended as you do not know if the source is reliable.
) x' T* w1 v$ S5 h* x( Y$ { S$ K4 b; y! C1 L
To select custom firmware on PC - press SHIFT and click on the restore button in iTunes.
& Q9 t1 t; ~ {% k+ H& c' B! f, @. H2 D/ }6 x8 n. o
iLiberty+ is available for PC and can be used to put iPhone/iPod into recovery mode or kick it out of recovery mode should you need to.3 ?) a- n8 l& x7 V' y
9 ^& G) R5 N8 I. q3 c% ?
You will require the iTunesMobileDevice.dll in order for WinPwn to work and you will have to put it inside the winpwn program files directory - these can be downloaded from winpwn.com. , A; R8 c; g' W3 ~. G
) }. a1 ^: W1 {! A uThey would have to be put in "C:\Program Files\cmw\winpwn"3 J; H8 S" N( L- L7 q* v6 z% W
% d9 K! |5 C# d. B( R2 D----
. g; e# A6 J( M0 ~$ x9 Y# o/ j: t' n2 e( r: G% O9 w
Should you use this if I already used ZiPhone/iPlus/iLiberty+?! h3 L( \# Q+ F5 i# R
/ Z; P8 G0 r8 {; L. HIf your phone is working at this time then there is NO need to use pwnage.
; g b2 S6 z, F0 J. v7 F4 o
" [3 @7 I, k% ?2 B8 S$ _% a7 \Pwnage is a safer method for jailbreaking/unlocking/activating but unless you like
2 E) k5 }- L! b5 R% N+ Cmessing with new firmware then there is no reason to use it.+ }! W6 E/ ~: p8 P9 w
I/ k1 s; o; v+ p, m2 MHowever, none of the above apps will unlock/activate/JB 2.0 or any of its betas.
6 F- ?% F) w5 q' r6 S7 w
. U2 {* B# K. e# d! q% |So for the next firmware you will have to use Pwnage.) p2 j5 E2 E, n s% s
+ h! Y! p& x) ^7 V) H
If you wish to revert to your original bootloader you can using pwnage now!
' q6 [7 j/ }3 l6 @3 z; k& b$ i+ w X
iPhone or iPod Touch?. U" }* V# M5 I: G0 g h
2 e; F3 T' {4 n
Both work with Pwnage - for iPod instructions just use iPod restore files instead of iPhone files I mention below!; ]4 S H' H8 U k. A# |# `0 g
; P9 g3 Q% A6 C/ k0 Q- b* x \
PWNAGE does not add 1.1.4 apps or wiggly icons on iPod touch- you can get those through installer by adding the source: http://repo.ispazio.net or buy them through iTunes, ]2 L3 }/ C5 U6 H/ n
Is it for Windows and Mac?
+ ~- ~' q% r$ D* c1 e3 ]- a( q/ ` {9 G% c5 _3 `2 f4 n$ K7 n1 I. Z
Right now a full version is available for Mac. Windows is currently available for Beta Testing!5 V7 \" @$ Z6 `, ^! u: J
1 {$ ~' w. D# \4 F. ]9 \" ~Is it safer than ZiPhone/iLiberty+
) K- s& U: I: H- i* Y3 o4 m
9 Y f8 U5 M/ J3 nYes as it changes your file system BEFORE you restore and therefore avoids all the possible problems you can have with other methods.
6 x1 a" T( Y; ~+ s; h) U+ {! H+ y! C
Will Installer be added automatically? w( I! B+ W3 O9 _& E+ C* P1 g
, x+ M7 T2 z' \
If you rebuild the firmware using pwnage then 1.1.4 will have installer added to the firmware. Installer is not added to 1.2 or 2.0 beta firmware as it would not work at this time.
5 R: u' z5 N& T) G' u; z1 T$ B7 r% G7 e' B8 g# {
Can I just jailbreak ONLY?* E( W- t! |( x4 S0 U& C7 q. v
7 V0 x4 c% n: l2 j' O! \, C6 o; l
Yes - don't tick any boxes on the firmware options and it will ONLY jailbreak your phone.+ G; ?) X( m7 Z
% |, x7 n8 [: s; vHow do I pwn my phone?/ Q( V; m0 n% P) M. v! r& H* z
) S2 `5 l! o& L, @Video of process courtesy of Engadget.com :http://www.viddler.com/explore/engadget/videos/5/% {% W5 F+ F/ B; y" V6 x. w7 i! v
Download the pwnage tool from the pirate bay! Do a search for "PwnageTool.app"
1 O- v5 ]' a7 f9 v& }7 d+ `9 H5 [/ ?& b6 t/ f- @; \) `% [& F
You can download from the iPhone DevTeam site but it does not have the bootloader files you need and so it is easier to download
$ w& c Q( z1 y5 t$ C. Fa complete copy from torrents., Y1 x7 w0 C" Z
4 q9 c) I. u, l* P7 T! y
The download without the bootloader files (which you WILL NEED to use pwnage) can be found here:
, S5 P* X' {8 |5 `9 d$ ^
& m7 y* F9 j% u. d% P& z% }* F+ DBootloaders can be found at: http://www.hackint0sh.org/forum/show...t=36508&page=2
8 y- h/ V( a+ P- `) ~3 ^' m, h6 D5 T: t$ ~; a4 k6 r. m9 X
Apple Firmware files can be downloaded from:
- k M$ p0 }1 a7 C- h# Y. v; I+ |, b; i" d% L. A
iPhone:
& X7 N2 b; c5 v$ U/ zhttp://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-4313.20080226.Sw39i/iPhone1,1_1.1.4_4A102_Restore.ipsw
: ^6 O* [$ | f: H# f8 e( o' r; PiPod:
) q7 E+ ?2 g3 ~2 Q( @/ R) w+ B* S3 [http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-4312.20080226.Btu45/iPod1,1_1.1.4_4A102_Restore.ipsw
3 r6 Z: Y5 e7 P$ oONLY use iPwner on 1.1.45 X% N5 ]5 z3 y1 ^& e# i% R. p* ^
5 K) a3 C/ \6 `; r* W9 T9 Z4 _+ v; t
BEFORE YOU TRY ANY OF THE 2.0 BETA VERSIONS YOU MUST PWN AND UNLOCK/ACTIVATE WITH 1.1.4; k9 A- B( D' t& d* B$ s, i+ A5 m
3 u9 Y- m& o* C. S# u2 L" A
If you do not have 1.1.4 then RESTORE to 1.1.4 using iTunes (also to familiarise yourself with the restore process) as normal then run the pwnage tool.
r x: h( c/ [' w
+ J9 S- V: s. ~3 j- ]# z b, fYou can pwn your phone without restoring first from 1.1.4
! _& X- [$ a) }+ R; g4 Q& h/ k1 |4 z$ m$ h6 _/ @9 z
1. Click the "Browse .ipsw" button.
! v; p b4 Q/ s8 G8 U( o
4 Y) y7 o+ u- \2. Select the 1.1.4 restore - on mac it is in the
" T7 _# F3 E; f, u @: i' L
! x2 \& D9 ?# q6 R; ~# uUser (ie your name on your mac)>Library>iTunes>iPhone Software upgrade1 P0 ?$ y4 j, F. c3 A& v4 ~
; M& [) ~2 f' d' R: h
Then you just select the firmware. There is even an iPod folder so you don't get confused!
9 o8 Q: }9 ]9 n& j: D5 {) t& a; U' ]# @1 H
MAKE SURE YOU SELECT THE CORRECT FIRMWARE FOR YOUR IPHONE/IPOD.
" h2 A! J( y. d) k7 |4 I9 t/ c8 Q% [1 ]5 _* T, e: G) l
EXAMPLE: IF YOU HAVE A 1.1.4 IPHONE THEN PWN IT USING THE 1.1.4 IPHONE RESTORE FILE!
/ U# Y) N& E* W. M! S0 R1 Q n( ^3 S/ ]6 J
DO NOT USE A 1.1.4 IPOD RESTORE FILE ON YOUR IPHONE OR IPHONE ON YOUR IPOD- n \2 W2 n' H( v! c6 v5 `
/ a. g1 D. J k, `+ l5 f( z8 R. U
If you do not have it then connect your iPhone and click on restore and it will start downloading in iTunes. : q) d) G2 T4 E2 L4 G' `
* ?$ }% z* P; x/ g& B! h/ G- C
UNPLUG your iPhone as soon as it starts downloading as we DO NOT WANT to restore yet!
, p. L) x' y$ K* ~/ l& ^
1 E1 d4 G7 { P6 QOr download it directly from the above link.
, \+ g4 c. U9 I, d6 [4 G
. ^5 ^7 Y" J2 C( M ~* D i3. Once the 1.1.4 file has been seen by the pwnage tool then click on "iPwner"... You have to put your phone in restore mode to do this.
/ W& c3 ~/ X! n5 j
; {8 n; m' h3 l# D+ tWhilst connected to your computer turn off your phone. Hold down the home button and turn the phone back on - it will go into restore mode. You can tell this from the "connect to iTunes" logo that comes up. If you have problems getting into restore mode - then I suggest downloading iLiberty+ and looking at the advanced menu on the top left of the screen gives you the option of putting it into restore mode using that.2 j- i9 k* k& A* L
$ {$ c. t* x Y D+ C
iTunes will open when the phone enters restore mode. PwnageTool will detect iTunes is open and ask you to close it." J: l) h! {8 @* Z, P4 t
; v4 u4 G5 f3 ?5 b9 r
Just close it anyway when it pops up by exiting it from the mac taskbar - no need to wait to be told to close it by the tool!
" A9 E% ^6 V. B1 s8 F
' A# }9 J0 u8 k3 r4 j1 a' Q( \Once in restore mode Pwnage tool will do its magic!2 }# t) g/ n) z
) u w3 T0 q4 \# l# p; LYour phone will restart with a pineapple instead of the apple logo and then boot back into normal mode.
( y/ a0 D0 S8 d1 e) Q' H4 J5 X( l# i9 T% j& G6 i3 K% P6 C B
4. Click on "IPSW builder" button. Make sure that Pwnage tool will rebuild the 1.1.4 file for you. Make sure that Enable baseband update, Neuter bootloader, unlock baseband and activate phone are selected. If you wish to keep the pineapple logo then click on use custom images if not the apple logo will come back!
2 T ], H9 L" O' b1 z1 Y4 `0 |) }$ J; S. E7 U% q
When you upgrade to 1.2/2.0 iPhone or iPod - pwnage automatically selects the correct settings so you don't have to do anything! But DON'T uncheck anything checked in that situation!
# z( O( ~( z" h* g5 t
$ T5 W6 l7 {, `2 r3 r' B6 iPwnageTool 1.1 has added additional options for custom firmware creation.
2 L, E8 M- b6 k3 U: ` t
8 p; l( a! V/ y* j% j5 d; a& I* Y"General" Tab
* J+ u5 u- E2 M. ~! c) L8 M, z5 N; Q( d: |' B3 ^
IMPORTANT: There are reports that BootNeuter CAN NOT unlock the phone unless BSD Subsystem part of your custom firmware. YOU MUST ADD IT TO THE CUSTOM FIRMWARE TO AVOID ANY ISSUES!' Y3 ^4 e9 }; v! N0 `8 G
0 H0 ?* H0 j4 G! w1 h5 mNow includes "Auto delete BootNeuter.app" - This deleted BootNeuter after it has been run once.& I0 ?% I5 G- U7 F- q
+ ^1 i5 \. T" K# z) v& p1 Q wThis avoids accidently or malicious fiddling of your phone settings by third partys as after your phone is unlocked it is deleted automatically. (Note: If you wish to re-lock your phone at a latter
; @& z4 @0 p4 a; Idate you would have to restore again to a new custom firmware with auto-delete unchecked so you can reset the settings or download BootNeuter directly from Installer)' _9 v6 \' @6 i) w
9 n& K: W# ~$ p* {& g% i% o! [! ~$ c
"Custom Packages" Tab( K- u8 X+ G, d+ [6 o
3 I! x& r3 l# O# bThis allows you to add applications you would have to download through Installer or chose whether set-up Installer on your phone in the first place.1 c+ \& H |. x. _& l/ S, p
0 F- W1 h8 J8 q1 x$ Q$ k# A. R
BSD Subsystem: This package of tools is needed by MOST 3rd party apps so they can run correctly HOWEVER your Installer will not "see" it as installed so for your phone to see it as installed you need to add the big boss recommended and beta sources from the sources catagory. Then go into the system category and install "Fake BSD Subsystem" then exit installer and you can now install all apps without redownloading BSD again!8 `6 U' O. e5 z# j- Z
2 n% r- n" I7 {5 _4 fInstaller: This is the application that lets you locate by category and download and install all 3rd party applications with the touch of one button - it MUST be selected if you want 3rd party applications on your iPhone.0 K4 Y* e7 z. C
0 g" y) G" T7 _5 y
OpenSSH: This is a tool that allows you to wirelessly connect your iPhone to your PC/Mac and transfer files and run complicated command line applications. It is not required and not recommended unless you KNOW you need it for something first!. d" f4 i( S8 a
3 g! H, U/ L: q! l f8 k"Custom Logos" Tab
$ I3 g+ b/ S% N& n _ P* Q$ k# L8 f$ u5 L( ?! o( E
This allows you to select your own custom logos for when your iPhone/iPod starts up and for recovery mode. If you do NOT check the boxes then the standard Apple logos will be used.
3 T+ k# z9 c6 n- _2 E& k/ S j8 G! b8 I2 \, ~
If you leave the boxes checked then the pineapple and Steve Jobs images will be used.
. s; C( Z% _1 k7 H H1 P5 l: M# ?. s
You can select your own image for the firmware by clicking on "browse" and selecting your own image however it must be a PNG gile in RGB or Grayscale format with alpha channel present. The dimensions must be below 320x480 pixels. The size of the compressed image is limited to 100 Kb.
" @' k* |& p; |8 g% ?* ?
2 }' e% P- x/ k% u* h' qIF it asks for bootloaders see bottom of page for how to select them!' ~# z4 @ c$ d% `/ ~
8 W% u w3 i6 \. kPwnage will then make a custom firmware file and save it to your iTunes directory.
! v6 o# A% r3 N' Y" Q$ D% n: e( i$ [$ p9 G6 \6 C/ r/ t- D: H" D( o
5. Connect iPhone to Computer. Click on alt+ restore ON MAC or Shift + restore on PC and it should open up the file select box. If it doesn't then try the buttons next to it and restore as I always get confused on Mac what the equivalent of shift is! lol
0 r( {. {5 i" g$ i& d/ [, t# L
9 V: H3 \% @& |4 n9 j% K) J# ]6. Select the firmware that says "custom restore" in the filename." J5 a" w! w* B h+ Y7 q2 \" N
2 d8 q5 K8 d* w& }
7. Your iPhone will now restore and restart.
* G1 S, r2 [% y+ i( o
5 k) s( r6 z7 o, |If you get a restore failed message then put the phone into recovery mode and try restoring again with the custom firmware before you do anything else and it should work!
9 \9 w1 M2 h g- `5 N8 n; z: t S) u& u/ E5 D
8. When it restarts it will load BootNeuter automatically. DO NOT TOUCH THE PHONE
4 s6 q- C2 F! E5 m% ~6 s3 N- S- E5 e( H
The phone will reboot when BootNeuter has completed its process back to the home screen.
- P8 J2 Q6 m4 B1 ?2 d4 i9 xhttp://wikee.iphwn.org/_media/sgold_bootrom:mainscreen.png?w=&h=&cache=cache
2 m( ~+ }# [1 y% X( S5 B9 lYour Done - unlocked and activated!
( D' g, \5 w a------------------------------
: n/ m0 g+ }& S: r9 M. Z% `& @% u. L& [" g* t
6 f _% v1 z1 a. A) |+ @% ~. E4 e
BOOTLOADER INSTRUCTIONS!
4 F) q) p8 k, `0 \ {) L$ K* I a5 q9 i; o! T
0 c! Y$ l9 i, t1 t2 B) | R/ L
If IPSW Builder asks you for the bootloader images.; l1 d; P' p# c, I
& X4 f9 y3 t7 q! w% {* dDownload bootloaders.rar from the link onto your Desktop. Double click this to extract its contents.& L% }* p! V. ~) U
1 P; {9 v+ E4 T+ U
Click the browse button for the bootloader 3.9 image and select BL-39.bin file from your Desktop.
' w4 C3 }! ]4 L& \. b2 p0 A q" ~& W% l# b' e5 v/ L; q; c" Q6 v+ b4 i" v
. _: s1 X @; p& P& N, z
Click the browse button for the bootloader 4.6 image and select BL-46.bin file from your Desktop.
# G" x7 W8 k' s+ ?1 m# i
: t0 N0 o5 y3 A/ ]4 r! D* U4 F" @2 zIt will look the same as the above photo BUT say 4.6 on the Bootloader file!
1 z3 D) N, }& K, X! \. J9 A0 \& G" r: S$ g4 R
Click OK button!
0 s- N4 i/ H0 w, i) P, |
7 L# _, p* X/ J+ _# Z3 Z% D% n& X- e3 m2 q
Can I go back to 4.6 from 3.9 that ZiPhone downgraded/ or 3.9FB that iLiberty/iPlus downgraded?
- ?7 a0 ?: `/ d, j6 R3 J4 p, |8 z! n# t& P
Yes! Just click on bootneuter on your home screen. It will "unload commcenter" DO NOT TOUCH while it is doing that!% a1 ]6 a! L1 b/ }6 n0 b
7 U; Z6 N1 X; Z/ O+ k) D
The current settings will then be highlighted. Select what you want and click on Flash and WAIT UNTIL IT FINISHES.
* p2 I G8 ^7 p7 F& f) ]7 e/ L. o$ H8 [1 e F
ALWAYS LEAVE Baseband unlocked and bootloader "neutered". I changed my 3.9FB back to 4.6 original but STILL neutered without any issues.
$ S4 r/ r0 O" n4 X
: y) t) X6 {3 C) R" DDO NOT FLASH UNECCESSARILY! it is still possible to damage your phone if you go back and forth over and over. If you need to go back to your original bootloader for warranty reasons then do so otherwise leave it alone!
3 S& `- L- u) D, F* |3 o) o
2 i) x* g7 p( ~$ F) s/ Z ^IF you load bootneuter and when you exit bootneuter it will take 15-20 seconds for your signal to return. just be patient!7 Q6 m3 j. G8 S1 I% ?
; ? b7 [6 t1 d
Can I return it to Apple and they won't know?4 u. O! Q% p5 N& P! x- a5 A
0 B ?( _+ {% U- I) vWhen you click the "iPwner" button in PwnageTool, your main s5l8900 bootloader (OS bootloader) gets pwned. To undo this, use iTunes to restore to a Apple ipsw.
8 L6 u. c$ T0 h3 A4 z! V! R( R& s% P* @% I( R( o
When you neuter using BootNeuter, your S-Gold radio bootloader (baseband bootloader) gets "pwned". To undo this, run BootNeuter again and turn off all options (and pick 3.9 or 4.6 depending on your preference).1 y' n+ I) D8 G; |6 f& ]
8 B. C, d) C# a3 ]; H
Two different CPUs, two different tools. But both the s5l8900 pwnage and S-Gold pwnage are 100% reversible.% J8 X% C( d5 d( V
5 y. @4 U! I3 g' W% ?
If you want to relock your phone - use bootneuter and click everything to off. Then restore with Apple firmware. And you are back to factory fresh.
! u2 a* J: l- I8 b' G
& l' \' W) I: g5 f9 [) N7 L& j I: yIf you restore with Apple firmware you will then have to use ipwner again to use custom firmware.
7 r4 @9 N* C; k2 g" Y) v2 s$ P; a% b6 ]0 f2 \9 ?4 V
Can I update to 2.0 Beta?
8 V" A! \, ~+ G6 U7 d7 M% j
; E- z$ q5 J8 t% vYes you can using pwnage. First use iPwner WITH 1.1.4. Then restore to 1.1.4 with the above mentioned settings. Then once your phone is at 1.1.4 close pwnage tool and reopen it and select the 2.0 beta.
# Q- ~; q1 ? t: \5 x9 U2 J9 [" v, l$ z; o
You only need to pwn your phone once! do not do it again!
6 Q) J4 G; J5 R
7 J o5 z, N9 u, B) n" \Once the 2.0 beta custom firmware is built then you can select it and restore in iTunes.
5 x" z2 b2 n% M0 I
7 J+ y8 r: p5 X/ A/ WTHERE IS NO iTUNES/AppSTORE in the leaked 2.0 beta. Installer WILL NOT be added to 2.0 beta as it does not work yet.
7 F/ @& o: Z) o# q O6 [! n6 W! Y1 p0 Y" O, }. f( D: v
2.0 is very buggy and it is not worth updating at this time.
1 q' S# |2 t' s0 h$ C9 g
$ B. @% ~+ W. P4 I! V6 @0 @Can I restore back to 1.1.4 from the beta?% e6 |. f: O, J2 ?5 u: H
5 t; g( I O S& t# y
Yes you can - just restore using your custom unlocked/activated/jailbreaked firmware in iTunes. You will have to use restore mode. You may get an error at the end in which case use Independence to boot your phone normally.5 \4 A4 q+ s5 ]8 D* P
; z4 W3 z7 P' t) i
( c$ V6 a+ u' S7 A' R& F2 H# L B4 kiTunes Error Messages - What they mean and how to fix them!
6 y) S( e$ X7 J% a: m1 _
) y* F) R/ s' T" h! B7 J* o6 G
8 F% a% W! r% f# B, R" T& j% }Error 1013/1014/1015 - This error message occurs when you downgrade or upgrade to a different baseband than the firmware your restoring to has. This message does NOT mean the restore failed - it simply means the phone firmware does not match the baseband. Use iLiberty/Independence to kick the phone into normal mode and out of recovery mode and it will work.; [5 \7 y0 N$ o( E9 r0 e: t: g6 U
( O9 i7 V3 K3 ]0 |/ `" }: t
Error 6 and 10 - This error message is because of a problem with your firmware - this message will occur most often because of using unsuitable boot/recovery images. Make a new custom firmware to fix this and use suitable boot images or use the standard images that came with the pwnage software. + h2 K) |5 {8 J' `- `
1 |* I+ P0 X8 C1 ]; yError 1603/1604 - 160? something% p$ a; l/ j- ^3 j* ?7 e
, M0 p4 T1 B3 I/ M. YIF YOU ARE RESTORING TO A STANDARD APPLE FIRMWARE *NOT CUSTOM FIRMWARE"
6 C Y8 s- E0 H9 g, B) n
; M1 p8 E$ ?( j y) B8 A5 O" l" B( @This error is down to itunes not liking your USB ports on your computer. Use a different USB slot or a different computer if possible. That is the easiest fix!
$ x% m4 Y8 Z8 R) W9 ^" [) l
0 D. h" S$ e0 {$ ~0 KIF YOU ARE RESTORING TO A CUSTOM FIRMWARE AFTER RESTORING FROM STANDARD APPLE FIRMWARE f1 A4 a- K Y3 g# e3 g. F0 q# r) j9 Y
# S" k9 R( Z- J1 ]5 I
IF you have pwned your phone once and then restored back to apple original firmware successfully and THEN tried to restore custom firmware you WILL get & ?; @. I4 |( V/ w. k
an error in iTunes as the apple firmware "unpawned" your phone. You have to repwn it using iPwner and then you can restore using custom firmware.
: _% k9 f+ e: I+ P' Q7 @; H
% d$ M6 c8 {' Q; }2 ]IF YOU ARE RESTORING TO CUSTOM FIRMWARE AND YOUR PHONE IS STILL PWNED2 W2 Q$ K4 U3 T, j, D5 m5 d
. h) M% z7 `6 O. P- T/ ~
See "if your restoring to apple firmware" above as it is the same issue.
4 H4 E/ ?; l* F% m1 |8 K3 H( Q) t. G& P+ a& ?" s! o Z
BootNeuter Error 5: This is because you upgraded to the 2.0 beta firmware without unlocking first in 1.1.4 like your supposed to. You will have to restore to 1.1.4 unlocked and then delete the 2.0 baseband. You can do this by adding iclarified to the installer sources (as explained in the localization part below) then select "Delete 1.2 Baseband" - install that and let it delete your baseband. You MUST then restore to 1.1.4 apple original firmware and then re-pwn your phone and restore to 1.1.4 custom unlocked before BootNeuter will work again.
3 {7 M2 n1 o" P- k$ H# S. v. o1 Y( l s6 i7 g
4 r3 L# X8 B# U' d- b7 K6 U4 s
I CAN'T BUILD MY CUSTOM FIRMWARE! WHAT CAN I DO?
& R0 }* o. Z F4 y
& D: u) H! \- ? o* Y: ~* d. o& Q4 m5 l+ j% V- ~! F
Your problem is related to your Mac. It appears that for whatever reason your computer is
3 s5 o( T/ V( Rnot mounting the image of the firmware and putting it back together so the process fails.8 U; @% t) j$ m
; l' [$ [! r: r0 Y n$ AThere may be a solution in this thread:% ~& v6 s! O" b& L8 l! @& j W+ L0 ?
; j3 ?" Z: q1 v1 jhttp://www.hackint0sh.org/forum/showthread.php?t=365259 |# t) M, B) O+ Z& U
! ~3 Z0 j4 s7 Z5 LHowever if there is not you have 2 options: Try a different Mac OR Wait for the Windows version. M0 {( k0 ] t: G' H' c( w. X
2 G1 }+ X3 z5 d! M9 }" M* y
Can I customise my firmware to add certain applications etc?
8 f8 R# b" \0 P' x
* v, B' m3 C# c6 y/ i! b- N! k/ s6 i1 z( {0 D! Z
UPDATE: Video of new process available here:8 E2 \2 c& U2 v- [" E
http://www.youtube.com/swf/l.swf?video_id=JZN92GCdb_U&rel=1&eurl=&iurl=http%3A//i.ytimg.com/vi/JZN92GCdb_U/default.jpg&t=OEgsToPDskJQVpT8JErDGY3xcJ92Uxbf
) f, T& j w1 Z/ C. H5 o3 v5 w- K
; C4 I+ o/ y' z1 i! \ G8 r- h, gYes you can but not with the devteam release.
: D9 |% S5 \; e; U/ Y2 p: S9 y C/ q8 {) S* y: d9 [4 X/ Q- g( i
Another team of hackers have made an application that uses a interface which lets you select what apps etc you want in your custom firmware and then rebuilds it.
6 [. k' ?( m* T3 H$ E5 y% S0 i( P) a( U
It works with the pwnage tool but is not out yet - the website is http://chronic-dev.org/pwnage:ipswtool:comingsoon5 f2 s: Z, D$ v, U' G6 ^
L7 c6 E Z) c5 u7 d T
UPDATE: We have had a great success in making it, iLiberty+/X payloads even work with minimal changes! We have been able to successfully use the program to open the root dmg, mount it so that it is Pwnage compatible, patch it, put the files in it, unmount so that it is Pwnage compatible, scan with asr, and re-zip the archive. We will probably be revealing a proof-of-concept tomorrow, ether by releasing it, or showing a video. It is not being released yet because most things are done via command line for now, via the engine aviegas made. We are working as hard as possible on the GUI so we can get this out to everyone ASAP.
4 V5 Z: P7 m1 T% |
9 Z+ H7 z! M* \, f; {2 ?It should hopefully be out in the next few days.
+ [$ p# g' N, q% {9 r+ y, ]3 F( J t& \0 S
Can I use pwnage with IPSF unlocked phones?; {8 g/ K- }, ?: V; {5 h
8 E- A, J! {3 c
Yes you can. It will from my understanding it will not touch the IPSF unlock but will unlock the phone a different way and is fully compatible.
" [& i9 n. g5 r1 h* h/ J& l
# D) N- w( @+ P- h3 [% _9 q( L( G A, F: w" E! C+ Y
[ 本帖最后由 lolo8 于 2008-4-22 22:24 编辑 ] |
|