<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7974942689883001737</id><updated>2012-02-24T00:18:28.044+01:00</updated><title type='text'>pod2g's iOS blog</title><subtitle type='html'>Apple iOS Security Research [ &lt;em&gt;note that I'm against piracy: no sim unlock, installous, xsellize, etc.&lt;/em&gt; ]</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pod2g-ios.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>28</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-9194344846778112724</id><published>2012-02-24T00:04:00.000+01:00</published><updated>2012-02-24T00:18:28.057+01:00</updated><title type='text'>A working GNU Debugger on iOS &gt;= 4.3</title><content type='html'>People know that the gdb package coming from Cydia is broken since 4.3.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;But here is a simple way to have a working gdb running on your iOS device : use the one from the Apple SDK !&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Prerequisites :&lt;/b&gt;&lt;/div&gt;&lt;div&gt;- a jailbroken iOS &amp;gt;= 4.3 device&lt;/div&gt;&lt;div&gt;- OpenSSH should be installed on the iOS device and should listen for connections&lt;/div&gt;&lt;div&gt;- an OSX machine with the iOS SDK &amp;gt;= 4.3 installed&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;How to :&lt;/b&gt;&lt;/div&gt;&lt;div&gt;- remove the gdb package from Cydia&lt;/div&gt;&lt;div&gt;-&amp;nbsp;do the following in the OSX terminal :&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace; font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;cd /tmp&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;cp /Developer/Platforms/iPhoneOS.platform/Developer/usr/libexec/gdb/gdb-arm-apple-darwin .&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;lipo -thin armv7 gdb-arm-apple-darwin -output gdb&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;nano entitlements.xml&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace; font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;- paste the following to the OSX terminal :&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace; font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;lt;!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;lt;plist version="1.0"&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;lt;dict&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;key&amp;gt;com.apple.springboard.debugapplications&amp;lt;/key&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;true/&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;key&amp;gt;get-task-allow&amp;lt;/key&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;true/&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;key&amp;gt;task_for_pid-allow&amp;lt;/key&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;true/&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;lt;/dict&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&amp;lt;/plist&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace; font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;- save the file by doing CTRL + X, then 'Y', then 'ENTER'&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- now do the following in the OSX terminal :&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;ldid -Sentitlements.xml gdb&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;scp gdb root@&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;&amp;lt;iOS Device IP Address&amp;gt;&lt;/i&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;:/usr/bin/&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- GDB is now installed to your iOS device.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Happy debugging !&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;~pod2g&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-9194344846778112724?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/9194344846778112724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/9194344846778112724'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/02/working-gnu-debugger-on-ios-43.html' title='A working GNU Debugger on iOS &gt;= 4.3'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-5591740320107373574</id><published>2012-01-26T09:35:00.001+01:00</published><updated>2012-01-26T09:52:27.705+01:00</updated><title type='text'>Absinthe v0.3</title><content type='html'>&lt;div style="text-align: justify;"&gt;Chronic Dev Team has released a new version of the A5 jailbreak tool Absinthe.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Don't reapply if your 5.0.x device is already jailbroken as it won't change anything.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The untether payload is exactly the same, only the computer part has been improved for stability issues.&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Here are the links:&lt;/b&gt;&lt;br /&gt;- &lt;a href="http://cache.greenpois0n.com/dl/absinthe-win-0.3.zip"&gt;Absinthe Windows v0.3&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://cache.greenpois0n.com/dl/absinthe-mac-0.3.zip"&gt;Absinthe MacOSX (&amp;gt;=10.6) v0.3&lt;/a&gt;&lt;br /&gt;- &lt;a href="http://cache.greenpois0n.com/dl/absinthe-linux-0.3.tar.gz"&gt;Absinthe Linux v0.3&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-5591740320107373574?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5591740320107373574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5591740320107373574'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/absinthe-v03.html' title='Absinthe v0.3'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-4423580963520876187</id><published>2012-01-20T22:08:00.002+01:00</published><updated>2012-01-26T09:55:28.555+01:00</updated><title type='text'>Absinthe update 0.1.2-2</title><content type='html'>&lt;div style="text-align: justify;"&gt;Chronic Dev Team has released a new build that'll point the web clip to greenpois0n.com instead of the absinthe dedicated page.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This will handle better the workload.&lt;/div&gt;&lt;br /&gt;Here is the modified build link :&amp;nbsp;&lt;a href="http://cache.greenpois0n.com/dl/absinthe-mac-0.1.2-2.zip"&gt;Absinthe MacOSX (&amp;gt;=10.6) v0.1.2-2&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-4423580963520876187?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4423580963520876187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4423580963520876187'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/absinthe-update-012-2.html' title='Absinthe update 0.1.2-2'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-3945295421590433293</id><published>2012-01-20T18:12:00.003+01:00</published><updated>2012-01-26T09:56:22.422+01:00</updated><title type='text'>Absinthe (iPhone 4S and iPad 2 untether installer) is out</title><content type='html'>&lt;div style="text-align: justify;"&gt;The greenpois0n blog is under heavy load... because it's indeed out !&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here is the download link of Chronic Dev Team's Absinthe : &lt;a href="http://cache.greenpois0n.com/dl/absinthe-mac-0.1.2-1.zip"&gt;Absinthe MacOSX (&amp;gt;=10.6) v0.1.2-1&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Happy Cydia !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-3945295421590433293?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/3945295421590433293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/3945295421590433293'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/absinthe-iphone-4s-and-ipad-2-untether.html' title='Absinthe (iPhone 4S and iPad 2 untether installer) is out'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-5848476011985942381</id><published>2012-01-20T15:10:00.002+01:00</published><updated>2012-01-20T15:24:51.971+01:00</updated><title type='text'>iPhone 4S and iPad 2 untether to be released real soon</title><content type='html'>Hello dear readers,&lt;br /&gt;&lt;br /&gt;I know the wait was long, too much long, but it's about to end! You'd be able to free your iPhone in some hours.&lt;br /&gt;&lt;br /&gt;A tool named Absinthe and developped by the Chronic Dev Team will install the untether on your device. Also the iPhone Dev Team will release a CLI (command line) tool to help diagnose issues and repair things if it goes wrong.&lt;br /&gt;&lt;br /&gt;This is a little scary I know, but the chance you break something is really small, since we made lots of tests to verify the process on different devices. But it is the first time we use the backup / restore functions of iTunes to install software, and there are maybe things we are not aware of.&lt;br /&gt;&lt;br /&gt;As you already know, different security researchers put a lot of energy to work out the different issues we had to install the untether on new devices.&lt;br /&gt;&lt;br /&gt;Thus, a unified PayPal account was opened so that everyone who worked on the A5 exploits will receive a fair split of your contributions. Here is the link : &lt;a href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&amp;amp;hosted_button_id=DPFUPCEAYUD4L"&gt;contribute&lt;/a&gt;&lt;br /&gt;As usual, contributions are not needed but are appreciated by developpers. By the way, thank you very much again for everyone who already participated. This is real nice.&lt;br /&gt;&lt;br /&gt;Here is the complete list of Absinthe supported devices :&lt;br /&gt;&lt;ul&gt;&lt;li&gt;iPhone 4S running iOS 5.0, 5.0.1 (9A405 and 9A406)&lt;/li&gt;&lt;li&gt;iPad 2 Wifi/GSM/CDMA running iOS 5.0.1&lt;/li&gt;&lt;/ul&gt;Also, here is MuscleNerd's which explains the whole story in a really precise way: &lt;a href="http://blog.iphone-dev.org/post/16162905938/corona-a5-jailbreak-nearly-ready-to-pop"&gt;iPhone Dev Team blog post&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;~pod2g&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-5848476011985942381?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5848476011985942381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5848476011985942381'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/iphone-4s-and-ipad-2-untether-to-be.html' title='iPhone 4S and iPad 2 untether to be released real soon'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-1717050438321853650</id><published>2012-01-18T10:26:00.001+01:00</published><updated>2012-01-18T10:26:30.669+01:00</updated><title type='text'>iPad 2 5.0.1 untethered</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-CrGWRg7M15Q/TxaQKuiUxOI/AAAAAAAAAA8/EgiibD02W-o/s1600/IMG_0077.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-CrGWRg7M15Q/TxaQKuiUxOI/AAAAAAAAAA8/EgiibD02W-o/s320/IMG_0077.JPG" width="240" /&gt;&lt;/a&gt;&lt;/div&gt;No more to say !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-1717050438321853650?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1717050438321853650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1717050438321853650'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/no-more-to-say.html' title='iPad 2 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-CrGWRg7M15Q/TxaQKuiUxOI/AAAAAAAAAA8/EgiibD02W-o/s72-c/IMG_0077.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-8029439822514506723</id><published>2012-01-16T01:49:00.001+01:00</published><updated>2012-01-16T01:52:02.254+01:00</updated><title type='text'>iPhone 4S 5.0.1 untethered</title><content type='html'>My friend @DHowett made a video of an untethered 4S iPhone 4,1 running iOS 5.0.1 some days ago.&lt;br /&gt;&lt;br /&gt;@DHowett is a famous iOS developer and a member of the Chronic Dev Team.&lt;br /&gt;&lt;br /&gt;Only a few to wait now.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/rDBHXbwgdc4/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/rDBHXbwgdc4?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/rDBHXbwgdc4?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;~pod2g&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-8029439822514506723?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/8029439822514506723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/8029439822514506723'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/4s-jailbreak.html' title='iPhone 4S 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-4745087968576137017</id><published>2012-01-16T01:17:00.001+01:00</published><updated>2012-01-16T01:17:16.885+01:00</updated><title type='text'>Corona 1.0.4 online</title><content type='html'>@saurik posted version 1.0.4 of Corona in Cydia. Update now ;-)&lt;br /&gt;&lt;br /&gt;This fixes both the launchd socket issue (last fix didn't work randomly) and iBooks.&lt;br /&gt;&lt;br /&gt;Thanks to @xvolks for the development and @iH8sn0w for the testing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-4745087968576137017?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4745087968576137017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4745087968576137017'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/corona-104-online.html' title='Corona 1.0.4 online'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-8055114515511274475</id><published>2012-01-12T19:46:00.006+01:00</published><updated>2012-01-12T19:47:38.256+01:00</updated><title type='text'>Corona iBooks fixes</title><content type='html'>@xvolks worked to include @comex sandbox patches into the Corona GIT.&lt;br /&gt;&lt;br /&gt;Expect a Corona update soon in Cydia that'll fix iBooks and other softwares having sandbox issues.&lt;br /&gt;&lt;br /&gt;I'll update the blog when this is released.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-8055114515511274475?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/8055114515511274475'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/8055114515511274475'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/corona-ibooks-fixes.html' title='Corona iBooks fixes'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-1280573808175006116</id><published>2012-01-12T10:06:00.001+01:00</published><updated>2012-01-12T10:06:20.757+01:00</updated><title type='text'>Sandox broken</title><content type='html'>Here are some news about the current work on the A5 research.&lt;br /&gt;&lt;br /&gt;@planetbeing escaped from the sandbox with the help of @saurik. Thanks to their awesome work, there should be nothing left blocking for the A5 jailbreak.&lt;br /&gt;&lt;br /&gt;Now it should be a matter of days. Still no precise ETA of course.&lt;br /&gt;&lt;br /&gt;We all want this to be finished ASAP, we're getting tired!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-1280573808175006116?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1280573808175006116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1280573808175006116'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/sandox-broken.html' title='Sandox broken'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-5316911021974432043</id><published>2012-01-06T12:29:00.002+01:00</published><updated>2012-01-12T19:40:19.066+01:00</updated><title type='text'>Sandbox difficulties</title><content type='html'>&lt;div style="text-align: justify;"&gt;@planetbeing, the legendary hacker behind iPhone Linux and lot of jailbreaks (see &lt;a href="http://theiphonewiki.com/wiki/index.php?title=User:Planetbeing"&gt;the iPhone wiki&lt;/a&gt;) has joined the A5 research!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The famous @MuscleNerd (&lt;a href="http://theiphonewiki.com/wiki/index.php?title=User:MuscleNerd"&gt;the iPhone wiki&lt;/a&gt;), the leader of the iPhone Dev Team, who did a lot of tests for Corona and whom integrated it and made it simple in redsn0w is willing to help also.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;And last, but not least @p0sixninja (&lt;a href="http://theiphonewiki.com/wiki/index.php?title=User:Posixninja"&gt;the iPhone wiki&lt;/a&gt;), the leader of the Chronic Dev Team, and my partner for years on iPhone security research has started to code and fuzz the Apple sandbox.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;We now have a dream team to find a path for a public release of the A5 jailbreak.&lt;/div&gt;&lt;br /&gt;Cross your fingers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-5316911021974432043?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5316911021974432043'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5316911021974432043'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/sandbox-difficulties.html' title='Sandbox difficulties'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-6357540443578960559</id><published>2012-01-05T10:00:00.010+01:00</published><updated>2012-01-05T20:40:49.178+01:00</updated><title type='text'>A5 FAQ</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-Lmh97rcXTsk/TwWDn_SbVUI/AAAAAAAAAAs/H8bDawl5-aY/s1600/liphone-jailbreak-a5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Lmh97rcXTsk/TwWDn_SbVUI/AAAAAAAAAAs/H8bDawl5-aY/s1600/liphone-jailbreak-a5.png" /&gt;&lt;/a&gt;&lt;i&gt;How could pod2g have an untethered 4S and dev teams still haven't released tools to achieve this at home?&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The exploit I used to inject the untethering files to the 4S relies on having a developer account, and can't be released publicly.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;It's the same reason why @MuscleNerd has an iPad 2 tethered jailbreak but couldn't distribute it.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, we need to find a distributable exploit to remount the system partition read/write and to set Corona files at the correct places.&lt;/div&gt;&lt;br /&gt;&lt;i&gt;Why A4 version of Corona was easier to release?&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Because a tethered jailbreak is a good way to install Corona!&lt;/div&gt;&lt;br /&gt;&lt;i&gt;Why don't you do a tethered jailbreak then?&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;A tethered jailbreak also relies on an exploitable vulnerability that we still haven't found yet!&lt;/div&gt;&lt;br /&gt;&lt;i&gt;pod2g, release this stuff quick, &lt;/i&gt;&lt;your here="" insult=""&gt;&lt;i&gt;[your insult here], I've waited enough now.&lt;/i&gt;&lt;br /&gt;&lt;/your&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;your here="" insult=""&gt; If I could, I would!&lt;/your&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-6357540443578960559?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/6357540443578960559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/6357540443578960559'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/a5-faq.html' title='A5 FAQ'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Lmh97rcXTsk/TwWDn_SbVUI/AAAAAAAAAAs/H8bDawl5-aY/s72-c/liphone-jailbreak-a5.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-2408124538172928029</id><published>2012-01-02T21:35:00.001+01:00</published><updated>2012-01-12T19:41:46.951+01:00</updated><title type='text'>Details on Corona</title><content type='html'>&lt;div style="text-align: justify;"&gt;Now that Corona was released by the iPhone Dev Team and the Chronic Dev Team, I can give details about how it works.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;1. the user land exploit&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Apple has fixed all previous known ways of executing unsigned binaries in iOS 5.0. Corona does it another way.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;By the past, the trick security researchers used was to include the untethering payload as a data page (as opposed to a code page) in the Mach-O binary. The advantage of a data page was that the Macho-O loader didn't check its authenticity. ROP is used so that code execution happens without writing executable code but rather by utilizing existing signed code in the &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;dyld&lt;/span&gt; cache. To have the ROP started by the Mach-O loader, they relied on different technics found by @comex, either :&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- the interposition exploit&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- the initializer exploit&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Here is a detailed explanation of incomplete code sign tricks used before 5.0 :&amp;nbsp;&lt;a href="http://theiphonewiki.com/wiki/index.php?title=Incomplete_Codesign_Exploit"&gt;the iPhone wiki&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;In iOS 5.0, data pages need also to be signed by Apple for the loader to authenticate the binary. @i0n1c seems to be able to pass through these verifications though (&lt;a href="https://twitter.com/#%21/i0n1c/status/145132665325105152"&gt;he twitted&lt;/a&gt;). We may see this in the 5.1 jailbreak.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Thus, for Corona, I searched for a way to start unsigned code at boot without using the Mach-O loader. That's why I looked for vulnerabilities in existing Apple binaries that I could call using standard &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;launchd&lt;/span&gt; plist mechanisms.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Using a fuzzer, I found after some hours of work that there's a format string vulnerability in the &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon&lt;/span&gt; configuration parsing code! &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon&lt;/span&gt; is the IPsec IKE daemon (&lt;a href="http://ipsec-tools.sourceforge.net/"&gt;http://ipsec-tools.sourceforge.net/&lt;/a&gt;). It comes by default with iOS and is started when you setup an IPsec connection.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Now you got it, Corona is an anagram of &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon&lt;/span&gt; :-) .&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;By the way, the exploitation of the format string vulnerability is different than what was done in 2001, check it out if you're interested !&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;For the jailbreak to be applied at boot, &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon&lt;/span&gt; is started by a &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;launchd&lt;/span&gt; plist file, executing the command :&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon -f racoon-exploit.conf&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon-exploit.conf&lt;/span&gt; is a large configuration file exploiting the format string bug to get the unsigned code started.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The format string bug is utilized to copy the ROP&amp;nbsp;bootstrap payload to the memory and to execute it by overwriting a saved LR in the &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;racoon&lt;/span&gt; stack by a stack pivot gadget.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The ROP&amp;nbsp;bootstrap payload copies the ROP&amp;nbsp;exploit payload from the &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;payload&lt;/span&gt; file which is distributed with Corona then stack pivot to it. The idea is to escape from format strings as fast as possible, because they are CPU time consuming.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The ROP exploit payload triggers the kernel exploit.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;2. the kernel exploit&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The kernel exploit relies on an HFS heap overflow bug I found earlier. I don't know exactly what happens in the kernel code, I never figured it out exactly, I found it by fuzzing the HFS btree parser.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I just realized that it is a heap overflow in the zone allocator, so I started to try to mount clean, overflowed and payload images in a Heap Feng Shui way :-) And hey, that worked :p Thanks to @i0n1c for his papers on this subject. This helped me a lot. I may have given up without them.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The kernel heap overflow exploit copies 0x200 bytes from the &lt;span class="Apple-style-span" style="font-family: 'Courier New',Courier,monospace;"&gt;vnimage.payload&lt;/span&gt; file to the kernel sysent replacing a syscall to a write anywhere gadget. Some syscalls (first 0xA0 bytes and the last 0x6 bytes) are trashed in the operation because I needed to respect the HFS protocol.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Thus, I restore them as fast as possible to get a stable exploit, then the write anywhere is used to copy the kernel exploit and jump to it.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The kernel exploit just patches the kernel security features, as usual. Nothing interesting there.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Happy New Year 2012 to you all, &amp;nbsp;thanks a lot for the donations.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;~pod2g&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-2408124538172928029?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/2408124538172928029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/2408124538172928029'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2012/01/details-on-corona.html' title='Details on Corona'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-7986197062473083322</id><published>2011-12-27T11:52:00.001+01:00</published><updated>2011-12-31T10:57:10.979+01:00</updated><title type='text'>A4 release</title><content type='html'>&lt;div style="text-align: justify;"&gt;Hello, as expected, the Chronic Dev Team and the iPhone Dev Team have released the A4 untethered for 5.0.1 based on my research.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It is exactly the same set of files, either distributed as a Cydia package for those that are already tethered or a redsn0w bundle for new users.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;They both did a great job testing and integrating the payload.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here is a link to their respective blog posts :&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- Chronic Dev Team : &lt;a href="http://greenpois0n.com/?p=150"&gt;http://greenpois0n.com/?p=150&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- iPhone Dev Team : &lt;a href="http://blog.iphone-dev.org/"&gt;http://blog.iphone-dev.org&lt;/a&gt;&lt;/div&gt;&lt;ul&gt;&lt;li style="text-align: justify;"&gt;temporary redsn0w download links: &lt;a href="http://pastie.org/3078869"&gt;http://pastie.org/3078869&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;~pod2g&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-7986197062473083322?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/7986197062473083322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/7986197062473083322'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/a4-release.html' title='A4 release'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-5815174620738128132</id><published>2011-12-22T22:20:00.001+01:00</published><updated>2011-12-31T10:57:32.971+01:00</updated><title type='text'>Focused on A5</title><content type='html'>&lt;div style="text-align: justify;"&gt;I read the comments on the blog, and I know that a lot of people are waiting for the A5 jailbreak.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Also, I know there are tons of people out there with A4 or even earlier devices who wants the untether now and don't care about it could be interesting to wait A5 is finished to release or even 5.1, so that we don't waste an exploit that took me months to find and develop.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I need to focus on A5 and hope I can find a path quick, and I have the feeling that chronic-dev could help me.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, here is what I did:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- I gave all the details to the chronic dev team so that they can finish, test, integrate and release the A4 jb ASAP.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;- I'll put all my energy from now on on the A5&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Hope I don't disappoint.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;See you.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-5815174620738128132?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5815174620738128132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/5815174620738128132'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/focused-on-a5.html' title='Focused on A5'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-2238394474789077184</id><published>2011-12-21T18:52:00.001+01:00</published><updated>2011-12-31T10:58:20.760+01:00</updated><title type='text'>iPhone 4 iOS 5.0.1 untethered jb demo</title><content type='html'>&lt;div style="text-align: justify;"&gt;Hello,&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Here is a new video demo of the current status of the 5.0.1 jailbreak running on an iPhone 4.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;This is meant to reassure people that were thinking it only works on older iPods.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The jailbreak is near ready for prime time (excluding 4S and iPad 2).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Patches are the same as redsn0w's. Expect the same level of stability.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Some more days to wait. Be patient, we're doing our best.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;~pod2g&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/qdF58anFtiQ/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/qdF58anFtiQ?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/qdF58anFtiQ?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-2238394474789077184?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/2238394474789077184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/2238394474789077184'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/iphone-4-ios-501-untethered-jb-demo.html' title='iPhone 4 iOS 5.0.1 untethered jb demo'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-2172080413409630136</id><published>2011-12-20T02:02:00.001+01:00</published><updated>2011-12-31T10:58:47.513+01:00</updated><title type='text'>No more cache troubles</title><content type='html'>&lt;div style="text-align: justify;"&gt;OK, figured it out, the A5 cache is not a problem anymore.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I sorted it out by doing the untether in a single thread and by flushing all the dcache then all the icache in a row at a strategical point of the process.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It took me like a hundred of tests to find the key. Hard for the nerves.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;For the tech guys, here is a link explaining issues related to self modifying code ( or code patching ) on the ARM platform : http://blogs.arm.com/software-enablement/141-caches-and-self-modifying-code/&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another news : I discussed with @saurik today about the launchd boot process, and he's found one missing piece of the puzzle I needed to have a perfectly stable jailbreak. He's definitly one of the best iOS gurus out there. Thank you saurik!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-2172080413409630136?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/2172080413409630136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/2172080413409630136'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/no-more-cache-troubles.html' title='No more cache troubles'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-1001182058967640843</id><published>2011-12-19T14:17:00.001+01:00</published><updated>2011-12-19T15:42:09.648+01:00</updated><title type='text'>News</title><content type='html'>Hello.&lt;br /&gt;&lt;br /&gt;Here are the news of the 4S week-end.&lt;br /&gt;&lt;br /&gt;The untether fails right now because I'm having processor cache issues.&lt;br /&gt;&lt;br /&gt;I'm close, but I can't figure out what happens. It certainly has something to do with the Cortex-A9 cache management.&lt;br /&gt;&lt;br /&gt;I could sort it out quick, it's a matter of chance.&lt;br /&gt;&lt;br /&gt;I'll report you my progress tomorrow.&lt;br /&gt;&lt;br /&gt;BTW: I removed (sorry) the greetings messages so that only articles related to the jailbreak remain in the main page. AFAIK Blogger don't have the option to move or fusion messages while keeping the comments.&lt;br /&gt;&lt;br /&gt;Ciao!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-1001182058967640843?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1001182058967640843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1001182058967640843'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/news.html' title='News'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-9208154193993950913</id><published>2011-12-16T00:11:00.001+01:00</published><updated>2011-12-16T00:11:40.043+01:00</updated><title type='text'>4S 5.0.1 Build 9A406 fail</title><content type='html'>@MuscleNerd tweeted something really interesting today:&lt;br /&gt;&lt;br /&gt;The latest ipsw released by Apple for the 4S contains an unencrypted&lt;br /&gt;ramdisk with the vfdecrypt key in plain text.&lt;br /&gt;&lt;br /&gt;Everybody can decrypt the filesystem with it !&lt;br /&gt;&lt;br /&gt;Is it a Christmas gift from Apple ?&lt;br /&gt;&lt;br /&gt;Weird, isn't it ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-9208154193993950913?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/9208154193993950913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/9208154193993950913'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/4s-501-build-9a406-fail.html' title='4S 5.0.1 Build 9A406 fail'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-7148779905507279020</id><published>2011-12-15T14:06:00.001+01:00</published><updated>2011-12-15T14:55:00.126+01:00</updated><title type='text'>Tested !</title><content type='html'>IPhone 3Gs 5.0.1 jb worked.&lt;br /&gt;&lt;br /&gt;Remaining to test: iPod 4G &amp; iPhone 4 CDMA running 5.0.1.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-7148779905507279020?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/7148779905507279020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/7148779905507279020'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/tested.html' title='Tested !'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-9018358738342625164</id><published>2011-12-15T08:54:00.001+01:00</published><updated>2011-12-15T14:54:42.556+01:00</updated><title type='text'>Progress</title><content type='html'>Hello my friends,I know that I've been silent yesterday and that it was annoying.&lt;br /&gt;&lt;br /&gt;Sorry for this, but I had to organize things for the release.&lt;br /&gt;Also, I've tested iPad 1 and it worked.&lt;br /&gt;Today I hope I can test a 3Gs.&lt;br /&gt;&lt;br /&gt;BTW: please don't propose to be a beta tester because I'm too paranoid, fearing leaks.&lt;br /&gt;&lt;br /&gt;Now the time to finalize the jailbreak for old devices, fix some stability issues and package the whole.That will take some days.&lt;br /&gt;&lt;br /&gt;In the meanwhile, I'm starting the research for iPad 2 and 4S.I'll take you informed of my progress.&lt;br /&gt;&lt;br /&gt;Finally, I want to thank all who donated. I now can buy both devices! I don't know what to say.&lt;br /&gt;&lt;br /&gt;Thank you very much my friends.&lt;br /&gt;Have a good day!&lt;br /&gt;&lt;br /&gt;See ya.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-9018358738342625164?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/9018358738342625164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/9018358738342625164'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/progress.html' title='Progress'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-761398423964450284</id><published>2011-12-14T00:25:00.000+01:00</published><updated>2011-12-14T00:25:04.393+01:00</updated><title type='text'>Apple TV 2 4.4.3 untethered</title><content type='html'>Done also. Rush mode = off for today.&lt;br /&gt;&lt;br /&gt;Will be able to test in some days, thanks to @firecore that'd ship me an Apple TV 2 for testing !&lt;br /&gt;&lt;br /&gt;Thanks mate ! That's awesome.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-761398423964450284?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/761398423964450284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/761398423964450284'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/apple-tv-2-443-untethered.html' title='Apple TV 2 4.4.3 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-6851277875493929161</id><published>2011-12-13T23:56:00.001+01:00</published><updated>2011-12-13T23:56:56.662+01:00</updated><title type='text'>iPod 4G 5.0.1 untethered</title><content type='html'>This one too ! :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-6851277875493929161?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/6851277875493929161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/6851277875493929161'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/ipod-4g-501-untethered.html' title='iPod 4G 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-4812677281547925911</id><published>2011-12-13T23:31:00.000+01:00</published><updated>2011-12-13T23:31:20.585+01:00</updated><title type='text'>iPhone 3Gs 5.0.1 untethered</title><content type='html'>Code done. Testing tomorrow also !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-4812677281547925911?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4812677281547925911'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4812677281547925911'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/iphone-3gs-501-untethered.html' title='iPhone 3Gs 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-8641855423381452472</id><published>2011-12-13T21:49:00.001+01:00</published><updated>2011-12-13T21:49:52.718+01:00</updated><title type='text'>iPad 1 5.0.1 untethered</title><content type='html'>Code is done, testing tomorrow with a friend's device.&lt;br /&gt;&lt;br /&gt;Just to let you know my progress in real time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-8641855423381452472?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/8641855423381452472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/8641855423381452472'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/ipad-1-501-untethered.html' title='iPad 1 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-1371822820360301818</id><published>2011-12-12T22:50:00.000+01:00</published><updated>2011-12-13T22:01:49.453+01:00</updated><title type='text'>iPod 3G 5.0.1 untethered</title><content type='html'>Hey,&amp;nbsp;this one's done.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Next: iPad 1,&amp;nbsp;iPhone 3Gs,&amp;nbsp;iPod 4G, Apple TV 2.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Rushing the best I can.&lt;/div&gt;&lt;div&gt;Bye !&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-1371822820360301818?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1371822820360301818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/1371822820360301818'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/ipod-3g-501-untethered.html' title='iPod 3G 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-4664053827918987152</id><published>2011-12-12T01:28:00.001+01:00</published><updated>2011-12-13T22:02:38.308+01:00</updated><title type='text'>iPhone 4 5.0.1 untethered</title><content type='html'>It's late, time to pass out.&lt;br /&gt;&lt;div&gt;I just want to let you know my iPhone 4 (iOS 5.0.1)&amp;nbsp;is untethered.&lt;/div&gt;&lt;div&gt;Some progress today heh ;-)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Next : iPod 3G,&amp;nbsp;iPad 1, iPhone 3Gs,&amp;nbsp;iPod 4G, Apple TV 2.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;See ya.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-4664053827918987152?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4664053827918987152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/4664053827918987152'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/its-late-time-to-pass-out.html' title='iPhone 4 5.0.1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7974942689883001737.post-737223499691348739</id><published>2011-12-09T21:00:00.000+01:00</published><updated>2011-12-09T21:00:58.497+01:00</updated><title type='text'>iOS 5.0 iPod3,1 untethered</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/kp_Mz6rs9fc/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/kp_Mz6rs9fc&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/kp_Mz6rs9fc&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;Today I succeed in jailbreaking my iPod 3G.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The exploit is user-land, rely on a user ROP payload and a kernel write anywhere exploit.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I can't give much details right now, but here are the next steps :&lt;/div&gt;&lt;div&gt;- upgrade the iPod 3G to iOS 5.0.1&lt;/div&gt;&lt;div&gt;- do the same on iPhone 4 / iOS 5.0.1&lt;/div&gt;&lt;div&gt;- then iPad 1 &amp;amp; iPod 4G&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;At every step, the exploit code needs certainly to be reworked, but I really don't know right now.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Next, I'll return to the research for iPad 2 and iPhone 4S. I don't know if I gonna release first for other devices or not. I've to think about it. Feel free to give your opinion.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'll update the blog when I have news.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Cya.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7974942689883001737-737223499691348739?l=pod2g-ios.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/737223499691348739'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7974942689883001737/posts/default/737223499691348739'/><link rel='alternate' type='text/html' href='http://pod2g-ios.blogspot.com/2011/12/ios-50-ipod31-untethered.html' title='iOS 5.0 iPod3,1 untethered'/><author><name>pod2g</name><uri>http://www.blogger.com/profile/17861400993355911950</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
