• Your favorite

    Apple

    ,

    iPhone

    ,

    iPad

    ,

    iOS

    ,
    Jailbreak
    , and
    Cydia
    site.
  • Just Don't Want to Update to iOS 7.0.6? – You Could Install Ryan Petrich's SSLPatch


    If you're running any iOS version earlier than iOS 7.0.6, then you really should update to iOS 7.0.6 to fix a very serious SSL connection verification bug that could leave you open to man-in-the-middle networking attacks. iOS 7.0.6 can be jailbroken with evasi0n7 version 1.0.6, so there's really no downside to upgrading.

    On the other hand, if you don't want to upgrade from iOS 6 to iOS 7.0.6 because you just can't stand iOS 7, or you're just too lazy to go through the restore and re-jailbreak process all over again, then you can install a new free jailbreak tweak called SSLPatch by iOS developer Ryan Petrich.

    First and foremost, it should be noted that SSLPatch is only a band aid. It's not a perfect fix. Updating to iOS 7.0.6 is still the BEST way to secure yourself from the SSL connection verification bug that plagues iOS devices running earlier versions of iOS firmware. Petrich tells us that SSLPatch "cannot be applied in safe mode or in apps that run as root, such as Cydia or iFile" so with that being said, it doesn't protect you 100% of the time, but it does protect you MOST of the time.

    The tweak is made available for free in Ryan Petrich's beta repository. If you want to add SSLPatch to your jailbroken iOS device, add Ryan Petrich’s beta repository by following the steps below:

    • tap on the Manage tab
    • tap on the Sources button
    • tap on the Edit button
    • tap on the Add button
    • enter the following URL and then tap Add Source:

    PHP Code:
    http://rpetri.ch/repo/ 
    SSLPatch is compatible with both iOS 6 and iOS 7 devices running iOS 7.0.5 and earlier.

    We would still personally recommend to anyone reading this that you upgrade to iOS 7.0.6 instead of installing this patch, but there are some of those stubborn folks out there that just don't want to upgrade. Even iOS hacker pod2g recommended upgrading to iOS 7.0.6 instead of installing any patches, but nonetheless, the option is there:



    Sources: Ryan Petrich
    This article was originally published in forum thread: Just Don't Want to Update to iOS 7.0.6? – You Could Install Ryan Petrich's SSLPatch started by Anthony Bouchard View original post
    Comments 54 Comments
    1. Anthony Bouchard's Avatar
      Anthony Bouchard -
      Quote Originally Posted by Zokunei View Post
      I don't think this bug exists in iOS 3, but I can't find where I read that again. Someone said it didn't even exist in 5.1.

      Can anyone verify?
      Ryan said this tweak was for iOS 6 and iOS 7, and pod2g said that this bug has been in iOS for the last year, so I would assume it's only for iOS 6 and later.

      I really have no way of completely confirming this, though.
    1. Werty12's Avatar
      Werty12 -
      Just downloaded it. I have way to much music on my phone to lose with a restore & back up.
    1. jwil736's Avatar
      jwil736 -
      Heh. Just waste another day on an unlikely chance of being exploited? Nah I'll go for the patch.
    1. sLi's Avatar
      sLi -
      Quote Originally Posted by CZroe View Post
      Any love for old devices that didn't get iOS7? My mother's iPhone 3GS went through the wash last night and she's now using an old iPhone 3G with iOS3-based whited00r7. I can put iOS4 on it but I doubt they are going to release a fixed iOS4. Will Ryan' patch work on iOS3/4?
      The bug only affects iOS 6.x to 7.0.5
    1. iH85CH001's Avatar
      iH85CH001 -
      Quote Originally Posted by Scotty Manley Silberhorn View Post
      Why are you on 7.0? Evasion was released after 7.0.4 was out. Why not just upgrade 7.0.4 then? Since it only takes about 5 mins to update ota. And evasion worked for me doing the ota updates.
      You can't update using OTA or evasi0n won't work right. You have to do a full restore. You should read and learn before criticizing.
    1. Christophxr's Avatar
      Christophxr -
      Beautiful. Gracias, Ryan.
    1. iH85CH001's Avatar
      iH85CH001 -
      Still hatin iOS 7, should probably just use the patch.
    1. Jj2345's Avatar
      Jj2345 -
      Anyone else getting that error code 2005 when trying to restore?
      I really wanna update but I can't due to this error code
    1. Scotty Manley Silberhorn's Avatar
      Scotty Manley Silberhorn -
      Quote Originally Posted by iH85CH001 View Post
      You can't update using OTA or evasi0n won't work right. You have to do a full restore. You should read and learn before criticizing.
      Weird. I updated ota, with 4 different devices and evasion worked fine... Maybe you shouldn't criticize people about what you don't know.

      Here's the thing about using this patch and not updating. You make purchases for tweaks in cydia and your paypal or Amazon information is susceptible to being compromised. Along with your google account or Facebook account. Will you ever get hacked on those accounts? we'll find out when it happens to you. And if something breaks and your phone goes into safemode without you knowing it, your phone is still using the internet in the background, where any account or information you have on your device that requires Internet is at risk. If you don't value security, go with this patch. If you do, upgrade and rejailbreak.
    1. jetsetjoey's Avatar
      jetsetjoey -
      I already had Ryan Petrich's Source installed, as he has some sweet utilities... BUT I can't find the SSLPatch! It's simply not there! Anyone else having a problem locating the SSLPatch? Any ideas anyone???

      *** B.T.W., I'm running iOS 7.04 on an iPhone 5.

      Thanks!!!
    1. Feanor64's Avatar
      Feanor64 -
      Quote Originally Posted by Anthony Bouchard View Post
      How is that? I think pod2g is just looking into the best interest of everyone.

      Since Ryan's tweak doesn't protect you 100% of the time like the iOS update does, I think he's right.
      You are prolly right. Overall people should update. That is the logical thing to do. I just try to look at the bigger picture. More updates mean more rejailbreaks and that means more money for pod2g. That's just a fact. I'm sure it's probably not his motivating factor. So Taig pod2g errrr i mean thanks pod2g!
    1. mirilopr's Avatar
      mirilopr -
      Whats the best backup tweak for cydia apps?
    1. 2k1's Avatar
      2k1 -
      Quote Originally Posted by mirilopr View Post
      Whats the best backup tweak for cydia apps?
      Pkgbackup
    1. Zokunei's Avatar
      Zokunei -
      This pretty reliable source says the bug is only in iOS 6 and 7. http://web.nvd.nist.gov/view/vuln/de...=CVE-2014-1266
    1. Ajugal's Avatar
      Ajugal -
      Quote Originally Posted by jetsetjoey View Post
      I already had Ryan Petrich's Source installed, as he has some sweet utilities... BUT I can't find the SSLPatch! It's simply not there! Anyone else having a problem locating the SSLPatch? Any ideas anyone???

      *** B.T.W., I'm running iOS 7.04 on an iPhone 5.

      Thanks!!!
      Just type SSL and it shows up.
    1. SuncoastDave's Avatar
      SuncoastDave -
      Wierd.
      Doesn't show in the repo list, or in the changes display, but search finds it. Yay.

      Now I can wait 'til the weekend to update.
    1. Scotty Manley Silberhorn's Avatar
      Scotty Manley Silberhorn -
      Quote Originally Posted by Feanor64 View Post
      You are prolly right. Overall people should update. That is the logical thing to do. I just try to look at the bigger picture. More updates mean more rejailbreaks and that means more money for pod2g. That's just a fact. I'm sure it's probably not his motivating factor. So Taig pod2g errrr i mean thanks pod2g!
      I don't think he gets money for every jailbreak. He gets donations, it's not like advertising where you make a certain amount of money per ad. If you're paying money to jailbreak, you're doing it wrong. I did donate $15 when it evasion 7 was first released though. But I won't donate again until 7.1 or iOS 8 is released.
    1. Zokunei's Avatar
      Zokunei -
      Quote Originally Posted by Scotty Manley Silberhorn View Post
      I don't think he gets money for every jailbreak. He gets donations, it's not like advertising where you make a certain amount of money per ad. If you're paying money to jailbreak, you're doing it wrong. I did donate $15 when it evasion 7 was first released though. But I won't donate again until 7.1 or iOS 8 is released.
      There are ads on Evasi0n.com. I don't think that's why he's telling people to update though.
    1. Scotty Manley Silberhorn's Avatar
      Scotty Manley Silberhorn -
      Quote Originally Posted by Zokunei View Post
      There are ads on Evasi0n.com. I don't think that's why he's telling people to update though.
      Right, but I don't redownload evasion everytime I want to jailbreak a device, I usually download the most updated version once and then jailbreak multiple devices from that single download.
    1. Anthony Bouchard's Avatar
      Anthony Bouchard -
      Quote Originally Posted by Jj2345 View Post
      Anyone else getting that error code 2005 when trying to restore?
      I really wanna update but I can't due to this error code
      This guy seems to have made his way around it:

      Error 2005 - FIXED | iPad, iPhone, and iPod touch forums | iFans

      Quote Originally Posted by Scotty Manley Silberhorn View Post
      I don't think he gets money for every jailbreak. He gets donations, it's not like advertising where you make a certain amount of money per ad. If you're paying money to jailbreak, you're doing it wrong. I did donate $15 when it evasion 7 was first released though. But I won't donate again until 7.1 or iOS 8 is released.
      Right. He's not getting money from jailbreaks. Users can choose to donate to the cause. Web-based ads on the evasi0n Web site might generate revenue; some of that goes to pay to keep the Web site up.