  • Dev-Team Confirms: New Bootrom Defeats 24kpwn

    image via StealthBravo.com

    As noted here on MMi last night, new iPhone 3GSes are shipping with an updated bootrom that is resistant to 24kpwn. Dev-Team member MuscleNerd confirms that the new bootrom, iBoot-359.3.2, is no longer vulnerable to the memory segment overrun exploit.

    This is the first time Apple has upgraded the bootrom during a normal production cycle, rather than when a new model is introduced. The bootrom is a snippet of code that runs at startup time, and checks on the status of the boot image. It's generally used to verify that the image has not been corrupted, but can also be used to check for unauthorized firmware. The 24kpwn exploit - otherwise known as 0x24000 Segment Overflow - bypassed the signature checks on iBoot and allowed unsigned firmware to be loaded. The new bootrom makes that impossible, so currently shipping 3GS phones cannot be jailbroken until a new exploit is found.

    To determine if your new 3GS is running the new bootrom, just check System Profiler while the phone is in DFU mode. Versions of iBoot prior to 359.3.2 should still be able to be jailbroken using known methods.
    1. awesomeSlayer's Avatar
      awesomeSlayer -
      Quote Originally Posted by aekhamsouk View Post
      it was a joke, get a life!

      i think you should get banned for having multiple ID's...
      I think you need to get a life! And how do you even know he has multiple IDs. Plus, one1 is MMi's Chuck Norris so don't even mess with him.

      Back on topic. Why does Apple have to ruin everything? If I get something, I can do anything I want like make a bomb out of an iPhone. The good news is there is a way to jailbreak. I hope it doesn't happen to the older generations as well.
    1. lkailburn's Avatar
      lkailburn -
      Any idea on shipment dates for this? I'm eligable for renewal on the 31st and was gonna walk in and pick up a 3gs for half the price i can buy it for now. hold off apple hold off! just 2 more weeks!

    1. aekhamsouk's Avatar
      aekhamsouk -
      Quote Originally Posted by awesomeiPod View Post
      I think you need to get a life! And how do you even know he has multiple IDs. Plus, one1 is MMi's Chuck Norris so don't even mess with him.

      Back on topic. Why does Apple have to ruin everything? If I get something, I can do anything I want like make a bomb out of an iPhone. The good news is there is a way to jailbreak. I hope it doesn't happen to the older generations as well.
      is that jaw of yours tired yet? or is he done?
    1. confucious's Avatar
      confucious -
      MN Twitter
      Brief writeup on the history of the tethered jailbreak: Tethered jailbreaks [iPhone Dev Team] History may be repeating itself
    1. leletyM3's Avatar
      leletyM3 -
      I am sure they will find a way it is just matter of time even it kinda sucks as we have to wait for a new method to unlock. I am wondering if I am gonna order it online now if they will ship it out with the new iBoot.
    1. ZipZapp's Avatar
      ZipZapp -
      I think the end of JB is near...
    1. nighthawk283's Avatar
      nighthawk283 -
      Quote Originally Posted by ZipZapp View Post
      I think the end of JB is near...
      I don think so there a way always a way
    1. JonFolse's Avatar
      JonFolse -
      Quote Originally Posted by nighthawk283 View Post
      I don think so there a way always a way
    1. MetallicaFan1991's Avatar
      MetallicaFan1991 -
      Just be glad Apple isn't getting help from Sony or the iPhone will be unhackable like the PS3!!
      Besides there's GeoHot, so it's going to be hacked!
      Remember no one could hack BL4.6 and people like me were waiting for an unlock and when GeoHot tried, took him less than 24 hours to unlock the iPhone 2G!
    1. Napoleon_PhoneApart's Avatar
      Napoleon_PhoneApart -
      Everyone who needs to exchange their 3GS for whatever reason is taking a big chance now.

      Don't drop it.
    1. JonFolse's Avatar
      JonFolse -

    1. kamaal's Avatar
      kamaal -
      personally if it wasn't for jailbreaking I would not mess with the Iphone nor AT&T, If I can't jailbreak Apple, iphone and myself must part ways.
    1. finalfantasy's Avatar
      finalfantasy -
      blah blah blah.... whats new? we all knew this was gonna happen soon. and we know the dev team and Geohot are the gods of jailbreaking so WOOPIE DO to what apple did, either dev team or geohot (most likely geohot) will break this new security feature... YES it will take time but it will happen... stop crying ppl.
    1. riku98523's Avatar
      riku98523 -
      Does anyone else think this might actually be a way for Apple to just get all the unsold iPhones sold? Like it was mentioned this is the first time they have ever done this without releasing a whole new version of the iPhone. I honestly think they know the new one will get hacked and figured they would use that to get rid of the current phones already out that can be hacked (everyone will rush to the stores to get one of the only hackable phones left)

      They basically kill 2 birds with one stone make a bunch of money off the phones that still haven't sold and put a limit on the Jailbroken phones for a while (even though they know it will get hacked).
    1. devorama's Avatar
      devorama -
      So I've read that the refurbished and older phones are obviously more likely to have the older bootrom. But how would one find these phones? I can't find a way to officially buy a refurbished 3GS. I don't want to do ebay because I need the AT&T subsidy. But I don't see how one could know how old the stock is at an AT&T store. They don't have dates on the boxes, do they? And even once the phone is in your hands, you can't tell the bootrom version unless you connect it to a computer in DFU mode, right?

      So far, the only one I've seem saying they personally got burned by this new rom is this guy. And I think he's in Hong Kong. Is this hitting new iPhone users in the US yet? I can't get my iPhone until Monday when my t-mobile contract is up. I'm afraid it will be too late by then.
    1. epiksol's Avatar
      epiksol -
      Just a small delay, no biggie. I have faith. DevTeam rapes...
    1. TrOpAzR's Avatar
      TrOpAzR -
      If Apple has finally devised a way to beat GeoHot, The DevTeam, and Saurik (which I highly doubt) I think it will be time to part ways when my contract is up on my iPhone next year.

      And if it has to come to that, I am pretty sure that I spy Liquid in my future...

      I understand the reasons for Apple to want to stop people from jailbreaking...but I am struggling to understand why they won't learn from us jailbreakers and allow us the ability to do the things that we know the iPhone can do.

      Why do they want to push a sub-par device on us when we all know that the iPhone is so much more than that???

      If Apple keeps up these shenanigans and refuses to listen to the most educated segment of iPhone owners...I will be taking my business elsewhere.

      Google is the company of the future, and I am afraid Apple will be left in a cloud of dust if they don't make some radical changes to how they do business.

      Android Liquid is sexy though isn't it???

      Acer Liquid mixes Snapdragon and Android 1.6 'donut' for a movable feast
    1. RaginAsian55's Avatar
      RaginAsian55 -
      I understand why Apple wants to prohibit jailbreaking but I don't understand why they refuse to allow factory unlocked iPhones onto the American market. I know ATT has their exclusive contract but I see people all over ebay and craigslist selling iPhones for full retail price OR MORE-- if you pay an unsubsidized price for an iPhone from Apple it should come factory unlocked to be used with any carrier. Maybe some people (like me) just want the iPhone for it's phone/ipod functions and don't even need the internet at all. I'm just saying. If jailbreaking it out, so is unlocking... and it seems like this will just decrease iPhone sales than boost them. (Because the other alternative is what, switch to ATT so I can pay twice as much for cellular service per month on top of paying $300 for a phone with no insurance?.... no thanks...)

      Wasn't there a stat on here a while ago that said almost 25% of iPhone users IN THE US are not on ATT? That's 25% of iPhone users who will soon be locked out... unless they paid crasy ca$h for a factory unlocked....
    1. kaaroFC's Avatar
      kaaroFC -
      Quote Originally Posted by timbo View Post
      Will this hurt there sales.... what is the JB footprint?
      I don't think it would affect sales, since not many people know how to jb... LOL
    1. excmodmyi's Avatar
      excmodmyi -
      hi guys, where is this System Profiler? does it exist on a PC? i bought a 3GS today and i'm trying to find out if it has the unjailbreakable firmware. i need more detailed instructions.

      thanks guys