Your favorite Apple, iPhone, iPad, iOS, Jailbreak, and Cydia site.
General iPhone Chatforums, a part of the
07-04-2010, 07:49 AM #1JAILBREAK iOS4 FOR 3Gs NEW BOOTROM..!!!
Ive just done it, and IT WORKS!! wOOt!!
Follow the guide as posted in iH8sn0w's forum:
Pwning 4.0 on New Bootrom 3G[S] w/3.1.2 SHSH Blobs
I wrote this all on the road with my iPad, so sorry if there is any major Grammar errors. If anyone points out any errors, Ill fix it up. Anyways
I figured making a tool would take a bit too long. So, im going to write up this tutorial. It isnt recommended for regular users.
**BEFORE PROCEEDING, ENSURE THAT YOU HAVE YOUR PHONE BACKED UP!**
WHAT YOU WILL NEED:
* An iPhone 3G[S] new bootrom
* 3.1.2 SHSH blobs.
* difrnts iBSS grabber
* Payload Pwner for the 3GS.
* sn0wbreeze V1.6.2
* LibUSB (64-Bit users read carefully!!!)
* 3.1.2/4.0 3GS firmware downloaded. [Download iPhone 3.1.2 / Download iOS 4.0]
STEP A : Grabbing your 3.1.2 iBSS file.
Pointing your hosts :
I : If you have your shsh blobs saved on Cydia/Sauriks server then follow this tutorial. Caching Apple's Signature Server - Jay Freeman (saurik)
II : If you have it saved with TinyUmbrella, then download the GUI here. The Firmware Umbrella
Restoring to grab the iBSS file.
I : Place your device in DFU.
II : Start up the iBSS/iBEC grabber.
III : Put the save folder on a new folder on your desktop.
IV : Hit "Start Monitoring".
V : Now go back to iTunes and do SHIFT + Restore. Then browse for your 3.1.2 IPSW. You will need to restore
to 3.1.2 in order to pwn 4.0.
Saving your iBSS
I : After Restoring, Go to the folder that you have specified to save your iBSS file.
II : You will see folders like (Per**.tmp). Go into one of them, and youll see a folder called "Firmware". Go there. Then go to the folder "dfu".
III : Copy the iBSS file to a safe place, then you can remove the folder created by the iBSS Grabber.
STEP B : Creating custom 4.0 firmware.
I : Download sn0wbreeze from iH8sn0w.com | Jailbreak your iPod touches and iPhones and create your custom 4.0 ipsw. [How to Guide]
*Ignore the warnings after browsing for the ipsw.*
STEP C : Installing LibUSB for iRecovery
Run this mini tool to detect your O/S + Arch. Windows + Arch. Detector
WARNING : IF LIBUSB IS NOT INSTALLED PROPERLY, YOUR USB MIGHT NO LONGER WORK!
Windows XP Users download this installer LibUSB Installer
Windows Vista/7 users RUNNING 32-Bit:
* Download the installer and run it in compatibility mode for Windows XP.
If you are a 64-Bit user, follow this tutorial
Once LibUSB is installed iRecovery should be able to function now.
STEP D : Pwning iBSS + iBoot
I : Download this easy tool here Payload Pwner for 3GS // It will help you create the payloads.
**SAVE THE PAYLOADS WHERE iBooty is.**
STEP E: iBooty Prep.
Most of you know of the utility "iBooty" that I made for Aki_nG.
It will work as long as you place all of the correct files there.
I : Download iBooty GUI here iBooty for 3GS and Extract it.
II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.
III : Grab the kernelcache and bring it into the same folder as ibooty.
Also grab the iBEC from the folder "Firmware\dfu\iBEC.n88ap.RELEASE.dfu"
* Rename your iBSS 3.1.2 signed to "ibss312.dfu"
* Rename your Kernel 4.0-Custom to "kernel.40"
* Rename your iBEC 4.0-Custom to "ibec40.dfu"
Your folder should look like this :
- iboot.payload < Created with Payload Pwner.
- exploitibss312 < Created with Payload Pwner.
- ibec40.dfu < Grabbed from Custom IPSW made by sn0wbreeze.
- irecovery.exe < Comes with iBooty.
- readline5.dll < Comes with iBooty.
- iBooty.exe < Comes with iBooty.
- ibss312.dfu < THIS NEEDS TO BE YOUR iBSS from the restore!
- kernel.40 < Grab from Custom IPSW made by sn0wbreeze.
- sn0w.img3 < Comes with iBooty.
STEP F: Restoring to 4.0 + Booting
*MAKE SURE YOU ARE ON 3.1.2 WHEN DOING THIS*
I : Run iBooty and Select "Prepare Device for Custom Firmware". Run the Process and if you see a snow flake, you can proceed!
II : Now open iTunes and restore to the custom ipsw.
***WHEN DONE, YOUR DEVICE WILL HAVE A BLACK SCREEN AND NOT BOOT! ITS IN A DFU LOOP [THIS IS NORMAL!]***
STEP G : Booting
I : Just Re-Run iBooty and select "Boot It". If all goes well it will boot!
Ask me anything, .. it made my head hurt, .. but i know it works now! )
Last edited by Mozzy; 07-04-2010 at 09:15 AM. Reason: Automerged Doublepost
07-04-2010, 09:32 AM #2
yep I seen this, made me get happy until I seen you have to have your 3.1.2 SHSH blobs backed up LOL
07-04-2010, 09:34 AM #3
Yeah, I saw this last night. Wasn't worth saying much because I don't have my damn 3.1.2 blobs
07-04-2010, 09:53 AM #4
Blobs ruined my life. True story.
07-04-2010, 10:36 AM #5
Cant u downgrade to 3.1.2 and get the blobs, then update to 4.0.?
Im sure u can!!
07-04-2010, 10:41 AM #6
untehered 3.1.3 sprint jailbreak >>> this
07-04-2010, 11:46 AM #7Dont!
I was quite excited about putting iOS4 on my 3Gs this morn,
After having this about 4hrs, ive decided to downgrade to 3.1.3!
Updating this ways is VERY UNSTABLE .. my advise ...
DONT DO THIS!!
The Following User Says Thank You to Mozzy For This Useful Post:
07-04-2010, 07:12 PM #8
man, can't even downgrade 3gs unless it's previously jailbroken right?
07-05-2010, 01:39 AM #9
Good news for some, same ole' "sucks for you" for newer 3Gs users that had 3.1.3 pre-loaded.. -_- i wish the news about stuff like this would stop until every device, every boot room is ready
07-05-2010, 07:57 AM #10u need Blobs!
Yup, u need BLOBS!
Users who want to downgrade their iPhone 3G and iPhone 3GS devices after accidentally upgrading to iOS 4 will find this guide useful. It has been tested to work on both iPhone 3G and iPhone 3GS.
Please note that you need your SHSH blobs saved on cydia before you can do this downgrade.
1. Open the file CWindows\System32\drivers\etc\hosts (Windows) or /etc/hosts (Mac OS X) and add the following entry to the bottom of the file.
2. Connect your iPhone to the USB and put it into DFU mode. iTunes will display an alert stating you need to restore your device, click ok then hold option + click restore and navigate to your previously downloaded 3.1.2 FW.
3. After the restore finishes you should be hit with a 1015 error. That’s expected. Your phone should be in Recovery mode now and iTunes will tell you to restore again. Click OK then hold option + click on restore again – this time you do not have to go into DFU mode – and navigate to the 3.1.2 FW.
4. After the restore finishes again it’ll throw another 1015 error. That’s expected again. This time, just select OK and close iTunes. Fire up redsn0w – make sure it’s the 0.9.4 version – and jailbreak as normal. Uncheck all the ticks while jailbreaking.
5. After the jailbreak is finalized your device should reboot and strange enough you successfully downgraded to 3.1.2.
I didnt use No 3 and 4 .. i just booted it with iREB..
Then Activited then upgraded to 3.1.3 then SPIRITed It!
Last edited by Mozzy; 07-05-2010 at 08:03 AM.