Your favorite Apple, iPhone, iPad, iOS, Jailbreak, and Cydia site.
07-19-2011, 08:11 PM #1How can I get iP4 out of restore mode without updating the baseband?
Picked up a $50 iPhone 4 today that had a shattered back and had the "iPhone is disable" message on it due to too many failed passcode attempts. I put it in restore mode to see what color the iTunes logo would be before doing a restore and its the older silver CD logo. So I know its running iOS 4.1 or lower. I'm hoping I scored a 4.0.x firmware and can unlock it. Problem is, the phone doesn't have files saved (tried restoring to 4.3.3 using pwnage) and even if I guessed the firmware correctly using redsnow, its disabled because of the passcode issue.
Any ideas how I can do a custom restore to 4.3.4? Will snowbreeze do this yet? I have a MacBook so I'm not up on snowbreeze but if it can get me custom 4.3.4, I can get access to a PC to do it. Help me out ya'll, thanks!
07-20-2011, 08:52 AM #2
If you believe it is 4.1 or lower then you can always try bypassing the passcode screen. However if the device is not yours (which is why the passcode screen would be on is my guess) then more than likely its going to get blacklisted eventually.
The bypass will only work if you're on 4.1 or lower from what I have tested. I tried this on 4.2.1 and 4.3.3 and it didn't work.
Turn the device on and get to the passcode screen
Go the emergency call screen and dial any random number
Hit the call button and immediately hit the power button.
You should now be in the phone dialer keypad screen
07-20-2011, 09:01 AM #3
07-20-2011, 09:04 AM #4
As far as I know thats the only bypass for the passcode screen. It was a major flaw and Apple had it patched up in the next update after 4.1
07-20-2011, 09:15 AM #5
Extract blobs.( this is shud tell u firmware )
Make signed ipsw
07-20-2011, 10:56 AM #6
07-20-2011, 11:31 AM #7
07-20-2011, 11:40 AM #8
I'm not denying your post about using ifaith. I am simply stating that ifaith will only pick up what it sees.
Last edited by ihappy; 07-20-2011 at 11:53 AM.
07-20-2011, 12:19 PM #9
Ifaith dumps shsh even if they are not on Cydia and tu.
All devices which run x firmware has x blobs. Ifaith is the only software which can dump/extract the blob of the firmware the device is running on even when U are terribly misinformed.
iFaith is the first public SHSH Dumper that dumps the SHSH blobs for the current iOS revision running on your iDevice.
I have estracted numerous blobs using it. Adviced many ppl to use it. I know am not wrong :-)
when your device comes from Apple, it comes with a firmware pre-installed. If Apple is no longer signing that firmware, you wouldn't be able to save the SHSH blobs in the past. With ih8sn0ws new tool, you can dump the SHSH blob directly from your currently installed firmware. The way this works is that Apple has signed image files that show up during the boot sequence with the SHSH blob. iFaith allows you to dump your SHSH key directly from those files.
After you have dumped the files, you then patch the firmware file you are trying to downgrade to with your SHSH key, this firmware file is considered a signed firmware file. Once you have created it, you simply restore it in Pwned-DFU mode just like you would if you were restoring any other custom firmware. iFaith is compatible with mostly all iDevices except for the iPad2 and a few others.
Last edited by xtacy; 07-20-2011 at 12:29 PM.
07-20-2011, 01:44 PM #10
You are correct. I understand what you are saying now.
But now am I to believe that after you extract the shsh blobs and create a signed ipsw with the shsh blobs intact using ifaith that it will preserve the baseband as he clearly is trying to do??
Last edited by ihappy; 07-20-2011 at 01:47 PM.
07-20-2011, 03:12 PM #11
If he is on 4.1 the baseband won't b unlockable . If he is 4.0 it will be. Baseband won't change
07-20-2011, 03:15 PM #12
Interesting. So basically ifaith not only extracts the shsh blobs of the current fw on the device but it also preserves the current baseband as well. Thanks for that insight.
07-20-2011, 03:28 PM #13
Nopes. Doesn't preserve. But the fact that we don know the current firmware doesn't help. I misquoted my statement.
07-20-2011, 03:44 PM #14
Create a custom fw using pwnage tool or sn0wbreeze to preserve said baseband and still use the extracted shsh blobs to restore??
I'm just brainstorming here. I haven't done this procedure before
07-20-2011, 03:58 PM #15
Technically yeah :-)
07-20-2011, 05:05 PM #16
Is iFaith osx compatible? The phone could potentially be running 4.1 and thus all of this be in vain since 4.1 has a baseband I can't unlock. I just figured it was worth a shot and maybe I'll get lucky running 4.0.x
Last edited by jdm.accord; 07-20-2011 at 05:09 PM.
07-20-2011, 05:10 PM #17
07-20-2011, 06:34 PM #18
07-20-2011, 09:31 PM #19
so I fired up my old PC (07 model running vista) and tried to get iFaith. Every time I download it from any source, the zip file is empty. I have the .NET 2.0 framework or whatever already installed as part of Vista. Any help would be appreciated
07-21-2011, 12:32 AM #20
Try another mirror :-)
Ih8sn0w sux that guy is a rude ***