Thread: SHSH - A Thing of the Past?
-
12-11-2010, 01:47 PM #1
SHSH - A Thing of the Past?
you guys see this thing about tinyumbrella not needing shsh files to restore any more?
check it out, what do you think?
iClarified - Apple News - TinyUmbrella Update Will Bypass SHSH Checks and Restore iDevice Without iTunes
-
12-11-2010, 05:05 PM #2Super Moderator
- Join Date
- Feb 2008
- Location
- Vancouver, Canada
- Posts
- 13,014
- Thanks
- 67
- Thanked 2,658 Times in 2,549 Posts
Interesting, we will wait for his release. Thanks

-
12-11-2010, 05:19 PM #3
Interesting...let's see how this plays out...

-
12-11-2010, 05:29 PM #4Super Duper Moderator
- Join Date
- Aug 2008
- Location
- Valley of the Sun, Arizona
- Posts
- 23,538
- Thanks
- 2,822
- Thanked 7,443 Times in 4,768 Posts
Pretty cool. This should be awesome if it does what it says it does.

-
12-11-2010, 06:32 PM #5Super Otiose Mod
- Join Date
- Aug 2010
- Location
- Elsewhere.
- Posts
- 3,740
- Thanks
- 37
- Thanked 346 Times in 315 Posts
So Semaphore possibly used my suggestion (there's no way I could have been the first one to suggest it, or if the suggestion actually works, et cetera) to fool the bootrom.
Exciting stuff, y'all. Cue school-girl-level-giddyness.
EDIT: I shouldn't be such a tease, considering the underlying exploit is both publicly released and in hardware. How I believe (supposition, not known facts) this might work:
I believe that the "SHSH" tag in the IMG3 firmware that is bootrom-checked is taken directly from the "PartialDigest" file in the SHSH blob, verified by the certificate attached.
That field should be the same across all SHSH blobs for any one piece (e.g., iBoot or LLB) for all devices on a particular firmware. For example, examine the blobs for 4.1 for the two 3GS units, ECIDs 0x276DA09B54C and 0x3C7C60A9D2E, available on Cydia (and devices I have control over).
They both have the same "partialdigest" for iBoot (in base64, QAAAAHihAgBax0aH0zfEwI2fcUAmdq9TrlLTXQ==). Further examination shows all 19 or so "partialdigest" values are shared across both devices.
Because of the way I believe limera1n works, we should be able to artificially inject code into the IMG3 files.
Therefore, I believe we can insert the correct ECID (known) and SHSH (since Cydia has a PartialDigest as part of the blob on file for at least one device since iOS 3.0, and since I hypothesize that these values are shared across all devices, therefore known for all firmwares) into the appropriate locations in an IMG3 file, and the bootrom will approve these correctly signed- and digested- values without an accompanying certificate/blob.
Or that's at least how I think it'd work.
MODERATORS: If you know this supposition to be factually incorrect, or believe this information needs to be suppressed to preserve exploits, please remove/redact at your discretion.Last edited by Orby; 12-11-2010 at 06:59 PM.

-
12-11-2010, 07:21 PM #6Superbad Moderator
- Join Date
- Nov 2007
- Location
- Bermuda
- Posts
- 38,289
- Thanks
- 1,933
- Thanked 5,991 Times in 4,294 Posts
Anybody else get that whooossh over their head? You are a smart guy orb
-
12-11-2010, 07:24 PM #7Super Otiose Mod
- Join Date
- Aug 2010
- Location
- Elsewhere.
- Posts
- 3,740
- Thanks
- 37
- Thanked 346 Times in 315 Posts
-
12-11-2010, 07:27 PM #8Superbad Moderator
- Join Date
- Nov 2007
- Location
- Bermuda
- Posts
- 38,289
- Thanks
- 1,933
- Thanked 5,991 Times in 4,294 Posts
Well you seem to have a very strong knowledge of the inner workings of the exploits and how they work. My knowledge doesnt go that deep for sure. I am more of a expert in what is needed for what and how to use them.
-
12-11-2010, 08:41 PM #9Super Duper Moderator
- Join Date
- Aug 2008
- Location
- Valley of the Sun, Arizona
- Posts
- 23,538
- Thanks
- 2,822
- Thanked 7,443 Times in 4,768 Posts
-
12-11-2010, 08:43 PM #10Superbad Moderator
- Join Date
- Nov 2007
- Location
- Bermuda
- Posts
- 38,289
- Thanks
- 1,933
- Thanked 5,991 Times in 4,294 Posts
-
-
12-12-2010, 02:19 AM #11
It definatly makes sense commonality exists. Building a unique hardware / software checker common to all devices that absolutely will not fail in the 100M+ unit field is a daunting task even for Apple. Unfortunately, they will continue to add and refine this technique in future generations.
The cat & mouse game continues. We must remain dilligent
.



LinkBack URL
About LinkBacks
Reply With Quote

