Tuesday, July 6, 2010

[How To] Jailbreak iOS 4 iPhone 3GS (New BootRom) With Sn0wBreeze 1.7

Download RealPlayer SP for FREE

Another update has been released for the popular Sn0wbreeze 1.7 utility. The update allows jailbreaking for the iPhone 3GS new bootrom on iOS 4.0 and is available for download. With this release, you can jailbreak iPhone 3GS with new bootrom if it's on OS 3.1.2 or you've SHSH blobs saved for OS 3.1.2. In order to create a custom iOS 4 and go for 4.0 firmware successfully you have to be on OS 3.1.2+ jailbroken.

IMPORTANT:

  • First and foremost backup your data. We strongly recommend you to read through the release notes before proceeding.

  • iPhone 3GS with New BootRom users MUST be on firmware 3.1.2 or have SHSH blobs saved for it (needed for downgrade). Otherwise you’re still out of Luck. The exploit used in this hack has been patched in OS 3.1.3 so firmware 3.1.2 is a MUST. [How to Check iPhone 3GS BootRom]

  • If you’re not on 3.1.2 firmware or don’t have saved SHSH blobs for it, you’ll have to wait for the upcoming Spirit jailbreak update which is almost ready (probably when iOS 4.0.1 or 4.1 comes out).

  • For iPhone 3GS New BootRom users it’s a Tethered jailbreak. For those who don’t know, a tethered jailbreak device once turned off/Reboot/run out of battery, you need to connect it to computer and execute a tool to boot up the device.

  • This guide is NOT for regular Windows users. Proceed with precaution and follow the guide at your own risk. Here are the step by step instructions to jailbreak iPhone 3GS New BootRom to iOS 4 from the official source.

Sn0wBreeze 1.7 Supports:

  • iPhone 3GS (New & Old BootRom)

  • iPhone 3G

  • iPod Touch 3G

  • iPhone Touch 2G (MC & non-MC)

How To Jailbreak iOS 4 iPhone 3GS (New BootRom):

Required:

  • An iPhone 3GS – new bootrom

  • 3.1.2 already installed or 3.1.2 installed via SHSH blobs. <– Broken blackra1n’d devices will work. (Especially if Spirit messed you up!).

  • Payload Pwner-r3 for the 3GS

  • Sn0wbreeze V1.7

  • iBooty V1.3

  • LibUSB (64-Bit users read carefully!!!)

  • Download iOS 4.0/3.1.2

Note:

If you have Sleep issue, you will need to restore back to 3.1.2 first.

STEP 1: Installing LibUSB for iRecovery

WARNING:

If LinUSB is Not installed properly, your USB might no longer work!
  • Windows 32-Bit users: download this install — LibUSB Installer. Windows Vista/7 users RUNNING 32-Bit will have to run it in compatibility mode for Windows XP.

  • Winsows 64-Bit users: follow this tutorial — LibUSB 64-Bit
Once LibUSB is installed iRecovery should be able to function now.

STEP 2:Pwning iBEC + iBoot

**Save the Payload + iBEC where iBooty is.**

STEP 3: Making a Custom IPSW

  • Download sn0wbreeze V1.7 from here — sn0wbreeze V1.7

  • USE EXPERT MODE!

  • In General, Checkmark “Disable NOR Flash” <– THIS IS ESSENTIAL!!

  • Build it. It will be on your Desktop.


**CUSTOM BOOT LOGOS THAT ARE MADE IN sn0wbreeze WILL NOT WORK ON NEW BOOTROMS!**

**Mac Users : PwnageTool does not have this option. I don’t think it will ever be in there. Use a Windows Virtual Machine or friends PC to create your firmware.**

STEP 4: iBooty Prep.

Most of you know of the utility “iBooty” that I made for Aki_nG. It will work as long as you place all of the correct files there.
  • Download iBooty GUI — iBooty for 3GS and extract it.

  • Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.

  • Grab the kernelcache and bring it into the same folder as ibooty.

  • Aswell as DeviceTree from the folder “Firmware\all_flash\all_flash.n88ap.production\DeviceTree.n88ap”

  • Rename your Kernel 4.0-Custom to “kernel.40″

  • Rename your iBEC 4.0-Custom to “ibec.40″

  • Rename your DeviceTree 4.0-Custom to “devtree.40″
Your folder should look like this:
- iboot.payload <– Created with Payload Pwner.
- devtree.40 <– Grabbed from Custom IPSW made by sn0wbreeze.
- ibec.40 <– Created with Payload Pwner.
- irecovery.exe <– Comes with iBooty.
- readline5.dll <– Comes with iBooty.
- iBooty.exe <– Comes with iBooty.
- kernel.40 <– Grab from Custom IPSW made by sn0wbreeze.
- sn0w.img3 <– Comes with iBooty.
- wait.img3 <– Comes with iBooty.

STEP 5: Restoring to 4.0 + Booting

Note:

Make sure your are on 3.1.2 when doing this step.
  • Run iBooty and Select “Prepare Device for Custom Firmware“. Run the Process and if you see the image, you can proceed!

  • Now open iTunes and restore to the custom ipsw.
**When done, your device will go into recovery mode. It won’t boot.**

STEP 6: Booting

Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!

And you are all set to enjoy! Hopefully the dev, iH8Sn0w can get a tool out there that will make all of this much easier.

If you have an iPhone 3GS old BootRom, you can jailbreak using Sn0wBreeze 1.6, PwnageTool 4 and then unlock iOS 4 on baseband 05.12.01, Baseband 05.13.04 and 05.11.07 using UltraSn0w 0.93. And, stay tuned for more jailbreak and unlocking info by following us on Twitter and/or subscribing to our RSS feeds.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.