Tuesday, July 10, 2007

iPhone SERIAL HACKED, FULL INTERACTIVE SHELL

Our friends at #iPhone made a major breakthrough this morning.
we got a serial console working, here is how
the serial has the same pinouts as iPod serial
use a 6.8kish resistor from pin 21 to gndtie pin 11-sergnd to the real ground
use iphoneinterface to send the following commands in recovery mode:
setenv debug-uarts 1
saveenv
reboot
that should work

IT GIVES YOU A FULL INTERACTIVE SHELL
I REPEAT, A FULL INTERACTIVE SHELL

The command list is:http://iphone.fiveforty.net/geohot/cmdlist.txt

You need a level convertor, like the max 232 to make this work
DIGG: http://digg.com/apple/iPhone_serial_mode_popped_open_full_shell_access

Monday, July 9, 2007

Activation via DVD John's PAS (Phone Activation Server)

This method works by spoofing Apple's activation server. It is unclear at this point if this method works in both the Windows XP and Windows Vista versions of iTunes, and no information in available on porting this method to OS X. Details here.

Instructions step by step:
1). Download UltraEdit-32, install it.
2). Download PhoneActivationServerV1.0, extract it to desktop or anywhere you want.
3). You might wanna backup the original iTunes.exe(located under C:\Program Files\iTunes) first.
4). Run UltraEdit-32, open file iTunes.exe, use Ctrl+G to go to address 2048912, then enter 33C0C3. Do the same for the rest two offsets: Go to address 257074 then enter 28 and go to 257013 then enter 33C9B1. Save the file and close UltraEdit-32.
5). Open Windows explorer and go to c:\windows\system32\drivers\etc. Open the "hosts" file in ULTRAEDIT and add the line 127.0.0.1 albert.apple.comto it. This will redirect any DNS query of "albert.apple.com" to your local host. Save & exit.
6). All you need to do is to run Phone Activation Server V1.0 first, leave it running and then run iTunes. Now when you plug in your iphone it will activate automatically in about 60 seconds.

Tuesday, July 3, 2007

Directory Listing and Files

The iPhone directory listing and readable files can be referenced at:

http://iphone.fiveforty.net/wiki/index.php?title=694-5259-38.dmg

iPhone Root Password Cracked

The password for root is "alpine"

The "mobile" user accounts password is "dottie"