Apple The SHAtter story continues...

alidsl

I am now a lurker
OP
Member
Joined
May 27, 2009
Messages
2,823
Trophies
0
Age
28
Location
Kanto - Pallet Town
XP
688
Country
This is NOT a release
QUOTE said:
The research started and the main actor of this story is posixninja. He found why the device reboots and proposed different ideas to exploit this. posixninja also reversed tons of assembly code of the bootrom in this period, giving a support discussion to the team. We're not talking about days, but months of work. So, major props to posixninja: SHAtter would not have been possible without the clever vulnerability he found and the research he did on the bootrom.
In the meanwhile, pod2g helped on the USB reversing side and found a way to have more control over the size of the USB packets sent. The finer-grained control of the packet sizes is the key of SHAtter.

icon11.gif
Source

I think we can expect a release soon
biggrin.gif
 

iFish

Slower than a 90s modem
Member
Joined
Jul 11, 2009
Messages
4,233
Trophies
1
Age
29
Location
Montreal, QC
XP
593
Country
Canada
gameguy95 said:
if this is not released soon, i will kill something. something fuzzy...

Why can you not wait?

You have an iPod touch 2G MC model.... this exploit only works on Apple A4 devices...

Anyway. i am excited.
 

Joktan

Well-Known Member
Member
Joined
Apr 5, 2010
Messages
662
Trophies
0
Age
29
Location
In a big mansion...in Rancoon
XP
151
Country
United States
ifish said:
gameguy95 said:
if this is not released soon, i will kill something. something fuzzy...

Why can you not wait?

You have an iPod touch 2G MC model.... this exploit only works on Apple A4 devices...

Anyway. i am excited.
um i heard its for every bootrom since the new one.so it will work with everything out so far,
 

gameguy95

Needs More Furries!
Banned
Joined
Jan 27, 2009
Messages
1,119
Trophies
0
Location
Furrytown
Website
Visit site
XP
82
Country
United States
if this does not work on my MC ipod, i will find a way to delete the website and replace it with your mom's tail. and boy, it sure is better looking than your girls. trust me i saw enough of each of them to compare.
 

iFish

Slower than a 90s modem
Member
Joined
Jul 11, 2009
Messages
4,233
Trophies
1
Age
29
Location
Montreal, QC
XP
593
Country
Canada
gameguy95 said:
if this does not work on my MC ipod, i will find a way to delete the website and replace it with your mom's tail. and boy, it sure is better looking than your girls. trust me i saw enough of each of them to compare.

Start hacking the site right now. Since I am willing to bet that it will not work. SINCE THERE IS ALREADY AN EXPLOIT FOR MC MODEL!!
 

iFish

Slower than a 90s modem
Member
Joined
Jul 11, 2009
Messages
4,233
Trophies
1
Age
29
Location
Montreal, QC
XP
593
Country
Canada
gameguy95 said:
^not a bootrom exploit. besides, i tried redsnow, snowbreeze, spirit, and jailbreakme.com but none of them work with 4.1

Jailbreak me obviously, spirit obviously.

redsn0w works with it!!! I AM TELLING YOU IT DOES!!! show me how it does not work. make a video of it and show me.
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
I'm pretty sure SHAtter will work with ALL models, ALL bootroms. The only reason for the specific mention of the A4 is because it was due to the A4 that the bootrom got dumped, I think. But by the looks of that page, it works on 3GS and 3rd gen Touch, and for everything before that there already is a bootrom exploit.

also, ifish: if there is no bootrom exploit for a particular device, redsn0w will NOT work, it relies on bootrom exploits. Not sure if the "MC Model" mentioned has a bootrom exploit or not, but i thought not, in which case redsn0w will NOT work.

EDIT: Actually a closer inspection of the wiki page implies it may be true that this only works for A4 chip (S5L8930):

QUOTE said:
This is an unsigned code execution vulnerability that resides in DFU Mode of the S5L8930 bootrom.
 

iFish

Slower than a 90s modem
Member
Joined
Jul 11, 2009
Messages
4,233
Trophies
1
Age
29
Location
Montreal, QC
XP
593
Country
Canada
SifJar said:
I'm pretty sure SHAtter will work with ALL models, ALL bootroms. The only reason for the specific mention of the A4 is because it was due to the A4 that the bootrom got dumped, I think. But by the looks of that page, it works on 3GS and 3rd gen Touch, and for everything before that there already is a bootrom exploit.

also, ifish: if there is no bootrom exploit for a particular device, redsn0w will NOT work, it relies on bootrom exploits. Not sure if the "MC Model" mentioned has a bootrom exploit or not, but i thought not, in which case redsn0w will NOT work.

EDIT: Actually a closer inspection of the wiki page implies it may be true that this only works for A4 chip (S5L8930):

QUOTE said:
This is an unsigned code execution vulnerability that resides in DFU Mode of the S5L8930 bootrom.

Wanna bet there is no bootrom exploit for the MC model iPod touch 2G?
rolleyes.gif


http://theiphonewiki.com/wiki/index.php?ti...2C_1%29_Exploit

rolleyes.gif


And that has been added to redsn0w
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
Like I said, I didn't know whether there was or not. I own no iOS devices, and don't follow the iOS "scene". I just vaguely remember before hearing talk of MC devices not being jailbreak-able.
 

gameguy95

Needs More Furries!
Banned
Joined
Jan 27, 2009
Messages
1,119
Trophies
0
Location
Furrytown
Website
Visit site
XP
82
Country
United States
ifish said:
SifJar said:
I'm pretty sure SHAtter will work with ALL models, ALL bootroms. The only reason for the specific mention of the A4 is because it was due to the A4 that the bootrom got dumped, I think. But by the looks of that page, it works on 3GS and 3rd gen Touch, and for everything before that there already is a bootrom exploit.

also, ifish: if there is no bootrom exploit for a particular device, redsn0w will NOT work, it relies on bootrom exploits. Not sure if the "MC Model" mentioned has a bootrom exploit or not, but i thought not, in which case redsn0w will NOT work.

EDIT: Actually a closer inspection of the wiki page implies it may be true that this only works for A4 chip (S5L8930):

QUOTE said:
This is an unsigned code execution vulnerability that resides in DFU Mode of the S5L8930 bootrom.

Wanna bet there is no bootrom exploit for the MC model iPod touch 2G?
rolleyes.gif


http://theiphonewiki.com/wiki/index.php?ti...2C_1%29_Exploit

rolleyes.gif


And that has been added to redsn0w
but does it work or firmware 4.0+
 

iFish

Slower than a 90s modem
Member
Joined
Jul 11, 2009
Messages
4,233
Trophies
1
Age
29
Location
Montreal, QC
XP
593
Country
Canada
gameguy95 said:
ifish said:
SifJar said:
I'm pretty sure SHAtter will work with ALL models, ALL bootroms. The only reason for the specific mention of the A4 is because it was due to the A4 that the bootrom got dumped, I think. But by the looks of that page, it works on 3GS and 3rd gen Touch, and for everything before that there already is a bootrom exploit.

also, ifish: if there is no bootrom exploit for a particular device, redsn0w will NOT work, it relies on bootrom exploits. Not sure if the "MC Model" mentioned has a bootrom exploit or not, but i thought not, in which case redsn0w will NOT work.

EDIT: Actually a closer inspection of the wiki page implies it may be true that this only works for A4 chip (S5L8930):

QUOTE said:
This is an unsigned code execution vulnerability that resides in DFU Mode of the S5L8930 bootrom.

Wanna bet there is no bootrom exploit for the MC model iPod touch 2G?
rolleyes.gif


http://theiphonewiki.com/wiki/index.php?ti...2C_1%29_Exploit

rolleyes.gif


And that has been added to redsn0w
but does it work or firmware 4.0+

Can you look at the link?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    How do you know if the night will be good when you're asleep
  • BakerMan @ BakerMan:
    because i didn't say i was asleep
  • BakerMan @ BakerMan:
    i said i was sleeping...
  • BakerMan @ BakerMan:
    sleeping with uremum
  • K3Nv2 @ K3Nv2:
    Even my mum slept on that uremum
  • TwoSpikedHands @ TwoSpikedHands:
    yall im torn... ive been hacking away at tales of phantasia GBA (the USA version) and have so many documents of reverse engineering i've done
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
    Karma177 @ Karma177: @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really...