The iPhone Wiki is no longer updated. Visit this article on The Apple Wiki for current information. |
Difference between revisions of "Limera1n"
(→Changelog) |
(→Changelog) |
||
Line 16: | Line 16: | ||
==Changelog== |
==Changelog== |
||
===RC1 beta 1=== |
===RC1 beta 1=== |
||
− | ''md5: 2f2b09a6ed5c5613d5361d8a9d0696b6'' |
+ | ''md5: 2f2b09a6ed5c5613d5361d8a9d0696b6''<br> |
First release. |
First release. |
||
===RC1 beta 2=== |
===RC1 beta 2=== |
||
− | ''md5: a70dccb3dfc0e505687424184dc3d1ce'' |
+ | ''md5: a70dccb3dfc0e505687424184dc3d1ce''<br> |
Fixed kernel patching magic. Rerun BETA2+ over BETA1. |
Fixed kernel patching magic. Rerun BETA2+ over BETA1. |
||
===RC1 beta 3=== |
===RC1 beta 3=== |
||
− | ''md5: 81730090f7de1576268ee8c2407c3d35'' |
+ | ''md5: 81730090f7de1576268ee8c2407c3d35''<br> |
Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]]) |
Fixed an issue with [[N88ap|iPhone 3GS]] ([[iBoot-359.3.2|new bootrom]]) |
||
===RC1 beta 4=== |
===RC1 beta 4=== |
||
− | ''md5: d901c4b3a544983f095b0d03eb94e4db'' |
+ | ''md5: d901c4b3a544983f095b0d03eb94e4db''<br> |
Uninstall fixed, respring fixed |
Uninstall fixed, respring fixed |
||
Revision as of 12:24, 10 October 2010
This is geohot's jailbreak utility. It uses his undisclosed exploit, along with comex's userland exploit, to achieve an untethered jailbreak on newer devices.
- iPhone 3GS (New bootrom is now working with Beta 3)
- iPhone 4
- iPod touch 2G (support announced, not released)
- iPod touch 3G
- iPod touch 4G
- iPad
It has been demonstrated multiple times by geohot, using blog posts on his now private blog. Geohot showed off a high-res picture of Cydia on an iPhone 4. He displayed an iPod touch 3G with an untethered jailbreak that met MuscleNerd's requirements for a good video. In addition, he took a picture of Cydia and blackra1n icons on his iPad's SpringBoard.
limera1n was released on October 9, 2010, delaying the release of greenpois0n. It only supports Windows at the moment and a large number of devices have issues.
Contents
Credit
Changelog
RC1 beta 1
md5: 2f2b09a6ed5c5613d5361d8a9d0696b6
First release.
RC1 beta 2
md5: a70dccb3dfc0e505687424184dc3d1ce
Fixed kernel patching magic. Rerun BETA2+ over BETA1.
RC1 beta 3
md5: 81730090f7de1576268ee8c2407c3d35
Fixed an issue with iPhone 3GS (new bootrom)
RC1 beta 4
md5: d901c4b3a544983f095b0d03eb94e4db
Uninstall fixed, respring fixed
Technical Information
Basics
- This does not use SHAtter.
- This uses a bootrom exploit to achieve the tethered jailbreak and unsigned code execution.
- This uses a userland exploit to make the jailbreak untethered, which geohot obtained under questionable circumstances from comex.
Exploits
limera1n uses an undisclosed bootrom exploit.
Process
The jailbreak appears to execute something like the following (in no particular order):
- In recovery1,
"setenv debug-uarts 1 setenv auto-boot false saveenv"
- In DFU, it uploads a payload.
- In recovery2, it uploads another payload and its ramdisk.
Controversy
The release of this jailbreak is specifically designed to pressure Chronic Dev into implementing the exploits in limera1n into greenpois0n. Now that geohot has released limera1n, SHAtter can't be released without major negative backlash from other hackers, as this would burn a bootrom exploit.