The iPhone Wiki is no longer updated. Visit this article on The Apple Wiki for current information. |
Difference between revisions of "Limera1n"
(→Exploits) |
("Introduction" doesn't need to be a section, and numerous minor edits.) |
||
Line 1: | Line 1: | ||
+ | [[Image:Ra1ndrop.png|right]] |
||
− | ==Introduction== |
||
− | + | This is [[User:Geohot|geohot's]] [[jailbreak]] utility. It uses his undisclosed exploit, along with [[User:Comex|comex]]'s [[userland exploit]], to achieve an [[untethered jailbreak]] on newer devices. |
|
− | * [[N88ap|iPhone 3GS]] |
+ | * [[N88ap|iPhone 3GS]] |
* [[N90ap|iPhone 4]] |
* [[N90ap|iPhone 4]] |
||
* [[N72ap|iPod touch 2G]] (support announced, not released) |
* [[N72ap|iPod touch 2G]] (support announced, not released) |
||
Line 10: | Line 10: | ||
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard]. |
It has been demonstrated multiple times by [[User:Geohot|geohot]], using blog posts on his now private blog. [[User:Geohot|Geohot]] [http://1.bp.blogspot.com/_NJ4JFBfr1tY/TDgkAsTQEmI/AAAAAAAAAcw/ZNHDxMNNL4Y/s1600/iphone4.png showed off a high-res picture of Cydia on an iPhone 4]. He [http://www.youtube.com/watch?v=__TR86PLiHw displayed an iPod touch 3G with an untethered jailbreak] that met MuscleNerd's requirements for a good video. In addition, he took a [http://4.bp.blogspot.com/_NJ4JFBfr1tY/S7_OvGMqJMI/AAAAAAAAAcE/R5WLrCizGw0/s1600/ipad_jb.jpg picture of Cydia and blackra1n icons on his iPad's SpringBoard]. |
||
− | + | limera1n beta 1 was released on October 9, 2010, delaying the release of [[greenpois0n]], because [[greenpois0n]] has to be rewritten to use the limera1n exploit instead of [[SHAtter]]. It only supports Windows at the moment and some devices have issues. |
|
==Release text== |
==Release text== |
||
− | <center>limera1n, 6 months in the making<br> |
+ | <center>limera1n, 6 months in the making<br /> |
− | iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G<br> |
+ | iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G<br /> |
− | 4.0-4.1 and beyond+++<br> |
+ | 4.0-4.1 and beyond+++<br /> |
− | limera1n is unpatchable<br> |
+ | limera1n is unpatchable<br /> |
− | untethered thanks to jailbreakme star '''comex'''<br> |
+ | untethered thanks to jailbreakme star '''comex'''<br /> |
− | released today to get chronicdev to do the right thing<br> |
+ | released today to get chronicdev to do the right thing<br /> |
− | brought to you by '''geohot'''<br> |
+ | brought to you by '''geohot'''<br /> |
− | hacktivates<br> |
+ | hacktivates<br /> |
− | Mac coming soon<br> |
+ | Mac coming soon<br /> |
− | follow the instructions in the box, sadly limera1n isn't one click<br> |
+ | follow the instructions in the box, sadly limera1n isn't one click<br /> |
− | that's the price of unpatchability<br> |
+ | that's the price of unpatchability<br /> |
− | as usual, donations appreciated but not required<br> |
+ | as usual, donations appreciated but not required<br /> |
− | still in beta, pardon my ragged edges<br> |
+ | still in beta, pardon my ragged edges<br /> |
− | AppleTV is technically supported, but theres no apps yet<br> |
+ | AppleTV is technically supported, but theres no apps yet<br /> |
zero pictures of my face</center> |
zero pictures of my face</center> |
||
==Credit== |
==Credit== |
||
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]]. |
*[[User:Geohot|geohot]] - the program itself, and [[bootrom exploit]]. |
||
− | *[[User:Comex|comex]] - [[userland exploit]] that allows |
+ | *[[User:Comex|comex]] - [[userland exploit]] that allows limera1n to run [[untethered jailbreak|untethered]]. |
==Changelog== |
==Changelog== |
||
Line 38: | Line 38: | ||
|<center>'''Version'''</center> |
|<center>'''Version'''</center> |
||
|<center>'''Release time'''</center> |
|<center>'''Release time'''</center> |
||
− | |<center>''' |
+ | |<center>'''MD5 Hash'''</center> |
|<center>'''Change comment'''</center> |
|<center>'''Change comment'''</center> |
||
|- |
|- |
||
Line 64: | Line 64: | ||
==Technical Information== |
==Technical Information== |
||
=== Basics === |
=== Basics === |
||
− | * |
+ | * limera1n does not use [[SHAtter]]. |
− | * |
+ | * limera1n uses a [[bootrom exploit]] to achieve the [[tethered jailbreak]] and [[unsigned code execution]]. |
− | * |
+ | * limera1n uses a userland exploit to make the jailbreak [[Untethered jailbreak|untethered]], which was developed by [[User:Comex|comex]]. |
=== Exploits === |
=== Exploits === |
||
Line 81: | Line 81: | ||
==Controversy== |
==Controversy== |
||
− | The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the |
+ | The release of this jailbreak is specifically designed to pressure [[Chronic Dev]] into not releasing the SHAtter exploit, instead implementing the limera1n exploit into [[greenpois0n]]. Now that [[User:Geohot|geohot]] has released limera1n, releasing [[SHAtter]] would uselessly disclose another [[bootrom exploit]] to Apple. |
− | [[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the |
+ | [[User:Geohot|geohot]]'s rationale is that Apple has already discovered, through internal testing, the limera1n exploit, making it very likely that it will be fixed in the next bootrom. Because [[iBoot]] code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his limera1n exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining useful in the 5th generation iPhone should it not be disclosed at this time. |
− | + | limera1n's [[Untethered jailbreak|untethered]] userland exploit was obtained by [[User:Geohot|geohot]] under questionable circumstances from [[User:Comex|comex]]. [[User:Comex|comex]] did in fact end up giving his approval for the exploit to be included in limera1n. |
|
==External Links== |
==External Links== |
||
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action] |
* [http://loadingchanges.com/wp-content/uploads/2010/10/limetime.jpg Picture of limera1n in action] |
||
− | * [http://limera1n.com/ |
+ | * [http://limera1n.com/ limera1n.com Official limera1n site] |
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n] |
* [http://theiphonewiki.com/limera1n Mirror Site http://theiphonewiki.com/limera1n] |
||
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire] |
* [http://www.mediafire.com/?5sovoo41rbcdspw Limera1n RC Beta2 Dump on Mediafire] |
Revision as of 05:49, 11 October 2010
This is geohot's jailbreak utility. It uses his undisclosed exploit, along with comex's userland exploit, to achieve an untethered jailbreak on newer devices.
- iPhone 3GS
- iPhone 4
- iPod touch 2G (support announced, not released)
- iPod touch 3G
- iPod touch 4G
- iPad
It has been demonstrated multiple times by geohot, using blog posts on his now private blog. Geohot showed off a high-res picture of Cydia on an iPhone 4. He displayed an iPod touch 3G with an untethered jailbreak that met MuscleNerd's requirements for a good video. In addition, he took a picture of Cydia and blackra1n icons on his iPad's SpringBoard.
limera1n beta 1 was released on October 9, 2010, delaying the release of greenpois0n, because greenpois0n has to be rewritten to use the limera1n exploit instead of SHAtter. It only supports Windows at the moment and some devices have issues.
Contents
Release text
iPhone 3GS, iPod Touch 3G, iPad, iPhone 4, iPod Touch 4G
4.0-4.1 and beyond+++
limera1n is unpatchable
untethered thanks to jailbreakme star comex
released today to get chronicdev to do the right thing
brought to you by geohot
hacktivates
Mac coming soon
follow the instructions in the box, sadly limera1n isn't one click
that's the price of unpatchability
as usual, donations appreciated but not required
still in beta, pardon my ragged edges
AppleTV is technically supported, but theres no apps yet
Credit
- geohot - the program itself, and bootrom exploit.
- comex - userland exploit that allows limera1n to run untethered.
Changelog
RC1 beta 1 | 9 Oct 2010 XX:XX GMT | 2f2b09a6ed5c5613d5361d8a9d0696b6 | First release. |
RC1 beta 2 | 9 Oct 2010 XX:XX GMT | a70dccb3dfc0e505687424184dc3d1ce | Fixed kernel patching magic. Rerun BETA2+ over BETA1. |
RC1 beta 3 | 9 Oct 2010 XX:XX GMT | 81730090f7de1576268ee8c2407c3d35 | Fixed an issue with iPhone 3GS (new bootrom) |
RC1 beta 4 | 9 Oct 2010 XX:XX GMT | d901c4b3a544983f095b0d03eb94e4db | Uninstall fixed, respring fixed |
Technical Information
Basics
- limera1n does not use SHAtter.
- limera1n uses a bootrom exploit to achieve the tethered jailbreak and unsigned code execution.
- limera1n uses a userland exploit to make the jailbreak untethered, which was developed by comex.
Exploits
Details of the bootrom exploit to follow.
Process
The jailbreak appears to execute something like the following (in no particular order):
- In recovery1,
"setenv debug-uarts 1 setenv auto-boot false saveenv"
Controversy
The release of this jailbreak is specifically designed to pressure Chronic Dev into not releasing the SHAtter exploit, instead implementing the limera1n exploit into greenpois0n. Now that geohot has released limera1n, releasing SHAtter would uselessly disclose another bootrom exploit to Apple.
geohot's rationale is that Apple has already discovered, through internal testing, the limera1n exploit, making it very likely that it will be fixed in the next bootrom. Because iBoot code is present both in the bootrom and firmware, and because firmware is refreshed much more often that bootrom code, any fix in this code branch would appear first in firmware. geohot observed his limera1n exploit was closed in firmware and concluded that it would almost certainly be fixed in the next bootrom revision, whereas SHAtter still has a chance of remaining useful in the 5th generation iPhone should it not be disclosed at this time.
limera1n's untethered userland exploit was obtained by geohot under questionable circumstances from comex. comex did in fact end up giving his approval for the exploit to be included in limera1n.