Difference between revisions of "IBoot (Bootloader)"

From The iPhone Wiki
Jump to: navigation, search
(Revisions)
(Commands used as an exploit vector: Rephrasings.)
Line 19: Line 19:
 
==Commands used as an exploit vector==
 
==Commands used as an exploit vector==
 
* Until 2.0 beta 6, the [[diags]] command would jump to code at the address provided to it. For example, if you sent "diags 0x9000000", it would directly jump to the code at written to 0x9000000. There is now a check that only allows engineering devices to utilize this backdoor.
 
* Until 2.0 beta 6, the [[diags]] command would jump to code at the address provided to it. For example, if you sent "diags 0x9000000", it would directly jump to the code at written to 0x9000000. There is now a check that only allows engineering devices to utilize this backdoor.
* In the iPod Touch 2G firmware 2.1.1 iBoot (iBoot version 385.22), the [[ARM7 Go]] command could be used to run a payload on the ARM7 in the iPod Touch 2G.
+
* For firmware 2.1.1, the [[N72ap|iPod touch 2G]] iBoot contains the [[ARM7 Go]] command, which could be used to run a payload on the ARM7 in the device.
* The [[iBoot Environment Variable Overflow]] exists in 3.0 iBoot, and is being used by [[purplera1n]] and [[redsn0w]] (as of version 0.8) in order to flash the oversized [[LLB]] which utilizes the [[24kPwn]] exploit to the iPhone 3GS. While this exploit is present on iPod Touch 2nd Gen, it is not used in favour of the [[ARM7 Go]] exploit.
+
* For firmware 3.0 and 3.0.1, the [[iBoot Environment Variable Overflow]] is used by [[purplera1n]] and [[redsn0w]] (as of version 0.8) in order to flash an oversized [[LLB]] that exploits the [[0x24000 Segment Overflow]] vulnerability.
* The [[usb_control_msg(0x21, 2) Exploit]] exists in 3.1 and 3.1.1 iBoot and is being used by [[greenpois0n]] in order to flash the oversized [[LLB]] which utilizes the [[24kPwn]] exploit to the iPhone 3GS and iPod Touch 3G. While this exploit is present on iPod Touch 2nd Gen, it is not used in favour of the [[ARM7 Go]] exploit.
+
* For firmware 3.1, 3.1.1, and 3.1.2, the [[usb_control_msg(0x21, 2) Exploit]] is used by [[greenpois0n]] and [[blackra1n]] in order to flash an oversized LLB that exploits the 0x24000 Segment Overflow vulnerability.
 
   
 
==OpeniBoot==
 
==OpeniBoot==

Revision as of 02:52, 9 November 2009

This is Apple's stage 2 bootloader for all of the iDevices. It runs what is known as Recovery Mode. It has an interactive interface which can be used over USB or serial.

Revisions

Commands used as an exploit vector

  • Until 2.0 beta 6, the diags command would jump to code at the address provided to it. For example, if you sent "diags 0x9000000", it would directly jump to the code at written to 0x9000000. There is now a check that only allows engineering devices to utilize this backdoor.
  • For firmware 2.1.1, the iPod touch 2G iBoot contains the ARM7 Go command, which could be used to run a payload on the ARM7 in the device.
  • For firmware 3.0 and 3.0.1, the iBoot Environment Variable Overflow is used by purplera1n and redsn0w (as of version 0.8) in order to flash an oversized LLB that exploits the 0x24000 Segment Overflow vulnerability.
  • For firmware 3.1, 3.1.1, and 3.1.2, the usb_control_msg(0x21, 2) Exploit is used by greenpois0n and blackra1n in order to flash an oversized LLB that exploits the 0x24000 Segment Overflow vulnerability.

OpeniBoot

There is an open source version of iBoot being made so that Linux on the iPhone will work. You can check out the source here. It is VERY useful if you are ever reversing iBoot and do not feel like finding out what certain hardware registers are yourself.

Remappings

// n88
0x4FF00000 => 0x0
0x40000000 => 0xC0000000

See also