Jailbreak iPhone 3GS, iOS 4, New Bootrom, on Mac [How to Guide]
Ok guys.. Mac version of the guide is now up! (Windows version can be found here) The requirements though as mentioned earlier remains the same. You will need a iPhone 3GS (with newbootrom) on iOS 4, which has SHSH blobs saved for iPhone 3.1.2. Some other important notes about the jailbreak are as follows.
1) it is a tethered jailbreak (whenever you turn off your phone, you will need to re-connect it to a computer to be able to turn it back on) and
If you meet all the requirements, and have lots of patience, you can follow the guide posted below to jailbreak your iPhone 3GS (with new bootrom) on iOS 4.
Warning Note: All the standard warnings apply. This is for advanced users only. Only proceed if you think you know your iPhone inside out.
Pwning 4.0 on New Bootrom 3G[S] w/3.1.2 SHSH Blobs [Mac]
Credits to iH8sn0w. Thanks to lilstevie for help. Required: libusb-1.0 xpwntool iOS 3.1.2, 4.0 iOS 3.1.2 SHSH blobs Download this (http://www.mediafire.com/?mmn1nnjlqoy) STEP 1 : Grabbing your 3.1.2 iBSS file. Pointing your hosts : I : If you have your shsh blobs saved on Cydia/Saurik’s server then follow this tutorial. — http://saurik.com/id/12 II : If you have it saved with TinyUmbrella, then download the GUI here. — http://thefirmwareumbrella.blogspot.com/ ——- Restoring to grab the iBSS file. I : Place your device in DFU. II : Start up the iBSS/iBEC grabber. III : Put the save folder on a new folder on your desktop. IV : Hit "Start Monitoring". V : Now go back to iTunes and do SHIFT + Restore. Then browse for your 3.1.2 IPSW. You will need to restore to 3.1.2 in order to pwn 4.0. STEP 2: Creating your custom firmware Use Pwanage Tool (blog.iphone-dev.org) to create a custom ipsw ignore the warnings about the new bootrom. STEP 3: Extract the zip file we downloaded earlier and use terminal to enter it STEP 4: Create a new folder inside this called 3.1.2 and extract your 3.1.2 ipsw here (unzip *.ipsw in terminal) STEP 5: Use xpwntool to patch iBoot & iBSS (run this in terminal)
STEP 6: Create a folder called 4.0_cust inside 4.0_pwn and enter it with terminal and copy your custom 4.0 ipsw here. STEP 7: Extract your custom ipsw (unzip *.zip) STEP 8: Run the following in terminal:
cp kernelcache.release.n88 ../kcache.40; cp Firmware/dfu/iBEC.n88ap.RELEASE.dfu ../iBEC.40; cd ..;
STEP 9: Copy your signed iBSS from earlier into 4.0_pwn STEP 10: Place your device in dfu mode (power home for 10 seconds, release power keep holding home (blank screen and itunes asking to restore). STEP 11: Run the following in terminal: