10.3.3_14G60_Restore.ipsw
[+] Installing dependencies
Updating Homebrew...
Warning: libtool 2.4.6_1 is already installed and up-to-date
To reinstall 2.4.6_1, run brew reinstall libtool
Warning: automake 1.16.1_1 is already installed and up-to-date
To reinstall 1.16.1_1, run brew reinstall automake
Warning: lsusb 1.0 is already installed and up-to-date
To reinstall 1.0, run brew reinstall lsusb
Warning: openssl 1.0.2t is already installed and up-to-date
To reinstall 1.0.2t, run brew reinstall openssl
Warning: libzip 1.5.2 is already installed and up-to-date
To reinstall 1.5.2, run brew reinstall libzip
Warning: pkg-config 0.29.2 is already installed and up-to-date
To reinstall 0.29.2, run brew reinstall pkg-config
Warning: libusbmuxd HEAD-53e832a_1 is already installed and up-to-date
To reinstall HEAD_1, run brew reinstall libusbmuxd
Warning: Already linked: /usr/local/Cellar/libusbmuxd/HEAD-53e832a_1
To relink: brew unlink libusbmuxd && brew link libusbmuxd
Warning: libimobiledevice HEAD-af91dc6_5 is already installed and up-to-date
To reinstall HEAD_5, run brew reinstall libimobiledevice
Warning: Already linked: /usr/local/Cellar/libimobiledevice/HEAD-af91dc6_5
To relink: brew unlink libimobiledevice && brew link libimobiledevice
Error: libplist 2.1.0 is already installed
To install HEAD, first run brew unlink libplist.
Warning: Skipping (old) /usr/local/Cellar/libplist/2.1.0 due to it being linked
Warning: Already linked: /usr/local/Cellar/libplist/2.1.0
To relink: brew unlink libplist && brew link libplist
From https://github.com/MatthewPierson/ipwndfu_public
branch master -> FETCH_HEAD
Already up to date.
2019-11-18 17:31:59.811 system_profiler[47507:198988] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
checkm8 exploit by axi0mX modified version by Linus Henze s5l8965x support by Matthew Pierson
Found: CPID:8960 CPRV:11 CPFM:03 SCEP:01 BDID:00 ECID:000005F549020150 IBFL:1C SRTG:[iBoot-1704.10]
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:32:27.606 system_profiler[48331:200312] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:32:43.321 system_profiler[49056:201480] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:32:59.027 system_profiler[49781:202623] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
checkm8 exploit by axi0mX modified version by Linus Henze s5l8965x support by Matthew Pierson
Found: CPID:8960 CPRV:11 CPFM:03 SCEP:01 BDID:00 ECID:000005F549020150 IBFL:1C SRTG:[iBoot-1704.10]
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:33:27.198 system_profiler[50506:203810] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:33:42.911 system_profiler[51231:204949] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:33:58.619 system_profiler[51956:206083] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
checkm8 exploit by axi0mX modified version by Linus Henze s5l8965x support by Matthew Pierson
Found: CPID:8960 CPRV:11 CPFM:03 SCEP:01 BDID:00 ECID:000005F549020150 IBFL:1C SRTG:[iBoot-1704.10]
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:34:26.822 system_profiler[52681:207251] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:34:42.537 system_profiler[53406:208389] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
ERROR: No Apple device in DFU Mode 0x1227 detected after 5.00 second timeout. Exiting.
2019-11-18 17:34:58.249 system_profiler[54131:209531] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
No matching processes belonging to you were found
Waiting 10 seconds to allow you to enter DFU mode
Attempting to get into pwndfu mode
Please just enter DFU mode again on each reboot
The script will run ipwndfu again and again until the device is in PWNDFU mode
checkm8 exploit by axi0mX modified version by Linus Henze s5l8965x support by Matthew Pierson
Found: CPID:8960 CPRV:11 CPFM:03 SCEP:01 BDID:00 ECID:000005F549020150 IBFL:1C SRTG:[iBoot-1704.10]
Device is now in pwned DFU Mode.
(12.40 seconds)
2019-11-18 17:35:21.351 system_profiler[54856:210694] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be
SecureROM Signature check remover by Linus Henze
Found: CPID:8960 CPRV:11 CPFM:03 SCEP:01 BDID:00 ECID:000005F549020150 IBFL:1C SRTG:[iBoot-1704.10] PWND:[checkm8]
Applying patches...
Successfully applied patches
Resetting device state
This will effectiveley disable pwned DFU Mode
Only the signature patches will remain
Device is now ready to accept unsigned images
We seem to be in pwned DFU mode!
[+] Build folder exists! If the script doesn't work please delete the 'Build' folder and run it again
shsh/stitch.shsh2
shsh
Killing iTunes as this will be quite annoying with what we are going to do.
No matching processes belonging to you were found
unzip: cannot find or open iPhone_4.0_64bit_10.3.3_14G60_Restore.ipsw, iPhone_4.0_64bit_10.3.3_14G60_Restore.ipsw.zip or iPhone_4.0_64bit_10.3.3_14G60_Restore.ipsw.ZIP.
cp: ipsw/Firmware/Mav7Mav8-7.60.00.Release.bbfw: No such file or directory
README.md iBoot64Patcher ipsw manifests shsh
build igetnonce ipwndfu_public restore.sh
Supported Device
iPhone6,1
Supported device found.
6551049994576
mv: rename ipsw/Firmware/dfu/.iphone6.im4p to ./.iphone6.im4p: No such file or directory
cp: ipsw/Firmware/all_flash/sep-firmware.n51.RELEASE.im4p: No such file or directory
img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182
img4tool: failed with exception:
[exception]:
what=failed to read lastArgFile
code=17956872
line=274
file=main.cpp
commit count=26:
commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd:
img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182
img4tool: failed with exception:
[exception]:
what=failed to read lastArgFile
code=17956872
line=274
file=main.cpp
commit count=26:
commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd:
main: Starting...
libc++abi.dylib: terminating with uncaught exception of type tihmstar::OFexception: std::exception
./restore.sh: line 311: 55710 Abort trap: 6 ./iBoot64Patcher iBSS.raw iBSS.prepatched
main: Starting...
libc++abi.dylib: terminating with uncaught exception of type tihmstar::OFexception: std::exception
./restore.sh: line 311: 55711 Abort trap: 6 ./iBoot64Patcher iBEC.raw iBEC.prepatched
img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182
img4tool: failed with exception:
[exception]:
what=failed to read lastArgFile
code=17956872
line=274
file=main.cpp
commit count=26:
commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd:
img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182
img4tool: failed with exception:
[exception]:
what=failed to read lastArgFile
code=17956872
line=274
file=main.cpp
commit count=26:
commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd:
Version: 78c1203bcb326dcc813cc24cce2df6b88c01eef4 - 301
libfragmentzip version: 0.58-ffec726ea514d8b8f3f3e42d04ce1430f3889747
[TSSC] manually specified ECID to use, parsed "6551049994576" to dec:6551049994576 hex:5f549020150
[TSSC] opening manifests/BuildManifest_iPhone6,1_1033_OTA.plist
[TSSR] Request URL set to https://gs.apple.com/TSS/controller?action=2
[TSSR] Sending TSS request attempt 1... success
also requesting APTicket for installType=Update
[Error] [TSSR] Error: could not get id0 for installType=Update
[WARNING] [TSSR] failed to build tssrequest for alternative installType
[TSSR] User specified doesn't to request a baseband ticket.
[TSSR] Request URL set to https://gs.apple.com/TSS/controller?action=2
[TSSR] Sending TSS request attempt 1... failure
[Error] ERROR: TSS request failed (status=128, message=An internal error occurred.)
Saved shsh blobs!
iOS 10.3.3 for device iPhone6,1 IS being signed!
shsh/6551049994576_iPhone6,1_10.3.3-14G60_e5be1eb12e1b25413f872b6336ffd5d09ab75032.shsh2 -> shsh/stitch.shsh2
img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182
img4tool: failed with exception:
[exception]:
what=assure failed
code=4653074
line=71
file=ASN1DERElement.cpp
commit count=26:
commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd:
img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182
img4tool: failed with exception:
[exception]:
what=assure failed
code=4653074
line=71
file=ASN1DERElement.cpp
commit count=26:
commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd:
cp: iBSS.img4: No such file or directory
cp: iBEC.img4: No such file or directory
zip warning: name not matched: *
zip error: Nothing to do! (try: zip -r9 ../downgrade.ipsw . -i *)
[==================================================] 100.0%
Version: 78c1203bcb326dcc813cc24cce2df6b88c01eef4 - 301
libfragmentzip version: 0.58-ffec726ea514d8b8f3f3e42d04ce1430f3889747
[TSSC] manually specified ECID to use, parsed "6551049994576" to dec:6551049994576 hex:5f549020150
[TSSC] manually specified apnonce to use, parsed "05518e4c905b01f7f210d65626e25fecb8f5d29f" to hex:05518e4c905b01f7f210d65626e25fecb8f5d29f
[TSSC] opening manifests/BuildManifest_iPhone6,1_1033_OTA.plist
[TSSR] Request URL set to https://gs.apple.com/TSS/controller?action=2
[TSSR] Sending TSS request attempt 1... success
also requesting APTicket for installType=Update
[Error] [TSSR] Error: could not get id0 for installType=Update
[WARNING] [TSSR] failed to build tssrequest for alternative installType
[TSSR] User specified doesn't to request a baseband ticket.
[TSSR] Request URL set to https://gs.apple.com/TSS/controller?action=2
[TSSR] Sending TSS request attempt 1... failure
[Error] ERROR: TSS request failed (status=128, message=An internal error occurred.)
Saved shsh blobs!
iOS 10.3.3 for device iPhone6,1 IS being signed!
6551049994576_iPhone6,1_10.3.3-14G60_05518e4c905b01f7f210d65626e25fecb8f5d29f.shsh -> shsh/apnonce.shsh2
Done prepping files! Time to downgrade!!!
RESTORING!
Waiting for device to reconnect...
Version: 7e66824796f697ea54597dadbdba462382f004b9 - 247
Odysseus support: no
[INFO] 64-bit device detected
futurerestore init done
reading signing ticket shsh/apnonce.shsh2 is done
Found device iPhone6,1 n51ap
[Error] failed to read SEP
[Error] Fail code=-15
Failed with errorcode=-15
Cleaning up :D
dummy_file
ipsw
If you see this, we're done! Shoutout to the devs and Matty for making this possible! - Merculous
P.S. You know, this could look even better and be even easier if we port it to Python :D
10.3.3_14G60_Restore.ipsw [+] Installing dependencies Updating Homebrew... Warning: libtool 2.4.6_1 is already installed and up-to-date To reinstall 2.4.6_1, run
brew reinstall libtool
Warning: automake 1.16.1_1 is already installed and up-to-date To reinstall 1.16.1_1, runbrew reinstall automake
Warning: lsusb 1.0 is already installed and up-to-date To reinstall 1.0, runbrew reinstall lsusb
Warning: openssl 1.0.2t is already installed and up-to-date To reinstall 1.0.2t, runbrew reinstall openssl
Warning: libzip 1.5.2 is already installed and up-to-date To reinstall 1.5.2, runbrew reinstall libzip
Warning: pkg-config 0.29.2 is already installed and up-to-date To reinstall 0.29.2, runbrew reinstall pkg-config
Warning: libusbmuxd HEAD-53e832a_1 is already installed and up-to-date To reinstall HEAD_1, runbrew reinstall libusbmuxd
Warning: Already linked: /usr/local/Cellar/libusbmuxd/HEAD-53e832a_1 To relink: brew unlink libusbmuxd && brew link libusbmuxd Warning: libimobiledevice HEAD-af91dc6_5 is already installed and up-to-date To reinstall HEAD_5, runbrew reinstall libimobiledevice
Warning: Already linked: /usr/local/Cellar/libimobiledevice/HEAD-af91dc6_5 To relink: brew unlink libimobiledevice && brew link libimobiledevice Error: libplist 2.1.0 is already installed To install HEAD, first runbrew unlink libplist
. Warning: Skipping (old) /usr/local/Cellar/libplist/2.1.0 due to it being linked Warning: Already linked: /usr/local/Cellar/libplist/2.1.0 To relink: brew unlink libplist && brew link libplist From https://github.com/MatthewPierson/ipwndfu_publiciOS 10.3.3 for device iPhone6,1 IS being signed! shsh/6551049994576_iPhone6,1_10.3.3-14G60_e5be1eb12e1b25413f872b6336ffd5d09ab75032.shsh2 -> shsh/stitch.shsh2 img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182 img4tool: failed with exception: [exception]: what=assure failed code=4653074 line=71 file=ASN1DERElement.cpp commit count=26: commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd: img4tool version: 0.163-c3df16cb998d5013aef092baeb71908475366182 img4tool: failed with exception: [exception]: what=assure failed code=4653074 line=71 file=ASN1DERElement.cpp commit count=26: commit sha =4c96389db50eeb7411f6e4c62eb073ef401ca6bd: cp: iBSS.img4: No such file or directory cp: iBEC.img4: No such file or directory zip warning: name not matched: *
zip error: Nothing to do! (try: zip -r9 ../downgrade.ipsw . -i *) [==================================================] 100.0% Version: 78c1203bcb326dcc813cc24cce2df6b88c01eef4 - 301 libfragmentzip version: 0.58-ffec726ea514d8b8f3f3e42d04ce1430f3889747 [TSSC] manually specified ECID to use, parsed "6551049994576" to dec:6551049994576 hex:5f549020150 [TSSC] manually specified apnonce to use, parsed "05518e4c905b01f7f210d65626e25fecb8f5d29f" to hex:05518e4c905b01f7f210d65626e25fecb8f5d29f [TSSC] opening manifests/BuildManifest_iPhone6,1_1033_OTA.plist [TSSR] Request URL set to https://gs.apple.com/TSS/controller?action=2 [TSSR] Sending TSS request attempt 1... success also requesting APTicket for installType=Update [Error] [TSSR] Error: could not get id0 for installType=Update [WARNING] [TSSR] failed to build tssrequest for alternative installType [TSSR] User specified doesn't to request a baseband ticket. [TSSR] Request URL set to https://gs.apple.com/TSS/controller?action=2 [TSSR] Sending TSS request attempt 1... failure [Error] ERROR: TSS request failed (status=128, message=An internal error occurred.) Saved shsh blobs!
iOS 10.3.3 for device iPhone6,1 IS being signed! 6551049994576_iPhone6,1_10.3.3-14G60_05518e4c905b01f7f210d65626e25fecb8f5d29f.shsh -> shsh/apnonce.shsh2 Done prepping files! Time to downgrade!!! RESTORING! Waiting for device to reconnect... Version: 7e66824796f697ea54597dadbdba462382f004b9 - 247 Odysseus support: no [INFO] 64-bit device detected futurerestore init done reading signing ticket shsh/apnonce.shsh2 is done Found device iPhone6,1 n51ap [Error] failed to read SEP [Error] Fail code=-15 Failed with errorcode=-15 Cleaning up :D dummy_file ipsw If you see this, we're done! Shoutout to the devs and Matty for making this possible! - Merculous P.S. You know, this could look even better and be even easier if we port it to Python :D