MatthewPierson / checkm8-nonce-setter

A nonce setter for devices compatible with checkm8
216 stars 77 forks source link

iPhone x no recovery mode #9

Closed salvatore8686 closed 5 years ago

salvatore8686 commented 5 years ago

Hi bro,Thank you for sharing this excellent instrument, With iPhone 5s I don't have any problems, It works well, While with iPhone X he can't send him to recovery mode. What can it be? Thanks 🙏 ( macOS Mojave version 10.14.6)

Matty's Checkm8 APNonce Setter Do you want to input a generator? (y,n) y Please enter your desiered generator. 0x1111111111111111 Your generator is 0x1111111111111111 0x1111111111111111 Supported Device iPhone10,6 Supported device found. Please connect device in DFU mode. Press enter when ready to continue

Cloning into 'ipwndfu'... remote: Enumerating objects: 432, done. remote: Total 432 (delta 0), reused 0 (delta 0), pack-reused 432 Receiving objects: 100% (432/432), 1.90 MiB | 3.29 MiB/s, done. Resolving deltas: 100% (217/217), done. Starting ipwndfu 2019-11-25 19:05:12.317 system_profiler[33601:127409] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:12.318 system_profiler[33601:127409] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:12.319 system_profiler[33601:127409] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:12.320 system_profiler[33601:127409] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:12.321 system_profiler[33601:127409] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:12.322 system_profiler[33601:127409] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be No matching processes belonging to you were found Waiting 10 seconds to allow you to enter DFU mode Attempting to get into pwndfu mode Please just enter DFU mode again on each reboot The script will run ipwndfu again and again until the device is in PWNDFU mode checkm8 exploit by axi0mX Found: CPID:8015 CPRV:11 CPFM:03 SCEP:01 BDID:0E ECID:000908590498402E IBFL:3C SRTG:[iBoot-3332.0.0.1.23] Device is now in pwned DFU Mode. (2.92 seconds) 2019-11-25 19:05:27.552 system_profiler[35417:130188] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:27.552 system_profiler[35417:130188] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:27.553 system_profiler[35417:130188] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:27.553 system_profiler[35417:130188] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:27.554 system_profiler[35417:130188] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be 2019-11-25 19:05:27.555 system_profiler[35417:130188] SPUSBDevice: IOCreatePlugInInterfaceForService failed 0xe00002be Device is an iPhone X, using akayn's signature check remover Heap repaired. Bootrom Patched you can now load unsigned firmware and debug the next boot stages Device is now in PWNDFU mode with signature checks removed (Thanks to Linus Henze & akayn) Entering PWNREC mode Entered PWNREC mode Current nonce NONC: a70c80fffaf615a6d7cea73fe3c337b146257617ff35b66f6d7779166fb06798 Setting nonce to 0x1111111111111111 Waiting for device to restart into recovery mode New nonce NONC: a70c80fffaf615a6d7cea73fe3c337b146257617ff35b66f6d7779166fb06798 We are done!

You can now futurerestore to the firmware that this SHSH is vaild for Assuming that signed SEP and Baseband are compatible MacBook-Pro:checkm8-nonce-setter-master salvatoredebari$

salvatore8686 commented 5 years ago

The problem has been solved, Changing door adaptor USB