axi0mX / ipwndfu

open-source jailbreaking tool for many iOS devices
GNU General Public License v3.0
7.04k stars 1.7k forks source link

Use iBoot-385.22 with Checkm8 to provide untethered jailbreak #151

Open rickmark opened 4 years ago

rickmark commented 4 years ago

Due to some looking, I believe that the latest processors should still boot old versions of iBoot that can be laid down by Checkm8 providing untethered jailbreaks via the ARM 7 GO defect.

https://www.theiphonewiki.com/wiki/IBoot-385.22 https://www.theiphonewiki.com/wiki/ARM7_Go

zEstLabs commented 4 years ago

If you look at the wiki page for that it explicitly states that the arm7_go exploit is exclusive to the iPod touch 2nd gen. This is not an issue it’s just wild unfounded speculation, please close this issue

rickmark commented 4 years ago

Making the inference that unrestricted code running on an ARM processor, being able to run a known vulnerable version of higher stage boot loaders, allowing for an "untethered jailbreak" due to the fact that the code is in fact "apple signed" is not exactly wild speculation. This issue is to discuss feasibility.

zEstLabs commented 4 years ago

This is not the place for discussion, it’s a place for issues with ipwndfu, this is not an issue with ipwndfu it’s your own speculation

N00byEdge commented 4 years ago

@rickmark It would work perfectly fine, you can install any signed version of iOS, the problem is that the signature is only valid for your specific instance of device.

This is what all the noise about saving blobs is about. The bootloader won't accept the signature unless it's valid for that version of iOS and your (simplified) serial number.