the iPod n3g does not use an EFI WTF like everything else, it just uses a flat binary that relies rather heavily on the bootrom. by changing the condition on two instructions, we can skip the entire sig check and boot into any modified image we send it.
tested on an n3g by decrypting FIRMWARE.x1242.RELEASE.dfu, modifying it so the "do not remove" icon is different, and then sending it using this method and observing that the change did, in fact, take.
the iPod n3g does not use an EFI WTF like everything else, it just uses a flat binary that relies rather heavily on the bootrom. by changing the condition on two instructions, we can skip the entire sig check and boot into any modified image we send it.
tested on an n3g by decrypting FIRMWARE.x1242.RELEASE.dfu, modifying it so the "do not remove" icon is different, and then sending it using this method and observing that the change did, in fact, take.