freemyipod / wInd3x

iPod Classic and Nano 3/4/5G bootrom exploit
GNU General Public License v2.0
209 stars 10 forks source link

implemented nano3g wtf defanger for full cfw #8

Open lemonjesus opened 11 months ago

lemonjesus commented 11 months ago

the iPod n3g does not use an EFI WTF like everything else, it just uses a flat binary that relies rather heavily on the bootrom. by changing the condition on two instructions, we can skip the entire sig check and boot into any modified image we send it.

tested on an n3g by decrypting FIRMWARE.x1242.RELEASE.dfu, modifying it so the "do not remove" icon is different, and then sending it using this method and observing that the change did, in fact, take.