How To Jailbreak iOS 4 For iPhone 3GS (New Bootrom) Users With SHSH Blobs (Windows)

News | Friday July 2 2010 2:27 PM | Comments (0) Tags: , , , , , , ,

This guide is only for advanced users. This guide is only for Windows users. We'll publish the guide for Mac users shortly.
.
Do not forget to backup your iPhone before you proceed. You can
.
This guide is only for iPhone 3GS users with new bootrom. You can use
.
It will be a tethered jailbreak, which means that the jailbreak needs to be reapplied every time you power down your iPhone 3GS. If you let the battery run out or restart your iPhone 3GS then you will need to reapply the jailbreak by connecting to your computer (tethering).
.
.
to jailbreak iOS 4. You can checkout our detailed
.
.
After the jailbreaking process is complete, do not forget to checkout our article on
. Also, remember to
.
This guide will NOT unlock your iPhone 3GS. You can use
to unlock it after you have successfully jailbroken iOS 4.
* 3.1.2 SHSH blobs.
* LibUSB (64-Bit users read carefully!!!)
STEP A : Grabbing your 3.1.2 iBSS file.
I : If you have your shsh blobs saved on Cydia/Saurik's server then follow this tutorial. —
II : If you have it saved with TinyUmbrella, then download the GUI here. —
Restoring to grab the iBSS file.
I : Place your device in DFU.
II : Start up the iBSS/iBEC grabber.
III : Put the save folder on a new folder on your desktop.
IV : Hit “Start Monitoring”.
V : Now go back to iTunes and do SHIFT + Restore. Then browse for your 3.1.2 IPSW. You will need to restore
to 3.1.2 in order to pwn 4.0.
I : After Restoring, Go to the folder that you have specified to save your iBSS file.
II : You will see folders like (Per**.tmp). Go into one of them, and you'll see a folder called “Firmware”. Go there. Then go to the folder “dfu”.
III : Copy the iBSS file to a safe place, then you can remove the folder created by the iBSS Grabber.
STEP B : Creating custom 4.0 firmware.
and create your custom 4.0 ipsw.
*Ignore the warnings after browsing for the ipsw.*
Run this mini tool to detect your O/S + Arch. —
WARNING : IF LIBUSB IS NOT INSTALLED PROPERLY, YOUR USB MIGHT NO LONGER WORK!
and run it in compatibility mode for Windows XP.
If you are a 64-Bit user, follow this tutorial —
Once LibUSB is installed iRecovery should be able to function now.
// It will help you create the payloads.
**SAVE THE PAYLOADS WHERE iBooty is.**
STEP E: iBooty Prep.
Most of you know of the utility “iBooty” that I made for Aki_nG.
It will work as long as you place all of the correct files there.
and Extract it.
II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.
III : Grab the kernelcache and bring it into the same folder as ibooty.
Also grab the iBEC from the folder “Firmware\dfu\iBEC.n88ap.RELEASE.dfu”
* Rename your iBSS 3.1.2 signed to “ibss312.dfu”
* Rename your Kernel 4.0-Custom to “kernel.40”
* Rename your iBEC 4.0-Custom to “ibec40.dfu”
– iboot.payload
– exploitibss312
– ibec40.dfu
– irecovery.exe
– readline5.dll
– iBooty.exe
– ibss312.dfu
– kernel.40
– sn0w.img3
STEP F: Restoring to 4.0 + Booting
*MAKE SURE YOU ARE ON 3.1.2 WHEN DOING THIS*
I : Run iBooty and Select “Prepare Device for Custom Firmware”. Run the Process and if you see a snow flake, you can proceed!
II : Now open iTunes and restore to the custom ipsw.
***WHEN DONE, YOUR DEVICE WILL HAVE A BLACK SCREEN AND NOT BOOT! ITS IN A DFU LOOP [THIS IS NORMAL!]***
I : Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!
Enjoy!
As always, please don't forget to drop us a line to tell us how it goes.
Thanks everyone for the tip!

No Comments »

No comments yet.

RSS feed. TrackBack URI

Leave a comment

You must be logged in to post a comment.