Skip to content

Posts tagged ‘geohot’

13
Oct

Chronic dev team releases greenpois0n jailbreak

greenpois0n logoThe chronic dev team (@chronicdevteam) have released greenpois0n, their iOS jailbreak tool featuring an implementation of geohot’s bootrom exploit. Downloads are available for Mac OS X, Windows and Linux. It also only works on iOS 4.1.

This release of greenpois0n supports:
– iPhone 4
– iPhone 3G S
– iPod touch (4th Generation)
– iPod touch (3rd Generation)
– iPad

Soon there will be another release, adding things like support for:
– Apple TV (2nd Generation)
– iPod touch (2nd Generation)

[Updated 4/2/2011] greenpois0n updated to jailbreak iOS 4.2.1

10
Oct

limera1n brings unpatchable iOS Jailbreak

geohot has released limera1n, the latest iOS jailbreak. After the success of comex’s Jailbreakme.com, which was patched by iOS 4.0.2, limera1n brings a theoretically unpatchable exploit thanks to an extremely low-level vulnerability that affects all of Apple’s iOS-base devices. Both Mac OS X and Windows versions of limera1n are now available for download.

The jailbreak uses an exploitable vulnerability in the iOS boot-rom. This is the reason it’s theoretically unpatchable, as the boot-rom is something that would need to be physically flashed on the affected devices. By ‘unpatchable’ I mean that Apple will not be able to patch the vulnerability that makes the jailbreak possible, on existing iOS devices. If this is indeed the case, then this would mean that the current line of iOS devices are guaranteed to be jailbreakable even when applying new iOS updates. Apple would have to patch the bug in the boot-rom in new devices they release down the line.

In other news, the jailbreaking scene has had its feathers ruffled as the chronic dev team were originally going to release their greenpois0n jailbreak (using their SHAtter exploit). Rumor has it they shared their exploit with geohot, who went ahead and published his own tool before they could. Fun times.

[Update] Although the boot-rom exploit might not be patchable, limera1n uses a userland exploit to perform the untethered jailbreak. This means that Apple could potentially patch the untethered part of the jailbreak – although the boot-rom exploit would still exist. For more info read Update #1 at the bottom of this post.

Many people seem to be wondering what is meant by limera1n being ‘unpatchable’. Hopefully this posts answers that question somewhat. If you’re still unsure, feel free to post a question in the comments.

css.php