3G  [iPhone 3G][Unlock][Supposition on the way of success]

blue邀月

普通会员
2005-09-06
1,215
0
0
Hi All !

1st Im not a programmer or hacker or analyser, but all I've done, and all experiences I had was cost much of time and money.

Some of them was success. So belive it or not it depend on you but I.

After 3 weeks fighting with devilPhones locked and not locked, with Pwntool and hardware method, I found out a theory myself.

And with the hit of many Mods and Admins in this forum, I decide to talk it out.

Apple after the 1st gen iPhone must had much more experiences on defending hacker. Now they use this "my theory" to

control all the lock state of their device that so much secure but I think the experts here such as Dev team will pass over and come to the real software unlock.

My suppositon is the BB now on 3G is no more locked. Why I think so ??
I did: exchanged the pair X-Gold and Nor of LOCKED phone to the International not lock phone. Both phone are in good condition of physical state with the right IMEI of the pair IC, have wifi. Then what happened ?

- The Locked phone now got the pair of IC not locked: put work sim inside
+ Pwned it: of cause No Service. Call 112, there no signal broadcast. I put the Nor out and dumped this state call State 1.
+ Restore it with original fw and active by iTunes: iTunes said can not active, and the phone must be broght to Apple Service. Still No Service in the top left of the screen. Call 112, there no signal broadcast. I put the Nor out and dumped this state call State 2.

- The Not Locked phone now got the pair of IC locked: put work sim inside
+ Pwned it: of cause No Service. Call 112, there no signal broadcast. I put the Nor out and dumped this state. I put the Nor out and dumped this state call State 3.
+ Restore it with original fw and active by iTunes: iTunes said can not active, and the phone must be broght to Apple Service. Still No Service in the top left of the screen. Call 112, there no signal broadcast. I put the Nor out and dumped this State 4.
- Compare State 1 2 3 4 to each other, all changed in 0xE8 to 0xFC (maybe logs data or whatever). And as we know with the memory map, this area doesnt effect to the LOCK STATE. Maybe just for the Jailbreak state.

After all of this test, I think the whole BB doesnot invole to the lock or not lock carrier. It just recieves the commands from the main firmware to work or not (broadcasting Rx + Tx transmission of the network).

The damn thing is whatever system action you want to act to the phone by iTunes, you must connect to the internet. And Im sure, iTunes collects all the log and force the state of phone in their rules: Activate or not, lock or not, crash the apps or not, etc ....

So my result here is: iTunes server handle all the devices they produces by: MODEL + SERIAL + IMEI (3 of these will be identified the phone belong to which carrier). Each sync action with iTunes, the server with check the database of the Factory (lol) then know this phone will be locked or not and with my damn naughty actions, they decide to BLOCK my phone forever or not

- The iTunes server BLOCKED my International phone cos of it found the MODEL + SERIAL not fit to the IMEI (I changed 1 pair IC of other locked phoned to, then the IMEI is the IMEI of the locked phone) so the server BLACKLIST my phone OUT OF FULL ACTIVATION WITH UNLOCK STATE.

- DEV TEAM must know why and where their Pwntool made the International phone relocked in the OS disk. Maybe they still not know how to resolve it.

Totatly, I can finish my post with the point: 3G BB NO MORE LOCKED - THE LOCKED STATE IS CONTROL BY: ITUNES SERVER + MODEL + SERIAL + IMEI AND IT STAY IN THE OS DISK WHEN THE PHONE SYNC WITH ITUNES. - NO MORE TRYING TO HACK THE X-GOLD.

Monitoring, capturing the transmission of usb and internet from iTunes then decrypt, patch ... will help the unlock process ???
Come on Dev Team, GeoHot, all other expert, let try and give out the soft .
Hoping some day my blocked Inter-phone will work again like it did

I give the thanks to all the good sense post from the one who know what to say event it show that I was stupid
 

nokia913

普通会员
2006-05-11
40
0
0
第一即时通讯不是一个程序员或黑客或分析仪,但所有我已经做了,所有的经验,我已是成本的大部分时间和金钱。

他们有些是成功的。因此,相信它或不依赖于你,但一。

经过三周的战斗与devilphones上锁,没有被锁定,与pwntool和硬件的方法,我发现了自己的理论。

与击中许多多器官功能障碍综合征和管理员在这个论坛上,我决定谈出来。

苹果后,第一根iphone必须有很大的更多的经验对捍卫黑客。现在,他们使用这个“我两国论”

控制所有被锁定的状况,他们的设备这么多的安全,但我认为此间专家,如开发团队将通过以上的和来真正的软件解锁。

suppositon是我的BB现在对3G是没有更多的锁定。所以,我觉得是这样吗?
我:交换了两人的X金,也锁定手机,向国际不锁的手机。这两个电话是在良好的条件,身体状况与权利的IMEI的对集成电路,有WiFi功能的产品。然后发生了什么问题?

-锁定手机现在得到了对集成电路没有被锁定:把S IM卡内的工作
+ pwned :原因没有服务。呼叫112 ,有没有信号的播出。我提出的NOR和倾倒,这种状况要求国家1 。
+恢复它与原来的又一城和活跃的iTunes : iTunes中说,不能活跃,手机必须broght Apple服务。还没有服务在左上方的屏幕上。呼叫112 ,有没有信号的播出。我提出的NOR和倾倒,这种状况要求国家2 。

-没有被锁定的手机现在得到了对集成电路锁定:把S IM卡内的工作
+ pwned :原因没有服务。呼叫112 ,有没有信号的播出。我提出的NOR和倾倒的这种状况。我提出的NOR和倾倒,这种状况要求国家3 。
+恢复它与原来的又一城和活跃的iTunes : iTunes中说,不能活跃,手机必须broght Apple服务。还没有服务在左上方的屏幕上。呼叫112 ,有没有信号的播出。我提出的NOR和倾倒这种状况4 。
-国家比较1 2 3 4向对方,所有的改变0 xe8,以0 xfc(可能是记录的数据或什么) 。和我们知道与记忆地图,这方面的doesn't效力锁定状态。也许仅仅是为了越狱国家。

毕竟这次试验,我认为整个BB心跳doesnot invole ,以锁定或不锁定承运人。它只是接收命令,从主要的固件去工作或没有(广播的RX +德克萨斯州的传输网络) 。

这个可恶的是,无论系统的行动你想采取行动,以电话iTunes ,你必须连接到互联网。和IM肯定的是, iTunes的收集所有日志,并迫使国家的电话,在他们的规则:启动或没有,或不锁,坠毁应用程序或没有,等....

所以我在这里的结果是: iTunes的服务器处理的所有设备,他们生产的:模型+ +串行的IMEI ( 3这些将确定手机,其中属于承运人) 。每个同步行动,有了iTunes ,服务器检查数据库的工厂( lol ) ,然后知道这个电话将被锁定或不和与我的可恶顽皮的行动,他们决定完全挡住了我的电话永远或不

-在i Tunes服务器封锁我国际电话产地来源证的发现,模型+串行不适合到的I MEI(我改变一对集成电路的其他锁定打电话来,那么的I MEI是的I MEI的锁定电话) ,使服务器黑名单,我的电话出于充分的活化与解锁状态。

-开发团队必须知道为什么,而他们的p wntool作出的国际长途电话r elocked在操作系统的磁盘。也许他们仍然不知道如何解决这个问题。

totatly ,我可以完成我的职务与这一点:第三代BB心跳,没有更多的锁定-锁定状态,是控制: i Tunes的服务器+模型+ +串行的I MEI和它留在操作系统的磁盘当手机与i Tunes同步。 -没有更多的试图入侵的X金。

监测,捕捉的USB传输和互联网从iTunes ,然后解密,修补程序...将有助于解开的过程? ? ?
来对开发团队, geohot ,所有其他的专家,让尝试,并给予了软。
希望有一天我阻止跨电话会的工作,再次它

我请他感谢所有的良好判断力员额从1谁知道该说些什么事件,它表明,我是愚蠢的