August 12, 2022
Como funciona el PurpleRa1n Jailbreak

Como funciona el PurpleRa1n Jailbreak

Posted July 13, 2009 at 9:22pm by iClarified · 15285 views
La gente de Geohot publicó en WIKI como funciona su PurpleRa1n Jailbreak:

* Purplera1n envía los comandos de recuperación de entrada utilizando iTunesMobileDevice
* Una vez en la recuperación (iBoot), envía la variable Exploit de entorno IBoot
* El Exploit adiciona un comando GeoHot que corre entonces el payload
* La comando "geohot" se ejecuta, el control es transferido de iboot ahora a la payload
* Se realiza entonces el cliente PurpleRa1n

Dentro del payload:
* El payload por defecto restaura el entorno y lo preserva para la nvram (fija el auto-arranque a true)
* Le coloca parches a la iBoot para cargar img3s sin firmar sin importar los tags
* Carga la imagen purplera1n (enviado con payload)
* Empieza la función de no parches
* IIb se descifra, parcheado, y el aumentado de tamaño a 0x24200. este es el segmento residente 0x24000 en la variable Exploit
* Un pequeño código de carga es colocado en 0x20000 para fijar la carga
* Iboot se descifra, parcheado
* Todo lo demás es como se lee
* Ni se escribe de vuelta, ni se hace patcher
* Kernel está cargado, descifrado, y parcheado
* Ramdisk está cargado (enviado con payload) y se trasladó a la región del Kernel 0x44000000.
* El Kernel parcheado es arrancado (booted)
* El Control de la carga está ahora transferido a ramdisk

Dentro de ramdisk
* Launchd se ejecuta, todo sucede aquí
* / Dev/disk0s1 está montado
* Fstab y servicios son sustituidos aquí para permitir que disk0s1 y afc2 escriban respectivamente
* se transfiere y el cargador de aplicaciones tiene bit SUID
* El Kernel parcheado se lee a partir del final de la RAM del dispositivo y escrito al sistema de ficheros
* Ramdisk está hecho, procede el reiniciado...

Read More

Como funciona el PurpleRa1n Jailbreak
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
iClarified Icon
Would you like to be notified when we post a new Apple news article or tutorial?
You must login or register to add a comment...
RRR - August 4, 2009 at 6:25am
i got an iphone 3gs w/c wont turned on. it got stuck on purplera1n's entering recovery mode.. the iphone wont turn on now.. can you help? i tried to connect to itunes sa i can do a recovery but it doesnt seem to see the iphone
yasha - July 15, 2009 at 8:48am
Real hax0rs not afraid to show code cuz they know there's always another bug waiting... much respect to geohot!
zenrock - July 14, 2009 at 1:50pm
LOL geohot and the dev team need to calm down before they kill the jailbreaking community with all this nonsense wtf is it with you guys giving out the code in a public forum so the experts at apple can look at this and start slamming the door shut on you guys 3.0 just showed how good they are getting at making it harder for both of you and now you just up and hand them all the jailbreak code i have lost all respect for you guys that's like the usa just handing the nuke formula to the germans in world war 2 what are you guys smoking seriouslly. you guys are going the why of winpwn,ziphone extincted keep this up. morons
dt - August 4, 2009 at 10:57am
Hey stupid. What are you contributing. GeoHot, the DevTeam, Zibri, etc... can do whatever they want with their code. Contribute more than hot air then you can call the shots. Until then shut up.
ayyywa - July 14, 2009 at 11:26am
What is somewhat frustrating is that Apple is taking North America for a ride. many other countries banned the sale of locked iPhones ande I don't see a reason why we can't lobby for that in US and Canada. I know that JB is different but an unlocked phone is a right since we are entering in a contract for service. Price with no contract should include an officially unlocked phone too. Unless we all go for this, it won't happen. cheers
21 More Comments
Recent. Read the latest Apple News.
Tutorials. Help is here.
Deals. Save on Apple devices and accessories.