Geohot Discovers Working Exploit For iPhone OS 3.1.3 Baseband

iPhone 3.1.3

If you accidentally upgraded your unlocked iPhone to iPhone OS 3.1.3 that was released two weeks back then we have another good news.

Geohot, the iPhone hacking expert who had released popular jailbreaking and unlocking tools like blackra1n, blacksn0w and more has discovered a working exploit for baseband 05.12.01 that was bundled with iPhone OS 3.1.3.

Geohot has tweeted the hash tag of the baseband crash for safekeeping:

d8b50dc95d7906e3ff6155331a534b55d0f6cac1=good. And motorama this weekend!

You might remember that Sherif Hashim had also discovered an exploit for iPhone OS 3.1.3 baseband last week and MuscleNerd of the iPhone Dev Team had confirmed that it is working.

iHackintosh has also published the conversation between Visnet (iHackintosh reader), Geohot and MuscleNerd:

<visnet_> What does geohot tweet mean?
<%geohot> its my bb exploit for safekeeping
<%Par4doX> geohot: did you turn that over to the dev team or are you doing something with it?
<%geohot> my days of turning things over are done
<%geohot> i hope its different from the one they have
<%geohot> but they prob already have it
<%geohot> its the one i orig wanted to release
blacksn0w with
<%Par4doX> it’s still there in the new bb
<%geohot> yep, just checked
<%geohot> but then opted to use xemn since it was public
<Evan> Oo, it carries over from 05.11 to 05.12?
<%geohot> why wouldn’t it, apple doesn’t fix things proactivly
<@MuscleNerd> geohot we prob should figure out a way to know if we have same exploit double blind, otherwise we may release 2 different ones at same time
<%geohot> any suggestions?
<@MuscleNerd> not sure how to do that without making it easy to brute force though
<%geohot> yea, i salted the hash
<@MuscleNerd> yeah
<@MuscleNerd> hmm maybe if we both hash the stack dump
<@Confucious> Can you two take this out of public sight?
<@MuscleNerd> the stack itself, not the header before it or the registers after it
<Her> muscle: any notice about the exploits are the same ?
<%geohot> we are working on it
<%geohot> cryptography, perfect for people who don’t trust each other

The conversation indicates that both the iPhone Dev Team and Geohot have a working exploit for the latest baseband and could release tools to jailbreak and unlock iPhone OS 3.1.3.

As always, we’ll keep you posted so stay tuned here at iPhone Hacks or follow us on Twitter or subscribe to our RSS feed.

[via iHackintosh, Geohot’s Twitter page]

Recent Posts

Comments:

Feed You can follow this conversation by subscribing to the comment feed for this post.


71 Responses to Geohot Discovers Working Exploit For iPhone OS 3.1.3 Baseband

  1. badboy says:

    awesome!!!!!!!!! love you Geohot

  2. Scott says:

    Cool, good work… BUT, I want my tethered jailbreak gone please. Thank you.

  3. will this work with the newest 3gs …i reallyy hopeeeeeeeeeeeee so cuz i have a iphone thats just sitting here all alone and wants to be use lol

  4. Jose says:

    Wow, we should all donate to these people providing us with these software hacks, don't be a stiff & donate for these hacks that turn these shitbricks into a nice product

    great job guys for your effort, keep up the awsome work, the iPhone would suck donkey balls if not for you

  5. kianush says:

    love you guys hope you releaseit :)

  6. Gia Nguyen says:

    you guys are awsome and really intelligent,cant wait until u guys release it

  7. steve says:

    but like his work on ps3 he does half z job then does a runner so I would mot look forward to nothing here

  8. jason says:

    Hi. can blackrain jailbreak 3gs version 3.1.3, firmware 05.12.01??

  9. Danny Jones says:

    good work guys, look forward to the next one.

  10. Danny Jones says:

    can anyone tell me how to see when an iphone was made???

  11. Wezzeli says:

    Danny Jones:

    To find out when your ipohone is made go to settings –> General –> About

    There you'll find your serial number
    Serial number's third number tells you the year when it's made and next two numbers (4th and 5th) tells you the week's number of that year when it's made. if those numbers are less than 940 you have older bootrom but remember to check then the model (mine is MC133KS so i have MC-model). MC meens you cant jailbreak with snowbreez.

  12. iWolf says:

    You sir are an idiot he did not halfass the PS3 it took 4 years for someone to do it being Geo and you think he does halfassed things? get a life buddy and let the real hackers do their job

  13. Murtaza Zakavi says:

    well these guyz are just gr8!

    hope they release the jailbreak n unlock sOOoooon!

    i have a 3gs which is more like n ipod with a camera!

    its useless basically!

  14. Sethomas1975 says:

    Not sure if this will help anybody but I was forced to upgrade (from jailbroke 3gs 3.1.2-blackrain to 3.1.3)my phone got stuck on apple logo. I had hashes on file but could not downgrade or jailbreak. after researching and restoring for 2 straight days I finally found a way to downgrade to 3.1.2 and jailbreak. Could be a fluke but i restored one other time since and was able to do it again. I am currently running 3.1.2 on my iphone 3gs model number mc135ll, carrier 5.6, modem fw 05.12.01 So what I did that worked is restored with an official 3.1.2 ipsw, it will give error 1015, at that point close itunes and reboot phone and it will finish installing 3.1.2 and then you can restore settings. Please let me know if this works for you. Not sure about unlock because I am on At&T. My email is sethomas1975@gmail.com

  15. Sethomas1975 says:

    I just ran blacksnow for the hell of it and it worked. not sure why I can jailbreak running fw 5.12.01 but two days without jailbreak was fucking hell. I literally tried everything before the official 3.1.2 ipsw. good luck!

  16. nsfw says:

    Can someone explain to me how many people end up in the latest firmware on the day its released and then say woops?! and beg for a fix for two weeks on every message board. Someone should take away your license to operate your iphone if you upgrade your firmware the day its released.

  17. TimW says:

    Haha, the old saying of:
    "When something is classed as FoolProof, the World produces a better Fool"

    For some, two paper cups and a piece of string is complicated

    Makes me wonder how they manage to post on boards and avoid pc virus's lol

  18. simon says:

    can any one tell me that i have the 3gs 3.1.2 but in the front page sat that my device has an shsh on file for the iphone os:3.1.3 what is that mean, becuse i have the 3.1.2 not 3.1.3….thank you

  19. Denton says:

    Not currently but Geohot is awsome so stay tuned.

  20. Denton says:

    Some people don't read so well but in my case my 3G crashed on Apple logo and wouldn't boot. Tried all the tricks to get it back but restore was only thing that worked. Really missing Blackra1n JB and reluctantly waiting this one out.

  21. Sethomas1975 says:

    Most if not all were forced to restore and upgrade because we were stuck on boot up and couldn't boot our iphones. Better to have a working non-jailbroke iphone then a $600 paperweight. Luckily I was able to downgrade to 3.1.2 after some trial and error. Find an official 3.1.2 ipsw and restore with that and reboot phone at error 1015. Voila, 3.1.2, JB with blackrain.

  22. Viz says:

    will the new unlock tool also cover 3G phones with the latest bootloader ver. 6…?

    does the bootloader version matter?

  23. jonnyenglish_75@hotmail.com says:

    when will it be out then ?

  24. dk says:

    none of them have an working version .. they are just fishing to see if the other side has one.
    and the rest of the fools are jumpig for joy like cimps in a zoo.

    3.1.3 can't be unlocked and jailb so wait for 4G :) apple won't allow a new unlock at this point so ppl will buy the 4g … ;)

  25. Zz says:

    if geohot and devteam has exploit then wot they are waiting for????
    they are just gettin loss n nothing more…most of the iphone user must get fucking off by iphone….

  26. Sethomas1975 says:

    Ammendment to my earlier post, must have shsh of file with cydia or follow instructions here:
    http://www.hackthatphone.com/3x/local_ecid_shsh.html
    If you have shsh on file redirect your hosts file to cydia. Download quickpwn 2.2 and launch after you receive error 1015 and after you close itunes. It will prompt you to press keys for a predetermined time to activate. You do not need to run anything in quickpwn just do the activation step. It should complete your restore process if you did it correctly. Sorry to all the people who emailed me. I did soo much shit trying to get phone to work that I wasn't sure what I did that finally worked but this works.

  27. Sethomas1975 says:

    I have done these steps 3 times to make sure they work and it's worked everytime. I am installing cydia now as I type, next is rock then restoring jailbreak apps.

  28. Cassini says:

    I jailbreaked my iphone 3g
    version – 3.1.3
    Baseband – 05.12.01
    Boothloader – 06.04
    using its to UNLOCK…

  29. Cassini says:

    I jailbreaked my iphone 3g
    version – 3.1.3
    Baseband – 05.12.01
    Boothloader – 06.04
    Using snowbreeze, it worked fine… Cydia and everything..Now its to get it UNLOCKED!

    Sorry abt above error..

  30. SassyOh360 says:

    Snowbreeze worked fine for jailbreaking the 3.13..
    Can't wait for unlock!!!

  31. JAT says:

    I upgraded my 3G iphone to 3.1.3 my base band was 5.12.01 and BL was 6.04.

    I tried every possible way to unlock but failed.

    I gave this phone to grey market for unlock, They downgraded bb to 5.11.07 and os to 3.1.2 and unlocked it. I paid them $40 to unlock it.

    Its working now on 3.1.2 base band 5.11.07 and on any SIM.

    I don't know how they downgraded it?

    Rgds

    JAT
    India

  32. eromance says:

    really? so its outhere already?

  33. jolene says:

    Hi i have successfully jailbreak 3.1.3 but i cant unlock my phone can someone help me !!! it keeps saying " unable to load network list"
    thanks ! jolene

  34. JEREMIAH says:

    Can the new jailbreak geohot is working on work on mc models? Because my iPod is an mc model and could not do any jailbreaking..

  35. listubhmoob@yahoo.com says:

    hey!can you tell me that its possible to jailbreak & Unlock my iphone 3gs Seral # <942 and Model MC137LL?

  36. sumkinduvmalice says:

    some mc models work with blackra1n my roomate did his new ipod touch and a few times it went to connect to itunes screen and he had to use blackra1n again and now after 3 weeks it never need blackra1n to boot again. Also I had gotten error 1611 with my iphone 3gs and that was from syncing i refused to update but could not get my phone to boot and i know all the tricks. I brought it to apple (risky) and stil they couldnt get it to work they were getting error 6000 even when they tried a restore. so they gave me a new phone and to my surprise it stil had 3.1.2 on it with a mb model number, yet the serial was 005 for 3rd,4th,5th numbers which is 5th week 2010, so i used black rain and it jailbroke and not tethered so it has old bootrom i guess the new serial num must be re put on the phone since it is most likely a referb but i just got lucky.

  37. Fred says:

    They must have used Redsnow to downgrade it back to 3.1.2. I have done that for a friend of mine, too and it was pretty easy!

  38. EmsBraverJunge says:

    I tried to do it the way you described but without success. every time i unplug it after the error 1015 message appears, there is the "connect to itunes" screen on my iphone. the same after i reboot it :(
    at what time exactly did you unplug (reboot) your phone??

  39. Mahmut says:

    I jailbreaked my iphone 3g
    version – 3.1.3
    Baseband – 05.12.01
    Boothloader – 06.04
    using its to UNLOCK…

  40. squiwwal21 says:

    i have bootloader 05.09 is it possible with that?

  41. jerome says:

    ,hellow.,how can i unlock my iphone 3g 3.1.3 foirmware 05.12.01 botloder 6.02??

    ,cuz i accidentally updated 3 weeks before.,

    ,is there any hacks that geohot found???

  42. chris says:

    sumbody help me i somehow downgraded back to 3.1.2 i have black rain but it wont pick up me sim card ne1 have a suggestion kuz i got this far n dnt wana go bac to square 1

  43. drdirty says:

    if you have a 3gs, you are stuck like the rest of us

  44. drdirty says:

    ya 3g DUH, not 3gS

  45. drdirty says:

    he is NOT working on a jailbreak, no one is. all this crap about finding exploits is just that, crap. if you have a 3gs, your stuck, if you have a 3g, that can be jailbroken.

    but from what the blogs and boards say, no one has anything out there, and no one is working on one.

  46. drdirty says:

    ya you can jailbreak a 3g, NOT a 3GS

  47. drdirty says:

    NOT on a 3GS. nothing works on a 3gs with 3.1.3 and 05.12.01, and no one is working on a program either.

  48. drdirty says:

    nothing works on a 3GS. a 3G, sure, not a GS

  49. drdirty says:

    WONT work on a 3GS, nothing does if you have 3.1.3 and 05.12.01

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>