New iPhone 5 Concept Called iPhone SJ


iPhone 5 rumors are starting again. Since the launch of the iPhone 4S last October, the designers started to release new concepts and rumors of the next iPhone, the iPhone 5. ADR Studio has given a fascinating iPhone 5 concept that we would like to show you. Details below!

The iPhone concept shown above is created by Antonio De Rosa, a designer who says that the concept will include a “Totally glass capacitive screen on a polycarbonate lightweight body.” He has given it the title of the iPhone SJ as it is inspired by Steve Jobs.

 

The design is based on the latest available iPhone models, the iPhone 4 and 4S. The concept would also include an A6 dual core processor and a 10-mega pixel camera.

Posted in iPhone | Tagged , , , , , | Leave a comment

Public Spire Siri Proxies


Many days ago, chpwn, the well-known figure in the jailbreaking community, launched the first legal port for Siri called Spire. The download of Spire from Cydia would download approximately 100 megabytes of data from Apple, and would give the entire Siri components into your iDevice, including the GUI and frameworks.

One problem though- it required a Siri proxy/gateway to communicate with Apple servers, which without it, would make Spire useless. Luckily, there have been some people nice enough to lend out their Siri proxy servers for the public.

NOTE that many/all of these servers may be off line due to the high traffic of people wanting access to Siri…do not expect them to work right off the bat.

Enter these proxies into the Spire settings in the Settings app to connect:

https://siri.cd-team.org/

https://97.188.76.85:443/

https://192.453.201:3544/

https://205.185.119.17:2000/

If you Google search for Siri proxies, you WILL run into scams and fakes- many will ask for donations or payments. Though some servers MAYBE legit, it is simply not worth paying up and risking fraud. Also note that the proxies by which you enter into Spire can receive much of your personal data, including your texts, emails, reminders, your location, etc. BE SMART.

Posted in iPad, iPhone, iPod | Tagged , , , | Leave a comment

A5 Jailbreak Update


pod2g has just updated his blog concerning the A5 jailbreak. Here’s what he said:

The exploit I used to inject the untethering files to the 4S relies on having a developer account, and can’t be released publicly.
It’s the same reason why @MuscleNerd has an iPad 2 tethered jailbreak but couldn’t distribute it.
So, we need to find a distributable exploit to remount the system partition read/write and to set Corona files at the correct places.

Why A4 version of Corona was easier to release ?

Because a tethered jailbreak is a good way to install Corona!

Why don’t you do a tethered jailbreak then ?

A tethered jailbreak also relies on an exploitable vulnerability that we still haven’t found yet !
Posted in iPad, iPhone | Tagged , , , , , , , , | Leave a comment

EXCELLENT NEWS FOR iPHONE 4S AND iPAD 2 USERS!!!


YES!!! You read it right! pod2g has just tweeted that he is one step closer to exploiting the A5 chip (which powers the iPhone 4S and the iPad2) and that we could be looking at an untethered solutions for A5 iDevices running iOS 5.0.1 within a week.

This comes as a wonderful surprise to of you user who just unwrapped that brand new 4S or iPad 2 less than a week ago!

Thanks pod2g and keep up the great work!!

For more news as it happens, subscribe to JoeSolutions 😀

Posted in iPad, iPhone | Tagged , , , , , , , | Leave a comment

How Corona Works


For those of you interested, here is how the corona untether works courtesy of pod2g 🙂
“1. the user land exploit
Apple has fixed all previous known ways of executing unsigned binaries in iOS 5.0. Corona does it another way.
By the past, the trick security researchers used was to include the untethering payload as a data page (as opposed to a code page) in the Mach-O binary. The advantage of a data page was that the Macho-O loader didn’t check its authenticity. ROP is used so that code execution happens without writing executable code but rather by utilizing existing signed code in the dyld cache. To have the ROP started by the Mach-O loader, they relied on different technics found by @comex, either :
– the interposition exploit
– the initializer exploit
Here is a detailed explanation of incomplete code sign tricks used before 5.0 : http://theiphonewiki.com/wiki/index.php?title=Incomplete_Codesign_Exploit
In iOS 5.0, data pages need also to be signed by Apple for the loader to authenticate the binary. @i0n1c seems to be able to pass through these verifications though (https://twitter.com/#!/i0n1c/status/145132665325105152). We may see this in the 5.1 jailbreak.
Thus, for Corona, I searched for a way to start unsigned code at boot without using the Mach-O loader. That’s why I looked for vulnerabilities in existing Apple binaries that I could call using standard launchd plist mechanisms.
Using a fuzzer, I found after some hours of work that there’s a format string vulnerability in theracoon configuration parsing code! racoon is the IPsec IKE daemon (http://ipsec-tools.sourceforge.net/). It comes by default with iOS and is started when you setup an IPsec connection.
Now you got it, Corona is an anagram of racoon 🙂 .
By the way, the exploitation of the format string vulnerability is different than what was done in 2001, check it out if you’re interested !
For the jailbreak to be applied at boot, racoon is started by a launchd plist file, executing the command : racoon -f racoon-exploit.conf
racoon-exploit.conf is a large configuration file exploiting the format string bug to get the unsigned code started.
The format string bug is utilized to copy the ROP bootstrap payload to the memory and to execute it by overwriting a saved LR in the racoon stack by a stack pivot gadget.
The ROP bootstrap payload copies the ROP exploit payload from the payload file which is distributed with Corona then stack pivot to it. The idea is to escape from format strings as fast as possible, because they are CPU time consuming.
The ROP exploit payload triggers the kernel exploit.
2. the kernel exploit
The kernel exploit relies on an HFS heap overflow bug I found earlier. I don’t know exactly what happens in the kernel code, I never figured it out exactly, I found it by fuzzing the HFS btree parser.
I just realized that it is a heap overflow in the zone allocator, so I started to try to mount clean, overflowed and payload images in a Heap Feng Shui way 🙂 And hey, that worked :p Thanks to @i0n1c for his papers on this subject. This helped me a lot. I may have given up without them.
The kernel heap overflow exploit copies 0x200 bytes from the vnimage.payload file to the kernel sysent replacing a syscall to a write anywhere gadget. Some syscalls (first 0xA0 bytes and the last 0x6 bytes) are trashed in the operation because I needed to respect the HFS protocol.
Thus, I restore them as fast as possible to get a stable exploit, then the write anywhere is used to copy the kernel exploit and jump to it.
The kernel exploit just patches the kernel security features, as usual. Nothing interesting there.”
Posted in iPad, iPhone, iPod | Tagged , , , | Leave a comment

P0sixninja Is Working On Jailbreaking A5 Devices Very Soon


What you heard is right, as it is a new happy year it also may become a happy jailbreaking year to all iPhone users especially for those guys who are using A5 devices like iPad 2 and iPhone 4S which no jailbreak has yet released for both of them, A few moments ago P0sixninja the well known hacker and the Chronic Dev team member and the guy behind Greenpois0n Jailbreak has just announced some good news on his Twitter account that many users waited for it too much time:

As we all know from some time Pod2G released iOS 5.0.1 Untethered jailbreak to all A4 devices and iPhone 4 users began jailbreaking using two methods which are Redsn0w 0.9.10b1 and Corona 5.0.1 jailbreak tweak but iPhone 4S and iPad 2 users didn’t enjoy at all…

With the beginning of 2012 year P0sixninja announces the possibility of making a new jailbreak for all A5 devices, and right now we don’t know if the jailbreak will be tethered or untethered..

Now, however, it seems that hackers are now close to the solution after thorough tests on the A5 processor of an iPhone 4S (the same also iPad 2), P0sixninja of the Chronic-Dev Team said:

Now everyone should update their devices to iPhone OS 5.0.1 (except for those in need dell’unlock) because it has a chance!
I hope that 2012 is the best year ever for the jailbreak (you know, at least before the world ends at all).

and just after the above tweets, P0sixninja followed the tweets with a new third tweet replying a user who asked him about a jailbreak for A5 devices and he replied:

“Yes including A5 devices…”

So really this may be a good year for A5 users specially after Pod2G worked sometime on iPhone 4S deep codes,

Posted in iPad, iPhone | Tagged , , , , | Leave a comment

Install Siri on iPhone 4, 3GS, iPod touch 4G, 3G and iPad 1 with Spire


Now install Siri on iPhone 4, iPhone 3GS, iPod touch 4G, iPod touch 3G and iPad 1 legally with Spire. Yes, the well-know iPhone developer Chpwn was managed to port Siri on older iDevices that running jailbroken iOS 5.x.x with new amazing Cydia teak called Spire.

 

How to get Spire to install Siri on iPhone 4G, 3GS, iPod touch 4G, 3G, iPad 1 :

Spire is available right now on Cydia via BigBoss repo only you have to open Cydia and search for Spire, if you did not found, tap on manage > Sources > Edit > Add the following repo :

http://smolk.myrepospace.com/

Then search again for Spire and install it, we recommend to use WiFi before installing Spire as it will download more than 100 MB to download some important files directly from Apple Servers

Here’s What Chpwn described Spire on his blog :

However, Spire is not a complete solution. Apple still requires authorization to use Siri, so information from an iPhone 4S is still required. To insert this information, Spire allows you to enter your own proxy server address. I’ve put up a list of my ideas on how you might get access to a proxy; hopefully you can figure something out.

How to install Siri on iPhone 4, 3GS, iPod touch 4G, 3G, iPad – [After installing Spire]

There’s any number of ways for you to get a proxy that will help you connect Siri to Apple. Here’s a few of my ideas:

  • westbaer’s SiriProxy fork
    • Own an iPhone 4S too: Maybe you already own an iPhone 4S, and just want Siri on another device of yours. This is simple; you can just use the above proxy yourself.
    • Find a friend: Maybe your friend has an iPhone 4S and will let you use their authentication tokens (maybe in exchange for some cool SiriProxy plugins). Then, you can share the authentication. Or, maybe you gave your relative your old iPhone when you got your iPhone 4S: now you can share your token and give them Siri.
  • Pay up: It’s very likely that soon we will see for-pay services online to rent you some space on a Siri proxy, attached to one of their iPhone 4S devices. I haven’t seen anything like this yet, but I’ll keep my eye out, and I would encourage anyone who is interested to set something like this up.
  • And now for something completely different: As I suggested earlier, you might be able to replace Siri entirely. A simple method might be to use Google Chrome’s speech “API” hooked up to some code to decode the Siri requests and parse Google’s result. Or, someone could hook it up to some logic backends like many of the clones available on Android: the possibilities are endless.

Finally you MUST have jailbroken device on iOS 5.x, you can follow our step by step guide to jailbreak iPhone, iPod or iPad – Click Here for 5.0.1 or Click Here for iOS 5.0.

Give it a try and share us with your thoughts.

Update: How to install Siri on iPhone 4, 3GS, iPod touch 4G, 3G, iPad – [Video Tutorial]

Here’s another video that shows you how to setup your own Siri-proxy [Advanced Guide] :

 

Posted in iPad, iPhone, iPod | Tagged , , | 1 Comment

Download Redsn0w v0.9.10b3 to Fix Previous Errors


Now, iPhone Dev team has just released new update of Redsn0w  0.9.10b3  to fix the problems that have occurred to the app that have stopped working after installing  version of Redsn0w 0.9.10b2 which released yesterday.

From the Dev Team blog:

Update #3: The b3 version of redsn0w fixes a problem where re-running redsn0w over an existing jailbreak would cause MobileSubstrate-based apps to stop running until MS was installed again.  Now you can re-run the redsn0w jailbreak step without worrying about that (but still remember to de-select the “Install Cydia” option if it’s already installed).
TIP: If auto-detection fails and redsn0w tells you no identifying data was found, you can always pre-select the appropriate 5.0.1 IPSW using “Extras->Select IPSW”.
Here are the redsn0w download links:
Posted in iPad, iPhone, iPod | Tagged , , , , , , , , , | 14 Comments

Chpwn Releases Zephyr, Brings Multitasking Gestures to iPhone and iPod Touch Thursday, 29th December 2011, 07:12 am


Chpwn has just released Zephyr, a new tweak that brings awesome multitasking gestures to the iPhone and iPod Touch. With just one finger, you can swipe up anywhere on the iPhone to bring up the multitasking switcher, or swipe left/right to switch to a different app.

Zephyr is multitasking gestures for iPhone and iPod touch. From swiping up to show the multitasking switcher or quickly swiping to a different app, Zephyr is all you need to quickly and easily control multitasking.

Zephyr is available in the Cydia Store for $2.99. (Probably soon on Xsellize repo for free)

Posted in iPhone, iPod | Tagged , , | Leave a comment

Download Redsn0w v0.9.10b2 to Fix Launchctl Error


Earlier today, we told about a new update about corona 1.0.3. iPhone DevTeam has just released the Redsn0w v0.9.10b2 updates to Fix Launchctl error.

Here are the redsn0w download links:

  • Download RedSnow 0.9.10b2 for Mac OS X
  • Download RedSnow 0.9.10b2 for Windows

Let us know in case you still have any problems.

Posted in iPad, iPhone, iPod | Tagged , , , , , , , , | Leave a comment