Unlock

How to Use an iPhone Without the Data Plan

[digg-me]After playing with my kids iTouch's it became clear to me how much the iTouch is lacking in functionality. Before buying one I considered it just an iPhone without the ability to make calls. The lack of camera was the biggest surprise, because I can't figure out why they left it out. The GPS and Camera would have been really nice to have even if I can't use it as a phone.

So would it still be better to buy an iPhone and use it just like an iTouch but with camera and GPS?  I found a thread on one of the iPhone forums where a guy, who was going to college and couldn't afford the $30.00 a month data plan, but wanted an iPhone anyway.  He was on campus where they had a robust wifi connection all of the time and didn't really need the data plan. He already had an AT&T cell phone (a Razor), and just wanted to get a used iPhone and put his SIM card into it.

After giving the guy a hard time, a good samaritan responded with a way to do just that.  He pointed out a cool service offered by unlockit.  It is an APN Changer for 3G iPhones.  It lets you turn off the Edge and 3G data service on your iPhone.  This lets you use an AT&T SIM card with your iPhone but lets you use it without adding the iPhone data plan.

To use this service do the following:

Put the AT&T Sim card in the already activated iPhone. Make a wifi connection to a local wifi source. Navigate to this page.  Click "Continue To The Next Page". Click Disable Data (Fake APN). The Install Profile window appears. Click Install. Another Install Profile window will popup warning you that authenticity of this profile cannot be verified.  Click Install on this window too. You should now see a message stating "Could not activate Cellular Data Network; You are not subscribed to a cellular data service.

You should now be able to make phone calls and be able to use wifi to access the internet.  When you aren't connected, you should get an error.

To remove the 3G/Edge block, simply go to your Network settings and removed the Fake APN profile.

This thread pointed out a really cool service.

Why Buy the Cow When You Can Get the Milk for Free?

[digg-me]Recently I've seen a lot of ads for people selling unlock/jailbreaking services. Some claim to be able to even do a software unlock for iPhone 3G. Prices range from $14.99 to $39.99 just for the ability to download unlocking and jailbreaking software from their website. Some require you to buy an additional piece of hardware (a SIM) to unlock the iPhone 3G, but some sites say you can just download a software.

This bothers me because I feel like this is contrary to spirit of Jailbreaking. Jailbreaking was made free to us by the hard work of the iPhone Dev Team and others, and these wonderful people are doing this to open up Apple's artificially closed offering to the iPhone lovers of the world.

One site I found is charging people for access to a "members only download area" where they can download Jailbreaking and iPhone 2G Unlocking software.

Also, some sites offer 3G software unlock services, although some people do admit that they will have to spend more money and buy a special SIM (from them of course).

There are still other services where you send them your iPhone and they will unlock it for you. I understand that it can be a bit scary to think you might brick your iPhone, but it would be scary for me to to send my beloved iPhone out to a complete stranger. If you they never send your phone back, what is your recourse?  Would you call the police and tell them you were trying to illegally unlock your phone?

The basic problems I have  with paying for unlocking/jailbreaking services (but not limited to) are:

They are charging an awful lot of money for what is free on the web. They are charging an awful lot of money for something they didn't even develop. Some of these people are promising services that may or may not even be possible. They are not warning people that new versions of the iPhone firmware may make their upgrade obsolete or they are promising them they will always be able to support the jailbreak/unlock. The people listing these services may not even be qualified or understand how to use the software.  I found a reference while researching this story of someone who created an Unlocking iPhone 3G website and was trying to sell it for $500, lock, stock, and barrel.

What do you think about this?

DevTeam still working on 3G unlock

The DevTeam posted today on its blog that it is still working on the iPhone 3G unlock. They apparently broke some hardware in their testings but got it back to work after a round of upgrades and downgrades. I don't like copy/pasting large parts from other people's blogs but in the DevTeam's case, I always find it hard to paraphrase them and it makes more sense to give you the full text. Read the full post here.

Disclaimer!! This is a purely technical post with no pragmatic use! There is no 3G unlock in this post. There is no iPod Touch 2G jailbreak in this post. It’s just a random technical post related to the 3G unlock.

We’ve been exploring different ideas with the 3G unlock, but this past weekend one of us hit a big snag. For whatever reason, all of our poking and prodding of the 3G baseband caused it to finally have a breakdown. After one specific exploit run, all of a sudden our baseband stopped responding to the OS.

Somehow our software hacking had caused the baseband chip’s SPI bus to stop responding (so it looked like a hardware problem). Even though BBUpdaterExtreme reported the correct baseband version, it failed basic tests like memtest.

If you’re familiar with the baseband revision history for the 3G iPhone, you may have noticed that the above captures were done at the original 01.45 baseband. As dire (and hardware-related) as these messages sounded, though, there was a simple solution. We just updated to 01.46 and then downgraded again (because we can run unsigned code on the baseband CPU) to 01.45.

We tried to recreate the problem by using the same exploit over again, but it doesn’t appear to be reproducible (which is actually disappointing, as it might have been exploitable).

Apple loosens their grip on China

I just read about Apple's new change in China, they are now offering unlocked phones there. The prices look like this:

HK$5,500 (≈ US$700) = 8GB model

HK$6,200 (≈ US$800) = 16GB

Who knows what the grey market might start selling now :) Have a nice autumn break for those of you who can still enjoy it.

News from the DevTeam

How much do you love the DevTeam? These guys are working day and night so you don't have to rely on Apple to provide you with great iPhone applications. I believe I use more jailbroken applications than I actually use "Apple approved" apps. All this thanks to the DevTeam.

Today, the DevTeam updated us on the status of their work.

While we continue working on the two current remaining challenges from Apple (the iPhone 3G soft unlock and iPod Touch 2G jailbreak…see the end of this post), we’re also watching the latest beta releases from Apple.

The first beta 2.2 from Apple reveals a few things:

They’re continuing with their ski-resort theme;  Version 2.2 is nicknamed TImberline. They’ve gone back to using expiry dates.  The first 2.2 beta is due to expire on November 30, 2008.  They stopped using expiry dates about halfway through the 2.1 betas, but for some reason they’ve started using them again. Version 2.2 is still vulnerable to pwnage and quickpwn on everything but iPod Touch 2G.

To demonstrate point #3, here’s the non-AppStore application Terminal.app running on 2.2, showing the kernel build information.

Hardware already vulnerable to pwnage remains vulnerable in version 2.2.

Regarding the two current challenges:  the 3G iPhone soft unlock and iPod Touch 2G jailbreak are still relatively new challenges (compare them with the timeframe of the iPhone challenges last year).  We’re making slow advances on both fronts, but it’s not the sort of thing that can be easily described in a blog like this.

But, to maybe show how interlinked these challenges are, this weekend we’ll be trying some hardware based ideas on the iPod Touch 2G jailbreak :)

As you can read, they are still working of this long-awaited iPhone 3G unlock. I am a "legit" AT&T customer so I don't care much about the unlock for myself, but I can't wait for them succeed as it will help thousands, if not more.

Keep up the good job DevTeam.

Unlock your iPhone 2G with QuickPwn

After posting the QuickPwn 2.1 tutorial yesterday, I got many emails from people asking me if the method worked for unlocking iPhones. The answer is yes! It does work to unlock the iPhone. It only works with the 1st Generation iPhone though. So if you have an iPhone 3G, it's not gonna work.

In the guide I posted yesterday, I show you how to jailbreak an iPhone (no matter what iPhone you have) but many people that are not really tech savvy asked me for a tutorial on how to unlock the iPhone 2G. So here we go...

Before starting, do not hold me responsible if something goes wrong. If you follow these instructions carefully, chances are you won't have any problem. So read everything!

Now before we start the process, you need to make sure you have downloaded and installed iTunes 8 and backed up your iPhone. And there are a few files you need to download too. Create a folder on your desktop and save all these files in there:

QuickPwn 2.1 for Windows BL 3.9 BL 4.6 iPhone 2G 2.1 firmware Connect your iPhone to your PC and open iTunes. Hold the Shift key and click "Restore" at the same time. You could click "Update" but that would eat up your disk space for nothing. See my previous post about that. So, when you click SHIFT + RESTORE, a window will pop up asking you to choose your firmware. Select the firmware you downloaded before Step 1. iTunes will then restore your iPhone to 2.1, which may take a while. Once iTunes has restored your iPhone to 2.1, launch QuickPwn. Make sure your iPhone is connected to your PC and click the blue arrow. Click the BROWSE button to locate your iPhone firmware you downloaded before Step 1. Select the firmware. QuickPwn will automatically check and make sure the ipsw (firmware) is correct. Click the blue arrow to go to the next step. Now select what you want to do. You HAVE TO install Cydia. Using custom logos and installing Installer is pretty useless at the time. Also make sure you check the "Unlock Phone" checkbox. Click the blue arrow to continue. You will then be asked to choose your BootLoader files you downloaded before step 1. Select them and click the blue arrow to continue. QuickPwn will ask you to confirm that your iPhone is connected to your computer. Make sure it is and click the blue arrow to continue. QuickPwn will now put your iPhone into recovery mode. Once it is in recovery mode you will be asked to: a) Hold the Home button for 5 seconds, b) Hold the Home and Power buttons for 10 seconds, c) Release the Power button and continuing holding the Home button until your iPhone is in DFU mode. QuickPwn gives you very detailed instructions to make it even easier for you! Once QuickPwn detects your iPhone in DFU mode, it will start the pwning process. Once pwned, QuickPwn will informa you that you successfully completed the pwnage process. Your iPhone will then proceed to run BootNeuter, which may take a few minutes, so be patient! Once done, your iPhone will reboot. Done!

How easy was that?

I closed the comments on this post but if you have any question about unlocking your iPhone 2G, please ask in the forum.

Apple Counters PwnageTool In iTunes 8, Patches Coming

The DevTeam said many times before that Apple cannot the bug they've exploited in PwnageTool unless they change the hardware, which is impossible until the next iPhones come out. While this is still true, Apple managed to have iTunes 8 detect and prevent the Pwnage exploit.

But hey, this is not gonna stop the DevTeam:

The nice thing about iTunes decisions is that we can provide you with patches to counter them.  We have one such patch already for Mac iTunes 8 for iPod touch.  We’ll be working out the full suite of patches for all the combinations over the next week.

A new ZiPhone in the work

Zibri posted this weekend that he is currently working on a new version of ZiPhone. I have always been a big fan of ZiPhone as it offers a one-click jailbreak/unlock for the iPhone. I really respect the DevTeam and cmw for QuickPwn and WinPwn, but I have to admit my heart goes to ZiPhone...

Here is what Zibri says:

I’m testing at the moment a very preliminary version of the next ZiPhone.. Let me tell you it’s impressive. A very few testers screamed when they saw how simple is this. I can’t tell you more for now.. It’s really to early.

This makes me think that ZiPhone is gonna be much easier to use than QuickPwn and WinPwn, which are already dead simple...

How to jailbreak your iPhone using WinPwn 2.5

We've been waiting for WinPwn 2.5 for quite a bit now (see my previous posts on the topic) but it is finally out!

WinPwn 2.5 makes it stupid simple to jailbreak or unlock your iPhone. Note that so far, you can only jailbreak the iPhone 2G. An unlock method for the iPhone 3G is not available yet but check out my blog every once in a while as I will be staying on top of that and I will be informing you.

So, how to jailbreak the iPhone? Pretty simple. I just created a guide that will show you every step of the process: jailbreak your iPhone with WinPwn 2.5.

This tutorial works for iPhone 2G and 3G. Only a few steps slightly change. Read the tutorial and leave comments.

How to unlock the iPhone using WinPwn

WinPwn 2.5 is out and it is making it even easier to unlock or jailbreak your iPhone 2G. So far, it doesn't allow you to unlock the iPhone 3G but the DevTeam is working day and night on it.

I just created and published a tutorial on how to use WinPwn 2.5. This tutorial works whether you have an iPhone 3G or an iPhone 2G. It also works whether you simply want to jailbreak or unlock your iPhone.

Enough talk: use this WinPwn tutorial to unlock your iPhone 2G.

WinPwn 2.5 Guide

How to jailbreak 3G iPhone? How to unlock an iPhone 2G? These are 2 questions that will find an answer in the next few paragraphs. Believe it or not but it is illegal to jailbreak or unlock your iPhone but more importantly, it voids your warranty. Basically, you are unlocking/jailbreaking your iPhone at your own risk.

One last thing before we start.... Please do not complain to me if you have problems or if you have to restore several times. I am providing this WinPwn tutorial without any guarantee. I mean, I know it works and I know if you do everything I tell you, you won't have any problem. But I hate receiving insulting emails telling me what a jackass I am (I already know that, haha). If you're having issues, please post in the comments and I will do my best to answer your questions. Any insulting comment will be deleted.

IMPORTANT UPDATE: There is a confirmed bug with WinPwn 2.5 that can cause the WinPwn application to crash during the creation of your IPSW. Some users are finding that increasing the partition size to 700MB will resolve the issue. To specify the root size partition click the "Expert Mode" button before starting the tutorial. You will be asked to resize the partition before the IPSW starts building.

UPDATE 2: A new version of WinPwn (WinPwn 2.5.0.2) is now available and fixes bugs such as crashes. Go to our iPhone Downloads section to download WinPwn 2.5.0.2.

Ok, so let's learn how to jailbreak or unlock an iPhone (note that unlock is only available for iPhone 2G so far).

Download WinPwn 2.5 from our iPhone Downloads section. make sure you have iTunes 7.7 or upper. Download bootloaders 3.9 and 4.6 if you want to unlock your iPhone 3G. Open WinPwn 2.5. You will need the .net framework installed on your PC. It is most likely already here but if WinPwn 2.5 crashes, go to Microsoft website and download the .net framework. Leave the "Basic Mode" on. Choose your device. Select the green thumb up if you are using an official carrier like AT&T. If not, select the red thumb down. The red thumbs down will unlock and activate while the green will not. Answer the rest of the questions WinPwn will ask you. They are pretty simple. Select if you want to use a custom logo or not. For the purpose of this tutorial, we will use a custom logo. Select your firmware. Select the logo you want. Click the "Browse" button should you want to go online find more logos. If you are on an approved carrier such as AT&T in the US, skip to the next step. Otherwise, you will have a message saying: "Could not find BL-39.bin! Do you want to search for the file?" Click the green thumb to find the file that you downloaded in step 1. Your custom firmware will be built, which should take a little while. Once your custom ipsw firmware has been built, WinPwn 2.5 will ask you if you want to see instructions on putting your iPhone into DFU Mode. Click the green thumbs up button for yes or the red thumbs down button for no. For this tutorial, we will assume you want to see instructions. WinPwn will then prompt you to connect your iPhone via USB and make sure it's turned off. Do this then click the green thumbs up button. WinPwn will then say its ready to start Pwnage. Click the green OK button. Follow the steps to get your iPhone into DFU mode. Once you iPhone is in DFU mode WinPwn will begin the pwnage process. You will be informed when pwnage is complete. Notice that your iPhone will display a "Ready to restore Custom IPSW" message. iTunes will now prompt you that you are in recovery mode. Hold down SHIFT and click the Restore button in iTunes. Select the Custom firmware file we created using WinPwn. Your iPhone will now be restored to the jailbroken 2.0.x firmware of your choice!

Done!

WinPwn 2.5 is out

WinPwn 2.5 is out and can be download either from here or from our iPhone Downloads section.

So, what's new on WinPwn 2.5?

QuickPwn Support for 2.0/2.0.1/2.0.2 Root partition resize support Installer support Basic / Expert modes Wizard style interface Automatic updater Support for WinXP and Vista 32/64bit

Notes from cmw:

- ONLINE IMAGE BROWSING IS DOWN DUE TO HIGH TRAFFIC

- Why is it beta? Well it's my way of saying.. Use at your own risk

- You MUST do a full uninstall of winpwn 1/2 before installing the new version

- Make sure you have the latest version of iTunes (Currently 7.7)

How to use WinPwn 2.5?

Use my WinPwn 2.5 Tutorial.