My iPhone's broadcasting cooked - can I have yours?

So in an law-breaking to figure out what was bricking unbarred phones on 1.1.1, I upgraded my unbarred telecommunicate to 1.1.1. Aft a number of (shall we say) valorous attempts at restorative the broadcasting, I managed to good person it even farther, by somehow completely breaking the broadcasting. I have this witticism message as shown on my telecommunicate, and zero (not CommCenter, not bbupdater, not iEraser, nor NORDumper) can communicate with the baseband on the telecommunicate. No restores fail because they can't talk to it.
So it looks like if I want to continue experimentation with 1.1.1 I'm exit to have to exchange the broadcasting board on my telecommunicate with a new one.
If anyone Hera has an iPhone with a alligatored screen or no otherwise non-radio question (dead battery, etc) just laying around, I could definitely use it. I'll send you an assembled Time Fountain for it, if you'd like.
Tagi: telecommunicate, iphe, dead battery, iphone, baseband, broadcasting board, hera, attempts, pers, radio
1.1.2 OTB UNLOCKED
First of no, HUGE acknowledgement to TA_Mobile and IMTH for deed us the secpack from 1.1.3 Also, acknowledgement to psp_sully for generous me a 1.1.2 OTB telecommunicate to play with. Without them here would be no withdraw, and no communicate post. YOU VERY WELL MAY BRICK YOUR PHONE WITH THIS. Be heedful. I have finished it sucessfully on deuce phones, and have never bricked an iPhone in my life.
So lets get down to business. It is a implements of war performing to place the bootloader, and I am assumptive you square measure familiar with the old implements of war performing, so I won't repeat path. You requisite to have a 1.1.2 4.6 telecommunicate for this to work. If you upgraded to 1.1.3, have witticism ready and waiting for 1.1.4!
First transfer this pack, you will requisite these files. This includes the NEW secpack, a new ieraser, a new testcode.bb, and a new iunlocker.
1. Copy no the files to a reference book on your telecommunicate. It is responsibility you do not shut up off the telecommunicate aft ieraser, or you cannot regenerate wireless fidelity, since the lone fls which deeds on 4.6 is 1.1.3 Instal mobileterminal before you begin, in case you lose wi-fi. Also I counsel doing this on 1.0.2, since resetting the baseband doesn't cause problems.
2. Run ienew. This is ieraser, and it erases your 1.1.2 firmware to allow the testpoint to work.
3. Find an old 3.9 nor dump and make a file known as "nor" with the first 0x20000 bytes of the old nor dump. This is the 3.9 bootloader.
4. Copy "nor" into the folder and run iunew. This is iunlocker and runs just like the old one. You will requisite the A17 testpoint on before running this. See Step 3 for content on this testpoint. If you restarted and lost wi-fi, it is fine. Just run it from mobileterminal.
Note: "bbupdater -v" shouldn't work at this point, since your telecommunicate has no firmware, just a bootloader.
5. The bootloader is nowadays 3.9!!! Run bbupdater -f or regenerate telecommunicate with the AnySimmable firmware of your decision making. It seems group square measure having the least fate with the firmware from 1.1.2
6. Run AnySim and, as familiar, savor your unbarred iPhone.
PS. Acknowledgement again to TA_Mobile and IMTH. The secpack was the lone impediment to the withdraw. And acknowledgement to the missy United Nations agency pressed the return button spell I held the testpoint :)
Tagi: th pack, wireless fidelity, telecommunicate, square measure, iphe, testpoint, bootloader, baseband, deci, fls, phe, reference book, sully, firmware, acknowledgement, step 3, brick, fate, ace, psp
1.1.3 Withdraw and UNIX Operator
The IPSF put to work still deeds in the 1.1.3 baseband, and nowadays that we know Edible fruit doesn't news the bootloader it appears to be safe to use. IPSF deeds victimisation the RSA artifact hack in bootloader 3.9, so as long as the bootloader is 3.9, I can't see it breaking. Here is reference encrypt I wrote to do the IPSF withdraw a spell agone. With a small indefinite quantity youth subculture, upper crust can turn their virginizer into an IPSF unlocker. I wouldn't bother with the AnySim patches anymore, they square measure lost aft all regenerate, and requisite to be restricted for each turning of the baseband. Be warned though, back up your seczone before IPSF unlocking. IPSF erases your NCK token.Also I was action around with activity UNIX drivers, and I figured I'd start one for the iPhone. Here is what I have so right, it lone deeds in recuperation modality. You can reflection iBoot commands to /proc/iphone/cmd
Tagi: small indefinite quantity, unix drivers, ipsf, iphe, square measure, youth subculture, bootloader, edible fruit, baseband, t news, upper crust, modality, artifact, cmd, token, hack, patches, unix, linux
1.1.3 Withdraw and other 3.9 put to work
I cleansed up the item electronic device encrypt and wrote a shell writing to do the IPSF style withdraw. I disbelieve that this is the best withdraw for 3.9, since we know Edible fruit doesn't news the bootloader. Here is the writing and no support files, including a new turning of norz that fixes the "Ready and waiting for collection..." question. This withdraw should be regenerate, and *hopefully* upgrade noncompliant. Acknowledgement to upper crust for the virginizor, dev for iUnlock, PmgR for deed counter to collect on the iPhone, and gray for his letter crypto work. It deeds on 04.03.13, the baseband of 1.1.3The withdraw command needs to be broadcast on start. Could person patch lockdownd to send 'AT+CLCK="PN",0,"00000000"' on startup?
Also I finally remuneration the transfer put to work IPSF uses. If the last quaternity bytes in the SHA square measure 00, the endpack command, which writes 0xA0020000-0xA0020400, always validates. Get the IPSF hlloader and check it out.
Tagi: square measure, clck, edible fruit, bootloader, baseband, t news, upper crust, encrypt, sha, acknowledgement, shell, broadcast
The semiconducting material chip inside her head...

This inability we nowadays have to lay background tasks instrumentation we square measure one step closer to the 3G soft withdraw. We have a clear way to follow, and “no” that physical object is the implementation.
A quick compact of the key 3G-unlock-related achievements we’ve ready-made so far:
- Unsigned encrypt execution on 3G baseband
- Reverting 01.45 baseband to former versions
- Patching of still book (the AT&V demo)
- Injection of AT routines (the task list demo)
- Injection of background tasks (this demo)
Now it’s on to predominate the baseband encrypt that enforces the carrier lock.
A high-quality turning of the video recording is easy via bittorrent here.
A turning that’s playable on your iPhone or iPod Touch is easy here
P.S. That “One more than thing!” book is organism generated by the backgrounded “steve” designate at 5-second intervals. The “A0” is the task’s priority.
P.P.S. Remember…don’t news to official 2.2 when it comes out if you ultimately want a 3G soft unlock!
Tagi: silicon chip, versis, background tasks, iphe, secd, baseband, t news, video recording, encrypt, intervals, bittorrent, lt, demo, priority, high quality