How the Devteam Conquered the iPhone
fabiensanglard.net
fabiensanglard.net
This is commonly done with fw updaters. first 0x400 bytes is a header that the earlier stage loader needs to see before it'll allow this stage to boot. So you RX the data, write it freely, just not the header. This is safe and will not allow any code exec since the header is missing. then at the end you sig check the whole thing you wrote, and if it is good, you write the header, making the whole image valid.
the trick here is you write 0x400 bytes of garbage first, 0x400 bytes earlier than your desired write. this is buffered but not written (treated as the headers). The rest of what you sent IS written (writing what you wanted where you wanted). then sig is checked. you fail. the first 0x400 is not written (and you did not want it written).
win
Recovery mode is implemented in iBoot; it provides mediated access to the command interpreter and some file-ish transfer capabilities.
Both are still in use; whilst the implementations have obviously evolved the fundamental interactions have not changed since the original Apple (not Samsung) ROMs.
I remember seeing the investigation on this iPhone protection back at the time, what a journey it has been since this work.
Also, I hope someone can provide more information about that minus 0x400 shift before data write so it would be completely explained.
Seek(fd, 0xA0020000 - 0x400);
We seek to 0x400 before where we need to write the data SendWrite(fd, foo, 0x400, false);
We set the first 0x400 bytes of what we want to write to 0 SendWrite(fd, fw, fwsize, true);
We then set the rest of the bytes to our data. SendEndSecpack(fd);
The iphone copies the data from 0x400 bytes onwards (which is all the data we wanted to write), then tries to verify the signature and fails. If the signature could be verified the first 0x400 bytes (which we left as all zeros) would then be copied.However, it seems the firmware was written as 0x800 byte pages:
From what I understand on this thread, the header of the firmware is 0x400 long. A page can be up to 0x800:
``` int size_to_write = Size > 0x800 ? 0x800 : Size; ```
So it would appear the firmware has a header of 0x400 which is buffered during upload but discarded if the firmware fails the checksum at the end of the upload.
It was a really fun time and I learned a lot.
Also, George Hotz endangered the welfare of a few people who had kindly gotten us access to some documentation in Japanese despite repeated pleas not to do so. Very frustrating and why the dev team all eventually stopped working on the project.
Would love any elaboration on this that you can provide which wouldn't expose you to a libel suit.
I’ll never know how real the threat to peoples jobs were but I don’t think they were being overly cautious.
Geohot seems to have a history of throwing other people under the bus to score "victories" for attention
Sounds like the pre-cursor to oAuth now days.
(Yep, it was called iPhone OS back then not iOS.)
Just like car manufacturers. Never buy the first few model years of a new product or platform.
Generally, "S" just indicated a marginal upgrade over the base model.
Same kind of quote: the S in IoT stands for security!
The S is missing, so security was missing too!