PDA

View Full Version : iPod touch 1.1 (3A101a) firmware file


gunsmith
09-12-2007, 08:06 AM
iPod touch 1.1 (3A101a) firmware file released...

http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPod/SBML/osx/bundles/061-3882.20070910.N8uyT/iPod1,1_1.1_3A101a_Restore.ipsw

Matistuta
09-12-2007, 03:21 PM
Thanks, very nice!

Somebody tried to decompress the DMG files? Maybe we can get the foreign keyboard layouts out of it and install it to the iPhone?

wunderbaren
09-12-2007, 03:34 PM
Yes!! Please give us access to the keyboards! :)

GogaMagoga
09-12-2007, 03:40 PM
Keyboards!!!!!!!!

theunknown
09-12-2007, 05:30 PM
Great - and german Autocorrection?

Would be nice 2 have :-)

dro
09-12-2007, 05:36 PM
how would i decode the dmg files? i´m on windows by the way :(
anybody know?
i would really like to take a look

gunsmith
09-12-2007, 06:00 PM
i tried the old method how the dev decrypt the iPhone firmware, but didn't get luck. maybe we need to wait, since everyone are crazy about the sw unlock right now...

kn3pp
09-12-2007, 06:03 PM
i second this request ;)

give us !

gunsmith
09-12-2007, 06:05 PM
btw, 3A101a is not the first known version. there is 3A100a before this version, just like there is a secret private version 1C27 between 1.0.1(1C25) and 1.0.2(1C28) for iPhone.

kallis
09-12-2007, 09:28 PM
We really need to decrypt this!

nofearl
09-13-2007, 02:18 AM
bump.......

Matistuta
09-13-2007, 03:38 PM
Anybody knows in which DMG file the language file are? Can we bruteforce to find out the passwords?

Thanks.

kallis
09-13-2007, 04:35 PM
I tried the iPhone method, but it didn't work. The key was probably wrong. Anybody knows how to find the new key?

Snowbird
09-13-2007, 10:15 PM
Has anyone made any progress here?

Zf_
09-13-2007, 11:30 PM
From what I've seen they encrypted everything this time, including the ramdisk, so it's probably going to be harder :)

Zf_
09-13-2007, 11:43 PM
Well if they were smart and the key is pre-installed onboard, keep trying without a device won't do much :)

kallis
09-14-2007, 12:36 AM
We got to keep trying.

mycintosh
09-14-2007, 12:35 PM
I need the language files *buhuuu*

bowser
09-14-2007, 02:14 PM
Me too! It would be one of the most needed fixes next to the total unlock of my iPhone!!

Hope someone can crack the iPod Touch and get those foreign dictionary files and keyboard settings!

Bowser

adyh
09-14-2007, 02:15 PM
Just wait , the iphone will be out in Europe soon enough.

chinaet
09-15-2007, 12:55 PM
how to decrypt dmg file?

iMags
09-15-2007, 04:35 PM
that is a very good question chinaet.

mycintosh
09-19-2007, 11:04 PM
Still no decrypted .dmg?
thats almost unbelievable ... was Apple doin' well this time with the passwords?

MuscleNerd
09-20-2007, 08:20 AM
Still no decrypted .dmg?
thats almost unbelievable ... was Apple doin' well this time with the passwords?

The pass key is not going to be brute forced.

The pass key on 1.0.0 was 28c909fc6d322fa18940f03279d70880e59a4507998347c70d 5b8ca7ef090ecccc15e82d

On 1.0.1 and 1.0.2 it was 7d5962d0b582ec2557c2cade50de90f4353a1c1de07b742125 13fef9cc71fb890574bfe5

Those are too long to be brute forced in any reasonable time. The keys above were found because they were exposed as simple strings in the "asr" recovery-mode executables.

mycintosh
09-20-2007, 09:06 AM
The pass key is not going to be brute forced.

The pass key on 1.0.0 was 28c909fc6d322fa18940f03279d70880e59a4507998347c70d 5b8ca7ef090ecccc15e82d

On 1.0.1 and 1.0.2 it was 7d5962d0b582ec2557c2cade50de90f4353a1c1de07b742125 13fef9cc71fb890574bfe5

Those are too long to be brute forced in any reasonable time. The keys above were found because they were exposed as simple strings in the "asr" recovery-mode executables.

So Apple fixed that Hole for the iPod touch ... dammit

netkas
09-20-2007, 11:31 AM
and no such string in itouch asr

Polo
09-20-2007, 05:34 PM
i dont know this can be of any help but i could offer computing power. i could spare 7 of my 8 xeon 3Ghz cores ;)
seriously, if computing power is needed, i could help out.

niknyce
09-21-2007, 03:14 AM
thanks for this! there is a newer one out there, can't seem to find it wih phobos.apple etc...let the decryption begin!! :D

Polo
09-21-2007, 04:20 AM
thanks for this! there is a newer one out there, can't seem to find it wih phobos.apple etc...let the decryption begin!! :D

the question os how to proceed? Bruteforce? Even so, this would take a considerable amount of time. What other possibilities are there?

aarongrider
09-24-2007, 04:21 AM
i would really like to know what i can do to help.

ShawnH
09-24-2007, 05:09 AM
I'll see what I can do.

yacoub
09-25-2007, 01:44 PM
My 8GB touch purchased at the local Apple store last Friday is running 1.1 (3A100a), according to the Settings/General/About/Version information.
Its serial begins with 1A737 (week 37 batch) and the model number is MA623LL.

If there is anything special about my version that would be useful to hacking community, let me know. I'd be willing to part with it for what I paid for it (plus shipping) and go buy another one.

GTPprix
09-25-2007, 08:29 PM
Someone should start a project like SETI at home for bruteforcing stuff like this, imagine if we had 2000 or so decent PC's working on this? It would be done today :D

Polo
09-25-2007, 09:10 PM
Someone should start a project like SETI at home for bruteforcing stuff like this, imagine if we had 2000 or so decent PC's working on this? It would be done today :D

there is, it's called "BOINC" even seti runs on it already as far as i know. but who'd be able to write a decent program for decrypt the file? i myself have no idea of cryptology or hacking password enabled files.
i think we need knowledge right now. if there's something to be computed, that's the next step and we need a reasonable softwaresolution for doing the job.

NetMage
09-26-2007, 02:42 AM
Some simple math reveals that a 72 character hex password would take a while...

Let's assume those 3GHz Xeon cores can generate a guess every cycle (impossibly fast).

Let's say every computer in the world has 7 free 3GHz Xeon cores to dedicate to this project (about 7 billion processors).

Let's say we get luck and we discover an answer after trying 1/2 the guesses.

Let's say there is no overhead to making these cores work together.

We'd be done in about 7.5 x 10^59 years.

Of course, if we converted all the atoms in the universe into 3GHz Xeon processors, and borrowed some wire and power from another universe, we'd be done in about 19 hours.

hollip3020
09-26-2007, 06:00 AM
I knew it would be some rediculous amount of time but I didn't think it would be that long. unfortunately my calculations confirm that within a factor of 10, which in this case is negligable. in fact the earth will be consumed by the sun well before the brute force method would yield a result. heres to hoping martyn can get the key from the flash.

ShawnH
09-26-2007, 06:12 AM
Some simple math reveals that a 72 character hex password would take a while...

Let's assume those 3GHz Xeon cores can generate a guess every cycle (impossibly fast).

Let's say every computer in the world has 7 free 3GHz Xeon cores to dedicate to this project (about 7 billion processors).

Let's say we get luck and we discover an answer after trying 1/2 the guesses.

Let's say there is no overhead to making these cores work together.

We'd be done in about 7.5 x 10^59 years.

Of course, if we converted all the atoms in the universe into 3GHz Xeon processors, and borrowed some wire and power from another universe, we'd be done in about 19 hours.

Well just have to use Blue Gene won't we.

Anyway i'll ignore your post and ask anyone if they want to start an xgrid :).

falken
10-03-2007, 09:55 PM
Has anyone put iTunes in a debugger as it updated their itouch? surely that key has be stored in memory while the image is decrypted, before it's passed to the itouch.

There is an easier way to decrypt the dmg than bruteforce.

ollydbg, immunity debugger, IDA (windows)
GDB, DDD, (OS X)

A Book Link: Introduction to Reverse Engineering Software (http://www.acm.uiuc.edu/sigmil/RevEng/)

lets go!
-falken

pendalf
10-03-2007, 10:40 PM
i played with this ipod,
it has all languaches all dictionarys inthere
would be very nice to use it on the iphone...
:)

Ninjafish
10-03-2007, 11:00 PM
I'm pretty sure that those languages are added in iPhone firmware 1.11. Unfortunately it's still encrypted. When we're able to decrypt the firmware we'll be able to use firmware 1.11 anyways so it won't matter.

Also if you think that your information would be useful Falken, add it to the wiki. You can reach it at TouchDev.net (http://www.touchdev.net).

pendalf
10-03-2007, 11:05 PM
I'm pretty sure that those languages are added in iPhone firmware 1.11. Unfortunately it's still encrypted. When we're able to decrypt the firmware we'll be able to use firmware 1.11 anyways so it won't matter.

Also if you think that your information would be useful Falken, add it to the wiki. You can reach it at TouchDev.net (http://www.touchdev.net).

no i played with the iphone runing 1.1.1
no languaches on it, no dictionary
at least on the legal activated iphone with att

:(

Ninjafish
10-03-2007, 11:48 PM
Apologies. Not sure where I thought I read that... You'd think with the iPhone coming out in Europe they'd have support for other languages by now...

falken
10-04-2007, 12:09 AM
Ninjafish: thanks, when I have something I'll toss it up there.

Other ideas:

Usb sniffer, log all the data going to the ipod as it is updated. Try and determine if the dmg decryption happens in itunes or on the ipod itself.

http://sourceforge.net/projects/usbsnoop/
http://www.pcausa.com/Utilities/UsbSnoop/default.htm