Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
P.S. nobody cares.

Security holes always exist, and comex had to work extremely hard to make this one do what he wanted it to do. hacking is not easy.

While this is a security hole, and its now public, i guarantee you that you never hear of malware getting on to iOS devices through this hole. It just doesn't happen the way you imagine it does.

very true. the only malware/virus that even came semi-close to getting on an iOS device through any kind of hole was when jailbreakers install openSSH and didn't change the default password. and even that only when you happen to be on the same wifi network as a hacker who is actively distributing said offensive content to iOS devices.
 
Nice

was using greenpoison and decided to update the OS and JB using this. Seems much cleaner.

The update was a real PITA but it's working fine now.

THANKS!
 
Security holes always exist, and comex had to work extremely hard to make this one do what he wanted it to do. hacking is not easy.

Apparently, it took 10 months to develop Jailbreakme 3.0. Most likely, not all that time was dedicated to the exploit's development but it shows that development is not easy.

As usual, it appears that some of these bugs are not present in OS X so using a derivative of this exploit in malware on a broader scale is not likely to occur before a patch is released by Apple.

very true. the only malware/virus that even came semi-close to getting on an iOS device through any kind of hole was when jailbreakers install openSSH and didn't change the default password. and even that only when you happen to be on the same wifi network as a hacker who is actively distributing said offensive content to iOS devices.

Actually, if the final payload for this exploit was changed from Cydia to something malicious, it would facilitate the install of malware.

This type of jailbreak is an example of a remote exploit being chained together with a local exploit to produce a remote root.

I believe much of the reason this occurs more frequently in iOS is that jailbreaking provides a motive to search for these bugs (most of which do not affect OS X but it somewhat represents a code audit of both iOS and OS X) and because iOS is only 32 bit.

32 bit security mitigations (ASLR and XD in this case) can be bypassed using brute force based methods or ROP (as I believe was used in this example; also works against 64 bit). Many of the security mitigations used in iOS differ from those of OS X.

Local exploits, as used in Jailbreakme, are not common in iOS.

http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=apple+ios+gain+privileges

That link shows previous examples of such vulnerabilities; one of which was used in Jailbreakme 2, which also used a Safari based exploitation vector.
 
Last edited:
Sorry dude LOC exemption is only for phones. You making it available for iPad or iPod is and always has been illegal.

This is ********. And by the way, LOC doesn't have to approve of anything before it becomes legal. Why are people all of a sudden so anxious to live in an Apple-ruled fascist state?

Jailbreaking is as legal as breathing air until proven otherwise in an enforceable court judgment.
 
In the heart of this fresh jailbreak, I present all those morally concerned on piracy an image, enjoy;):

xs3qw_02b4.jpg
 
Last edited:
doesn't download on my iPhone 4...!

Don't know why, but I've been trying on and on during the last 30'. Once I click on the "install", the app comes, download starts but immediately appears: "Tehre was a problem downloading the jailbreak files. Invalid checksum". I just eamil Comex as a message came up on the phone following these failures.

Anybody experienced the same? :confused::confused::(:(
 
Reboot

Every iPhone reboot took forever after jail breaking on an iPhone 4 with 4.2.8.

I never had this problem on any other iPhone after jail breaking . Anyone else seeing this issue?
 
Jailbroke my 32gb verizon iphone with 4.2.8 and i tried to download several apps but either the installer has frozen or the phone goes blank and is unresponsive. I'm on my second restore already :( any thoughts?
 
Wirelessly posted (Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_3_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8J2 Safari/6533.18.5)

Cydia would load but not install! I ended up doing a full restore (to make my 3GS like new), THEN reloaded everything, THEN jailbroke the device. Cydia FINALLY loaded & I am good to go! Took about 1 1/2 hrs total.
 
Same boat

Jailbroke my 32gb verizon iphone with 4.2.8 and i tried to download several apps but either the installer has frozen or the phone goes blank and is unresponsive. I'm on my second restore already :( any thoughts?

I have jail broken all five versions of the iPhone (I count the Verizon iPhone 4 counts as a separate version). Never had this problem. Ever...

Wonder if it is not fully compatible.
 
I was having the same problem with the "invalid checksum" error and was successful with the following:

1. Close all open apps
2. Do a hard reboot of iPhone by pressing and holding both Home button and Sleep/Wake button simultaneously until the phone reboots (white Apple logo appears)
3. Go to www.jailbreakme.com and download Cydia

Worked great...easiest jailbreak ever.

Don't forget to change your root and mobile root password...the Mobile Terminal app crashes for some reason following 4.3.1, but I found the solution here:

http://iphonejailbreaks.org/mobile-terminal-crashes-on-ios-4-3-1-here-is-the-solution/

Cheers,
Johnny
 
ah
went to site on my verizon iphone cydia installed but go to packages or browse goodies and get msssg nothing there ect..
 
This may seem like a no-brainer to some, but I was dumb enough to have it happen to me, so I thought I'd post it: once you've jailbroken your iPad, be very wary about installing Cydia packages designed for iPhone/iPod touch. There could be compatibility issues of varying seriousness.

I installed Light Bright on my iPad 2 to try it out. That was a mistake. Froze the device solid after a few seconds of use, and once I hard-rebooted it, SpringBoard seemed to think it was running on an iPhone — the whole screen was filled, but all icons (except folder icons) were rendered at their iPhone sizes, spaced way out near the edges at 4x4 instead of the iPad's 5x5. Even the keyboard in Spotlight was an iPhone keyboard, stuck at the far left. Running any app, including Cydia, crashed the thing so hard it rebooted all over again. It's currently stuck most of the way through restoring, with no sign that it intends to finish. (Edit: it just finished...which may or may not have anything to do with the fact that I installed and opened the latest version of TinyUmbrella seconds earlier.)

Don't be a dumbass like me! Be wise. Be safe. Be...aware. :D
 
Last edited:
I just don't like Jailbreaks, because well I guess I am lazy...
I mean what is it you can do with a jailbreak?
You can install non-apple-approved software, use pirated apps, browse the file system, right?

The non-apple-approved software may or may not be non-approved for a good reason, if it is a good or bad reason, well that is a different topic.
Personally I admit I don't no much about the Cyndia apps, but I don't really care either, some may be good e.g. wifi- sync, but that will come anyway with ios 5 so I just wait.

Second the pirated apps, most of the iphone developers are indie devs or people like you and me, I don't no about you, but I don't like the idea of some small developer losing part of there income, because of a jailbreak. It is just wrong not to pay them for their work!

And last the file browsing capability, while I see the potential in there it isn't just easy enough. You either have to install openssh or use some other software, why do I have to do this, that is not why I bought an apple device.
If I would want software, where I would have/want to adjust anything I would buy android and use windows or linux.

What I like about apple products is they are almost carefree and they are dumped down enough, so I can concentrate on the work itself, not on the device.


But well if you folk want to use the jailbreak go ahead and do so, I won't and this post was a waste of my time...
 
Don't know why, but I've been trying on and on during the last 30'. Once I click on the "install", the app comes, download starts but immediately appears: "Tehre was a problem downloading the jailbreak files. Invalid checksum". I just eamil Comex as a message came up on the phone following these failures.

Anybody experienced the same? :confused::confused::(:(

I finally succeeded by using the mobile network (3G) rather than my WiFi network... Don't really know why, but it did work immediately. And then spent 1 or 2 hours getting some apps on Cydia.
 
had already jailbroken my iPad 1.0 (ios 4.3.2) through other means. upgrading to 4.3.3 should not really be necessary (amirite?).

and if ever i upgrade (and using jailbreakme), would all installed cydia apps have to be reinstalled and reconfigured?
 
Wirelessly posted (Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_3_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8J2 Safari/6533.18.5)

Cydia would load but not install! I ended up doing a full restore (to make my 3GS like new), THEN reloaded everything, THEN jailbroke the device. Cydia FINALLY loaded & I am good to go! Took about 1 1/2 hrs total.

Yea, I had to do the same thing. I restored to factory, installed from a previous backup, the installing Cydia worked. Unfortunately for me, like a dummy, I didn't start the process until late and ended up not getting to bed till after 2am!! Ug. Today is going to suck....
 
German magazine "Spiegel Online":

http://www.spiegel.de/netzwelt/gadgets/0,1518,772962,00.html

Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security; similar role as the NIST, United States, or CCTA, United Kingdom; Wikipedia) warns of iOS 4: Critical security hole in iOS 4 PDF reader.

Wikipedia: Spiegel Online

Spiegel Online (or short: SPON), the online version of Der Spiegel, is one of the most visited news websites in German language.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.