An Open-Source Work-In-Progress iOS 6 Jailbreak Using a Custom Ramdisk
This tool allows you to Verbose Boot a SSH Ramdisk, and hence get full RootFS access on your device. From here you can modify the RootFS in any way you please.
- Set up a Window 7 Virtual Machine (this is a requirement)
- Download the latest release of PwnBoot (www.pwnboot.tk) to your Windows 7 VM
- Connect your iPhone2,1 to your VM in DFU mode
- Run
PwnBootCLI
to see a list of uses of PwnBoot
- Booting a Custom SSH Ramdisk on your iPhone2,1 (
PwnBootCLI iPhone2,1 -b
) - VERBOSE BOOTING a Custom SSH Ramdisk on your iPhone2,1 (
PwnBootCLI iPhone2,1 -vb
) - Forwarding the resulting SSH connection over USB (
PwnBootCLI iPhone2,1 -j
) (This must be run AFTER booting the SSH Ramdisk using one of the above commands)
PwnBootCLI iPhone2,1 -vb
PwnBootCLI iPhone2,1 -j
C:/PwnBoot/itunnel_mux --lport 2022
- SSH into the device in a new CMD window (root@127.0.0.1 over port 2022 with password
alpine
). Don't close itunnel_mux window until you're done. - Over SSH run
mount.sh
and you will now be able to access the full root filesystem of your device
- Support FULLY JAILBREAKING YOUR DEVICE (Cydia, etc.) (Just requires more kernel patches by me)
- Support more devices (iPhone 4 tethered, iPhone 3G untethered, etc.)
- Add custom bootlogos
- Utilize the
launchd.conf
untether bug for some cool stuff :)