Finally there is some great news for iPod Touch 2G MC model and iPod Touch 3G owners who were looking to jailbreak iOS 4 on their devices.
iH8Sn0w has authored a comprehensive guide that will allow you to successfully pwn your devices provided that you have ample hands-on jailbreaking experience. In case you are a regular user and haven’t done any root level mods to your iDevice, then it is advised to wait for the next version of Sn0wBreeze [which might do this for you automatically]. Here are the step by step directions on jailbreaking iOS 4 on iPod Touch 2G MC model and iPod Touch 3G according to iH8Sn0w. Also note that you can use this method to jailbreak your iPhone 3GS with new Bootrom using this method too. This jailbreak only works if you have OS 3.1.2 Firmware currently installed on your device or you have saved SHSH Blobs of this firmware.
It is advised to thoroughly read and re-read this tutorial 2 or 3 times before embarking on the pwning process.
*BEFORE PROCEEDING, ENSURE THAT YOU HAVE YOUR iPod/PHONE BACKED UP!**
THIS TUTORIAL ASSUMES YOU ARE ALREADY ON 3.1.2!
Q: Why not 3.1.3???
A: The exploit used is closed in 3.1.3 and beyond.
WHAT YOU WILL NEED:
* An iPhone 3G[S] or iPod Touch 2G MC or iPod Touch 3– new bootrom
* 3.1.2 already installed or 3.1.2 installed via SHSH blobs. <– Broken blackra1n’d devices will work. (Especially if Spirit messed you up!).
* Payload Pwner-r5
* sn0wbreeze V1.7
* iBooty V1.5
* 3.1.2/4.0 firmware downloaded.
* iTunes 9.2 Installed
STEP A : Pwning iBoot
I : Download this easy tool here — Payload Pwner-r5 // It will help you create the payload.
II : Extract it to a directory and run Pwner.exe
**SAVE THE PAYLOAD WHERE iBooty is.**
STEP B : Making a Custom IPSW
I : Download sn0wbreeze V1.7 from here — sn0wbreeze V1.7
II : USE EXPERT MODE!
III : In General, Checkmark “Disable NOR Flash” <– THIS IS ESSENTIAL!!!!
IV : Build it. It will be on your Desktop.
**CUSTOM BOOT LOGOS THAT ARE MADE IN sn0wbreeze WILL NOT WORK ON NEW BOOTROMS!**
*Mac Users : PwnageTool does not have this option. I don’t think it will ever be in there. Use a Windows Virtual Machine or friends PC to create your firmware.*
STEP C: iBooty Prep.
Most of you know of the utility “iBooty” that I made for Aki_nG.
It will work as long as you place all of the correct files there.
I : Download iBooty GUI here — iBooty V1.5 and Extract it.
II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.
III : Grab the kernelcache and bring it into the same folder as ibooty.
Also grab iBEC from the folder “Firmwaredfu”.
Aswell as DeviceTree from the folder “Firmwareall_flashall_flash.n88ap.productionDeviceTree.n88ap”.
* Rename your Kernel 4.0-Custom to “kernel.40”
* Rename your iBEC 4.0-Custom to “ibec.40”
* Rename your DeviceTree 4.0-Custom to “devtree.40”
***MAKE SURE YOU REMOVE THE .img3/.dfu/etc extensions!***
Your folder should look like this :
– iboot.payload <– Created with Payload Pwner.
– devtree.40 <– Grabbed from Custom IPSW made by sn0wbreeze.
– ibec.40 <– Created with Payload Pwner.
– bspatch.exe <– Comes with iBooty.
– iBooty.exe <– Comes with iBooty.
– kernel.40 <– Grab from Custom IPSW made by sn0wbreeze.
– sn0w.img3 <– Comes with iBooty.
– wait.img3 <– Comes with iBooty.
STEP D: Restoring to 4.0 + Booting
*MAKE SURE YOU ARE ON 3.1.2 WHEN DOING THIS*
I : Run iBooty and Select “Prepare Device for Custom Firmware”. Make sure that your device is in Recovery Mode (The one with the iTunes Connect Logo). Run the Process and if you see the image, you can proceed!
II : Now open iTunes and restore to the custom ipsw.
***WHEN DONE, YOUR DEVICE WILL GO INTO RECOVERY MODE. IT WONT BOOT.***
STEP E : Booting
I : Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!
Disclaimer: Please make sure that you have ample hands-on jailbreaking and pwning experience before trying your hands on this one. AddictiveTips won’t be liable for any damages that may incur to your device during the process
How To Save OS 3.1.2 SHSH Blobs