Jul
28
2011

Jailbreak iOS 4.3.5 Using PwnageTool to preserve Baseband

Apple has released iOS 4.3.5 updating your iDevice frimware ,obviously you’ll lose your jailbreak. To jailbreak your iDevice by using Pwnage tool you should follow these below mention steps. Pwnage Tool bundles has advantage over Redsnow as it can preserve your base band for unlocking via Ultrasnow, “iPad 2 users should stay away from this update as there is no jailbreak for it.”

Compatibility

  • iPhone 4
  • iPod touch 3G
  • iPod touch 4G
  • iPad 1

Requirements

Download all above files before proceed, after completing your downloading follow these steps.

Extract Custom Bundle

Extract the .zip folder. Now you will find a .bundle file, move this file to your desktop

Pwnage tool app

Drag the PwnageTool app to the /Applications folder, right click over it and simply click on “Show Package Contents” as shown in the pic.

PwnageTool Jailbreak iOS 4.3.5 Using PwnageTool to preserve Baseband

Place .bundle file

Go to Contents/Resources/FirmwareBundles/ and paste the .bundle file that you copied to your desktop in this location.

Create Custom Firmware

Launch Pwnage Tool

Launch PwnageTool in Expert mode, and select your iDevice and click on next button.

ipsw Firmware

Browse for iOS 4.3.5 IPSW firmware for your iDevice.

Jailbroken Firmware.

After this click on Build to start making a jailbroken firmware as shown below.A custom .ipsw file will then be created by PwnageTool for your iDevice which will be jailbroken.

select Build1 Jailbreak iOS 4.3.5 Using PwnageTool to preserve Baseband

DFU Mode

To put your device in DFU mode , hold down both the “Home” and “Power” button for ten seconds, Then release “Power” button but keep holding the ‘Home’ button for ten more seconds now your device would be in DFU mode.

DFU Mood1 Jailbreak iOS 4.3.5 Using PwnageTool to preserve Baseband

Start iTunes

Restore your device to your pre-jailbroken custom 4.3.5 .ipsw files by doing this ,Start iTunes, click on your device icon from the sidebar in iTunes. Then press and hold left “alt” (option) button on Mac, or Left “Shift” button if you are on Windows on the keyboard and then click on “Restore” button in the iTunes and then release this button.

iTunes 10.2.21 Jailbreak iOS 4.3.5 Using PwnageTool to preserve Baseband

iTunes prompt you to select the location for your custom firmware 4.3.5 file. Select the required custom .ipsw file that you created above, and click on “Open”.
Wait till iTunes installs the new firmware 4.3.5 on your device.Once the installation is done, your device will be jailbroken on iOS 4.3.5.

Booting in Tethered Mode

This is tethered jailbreak so you have to run this small tetheredboot utility by following these steps.

  • Extract the tethered boot .zip file which you have download before
  • we need two files from the custom iOS 4.3.5 firmware namely:kernelcache.release.n90 and iBSS.n90ap.RELEASE.dfu. To do this, make a copy of your custom iOS 4.3.5 file that you created above, change the extension of this file from .ipsw to .zip, and then extract this .zip file.
    Now copy kernelcache.release.n90 file, and then copy iBSS.n90ap.RELEASE.dfufiles which are found under /Firmware/dfu/.
    Move all these files, and tetheredboot utility to a new folder named “tetheredboot” on the desktop.

Commands

Turn off your iOS device, and start Terminal on OS X and run the following commands:

sudo -s

enter your administrator password, then:

/Users/Tech/Downloads/tetheredboot/tetheredboot
/Users/Tech/Downloads/tetheredboot/iBSS.n90ap.RELEASE.dfu
/Users/Tech/Downloads/tetheredboot/kernelcache.release.n90

You need to replace “Tech” with the name of the directory on your PC.
If the command given above does not work you can always try ‘tetheredboot -i ibss -k kernel’ instead of ‘tetheredboot ibss kernel’:

/Users/Tech/Desktop/tetheredboot/tetheredboot –i
/Users/Tech/Desktop/tetheredboot/iBSS.n90ap.RELEASE.dfu -k
/Users/Tech/Desktop/tetheredboot/kernelcache.release.n90

You should now see some code running in the Terminal window, at some point, it will ask you to enter DFU mode. Now follow the following steps to enter DFU mode:

  • Hold Power and Home buttons for 10 seconds
  • Now release the Power button but continue holding the Home button for 10 more seconds

You device should now be in DFU mode
Now wait for your device to boot, Terminal at this point will be showing “Exiting libpois0n” message. After a short while, your device will be booted in a jailbroken tethered mode !

Related Posts

About the Author: Abdul Malik

  • Pingback: Download iOS 4.3.5 For iPhone 4, 3GS, iPad 2, 1, And Pod touch (ipsw) | TechFlipper

  • Pingback: Jailbreak ios 4.3.4 with pwnage tool (tutorial) | TechFlipper

  • Zander

    Is this applicable to the iphone 3GS?  i attempted to run through the steps you outlined, but substituted the 3GS 4.3.5 ipsw file.  however pwnage 4.3.3 returned the error “wrong package” (or something to that effect).
     
    can you suggest a solution?
     
    -Zander

    • Star_craft83686

      I’m getting the same problem and have been searching everywhere for a pwnage 3GS 4.3.5 bundle but haven’t found one. If anyone has it let me know ASAP!

    • Nitin

      it works fine for my 3GS  thanx for the post . @79936a72a13abb89e57678f66df4636b:disqus  zander have u follow the steps correctly i think u miss some or problem with ur downloading file keep in mind pwnage tool is mac only software…
      Nitin

    • http://pulse.yahoo.com/_ORHZN6W33NUZUS4ICWZNFAHMA4 Jens J

      No Nitin.. There is no bundle for 3gs. Pwnagetool does not work without the bundle for the ios AND the device.

    • Kate

      Any updates on a bundle for 3GS?

  • Matty

    At this point: /Users/Tech/Downloads/tetheredboot/iBSS.n90ap.RELEASE.dfu
    I get an error in Terminal – “Permission Denied”

    Any advice?

    • Ralph

      You need to replace “Tech” with the name of the directory on your PC.

    • Matty

      I sure did otherwise it wouldn’t find the directory. It just won’t allow due to permissions. I guess nobody else has experienced the same concern?

  • sandraqu

    What I have noticed is that if the Pwnage ticker stops at 6, you get DFU success and the Restore to custom ipsw works.  IF Pwnage ticker stops at 7, you get DFU success, but the Restore to custom does not work.  So if the Pwnage ticker stops at 7 for you, try again despite the blue ballon.  Hit OK, Hit DFU mode, or the back button on Pwnage (whatever works) and try again.

  • sandraqu

    Also, to date, Cydia and Safari do not work for me.  They crash upon launch.  In an attempt to fix this, I tried accessing the phone via SSH, SFTP and also with PhoneView.  I can’t access the phone via SSH or SFTP.  The /lib is not visible with PhoneView.  Back to zero.

  • Pingback: Download And Install iSSLfix Jailbreak Tweak Repairs SSL Vulnerability On iOS 4.3.3 Jailbroken iPhone, iPad, iPod touch | TechFlipper

  • Pingback: Add Custom Startup Video To iPhone or iPad (Jailbreak Tweak) | TechFlipper

  • Rastaman

    Does somebody try his for iPad2 ?
    Still on 4.3.5 on iPad2. Can’t find solution to have Cydia inside ;(

  • Jassel

    I get an error in Terminal – “Permission Denied”  helpppppppp!!!! i have over 12 hours looking for the solution!

    • Guset

      u must have administrator previllages  

  • http://usb3gvn.com USB 3G

    Wow… This is great! I can say that this is the first time I visited the site and I found out that this blog is interesting to read. Thanks for this awesome monitor.
    this is exciting technology imformation. I like it. Thank you very much!

  • http://usb3gvn.com USB 3G

    Hi! I read your report and I want to said it is good imformation. I like it and I appreciate your effort. Thank you very…much! (^-^)

Advertisement

Ads

Follow Us