4.0 Jailbreak iPod Touch 3G with sn0wbreeze 1.7 on Windows [Tethered]

July 10, 2010

Sn0wbreeze 1.7 was released which fulfilled the promise to provide a tether jailbreak 4.0 for iPhone 3GS new bootrom and iPod Touch 3G 2G MC models. It is a bit complex procedure for normal users to handle with. The developer of sn0wbreeze 1.7, has been trying to make it more easy for the users. He recently updated the tutorial and tools to make it more simple.

The detailed procedure as instructed by ih8sn0w is follows

If people read the tutorial they will succeed. If not they will fail.

I figured making a tool would take a bit too long. So, i’m going to write up this tutorial. It isn’t recommended for regular users.

**BEFORE PROCEEDING, ENSURE THAT YOU HAVE YOUR iPod/PHONE BACKED UP!**

THIS TUTORIAL ASSUMES YOU ARE ALREADY ON 3.1.2!

Q: Why not 3.1.3???
A: The exploit used is closed in 3.1.3 and beyond.
——-
WHAT YOU WILL NEED:

* An iPhone 3G[S] or iPod Touch 2G MC or iPod Touch 3– new bootrom
* 3.1.2 already installed or 3.1.2 installed via SHSH blobs. <– Broken blackra1n’d devices will work. (Especially if Spirit messed you up!).
* Payload Pwner-r6
* sn0wbreeze V1.7
* iBooty V1.5
* 3.1.2/4.0 firmware downloaded.
* iTunes 9.2 Installed
——-
STEP A : Pwning iBoot

I : Download this easy tool here — Payload Pwner-r6 // It will help you create the payload.

II : Extract it to a directory and run Pwner.exe

**SAVE THE PAYLOAD WHERE iBooty is.**

——-
STEP B : Making a Custom IPSW

I : Download sn0wbreeze V1.7 from here — sn0wbreeze V1.7

II : USE EXPERT MODE!

III : In General, Checkmark “Disable NOR Flash” <– THIS IS ESSENTIAL!!!!

IV : Build it. It will be on your Desktop.

**CUSTOM BOOT LOGOS THAT ARE MADE IN sn0wbreeze WILL NOT WORK ON NEW BOOTROMS!**

*Mac Users : PwnageTool does not have this option. I don’t think it will ever be in there. Use a Windows Virtual Machine or friends PC to create your firmware.*
——-
STEP C: iBooty Prep.

Most of you know of the utility “iBooty” that I made for Aki_nG.

It will work as long as you place all of the correct files there.

I : Download iBooty GUI here — iBooty V1.5 and Extract it.

II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.

III : Grab the kernelcache and bring it into the same folder as ibooty.
Also grab iBEC from the folder “Firmware\dfu”.
Aswell as DeviceTree from the folder “Firmware\all_flash\all_flash.n88ap.production\DeviceTree.n88ap”.

IV :
* Rename your Kernel 4.0-Custom to “kernel.40″
* Rename your iBEC 4.0-Custom to “ibec.40″
* Rename your DeviceTree 4.0-Custom to “devtree.40″
***MAKE SURE YOU REMOVE THE .img3/.dfu/etc extensions!***
======
Your folder should look like this :

- iboot.payload <– Created with Payload Pwner.
- devtree.40 <– Grabbed from Custom IPSW made by sn0wbreeze.
- ibec.40 <– Created with Payload Pwner.
- bspatch.exe <– Comes with iBooty.
- iBooty.exe <– Comes with iBooty.
- kernel.40 <– Grab from Custom IPSW made by sn0wbreeze.
- sn0w.img3 <– Comes with iBooty.
- wait.img3 <– Comes with iBooty.
======
——-
STEP D: Restoring to 4.0 + Booting
——-
*MAKE SURE YOU ARE ON 3.1.2 WHEN DOING THIS*

I : Run iBooty and Select “Prepare Device for Custom Firmware”. Make sure that your device is in Recovery Mode (The one with the iTunes Connect Logo). Run the Process and if you see the image, you can proceed!

II : Now open iTunes and restore to the custom ipsw.

***WHEN DONE, YOUR DEVICE WILL GO INTO RECOVERY MODE. IT WONT BOOT.***
——-
STEP E : Booting

I : Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!
——-
Enjoy!
——-
============
CREDITS:
============
* AKi_nG (For testing 3GS.)
* demize95 (For testing iPod Touch 3!)
* msft.Guy (Helping out here and there.)
* planetbeing (For xpwn.)
* posixninja (For his continuous help!!!)
* You (For making this community possible.)

Following this tutorial, you can tether jailbreak iPod Touch 3G and 2G [MC Models]on iOS 4.0 if you have earlier saved 3.1.2 SHSH Blobs or currently on 3.1.2 firmware. iPhone Dev Team has successfully managed to find a uersland jailbreak which will probably be released as Spirit after Apple rolls out 4.0.1 update. It will be a single click jailbreak solution for all iDevices on 4.0.1 firmware.

Related Articles:

{ 12 comments… read them below or add one }

Fruchtfliege July 14, 2010 at 05:00

So if it is possible now, can you create a tethered jailbroken custom firmware and upload it anywhere, as you did it for the iphone 3g, 3gs and the ipod touch 2g? i would thank a lot!
greetz, Fruchtfliege

Reply

jS July 16, 2010 at 07:20

Has anyone had success with this method? I’m afraid of bricking my phone

Reply

Rhys July 29, 2010 at 06:19

impossible to brick idevice. you can restore easily via itunes.

Reply

bobbyyyy July 16, 2010 at 11:40

How the hell do you Checkmark “Disable NOR Flash”? it wont let me check that box :(

Reply

Scoob July 17, 2010 at 13:40

I did this, but iy kept coming up with an error message saying thet my “icuuc36.dll was not a valid windows image” .. also what “image” am i supposed to see? for me the connect to itunes logo remains.. any ideas?

Reply

sunny July 19, 2010 at 06:59

it works!

Reply

fets July 19, 2010 at 09:25

All did worked but step E not…
The screen stays black.

Reply

fets July 19, 2010 at 11:19

Sorry for dubble post but I tried it again and now it worked!!

Reply

fightingko July 20, 2010 at 13:12

omfg, this thing sucks. I tried it like 16 times and allways when i click prepare device for custom firmware or something it just gives my ipod a black/grey screen. Does some1 have the solution for this problem?

Reply

pearberryxox July 26, 2010 at 19:49

i've never jailbroken anything, so i have no clue what half of this means.. someone needs to post instructions for noobs like mehh :( i'm confused

Reply

dffdfdfdf July 27, 2010 at 20:09

canu jailbreak a 3g 4.0 firmware MC version with this???!!??

Reply

8768 July 31, 2010 at 17:56

Yeah well does it?

Reply

Leave a Comment