Ads 468x60px

Monday, March 21, 2011

New Progress on iPhone 4 Unlock Basebands 2.10.04 / 3.10.01.

Today MuscleNerd has announced some new progress on the iPhone 4 unlock project for basebands 2.10.04 / 3.10.01, the news are related to the iPhone 4 NCK unlock which they are now concentrated to crack the NCK's 40 bit code. MuscleNerd has confirmed via his Twitter account that he finally got the SecZone dumper working.
Someone Asking MuscleNerd: Anything positive coming about your NCK attempts?
MuscleNerd Replying: finally got the SecZone dumper working (turns out it's very different than in 2G/3G/3GS, where SZ was simply memory mapped)
You may ask about the meaning of these tecky expressions:

What is the SecZone?
This is the area in the baseband where the lock state is stored.

What is NCK Brute Force?
This is a theoretical exploit which involves brute forcing the NCK from the seczone the CHIPID and the NORID. So far no one has made public an instance of NCK discovery using this theoretical approach.
MuscleNerd mentioned that the iPhone 4's SecZone is very different and difficult than the one of iPhone 2G / 3G / 3GS. Today's progress is definitely a new milestone. Now dev-team is working on capture the official NCK code and finally capturing after SecZone then work out an offline BF flow

so the idea is: capture (a) before-seczone, (b) official NCK code (c) after-seczone. Then work out an offline BF flow
after those steps a,b,c, then get back to the SW-based hacked unlock (and revisit BF results when they're done)
On the other hand, you have to know that there is another hardware solution for unlocking iPhone 4 basebands 2.10.04 / 3.10.01 with Gevey SIM.

1 comment:

  1. Nice information. There are lot of methods available to unlock iPhone. We can also get it unlock our iPhone safe and securely using Remote unlocking method from This will be a permanent unlocking solution. Both upgrading and downgrading will not lock your iPhone again. This method does not require jailbreak.