Ok I'm not totally clear on everything. Lightly correct errors
-- basically the segment is overwritten. This means that anything over 0x24000 bytes will not be read (or signature checked) by the bootrom during the RSA BootRom Check. This allows unsigned code to be executed in the overwritten segment Allowing a custom LLB to be booted and other such things (cydia installer etc. ) to be executed. And because you have the bootrom out of the way you can patch the LLB-> iBoot -> Kernel -> codes in kernel allowing am untethered jailbreak.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment