Search This Blog

Wednesday, September 22, 2010

Pod2g Found another Exploit for iPod Touch 2g MC Model!

Pod2g former member of the chronic dev team found another exploit that will pwn the ipod touch 2g mc model for life! This exploit is different than his other exploit SHAtter.The name for this exploit is- _control_msg(0xA1, 1) exploit. Here is some more information on how it works: A heap overflow exists in the iPod touch 2G (both old and new) bootrom’s DFU Mode when sending a USB control message of request type 0xA1, request 0×1.On newer devices, the same USB message triggers a double free when this is  marked as finished, also rebooting the device (but that’s not exploitable because the double free happens in a row) via theiphonewiki.com. Posixninja analyzed and explained this one.This new exploit will be incorporated with ih8sn0ws sn0wbreeze 2.0! The release will be soon i will keep you guys updated on when it comes out! Picture from redmondpie.com check out ih8sn0w: ih8sn0w.com and twitter.com/ih8sn0w, follow pod2g on twitter twitter.com/pod2g and last but not least follow me on twitter twitter.com/nkapoor124 thanks! For more information about the exploit go to theiphonewiki.com

No comments:

Post a Comment