iPhone 4 (N90AP) iOS Multi Boot - Kloader and Limera1n DFU Bootstrap @pmbonneau
iPhone 4 (N90AP) iOS Multi Boot - Kloader and Limera1n DFU Bootstrap  @pmbonneau
Uploaded December 2015 | Updated September 2026, 44 minutes ago
IMPORTANT!!! Please note that this video is for educational purpose only. By watching this video, you agree that I'm not responsible of what might happen with the use of informations provided.

WARNING : This video involves hacking on Low-Level parts of iOS. Unlike userland, those parts contains lot of critical informations about the device's hardware, which could be corrupted and lead to a hard brick if something goes wrong by following instructions provided in this video.

From a jailbroken iOS 7.1.2 kernel on which TaskforPid() is patched, Winocm's Kloader can be executed to bootstrap the beginning of another iOS bootchain instance (in this video, it's an iOS 6.1.3 one). The ARM image usually used with kloader is iBSS, from the DFU Bootchain. Most Kloader bootstraps use DFU Bootchain's images even if it is also possible to use Flashed Bootchain ones, which are usually more complete (like flashed iBoot can interact with File System, while iBEC can't). DFU one usually involve more loading in memory than Flashed Bootchain, which is more File System friendly. Once Kloader did it's magic and loaded iBSS, we have to send to it iBEC ARM image, the second stage of the DFU Bootchain. The LCD screen of the iOS device light up when iBEC is launched. Now the most interesting part begins. We have to send to iBEC each boot components in a specific order. First, send and execute the DeviceTree. Second, send and load a Ramdisk (seems to make no sense because we want to boot the File System, but there is something tricky here). Third, send the iOS Kernel and launch it using "bootx".

If you do those steps using original decrypted and patched files, without patching boot-args, this will load the restore Ramdisk. If you don't specify a Ramdisk in steps above, this will load the File System, but without taking in consideration boot-args (no verbose boot). If you open the decrypted iBEC file using a Hex editor, you will notice that boot-args are set like that : rd=md0 nand-enable-reformat=1 -progress. Those are boot-args used when booting a Ramdisk. If we change this boot-args string to : "-v", iBEC will load the File System by default, because we removed "rd=md0" which sets the RootDevice to "MemoryDevice0", which is the Ramdisk. It's also possible to change the default root device by adding "rd=[Root Device]" in iBEC's boot-args string.

Limera1n BootROM exploit is superior than Kloader. It acts directly from DFU mode, so an installed Operating System is not required. In the second part of this video, I simply use RedSn0w jailbreak utility to inject Limera1n over the DFU Mode. The root device is set to the iOS 5.1.1 filesystem in iBEC's boot-args. Then, RedSn0w will automatically send and execute each bootloaders in their respective order.
iPhone 4 (N90AP) iOS Multi Boot - Kloader and Limera1n DFU BootstrapImgTool v1.0b (1A0116c) - Analysis of Decrypted Apple Img3 ContainersCrash Bandicoot The Wrath Of Cortex Level Editor : Custom Jungle RumbleSuper Mario World Hack: Le Retour de Mario - Title & Intro ScreeniOS Diagnostic Tool - PurpleSNIFFTriple Boot iOS 7.1.2, iOS 6.1.3 and iOS 5.1.1 on iPhone 4 (N90AP)Crash Team Racing - Nitro Oxide in Adventure ModeLxShadows Crash Bandicoot The Wrath Of Cortex Level Editor Guide : Part 6 - The Object EditorCrash Bandicoot The Wrath Of Cortex Hacked : Unused Beta Level No. 2 - Removed AirShip LevelMicrosoft XBOX Jailbreak Tutorial - Installation dun exploit NdureiOS Self-DestructionCrash Team Racing - Hot Air Skyway OST [Prototype & Release Mix]
Pierre-Marc Bonneau |

iPhone 4 (N90AP) iOS Multi Boot - Kloader and Limera1n DFU Bootstrap

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER