iPhone 4S (N94AP) iOS 6.1.3 Kloader Manual Bootstrap with Verbose @pmbonneau
iPhone 4S (N94AP) iOS 6.1.3 Kloader Manual Bootstrap with Verbose  @pmbonneau
Uploaded October 2015 | Updated September 2026, 10 hours ago
IMPORTANT!!! Please note that this video is for educational purpose only. By watching this video, you agree that I'm not responsible of what might happen with the use of informations provided.

WARNING : This video involves hacking on Low-Level parts of iOS. Unlike userland, those parts contains lot of critical informations about the device's hardware, which could be corrupted and lead to a hard brick if something goes wrong by following instructions provided in this video.

First, I downgraded my N94AP from iOS 9.0.2 back to 6.1.3 especially because Low-Level Bootloaders and Kernel patches are already made for that still signed version, so it makes things easier. From a jailbroken iOS 6.1.3 kernel on which TaskforPid() is patched, Winocm's Kloader can be executed to bootstrap the beginning of another iOS bootchain instance. The ARM image usually used with kloader is iBSS, from the DFU Bootchain. Most Kloader bootstraps use DFU Bootchain's images even if it is also possible to use Flashed Bootchain ones, which are usually more complete (like flashed iBoot can interact with File System, while iBEC can't). DFU one usually involve more loading in memory than Flashed Bootchain, which is more File System friendly. Once Kloader did it's magic and loaded iBSS, we have to send to it iBEC ARM image, the second stage of the DFU Bootchain. The LCD screen of the iOS device light up when iBEC is launched. Now the most interesting part begins. We have to send to iBEC each boot components in a specific order. First, send and execute the DeviceTree. Second, send and load a Ramdisk (seems to make no sense because we want to boot the File System, but there is something tricky here). Third, send the iOS Kernel and launch it using "bootx".

If you do those steps using original decrypted and patched files, without patching boot-args, this will load the restore Ramdisk. If you don't specify a Ramdisk in steps above, this will load the File System, but without taking in consideration boot-args (no verbose boot). If you open the decrypted iBEC file using a Hex editor, you will notice that boot-args are set like that : rd=md0 nand-enable-reformat=1 -progress. Those are boot-args used when booting a Ramdisk. If we change this boot-args string to : "-v", iBEC will load the File System by default, because we removed "rd=md0" which sets the RootDevice to "MemoryDevice0", which is the Ramdisk.

Special thanks to @blackgeektuto for Beehind downgrade and @xerub for the Odysseus Method, used in Beehind. This saved me lot of time, because I had to restore my N94AP to 9.0.2 and downgrade it back to 6.1.3 multiple times. Also, a special thanks to @dayt0n and @iH8Sn0w for many advices about boot-args and verbose booting.
iPhone 4S (N94AP) iOS 6.1.3 Kloader Manual Bootstrap with VerboseNew Super Mario Bros. DS - Custom LevelCrash Bandicoot The Wrath Of Cortex Hacked - Unlimited Wumpa Fruits & LivesCéline Dion - Pour que tu maimes encore (Interprété par Sarah-Jeanne)iPhone 4 (N90AP) iOS 7.1.2 Pangu Jailbreak - Cydia Applications Stashing FailFuturama - Holophonor Sonnet for Leela [Piano]Test Léger Navette (Bips) 20 MètresiPhone 4 (N90AP) iOS Multi Boot - Kloader and Limera1n DFU BootstrapImgTool v1.0b (1A0116c) - Analysis of Decrypted Apple Img3 ContainersCrash Bandicoot The Wrath Of Cortex Level Editor : Custom Jungle RumbleSuper Mario World Hack: Le Retour de Mario - Title & Intro ScreeniOS Diagnostic Tool - PurpleSNIFF
Pierre-Marc Bonneau |

iPhone 4S (N94AP) iOS 6.1.3 Kloader Manual Bootstrap with Verbose

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER