Pierre-Marc Bonneau
For this video, I did a dualboot with iOS 5.1.1 and iOS 6.1.6 on my iPod Touch 4th. This time, I resized actual LWVM partitions instead of overwriting the whole table. With this method, I keep the initial restored firmware and it's properly signed bootchain. This means that the lastest iOS 6.1.6 firmware can boot untethered. A signed bootchain also means no weird sleep bug which causes dead LCD screen for other iOS versions. Read here theiphonewiki.com/wiki/Tethered_Downgrade about this weird bug. To switch between firmwares, RedSn0w's Tethered Boot (A4 and older) or Winocm's KexecUtils (on some newer devices) can be used to load operating systems from the DFU bootchain. Even the iPhone 3Gs old BootROM would require a tool such kloader to get an untethered dual boot. If you dual boot iOS 6.x and 5.x and you set nvram rd=disk0s1s3 (iOS 5.x), the iOS 6.x PWNiBoot will attempt to load an iOS 5.x kernelcache, which would result in some panics. Using Winocm's tool, it's possible to bootstrap a pwned 5.x DFU bootchain to chainload 5.x firmwares from 6.x userland. There is a little exception with BootROM exploited devices which we can set nvram variables. An untethered dual boot may be possible if it involves two same generation firmwares, like 5.1 with 5.1.1 or two same firmware. The only thing is that the flashed bootchain must be able to load both firmwares. My next goal with that dual boot is to make it untethered. The hardest part will be to get a fully automated DFU bootstrap using kloader. I now have to play with iBoot for hours.
updated 11 years ago
I'm currently working on a complete write-up about De Rebus Antiquis iBoot exploit. Once it will be released, you should get most of the necessary knowledge to implement what you see in this video. See my personal blog here, pmbonneau.com for more details.
Many thanks to @dora2ios (Twitter) for help with some issues I had while debugging.
After ten years on this channel, here is a new Crash Bandicoot related video!
Hot Air Skyway from CTR, along with Rock it & Pack Attack from Crash Bandicoot 2 and Knight Time from Crash Bandicoot : The Wrath of Cortex are ones of my favorites soundtracks from the serie. Hot Air Skyway being my first favorite Crash Bandicoot sountrack I fell in love with mostly 20 years ago when I played CTR for the first time.
Recently, I found out that there's an extended version of Hot Air Skyway, called "Pre-console" that has been released by composer Josh Mancell. It includes an additional 28 seconds segment that consists mostly of the fist loop plus an instrument called the "Cortex's Trumpet". Pre-Console music consists of music before instruments get stripped down, in this case, for the Playstation 1. CTR pre-console music sound great, but I always prefered original console music.
More recently, I joined the CTR-Tools (software used in this video) official Discord server and someone there told me that the original full length Hot Air Skyway is still here in one of some leaked CTR prototype builds. Okay, so I decided to take a look at this prototype build and I found out that the prototype Hot Air Skyway console version doesn't sounds like the release build console one. Some improvements have been made in the release version, especially in the first loop (compare 03:29 with 05:02). Also, the ripped version quality I found on The Cutting Room Floor is quite lower than what we can find in other video game music websites for the release version.
So, nothing really complicated for this video, we are trying to assemble the cut part of the prototype version while keeping the improvements made to the release one.
List of Hot Air Skyway versions you will hear in this video :
[ 00:10 - 03:12 ] Prototype & Release Mix
[ 03:12 - 04:44 ] Prototype
[ 04:45 - 05:50 ] Release
[ 05:50 - 07:22 ] Prototype, MIDI
[ 07:23 - 07:34 ] Cortex's Trumpet, cut part.
There are three software used in the making of this arrangement.
1 - AnthemScore: To "reverse" the original MP3 version of the song. This software allows me to see a visual representation of the actual song and guess notes, plus it uses an IA to automatically do a part of this work. The final product is a sheet music in MusicXML file format.
2 - MuseScore: To re-encode the MusicXML output of AnthemScore to a more versatile MusicXML format. I don't know why, but using AnthemScore's MusicXML output in Synthesia doesn't work well, the BPM isn't the right one. Converting the file with Musescore will produce a MusicXML file that will be better with Synthesia.
3 - Synthesia: To get this nice piano roll and also to practice the song on a real piano.
Album : Persona (3 to 5)
Title : Aria of the Soul
Arrangment type : Reversed from MP3 version
Download sheet music from my blog here : pmbonneau.com/music/arrangements
Tour approximative time : 1h30
Distance : 10.30 km
Average speed : 5.1 km/h
Date : March 05, 2022
Tour approximative time : 1h00
Distance : 7.28 km
Average speed : 5.8 km/h
Date : January 22, 2022
There are five softwares used in the making of this arrangement.
1 - Nero Recode (probably, I don't remember exactly): To extract the audio from the original video. Then, I cut all the audio except the holophonor part and exported to WAV format using audacity.
2 - AnthemScore: To "reverse" the song. This software allows me to see a visual representation of the actual song and guess notes, plus it uses an IA to automatically do a part of this work. The final product is a sheet music in MusicXML file format.
3 - MuseScore: To re-encode the MusicXML output of AnthemScore to a more versatile MusicXML format. I don't know why, but using AnthemScore's MusicXML output in Synthesia doesn't work well, the BPM isn't the right one. Converting the file with Musescore will produce a MusicXML file that will be better with Synthesia.
4 - Synthesia: To get this nice piano roll and also to practice the song on a real piano.
Album : N/A
Title : Holophonor Sonnet for Leela
Arrangment type : Reversed from soundtrack
Download sheet music from my blog here : pmbonneau.com/music/arrangements
There are three software used in the making of this arrangement.
1 - AnthemScore: To "reverse" the original MP3 version of the song. This software allows me to see a visual representation of the actual song and guess notes, plus it uses an IA to automatically do a part of this work. The final product is a sheet music in MusicXML file format.
2 - MuseScore: To re-encode the MusicXML output of AnthemScore to a more versatile MusicXML format. I don't know why, but using AnthemScore's MusicXML output in Synthesia doesn't work well, the BPM isn't the right one. Converting the file with Musescore will produce a MusicXML file that will be better with Synthesia.
3 - Synthesia: To get this nice piano roll and also to practice the song on a real piano.
Album : Rayman 3: Hoodlum Havoc
Title : Out of Control ~ The Spell is Broken
Arrangment type : Reversed from MP3 version
Download sheet music from my blog here : pmbonneau.com/music/arrangements
For this video, I implemented an untethered triple boot involving iOS 8.4.1, iOS 6.1.3 and iOS 10.3.3 on my iPad 4 (P102AP).
I wrote a tutorial about how to implement an untethered iOS Multi-Boot here two years ago,
http://www.pmbonneau.com/apple/ios/multiboot.php.
It's a testing version, currently only supports iOS 7.1.2 and 6.1.6 on iPhone 4 (N90AP). Currently, I would recommand you @nyan_satan's guide instead since his one is really more complete and mine hasn't been updated since a long time.
This is my daily driver iPad, the one I use everyday. Before, it was running the lastest available iOS as main only. Somewhere in January 2018, something special has been happened in the world of iOS devices. This was the "downgrade party", where Apple signed many old iOS versions for many devices during a few hours. This was the time to grab those SHSH blobs and downgrade back to a desired iOS version, if blobs were available for. I told a friend to grab the blobs for me during the party since I was away, but had the ECID somewhere on my phone. He sent me the downloaded blobs. I then decided to restore my iPad 4th back to iOS 6.1.3 which I had blobs for. Unfortunately, I noticed that the SHSH blobs had the right ECID, but there were for iPad2,4 (WiFi only) model and I had the iPad2,5 (Wi-Fi + Cellular). I forgot to specify the exact model to my friend, was my mistake. Remembered that iOS 8.4.1 OTA was still signed for iPad 4 and there was an untethered jailbreak for (ETAson JB), so I decided to re-engineer my setup in order to have iOS 8.4.1 as main OS. Implemented this multi-boot during somewhat like four months, because I ran into many issues with secondary OS instances. Now, the setup is complete and I can enjoy my multi-boot iPad. Currently, it is pretty stable. All secondary OS instances use the no-effaceable-storage patch for the DeviceTree, means that I can change iOS passcode without having fear about bootloops. Concept is simple, only iOS 8.4.1 is jailbroken and both secondary OS instances almost have all stock security features turned to on.
Do not try iMultiBoot on A6 devices (iPhone 5 and iPad 4th) because it needs to restore your device in order to flash additional boot images in the firmware. Actually, the latest signed iOS version for A6 devices can't be jailbroken. So, iMultiBoot won't be able to continue the setup once the restore process is finished because it requires jailbreak to complete it. Jailbreak must also have tfp0 enabled to properly execute kloader.
The soundtrack of this video is a mix made by me with the following tracks :
A) DJ ASSASS1N - Frag Out [NCS Release],
youtube.com/watch?v=gWapX12pHPQ
B) DEAF KEV - Invincible [NCS Release],
youtube.com/watch?v=J2X5mJ3HDYE
C) Syn Cole - Feel Good [NCS Release],
youtube.com/watch?v=q1ULJ92aldE
D) Tobu & Itro - Sunburst [NCS Release],
youtube.com/watch?v=4lXBHD5C8do
E) Spektrem - Shine (Gabriel Drew & Bloom Remix) [NCS Release],
youtube.com/watch?v=rWVjht-MIto
F) Waysons - Daydream [NCS Release],
youtube.com/watch?v=ZynbJWCjJxg
G) Lensko - Cetus [NCS Release],
youtube.com/watch?v=i3vrV-WNmsc
H) Tobu - Candyland [NCS Release],
youtube.com/watch?v=IIrCDAV3EgI
I) Jim Yosef - Eclipse [NCS Release],
youtube.com/watch?v=1WP_YLn1D1c
Few weeks ago, @alitek123 told me that I could bypass the iCloud lock using an online service to get the device in an almost fully working condition. Like all iCloud bypass methods I've seen, functions which requires a valid activation ticket such as phone signal would not work. That iOS 7.x iCloud bypass method is provided here, http://mcxserver.com/icloudbp.php, by MinaCriss. It's a paid service, it costs $15 USD to register the locked device UDID on the bypass server. Once the payment is received, the device can be bypassed using MinaCriss' tool (which can be downloaded from the website above). I suggest to download the tool first to find the device's UDID. It's a tethered iCloud bypass, which means that the device needs to be bypassed again with the tool after each boot. However, an untether can be done by jailbreaking the device and removing /Applications/setup.app once the activation lock is bypassed. After that, MinaBypass tool won't be required at each boot. Jailbreak tool used is u3Tools, http://www.3u.com. Please note that activation lock is still activated on Apple's servers, the tool does not remove it. Device will still be iCloud locked if restored or erased.
I've been motivated to bypass and jailbreak that device since @axi0mX released an updated kloader which supports some 64-bit devices on iOS 7.x or 8.x, iPhone 5S included.
The soundtrack of this video is a mix made by me with the following tracks :
A) DJ ASSASS1N - Frag Out [NCS Release],
youtube.com/watch?v=gWapX12pHPQ
B) DEAF KEV - Invincible [NCS Release],
youtube.com/watch?v=J2X5mJ3HDYE
C) Syn Cole - Feel Good [NCS Release],
youtube.com/watch?v=q1ULJ92aldE
D) Tobu & Itro - Sunburst [NCS Release],
youtube.com/watch?v=4lXBHD5C8do
E) Spektrem - Shine (Gabriel Drew & Bloom Remix) [NCS Release],
youtube.com/watch?v=rWVjht-MIto
http://www.pmbonneau.com/apple/ios/multiboot.php.
Patches for iPod Touch 4 iOS 5.1 bootchain are available to download here, http://www.pmbonneau.com/apple/ios/multiboot_patches.php.
For this video, I implemented an untethered iOS 6.1.6 and iOS 5.1 dual boot on my iPod Touch 4 (N81AP). This is mostly an update of youtube.com/watch?v=JEyiftFmmX0, uploaded last summer. This was the first semi-tethered dual boot I made.
For an untethered dual boot, the whole bootchain of a subsequent operating system does chainload untethered when kloader successfully executed the first stage bootloader (LLB).
Kloader tends to crash around one time on two, depending on many factors. In this video, kloader worked four times and it crashed about three times.
When I launch the iOS 5 bootstrap application, the device (should) execute the LLB (Low-Level Bootloader) file set in the script which will execute iBoot (second stage bootloader), which will display the classic apple logo, load the devicetree and boot the kernel with the boot-args (verbose boot, root device and so) set in the appropriate string.
Please note that this video is a demonstration, not really a tutorial. Set up a dual-boot like this one can take few hours, depending on many technological factors.
Special thanks to @xerub, @iH8Sn0w and @JonathanSeals for many advices to help me solve some problems I encountered during the multi-boot implementation.
The soundtrack of this video is a mix made by me with the following tracks :
A) Jim Yosef - Eclipse [NCS Release]
youtube.com/watch?v=1WP_YLn1D1c
B) Different Heaven - Nekozilla [NCS Release], youtube.com/watch?v=6FNHe3kf8_s
C) Jim Yosef - Firefly [NCS Release],
youtube.com/watch?v=x_OwcYTNbHs
D) Unison - Aperture [NCS Release],
youtube.com/watch?v=8VDjPYcL-oU
E) Tobu - Candyland [NCS Release]
youtube.com/watch?v=IIrCDAV3EgI
F) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
G) Spektrem - Shine (Gabriel Drew & Bloom Remix) [NCS Release]
youtube.com/watch?v=rWVjht-MIto
H) Itro & Tobu - Cloud 9 [NCS Release]
youtube.com/watch?v=VtKbiyyVZks
I) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
J) Ahrix - Nova [NCS Release]
youtube.com/watch?v=FjNdYp2gXRY
I wrote a tutorial about how to implement an untethered iOS Multi-Boot here,
http://www.pmbonneau.com/apple/ios/multiboot.php.
It's a testing version, currently only supports iOS 7.1.2 and 6.1.6 on iPhone 4 (N90AP).
The iOS device normally do a signed boot to iOS 7.1.2 untethered jailbroken at userland level. I resized the data partition, then I created four new partitions (system, data for iOS 6 and system, data for iOS 5). I formatted new partitions in HFS+ volumes, then I mounted them. Into those new volumes, I copied the content from respective file system .dmg images. I did adjustements to the fstab and fixed that kb_load() fatal error (incompatible system keybag format between iOS 7.1.2 and older). The iOS 6 and iOS 5 bootstrap applications I made are only a script launcher. There is a system() call with the command line to execute as argument. Something like system("Bootstrap.sh"), where Bootstrap.sh is a script stored in /bin. The script only launches kloader with the unsigned bootloader image to bootstrap. When I launch a bootstrap application, the device (should) execute the LLB (Low-Level Bootloader) file set in the script which will execute the appropriate iOS specific iBoot (second stage bootloader), which will display the classic apple logo, load the devicetree and boot the kernel with the boot-args (verbose boot, root device and so) set in the appropriate string.
The whole bootchain of a subsequent operating system does chainload untethered when kloader successfully executed the first stage bootloader (LLB).
Kloader tends to crash around one time on two, depending on many factors.
Please note that this video is a demonstration, not really a tutorial. Set up a dual-boot like this one can take few hours, depending on many technological factors.
Special thanks to @xerub, @iH8Sn0w and @JonathanSeals for many advices to help me solve some problems I encountered during the multi-boot implementation.
The soundtrack of this video is a mix made by me with the following tracks :
A) Jim Yosef - Eclipse [NCS Release]
youtube.com/watch?v=1WP_YLn1D1c
B) Different Heaven - Nekozilla [NCS Release], youtube.com/watch?v=6FNHe3kf8_s
C) Jim Yosef - Firefly [NCS Release],
youtube.com/watch?v=x_OwcYTNbHs
D) Unison - Aperture [NCS Release],
youtube.com/watch?v=8VDjPYcL-oU
E) Tobu - Candyland [NCS Release]
youtube.com/watch?v=IIrCDAV3EgI
F) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
G) Spektrem - Shine (Gabriel Drew & Bloom Remix) [NCS Release]
youtube.com/watch?v=rWVjht-MIto
H) Itro & Tobu - Cloud 9 [NCS Release]
youtube.com/watch?v=VtKbiyyVZks
I) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
J) Jim Yosef - Lights [NCS Release]
youtube.com/watch?v=vb3ks4WllXA
K) Ahrix - Nova [NCS Release]
youtube.com/watch?v=FjNdYp2gXRY
http://www.pmbonneau.com/apple/ios/multiboot.php.
It's a testing version, currently only supports iOS 7.1.2 and 6.1.6 on iPhone 4 (N90AP).
For this video, I implemented an untethered iOS 7.1.2 and iOS 6.1.3 dual boot on my iPhone 4 (N90AP). In the video I uploaded last week about a semi-untethered iOS 7.1.2 and iOS 6.1.3 dual boot, an external SSH connection was required to bootstrap an image using kloader. In fact, only on-device Terminal applications causes issues with kloader (I actually don't know why). So, a dedicated application is required to do the untethered boot. I haven't tried, but maybe a dedicated daemon could also works. The iOS 6 bootstrap application I made is only a script launcher. There is a system() call with the command line to execute as argument. Something like system("iOS6Bootstrap.sh"), where iOS6Bootstrap.sh is a script stored in /bin. The script only launches kloader with the unsigned bootloader to bootstrap.
Same as the semi-untethered dual boot, the whole bootchain of a subsequent operating system does chainload untethered when kloader successfully executed the first stage bootloader (LLB).
Kloader tends to crash around one time on two, depending on many factors. In this video, kloader worked four times and it crashed about three times.
When I launch the iOS 6 bootstrap application, the device (should) execute the LLB (Low-Level Bootloader) file set in the script which will execute iBoot (second stage bootloader), which will display the classic apple logo, load the devicetree and boot the kernel with the boot-args (verbose boot, root device and so) set in the appropriate string.
Please note that this video is a demonstration, not really a tutorial. Set up a dual-boot like this one can take few hours, depending on many technological factors.
Special thanks to @xerub, @iH8Sn0w and @JonathanSeals for many advices to help me solve some problems I encountered during the multi-boot implementation.
The soundtrack of this video is a mix made by me with the following tracks :
A) Jim Yosef - Eclipse [NCS Release]
youtube.com/watch?v=1WP_YLn1D1c
B) Different Heaven - Nekozilla [NCS Release], youtube.com/watch?v=6FNHe3kf8_s
C) Jim Yosef - Firefly [NCS Release],
youtube.com/watch?v=x_OwcYTNbHs
D) Unison - Aperture [NCS Release],
youtube.com/watch?v=8VDjPYcL-oU
E) Tobu - Candyland [NCS Release]
youtube.com/watch?v=IIrCDAV3EgI
F) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
G) Spektrem - Shine (Gabriel Drew & Bloom Remix) [NCS Release]
youtube.com/watch?v=rWVjht-MIto
H) Itro & Tobu - Cloud 9 [NCS Release]
youtube.com/watch?v=VtKbiyyVZks
I) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
J) Ahrix - Nova [NCS Release]
youtube.com/watch?v=FjNdYp2gXRY
Please note that this video is a demonstration, not really a tutorial. Set up a dual-boot like this one can take few hours, depending on many technological factors.
I wrote a tutorial about how to implement an untethered iOS Multi-Boot here,
http://www.pmbonneau.com/apple/ios/multiboot.php.
It's a testing version, currently only supports iOS 7.1.2 and 6.1.6 on iPhone 4 (N90AP).
For this video, I implemented a semi-untethered iOS 7.1.2 and iOS 6.1.3 dual boot on my iPhone 4 (N90AP). This is semi-untethered because kloader actually needs to be executed from an external SSH connection. Otherwise, the first stage bootloader (LLB) of subsequent (unsigned) operating systems will not execute and the device will stay on a black screen. Using a computer or another iOS device with a SSH terminal application can be used to execute kloader on that device and bootstrap to others operating systems. With some further research, I may be able to figure out why this kloader bootstrap does not execute from the device itself. Also, kloader tends to fail sometimes, even if the bootstrap is initialized from an external SSH connection or the device itself.
However, the whole bootchain of a subsequent operating system does chainload untethered when kloader successfully executed the first stage bootloader (LLB).
When I send the command "kloader /LLB.n90ap.RELEASE.img3", the device (should) execute LLB (Low-Level Bootloader) which will execute iBoot (second stage bootloader), which will display the classic apple logo, load the devicetree and boot the kernel with the boot-args (verbose boot, root device and so) set in the appropriate string.
Special thanks to @xerub, @iH8Sn0w and @JonathanSeals for many advices to help me solve some problems I encountered during the multi-boot implementation.
The soundtrack of this video is a mix made by me with the following tracks :
A) Jim Yosef - Eclipse [NCS Release]
youtube.com/watch?v=1WP_YLn1D1c
B) Different Heaven - Nekozilla [NCS Release], youtube.com/watch?v=6FNHe3kf8_s
C) Jim Yosef - Firefly [NCS Release],
youtube.com/watch?v=x_OwcYTNbHs
D) Unison - Aperture [NCS Release],
youtube.com/watch?v=8VDjPYcL-oU
E) Tobu - Candyland [NCS Release]
youtube.com/watch?v=IIrCDAV3EgI
F) Spektrem - Shine [NCS Release]
youtube.com/watch?v=n4tK7LYFxI0
G) Spektrem - Shine (Gabriel Drew & Bloom Remix) [NCS Release]
youtube.com/watch?v=rWVjht-MIto
H) Itro & Tobu - Cloud 9 [NCS Release]
youtube.com/watch?v=VtKbiyyVZks
I've heard and seen some videos about a home screen glitch in iOS 9.2.1 setup application. Setup.app is the application used to configure the device at first boot. The glitch is trigerred when doing a hard reset by pressing both power and home button while the device is changing its display language. When the device's boot sequence is almost finished, it will be possible to see the home screen for around a second then it will go back to the setup application.
The soundtrack of this video is a mix made by me with the following tracks :
A) Different Heaven - Nekozilla [NCS Release], youtube.com/watch?v=6FNHe3kf8_s
B) Jim Yosef - Firefly [NCS Release],
youtube.com/watch?v=x_OwcYTNbHs
C) Unison - Aperture [NCS Release],
youtube.com/watch?v=8VDjPYcL-oU
Two weeks ago, I accidently bought an iCloud locked cellular iPad 4 (P102AP) on local classifieds. There is not much things to do with an iCloud locked device, except playing with iOS low-level components or with the first screens of the setup application (setup.app).
I've heard about an interesting method which tricks a captive portal from a DNS server redirection, as I understand it. So, I decided to try it on my iCloud locked iPad to see how it works and the results are interesting.
Of course, it's not a complete iCloud lock bypass because this method is like a web browser encapsulated in a captive portal. Apple will not send the activation ticket to the device unless the correct user and password combination is provided.
At least, this method provides some interesting functionalities to iCloud locked devices like web surfing, view maps, watching videos, play some web games and so.
Here is a list of DNS servers and their respective continent, as seen at 3:48 in the video :
104.154.51.7 (North America)
104.155.28.90 (Europe)
104.155.220.58 (Asia)
Donate here, iclouddnsbypass.com/donation to support the project.
Two months of intensive coding and endless long nights, ImgTool is made from scratch. I did not used code made by others, only mine.
I used C++ as programming language in Eclipse IDE. To make the Graphical User Interface, I used Qt Framework, integrated to Eclipse.
ImgTool will be publicly available when I will fix some bugs I found while making this video, especially in the ExportCert() and ExportImage() functions.
By watching this video, you agree that I'm not responsible of what might happen with the use of informations provided. Do it at your own risks.
Few months ago, I bought an iPad 2nd 64 GB with cellular (K94AP) on local classifieds. It was listed as broken and the seller told me that the device had a restore problem. It doesn't boot in normal mode, always in DFU mode. So, iTunes always ask to restore it. I tried to restore the device. It uploads iBSS, then iBEC and the device screen lights up. The restore ramdisk is uploaded, the device tree and the kernel cache too. The iPad boot the restore ramdisk, then the Apple logo with the progress bar appear on the screen. The progress bar doesn't fill and iTunes says "Waiting for iPad" indefinitely.
After many tests, it's about a logicboard hardware problem. After asking few people and reading a lot on Internet about similar issues, I concluded that the broken part could be the power supply IC chip.
I disassembled the iPad to remove the logicboard. Then, I put aluminium to protect other components and I used hot air gun to unsolder the chip.
WARNING : This video involves hacking on Low-Level parts of iOS. Unlike userland, those parts contains lot of critical informations about the device's hardware, which could be corrupted and lead to a hard brick if something goes wrong by following instructions provided in this video.
From a jailbroken iOS 7.1.2 kernel on which TaskforPid() is patched, Winocm's Kloader can be executed to bootstrap the beginning of another iOS bootchain instance (in this video, it's an iOS 6.1.3 one). The ARM image usually used with kloader is iBSS, from the DFU Bootchain. Most Kloader bootstraps use DFU Bootchain's images even if it is also possible to use Flashed Bootchain ones, which are usually more complete (like flashed iBoot can interact with File System, while iBEC can't). DFU one usually involve more loading in memory than Flashed Bootchain, which is more File System friendly. Once Kloader did it's magic and loaded iBSS, we have to send to it iBEC ARM image, the second stage of the DFU Bootchain. The LCD screen of the iOS device light up when iBEC is launched. Now the most interesting part begins. We have to send to iBEC each boot components in a specific order. First, send and execute the DeviceTree. Second, send and load a Ramdisk (seems to make no sense because we want to boot the File System, but there is something tricky here). Third, send the iOS Kernel and launch it using "bootx".
If you do those steps using original decrypted and patched files, without patching boot-args, this will load the restore Ramdisk. If you don't specify a Ramdisk in steps above, this will load the File System, but without taking in consideration boot-args (no verbose boot). If you open the decrypted iBEC file using a Hex editor, you will notice that boot-args are set like that : rd=md0 nand-enable-reformat=1 -progress. Those are boot-args used when booting a Ramdisk. If we change this boot-args string to : "-v", iBEC will load the File System by default, because we removed "rd=md0" which sets the RootDevice to "MemoryDevice0", which is the Ramdisk. It's also possible to change the default root device by adding "rd=[Root Device]" in iBEC's boot-args string.
Limera1n BootROM exploit is superior than Kloader. It acts directly from DFU mode, so an installed Operating System is not required. In the second part of this video, I simply use RedSn0w jailbreak utility to inject Limera1n over the DFU Mode. The root device is set to the iOS 5.1.1 filesystem in iBEC's boot-args. Then, RedSn0w will automatically send and execute each bootloaders in their respective order.
Also, please note that this video is a demonstration, not a tutorial. Set up a triple boot like this one can take few hours, depending on many technological factors. Maybe a day I will release a complete tutorial about how to do it.
In this video, I'm doing a triple boot between iOS 7.1.2 (signed), 6.1.3 and 5.1.1 on an iPhone 4 (N90AP). From the power button, the device boots on iOS 7.1.2, which is correctly signed. Then, I use RedSn0w's Tethered Boot function to inject Limera1n exploit over the DFU mode and allow an unsigned (patched) iOS 6.x bootchain to be executed. The root device has been set to the partition which contains iOS 6.1.3 file system in iBEC's boot-args string. The kernel will search for launchd on that partition. Then, iOS 6.1.3 starts up. The modem (baseband) works properly, it can receive calls. Over all, the firmware is really stable.
After, I use again RedSn0w's Tethered Boot function to inject Limera1n exploit over the DFU mode and allow an unsigned (patched) iOS 5.x bootchain to be executed. The root device has been set to the partition which contains iOS 5.1.1 file system in iBEC's boot-args string. The kernel will search for launchd on that partition. Then, iOS 5.1.1 starts up. The modem (baseband) works properly, it can receive calls. Over all, the firmware is really stable, but some old applications like YouTube, or old versions like the AppStore and iTunes Store are a bit broken.
Special thanks to @iH8Sn0w for advices about the kb_load(), this helped me with my research about.
iOS Multi-Booting status list :
A4 SecureROM and less, Multi-Booting 5.x and newer, with 4.x and lower using DFU Limera1n exploit [FAILED]
A4 SecureROM and less, Multi-Booting similar iOS versions (like 5.x and 6.x) using DFU Limera1n exploit [PASS]
iPhone 4 (N90AP), Multi-Booting iOS 7.x with lower using DFU Limera1n exploit [PASS]
A5 SecureROM and up (32-bits), Multi-Booting really similar iOS versions (6.1.3 and 6.0) using kloader bootstrap method [PASS]
A5 SecureROM and up (32-bits), Multi-Booting 6.1.3 with 5.x using kloader bootstrap method [CURRENTLY WORKING ON]
A5 SecureROM and up (32-bits), Multi-Booting 6.1.3 with 7.x and newer using kloader bootstrap method [FAILED]
A5 SecureROM and up (32-bits), Multi-Booting 9.x with 7.x using kloader bootstrap method [FAILED]
So, I tried to jailbreak my iPhone with what I have. I took an already jailbroken iOS 7.1.2 iPhone 4 (N90AP) then I used tar utility to pack Pangu iOS 7.x Untether files. Using an SSH Ramdisk, I extracted this tar archive inside the iOS 7.1.2 root file system, files at their right location. After, I extracted the tar archive which contains Cydia's files. I did a reboot, then this happened.
At least, unsigned code execution seems to works well! ;)
Please note that this video is a demonstration, not really a tutorial. Set up a dual-boot like this one can take few hours, depending on many technological factors. Maybe a day I will release a complete tutorial about how to do it.
Also, because of the way about how Apple implements security on iOS devices, this kind of multi-booting is really not the same thing than on any other desktop computers, laptops, even not like ones we can do on some Android devices. Main issues of iOS multi-booting are the Secure Bootchains on regular (flashed) boot, DFU boot and even the Baseband. Using kloader, we can "simulate" a new regular or DFU bootchain. This partially solve that part of the problem, but kloader stills need a jailbroken main filesystem to host itself and be able to run. Because we usually work with DFU bootchain when doing kloader bootstraps, this means tethered. DFU bootloaders usually wait for executable ARM images on USB connection. That's a good thing, this is like booting a computer from an USB stick when hard drive OS can't boot. It could be possible to untether those kloader bootstraps, but it requires years of high ARM assembly and Reverse Engineering knowledge. The other part of issues is the Baseband, found on iPhones and cellular iPads. The Baseband has its own bootchain, with its own bootloaders. Kloader can't, unfortunately, do Baseband bootstraps. This means that the Baseband won't work on other iOS versions than the main one. So, phone calls, cellular internet and everything related to the Baseband won't work.
In this video, I'm doing a kloader bootstrap from a signed iOS 6.1.3 file system to an unsigned iOS 6.0 one. The method used to chainload iOS 6.0 is almost the same than the one used in this video youtube.com/watch?v=hyDGOfM0Aqk but I added rd=disk0s1s3 in iBEC's boot-args string. This tells the kernel to search for launchd in that root device.
iOS Multi-Booting status list :
A4 SecureROM and less, Multi-Booting 5.x and newer, with 4.x and lower using DFU Limera1n exploit [FAILED]
A4 SecureROM and less, Multi-Booting similar iOS versions (like 5.x and 6.x) using DFU Limera1n exploit [PASS]
iPhone 4 (N90AP), Multi-Booting iOS 7.x with lower using DFU Limera1n exploit [FAILED]
A5 SecureROM and up (32-bits), Multi-Booting really similar iOS versions (6.1.3 and 6.0) using kloader bootstrap method [PASS]
A5 SecureROM and up (32-bits), Multi-Booting 6.1.3 with 5.x using kloader bootstrap method [CURRENTLY WORKING ON]
A5 SecureROM and up (32-bits), Multi-Booting 6.1.3 with 7.x and newer using kloader bootstrap method [FAILED]
A5 SecureROM and up (32-bits), Multi-Booting 9.x with 7.x using kloader bootstrap method [FAILED]
As you can see, iOS 6.0 is really stable except the baseband which isn't even loaded, because of the reason I tell above. Switching from 6.1.3 to 6.0 is relatively fast when bootchain files are ready. Switching from 6.0 to 6.1.3 is fully untethered.
One thing I can say, Swing Copters as well as many other AppStore apps works perfectly! Also, this kind of dual boot can be do to have a jailbroken, full of tweaks iOS 6.1.3 and a clean iOS 6.0 set up.
Special thanks to @blackgeektuto for Beehind downgrade and @xerub for the Odysseus Method, used in Beehind. This saved me lot of time, because I had to restore my N94AP to 9.0.2 and downgrade it back to 6.1.3 multiple times. Also, a special thanks to @dayt0n and @iH8Sn0w for many advices about boot-args and verbose booting.
Probably the most important thing to do before anything, backup your device before begin the jailbreak process. An iOS device isn't like a PC in terms of data security. If the jailbreak fails and your device isn't able to boot and "auto-boot = true" magic doesn't work, you will have to restore your device and this will erase all keybags which hold important data encryption keys. Without those keys, a data recovery is almost impossible to do.
I'm using PanGu7 1.2.1 on Windows 7 Home Premium x64.
Probably the most important thing to do before anything, backup your device before begin the jailbreak process. An iOS device isn't like a PC in terms of data security. If the jailbreak fails and your device isn't able to boot and "auto-boot = true" magic doesn't work, you will have to restore your device and this will erase all keybags which hold important data encryption keys. Without those keys, a data recovery is almost impossible to do.
Also, I heard today [October 29th 2015] that Apple stopped to sign iOS 9.0.2 for all compatible devices as I know. This means that if the jailbreak fails and the device isn't able to boot, you will have to upgrade to iOS 9.1 which can't be jailbroken actually.
I'm using PanGu9 1.2.1 on Windows 7 Home Premium x64.
WARNING : This video involves hacking on Low-Level parts of iOS. Unlike userland, those parts contains lot of critical informations about the device's hardware, which could be corrupted and lead to a hard brick if something goes wrong by following instructions provided in this video.
First, I downgraded my N94AP from iOS 9.0.2 back to 6.1.3 especially because Low-Level Bootloaders and Kernel patches are already made for that still signed version, so it makes things easier. From a jailbroken iOS 6.1.3 kernel on which TaskforPid() is patched, Winocm's Kloader can be executed to bootstrap the beginning of another iOS bootchain instance. The ARM image usually used with kloader is iBSS, from the DFU Bootchain. Most Kloader bootstraps use DFU Bootchain's images even if it is also possible to use Flashed Bootchain ones, which are usually more complete (like flashed iBoot can interact with File System, while iBEC can't). DFU one usually involve more loading in memory than Flashed Bootchain, which is more File System friendly. Once Kloader did it's magic and loaded iBSS, we have to send to it iBEC ARM image, the second stage of the DFU Bootchain. The LCD screen of the iOS device light up when iBEC is launched. Now the most interesting part begins. We have to send to iBEC each boot components in a specific order. First, send and execute the DeviceTree. Second, send and load a Ramdisk (seems to make no sense because we want to boot the File System, but there is something tricky here). Third, send the iOS Kernel and launch it using "bootx".
If you do those steps using original decrypted and patched files, without patching boot-args, this will load the restore Ramdisk. If you don't specify a Ramdisk in steps above, this will load the File System, but without taking in consideration boot-args (no verbose boot). If you open the decrypted iBEC file using a Hex editor, you will notice that boot-args are set like that : rd=md0 nand-enable-reformat=1 -progress. Those are boot-args used when booting a Ramdisk. If we change this boot-args string to : "-v", iBEC will load the File System by default, because we removed "rd=md0" which sets the RootDevice to "MemoryDevice0", which is the Ramdisk.
Special thanks to @blackgeektuto for Beehind downgrade and @xerub for the Odysseus Method, used in Beehind. This saved me lot of time, because I had to restore my N94AP to 9.0.2 and downgrade it back to 6.1.3 multiple times. Also, a special thanks to @dayt0n and @iH8Sn0w for many advices about boot-args and verbose booting.
In technical details, Application Stashing is the process where Cydia moves "/Applications" folder from the first partition (/dev/disk0s1s1) to "/var/stash/[random string]/Applications", which is on the second partition (/dev/disk0s1s2). After moving applications, a Unix symlink refeering "/Applications" folder to "/var/stash/[random string]/Applications" is made to trick the iOS system. The goal of Application Stashing is to free up disk space on the system partition (/dev/disk0s1s1) for Cydia packages, some iOS system tweaking and so.
I now have to restore (again) that N90AP.
PurpleSNIFF is a tool used by Apple to read indentification and diagnostic information from an iOS device, especially for engineering tests.
When executing PurpleSNIFF, it will wait for an iOS device to be connected to the computer. Once the device connected, the main screen of the software will turn green if it has successfully identified the device or will turn red if an error has occured.
PurpleSNIFF is divided in three main sections: Device, Console and IORegistry.
"Device" shows all information about the device and its iOS version like baseband version, carrier info, activation, NAND total size, partitions size and free space, audio and video codecs, security fusing (production or development) and lot more.
" Console" runs live diagnostic on an iOS device. Actions made on the device are reported to PurpleSNIFF, may be used to detect software and hardware errors.
"IORegistry" seems to show information about iOS drivers.
PurpleFAT is a tool used in Apple's factories for Units Under Test (UUT's) activation.
Outside of Apple's factories, this tool does not work. It will un-activate iDevices instead of activate them, as you can see in this video.
More info about PurpleFAT:
theiphonewiki.com/wiki/PurpleFAT
In this video, I'm downgrading my iPhone 3GS (MC Model, new bootrom) 6.1.3 firmware back to 4.1 without using SHSH blobs. Apple still sign iOS 4.1 for some old iDevices (iPod Touch 2nd, iPhone 3G and iPhone 3GS as I know) thats why this downgrade does not needs SHSHs. Apple use another downgrade restriction, which is the Baseband version. When you do an iDevice restore, in most case, the baseband can not be rolled back and the restore will fail if your current baseband version is higher than the one of the iOS version you want to downgarde to. Thats why we have to trick the iPhone by upgrading the baseband to iPad 6.15.00 and then, downgrade it back to 5.13.04, so iOS 4.1 firmware will install 5.14.02 baseband without problem.
Videos to see before doing anything, if your iPhone baseband is higher than 5.14.02:
First, upgrade your iPhone to iPad 6.15.00
youtube.com/watch?v=7ZczdJoBCCo
After, downgarde it back to 5.13.04
youtube.com/watch?v=DMrz-NdOfSI
Finally, do the downgrade like in this video.
I AM NOT RESPONSIBLE OF WHAT MIGHT HAPPEN TO YOUR IPHONE BY FOLLOWING THIS TUTORIAL.
The first part of this video is an analysis of .AFS file structure. You will see how these (not-so) mysterious files are working and also understand the inner working of my .AFS File Extractor.
The second part will show to you the extraction process of some .AFS files, including the biggest one (STAGE.AFS) which store all stages data.
Here is the download link for this utility:
http://www.pmbonneau.com/vgames/smbdx/afs.php
By using this utility, I'm not responsible of any damages that could happen to your hardware or operating system. Use it at your own risks.
WARNING: BOOTLOADER MODIFICATIONS & KERNEL FLASHING
Before doing anything: First, I recommand to use an old iPhone that you don't use, like mine which has some dead pixels at the bottom of the LCD screen. If its the phone you use everyday, backup your iPhone with iTunes because if iOS becomes unstable after iDroid installation (it might happen), you still have a copy of your precious data.
I AM NOT RESPONSIBLE OF WHAT MIGHT HAPPEN TO YOUR IPHONE BY FOLLOWING THIS TUTORIAL.
OpeniBoot is an iBoot alternative for Bootrom level hacked or exploited iDevices. With that, it is possible to dualboot a linux kernel with iOS. Compatibles iPhones and iPods Touchs are mostly models which it is possible to change boot and recovery logos with jailbreaking tools, such as iPhone 2G, 3G and iPod Touch 1st generation. OpeniBoot is made to run very low-level code on iDevices, thats why it needs a bootrom exploit.
IMPORTANT:
If your iDevice is jailbroken with any userland jailbreaks such as JailbreakMe or Spirit, bootlace (OpeniBoot install tool) will not work or OpeniBoot install will fail and you will have to restore your iDevice.
iDroid is a project which is an Android port for OpeniBoot compatible iDevices.
Before doing anything, you need to understand that if something goes wrong by modifying something at baseband level of an iPhone, some functions related to phone, mobile network, Wi-Fi, Bluetooth, every things that require an antenna could be bricked definitively. There is sometimes no way to restore.
I AM NOT RESPONSIBLE OF WHAT MIGHT HAPPEN TO YOUR IPHONE BY FOLLOWING THIS TUTORIAL.
In this video, I'm downgrading my iPhone 3GS (MC Model, new bootrom) iPad 6.15.00 baseband back to 5.13.04 naturally flashed by an iTunes iDevice update/restore from iOS 3.x.x to iOS 4.0, 4.0.1, 4.0.2. Downgrade an iPhone 3G or 3GS iPad 6.15.00 baseband to an older one like 5.13.04 has a lot of advantages. First, it removes all issues or bugs of 6.15.00 installation. So, iPhone restore from iTunes don't need a custom firmware and GPS and mobile network are working as they should. Secondly, 5.13.04 baseband is unlockable with UltraSn0w.
If your iPhone 3G or 3GS is unlocked with iPad 6.15.00 baseband, you should downgrade back to 5.13.04 and unlock it again with UltraSn0w. Your iPhone will be more stable and also more reliable.
Please read carefully instructions provided by RedSn0w, your iPhone may not be elligible to 06.15.00 update or 5.13.04 downgrade. See the most important at 02:34 .
Before doing anything, you need to understand that if something goes wrong by modifying something at baseband level of an iPhone, some functions related to phone, mobile network, Wi-Fi, Bluetooth, every things that require an antenna could be bricked definitively. There is sometimes no way to restore.
I AM NOT RESPONSIBLE OF WHAT MIGHT HAPPEN TO YOUR IPHONE BY FOLLOWING THIS TUTORIAL.
In this video, I'm updating my iPhone 3GS (MC Model, new bootrom) baseband to iPad's 06.15.00 to downgrade it back to 05.13.04 ( http://www.youtube.com/watch?v=7ZczdJoBCCo ) for unlock & iOS downgrades. The iPad 06.15.00 baseband was used to unlock with UltraSn0w iPhones 3G & 3GS which had an unsupported baseband version. Installing it bring some issues to the iPhone, like buggy GPS & phone network, phone can only be restored with a baseband preserving custom iOS firmware because baseband can't be rolled back (06.15.00 is higher than the lastest iPhone 3GS official baseband). A 06.15.00 baseband downgrade function has been added to RedSn0w jailbreaking utility to downgrade it back to 05.13.04 which is official, stable and unlockable with UltraSn0w.
Please read carrefuly instructions provided by RedSn0w, your iPhone may not be elligible to 06.15.00 update. See the most important at 03:14 .
PurpleRestore is a tool used by Apple to restore iOS devices, especially for engineering tests.
It is made to do almost everything related to iOS restoring, including restore to every hardware-compatible iOS version, make root filesystem writable, system partition size, adding/removing boot & restore args, activation bypass, break between restore stages and more. Instead of regular .IPSW files to restore iOS devices, PurpleRestore uses "restore bundles". They can be made by unzipping a regular .IPSW file.
Using this tool at home will do nothing more than iTunes already does. Release type firmwares will be restored without considering additional options (boot-args, activation bypass, etc.). It is also not possible to restore to a firmware unsigned by Apple (no downgrades). The only différences with iTunes' iOS restore process are the Apple's logo in purple background and the possibility to see restore steps, in PurpleRestore.
.WAD files in Insomniac's Spyro the Dragon series mostly contains RAW data, thats why extracted files have no meaning names (I used files' number and address in the .WAD file as name) and no file extension (I marked them as .bin for "binary").
Le Retour de Mario - Green Mountains (Area 1 - Level 105):
dl.dropboxusercontent.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20-%20Green%20Mountains%20(Area%201%20-%20Level%20105).mwl
Le Retour de Mario - Green Mountains (Area 2 - Level 137):
dl.dropboxusercontent.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20-%20Green%20Mountains%20(Area%202%20-%20Level%20137).mwl
Be sure to backup your precious game saves on your Memory Card before doing anything in this tutorial. A simple little mistake can corrupt your(s) Memory Card(s). Thats why I'm using an emulator... I am not responsible for what might happen to your hardware by following this tutorial.
What is a Memory Dump ?
First, the Sony Playstation 2 has 32 Megabyte of RAM.
A Memory Dump allow you to "save" the RAM of your console on a storage device to be able to disassemble and analyse it. In this video, I dump the RAM on a Memory Card by tweaking Crash Bandicoot The Wrath Of Cortex game saving function. Instead of saving the game normally, two MIPS assembly instructions will tell the game to dump a range (or all) of Ps2's Memory. As you can see in the video at (25:08), the number of files in a regular save will determine the number of dump copies that the game will do. So, if you want to dump entierely the RAM of your Ps2 (32 Mb), you need a (32 x n)Mb Memory Card, which "n" represent the number of files in the regular save game. Crash Bandicoot The Wrath of Cortex save contains 3 files. To make a complete dump of this game, you need approximately a (32*3 = 96)Mb Memory Card.
Note: This tutorial does not apply only to Crash Bandicoot The Wrath of Cortex, but to a lot of Playstation 2 games.
Feel free to share your Memory Dumps!
For more informations about Save Game Dumping,
http://www.codemasters-project.net/guides/showentry.php?e=34&epage=2
Please lower the volume of your speakers or headphones, because with this editor, some sounds of the game become garbage, and can damage your sound device, or your sens of hearing.
Veuillez baisser le son de vos hauts-parleurs ou de votre casque d'écoute, car avec cet éditeur, certains sons du jeu deviennes du «garbage» et peuvent endommager votre matériel sonore ou encore, votre ouïe.
A special thanks to LXShadow, who worked very hard to hack level editor's code in the game. Also, another special thanks to him for the editor guide (explanations you see at the beginning of each tutorial videos about the editor). It helped me a lot to understand how the editor works.
Français:
-Contenu de la vidéo en Anglais seulement-
La huitième et dernière partie du guide de l'éditeur de niveau caché du jeu Crash Bandicoot 4: The Wrath Of Cortex (Ps2). Cette partie présente le positionneur de particules (Particle Positioner) qui est beaucoup lié à l'éditeur d'animations (Anim Editor), mais en beaucoup plus complet, bien qu'il soit beaucoup plus difficile à maîtriser. Les particules sont en quelque sorte des animations que l'on peut attacher sur presque tout autre éléments du jeu (AIs, objets, animations, etc.) et on peut aussi leur ajouter des sons en choisissant parmi plusieurs que l'on entend dans le jeu.
English:
The last part of Crash Bandicoot 4: The Wrath Of Cortex (Ps2) hidden level editor guide. This section presents the Particle Positioner which is similar to Anim Editor, but much more complete and much more difficult to master. Particles are like animations that can be attached to almost any other game elements (AIs, objects, animations, etc.). Its also possible to add sounds by choosing among all that we hear in this Crash Bandicoot game.
- Voici les projets que nous avons réalisé -
1. Le Dragster ( 0:10 )
2. Le «Mini-Sumo Bot» ( 1:03 )
3. Le Stationnement ( 2:29 )
4. La Communication ( 3:43 )
5. L'Insecte ( 4:54 )
6. Le Trieur de Briques ( 6:04 )
7. Le «Peg Sorter» ( 6:34 )
8. La Bipédie ( 6:45 )
9. Diverses Photos ( 7:49 )
Some debug menus used by developers, buried in Crash Bandicoot : The Wrath Of Cortex game's code. Developers of this mysterious Crash game probably used these menus to test levels and have a fast access to each elements.
List of debug menus :
1 - The Cutscene Menu : Watch all "movies" of the game.
2 - Draw Settings Menu : Used to control levels draw settings. I dont really know how to use it.
3 - Memory Information : See information about SuperBuffer and High Allocation Address used memory, probably about graphics.
4 - The Cheat Menu : The most interesting debug menu. This one is used to reach rapidely some parts of the game.
- Restart Level : The level is reset and the player restart from the beginning.
- Reset Level : The level is reset.
- GoTo Level : Fast access to each level of the game, including the well known "Game Over" (When I did the game for the first time, I saw it a lot of time! Its really a level ?)
- Invincibility : Crash or Coco can't die.
- GoTo Next CheckPoint : Fast forward in a level, the player go to the next checkpoint.
- GoTo Last CheckPoint : The player go to the last checkpoint.
- Open Game : 106% in few microseconds, its like the "Wombat" code in the XBOX and GameCube Version of the game.
- Lift Player : Crash or Coco can "fly" through the entire level.
- Player Coordinate : Show X, Y and Z coordinates of the player's position.
- Extra Moves : I dont know, perhaps its special moves earned after each boss.
- Reset Game : Back to 0% in few seconds.
Who is MIDGET ( 12:00 ) ?
The hidden and unused flight level of Crash Bandicoot: The Wrath of Cortex accessible (I believe) by two ways or methods, Data-Swapping Method and Code Hacking Method.
Using Data-Swapping Method : http://www.youtube.com/watch?v=vS-Ky4_RRW4
Using Code-Hacking Method : This Video, using LXShadow's Codes.
As you can see in this video, Crash does not have to walk on a Warp Pad to go into this level. By holding X, Square, Triangle and Circle (Joker Command of the code) on the controller, Crash is automatically warped to this level.
With Code Hacking Method, this hidden level is almost complete, the Airship (the only thing in this level) interact with Crash by shooting fire bullets on his airplane. The goal of this level was to destroy all twelve machine guns of the Airship to disarm it. Some missing elements on the AirShip prevent it to be done and get the crystal. Actually, I can't get further than eight on twelve, probably because this level is unfinished.
More informations about this level on Crash Mania : http://www.crashmania.net/?menu=woc&page=mysteries-4-3
"An extra hub can be found in the disc. It's the E3 Hub, used to showcase the game when it was presented at E3 2001" ( www.crashmania.net ). The most interesting thing in this E3 Hub are warp pads. As you can see in this video, each pad has a preview picture of its associated level and theses pictures doesn't represent levels of the actual game.
This Hub was probably the one in the Late Beta version of the game.
More Informations : http://www.crashmania.net/?menu=woc&page=mysteries-2
Warp Pad 1 - It seems to be a picture of an old prototype version of Crash and Burn level
More informations : http://www.crashmania.net/?menu=woc&page=mysteries-4-2
Warp Pad 2 - Tornado Alley with a nice weather.
More Informations : http://www.crashmania.net/?menu=woc&page=mysteries-2
Warp Pad 3 - Looks like the original Wizards and Lizards Level.
Warp Pad 4 - Cortex statue, in an unseen place ?
See it there : http://www.crashmania.net/?menu=woc&page=mysteries-5
Warp Pad 5 - It seems to be an early beta version of Ice Station Bandicoot, which was like a normal (on-foot) Crash Bandicoot level.
Read more on Crash Mania : http://www.crashmania.net/?menu=woc&page=mysteries-1
In this Hub, warp pads are not linked to levels, they are transparent and Crash fall when he walk on them. You have now only one thing to do, push the reset button of your Ps2.
Note : It is supposed to have a Red Buzzy Beetle, walking on black plants at 3:58 and Mario was supposed to do spin jumps on it. For some sprite memory reasons, it was not there.
http://dl.dropbox.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20-%20Ice%20Cavern%20(Area%201%20-%20Level%2010B).mwl
I uploaded on my Dropbox the first area (Yoshi's House) in .mwl format that you can import in Lunar Magic Editor if you want to play or modify this level.
http://dl.dropbox.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20-%20Yoshi's%20House%20(Area%201%20-%20Level%20104).mwl
I also uploaded the second part in an image file .bmp format because .mwl does not save External Graphics. So, you can't import it in Lunar Magic. Its only if you want to have some ideas for your levels.
http://dl.dropbox.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20-%20Yoshi's%20House%20(Area%202%20-%20Level%20106).bmp
I uploaded on my DropBox account this custom title screen level in .mwl format with Lunar Magic level export function and Mario's moves inserted in a Zsnes Savestate (.zst) with the Export Title Moves Playback function of the overworld editor.
Title Screen Level (.mwl) : http://dl.dropbox.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20Title%20Screen%20-%20Custom%20Level%20C7.mwl
Mario's Moves (.zst) : http://dl.dropbox.com/u/26893289/uploads/Le%20Retour%20de%20Mario%20Title%20Screen%20-%20Mario's%20Moves.zst
Feel free to import theses files in your hacks if you want!
I recorded this gameplay video with the excellent recording option of Desmume Nintendo DS Emulator.
If you like this level and want to play it, you can download the .nml of each area and put them back in a New Super Mario Bros. DS.nds ROM with the level editor.
Area 1 (Grassland) : http://dl.dropbox.com/u/26893289/uploads/New%20Super%20Mario%20Bros.%20DS%20-%20Custom%20Level%20Area%201%20(Grassland).nml
Area 2 (Volcano) : http://dl.dropbox.com/u/26893289/uploads/New%20Super%20Mario%20Bros.%20DS%20-%20Custom%20Level%20Area%202%20(Volcano).nml
Area 3 (Castle) : http://dl.dropbox.com/u/26893289/uploads/New%20Super%20Mario%20Bros.%20DS%20-%20Custom%20Level%20Area%203%20(Castle).nml
Feel free to bring some modifications in this custom level if you want, to make it better! Post the result as a video comment!


