How to Jailbreak iPhone 3GS New Bootrom on iOS 4 Using Sn0wbreeze 1.7
The latest version of sn0wbreeze, version 1.7(for windows) is now out to jailbreak iOS 4.0. Although this release supports all versions of iPhones and iPod touch, you will need the iPhone 3GS(new bootrom), iPod touch 2G(MC model) and iPod Touch 3G will have to be on firmware 3.1.2, or will need to have their SHSH blobs saved for iOS 3.1.2 in order to successfully jailbreak these devices on iOS4. The jailbreaks on the above devices will also be tethered jailbreaks, meaning that you will have to connect it to the computer to turn it back on every time you turn it off.

sn0wbreze 1.7
The steps you should follow to jailbreak your device are almost exactly the same as the previous version we posted a few days ago, version 1.6. All you have to do is restore using iTunes 9.2.
Once you have jailbroken your phone, you can unlock it using ultrasn0w 0.93 (on any baseband), guide for which is posted here.
All of those amongst you who don’t have your 3.1.2 SHSH blobs files saved, you will have to wait for the next version of spirit jailbreak tool, which rumors suggest will be released as soon as Apple releases the next firmware update for iOS 4, i.e. iOS 4.0.1/4.1, and it will support all iOS devices including the iPhone 4.
Download Sn0wbreeze 1.7 for Windows
UPDATE 1: ok guys, you will need to follow the following instructions to jailbreak iPhone 3GS (new bootrom) on 3.1.2, or with 3.1.2 SHSH blobs saved.
Warning Note: All the standard warnings apply. This is for advanced users only. Only proceed if you think you know your iPhone inside out.
I figured making a tool would take a bit too long. So, i’m going to write up this tutorial. It isn’t recommended for regular users.
**BEFORE PROCEEDING, ENSURE THAT YOU HAVE YOUR PHONE BACKED UP!**
THIS TUTORIAL ASSUMES YOU ARE ALREADY ON 3.1.2!
——-
WHAT YOU WILL NEED:
* An iPhone 3G[S] — new bootrom
* 3.1.2 already installed or 3.1.2 installed via SHSH blobs. <– Broken blackra1n’d devices will work. (Especially if Spirit messed you up!).
* Payload Pwner-r3 for the 3GS. (http://www.mediafire.com/?fyozyytzze1)
* sn0wbreeze V1.7
* iBooty V1.3 (http://www.mediafire.com/?g1nynqrnz03)
* LibUSB (64-Bit users read carefully!!!)
* 3.1.2/4.0 3GS firmware downloaded.
——-
*NOTE : IF YOU HAVE THE SLEEP ISSUE, YOU WILL NEED TO RESTORE BACK TO 3.1.2 FIRST.*
STEP A : Installing LibUSB for iRecovery
Run this mini tool to detect your O/S + Arch. — Windows + Arch. Detector (http://www.mediafire.com/?imyzm2t3zam)
*********
WARNING : IF LIBUSB IS NOT INSTALLED PROPERLY, YOUR USB MIGHT NO LONGER WORK!
*********
Windows XP Users download this installer — LibUSB Installer (http://www.mediafire.com/?zyy0mjthhij)
*********
Windows Vista/7 users RUNNING 32-Bit:
* Download the installer and run it in compatibility mode for Windows XP. (http://www.mediafire.com/?zyy0mjthhij)
*********
If you are a 64-Bit user, follow this tutorial — LibUSB 64-Bit Tut (http://www.ipodtouchfans.com/forums/showthread.php?t=148985)
*********
Once LibUSB is installed iRecovery should be able to function now.
——-
STEP B : Pwning iBEC + iBoot
I : Download this easy tool here — Payload Pwner-r3 for 3GS (http://www.mediafire.com/?fyozyytzze1) // It will help you create the payload + iBEC.
**SAVE THE PAYLOAD + iBEC WHERE iBooty is.**
——-
STEP C : Making a Custom IPSW
I : Download sn0wbreeze V1.7 from here — sn0wbreeze V1.7
II : USE EXPERT MODE!
III : In General, Checkmark “Disable NOR Flash” <– THIS IS ESSENTIAL!!!!
IV : Build it. It will be on your Desktop.
**CUSTOM BOOT LOGOS THAT ARE MADE IN sn0wbreeze WILL NOT WORK ON NEW BOOTROMS!**
*Mac Users : PwnageTool does not have this option. I don’t think it will ever be in there. Use a Windows Virtual Machine or friends PC to create your firmware.*
——-
STEP D: iBooty Prep.
Most of you know of the utility “iBooty” that I made for Aki_nG.
It will work as long as you place all of the correct files there.
I : Download iBooty GUI here — iBooty for 3GS (http://www.mediafire.com/?g1nynqrnz03) and Extract it.
II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.
III : Grab the kernelcache and bring it into the same folder as ibooty.
Also grab the iBEC from the folder “Firmware\dfu\iBEC.n88ap.RELEASE.dfu”
Aswell as DeviceTree from the folder “Firmware\all_flash\all_flash.n88ap.production\DeviceTree.n88ap”
IV :
* Rename your Kernel 4.0-Custom to “kernel.40″
* Rename your iBEC 4.0-Custom to “ibec.40″
* Rename your DeviceTree 4.0-Custom to “devtree.40″
======
Your folder should look like this :
- iboot.payload <– Created with Payload Pwner.
- devtree.40 <– Grabbed from Custom IPSW made by sn0wbreeze.
- ibec.40 <– Grabbed from Custom IPSW made by sn0wbreeze.
- irecovery.exe <– Comes with iBooty.
- readline5.dll <– Comes with iBooty.
- iBooty.exe <– Comes with iBooty.
- kernel.40 <– Grab from Custom IPSW made by sn0wbreeze.
- sn0w.img3 <– Comes with iBooty.
- wait.img3 <– Comes with iBooty.
======
——-
STEP E: Restoring to 4.0 + Booting
——-
*MAKE SURE YOU ARE ON 3.1.2 WHEN DOING THIS*
I : Run iBooty and Select “Prepare Device for Custom Firmware”. Run the Process and if you see the image, you can proceed!
II : Now open iTunes and restore to the custom ipsw.
***WHEN DONE, YOUR DEVICE WILL GO INTO RECOVERY MODE. IT WONT BOOT.***
——-
STEP F : Booting
I : Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!

















Pingback: Jailbreak iPhone 4, 3GS, 3G on iOS 4 / 4.0.1 and iPad on iOS 3.2.1 with JailbreakMe 2.0 | The Geek Engineer | Covering iPhone, iPad, Android, Windows and More