Jailbreak iPod Touch 3G iOS 4 with Sn0wBreeze 1.7 - iPhoneHeat

Jailbreak iPod Touch 3G iOS 4 with Sn0wBreeze 1.7

iH8Sn0w has release Sn0wBreeze v1.7 to jailbreak iPod Touch 3G iOS 4 a few days ago. Today he releases iBooty + Payload Pwner for the iPod Touch 3G, 2G (MC). Which means if your iPod Touch 3G or iPod Touch 2G (MC) are running OS 3.1.2 or you have saved SHSH blobs of OS 3.1.2 for your iPod Touch 3G, you can create a custom iOS 4 to jailbreak iPod Touch 3G, 2G (MC).

UPDATE: *** Comex has released the All iDevices jailbreak. Check the Update at the bottom. ***

Sn0wBreeze v1.7 with iBooty + Payloader Supports:

  • iPod Touch 3G only if running firmware 3.1.2 or you’ve SHSH blobs for 3.1.2 (needed for downgrade)
  • iPod Touch 2G (MC)
  • iPhone 3GS only if running firmware 3.1.2 or you’ve SHSH blobs for 3.1.2 (needed for downgrade)


  • iPhone 3GS with New BootRom, iPod Touch 3G, 2G (MC) users MUST be on firmware 3.1.2 or have SHSH blobs saved for it (needed for downgrade). Otherwise you’re still out of Luck. The exploit used in this hack has been patched in OS 3.1.3 so firmware 3.1.2 is a MUST. [How to Check iPhone 3GS BootRom]
  • If you’re not on 3.1.2 firmware or don’t have saved SHSH blobs for it, you’ll have to wait for the Spirit jailbreak update which is almost ready. I think they are waiting for the next firmware update (iOS 4.1 or iOS 4.01).
  • For iPhone 3GS (New BootRom), iPod Touch 3G, 2G (MC) users it’s a Tethered jailbreak. For those who don’t know, a tethered jailbreak device once turned off/Reboot/run out of battery, you need to connect it to computer and execute a tool to boot up the device.
  • Once jailbroken then you can unlock iPhone iOS 4 with UltraSn0w.

This guide is NOT for regular Windows users. So, proceed with precaution and follow the guide at your own risk. Let’s jailbreak iPod Touch 3G iOS 4 and iPod Touch 2G-MC iOS with Sn0wBreeze 1.7 and iBooty + Payload Pwner. Below are the step-by-step instructions from the official source:


Jailbreak iPod Touch 3G iOS 4

This tutorial assumes that you are already on 3.1.2! (Video also posted below)

What You Will Need

STEP A : Pwning iBoot

  1. Download this easy tool here — Payload Pwner-r6 // It will help you create the payload.
  2. Extract it to a directory and run Pwner.exe

**Save the Payload where iBooty is.**

STEP B : Making a Custom IPSW

  1. Download sn0wbreeze V1.7 from here — sn0wbreeze V1.7
  3. In General, Checkmark “Disable NOR Flash” <– THIS IS ESSENTIAL!!!!
  4. Build it. It will be on your Desktop.


*Mac Users : PwnageTool does not have this option. I don’t think it will ever be in there. Use a Windows Virtual Machine or friends PC to create your firmware.*

STEP C: iBooty Prep.

Most of you know of the utility “iBooty” that I made for Aki_nG. It will work as long as you place all of the correct files there.

  1. Download iBooty GUI here — iBooty V1.6 and Extract it.
  2. Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.
  3. Grab the kernelcache and bring it into the same folder as ibooty.
  4. Also grab iBEC from the folder “Firmware\dfu”.
  5. Aswell as DeviceTree from the folder “Firmware\all_flash\all_flash.n88ap.production\DeviceTree.n88ap”
  6. Rename your Kernel 4.0-Custom to “kernel.40”
  7. Rename your iBEC 4.0-Custom to “ibec.40”
  8. Rename your DeviceTree 4.0-Custom to “devtree.40”

Your folder should look like this:

– iboot.payload <– Created with Payload Pwner.
– devtree.40 <– Grabbed from Custom IPSW made by sn0wbreeze.
– ibec.40 <– Created with Payload Pwner.
– bspatch.exe <– Comes with iBooty.
– iBooty.exe <– Comes with iBooty.
– kernel.40 <– Grab from Custom IPSW made by sn0wbreeze.
– sn0w.img3 <– Comes with iBooty.
– wait.img3 <– Comes with iBooty.

STEP D: Restoring to 4.0 + Booting

*Make sure your are on 3.1.2 when doing this*

  1. Run iBooty and Select “Prepare Device for Custom Firmware“. Run the Process and if you see the image, you can proceed!
  2. Now open iTunes and restore to the custom ipsw.

***When done, your device will go into recovery mode. It won’t boot.***

STEP E : Booting

Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!

Enjoy! Hopefully iH8Sn0w can get a tool out there that will make all of this much easier.

If you have an iPhone 3GS old BootRom, you can jailbreak using Sn0wBreeze 1.6, PwnageTool 4 and then unlock iOS 4 on baseband 05.12.01, Baseband 05.13.04 and 05.11.07 using UltraSn0w 0.93.

To jailbreak iPhone 3Gs new bootrom, you can follow the guide linked below:

How to: Jailbreak iPhone 3GS New BootRom iOS 4

Update 1: iPhone 4 Jailbreak by GeoHot

Update 2: iPhone 4 Unlocked

Update 3:

Update 4

Also check out:

Download Sn0wBreeze (All versions New & Old)

53 comments… add one
KING Ayub July 10, 2010, 10:27 pm

its done and its gud.. thanks 4 new version
but there is a problem… when we restart it , it asks to connect with itunes and it starts when we again boot it with ibooty.any solution for this

i have ipod touch 2g with model mc.

Mickey July 27, 2010, 9:57 pm

ipod touch 2g mc model plz
can it jail with this method

xqprevolverqpx July 11, 2010, 8:42 am

ok…i know i sound like a noob. but how do i “grab” these things you speak of in the iBooty prep?

xqprevolverqpx July 11, 2010, 9:11 am

nevermind. i figured it out. 🙂

xqprevolverqpx July 11, 2010, 9:20 am

my only problem now is getting the iboot.payload

ARY July 11, 2010, 10:21 am

I have a unjailbroker iphone 3g and I have jailbroken an ipod touch awhile ago and I’m now thinking about jailbreaking my iphone. I have the greyed out wifi on my iphone and was wondering if this would affect the jailbreaking process for my phone and if my apps on my phone now will be accessable after the jailbreak..thank you

glamb July 11, 2010, 1:55 pm

error 1604 with itunes

Dennis A. July 12, 2010, 12:49 am

thnx1 it works1 it just take 2 hours, but it works!!!

xqprevolverqpx July 12, 2010, 4:07 am

when i try to run ibooty it says, “WARNING! iBoot Payload was not found or named”iboot.payload” Please correct this!”
how do i fix this? when i run pwner.exe, it doesnt put anything in the folder that i specify.

xqprevolverqpx July 12, 2010, 8:44 pm

will someone please help me? i dont know what to do. 🙁

iPhoneHeat July 13, 2010, 1:07 am

watch the video at the bottom of the guide

xqprevolverqpx July 13, 2010, 1:56 am

i have. multiple times. pwner.exe does not give me anything after it has completed all of its processes. it shows a dialog box after its done that say something along the lines of “your iboot payload should be in the specified folder. but then i go and look in the folder and its empty. 🙁 im doing everything exactly as the video and the tutorial say to

xqprevolverqpx July 13, 2010, 6:26 am

i figured out the problem with the payload. but now, whenever i get to the part where im supposed to boot it, it freezes on the “Setting up iBEC” part. this is all so frustrating. im going back to my 3.1.2 jsilbreak. lol

p2bc14 July 20, 2010, 2:37 am

How did you get payload to produce a file?

JairoJavierEmer July 16, 2010, 12:15 am

I only have SHSH blobs on 3.1.3 and not 3.1.2 , can i still jailbreak my iPod 3G if u upgrade to 4.0 ??

iPhoneHeat July 16, 2010, 1:21 am

nope.. but hopefully soon

shando July 17, 2010, 10:55 am

I upgraded my ipod touch 3g to ios4 can i jailbreak it?

iPhoneHeat July 18, 2010, 1:49 am


shando July 18, 2010, 6:52 am

so when can i jailbreak it?

Harry July 17, 2010, 5:25 pm

Finally Done it , But it’s running very slow , is this problem cause from jailbreak tool?

anthony July 17, 2010, 5:26 pm

hey guys. i dun really understand step A. can someone explain it to me clearly? thanks in advance.

anonymous July 19, 2010, 5:16 am

anyone know if i have to change the whole name for the 3 required in step C? like if i have to change the file type from .img3 to .40??

cymistry July 20, 2010, 4:39 am

I can’t get the TSS server to start. I am running as admin and nothing appears to be using port 80. Any help?

iPhoneHeat July 20, 2010, 11:56 pm

close the application that is using Port 80 e.g. Antivirus
or log into another user account

theyoyojo July 20, 2010, 10:29 pm

what does it mean by “the image”? my ipod just restarts and doesnt show any immage, if i put it in dfu and use ibooty then it reboots. does “the image” mean the apple boot logo?

Zeggy July 29, 2010, 9:12 am

When I go into recovery mode then click prepare for custom firmware the picture dont come up !!!! Help please

Centurion July 30, 2010, 6:31 am

Same thing is happening for me – I have an ipod touch 3g running a jailbroken 3.1.2 iOS, and I follow the steps exactly, but when I run ibooty 1.6 (with ipod in recovery mode) nothing happens.
Any ideas what could be wrong? All files in the ibooty folder are there and named correctly -although i will mention, my ibec.40 came from the sn0wbreeze ISPW as it’s supposed to, but this tutorial, where it says ‘your folder should look like this:’, says “ibec.40 <– Created with Payload Pwner.", but I believe that's a typo.

Anyways, any help with getting the image to appear would be appreciated.

hi July 30, 2010, 5:21 pm

still in recovery mode!!!!!!!
what should i do?

Enny August 1, 2010, 4:01 am

Thanx soo much… it worked

Mamatozay August 8, 2010, 10:10 am

I have been watch your video and reading your tutorial too..

i have ipod 3g with 3.1.3 installed on it. can i just proceed your tutorial when i am in 3.1.3 or waiting again?

normann August 16, 2010, 9:14 pm

when i run the ibooty nothing happens to my ipod 2g mc model no logo appears wat should i do??

sanj123 October 19, 2010, 3:30 pm

I Have Apple 3g OS 4 after updation the phone was locked. please tell me how to unlock my phone.

Leave a Comment