Jailbreak iPhone 3GS (New BootRom) iOS 4.0 Firmware - iPhoneHeat

Jailbreak iPhone 3GS (New BootRom) iOS 4.0 Firmware

iH8Sn0w has posted detailed instructions on how to jailbreak iPhone 3GS new bootrom running iOS 4 with Sn0wBreeze 1.6.2. Yes! using this method you can jailbreak iOS 4 on iPhone 3GS new bootrom. But there are few things to note first.


  • This Jailbreaks iPhone 3GS New BootRom iOS 4 for now. [How to: check iPhone 3GS BootRom]
  • You MUST have SHSH blobs saved for OS 3.1.2. The exploit used in this hack has been patched in OS 3.1.3 so firmware 3.1.2 is a MUST.
  • It’s a tethered jailbreak. For those who don’t know, a tethered jailbreak device once turned off/Reboot/run out of battery, you need to connect it to computer and execute a tool to boot up the device.
  • Jailbreak for iPod Touch 3G and 2G (MC) is also in projects along an easy to use tool to automate the steps below provided that you’ve SHSH for 3.1.2 saved.

This guide is only for advanced windows users only. So, proceed with precaution and follow the guide at your own risk. Here are the step by step instructions from the official source:


Please follow the Updated guide with video instructions here.


* An iPhone 3G[S] — new bootrom
* 3.1.2 SHSH blobs.
* difrnt’s iBSS grabber
* Payload Pwner for the 3GS.
* sn0wbreeze V1.6.2
* iBooty
* LibUSB (64-Bit users read carefully!!!)
* 3.1.2/4.0 3GS firmware downloaded.
STEP A : Grabbing your 3.1.2 iBSS file.

Pointing your hosts :

I : If you have your shsh blobs saved on Cydia/Saurik’s server then follow this tutorial. — http://saurik.com/id/12

II : If you have it saved with TinyUmbrella, then download the GUI here. — http://thefirmwareumbrella.blogspot.com/
Restoring to grab the iBSS file.

I : Place your device in DFU.

II : Start up the iBSS/iBEC grabber.

III : Put the save folder on a new folder on your desktop.

IV : Hit “Start Monitoring”.

V : Now go back to iTunes and do SHIFT + Restore. Then browse for your 3.1.2 IPSW. You will need to restore
to 3.1.2 in order to pwn 4.0.
Saving your iBSS

I : After Restoring, Go to the folder that you have specified to save your iBSS file.

II : You will see folders like (Per**.tmp). Go into one of them, and you’ll see a folder called “Firmware”. Go there. Then go to the folder “dfu”.

III : Copy the iBSS file to a safe place, then you can remove the folder created by the iBSS Grabber.
STEP B : Creating custom 4.0 firmware.

I : Download sn0wbreeze from http://ih8sn0w.com and create your custom 4.0 ipsw.

*Ignore the warnings after browsing for the ipsw.*
STEP C : Installing LibUSB for iRecovery

Run this mini tool to detect your O/S + Arch. — Windows + Arch. Detector

Windows XP Users download this installer — LibUSB Installer
Windows Vista/7 users RUNNING 32-Bit:

* Download the installer and run it in compatibility mode for Windows XP.

If you are a 64-Bit user, follow this tutorial — LibUSB 64-Bit Tut

Once LibUSB is installed iRecovery should be able to function now.
STEP D : Pwning iBSS + iBoot

I : Download this easy tool here — Payload Pwner for 3GS // It will help you create the payloads.

STEP E: iBooty Prep.

Most of you know of the utility “iBooty” that I made for Aki_nG.

It will work as long as you place all of the correct files there.

I : Download iBooty GUI here — iBooty for 3GS and Extract it.

II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver.

III : Grab the kernelcache and bring it into the same folder as ibooty.
Also grab the iBEC from the folder “Firmware\dfu\iBEC.n88ap.RELEASE.dfu”

IV :
* Rename your iBSS 3.1.2 signed to “ibss312.dfu”
* Rename your Kernel 4.0-Custom to “kernel.40”
* Rename your iBEC 4.0-Custom to “ibec40.dfu”
Your folder should look like this :

– iboot.payload <– Created with Payload Pwner.
– exploitibss312 <– Created with Payload Pwner.
– ibec40.dfu <– Grabbed from Custom IPSW made by sn0wbreeze.
– irecovery.exe <– Comes with iBooty.
– readline5.dll <– Comes with iBooty.
– iBooty.exe <– Comes with iBooty.
– ibss312.dfu <– THIS NEEDS TO BE YOUR iBSS from the restore!
– kernel.40 <– Grab from Custom IPSW made by sn0wbreeze.
– sn0w.img3 <– Comes with iBooty.
STEP F: Restoring to 4.0 + Booting

I : Run iBooty and Select “Prepare Device for Custom Firmware”. Run the Process and if you see a snow flake, you can proceed!

II : Now open iTunes and restore to the custom ipsw.

STEP G : Booting

I : Just Re-Run iBooty and select “Boot It”. If all goes well it will boot!
Hopefully I can get a tool out there that will make all of this much easier. Of course, that only happens when I get bored from ppl msging me on Twitter =p

via [Openpwn]

If you have an iPhone 3GS old BootRom, you can jailbreak using Sn0wBreeze 1.6, PwnageTool 4 and then unlock iOS 4 on baseband 05.12.01, Baseband 05.13.04 and 05.11.07 using UltraSn0w 0.93.

30 comments… add one
AfRoo July 4, 2010, 1:38 pm

GOSH, MY Mind is stuckup, I’m so confuse, is any way like spirit tool ??? easly like pee

narayan July 4, 2010, 6:57 pm

i have iPhone3GS factory unlocked. at first i was on 3.1.3 with spirit jb. then i upgraded to iOS4 from itunes directly.pls tell me how to jb this iOS 4 on my 3gs.i checked it has oldrom.

iNefos July 4, 2010, 10:37 pm

i haven’t 3.1.2 SHSH BLOBS………… i am Stuck ?

Please Reply….

iPhoneHeat July 4, 2010, 11:35 pm

for now.. Yes.

nubuki July 5, 2010, 3:08 am

I don’t have 3.1.2 shsh blobs, but I’m on 3.1.2 still (when I bought it the machine came with 3.1.2 but the new bootrom). Would this work?

Or should I wait?

iPhoneHeat July 5, 2010, 1:26 pm

Wait for the official tool to come out.. it’ll automate all the steps mentioned above 🙂
BTW – if you depend on unlock and don’t have SHSH blobs saved for 3.1.3, you better stay away from update because if anything goes wrong you won’t be able to unlock it

lykimsiv July 5, 2010, 6:00 am

I have 3.1.3 SHSH so does it work with above guide??

pheakrith July 5, 2010, 7:36 am

it so complicate could you update and easy tool to jailbreak? like: Spirit just double click jailbreak

iPhoneHeat July 5, 2010, 1:33 pm

releasing tomorrow i Think 🙂

AfRoo July 5, 2010, 3:26 pm

OMG, are u serously guys, 😀 oh no u think 🙁
lol well hope so

iPhone3GS July 5, 2010, 8:08 am

my iPhone3GS is currently in 3.1.2.. Jailbroken with blackra1n…

So, I just restore custom 4.0 firmware with itunce?

iPhoneHeat July 5, 2010, 1:34 pm

do you depend on unlock?
if yes, have you saved SHSH blobs for 3.1.3 or 3.1.2?

IzzY July 5, 2010, 5:04 pm

Hi will there be a hacktivation tool for 3gs 3.1.3 new bootrom?

Franco July 5, 2010, 7:22 pm

this one isn’t really good. stay away!

hakintosh July 10, 2010, 2:21 am

i have an iphone 3gs runing os 3.0. i bought it last year in US. i use it in another country now with jailbroken by cydia. i think cydia has my shsh blobs. so what should i do for upgrading to os 4.0 ??

iPhoneHeat July 10, 2010, 5:56 pm

use tinyumbrella to confirm your SHSH blobs or see in cydia:

lionslayer July 19, 2010, 9:25 pm

i have the new 3gs (new bootrom) and its the version 4.0.1 (8A306) MC model and has a firmware with 05.13.04. can i use this to jb my iphone or is it not possible?

iPhoneHeat July 20, 2010, 11:47 pm

No, you can’t.

gagi July 23, 2010, 4:06 pm

Hi there! I have an iPhone 3Gs new bootrom with 4.0 (8A293) Firmware.. It’s new and it has never been jailbreaked or unlocked.. On the screen it’s showing: Insert a valid SIM Card with no PIN lock to activate! What should I do? Can I use this tutorial? If not, when do you think that there we’ll be a tool to unlock it???

iPhoneHeat July 24, 2010, 1:34 am

wait for a few days.. jailbreak is on its way..

Leave a Comment