Help with jailbreaking and Cydia for iPhones, iPads, and iPod touches.

Pangu provides an iOS 9.0 untethered jailbreak. TaiG provides an iOS 8.4 and 8.3 untethered jailbreak.
Check @PanguTeam, @taig_jailbreak, @saurik, and /r/jailbreak for news and updates.
You can use Cydia Impactor if you need to un-jailbreak an 8.1-8.4 device without restoring.
Instructions for jailbreaking iOS 8.0-8.4.
Before asking a question, check Frequently Asked Questions to find quick answers!
How to fix some mysterious problems.

Hello I have an iphone 3GS, it was jail broken to work with Indian networks. I upgraded accidently to IOS 6.1.2 through itunes, it gave me an activation error. It was displayng 15 digits number but ICCID display as unknown.

I took help from answers posted at thread "Cannot activate Iphone 3gs after IOS 6 upgrade". As per Answer provided by Sandkuma002, I downloaded iOS 6.1.2 IPSW, used Sn0wbreeze and shift+itunes restore to jailbreak and then installed Ultrasn0w. After these steps I could get all the icons on screen and Cydia working but SIM was not working. Iphone was reporting Modem firmware as 6.15, So I followed instructions to downgrade baseband to 5.13 with Redsn0w. In the process I needed to download IPSW 6.0 also. During downgrade process a long list of messages were displayed on iphone and then it displayed an error. Now it is stuck in iTunes recovery mode reboot loop. I am unable to switch it off or put it in DFU mode.

In the mean time itunes has stopped signing 6.1.2. Only option left is let itunes update it to 6.1.3, which looks very scary to me, as I may not be able to jailbreak it after 6.1.3 update.

I am seriously facing prospects of bricking my iphone. HELP HELP HELP!

asked 20 Mar '13, 05:09

jmdesai's gravatar image


jmdesai, your long explanation already reflects you need HELP! Now tell us the exact Error! Did it say some problem with - slide to power off? it means that when you put your phone in DFU mode, you did not properly switched off your phone. Please flash ipadbaseband again using redsn0w. Please don't click next when you re asked to put your phone in DFU. Just press both home and sleep button for 10 secs and then release sleep and continue to hold hoe button for another 16 secs, you will see redsn0w exploiting with limera1n. Then you should have flashing logo on your phone. After that you can downgrade again! And don't worry about 6.1.2. if you were jailbroken, your blobs are on Cydia and you can use redsn0w to fetch them 3GS can be downgraded to any 4.x or 5.x or 6.x ios so long as you have the blobs. Try and get back to us with the new errors if any!

(20 Mar '13, 07:36) sandkuma002 sandkuma002's gravatar image

Thanks for your help.

The phone was last stuck in iTunes recovery mode reboot loop. I was unable to switch it off or put it in DFU mode. So I could not use Redsn0w to downgrade.

Anyway, the problem is deepened further (doomed?). I updated to 6.1.3.

(20 Mar '13, 08:32) jmdesai jmdesai's gravatar image

@sandkuma002: Thanks buddy. You are the savior! Giving me a ray of hope. I am travelling for a few days, so I will try thereafter and report the results.

(21 Mar '13, 00:09) jmdesai jmdesai's gravatar image

@jmdesai, please use ifaith mode of sn0wbreeze to create custom ipsw by stitching 6.1.2 blobs, your phone will be in pwned dfu, using iTunes- shift+restore, you should have jailbreak and hacktivated 6.1.2 working. For any iTunes errors, please read FAQ here!

(21 Mar '13, 00:23) sandkuma002 sandkuma002's gravatar image

@sandkuma002: where to find shsh blobs? I can not find any *.shsh files on my PC.

(21 Mar '13, 00:51) jmdesai jmdesai's gravatar image

Already explained above, use ifaith/redsn0w/tiny umbrella to fetch them and save it on your computer.

(21 Mar '13, 00:55) sandkuma002 sandkuma002's gravatar image

When I use iFaith to fetch blobs for ECID 4185462496716 it reports availability as NONE.

(21 Mar '13, 02:47) jmdesai jmdesai's gravatar image

What is the serial no of your 3GS, old bootrom 3GS don't need blobs to downgrade, use idetector to check your bootrom status!

(21 Mar '13, 04:31) sandkuma002 sandkuma002's gravatar image

SerialNumber: 5K1023KWEDG

(21 Mar '13, 05:04) jmdesai jmdesai's gravatar image

@jmdesai, i just checked using redsn0w, SHSH blob- query and it clearly says that the following blobs are available: iPhone2,1 4185462496716 remote blobs: 6.1.2, 6.0.1, 4.1, So you are in the game. Now we just need to fetch them. Please retry using any of the tools once again!

(21 Mar '13, 05:16) sandkuma002 sandkuma002's gravatar image

I just now downloaded your blobs on my computer using ifaith using your ECID, you can also download yourself using ifaith in "show available SHSH caches on server"! I have also submitted your 6.1.3 blobs to cydia server for future use.

(21 Mar '13, 05:24) sandkuma002 sandkuma002's gravatar image

Yes, I was jailbreaken on 6.1.2 and my cydia was working

(21 Mar '13, 05:30) jmdesai jmdesai's gravatar image

Great... I think proxy server at job might have blocked the blobs. I think I would try from home.

(21 Mar '13, 05:37) jmdesai jmdesai's gravatar image

OK. I could download blobs for 4.1, 6.0.1 and 6.1.2 using ifaith. I stitched 6.1.2 blobs to 6.1.2 ipsw in snowbreze and shift+restored custom ipsw to iphone. After restore, iphone is now stuck up at restoration screen with message in itunes "We're sorry, we are unable to continue with your activation at this time". With wifi also, phone is not activated. It just returns to "Try again" screen after some time.

(23 Mar '13, 15:05) jmdesai jmdesai's gravatar image

Hacktivate! Use redsn0w to jailbreak your phone and it will be hacktivated.


answered 23 Mar '13, 15:43

ml05019's gravatar image


I think I need to choose an option to hacktivate when I build custom ipsw using shsh blobs and snowbreeze.

(23 Mar '13, 16:14) jmdesai jmdesai's gravatar image

Once jailbroken, it can't be jailbroken again! And if you choose ifaith mode in sn0wbreeze, it is automatically hacktivated. However if you use ifaith , then it is not hacktivated. And it has been found that 6.1.2 is tether jailbreak.

(23 Mar '13, 16:34) sandkuma002 sandkuma002's gravatar image

If you use iFaith mode in Sn0wbreeze, does it end up with a jailbroken ipsw? I tend to think it creates a clean ipsw with just the blobs included, so it should be fine to, following restore, jailbreak it with redsn0w.

(23 Mar '13, 16:47) ml05019 ml05019's gravatar image

@ml05019 Yes, ifaith mode in sn0wbreeze hactivates and jailbreak.Clean ipsw restore happens with ifaith and yes it can be jailbroken and easy method is evasi0n.

(23 Mar '13, 16:54) sandkuma002 sandkuma002's gravatar image

@jmdesai (1 hour ago) has written that he created an ipsw with sn0wbreeze, restored to it, and got a working phone that needs only hacktivation.

Well, there are 2 ways to go from here:

  • create other ipsw in Snowbreeze with other options, and restore to it, or

  • take a phone as it is, jailbreak it with redsn0w and see what happens.

1st option means you erase a phone with a working 6.1.2, and risk getting a black screen.

I would prefer 2nd option, because if you do that, you either get a working phone with jailbreak and hacktivation, or, you get a broken firmware because you've jailbroken a phone that already had jailbreak, and you can go back to Snowbreeze - but it's 50:50 need to restore, and not 100 as in 1st option.

(23 Mar '13, 17:07) ml05019 ml05019's gravatar image

@ml05019, no, @jmdesai stitched blobs and it is only possible in ifaith mode so he might have not clearly written but that was i suggested to him in the first place 2 days ago (when no one knew about the black screen issue) but may be he did something to say no to hacktivation and that is why he is in activation screen but surprisingly why no black screen, only @jmdesai can explain again what exactly he did ??

(23 Mar '13, 17:15) sandkuma002 sandkuma002's gravatar image

I just went to ifaith mode, pointed to the blobs, and selected "build ipsw". I did not go to "general" and did not select "hactivate" option.

(23 Mar '13, 17:24) jmdesai jmdesai's gravatar image

@jmdesai, can you just take your iPhone in your hand, connect it to your computer, open redsn0w, go to Extras -> Select IPSW, select iOS 6.0 file, go back to main screen, and jailbreak? Just do it. We'll go from there.

(23 Mar '13, 17:28) ml05019 ml05019's gravatar image

started trying it now...but it will take some time.

(23 Mar '13, 17:41) jmdesai jmdesai's gravatar image

exploit trying option1.

(23 Mar '13, 18:40) jmdesai jmdesai's gravatar image

BTW "exploit failed" is a very common error from redsn0w. You just try again, reboot your PC, change USB ports... eventually it'll work

(23 Mar '13, 19:31) ml05019 ml05019's gravatar image

Anyway, Option 1 worked. The phone is now jailbroken with 6.1.2 firmware and Cydia working. Just to summarize, what I did: Snowbreeze-->iFaith mode-->pointed to blobs-->general-->hactivate and shsh selected-->build ipsw, then shift+restore in itunes. I have to now work on downgrading baseband from 6.15 so that SIM starts working. On my first attempt downgrading baseband, exploit failed error appeared on Redsn0w. I will try again with another USB port. Thanx to sandkuma002 and ml05019 that I could reach upto this point.

(24 Mar '13, 03:44) jmdesai jmdesai's gravatar image

@jmdesai, please try to reflash ipadbaseband by selecting 6.0 in redsn0w (if you are unable to downgrade)! And remember to slide to power of and put in DFU directly by holding sleep+home for 10 sec and then holding home for another 16 secs (without waiting for redsn0w to guide you). Please share your experience after you get back your signal or not!

(24 Mar '13, 06:34) sandkuma002 sandkuma002's gravatar image

No luck with BB downgrade or reflash ipadbaseband. Everytime the error is same: exploit failed.

(24 Mar '13, 07:40) jmdesai jmdesai's gravatar image

@jmdesai, when you are flashing ipadbaseband, is cydia unchecked?

(24 Mar '13, 07:56) sandkuma002 sandkuma002's gravatar image


(24 Mar '13, 09:04) jmdesai jmdesai's gravatar image

Exploit failed is improper DFU, please try 3-4 times sometimes it is even verified as DFU but it is still not proper. Put in DFU without the help of redsn0w by timing the sleep and home button. Sometimes keep holding home button while connected to redsn0w till the limera1n exploit start is better.

(24 Mar '13, 09:08) sandkuma002 sandkuma002's gravatar image

After many tries and eliminations I could run Redsn0w to downgrade BB, but after several messages on iphone, there was an error displayed (on device) asking to power off device and retry redsn0w. This happened before displaying pwnd apple graphic on device. Now phone is stuck in recovery mode loop. So basically I am back to square one! Should I try downloading 4.1-8B117 ipsw and stitch my 4.1-8B117 blobs to custom build ipsw?

(24 Mar '13, 14:27) jmdesai jmdesai's gravatar image

Hello to you today. The reason to what you have on your iPhone is that redsn0w jailbreaks your phone, and it was already jailbroken by Sn0wbreeze. You shouldn't re-jailbreak an already jailbroken phone.

11 hours ago, Option 1 worked for you. I suggest you now go back to that step, and now also add iPad BB to the firmware. You'll end up with 06.15.00 BB on your phone, but at least ultrasn0w will work.

If you're not happy with that, there's another method; you can use iFaith (and not Snowbreeze's iFaith mode) to create a non-jailbroken ipsw with blobs, restore to it, and then jailbreak, hacktivate and BB-downgrade your phone using redsn0w only. The choice is yours.

(24 Mar '13, 15:03) ml05019 ml05019's gravatar image

non-jailbroken ipsw created with iFaith and restored, then jailbreak with Redsn0w, but Cydia not found on device. SIM also not supported.

(24 Mar '13, 17:55) jmdesai jmdesai's gravatar image

Darn it. I remember about this bug in redsn0w. There's a solution for this, but you'll need to do some SSH commands. Do you want this? Then try googling "install Cydia on iOS 6.0 beta 3"

BTW if you don't actually need Cydia, you don't need to bother installing it, you can just install mobilesubstrate+ultrasn0w using SSH to get your SIM working.

(24 Mar '13, 19:43) ml05019 ml05019's gravatar image
Your answer: (please use the "add new comment" button unless you are actually answering the original question)
toggle preview

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported



Asked: 20 Mar '13, 05:09

Seen: 6,241 times

Last updated: 24 Mar '13, 19:43

JailbreakQA is by chpwn and comex.
About JailbreakQA. Powered by OSQA.