This page has been robot translated, sorry for typos if any. Original content here.

Instructions for unlocking (hacking) iPhone

iPhone unlocked! The confrontation between Apple and hackers, which lasted from the moment the iPhone was released, is temporarily suspended. This can not be called a complete victory for hackers, because the way that allows you to use the SIM cards of other operators on the iPhone is more likely a "tricky deception" of protection and not its hacking.

The unlock method is very simple, you will not need any military technology.
All that is required is easily bought in online stores:
- The programmer of SIM cards (reading / writing SIM cards), about 1800 rubles.
- Pure multisimka - this is Silvercard (CPU card chip PIC16F876 + Memory 24C64 + 8 different mobile operators, 208 numbers in a notebook, 10 SMS), 250 rubles;
- Programs for calculating KI and flashing SIM cards (Woron Scan is suitable - it works faster than its counterparts), free of charge.
The essence of the method is as follows:
Attention, is not responsible for the consequences of following the steps below. You commit them at your own risk.
1. The preparatory phase.
For MAC users
For Windows Users
2. Work with AT&T SIM card.
Now you need a SIM card AT&T, which came with the phone.
For MAC users
For Windows Users
3. Read IMSI, ICCID and KI
Reading IMSI, ICCID and KI takes time. Although it is not difficult to find out the IMSI number, it is much more difficult to find out the KI value, this requires physical access to the SIM card, since KI is not transmitted in the clear on the air. When a subscriber authenticates at the operator’s base station, the SIM card encrypts with a KI key a message (pseudo-random request) transmitted by the operator’s network and returns the result. The network performs the same action on its part - and if the keys match, then the encrypted messages will also match.

Experimental data on Russian operators.

SIM card Raven Scan
Min time The number of calls to the SIM card Frequency, Mhz
MTS Jeans five 5354 14.28
MTS Media thirty 14696 7.14
MTS info 20 18330 7.14
MTS info 27 18863 7.14
MTS Media eleven 6349 7.14
Bee Line 96 17566 3.57

Most programmers operate at a fixed frequency of 3.57 Mhz, but in our case (USI v 2.0) there was a possibility of choosing a frequency between 3.57, 7.14 and 14.28 Mhz. The higher the frequency of the crystal oscillator, the faster the scanning process will end. However, it should be noted that SIM cards of different operators lend themselves to scanning at different frequencies, more precisely, at a frequency of 3.57 Mhz, all SIM cards are scanned, but not at a higher frequency. For example, in Moscow, Beeline SIM cards are scanned only at a frequency of 3.57 Mhz, MTS SIM cards at a frequency of 7.14 Mhz (MTS-media and MTS-info) and at a frequency of 14.28 Mhz (Jeans). Megafon SIM cards are scanned at a frequency of 14.28 Mhz, however, it will not be possible to find out KI.

So we need:
- Insert your own, not AT&T SIM card into Woronscan and pull out IMSI + KI from it (the process can take up to 40-50 minutes);
- Do the same operations with SIM AT&T to get IMSI + ICCID.

As a result, we get approximately the following result (depends on your card):

Save the result to a file. Then we open the resulting file with a text editor and find the KI and IMSI values ​​of your SIM card in it. If it is impossible to find KI, the program will stop working on 60,000 calls to the SIM card. This is done in order to avoid blocking the card due to exceeding the threshold number of calls. However, you can forcefully continue scanning, but from personal experience we can say that if KI was not found in less than 60,000 attempts, then it will never be found. We checked on the megaphone SIM card, after 90,000 calls, the SIM card was blocked. Those. it became impossible to use it (such things, experiment on cards that are not a pity).

Fine. Let's continue. You will be required to:

- Download utility SIM_EMU_6.01_iPhone.rar [ Download ] [ Download ] [ Download ]
- Place Silvercard in the programmer, run SIM-EMU;
- Configure tab >> Read from disk >> pick up SIM_EMU_6.01_iphone. HEX and SIM_EMU_6.01_iphone_EP. HEX >> make sure utility cells 0 through 9 turn red;
- In the 0-cell we drive in IMSI and Ki of your SIM card, then AT&T ICCID. For ADN / SMS / FDN # we manually assign 161, 15, 4. For SMS Center we use your service number for sending SMS (we look in the phone settings or on the operator’s website);
- In the 9-cell insert IMSI AT&T;
- In the options Config mode mark Card;
- Click Write to card;
- Turn off the iPhone, insert the created super-sim card;
- Turn on the iPhone;
- We observe the icon of our operator and make a test call.

Congratulations to all iPhone fans in Russia! Now this wonderful phone will work with us!

Photo of the first unlocked Russian iPhone