This page has been robot translated, sorry for typos if any. Original content here.

Instructions for unlocking (breaking) iPhone

IPhone unlocked! The confrontation between Apple and hackers, which lasted since the iPhone's release, was suspended. A complete victory for hackers can not be called this, because by the spoils that allows the use on the iPhone of other operators' sims, it's more likely that they are a "tricky deception" of protection rather than hacking it.

The unlocking method is very simple, you will not need any military technology.
All that you need is easily bought in online stores:
- SIM card reader (read / write SIM cards), about 1800 rubles.
- Net malysimka is Silvercard (CPU chip PIC16F876 + Memory 24C64 + 8 different cellular operators, 208 numbers in the address book, 10 SMS), 250 rubles;
- Programs for calculating KI and firmware for SIM cards (Woron Scan works - it works faster than its counterparts), for free.
The essence of the method lies in the following:
Attention, does not bear responsibility for the consequences of the following actions. You do it at your own peril and risk.
1. Preparatory stage.
For MAC users
For Windows users
2. Work with AT & T Sim.
Now you will need "simka" AT & T, which went with the phone.
For MAC users
For Windows users
3. Read IMSI, ICCID and KI
Reading IMSI, ICCID and KI takes time. Although it is not difficult to find the IMSI number, the KI value is much harder to learn, it requires physical access to the SIM card, since it is not broadcast on the air in an open form. When authenticating a subscriber at the operator's base station, the SIM card encrypts a certain message (pseudo-random request) transmitted by the operator's network with the KI key and returns the result. The network performs the same action on its part - and if the keys match, then the encrypted messages will also coincide.

Experimental data on Russian operators.

Sim card Raven Scan
Time, min. Number of calls to the SIM card Frequency, Mhz
MTS-Jeans 5 5354 14.28
MTS-media thirty 14696 7.14
MTS-info 20 18330 7.14
MTS-info 27th 18886 7.14
MTS-media eleven 6349 7.14
BiLine 96 17566 3.57

Most programmers work at a fixed frequency of 3.57 Mhz, but in our case (USI v 2.0) there was a choice of frequency between 3.57, 7.14 and 14.28 Mhz. The higher the frequency of the crystal oscillator, the faster the scanning process ends. However, it must be taken into account that the SIM cards of different operators can be scanned at different frequencies, more precisely at a frequency of 3.57 Mhz all SIM cards are scanned, at a higher frequency, not all. For example, in Moscow, SimLine BileLine cards are scanned only at a frequency of 3.57 Mhz, SIM cards on MTS at 7.14 Mhz (MTS-media and MTS-info) and at a frequency of 14.28 Mhz (Jeans). Sim card Megaphone scanned at a frequency of 14.28 Mhz, but you will not be able to learn KI.

So, we need:
- Insert your own, not AT & T sim card in Woronscan and pull out IMSI + KI from it (the process can take up to 40-50 minutes);
- Do the same operations with the SIM AT & T to get IMSI + ICCID.

As a result, we get approximately the following result (depends on your card):

Save the result to a file. Then open the resulting file with a text editor and find the KI and IMSI values ​​of your sim card in it. In the event that you can not find KI, the program will stop working on 60000 calls to the SIM card. This is done for the purpose to avoid blocking the card due to exceeding the threshold number of hits. However, you can force the scan to continue, but from personal experience we can say that if KI was not found in less than 60,000 attempts, it will not be found again. We checked on the Megaphone SIM card, after 90 000 calls the SIM card was blocked. Those. It became impossible to use it (such cases, experiment on cards that are not pitiful).

Excellent. Let's continue. You will need:

- Download the utility SIM_EMU_6.01_iPhone.rar [ Download ] [ Download ] [ Download ]
- Place the Silvercard in the programmer, run SIM-EMU;
- Configure tab >> Read from disk >> pick up SIM_EMU_6.01_iphone. HEX and SIM_EMU_6.01_iphone_EP. HEX >> make sure that the utility cells from 0 to 9 are red;
- In the 0-cell drive IMSI and Ki of your SIM, then AT & T ICCID. For ADN / SMS / FDN # manually 161, 15, 4. For SMS Center we use your service number to send SMS (look in the phone settings or on the operator's website);
- In the 9-cell insert IMSI AT & T;
- In the Config mode options, select Card;
- Click Write to card;
- Turn off the iPhone, insert the created super sim card;
- Turn on the iPhone;
- Watch the icon of your operator and make a test call.

Congratulations to all iPhone fans in Russia! Now this miracle phone will work with us!

Photos of the first unlocked Russian iPhone