This is the low down on our tools for use with the 2.2.1 firmare from Apple, read the whole post in full before attempting anything. Please note that the Windows version of QuickPwn has been updated to version 2.2.5-2
- GOLDEN RULE: If you have a 3G iPhone running 2.2 firmware and you want to keep your ability to use yellowns0w (or the option to use it in the future) do NOT use QuickPwn, and do not use the official ipsw or the iTunes update process without using PwnageTool.
- Yellowsn0w will NOT work with the baseband version (02.30.03) that is present in the recent 2.2.1 update. If you want to use Yellownsn0w you will need to create and restore using a custom .ipsw that will allow you to update safely to 2.2.1 without applying the 02.30.03 baseband update. You’ll then have a 3G iPhone running 2.2.1 with an older baseband version that is still vulnerable to yellowsn0w, following these steps ensures that yellowsn0w will still operate. 
- Please read all parts of this post before downloading and using these tools.
- Read items 1, 2 and 3 again and again.
- At the bottom of this post are the bittorrent files for the latest versions of PwnageTool and QuickPwn.
- These apps are suitable for the recent 2.2.1 release.
- The Yellowsn0w version has been updated to 0.9.7. Yellowsn0w is available from Cydia or Installer - this version allows compatibility with pwned 2.2.1 system (not baseband). Again,, remember 0.9.7 yellowsn0w DOES NOT WORK WITH 2.2.1 (02.30.03) directly - you need to be running a ‘pwned’ version of 2.2.1 which didn’t upgrade the baseband during the restore/upgrade.
- Users of OS X 10.5.6 will be unable to use DFU mode correctly, please see the note towards the end of this post to easily fix this issue.
Baseband 101
The ‘baseband’ is the generic name given to the internal components of the iPhone that handle the phone calls and Internet access. This ‘baseband’ is a tiny and unique independent computer system that runs inside your iPhone, it is separate to the main system that handles the applications (such as email and google maps) and it talks to the main part of the phone over an internal communications network. Think of it like a cable modem or other peripheral that is attached to your home PC that needs occasional updates. When a software update is released and presented to you within iTunes the baseband is sometimes updated (to fix bugs or add new features). The 2.2.1 update for the iPhone 3G contains such an update, so running the vanilla updater straight away with iTunes will reprogram and update the baseband. This could be bad for certain people, depending on your ultimate aim.
SIM Free/SP Unlocked/Factory Unlocked iPhone 3G
This applies if you bought your iPhone 3G for $$$$$$$. This model of iPhone 3G doesn’t have an Service Provider lock (aka factory unlocked) and you are able to put any SIM card into the phone and get service. Your phone is already unlocked so you do not need to worry about baseband updates, simply upgrade to 2.2.1 using iTunes and then use QuickPwn to Pwn and Jailbreak. This will add Cydia and Installer too.
Locked iPhone 3G - Preserve Baseband
This applies if you have a locked iPhone 3G and you wish to update to 2.2.1 but preserve the iPhone’s current baseband software. Preserving the baseband will ensure that you can still use “yellowsn0w” the iPhone 3G unlock application. To upgrade your phone to 2.2.1 and preserve the state of the baseband you need to create a custom .ipsw with PwnageTool. This custom .ipsw will not contain the baseband update but of course will still give you any new stuff from 2.2.1
There are plenty of tutorials about this process on the web, but PwnageTool contains intuitive graphics and easy to follow prompts that should have you up and running in no time at all. Please note: PwnageTool is only available for Mac OS X.
Locked iPhone 3G
If you are using your iPhone with one carrier and have no interest in the possibility of an iPhone 3G unlock in the near future then just restore or upgrade to 2.2.1 using iTunes and use QuickPwn to Jailbreak and add Cydia and Installer.
iPhone 2G (1st Generation)
Update or Restore your iPhone 2G with iTunes then run QuickPwn to do the magic, ‘nuff said, you don’t need to worry about anything.
iPod Touch 1G (Original iPod Touch)
Update to 2.2.1 with iTunes and run QuickPwn.
iPod Touch 2G (New iPod Touch)
Sorry, no support at this time, but Redsn0w is being actively researched and developed.
Fixing DFU mode on 10.5.6
As noted previously OS X 10.5.6 introduced a bug that affected the use of DFU mode. with some Macs. There have been previously published hacks and techniques to fix this, but here is another method that can be used to temporarily restore DFU functionality in order to use QuickPwn or PwnageTool.
- You will need an account with ADC (Apple Developer Connection) this is free and takes a few minutes to sign up, you should read the terms and conditions carefully and you should only sign up if you are thinking of developing applications in the future - http://developer.apple.com/mac/
- Download the disk image “IOUSBFamily-315.4-log.dmg" for Mac OS X 10.5.5 Build 9F33” (yes, that is a “5” in 10.5.5 - this is a developer debug package of the USB kernel extension).
- Unplug non-vital USB equipment, such as external DVD writers, USB scanners, USB mass storage devices, at the most leave a Keyboard and Mouse connected.
- Install IOUSBFamily-315.4.1.pkg from within the disk image
- Reboot your system!
- Perform necessary DFU activity with QuickPwn or PwnageTool.
- Download the disk image “IOUSBFamily-327.4.0-log.dmg” for Mac OS X 10.5.6 Build 9G55"
- Intall IOUSBFamily-327.4.0.pkg from within the disk image
- Reboot your system!
- Reattach your USB peripherals.
Official Bittorrent Releases -
- PwnageTool 2.2.5 for Mac OSX is here SHA1 Sum - 8fe2f20c00f48b37d8262d6872a12166c6e165ba
- QuickPwn 2.2.5 for Mac OSX is here SHA1 Sum - 2f1353242ef10dc408e95786643e497fcd04e4ea
- QuickPwn 2.2.5 for Windows is here SHA1 Sum - <release deleted use 2.2.5-2 instead>
- QuickPwn 2.2.5-2 for Windows is here SHA1 Sum - 82aae63218316af42e4fa20f8c69d9eb4fe9d4ee
Unofficial Mirrors
The following links are unofficial download mirrors, you download these at your own risk, we accept no responsibility if your computer explodes or if it becomes part of a NASA attacking botnet or even worse if your hands fall off mid-way during the use of these archives. We do not check these links or archives and we accept no responsibility with regard to the validity of the files, or with other content these links provide or with the content that is on the linked site.  Always check the published SHA1 sums. We would prefer that you downloaded the official bittorrent release that is linked above, but you are welcome to try these if you really must. Mirror owners should email direct links only to blog.iphone-dev.com , please don’t place mirrors in the comments as they will be deleted.
Mac PwnageTool
- http://iphone-dev.fgv6.net/PwnageTool_2.2.5.dmg
- http://iphone.schwarzmetall.cn/PwnageTool_2.2.5.dmg
- http://rabstalk.bplaced.net/mirrors/PwnageTool_2.2.5.dmg
- http://jmcoon.net/PwnageTool_2.2.5.dmg
- http://downloads2.ipod.backshot.eu/PwnageTool_2.2.5.dmg
- http://www.iphone-storage.de/PwnageTool_2.2.5.dmg
- http://miphone.ca/iphone-dev/PwnageTool_2.2.5.dmg
Mac QuickPwn
- http://iphone-dev.fgv6.net/QuickPwn_2.2.5.dmg
- http://iphone.schwarzmetall.cn/QuickPwn_2.2.5.dmg
- http://rabstalk.bplaced.net/mirrors/QuickPwn_2.2.5.dmg
- http://jmcoon.net/QuickPwn_2.2.5.dmg
- http://www.iphone-storage.de/QuickPwn_2.2.5.dmg
- http://downloads2.ipod.backshot.eu/QuickPwn_2.2.5.dmg
- http://miphone.ca/iphone-dev/QuickPwn_2.2.5.dmg
Windows QuickPwn
- http://miphone.ca/iphone-dev/QuickPwn225-2.zip
- http://foskarulla.com/QuickPwn-225-2.zip
- http://downloads2.touch-mania.com/QuickPwn-225-2.zip
- http://www.applei.ph/devteam/QuickPwn-225-2.zip
- http://phonenews.com/phones/gsm/apple/QuickPwn225-2.zip
- http://rabstalk.bplaced.net/mirrors/QuickPwn-225-2.zip
- http://www.evil-crew.de/QuickPwn-225-2.zip
- http://daniel14.com/QuickPwn-225-2.zip

