#tvos-jailbreaks

1 messages Ā· Page 15 of 1

ionic copper
#

you mean settings fr

outer spruce
#

nooo šŸ’€

#

like

#

well kinda?

heavy patrol
#

So did it update or no

outer spruce
#

ok lemme make this clear

#

i don’t know if it updated or not

#

there’s no reason it should’ve

heavy patrol
#

Check on the tv

outer spruce
#

due to the ota blocker

outer spruce
heavy patrol
#

If it did a normal update

outer spruce
#

it shouldn’t have

heavy patrol
#

And u ran the cat command

outer spruce
#

misaka ota blocker

#

i already had TrollStore on it

heavy patrol
#

The blob should still be there i think

outer spruce
#

then IF it updated

heavy patrol
#

.

outer spruce
#

then it’s not that bad

outer spruce
#

true ^

heavy patrol
#

Need to jb ssh and check

outer spruce
#

the only other person

#

who uses it (that i gave permission to use it)

#

knows not to update it

#

if it ever so happened to prompt one

outer spruce
heavy patrol
#

My apple tvs that have misaka ota block

#

Still say the version properly in icloud

outer spruce
outer spruce
#

icloud reports everything correctly

#

so that means someone else was using my stuff without permission if it was ever updated

#

when i get access to the tv again we’ll just have to see if it saved the 16.1 data properly

#

IF it updated

heavy patrol
#

Also the command u ran

#

Not sure which one u ran

outer spruce
#

idk it was cat smth smth

#

i don’t feel like digging through dms to find the command

heavy patrol
#

But i had to modify it bc the normal cat command wouldnt give a proper blob

#

It would fail when converting the raw file

ionic copper
#

Just not converted

heavy patrol
ionic copper
#

luckily enough; they didn't update so the command can be modified and re-run

heavy patrol
#

Why are they saying they updated lol

ionic copper
ionic copper
#

oh @outer spruce

outer spruce
#

there’s no reason it should’ve

ionic copper
#

I was going to ask

outer spruce
#

however icloud says otherwise

#

and i can’t confirm if it did or didn’t

ionic copper
#

when you plug in DCSD to trigger DFU for the 4K..

#

how many blinks does it take until the apple tv trips?

#

or does it happen immediately?

outer spruce
#

immediately

ionic copper
#

really? so the moment you plug it in to a pc with goldeneye it just.. boom?

outer spruce
#

it’s like as if you were to throw an iphone or ipad into dfu mode normally

ionic copper
#

interesting

outer spruce
#

is that not normally supposed to happen?

ionic copper
#

the breakout board DFU takes 12 blinks whilst holding down the button

#

in order to trip dfu

outer spruce
#

damn

ionic copper
#

which i don't mind

outer spruce
#

idk i dont find it too terrible to just use dongles

#

nothing cable management can’t fix

ionic copper
#

but my DCSD doesn't trip with the breakout board installed.. maybe it's the solder job

#

I'm currently teeter-tottering between a theory of having a bad cable.. or the Apple TV mod is getting in the way

ionic copper
outer spruce
#

does any documentation specify that it happens instantly?

#

or that it is supposed to immediately trip DFU

ionic copper
outer spruce
outer spruce
#

idk how to explain it

#

when i get access and rejb the tv i can like film how it goes

ionic copper
#

I thought maybe the lights would blink or change to signify the process of DFU

ionic copper
outer spruce
#

should i test it?

#

(obviously when i have access)

outer spruce
#

kinda works

#

you plug it into a mac and it trips dfu

ionic copper
# outer spruce should i test it?

if you want. AFAIK, I'm going to make a document as to how this works with the Apple TV seeing as the applewiki has zero documents about it specifically.. including the Goldeneye pinout and voltages and how it works to DFU whilst splitting USB and ethernet

#

because the goldeneye doesn't just split the connection

outer spruce
#

i don’t have ways to measure pinout and voltages but i can test the dfu thing so at least not all is lost

outer spruce
#

based

ionic copper
#

i have the goldeneye too

ionic copper
#

and it's confirmed working because I have re-restored my 4k

ionic copper
#

not that i NEEDED to, but I wanted to test the modded ipsw

#

which worked to install trollstore without an exploit WeSmart

#

and of course, permanently block the OTA with no vpn, profiles or anything like that needed

ionic copper
outer spruce
#

seeing as recent 18.1 betas break palera1n

outer spruce
ionic copper
outer spruce
ionic copper
outer spruce
#

i know

ionic copper
#

is it worth it? no

outer spruce
#

is it funny? yes

ionic copper
#

is it a waste of time and tedious? also yes

outer spruce
#

failure rate? yes!!

ionic copper
#

are you prone to tripping over more cables than you were when just the laptop was plugged in? Absolutely

outer spruce
#

funnily enough it’s not more cables because i don’t have a laptop with a usb port

ionic copper
#

How do you not have a laptop with a port? literally every laptop has a port

outer spruce
#

like

#

a normal usb port

#

it has usb c ports

ionic copper
#

oh, usb-c

outer spruce
#

so i had to use an adapter

ionic copper
#

I'm guessing macbook 2019?

outer spruce
#

yes!!!

ionic copper
outer spruce
#

(somebody kill me)

ionic copper
#

I wonder if someone has found a hardware mod to convert usb-c to usb-a without an adapter

outer spruce
#

usb-a to usb-c!!

#

modernize AppleInternal! (why does everything go back to lightning!)

ionic copper
outer spruce
#

sigh

ionic copper
#

and to be recognized by billions of devices without the "this cable might not work.." message

outer spruce
#

the alert?

#

or was that like a whole

#

idk i’m sleep deprived fr

ionic copper
outer spruce
#

interesting

ionic copper
#

which is why the cables are the same price as the cases and screen protectors

outer spruce
#

well i do find that kind of odd, maybe i just purchase the right cables because i’ve never actually seen a message deliberately say ā€œcable badā€

ionic copper
#

9/10 it would either charge on and off or will fail to sync. Some cases, DFU would never prompt or during restore, the device would stay in recovery

ionic copper
#

you'll notice this when you plug the phone to charge... it takes about 5-8 seconds for the charge to initiate

#

this is the action of iOS checking the authenticity of the cable

outer spruce
#

interesting

ionic copper
outer spruce
#

but i do wonder is this with older devices that take a while to verify the authenticity because any cable i’ve ever tried has always just immediately worked

ionic copper
#

I believe that tool also has the extracted list from iOS that it also runs down to tell if it's MFI certified

carmine ravine
#

My Apple TV is on tvOS 12.2.1 is there a way I can update to a certain tvOS or no?

carmine ravine
ionic copper
carmine ravine
ionic copper
#

you can also save your on-board blobs and get that 12.2.1 blob

carmine ravine
ionic copper
#

it'll automatically save all the blobs mentioned above

carmine ravine
ionic copper
#

click "read device"

#

click "start"

#

profit

carmine ravine
#

This the one?

ionic copper
#

yes

carmine ravine
# ionic copper yes

How do I restore from blobs? My bad for all the questions. Was looking it up and not really finding anything

ionic copper
carmine ravine
#

Checkra1n or unc0ver? Which is better in your opinion

severe kestrel
#

Did palera1n for Apple TV released?

#

Still on 14.4 with checkra1n on 4k gen 1 🄲

midnight dune
#

could anyone help me with this?

ionic copper
ionic copper
severe kestrel
ionic copper
#

If you update, palera1n won't work well

severe kestrel
#

I see

#

So I’ll stay on 14.4 ig

#

Thank you

midnight dune
midnight dune
ionic copper
#

is it mac or windows?

ionic copper
#

and what are you trying to do?

midnight dune
ionic copper
#

you're on the right track, just don't use baseband

midnight dune
# ionic copper and what are you trying to do?

i have an apple tv HD in 14.2 and i want to update to 17.6 using delayota, but given that I used jailbreak from checkra1n i’m not able to update son i’m triying to reinstall 14.2 through future restore cause installing the firmware ipsw will fix the update error and allow me to do the delayota thing

midnight dune
midnight dune
ionic copper
#

it won't work either way

#

(palera1n)

midnight dune
#

why?

ionic copper
#

because palera1ns broken

midnight dune
#

i’ve seen it working

ionic copper
#

like what you could do... is delayota.. save the blob

ionic copper
midnight dune
ionic copper
#

where you need to restore root fs the device in order to get the jailbreak to work again

midnight dune
ionic copper
midnight dune
ionic copper
#

but again, the process is tedious

#

what tvOS are you currently on?

midnight dune
ionic copper
#

that's a good firmware

midnight dune
#

and i want to update to 17 to use tailscale exit node thing

ionic copper
#

i'd save the on-board blob for that

midnight dune
#

i supposedly have it

ionic copper
midnight dune
#

but i’d like to reinstall 14.2 to be able to update and save 17.6 blobs

midnight dune
ionic copper
#

`BuildNumber : 18K57
BuildTrain : ArcherB
DeviceClass : j42dap
FDRSupport : YES
MobileDeviceMinVersion : 1253
RecoveryVariant : Recovery Customer Install
RestoreBehavior : Update
Variant : Customer Upgrade Install (IPSW)

[IMG4TOOL] APTicket is GOOD!
[IMG4TOOL] SHSH2 contains generator 0x871fb3c28d7d469f which is GOOD for nonce in IM4M!
`

midnight dune
ionic copper
ionic copper
midnight dune
#

ok so i could skip it in the gui? or use te binary?

ionic copper
midnight dune
#

what would be the binary command? i just need to specify the shsh, ipsw and version am i right?

ionic copper
#

download, extract

#

chmod 0755 /location/of/binary

midnight dune
ionic copper
#

the binary command would be futurerestore -u -t blob.shsh2 --latest-sep --latest-baseband ipsw.ipsw --no-baseband

midnight dune
ionic copper
#

or.. you can use pwndfu

#

i find it easier with checkra1n though

midnight dune
#

ive done it with trollstore from your repo

ionic copper
#

this has nothing to do with trollstore

midnight dune
#

i used trollnonce

#

how can i do it with checkra1n?

ionic copper
#

trollnonce will not work

ionic copper
midnight dune
#

ok

#

done it

ionic copper
#

then you'd type nvram com.apple.System.boot-nonce={Generator Code OF Blob)

#

make sure the generator code is the code inside the blob

#

did you save the blob for 17.6.1?

midnight dune
#

just for 14.2

ionic copper
#

you can with blobsaver

#

what?? you can go to 17.5.1??

#

cool

midnight dune
ionic copper
midnight dune
ionic copper
midnight dune
#

yesterday

ionic copper
# midnight dune it was
[IMG4TOOL] IM4M is valid for the given BuildManifest for the following restore:
BuildNumber : 21M80
BuildTrain : StarlightG
DeviceClass : j42dap
FDRSupport : YES
MobileDeviceMinVersion : 1600
RecoveryVariant : Recovery Customer Install
RestoreBehavior : Erase
Variant : Customer Erase Install (IPSW)

[IMG4TOOL] APTicket is GOOD!
[IMG4TOOL] SHSH2 contains generator 0x1111111111111111 which is GOOD for nonce in IM4M!```
midnight dune
#

i’m facing the same error again

#

Salon:~ root# nvram com.apple.System.boot-nonce=871fb3c28d7d469f

ionic copper
midnight dune
#

Product version: 14.2
Product build: 18K57 Major: 18
Device supports Image4: true
Got ApNonce from device: 06 3d fe 7d de a2 23 40 8f 8c 92 c9 27 e5 c3 bc 4d c4 15 dd
Cleaning up...
[exception]:
what=Device ApNonce does not match APTicket nonce

code=63897668
line=975
file=/Users/runner/work/futurerestore/futurerestore/src/futurerestore.cpp
commit count=308
commit sha =9554c0068dc50e141872ced5da2bd95baa595805
Done: restoring failed!

midnight dune
ionic copper
#

nvram com.apple.System.boot-nonce=0x871fb3c28d7d469f

midnight dune
#

sorry for being so dumb

ionic copper
#

what you should do is nvram -d com.apple.System.boot-nonce=871fb3c28d7d469f

#

first

#

then the command above

midnight dune
#

ok thanks

#

gonna try

ionic copper
#

after that, nvram auto-boot=false

#

then reboot

ionic copper
midnight dune
ionic copper
#

working?

midnight dune
ionic copper
#

christ, your screens more cluttered than apple's security team when checkra1n launched

midnight dune
#

i’m devastated hahahhaa

ionic copper
#

let's take a moment to admire the laptop-hotfix-whilst-taking-iphone-photo moment

ionic copper
#

seeing as you're already on 14.2

midnight dune
ionic copper
#

but why re-restore? unless the OS is corrupt?

midnight dune
#

btw, let’s say i update to tvos 17.6.1 or 18, how could i downgrade to 14.2 if it doesn’t allow jailbreak

midnight dune
#

is a big many people experiment

ionic copper
#

at one point

midnight dune
ionic copper
#

was because checkra1n was still installed

midnight dune
#

how am i supposed to do it?

ionic copper
ionic copper
#

because the OTA has check proceedings where it double checks to make sure

midnight dune
#

what’s the removal of the jailbreak you refer to?

ionic copper
ionic copper
#

because -u is update

#

which saves jailbreak files

midnight dune
#

so i should have done it without the -u then

#

probably update process will fail again then

ionic copper
#

I use -u to keep everything in place and test out new versions of jailbreaks

midnight dune
#

i just wanted to restore the apple tv to 14.2

#

erase everything

ionic copper
midnight dune
#

and then do the delayota

midnight dune
#

btw, let’s say i update to tvos 17.6.1 or 18, how could i downgrade to 14.2 if it doesn’t allow jailbreak

ionic copper
midnight dune
ionic copper
#

It's not easy but very possible

ionic copper
#

it's on my github

#

mind you; it hasn't been updated yet, but should still work nonetheless

midnight dune
#

ok i’ll try it in the future

#

about palera1n? is it that hard to maintain that jailbreak?

ionic copper
midnight dune
ionic copper
midnight dune
#

so what’s the best tvos version and jailbreak for apple tv then?

midnight dune
ionic copper
midnight dune
#

mmm

#

i was on 14.2

#

that I installed ages ago

#

I saved the blob with the delay it’s profile installed

ionic copper
# midnight dune mmm

it's because you're using it to factory restore instead of update which is what that blob is signed for

midnight dune
#

is it what you mean

midnight dune
ionic copper
#

but good thing is, you can just use -u

midnight dune
#

but i need to restore

#

cause if i doesn’t restore it fails while updating

ionic copper
#

that's a literal restore

midnight dune
#

i’ve already tried, but i’ll do it again

#

remove checkra1n and the reset? anithing else?

#

i didn’t know what that means

ionic copper
midnight dune
#

be able to delayota to 17.5.1

#

but apple tv fails to update

#

and i need to restore from ipsw to fix it

ionic copper
ionic copper
#

then what's the error?

midnight dune
#

unless future restore have deleted that

midnight dune
#

it’s a two step process

#

crash - reboot - throws an error when step 2 is about to start

#

what can i do?

ionic copper
#

are you running checkra1n at all?

midnight dune
#

i was

#

but i just removed it

#

and now restore the apple tv

midnight dune
midnight dune
ionic copper
#

use futurerestore, do a clean restore

midnight dune
#

how?

ionic copper
#

then try the ota whilst supervised and the profile installed

midnight dune
#

i can’t without the -u flag

ionic copper
ionic copper
midnight dune
#

i’m not running checkra1n right now

ionic copper
#

as a clean restore

#

then use ota

midnight dune
#

or 17.5.1?

ionic copper
midnight dune
#

te ha i know

#

but i could update to 14.2 then with future restore right?

#

so you mean installing apple signed 13.4.8

#

and then delayota to 17.5.1?

ionic copper
ionic copper
midnight dune
#

i’m gonna try

#

can i go from 17.5.1 to 14.2 with futurerestore right?

ionic copper
#

you'd have to go to 13.4.8 first

midnight dune
#

but it’s ok, no problem with that

#

hope 13.4.8 to 17.5.1 works

ionic copper
#

reason being: downgrading the SEP on an update will error and fail

midnight dune
#

btw THANKYOU FOR ALL YOUR HELP

ionic copper
#

and that 14.2 blob is only for updating

midnight dune
#

for future times

#

how can i save recovery blobs?

ionic copper
#

there's no such 'recovery' blobs

#

you can save blobs locally to recover them

#

perhaps OneDrive

midnight dune
ionic copper
midnight dune
#

ok

#

that’s good to know

#

where can i check blobs, like you did previously

ionic copper
midnight dune
#

that’s on the ipsw right?

ionic copper
#

you can use pzb to get them

midnight dune
#

and then?

ionic copper
#

for HD 14.2: pzb -g BuildManifest.plist https://updates.cdn-apple.com/2020FallFCS/fullrestores/001-19905/DBD18749-514B-48F0-B5A3-EC4DD4E5E7CC/AppleTV5,3_14.2_18K57_Restore.ipsw

#

for other versions, just change the URL

#

then you can mv ./BuildManifest.plist ~/Desktop/BuildManifest(whatever_Version).plist

#

which will allow you to sort based on differentiation

#

I could make a script to verify quickly

midnight dune
#

now

midnight dune
somber verge
#

Hey, I’m currently attempting to jailbreak my appleTV 4K running 17.4 and I got palera1n installed on my Mac

#

How do I connect to the Apple TV that doesn’t have a usb-c port? Do I buy some form of Ethernet adapter so that I can connect the two?

vital badge
#

What cable can use to downgrade an Apple TV 4gen ?

ionic copper
ionic copper
heavy patrol
#

Shoulda just updated normally to that via pc

midnight dune
heavy patrol
#

Works on that

midnight dune
#

anyway, i don’t know why my apple tv is not capable of being updated

#

i’ve tried everything

#

restored from ipsw from pc

heavy patrol
#

Just do via pc

midnight dune
#

but then i try to update and it fails

midnight dune
#

to get 17.5.1

#

does any of you know what could be happening?

#

cause it fails when is about to enter the step 2 of updating

#

the bar doesn’t got to reach the end

#

it just throws an error saying apple tv couldn’t be updated

midnight dune
heavy patrol
#

U could still update to latest

#

And palerain still works

#

Always have that 14.x blob in case u dont like

heavy patrol
midnight dune
#

i’m updating to 17.6.1 cause i have blobs for that version, but probably it would be better to just update to tvos18? right?

midnight dune
heavy patrol
#

If u use pc u dont need to do anything

#

Just get tvos18 ipsw and update on pc

somber verge
ionic copper
somber verge
#

A2843

sick atlas
somber verge
#

oh damn

#

is there any work being done on developing one?

ionic copper
sick atlas
ionic copper
somber verge
#

so we can't use the goldeneye module to install it

#

that's what's limiting us?

ionic copper
#

makes it virtually impossible to install via hardwire unless you sideload an app

somber verge
#

Wouldn’t it be possible to solder a connector

ionic copper
somber verge
#

Ohhhh

ionic copper
#

that was the basis behind the first gen 4k, it has said lightning port that one could solder if the cables were unavailable at the time

somber verge
#

yeah fair enough

#

so we won’t be seeing a jailbreak for any newer models?

ionic copper
#

I mean, it is certainly possible if one were to not update their apple tv.. the same exploits for ios can be used in tandem for apple tv

#

the main question is: is it worth it?

#

afaik, most folks are just using apple tv jailbreaks to pirate

#

which is primarily why apple put restrictions in the AppStore for higher versions

#

and jailbreak detection

#

seeing as there's no actual user data on the apple tv

#

which eliminates the theory of the 'security' aspect unlike ios that's stupidly locked down

ionic copper
#

It does purple mode and serial shell, but won't trip my 4K in DFU

outer spruce
#

F

ionic copper
#

And also, I can DFU via solder WeSmart

outer spruce
ionic copper
#

Doing the single DFU point on the board was simple. What made it complicated was connecting the remaining individual points for usb data +/- and usb stability

outer spruce
#

idk repairing and soldering are two diff things and i can only do the first thing without messing up

ionic copper
#

Just one single wire

#

The wire is set to send 2 volts of electricity to that point on the apple tv logic board which then, sends the apple tv to hardware update mode

#

This all happens by holding down a button as the device powers on

outer spruce
#

interesting

ionic copper
quasi glade
#

I bought both a DCSD and a GoldenEye adapter on ebay and they took like 3 weeks to arrive

#

they do work at least although my DCSD cable only seems to kick the TV 4K into DFU in one direction than both

trim wagon
#

looks like latest homepod version bricks homepod minis lmao

#

i wonder what happens if they actually brick ATV4Ks

#

free replacement hopefully lmao

ionic copper
ionic copper
# trim wagon free replacement hopefully lmao

This shouldn't be a thing. I am grateful that they're replacing the device but wouldn't it be more economically viable from a higher up company to at least allow the users to fix their own devices?

#

I do however wonder what Apple does to remedy said bricked devices? Do they restore them and resell as refurbished or is it recycled or are the chips taken out but the other parts placed in other devices?

ionic copper
outer spruce
#

yes iirc

ionic copper
#

Yeah, mine says HWTE

ionic copper
#

No wonder DFU didn't work

outer spruce
#

tragic

quasi glade
#

mine says HWTE and does kick into DFU

ionic copper
#

This is some jailbreak inception shenanigans

quasi glade
#

it gets unusually warm while connected though

ionic copper
#

Mine just lights up

quasi glade
#

it only works on that Apple TV though

#

it didn't kick my SE 3rd gen into DFU (although I have no idea if it's meant to work there)

#

it does charge it

#

ouch

#

I had to discover mine is proper dead

#

iBEC always takes too long and I have no idea if the board is damaged

#

at least I couldn't see anything obvious

#

I dunno how possible it is to actually kill the storage on an Apple TV though

ionic copper
quasi glade
#

it's my only guess yeah

#

the processor seems to work and video output is fine too

#

I doubt even sending anything iBoot related would work if the RAM was damaged so I assume something about its NAND is damaged

#

it always fails when it gets to booting iBEC

#

after sending it takes like a full minute to show any image and then fails APTicket/APNonce stuff

#

I got it damaged and it looked unopened so god knows what happened to it

#

I don't know where to even start with diagnosing this

ionic copper
#

Without taking it apart though, checkm8 can brick it

quasi glade
#

damn

ionic copper
quasi glade
#

I did try 17.2 and 18.0

#

both failed

#

17.2 made it to iBEC and 18.0 lacks dumped keys I think

ionic copper
quasi glade
#

they weren't on the apple wiki I think

#

I dunno if that's where futurerestore gets its key JSON files from though

ionic copper
quasi glade
#

I never figured out how to get them off the device but I do have ones downloaded for 17.2 and 18.0

#

I've never seen this one function

ionic copper
quasi glade
#

yes I did this

ionic copper
#

you'll just need to provide the buildmanifest from the otas

quasi glade
#

yes

ionic copper
#

then I use -Z with the build ID

ionic copper
quasi glade
#

yeah

ionic copper
#

cat /dev/rdisk1 | dd of=dump.raw bs=256 count=$((0x4000))

analog elk
#

hi - repost from main jailbreak channel:

I recently got a Apple TV A2737 model - it has no USB, has WiFi and I've successfully sideloaded only 1 app on it - Misaka 5.3 (but this crashes upon running).
My question is - given the recent palera1n update a few days ago - is there a way to jailbreak my model? (I also have a macOS which is now paired with the Apple TV) or am I stuck with sideloading? (which also doesn't completely work)
In reality I would only like to get KODI up and running on the Apple TV or uYou+ and a web browser then I'd be a happy chappy but if it needs to be jailbroken - I am open to this too.
If anyone can assist in any way, shape or form - I would be really greatful.
Thank you 🫔

stone canyon
#

Say I can to help for apple web with my jb?

ionic copper
#

What tvOS is it on?

ionic copper
analog elk
analog elk
ionic copper
analog elk
#

I.e. wasn't sure what I was doing 😭

analog elk
ionic copper
analog elk
#

I see

#

Thank you šŸ™ for your help - really appreciate it

ionic copper
#

I'm finding the common issue is: Old apple tv 4k: need cables to jailbreak - don't want to spend money/bricked - need to buy another
new apple tv: can't jailbreak it, cables don't work.. gotta sideload

midnight dune
#

Hi! I've finally jailbroken my AppleTV HD on tvOS 17.6.1 thanks to @ionic copper and @heavy patrol. Im really thankful for that šŸ˜‰

By the way, does anyone knows how to install TrollAppsTV? and what repos to add to PurePkg or repos for TrollStore ipas? I've done a bit of a research but i didn't found anything interesting

ionic copper
#

TrollStore won't work and trollapps are only for iOS

midnight dune
#

so cannot use trollstore? on that version?

midnight dune
midnight dune
# ionic copper Where?

where’s there’s no ipa but they talk about it on twitter and they have the repo so i supposed it was in the base IOS ipa

ionic copper
#

Nah

midnight dune
#

btw, cannot ssh into the appletv, pass isn’t alpine anymore?

ionic copper
#

You can, just log in to mobile

midnight dune
#

ohhh not root ok

#

that’s why they ask you for a sudo pass

ionic copper
#

Because tis rootless

midnight dune
#

the best way to install ipa files? on tvos 14 I occasionally used appinst

#

is there any better way?

ionic copper
#

TrollStore

#

What app are you installing?

midnight dune
#

some like games, kodi...

#

i do know how to install .deb apps (I assume its with the dpkg -i ...) but i dont know how to install .ipa files (i used to use appinst cli on tvOS 14)

#

I'm on 17.6.1? does trollstore works?

ionic copper
midnight dune
#

i thought it wont work on that os version

ionic copper
#

just not persisting

midnight dune
#

ohhh yeahh so only while jailbroken

#

and about that rootfs thing you told me some days ago... if the apple tv restarts do i need to do anything or just re-jailbreak?

ionic copper
midnight dune
ionic copper
midnight dune
lavish copper
#

Apple TV upgraded to ios18 last night without me knowing - luckily I have a older apple tv hd and it palrine worked POG

lavish copper
ripe summit
#

Hi all, about to install TrollStore on my first gen AppleTV 4k running tvos 16.3, anything to keep in mind while following the instructions?

earnest grotto
#

does palera1n work on ATV HD on 18.0?

gritty hamlet
#

it should

earnest grotto
#

my HD isn't on 18 yet

ionic copper
ripe summit
ionic copper
ripe summit
ionic copper
ripe summit
#

Could you perhaps give me a bit more relevant steps please? šŸ˜…

ionic copper
ripe summit
#

So am I left with jailbreak first and then trollstore?

ripe summit
#

I could swear the GitHub said up to 16.6 is supported

ripe summit
ionic copper
vital badge
#

Can I jailbreak a Apple TV first gen 4K?

compact dagger
lone loom
#

I can’t seem to get futurerestore to work properly, I saved blobs using Blob Saver. The other blobs I have for other devices work so I think the blobs are valid.

When I try to start it initially I was getting an exception APTicket can’t be used with this restore, I tried it with 2 versions and both of them gave me the same error (version match blobs). I was also getting a IM4M signature is not valid.

I tried another copy of FutureRestore and segmentation fault with my options listed.

I’m trying to futurerestore an Apple TV 4 HD. From 14.6 to 17.0 (16.6 if it can’t be done, since I just want to be able to use Troll Store)

ionic copper
#

as long as you have the proper blobs for the proper device

#

also, what configuration did you use for the blob saver?

#

you can.. save 17.2 blobs as of right now. If you give me you ECID, I can save it

lone loom
#

I have blob saver automatically saving blobs, it checks it weekly and downloads them to my computer

#

The problem is I’m trying to restore to 17.0 so I can use updated apps and use trollstore

#

But for some reason futurerestore keeps spitting out an error that I can’t use the blobs I saved with the restore file

#

Is there a specific compiled version that someone has used to successfully futurerestore with?

#

If someone has one I can try then I can verify if my blobs are valid or not or if it was just the copy of FR I was trying to use.

vital badge
#

?

ripe summit
#

Yeah would also like to know how to do it without a cable

ionic copper
vital badge
#

How Can i jailbreak my Apple TV 4K whitout a cable

cyan quiver
#

What is the benefit to jailbreaking Apple TV

ionic copper
vital badge
#

It has no Port

unreal sand
vital badge
#

I cant jailbreak it ?

#

it dont work at all

vital badge
#

Golden Eyecable ?

ionic copper
compact dagger
vital badge
trim wagon
#

it's the third or fourth message

ripe summit
trim wagon
#

yep

vital badge
ripe summit
#

Thankfully I only bought my 4k apple TV for 5e šŸ˜‚

vital badge
compact dagger
#

Why would someone need 9x Siri Remotes without having 9x Apple TVs all without remotes

trim wagon
#

9 bricked ATVs :)

vital badge
#

Is there a a10 hd Apple TV ?

ionic copper
ionic copper
vital badge
ionic copper
#

also, is this 4k even the first gen?

vital badge
#

I have the money but

ionic copper
vital badge
ionic copper
vital badge
#

And Its relly cheap

lone loom
ionic copper
#

blobs hold no sensitive info

lone loom
#

Well more of I thought it might clutter the group but ok

ionic copper
lone loom
#

2

ionic copper
#

that's fine

ionic copper
# lone loom

16.6: ``[IMG4TOOL] IM4M signature is verified by TssAuthority
[IMG4TOOL] IM4M is valid for the given BuildManifest for the following restore:
BuildNumber : 20M73
BuildTrain : ParisG
DeviceClass : j42dap
FDRSupport : YES
MobileDeviceMinVersion : 1400
RecoveryVariant : Recovery Customer Install
RestoreBehavior : Erase
Variant : Customer Erase Install (IPSW)

[IMG4TOOL] APTicket is GOOD!
[IMG4TOOL] SHSH2 contains generator 0x1111111111111111 which is GOOD for nonce in IM4M!``

#

17.0: ``[IMG4TOOL] IM4M signature is verified by TssAuthority
[IMG4TOOL] IM4M is valid for the given BuildManifest for the following restore:
BuildNumber : 21J354
BuildTrain : Starlight
DeviceClass : j42dap
FDRSupport : YES
MobileDeviceMinVersion : 1600
RecoveryVariant : Recovery Customer Install
RestoreBehavior : Erase
Variant : Customer Erase Install (IPSW)

[IMG4TOOL] APTicket is GOOD!
[IMG4TOOL] SHSH2 contains generator 0x1111111111111111 which is GOOD for nonce in IM4M!``

lone loom
#

ok, so they are correct...

#

these can't be used to upgrade right?

ionic copper
#

they are, but here's the thing: you cannot upgrade, only erase

lone loom
#

ah that might be it then

ionic copper
#

which isn't bad... you just lose your apps and settings

lone loom
#

didn't know there were 2 separate ones for upgrading erasing...

ionic copper
#

which is on-board

#

or using the apple tv 4K

lone loom
#

oh?

#

can i pull the blobs still? or is it too late?

ionic copper
#

but blob saver doesn't save ota blobs as effeciently

ionic copper
#

at least apple tv has no user data

lone loom
#

sorta does, I'm logged into someone else's account as well for Apple TV sub haha

#

hmm ok i'' look up how to pull onboard blobs to see if i can update to 17.0

#

unfortunately 1conan's tssaver has 2 files but they are 0 bytes

ionic copper
lone loom
#

no I'm on 14.4.6

#

err 14.6

#

ah it's only for currently installed version?

ionic copper
#

you can still get to 17

#

you just start fresh

lone loom
#

ah alright

#

oh well

#

I guess after I install 17 I should pull blobs again so I can use update in the future?

ionic copper
lone loom
#

well first things first is I'll be updating to 17.0

#

to at least use trollstore

#

hmm ok, so I think my copy of futurerestore is not working with the ATV... I keep getting:

IM4M signature is not valid!
Cleaning up...
[exception]:
what=APTicket can't be used for this restore

ionic copper
#

1 what version of futurerestore are you using?

#

and 2 what commands are you using?

lone loom
lone loom
ionic copper
lone loom
#

v2.0.0(e7abce113e1b98e126eff0e77fa3a002b99a195a-332)

ionic copper
ionic copper
lone loom
#

latest baseband? but there's no baseband on apple tv right?

#

also is this not the proper github? futurerestore/futurerestore/

lone loom
ionic copper
#

can i get the full log?

ionic copper
lone loom
#

USB-c to USB-A with a usb-c adapter

#

my MBP is only usb-c

ionic copper
lone loom
#

I know the adapter works, because I used it with lightning-USB-A and futurerestore worked

#

should I use C-to-C?

ionic copper
#

no, use another computer

lone loom
#

uhhh....

#

oh wait i have an old MBA... that has USB-A ports

#

would that work?

ionic copper
#

but did you also set the nonce?

lone loom
#

I did by SSH with checkra1n

#

then disabled auto-renew just in case I had to keep restarting the thing (which I have)

ionic copper
lone loom
#

before yes but not the last try

lone loom
#

I got the same error

#

using the macbook air

#

with --latest-baseband setting I get:

[Error] futurerestore: failed with exception:
[exception]:
what=Could not get BasebandFirmware path

ionic copper
#

with latest on both

lone loom
#

ok, so --lastest-baseband --latest-sep --no-baseband

#

like this?

#

still same error

ionic copper
ionic copper
lone loom
# ionic copper You could.. Do a pwned restore..

[IMG4TOOL] failed to verify IM4M signature with error:
[exception]:
what=assure failed
code=12910610
line=197
file=ASN1DERElement.cpp
commit count=202
commit sha =e1c37d6ce8c629ca9669efc9cb5b5f7d6810ed30
IM4M signature is not valid!
Cleaning up...
[exception]:
what=APTicket can't be used for this restore

#

Strings used: --no-baseband --latest-sep --use-pwndfu

ionic copper
#

Then --skip-blob

#

Gaster pwn

#

Gaster reset

cyan veldt
#

nevermind, restoring

ionic copper
cyan veldt
#

I was going to ask your help with futurerestore, but I got it restoring. although it is failing once restore is done

#

am trying it again

#

do you mind if I DM you about it?

#

is there a specific build of futurerestore for A10?

ionic copper
lone loom
#

It finally went through!

#

thank you

ionic copper
#

unless you just kept doing it like trying to convince a toddler to eat their veggies until they buckled down

lone loom
#

Now I need to figure outbhow to install troll store… but looking at everything I might need to pull on board blobs so I can use upgrade

#

Then downgrade and upgrade back…

ionic copper
stiff stone
#

Any apps released that may be worth using?

lone loom
lone loom
#

darn thought i might be able to us method 2 without going through futurerestore agan... but maybe not

vital badge
#

how can sideloud to apple tv 4k first gen

#

?

#

Ā«

leaden geode
vital badge
#

macos

#

over wifi

#

have i to somepfing whit xcode?

leaden geode
timid spindle
#

comand line no Blobs Appletv4 futurerestore thanks

leaden geode
#

i'm not that experiances with apple tvs

timid spindle
#

AppleTv 4 hd in pwndfu futurerestore no blobs command thanks

ionic copper
leaden geode
ionic copper
timid spindle
#

no blobs 17.0 tvhd 4 I am with pwndfu in fiƱuturerestore thanks

hollow ivy
#

Hi, I was wondering what the state of tvOS shenanigans is atm, specifically for tvOS 16.6, on a 4th gen Apple TV. Reason being, I’ve seen what has happened on iOS 16 with trollstore, misaka (tho not a fan tbh), KFD exploit based apps, etc.

#

So I was wondering if I could install Trollstore on my Apple TV, jailbreak it perhaps (though with what I’ve heard about pailra1n I’m not sure I will), and perhaps something else if I’m missing it

ionic copper
#

And you can install TrollStore from my repo

hollow ivy
#

You happen to have it on hand? Asking as I’m on mobile, if you don’t no worries I’ll just Google it later when I’m on my desktop

hollow ivy
#

Thanks Zenzeq :)

vital badge
ionic copper
vital badge
#

maybe

ionic copper
vital badge
#

Only whit trollstore ?

ionic copper
vital badge
#

Whats whit The Minecraft Apple TV edition

vital badge
#

@ionic copper

leaden geode
#

Is this a normal minecraft ipa or the one for the appletv version

hollow ivy
#

Since when does Minecraft for the Apple TV exist uhh

ionic copper
#

Email leak

#

And what you've downloaded is piracy

vital badge
#

When it down exist in the first place?

ionic copper
#

Okay, where did you get it from?

vital badge
#
  1. Bought the game
ionic copper
#

How? It hasn't been on the store in years

vital badge
#

On my dead Apple TV 4?

ionic copper
#

Don't know how it died if you were able to jailbreak it

vital badge
#

It was around iOS 8-10 idk

ionic copper
#

You're making less sense but okay

vital badge
#

I can’t download it in the store anymore

ionic copper
#

Exactly my point

vital badge
#

but I want to play Minecraft on my Apple TV 4K

#

I already ordered the cables

ionic copper
#

Okay?

vital badge
ionic copper
#

You can do that with the cables

vital badge
#

They come in 14 days i live in Germany Bro

ionic copper
#

Okay, what's the hurry?

lone loom
#

So I want to try and use the SSHRD method to install trollstore but following the guide on Reddit what should I use instead of Tips since there is no tips app

ionic copper
lone loom
ionic copper
#

You just use SSHRD then follow the rest in method 1

lone loom
#

Can you install persistence helper if you jailbreak first?

ionic copper
lone loom
#

Kinda need and ELI5 guide because I’m so confused reading it

#

But jailbreak with palera1n, add repo install trollhelper seems much more straightforward

#

But I need to se what options are available for persistence helper through trollstore

ionic copper
#

sshrd.sh (link to hd ipsw) 15.5

#

sshrd.sh boot

#

then just transfer persistence helper

lone loom
ionic copper
#

it's right there.

lone loom
#

I meant the sshrd commands, the message you sent just now is the first seeing that command that’s why I couldn’t figure it out

ionic copper
#

but this is for misaka.. you'd install it in /Applications/whateverapp.app

ionic copper
lone loom
lone loom
#

Ok

#

Now it makes more sense

#

I’ll try

lone loom
#

hmm I get an error when launching SSHRD

#

I ended up just doing ./sshrd 17.0 as the command

#

ownload succeeded
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Now you can boot untrusted images.
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Now you can boot untrusted images.
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
Version: 26bee8a5fe80f874a590b776da450cac62c01328-26
main: Starting...
iOS 17 iBoot detected!
getting get_sigcheck_patch() patch
main: Error doing patch_rsa_check()! (img4interposercallback couldn't find branch for ret2!)
[-] An error occurred

lone loom
#

I just got in with 17.5

#

and then it just restarted on me

#

ah nevermind it panicked

#

I'll try 15.5

#

ok so it looks like it went through, but it's now just flashing the light in the front, and nothing on the screen

#

apple configurator doesn't show it either

lone loom
#

ok I think I'm in

#

I ran ssh, then mount_filesystems

lone loom
#

when I run "find / -name airbnb" I get an error

#

localhost:~ root# find / -name airbnb
find: /mnt2/mobile/Library/Caches/com.apple.amsengagementd.classicdatavault: Operation not permitted
find: /mnt2/mobile/Library/com.apple.nsurlsessiond: Operation not permitted
find: /mnt2/mobile/Library/com.apple.internal.ck: Operation not permitted
find: /mnt2/mobile/Library/CoreDuet/Knowledge: Operation not permitted

#

yeah I can't see where the apps are located, I've also used Cyberduck to view the mounted folders but I don't see anything

ionic copper
#

Just go to Applications and overwrite fitness.app

lone loom
#

I thought I could overwrite any downloaded/sideloaded app

lone loom
#

So do I rename persistence helper to bundle.app and replace the folder?

vital badge
#

Have someone tryd to install Fortnite on Apple TV 4K?

#

Over trollstore ?

ionic copper
ionic copper
neon estuary
#

is there a ipa installer for tvOS?

leaden geode
ionic copper
#

either the cable is borked or the 4k is.. dunno

outer spruce
#

mines working troll

leaden geode
#

Sounds familier, i saw it somewhere

#

Update: I'm wrong, ALEX is just the "code name" if you will for the DCSD cable. https://theapplewiki.com/wiki/DCSD_Cable

The Apple Wiki

The DCSD Alex cable is used in factories to communicate over serial to run tests and write to the SysCfg (for serial definitions, etc) during production. These cables are produced by ShenZhen Alex Connector Co., Ltd. in China. They can be purchased from obscure markets. There are two known types of DCSD cable. An older one, with lights and only ...

ionic copper
outer spruce
#

i don’t know

#

if you want i can like

#

record it

#

later

ionic copper
#

sure

ionic copper
neon estuary
lone loom
#

I really can't seem to do this....

#

Used command in terminal:
scp -P 44 /Users/qong2/Downloads/TrollstoreTV/Podcasts root@localhosts/mnt1/Applications/Podcasts.app/Podcasts

ssh: Could not resolve hostname localhosts: nodename nor servname provided, or not known

lost connection

#

tried with -P44, turned on "iproxy 2222 22"

#

then tried with -P 2222

#

tried using localhosts:2222

#

always not found

#

I tried mounting filesystem, logging in with Cyberduck, and overwriting the file there

#

when I restart the ATv it just goes back to the regular podcast app

ionic copper
lone loom
#

i've tried all ports

#

44, 22, 2222

#

no matter what it didn't work

ionic copper
#

You need to make 2 terminal windows

#

One is iproxy 2233 44

#

The second, use Ssh to port 44

#

If that doesn't work, change iproxy to port 22

lone loom
#

2233?

#

ok

ionic copper
#

Then ssh to port 22

lone loom
#

mount filesystems first?

ionic copper
#

You can't mount filesystem unless you ssh first

lone loom
#

i use ./sshrd.sh ssh

#

and it brings up a root terminal

#

but I can't copy things from the computer there

ionic copper
lone loom
#

ssh -p 44 localhost
ssh: connect to host localhost port 44: Connection refused

#

so far only boot

#

and then iproxy 2233 44

#

now trying ssh but not connecting

ionic copper
#

If 44 doesn't work, 22 will

lone loom
#

so run iproxy 2222 22 ?

ionic copper
#

No

lone loom
#

ssh -p 22 localhost
ssh: connect to host localhost port 22: Connection refused

ionic copper
#

You use sshrd to boot

lone loom
#

I did

ionic copper
#

Then run iproxy 2233 22

#

Then ssh in to 22

lone loom
#

what's my server ip?

ionic copper
#

Localhost

lone loom
#

I'm connected by USB

#

ssh -p 22 localhost
ssh: connect to host localhost port 22: Connection refused

ionic copper
#

Bruh you got the command wrong

#

ssh -p 22 root@localhost

lone loom
#

ssh -p 22 root@localhost
ssh: connect to host localhost port 22: Connection refused

#

iproxy 2233 22
Creating listening port 2233 for device port 22
waiting for connection

ionic copper
#

Unplug usb, replug

lone loom
#

ok

ionic copper
#

If iproxy says nothing and yet ssh refuses, means usb isn't connecting

#

Because for ssh to refuse, iproxy would be going off with a connection attempt

lone loom
#

I can connect to 2233 for 22

ionic copper
#

Okay, as long as you're in ssh

lone loom
#

ssh -p 2233 root@localhost
The authenticity of host '[localhost]:2233 ([::1]:2233)' can't be established.
ECDSA key fingerprint is SHA256:lb9y8xaKPkXl5gUgA+WHH5TbDlRwWZ6Io7BBLbX+PuE.
This host key is known by the following other names/addresses:
~/.ssh/known_hosts:2: [localhost]:2222
~/.ssh/known_hosts:3: [127.0.0.1]:2222
Are you sure you want to continue connecting (yes/no/[fingerprint])?

ionic copper
#

Yes

lone loom
#

New connection for 2233->22, fd = 5
waiting for connection
Requesting connecion to USB device handle 458 (serial: ramdisk tool Aug 14 2022 11:28:57), port 22

ionic copper
#

You have to type yes for that question

lone loom
#

I did

#

I was just copying what iproxy was showing

ionic copper
#

Okay and did it ask for a password?

lone loom
#

yes

#

did alpine

ionic copper
#

So then you're in

lone loom
#

now i"m in as localhost:~ root#

ionic copper
#

Then you mount filesystem

lone loom
#

ok so "mount_filesystesm"

ionic copper
#

Yes

lone loom
#

ok

#

next I"m doing "find / -name podcasts.app"

ionic copper
#

Then in a third terminal window, run the SCP command on port 22

lone loom
#

find / -name podcasts.app
find: /mnt2/mobile/Library/Caches/com.apple.amsengagementd.classicdatavault: Operation not permitted
find: /mnt2/mobile/Library/com.apple.nsurlsessiond: Operation not permitted
find: /mnt2/mobile/Library/com.apple.internal.ck: Operation not permitted
find: /mnt2/mobile/Library/CoreDuet/Knowledge: Operation not permitted

ionic copper
#

You don't need to find it, it's in /Applications

#

Or mnt2 I think

#

Probably ls /mnt2/Applicatons

#

You'll find podcasts

lone loom
#

p: root@localhost/mnt2/Applications/Podcasts.app/Podcasts: No such file or directory

#

cp: root@localhost/Applications/Podcasts.app/Podcasts: No such file or directory

ionic copper
#

Odd

#

Bruh.. Did the command wrong

lone loom
#

scp -P 22 /Users/qong2/Downloads/TrollstoreTV/Podcasts root@localhost/Applications/Podcasts.app/Podcasts

ionic copper
#

Yeah, it's wrong

#

scp -P 22 /Users/qong2/Downloads/TrollstoreTV/Podcasts root@localhost:/Applications/Podcasts.app/Podcasts

lone loom
#

ssh: connect to host localhost port 22: Connection refused
lost connection

#

iproxy still running