3 ms·
That was me. The iPod 4G was very similar to its predecessors. The software was stored on the internal drive, kind of like the MBR of a PC. In addition, the iP
by nilss 3y ago
That was me.
The iPod 4G was very similar to its predecessors. The software was stored on the internal drive, kind of like the MBR of a PC. In addition, the iPod had a mode where it would act as a regular USB storage device (or firewire). That firmware was stored in a flash. Even with a blank drive the USB storage mode was always accessible. This made this whole hack somewhat safe.
With custom code put at the correct offset with some magic numbers in the right places the iPod would start executing code from the first sectors of its drive. This was just a dd if=mycode.bin of=/dev/sdb, so no exploit or anything special was needed. A few people on the #ipodlinux channel helped me with C and creating position-independent binaries without any external libraries. I had some experience writing a toy OS in assembler on x86 which came in handy.
The piezo was controlled by writing to some memory addresses. Someone else already figured that out. I toyed around with various values until I had two distinct noises, one for 0 and the other for 1. Then I write code for loop over a memory region one bit at a time while the piezo played either of those noises. I had audacity (an audio recorder) open on my computer and just started recording using a cheap dynamic microphone. The decoding software was embarrassingly stupid but I had no clue about signal analysis in 2005. It would have been possible to use a modulation method to speed up the process quite a lot. I opted for a compression algorithm instead.
I think I tried different memory regions until I found one that started with data that looked like ARM opcodes. When I found that region the final dump took a few hours over night.
After sending the extracted binary over to the other devs we had a kernel running not much later.
This project taught me a lot: ARM assembler, C, SDL (for visualization), sox (audio processing tools) and patching/porting the linux kernel for new hardware. It also got me job offers from a few big companies but I did not take any of them as I had different plans already. I kept on hacking and contributing to various open-source projects over the years, spent way too much time on hyper-optimizing crypto mining algorithms, and eventually got back to hacking more meaningful code again. Basically, my career after this hack has been almost exclusively open-source projects.
- Emigre_ 3y agoWow, man, it's really impressive. Fascinating. Hats off, sir. : )
- pyinstallwoes 3y agoHow did you support yourself financially with a career of mostly open source? Fascinating story. Very good anecdote of just doing it and learning. Thanks!
- sandreas 3y agoGreat work, thank you. Till today, I use the "unhackable" iPod Nano 7g. I collected a ton of information what would be needed to hack it, but unfortunately, I did not have the time. In case you are interested in getting functional / non-functional devices to experiment, reach out on https://pilabor.com https://pilabor.com (I'm from Germany). My plan was to desolder the 16GB flash chip (it's LGA60) and try to reprogram it with a device like this: https://de.aliexpress.com/i/32951067630.html https://de.aliexpress.com/i/32951067630.html Maybe soldering it back on the iPod with this in between to debug / reprogram faster: https://de.aliexpress.com/item/32844952323.html https://de.aliexpress.com/item/32844952323.html Old iPhones (I think the 5s has the same LGA60 Nand) can be reprogrammed with a JC Pro 1000S Programmer, but they don't have a setting for iPods AFAIK. So maybe with a lot of effort it would be possible to use it to reprogram a Nand Chip having an Apple Serial No. There also was a project called Nand-AID (https://www.timeextension.com/news/2023/04/modder-is-resurrecting-dead-wii-u-consoles-with-the-free-nand-aid https://www.timeextension.com/news/2023/04/modder-is-resurre...) providing a microSD-Card replacement for dead nands on the Wii U consoles. Sounded interesting to try on the iPod Nano 7G :-) lemonjesus (https://github.com/lemonjesus/iPodBluetooth https://github.com/lemonjesus/iPodBluetooth) created a bootloader Hack for the iPod Nano 3g enabling him to use a bluetooth device. He also made a youtube video about it. But I never got into it too far. I just found out that milling out the backplate of an iPod Nano 7g can fit an iPod Mini 600mah battery and make it "replaceable" without opening the device again - so as long as the Nand does not die, I'll keep using my iPods :-) The next device I'm planning to buy is the HiBy M300. It's way bigger but runs Android 13 and is a real DAP.
- q3k 3y ago> Till today, I use the "unhackable" iPod Nano 7g. CUB3D recently got code execution on n6g/n7g via a freetype 1day (comex's star vuln/exploit, after using another bug which allowed disabling resource partition checks). https://github.com/CUB3D/ipod_sun https://github.com/CUB3D/ipod_sun
- sandreas 3y agoThis is great news, thank you for pointing this out. I'll transfer that knowledge to the rockbox community, if they don't know. Maybe someone is willing / has time to do the work. I unfortunately can't (2 kids, 2 jobs...).
- Solvency 3y agoWhat are these "magic numbers"? How'd you find them? Why is that detail so vague...
- kalleboo 3y agohttp://www.ipodlinux.org/Firmware.html#Firmware_Partition_format http://www.ipodlinux.org/Firmware.html#Firmware_Partition_fo...