Results

See more...

How to Use Redsn0w as iREB Alternative in Mac OS X to Put iPhone in Pwned DFU Mode?

To jailbreak your iPhone, iPod Touch or iPad using custom IPSW, you must use iREB to pwn your iBoot so that it may accept the custom IPSWs without throwing any restore error. Restoring custom IPSW without iREB usually results in 1600, 1601, 1602, 1603 or 1604 error. To bypass these errors on Windows, the best possible solution is to use iREB but unfortunately iREB is not available for Mac OS X. This guide will teach you how to use Redsn0w as an iREB alternative in Mac to put your iDevice in pwned DFU mode.

NOTE: First i used this method to put my iPhone 4 in pwned DFU mode to restore iOS 4.3 custom IPSW created with PwnageTool bundles and then i used it again to downgrade my iPhone 4 firmware from iOS 4.3 to iOS 4.2.1. In either case i didn't even got a single 16xx error. This guide is applicable to iPhone 4/3GS/3G, iPod Touch 4G/3G/2G & iPad.
Redsn0w (Main)

Steps to Put iDevice into Pwned DFU Mode Using Redsn0w:

  1. Download Redsn0w 0.9.7b6 for Mac from here | Mirror
  2. Download stock iOS 4.2.1 IPSW for your iPhone, iPod Touch or iPad from here
  3. Launch Redsn0w 0.9.7b6 and click on Browse button.
  4. Choose stock iOS 4.2.1 IPSW for your iDevice and click Open button.
  5. Redsn0w (Select IPSW)

  6. Wait while Redsn0w verify your firmware file.
  7. Redsn0w (Processing Firmware)

  8. When Redsn0w echos IPSW successfully identified message, click on the Next button.
  9. Redsn0w (IPSW Successfully Identified)

  10. Now Redsn0w will patch the kernel of provided IPSW.
  11. Redsn0w (Patching Kernel)

  12. When Redsn0w shows you the jailbreak options as shown in the screenshot below, choose Just enter pwned DFU mode right now and click on the Next button.
  13. Redsn0w (Select Pwned DFU Mode)

  14. Plug your iDevice to your Mac and turn it OFF completely by pressing the Power button.
  15. Redsn0w (Prepare for DFU)

  16. Now put your iDevice into DFU mode using the following instructions:
  17. Redsn0w (Instructions for DFU)

    • Hold down the Power (corner) button for 3 seconds.
    • Without releasing the Power button, also hold down the Home (bottom center) button for 10 seconds.
    • Without releasing the Home button, release the Power button BUT KEEP holding the Home button for 15 seconds until Redsn0w detects your iDevice in DFU mode.
  18. Now Redsn0w will patch the iBoot of your iDevice using Geohot's Limrea1n exploit.
  19. Redsn0w (Exploiting Limera1n)

  20. Thats! Now your iDevice is in pwned DFU mode and is ready to accept any custom IPSW file without throwing 16xx, 29 or 21 error.
  21. Redsn0w (Pwned DFU Mode)

  22. Close Redsn0w, launch iTunes and restore the custom IPSW.

Thanks to Boneless for sharing this useful tip in comments.

Contact Us for News Tips, Corrections and Feedback

Related posts

58 comments
Leave a message...

  •  
    Magnus the Red3 years, 3 months ago

    Is it possible for a carrier to make an iPhone unable to be unlocked?
    (I’ve just returned to the States from Japan and am using an iPhone from
    a Japanese carrier, SoftBank.) I do all the steps in your guide. When I
    do the ALT click (on Mac OSX), iTunes reads and extracts the NO_BB ipsw
    file, then I get the following error:”The iPhone ‘iPhone’ could not be restored. This device isn’t eligible for the requested build.”Any ideas?Using:- an iPhone 4 on the latest iOS- the latest Mac OSX- the version of RedSn0w that the dashboard links to- the latest iTunes

  •  
    Raquel Tolentino Cabello4 years, 2 months ago

    i already did the steps but the error still exist..*unknown error 1015*still my problem..im running out of idea,,please any help?
    thanks pramond

  •  
    Maria Olson4 years, 3 months ago

    You are amazing!!!!!

  •  
    joe4 years, 9 months ago

    it worked, but i can only restore it to 4.2.1, once i try to update it, it just goes into recovery mode and error 21 or 1600 show up

  •  
    michellehamm4 years, 9 months ago

    this is exactly what my phone is doing… how did you end up fixing it?

  •  
    michellehamm4 years, 9 months ago

    How long should your computer stay on screen N.11… it’s been on it for about half hour. its not my computer

  •  
    shan4 years, 9 months ago

    i got a error 11
    help

  •  
    Avikant4 years, 10 months ago

    i reset? this in the settings menu, it hanged, so i put it in DFU and try to restore it, error 3194 came and i tried to fix with any measure but it didn’t work! now it says cannot? be restored can anyone help me!

  •  
    Mika4 years, 10 months ago

    Thank You so much for clearing me my situation! Unfortunately, i’m not able to backup my device, even tho iTunes ‘sees it’ – but unable to do anything with it (i can see it, with reloading circle next to it, witch goes on and on..)

    I’m curious to know if there is any chance to somehow upload appsync 4.0 back to my device? Because i believe that is the only thing what is wrong in my iphone. Do i have any possibilites to upload appsync 4.0.deb file back to my iphone, and if i can, how to do that, in with what program?

    •  
      Pramod4 years, 10 months ago

      AppSync is merely a Cydia tweak which I suppose could be an issue due to incompatibility. Or it could be any other such Cydia app / tweak. Using a custom IPSW to restore your device with its SHSH is an option that you can try at the moment.

  •  
    Roger4 years, 10 months ago

    I have a ipt2g and don’t know it it’s an MC version. redsn0w goes thru and get hung at wait for reboot. I get the 1601 when trying to restore thru itunes. I recently got this and replaced the screen, digitizer and battery. don’t know if previous owner jailboke it. Also tried ih8snow and tiny umbrella and didn’t work. Please help.

    •  
      Pramod4 years, 10 months ago

      Go ahead & restore your device to iOS 4.2.1 via iTunes itself. You need not use any 3rd party tools either. Try a different PC as well.

  •  
    Mika4 years, 10 months ago

    I have following Problem: My beautifully working iPhone 4 (JB w/redsn0w_mac_0.9.9b5) stopped working after i smartly decided to fix something that wasn’t broken. I upgraded AppSync 4.0 to 5.0, since Cydia recommended me to do so. During installation process, i saw some reported errors on screen, but was unable to do nothing than respring after installation process. Since then i’ve been screwed and desperately looking for solution my problem w/o any luck.
    iPhone wont start, i manage to get the ‘pineapple’ logo, and my iPhoto even kind of starts (cos i can see my iPhone photos too) even tho i see just pineapple logo on screen. iTunes shows the phone too (but with a reloading circle and not access to it) but the phone won’t start.
    Putting into DFU mode doesn’t help either.

    So I tried to Jailbreak again, but it gives me an error:

    “Mounting rootfs as read-only’
    ERROR!
    AppleBCMWLANCore::handleOKitBusyWatchingTimeout(): Error, no successful firmware download after 60000 ms…

    If i try to restore from iTunes with custom ISPW, i get every time the same error message: The iPhone could not be restored. This device isn’t eligible for the requested build.

    I d/l tinyumbrella and it goes bit further now, but gives me: I Phone could not be restored. 1600 error.

    Setup: iPhone 4 w/ 5.0 iOS, redsnow untethered used as JB.
    Mac OS X Lion, iTunes 10.5.1

    Any wise help much appreciated!

    Ps. I have not tried to restore with latest firmware from Apple, cos want to keep my data & apps.

    •  
      Pramod4 years, 10 months ago

      All what you can do right now is to backup your device in anyway possible once iTunes detects it & then later restore to a custom iOS 5.0.1 instead. You can’t restore to iOS 5 anymore since Apple has long closed its signing window & hence you get the not eligible error. A re-JB would never help in getting your device out of it. :(

  •  
    Stanley4 years, 10 months ago

    I need your help to understand what I must do exactly. My 3gs iphone was jailbroken and the baseband changed
    from 05.16.02 to 06.15.00
    from version 4.3.3 to 4.1 (8B117)
    Now when I connect it to the PC I get an update message from itunes to the effect (updating to iOS 5.0.1 will back up and restore the apps, media, contacts, calendars, notes, messages and settings on your iphone). That is the message.
    My fear is that this is a jailbroken iphone and updating it using itunes may render my iphone useless again as I experienced before. Please advise what I must do, if I must update the iOS to 5.0.1
    Stanley

    •  
      Pramod4 years, 10 months ago

      You can create a custom iOS 5.0.1 IPSW using Sn0wbreeze & restore to it. But, Ultrasn0w isn’t compatible just yet on iOS 5.0.1, so won’t it be pretty useless if you update the iOS alone w/o an unlock?

  •  
    Mitxel4 years, 10 months ago

    Hi there,

    My iPhone 3G was jailbroken & unlock with iOS 4.2.1 and I upgraded the baseband to 06.15 with total success.
    I had some issues with the wifi so, I decided to reset the device to factory settings directly from the iPhone Settings menu. The iPhone never restore the system. It got stuck and had to manually shut down. I regret having done that because now every time I try to restore my device I get the error 1015 on iTunes.
    I have tried your process three times without success. I am running out of ideas. Any advice would be greatly appreciated.
    I run redsn0w 0.9.6b5 with the iPhone1,2_4.2.1_8C148_Restore.ipsw

    Thanks in advance

  •  
    Nemo4 years, 11 months ago

    Hello, I jailbroke ios5 with redsn0w 0.9.9b7, and after a few days, my phone crashed unexpectedly. i tried re-booting tethered with redsn0w and i keep getting “unexpected error”. I tried to restore with itunes and got a 1601.

    My phone is currently stuck on the apple logo boot screen and tries to restart every 60 seconds or so. i really don’t know what to do. will i be able to downgrade with redsn0w using the process outlined in this article?

    •  
      Pramod4 years, 11 months ago

      You need to first put your device into a pwned DFU mode before you proceed with the actual restore. Use Redsn0w / iReb.

  •  
    DosXchachi4 years, 11 months ago

    I was just about to thank you a billion times when at the end of the restore it gave me this error
    (1015) please help me I have been trying to downgrade for three days now
    -iphone 3gs 32 gig- new bootrom
    -running iOS 4.3.5
    -ive tried the host files and tiny umbrella
    – before i used redsnow the error message i was getting every time was 20

    please I would so appreciate it if you have any suggestions.

    •  
      Pramod4 years, 11 months ago

      Use Redsn0w 0.9.9b7’s Recovery Fix option to fix your installation right after it errors out.

  •  
    Haris4 years, 11 months ago

    Thank you million times :)

  •  
    Benedict Lewis5 years, 1 month ago

    When I do it I don’t have the option to enter pwned duf mode. PLEASE HELP!!!!!!!

    •  
      Pramod5 years, 1 month ago

      Every version of Redsn0w that was ever out has that option. Verify it once again.

  •  
    Shashwat5 years, 1 month ago

    Will this work with the ipad 2?

    •  
      Pramod5 years, 1 month ago

      No, not until a bootrom level exploit is found for the A5 processors.

  •  
    Maria5 years, 1 month ago

    Amazing! Thank you very much!

  •  
    amran5 years, 1 month ago

    I am living in Bangladesh Here is No apple store or service center. Probably My I Ipodtouch will die in a short life, Earlier my found my device turns too hot but I did not find any reason.

  •  
    amran5 years, 1 month ago

    Brother Pramod I jailbroke my Ipod touch 3G with red snow and used it for few days then my Ipod touch automatically turned to black screen while connected to My pc I tried to start it it didnt work then I tried to tethered using red snow but it stacked in in the logo screen. Now it is in Black screen. ITunes detects it in recovery mode. but while I try to restore it shows error 28.
    after jail breaking I found my device becomes very hot while paying games. Is there any problem in its Hard disk.

    •  
      Pramod5 years, 1 month ago

      Error 28 suggests of a hardware issue specific to a bad dock connector on your iPT3G. I would suggest you to take it to the nearest Apple store to get it checked. A possible issue with the hard disk as well.

  •  
    stanley5 years, 1 month ago

    Dear Pramod,
    Please let me know if there is no hope for my 3gs iphone. The situation is as follows:
    I never saved any shsh blobs when I unlocked the iphone in the first place. But changed the baseband from 05.15.02 to 06.16.00. The next time I connected it to the PC things went wrong and I cannot recall at what point exactly.

    What I am getting right now is error 3194. I have tried using hosts file but I still cannot go through. When I use TinyUmbrella I get the following in the log:
    (Cydia does not have shsh for your iphone 3gs. There is no way for you to get them. Sorry. You are just too late.)
    The iphone is still in recovery mode. What must I do? Is it too late and can I just throw away this beautiful thing?
    Please help.
    Stanley

    •  
      Pramod5 years, 1 month ago

      Do not attempt any kind of restore? Use iFaith & save the SHSH blob of your device right now. Read this http://bit.ly/qIa3E7 & save it first.
      Which iOS version was it on prior to the loop? You might want to try FixRecovery from Tiny Umbrella if you were on iOS 4.2,1/ the standalone FixRec43 if you were on iOS 4.3.3 as well once the SHSH blob is saved.

  •  
    amran5 years, 2 months ago

    I used red snow redsn0w-0.9.6rc12 to unlock ios 4.3.4 now my ipod is in black screen and it does not start and red snow crashes pls tell me what to do

    •  
      Pramod5 years, 2 months ago

      RC12 never supported iOS 4.3.4 in the first place. That’s the mistake. You need to use Redsn0w0.9.8b4 instead.

  •  
    amed5 years, 2 months ago

    i dont get the option to enter pwn dfu mode, im using the same version and have an ipod touch 2g mb model 4.2.1 What should i do?

  •  
    exskuces5 years, 2 months ago

    OMG! You saved my ASS! Rock on!

  •  
    michael5 years, 2 months ago

    i dont get the option to enter pwn dfu mode :S

    •  
      Pramod5 years, 2 months ago

      Every Redsn0w version released has that option right there. Your using Redsn0w right?

  •  
    Bill5 years, 2 months ago

    Brilliant solution thank you very much. I was struggling with errors 1600, 1608 etc when using iTunes until I found your page. So I have gone from 4.1 baseband 06.15.00 to 4.3.3 and then an untethered jailbreak using the new Jailbreak 3.0. (I have just downloaded Fring and it works perfectly on my wifi).

  •  
    Bluedog5 years, 5 months ago

    I’ve been trying to use your method to restore ANY IPSW to an iPod Touch 2G that I believe is an MC version. The Redsn0w you link to says it does not yet support the MC model, and if I say it is NOT an MC it goes through its motions but doesn’t offer the ‘restart in pwned DFU mode’ as an option.

    My issue is, this iPod doesn’t have any current firmware thats loaded and usable. It was likely corrupted when someone tried to update a firmware with bad software or such. It only boots into DFU mode or ‘recovery mode’ according to some software I’ve used but in that mode its simply a white screen. Some RedSn0w versions will do everything in the pwning process including and up to the loading of the final ramdisk and then bails to the white screen.

    Any suggestions?

    •  
      Wolverine5 years, 5 months ago

      Have you saved SHSH blobs of any firmware in past? If yes then restore STOCK IPSW (No iREB or TU required) of the firmware for which you have saved your SHSH blobs. Just incase you have not saved any SHSH blobs, restore stock iOS 4.2.1 IPSW to kick your iPod out of recovery mode loop.

  •  
    Ann5 years, 5 months ago

    Hi,

    When doing the last step, should I restore 4.3.1 custom IPSW or 4.2.1?? Great thanks for your help~!

  •  
    J Tan5 years, 6 months ago

    Thanks for this tip. iReb won’t work in a virtual machine; throws up an error. I need to upgrade to something more recent than 4.1 to see if bluetooth disconnect issues are resolved.

    TinyUmbrella throws up the 1601 error too with 4.2.1 firmware. Their FixRecovery just dumps a bunch of files in my Applications and root directory of my Mac. This is the only way I’ve seen that gets to the Apple progress bar on the iPhone 4 that skips the 1601 error on iTunes.

    Update: Now that the restore has finished, I can testify this method works. I finally have 4.2.1 on my iPhone 4 using SHSH from Cydia.

    •  
      Wolverine5 years, 6 months ago

      Thankyou T Jan for confirming and winning the confidence of visitors :)

      •  
        J Tan5 years, 5 months ago

        Wolv,

        I’m happy to report 4.2.1 also fixed the constant bluetooth connect/disconnect issues I had with my Jawbone 2 using iOS 4.1 even though 4.1 was supposed to fix those issues and that 4.2.1 didn’t indicate any fixes for bluetooth.

        Since 4.3.1 has the 1 bar display issue, I’m back on 4.2.1. Although I found a bug, don’t know if it is because of jailbreak or iOS. Turning the physical hold switch from ringer to mute over and over again will cause vibration to happen when switching to ringer and no vibration when switching to mute. Although I can’t tell whether this affected actual vibration when receiving a call.

        •  
          Maverick5 years, 5 months ago

          Yeah it is a known bug in iOS 4.3.1.

  •  
    Iscrewed in Afghanistan5 years, 6 months ago

    Didn’t work for me. still got the 1600, loaded iREB in windows, followed other instructions, still got 1600. Also seems like my phone won’t leave DFU mode, even used Tiny umbrella “fix recovery” option. Was able to run through the loops of the jailbreak afterward when the device should be restarting- I get nothing but a black screen. i was running 4.2.1 FW 3.10 before.

    I’ve previously successfully jail broken with greepois0n on the same phone. I’m at the point I just don’t care any more and want my phone back. Right now its a beautiful slab of black scree, Any advice? I’d appreciate it!

    •  
      Wolverine5 years, 6 months ago

      If you have iOS 4.2.1 SHSH blobs saved, restore stock iOS 4.2.1 using TinyUmbrella. You will not get any 1600 error. Also ur baseband is already 3.10, so you should not afraid of restoring stock iOS 4.2.1 on your iPhone.

      •  
        Iscrewed in Afghanistan5 years, 6 months ago

        Thanks for the reply!
        I do have my SHSH code saved with TU. I start the TSS server – then go to itunes and attempt to restore to iPhone3,1_4.2.1_8C148, itunes extracts the software, prompts me to continue then givers me the 1600 error. I can see in the TU logs where it receives the requests and responds with the blobs.
        TU seems to be the only tool with any kind of logging…
        The end of the log looks like this:
        Received request for [iPhone4 4.2.1 (8C148)]
        Validating saved SHSH…
        RESPONSE:
        ?xml version=”1.0″ encoding=”UTF-8″?> @ServerVersion0.6.30-b2
        Wrote TSS response
        DFU Device disconnected
        DFU Device connected
        DFU Device disconnected
        DFU Device connected

        Thanks again for the advice – at this point im willing to try anything, I cant even abandon the process and go to 4.3 because my connection here isn’t stable enough to complete the download.

        •  
          Wolverine5 years, 6 months ago

          You will never receive at 1600 error if you are really restoring iOS 4.2.1 stock IPSW. Make sure the file you are restoring has name iPhone3,1_4.2.1_8C148_Restore.ipsw and has size 624 MB. Also before restoring the firmware, put your iPhone into recovery mode. To do that, make sure your iPhone is disconnected from your PC and is powered OFF. Hold down the Home button and plug the cable into your iPhone. Do not release the Home button until iTunes detects your iPhone in recovery mode.

          •  
            Iscrewed in Afghanistan5 years, 6 months ago

            My version of the IPSW is 654 MB, but I was able to use the same file to JB the phone once before using the same file. I’ve put the phone in DFU mode (can’t seem to get it out of DFU mode actually) and itunes detects it as an iphone in recovery mode. I get the 1600 error with both the custom and original versions of the IPSW. I am able to run the jail break procedure (both GreenPois0n & RedSn0w) – but after wards – nada. When the JB completes Im left again with a black screen and phone that doesnt seem to respond to any button press combinations (other than to trip DFU mode alerts as logged by tiny umbrella)

          •  
            Wolverine5 years, 6 months ago

            That is technically and logically impossible. iREB fixes all 16xx errors and its affirmative. Just use this guide http://youtu.be/bITIiGswjFI to put your iPhone into DFU mode and this guide http://bit.ly/i9HUGL to put your iPhone into Pwned DFU mode. Once your iPhone is in Pwned DFU mode, you WILL not get any of 16xx error. Do not miss any step!

  •  
    guykggkjgiluihhu5 years, 6 months ago

    thank you one billion times:D

  •  
    j.s.5 years, 6 months ago

    It worked!!! thank you! I used this to get my ipad from tethered jailbreak state 4.2.1 to tethered jailbreak state 4.3.1

    I had modded the ipsw file but couldnt restore it onto my ipad until i followed the above steps. my error messages were 1600 and 29 but it immediately once it was put in pwned DFU mode.

    thanks guys!