See more...

NCK Brute Force Method Might Lead to iPhone 4 02.10.04, 03.10.01 Baseband Unlock [Update: 3x]

The Sherif Hashim's exploit which he handed over to MuscleNerd for iPhone 4 unlock is SIM dependent but it do gives enough information which can help hackers to crack the unique NCK (Network Control Key) from the Seczone. NCK is a cryptographic key which is used by phone to access required cellular network and Seczone is the area of baseband where NCK is stored.

Crack NCK for iPhone 4 Unlock

@toromand 40 bits brute force is trivial if you can get your NOR and SGOLD chip IDs via current vulnerabilities

Each iPhone has its own HWID, NORID and CHIPID. All of these IDs are embedded into internal hardware chips of an iPhone. When you connect a locked iPhone to iTunes, it send your unique HWID, NORID and CHIPID to Apple servers which then generates and sends a NCK to unlock your iPhone on official carrier. The length of NCK unlock code is 15 digits only; having said that, keyspace of size 10^15 is too large to enumerate and crack thorugh brute force methods.

According to recent tweet by MuscleNerd, the current known vulnerabilities can help them to know the NORID and CHIPID which leaves only 40-bits to crack the NCK key. Again, cracking the NCK though brute force method is just a theoretical exploit until now but if iPhone Dev-Team manages to crack the NCK with known NORID and CHIPID, this might lead to the unlock of all locked iPhone 4s for life.

Stay tuned while we update you with the latest news on iPhone 4 unlock!

Update#:1 Vincet, the admin of TheiPhoneWiki further clarifies the situation:
Vincent iPhone 4 Unlock Tweet

The exploit the got now gives you enough information to bruteforce crack your unique NCK key -> gives you an (official) permanent unlock.

Vincent iPhone 4 Unlock Tweet

Being able to capture NORID+CHIPID leaves (apparently) only 40-bits left to check/crack, which is might be pretty reasonable.

Update#:3 Vincent has just published a FAQ which answers the following questions:

  • Why iPhone 4 iPhone 4 02.10.04, 03.10.01 baseband unlock got delayed?
  • What is this NCK-key cracking? How does it work?
  • Should I sell my locked iPhone 4?
  • If the NCK method fails, how long do you think it will take for the Dev-Team to unlock the iPhone 4?

Vincent on iPhone 4 Unlock
Update#4: What is Gevey SIM Hack & How Gevey SIM Interposer Work to Unlock iPhone 4?
Update#5: Update on iPhone 4 Unlock Through NCK Brute Force Method
[Sources: TheiPhoneWiki, Tweet, Tweet]

Contact Us for News Tips, Corrections and Feedback

Related posts

Leave a message...

    Dreezy inco8 years, 7 months ago

    Anything on unlocking on jailbreak 5.1.1 on baseband 04.12.02?? Iphone 4 unlocked to Fido and i want to use it with Telus im in Canada

    mansoor9 years, 8 months ago

    is there any way to unlock iphone4, 4.3.5, BB 04.10.01?

    Kevin9 years, 9 months ago

    Any news?
    Maybe they found something in the iPhone 4s?

      Pramod9 years, 9 months ago

      There are no new updates about this approach for a pretty long time now. This idea seems to be have been long dropped by the Dev-Team.

    Taps10 years ago

    Any further update on 3.10.01 baseband unlock

      Pramod10 years ago

      No, and don’t expect it anytime soon either.

    chan10 years, 2 months ago

    Hi any further update in regards to unlock for these BB?
    02.10.04, 03.10.01

      Wolverine10 years, 2 months ago

      Nops. MuscleNerd is such a lazy a**. I think iPhone Dev-Team is on the losing side this time.

    Eduardo Pedroso10 years, 4 months ago

    How do the sites that charge for Unlocking say they can do it for iPhone 4 iPhone 4 4.2.1 03.10.01? Is it a scam?

      Wolverine10 years, 4 months ago

      These sites are 100% fake. Do not purchase anything from them. Keep my words in your bank :P