Here is a step-by-step guide to jailbreak iOS 4.3.1 on Windows and Mac OS X using Redsn0w 0.9.6RC9. For those who don't know, Redsn0w 0.9.6RC9 is based on Stefan Esser's untethered exploit which he handed over to iPhone Dev-Team last week. Using Redsn0w 0.9.6RC9, you can jailbreak all supported iDevices on iOS 4.3.1 untethered except Apple TV 2G and iPad 2. The procedure to use Redsn0w 0.9.6RC9 on Windows is exactly same for Mac OS X.

NOTE: If you rely on an unlocked iPhone, DO NOT follow the above procedure directly. It will upgrade your baseband to 05.16.02 on iPhone 3GS and 04.10.01 on iPhone 4. All those who rely on an unlocked iPhone should follow this guide first to preserve their current baseband. Once done, follow the step-by-step guide below but skip step 3, 4.
Steps to Jailbreak iOS 4.3.1 Untethered Using Redsn0w 0.9.6RC9:
- Download and install iTunes 10.2.1 from here
- Download Redsn0w 0.9.6RC9 for Windows or Mac OS X from here
- Download stock iOS 4.3.1 IPSW for your iDevice from here
- Restore stock iOS 4.3.1 IPSW to your iDevice using iTunes.
- Launch Redsn0w.exe and click on the Browse button. Select stock iOS 4.3.1 IPSW for your iDevice which you downloaded in step 3.
- Now wait while Redsn0w processes the provided IPSW.
- Once IPSW has been successfully identified, click on the Next button to continue.
- Now wait while Redsn0w patches the kernel in provided IPSW.
- When Redsn0w will provide you with the jailbreak options, choose Cydia and click on the Next button.
- Plug your iDevice to your PC or Mac and turn it OFF completely by pressing the Power button.
- Now put your iDevice into DFU mode using the following instructions:
- Hold down the Power (corner) button for 3 seconds.
- Without releasing the Power button, also hold down the Home (bottom center) button for 10 seconds.
- Without releasing the Home button, release the Power button BUT KEEP holding the Home button for 15 seconds until Redsn0w detects your iDevice in DFU mode.
- Now Redsn0w will patch the iBoot of your iDevice using Geohot's Limrea1n exploit.
- Once iBoot of your iDevice has been patched with Limera1n exploit, Redsn0w will upload the Ramdisk. If you get stuck at uploading Ramdisk step, use this guide to solve the issue.
- In last step, Redsn0w will upload the patched kernel to your iDevice.
- Once done, click on the finish button to close Redsn0w.
- Thats it! If you rely on an unlocked iPhone, use this guide to enable Push Notifications and fix YouTube app using SAM and this guide to install AppSync for iOS 4.3.1. Do not install Ultrasn0w 1.2 from Cydia until you are told to do so. Ultrasn0w for iOS 4.3.1 is different from Ultrasn0w for all other firmwares and it'll be available soon as a Cydia package update.











Update#1: Download Ultrasn0w Fixer to Unlock iPhone 4/3GS on iOS 4.3.1 [Unofficial]
Update#2: Download Redsn0w 0.9.6RC10 & Redsn0w 0.9.6RC11 for Windows & Mac OS X
Update#3: Download Redsn0w 0.9.6RC12 to Fix Boot Logos Lingering Issues



