Free Carrier Unlock Ultrasn0w 1.2 Available for iPhone3G/3GS Owners with Baseband Later Than 05.13.04

Written By Sam on 29 November 2010

While Apple leads with innovative devices, it is a fact of life that they also place limitations on the choice of carriers and app providers. Developers and hackers prove to be equally ingenious and inventive, finding ways to help users circumvent these restrictions and enhance versatility of their iPhones.

Now, a free Pwnage tool is available for download that will enable carrier unlock for Apple iPhone 3G/3GS models but these should have a baseband version later than 05.13.04. This tool exploits the same AT+XAPP command hole used to unlock that baseband but in a different way. This new tool, termed Ultra-recycle, uses iPad modem firmware flashed to iPhone 3G/3GS to unlock and avail iOS 4.2.1 updates.

Dev-Team developers in the know are fully aware that the iPad baseband is designed around the same baseband chip as the iPhone 3G/3GS and both are fully compatible. The iPad firmware 3.2.2 has a baseband version 06.15.00 which is still vulnerable to AT+XAPP exploitation so these developers ran 06.15 on their iphones anticipating this release.

How would you go about it then?

In brief:

Method 1 using Pwnage tool for Apple OSX:

  • First of all read update #1 for an updated 3GS bundle.
  • Download the related IPSW.
  • Then run Pwnage Tool for a customised 4.1 IPSW.
  • Enter details of the iPad baseband you want to use which is downloaded. Then restore to this custom IPSW.
  • Next you can install Ultrasn0w through Cydia.

This is a short cut which works.

Method 2 (redsn0w for OSX + Windows):

  • Use redsn0w, for OSX or Windows.
  • Accept the warning, enable the “Install iPad baseband” feature.
  • When the redsn0w ram disk finishes installing, go on to installing ultrasn0w via Cydia. That’s it.

In both cases if the iPhone has an old bootrom 3GS which might be unlockable, update to iOS 4.2.1 and wait for the release of the unofficial bundle from the developer to unlock carrier on this model.

iPads have baseband version 06.15 which is higher than 05.14 or even 05.15. Users having older versions of the baseband first have to upgrade to baseband version 06.15 and try unlocking successfully. Apple still makes available for download iPad FW 3.2.2 with the above mentioned AT+XAPP command, so take advantage before it is pulled down and is no longer available. Note that baseband version 05.11.07 is not unlockable!

Pwnage Tool 4.1.3 Unlock Edition

  • When you first run it a dialog box asks if you wish to update to the iPad baseband 06.15. For this it is necessary to have installed on your computer the iPad 3.2.2 IPSW.
  • When asked in the dialog box, point to the location on your computer or let it find it automatically. The software will then work with AT+XAPP loophole to unlock the iPhone. You will need to download the IPSW files, specifically the 3.2.2 IPSW.
  • Create custom IPSW using baseband 06.15 from the iPad IPSW and iOS 4.2.1 update for iPhone 3G/3GS. Complete the bundle and then update the iPhone using iTunes 10.1. Press ALT key and then hit restore button to locate the IPSW. You need a Mac to do this!

Redsn0w 0.9.6 beta 5

Thankfully this works both on PC and Mac

  • First download the Redsn0w tool and update iPhone with iOS 4.2.1
  • Next run Redsn0w and wait till it recognizes the newer iOS 4.2.1 and then goes into DFU mode
  • Once the iPhone is in DFU mode, click install iPad Baseband selection that will enable you to get 06.15 baseband which is done once you have downloaded the iPad 3.2.2 IPSW from Apple servers.
  • Once your iPhone 3G/3GS has the newer version then you can run Cydia app and proceed to installing ultrasn0w 1.2 to unlock the device.

Perhaps this tool will find more favor with users of the iPhone.


Once upgraded to 06.15 you can not downgrade back to previous versions. This action will void Apple warranties.

  • You will not be able to restore stock firmware, only the stock IPSW can be restored.
  • If not clear about these instructions, it would be worthwhile waiting for simplified tools to come along which will make unlocking a snap.
  • This Pwnage Tool is bundled with iOS 4.2.1 upgrade for iPhone 3G. Old iPhone 3GS users with old bootrooms will need to use redsn0w for untethered jailbreak.

For all other devices it is a tethered jailbreak for now till something better comes along.

  • Remember to backup old files on your devices.
  • While flashing the newer baseband keep the device plugged into USB while on a PC unlock op.

Also note:

While following method 1 Pwnage tool, please note that there is an error in the bundle for iPhone 3GS 4.1. You will need to download the fixed bundle, unzip it and then click “show package contents of Pwnage Tool, navigate to contents>resources>firmwarebundles and drop the update there.

Method2: Redsnow beta 0.9.6 beta5 allows users to flash iPad 06.15 baseband directly on the iPhone, downloading the baseband files directly from Apple servers(this may take a while as their servers are fully loaded).

For the moment these methods are somewhat risky and entail precise sequencing of the events so please be careful and ensure that you know the sequence well enough to undertake this task. Always download from the recommended link!

  • OSX (SHA1 a322ec2c9e91993eca21abaf2e655bb44de3d7d4)
  • Windows (SHA1 7250416e17c3aea9838cdfc73712b38b025e2ed0)   (Windows 7 and Vista users, please run redsn0w as Administrator in “XP Compatibility Mode”)

Leave your response!