Selasa, 29 Maret 2011

iOS 4.3.1 Untethered Jailbreak In Beta Testing Stage [Release Imminent]

 

As promised, Stefan Esser aka @in01c has finally handed over the iOS 4.3.1 untethered exploit to the iPhone Dev Team.
For folks who are not aware, Stefan has made an untethered exploit for iOS 4.3.1 and demoed it on iPad 1 running iOS 4.3 & iPodTouch running iOS 4.3.1.


This untethered exploits is expected to jailbreak iPhone 4, iPhhone 3GS, iPodTouch 4G, iPodTouch 3G, iPad. Unfortunately, iPad 2 is not supported.If u like to support me for my new Ipad 2 for further Jailbreak´s and Testing ;) 
U can Donate Here or Below
Thank so much !




According to Stefan, his untethered exploit is in the iPhone Dev Team’s hands, and the iPhone Dev team has already started testing it.
@in01c – The iphone-dev-team is already beta-testing the untether. So it is up to them to give you your tool of choice.
@in01c – Please don’t bother the dev-team now. The deal is: if the beta test is successfull, they are free to do whatever they want with it.
Now, its the iPhone Dev Team who will make the decision on releasing a Jailbreak tool. Its is not confirmed whether this untethered exploit will be used in RedSn0w or PwnageTool. But, chances are that it will be used in RedSn0w.
As always, we will keep you posted with any updated news on jailbreak & unlock. Stay tuned.. we will be posted a step by step guide on how to jailbreak your iOS device running iOS 4.3.1.
Update #1 – MuscleNerd Confirmed that @in01c’s Untethered Jailbreak is solid.
well @i0n1c‘s untether is solid! Just working out overall 4.3.x JB issues and Cydia :) http://is.gd/ac44em

Support for my new Ipad 2 for further Jailbreak´s and Testing !

If u like to support me for my new Ipad 2 for further Jailbreak´s and Testing ;)
Thank so much !



iPhone Dev Team Beta-Testing an Untethered Jailbreak

It seems like all of the eyes in the jailbreak community are on the Dev Team and their associated hackers.
Apple introduced iOS 4.3 almost 3 weeks ago and since then we have yet to see an untethered jailbreak come out of the Dev Team’s camp.
iPad 2 users and those that accidentally installed iOS 4.3 are starting to sweat as a jailbreak that was once thought to be released shortly after iOS 4.3, has turned into a 3 week stand off. Well it looks like there has been some breakthroughs from the Dev Team…Well-known hacker i0n1c tweeted a few hours ago that the iPhone Dev Team is already beta-testing his untethered jailbreak. He also noted that it would be up to them to package the jailbreak software. But the fact that they are beta-testing should give jailbreakers some hope that an official release will be announced soon.
I’ve been holding out on all the tethered jailbreaks that have come along for 4.3. It just simply wasn’t feasible for me to be at my computer every time my phone restarted. What would happen if my springboard crashed from one of my many mobile substrate tweaks while I was out and about? There also hasn’t been anything I’ve seen in iOS 4.3 that I just had to have, except maybe the AirPlay enhancements.
Are we close to an untethered solution? Are you on 4.3 and dying for an official jailbreak release? Tell us below! Unfortunately, iPad 2 is not supported.If u like to support me for my new Ipad 2 for further Jailbreak´s and Testing ;)
Thank so much !

Giveaway to our Reader´s !

We have to giveaway these wounderfull invisble shield from zagg.com
Tell us why u want it ?
from where do come?
and how long u read this blog`?

and send me email to egohot.dev@googlemail.com

and may u will be the ne owner of the Invisible Shield !

Good luck ervyone ;-)

Senin, 28 Maret 2011

Apple Patched Comex’s Exploit in iOS 4.3.1

The cat and mouse game between Apple and jailbreakers is getting intense.
Apple got real serious when they added ASLR to iOS 4.3 and forced iDevice hackers back to their drawing boards. But members of the jailbreak community responded, and a tethered jailbreak was quickly made available with a patched mobile substrate file.
The latest move from Apple seems to be a big one. Comex tweeted about an hour ago that his kernel exploit was fixed in Apple’s latest version of the firmware, iOS 4.3.1. It was public knowledge that i0n1c and other jailbreakers were specifically waiting for iOS 4.3.1 to be released to prevent something like this from happening…
Comex went on to say that he’s trying not to be paranoid, but couldn’t think of any explanation for the patch other than a leak. The exploit was available from 4.0.2 through 4.3, but was “magically” patched in the latest update.
Negativity aside, he does have some good news for jailbreak hopefuls. He mentions some details about his “new” kernel exploit. He claims it is actually the same kernel exploit that was used in JailbreakMe 2.0.
He also gives encouragement to i0n1c and MuscleNerd, hinting that the 4.3.1 release didn’t affect their jailbreak method. As always stay tuned to iDB for the latest in jailbreaking news.
Do you think we’ll see a JailbreakMe 3.0 or another untethered jailbreak option soon? Tell us your thoughts below!

How To Jailbreak iPodTouch 4G, iPodTouch 3G & iPad On iOS 4.3.1 Using Sn0wbreeze [Windows]

Just a little while ago, @iH8Sn0w released an updated version of Sn0wbreeze 2.4 beta 1.
This version of Sn0wbreeze 2.4b1 jailbreak iPhone 4, iPhone 3GS, iPodTouch 4G, iPodTouch 3G & iPad 1G running iOS 4.3.1. iPhone 4 & iPhone 3GS users can follow these instructions to Jailbreak & Unlock your device on iOS 4.3.1. iPad & iPodTouch users can follow the below step by step guide to jailbreak your iDevice. Keep in mind that this is a tethered Jailbreak.
Sn0wbreeze 2.4 Beta 1
Step 1: Download the required Files – Links posted at the bottom of the post
Step 2: Launch Sn0wbreeze 2.4 BETA 1 and Click Ok on the disclaimer.
Step 3: Click Next – Blue Arrow in the bottom right corner
Step 4: Click on Browse, Navigate to the Original iOS 4.3.1 firmware and Click Open
Step 5: Let it verify the IPSW file. Once Verified Click Next
Step 6: Now, click on Expert Mode (Selecting Baseband Prservation Mode will only preserve your iPhone baseband. It will not Jailbreak your iPhone)
Step 7: Now, Click on General and then click on Next
Step 8: Check mark Install SSH and then Click Next (optional)
Step 9: Now, If you want to add any custom packages add them here. If not, just click Next
Step 10: Now, Click on Build IPSW and Click Next to cook custom firmware.
Note: By now, Snowbreeze should create custom cooked IPSW file for your device. And you will also notice a iBooty Folder for iOS 4.3.1. You need this to tethered boot into your iOS device.

Step 11: Once the custom firmware is cooked, Connect your iOS device and turn it OFF.
Step 12: Now, follow the on screen instructions to put your iOS device in PWNED DFU mode.
Step 13: Once your iOS device in PWNED DFU mode, Launch iTunes
Step 14: Hold down SHIFT KEY and Click on Restore on iTunes, Navigate to the custom cooked IPSW file, which should be saved on your desktop, and click on Open.
Step 15: Now, just sit and relax, iTunes will take care of the rest.
via[MacHackPc]
Download Links




  • Download Sn0wbreeze 2.4 BETA 1– For Windows
  • Download iOS 4.3.1 For all iOS Device – Direct Links
  • Download iBooty 4.3.1 - This will be created by Sn0wbreeze when you create custom firmware.

How To Jailbreak & Unlock iPhone 4 & iPhone 3GS On iOS 4.3.1 Using Sn0wbreeze [Windows]


Just a minute ago, @iH8Sn0w released an updated version of Sn0wbreeze 2.4 Beta 1,
which not only supports iOS 4.3.1 Jailbreak, it also support Ultrasn0w for the following basebands only (01.59.00 / 04.26.08 / 05.11.07 / 05.12.01 / 05.13.04 / 06.15.00). Keep in mind this is not a Untethered Jailbreak. The Dev Team’s are working on untethered jailbreak for iOS 4.3 / iOS 4.3.1 and is expected to be released soon. For those who can’t wait, you use Sn0wbreeze 2.4b1 (Tethered Jailbreak), which can jailbreak all iOS device (iPhone 4, iPhone 3GS, iPodTouch 4G, iPodTouch 3G, iPad) running iOS 4.3.
Sn0wbreeze 2.4b1 – Details
  • ultrasn0w now works for basebands (01.59.00 / 04.26.08 / 05.11.07 / 05.12.01 / 05.13.04 / 06.15.00)
  • ultrasn0w is NOT compatible with the folllowing basebands! (02.10.04 / 03.10.01 / 04.10.01 / 05.14.02 / 05.15.04)
  • iOS 4.3.1 is now supported.
  • iPhone 3GS users can upgrade to 06.15.00 baseband now under Unlocks section in Expert.
  • Upgrading your iPhone 3GS baseband to the 06.15.00 iPad baseband hack to unlock MAY cause you to lose your GPS!
Sn0wbreeze 2.4beta 1
How To Jailbreak & Unlock iPhone 4 & iPhone 3GS Running iOS 4.3 Using Sn0wbreeze 2.4b1
Step 1: Download the required files – Links posted at the bottom of the post
Step 2: Launch Sn0wbreeze 2.4 BETA 1 and Click Ok on the disclaimer.
Step 3: Click Next – Blue Arrow in the bottom right corner
Step 4: Click on Browse, Navigate to the Original iOS 4.3.1 Firmware and Click Open
Step 5: Let it verify the IPSW file. Once Verified Click Next
Step 6: Now, click on Expert Mode (Selecting Baseband Prservation Mode will only preserve your iPhone baseband. It will not Jailbreak your iPhone)
Step 7: Now, Click on General and then click on Next
Step 8: Check mark, Activate The iPhone to hacktivate your iPhone  (Do this if you don’t have your original iPhone SIM) , Check mark Install SSH and then Click Next.
Step 9: Now, If you want to add any custom packages add them here. If not, just click Next
Step 10: Now, Click on Build IPSW and Click Next to cook custom firmware.
Note: By now, Snowbreeze should create custom cooked IPSW file for your device. And you will also notice a iBooty Folder for iOS 4.3. You need this to tethered boot into your iOS device.

Step 11: Once the custom firmware is cooked, Connect your iOS device and turn it OFF.
Step 12: Now, follow the on screen instructions to put your iOS device in PWNED DFU mode.
Step 13: Once your iOS device in PWNED DFU mode, Launch iTunes
Step 14: Hold down SHIFT KEY and Click on Restore on iTunes, Navigate to the custom cooked IPSW file, which should be saved on your desktop, and click on Open.
Step 15: Now, just sit and relax, iTunes will take care of the rest.
via[MacHackPc]

Download Links




  • Download Sn0wbreeze 2.4 BETA 1– For Windows
  • Download iOS 4.3.1 For all iOS Device – Direct Links
  • Download iBooty 4.3.1 - This will be created by Sn0wbreeze when you create custom firmware.

iOS 4.3.1 Untethered Jailbreak [One More Video Demonstration]

Here is the complete description from Stefan Esser.

Meanwhile everyone should have noticed that my prediction became true and Apple released iOS 4.3.1 in order to fix the PWN2OWN vulnerability in Safari.
It was very unlikely that Apple also fixed the kernel vulnerability I used for my untether exploit. Mainly because the kernelcache binary is about 8-10 MB in size and the likelihood that Apple finds the same vulnerability in that short amount of time was very low.
However you never know until you try it. So this morning when I woke up and saw that Sn0wbreeze 2.4 beta was released I thought it would be fun to create a new video.
Unfortunately Sn0wbreeze does not work with my iPad 1 and so I had to test with my iPod 4G.
In the video you can see how I switch off the iPod, then restart it, show the version, show that it is tethered and has the multitasking gestures, i show that you can buy ringtones and then I show cydia and the ninja jump game from last time.
Because several people misunderstood me in the past:
a. I repeatedly stated that I will not release a jailbreak tool – I will only give out the untether. I did not try yet, but if it is feasible the untether could be a cydia package.
b. While the vulnerability I use is in the iPad 2 kernel my untether will NOT SUPPORT the iPad 2, because there is no way to install it there (bootrom exploits fixed). – however Comex is working on that part.
c. I am not giving out any ETA again, because the Jailbreak community is simply nuts. Last time I gave an ETA and even before that had passed I got constantly insulted by people that were demanding an immediate release. Sorry guys the more you insult people with the knowledge to actually do what YOU WANT the less motivation there is to use our free time to give it to you.
d. The only reason why I did not finish the untether before the ETA was due to unexpected work overload in my real job. It had nothing todo with the untether being too hard or unreal.
e. I don’t know why the dev team has not released a redsn0w that does tethered jailbreak for 4.3.1 – I would prefer that to be available, cause sn0wbreeze obviously does not work 100% yet.
f. If you want to learn more about iPhone kernel hacking/exploitation you should come to SyScan Singapore at the end of April. http://syscan.org/index.php/sg/program






for get my iPad2 for more Test´s 
So, this is really exciting news that we will soon get untethered jailbreak. As mentioned by the hackers, there is no ETA (Estimated Time of Arrival).

For those who can’t wait, you can jailbreak your iOS device using Sn0wbreeze 2.4b1 -

Sn0wbreeze 2.4b1 Released to Jailbreak iOS 4.3.1

iH8sn0w has just released Sn0wbreeeze 2.4b1 to jailbreak iOS 4.3.1 on iPhone 4, 3GS, iPod touch 4G, 3G and iPad.
Sn0wbreeze 2.4b1 is also tethered jailbreak for all devices which means you will have to boot into jailbroken state evey time you reboot your device.


You have to know that Sn0wbreeze 2.4b1 supports ultrasn0w unlock for basebands (01.59.00 / 04.26.08 / 05.11.07 / 05.12.01 / 05.13.04 / 06.15.00) ONLY.



Minggu, 27 Maret 2011

Gevey SIM is illegal [Warning]



MuscleNerd of iPhone dev-team has announced some bad news about Gevey SIM which unlock iPhone 4 basebands 2.10.04 / 3.10.01 / 4.10.01,
MuscleNerd said that Gevey SIM is illegal in USA and probably other countires as it dials 112 (emergency) then hang up.


Likely the carriers will block the SIMs that are causing the repeated emergency call hang ups, and if you change the blocked SIM many times, you yourself will get banned by carrier.
That "dial 112 then hang up" in gevey http://is.gd/FGNeJi is illegal in USA, and probably other countries. Buyer beware.
So the question is can the hackers improve Gevey SIM to work legally? Unfortunately, MucleNerd confirmed that there is no way to make Gevey SIM method legal. So I highly recommend who is looking for unlock to wait for ultrasn0w from the dev-team.

TinyUmbrella 4.30.05 Brings iOS 4.3.1 Support

Notcom has released TinyUmbrella 4.30.05 for iPhone 4, 3GS, iPod touch 4G, 3G, iPad 2 and iPad 1 to support iOS 4.3.1.
TinyUmbrella doesn't support Verizon iPhone 4 as iOS 4.3.1 still not available for it.


TinyUmbrella now supports 4.3.1 for the relevant devices. Currently only iPhone 4 for verizon does not have 4.3.1 support (as there is no 4.3.1 available for the verizon iphone). Enjoy!
With TinyUmbrella 4.30.05 you can save iOS 4.3.1 SHSH blobs for iPhone 4, 3GS, iPod touch 4G, 3G, iPad 2 and iPad 1.


Sabtu, 26 Maret 2011

How To Manually Install Cydia 1.1.1 On Your iOS Device

Just a little while ago, Jay Freeman AKA @Saurik has pushed out an updated version of Cydia 1.1.1.
As mentioned earlier this update is faster, slimmer and is more stable than ever. Additionally, this upgrade includes an improved search algorithm and ‘resume where you left off’.
To get this update all you need to do is Launch Cydia and take offered update. If in case, cydia doesn’t offer you an update, just follow the below steps to manually install Cydia 1.1.1 on your Jailbroken iOS Device.

How to Install New Cydia 1.0.3366.7 On device running iOS 4.1
Step 1: Download the New Cydia 1.0.3366.7 and save it on your desktop – Download links posted below
Step 2: Download & Install CyberDuck (Mac) / WinSCP (Win) – If its not already
Step 3: Launch Cydia, Install OpenSSH, & then Install iFile - If its not already
Step 4: Connect your iPhone, Launch CyberDuck or WinSCP and SSH into the device

  • Mac – CyberDuck (Server = Your iPhone IP Addess, UserName = root, Password = alpine and Protocol = SSH File Transfer)
  • Win – WinSCP (Hostname = Your iPhone IP Address, Username = root, Password = alpine and Protocol = SCP)
Step 5: Navigate to the following folder and move the download Cydia file ‘cydia_1.1.1_iphoneos-arm.deb’ here.

  • /root/private/var/root/
Step 6: On your device, launch iFile, Navigate to the following folder & Tap on ‘cydia_1.1.1_iphoneos-arm.deb ’

  • /root/private/var/root/
Step 7: Tap on, Tap on Installer to install the new Cydia on your device.
That’s it! You have the updated version of Cydia
via[MacHackPc]
Download Links

Jailbreak 4.3.1 iPhone 4 PwnageTool [How to Guide]

The newly iOS 4.3.1 has been successfully jailbroken on iPhone, iPod touch and iPad.
But you have to know that it's a tethered jailbreak for now which means that you will have to boot it into jailbroken state every time you reboot. You can follow the step by step guide below to jailbreak iOS 4.3.2 on iPhone 4 using combination of PwnageTool 4.2, Universal Ramdisk Fixer and tetheredboot utility.



Here’s what you will need:
  • PwnageTool 4.2
  • iOS 4.3.1 firmware
  • iTunes 10.2.1
  • Mac OS X
  • PwnageTool bundle for iOS 4.3.1
  • Universal Ramdisk Fixer
  • tetheredboot utility
Note:
  • There is no unlock for the new baseband on iOS 4.3.1. If your iPhone relies on a carrier unlock, DO NOT update to stock iOS 4.3.1.
  • iPad 2 users on iOS 4.3 should stay away from iOS 4.3.1 until further confirmation.
  • Cydia is fully working on iOS 4.3.1
  • It is a semi-tethered jailbreak.
  • Your baseband will not be upgraded during restore process.
Modifying PwnageTool
Step 1: Download PwnageTool bundle for your version of iOS device. Extract the .zip folder, in there you will find a .bundle file, for this guide, we are using iPhone 4 bundle iPhone3,1_4.3.1_8G4.bundle. Move this file to your desktop.
Step 2: Download PwnageTool 4.2 and copy it to /Applications directory. Right click, and then click on “Show Package Contents” as shown in the screenshot below.

Step 3: Navigate to Contents/Resources/FirmwareBundles/ and paste iPhone3,1_4.3.1_8G4.bundle file in this location.

Creating Custom Ramdisk for iOS 4.3.1 Custom Firmware
Step 4: Download Universal Ramdisk Maker and simply install it as shown in the screenshots below. This is important because Ramdisk in the current version of PwnageTool is broken. This Universal Ramdisk Maker basically patches it correctly for iOS 4.3.1 firmware.
 



Building iOS 4.3.1 Custom Firmware
Step 5: Download iOS 4.3.1 firmware. Move this file to your desktop.
Step 6: Start PwnageTool in “Expert mode” and select your device:

Step 7: Browse for iOS 4.3.1 firmware for your device as shown in the screenshot below:

Step 8: Now select “Build” to start creating custom 4.3.1 firmware file:

Step 9: PwnageTool will now create the custom .ipsw file for your iPhone which will be jailbroken.

Step 10: Now follow the following steps to enter DFU mode using PwnageTool:
  • Hold Power and Home buttons for 10 seconds
  • Now release the Power button but continue holding the Home button for 10 more seconds
  • You device should now be in DFU mode 

Restore iOS 4.3.1 Custom Firmware Using iTunes
Step 11: Start iTunes, click on your iOS device icon from the sidebar in iTunes. Now press and hold left “alt” (option) button on Mac, or Left “Shift” button if you are on Windows on the keyboard and then click on “Restore” (Not “Update” or “Check for Update”) button in the iTunes and then release this button.

This will make iTunes prompt you to select the location for your custom firmware 4.3.1 file. Select the required custom .ipsw file that you created above, and click on “Open”.
Step 12: Now sit back and enjoy as iTunes does the rest for you. This will involve a series of automated steps. Be patient at this stage and don’t do anything silly. Just wait while iTunes installs the new firmware 4.3.1 on your iOS device. Your iOS device screen at this point will be showing a progress bar indicating installation progress. After the installation is done, your iOS device will be jailbroken on iOS 4.3.1.
Booting in Tethered Mode
Last but not the least, since there is no untethered jailbreak for iOS 4.3.1 yet, we will have to boot it into a tethered jailbroken state. To do this, we will make use of a utility named “tetheredboot” as shown in the steps below.
Step 13: Download tetheredboot.zip utility for Mac OS X and extract the .zip file.
Step 14: First, we will need two files from the custom iOS 4.3.1 firmware namely: kernelcache.release.n90 and iBSS.n90ap.RELEASE.dfu. To do this, make a copy of your custom iOS 4.3.1 file that you created above, change the extension of this file from .ipsw to .zip, and then extract this .zip file.
Now copy kernelcache.release.n90 file, and then copy iBSS.n90ap.RELEASE.dfu files which are found under /Firmware/dfu/.
Move all these files, and tetheredboot utility to a new folder named “tetheredboot” on the desktop as shown in the screenshot below.

Step 15: Turn off your iOS device, and start Terminal on OS X and run the following commands:
sudo -s
enter your administrator password, then:
/Users/TaimurAsad/Downloads/tetheredboot/tetheredboot
/Users/TaimurAsad/Downloads/tetheredboot/iBSS.n90ap.RELEASE.dfu
/Users/TaimurAsad/Downloads/tetheredboot/kernelcache.release.n90
You will have to of course replace “TaimurAsad” with the name of the directory on your computer.
now press enter.

You should now see some code running in the Terminal window, at some point, it will ask you to enter DFU mode. Now follow the following steps to enter DFU mode:
  • Hold Power and Home buttons for 10 seconds
  • Now release the Power button but continue holding the Home button for 10 more seconds
  • You device should now be in DFU mode
Now wait for your device to boot, Terminal at this point will be showing “Exiting libpois0n” message. After a short while, your iPhone, iPad or iPod touch will be booted in a jailbroken tethered mode !

How to Get Cydia 1.1

Cydia 1.1 has just been released. Jay Freeman (aka Saurik) -Cydia creator- has just announced via his Twitter account that Cydia 1.1 is now available.
Freeman mentioned that Cydia 1.1 is faster, slimmer and more stable and it's including an improved search alogrithm and a "resume where you left off" feature.


Cydia 1.1: faster, slimmer, and more stable; including an improved search algorithm and “resume where you left off”. Available in Cydia now!
How to get new Cydia 1.1 ? you only have to run Cydia and it will prompt you to run some updates, just accept and it will automatically update your Cydia to version 1.1

Jumat, 25 Maret 2011

Download iOS 4.3.1 for iPhone, iPad, iPod touch [Direct Links]

Apple has just released iOS 4.3.1 update for iPhone 4, iPhone 3GS, iPad 2, iPad, and iPod touch 4G/3G.
This is just a minor update to fix bugs, vulnerabilities and battery life woes on all iOS devices.

To update to iOS 4.3.1, all you need to do is to connect your iPhone, iPad or iPod touch with your computer via USB and start iTunes 10.2.1. You should now see a message as shown below, simply click on “Download and Install” button to get on to the new firmware.

The final version of the last major update, iOS 4.3, was released back on March 10.
Direct Download Links for iOS 4.3.1 (Official from Apple)
Download iTunes 10.2.1 for Windows and Mac

Kamis, 24 Maret 2011

Jailbreaking 101 - Seas0nPass

NOTE: Currently the jailbreak for the 4.2.1 (iOS 4.3) software is ‘tethered’. A tethered jailbreak requires the AppleTV to be connected to a computer for a brief moment during startup.
Seas0nPass makes this as easy as possible, but please do not proceed unless you are comfortable with this process.

Pre-launch checklist

  1. Make sure you're running the latest version of iTunes.
  2. Download Seas0nPass: Mac [10.6 or later] | Windows [XP or later]
  3. micro USB cable will be required to complete the jailbreak.
  4. Disconnect all iPods, iPhones, and iPads from the computer before running Seas0nPass.

Using Seas0nPass to jailbreak the AppleTV

Step 1: Unzip the 'Seas0nPass.zip' file and launch Seas0nPass.
SP-launch.jpg
Step 2: If your AppleTV is not yet jailbroken, select 'Create IPSW'. (if already jailbroken, and you just need to do a 'tethered boot' scroll down).
SP-main.jpg
Step 3: The latest AppleTV software will be downloaded and used to create a custom 'jailbroken' software file.
SP-create.jpg
Step 4: When prompted, connect your AppleTV using a micro-USB cable (leave power disconnected), and hold both the 'MENU' and 'PLAY/PAUSE' buttons for 7 seven seconds.
SP-restore.jpg
Step 5: iTunes will open automatically and start the restore process.
 SP-itunes.jpg
Step 6: iTunes will confirm the restore when complete - your AppleTV is now jailbroken. Please proceed to the 'tethered boot' section below.

Using Seas0nPass for a 'tethered boot'

Some AppleTV software versions require a tethered boot. This means the AppleTV must be connected to a computer for a brief moment during startup.
Note: The AppleTV MUST be disconnected from the computer (for at least a brief moment) after restoring in iTunes for the tethered boot process below to work properly.
Step 1: Open Seas0nPass and select the 'Boot Tethered' option.
SP-main.jpg
Step 2: When prompted, connect the AppleTV to your computer via USB. Wait for the rapid flashing light then connect the power. Once both are connected hold both the 'MENU' and 'PLAY/PAUSE' buttons for 7 seven seconds.
SP-tetherprompt.jpg
Step 3: Seas0n Pass will complete the tethered boot automatically. Once complete, remove the USB cable and connect the HDMI cable.
Note: Timing is key. Once the you receive the success message shown below, the USB cable should be removed and HDMI cable connected before the light on the front of the AppleTV stops flashing. (Don't worry there is ample to do this, so you don't need Superman speed).