<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://freemyipod.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=User890104</id>
	<title>freemyipod - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://freemyipod.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=User890104"/>
	<link rel="alternate" type="text/html" href="https://freemyipod.org/wiki/Special:Contributions/User890104"/>
	<updated>2026-08-05T19:27:49Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://freemyipod.org/index.php?title=Modes&amp;diff=22408</id>
		<title>Modes</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Modes&amp;diff=22408"/>
		<updated>2026-07-31T15:44:39Z</updated>

		<summary type="html">&lt;p&gt;User890104: /* Diagnostic mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;At any given time an iPod can be in one of several modes, some of which can be activated by holding down certain buttons while the iPod is booting.  &lt;br /&gt;
&lt;br /&gt;
==Normal mode==&lt;br /&gt;
&amp;quot;Normal mode&amp;quot; is when the iPod is booted into [[RetailOS]] normally. In this mode the iPod presents as a mass storage device to a computer, allowing files to be transferred. Receiving device information from the iPod, as well as updating the iPod&#039;s [[Firmware]], can be done from normal mode through the use of proprietary SCSI commands.&lt;br /&gt;
&lt;br /&gt;
==Disk mode==&lt;br /&gt;
In disk mode, like normal mode, the iPod presents as a mass storage device to a computer and can have its information read and firmware updated. When in disk mode, the iPod screen will display, with a black foreground and white background, either a no symbol with the text &amp;quot;Do not disconnect.&amp;quot; or a checkmark symbol with the text &amp;quot;OK to disconnect.&amp;quot; depending on whether the iPod is connected and if it has been ejected. &lt;br /&gt;
&lt;br /&gt;
Disk mode exists on all iPod models. For more information on how to enter disk mode, refer to [https://support.apple.com/kb/ht1363 this Apple support document]&lt;br /&gt;
&lt;br /&gt;
Disk mode is also referred to as &amp;quot;forced disk mode&amp;quot; in device information received from the iPod.&lt;br /&gt;
&lt;br /&gt;
The place where disk mode is stored on the device differs depending on the iPod model. On the iPod nano (4th generation) and newer, disk mode is stored in the &amp;quot;disk&amp;quot; partition of the [[Firmware]].&lt;br /&gt;
&lt;br /&gt;
=== How to access it===&lt;br /&gt;
* Clickwheel iPods (except for the very first models):&lt;br /&gt;
** hold down &#039;&#039;&#039;Menu&#039;&#039;&#039; and &#039;&#039;&#039;Center&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Center&#039;&#039;&#039; and &#039;&#039;&#039;Play/Pause&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 6G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 7G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Menu&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Nano2g-diskmode-1.jpg|[[Nano 2G]] Do not disconnect&lt;br /&gt;
File:Nano2g-diskmode-2.jpg|[[Nano 2G]] OK to disconnect&lt;br /&gt;
File:Nano3g-diskmode-1.jpg|[[Nano 3G]] Do not disconnect&lt;br /&gt;
File:Nano3g-diskmode-2.jpg|[[Nano 3G]] OK to disconnect&lt;br /&gt;
File:Nano4g-diskmode-1.jpg|[[Nano 4G]] Do not disconnect&lt;br /&gt;
File:Nano4g-diskmode-2.jpg|[[Nano 4G]] OK to disconnect&lt;br /&gt;
File:Nano5g-diskmode-1.jpg|[[Nano 5G]] Do not disconnect&lt;br /&gt;
File:Nano5g-diskmode-2.jpg|[[Nano 5G]] OK to disconnect&lt;br /&gt;
File:Nano6g-diskmode-1.jpg|[[Nano 6G]] Do not disconnect&lt;br /&gt;
File:Nano6g-diskmode-2.jpg|[[Nano 6G]] OK to disconnect&lt;br /&gt;
File:Nano7g-diskmode-1.jpg|[[Nano 7G]] Do not disconnect&lt;br /&gt;
File:Nano7g-diskmode-2.jpg|[[Nano 7G]] OK to disconnect&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==DFU mode==&lt;br /&gt;
[https://en.wikipedia.org/wiki/Device_Firmware_Upgrade Device Firmware Upgrade], or DFU, is a standard for upgrading firmware over USB that is used by many devices, including iOS devices and newer iPods. DFU mode exists on the [[Nano 3G]] and newer and the [[Classic 6G]] and newer, coinciding with Apple&#039;s switch from PortalPlayer to Samsung processors. DFU mode is contained in the on-processor BootROM. Instructions on entering DFU mode can be found [https://theapplewiki.com/wiki/DFU_Mode#iPod here].&lt;br /&gt;
&lt;br /&gt;
When in DFU mode, the iPod can be sent a special WTF [[IMG1]] firmware image to enter WTF mode. Other IMG1 images cannot be sent in this mode.&lt;br /&gt;
&lt;br /&gt;
The [[Nano 2G]] also has a DFU mode, but it can only be entered by shorting testpoints on the iPod&#039;s circuit board or flashing the NOR with an image with an invalid signature or hash. It does, however, support a NOR DFU mode that can be entered by holding down &#039;&#039;&#039;Rewind&#039;&#039;&#039; and &#039;&#039;&#039;Play/Pause&#039;&#039;&#039; right after rebooting the device&amp;lt;ref&amp;gt;https://www.rockbox.org/irc/log-20080904#13:31:44&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== How to access it===&lt;br /&gt;
# Connect the iPod to a computer using a USB cable&lt;br /&gt;
# Check which key combo you need to hold down depending on the iPod&#039;s model&lt;br /&gt;
# Keep holding down the same buttons until the Apple logo appears, keep holding until the screen goes black, wait about 1 second and release the buttons.&lt;br /&gt;
&lt;br /&gt;
* [[Nano_3G]], [[Nano_4G]], [[Nano_5G]] and [[Classic_1G]]: &#039;&#039;&#039;Menu&#039;&#039;&#039; and &#039;&#039;&#039;Center&#039;&#039;&#039;&lt;br /&gt;
* [[Nano 6G]]: &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039;&lt;br /&gt;
* [[Nano 7G]]: &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Menu&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Note: On [[Nano 7G]] use a USB-A to Lightning cable. You cannot enter DFU mode using a USB-C to Lightning cable.&lt;br /&gt;
&lt;br /&gt;
==WTF mode==&lt;br /&gt;
In WTF mode (possibly &#039;Where&#039;s The Firmware?&#039;), the iPod will accept any [[IMG1]] image it is sent over DFU and, if signature and decryption checks pass, will attempt to boot to it. It is entered from DFU mode when a specific WTF [[IMG1]] firmware image is sent. While in WTF mode the iPod still uses the standard DFU protocol.&lt;br /&gt;
&lt;br /&gt;
The iTunes behavior upon seeing an iPod in WTF mode is to send it a &amp;quot;recovery&amp;quot; firmware image, which places the iPod in disk mode. However, any firmware image can be sent to it, including, for example, the &amp;quot;osos&amp;quot; partition from production iPod firmware, which enables tethered booting an iPod into [[RetailOS]].&lt;br /&gt;
&lt;br /&gt;
==Diagnostic mode==&lt;br /&gt;
This mode will give quite a lot of info about your iPod. In diagnostics mode you can find info about the battery power check the LCD, button inputs, radio signals, DRAM, NAND, Accelerometer, dock information and an about section. On touchscreen iPods there is also a section for touchscreen testing.&lt;br /&gt;
=== How to access it===&lt;br /&gt;
* Clickwheel iPods (except for the very first models):&lt;br /&gt;
** hold down &#039;&#039;&#039;Menu&#039;&#039;&#039; and &#039;&#039;&#039;Center&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Center&#039;&#039;&#039; and &#039;&#039;&#039;Rewind&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 6G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039;, &#039;&#039;&#039;Volume Down&#039;&#039;&#039; and &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 7G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Menu&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039;, &#039;&#039;&#039;Volume Down&#039;&#039;&#039; and &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Nano2g-diagmode.jpg|[[Nano 2G]]&lt;br /&gt;
File:Nano3g-diagmode.jpg|[[Nano 3G]]&lt;br /&gt;
File:Nano4g-diagmode.jpg|[[Nano 4G]]&lt;br /&gt;
File:Nano5g-diagmode.jpg|[[Nano 5G]]&lt;br /&gt;
File:Nano6g-diagmode.jpg|[[Nano 6G]]&lt;br /&gt;
File:Nano7g-diagmode.jpg|[[Nano 7G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==USB IDs==&lt;br /&gt;
When connected to a computer, the iPod presents a vendor ID of 05ac (Apple Inc.) and a product ID that depends on its model and which mode it is in: &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; &lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Model&lt;br /&gt;
! Normal/disk mode&lt;br /&gt;
! DFU mode&lt;br /&gt;
! WTF mode&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 2G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1260&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1220&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1240&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 3G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1262&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1223&amp;lt;/code&amp;gt;/&amp;lt;code&amp;gt;1224&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1242&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 4G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1263&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1225&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1243&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 5G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1265&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1231&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1246&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 6G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1266&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1232&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1248&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; | [[Nano 7G]]&lt;br /&gt;
| Initial&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; | &amp;lt;code&amp;gt;1267&amp;lt;/code&amp;gt;&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; | &amp;lt;code&amp;gt;1234&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1249&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev A&lt;br /&gt;
| &amp;lt;code&amp;gt;124a&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | [[Classic 6G]]&lt;br /&gt;
| [[Classic 6G#Initial|Initial]]&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | &amp;lt;code&amp;gt;1261&amp;lt;/code&amp;gt;&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | &amp;lt;code&amp;gt;1223&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1241&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| [[Classic 6G#Rev A|Rev A]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1245&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| [[Classic 6G#Rev B|Rev B]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1247&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev C&lt;br /&gt;
| &amp;lt;code&amp;gt;1250&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Modes&amp;diff=22407</id>
		<title>Modes</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Modes&amp;diff=22407"/>
		<updated>2026-07-31T15:42:58Z</updated>

		<summary type="html">&lt;p&gt;User890104: /* Disk mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;At any given time an iPod can be in one of several modes, some of which can be activated by holding down certain buttons while the iPod is booting.  &lt;br /&gt;
&lt;br /&gt;
==Normal mode==&lt;br /&gt;
&amp;quot;Normal mode&amp;quot; is when the iPod is booted into [[RetailOS]] normally. In this mode the iPod presents as a mass storage device to a computer, allowing files to be transferred. Receiving device information from the iPod, as well as updating the iPod&#039;s [[Firmware]], can be done from normal mode through the use of proprietary SCSI commands.&lt;br /&gt;
&lt;br /&gt;
==Disk mode==&lt;br /&gt;
In disk mode, like normal mode, the iPod presents as a mass storage device to a computer and can have its information read and firmware updated. When in disk mode, the iPod screen will display, with a black foreground and white background, either a no symbol with the text &amp;quot;Do not disconnect.&amp;quot; or a checkmark symbol with the text &amp;quot;OK to disconnect.&amp;quot; depending on whether the iPod is connected and if it has been ejected. &lt;br /&gt;
&lt;br /&gt;
Disk mode exists on all iPod models. For more information on how to enter disk mode, refer to [https://support.apple.com/kb/ht1363 this Apple support document]&lt;br /&gt;
&lt;br /&gt;
Disk mode is also referred to as &amp;quot;forced disk mode&amp;quot; in device information received from the iPod.&lt;br /&gt;
&lt;br /&gt;
The place where disk mode is stored on the device differs depending on the iPod model. On the iPod nano (4th generation) and newer, disk mode is stored in the &amp;quot;disk&amp;quot; partition of the [[Firmware]].&lt;br /&gt;
&lt;br /&gt;
=== How to access it===&lt;br /&gt;
* Clickwheel iPods (except for the very first models):&lt;br /&gt;
** hold down &#039;&#039;&#039;Menu&#039;&#039;&#039; and &#039;&#039;&#039;Center&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Center&#039;&#039;&#039; and &#039;&#039;&#039;Play/Pause&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 6G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 7G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Menu&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Nano2g-diskmode-1.jpg|[[Nano 2G]] Do not disconnect&lt;br /&gt;
File:Nano2g-diskmode-2.jpg|[[Nano 2G]] OK to disconnect&lt;br /&gt;
File:Nano3g-diskmode-1.jpg|[[Nano 3G]] Do not disconnect&lt;br /&gt;
File:Nano3g-diskmode-2.jpg|[[Nano 3G]] OK to disconnect&lt;br /&gt;
File:Nano4g-diskmode-1.jpg|[[Nano 4G]] Do not disconnect&lt;br /&gt;
File:Nano4g-diskmode-2.jpg|[[Nano 4G]] OK to disconnect&lt;br /&gt;
File:Nano5g-diskmode-1.jpg|[[Nano 5G]] Do not disconnect&lt;br /&gt;
File:Nano5g-diskmode-2.jpg|[[Nano 5G]] OK to disconnect&lt;br /&gt;
File:Nano6g-diskmode-1.jpg|[[Nano 6G]] Do not disconnect&lt;br /&gt;
File:Nano6g-diskmode-2.jpg|[[Nano 6G]] OK to disconnect&lt;br /&gt;
File:Nano7g-diskmode-1.jpg|[[Nano 7G]] Do not disconnect&lt;br /&gt;
File:Nano7g-diskmode-2.jpg|[[Nano 7G]] OK to disconnect&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==DFU mode==&lt;br /&gt;
[https://en.wikipedia.org/wiki/Device_Firmware_Upgrade Device Firmware Upgrade], or DFU, is a standard for upgrading firmware over USB that is used by many devices, including iOS devices and newer iPods. DFU mode exists on the [[Nano 3G]] and newer and the [[Classic 6G]] and newer, coinciding with Apple&#039;s switch from PortalPlayer to Samsung processors. DFU mode is contained in the on-processor BootROM. Instructions on entering DFU mode can be found [https://theapplewiki.com/wiki/DFU_Mode#iPod here].&lt;br /&gt;
&lt;br /&gt;
When in DFU mode, the iPod can be sent a special WTF [[IMG1]] firmware image to enter WTF mode. Other IMG1 images cannot be sent in this mode.&lt;br /&gt;
&lt;br /&gt;
The [[Nano 2G]] also has a DFU mode, but it can only be entered by shorting testpoints on the iPod&#039;s circuit board or flashing the NOR with an image with an invalid signature or hash. It does, however, support a NOR DFU mode that can be entered by holding down &#039;&#039;&#039;Rewind&#039;&#039;&#039; and &#039;&#039;&#039;Play/Pause&#039;&#039;&#039; right after rebooting the device&amp;lt;ref&amp;gt;https://www.rockbox.org/irc/log-20080904#13:31:44&amp;lt;/ref&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
=== How to access it===&lt;br /&gt;
# Connect the iPod to a computer using a USB cable&lt;br /&gt;
# Check which key combo you need to hold down depending on the iPod&#039;s model&lt;br /&gt;
# Keep holding down the same buttons until the Apple logo appears, keep holding until the screen goes black, wait about 1 second and release the buttons.&lt;br /&gt;
&lt;br /&gt;
* [[Nano_3G]], [[Nano_4G]], [[Nano_5G]] and [[Classic_1G]]: &#039;&#039;&#039;Menu&#039;&#039;&#039; and &#039;&#039;&#039;Center&#039;&#039;&#039;&lt;br /&gt;
* [[Nano 6G]]: &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039;&lt;br /&gt;
* [[Nano 7G]]: &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Menu&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Note: On [[Nano 7G]] use a USB-A to Lightning cable. You cannot enter DFU mode using a USB-C to Lightning cable.&lt;br /&gt;
&lt;br /&gt;
==WTF mode==&lt;br /&gt;
In WTF mode (possibly &#039;Where&#039;s The Firmware?&#039;), the iPod will accept any [[IMG1]] image it is sent over DFU and, if signature and decryption checks pass, will attempt to boot to it. It is entered from DFU mode when a specific WTF [[IMG1]] firmware image is sent. While in WTF mode the iPod still uses the standard DFU protocol.&lt;br /&gt;
&lt;br /&gt;
The iTunes behavior upon seeing an iPod in WTF mode is to send it a &amp;quot;recovery&amp;quot; firmware image, which places the iPod in disk mode. However, any firmware image can be sent to it, including, for example, the &amp;quot;osos&amp;quot; partition from production iPod firmware, which enables tethered booting an iPod into [[RetailOS]].&lt;br /&gt;
&lt;br /&gt;
==Diagnostic mode==&lt;br /&gt;
[[File:Nano 7G diagnostic mode.jpg|thumb|right|[[Nano 7G]] in diagnostics mode]]&lt;br /&gt;
This mode will give quite a lot of info about your iPod. In diagnostics mode you can find info about the battery power check the LCD, button inputs, radio signals, DRAM, NAND, Accelerometer, dock information and an about section. On touchscreen iPods there is also a section for touchscreen testing.&lt;br /&gt;
=== How to access it===&lt;br /&gt;
* Clickwheel iPods (except for the very first models):&lt;br /&gt;
** hold down &#039;&#039;&#039;Menu&#039;&#039;&#039; and &#039;&#039;&#039;Center&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Center&#039;&#039;&#039; and &#039;&#039;&#039;Rewind&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 6G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Volume Down&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039;, &#039;&#039;&#039;Volume Down&#039;&#039;&#039; and &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
* [[Nano 7G]]&lt;br /&gt;
** hold down &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; and &#039;&#039;&#039;Menu&#039;&#039;&#039; to do a hard reboot&lt;br /&gt;
** hold down &#039;&#039;&#039;Volume Up&#039;&#039;&#039;, &#039;&#039;&#039;Volume Down&#039;&#039;&#039; and &#039;&#039;&#039;Sleep/Wake&#039;&#039;&#039; when the Apple logo appears&lt;br /&gt;
&amp;lt;br clear=&amp;quot;all&amp;quot; /&amp;gt;&lt;br /&gt;
==USB IDs==&lt;br /&gt;
When connected to a computer, the iPod presents a vendor ID of 05ac (Apple Inc.) and a product ID that depends on its model and which mode it is in: &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; &lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Model&lt;br /&gt;
! Normal/disk mode&lt;br /&gt;
! DFU mode&lt;br /&gt;
! WTF mode&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 2G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1260&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1220&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1240&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 3G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1262&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1223&amp;lt;/code&amp;gt;/&amp;lt;code&amp;gt;1224&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1242&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 4G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1263&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1225&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1243&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 5G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1265&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1231&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1246&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | [[Nano 6G]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1266&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1232&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1248&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; | [[Nano 7G]]&lt;br /&gt;
| Initial&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; | &amp;lt;code&amp;gt;1267&amp;lt;/code&amp;gt;&lt;br /&gt;
| rowspan=&amp;quot;2&amp;quot; | &amp;lt;code&amp;gt;1234&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1249&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev A&lt;br /&gt;
| &amp;lt;code&amp;gt;124a&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | [[Classic 6G]]&lt;br /&gt;
| [[Classic 6G#Initial|Initial]]&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | &amp;lt;code&amp;gt;1261&amp;lt;/code&amp;gt;&lt;br /&gt;
| rowspan=&amp;quot;4&amp;quot; | &amp;lt;code&amp;gt;1223&amp;lt;/code&amp;gt;&lt;br /&gt;
| &amp;lt;code&amp;gt;1241&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| [[Classic 6G#Rev A|Rev A]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1245&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| [[Classic 6G#Rev B|Rev B]]&lt;br /&gt;
| &amp;lt;code&amp;gt;1247&amp;lt;/code&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| Rev C&lt;br /&gt;
| &amp;lt;code&amp;gt;1250&amp;lt;/code&amp;gt;&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Main_Page&amp;diff=22406</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Main_Page&amp;diff=22406"/>
		<updated>2026-07-31T15:40:38Z</updated>

		<summary type="html">&lt;p&gt;User890104: /* Gallery */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
This is the wiki for the freemyipod project. Freemyipod is a project aimed at reverse-engineering non-iOS iPods (all models other than the Touch) and creating tools and documentation so that other people can port alternative firmwares to them such as [https://www.rockbox.org/ Rockbox] or [https://kernel.org/ Linux]. Freemyipod is a relaunch of [[Linux4nano]].&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m not an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
* If you have an [[Nano 2G]], [[Classic 6G]] or an older iPod, you can install [https://www.rockbox.org/download/ Rockbox].&lt;br /&gt;
* If you have an [[Nano 6G]] or [[Nano 7G]], you can [https://github.com/nfzerox/ipod_theme#ipod_theme install a theme].&lt;br /&gt;
* If you have an [[Nano 7G]], you can install [[NanoApps]].&lt;br /&gt;
* If you have another model, there&#039;s nothing you can currently do to help us add support and/or speed up the process, since it requires &#039;&#039;&#039;a lot&#039;&#039;&#039; of time and effort. Keep an eye on our wiki and social media for any updates!&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs on [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification) on [[Nano 3G]], [[Nano 4G]], [[Nano 5G]], [[Nano 6G]] and [[Nano 7G]]&lt;br /&gt;
* Rockbox bootloader has been published for [[Nano 3G]] and [[Nano 4G]], but [https://isthererockboxonipodnano3g.freemyipod.org/ the Rockbox port is not yet completed].&lt;br /&gt;
* Tethered code execution using [[S5Late]] (a vulnerability in DFU_DNLOAD packet parsing code) for [[Nano 6G]], [[Nano 7G]] and iPod shuffle (4th generation).&lt;br /&gt;
* Untethered code execution using [[ipod_sun]] (CVE-2010-1797) for [[Nano 6G]] and [[Nano 7G]].&lt;br /&gt;
* There&#039;s a set of earlier tooling ([[emCORE]]/[[emBIOS]]/[[iBugger]]) for [[Nano 2G]], [[Nano 3G]], [[Nano 4G]] and [[Classic 1G]] which was exploiting other vulnerabilities and was a lead-up to a port of Rockbox, but it&#039;s mostly abandoned.&lt;br /&gt;
&lt;br /&gt;
== Gallery ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Nano6g-patched-osos.jpeg|Patched [[retailOS]] on [[Nano 6G]]&lt;br /&gt;
File:Fastfetch_nano_7g_7.1-rc3.png|fastfetch on [[Nano 7G]]&lt;br /&gt;
File:Fastfetch nano 2g 6.10.png|fastfetch on [[Nano 2G]]&lt;br /&gt;
File:Linux nano 7g 7.1-rc3.jpg|[[Linux]] 7.1.0-rc3 on [[Nano 7G]]&lt;br /&gt;
File:Photo 2025-12-27 20-36-24.jpg|[[Linux]] 6.14.0 on [[Nano 7G]]&lt;br /&gt;
File:S5L8702X01.png|S5L8702 under an EM&lt;br /&gt;
File:S5L8701B05.png|S5L8701 under an EM&lt;br /&gt;
File:Nano7g-patched-osos.png|Patched [[retailOS]] on [[Nano 7G]]&lt;br /&gt;
File:Nano5g-wayland.png|Wayland on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-neofetch.png|neofetch on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-diskmode-patched.png|Patched [[Modes#Disk_mode|disk mode]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console2.png|[[Linux]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console.png|[[Linux]] 6.2.0-rc4 on [[Nano 5G]]&lt;br /&gt;
File:EmCORE_Nano2G_Nano4G_Classic.jpg|[[emCORE]] r779 on [[Nano 2G]], [[Nano 4G]] and [[Classic 2G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting an account ==&lt;br /&gt;
Due to spambots, registration is closed. For an account contact [[User:User890104|User890104]] or [[User:Q3k|q3k]].&lt;br /&gt;
&lt;br /&gt;
==Updates==&lt;br /&gt;
* {{#dateformat:2026-03-30}} - Some of us will be at [https://entropia.de/GPN24 GPN24] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2025-12-28}} - [[User:Hug0|Hug0]] made a lightning talk at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] on [https://www.youtube.com/watch?v=FKHL1yyOKJc iPod Nano reverse engineering].&lt;br /&gt;
* {{#dateformat:2025-12-26}} - Some of us will be at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] in Hamburg! Get in touch with [https://events.ccc.de/congress/2025/hub/en/user/q3k q3k] and/or [https://events.ccc.de/congress/2025/hub/en/user/slackware Slackware] if you&#039;re around!&lt;br /&gt;
* {{#dateformat:2025-06-12}} - Some of us will be at [https://entropia.de/GPN23 GPN23] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2024-12-25}} - Some of us will be at [https://events.ccc.de/congress/2024/infos/startpage.html 38C3] in Hamburg! [https://events.ccc.de/congress/2024/hub/en/project/ipod-nano-hacking-freemyipod/ Come say hi!]&lt;br /&gt;
* {{#dateformat:2024-12-16}} - [[S5Late]], a tethered iPod bootrom/DFU exploit for [[Nano 7G]] (and possibly [[Nano 6G]]), is released.&lt;br /&gt;
* {{#dateformat:2023-12-28}} - [[ipod_sun]], a tool that enables code execution on the [[Nano 6G]] and [[Nano 7G]], is released.&lt;br /&gt;
* {{#dateformat:2023-01-07}} - A preliminary [[U-Boot]] port to the [[Nano 5G]] [https://social.hackerspace.pl/@q3k/109655916469636189 has been developed].&lt;br /&gt;
* {{#dateformat:2022-01-04}} - The bootrom of [[Nano 5G]] was successfully dumped, and is in the process of being reverse-engineered!&lt;br /&gt;
* {{#dateformat:2021-12-31}} - An exploit named [[wInd3x]], which exploits the latest vulnerability, is being prepared for [[Nano 4G]] and [[Nano 5G]].&lt;br /&gt;
* {{#dateformat:2021-12-27}} - A new vulnerability was discovered in [[Nano 4G]] and [[Nano 5G]] bootrom, which allows arbitrary code execution!&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* {{#dateformat:2018-08-25}} - The website software has been updated to MediaWiki 1.31 after about 2 months of downtime.&lt;br /&gt;
* {{#dateformat:2016-06-17}} - The freemyipod project is becoming deprecated, as parts of the code is slowly being integrated in Rockbox. It is likely that no future development on the freemyipod project will take place. Essential parts of emCORE helped building a Rockbox bootloader for iPod Classic, and any future development will take place in the Rockbox project.&lt;br /&gt;
* {{#dateformat:2014-03-26}} - A bug that prevented [[emCORE]] installations on certain Windows configurations (getting stuck on &amp;quot;Booting UBI file...&amp;quot;), has been finally fixed! If the installation has failed for you before, you can retry it using the updated version of our tool (use the iTunes method for now).&lt;br /&gt;
* {{#dateformat:2012-01-02}} - There have been some problems with the latest release. A hotfix release ([[EmCORE_Releases/r859|r859]]) has been published to fix some of these problems. [[Nano 2G]] users are advised to upgrade.  See the [[EmCORE_Releases/r859|release details page]] for more information.&lt;br /&gt;
* {{#dateformat:2012-01-01}} - A new release &amp;lt;s&amp;gt;([[EmCORE_Releases/r855|r855]])&amp;lt;/s&amp;gt; is out! It includes a couple of new features, several bugfixes and a new bootmenu theme! More information on the &amp;lt;s&amp;gt;[[EmCORE_Releases/r855|release details page]]&amp;lt;/s&amp;gt;.&lt;br /&gt;
* {{#dateformat:2011-04-25}} - The [[emCORE]] kernel now runs on the iPod Touch 2G as well, thanks to the help of kleemajo. This is of course not a fully functional port yet, but we&#039;ll see how it continues. It&#039;s about the same state as the [[Nano 4G]] now. /7&lt;br /&gt;
* {{#dateformat:2011-03-25}} - [[emCORE]] is replacing [[emBIOS]] completely now. Therefore [[emBIOS]] will be deprecated software as of now! All emBIOS users are advised to upgrade to emCORE including people using iLoader 0.2.2 or less. More detailed update instructions will follow!&lt;br /&gt;
* {{#dateformat:2011-01-08}} - The Rockbox port for the iPod Classic is slowly getting usable. Most of the blocking issues have been fixed. The  first-generation 160GB model still doesn&#039;t work, and some people are experiencing slightly garbled display contents.&lt;br /&gt;
* {{#dateformat:2011-01-04}} - There is an early Rockbox port for the iPod Classic! It still isn&#039;t quite usable, playback stutters etc., but if you want to play around with it, here are some quick&#039;n&#039;dirty notes on the installation procedure: [[IPod Classic iLoader Installation]]&lt;br /&gt;
* {{#dateformat:2010-11-22}} - We now have emBIOS support for the iPod classic 1g, the others might follow soon&lt;br /&gt;
* {{#dateformat:2010-08-29}} - We&#039;re proud to announce the release of [[emBIOS]] v0.1.0 and [[iLoader]] v0.2.0!&lt;br /&gt;
* {{#dateformat:2010-08-26}} - [[iLoader]], its installer and uninstaller all have been fully ported to [[emBIOS]] now. A beta release will be coming soon!&lt;br /&gt;
* {{#dateformat:2010-08-13}} - [[emBIOS]] is continually being improved and the next step is porting tools like [[iLoader]] to use it.&lt;br /&gt;
* {{#dateformat:2010-08-06}} - The wiki has now been moved to www.freemyipod.org&lt;br /&gt;
* {{#dateformat:2010-08-05}} - Recently we&#039;ve been working on a hardware abstraction project called [[emBIOS]]. Follow development [https://websvn.freemyipod.org/listing.php?repname=freemyipod&amp;amp;path=/embios/ here]&lt;br /&gt;
* {{#dateformat:2010-08-03}} - We can now access the [[Nano 4G]] accelerometer.&lt;br /&gt;
* {{#dateformat:2010-08-02}} - serpilliere managed to decrypt the NOR flash on the [[Nano 3G]].&lt;br /&gt;
* {{#dateformat:2010-08-01}} - serpilliere managed to access and dump the NOR flash on the [[Nano 3G]]. This code could possibly work on the Classics.&lt;br /&gt;
* {{#dateformat:2010-07-27}} - The server got zapped by lightning but a new one was up and running within a day.&lt;br /&gt;
* {{#dateformat:2010-02-23}} - We can now execute code on everything besides the [[Nano 5G]]! Minimalistic iBugger working on [[Nano 3G]]!&lt;br /&gt;
* {{#dateformat:2009-11-01}} - iBugger core v0.1 successfully running on [[Nano 4G]]! [https://img217.imageshack.us/img217/4122/img0969.jpg]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
Follow [https://x.com/freemyipod our X feed] to get status updates automatically. See the [[Status]] page for more detailed information. Check our [https://github.com/freemyipod GitHub repositories] for the latest changes to our source code.&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Project info===&lt;br /&gt;
* [[ Status ]]&lt;br /&gt;
* [[ Contact ]]&lt;br /&gt;
* [[ Contributing ]]&lt;br /&gt;
&lt;br /&gt;
===Released Software===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[ipod_sun]]&lt;br /&gt;
* [[U-Boot|U-Boot port]]&lt;br /&gt;
* [[Linux|Linux port]]&lt;br /&gt;
* Legacy:&lt;br /&gt;
** [[iBugger]]&lt;br /&gt;
** [[iLoader]]&lt;br /&gt;
** [[emCORE]]&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
===Basic skills===&lt;br /&gt;
* [[Working with binaries]]&lt;br /&gt;
* [[Dumping firmware]]&lt;br /&gt;
* [[Extracting firmware]]&lt;br /&gt;
* [[Firmware downgrading]]&lt;br /&gt;
* [[Troubleshooting]]&lt;br /&gt;
&lt;br /&gt;
===Reverse engineering results===&lt;br /&gt;
* [[Firmware]]&lt;br /&gt;
** [[Bootrom]]&lt;br /&gt;
** [[Boot Process]]&lt;br /&gt;
** [[Firmware decryption]]&lt;br /&gt;
** [[FTL|Flash Translation Layer]]&lt;br /&gt;
** [[RetailOS]]&lt;br /&gt;
*** [[RetailOS Options]]&lt;br /&gt;
* [[GUID table]]&lt;br /&gt;
* [[JTAG]]&lt;br /&gt;
* Nano 2G&lt;br /&gt;
** [[Nano2G clock gates‎]]&lt;br /&gt;
** [[Nano2G LCD init]]&lt;br /&gt;
** [[Nano2G HW analysis]]&lt;br /&gt;
** [[S5L8701 analysis]]&lt;br /&gt;
* Nano 4G&lt;br /&gt;
** [[Nano4G firmware upgrade process]]&lt;br /&gt;
* Nano 5G&lt;br /&gt;
** [[Nano 5G|General]]&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Hardware===&lt;br /&gt;
* [[Hardware]]&lt;br /&gt;
** [[Nano 1G]]&lt;br /&gt;
** [[Nano 2G]]&lt;br /&gt;
** [[Nano 3G]]&lt;br /&gt;
** [[Nano 4G]]&lt;br /&gt;
*** [[920-0614-03]]&lt;br /&gt;
** [[Nano 5G]]&lt;br /&gt;
** [[Nano 6G]]&lt;br /&gt;
** [[Nano 7G]]&lt;br /&gt;
** [[Classic 6G]]&lt;br /&gt;
* [[Chronology]]&lt;br /&gt;
* [[S5L8700 datasheet]]&lt;br /&gt;
* [[Modes]]&lt;br /&gt;
&lt;br /&gt;
===Exploiting===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[Pwnage 2.0]]&lt;br /&gt;
* [[Notes vulnerability]]&lt;br /&gt;
** [[Address bruteforcing]]&lt;br /&gt;
** [[Nanotron 3000]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano7g-diskmode-2.jpg&amp;diff=22405</id>
		<title>File:Nano7g-diskmode-2.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano7g-diskmode-2.jpg&amp;diff=22405"/>
		<updated>2026-07-31T15:37:07Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano7g-diskmode-1.jpg&amp;diff=22404</id>
		<title>File:Nano7g-diskmode-1.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano7g-diskmode-1.jpg&amp;diff=22404"/>
		<updated>2026-07-31T15:36:53Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano7g-diagmode.jpg&amp;diff=22403</id>
		<title>File:Nano7g-diagmode.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano7g-diagmode.jpg&amp;diff=22403"/>
		<updated>2026-07-31T15:36:38Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano6g-diskmode-2.jpg&amp;diff=22402</id>
		<title>File:Nano6g-diskmode-2.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano6g-diskmode-2.jpg&amp;diff=22402"/>
		<updated>2026-07-31T15:36:23Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano6g-diskmode-1.jpg&amp;diff=22401</id>
		<title>File:Nano6g-diskmode-1.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano6g-diskmode-1.jpg&amp;diff=22401"/>
		<updated>2026-07-31T15:36:04Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano6g-diagmode.jpg&amp;diff=22400</id>
		<title>File:Nano6g-diagmode.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano6g-diagmode.jpg&amp;diff=22400"/>
		<updated>2026-07-31T15:35:45Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-diskmode-2.jpg&amp;diff=22399</id>
		<title>File:Nano5g-diskmode-2.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-diskmode-2.jpg&amp;diff=22399"/>
		<updated>2026-07-31T15:35:29Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-diskmode-1.jpg&amp;diff=22398</id>
		<title>File:Nano5g-diskmode-1.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-diskmode-1.jpg&amp;diff=22398"/>
		<updated>2026-07-31T15:35:14Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-diagmode.jpg&amp;diff=22397</id>
		<title>File:Nano5g-diagmode.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-diagmode.jpg&amp;diff=22397"/>
		<updated>2026-07-31T15:34:56Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano4g-diskmode-2.jpg&amp;diff=22396</id>
		<title>File:Nano4g-diskmode-2.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano4g-diskmode-2.jpg&amp;diff=22396"/>
		<updated>2026-07-31T15:34:39Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano4g-diskmode-1.jpg&amp;diff=22395</id>
		<title>File:Nano4g-diskmode-1.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano4g-diskmode-1.jpg&amp;diff=22395"/>
		<updated>2026-07-31T15:34:24Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano4g-diagmode.jpg&amp;diff=22394</id>
		<title>File:Nano4g-diagmode.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano4g-diagmode.jpg&amp;diff=22394"/>
		<updated>2026-07-31T15:34:05Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano3g-diskmode-2.jpg&amp;diff=22393</id>
		<title>File:Nano3g-diskmode-2.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano3g-diskmode-2.jpg&amp;diff=22393"/>
		<updated>2026-07-31T15:33:44Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano3g-diskmode-1.jpg&amp;diff=22392</id>
		<title>File:Nano3g-diskmode-1.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano3g-diskmode-1.jpg&amp;diff=22392"/>
		<updated>2026-07-31T15:33:28Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano3g-diagmode.jpg&amp;diff=22391</id>
		<title>File:Nano3g-diagmode.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano3g-diagmode.jpg&amp;diff=22391"/>
		<updated>2026-07-31T15:33:11Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano2g-diskmode-2.jpg&amp;diff=22390</id>
		<title>File:Nano2g-diskmode-2.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano2g-diskmode-2.jpg&amp;diff=22390"/>
		<updated>2026-07-31T15:32:49Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano2g-diskmode-1.jpg&amp;diff=22389</id>
		<title>File:Nano2g-diskmode-1.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano2g-diskmode-1.jpg&amp;diff=22389"/>
		<updated>2026-07-31T15:31:50Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano2g-diagmode.jpg&amp;diff=22388</id>
		<title>File:Nano2g-diagmode.jpg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano2g-diagmode.jpg&amp;diff=22388"/>
		<updated>2026-07-31T15:28:39Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22387</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22387"/>
		<updated>2026-07-31T10:12:06Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
We&#039;ve been working on an experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]. It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an [[IMG1]] and sending it to [[WTF]]. This is what [[wInd3x]] does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Getting the source ===&lt;br /&gt;
&lt;br /&gt;
 $ git clone git@github.com:freemyipod/u-boot.git&lt;br /&gt;
 $ cd u-boot&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 $ make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 $ make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 $ make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 $ make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
You&#039;ll need GCC for ARM (for bare metal targets, not for Linux targets), OpenSSL and GnuTLS.&lt;br /&gt;
&lt;br /&gt;
On Linux distros that use apt, these can be installed using the following command.&lt;br /&gt;
&lt;br /&gt;
 # apt install gcc-arm-none-eabi libssl-dev gnutls-dev&lt;br /&gt;
&lt;br /&gt;
Then, build the U-boot binary.&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi- u-boot.bin&lt;br /&gt;
&lt;br /&gt;
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:&lt;br /&gt;
&lt;br /&gt;
 HOSTCFLAGS=&amp;quot;-I/opt/homebrew/Cellar/openssl@3/3.6.1/include&amp;quot; HOSTLDFLAGS=&amp;quot;-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib&amp;quot;&lt;br /&gt;
&lt;br /&gt;
substituting your OpenSSL version/path as needed.&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
If you have a 30-pin breakout cable with the UART pins connected to your computer (for [[Nano 6G]] and older), or a Alex/DCSD cable (for [[Nano 7G]]), you can see and interact with U-boot&#039;s console. Launch a serial client like picocom before running U-boot. Here is an example command line.&lt;br /&gt;
&lt;br /&gt;
 $ picocom --quiet --baud 115200 --imap lfcrlf /dev/ttyUSB0 # or whatever the correct port is&lt;br /&gt;
&lt;br /&gt;
Make sure your user is in the &amp;lt;code&amp;gt;dialout&amp;lt;/code&amp;gt; group or similar, so you can access serial ports.&lt;br /&gt;
&lt;br /&gt;
If you have a regular cable, skip this command. USB DFU interface will still be accessible.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 2G]] ====&lt;br /&gt;
&lt;br /&gt;
Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:&lt;br /&gt;
 $ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod&lt;br /&gt;
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).&lt;br /&gt;
&lt;br /&gt;
The command may fail the first time, retry one or two times before asking for help.&lt;br /&gt;
&lt;br /&gt;
=== Pushing an image to U-boot ===&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;br /&gt;
&lt;br /&gt;
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).&lt;br /&gt;
&lt;br /&gt;
== Work in progress==&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 4G]] and it seems to be working at first glance.&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 6G]], but if you don&#039;t stop the countdown before auto-booting, it gets stuck since the timer which is used to measure how much a second takes is not initialized properly. You can flood the UART console with key presses just while U-boot is printing the messages to skip the auto-boot prompt entiery and get dropped into a U-boot console.&lt;br /&gt;
&lt;br /&gt;
Your mileage may vary. Patches welcome.&lt;br /&gt;
&lt;br /&gt;
== U-boot logs ==&lt;br /&gt;
=== [[Nano 2G]] ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;debug_uart&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:02 +0300)&lt;br /&gt;
&lt;br /&gt;
CPU:   Samsung S5L8701 (ARM940T)&lt;br /&gt;
Model: Apple iPod nano (2nd generation)&lt;br /&gt;
DRAM:  32 MiB&lt;br /&gt;
Core:  8 devices, 7 uclasses, devicetree: separate&lt;br /&gt;
MMC:   &lt;br /&gt;
Loading Environment from nowhere... OK&lt;br /&gt;
In:    uart@3cc00000&lt;br /&gt;
Out:   uart@3cc00000&lt;br /&gt;
Err:   uart@3cc00000&lt;br /&gt;
Net:   No ethernet found.&lt;br /&gt;
Hit any key to stop autoboot:  0 &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== [[Nano 3G]] ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;debug_uart&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:14 +0300)&lt;br /&gt;
&lt;br /&gt;
CPU:   Samsung S5L8702 (ARM926EJ-S)&lt;br /&gt;
Model: Apple iPod nano (3rd generation)&lt;br /&gt;
DRAM:  32 MiB&lt;br /&gt;
LCD:   Type 38b3 (0)&lt;br /&gt;
Core:  8 devices, 7 uclasses, devicetree: separate&lt;br /&gt;
MMC:   &lt;br /&gt;
Loading Environment from nowhere... OK&lt;br /&gt;
In:    uart@3cc00000&lt;br /&gt;
Out:   uart@3cc00000&lt;br /&gt;
Err:   uart@3cc00000&lt;br /&gt;
Net:   No ethernet found.&lt;br /&gt;
Hit any key to stop autoboot:  0 &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== [[Nano 5G]] ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;debug_uart&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:25 +0300)&lt;br /&gt;
&lt;br /&gt;
CPU:   Samsung S5L8730 (ARM1176JZF-S)&lt;br /&gt;
Model: Apple iPod nano (5th generation)&lt;br /&gt;
DRAM:  64 MiB&lt;br /&gt;
LCD:   Type 38b3 (0)&lt;br /&gt;
Core:  8 devices, 7 uclasses, devicetree: separate&lt;br /&gt;
MMC:   &lt;br /&gt;
Loading Environment from nowhere... OK&lt;br /&gt;
In:    uart@3cc00000&lt;br /&gt;
Out:   uart@3cc00000&lt;br /&gt;
Err:   uart@3cc00000&lt;br /&gt;
Net:   No ethernet found.&lt;br /&gt;
Hit any key to stop autoboot:  0 &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
=== [[Nano 7G]] ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;debug_uart&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
U-Boot 2025.07-rc4-g116c6099a58f (Jul 31 2026 - 12:47:39 +0300)&lt;br /&gt;
&lt;br /&gt;
CPU:   Samsung S5L8740 (ARM Cortex A5)&lt;br /&gt;
Model: Apple iPod nano (7th generation)&lt;br /&gt;
DRAM:  64 MiB&lt;br /&gt;
Core:  10 devices, 7 uclasses, devicetree: separate&lt;br /&gt;
MMC:   &lt;br /&gt;
Loading Environment from nowhere... OK&lt;br /&gt;
In:    uart@3dd00000&lt;br /&gt;
Out:   uart@3dd00000&lt;br /&gt;
Err:   uart@3dd00000&lt;br /&gt;
Net:   No ethernet found.&lt;br /&gt;
Hit any key to stop autoboot:  0 &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=NanoApps&amp;diff=22386</id>
		<title>NanoApps</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=NanoApps&amp;diff=22386"/>
		<updated>2026-07-29T20:41:42Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===== Run custom homebrew apps on iPod nano 7th generation. =====&lt;br /&gt;
== Overview ==&lt;br /&gt;
NanoApps is an early developer preview for hobbyists and tinkerers who want to build and run custom apps for iPod nano 7th generation. This is the very beginning of custom apps on nano: it needs a lot more research and polish before it can become a daily-driver app platform, but early results are promising, allowing you to run basic versions of [[:File:NanoApps_Paint.png|Paint]], [[:File:NanoApps_Notes.png|Notes]], [[:File:NanoApps_WAV_Player.png|WAV Player]], and [[:File:NanoApps_Launcher.png|Homebrew Launcher]] on nano today. Contributions are very welcome; see [https://github.com/nfzerox/NanoApps/blob/main/README.md#contributing-to-nanoapps Contributing to NanoApps], join the [https://discord.gg/Er3KJwaCMg Discord server], and share what you build on [https://www.reddit.com/r/ipod/ r/ipod].&lt;br /&gt;
&lt;br /&gt;
[[File:NanoApps_Overview.png|640px]]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
* Source code: https://github.com/nfzerox/NanoApps&lt;br /&gt;
* Discord server: https://discord.gg/Er3KJwaCMg&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=NanoApps&amp;diff=22385</id>
		<title>NanoApps</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=NanoApps&amp;diff=22385"/>
		<updated>2026-07-29T20:41:24Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===== Run custom homebrew apps on iPod nano 7th generation. =====&lt;br /&gt;
== Overview ==&lt;br /&gt;
NanoApps is an early developer preview for hobbyists and tinkerers who want to build and run custom apps for iPod nano 7th generation. This is the very beginning of custom apps on nano: it needs a lot more research and polish before it can become a daily-driver app platform, but early results are promising, allowing you to run basic versions of [[:File:NanoApps_Paint.png|Paint]], [[:File:NanoApps_Notes.png|Notes]], [[:File:NanoApps_WAV_Player.png|WAV Player]], and [[:File:NanoApps_Launcher.png|Homebrew Launcher]] on nano today. Contributions are very welcome; see [https://github.com/nfzerox/NanoApps/blob/main/README.md#contributing-to-nanoapps Contributing to NanoApps], join the Discord server, and share what you build on [https://www.reddit.com/r/ipod/ r/ipod].&lt;br /&gt;
&lt;br /&gt;
[[File:NanoApps_Overview.png|640px]]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
* Source code: https://github.com/nfzerox/NanoApps&lt;br /&gt;
* Discord server: https://discord.gg/Er3KJwaCMg&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=NanoApps&amp;diff=22384</id>
		<title>NanoApps</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=NanoApps&amp;diff=22384"/>
		<updated>2026-07-29T20:40:45Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===== Run custom homebrew apps on iPod nano 7th generation. =====&lt;br /&gt;
== Overview ==&lt;br /&gt;
NanoApps is an early developer preview for hobbyists and tinkerers who want to build and run custom apps for iPod nano 7th generation. This is the very beginning of custom apps on nano: it needs a lot more research and polish before it can become a daily-driver app platform, but early results are promising, allowing you to run basic versions of [[:File:NanoApps_Paint.png|Paint]], [[:File:NanoApps_Notes.png|Notes]], [[:File:NanoApps_WAV_Player.png|WAV Player]], and [[:File:NanoApps_Launcher.png|Homebrew Launcher]] on nano today. Contributions are very welcome; see [https://github.com/nfzerox/NanoApps/blob/main/README.md#contributing-to-nanoapps Contributing to NanoApps], join the [https://discord.gg/7PnGEXjW3X iPod nano Hacking Discord], and share what you build on [https://www.reddit.com/r/ipod/ r/ipod].&lt;br /&gt;
&lt;br /&gt;
[[File:NanoApps_Overview.png|640px]]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
* Source code: https://github.com/nfzerox/NanoApps&lt;br /&gt;
* Discord server: https://discord.gg/Er3KJwaCMg&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=WInd3x&amp;diff=22383</id>
		<title>WInd3x</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=WInd3x&amp;diff=22383"/>
		<updated>2026-07-28T21:14:25Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== wInd3x Vulnerability ==&lt;br /&gt;
{{DISPLAYTITLE:wInd3x}}&lt;br /&gt;
&lt;br /&gt;
A [[S5L8720 Bootrom|Bootrom]] vulnerability discovered and exploited by [[User:Q3k|q3k]] in December 2021. It allows code execution in the bootrom over USB.&lt;br /&gt;
&lt;br /&gt;
=== Affected Devices ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Device/SoC !! Vulnerable? !! Exploited?&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 3G]] || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 4G]] || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 5G]] || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 6G]] || No || &lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 7G]] || No || &lt;br /&gt;
|-&lt;br /&gt;
| Classic “6G” || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| iPhone || ? ||&lt;br /&gt;
|-&lt;br /&gt;
| iPhone 3G || Yes || No&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://github.com/freemyipod/wInd3x&lt;br /&gt;
 $ cd wInd3x&lt;br /&gt;
&lt;br /&gt;
You&#039;ll need Golang and libusb. On a Linux system that uses apt, they can be installed using:&lt;br /&gt;
 # apt install golang libusb-1.0-0-dev&lt;br /&gt;
It is recommended that you get an up-to-date Golang distribution from https://go.dev/ or build it yourself, instead of relying on your distro&#039;s probably outdated version.&lt;br /&gt;
&lt;br /&gt;
Then:&lt;br /&gt;
 $ go build ./cmd/wInd3x&lt;br /&gt;
Or, if you have Nix(OS), just do:&lt;br /&gt;
 $ nix-build&lt;br /&gt;
=== Running / Usage ===&lt;br /&gt;
&lt;br /&gt;
wInd3x currently allows you to:&lt;br /&gt;
&lt;br /&gt;
# Decrypt [[IMG1]] files, like [[OSOS]] or the bootloader/[[WTF]]/...&lt;br /&gt;
# Access arbitrary memory and experiment with peripherals&lt;br /&gt;
# Run unsigned DFU payloads&lt;br /&gt;
# Run an unsigned [[OSOS]] or [[U-Boot]] by first running an automatically patched [[WTF]].&lt;br /&gt;
&lt;br /&gt;
For guides, see [https://github.com/freemyipod/wInd3x github.com/freemyipod/wInd3x]&lt;br /&gt;
&lt;br /&gt;
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability ===&lt;br /&gt;
&lt;br /&gt;
This exploits a vulnerability in the standard SETUP packet parsing code of the bootrom, in which the wIndex parameter is not checked for bmRequest == {0x20, 0x40}, but is still used to index an array of interface/class handlers (that in the Bootrom has a length of 1).&lt;br /&gt;
&lt;br /&gt;
==== Nano 4G and 5G Exploit Chain ====&lt;br /&gt;
&lt;br /&gt;
The first requirement is to find a suitable (blx r0) instruction in the bootrom code of the device. For Nano 4G the only one such instruction is at offset 0x3b0, and for Nano 5G there is such instruction at 0x37c. We&#039;ll refer to it as X below.&lt;br /&gt;
&lt;br /&gt;
We abuse the fact that wIndex == 3 for bmRequest 0x40 treats a &#039;bytes left to sent over USB&#039; counter as a function pointer and calls it with r0 == address of SETUP. We massage the DFU mode into attempting to send us X+0x40 bytes, and failing after 0x40 bytes, thereby leaving the counter at X bytes and executing code at address X.&lt;br /&gt;
&lt;br /&gt;
Since the bootrom is mapped at offset 0x0 as well as 0x20000000 at boot, this means we execute bootrom code, and X happens to point to a &#039;blx r0&#039; instruction. This in turn causes the CPU to interpret the SETUP packet received as ARM code, because the SETUP handler is called with the SETUP packet as its argument, i.e. r0.&lt;br /&gt;
&lt;br /&gt;
We specially craft the SETUP packet to be a valid ARM branch instruction, pointing somewhere into a temporary DFU image buffer. By first sending a payload as a partial DFU image (aborting before causing a MANIFEST), we finally get up to be able to execute either 0x800 on Nano 4G or 0x400 on Nano 5G bytes of fully user controlled code.&lt;br /&gt;
&lt;br /&gt;
In that payload, we send a stub which performs some runtime changes to the DFU&#039;s data structures to a) return a different product string b) overwrite an image verification vtable entry with a function that allows unsigned images. Some SRAM is carved out by this pay&lt;br /&gt;
&lt;br /&gt;
==== Nano 3G and Classic (”6G”) ====&lt;br /&gt;
&lt;br /&gt;
With bRequestType == 0x20 and wIndex == 6 we directly jump to code execution at the SETUP packet.&lt;br /&gt;
&lt;br /&gt;
This Bootroom does not have a VTable which can be easily hooked to override functions to provide Haxed DFU functionality. However, an &#039;OnImage&#039; function pointer is present in the State structure, which we override with our own code (copied to carved out SRAM). This code reimplements the bare minimum of the hooked function, without calling any decryption/verification code on the header/body.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22382</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22382"/>
		<updated>2026-07-28T21:10:43Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
We&#039;ve been working on an experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]. It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an [[IMG1]] and sending it to [[WTF]]. This is what [[wInd3x]] does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Getting the source ===&lt;br /&gt;
&lt;br /&gt;
 $ git clone git@github.com:freemyipod/u-boot.git&lt;br /&gt;
 $ cd u-boot&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 $ make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 $ make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 $ make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 $ make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
You&#039;ll need GCC for ARM (for bare metal targets, not for Linux targets), OpenSSL and GnuTLS.&lt;br /&gt;
&lt;br /&gt;
On Linux distros that use apt, these can be installed using the following command.&lt;br /&gt;
&lt;br /&gt;
 # apt install gcc-arm-none-eabi libssl-dev gnutls-dev&lt;br /&gt;
&lt;br /&gt;
Then, build the U-boot binary.&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi- u-boot.bin&lt;br /&gt;
&lt;br /&gt;
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:&lt;br /&gt;
&lt;br /&gt;
 HOSTCFLAGS=&amp;quot;-I/opt/homebrew/Cellar/openssl@3/3.6.1/include&amp;quot; HOSTLDFLAGS=&amp;quot;-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib&amp;quot;&lt;br /&gt;
&lt;br /&gt;
substituting your OpenSSL version/path as needed.&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
If you have a 30-pin breakout cable with the UART pins connected to your computer (for [[Nano 6G]] and older), or a Alex/DCSD cable (for [[Nano 7G]]), you can see and interact with U-boot&#039;s console. Launch a serial client like picocom before running U-boot. Here is an example command line.&lt;br /&gt;
&lt;br /&gt;
 $ picocom --quiet --baud 115200 --imap lfcrlf /dev/ttyUSB0 # or whatever the correct port is&lt;br /&gt;
&lt;br /&gt;
Make sure your user is in the &amp;lt;code&amp;gt;dialout&amp;lt;/code&amp;gt; group or similar, so you can access serial ports.&lt;br /&gt;
&lt;br /&gt;
If you have a regular cable, skip this command. USB DFU interface will still be accessible.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 2G]] ====&lt;br /&gt;
&lt;br /&gt;
Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:&lt;br /&gt;
 $ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod&lt;br /&gt;
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).&lt;br /&gt;
&lt;br /&gt;
The command may fail the first time, retry one or two times before asking for help.&lt;br /&gt;
&lt;br /&gt;
=== Pushing an image to U-boot ===&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;br /&gt;
&lt;br /&gt;
Make sure your user can access the raw USB device, add udev rules (recommended) or run with root (not recommended).&lt;br /&gt;
&lt;br /&gt;
== Work in progress==&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 4G]] and it seems to be working at first glance.&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 6G]], but if you don&#039;t stop the countdown before auto-booting, it gets stuck since the timer which is used to measure how much a second takes is not initialized properly. You can flood the UART console with key presses just while U-boot is printing the messages to skip the auto-boot prompt entiery and get dropped into a U-boot console.&lt;br /&gt;
&lt;br /&gt;
Your mileage may vary. Patches welcome.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22381</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22381"/>
		<updated>2026-07-28T16:55:10Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
An experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] lives at https://github.com/freemyipod/u-boot/tree/s5l87xx .&lt;br /&gt;
&lt;br /&gt;
It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an IMG1 and sending it to [[WTF]]. This is what wInd3x does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 $ make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 $ make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 $ make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 $ make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi- u-boot.bin&lt;br /&gt;
&lt;br /&gt;
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:&lt;br /&gt;
&lt;br /&gt;
 HOSTCFLAGS=&amp;quot;-I/opt/homebrew/Cellar/openssl@3/3.6.1/include&amp;quot; HOSTLDFLAGS=&amp;quot;-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib&amp;quot;&lt;br /&gt;
&lt;br /&gt;
substituting your OpenSSL version/path as needed.&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 2G]] ====&lt;br /&gt;
&lt;br /&gt;
Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:&lt;br /&gt;
 $ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod&lt;br /&gt;
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
=== Pushing an image to U-boot ===&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;br /&gt;
&lt;br /&gt;
== Work in progress==&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 4G]] and it seems to be working at first glance.&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 6G]], but if you don&#039;t stop the countdown before auto-booting, it gets stuck since the timer which is used to measure how much a second takes is not initialized properly. You can flood the UART console with key presses just while U-boot is printing the messages to skip the auto-boot prompt entiery and get dropped into a U-boot console.&lt;br /&gt;
&lt;br /&gt;
Your mileage may vary. Patches welcome.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Linux&amp;diff=22380</id>
		<title>Linux</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Linux&amp;diff=22380"/>
		<updated>2026-07-26T21:04:19Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Current: Freemyipod Linux ==&lt;br /&gt;
&lt;br /&gt;
We are working on supporting Samsung/S5L-based devices which have an MMU. Currently our main focus is the [[Nano 7G]], there are also builds for [[Nano 2G]], [[Nano 3G]] and [[Nano 5G]]. An experimental source tree is available on [https://github.com/freemyipod/linux github.com/freemyipod/linux]. Aditionaly [[User:ZeOne]] is working on making it work with the [[Nano 6G]] you can read more about that on his page.&lt;br /&gt;
&lt;br /&gt;
=== User Guide ===&lt;br /&gt;
&lt;br /&gt;
Not yet available, as the Linux port isn&#039;t yet practical to use. We have no storage drivers, no sound driver...&lt;br /&gt;
&lt;br /&gt;
=== Developer Guide ===&lt;br /&gt;
&lt;br /&gt;
If you&#039;re somewhat familiar with embedded Linux, you can get started by building [[WInd3x|wInd3x]], [[U-Boot]] and the Kernel as described below. However, &#039;&#039;&#039;you will have to provide your own userland&#039;&#039;&#039; (eg. buildroot, archlinux arm, ... anything armv6 compatible) and either run it from an initramfs or over NFS. &#039;&#039;&#039;A serial cable is not necessary, but very useful to troubleshoot boot issues.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== Build everything ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;These are not copy-paste instructions. You are expected to understand what&#039;s happening.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
You will need an arm-none-eabi- toolchain into your $PATH, eg. gcc-arm-embedded from your package manager.&lt;br /&gt;
&lt;br /&gt;
First, build [[wInd3x#Building]].&lt;br /&gt;
&lt;br /&gt;
Second, build [[U-Boot]].&lt;br /&gt;
&lt;br /&gt;
Third, Linux:&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://github.com/freemyipod/linux&lt;br /&gt;
 $ cd linux&lt;br /&gt;
&lt;br /&gt;
For [[Nano 2G]]:&lt;br /&gt;
 $ git checkout n2g-wip&lt;br /&gt;
 $ make ARCH=arm nano2g_defconfig&lt;br /&gt;
&lt;br /&gt;
For [[Nano 3G]] and [[Nano 7G]]:&lt;br /&gt;
 $ git checkout s5l87xx&lt;br /&gt;
 $ make ARCH=arm apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 $ make ARCH=arm apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
For iPod nano (5th generation):&lt;br /&gt;
 $ git checkout n5g-wip&lt;br /&gt;
 $ make ARCH=arm nano5g_defconfig&lt;br /&gt;
&lt;br /&gt;
After configuring, build the kernel:&lt;br /&gt;
 $ make ARCH=arm CROSS_COMPILE=arm-none-eabi- -j $(nproc) zImage&lt;br /&gt;
&lt;br /&gt;
By this point, have a initramfs ready. If you wanna boot directly from nfs, edit CMDLINE in the kernel .config accordingly.&lt;br /&gt;
&lt;br /&gt;
Finally, bundle together an u-boot image containing the kernel, your initramfs, and the device-tree (built by u-boot):&lt;br /&gt;
&lt;br /&gt;
 $ mkimage -A arm -C none -O linux -T multi -a 0x08000000 -e 0x08000000 -d arch/arm/boot/zImage:initramfs.gz:../u-boot/arch/arm/dts/s5l8730.dtb mImage&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;mImage&#039;&#039; is your combined image.&lt;br /&gt;
&lt;br /&gt;
TODO: add instructions how to use the Makefile-based initramfs generation script and mkimage from U-boot.&lt;br /&gt;
&lt;br /&gt;
==== Running ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod nano in DFU mode.&lt;br /&gt;
&lt;br /&gt;
===== For [[Nano 3G]] and later =====&lt;br /&gt;
&lt;br /&gt;
Execute u-boot using wInd3x:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run ../u-boot/u-boot.bin&lt;br /&gt;
&lt;br /&gt;
This should start u-boot. Running this for the first time will take a while, as some bootloader stages need to be downloaded, decrypted and modified. A new USB device (05ac:8007) appear on your host. Use dfu-util to upload mImage:&lt;br /&gt;
&lt;br /&gt;
 dfu-util --device 05ac:8007 --download mImage&lt;br /&gt;
 dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;br /&gt;
&lt;br /&gt;
===== For the [[Nano 2G]] =====&lt;br /&gt;
&lt;br /&gt;
You will have to chainload the rockbox bootloader with U-boot.&lt;br /&gt;
&lt;br /&gt;
To do this, we assume you have already built U-boot dtbs along with Linux.&lt;br /&gt;
&lt;br /&gt;
To create the mImage, run this command inside your Linux folder:&lt;br /&gt;
&lt;br /&gt;
 $ ./create_image.sh&lt;br /&gt;
&lt;br /&gt;
Note: if it dosen’t work, you will have to make it executable, usually by running:&lt;br /&gt;
&lt;br /&gt;
 $ chmod +x create_image.sh&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After it creates the mImage, go to your u-boot folder and build u-boot.bin.&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi- -j $(nproc) u-boot.bin&lt;br /&gt;
&lt;br /&gt;
Now generate a fake rockbox.ipod that tricks it into starting U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./tools/mkimage -T ipod -d u-boot.bin rockbox.ipod&lt;br /&gt;
&lt;br /&gt;
Copy this new rockbox.ipod into the .rockbox folder on your iPod nano 2G.&lt;br /&gt;
&lt;br /&gt;
Then, in the serial console you&#039;ll see Linux booting:&lt;br /&gt;
&lt;br /&gt;
 ## Booting kernel from Legacy Image at 08000000 ...&lt;br /&gt;
 ...&lt;br /&gt;
 Starting kernel ...&lt;br /&gt;
 &lt;br /&gt;
 [    0.000000] Booting Linux on physical CPU 0x0&lt;br /&gt;
 [    0.000000] Linux version 6.2.0-rc4-00476-g4c4af4d7e53c (q3k@mimeomia) (arm-none-eabi-gcc (GNU Arm Embedded Toolchain 10.3-2021.10) 10.3.1 20210824 (release), GNU ld (GNU Arm Embedded Toolchain 10.3-2021.10) 2.36.1.20210621) #70 Fri Jan 20 18:02:56 CET 2023&lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
The LCD display should start up and show a boot log. If not, try adding &amp;lt;code&amp;gt;console=tty0&amp;lt;/code&amp;gt; to your CMDLINE? You might also use &amp;lt;code&amp;gt;fbcon=rotate:1&amp;lt;/code&amp;gt; to rotate the framebuffer 90 degrees.&lt;br /&gt;
&lt;br /&gt;
If everything goes well, the kernel should boot up and attempt to mount a rootfs. It&#039;s up to you to get this part working, at least until we streamline the process. The USB CDC EEM ethernet gadget should also appear on your host (probably as usb0, or some long systemd predictable name). The other end will be visible as &#039;usb0&#039; on the device.&lt;br /&gt;
&lt;br /&gt;
On [[Nano 7G]] you&#039;ll need a DCSD cable (Alex/Magico), and the command line to get proper serial output:&lt;br /&gt;
&lt;br /&gt;
 picocom --baud 115200 --imap lfcrlf /dev/ttyUSB0&lt;br /&gt;
&lt;br /&gt;
Now go on and have a go at reverse-engineering some peripherals! :)&lt;br /&gt;
&lt;br /&gt;
== Legacy: iPodLinux ==&lt;br /&gt;
&lt;br /&gt;
The [http://www.ipodlinux.org/ iPodLinux] project supports all the PortalPlayer based iPods: iPod 1G-4G, Photo/Color, Video/5G/5.5G, Mini, iPod Nano 1G. It is currently semi-abandoned, and uses a very old ucLinux kernel build.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22379</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22379"/>
		<updated>2026-07-26T20:57:51Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
An experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] lives at https://github.com/freemyipod/u-boot/tree/s5l87xx .&lt;br /&gt;
&lt;br /&gt;
It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an IMG1 and sending it to [[WTF]]. This is what wInd3x does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 $ make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 $ make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 $ make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 $ make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi-&lt;br /&gt;
&lt;br /&gt;
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:&lt;br /&gt;
&lt;br /&gt;
 HOSTCFLAGS=&amp;quot;-I/opt/homebrew/Cellar/openssl@3/3.6.1/include&amp;quot; HOSTLDFLAGS=&amp;quot;-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib&amp;quot;&lt;br /&gt;
&lt;br /&gt;
substituting your OpenSSL version/path as needed.&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 2G]] ====&lt;br /&gt;
&lt;br /&gt;
Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:&lt;br /&gt;
 $ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod&lt;br /&gt;
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
=== Pushing an image to U-boot ===&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;br /&gt;
&lt;br /&gt;
== Work in progress==&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 4G]] and it seems to be working at first glance.&lt;br /&gt;
&lt;br /&gt;
You can run the [[Nano 5G]] image on a [[Nano 6G]], but if you don&#039;t stop the countdown before auto-booting, it gets stuck since the timer which is used to measure how much a second takes is not initialized properly. You can flood the UART console with key presses just while U-boot is printing the messages to skip the auto-boot prompt entiery and get dropped into a U-boot console.&lt;br /&gt;
&lt;br /&gt;
Your mileage may vary. Patches welcome.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Main_Page&amp;diff=22378</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Main_Page&amp;diff=22378"/>
		<updated>2026-07-26T00:19:03Z</updated>

		<summary type="html">&lt;p&gt;User890104: /* Gallery */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
This is the wiki for the freemyipod project. Freemyipod is a project aimed at reverse-engineering non-iOS iPods (all models other than the Touch) and creating tools and documentation so that other people can port alternative firmwares to them such as [https://www.rockbox.org/ Rockbox] or [https://kernel.org/ Linux]. Freemyipod is a relaunch of [[Linux4nano]].&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m not an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
* If you have an [[Nano 2G]], [[Classic 6G]] or an older iPod, you can install [https://www.rockbox.org/download/ Rockbox].&lt;br /&gt;
* If you have an [[Nano 6G]] or [[Nano 7G]], you can [https://github.com/nfzerox/ipod_theme#ipod_theme install a theme].&lt;br /&gt;
* If you have an [[Nano 7G]], you can install [[NanoApps]].&lt;br /&gt;
* If you have another model, there&#039;s nothing you can currently do to help us add support and/or speed up the process, since it requires &#039;&#039;&#039;a lot&#039;&#039;&#039; of time and effort. Keep an eye on our wiki and social media for any updates!&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs on [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification) on [[Nano 3G]], [[Nano 4G]], [[Nano 5G]], [[Nano 6G]] and [[Nano 7G]]&lt;br /&gt;
* Rockbox bootloader has been published for [[Nano 3G]] and [[Nano 4G]], but [https://isthererockboxonipodnano3g.freemyipod.org/ the Rockbox port is not yet completed].&lt;br /&gt;
* Tethered code execution using [[S5Late]] (a vulnerability in DFU_DNLOAD packet parsing code) for [[Nano 6G]], [[Nano 7G]] and iPod shuffle (4th generation).&lt;br /&gt;
* Untethered code execution using [[ipod_sun]] (CVE-2010-1797) for [[Nano 6G]] and [[Nano 7G]].&lt;br /&gt;
* There&#039;s a set of earlier tooling ([[emCORE]]/[[emBIOS]]/[[iBugger]]) for [[Nano 2G]], [[Nano 3G]], [[Nano 4G]] and [[Classic 1G]] which was exploiting other vulnerabilities and was a lead-up to a port of Rockbox, but it&#039;s mostly abandoned.&lt;br /&gt;
&lt;br /&gt;
== Gallery ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Nano6g-patched-osos.jpeg|Patched [[retailOS]] on [[Nano 6G]]&lt;br /&gt;
File:Fastfetch_nano_7g_7.1-rc3.png|fastfetch on [[Nano 7G]]&lt;br /&gt;
File:Fastfetch nano 2g 6.10.png|fastfetch on [[Nano 2G]]&lt;br /&gt;
File:Linux nano 7g 7.1-rc3.jpg|[[Linux]] 7.1.0-rc3 on [[Nano 7G]]&lt;br /&gt;
File:Photo 2025-12-27 20-36-24.jpg|[[Linux]] 6.14.0 on [[Nano 7G]]&lt;br /&gt;
File:S5L8702X01.png|S5L8702 under an EM&lt;br /&gt;
File:S5L8701B05.png|S5L8701 under an EM&lt;br /&gt;
File:Nano7g-patched-osos.png|Patched [[retailOS]] on [[Nano 7G]]&lt;br /&gt;
File:Nano5g-wayland.png|Wayland on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-neofetch.png|neofetch on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-diskmode-patched.png|Patched [[Modes#Disk_mode|disk mode]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console2.png|[[Linux]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console.png|[[Linux]] 6.2.0-rc4 on [[Nano 5G]]&lt;br /&gt;
&lt;br /&gt;
File:EmCORE_Nano2G_Nano4G_Classic.jpg|[[emCORE]] r779 on [[Nano 2G]], [[Nano 4G]] and [[Classic 2G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting an account ==&lt;br /&gt;
Due to spambots, registration is closed. For an account contact [[User:User890104|User890104]] or [[User:Q3k|q3k]].&lt;br /&gt;
&lt;br /&gt;
==Updates==&lt;br /&gt;
* {{#dateformat:2026-03-30}} - Some of us will be at [https://entropia.de/GPN24 GPN24] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2025-12-28}} - [[User:Hug0|Hug0]] made a lightning talk at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] on [https://www.youtube.com/watch?v=FKHL1yyOKJc iPod Nano reverse engineering].&lt;br /&gt;
* {{#dateformat:2025-12-26}} - Some of us will be at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] in Hamburg! Get in touch with [https://events.ccc.de/congress/2025/hub/en/user/q3k q3k] and/or [https://events.ccc.de/congress/2025/hub/en/user/slackware Slackware] if you&#039;re around!&lt;br /&gt;
* {{#dateformat:2025-06-12}} - Some of us will be at [https://entropia.de/GPN23 GPN23] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2024-12-25}} - Some of us will be at [https://events.ccc.de/congress/2024/infos/startpage.html 38C3] in Hamburg! [https://events.ccc.de/congress/2024/hub/en/project/ipod-nano-hacking-freemyipod/ Come say hi!]&lt;br /&gt;
* {{#dateformat:2024-12-16}} - [[S5Late]], a tethered iPod bootrom/DFU exploit for [[Nano 7G]] (and possibly [[Nano 6G]]), is released.&lt;br /&gt;
* {{#dateformat:2023-12-28}} - [[ipod_sun]], a tool that enables code execution on the [[Nano 6G]] and [[Nano 7G]], is released.&lt;br /&gt;
* {{#dateformat:2023-01-07}} - A preliminary [[U-Boot]] port to the [[Nano 5G]] [https://social.hackerspace.pl/@q3k/109655916469636189 has been developed].&lt;br /&gt;
* {{#dateformat:2022-01-04}} - The bootrom of [[Nano 5G]] was successfully dumped, and is in the process of being reverse-engineered!&lt;br /&gt;
* {{#dateformat:2021-12-31}} - An exploit named [[wInd3x]], which exploits the latest vulnerability, is being prepared for [[Nano 4G]] and [[Nano 5G]].&lt;br /&gt;
* {{#dateformat:2021-12-27}} - A new vulnerability was discovered in [[Nano 4G]] and [[Nano 5G]] bootrom, which allows arbitrary code execution!&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* {{#dateformat:2018-08-25}} - The website software has been updated to MediaWiki 1.31 after about 2 months of downtime.&lt;br /&gt;
* {{#dateformat:2016-06-17}} - The freemyipod project is becoming deprecated, as parts of the code is slowly being integrated in Rockbox. It is likely that no future development on the freemyipod project will take place. Essential parts of emCORE helped building a Rockbox bootloader for iPod Classic, and any future development will take place in the Rockbox project.&lt;br /&gt;
* {{#dateformat:2014-03-26}} - A bug that prevented [[emCORE]] installations on certain Windows configurations (getting stuck on &amp;quot;Booting UBI file...&amp;quot;), has been finally fixed! If the installation has failed for you before, you can retry it using the updated version of our tool (use the iTunes method for now).&lt;br /&gt;
* {{#dateformat:2012-01-02}} - There have been some problems with the latest release. A hotfix release ([[EmCORE_Releases/r859|r859]]) has been published to fix some of these problems. [[Nano 2G]] users are advised to upgrade.  See the [[EmCORE_Releases/r859|release details page]] for more information.&lt;br /&gt;
* {{#dateformat:2012-01-01}} - A new release &amp;lt;s&amp;gt;([[EmCORE_Releases/r855|r855]])&amp;lt;/s&amp;gt; is out! It includes a couple of new features, several bugfixes and a new bootmenu theme! More information on the &amp;lt;s&amp;gt;[[EmCORE_Releases/r855|release details page]]&amp;lt;/s&amp;gt;.&lt;br /&gt;
* {{#dateformat:2011-04-25}} - The [[emCORE]] kernel now runs on the iPod Touch 2G as well, thanks to the help of kleemajo. This is of course not a fully functional port yet, but we&#039;ll see how it continues. It&#039;s about the same state as the [[Nano 4G]] now. /7&lt;br /&gt;
* {{#dateformat:2011-03-25}} - [[emCORE]] is replacing [[emBIOS]] completely now. Therefore [[emBIOS]] will be deprecated software as of now! All emBIOS users are advised to upgrade to emCORE including people using iLoader 0.2.2 or less. More detailed update instructions will follow!&lt;br /&gt;
* {{#dateformat:2011-01-08}} - The Rockbox port for the iPod Classic is slowly getting usable. Most of the blocking issues have been fixed. The  first-generation 160GB model still doesn&#039;t work, and some people are experiencing slightly garbled display contents.&lt;br /&gt;
* {{#dateformat:2011-01-04}} - There is an early Rockbox port for the iPod Classic! It still isn&#039;t quite usable, playback stutters etc., but if you want to play around with it, here are some quick&#039;n&#039;dirty notes on the installation procedure: [[IPod Classic iLoader Installation]]&lt;br /&gt;
* {{#dateformat:2010-11-22}} - We now have emBIOS support for the iPod classic 1g, the others might follow soon&lt;br /&gt;
* {{#dateformat:2010-08-29}} - We&#039;re proud to announce the release of [[emBIOS]] v0.1.0 and [[iLoader]] v0.2.0!&lt;br /&gt;
* {{#dateformat:2010-08-26}} - [[iLoader]], its installer and uninstaller all have been fully ported to [[emBIOS]] now. A beta release will be coming soon!&lt;br /&gt;
* {{#dateformat:2010-08-13}} - [[emBIOS]] is continually being improved and the next step is porting tools like [[iLoader]] to use it.&lt;br /&gt;
* {{#dateformat:2010-08-06}} - The wiki has now been moved to www.freemyipod.org&lt;br /&gt;
* {{#dateformat:2010-08-05}} - Recently we&#039;ve been working on a hardware abstraction project called [[emBIOS]]. Follow development [https://websvn.freemyipod.org/listing.php?repname=freemyipod&amp;amp;path=/embios/ here]&lt;br /&gt;
* {{#dateformat:2010-08-03}} - We can now access the [[Nano 4G]] accelerometer.&lt;br /&gt;
* {{#dateformat:2010-08-02}} - serpilliere managed to decrypt the NOR flash on the [[Nano 3G]].&lt;br /&gt;
* {{#dateformat:2010-08-01}} - serpilliere managed to access and dump the NOR flash on the [[Nano 3G]]. This code could possibly work on the Classics.&lt;br /&gt;
* {{#dateformat:2010-07-27}} - The server got zapped by lightning but a new one was up and running within a day.&lt;br /&gt;
* {{#dateformat:2010-02-23}} - We can now execute code on everything besides the [[Nano 5G]]! Minimalistic iBugger working on [[Nano 3G]]!&lt;br /&gt;
* {{#dateformat:2009-11-01}} - iBugger core v0.1 successfully running on [[Nano 4G]]! [https://img217.imageshack.us/img217/4122/img0969.jpg]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
Follow [https://x.com/freemyipod our X feed] to get status updates automatically. See the [[Status]] page for more detailed information. Check our [https://github.com/freemyipod GitHub repositories] for the latest changes to our source code.&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Project info===&lt;br /&gt;
* [[ Status ]]&lt;br /&gt;
* [[ Contact ]]&lt;br /&gt;
* [[ Contributing ]]&lt;br /&gt;
&lt;br /&gt;
===Released Software===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[ipod_sun]]&lt;br /&gt;
* [[U-Boot|U-Boot port]]&lt;br /&gt;
* [[Linux|Linux port]]&lt;br /&gt;
* Legacy:&lt;br /&gt;
** [[iBugger]]&lt;br /&gt;
** [[iLoader]]&lt;br /&gt;
** [[emCORE]]&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
===Basic skills===&lt;br /&gt;
* [[Working with binaries]]&lt;br /&gt;
* [[Dumping firmware]]&lt;br /&gt;
* [[Extracting firmware]]&lt;br /&gt;
* [[Firmware downgrading]]&lt;br /&gt;
* [[Troubleshooting]]&lt;br /&gt;
&lt;br /&gt;
===Reverse engineering results===&lt;br /&gt;
* [[Firmware]]&lt;br /&gt;
** [[Bootrom]]&lt;br /&gt;
** [[Boot Process]]&lt;br /&gt;
** [[Firmware decryption]]&lt;br /&gt;
** [[FTL|Flash Translation Layer]]&lt;br /&gt;
** [[RetailOS]]&lt;br /&gt;
*** [[RetailOS Options]]&lt;br /&gt;
* [[GUID table]]&lt;br /&gt;
* [[JTAG]]&lt;br /&gt;
* Nano 2G&lt;br /&gt;
** [[Nano2G clock gates‎]]&lt;br /&gt;
** [[Nano2G LCD init]]&lt;br /&gt;
** [[Nano2G HW analysis]]&lt;br /&gt;
** [[S5L8701 analysis]]&lt;br /&gt;
* Nano 4G&lt;br /&gt;
** [[Nano4G firmware upgrade process]]&lt;br /&gt;
* Nano 5G&lt;br /&gt;
** [[Nano 5G|General]]&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Hardware===&lt;br /&gt;
* [[Hardware]]&lt;br /&gt;
** [[Nano 1G]]&lt;br /&gt;
** [[Nano 2G]]&lt;br /&gt;
** [[Nano 3G]]&lt;br /&gt;
** [[Nano 4G]]&lt;br /&gt;
*** [[920-0614-03]]&lt;br /&gt;
** [[Nano 5G]]&lt;br /&gt;
** [[Nano 6G]]&lt;br /&gt;
** [[Nano 7G]]&lt;br /&gt;
** [[Classic 6G]]&lt;br /&gt;
* [[Chronology]]&lt;br /&gt;
* [[S5L8700 datasheet]]&lt;br /&gt;
* [[Modes]]&lt;br /&gt;
&lt;br /&gt;
===Exploiting===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[Pwnage 2.0]]&lt;br /&gt;
* [[Notes vulnerability]]&lt;br /&gt;
** [[Address bruteforcing]]&lt;br /&gt;
** [[Nanotron 3000]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano6g-patched-osos.jpeg&amp;diff=22377</id>
		<title>File:Nano6g-patched-osos.jpeg</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano6g-patched-osos.jpeg&amp;diff=22377"/>
		<updated>2026-07-26T00:18:03Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Main_Page&amp;diff=22376</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Main_Page&amp;diff=22376"/>
		<updated>2026-07-26T00:15:30Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
This is the wiki for the freemyipod project. Freemyipod is a project aimed at reverse-engineering non-iOS iPods (all models other than the Touch) and creating tools and documentation so that other people can port alternative firmwares to them such as [https://www.rockbox.org/ Rockbox] or [https://kernel.org/ Linux]. Freemyipod is a relaunch of [[Linux4nano]].&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m not an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
* If you have an [[Nano 2G]], [[Classic 6G]] or an older iPod, you can install [https://www.rockbox.org/download/ Rockbox].&lt;br /&gt;
* If you have an [[Nano 6G]] or [[Nano 7G]], you can [https://github.com/nfzerox/ipod_theme#ipod_theme install a theme].&lt;br /&gt;
* If you have an [[Nano 7G]], you can install [[NanoApps]].&lt;br /&gt;
* If you have another model, there&#039;s nothing you can currently do to help us add support and/or speed up the process, since it requires &#039;&#039;&#039;a lot&#039;&#039;&#039; of time and effort. Keep an eye on our wiki and social media for any updates!&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs on [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification) on [[Nano 3G]], [[Nano 4G]], [[Nano 5G]], [[Nano 6G]] and [[Nano 7G]]&lt;br /&gt;
* Rockbox bootloader has been published for [[Nano 3G]] and [[Nano 4G]], but [https://isthererockboxonipodnano3g.freemyipod.org/ the Rockbox port is not yet completed].&lt;br /&gt;
* Tethered code execution using [[S5Late]] (a vulnerability in DFU_DNLOAD packet parsing code) for [[Nano 6G]], [[Nano 7G]] and iPod shuffle (4th generation).&lt;br /&gt;
* Untethered code execution using [[ipod_sun]] (CVE-2010-1797) for [[Nano 6G]] and [[Nano 7G]].&lt;br /&gt;
* There&#039;s a set of earlier tooling ([[emCORE]]/[[emBIOS]]/[[iBugger]]) for [[Nano 2G]], [[Nano 3G]], [[Nano 4G]] and [[Classic 1G]] which was exploiting other vulnerabilities and was a lead-up to a port of Rockbox, but it&#039;s mostly abandoned.&lt;br /&gt;
&lt;br /&gt;
== Gallery ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Fastfetch_nano_7g_7.1-rc3.png|fastfetch on [[Nano 7G]]&lt;br /&gt;
File:Fastfetch nano 2g 6.10.png|fastfetch on [[Nano 2G]]&lt;br /&gt;
File:Linux nano 7g 7.1-rc3.jpg|[[Linux]] 7.1.0-rc3 on [[Nano 7G]]&lt;br /&gt;
File:Photo 2025-12-27 20-36-24.jpg|[[Linux]] 6.14.0 on [[Nano 7G]]&lt;br /&gt;
&lt;br /&gt;
File:S5L8702X01.png|S5L8702 under an EM&lt;br /&gt;
File:S5L8701B05.png|S5L8701 under an EM&lt;br /&gt;
File:Nano7g-patched-osos.png|Patched [[retailOS]] on [[Nano 7G]]&lt;br /&gt;
File:Nano5g-wayland.png|Wayland on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-neofetch.png|neofetch on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-diskmode-patched.png|Patched [[Modes#Disk_mode|disk mode]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console2.png|[[Linux]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console.png|[[Linux]] 6.2.0-rc4 on [[Nano 5G]]&lt;br /&gt;
&lt;br /&gt;
File:EmCORE_Nano2G_Nano4G_Classic.jpg|[[emCORE]] r779 on [[Nano 2G]], [[Nano 4G]] and [[Classic 2G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting an account ==&lt;br /&gt;
Due to spambots, registration is closed. For an account contact [[User:User890104|User890104]] or [[User:Q3k|q3k]].&lt;br /&gt;
&lt;br /&gt;
==Updates==&lt;br /&gt;
* {{#dateformat:2026-03-30}} - Some of us will be at [https://entropia.de/GPN24 GPN24] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2025-12-28}} - [[User:Hug0|Hug0]] made a lightning talk at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] on [https://www.youtube.com/watch?v=FKHL1yyOKJc iPod Nano reverse engineering].&lt;br /&gt;
* {{#dateformat:2025-12-26}} - Some of us will be at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] in Hamburg! Get in touch with [https://events.ccc.de/congress/2025/hub/en/user/q3k q3k] and/or [https://events.ccc.de/congress/2025/hub/en/user/slackware Slackware] if you&#039;re around!&lt;br /&gt;
* {{#dateformat:2025-06-12}} - Some of us will be at [https://entropia.de/GPN23 GPN23] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2024-12-25}} - Some of us will be at [https://events.ccc.de/congress/2024/infos/startpage.html 38C3] in Hamburg! [https://events.ccc.de/congress/2024/hub/en/project/ipod-nano-hacking-freemyipod/ Come say hi!]&lt;br /&gt;
* {{#dateformat:2024-12-16}} - [[S5Late]], a tethered iPod bootrom/DFU exploit for [[Nano 7G]] (and possibly [[Nano 6G]]), is released.&lt;br /&gt;
* {{#dateformat:2023-12-28}} - [[ipod_sun]], a tool that enables code execution on the [[Nano 6G]] and [[Nano 7G]], is released.&lt;br /&gt;
* {{#dateformat:2023-01-07}} - A preliminary [[U-Boot]] port to the [[Nano 5G]] [https://social.hackerspace.pl/@q3k/109655916469636189 has been developed].&lt;br /&gt;
* {{#dateformat:2022-01-04}} - The bootrom of [[Nano 5G]] was successfully dumped, and is in the process of being reverse-engineered!&lt;br /&gt;
* {{#dateformat:2021-12-31}} - An exploit named [[wInd3x]], which exploits the latest vulnerability, is being prepared for [[Nano 4G]] and [[Nano 5G]].&lt;br /&gt;
* {{#dateformat:2021-12-27}} - A new vulnerability was discovered in [[Nano 4G]] and [[Nano 5G]] bootrom, which allows arbitrary code execution!&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* {{#dateformat:2018-08-25}} - The website software has been updated to MediaWiki 1.31 after about 2 months of downtime.&lt;br /&gt;
* {{#dateformat:2016-06-17}} - The freemyipod project is becoming deprecated, as parts of the code is slowly being integrated in Rockbox. It is likely that no future development on the freemyipod project will take place. Essential parts of emCORE helped building a Rockbox bootloader for iPod Classic, and any future development will take place in the Rockbox project.&lt;br /&gt;
* {{#dateformat:2014-03-26}} - A bug that prevented [[emCORE]] installations on certain Windows configurations (getting stuck on &amp;quot;Booting UBI file...&amp;quot;), has been finally fixed! If the installation has failed for you before, you can retry it using the updated version of our tool (use the iTunes method for now).&lt;br /&gt;
* {{#dateformat:2012-01-02}} - There have been some problems with the latest release. A hotfix release ([[EmCORE_Releases/r859|r859]]) has been published to fix some of these problems. [[Nano 2G]] users are advised to upgrade.  See the [[EmCORE_Releases/r859|release details page]] for more information.&lt;br /&gt;
* {{#dateformat:2012-01-01}} - A new release &amp;lt;s&amp;gt;([[EmCORE_Releases/r855|r855]])&amp;lt;/s&amp;gt; is out! It includes a couple of new features, several bugfixes and a new bootmenu theme! More information on the &amp;lt;s&amp;gt;[[EmCORE_Releases/r855|release details page]]&amp;lt;/s&amp;gt;.&lt;br /&gt;
* {{#dateformat:2011-04-25}} - The [[emCORE]] kernel now runs on the iPod Touch 2G as well, thanks to the help of kleemajo. This is of course not a fully functional port yet, but we&#039;ll see how it continues. It&#039;s about the same state as the [[Nano 4G]] now. /7&lt;br /&gt;
* {{#dateformat:2011-03-25}} - [[emCORE]] is replacing [[emBIOS]] completely now. Therefore [[emBIOS]] will be deprecated software as of now! All emBIOS users are advised to upgrade to emCORE including people using iLoader 0.2.2 or less. More detailed update instructions will follow!&lt;br /&gt;
* {{#dateformat:2011-01-08}} - The Rockbox port for the iPod Classic is slowly getting usable. Most of the blocking issues have been fixed. The  first-generation 160GB model still doesn&#039;t work, and some people are experiencing slightly garbled display contents.&lt;br /&gt;
* {{#dateformat:2011-01-04}} - There is an early Rockbox port for the iPod Classic! It still isn&#039;t quite usable, playback stutters etc., but if you want to play around with it, here are some quick&#039;n&#039;dirty notes on the installation procedure: [[IPod Classic iLoader Installation]]&lt;br /&gt;
* {{#dateformat:2010-11-22}} - We now have emBIOS support for the iPod classic 1g, the others might follow soon&lt;br /&gt;
* {{#dateformat:2010-08-29}} - We&#039;re proud to announce the release of [[emBIOS]] v0.1.0 and [[iLoader]] v0.2.0!&lt;br /&gt;
* {{#dateformat:2010-08-26}} - [[iLoader]], its installer and uninstaller all have been fully ported to [[emBIOS]] now. A beta release will be coming soon!&lt;br /&gt;
* {{#dateformat:2010-08-13}} - [[emBIOS]] is continually being improved and the next step is porting tools like [[iLoader]] to use it.&lt;br /&gt;
* {{#dateformat:2010-08-06}} - The wiki has now been moved to www.freemyipod.org&lt;br /&gt;
* {{#dateformat:2010-08-05}} - Recently we&#039;ve been working on a hardware abstraction project called [[emBIOS]]. Follow development [https://websvn.freemyipod.org/listing.php?repname=freemyipod&amp;amp;path=/embios/ here]&lt;br /&gt;
* {{#dateformat:2010-08-03}} - We can now access the [[Nano 4G]] accelerometer.&lt;br /&gt;
* {{#dateformat:2010-08-02}} - serpilliere managed to decrypt the NOR flash on the [[Nano 3G]].&lt;br /&gt;
* {{#dateformat:2010-08-01}} - serpilliere managed to access and dump the NOR flash on the [[Nano 3G]]. This code could possibly work on the Classics.&lt;br /&gt;
* {{#dateformat:2010-07-27}} - The server got zapped by lightning but a new one was up and running within a day.&lt;br /&gt;
* {{#dateformat:2010-02-23}} - We can now execute code on everything besides the [[Nano 5G]]! Minimalistic iBugger working on [[Nano 3G]]!&lt;br /&gt;
* {{#dateformat:2009-11-01}} - iBugger core v0.1 successfully running on [[Nano 4G]]! [https://img217.imageshack.us/img217/4122/img0969.jpg]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
Follow [https://x.com/freemyipod our X feed] to get status updates automatically. See the [[Status]] page for more detailed information. Check our [https://github.com/freemyipod GitHub repositories] for the latest changes to our source code.&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Project info===&lt;br /&gt;
* [[ Status ]]&lt;br /&gt;
* [[ Contact ]]&lt;br /&gt;
* [[ Contributing ]]&lt;br /&gt;
&lt;br /&gt;
===Released Software===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[ipod_sun]]&lt;br /&gt;
* [[U-Boot|U-Boot port]]&lt;br /&gt;
* [[Linux|Linux port]]&lt;br /&gt;
* Legacy:&lt;br /&gt;
** [[iBugger]]&lt;br /&gt;
** [[iLoader]]&lt;br /&gt;
** [[emCORE]]&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
===Basic skills===&lt;br /&gt;
* [[Working with binaries]]&lt;br /&gt;
* [[Dumping firmware]]&lt;br /&gt;
* [[Extracting firmware]]&lt;br /&gt;
* [[Firmware downgrading]]&lt;br /&gt;
* [[Troubleshooting]]&lt;br /&gt;
&lt;br /&gt;
===Reverse engineering results===&lt;br /&gt;
* [[Firmware]]&lt;br /&gt;
** [[Bootrom]]&lt;br /&gt;
** [[Boot Process]]&lt;br /&gt;
** [[Firmware decryption]]&lt;br /&gt;
** [[FTL|Flash Translation Layer]]&lt;br /&gt;
** [[RetailOS]]&lt;br /&gt;
*** [[RetailOS Options]]&lt;br /&gt;
* [[GUID table]]&lt;br /&gt;
* [[JTAG]]&lt;br /&gt;
* Nano 2G&lt;br /&gt;
** [[Nano2G clock gates‎]]&lt;br /&gt;
** [[Nano2G LCD init]]&lt;br /&gt;
** [[Nano2G HW analysis]]&lt;br /&gt;
** [[S5L8701 analysis]]&lt;br /&gt;
* Nano 4G&lt;br /&gt;
** [[Nano4G firmware upgrade process]]&lt;br /&gt;
* Nano 5G&lt;br /&gt;
** [[Nano 5G|General]]&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Hardware===&lt;br /&gt;
* [[Hardware]]&lt;br /&gt;
** [[Nano 1G]]&lt;br /&gt;
** [[Nano 2G]]&lt;br /&gt;
** [[Nano 3G]]&lt;br /&gt;
** [[Nano 4G]]&lt;br /&gt;
*** [[920-0614-03]]&lt;br /&gt;
** [[Nano 5G]]&lt;br /&gt;
** [[Nano 6G]]&lt;br /&gt;
** [[Nano 7G]]&lt;br /&gt;
** [[Classic 6G]]&lt;br /&gt;
* [[Chronology]]&lt;br /&gt;
* [[S5L8700 datasheet]]&lt;br /&gt;
* [[Modes]]&lt;br /&gt;
&lt;br /&gt;
===Exploiting===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[Pwnage 2.0]]&lt;br /&gt;
* [[Notes vulnerability]]&lt;br /&gt;
** [[Address bruteforcing]]&lt;br /&gt;
** [[Nanotron 3000]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Main_Page&amp;diff=22375</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Main_Page&amp;diff=22375"/>
		<updated>2026-07-26T00:14:28Z</updated>

		<summary type="html">&lt;p&gt;User890104: reorder the developer faq items&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
This is the wiki for the freemyipod project. Freemyipod is a project aimed at reverse-engineering non-iOS iPods (all models other than the Touch) and creating tools and documentation so that other people can port alternative firmwares to them such as [https://www.rockbox.org/ Rockbox] or [https://kernel.org/ Linux]. Freemyipod is a relaunch of [[Linux4nano]].&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m not an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
If you have an [[Nano 2G]], [[Classic 6G]] or an older iPod, you can install [https://www.rockbox.org/download/ Rockbox].&lt;br /&gt;
&lt;br /&gt;
If you have an [[Nano 6G]] or [[Nano 7G]], you can [https://github.com/nfzerox/ipod_theme#ipod_theme install a theme].&lt;br /&gt;
&lt;br /&gt;
If you have an [[Nano 7G]], you can install [[NanoApps]].&lt;br /&gt;
&lt;br /&gt;
If you have another model, there&#039;s nothing you can currently do to help us add support and/or speed up the process, since it requires &#039;&#039;&#039;a lot&#039;&#039;&#039; of time and effort. Keep an eye on our wiki and social media for any updates!&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs on [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification) on [[Nano 3G]], [[Nano 4G]], [[Nano 5G]], [[Nano 6G]] and [[Nano 7G]]&lt;br /&gt;
* Rockbox bootloader has been published for [[Nano 3G]] and [[Nano 4G]], but [https://isthererockboxonipodnano3g.freemyipod.org/ the Rockbox port is not yet completed].&lt;br /&gt;
* Tethered code execution using [[S5Late]] (a vulnerability in DFU_DNLOAD packet parsing code) for [[Nano 6G]], [[Nano 7G]] and iPod shuffle (4th generation).&lt;br /&gt;
* Untethered code execution using [[ipod_sun]] (CVE-2010-1797) for [[Nano 6G]] and [[Nano 7G]].&lt;br /&gt;
* There&#039;s a set of earlier tooling ([[emCORE]]/[[emBIOS]]/[[iBugger]]) for [[Nano 2G]], [[Nano 3G]], [[Nano 4G]] and [[Classic 1G]] which was exploiting other vulnerabilities and was a lead-up to a port of Rockbox, but it&#039;s mostly abandoned.&lt;br /&gt;
&lt;br /&gt;
== Gallery ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Fastfetch_nano_7g_7.1-rc3.png|fastfetch on [[Nano 7G]]&lt;br /&gt;
File:Fastfetch nano 2g 6.10.png|fastfetch on [[Nano 2G]]&lt;br /&gt;
File:Linux nano 7g 7.1-rc3.jpg|[[Linux]] 7.1.0-rc3 on [[Nano 7G]]&lt;br /&gt;
File:Photo 2025-12-27 20-36-24.jpg|[[Linux]] 6.14.0 on [[Nano 7G]]&lt;br /&gt;
&lt;br /&gt;
File:S5L8702X01.png|S5L8702 under an EM&lt;br /&gt;
File:S5L8701B05.png|S5L8701 under an EM&lt;br /&gt;
File:Nano7g-patched-osos.png|Patched [[retailOS]] on [[Nano 7G]]&lt;br /&gt;
File:Nano5g-wayland.png|Wayland on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-neofetch.png|neofetch on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-diskmode-patched.png|Patched [[Modes#Disk_mode|disk mode]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console2.png|[[Linux]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console.png|[[Linux]] 6.2.0-rc4 on [[Nano 5G]]&lt;br /&gt;
&lt;br /&gt;
File:EmCORE_Nano2G_Nano4G_Classic.jpg|[[emCORE]] r779 on [[Nano 2G]], [[Nano 4G]] and [[Classic 2G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting an account ==&lt;br /&gt;
Due to spambots, registration is closed. For an account contact [[User:User890104|User890104]] or [[User:Q3k|q3k]].&lt;br /&gt;
&lt;br /&gt;
==Updates==&lt;br /&gt;
* {{#dateformat:2026-03-30}} - Some of us will be at [https://entropia.de/GPN24 GPN24] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2025-12-28}} - [[User:Hug0|Hug0]] made a lightning talk at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] on [https://www.youtube.com/watch?v=FKHL1yyOKJc iPod Nano reverse engineering].&lt;br /&gt;
* {{#dateformat:2025-12-26}} - Some of us will be at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] in Hamburg! Get in touch with [https://events.ccc.de/congress/2025/hub/en/user/q3k q3k] and/or [https://events.ccc.de/congress/2025/hub/en/user/slackware Slackware] if you&#039;re around!&lt;br /&gt;
* {{#dateformat:2025-06-12}} - Some of us will be at [https://entropia.de/GPN23 GPN23] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2024-12-25}} - Some of us will be at [https://events.ccc.de/congress/2024/infos/startpage.html 38C3] in Hamburg! [https://events.ccc.de/congress/2024/hub/en/project/ipod-nano-hacking-freemyipod/ Come say hi!]&lt;br /&gt;
* {{#dateformat:2024-12-16}} - [[S5Late]], a tethered iPod bootrom/DFU exploit for [[Nano 7G]] (and possibly [[Nano 6G]]), is released.&lt;br /&gt;
* {{#dateformat:2023-12-28}} - [[ipod_sun]], a tool that enables code execution on the [[Nano 6G]] and [[Nano 7G]], is released.&lt;br /&gt;
* {{#dateformat:2023-01-07}} - A preliminary [[U-Boot]] port to the [[Nano 5G]] [https://social.hackerspace.pl/@q3k/109655916469636189 has been developed].&lt;br /&gt;
* {{#dateformat:2022-01-04}} - The bootrom of [[Nano 5G]] was successfully dumped, and is in the process of being reverse-engineered!&lt;br /&gt;
* {{#dateformat:2021-12-31}} - An exploit named [[wInd3x]], which exploits the latest vulnerability, is being prepared for [[Nano 4G]] and [[Nano 5G]].&lt;br /&gt;
* {{#dateformat:2021-12-27}} - A new vulnerability was discovered in [[Nano 4G]] and [[Nano 5G]] bootrom, which allows arbitrary code execution!&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* {{#dateformat:2018-08-25}} - The website software has been updated to MediaWiki 1.31 after about 2 months of downtime.&lt;br /&gt;
* {{#dateformat:2016-06-17}} - The freemyipod project is becoming deprecated, as parts of the code is slowly being integrated in Rockbox. It is likely that no future development on the freemyipod project will take place. Essential parts of emCORE helped building a Rockbox bootloader for iPod Classic, and any future development will take place in the Rockbox project.&lt;br /&gt;
* {{#dateformat:2014-03-26}} - A bug that prevented [[emCORE]] installations on certain Windows configurations (getting stuck on &amp;quot;Booting UBI file...&amp;quot;), has been finally fixed! If the installation has failed for you before, you can retry it using the updated version of our tool (use the iTunes method for now).&lt;br /&gt;
* {{#dateformat:2012-01-02}} - There have been some problems with the latest release. A hotfix release ([[EmCORE_Releases/r859|r859]]) has been published to fix some of these problems. [[Nano 2G]] users are advised to upgrade.  See the [[EmCORE_Releases/r859|release details page]] for more information.&lt;br /&gt;
* {{#dateformat:2012-01-01}} - A new release &amp;lt;s&amp;gt;([[EmCORE_Releases/r855|r855]])&amp;lt;/s&amp;gt; is out! It includes a couple of new features, several bugfixes and a new bootmenu theme! More information on the &amp;lt;s&amp;gt;[[EmCORE_Releases/r855|release details page]]&amp;lt;/s&amp;gt;.&lt;br /&gt;
* {{#dateformat:2011-04-25}} - The [[emCORE]] kernel now runs on the iPod Touch 2G as well, thanks to the help of kleemajo. This is of course not a fully functional port yet, but we&#039;ll see how it continues. It&#039;s about the same state as the [[Nano 4G]] now. /7&lt;br /&gt;
* {{#dateformat:2011-03-25}} - [[emCORE]] is replacing [[emBIOS]] completely now. Therefore [[emBIOS]] will be deprecated software as of now! All emBIOS users are advised to upgrade to emCORE including people using iLoader 0.2.2 or less. More detailed update instructions will follow!&lt;br /&gt;
* {{#dateformat:2011-01-08}} - The Rockbox port for the iPod Classic is slowly getting usable. Most of the blocking issues have been fixed. The  first-generation 160GB model still doesn&#039;t work, and some people are experiencing slightly garbled display contents.&lt;br /&gt;
* {{#dateformat:2011-01-04}} - There is an early Rockbox port for the iPod Classic! It still isn&#039;t quite usable, playback stutters etc., but if you want to play around with it, here are some quick&#039;n&#039;dirty notes on the installation procedure: [[IPod Classic iLoader Installation]]&lt;br /&gt;
* {{#dateformat:2010-11-22}} - We now have emBIOS support for the iPod classic 1g, the others might follow soon&lt;br /&gt;
* {{#dateformat:2010-08-29}} - We&#039;re proud to announce the release of [[emBIOS]] v0.1.0 and [[iLoader]] v0.2.0!&lt;br /&gt;
* {{#dateformat:2010-08-26}} - [[iLoader]], its installer and uninstaller all have been fully ported to [[emBIOS]] now. A beta release will be coming soon!&lt;br /&gt;
* {{#dateformat:2010-08-13}} - [[emBIOS]] is continually being improved and the next step is porting tools like [[iLoader]] to use it.&lt;br /&gt;
* {{#dateformat:2010-08-06}} - The wiki has now been moved to www.freemyipod.org&lt;br /&gt;
* {{#dateformat:2010-08-05}} - Recently we&#039;ve been working on a hardware abstraction project called [[emBIOS]]. Follow development [https://websvn.freemyipod.org/listing.php?repname=freemyipod&amp;amp;path=/embios/ here]&lt;br /&gt;
* {{#dateformat:2010-08-03}} - We can now access the [[Nano 4G]] accelerometer.&lt;br /&gt;
* {{#dateformat:2010-08-02}} - serpilliere managed to decrypt the NOR flash on the [[Nano 3G]].&lt;br /&gt;
* {{#dateformat:2010-08-01}} - serpilliere managed to access and dump the NOR flash on the [[Nano 3G]]. This code could possibly work on the Classics.&lt;br /&gt;
* {{#dateformat:2010-07-27}} - The server got zapped by lightning but a new one was up and running within a day.&lt;br /&gt;
* {{#dateformat:2010-02-23}} - We can now execute code on everything besides the [[Nano 5G]]! Minimalistic iBugger working on [[Nano 3G]]!&lt;br /&gt;
* {{#dateformat:2009-11-01}} - iBugger core v0.1 successfully running on [[Nano 4G]]! [https://img217.imageshack.us/img217/4122/img0969.jpg]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
Follow [https://x.com/freemyipod our X feed] to get status updates automatically. See the [[Status]] page for more detailed information. Check our [https://github.com/freemyipod GitHub repositories] for the latest changes to our source code.&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Project info===&lt;br /&gt;
* [[ Status ]]&lt;br /&gt;
* [[ Contact ]]&lt;br /&gt;
* [[ Contributing ]]&lt;br /&gt;
&lt;br /&gt;
===Released Software===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[ipod_sun]]&lt;br /&gt;
* [[U-Boot|U-Boot port]]&lt;br /&gt;
* [[Linux|Linux port]]&lt;br /&gt;
* Legacy:&lt;br /&gt;
** [[iBugger]]&lt;br /&gt;
** [[iLoader]]&lt;br /&gt;
** [[emCORE]]&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
===Basic skills===&lt;br /&gt;
* [[Working with binaries]]&lt;br /&gt;
* [[Dumping firmware]]&lt;br /&gt;
* [[Extracting firmware]]&lt;br /&gt;
* [[Firmware downgrading]]&lt;br /&gt;
* [[Troubleshooting]]&lt;br /&gt;
&lt;br /&gt;
===Reverse engineering results===&lt;br /&gt;
* [[Firmware]]&lt;br /&gt;
** [[Bootrom]]&lt;br /&gt;
** [[Boot Process]]&lt;br /&gt;
** [[Firmware decryption]]&lt;br /&gt;
** [[FTL|Flash Translation Layer]]&lt;br /&gt;
** [[RetailOS]]&lt;br /&gt;
*** [[RetailOS Options]]&lt;br /&gt;
* [[GUID table]]&lt;br /&gt;
* [[JTAG]]&lt;br /&gt;
* Nano 2G&lt;br /&gt;
** [[Nano2G clock gates‎]]&lt;br /&gt;
** [[Nano2G LCD init]]&lt;br /&gt;
** [[Nano2G HW analysis]]&lt;br /&gt;
** [[S5L8701 analysis]]&lt;br /&gt;
* Nano 4G&lt;br /&gt;
** [[Nano4G firmware upgrade process]]&lt;br /&gt;
* Nano 5G&lt;br /&gt;
** [[Nano 5G|General]]&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Hardware===&lt;br /&gt;
* [[Hardware]]&lt;br /&gt;
** [[Nano 1G]]&lt;br /&gt;
** [[Nano 2G]]&lt;br /&gt;
** [[Nano 3G]]&lt;br /&gt;
** [[Nano 4G]]&lt;br /&gt;
*** [[920-0614-03]]&lt;br /&gt;
** [[Nano 5G]]&lt;br /&gt;
** [[Nano 6G]]&lt;br /&gt;
** [[Nano 7G]]&lt;br /&gt;
** [[Classic 6G]]&lt;br /&gt;
* [[Chronology]]&lt;br /&gt;
* [[S5L8700 datasheet]]&lt;br /&gt;
* [[Modes]]&lt;br /&gt;
&lt;br /&gt;
===Exploiting===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[Pwnage 2.0]]&lt;br /&gt;
* [[Notes vulnerability]]&lt;br /&gt;
** [[Address bruteforcing]]&lt;br /&gt;
** [[Nanotron 3000]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Main_Page&amp;diff=22374</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Main_Page&amp;diff=22374"/>
		<updated>2026-07-26T00:06:43Z</updated>

		<summary type="html">&lt;p&gt;User890104: update faq&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
This is the wiki for the freemyipod project. Freemyipod is a project aimed at reverse-engineering non-iOS iPods (all models other than the Touch) and creating tools and documentation so that other people can port alternative firmwares to them such as [https://www.rockbox.org/ Rockbox] or [https://kernel.org/ Linux]. Freemyipod is a relaunch of [[Linux4nano]].&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m not an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
If you have an [[Nano 2G]], [[Classic 6G]] or an older iPod, you can install [https://www.rockbox.org/download/ Rockbox].&lt;br /&gt;
&lt;br /&gt;
If you have an [[Nano 6G]] or [[Nano 7G]], you can [https://github.com/nfzerox/ipod_theme#ipod_theme install a theme].&lt;br /&gt;
&lt;br /&gt;
If you have an [[Nano 7G]], you can install [[NanoApps]].&lt;br /&gt;
&lt;br /&gt;
If you have another model, there&#039;s nothing you can currently do to help us add support and/or speed up the process, since it requires &#039;&#039;&#039;a lot&#039;&#039;&#039; of time and effort. Keep an eye on our wiki and social media for any updates!&lt;br /&gt;
&lt;br /&gt;
=== I&#039;m an embedded software developer, what can I do with my iPod? ===&lt;br /&gt;
&lt;br /&gt;
Here&#039;s the current progress, by iPod model:&lt;br /&gt;
&lt;br /&gt;
[[Nano 2G]]&lt;br /&gt;
* [[U-Boot]] can be chainloaded from Rockbox.&lt;br /&gt;
&lt;br /&gt;
[[Nano 3G]] and [[Nano 4G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification).&lt;br /&gt;
* Rockbox bootloader has been published, but [https://isthererockboxonipodnano3g.freemyipod.org/ the Rockbox port is not yet completed].&lt;br /&gt;
&lt;br /&gt;
[[Nano 5G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification).&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs.&lt;br /&gt;
&lt;br /&gt;
[[Nano 6G]] and [[Nano 7G]]&lt;br /&gt;
* Tethered code execution using [[S5Late]] (a vulnerability in DFU_DNLOAD packet parsing code) (also for iPod shuffle (4th generation))&lt;br /&gt;
* Untethered code execution using [[ipod_sun]] (CVE-2010-1797)&lt;br /&gt;
&lt;br /&gt;
[[Nano 7G]]&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs.&lt;br /&gt;
&lt;br /&gt;
There&#039;s a set of earlier tooling ([[emCORE]]/[[emBIOS]]/[[iBugger]]) which was exploiting other vulnerabilities and was a lead-up to a port of Rockbox, but it&#039;s mostly abandoned.&lt;br /&gt;
&lt;br /&gt;
== Gallery ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Fastfetch_nano_7g_7.1-rc3.png|fastfetch on [[Nano 7G]]&lt;br /&gt;
File:Fastfetch nano 2g 6.10.png|fastfetch on [[Nano 2G]]&lt;br /&gt;
File:Linux nano 7g 7.1-rc3.jpg|[[Linux]] 7.1.0-rc3 on [[Nano 7G]]&lt;br /&gt;
File:Photo 2025-12-27 20-36-24.jpg|[[Linux]] 6.14.0 on [[Nano 7G]]&lt;br /&gt;
&lt;br /&gt;
File:S5L8702X01.png|S5L8702 under an EM&lt;br /&gt;
File:S5L8701B05.png|S5L8701 under an EM&lt;br /&gt;
File:Nano7g-patched-osos.png|Patched [[retailOS]] on [[Nano 7G]]&lt;br /&gt;
File:Nano5g-wayland.png|Wayland on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-neofetch.png|neofetch on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-diskmode-patched.png|Patched [[Modes#Disk_mode|disk mode]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console2.png|[[Linux]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console.png|[[Linux]] 6.2.0-rc4 on [[Nano 5G]]&lt;br /&gt;
&lt;br /&gt;
File:EmCORE_Nano2G_Nano4G_Classic.jpg|[[emCORE]] r779 on [[Nano 2G]], [[Nano 4G]] and [[Classic 2G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting an account ==&lt;br /&gt;
Due to spambots, registration is closed. For an account contact [[User:User890104|User890104]] or [[User:Q3k|q3k]].&lt;br /&gt;
&lt;br /&gt;
==Updates==&lt;br /&gt;
* {{#dateformat:2026-03-30}} - Some of us will be at [https://entropia.de/GPN24 GPN24] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2025-12-28}} - [[User:Hug0|Hug0]] made a lightning talk at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] on [https://www.youtube.com/watch?v=FKHL1yyOKJc iPod Nano reverse engineering].&lt;br /&gt;
* {{#dateformat:2025-12-26}} - Some of us will be at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] in Hamburg! Get in touch with [https://events.ccc.de/congress/2025/hub/en/user/q3k q3k] and/or [https://events.ccc.de/congress/2025/hub/en/user/slackware Slackware] if you&#039;re around!&lt;br /&gt;
* {{#dateformat:2025-06-12}} - Some of us will be at [https://entropia.de/GPN23 GPN23] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2024-12-25}} - Some of us will be at [https://events.ccc.de/congress/2024/infos/startpage.html 38C3] in Hamburg! [https://events.ccc.de/congress/2024/hub/en/project/ipod-nano-hacking-freemyipod/ Come say hi!]&lt;br /&gt;
* {{#dateformat:2024-12-16}} - [[S5Late]], a tethered iPod bootrom/DFU exploit for [[Nano 7G]] (and possibly [[Nano 6G]]), is released.&lt;br /&gt;
* {{#dateformat:2023-12-28}} - [[ipod_sun]], a tool that enables code execution on the [[Nano 6G]] and [[Nano 7G]], is released.&lt;br /&gt;
* {{#dateformat:2023-01-07}} - A preliminary [[U-Boot]] port to the [[Nano 5G]] [https://social.hackerspace.pl/@q3k/109655916469636189 has been developed].&lt;br /&gt;
* {{#dateformat:2022-01-04}} - The bootrom of [[Nano 5G]] was successfully dumped, and is in the process of being reverse-engineered!&lt;br /&gt;
* {{#dateformat:2021-12-31}} - An exploit named [[wInd3x]], which exploits the latest vulnerability, is being prepared for [[Nano 4G]] and [[Nano 5G]].&lt;br /&gt;
* {{#dateformat:2021-12-27}} - A new vulnerability was discovered in [[Nano 4G]] and [[Nano 5G]] bootrom, which allows arbitrary code execution!&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* {{#dateformat:2018-08-25}} - The website software has been updated to MediaWiki 1.31 after about 2 months of downtime.&lt;br /&gt;
* {{#dateformat:2016-06-17}} - The freemyipod project is becoming deprecated, as parts of the code is slowly being integrated in Rockbox. It is likely that no future development on the freemyipod project will take place. Essential parts of emCORE helped building a Rockbox bootloader for iPod Classic, and any future development will take place in the Rockbox project.&lt;br /&gt;
* {{#dateformat:2014-03-26}} - A bug that prevented [[emCORE]] installations on certain Windows configurations (getting stuck on &amp;quot;Booting UBI file...&amp;quot;), has been finally fixed! If the installation has failed for you before, you can retry it using the updated version of our tool (use the iTunes method for now).&lt;br /&gt;
* {{#dateformat:2012-01-02}} - There have been some problems with the latest release. A hotfix release ([[EmCORE_Releases/r859|r859]]) has been published to fix some of these problems. [[Nano 2G]] users are advised to upgrade.  See the [[EmCORE_Releases/r859|release details page]] for more information.&lt;br /&gt;
* {{#dateformat:2012-01-01}} - A new release &amp;lt;s&amp;gt;([[EmCORE_Releases/r855|r855]])&amp;lt;/s&amp;gt; is out! It includes a couple of new features, several bugfixes and a new bootmenu theme! More information on the &amp;lt;s&amp;gt;[[EmCORE_Releases/r855|release details page]]&amp;lt;/s&amp;gt;.&lt;br /&gt;
* {{#dateformat:2011-04-25}} - The [[emCORE]] kernel now runs on the iPod Touch 2G as well, thanks to the help of kleemajo. This is of course not a fully functional port yet, but we&#039;ll see how it continues. It&#039;s about the same state as the [[Nano 4G]] now. /7&lt;br /&gt;
* {{#dateformat:2011-03-25}} - [[emCORE]] is replacing [[emBIOS]] completely now. Therefore [[emBIOS]] will be deprecated software as of now! All emBIOS users are advised to upgrade to emCORE including people using iLoader 0.2.2 or less. More detailed update instructions will follow!&lt;br /&gt;
* {{#dateformat:2011-01-08}} - The Rockbox port for the iPod Classic is slowly getting usable. Most of the blocking issues have been fixed. The  first-generation 160GB model still doesn&#039;t work, and some people are experiencing slightly garbled display contents.&lt;br /&gt;
* {{#dateformat:2011-01-04}} - There is an early Rockbox port for the iPod Classic! It still isn&#039;t quite usable, playback stutters etc., but if you want to play around with it, here are some quick&#039;n&#039;dirty notes on the installation procedure: [[IPod Classic iLoader Installation]]&lt;br /&gt;
* {{#dateformat:2010-11-22}} - We now have emBIOS support for the iPod classic 1g, the others might follow soon&lt;br /&gt;
* {{#dateformat:2010-08-29}} - We&#039;re proud to announce the release of [[emBIOS]] v0.1.0 and [[iLoader]] v0.2.0!&lt;br /&gt;
* {{#dateformat:2010-08-26}} - [[iLoader]], its installer and uninstaller all have been fully ported to [[emBIOS]] now. A beta release will be coming soon!&lt;br /&gt;
* {{#dateformat:2010-08-13}} - [[emBIOS]] is continually being improved and the next step is porting tools like [[iLoader]] to use it.&lt;br /&gt;
* {{#dateformat:2010-08-06}} - The wiki has now been moved to www.freemyipod.org&lt;br /&gt;
* {{#dateformat:2010-08-05}} - Recently we&#039;ve been working on a hardware abstraction project called [[emBIOS]]. Follow development [https://websvn.freemyipod.org/listing.php?repname=freemyipod&amp;amp;path=/embios/ here]&lt;br /&gt;
* {{#dateformat:2010-08-03}} - We can now access the [[Nano 4G]] accelerometer.&lt;br /&gt;
* {{#dateformat:2010-08-02}} - serpilliere managed to decrypt the NOR flash on the [[Nano 3G]].&lt;br /&gt;
* {{#dateformat:2010-08-01}} - serpilliere managed to access and dump the NOR flash on the [[Nano 3G]]. This code could possibly work on the Classics.&lt;br /&gt;
* {{#dateformat:2010-07-27}} - The server got zapped by lightning but a new one was up and running within a day.&lt;br /&gt;
* {{#dateformat:2010-02-23}} - We can now execute code on everything besides the [[Nano 5G]]! Minimalistic iBugger working on [[Nano 3G]]!&lt;br /&gt;
* {{#dateformat:2009-11-01}} - iBugger core v0.1 successfully running on [[Nano 4G]]! [https://img217.imageshack.us/img217/4122/img0969.jpg]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
Follow [https://x.com/freemyipod our X feed] to get status updates automatically. See the [[Status]] page for more detailed information. Check our [https://github.com/freemyipod GitHub repositories] for the latest changes to our source code.&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Project info===&lt;br /&gt;
* [[ Status ]]&lt;br /&gt;
* [[ Contact ]]&lt;br /&gt;
* [[ Contributing ]]&lt;br /&gt;
&lt;br /&gt;
===Released Software===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[ipod_sun]]&lt;br /&gt;
* [[U-Boot|U-Boot port]]&lt;br /&gt;
* [[Linux|Linux port]]&lt;br /&gt;
* Legacy:&lt;br /&gt;
** [[iBugger]]&lt;br /&gt;
** [[iLoader]]&lt;br /&gt;
** [[emCORE]]&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
===Basic skills===&lt;br /&gt;
* [[Working with binaries]]&lt;br /&gt;
* [[Dumping firmware]]&lt;br /&gt;
* [[Extracting firmware]]&lt;br /&gt;
* [[Firmware downgrading]]&lt;br /&gt;
* [[Troubleshooting]]&lt;br /&gt;
&lt;br /&gt;
===Reverse engineering results===&lt;br /&gt;
* [[Firmware]]&lt;br /&gt;
** [[Bootrom]]&lt;br /&gt;
** [[Boot Process]]&lt;br /&gt;
** [[Firmware decryption]]&lt;br /&gt;
** [[FTL|Flash Translation Layer]]&lt;br /&gt;
** [[RetailOS]]&lt;br /&gt;
*** [[RetailOS Options]]&lt;br /&gt;
* [[GUID table]]&lt;br /&gt;
* [[JTAG]]&lt;br /&gt;
* Nano 2G&lt;br /&gt;
** [[Nano2G clock gates‎]]&lt;br /&gt;
** [[Nano2G LCD init]]&lt;br /&gt;
** [[Nano2G HW analysis]]&lt;br /&gt;
** [[S5L8701 analysis]]&lt;br /&gt;
* Nano 4G&lt;br /&gt;
** [[Nano4G firmware upgrade process]]&lt;br /&gt;
* Nano 5G&lt;br /&gt;
** [[Nano 5G|General]]&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Hardware===&lt;br /&gt;
* [[Hardware]]&lt;br /&gt;
** [[Nano 1G]]&lt;br /&gt;
** [[Nano 2G]]&lt;br /&gt;
** [[Nano 3G]]&lt;br /&gt;
** [[Nano 4G]]&lt;br /&gt;
*** [[920-0614-03]]&lt;br /&gt;
** [[Nano 5G]]&lt;br /&gt;
** [[Nano 6G]]&lt;br /&gt;
** [[Nano 7G]]&lt;br /&gt;
** [[Classic 6G]]&lt;br /&gt;
* [[Chronology]]&lt;br /&gt;
* [[S5L8700 datasheet]]&lt;br /&gt;
* [[Modes]]&lt;br /&gt;
&lt;br /&gt;
===Exploiting===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[Pwnage 2.0]]&lt;br /&gt;
* [[Notes vulnerability]]&lt;br /&gt;
** [[Address bruteforcing]]&lt;br /&gt;
** [[Nanotron 3000]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Main_Page&amp;diff=22373</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Main_Page&amp;diff=22373"/>
		<updated>2026-07-25T23:49:11Z</updated>

		<summary type="html">&lt;p&gt;User890104: add images to the gallery&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
This is the wiki for the freemyipod project. Freemyipod is a project aimed at reverse-engineering non-iOS iPods (all models other than the Touch) and creating tools and documentation so that other people can port alternative firmwares to them such as [https://www.rockbox.org/ Rockbox] or [https://kernel.org/ Linux]. Freemyipod is a relaunch of [[Linux4nano]].&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
=== What can I do with my [[Nano 2G]], [[Classic 6G]] or older iPods? ===&lt;br /&gt;
&lt;br /&gt;
There&#039;s an upstream Rockbox port for these devices. [https://www.rockbox.org/download/ Go use that].&lt;br /&gt;
&lt;br /&gt;
=== What can I do with my [[Nano 3G]] or newer? ===&lt;br /&gt;
&lt;br /&gt;
Not much (yet) unless you&#039;re an embedded developer :).&lt;br /&gt;
&lt;br /&gt;
Here&#039;s the current progress, by iPod model:&lt;br /&gt;
&lt;br /&gt;
[[Nano 3G]] and [[Nano 4G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification).&lt;br /&gt;
* Rockbox bootloader has been published, but [https://isthererockboxonipodnano3g.freemyipod.org/ the Rockbox port is not yet completed].&lt;br /&gt;
&lt;br /&gt;
[[Nano 5G]]&lt;br /&gt;
* [[wInd3x]] allows untethered and safe code execution (no permanent modification).&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs.&lt;br /&gt;
&lt;br /&gt;
[[Nano 6G]] and [[Nano 7G]]&lt;br /&gt;
* Tethered code execution using [[S5Late]] (a vulnerability in DFU_DNLOAD packet parsing code) (also for iPod shuffle (4th generation))&lt;br /&gt;
* Untethered code execution using [[ipod_sun]] (CVE-2010-1797)&lt;br /&gt;
&lt;br /&gt;
[[Nano 7G]]&lt;br /&gt;
* There&#039;s a [[U-Boot]] port, and [[Linux|Linux]] boots with an initramfs.&lt;br /&gt;
* [[NanoApps]] allows you to run custom homebrew apps.&lt;br /&gt;
&lt;br /&gt;
There&#039;s a set of earlier tooling ([[emCORE]]/[[emBIOS]]/[[iBugger]]) which was exploiting other vulnerabilities and was a lead-up to a port of Rockbox, but it&#039;s mostly abandoned.&lt;br /&gt;
&lt;br /&gt;
== Gallery ==&lt;br /&gt;
&amp;lt;gallery&amp;gt;&lt;br /&gt;
File:Fastfetch_nano_7g_7.1-rc3.png|fastfetch on [[Nano 7G]]&lt;br /&gt;
File:Fastfetch nano 2g 6.10.png|fastfetch on [[Nano 2G]]&lt;br /&gt;
File:Linux nano 7g 7.1-rc3.jpg|[[Linux]] 7.1.0-rc3 on [[Nano 7G]]&lt;br /&gt;
File:Photo 2025-12-27 20-36-24.jpg|[[Linux]] 6.14.0 on [[Nano 7G]]&lt;br /&gt;
&lt;br /&gt;
File:S5L8702X01.png|S5L8702 under an EM&lt;br /&gt;
File:S5L8701B05.png|S5L8701 under an EM&lt;br /&gt;
File:Nano7g-patched-osos.png|Patched [[retailOS]] on [[Nano 7G]]&lt;br /&gt;
File:Nano5g-wayland.png|Wayland on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-neofetch.png|neofetch on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-diskmode-patched.png|Patched [[Modes#Disk_mode|disk mode]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console2.png|[[Linux]] on [[Nano 5G]]&lt;br /&gt;
File:Nano5g-console.png|[[Linux]] 6.2.0-rc4 on [[Nano 5G]]&lt;br /&gt;
&lt;br /&gt;
File:EmCORE_Nano2G_Nano4G_Classic.jpg|[[emCORE]] r779 on [[Nano 2G]], [[Nano 4G]] and [[Classic 2G]]&lt;br /&gt;
&amp;lt;/gallery&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Getting an account ==&lt;br /&gt;
Due to spambots, registration is closed. For an account contact [[User:User890104|User890104]] or [[User:Q3k|q3k]].&lt;br /&gt;
&lt;br /&gt;
==Updates==&lt;br /&gt;
* {{#dateformat:2026-03-30}} - Some of us will be at [https://entropia.de/GPN24 GPN24] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2025-12-28}} - [[User:Hug0|Hug0]] made a lightning talk at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] on [https://www.youtube.com/watch?v=FKHL1yyOKJc iPod Nano reverse engineering].&lt;br /&gt;
* {{#dateformat:2025-12-26}} - Some of us will be at [https://events.ccc.de/congress/2025/infos/startpage.html 39C3] in Hamburg! Get in touch with [https://events.ccc.de/congress/2025/hub/en/user/q3k q3k] and/or [https://events.ccc.de/congress/2025/hub/en/user/slackware Slackware] if you&#039;re around!&lt;br /&gt;
* {{#dateformat:2025-06-12}} - Some of us will be at [https://entropia.de/GPN23 GPN23] in Karlsruhe! [[Contact|Let us know on IRC/Discord/Matrix]] if you&#039;re also there!&lt;br /&gt;
* {{#dateformat:2024-12-25}} - Some of us will be at [https://events.ccc.de/congress/2024/infos/startpage.html 38C3] in Hamburg! [https://events.ccc.de/congress/2024/hub/en/project/ipod-nano-hacking-freemyipod/ Come say hi!]&lt;br /&gt;
* {{#dateformat:2024-12-16}} - [[S5Late]], a tethered iPod bootrom/DFU exploit for [[Nano 7G]] (and possibly [[Nano 6G]]), is released.&lt;br /&gt;
* {{#dateformat:2023-12-28}} - [[ipod_sun]], a tool that enables code execution on the [[Nano 6G]] and [[Nano 7G]], is released.&lt;br /&gt;
* {{#dateformat:2023-01-07}} - A preliminary [[U-Boot]] port to the [[Nano 5G]] [https://social.hackerspace.pl/@q3k/109655916469636189 has been developed].&lt;br /&gt;
* {{#dateformat:2022-01-04}} - The bootrom of [[Nano 5G]] was successfully dumped, and is in the process of being reverse-engineered!&lt;br /&gt;
* {{#dateformat:2021-12-31}} - An exploit named [[wInd3x]], which exploits the latest vulnerability, is being prepared for [[Nano 4G]] and [[Nano 5G]].&lt;br /&gt;
* {{#dateformat:2021-12-27}} - A new vulnerability was discovered in [[Nano 4G]] and [[Nano 5G]] bootrom, which allows arbitrary code execution!&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* {{#dateformat:2018-08-25}} - The website software has been updated to MediaWiki 1.31 after about 2 months of downtime.&lt;br /&gt;
* {{#dateformat:2016-06-17}} - The freemyipod project is becoming deprecated, as parts of the code is slowly being integrated in Rockbox. It is likely that no future development on the freemyipod project will take place. Essential parts of emCORE helped building a Rockbox bootloader for iPod Classic, and any future development will take place in the Rockbox project.&lt;br /&gt;
* {{#dateformat:2014-03-26}} - A bug that prevented [[emCORE]] installations on certain Windows configurations (getting stuck on &amp;quot;Booting UBI file...&amp;quot;), has been finally fixed! If the installation has failed for you before, you can retry it using the updated version of our tool (use the iTunes method for now).&lt;br /&gt;
* {{#dateformat:2012-01-02}} - There have been some problems with the latest release. A hotfix release ([[EmCORE_Releases/r859|r859]]) has been published to fix some of these problems. [[Nano 2G]] users are advised to upgrade.  See the [[EmCORE_Releases/r859|release details page]] for more information.&lt;br /&gt;
* {{#dateformat:2012-01-01}} - A new release &amp;lt;s&amp;gt;([[EmCORE_Releases/r855|r855]])&amp;lt;/s&amp;gt; is out! It includes a couple of new features, several bugfixes and a new bootmenu theme! More information on the &amp;lt;s&amp;gt;[[EmCORE_Releases/r855|release details page]]&amp;lt;/s&amp;gt;.&lt;br /&gt;
* {{#dateformat:2011-04-25}} - The [[emCORE]] kernel now runs on the iPod Touch 2G as well, thanks to the help of kleemajo. This is of course not a fully functional port yet, but we&#039;ll see how it continues. It&#039;s about the same state as the [[Nano 4G]] now. /7&lt;br /&gt;
* {{#dateformat:2011-03-25}} - [[emCORE]] is replacing [[emBIOS]] completely now. Therefore [[emBIOS]] will be deprecated software as of now! All emBIOS users are advised to upgrade to emCORE including people using iLoader 0.2.2 or less. More detailed update instructions will follow!&lt;br /&gt;
* {{#dateformat:2011-01-08}} - The Rockbox port for the iPod Classic is slowly getting usable. Most of the blocking issues have been fixed. The  first-generation 160GB model still doesn&#039;t work, and some people are experiencing slightly garbled display contents.&lt;br /&gt;
* {{#dateformat:2011-01-04}} - There is an early Rockbox port for the iPod Classic! It still isn&#039;t quite usable, playback stutters etc., but if you want to play around with it, here are some quick&#039;n&#039;dirty notes on the installation procedure: [[IPod Classic iLoader Installation]]&lt;br /&gt;
* {{#dateformat:2010-11-22}} - We now have emBIOS support for the iPod classic 1g, the others might follow soon&lt;br /&gt;
* {{#dateformat:2010-08-29}} - We&#039;re proud to announce the release of [[emBIOS]] v0.1.0 and [[iLoader]] v0.2.0!&lt;br /&gt;
* {{#dateformat:2010-08-26}} - [[iLoader]], its installer and uninstaller all have been fully ported to [[emBIOS]] now. A beta release will be coming soon!&lt;br /&gt;
* {{#dateformat:2010-08-13}} - [[emBIOS]] is continually being improved and the next step is porting tools like [[iLoader]] to use it.&lt;br /&gt;
* {{#dateformat:2010-08-06}} - The wiki has now been moved to www.freemyipod.org&lt;br /&gt;
* {{#dateformat:2010-08-05}} - Recently we&#039;ve been working on a hardware abstraction project called [[emBIOS]]. Follow development [https://websvn.freemyipod.org/listing.php?repname=freemyipod&amp;amp;path=/embios/ here]&lt;br /&gt;
* {{#dateformat:2010-08-03}} - We can now access the [[Nano 4G]] accelerometer.&lt;br /&gt;
* {{#dateformat:2010-08-02}} - serpilliere managed to decrypt the NOR flash on the [[Nano 3G]].&lt;br /&gt;
* {{#dateformat:2010-08-01}} - serpilliere managed to access and dump the NOR flash on the [[Nano 3G]]. This code could possibly work on the Classics.&lt;br /&gt;
* {{#dateformat:2010-07-27}} - The server got zapped by lightning but a new one was up and running within a day.&lt;br /&gt;
* {{#dateformat:2010-02-23}} - We can now execute code on everything besides the [[Nano 5G]]! Minimalistic iBugger working on [[Nano 3G]]!&lt;br /&gt;
* {{#dateformat:2009-11-01}} - iBugger core v0.1 successfully running on [[Nano 4G]]! [https://img217.imageshack.us/img217/4122/img0969.jpg]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
Follow [https://x.com/freemyipod our X feed] to get status updates automatically. See the [[Status]] page for more detailed information. Check our [https://github.com/freemyipod GitHub repositories] for the latest changes to our source code.&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;3&amp;quot; width=&amp;quot;100%&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Project info===&lt;br /&gt;
* [[ Status ]]&lt;br /&gt;
* [[ Contact ]]&lt;br /&gt;
* [[ Contributing ]]&lt;br /&gt;
&lt;br /&gt;
===Released Software===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[ipod_sun]]&lt;br /&gt;
* [[U-Boot|U-Boot port]]&lt;br /&gt;
* [[Linux|Linux port]]&lt;br /&gt;
* Legacy:&lt;br /&gt;
** [[iBugger]]&lt;br /&gt;
** [[iLoader]]&lt;br /&gt;
** [[emCORE]]&lt;br /&gt;
&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
===Basic skills===&lt;br /&gt;
* [[Working with binaries]]&lt;br /&gt;
* [[Dumping firmware]]&lt;br /&gt;
* [[Extracting firmware]]&lt;br /&gt;
* [[Firmware downgrading]]&lt;br /&gt;
* [[Troubleshooting]]&lt;br /&gt;
&lt;br /&gt;
===Reverse engineering results===&lt;br /&gt;
* [[Firmware]]&lt;br /&gt;
** [[Bootrom]]&lt;br /&gt;
** [[Boot Process]]&lt;br /&gt;
** [[Firmware decryption]]&lt;br /&gt;
** [[FTL|Flash Translation Layer]]&lt;br /&gt;
** [[RetailOS]]&lt;br /&gt;
*** [[RetailOS Options]]&lt;br /&gt;
* [[GUID table]]&lt;br /&gt;
* [[JTAG]]&lt;br /&gt;
* Nano 2G&lt;br /&gt;
** [[Nano2G clock gates‎]]&lt;br /&gt;
** [[Nano2G LCD init]]&lt;br /&gt;
** [[Nano2G HW analysis]]&lt;br /&gt;
** [[S5L8701 analysis]]&lt;br /&gt;
* Nano 4G&lt;br /&gt;
** [[Nano4G firmware upgrade process]]&lt;br /&gt;
* Nano 5G&lt;br /&gt;
** [[Nano 5G|General]]&lt;br /&gt;
|style=&amp;quot;border: 1px dashed #c6c9ff; background-color: #f0f0ff&amp;quot;|&lt;br /&gt;
===Hardware===&lt;br /&gt;
* [[Hardware]]&lt;br /&gt;
** [[Nano 1G]]&lt;br /&gt;
** [[Nano 2G]]&lt;br /&gt;
** [[Nano 3G]]&lt;br /&gt;
** [[Nano 4G]]&lt;br /&gt;
*** [[920-0614-03]]&lt;br /&gt;
** [[Nano 5G]]&lt;br /&gt;
** [[Nano 6G]]&lt;br /&gt;
** [[Nano 7G]]&lt;br /&gt;
** [[Classic 6G]]&lt;br /&gt;
* [[Chronology]]&lt;br /&gt;
* [[S5L8700 datasheet]]&lt;br /&gt;
* [[Modes]]&lt;br /&gt;
&lt;br /&gt;
===Exploiting===&lt;br /&gt;
* [[wInd3x]]&lt;br /&gt;
* [[Pwnage 2.0]]&lt;br /&gt;
* [[Notes vulnerability]]&lt;br /&gt;
** [[Address bruteforcing]]&lt;br /&gt;
** [[Nanotron 3000]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-console.png&amp;diff=22372</id>
		<title>File:Nano5g-console.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-console.png&amp;diff=22372"/>
		<updated>2026-07-25T23:42:26Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-console2.png&amp;diff=22371</id>
		<title>File:Nano5g-console2.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-console2.png&amp;diff=22371"/>
		<updated>2026-07-25T23:42:15Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-diskmode-patched.png&amp;diff=22370</id>
		<title>File:Nano5g-diskmode-patched.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-diskmode-patched.png&amp;diff=22370"/>
		<updated>2026-07-25T23:42:00Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-neofetch.png&amp;diff=22369</id>
		<title>File:Nano5g-neofetch.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-neofetch.png&amp;diff=22369"/>
		<updated>2026-07-25T23:41:51Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano5g-wayland.png&amp;diff=22368</id>
		<title>File:Nano5g-wayland.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano5g-wayland.png&amp;diff=22368"/>
		<updated>2026-07-25T23:41:39Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:Nano7g-patched-osos.png&amp;diff=22367</id>
		<title>File:Nano7g-patched-osos.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:Nano7g-patched-osos.png&amp;diff=22367"/>
		<updated>2026-07-25T23:41:30Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:S5L8701B05.png&amp;diff=22366</id>
		<title>File:S5L8701B05.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:S5L8701B05.png&amp;diff=22366"/>
		<updated>2026-07-25T23:41:20Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=File:S5L8702X01.png&amp;diff=22365</id>
		<title>File:S5L8702X01.png</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=File:S5L8702X01.png&amp;diff=22365"/>
		<updated>2026-07-25T23:41:02Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22364</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22364"/>
		<updated>2026-07-25T23:32:51Z</updated>

		<summary type="html">&lt;p&gt;User890104: add nano 2nd instructions&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
An experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] lives at https://github.com/freemyipod/u-boot/tree/s5l87xx .&lt;br /&gt;
&lt;br /&gt;
It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an IMG1 and sending it to [[WTF]]. This is what wInd3x does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 $ make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 $ make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 $ make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 $ make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi-&lt;br /&gt;
&lt;br /&gt;
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:&lt;br /&gt;
&lt;br /&gt;
 HOSTCFLAGS=&amp;quot;-I/opt/homebrew/Cellar/openssl@3/3.6.1/include&amp;quot; HOSTLDFLAGS=&amp;quot;-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib&amp;quot;&lt;br /&gt;
&lt;br /&gt;
substituting your OpenSSL version/path as needed.&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 2G]] ====&lt;br /&gt;
&lt;br /&gt;
Install Rockbox. Create an u-boot.ipod file by using the following tool from the Rockbox source code:&lt;br /&gt;
 $ ./rockbox/tools/scramble -add=nn2g u-boot.bin u-boot.ipod&lt;br /&gt;
Upload the file to your iPod. Run Rockbox, go to File Manager, find the u-boot.ipod file and select it.&lt;br /&gt;
&lt;br /&gt;
==== [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
=== Pushing an image to U-boot ===&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 $ dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Linux&amp;diff=22363</id>
		<title>Linux</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Linux&amp;diff=22363"/>
		<updated>2026-07-25T23:17:55Z</updated>

		<summary type="html">&lt;p&gt;User890104: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Current: Freemyipod Linux ==&lt;br /&gt;
&lt;br /&gt;
We are working on supporting Samsung/S5L-based devices which have an MMU. Currently our main focus is the [[Nano 7G]], there are also builds for [[Nano 2G]], [[Nano 3G]] and [[Nano 5G]]. An experimental source tree is available on [https://github.com/freemyipod/linux github.com/freemyipod/linux]. Aditionaly [[User:ZeOne]] is working on making it work with the [[Nano 6G]] you can read more about that on his page.&lt;br /&gt;
&lt;br /&gt;
=== User Guide ===&lt;br /&gt;
&lt;br /&gt;
Not yet available, as the Linux port isn&#039;t yet practical to use. We have no storage drivers, no sound driver...&lt;br /&gt;
&lt;br /&gt;
=== Developer Guide ===&lt;br /&gt;
&lt;br /&gt;
If you&#039;re somewhat familiar with embedded Linux, you can get started by building [[WInd3x|wInd3x]], [[U-Boot]] and the Kernel as described below. However, &#039;&#039;&#039;you will have to provide your own userland&#039;&#039;&#039; (eg. buildroot, archlinux arm, ... anything armv6 compatible) and either run it from an initramfs or over NFS. &#039;&#039;&#039;A serial cable is not necessary, but very useful to troubleshoot boot issues.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== Build everything ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;These are not copy-paste instructions. You are expected to understand what&#039;s happening.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
You will need an arm-none-eabi- toolchain into your $PATH, eg. gcc-arm-embedded from your package manager.&lt;br /&gt;
&lt;br /&gt;
First, build [[wInd3x#Building]].&lt;br /&gt;
&lt;br /&gt;
Second, build [[U-Boot]].&lt;br /&gt;
&lt;br /&gt;
Third, Linux:&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://github.com/freemyipod/linux&lt;br /&gt;
 $ cd linux&lt;br /&gt;
&lt;br /&gt;
For iPod nano (2nd generation):&lt;br /&gt;
 $ git checkout n2g-wip&lt;br /&gt;
 $ make ARCH=arm nano2g_defconfig&lt;br /&gt;
&lt;br /&gt;
For iPod nano (3rd generation):&lt;br /&gt;
 $ git checkout n3g-wip&lt;br /&gt;
 $ make ARCH=arm nano3g_defconfig&lt;br /&gt;
&lt;br /&gt;
For iPod nano (5th generation):&lt;br /&gt;
 $ git checkout n5g-wip&lt;br /&gt;
 $ make ARCH=arm nano5g_defconfig&lt;br /&gt;
&lt;br /&gt;
For iPod nano (7th generation):&lt;br /&gt;
 $ git checkout n7g-wip&lt;br /&gt;
 $ make ARCH=arm apple_n31_defconfig&lt;br /&gt;
&lt;br /&gt;
Alternatively, there is an experimental branch which should merge all of the ports:&lt;br /&gt;
 $ git checkout s5l87xx&lt;br /&gt;
Then use the relevant defconfig according to the above commands.&lt;br /&gt;
&lt;br /&gt;
After configuring, build the kernel:&lt;br /&gt;
 $ make ARCH=arm CROSS_COMPILE=arm-none-eabi- -j $(nproc) zImage&lt;br /&gt;
&lt;br /&gt;
By this point, have a initramfs ready. If you wanna boot directly from nfs, edit CMDLINE in the kernel .config accordingly.&lt;br /&gt;
&lt;br /&gt;
Finally, bundle together an u-boot image containing the kernel, your initramfs, and the device-tree (built by u-boot):&lt;br /&gt;
&lt;br /&gt;
 $ mkimage -A arm -C none -O linux -T multi -a 0x08000000 -e 0x08000000 -d arch/arm/boot/zImage:initramfs.gz:../u-boot/arch/arm/dts/s5l8730.dtb mImage&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;mImage&#039;&#039; is your combined image.&lt;br /&gt;
&lt;br /&gt;
==== Running ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod nano in DFU mode.&lt;br /&gt;
&lt;br /&gt;
For [[Nano 3G]] and later, execute u-boot using wInd3x:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run ../u-boot/u-boot.bin&lt;br /&gt;
&lt;br /&gt;
This should start u-boot. Running this for the first time will take a while, as some bootloader stages need to be downloaded, decrypted and modified. A new USB device (05ac:8007) appear on your host. Use dfu-util to upload mImage:&lt;br /&gt;
&lt;br /&gt;
 dfu-util -d 05ac:8007 -D mImage &amp;amp;&amp;amp; dfu-util -d 05ac:8007 -e&lt;br /&gt;
&lt;br /&gt;
For the [[Nano 2G]], you will have to chainload the rockbox bootloader with u-boot.&lt;br /&gt;
&lt;br /&gt;
To do this, we assume you have already built u-boot dtbs along with Linux.&lt;br /&gt;
&lt;br /&gt;
To create the mImage, run this command inside your Linux folder:&lt;br /&gt;
&lt;br /&gt;
 $ ./create_image.sh&lt;br /&gt;
&lt;br /&gt;
Note: if it dosen’t work, you will have to make it executable, usually by running:&lt;br /&gt;
&lt;br /&gt;
 $ chmod +x create_image.sh&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After it creates the mImage, go to your u-boot folder and build u-boot.bin.&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi- -j $(nproc) u-boot.bin&lt;br /&gt;
&lt;br /&gt;
Now generate a fake rockbox.ipod that tricks it into starting U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./tools/mkimage -T ipod -d u-boot.bin rockbox.ipod&lt;br /&gt;
&lt;br /&gt;
Copy this new rockbox.ipod into the .rockbox folder on your iPod nano 2G.&lt;br /&gt;
&lt;br /&gt;
Then, in the serial console you&#039;ll see Linux booting:&lt;br /&gt;
&lt;br /&gt;
 ## Booting kernel from Legacy Image at 08000000 ...&lt;br /&gt;
 ...&lt;br /&gt;
 Starting kernel ...&lt;br /&gt;
 &lt;br /&gt;
 [    0.000000] Booting Linux on physical CPU 0x0&lt;br /&gt;
 [    0.000000] Linux version 6.2.0-rc4-00476-g4c4af4d7e53c (q3k@mimeomia) (arm-none-eabi-gcc (GNU Arm Embedded Toolchain 10.3-2021.10) 10.3.1 20210824 (release), GNU ld (GNU Arm Embedded Toolchain 10.3-2021.10) 2.36.1.20210621) #70 Fri Jan 20 18:02:56 CET 2023&lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
The LCD display should start up and show a boot log. If not, try adding &amp;lt;code&amp;gt;console=tty0&amp;lt;/code&amp;gt; to your CMDLINE? You might also use &amp;lt;code&amp;gt;fbcon=rotate:1&amp;lt;/code&amp;gt; to rotate the framebuffer 90 degrees.&lt;br /&gt;
&lt;br /&gt;
If everything goes well, the kernel should boot up and attempt to mount a rootfs. It&#039;s up to you to get this part working, at least until we streamline the process. The USB CDC EEM ethernet gadget should also appear on your host (probably as usb0, or some long systemd predictable name). The other end will be visible as &#039;usb0&#039; on the device.&lt;br /&gt;
&lt;br /&gt;
On [[Nano 7G]] you&#039;ll need a DCSD cable (Alex/Magico), and the command line to get proper serial output:&lt;br /&gt;
&lt;br /&gt;
 picocom --baud 115200 --imap lfcrlf /dev/ttyUSB0&lt;br /&gt;
&lt;br /&gt;
Now go on and have a go at reverse-engineering some peripherals! :)&lt;br /&gt;
&lt;br /&gt;
== Legacy: iPodLinux ==&lt;br /&gt;
&lt;br /&gt;
The [http://www.ipodlinux.org/ iPodLinux] project supports all the PortalPlayer based iPods: iPod 1G-4G, Photo/Color, Video/5G/5.5G, Mini, iPod Nano 1G. It is currently semi-abandoned, and uses a very old ucLinux kernel build.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=Linux&amp;diff=22362</id>
		<title>Linux</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=Linux&amp;diff=22362"/>
		<updated>2026-07-25T23:15:28Z</updated>

		<summary type="html">&lt;p&gt;User890104: update building instructions&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Current: Freemyipod Linux ==&lt;br /&gt;
&lt;br /&gt;
We are working on supporting Samsung/S5L-based devices which have an MMU. Currently our main focus is the [[Nano 7G]], there are also builds for [[Nano 2G]], [[Nano 3G]] and [[Nano 5G]]. An experimental source tree is available on [https://github.com/freemyipod/linux github.com/freemyipod/linux]. Aditionaly [[User:ZeOne]] is working on making it work with the [[Nano 6G]] you can read more about that on his page.&lt;br /&gt;
&lt;br /&gt;
=== User Guide ===&lt;br /&gt;
&lt;br /&gt;
Not yet available, as the Linux port isn&#039;t yet practical to use. We have no storage drivers, no sound driver...&lt;br /&gt;
&lt;br /&gt;
=== Developer Guide ===&lt;br /&gt;
&lt;br /&gt;
If you&#039;re somewhat familiar with embedded Linux, you can get started by building [[WInd3x|wInd3x]], [[U-Boot]] and the Kernel as described below. However, &#039;&#039;&#039;you will have to provide your own userland&#039;&#039;&#039; (eg. buildroot, archlinux arm, ... anything armv6 compatible) and either run it from an initramfs or over NFS. &#039;&#039;&#039;A serial cable is not necessary, but very useful to troubleshoot boot issues.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== Build everything ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;These are not copy-paste instructions. You are expected to understand what&#039;s happening.&#039;&lt;br /&gt;
&lt;br /&gt;
You will need an arm-none-eabi- toolchain into your $PATH, eg. gcc-arm-embedded from your package manager.&lt;br /&gt;
&lt;br /&gt;
First, build [[wInd3x#Building]].&lt;br /&gt;
&lt;br /&gt;
Second, build [[U-Boot]].&lt;br /&gt;
&lt;br /&gt;
Third, Linux:&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://github.com/freemyipod/linux&lt;br /&gt;
 $ cd linux&lt;br /&gt;
&lt;br /&gt;
For iPod nano (2nd generation):&lt;br /&gt;
 $ git checkout n2g-wip&lt;br /&gt;
 $ make ARCH=arm nano2g_defconfig&lt;br /&gt;
&lt;br /&gt;
For iPod nano (3rd generation):&lt;br /&gt;
 $ git checkout n3g-wip&lt;br /&gt;
 $ make ARCH=arm nano3g_defconfig&lt;br /&gt;
&lt;br /&gt;
For iPod nano (5th generation):&lt;br /&gt;
 $ git checkout n5g-wip&lt;br /&gt;
 $ make ARCH=arm nano5g_defconfig&lt;br /&gt;
&lt;br /&gt;
For iPod nano (7th generation):&lt;br /&gt;
 $ git checkout n7g-wip&lt;br /&gt;
 $ make ARCH=arm apple_n31_defconfig&lt;br /&gt;
&lt;br /&gt;
Alternatively, there is an experimental branch which should merge all of the ports:&lt;br /&gt;
 $ git checkout s5l87xx&lt;br /&gt;
Then use the relevant defconfig according to the above commands.&lt;br /&gt;
&lt;br /&gt;
After configuring, build the kernel:&lt;br /&gt;
 $ make ARCH=arm CROSS_COMPILE=arm-none-eabi- -j $(nproc) zImage&lt;br /&gt;
&lt;br /&gt;
By this point, have a initramfs ready. If you wanna boot directly from nfs, edit CMDLINE in the kernel .config accordingly.&lt;br /&gt;
&lt;br /&gt;
Finally, bundle together an u-boot image containing the kernel, your initramfs, and the device-tree (built by u-boot):&lt;br /&gt;
&lt;br /&gt;
 $ mkimage -A arm -C none -O linux -T multi -a 0x08000000 -e 0x08000000 -d arch/arm/boot/zImage:initramfs.gz:../u-boot/arch/arm/dts/s5l8730.dtb mImage&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;mImage&#039;&#039; is your combined image.&lt;br /&gt;
&lt;br /&gt;
==== Running ====&lt;br /&gt;
&lt;br /&gt;
Connect your iPod nano in DFU mode.&lt;br /&gt;
&lt;br /&gt;
For [[Nano 3G]] and later, execute u-boot using wInd3x:&lt;br /&gt;
&lt;br /&gt;
 $ ./wInd3x cfw run ../u-boot/u-boot.bin&lt;br /&gt;
&lt;br /&gt;
This should start u-boot. Running this for the first time will take a while, as some bootloader stages need to be downloaded, decrypted and modified. A new USB device (05ac:8007) appear on your host. Use dfu-util to upload mImage:&lt;br /&gt;
&lt;br /&gt;
 dfu-util -d 05ac:8007 -D mImage &amp;amp;&amp;amp; dfu-util -d 05ac:8007 -e&lt;br /&gt;
&lt;br /&gt;
For the [[Nano 2G]], you will have to chainload the rockbox bootloader with u-boot.&lt;br /&gt;
&lt;br /&gt;
To do this, we assume you have already built u-boot dtbs along with Linux.&lt;br /&gt;
&lt;br /&gt;
To create the mImage, run this command inside your Linux folder:&lt;br /&gt;
&lt;br /&gt;
 $ ./create_image.sh&lt;br /&gt;
&lt;br /&gt;
Note: if it dosen’t work, you will have to make it executable, usually by running:&lt;br /&gt;
&lt;br /&gt;
 $ chmod +x create_image.sh&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
After it creates the mImage, go to your u-boot folder and build u-boot.bin.&lt;br /&gt;
&lt;br /&gt;
 $ make CROSS_COMPILE=arm-none-eabi- -j $(nproc) u-boot.bin&lt;br /&gt;
&lt;br /&gt;
Now generate a fake rockbox.ipod that tricks it into starting U-Boot:&lt;br /&gt;
&lt;br /&gt;
 $ ./tools/mkimage -T ipod -d u-boot.bin rockbox.ipod&lt;br /&gt;
&lt;br /&gt;
Copy this new rockbox.ipod into the .rockbox folder on your iPod nano 2G.&lt;br /&gt;
&lt;br /&gt;
Then, in the serial console you&#039;ll see Linux booting:&lt;br /&gt;
&lt;br /&gt;
 ## Booting kernel from Legacy Image at 08000000 ...&lt;br /&gt;
 ...&lt;br /&gt;
 Starting kernel ...&lt;br /&gt;
 &lt;br /&gt;
 [    0.000000] Booting Linux on physical CPU 0x0&lt;br /&gt;
 [    0.000000] Linux version 6.2.0-rc4-00476-g4c4af4d7e53c (q3k@mimeomia) (arm-none-eabi-gcc (GNU Arm Embedded Toolchain 10.3-2021.10) 10.3.1 20210824 (release), GNU ld (GNU Arm Embedded Toolchain 10.3-2021.10) 2.36.1.20210621) #70 Fri Jan 20 18:02:56 CET 2023&lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
The LCD display should start up and show a boot log. If not, try adding &amp;lt;code&amp;gt;console=tty0&amp;lt;/code&amp;gt; to your CMDLINE? You might also use &amp;lt;code&amp;gt;fbcon=rotate:1&amp;lt;/code&amp;gt; to rotate the framebuffer 90 degrees.&lt;br /&gt;
&lt;br /&gt;
If everything goes well, the kernel should boot up and attempt to mount a rootfs. It&#039;s up to you to get this part working, at least until we streamline the process. The USB CDC EEM ethernet gadget should also appear on your host (probably as usb0, or some long systemd predictable name). The other end will be visible as &#039;usb0&#039; on the device.&lt;br /&gt;
&lt;br /&gt;
On [[Nano 7G]] you&#039;ll need a DCSD cable (Alex/Magico), and the command line to get proper serial output:&lt;br /&gt;
&lt;br /&gt;
 picocom --baud 115200 --imap lfcrlf /dev/ttyUSB0&lt;br /&gt;
&lt;br /&gt;
Now go on and have a go at reverse-engineering some peripherals! :)&lt;br /&gt;
&lt;br /&gt;
== Legacy: iPodLinux ==&lt;br /&gt;
&lt;br /&gt;
The [http://www.ipodlinux.org/ iPodLinux] project supports all the PortalPlayer based iPods: iPod 1G-4G, Photo/Color, Video/5G/5.5G, Mini, iPod Nano 1G. It is currently semi-abandoned, and uses a very old ucLinux kernel build.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=WInd3x&amp;diff=22361</id>
		<title>WInd3x</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=WInd3x&amp;diff=22361"/>
		<updated>2026-07-25T23:04:06Z</updated>

		<summary type="html">&lt;p&gt;User890104: add building instructions&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== wInd3x Vulnerability ==&lt;br /&gt;
{{DISPLAYTITLE:wInd3x}}&lt;br /&gt;
&lt;br /&gt;
A [[S5L8720 Bootrom|Bootrom]] vulnerability discovered and exploited by [[User:Q3k|q3k]] in December 2021. It allows code execution in the bootrom over USB.&lt;br /&gt;
&lt;br /&gt;
=== Affected Devices ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Device/SoC !! Vulnerable? !! Exploited?&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 3G]] || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 4G]] || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 5G]] || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 6G]] || No || &lt;br /&gt;
|-&lt;br /&gt;
| [[Nano 7G]] || No || &lt;br /&gt;
|-&lt;br /&gt;
| Classic “6G” || Yes || Yes&lt;br /&gt;
|-&lt;br /&gt;
| iPhone || ? ||&lt;br /&gt;
|-&lt;br /&gt;
| iPhone 3G || Yes || No&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 $ git clone https://github.com/freemyipod/wInd3x&lt;br /&gt;
 $ cd wInd3x&lt;br /&gt;
&lt;br /&gt;
You&#039;ll need go and libusb. Then:&lt;br /&gt;
 $ go build ./cmd/wInd3x&lt;br /&gt;
Or, if you have Nix(OS), just do:&lt;br /&gt;
 $ nix-build&lt;br /&gt;
=== Running / Usage ===&lt;br /&gt;
&lt;br /&gt;
wInd3x currently allows you to:&lt;br /&gt;
&lt;br /&gt;
# Decrypt [[IMG1]] files, like [[OSOS]] or the bootloader/[[WTF]]/...&lt;br /&gt;
# Access arbitrary memory and experiment with peripherals&lt;br /&gt;
# Run unsigned DFU payloads&lt;br /&gt;
# Run an unsigned [[OSOS]] or [[U-Boot]] by first running an automatically patched [[WTF]].&lt;br /&gt;
&lt;br /&gt;
For guides, see [https://github.com/freemyipod/wInd3x github.com/freemyipod/wInd3x]&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability ===&lt;br /&gt;
&lt;br /&gt;
This exploits a vulnerability in the standard SETUP packet parsing code of the bootrom, in which the wIndex parameter is not checked for bmRequest == {0x20, 0x40}, but is still used to index an array of interface/class handlers (that in the Bootrom has a length of 1).&lt;br /&gt;
&lt;br /&gt;
==== Nano 4G and 5G Exploit Chain ====&lt;br /&gt;
&lt;br /&gt;
The first requirement is to find a suitable (blx r0) instruction in the bootrom code of the device. For Nano 4G the only one such instruction is at offset 0x3b0, and for Nano 5G there is such instruction at 0x37c. We&#039;ll refer to it as X below.&lt;br /&gt;
&lt;br /&gt;
We abuse the fact that wIndex == 3 for bmRequest 0x40 treats a &#039;bytes left to sent over USB&#039; counter as a function pointer and calls it with r0 == address of SETUP. We massage the DFU mode into attempting to send us X+0x40 bytes, and failing after 0x40 bytes, thereby leaving the counter at X bytes and executing code at address X.&lt;br /&gt;
&lt;br /&gt;
Since the bootrom is mapped at offset 0x0 as well as 0x20000000 at boot, this means we execute bootrom code, and X happens to point to a &#039;blx r0&#039; instruction. This in turn causes the CPU to interpret the SETUP packet received as ARM code, because the SETUP handler is called with the SETUP packet as its argument, i.e. r0.&lt;br /&gt;
&lt;br /&gt;
We specially craft the SETUP packet to be a valid ARM branch instruction, pointing somewhere into a temporary DFU image buffer. By first sending a payload as a partial DFU image (aborting before causing a MANIFEST), we finally get up to be able to execute either 0x800 on Nano 4G or 0x400 on Nano 5G bytes of fully user controlled code.&lt;br /&gt;
&lt;br /&gt;
In that payload, we send a stub which performs some runtime changes to the DFU&#039;s data structures to a) return a different product string b) overwrite an image verification vtable entry with a function that allows unsigned images. Some SRAM is carved out by this pay&lt;br /&gt;
&lt;br /&gt;
==== Nano 3G and Classic (”6G”) ====&lt;br /&gt;
&lt;br /&gt;
With bRequestType == 0x20 and wIndex == 6 we directly jump to code execution at the SETUP packet.&lt;br /&gt;
&lt;br /&gt;
This Bootroom does not have a VTable which can be easily hooked to override functions to provide Haxed DFU functionality. However, an &#039;OnImage&#039; function pointer is present in the State structure, which we override with our own code (copied to carved out SRAM). This code reimplements the bare minimum of the hooked function, without calling any decryption/verification code on the header/body.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22360</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22360"/>
		<updated>2026-07-25T23:01:16Z</updated>

		<summary type="html">&lt;p&gt;User890104: add macOS instruction&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
An experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] lives at https://github.com/freemyipod/u-boot/tree/s5l87xx .&lt;br /&gt;
&lt;br /&gt;
It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an IMG1 and sending it to [[WTF]]. This is what wInd3x does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 make CROSS_COMPILE=arm-none-eabi-&lt;br /&gt;
&lt;br /&gt;
On macOS, you need to install openssl using homebrew. If the build system does not find it, append the following to the build command:&lt;br /&gt;
&lt;br /&gt;
 HOSTCFLAGS=&amp;quot;-I/opt/homebrew/Cellar/openssl@3/3.6.1/include&amp;quot; HOSTLDFLAGS=&amp;quot;-L/opt/homebrew/Cellar/openssl@3/3.6.1/lib&amp;quot;&lt;br /&gt;
&lt;br /&gt;
substituting your OpenSSL version/path as needed.&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
After building, connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
	<entry>
		<id>https://freemyipod.org/index.php?title=U-Boot&amp;diff=22359</id>
		<title>U-Boot</title>
		<link rel="alternate" type="text/html" href="https://freemyipod.org/index.php?title=U-Boot&amp;diff=22359"/>
		<updated>2026-07-25T22:58:47Z</updated>

		<summary type="html">&lt;p&gt;User890104: update with support for other models besides n5g&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== U-Boot Port ==&lt;br /&gt;
&lt;br /&gt;
An experimental U-Boot port for the [[Nano 2G]], [[Nano 3G]], [[Nano 5G]] and [[Nano 7G]] lives at https://github.com/freemyipod/u-boot/tree/s5l87xx .&lt;br /&gt;
&lt;br /&gt;
It can be started using [[wInd3x]] and will start up a CDC-ACM serial console over USB for debugging purposes. Currently it has no storage driver.&lt;br /&gt;
&lt;br /&gt;
The current port expects to be loaded in place of [[OSOS]], eg. by packaging it into an IMG1 and sending it to [[WTF]]. This is what wInd3x does. This way, U-Boot does not have to do any of the &#039;annoying&#039; early boot stuff like bringing up DRAM.&lt;br /&gt;
&lt;br /&gt;
=== Configuring ===&lt;br /&gt;
&lt;br /&gt;
 make apple_n36_defconfig # iPod nano (2nd generation)&lt;br /&gt;
 make apple_n46_defconfig # iPod nano (3rd generation)&lt;br /&gt;
 make apple_n33_defconfig # iPod nano (5th generation)&lt;br /&gt;
 make apple_n31_defconfig # iPod nano (7th generation)&lt;br /&gt;
&lt;br /&gt;
=== Building ===&lt;br /&gt;
&lt;br /&gt;
 make CROSS_COMPILE=arm-none-eabi-&lt;br /&gt;
&lt;br /&gt;
=== Running ===&lt;br /&gt;
&lt;br /&gt;
After building, connect your iPod in [[Modes|DFU Mode]] and use [[wInd3x]] to start U-Boot:&lt;br /&gt;
&lt;br /&gt;
 ./wInd3x cfw run u-boot.bin&lt;br /&gt;
&lt;br /&gt;
When successfully started, U-Boot will then enumerate as yet another DFU device, this time ready to receive an U-Boot compatible image. You can load an image using dfu-util:&lt;br /&gt;
&lt;br /&gt;
 dfu-util --device 05ac:8007 --download foo&lt;br /&gt;
 dfu-util --device 05ac:8007 --detach&lt;br /&gt;
&lt;br /&gt;
Note the &amp;lt;code&amp;gt;--detach&amp;lt;/code&amp;gt; command: this is needed to get U-Boot to exit DFU mode and actually execute the image.&lt;/div&gt;</summary>
		<author><name>User890104</name></author>
	</entry>
</feed>