Finally i got a good news for you which is, you can now unlock any iPhone on any baseband using SAM (Subscriber Artificial Module). This method works for every iPhone running iOS 5.0 or above, we’re not explicitly saying that it ONLY works on mentioned iOS firmwares but we’ve tested it on devices running iOS 5.0 and above and it works. The working is pretty simple and found by username Lockstar_Sun, he found a vulnerability in ICCID and iTunes BB unlock activation ticket which allowed him to trick iTunes and make it believe that you’re running official SIM card on your carrier locked device.
This method works for iPhone 3GS, iPhone 4 and iPhone 4S. But i like to tell you couple of things about this procedure:
- This is a SIM specific unlock which means that once you unlock using a specific SIM that iPhone would stay unlocked to that SPECIFIC SIM only. You cannot use it with any other SIM card.
- Your iPhone must be jailbroken
So let’s begin the process on how you can do it to unlock your iPhone
STEP 1: Launch Cydia and add this repo:
after adding this repor search for SAM and install it.
STEP 2: Once installed, SAM will create SAMPrefs icon on your home screen, tap it.
STEP 3: Go to utilities and select “De-Activate iPhone”, your ActivationState under “More Information” should now be “Unactivated”
STEP 4: Make sure that SAM is Enabled, choose “By Country and Carrier” in “Method”; find your carrier, for some carriers operating more than one Carrier ID you may need to select “SIM ID”; easy to tell since iTunes will not activate if the wrong IMSI is selected.
STEP 5: Navigate to More Information, copy or write down the IMSI in “SAM Details”, then tap “Spoof Real SIM to SAM”.
STEP 6: Go back to the main SAM screen and change your “Method” to manual. Paste or enter the IMSI number you saved in last step.
STEP 7: Connect your iPhone to your computer and launch iTunes, iTunes will now activate your iPhone, double click “Phone Number” parameter at the main device screen and make sure that the ICCID matches that of your SIM card. If not you need to start over from Step 3.
STEP 8: Unplug your phone, close iTunes.
STEP 9: Disable SAM. The source article says to uninstall SAM and delete your lockdownd folders; it’s unnecessary.
STEP 10: Connect your phone to iTunes again, you should get an error saying that your phone cannot be activated. This is a good news for you DON’T PANIC. Just close iTunes and open it again.
STEP 11: You should see signal bars in a short time, congratulations.
Push notifications may stop working after this procedure but can be easily restored with “clear push” utility in SAM followed by connecting to iTunes.
Save everything located in /var/root/Library/Lockdown/ and you’re golden.