• Now you can dump rootkey without Linux, @willemse21 brought this news to the board. Nice to see more progress being made on this topic. Needless to say use it at your own RISK. Don’t ask about a n00b tutorial, as far as i know nobody is doing it, hence we are in *testing* stances. When something *foolproof* and noob friendly arises you will see it posted.

    dump_rootkey – 2012 by naehrwert

    === How-to ===
    [1] Install asbestos_ldr.g.pkg on your PS3 (a firmware with lv2 peek/poke is
    required to run it).
    [2] Compile the client (make sure PS3HOST in main.cpp points to your PS3).
    [3] Make sure you got your metldr in ‘./data’ as ‘metldr’.
    [4] A prebuilt ‘dumper’ is included in ‘./data’ (dumper.elf and build.bat is
    included too if you want to change parameters).
    [5] Start asbestos_ldr on your PS3.
    [6] Start the client on your PC.
    [7] Unicorns!

    === Asbestos License ===
    Copyright (C) 2010-2011 Hector Martin “marcan” SPU mailbox threshold interrupt
    [INFO] Interrupt status (2, application) = 0000000000000011
    [INFO] -> SPU mailbox threshold interrupt
    [INFO] -> mailbox interrupt
    [INFO] Mailbox value = 1
    [INFO] -> Dumper loaded.
    [INFO] Transferring eid_root_key to buffer…finished.
    [INFO] Dumping eid_root_key…done.
    [INFO] SPU status = 0×00000081
    [INFO] Destructing spe…done.
    [INFO] Press any key to exit…

    Download Link: http://www.sendspace.com/file/dxdmat

    Pastie: http://pastie.org/4301209

    To quote:

    Something interesting that wrote @JonahUK:

    You will still need to do some manual editing for the conversion but this is still great news.

    @PsDev response:

    Nope, once root key is dumped you’re good, just run flash and root key my/gunner tool (Depending on flash) and then validation will be done, just re-flash to you’re now DEX flash and it will still boot into gameOS just now update to 4.11 DEX FW or any DEX FW

    Source:
    https://twitter.com/naehrwert

     

    Discuss in Forums (348)


  • 348 Comments

    1. JonahUK
      07-22-2012
      02:08 PM
      1

      Also:

      <naehrwert> nope only gives you the key
      You will still need to do some manual editing for the conversion but this is still great news.

    2. benzinjiq
      07-22-2012
      02:13 PM
      2

      I just love the way new methods and stuff appear all the time. Makes the scene feel "alive" like old times... Thank you [MENTION=208169]willemse21[/MENTION] for the topic, and thank you @naehrwert for the good work, like always.

    3. PsDev
      07-22-2012
      02:14 PM
      3

      Originally Posted by JonahUK View Post
      Also:



      You will still need to do some manual editing for the conversion but this is still great news.
      Nope, once root key is dumped you're good, just run flash and root key my/gunner tool (Depending on flash) and then validation will be done, just re-flash to you're now DEX flash and it will still boot into gameOS just now update to 4.11 DEX FW or any DEX FW

    4. JonahUK
      07-22-2012
      02:17 PM
      4

      Originally Posted by PsDev View Post
      Nope, once root key is dumped you're good
      Thanks for the confirmation.

    5. zaphod
      07-22-2012
      02:17 PM
      5

      @naehrwert

      wow, youre so fast in developing this.. BIG THANKS for that..

      i guess you did not need any metldr dumps as requested in a other thread?
      if still needed.. no prop wanna test the ps3 app for dumping it ;-)

    6. OrangeC
      07-22-2012
      02:20 PM
      6

      Is this the per console key or the actual ps3 rootkey?

    7. triadis
      07-22-2012
      02:28 PM
      7

      so if i got it right all we have to do to get our root key is to install asbestos run an ftp client and we are ok right?

    8. zaphod
      07-22-2012
      02:29 PM
      8

      hm, for compiling the PC-Side i have to install something like gcc or visual studio...

      can you "outsource" the PS3 IP-Adress as a parameter in a config file?
      So everyone can use it more flexible???

    9. a$h x
      07-22-2012
      02:29 PM
      9

      What commands would I use to compile this? $ make *client_name_here*

    10. zecoxao
      07-22-2012
      02:31 PM
      10

      not posix, but unix... whatever xD

    11. a$h x
      07-22-2012
      02:32 PM
      11

      Originally Posted by triadis View Post
      so if i got it right all we have to do to get our root key is to install asbestos run an ftp client and we are ok right?
      Nah, you compile an app to run locally (on your PC, and you need to edit the main.cpp so it contains your PS3 IP address) then run the .pkg file on the PS3, and the EID is sent to the client app. Better and quicker than wiping your entire internal HDD to install linux.

    12. homedog
      07-22-2012
      02:33 PM
      12

      Originally Posted by OrangeC View Post
      Is this the per console key or the actual ps3 rootkey?
      it's the per console key aka eid_root_key.

    13. rrr159
      07-22-2012
      02:42 PM
      13

      Alright so can we use windows to do this?

      I don't have a computer so I can't see download files

      Sent from my SPH-M580 using Tapatalk 2

    14. triadis
      07-22-2012
      02:43 PM
      14

      Originally Posted by a$h x View Post
      Nah, you compile an app to run locally (on your PC, and you need to edit the main.cpp so it contains your PS3 IP address) then run the .pkg file on the PS3, and the EID is sent to the client app. Better and quicker than wiping your entire internal HDD to install linux.
      thanks i edit the main.cpp but i have no idea how to compile the client.

    15. a$h x
      07-22-2012
      02:49 PM
      15

      It's C++ source code, so you could use Microsoft Visual C++ 2010 Express (it's free to compile a client.
      Someone will soon make an .exe with a GUI which asks for your PS3's IP addy, it will become relatively foolproof... I hope.

    16. xangma
      07-22-2012
      03:04 PM
      16

      Has anyone actually gotten this to work?

      I changed IP of the PS, and changed the IP in the main.cpp file. The program built fine (using "sudo sh ./build.sh") I could ping the PS3 in the XMB, but when I loaded up the asbestos.g.pkg file, the screen went black, and no more ping.

      I ran the program dump_rootkey, and it printed one line:

      Code:
      [INFO] Connecting to 192.168.0.2 ... ok
      Nothing more =[ Thanks for the dev work though!

    17. tul
      07-22-2012
      03:33 PM
      17

      Originally Posted by xangma View Post
      Has anyone actually gotten this to work?

      I changed IP of the PS, and changed the IP in the main.cpp file. The program built fine (using "sudo sh ./build.sh") I could ping the PS3 in the XMB, but when I loaded up the asbestos.g.pkg file, the screen went black, and no more ping.

      I ran the program dump_rootkey, and it printed one line:

      Code:
      [INFO] Connecting to 192.168.0.2 ... ok
      Nothing more =[ Thanks for the dev work though!
      same here, maybe we cant use kmeaw firmware, i dont know what is lv2 peek poke, but prolly that it.

    18. xangma
      07-22-2012
      03:57 PM
      18

      Originally Posted by tul View Post
      same here, maybe we cant use kmeaw firmware, i dont know what is lv2 peek poke, but prolly that it.
      I've tried with the gitbrew and rebug 3.55.2 fw =[

    19. haz367
      07-22-2012
      04:02 PM
      19

      kmeaw,rogero they all should do the job
      its just connecting....nothing more..hard reset to quit app, yes i block it internet access, only ps3ip allowed..to bad..maibe someone else has more luck ...thx anyway

    20. mcmrc1
      07-22-2012
      04:03 PM
      20

      thx naehrwert good to know you are in the ps3 scene.

    21. haz367
      07-22-2012
      04:04 PM
      21

      kmeaw,rogero they all should do the job
      its just connecting....nothing more..hard reset to quit app, yes i block it internet access, only ps3ip allowed..to bad..maibe someone else has more luck ...thx anyway..wait lets try again

    22. Asure
      07-22-2012
      05:06 PM
      22

      My results are at http://pastie.org/4302552

      The ps3 app just hangs on blackscreened ps3 and you can't ping it. I guess that's the problem?

      Also dump_rootkey doesn't compile on gcc, i needed to use g++ but get the same results you guys do..

    23. ovhaum
      07-22-2012
      05:16 PM
      23

      Too bad im not the only one who cant get the root_key from this metod... I've tried with Kmeaw (need to hard reset and then Rebuild Databese in Recovery Menu every time i run asbestos_ldr on KMEAW) and CFW355-OTHEROS++-SPECIAL.

      But i only get
      [INFO] Connecting to 'ip_adress'...ok.

      Damn.

    24. zaphod
      07-22-2012
      05:17 PM
      24

      Originally Posted by Asure View Post
      My results are at http://pastie.org/4302552

      The ps3 app just hangs on blackscreened ps3 and you can't ping it. I guess that's the problem?

      Also dump_rootkey doesn't compile on gcc, i needed to use g++ but get the same results you guys do..
      as i understand the client code is for windows-pc? cause there is microsoft visual c++ mentioned above?

    25. Asure
      07-22-2012
      05:24 PM
      25

      Originally Posted by zaphod View Post
      as i understand the client code is for windows-pc? cause there is microsoft visual c++ mentioned above?
      There were no proper instructions to compile the client, but the build.sh script was a clear 'bash shell' reference for me to compile it on linux, i had a vmware box ready to roll anyways. (As the others in this thread probably also did.)

      I tried to compile a version with mingw for win32 as well, but this didn't compile as mingw's gcc requires a large number of path modifications to even run 'gcc.exe' from the commandline. Or i'm missing something

      I don't think the compiling is the cause of the problem. The rpc server seems to be, as it seems to 'just blackscreen' and you can't even ping the ps3 after that. I need to use the ps3's hardware power switch to get it back up again..

    26. cory1492
      07-22-2012
      06:08 PM
      26

      I think someone forgot to add a couple ULL to the end of some important numbers, and it's causing some issues. But hey, I can't even get the .g.pkg to install without getting an error

      edit:/ nix that (well those two errors on line 243 still need to be resolved by adding a ULL), the client doesn't seem to care if it finds a ps3 with rpc server at all when it does connect, it will always say ok even with wildly wrong IP addresses. The package don't like me either way (80029564), not that I need it as I already did this process weeks ago anyway on my own steam.

    27. LiteSoul
      07-22-2012
      06:37 PM
      27

      Originally Posted by cory1492 View Post
      I think someone forgot to add a couple ULL to the end of some important numbers, and it's causing some issues. But hey, I can't even get the .g.pkg to install without getting an error

      edit:/ nix that (well those two errors on line 243 still need to be resolved by adding a ULL), the client doesn't seem to care if it finds a ps3 with rpc server at all when it does connect, it will always say ok even with wildly wrong IP addresses. The package don't like me either way (80029564), not that I need it as I already did this process weeks ago anyway on my own steam.
      Thanks for taking the time to test and report, even though you don't really need it.

    28. daflip
      07-22-2012
      06:40 PM
      28

      i can't wait for proper working tutorial on this....

    29. hellsing9
      07-22-2012
      06:50 PM
      29

      Frontpaged

    30. calo
      07-22-2012
      06:58 PM
      30

      Originally Posted by hellsing9 View Post
      Frontpaged
      off subject but ur sig is funny.

      4.11 NO CFW = Fake

      which would mean there is 4.11 cfw

    31. hellsing9
      07-22-2012
      07:01 PM
      31

      Originally Posted by calo View Post
      off subject but ur sig is funny.

      4.11 NO CFW = Fake

      which would mean there is 4.11 cfw
      It's a booby trap If someone clicks the sig that don't know will *learn* something about 4.11 CFW, no MAGIC 4.11 cfw for the moment. It's a list of fakes among other data to spot a faker.

    32. tul
      07-22-2012
      07:08 PM
      32

      prolly this is the error we are facing off!?
      [3] Make sure you got your metldr in ‘./data’ as ‘metldr’.

      where can we get this without linux?

    33. cory1492
      07-22-2012
      07:10 PM
      33

      OK, I had to repackage it a couple different ways but once I got it to install it worked great. The ps3 is a slim running 3.41 hermes cfw, when the app starts the PS3 black screened, I then ran the client after editing in my PS3's IP (edit: and copying a metldr extracted from my NOR dump over to the folder as instructed), compiled under cygwin using the supplied .sh script which is really just a gcc command (I added the ULL to those two vars to fix any problems that 'int is not a long' causes under windows) and got:

      Code:
      C:\cygwin\home\Cory\PS3test\dump_rootkey>dump_rootkey.exe
      [INFO] Connecting to '192.168.2.110'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2   0x00004C00013E0000
      [INFO] problem 0x00004C00013C0000
      [INFO] LS      0x00004C0001380000
      [INFO] shadow  0x0000300000028000
      [INFO] ID      0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000010
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] Interrupt status (2, application) = 0x0000000000000011
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] -> mailbox interrupt
      [INFO] Mailbox value = 1
      [INFO] -> Dumper loaded.
      [INFO] Transferring eid_root_key to buffer...finished.
      [INFO] Dumping eid_root_key...done.
      [INFO] SPU status = 0x00000081
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.
      [INFO] Press any key to exit...
      I reflashed from 4.11 dex back to hermes to test this easy way to get the RPC server going that doesn't involve installing asbestos and not only does the RPC server work a treat, I can also confirm this release dumped the same EID root key that I had obtained previously via a metldr dump.

      I'm a happy camper now, with a RPC server I can just run like an app. Sure beats going back to those old graf dongle payloads thanks naehrwert or marcan, whoever made that pkg!

      tul: follow the info deank posted to use multiman to take a dump of your console flash, and use one of the existing tools to extract the crypted metdlr - that is all you need to do to get metldr for this.

      btw, this is the fix for line 243:
      Code:
      	spu_slb_set_entry(&ctxt, priv2_addr, 0, 0x8000000018000000ULL, 0x0000800000001400ULL);
      it was missing ULL and many (well mostly just windows/32bit ones really) compilers will treat it as a 32bit value instead of a 64bit value when you forget that.

    34. tul
      07-22-2012
      08:06 PM
      34

      hi thnx for the reply, and i did already extracted metldr and puted it in data folder, still no luck in the process, it just show connecting 192.168..... ok and hangs in there.
      im using kmeaw and ubuntu in vmware, still dump win32app gave same result.

    35. veesowavy
      07-22-2012
      08:14 PM
      35

      a video would be much better for us noob

    36. jrtux
      07-22-2012
      08:54 PM
      36

      My little contribution...

      Using dump_rootkey on Ubuntu 12.04

      1- Extracting :
      sudo apt-get install p7zip
      p7zip -d dump_rootkey.7z

      2- Edit PS3HOST in main.cpp with the IP of your ps3 :
      cd dump_rootkey/
      gedit main.cpp
      edit :
      #define PS3HOST "169.254.0.2" <- your PS3 ip
      save

      3- Compile :
      sudo apt-get --reinstall install build-essential
      chmod +x build.sh
      sudo ./build.sh

      4- Extract the metldr from your flash dump and copy your metldr in 'data' dir as 'metldr' :
      (Get your flash dump with mmOs or memdump_0.01-FINAL and extract METLDR with CEX2DEX Application)

      5- Run :
      ./dump_rootkey

      enjoy

    37. TRoN_1
      07-22-2012
      08:56 PM
      37

      Hey, the Scene Status up on top finally changed....

    38. cory1492
      07-22-2012
      08:59 PM
      38

      tul: my guess is you are simply not able to see your PS3 from your PC. Check for routing issues or similar things like firewall blocking the app, it's not on the same port as FTP for example.

      I'm off, good luck anyone trying this... all I can really say is it's easy and it works to grab the key.

    39. KitsunePaws
      07-22-2012
      09:31 PM
      39

      To get this to compile is VS 2010 alter the header of main.cpp



      Code:
      #define _ERROR(...) printf("[ERROR] " __VA_ARGS__)
      #define _INFO(...) printf("[INFO] " __VA_ARGS__)
      #pragma comment(lib, "ws2_32.lib")
      I'm having connection issues though



      Watching the traffic in network monitor I can see that if the console is sitting at XMB and I start the app, there are two ARPs and then a UDP packet sent from my pc, no reply as expected.

      If I fire up the RPC and then start the app on the pc I see the two ARPs but never an outgoing UDP packet because the ARP comes back empty handed. I'm going to try another router, it seems that once the RPC is active I start to get IPv6 DHCP requests on the network (router does not support that)

      Update: Attempted with another router running open-wrt, same story.

    40. xtreme1
      07-22-2012
      09:33 PM
      40

      sorry to be the noob here, but how big of a deal is this? just glancing through the most recent posts it would seem that we are on the verge of making the complete breakthrough of cfw? am i wrong, still a ways to go? could someone clue me in?

    41. AsSiTcH
      07-22-2012
      09:48 PM
      41

      Originally Posted by xtreme1 View Post
      sorry to be the noob here, but how big of a deal is this? just glancing through the most recent posts it would seem that we are on the verge of making the complete breakthrough of cfw? am i wrong, still a ways to go? could someone clue me in?
      you are wrong

    42. zaphod
      07-22-2012
      10:55 PM
      42

      success in compiling with cygwin after fixing the source.. thnx cory1492 for your fix..

      but i only get this:
      INFO] Connecting to '192.168.1.104'...ok.

      i think it is an timing problem.. the dump_rootkey.exe opens a random UDP-Port (above 60000 i think) on the PC... but the PS3 is not able to connect back

      maybe my wlan is the problem or the acess-point..

      to tired now to watch ahead... maybe fixing tomorrow.. soooo close to it ;-)

    43. seanking
      07-22-2012
      11:39 PM
      43

      Can I extract metldr from 4.11 nor backup and use it in this app?

      Im using Downgraded PS3 and I have nor backup from FW4.11 is its metldr same as 3.55's metldr ?

      if not Please someone direct me to extract metldr from my 3.55 cfw

    44. ovhaum
      07-22-2012
      11:52 PM
      44

      Originally Posted by seanking View Post
      Can I extract metldr from 4.11 nor backup and use it in this app?

      Im using Downgraded PS3 and I have nor backup from FW4.11 is its metldr same as 3.55's metldr ?

      if not Please someone direct me to extract metldr from my 3.55 cfw
      From deank tutorial:
      Code:
      * Create a dump of your NOR/NAND (use multiMAN to create a .NORBIN/.NANDBIN file - USB connected as /dev_usb000 required)
              - To dump flash: mmOS->Select any file->Open in HEX viewer->[SELECT]->[START]->DUMP LV2(NO)->DUMP LV1(NO)->DUMP FLASH(YES)
          * Transfer to your PC and unpack it with norunpack.exe or cex2dex to a folder and grab "metldr" from the "asecure_loader" folder
          * Put "metldr" into the "metldrpwn" folder on your USB
      I used norunpack to extract metldr on cygwin
      norunpack.exe lot_of_numbers_FLASH-NOR-FW3.55.NORBIN metldr

    45. aldostools
      07-22-2012
      11:52 PM
      45

      Originally Posted by seanking View Post
      Can I extract metldr from 4.11 nor backup and use it in this app?

      Im using Downgraded PS3 and I have nor backup from FW4.11 is its metldr same as 3.55's metldr ?

      if not Please someone direct me to extract metldr from my 3.55 cfw
      To get the "metldr", just dump your flash with the latest build of multiMAN:
      mmOS->Select any file->Open in HEX viewer->[SELECT]->[START]->DUMP LV2(NO)->DUMP LV1(NO)->DUMP FLASH(YES)

      Transfer the dumped file of the NOR or NAND flash (copied to the USB) to your PC, and use norunpack.exe:
      norunpack.exe flash.BIN extract_folder

      In the extract_folder you will find the "metldr" (59KB) inside the folder "asecure_loader".

      An alternative method to extract "metldr" is using the CEX2DEX application by Gunner54.

      You first have to downgrate to 3.55 (DEX or CEX), to apply any flash patch using multiMAN.

    46. synce
      07-22-2012
      11:53 PM
      46

      No Linux, but you have to compile ****...

    47. seanking
      07-23-2012
      12:01 AM
      47

      Originally Posted by synce View Post
      No Linux, but you have to compile ****...

      I think "No Linux" referred to PS3 not PC

      It took me 10 minuets too run/setup/install Ubuntu on VMware and 5 minuets to compile, yet again cygwin or Microsoft Visual Studio is on windows if you have time to work with.
      ************* [ - Post Merged - ] *************
      Originally Posted by aldostools View Post
      To get the "metldr", just dump your flash with the latest build of multiMAN:
      mmOS->Select any file->Open in HEX viewer->[SELECT]->[START]->DUMP LV2(NO)->DUMP LV1(NO)->DUMP FLASH(YES)

      Transfer the dumped file of the NOR or NAND flash (copied to the USB) to your PC, and use norunpack.exe:
      norunpack.exe flash.BIN extract_folder

      In the extract_folder you will find the "metldr" (59KB) inside the folder "asecure_loader".

      An alternative method to extract "metldr" is using the CEX2DEX application by Gunner54.

      You first have to downgrate to 3.55 (DEX or CEX), to apply any flash patch using multiMAN.
      thanks for your complete answer

      Im already downgraded and was looking for way do get metldr in 3.55 with your post there is noting left unanswered

    48. xtreme1
      07-23-2012
      12:26 AM
      48

      Originally Posted by AsSiTcH View Post
      you are wrong
      any more of an explanation you can offer?

    49. seanking
      07-23-2012
      12:35 AM
      49

      I get error about free up flash memory at least 16 mg and put it in dev_usb try again my flash is empty just one pkg and the rest of ~14gig emptiness!!! any Ideas?

    50. lolilolz
      07-23-2012
      01:33 AM
      50

      hi guys,
      it is modified and compiled for windows using cygwin:
      http://www.ps3-infos.fr/forum/applic...ps3-t3267.html

      you need to provide the ip as parameter

    51. kokotas
      07-23-2012
      01:55 AM
      51

      thanks loliloz, here is a mirror for those lazy to register:
      http://disk.karelia.pro/fast/7WzfCmJ...r%20Attila.zip

    52. Tails
      07-23-2012
      02:31 AM
      52

      Hi, sorry for the n00b question before trying this program.... once i dump the root key, how can I change to DEX without linux? Thanks

    53. DEFAULTDNB
      07-23-2012
      02:53 AM
      53

      Cheers [MENTION=43448]kokotas[/MENTION]

    54. stussy1
      07-23-2012
      03:15 AM
      54

      Is this a full dex convert if so is my slim gonna be worth $2000
      How many units will be going on ebay lol

    55. Asure
      07-23-2012
      03:17 AM
      55

      Naerwehrt pointed out asbestos will ask your router for an IP by DHCP .. and listen on that IP. So you guys should check your router's DHCP client table or sniff the assignment with Wireshark to find out on which IP your PS3 is active.

      I'm at work right now so i can't confirm if it works, but it seems to me that is the reason the client never connects. I couldn't ping the IP i had assigned to the PS3 after running Asbestos, so it must have gotten a new one at that point

      If it works, someone kindly confirm Thanks!

    56. loike
      07-23-2012
      03:22 AM
      56

      Originally Posted by kokotas View Post
      thanks loliloz, here is a mirror for those lazy to register:
      http://disk.karelia.pro/fast/7WzfCmJ...r%20Attila.zip
      Thanks for the upload.

    57. sanek44
      07-23-2012
      03:33 AM
      57

      not working((

    58. bleh
      07-23-2012
      03:35 AM
      58

      Originally Posted by sanek44 View Post
      not working((
      dump_rootkey YourPS3IpAddress

    59. loike
      07-23-2012
      03:36 AM
      59

      Originally Posted by sanek44 View Post
      not working((
      You have to fill in the ip address after dump_rootkey. Like this:

      dump_rootkey.exe 192.168.0.1

    60. sanek44
      07-23-2012
      03:37 AM
      60

      Ок thanks)))

    61. tul
      07-23-2012
      03:52 AM
      61

      Originally Posted by seanking View Post
      I get error about free up flash memory at least 16 mg and put it in dev_usb try again my flash is empty just one pkg and the rest of ~14gig emptiness!!! any Ideas?
      make sure you use the rightest usb port, next to the power button, and after the dump with multiman you have to search for hidden files, i was getting blank dump also, but only then i search for hidden files, as i was able to see them with mmCm.
      ************* [ - Post Merged - ] *************
      Originally Posted by Asure View Post
      Naerwehrt pointed out asbestos will ask your router for an IP by DHCP .. and listen on that IP. So you guys should check your router's DHCP client table or sniff the assignment with Wireshark to find out on which IP your PS3 is active.

      I'm at work right now so i can't confirm if it works, but it seems to me that is the reason the client never connects. I couldn't ping the IP i had assigned to the PS3 after running Asbestos, so it must have gotten a new one at that point

      If it works, someone kindly confirm Thanks!
      can some1 confirm this?, if that the case i would be pissed,lolz, i set for the first time a manual ip at the ps3 to use this.

      well i can confirm thats not the case, i checked my router dhcp and no new dhcp ip was found, also check straight connection wiht only a simple switch, and even also by wlan address, none of them works :S
      to be covering all possibilitys, i have tried with ubuntu compilation and with windows compilations, none of them :S

    62. nuzz
      07-23-2012
      05:13 AM
      62

      Asbestos doesn't seem to run on rebug, it goes black screen, no ip is requested, have to do a hard reset too.

    63. Asure
      07-23-2012
      05:15 AM
      63

      Reading this, i believe we need to set up addition dhcp/tftp server with rootfs + kernel.

      Naerwehrt didn't say this would work off-the-bat as-is. I guess we'll need to boot from a nfs share to get a minimal linux running. Also at this point i'm not sure if we can use netrpc as soon as the kernel is booted, or even if no kernel is booted

      See http://marcansoft.com/blog/2010/10/a...nux-as-gameos/

      And some people wrote a semi-coherent step-by-step guide to boot: http://mrgatz85.blogspot.nl/2010/10/...os-hybrid.html

      We should really be seeing some dhcp-related chatter from the ethernet port after running the asbestos pkg.. nobody has a sniffer handy to confirm? (still at work here..)

    64. uvekilledkenny
      07-23-2012
      06:17 AM
      64

      I found something which is odd I think, Whatever IP I write, it'll say :

      [INFO] Connecting to 'X' ...ok.
      Screenshot: http://puu.sh/KYct

      PS : I used the modified exe by Atilla ( you'll see in the Screenshot )

    65. DEFAULTDNB
      07-23-2012
      06:24 AM
      65

      Wasn't asbestOS for 3.41? could that be why it fails?

      EDIT: tried accessing PS3devwiki, but cant, to confirm it..

    66. tul
      07-23-2012
      06:31 AM
      66

      Originally Posted by DEFAULTDNB View Post
      Wasn't asbestOS for 3.41? could that be why it fails?

      EDIT: tried accessing PS3devwiki, but cant, to confirm it..
      i really think its a issue with the current firmware we are running, if anyone with kmeaw got Unicorns pls drop your success quote.

    67. iT0ny
      07-23-2012
      06:51 AM
      67

      Originally Posted by tul View Post
      i really think its a issue with the current firmware we are running, if anyone with kmeaw got Unicorns pls drop your success quote.
      tried on kmeaw/rogero3.4...not working(

    68. DEFAULTDNB
      07-23-2012
      06:54 AM
      68

      someone try on 3.41? cant hurt can it?

    69. Asure
      07-23-2012
      06:55 AM
      69

      I don't want to quote myself, but if people read my two lasts posts in this topic, you still use linux, so the topic title is wrong, and this won't work as-is. Some more steps are needed.

      Asbestos ldr kills gameos and loads a kernel by tftp from a server you provided it with by dhcp. The whole procedure should go a little like this:

      1. Install PKG
      2. Setup PC with linux (virtual machine) which runs NFS export with your linux filesystem.
      3. Setup TFTP server, to server kernel to the PS3
      4. Setup DHCP server, to assign IP to the PS3, and provide tftp server address (from #3)
      5. Patch linux kernel to use NFS as root filesystem (from #2)

      - Run the installed asbestos app.
      - The ps3 will 'warm boot' and get rid of gameOS
      - It will get an IP and the tftp server adress by DHCP
      - It will load the kernel from the TFTP server & boot it.
      - The kernel will boot, and try to mount the rootfs from NFS
      - Linux is now ready to be used
      - Run exploit

      So technically, there is no 'linux installed' on the ps3, but your still booting it up. By network.

    70. kokotas
      07-23-2012
      06:57 AM
      70

      This is a wild guess, since I have no knowledge on ps3 stuff. I took a look on build_dumper.bat and changed the self-fw-version from 0003004100000000 to 0003005500000000, and run the dumper again using scetool. This is the file it produced:

      http://disk.karelia.pro/fast/6YARoen/dumper

      Can't hurt to give it a shot now, can it?

    71. DEFAULTDNB
      07-23-2012
      07:04 AM
      71

      Originally Posted by kokotas View Post
      I took a look on build_dumper.bat and changed the self-fw-version from 0003004100000000 to 0003005500000000
      Nice one [MENTION=43448]kokotas[/MENTION]

    72. Asure
      07-23-2012
      07:30 AM
      72

      The original files are confirmed as working on 3.41 'hermes' on another ps3 news site. You don't need to have nfs/tftp setup it seems, so my assumption seems to be wrong. Guess all it needs is a proper dhcp.

      Unconfirmed on 3.55 (rebug/kmeaw etc.) still.

    73. DEFAULTDNB
      07-23-2012
      07:31 AM
      73

      Originally Posted by Asure View Post
      The original files are confirmed as working on 3.41
      I thought as much

    74. klaxnek
      07-23-2012
      07:43 AM
      74

      naehrwert has confirmed that asbestos pkg only works in 3.41
      He has posted the source of asbestos to change the offset for people to adapt it to other firmware versions: http://t.co/61ApHQni

    75. cookie42
      07-23-2012
      07:44 AM
      75

      Check naehrwert's latest tweets. Looks like it was compiled for 3.41. He provided the source, so if you change lv2 offsets, etc, it should work for 3.55.

    76. haz367
      07-23-2012
      07:44 AM
      76

      lol..don't get me wrong but by the time we have it up&running u have it dumped via linux..used the redribbon way..this simply aint working on 355

      tryed everyting in the topic, cygwin/wubi-linux..all the same..thx fo sharing...

    77. DEFAULTDNB
      07-23-2012
      07:47 AM
      77

      Looking forward to an updated one complied, once this is incorporated into [MENTION=114607]deank[/MENTION]'s cexdex tutorial this is going to be uber simple :D

    78. cookie42
      07-23-2012
      07:54 AM
      78

      According to this page, I think this should be the right changes. http://www.ps3devwiki.com/wiki/LV2_F...s_and_Syscalls


      #define LV2_SYSCALL_TABLE 0x8000000000346570ULL
      #define LV2_MEMCPY 0x800000000007C3A4ULL

      Edit: You may also have to change the syscall to match your mfw. They're also listed on that page.

    79. tul
      07-23-2012
      07:54 AM
      79

      Originally Posted by haz367 View Post
      lol..don't get me wrong but by the time we have it up&running u have it dumped via linux..used the redribbon way..this simply aint working on 355

      tryed everyting in the topic, cygwin/wubi-linux..all the same..thx fo sharing...
      yeh, you are prolly right, but when the times comes, i dont need to wipe my entire disk, that is my only goal.

    80. haz367
      07-23-2012
      08:12 AM
      80

      sure..if it worked out of the can small fix afteral for 355 if re-compiled?

      edited the dumper.bat to 355 and with scetool build another one, unself'd with scetool and repacked it but the eboot.bin is way to small..the repack noob we noobs have to wait a litlle or get of our lazy ass...

      great share nontheless!!

    81. DEFAULTDNB
      07-23-2012
      08:40 AM
      81

      http://www.sendspace.com/file/54r98m

      Precompiled asbestos_ldr for 3.41 retail and 3.55 retail lv2 kernels with peek/poke.
      contains

      asbestos_ldr_retail_355.elf and
      asbestos_ldr_retail_341.elf

    82. tweetymr
      07-23-2012
      08:46 AM
      82

      Originally Posted by DEFAULTDNB View Post
      http://www.sendspace.com/file/54r98m



      contains

      asbestos_ldr_retail_355.elf and
      asbestos_ldr_retail_341.elf

      But how to run elf-Files? :/
      Can somebody compile it to an pkg File? Would be way better to manage I think.

    83. tul
      07-23-2012
      08:48 AM
      83

      Originally Posted by tweetymr View Post
      But how to run elf-Files? :/
      Can somebody compile it to an pkg File? Would be way better to manage I think.
      i think you can run it with multiman, not sure tho, not at home to check atm.

    84. sanek44
      07-23-2012
      08:59 AM
      84

      multiman not run elf((

    85. Asure
      07-23-2012
      09:16 AM
      85

      Video tut for elf -> eboot here:

      PS3 3.55-geohot EBOOT patching and packaging TUTORIAL - YouTube

      Or use any of the public tools/gui stuff for it

    86. DEFAULTDNB
      07-23-2012
      09:16 AM
      86

      http://www.ps3hax.net/2012/07/make-p...bzero-dezigns/ could this be used to make pkg and launch it on kmeaw/rebug 3.55?

    87. Asure
      07-23-2012
      09:27 AM
      87

      If you create an EBOOT from the elf first, yes.

      make_self_npdrm EBOOT.ELF EBOOT.BIN <GAME/PATCHID>

    88. DEFAULTDNB
      07-23-2012
      10:10 AM
      88

      [MENTION=7808]Asure[/MENTION] did you manage to get 3.55 version working?

    89. deank
      07-23-2012
      10:12 AM
      89

      It is not working on kmeaw 3.55 and I guess naehrwert knows that the stage2 is different for 3.55 (the elfs he provided differ only with the memcpy/syscall11 offsets). Kudos to Hermes/ArielX/marcan for creating the loader almost 2 years ago.

    90. tul
      07-23-2012
      10:19 AM
      90

      i compiled the elf to pkg file, not at home, will test it as soon as i arrive, meanwhile of some1 wnat to give a shot.

    91. DEFAULTDNB
      07-23-2012
      10:21 AM
      91

      Originally Posted by tul View Post
      i compiled the elf to pkg file, not at home, will test it as soon as i arrive, meanwhile of some1 wnat to give a shot.
      Nice one [MENTION=116418]tul[/MENTION], I'm not at home either.. any idea how can we get this working for KMEAW too?

    92. JayDee78
      07-23-2012
      10:27 AM
      92

      Originally Posted by tul View Post
      i compiled the elf to pkg file, not at home, will test it as soon as i arrive, meanwhile of some1 wnat to give a shot.
      Not working. It just goes to black screen, some hdd activity indicated by the yellow led, and then the ps3 restarts...

    93. iT0ny
      07-23-2012
      10:27 AM
      93

      Originally Posted by tul View Post
      i compiled the elf to pkg file, not at home, will test it as soon as i arrive, meanwhile of some1 wnat to give a shot.
      crashes to XMB w/o any error message btw i tried the .elf itself via ps3load,also crashes

    94. DEFAULTDNB
      07-23-2012
      10:31 AM
      94

      Originally Posted by iT0ny View Post
      crashes to XMB w/o any error message btw i tried the .elf itself via ps3load,also crashes
      [MENTION=196406]iT0ny[/MENTION] [MENTION=235814]JayDee78[/MENTION] are you using kmeaw? or what cfw?

    95. seanking
      07-23-2012
      10:34 AM
      95

      Originally Posted by tul View Post
      i compiled the elf to pkg file, not at home, will test it as soon as i arrive, meanwhile of some1 wnat to give a shot.
      http://t.co/41wOlquT

      can you make sence out of this one 9 minuets ago provided by naehrwert instead on elf file!!!

    96. DEFAULTDNB
      07-23-2012
      10:40 AM
      96

      Originally Posted by seanking View Post
      http://t.co/41wOlquT

      can you make sence out of this one 9 minuets ago provided by naehrwert instead on elf file!!!
      Looks like he is watching this thread(?), he seems to have included stage 2 files that [MENTION=114607]deank[/MENTION] mentioned earlier.

    97. JayDee78
      07-23-2012
      10:42 AM
      97

      Originally Posted by DEFAULTDNB View Post
      [MENTION=196406]iT0ny[/MENTION] [MENTION=235814]JayDee78[/MENTION] are you using kmeaw? or what cfw?
      Kmeaw with oos patches

    98. DEFAULTDNB
      07-23-2012
      10:43 AM
      98

      Originally Posted by JayDee78 View Post
      Kmeaw with oos patches
      Deank did mention it would not work for kmeaw.

    99. iT0ny
      07-23-2012
      10:44 AM
      99

      Originally Posted by DEFAULTDNB View Post
      [MENTION=196406]iT0ny[/MENTION] [MENTION=235814]JayDee78[/MENTION] are you using kmeaw? or what cfw?
      i'm using kmeaw, i think there's smth wrong with source code

    100. DEFAULTDNB
      07-23-2012
      10:48 AM
      100

      Originally Posted by iT0ny View Post
      i'm using kmeaw, i think there's smth wrong with source code
      http://www.ps3hax.net/showpost.php?p...4&postcount=90

      It is not working on kmeaw 3.55 and I guess naehrwert knows that the stage2 is different for 3.55 (the elfs he provided differ only with the memcpy/syscall11 offsets)
      Naehrwert has since released the source code, see http://www.sendspace.com/file/2064nl

    101. shames
      07-23-2012
      10:54 AM
      101

      Well, Naehrwert is gonna teach us all a little bit in "do the s*** by yourself".

      He has thrown out an .pup where he knew it´s only working in 3.41... the scene figured that out.
      He has provided an .ELF which needed to get a .pup... the scene figured out... but, noone knew (understood) what´s inside the .ELF.
      I think the next step will be: de-compile the .ELF, change the base2, re-compile and doing a .pup again.

      I wonder if that will be the final move....

      Btw.: I like the way he´s doing that.

    102. seanking
      07-23-2012
      10:57 AM
      102

      Im using downgraded PS3 and its flash is kind of messed up enough last tutorial includes whiping hard installing linux and other stuff is there any hope that this one make clean convert without bricking my PS3?

      another question is it even possible that any of these methods work on Downgraded PS3(ROGERO cfw 3.55)?

    103. iT0ny
      07-23-2012
      10:59 AM
      103

      Originally Posted by DEFAULTDNB View Post
      http://www.ps3hax.net/showpost.php?p...4&postcount=90



      Naehrwert has since released the source code, see http://www.sendspace.com/file/2064nl
      so.it's not working only on kmeaw 3.55? what about other cfws? *i'll check it on other 3.55 cfws anyway*

    104. Dudshl
      07-23-2012
      10:59 AM
      104

      Originally Posted by shames View Post
      Well, Naehrwert is gonna teach us all a little bit in "do the s*** by yourself".

      He has thrown out an .pup where he knew it´s only working in 3.41... the scene figured that out.
      He has provided an .ELF which needed to get a .pup... the scene figured out... but, noone knew (understood) what´s inside the .ELF.
      I think the next step will be: de-compile the .ELF, change the base2, re-compile and doing a .pup again.

      I wonder if that will be the final move....

      Btw.: I like the way he´s doing that.
      I think so too
      ************* [ - Post Merged - ] *************
      Originally Posted by iT0ny View Post
      so.it's not working only on kmeaw 3.55? what about other cfws? *i'll check on other 3.55 cfws anyway*
      It works only on 3.41 and does not work on any 3.55

    105. iT0ny
      07-23-2012
      11:09 AM
      105

      Originally Posted by Dudshl View Post
      I think so too
      ************* [ - Post Merged - ] *************


      It works only on 3.41 and does not work on any 3.55
      thanks, one more question)what will happen if i downgrade my ps3 to 3.41 (my min version is 3.50)?

    106. gsgm
      07-23-2012
      11:10 AM
      106

      Ok, I spoke with Naehr on IRC and he has this to say:

      Asbestos and asbestos_ldr need to be modified to work on 3.55. First you got to find a good base address for asbestos stage2 and then change the base and offsets in asbestos_ldr for 3.55.

      I got no 3.55 to test it, so someone else needs to port it.

    107. GregoryRasputin
      07-23-2012
      11:14 AM
      107

      Hо мы пpойдем с тобою пyть чеpез тyман!
      Hо мы пpойдем с тобою пyть чеpез тyман!
      Hо мы пpойдем опасный пyть чеpез тyман!

    108. gsgm
      07-23-2012
      11:17 AM
      108

      Originally Posted by GregoryRasputin View Post
      Hо мы пpойдем с тобою пyть чеpез тyман!
      Hо мы пpойдем с тобою пyть чеpез тyман!
      Hо мы пpойдем опасный пyть чеpез тyман!
      Professor Farnsworth: Eh wha? - YouTube

    109. Dudshl
      07-23-2012
      11:17 AM
      109

      Originally Posted by iT0ny View Post
      thanks, one more question)what will happen if i downgrade my ps3 to 3.41 (my min version is 3.50)?
      If You have flasher - You can try use this E3` manual:
      http://e3-tech.net/download/E3%20CFW...W%20manual.rar

    110. alienkid
      07-23-2012
      11:20 AM
      110

      Originally Posted by iT0ny View Post
      thanks, one more question)what will happen if i downgrade my ps3 to 3.41 (my min version is 3.50)?
      You can't downgrade past your PS3s stock FW. I'm sure you'll risk a brick.

    111. iT0ny
      07-23-2012
      11:26 AM
      111

      Originally Posted by alienkid View Post
      You can't downgrade past your PS3s stock FW. I'm sure you'll risk a brick.
      only a brick?nice,i hope i'll be able to unbrick my ps3

    112. Dudshl
      07-23-2012
      11:26 AM
      112

      Originally Posted by alienkid View Post
      You can't downgrade past your PS3s stock FW. I'm sure you'll risk a brick.
      I think QA-flagged console with Enabled "DEBUG UPDATE" may be downgraded to version lower that MinVerCheck.PUP shown.

    113. iT0ny
      07-23-2012
      11:28 AM
      113

      Originally Posted by Dudshl View Post
      I think QA-flagged console with Enabled "DEBUG UPDATE" may be downgraded to version lower that MinVerCheck.PUP shown.
      thx guys!)

    114. alienkid
      07-23-2012
      11:29 AM
      114

      I didn't know a QA Flagged PS3 could do that. I'll have to look into that. That the 1st I've heard of such.

    115. haz367
      07-23-2012
      11:30 AM
      115

      he must have a binnepretje seeing this topic..funny guys.. haha no problem, i have tryed to repack it errors out with 80029533 and in the meantime dumped 2 rootkeys, let's sit this one out...

    116. zaphod
      07-23-2012
      11:33 AM
      116

      Originally Posted by gsgm View Post
      Ok, I spoke with Naehr on IRC and he has this to say:
      [MENTION=176872]gsgm[/MENTION]

      thnx for making this clear.. so thats the point i cant follow any more
      have compiled the client, portet the 3.55-elf to a EBOOT.BIN and packed it up to a pkg file..

      this file installed but the PS3 falls back to XMB without any error...

      so i know i have to wait since one of the programmers which have no problem in fixing asbestos+loader for 3.55 will give us the ready-2-go pkg for 3.55

      btw... learned so much in this process :-)
      thnx for that at all devs here...

    117. Asure
      07-23-2012
      11:35 AM
      117

      Right, that's it, i'm QA flagging & back to 3.41.

    118. tul
      07-23-2012
      11:39 AM
      118

      damm, so i guess i have no chance besides wiping the entire disk :S

    119. seanking
      07-23-2012
      11:43 AM
      119

      Originally Posted by Asure View Post
      Right, that's it, i'm QA flagging & back to 3.41.
      Point was to make it easy by removing need to install Linux on PS3 guess is now is the time to wait for someone make absentos3.55.pkg...

    120. a$h x
      07-23-2012
      11:57 AM
      120

      Originally Posted by seanking View Post
      now is the time to wait for someone make absentos3.55.pkg...
      If it's absentos they might forget...

    121. DEFAULTDNB
      07-23-2012
      12:09 PM
      121

      Originally Posted by Dudshl View Post
      I think QA-flagged console with Enabled "DEBUG UPDATE" may be downgraded to version lower that MinVerCheck.PUP shown.
      I severely doubt that.

    122. JonahUK
      07-23-2012
      12:52 PM
      122

      Can you not use kmeaw's BootOS and LV2 Patcher to do the same thing? IIRC, that supports 3.55

    123. DEFAULTDNB
      07-23-2012
      01:14 PM
      123

      Originally Posted by JonahUK View Post
      Can you not use kmeaw's BootOS and LV2 Patcher to do the same thing? IIRC, that supports 3.55
      Good thinking Batman!

      kmeaw and Kha0s' BootOS (formally AsbestOS Installer) lets you boot a Linux kernel using LV2 Patcher v9.

      Click here for more info.

      AsbestOS Installer v1.2

      An ethernet cable is no longer needed (the option is still there though)

      AsbestOS Installer v1.3

      Now auto-detects PS3 model. There is no need for two (fat and slim) pkgs.
      Fixes a problem with incorrectly partitioned USB drives.

      AsbestOS Installer v1.4

      Improved stability
      Faster LV1 scanning

      AsbestOS Installer v1.5

      You can now boot from network, HDD, or USB

      AsbestOS Installer v2.0

      Easier to use and easier to install Debian GNU/Linux

      BootOS v2.01

      Now works on non-Slim (Fat) PS3 consoles
      DOWNLOAD 2.01 PKG HERE

    124. zaphod
      07-23-2012
      01:22 PM
      124

      got the same idea.. have bootos 2.01 and lv2-v9 installed..

      but know? i can install debian or any other linux distro... thats the beginning...

      what is to do do get the rpc-server running with this 2 progs??


      /edit
      ok 1 step closer.. so i can install Red Ribbon with the livecd-version and dont have to format my internal hdd cause installing
      on USB-Stick...

      But... completely without this step is the final we all want :-)
      /edit off

    125. Asure
      07-23-2012
      02:26 PM
      125

      Got my rootkey. Now looking at the other pasties (apr 29th?) that popped up recently.

    126. bladerunner6
      07-23-2012
      02:39 PM
      126

      does this work with 256nand phat on 3.55 ?

    127. DEFAULTDNB
      07-23-2012
      02:43 PM
      127

      Originally Posted by Asure View Post
      Got my rootkey. Now looking at the other pasties (apr 29th?) that popped up recently.
      [MENTION=7808]Asure[/MENTION] if you compiled it for kmeaw: can you share your methods? or did you go back to 3.41?

    128. Asure
      07-23-2012
      02:49 PM
      128

      Originally Posted by DEFAULTDNB View Post
      [MENTION=7808]Asure[/MENTION] if you compiled it for kmeaw: can you share your methods? or did you go back to 3.41?
      Sorry mate, i went back to 3.41 as that took less time than:

      - Install all the stuff required for psl1ght (took ages to compile..)
      - Install psl1ght itself
      - Patch the asbestos loader & kernel
      - Figure out the second stage stuff so it boots on 3.55 (needs a skilled dev, i'm just a linux guy..)

    129. DEFAULTDNB
      07-23-2012
      02:52 PM
      129

      Originally Posted by Asure View Post
      Sorry mate, i went back to 3.41 as that took less time than:

      - Install all the stuff required for psl1ght (took ages to compile..)
      - Install psl1ght itself
      - Patch the asbestos loader & kernel
      - Figure out the second stage stuff so it boots on 3.55 (needs a skilled dev, i'm just a linux guy..)
      Fair play mate

      Hopefully someone will make a KMEAW version one day soon.

    130. klaxnek
      07-23-2012
      02:56 PM
      130

      Oh man. I downgraded from 3.55KMEAW to 3.41Hermes and now I cannot install arbestos_ldr.g.pkg.... It throws an error. I think you have to install it in 3.55 before downgrading... Now I'll upgrade to 3.55 again, install, and downgrade to 3.41

    131. DEFAULTDNB
      07-23-2012
      02:58 PM
      131

      Originally Posted by klaxnek View Post
      Oh man. I downgraded from 3.55KMEAW to 3.41Hermes and now I cannot install arbestos_ldr.g.pkg.... It throws an error. I think you have to install it in 3.55 before downgrading... Now I'll upgrade to 3.55 again, install, and downgrade to 3.41
      No that's not correct. You install it on 3.41 not on 3.55 (then downgrade to 3.41) that makes no sense.

    132. klaxnek
      07-23-2012
      03:00 PM
      132

      I can install other pkgs in 3.41CFW from the Install Package menu but installing the arbestos pkg thows an error 80029564...

    133. uvekilledkenny
      07-23-2012
      03:17 PM
      133

      I've got the same problem as you klaxnex, what we need to do in order to install this package ?

    134. klaxnek
      07-23-2012
      03:19 PM
      134

      I'm now in 3.55 and I installed asbestos pkg perfectly!!! This is weird hehe
      Now QA and downgrade again to 3.41....

    135. cory1492
      07-23-2012
      03:23 PM
      135

      All I had to do was extract the package and rebuild it, I think the .g. mean geohot type package or something, and hermes' firmware does not care for those at all. My guess is naehrwert is using some slick mfw 3.41 or oos++ 3.41.

    136. haz367
      07-23-2012
      03:24 PM
      136

      hehe..same error here
      Qaflag console
      OtherOS special pup
      back to 3.41
      rammed the hermes payload on the good old x3maxie
      bam..error..we must be doing something wrong
      atm.grabbing Hermes PS3 Custom Firmware 3.41 with Payload 4

      can someone refresh my mind..one install OFW341 and using a donlge with hermes payload to JB right? it's the same as installing the above firmware?

      atm..it isn't faster....miepmiepzoef..

      thx for the awsome share though

      edit: ok..repacking it..thx!

    137. voldemar_u2
      07-23-2012
      03:28 PM
      137

      Here is a command line version of dump_rootkey utility. Just type dump_rootkey your_ps3_ip_address to connect.
      Added: repacked .pkg for 3.41
      PS: Uploaded to http://www.sendspace.com/file/zbh5pn http://www.sendspace.com/file/58spws

    138. DEFAULTDNB
      07-23-2012
      03:33 PM
      138

      Originally Posted by voldemar_u2 View Post
      Here is a command line version of dump_rootkey utility. Just type dump_rootkey your_ps3_ip_address to connect.
      Added: repacked .pkg for 3.41
      Nice one cheers.

    139. Asure
      07-23-2012
      03:36 PM
      139

      Originally Posted by haz367 View Post
      hehe..same error here
      Qaflag console
      OtherOS special pup
      back to 3.41
      rammed the hermes payload on the good old x3maxie
      bam..error..we must be doing something wrong
      atm.grabbing Hermes PS3 Custom Firmware 3.41 with Payload 4

      can someone refresh my mind..one install OFW341 and using a donlge with hermes payload to JB right? it's the same as installing the above firmware?

      atm..it isn't faster....miepmiepzoef..

      thx for the awsome share though

      edit: ok..repacking it..thx!
      Interesting, i did install it on 3.55 and it survived the downgrade and ran with no problems. Must be the pkg that's signed with some odd key?

      Oh and i didn't grab hermes 3.41, just rolled my own with MFW builder. I did flash 3.41 ofw first, but probably could have gone directly to 3.41+peekpoke, that's all that was needed.

      When i was back on 3.41 ofw i thought 'crap, no more htc desire with hacked bootmenu+jailbreak on it..' hehehe.

    140. MakinaCore
      07-23-2012
      03:39 PM
      140

      To get the "metldr", just dump your flash with the latest build of multiMAN:
      mmOS->Select any file->Open in HEX viewer->[SELECT]->[START]->DUMP LV2(NO)->DUMP LV1(NO)->DUMP FLASH(YES)



      i dont even get dump lv2 dump lv1 dump flash ? lol on the latest version of multiman ???

    141. a$h x
      07-23-2012
      03:48 PM
      141

      Originally Posted by voldemar_u2 View Post
      Here is a command line version of dump_rootkey utility. Just type dump_rootkey your_ps3_ip_address to connect.
      Added: repacked .pkg for 3.41
      PS: Uploaded to http://www.sendspace.com/filegroup/i...jjMcfv%2BdkHYQ
      Windows executable doesn't work bro:

    142. DEFAULTDNB
      07-23-2012
      03:50 PM
      142

      Originally Posted by MakinaCore View Post
      To get the "metldr", just dump your flash with the latest build of multiMAN:
      mmOS->Select any file->Open in HEX viewer->[SELECT]->[START]->DUMP LV2(NO)->DUMP LV1(NO)->DUMP FLASH(YES)



      i dont even get dump lv2 dump lv1 dump flash ? lol on the latest version of multiman ???
      Hold L2 and R2 at start up of multiman and update through debug. (it will say version 04.04.DD)

    143. voldemar_u2
      07-23-2012
      03:52 PM
      143
    144. MakinaCore
      07-23-2012
      03:56 PM
      144

      cheers :D b-) (( ---DEFAULTDNB ---))

    145. haz367
      07-23-2012
      03:57 PM
      145

      Originally Posted by Asure View Post
      Interesting, i did install it on 3.55 and it survived the downgrade and ran with no problems. Must be the pkg that's signed with some odd key?


      Oh and i didn't grab hermes 3.41, just rolled my own with MFW builder


      I did flash 3.41 ofw first, but probably could have gone directly to 3.41+peekpoke, that's all that was needed.

      When i was back on 3.41 ofw i thought 'crap, no more htc desire with hacked bootmenu+jailbreak on it..' hehehe.
      hehe..at rolling one..didn't think of it..to much tools..need to re-order the toolbox and last CEX-355 pup made with euss MFW build keeps failing on showing the APP/PS3_GAME/Install packages, need to check that again cuse it looks like the tlc' are for DEX anyway cuse rolling a dex up and all working great on 3.55..MFW rant off...

      HTC desire...blackberry FTW j/k

      anyway...after repacking it installed fine(PKG Toolkit GUI) thx for tip cory1492

      http://dl.dropbox.com/u/19078406/UP0...1122223333.pkg
      ok..let's roll another one and move on, let's see if its working

    146. klaxnek
      07-23-2012
      04:09 PM
      146

      I cannot dump flash with Multiman 04.04.03.
      I've tried in normal and debug mode (L2+R2).

      I'm in CFW3.41.

      1. I have USB pendrive in the right usb connection (dev_usb0)
      2. I open a file in HEX Viewer
      3. I press SELECT (LV2 View)
      4. I press START.
      5. It exports GameOS (DATE-HOUR-LV2-FW3.41.BIN) and it asks me to export HV LV1 (I say no). The file (LV2) is exported in /dev_hdd0 ????

      I don't know what I'm doing wrong...

    147. AsSiTcH
      07-23-2012
      04:35 PM
      147

      Originally Posted by klaxnek View Post
      I cannot dump flash with Multiman 04.04.03.
      I've tried in normal and debug mode (L2+R2).

      I'm in CFW3.41.

      1. I have USB pendrive in the right usb connection (dev_usb0)
      2. I open a file in HEX Viewer
      3. I press SELECT (LV2 View)
      4. I press START.
      5. It exports GameOS (DATE-HOUR-LV2-FW3.41.BIN) and it asks me to export HV LV1 (I say no). The file (LV2) is exported in /dev_hdd0 ????

      I don't know what I'm doing wrong...

      I'm having the same problem as you. I dont see an option to dump flash.

    148. haz367
      07-23-2012
      04:38 PM
      148

      Thanks to naehrwert

      eid_rootkey dumped on 3.41/hermes-psgroove payload with "repacked" PKG

      repacked cuse the original won't install atleast on my setup..connected PS3>PC via router..no special settings..dumped it right away using the original package with edited "main.cpp(use notepad++ or someting) and the correction made/posted by [MENTION=11165]cory1492[/MENTION] =

      Code:
      line 243
      
      spu_slb_set_entry(&ctxt, priv2_addr, 0, 0x8000000018000000ULL, 0x0000800000001400ULL);
      drop dumper&metldr in "data" folder
      run Cygwin.bat
      cd dump_rootkey
      ./build.sh

      unicorns

    149. jrtux
      07-23-2012
      04:40 PM
      149

      Originally Posted by klaxnek View Post
      I cannot dump flash with Multiman 04.04.03.
      I've tried in normal and debug mode (L2+R2).

      I'm in CFW3.41.

      1. I have USB pendrive in the right usb connection (dev_usb0)
      2. I open a file in HEX Viewer
      3. I press SELECT (LV2 View)
      4. I press START.
      5. It exports GameOS (DATE-HOUR-LV2-FW3.41.BIN) and it asks me to export HV LV1 (I say no). The file (LV2) is exported in /dev_hdd0 ????

      I don't know what I'm doing wrong...

      Use MemDump from ps3devwiki, is easier ...
      -Usage:
      Place the necessary pkg file in the root of an empty USB flash dongle, and install like any
      other pkg.

      1. Place pkg on USB flash dongle.
      2. Select “memdump” icon.
      3. Select type of dump to perform once loaded :

      ✕ Dump FLASH storage



      Download

    150. klaxnek
      07-23-2012
      05:01 PM
      150

      Thanks jrtux. It worked!!
      Dumped flash storage with the tool you said and later I extracted metldr with CEX-DEX-Gunner54 tool.

      I've placed metldr in /data directory in dump_rootkey directory.

      1. Execute asbestos_ldr in PS3. Black screen
      2. Execute in a cmd (windows): dump_rootkey.exe 192.168.2.104

      And it only says:
      [INFO] Connecting to '192.168.2.104'...OK

      I have the PS3 connected by wifi and the PS3 IP is in DMZ router...

      Remember I'm in 3.41CFW. Can anyone help me?
      Thanks in advance

    151. uvekilledkenny
      07-23-2012
      05:04 PM
      151

      Originally Posted by klaxnek View Post
      Thanks jrtux. It worked!!
      Dumped flash storage with the tool you said and later I extracted metldr with CEX-DEX-Gunner54 tool.

      I've placed metldr in /data directory in dump_rootkey directory.

      1. Execute asbestos_ldr in PS3. Black screen
      2. Execute in a cmd (windows): dump_rootkey.exe 192.168.2.104

      And it only says:
      [INFO] Connecting to '192.168.2.104'...OK

      I have the PS3 connected by wifi and the PS3 IP is in DMZ router...

      Remember I'm in 3.41CFW. Can anyone help me?
      Thanks in advance
      I'm exactly like you, PS3 is connected by Wifi and it says only " Connecting to X ... Ok"

    152. klaxnek
      07-23-2012
      05:06 PM
      152

      I promise you all I'm not that nerd, but I don't know why I have problems in every step...

      Hehe uvekilledkenny. Maybe one day we'll see unicorns too

    153. Asure
      07-23-2012
      05:10 PM
      153

      Originally Posted by uvekilledkenny View Post
      I'm exactly like you, PS3 is connected by Wifi and it says only " Connecting to X ... Ok"
      It doesn't work by wifi. Break out the cat5 cable.
      It also doesn't work on 3.55 at this point.

      Maybe the news post could be edited to reflect this.

      Only 3.41+peek/poke works for this atm.

    154. klaxnek
      07-23-2012
      05:21 PM
      154

      Thanks Asure. Connected wired ps3 and pc to router and it dumped eid_root_key.bin!!!

    155. AsSiTcH
      07-23-2012
      05:24 PM
      155

      Originally Posted by jrtux View Post
      Use MemDump from ps3devwiki, is easier ...
      -Usage:
      Place the necessary pkg file in the root of an empty USB flash dongle, and install like any
      other pkg.

      1. Place pkg on USB flash dongle.
      2. Select “memdump” icon.
      3. Select type of dump to perform once loaded :

      ✕ Dump FLASH storage



      Download

      memdump.gnpdrm.pkg
      memdump.npdrm.pkg

      which to use?

    156. jrtux
      07-23-2012
      05:28 PM
      156

      Originally Posted by AsSiTcH View Post
      memdump.gnpdrm.pkg
      memdump.npdrm.pkg

      which to use?
      memdump.npdrm.pkg

    157. AsSiTcH
      07-23-2012
      05:31 PM
      157

      Originally Posted by jrtux View Post
      memdump.npdrm.pkg
      Thank you!!!!

    158. klaxnek
      07-23-2012
      05:51 PM
      158

      For your info:
      I have updated Multiman (before the servers seems to be down) and installed it when in debug mode. Although it has the same version as the one that I had installed, now dumping flash works!!!

    159. zaphod
      07-23-2012
      07:04 PM
      159

      Originally Posted by klaxnek View Post
      For your info:
      I have updated Multiman (before the servers seems to be down) and installed it when in debug mode. Although it has the same version as the one that I had installed, now dumping flash works!!!
      there are new versions of multiman... but with the same version number...

      read something about fixing NAND flashing... didnt tried yet..

      see here

      http://www.ps3hax.net/showpost.php?p...&postcount=246

    160. rrr159
      07-23-2012
      08:51 PM
      160

      So just to make sure, this will definitely not work on CFW 3.55. If not, why?

    161. AsSiTcH
      07-23-2012
      09:01 PM
      161

      Originally Posted by rrr159 View Post
      So just to make sure, this will definitely not work on CFW 3.55. If not, why?
      I dumped mine and Im on 3.55kmeaw

    162. spectlze
      07-23-2012
      09:03 PM
      162

      Originally Posted by jrtux View Post
      Use MemDump from ps3devwiki, is easier ...
      -Usage:
      Place the necessary pkg file in the root of an empty USB flash dongle, and install like any
      other pkg.

      1. Place pkg on USB flash dongle.
      2. Select “memdump” icon.
      3. Select type of dump to perform once loaded :

      ✕ Dump FLASH storage



      Download
      You should edit that this doesn't work well with NAND consoles. Some users reported getting smaller filesize on flash dumps. This is mostly for NOR consoles.

    163. br0br0
      07-23-2012
      09:20 PM
      163

      ..........

    164. zizoux
      07-23-2012
      09:26 PM
      164

      Any ideas?

    165. seanking
      07-23-2012
      10:50 PM
      165

      Did someone repacked AbsentOS on 3.55 I', Using downgraded PS3 and I cant mess with firmware like other users!!

    166. jrtux
      07-23-2012
      11:42 PM
      166

      I compiled the asbestos stage2 for 3.55 with toolchain as naehrwert commented on twitter.

      "‏@naehrwert
      this is the modified stage2 I'm using (I guess you can change the entry and compile this yourself) http://www.sendspace.com/file/2064nl"

      build resulted in:
      stage2_raw.bin
      stage2_raw.elf
      stage2_raw.lzma

      Download

    167. seanking
      07-24-2012
      02:46 AM
      167

      Originally Posted by jrtux View Post
      I compiled the asbestos stage2 for 3.55 with toolchain as naehrwert commented on twitter.

      "‏@naehrwert
      this is the modified stage2 I'm using (I guess you can change the entry and compile this yourself) http://www.sendspace.com/file/2064nl"

      build resulted in:
      stage2_raw.bin
      stage2_raw.elf
      stage2_raw.lzma

      Download
      noob here what happens between this point and point that gives us .PKG

    168. DEFAULTDNB
      07-24-2012
      02:57 AM
      168

      Great work thank you [MENTION=203760]jrtux[/MENTION]. It would be great if someone could do a kmeaw tutorial for this

    169. iT0ny
      07-24-2012
      03:56 AM
      169

      thanks [MENTION=203760]jrtux[/MENTION]! tried to compile(&test) asbestos loader with ur stage2,
      black screen only dump_rootkey returns "[INFO] Ping...[bad reply size (-1)]" ->i think i did smth wrong w/ stage2

      stage2(3.55 mod).h

    170. Hannibal1471
      07-24-2012
      04:30 AM
      170

      Originally Posted by haz367 View Post
      he must have a binnepretje seeing this topic..funny guys.. haha no problem, i have tryed to repack it errors out with 80029533 and in the meantime dumped 2 rootkeys, let's sit this one out...
      U dutch or flemish?

    171. MakinaCore
      07-24-2012
      04:51 AM
      171

      right noob here trying this c2d see after i get the flash from that memdump ? what happens next ? lol do i open the flash in CEX2DEX_BY_GUNNER54 ?

    172. Asure
      07-24-2012
      05:03 AM
      172

      Originally Posted by Hannibal1471 View Post
      U dutch or flemish?
      Guilty to the first one. But there are more dutchies here, you can spot them easily

      [MENTION=220152]MakinaCore[/MENTION]: When you've done the memdump, run the cex2dex from gunnar54 and extract metldr. Then use that file with this exploit. Are you on 3.41?

    173. zaphod
      07-24-2012
      05:23 AM
      173

      the first 3.55 pkg did not work...

      hope that a talented dev can fix it..
      thinking of going back to 3.41 to get the root-key.. dont wanna change my internal hdd its mostly full and too much data-jongling work to do ;-)

      [MENTION=7808]Asure[/MENTION] you have downgraded to 3.41? what did i need to go back? i will make my own 3.41 with mfw for peek/poke.. must i use the qa-flags thing to go back?
      my cfw now is a 3.55 buildt with mfw (only the things i need peek/poke/paket installation) thats it..

    174. MakinaCore
      07-24-2012
      05:59 AM
      174

      no m8 am on 3.55 ??

    175. DEFAULTDNB
      07-24-2012
      06:04 AM
      175

      Originally Posted by jrtux View Post
      I compiled the asbestos stage2 for 3.55 with toolchain as naehrwert commented on twitter.

      "‏@naehrwert
      this is the modified stage2 I'm using (I guess you can change the entry and compile this yourself) http://www.sendspace.com/file/2064nl"

      build resulted in:
      stage2_raw.bin
      stage2_raw.elf
      stage2_raw.lzma

      Download
      Any progress for us Kmeaw users?

    176. javier4
      07-24-2012
      06:08 AM
      176

      My ps3 is on 3.41 ofw + dongle hermas 4 p. Does anyone know what to setting Dump rootkey naehrwert in pc,ps3 win xp ftp client ...Does anyone know to write a guide for stupid people..

    177. Asure
      07-24-2012
      06:49 AM
      177

      Originally Posted by zaphod View Post
      the first 3.55 pkg did not work...

      hope that a talented dev can fix it..
      thinking of going back to 3.41 to get the root-key.. dont wanna change my internal hdd its mostly full and too much data-jongling work to do ;-)

      [MENTION=7808]Asure[/MENTION] you have downgraded to 3.41? what did i need to go back? i will make my own 3.41 with mfw for peek/poke.. must i use the qa-flags thing to go back?
      my cfw now is a 3.55 buildt with mfw (only the things i need peek/poke/paket installation) thats it..
      I installed everything on my 3.55 before QA-flagging and going back to 3.41.
      - Install Memdump
      - Install the Asbestos ldr
      - Dump with memdump to USB, use PC & cex2dex to get 'metldr' extracted from that dump.

      At this point you can't do the exploit because the Asbestos ldr doesn't work. Time to downgrade, it's pretty easy.

      - Follow this Tutorial to goto 3.41 ofw.
      - Use MFW Builder to make a 3.41 pup that has peek/poke
      - Install that on top of 3.41ofw using recovery menu.
      - Now the asbestos ldr works, and you can do the exploit by network.

      Probably you can also install your mfw-built 3.41cfw+peekpoke directly, but i'm told that for safety reasons it's better to flash 3.41 ofw first.

      My box is still on 3.41 peekpoke btw, it didn't convert it to DEX yet. I have two ps3's so i can play my original games anyway, and abuse the data transfer function between the two :0

    178. DEFAULTDNB
      07-24-2012
      06:51 AM
      178

      [MENTION=7808]Asure[/MENTION], when you downgraded did you lose your data off your internal HDD? did it get affected in anyway?

    179. haz367
      07-24-2012
      07:02 AM
      179

      Originally Posted by Asure View Post
      Guilty to the first one. But there are more dutchies here, you can spot them easily
      hehe..spot on...must be my poor engrish..can't blame the dutch..it must be me doing flemish scool back in the day j/k so yeah [MENTION=209706]Hannibal1471[/MENTION]...another dutchy here..ur flemish right?



      [MENTION=198164]zizoux[/MENTION] : that error is not having "gcc" installed

      Code:
      Do scan for gcc.exe
      If you don't have it, you must go back and download it. IIRC, its called something like "development packages" in the setup program. You have to look for one that says "compiler".
      so run the installer package again and tick" whatever u'll need to get "gcc" working

    180. Asure
      07-24-2012
      07:02 AM
      180

      Originally Posted by DEFAULTDNB View Post
      [MENTION=7808]Asure[/MENTION], when you downgraded did you lose your data off your internal HDD? did it get affected in anyway?
      Everything (all 400+GB) was still there. Including the Asbestos LDR and Memdump apps, accounts, edat files etc.

      Probably not all apps/games would run, but at least Asbestos and Memdump ran perfectly, they seem to be signed with keys that work on 3.41/3.55 (geohot fake npdrm?). Or it might have been an option in MFW builder to allow unsigned eboots to run..i checked every option to allow peek/poke/unsigned code execution hehehe..

      If you have everything set up before hand, the downgrade and dump doesn't take long, and then you finally have that coveted key. Also you don't need to re-use memdump again if you already did that and have metldr file. I wasted ~14 minutes or so to dump the whole nand/lv/eid stuff again on 3.41 but it wasn't needed, the extracted metldr file was the same from both dumps (duh!).

      I'm wondering still what we can do with the SDK and live debugging over network, won't that get us keys?

    181. Hannibal1471
      07-24-2012
      07:12 AM
      181

      Originally Posted by haz367 View Post
      hehe..spot on...must be my poor engrish..can't blame the dutch..it must be me doing flemish scool back in the day j/k so yeah [MENTION=209706]Hannibal1471[/MENTION]...another dutchy here..ur flemish right?
      Yeah, a flemish one over here. I recognised binnepretje ;d

    182. haz367
      07-24-2012
      07:20 AM
      182

      hehe..i bet he did but we don't give up so easely right
      anyone ported to 3.55? can't seem to get it working..any tips on compiling..gonna look into that..need to setup PS1LIGHT in cygwin if thats even possible....if anyone have info/links pls do post

    183. MakinaCore
      07-24-2012
      08:03 AM
      183

      this even right ? got it from cex2dex by gunner


      - Loading Flash Dump...
      - METLDR Address : 0x00000817
      - METLDR Size : 0x0000E920


      flash_eEID_35500.bin << got that from memdump ? this correct

    184. lamaboy
      07-24-2012
      09:04 AM
      184

      can some1 write their connection settings plz
      i'm on 3.41 hermes and can connect to ftp server but still no results with this program

    185. spectlze
      07-24-2012
      09:52 AM
      185

      Originally Posted by MakinaCore View Post
      this even right ? got it from cex2dex by gunner


      - Loading Flash Dump...
      - METLDR Address : 0x00000817
      - METLDR Size : 0x0000E920


      flash_eEID_35500.bin << got that from memdump ? this correct
      If you have a NOR console and the total size of the flash equals 16,777,216 bytes i think your good to go. metldr file should be 59 kb in size.

    186. pSydeFX
      07-24-2012
      11:03 AM
      186

      Originally Posted by AsSiTcH View Post
      I dumped mine and Im on 3.55kmeaw
      how ??????????

    187. ovhaum
      07-24-2012
      11:10 AM
      187

      Originally Posted by lamaboy View Post
      can some1 write their connection settings plz
      i'm on 3.41 hermes and can connect to ftp server but still no results with this program
      Yeah, i want to know that too. I have tryed everything and still no unicorns. The problem must be on my internet network*... it HAVE to be!!

    188. zizoux
      07-24-2012
      11:17 AM
      188

      My router has only one ethernet port, so i connected my ps3 to the pc but it didn't work.

    189. JayDee78
      07-24-2012
      11:37 AM
      189

      Short tut on how i did it.

      On PC:

      Extract the dump_rootkey.7z (or the precompiled dump_rootkey modifie par Attila) to c:

      Put the metldr in the c:\dump_rootkey\data folder (read below on how you get this file)

      PS3:

      Get your flash dump with memdump_0.01-FINAL, and extract the metldr with cex2dex etc etc etc, and put it in the data folder on the pc as i explained earlier

      Install the asbestos_ldr.g.pkg from Naehrwert´s original download (dump_rootkey.7z)

      As i was on 3.55 kmeaw and could downgrade i just got the 3.41 OFW (just google "ofw 3.41 download" and you will find it fast) and ran it through mfw builder 0.2

      The settings i used:

      Patch LV1 hypervisor
      Patch LV2 kernel
      Patch package installer
      Patch application launcher


      Went into recovery on the ps3 and flashed the mfw 3.41

      Started the asbestos loader after boot up and then started dump_rootkey on my pc with the right ip and as promised: UNICORNS!

      [INFO] Connecting to '192.168.2.186'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2 0x00004C0001260000
      [INFO] problem 0x00004C0001240000
      [INFO] LS 0x00004C0001200000
      [INFO] shadow 0x0000300000025000
      [INFO] ID 0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000011
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] -> mailbox interrupt
      [INFO] Mailbox value = 1
      [INFO] -> Dumper loaded.
      [INFO] Transferring eid_root_key to buffer...finished.
      [INFO] Dumping eid_root_key...done.
      [INFO] SPU status = 0x00000081
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.
      [INFO] Press any key to exit...

      Hope this helps some of you (atleast you that CAN downgrade)

    190. ovhaum
      07-24-2012
      11:45 AM
      190

      Originally Posted by JayDee78 View Post
      Short tut on how i did it.

      On PC:

      Extract the dump_rootkey.7z (or the precompiled dump_rootkey modifie par Attila) to c:

      Put the metldr in the data folder

      PS3:

      Get your flash dump with memdump_0.01-FINAL, and extract the metldr with cex2dex, and put it in the data folder as i explained earlier

      Install the asbestos_ldr.g.pkg from Naehrwert´s original download (dump_rootkey.7z)

      As i was on 3.55 kmeaw and could downgrade i just got the 3.41 OFW (just google ofw 3.41 download and you will find it fast) and ran it through mfw 0.2

      Patch LV1 hypervisor
      Patch LV2 kernel
      Patch package installer
      Patch application launcher

      Went into recovery on the ps3 and flashed the mfw 3.41

      Started the asbestos loader after boot up and then started dump_rootkey with the right ip and as promised: UNICORNS!

      [INFO] Connecting to '192.168.2.186'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2 0x00004C0001260000
      [INFO] problem 0x00004C0001240000
      [INFO] LS 0x00004C0001200000
      [INFO] shadow 0x0000300000025000
      [INFO] ID 0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000011
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] -> mailbox interrupt
      [INFO] Mailbox value = 1
      [INFO] -> Dumper loaded.
      [INFO] Transferring eid_root_key to buffer...finished.
      [INFO] Dumping eid_root_key...done.
      [INFO] SPU status = 0x00000081
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.
      [INFO] Press any key to exit...

      Hope this helps some of you (atleast you that CAN downgrade)
      I already did all of this with ps3mfw, hermes 3.41 patched cfw, 3.55 otheross++_Special pup kmeaw... its like pursueing the rainbow.

    191. Asure
      07-24-2012
      11:51 AM
      191

      Originally Posted by JayDee78 View Post
      As i was on 3.55 kmeaw and could downgrade i just got the 3.41 OFW (just google "ofw 3.41 download" and you will find it fast) and ran it through mfw builder 0.2
      You didn't need to set QA flag for this? It picked up 3.41mfw output pup as a valid 'upgrade' version then?

    192. haxxxen
      07-24-2012
      11:57 AM
      192

      what about loading only 3.41 kernel with lv2loader on 3.55 and run the script and pkg?

    193. lamaboy
      07-24-2012
      11:59 AM
      193

      i managed to get the keys
      ps3 must be connected to pc ONLY via ROUTER. without it nothing will work.

    194. dadi4168
      07-24-2012
      12:00 PM
      194

      Ok, maybe a little off topic, but I dumped my flash using multiman on a usb stick and I can't seem to get windows to "see" it. I've ticked the hidden file option in the control panel. The displacement for the file is there. Easeus partition manager can see the file, but I can't do anything with it.

    195. JayDee78
      07-24-2012
      12:01 PM
      195

      Originally Posted by Asure View Post
      You didn't need to set QA flag for this? It picked up 3.41mfw output pup as a valid 'upgrade' version then?
      QA flag set (did it ages ago it feels like) Forgot to say that...

    196. iT0ny
      07-24-2012
      12:02 PM
      196

      Originally Posted by lamaboy View Post
      i managed to get the keys
      ps3 must be connected to pc ONLY via ROUTER. without it nothing will work.
      on which cfw?

    197. Hannibal1471
      07-24-2012
      12:05 PM
      197

      Originally Posted by dadi4168 View Post
      Ok, maybe a little off topic, but I dumped my flash using multiman on a usb stick and I can't seem to get windows to "see" it. I've ticked the hidden file option in the control panel. The displacement for the file is there. Easeus partition manager can see the file, but I can't do anything with it.
      Cause they are not stored on the external usb device standard. When you dump the flash, multiman shows where it's being stored. You can copy them from that location to your usb.

    198. lamaboy
      07-24-2012
      12:06 PM
      198

      Originally Posted by iT0ny View Post
      on which cfw?
      3.41 hermes

    199. dadi4168
      07-24-2012
      12:23 PM
      199

      Originally Posted by Hannibal1471 View Post
      Cause they are not stored on the external usb device standard. When you dump the flash, multiman shows where it's being stored. You can copy them from that location to your usb.
      Nope, the file is on the usb stick. I watched as it was extracted and the light was flashing. Easeus partition manager finds it, multiman finds it, windows won't.

    200. Atrion
      07-24-2012
      12:26 PM
      200

      Originally Posted by dadi4168 View Post
      Nope, the file is on the usb stick. I watched as it was extracted and the light was flashing. Easeus partition manager finds it, multiman finds it, windows won't.
      It was doing the same thing for me as well, so I just FTP'd to the PS3 and copied it over to my windows Machine

    201. jrtux
      07-24-2012
      12:31 PM
      201

      Originally Posted by iT0ny View Post
      thanks [MENTION=203760]jrtux[/MENTION]! tried to compile(&test) asbestos loader with ur stage2,
      black screen only dump_rootkey returns "[INFO] Ping...[bad reply size (-1)]" ->i think i did smth wrong w/ stage2

      stage2(3.55 mod).h
      OK, thanks,
      Now compiled the stage1 and stage2 from the original source of asbestos:
      stage1.elf
      stage2_native.elf
      stage2_raw.elf
      stage2_raw.lzma
      From original source:
      Download

      From Naehrwert source:
      Download

    202. rrr159
      07-24-2012
      12:31 PM
      202

      Now for the downgrade option do u hav to QA flag? I don't want to go through that right now and find tut. Is there another way?

      Sent from my SPH-M580 using Tapatalk 2

    203. Hannibal1471
      07-24-2012
      12:31 PM
      203

      try dumping it again

    204. DEFAULTDNB
      07-24-2012
      12:33 PM
      204

      Originally Posted by rrr159 View Post
      Now for the downgrade option do u hav to QA flag? I don't want to go through that right now and find tut. Is there another way?

      Sent from my SPH-M580 using Tapatalk 2
      qa flag is easy, use rebug qa toggle, use the button combo and bobs your uncle.

    205. dadi4168
      07-24-2012
      12:35 PM
      205

      Originally Posted by Atrion View Post
      It was doing the same thing for me as well, so I just FTP'd to the PS3 and copied it over to my windows Machine
      Excellent, I'll try that now.

    206. rrr159
      07-24-2012
      12:38 PM
      206

      Originally Posted by DEFAULTDNB View Post
      qa flag is easy, use rebug qa toggle, use the button combo and bobs your uncle.
      Yeah never mind I was being an idiot lol. How confused qa flag with something about linux because I just woke up. Yeah I remembrr

      Sent from my SPH-M580 using Tapatalk 2

    207. JayDee78
      07-24-2012
      01:34 PM
      207

      Got everything up and running and played around abit.

      Used Itskamel 3.55 Dex, as devwiki is slower then frozen honey, now that everyone is downloading fw files like crazy again.

      Gonna install rogero when it is done so i can upgrade/downgrade as a i want. Got a couple of games (retail, with the plastic wrapper still on!) that i have been waiting to play.

      Well, the info:

      Had to delete some trophys for some games (like gt5) while others (Uncharted 1) worked right away. Multiman, Blackbox etc are all working fine. Everything that was on the hdd is still on the hdd and working...

    208. zaphod
      07-24-2012
      01:40 PM
      208

      Originally Posted by dadi4168 View Post
      Ok, maybe a little off topic, but I dumped my flash using multiman on a usb stick and I can't seem to get windows to "see" it. I've ticked the hidden file option in the control panel. The displacement for the file is there. Easeus partition manager can see the file, but I can't do anything with it.
      open dos box, go to the stick and type attrib -S -H *.*

      it seems that windows has a prob with the created dump-files..
      ************* [ - Post Merged - ] *************
      [MENTION=7808]Asure[/MENTION]

      thnx for the short tut :-)

      its not the easy way when you got 3.55 but much more easier then the linux thing on the internal hdd... and it cost less time, you lose NO data on hdd :-)

      with 3.15 i have installed linux on the PS3..ok got it running, fixed a lot of things (display size, buffer...) it was not the fastest..
      if i need linux for something i fire up the vmplayer :-)

    209. zizoux
      07-24-2012
      01:59 PM
      209

      We should be able to get the rootkey by connecting ps3 to via ethernet?
      I believe many of us don't have router with multiple ports.

    210. ovhaum
      07-24-2012
      02:07 PM
      210

      Just got my key

      I just let the ps3 set the connection settings automatically, (easy option) go system information for the ip, compiled again on ubuntu and unicorns finally.

      48 bytes .bin, thats right, right?

    211. iT0ny
      07-24-2012
      02:09 PM
      211

      Originally Posted by haxxxen View Post
      what about loading only 3.41 kernel with lv2loader on 3.55 and run the script and pkg?
      nice idea! can some1 extract lv2 from 3.41 cfw?
      http://d.pr/f/jChh (core_os_package.pkg from 3.41 cfw,idk how to unpack it)

    212. rrr159
      07-24-2012
      02:18 PM
      212

      alright i downgraded (all files stay intact)
      got the dump (connected via ethernet and easy options to connect)
      by running compiled client

      now what is the next step to convert

      used cex2dex to get rflash.bin

      now what

    213. MakinaCore
      07-24-2012
      02:23 PM
      213

      could someone test this for me before i flash it ?

      https://www.yousendit.com/download/ QlVpRGw1YUlENlJFQmNUQw

      try get the metlrd and compile it haha :-" ??? please

    214. JayDee78
      07-24-2012
      02:27 PM
      214

      Originally Posted by rrr159 View Post
      alright i downgraded (all files stay intact)
      got the dump (connected via ethernet and easy options to connect)
      by running compiled client

      now what is the next step to convert
      Use c2d or cex2dex to get your patched full *dex.bin

      Rename it to my-DEX-flash.EID0.NORBIN (should be 16384kb) and place on usb.

      Then google for "multiman 20120722" and install this.

      Goto mmOS and then navigate to your usb and double click on your my-DEX-flash.EID0.NORBIN. You get to accept install three times. Reboot

      Flash your dex fw from within xmb

    215. zizoux
      07-24-2012
      02:33 PM
      215

      Is my ps3 supposed to freeze at blackscreen after i run asbestos?

    216. rrr159
      07-24-2012
      02:34 PM
      216

      Will try

      Sent from my SPH-M580 using Tapatalk 2

    217. JayDee78
      07-24-2012
      02:34 PM
      217

      Originally Posted by zizoux View Post
      Is my ps3 supposed to freeze at blackscreen after i run asbestos?
      Yes, the rest you do from the pc...

    218. rrr159
      07-24-2012
      02:37 PM
      218

      Successfully flashed, will proceed to install dex fw now.

      Sent from my SPH-M580 using Tapatalk 2

    219. zizoux
      07-24-2012
      02:40 PM
      219

      Originally Posted by JayDee78 View Post
      Yes, the rest you do from the pc...
      Hmm, I connect the ps3 to my pc, and at the system info IP shows 169.254.91.35.
      So having router with multiple ports is the only way to obtain keys atm.

    220. zaphod
      07-24-2012
      02:45 PM
      220

      Originally Posted by zizoux View Post
      We should be able to get the rootkey by connecting ps3 to via ethernet?
      I believe many of us don't have router with multiple ports.
      lol.. i think most of the ppl here got minimum 1 router or switch with 4 eth Ports... i have 2 firewalls with 4 eth ports,a wlan AP with 4 eth Ports

      and if you wanna know exactly:
      - you can use a normal switch for connecting
      - a cross wired ethernet-cable without a router or switch (Pc<--cable-->PS3)
      - wlan is maybe also working.. its better to use wired connection
      ************* [ - Post Merged - ] *************
      Originally Posted by zizoux View Post
      Hmm, I connect the ps3 to my pc, and at the system info IP shows 169.254.91.35.
      So having router with multiple ports is the only way to obtain keys atm.
      thats APIPA.. your PC or the PS3 didnt get an Adress per DHCP so it used APIPA hoping the other device also used it..

      Networking Basics:
      give the PS3 manal this:
      IP: 192.168.0.1
      SUB: 255.255.255.0

      and your PC:
      IP: 192.168.0.2
      SUB: 255.255.255.0

      gateway and dns is not the point for that..

      if you have set.. open dos box and ping 192.168.0.1 if it works you have build a little P2P-Ethernet with 2 members

    221. zizoux
      07-24-2012
      02:57 PM
      221

      Thanks but I've been trying to get the keys by using this method since yesterday. lol
      a cross wired ethernet-cable without a router or switch (Pc<--cable-->PS3)


      I don't think I'm doing anything wrong. This is why I've been trying to tell that a router with multiple ethernet ports is the only way to obtain rootkey

    222. zaphod
      07-24-2012
      03:01 PM
      222

      Originally Posted by zizoux View Post
      Thanks but I've been trying to get the keys by using this method since yesterday. lol
      a cross wired ethernet-cable without a router or switch (Pc<--cable-->PS3)


      I don't think I'm doing anything wrong. This is why I've been trying to tell that a router with multiple ethernet ports is the only way to obtain rootkey
      thats the error we all got with fw 3.55 ...

      it only works with 3.41 peek poke fw (not booting with a dongle/ a patched 3.41..)

    223. zizoux
      07-24-2012
      03:06 PM
      223

      I'm on 3.41 MFW.
      Tried 3.41 custom fw with payload4

    224. JayDee78
      07-24-2012
      03:13 PM
      224

      169.*.*.* is NOT a valid ip...

      "When your computer is configured to get an IP address from a DHCP server, but is unable to find a DHCP server the APIPA service will assign itself a 169.x.x.x IP address, and checks for a DHCP server periodically."

      Your pc3 isn´t talking to your pc, even though the cable is present, unless you set up a dhcp server on your pc or manually configure your pc and ps3 and hook them up directly.

      Keep trying with the 169.* address, it wont change the fact that it will NEVER work...

      Get a switch or router if you do not know how to manually configure the network on the pc/ps3

    225. Asure
      07-24-2012
      03:23 PM
      225

      On startup, asbestos ldr wipes ps3 memory and that's why it blackscreens.
      It then brings up ethernet port again and tries to get an IP by DHCP.
      So you need to run at least a DHCP server on your PC if you have no router.. y u have no routor?

      No router solution:
      Try http://tftpd32.jounin.net/ installing this, then check the 'dhcp server' tab to see which it assigned to your ps3. you should see another dhcp request pop by when you launch asbestos ldr.. and then use that IP to connect with the exploit tool.

    226. zizoux
      07-24-2012
      04:11 PM
      226

      I think I'm going nuts.
      It doesn't show anything AT ALL. Just server interface numbers are changing and I've tried all of them.

    227. Gonzakpo
      07-24-2012
      04:15 PM
      227

      If you configure your PC as a router (share internet option on the ethernet interface) then a DHCP server is activated. That is if you are using Windows.

    228. justforyou
      07-24-2012
      04:32 PM
      228

      whaha this is funny [MENTION=198164]zizoux[/MENTION] some basic sjit there :D you'll figure it out

    229. zizoux
      07-24-2012
      04:38 PM
      229

      Originally Posted by Gonzakpo View Post
      If you configure your PC as a router (share internet option on the ethernet interface) then a DHCP server is activated. That is if you are using Windows.
      Didn't work.Anyway I guess I'll have to buy another router.
      Thanks for your efforts guys.

      justforyou@
      Lol you're right.

    230. a$h x
      07-24-2012
      04:49 PM
      230

      As far as I know there are two things missing from this guide:

      1) A pre-compiled version of dump_rootkey - Right now, you need to compile you own version with your PS3's IP address in one of the files. Please, someone have pity on us non-programmer types, and give a version which runs on MSDOS or better yet a GUI!

      2) A asbestos_ldr.pkg that runs on 3.55 CEX. The current version ONLY runs on 3.41 or lower. I know your can downgrade, but surely someone can create a package that runs on 3.55? Pretty please?

      If these two issues can be addressed, I promise to write up a super-n00b guide so everyone can enjoy CEX-2-DEX goodness!

    231. rrr159
      07-24-2012
      04:58 PM
      231

      Originally Posted by a$h x View Post
      As far as I know there are two things missing from this guide:

      1) A pre-compiled version of dump_rootkey - Right now, you need to compile you own version with your PS3's IP address in one of the files. Please, someone have pity on us non-programmer types, and give a version which runs on MSDOS or better yet a GUI!

      2) A asbestos_ldr.pkg that runs on 3.55 CEX. The current version ONLY runs on 3.41 or lower. I know your can downgrade, but surely someone can create a package that runs on 3.55? Pretty please?

      If these two issues can be addressed, I promise to write up a super-n00b guide so everyone can enjoy CEX-2-DEX goodness!
      Truthfully u sound like a noob.

      Also there are other issues to address like will it work over wifi and well that's all I can think of right now lol

      Sent from my SPH-M580 using Tapatalk 2

    232. pSydeFX
      07-24-2012
      05:02 PM
      232

      Originally Posted by rrr159 View Post
      Truthfully u sound like a noob.

      Also there are other issues to address like will it work over wifi and well that's all I can think of right now lol

      Sent from my SPH-M580 using Tapatalk 2
      what?? a asbestos_ldr.pkg for 3.55 is needed as theres lots of people on kmeaw cfw

    233. haz367
      07-24-2012
      05:11 PM
      233

      Originally Posted by zaphod View Post
      it only works with 3.41 peek poke fw (not booting with a dongle/ a patched 3.41..)
      hi, patched 341firmware or using ofw341+payload dongle is the same right, patching it more(mfw)would have more options....but the last option worked fine here on ofw341/dongle-payload hermes/psgroove_3.41

      isn't there something we can do with asbestos.pkg/lv2-9.pkg for 3.5? tested some diff ways..no luck there

      asbestos_ldr_355_retail.elf works or not or is re-compiling required?
      hope someone comes up with 355fix not everyone can downgrade to 341

    234. rrr159
      07-24-2012
      05:25 PM
      234

      Originally Posted by pSydeFX View Post
      what?? a asbestos_ldr.pkg for 3.55 is needed as theres lots of people on kmeaw cfw
      I mispoke. What I meant was yes it wud be good to hav but it is eaaasy to do. I did it in ten min. I am currently trying to get driver to work

      Sent from my SPH-M580 using Tapatalk 2

    235. greyestest
      07-24-2012
      05:30 PM
      235

      Can someone modify the utility so that a multiport router wouldn't be neccessary please?

      Direct PC-PS3 connection would be super nice.

    236. a$h x
      07-24-2012
      05:33 PM
      236

      I setup a Ubuntu virtual machine, so if anyone wants, I can compile the dump_rootkey program for with their own PS3 IP addresses so all they need to do is run it. All we need now is the 3.55 asbestos_ldr.pkg

    237. Atrion
      07-24-2012
      05:39 PM
      237

      If I do a QA Flagged downgrade to 3.41 do I need to go to OFW first or can I just go to say Rebug 3.41?

    238. rrr159
      07-24-2012
      05:46 PM
      238

      U stay

      Sent from my SPH-M580 using Tapatalk 2

    239. datniccaillah
      07-24-2012
      06:02 PM
      239

      cant downgrade don't know how to make a pkg file stuck just have to wait...

    240. zaphod
      07-24-2012
      06:29 PM
      240

      success..

      couldnt wait until 355 version so i downgraded to 3.41 and all is fine..
      got my eid_root_key.bin (length: 48 Byte)

      Code:
      $ ./dump_rootkey.exe
      [INFO] Connecting to '192.168.1.103'...ok.
      test from zaphod
      ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2   0x00004C0001260000
      [INFO] problem 0x00004C0001240000
      [INFO] LS      0x00004C0001200000
      [INFO] shadow  0x0000300000025000
      [INFO] ID      0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000011
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] -> mailbox interrupt
      [INFO] Mailbox value = 1
      [INFO] -> Dumper loaded.
      [INFO] Transferring eid_root_key to buffer...finished.
      [INFO] Dumping eid_root_key...done.
      [INFO] SPU status = 0x00000081
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.

    241. andrewrich
      07-24-2012
      06:53 PM
      241

      when i try to run dump_rootkey.exe on my pc it opens for a split second and the closes again. If some one would be able to help me it would be much appreciated

    242. stussy1
      07-24-2012
      06:54 PM
      242

      The first person who makes a video will be a legend

    243. zaphod
      07-24-2012
      07:00 PM
      243

      Originally Posted by stussy1 View Post
      The first person who makes a video will be a legend


      as i read that ....rofl.....

    244. stussy1
      07-24-2012
      07:10 PM
      244

      Originally Posted by zaphod View Post


      as i read that ....rofl.....
      Well alot of people will be crying after bricks
      Not the hole process
      From 3,41 and on

    245. zaphod
      07-24-2012
      07:18 PM
      245

      Originally Posted by stussy1 View Post
      Well alot of people will be crying after bricks
      Not the hole process
      From 3,41 and on
      only advanced ppl should try the conversion.. thats not a beginners thing cause so many different steps.. a little mistake or to fast reboot and your PS3 is a legend......

    246. AsSiTcH
      07-24-2012
      07:22 PM
      246

      "Well alot of people will be crying after bricks"
      That is the fun part.

    247. kneeandarrow
      07-24-2012
      07:31 PM
      247

      I am on Hermes 3.41 CFW with peek/poke.

      I have tried all these asbestos.pkg's but some of them gave error when I try to install from "Install package files" menu.

      - Should the asbestos_ldr.g.pkg be specific to my PS3 IP?
      - I have extracted my metldr. What should be the file name?
      - I have windows so which dump_rootkey.exe should I use or do I have to make (my ps3 IP is 192.168.1.5) ?

    248. rrr159
      07-24-2012
      07:36 PM
      248

      Originally Posted by kneeandarrow View Post
      I am on Hermes 3.41 CFW with peek/poke.

      I have tried all these asbestos.pkg's but some of them gave error when I try to install from "Install package files" menu.

      - Should the asbestos_ldr.g.pkg be specific to my PS3 IP?
      - I have extracted my metldr. What should be the file name?
      - I have windows so which dump_rootkey.exe should I use or do I have to make (my ps3 IP is 192.168.1.5) ?
      How about u wait?

      But ill try to help. The file name should be metldr. Put it in the data folder. Open command prompt. Drag the dump_rootkey.exe into command prompt. Beforre u press enter, press space after it says rootkey.exe and type in ur ps3 ip adress. Before u press enter run asbestos package on ps3, it shud be black screen. Now press enter on command prompt. It shud work

      Sent from my SPH-M580 using Tapatalk 2

    249. rrr159
      07-24-2012
      07:37 PM
      249

      Also use the original asbestos from original download. Also I wudnt use hermes, make ur own mfw.

      Sent from my SPH-M580 using Tapatalk 2

    250. kneeandarrow
      07-24-2012
      07:44 PM
      250

      Originally Posted by rrr159 View Post
      Also use the original asbestos from original download. Also I wudnt use hermes, make ur own mfw.

      Sent from my SPH-M580 using Tapatalk 2
      Which original? The original one ( http://t.co/yATUC9Ap ) has no exe file compiled for windows. The asbestos_ldr_g.pkg of that file gives : "error install operation (80029564) ".

    251. rrr159
      07-24-2012
      07:47 PM
      251

      Originally Posted by kneeandarrow View Post
      Which original? The original one ( http://t.co/yATUC9Ap ) has no exe file compiled for windows. The asbestos_ldr_g.pkg of that file gives : "error install operation (80029564) ".
      Alright if u can get original 3.41 pup, then get mfw 0.2, make ur own pup and install that, or wait maybe a couple hours and I can upload my pup. But it is easier if u make ur own. I don't think hermes supports unsigned content. The compiled .exe works. I meant original asbestos

      Sent from my SPH-M580 using Tapatalk 2

    252. rrr159
      07-24-2012
      07:48 PM
      252

      Rep me or thank me if I help

      Sent from my SPH-M580 using Tapatalk 2

    253. kneeandarrow
      07-24-2012
      07:51 PM
      253

      Originally Posted by rrr159 View Post
      Rep me or thank me if I help

      Sent from my SPH-M580 using Tapatalk 2
      I need the exact file link, that is what I am asking

    254. rrr159
      07-24-2012
      07:53 PM
      254

      Originally Posted by kneeandarrow View Post
      I need the exact file link, that is what I am asking
      I'm sorry I talked about like 3 different files what link r u talking about

      Sent from my SPH-M580 using Tapatalk 2

    255. kneeandarrow
      07-24-2012
      07:56 PM
      255

      Originally Posted by rrr159 View Post
      I'm sorry I talked about like 3 different files what link r u talking about

      Sent from my SPH-M580 using Tapatalk 2
      Only these :

      - Asbestos_ldr_g.pkg : Running on 3.41 CFW
      - Dump_rootkey.exe : compiled for windows (if required my ps3 ip 192.168.1.5)

    256. rrr159
      07-24-2012
      08:01 PM
      256

      Originally Posted by kneeandarrow View Post
      Only these :

      - Asbestos_ldr_g.pkg : Running on 3.41 CFW
      - Dump_rootkey.exe : compiled for windows (if required my ps3 ip 192.168.1.5)
      Ok. Upgrade to 3.55 kmeaw cfw. Install asbestos. Downgrade to 3.55 cfw any that has peek and poke.

      The already compiled dump_rootkey.exe shud work. Look through this forum u shud find it if u don't have it. Then use my directions that I posted earlier on how to run it. If u don't know how to downgrade google q&a downgrade tutorial ps3hax.

      Sent from my SPH-M580 using Tapatalk 2

    257. kneeandarrow
      07-24-2012
      08:07 PM
      257

      Originally Posted by rrr159 View Post
      Ok. Upgrade to 3.55 kmeaw cfw. Install asbestos. Downgrade to 3.55 cfw any that has peek and poke.

      The already compiled dump_rootkey.exe shud work. Look through this forum u shud find it if u don't have it. Then use my directions that I posted earlier on how to run it. If u don't know how to downgrade google q&a downgrade tutorial ps3hax.

      Sent from my SPH-M580 using Tapatalk 2
      I am already on 3.41 MFW , I need just the exact files. I couldn't pick the right ones.

    258. rrr159
      07-24-2012
      08:33 PM
      258

      Originally Posted by kneeandarrow View Post
      I am already on 3.41 MFW , I need just the exact files. I couldn't pick the right ones.
      Yes except I don't think asbestos installs on 3.41

      Sent from my SPH-M580 using Tapatalk 2

    259. andrewrich
      07-24-2012
      08:49 PM
      259

      could any one help with this error

      Microsoft Windows [Version 6.1.7601]
      Copyright (c) 2009 Microsoft Corporation. All rights reserved.

      C:\Users\Andy>C:\dump_rootkey\dump_rootkey.exe 92.30.157.212
      [INFO] Connecting to '92.30.157.212'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [ERROR] Could not open './data/metldr'.
      [ERROR] Could not open './data/dumper'.
      3 [main] dump_rootkey 2984 exception::handle: Exception: STATUS_ACCESS_VIO
      LATION
      743 [main] dump_rootkey 2984 open_stackdumpfile: Dumping stack trace to dump
      _rootkey.exe.stackdump

      C:\Users\Andy>
      .................................................................................................

      I have the my metldr in the data folder and so is the dumper. i am also on 3.41 mfw
      with the suggested patches. I dont know what could be wrong. Can any one help?

    260. kneeandarrow
      07-24-2012
      08:52 PM
      260

      Still on square one:

      I am on 3.41 MFW with peek/poke.

      I have tried all these asbestos_ldr.g.pkg's but some of them gave error when I try to install from "Install package files" menu.( naehrwert 's pachake file cannot be installed but some on the thread seems good but don't know if they are for me)

      - Should the asbestos_ldr.g.pkg be specific to my PS3 IP?
      - I have windows so which dump_rootkey.exe should I use or do I have to make (my ps3 IP is 192.168.1.5) ? There are so many ones on the thread but some stuck on "Ip adress ..OK" screen, some stuck on "PING..." screen.

    261. rrr159
      07-24-2012
      08:52 PM
      261

      Originally Posted by andrewrich View Post
      could any one help with this error

      Microsoft Windows [Version 6.1.7601]
      Copyright (c) 2009 Microsoft Corporation. All rights reserved.

      C:\Users\Andy>C:\dump_rootkey\dump_rootkey.exe 92.30.157.212
      [INFO] Connecting to '92.30.157.212'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [ERROR] Could not open './data/metldr'.
      [ERROR] Could not open './data/dumper'.
      3 [main] dump_rootkey 2984 exception::handle: Exception: STATUS_ACCESS_VIO
      LATION
      743 [main] dump_rootkey 2984 open_stackdumpfile: Dumping stack trace to dump
      _rootkey.exe.stackdump

      C:\Users\Andy>
      .................................................................................................

      I have the my metldr in the data folder and so is the dumper. i am also on 3.41 mfw
      with the suggested patches. I dont know what could be wrong. Can any one help?
      Create a command prompt shortcut inside the directory where the rootkey.exe is and then try it

      Sent from my SPH-M580 using Tapatalk 2

    262. kneeandarrow
      07-24-2012
      08:56 PM
      262

      [MENTION=119271]andrewrich[/MENTION]

      Which dump_rootkey.exe do you use? Is it a specially compiled for the IP adress? And which asbestos_ldr.g.pkg you are using?

    263. andrewrich
      07-24-2012
      09:09 PM
      263

      Which dump_rootkey.exe do you use? = dump_rootkey modifie par Attila.zip

      which asbestos_ldr.g.pkg you are using? = the original one



      Originally Posted by kneeandarrow View Post
      [MENTION=119271]andrewrich[/MENTION]

      Which dump_rootkey.exe do you use? Is it a specially compiled for the IP adress? And which asbestos_ldr.g.pkg you are using?
      ************* [ - Post Merged - ] *************
      Originally Posted by rrr159 View Post
      Create a command prompt shortcut inside the directory where the rootkey.exe is and then try it

      Sent from my SPH-M580 using Tapatalk 2


      ok mate tried that and it did not work here is a pic to see if you can see anything wrong.

    264. rrr159
      07-24-2012
      09:45 PM
      264

      Ill try to help u more. Once I get home. But right now try to use cd to the directory and then drag the exe and type in ip and enter. Btw are u using ethernet or wifi

      Sent from my SPH-M580 using Tapatalk 2

    265. zaphod
      07-24-2012
      09:46 PM
      265

      [MENTION=119271]andrewrich[/MENTION]

      open a cmd-window

      then type cd dump_rootkey /* to switch in that dir */
      then run the prog and all should be fine..

      the program use relative paths so you MUST change in the dir where the exe is...


      /sleepmode on

    266. andrewrich
      07-24-2012
      09:56 PM
      266

      Originally Posted by rrr159 View Post
      Ill try to help u more. Once I get home. But right now try to use cd to the directory and then drag the exe and type in ip and enter. Btw are u using ethernet or wifi

      Sent from my SPH-M580 using Tapatalk 2
      thanks for all your help so far its worked. just got to figure out what to do next?

      Microsoft Windows [Version 6.1.7601]
      Copyright (c) 2009 Microsoft Corporation. All rights reserved.

      C:\Users\Andy>cd c:/

      c:\>cd dump_rootkey

      c:\dump_rootkey>dump_rootkey.exe 92.30.157.212
      [INFO] Connecting to '92.30.157.212'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2 0x00004C00012E0000
      [INFO] problem 0x00004C00012C0000
      [INFO] LS 0x00004C0001280000
      [INFO] shadow 0x0000300000026000
      [INFO] ID 0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000011
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] -> mailbox interrupt
      [INFO] Mailbox value = 1
      [INFO] -> Dumper loaded.
      [INFO] Transferring eid_root_key to buffer...finished.
      [INFO] Dumping eid_root_key...done.
      [INFO] SPU status = 0x00000081
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.
      [INFO] Press any key to exit...
      ************* [ - Post Merged - ] *************
      Originally Posted by zaphod View Post
      [MENTION=119271]andrewrich[/MENTION]

      open a cmd-window

      then type cd dump_rootkey /* to switch in that dir */
      then run the prog and all should be fine..

      the program use relative paths so you MUST change in the dir where the exe is...


      /sleepmode on

      you really helped me out there thanks.
      will prob be thanking you later on when i get stuck again, its just a matter of time lol

    267. rrr159
      07-24-2012
      10:01 PM
      267

      Originally Posted by andrewrich View Post
      thanks for all your help so far its worked. just got to figure out what to do next?

      Microsoft Windows [Version 6.1.7601]
      Copyright (c) 2009 Microsoft Corporation. All rights reserved.

      C:\Users\Andy>cd c:/

      c:\>cd dump_rootkey

      c:\dump_rootkey>dump_rootkey.exe 92.30.157.212
      [INFO] Connecting to '92.30.157.212'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2 0x00004C00012E0000
      [INFO] problem 0x00004C00012C0000
      [INFO] LS 0x00004C0001280000
      [INFO] shadow 0x0000300000026000
      [INFO] ID 0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000011
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] -> mailbox interrupt
      [INFO] Mailbox value = 1
      [INFO] -> Dumper loaded.
      [INFO] Transferring eid_root_key to buffer...finished.
      [INFO] Dumping eid_root_key...done.
      [INFO] SPU status = 0x00000081
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.
      [INFO] Press any key to exit...
      Get cex2dex application and load up this and the original flash I think. Then it gives u a flash in which u take to mmOS. Before u do, rename to mydexflash.eid0.norbin. then open up in mmos. When u click it gives u 3 questions. Say yes to all, then flash. Boom done. Then get dex 4.11 and install via xmb.

      Sent from my SPH-M580 using Tapatalk 2

    268. andrewrich
      07-24-2012
      10:06 PM
      268

      Originally Posted by rrr159 View Post
      Get cex2dex application and load up this and the original flash I think. Then it gives u a flash in which u take to mmOS. Before u do, rename to mydexflash.eid0.norbin. then open up in mmos. When u click it gives u 3 questions. Say yes to all, then flash. Boom done. Then get dex 4.11 and install via xmb.

      Sent from my SPH-M580 using Tapatalk 2
      great news thanks again for the help.
      oh and one more thing if you don't mind
      before i do this can i all ways go back to cex if i want to if so would i just install from xmb

    269. rrr159
      07-24-2012
      10:31 PM
      269

      I think u can. I'm not hundred percent sure though

      Sent from my SPH-M580 using Tapatalk 2

    270. andrewrich
      07-24-2012
      10:37 PM
      270

      Originally Posted by rrr159 View Post
      I think u can. I'm not hundred percent sure though

      Sent from my SPH-M580 using Tapatalk 2
      could i update back to 3.55 mfw and then flash with mm

    271. rrr159
      07-24-2012
      11:02 PM
      271

      Originally Posted by andrewrich View Post
      could i update back to 3.55 mfw and then flash with mm
      I feel like u shud be able to. But there is no need. It won't make a difference. Why wat r u tryinh to do

      Sent from my SPH-M580 using Tapatalk 2

    272. andrewrich
      07-24-2012
      11:15 PM
      272

      Originally Posted by rrr159 View Post
      I feel like u shud be able to. But there is no need. It won't make a difference. Why wat r u tryinh to do

      Sent from my SPH-M580 using Tapatalk 2
      just thinking now that i have made my dex flash maybe to wait until someone confirms that i can go back to cex. I was reading on a tut and it said i had to look in eid_root_key.bin with hex editor and find my keys. how would i find them?

    273. rrr159
      07-24-2012
      11:17 PM
      273

      Originally Posted by andrewrich View Post
      just thinking now that i have made my dex flash maybe to wait until someone confirms that i can go back to cex. I was reading on a tut and it said i had to look in eid_root_key.bin with hex editor and find my keys. how would i find them?
      Find ur keys for going back to cex?

      Sent from my SPH-M580 using Tapatalk 2

    274. Atrion
      07-24-2012
      11:23 PM
      274

      Can someone explain to me what I may be doing wrong while trying to downgrade to 3.41. I installed OtherOS for QA... Installed QA Extra, Ran qa Extra, got the beeps, tested the button combo and was working. shutdown PS3, started it up with proper way to get into recovery menu, but in stead of loading recovery menu it boots me into Petiboot (Installed from something else I did before).

      I also tried Using Rebug 3.55 and using there QA tool, installed and ran it, it worked, shutdown, loaded up into Recovery menu fine but when it searched for the update on my thumbdrive it says corrupt (I re-downloaded file and tried again to make sure it wasn't my file.

      any help in why this isn;t working for me would be great.

    275. andrewrich
      07-24-2012
      11:36 PM
      275

      Originally Posted by rrr159 View Post
      Find ur keys for going back to cex?

      Sent from my SPH-M580 using Tapatalk 2
      no the tut was for cex2dex and said this.

      Copy your newly created “dump_eid0.bin” file to your USB and plug it back into your PC

      28.
      Copy the “dump_eid0.bin” & your “355CEX.NORBIN” into the c2d.exe folder (copy C2D.exe folder to root of C drive for ease of use)

      29.
      Open your “dump_eid0.bin” in a hexeditor of you choosing (I used HXD) and extract your keys - keys are either at start of the file (0x00 - 0x2f) or somewhere else. You can find the right location by searching the dump. You can search for bytes 0x00-0x10 and you may find the proper erk/iv at 0xc0*** location

      30.
      Highlight and copy your keys (3 lines) and create a new file in your hex program, paste your keys in and save it as “keys.BIN”
      .......................................................................................................................

      so i am guessing i must of skipped getting my keys which i will probably need to make the dex flash

    276. rrr159
      07-25-2012
      12:00 AM
      276

      Originally Posted by andrewrich View Post
      no the tut was for cex2dex and said this.

      Copy your newly created “dump_eid0.bin” file to your USB and plug it back into your PC

      28.
      Copy the “dump_eid0.bin” & your “355CEX.NORBIN” into the c2d.exe folder (copy C2D.exe folder to root of C drive for ease of use)

      29.
      Open your “dump_eid0.bin” in a hexeditor of you choosing (I used HXD) and extract your keys - keys are either at start of the file (0x00 - 0x2f) or somewhere else. You can find the right location by searching the dump. You can search for bytes 0x00-0x10 and you may find the proper erk/iv at 0xc0*** location

      30.
      Highlight and copy your keys (3 lines) and create a new file in your hex program, paste your keys in and save it as “keys.BIN”
      .......................................................................................................................

      so i am guessing i must of skipped getting my keys which i will probably need to make the dex flash
      R u on nand? Also, use the gunner54 app to get new flash dump.

      Sent from my SPH-M580 using Tapatalk 2

    277. rrr159
      07-25-2012
      12:02 AM
      277

      Originally Posted by Atrion View Post
      Can someone explain to me what I may be doing wrong while trying to downgrade to 3.41. I installed OtherOS for QA... Installed QA Extra, Ran qa Extra, got the beeps, tested the button combo and was working. shutdown PS3, started it up with proper way to get into recovery menu, but in stead of loading recovery menu it boots me into Petiboot (Installed from something else I did before).

      I also tried Using Rebug 3.55 and using there QA tool, installed and ran it, it worked, shutdown, loaded up into Recovery menu fine but when it searched for the update on my thumbdrive it says corrupt (I re-downloaded file and tried again to make sure it wasn't my file.

      any help in why this isn;t working for me would be great.
      If it says corrupted it means u can't download to 3.41. Its not allowed on ur ps3

      Sent from my SPH-M580 using Tapatalk 2

    278. Atrion
      07-25-2012
      12:05 AM
      278

      Originally Posted by rrr159 View Post
      If it says corrupted it means u can't download to 3.41. Its not allowed on ur ps3

      Sent from my SPH-M580 using Tapatalk 2
      well then.. that sucks... hopefully someone will get a way for us to use this app on 3.55 then...

    279. andrewrich
      07-25-2012
      12:12 AM
      279

      Originally Posted by rrr159 View Post
      R u on nand? Also, use the gunner54 app to get new flash dump.

      Sent from my SPH-M580 using Tapatalk 2
      no on nor. my dump is 48 bytes is this right. basically what i want to know is how do i check to see if i have the right keys

    280. rrr159
      07-25-2012
      12:14 AM
      280

      Alright, get the original cex2dex by gunnerhd. And use that.. it'll work for sure

      Sent from my SPH-M580 using Tapatalk 2

    281. rrr159
      07-25-2012
      12:14 AM
      281

      Remember to thank me /rep me

      Sent from my SPH-M580 using Tapatalk 2

    282. Atrion
      07-25-2012
      01:39 AM
      282

      has anyone figured out a way to compile the pkg for 3.55? or figure out if there is another app that might work for it? I ask as it seems my slim can only downgrade to 3.50 so this pkg is a no go for me...

    283. JayDee78
      07-25-2012
      01:56 AM
      283

      Here goes:

      Tools you need:

      C2D
      or
      CEX2DEX

      Memdump_0.01-FINAL
      To read and save a flash dump to your USB

      Multiman 20120722 (link is from deanks tutorial)
      To install/flash EIDO when your dex flashdump is done

      OFW 3.41
      OFW 3.41 Mirror

      MFW 3.41
      MFW 3.41 Mirror
      MFW 3.41 Mirror
      MFW 3.41 Mirror
      This is the pup i myself used, with the patches added, use if you trust me..
      Get OFW and do it yourself otherwise


      MFW builder 0.2
      To make your ofw 3.41 into a mfw 3.41

      Dump_rootkey modifie par Attila
      No need to compile dump_rootkey as it is done for you in this zip
      Use like this: c:\dump_rootkey\dump_rootkey 192.168.2.186

      Optional:
      http://rebug.me/toggle-qa/



      On the PS3:

      Lets start with installing memdump (PLACE USB IN SLOT NEAREST TO POWER IN THE FRONT) and dump the flash with X.
      On NOR (AND THIS IS A NOR GUIDE ONLY) it should take like 5 seconds.

      On PC:

      When done take the dump to the pc and copy it to the CEX2DEX folder and start the program, load the flash*.bin and extract metldr.
      SAVE A BACKUP OF YOUR UNTOUCHED FLASH!!!

      Take the metldr and copy it to the data folder in the dump_rootkey folder on your PC

      On the PS3:

      I presume you are on CFW 3.55 for this AND CAN DOWNGRADE TO 3.41. MAKE SURE YOU CAN BEFORE CONTINUING

      Install the asbestos_ldr.pkg

      Install the 20120722 version of multiman (do not try and upgrade from within MM, wont work) Just google for it

      Prepare so you can downgrade easy (qa toogle´d machines are far faster, so I went this road.) How YOU downgrade is up to you, and if you do not know how, then stop right now and DO NOT CONTINUE before you are 100% sure what you do!

      On PC:

      Start mfw builder and load your OFW 3.41

      Tick these options:

      Code:
      Patch LV1 hypervisor
      Patch LV2 kernel
      Patch package installer
      Patch application launcher
      Save and flash on the PS3.

      On the PS3:

      When it is in XMB check your IP and then launch asbestos_ldr

      On PC:
      Start a cmd window and cd to your dump_rootkey folder

      Issue command; dump_rootkey 192.168.*.*

      *=PS3 ip

      Unicorns! (FINALLY!)

      In the dump_rootkey folder you now have eid_root_key.bin

      Copy this to your CEX2DEX folder and rename it to dump (no file extension) and put it in the metldr dump row. (Notice your flash*.bin should also be loaded)

      Save as my-DEX-flash.EID0.bin

      Close CEX2DEX

      Rename your my-DEX-flash.EID0.bin to my-DEX-flash.EID0.NORBIN and place on usb.

      On the PS3:

      Insert usb and start multiman.

      Navigate to your "my-DEX-flash.EID0.NORBIN" and double-click on it. You should get a 3x yes/no promt (choose yes on all to flash the dex eido part)
      Should give you a Success and then you reboot.

      Now you can flash a DEX fw from XMB (I used Itskamel´s 3.55, but will go to rogero so i can downgrade with ease)

      You are now on a DEX PS3...

      w00t?

      If you screw up, do not come and blame me. No one is forcing you to do this....

    284. killerninja
      07-25-2012
      01:59 AM
      284

      Thanks for the tut

    285. Hannibal1471
      07-25-2012
      02:07 AM
      285

      Start a cmd window and cd to your dump_rootkey folder
      what does start a cd mean

    286. JayDee78
      07-25-2012
      02:10 AM
      286

      Originally Posted by Hannibal1471 View Post
      what does start a cd mean
      One of the most BASIC dos commands ever

      cd = change directory

      ie: "cd c:\dump_rootkey" takes you directly to this folder

      This is really really basic stuff. No offense, but are you sure you know what you are doing?! Think twice, one screw up and you might have a brick...

    287. Hannibal1471
      07-25-2012
      02:12 AM
      287

      Oops sorry, I forgot

      If I do what you described, nothing can go wrong, right?

      Never mind, I'll use linux.

    288. JayDee78
      07-25-2012
      02:17 AM
      288

      Originally Posted by Hannibal1471 View Post
      Oops sorry, I forgot

      If I do what you described, nothing can go wrong, right?

      Never mind, I'll use linux.
      No one can ever say too 100% it will work, but i have now done four PS3´s and all work fine.

      The big risk is if you flash the WHOLE nor. Just flash the eido parts (with multiman or linux) and you minimize the risk!

      No 100% guarantee, on any method!

    289. Hannibal1471
      07-25-2012
      02:19 AM
      289

      Originally Posted by JayDee78 View Post
      No one can ever say too 100% it will work, but i have now done four PS3´s and all work fine. The big risk is if you flash the WHOLE nor. Just flash the eido parts (with multiman or linux) and you minimize the risk!

      No 100% guarantee, on any method!
      Well, how could we flash whole NOR?

      It's just a question, I'm sure I'm going to double click, with multiman.

    290. JayDee78
      07-25-2012
      02:21 AM
      290

      Originally Posted by Hannibal1471 View Post
      Well, how could we flash whole NOR?

      It's just a question, I'm sure I'm going to double click, with multiman.
      jaicrab preloader flashes whole nor.

      multiman do not

    291. Hannibal1471
      07-25-2012
      02:23 AM
      291

      Ok, thank you.

    292. Asure
      07-25-2012
      02:31 AM
      292

      Anyway, how about dumping the local storage afterwards?

      http://www.ps3hax.net/showpost.php?p...9&postcount=48

    293. kneeandarrow
      07-25-2012
      02:48 AM
      293

      Originally Posted by andrewrich View Post
      Which dump_rootkey.exe do you use? = dump_rootkey modifie par Attila.zip

      which asbestos_ldr.g.pkg you are using? = the original one


      Will I have to edit them?

    294. danixleet
      07-25-2012
      03:33 AM
      294

      http://www.mediafire.com/?ng5os9oqgtttpaw


      i made the edit of dump_rootkey.exe before i relized attila did it, lol pack includes prettyy much everything needed for this method.. go for it.. you brick your fault lol.


      this is not for the simple minded sorry but its not..

      use the includes bat file to run the dump_key just replace with your ip.

    295. haz367
      07-25-2012
      03:42 AM
      295

      Originally Posted by kneeandarrow View Post
      I am already on 3.41 MFW , I need just the exact files. I couldn't pick the right ones.
      if u can't install the original pkg(error istalling) use my repacked one a couple posts back and use the original dump_rootkey package, edit main.cpp and build exe file, if u tell me wich IP u are using i build the exe for u if u like, then simply connect PS3-PC and dump rootkey

    296. zizoux
      07-25-2012
      03:53 AM
      296

      Finally I was able to dump the rootkey.
      I used cmd instead of cygwin.bat and also gave ps3 a IP addres.
      directly connected to pc. No router.

    297. kneeandarrow
      07-25-2012
      04:19 AM
      297

      Originally Posted by haz367 View Post
      if u can't install the original pkg(error istalling) use my repacked one a couple posts back and use the original dump_rootkey package, edit main.cpp and build exe file, if u tell me wich IP u are using i build the exe for u if u like, then simply connect PS3-PC and dump rootkey
      Thanks

      PS3 is 192.168.1.5
      PC is 192.168.1.2
      Router is 192.168.1.1

      I tried all the dump_rootkey exe files,
      But stuck at :

      c:\test\>dump_rootkey 192.168.1.5
      connecting to 192.168.1.5 . OK

    298. haz367
      07-25-2012
      04:57 AM
      298

      assuming u have everything ready(341 lv2 peek/poke)
      then this should work fine
      http://dl.dropbox.com/u/19078406/dump_rootkey.rar
      drop "metldr" from console into "data"

      if not..pls check ur connection between PS3/router, make sure nothing is blocked or add the trusted ip's to dump_rootkey in firewall and ping must be allowed, each setup is diff..if it fails check ur firewall/router settings, it worked out of the box for me connected to the wired router

    299. zizoux
      07-25-2012
      06:39 AM
      299

      Is eid_root_key.bin 1kb?
      It's supposed to be 256kb but it dumps 1kb

    300. gsgm
      07-25-2012
      07:51 AM
      300

      So guys... Nothing for 3.55 cfw? Is there a working version for us on 3.55?

    301. DEFAULTDNB
      07-25-2012
      08:14 AM
      301

      I would love a KMEAW version

    302. stussy1
      07-25-2012
      08:24 AM
      302

      Originally Posted by Atrion View Post
      has anyone figured out a way to compile the pkg for 3.55? or figure out if there is another app that might work for it? I ask as it seems my slim can only downgrade to 3.50 so this pkg is a no go for me...
      Did it come with 3.50 mine did but when i tryed minverchk
      And told me i can downgrade to 3.15 or somewhere there

      http://www.ps3hax.net/2011/07/offici...ate-on-jfw-dh/

    303. zizoux
      07-25-2012
      09:57 AM
      303

      I am good to go, right?

    304. JayDee78
      07-25-2012
      10:32 AM
      304

      Originally Posted by zizoux View Post
      I am good to go, right?
      Just go for it.

      Load flash, load dump, click cex2dex. Save new bin and check window for "cmac dex: pass"
      Shouldn´t even give you a option to save a new bin if the dump file is incorrect, now when i think about it, so just try and then follow the rest of my guide a page or two back...

    305. zizoux
      07-25-2012
      10:56 AM
      305

      when i try to flash my-DEX-flash.EID0 in mmOS
      ''error writing to flash EID0''
      flashing doesn't start att all

      edit: I think I should install multiMAN ver 04.04.03 BASE CEX DEX

    306. JayDee78
      07-25-2012
      11:00 AM
      306

      Originally Posted by zizoux View Post
      when i try to flash my-DEX-flash.EID0 in mmOS
      ''error writing to flash EID0''
      flashing doesn't start att all
      You are 100% sure you are using the 20120722 multiman and not the 20120721

      20120721 gives error on writing the eido

      Tutorial post updated: http://www. p s 3 c r u n c h .net/forum/threads/4111-C2D-EXE-v2-%28PS3-Flash-Patcher%29-Now-Allows-Users-to-Modify-Region-TargetID-Settings?p=45668#post45668

      * New link to mM: multiMAN ver 04.04.03 BASE CEX DEX (20120722)
      * New links for the complete packages
      * Included cygwin DLL files in "norunpack" folder

      DO NOT USE OLDER (20120721) VERSIONS OF MM IF GOING TO FLASH NOR EID0 (you will get an error / nor flash won't be changed). USE 20120722 LINK.

    307. Atrion
      07-25-2012
      11:09 AM
      307

      Originally Posted by stussy1 View Post
      Did it come with 3.50 mine did but when i tryed minverchk
      And told me i can downgrade to 3.15 or somewhere there

      http://www.ps3hax.net/2011/07/offici...ate-on-jfw-dh/
      I am going by what someone else posted (Sry I forget your screen name) who said if after trying multiple times you got corrupt data it meant it would not install. The minimum version checker PUP would not work for me, never has. as for what it came on when I got it, i think 3.50 but I really n ot to sure that was awhile ago now...

    308. stussy1
      07-25-2012
      11:16 AM
      308

      Originally Posted by Atrion View Post
      I am going by what someone else posted (Sry I forget your screen name) who said if after trying multiple times you got corrupt data it meant it would not install. The minimum version checker PUP would not work for me, never has. as for what it came on when I got it, i think 3.50 but I really n ot to sure that was awhile ago now...
      Did you install it right sounds od never had that problem


      PS3/UPDATE/UPDATE.PUP

    309. Atrion
      07-25-2012
      11:19 AM
      309

      Originally Posted by stussy1 View Post
      Did you install it right sounds od never had that problem


      PS3/UPDATE/UPDATE.PUP
      yes I am aware of how to install updates. every time I have done it from USb it errors out (But not in the way it supposed to) and If I put it in my updater folder (The way of installing firmware from the harddrive) it just makes the whole thing error and not even allow me access to my other firmwares until I go in and delete it from that folder.

    310. JayDee78
      07-25-2012
      11:24 AM
      310

      Just a little self bump:

      http://www.ps3hax.net/showpost.php?p...&postcount=284

      Updated my guide with downloads etc etc.
      This is for those who can downgrade to 3.41

    311. andrewrich
      07-25-2012
      11:44 AM
      311

      Originally Posted by kneeandarrow View Post
      Will I have to edit them?
      no i did not edit them just used them as they were.

    312. greyestest
      07-25-2012
      01:11 PM
      312

      Originally Posted by zizoux View Post
      Finally I was able to dump the rootkey.
      I used cmd instead of cygwin.bat and also gave ps3 a IP addres.
      directly connected to pc. No router.

      Oh that's great, how about mini tutorial about how to do it without router?

    313. zizoux
      07-25-2012
      01:31 PM
      313

      Originally Posted by greyestest View Post
      Oh that's great, how about mini tutorial about how to do it without router?
      Download and install tftpd32. Under the dhcp server tab, you'll see ps3's IP address. If you can't see, manually configure your network setting on the ps3.
      I did it like this
      i.e:
      IP: 192.168.2.7
      Default router: 192.168.2.1
      Mask: 255.255.255.0
      Dns1: 4.2.2.2
      dns2: 4.2.0.0

      If you still cannot see, set them as auto

      Should you see the ps3 address under the dhcp server tab
      Launch asbestos
      Open CMD.
      type
      cd desktop (If your dump_rootkey folder is on desktop)
      cd dump_rootkey
      dump_rootkey Your-Ps3's-IP
      thats pretty much it

    314. greyestest
      07-25-2012
      01:41 PM
      314

      Thank you.

      May I connect PC-PS3 with the cable that connects my adsl router and PC (there is "cat 5 patch" mark on it)?

      PS: my router has only one port so I cannot use it for this method.

    315. a$h x
      07-25-2012
      01:52 PM
      315

      Can someone please upload a 3.41 PUP with peek + poke etc as I'm trying to gather all the files necessary for MFW builder, but all sources are dead including git-hacks.

    316. zizoux
      07-25-2012
      01:59 PM
      316

      Originally Posted by a$h x View Post
      Can someone please upload a 3.41 PUP with peek + poke etc as I'm trying to gather all the files necessary for MFW builder, but all sources are dead including git-hacks.

      http://www.ps3hax.net/downloads.php?do=file&id=407

    317. Eiji
      07-25-2012
      02:12 PM
      317

      Can this be done if you connect to the PS3 through a router BRIDGE?

    318. a$h x
      07-25-2012
      02:12 PM
      318

      Thanks, is that the OFW 3.41 or a modified version? Anyway, I found the files i was looking for so I built my own CFW 3.41 and am testing it right now. If it works I'll upload it so others can use it.

    319. JayDee78
      07-25-2012
      02:26 PM
      319

      Originally Posted by a$h x View Post
      Thanks, is that the OFW 3.41 or a modified version? Anyway, I found the files i was looking for so I built my own CFW 3.41 and am testing it right now. If it works I'll upload it so others can use it.
      Appending the pup i made/used with mfw builder in my guide for those who feel safe with having it done for them by a stranger :D

    320. Eiji
      07-25-2012
      02:33 PM
      320

      Originally Posted by Eiji View Post
      Can this be done if you connect to the PS3 through a router BRIDGE?
      Just to confirm, UNICORNS!

      Thanks JayDee78 for your guide. I am now on DEX!

    321. pSydeFX
      07-25-2012
      02:40 PM
      321

      JayDee78 does your 3.41 mfw multipload link work? i get redirected to some internet vs hollywood site

    322. Asure
      07-25-2012
      02:44 PM
      322

      I modified the exploit a tiny bit, to dump 4096 bytes. There's part of the dumper code still inside when it dumps the eid0 root key it seems. (offset at 0x180 the dumper code starts)

      There is also a bunch of unknown data at 0x30 - 0x180

      I wonder if this somehow can be used (in some shape or form) with lv0 from 3.60 for example.

    323. JayDee78
      07-25-2012
      02:46 PM
      323

      Originally Posted by pSydeFX View Post
      JayDee78 does your 3.41 mfw multipload link work? i get redirected to some internet vs hollywood site


      Works here...

    324. pSydeFX
      07-25-2012
      02:50 PM
      324

      Originally Posted by JayDee78 View Post


      Works here...
      hmmm. must be adblock plus thats messin it up

    325. shellz1222
      07-25-2012
      09:16 PM
      325

      JayDee78 i am also getting the internet vs hollwood page when trying to download your 3.41 mfw i tried making my own custom firmware but it never finds mine when i try to update in recovery mode could you upload it again please

    326. Atrion
      07-25-2012
      09:20 PM
      326

      anyone had any luck figuring out a way to have this work on 3.55 as downgrading to 3.41 is not an option for my slim Ps3 (3.50 lowest)

    327. jacku123
      07-25-2012
      09:34 PM
      327

      hi, minverchk shows 3.50 is the lowest fw in my ps3...can anyone confirm whether i can downgrade my ps3 frm 3.55 to 3.41 using http://www.ps3hax.net/2011/06/qa-fla...3-15-tutorial/ this method or any other method plz...because i cant afford another ps3

    328. Atrion
      07-25-2012
      09:39 PM
      328

      Originally Posted by jacku123 View Post
      hi, minverchk shows 3.50 is the lowest fw in my ps3...can anyone confirm whether i can downgrade my ps3 frm 3.55 to 3.41 using http://www.ps3hax.net/2011/06/qa-fla...3-15-tutorial/ this method or any other method plz...because i cant afford another ps3
      nope if thats the minimum version then you cant go lower than that, Im in the same boat

    329. aldostools
      07-25-2012
      09:52 PM
      329

      Originally Posted by Atrion View Post
      nope if thats the minimum version then you cant go lower than that, Im in the same boat
      In that case, use deank's tutorial to get the dump_eid0.bin with metldrpwn via Red Ribbon linux (or wait for a fix of asbestos_ldr.g.pkg on 3.55).

      I got the dump following carefully deank's tutorial and it was not difficult...

    330. Atrion
      07-25-2012
      09:55 PM
      330

      Originally Posted by aldostools View Post
      In that case, use deank's tutorial to get the dump_eid0.bin with metldrpwn via Red Ribbon linux (or wait for a fix of asbestos_ldr.g.pkg on 3.55).

      I got the dump following carefully deank's tutorial and it was not difficult...
      yeah I had linux on my PS3 before (Installed to USB drive instead of internal) was a bit of a hassle for me, would rather wait a bit longer in hopes of this pkg being fixed for 3.55 or some other method.

      Any chance another app like BootOS2.1 or Asbestos for 3.55 would work, I don't have much knowledge on the topic so I don't know the difference between asbestos ldr and asbestos is.

    331. Bereuza
      07-25-2012
      10:12 PM
      331

      Hey JayDee78 have you tested your method via wireless? Or have all your tests been done over a wired connection? I have a router configured for sometime now, I can see my ps3 just fine and sometimes ping it's IP on FlashFXP to tranfers some files every now and then and would like to know if anyone here have sucessfully converted to DEX via wireless. Thank you for your tutorial by the way, I'd be checking if I can downgrade to 3.41 fw and convert my currently Kmeaw console. Cheers!

    332. JayDee78
      07-26-2012
      12:28 AM
      332

      Originally Posted by Bereuza View Post
      Hey JayDee78 have you tested your method via wireless? Or have all your tests been done over a wired connection? I have a router configured for sometime now, I can see my ps3 just fine and sometimes ping it's IP on FlashFXP to tranfers some files every now and then and would like to know if anyone here have sucessfully converted to DEX via wireless. Thank you for your tutorial by the way, I'd be checking if I can downgrade to 3.41 fw and convert my currently Kmeaw console. Cheers!
      Only with wired connection to PS3. Using a wifi repeater so i do not need to have a 20 meter cable from the pc to the PS3.

      PC->ROUTER->REPEATER->PS3

    333. Bereuza
      07-26-2012
      02:35 AM
      333

      Much obliged!

    334. MakinaCore
      07-26-2012
      03:22 AM
      334

      EDITED


      whats the best firmware to get QA FLAGGING TO WORK ?

      i have tryed that special CFW other os++ does not work ? any help thanks

    335. JayDee78
      07-26-2012
      04:08 AM
      335

      I do dont want to sound like a dick but please follow my guide a few pages back

    336. greyestest
      07-26-2012
      04:52 AM
      336

      Originally Posted by zizoux View Post
      Download and install tftpd32. Under the dhcp server tab, you'll see ps3's IP address. If you can't see, manually configure your network setting on the ps3.
      I did it like this
      i.e:
      IP: 192.168.2.7
      Default router: 192.168.2.1
      Mask: 255.255.255.0
      Dns1: 4.2.2.2
      dns2: 4.2.0.0

      If you still cannot see, set them as auto

      Should you see the ps3 address under the dhcp server tab
      Launch asbestos
      Open CMD.
      type
      cd desktop (If your dump_rootkey folder is on desktop)
      cd dump_rootkey
      dump_rootkey Your-Ps3's-IP
      thats pretty much it

      Can I use "Cat 5 Patch" cable to connect PC <-> PS3 for this "routerless" method to work, or only crossover will do?

    337. MakinaCore
      07-26-2012
      07:41 AM
      337

      well iam trying to downgrade 3.55 to 3.41 and the dam QA flag wont beep ? any help ?

    338. Gonzakpo
      07-26-2012
      08:55 AM
      338

      Originally Posted by MakinaCore View Post
      well i managed to get the nor flash from mm but when i plug my usb in to my laptop its not there ? tryed the folder options to se hidden files does not come up ? only shows in MM ?


      sorrry had to rename it then it came up lol


      right can someone tell me if this is correct ? thats after i clicked cex 2 dex


      - ROOT-KEY :
      - ROOT-IV :
      - EID0-KEY :
      - EID0-IV :
      - EID0-SECTION-KEY :
      - EID0-DATA-DECRYPT [CEX] :
      - CMAC-EID0 [CEX] :
      - CMAC :
      You don't want to make this info public. I think it could be used against you (eg. BAN!).

    339. RageNigga
      07-26-2012
      09:35 AM
      339

      WE NEED SOLUTION TO USE THIS METHOD WITHOUT FCKING ROUTER!!!
      !!!PS3 <-cable-> PC !!! it's wont work!

    340. greyestest
      07-26-2012
      09:38 AM
      340

      Originally Posted by RageNigga View Post
      WE NEED SOLUTION TO USE THIS METHOD WIHOUT FCKING ROUTER!!!
      !!!PS3 <-cable-> PC !!! it's wont work!

      Did you try what zizoux wrote? :


      Download and install tftpd32. Under the dhcp server tab, you'll see ps3's IP address. If you can't see, manually configure your network setting on the ps3.
      I did it like this
      i.e:
      IP: 192.168.2.7
      Default router: 192.168.2.1
      Mask: 255.255.255.0
      Dns1: 4.2.2.2
      dns2: 4.2.0.0

      If you still cannot see, set them as auto

      Should you see the ps3 address under the dhcp server tab
      Launch asbestos
      Open CMD.
      type
      cd desktop (If your dump_rootkey folder is on desktop)
      cd dump_rootkey
      dump_rootkey Your-Ps3's-IP
      thats pretty much it

    341. RageNigga
      07-26-2012
      09:44 AM
      341

      Originally Posted by greyestest View Post
      Did you try what zizoux wrote? :
      yep, not work.

    342. DEFAULTDNB
      07-26-2012
      09:47 AM
      342

      [MENTION=236189]RageNigga[/MENTION] Have you tried crossover cable?

    343. RageNigga
      07-26-2012
      09:55 AM
      343

      Originally Posted by DEFAULTDNB View Post
      [MENTION=236189]RageNigga[/MENTION] Have you tried crossover cable?
      yep, blackb0x or mm ftp works great.

    344. greyestest
      07-26-2012
      10:24 AM
      344

      RageNigga, matbe try 'Tiny DHCP Server'?

    345. pSydeFX
      07-28-2012
      04:23 PM
      345

      so any updates on a asbestos pkg for 3.55 ??

    346. z10m
      07-29-2012
      05:26 PM
      346

      Hi guys.
      I've downgraded my ps3 to 3.41 hermes cfw and installed ubuntu on virtual machine.
      dump_rootkey seem to connect to my ps3 fine but doesn't save the rootkey file.
      that's what i get:
      ziom@ziom-VirtualBox:~/dump_rootkey$ ./dump_rootkey
      [INFO] Connecting to '192.168.1.115'...ok.
      [INFO] Ping...ok.
      [INFO] VAS ID = 0x000000000000000B
      [INFO] map_lpar_memory_region(data): res = 0
      [INFO] Copying files out...done.
      [INFO] Constructing SPE...done. (res = 0)
      [INFO] priv2 0x00004C00012E0000
      [INFO] problem 0x00004C00012C0000
      [INFO] LS 0x00004C0001280000
      [INFO] shadow 0x0000300000026000
      [INFO] ID 0x0000000000000002
      [INFO] Setting up SPE...done.
      [INFO] map_lpar_memory_region(shadow) : res = 0
      [INFO] map_lpar_memory_region(problem) : res = 0
      [INFO] map_lpar_memory_region(priv2) : res = 0
      [INFO] map_lpar_memory_region(ls) : res = 0
      [INFO] set_spe_privilege_state_area_1_register : res = 0
      [INFO] Starting SPE in isolation mode...done.
      [INFO] Interrupt status (2, application) = 0x0000000000000012
      [INFO] -> stop-and-signal instruction trap
      [INFO] -> SPU mailbox threshold interrupt
      [INFO] SPU status = 0x00020282
      [INFO] Requesting SPE isolation exit and stop.
      [INFO] Destructing SPE...done.
      [INFO] Press any key to exit...

      any ideas.?

    347. zaphod
      07-29-2012
      05:47 PM
      347

      does your 3.41 cfw got the needed patches? lv1/lv2/peekpoke/run unsigned/ and so on as mentioned in the thread?

      did you copy the extracted metldr in the data dir from dump_rootkey?

    348. z10m
      07-30-2012
      02:31 AM
      348

      yes extracted metldr key is in data dir and 3.41 cfw is hermes v4 so it should have peek/poke and all.
      anyways i'm gonna try another 3.41 cfw if i can find one.
      which one shoul i try.?
      ************* [ - Post Merged - ] *************
      ok i tried 3.41 MFW made by JayDee78 in post 284 with same resoults.
      ************* [ - Post Merged - ] *************
      Yessss. finally obtained the eid_root_key.bin by using everything from post 284.
      Thank You JayDee78.