PS3Hax Network - Playstation 3 Hacks and Mods

PS3Hax Network - Playstation 3 Hacks and Mods (http://www.ps3hax.net/forums.php)
-   PS3 | Member News (http://www.ps3hax.net/forumdisplay.php?f=142)
-   -   How to Dump Lv0 :D (http://www.ps3hax.net/showthread.php?t=40067)

ben.ss7 07-14-2012 09:58 AM

How to Dump Lv0 :D
 
This is quite old but it's for those who are whining asking about 3.60+ keys. Basically to gain these keys you need to dump lv0. Decrypting lv0 is possible but you will need the bootloader keys which at this stage is quite difficult,because the bootloader decrypts the lv0 so unless you get bootloader keys you can't decrypt lv0, you can only dump lv0. Hope Noobs understand now :D

When lv0 is dumped it will contain the encrypted loaders. What you do is you decrypt the encrypted loaders with the metldr key so in other words dumping is the target, after dumping the loaders can be decrypted with metldr key and when decrypted=Keys

So thats out the way,:P

Now there are quite a few methods on how to dump lv0:
Cell reset line method in which you need a dual nor and signed lv1 (Mathieulh's method)
Dumping the ram at time when the ram holds the encrypted loaders before given to metldr (PsDev's Method)

Basically there's alot of whining going on and less research because if you actually dump the ram at a certain time before the loaders are given to metldr to run, and are held in the ram like PsDev said you can actually dump out the encrypted loaders by just dumping the ram using hardware.

Now to dump the ram you need a kernel module which maps out the real memory(AKA ram).
Now the rest is up to you how you use this kernel module but using hardware you insert this module and it will read out the real memory and dumping is the next step:D

Once dumped you basically got keys because you will dump the ram which will contain the encrypted loaders(appldr,rvkldr,isoldr etc) and you can decrypt these loaders with the metldr key.

Now have a go at dumping it now, Whining wont get you anywhere:D

Thanks to PsDev for his ram dump method and KaKaRoToKS for his kernel module

P.S I dont want any credit for this i just posted this so people can actually explore this method instead of whining and abusing other devs which is common :D

nevik 07-14-2012 10:38 AM

Quote:

Originally Posted by ben.ss7 (Post 392122)
This is quite old but it's for those who are whining asking about 3.60+ keys. Basically to gain these keys you need to dump lv0. Decrypting lv0 is possible but you will need the bootloader keys which at this stage is quite difficult,because the bootloader decrypts the lv0 so unless you get bootloader keys you can't decrypt lv0, you can only dump lv0. Hope Noobs understand now :D

When lv0 is dumped it will contain the encrypted loaders. What you do is you decrypt the encrypted loaders with the metldr key so in other words dumping is the target, after dumping the loaders can be decrypted with metldr key and when decrypted=Keys

So thats out the way,:P

Now there are quite a few methods on how to dump lv0:
Cell reset line method in which you need a dual nor and signed lv1 (Mathieulh's method)
Dumping the ram at time when the ram holds the encrypted loaders before given to metldr (PsDev's Method)

Basically there's alot of whining going on and less research because if you actually dump the ram at a certain time before the loaders are given to metldr to run, and are held in the ram like PsDev said you can actually dump out the encrypted loaders by just dumping the ram using hardware.

Now to dump the ram you need a kernel module which maps out the real memory(AKA ram) so i have attached it. Thanks to KaKaRoToKS

Now the rest is up to you how you use this kernel module but using hardware you insert this module and it will read out the real memory and dumping is the next step:D

Once dumped you basically got keys because you will dump the ram which will contain the encrypted loaders(appldr,rvkldr,isoldr etc) and you can decrypt these loaders with the metldr key.

Now have a go at dumping it now, Whining wont get you anywhere:D

Thanks to PsDev for his ram dump method and KaKaRoToKS for his kernel module

P.S I dont want any credit for this i just posted this so people can actually explore this method instead of whining and abusing other devs which is common :D


Sounds like it will work. Did you accomplish this and or what hardware did you use?

rafa11 07-14-2012 10:48 AM

Sounds wicked ;)
If it works, that is...

TheEvolution_PT 07-14-2012 12:19 PM

I smell a trolololol in this one...

oPolo 07-14-2012 12:28 PM

Only thing I will whine about is that PsDev gets credit for that. Honestly, its obvious and the first thing that imo comes to mind, when you think about getting the keys. Atleast for anyone with the slightest computer knowledge.
Anyone (or almost anyone) that needs to move around, learns to walk if they are capable of it. It has been like that for thousands of years. If some in the present comes about and suggest that people should walk to get around, should they get the credit connected with having made the present man walking?


Edit: Had he had more details to how it should be done, some specifics, then I would, have understood that he received the credit. Had he mentioned timings or contributed with anything new to concrete the abstraction of the theory on the PS3. Such as Team-Xecutor with their RGH exploit at which they state at which ns the cpu should receive a pulse of x ns on the cpu_rst line, then it was new. What he has suggested isn't actually new <.< And sorry if he has in fact mentioned elements relevant to the implementation of this already well known technique, which you just haven't mentioned. But as it's presented there, it actually makes him shame instead of making him glory, if he has stated this as his technique, which he should have known was obvious. It is a bit like Zadow with his findings that are not in the wiki, which defyboy points out is not, because it is assumed that people should know it already... I'm on an iPad so I'll keep it short, but look at the twitter conversations between defyboy and zadow, if you do not know what I mean.

By the way, _no_ hate towards Zadow, I haven't looked at what he has done myself, and I have seen/heard too little from 3th party sources, so I have no opinions about it.

calo 07-14-2012 02:15 PM

Quote:

Originally Posted by TheEvolution_PT (Post 392167)
I smell a trolololol in this one...

he's just refreshing everybody on the method's to get lv0. that is all.

furtsiv 07-14-2012 03:07 PM

hope it is the way that dongles use

tjhooker73 07-14-2012 03:54 PM

Old stuff is old. I didn't even have to read it and knew it was old.

oPolo 07-14-2012 04:11 PM

Quote:

Originally Posted by tjhooker73 (Post 392229)
Old stuff is old. I didn't even have to read it and knew it was old.

As calo said, he is just refreshing it for us, along with a tool to help facilitate it. The way he writes it, reflects that its known stuff and nothing new.

playerkp420 07-14-2012 04:20 PM

Quote:

Originally Posted by ben.ss7 (Post 392122)
This is quite old

The first 4 words clued me that it was old. LOL :D


All times are GMT -5. The time now is 04:25 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.