Originally Posted by Another_Anon
Congrats, you miss just a little part to decrypt retail self :P
You "just" jave to build a fself that run an external retail self, than you can read it from ram (decrypted) via core dump, via debugger or directly using the fself itself!
SDK samples explain how to do that, you just have to read them! :P
I forgot to say that i think (never tried)
it can be done also via Release Mode, if you run a fself homebrew you're allowed to trigger a core dump. if the fself runs the a retail eboot.bin and then throw an exemption you'll dump the decrypted elf directly from ram and the ps3 will do the work for you! :P
Originally Posted by JonahUK
Is it not possible to use the Debug Station Launcher (part of the SDK)?
That will launch whatever is mapped to app_home via LAN.
Also, its an fself that will launch a retail self.
No, it won't work that way! TM can only run fself not retail ones