|
|
#271 |
|
Member
![]() Join Date: Oct 2011
Posts: 442
Likes: 1,259
Liked 45 Times in 40 Posts
Mentioned: 23 Post(s)
Tagged: 0 Thread(s)
|
nice guide
|
|
|
|
|
|
#272 |
|
Apprentice
![]() Join Date: Jul 2011
Location: Southeast Unite States
Posts: 15
Likes: 4
Liked 10 Times in 5 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
So am I correct in saying, for the end user, this MAY end up similar to the xbox360 jtag exploit i.e:
Install Linux (xell, xellous) boot to system, extract cpu keys (per console keys) Open and drop keys into your favorite bootmaker on pc Flash the nand with said image tailored to the specific system? (pkg or whatever) Or am I WAY off? |
|
|
|
|
|
#274 | |
|
Apprentice
Join Date: Nov 2011
Posts: 6
Likes: 3
Liked 8 Times in 4 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
"P.S. Oh! and btw, if you talented enough to make hardware to dump the shared lsa, you can decrypt any lv0 using this technique. " I think that will take some time... |
|
|
|
|
|
Likes: (1) |
|
|
#275 |
|
Member
![]() Join Date: Sep 2010
Location: In My World
Posts: 307
Likes: 954
Liked 138 Times in 75 Posts
Mentioned: 25 Post(s)
Tagged: 0 Thread(s)
|
i total agree with you Albert Wesker
![]() what really needs to be investigated is this tweet: http://twitter.com/#!/Mathieulh/stat...22170719436800 // verify metadata offset is not too big //if (data->self_header->metaOffset >= 0x800) //return 0x20; // (cont) http://tl.gd/e2te63 and this tweet: http://twitter.com/#!/Mathieulh/stat...76434690621441 Oh and btw, if you talented enough to make hardware to dump the shared lsa, you can decrypt any lv0 using this technique/exploit both of these hints are very interesting. with another self fail we could get later keys. if we dump a decrypted lv0 we get later keys. two ways right there to get later public keys. Last edited by luqi; 11-09-2011 at 02:50 PM. |
|
|
|
|
Likes: (2) |
|
|
#276 |
|
Member
![]() Join Date: Dec 2010
Posts: 42
Likes: 7
Liked 4 Times in 3 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
|
are bootldr and metldr not encryted with the same key eg the per console key so would this mean once i have my per console key from metldr could i use it to decrypt bootldr ? also from what i can fathom u need hardware to dump bootldr but gitbrew already has a dump of it is it public ? would my key decrypt there dump ? lol that just sounds awesome i know
|
|
|
|
|
|
#277 |
|
Member
![]() Join Date: Dec 2010
Posts: 42
Likes: 7
Liked 4 Times in 3 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
|
cool so what kinda hardware would i need would it be possible with e3 as my soldering skills are non existant
|
|
|
|
|
|
#278 | |
|
Member
![]() Join Date: Oct 2011
Posts: 68
Likes: 13
Liked 41 Times in 15 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
no disrespect, it just seems totally random and out of place to mention your girlfriend's tv watching habit in a hacking tutorial. anyways, here is hoping some permanent solution comes out of this. |
|
|
|
|
|
|
#279 |
|
Apprentice
![]() Join Date: Oct 2011
Posts: 22
Likes: 6
Liked 5 Times in 3 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
|
about hex2key
Just a quick question;
I've compiled hex2key (attached) and tried the first 3 hex line lunuxx posted above @231 and basically all I get is the ANSI code converted from hex code. Is this really what hex2key supposed to do? I mean we could easily get this with an hex editor or am I doing something wrong? Anyone have any idea? Rgrds |
|
|
|
|
Likes: (1) |
|
|
#280 | |
|
Homebrew Developer
![]() Join Date: Jun 2011
Posts: 175
Likes: 33
Liked 207 Times in 76 Posts
Mentioned: 21 Post(s)
Tagged: 0 Thread(s)
|
i cant do very much on the tv sometimes and id rather not bore everyone in the room by having the tv sit on a black screen fyi about the hex2key i fixed one and left a note on the wiki so there are 2 links to hex2key the edit is the one i slightly repaired all credit for the app goes to anon for creating it its supposed to make a binary file |
|
|
|
|
|
Likes: (1) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|