|
|
#401 |
|
Apprentice
Join Date: Jun 2011
Posts: 5
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
|
I hate to burst everyone's bubble but this means nothing. The chain of trust was fixed by moving loaders into lv0.
Until lv0 is either dumped or decrypted, the loaders, and therefore the keys will remain just out of reach. Cold boot exploits are not possible because lv0 sets up the loaders table before passing execution to lv1. Decrypting lv0 requires pwning the bootloader_PE, which is very difficult. If you could sniff the flexio you might be able to dump it that way. Or you could use what is known about the CBE secure boot to preempt bootldr. I suggest the IBM docs as reading material. -adrianc |
|
|
|
|
|
#402 | ||
|
Senior Member
![]() Join Date: Sep 2010
Posts: 1,171
Likes: 601
Liked 621 Times in 372 Posts
Mentioned: 137 Post(s)
Tagged: 0 Thread(s)
|
![]() ![]() .... ![]() ************* [ - Post Merged - ] *************
|
||
|
|
|
|
|
#403 | |
|
Apprentice
Join Date: Jun 2011
Posts: 5
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
|
Metldr has no involvement with decrypting bootldr, for that you require a root key. -adrianc |
|
|
|
|
|
|
#404 | |
|
Senior Member
![]() Join Date: Sep 2010
Posts: 1,171
Likes: 601
Liked 621 Times in 372 Posts
Mentioned: 137 Post(s)
Tagged: 0 Thread(s)
|
thanks for clearing that up. Sorry for being a retard. Are you saying that the contents of METLDR are no help in decrypting bootldr\lv0. I think that's the general (mis)conception at the moment amongst the peons.You've got me curious here as Math seems to be saying that his leaked hack can be applied in principle to a dump a decrypted bootldr\lv0. Does his leaked hack actually provide any practical help with that or is it merely in a philosophical sense in your opinion? Cheers, |
|
|
|
|
|
|
#405 | |
|
Senior Member
![]() Join Date: Feb 2011
Posts: 1,481
Likes: 530
Liked 997 Times in 500 Posts
Mentioned: 483 Post(s)
Tagged: 0 Thread(s)
|
you know the one you told us all said you had to remove everything about yourself from the net (inc your twitter acc) also i thought you were banned from ps3hax for ripping ppl off over the ps3 development unit. very strange to see you back !! |
|
|
|
|
|
Likes: (1) |
|
|
#406 |
|
Member
![]() Join Date: Jan 2008
Posts: 203
Likes: 1
Liked 35 Times in 25 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
@adrianc
is the metldr and bootldr not encrypted with the same key? If so isn't it not entirely possible to sign and encrypt your own bootldr?
@baileyscream Don't start that crap again. That is a completely off topic post take it up somewhere else kthxbye. @baargle someone needs to explain how the general misconception is wrong first =/ In the case that is, the metldr exploit should still be a good basis for how to make a bootldr exploit. The issue with the bootldr exploit is you need a hardware hack unless there's a way to overwrite the bootldr software wise that I'm not thinking of (entirely possible I guess). Last edited by Elegant; 11-11-2011 at 01:40 PM. |
|
|
|
|
|
#407 |
|
Senior Member
![]() Join Date: Feb 2011
Posts: 1,481
Likes: 530
Liked 997 Times in 500 Posts
Mentioned: 483 Post(s)
Tagged: 0 Thread(s)
|
[QUOTE=Elegant;280387]
@baileyscream Don't start that crap again. That is a completely off topic post take it up somewhere else kthxbye.[QUOTE] i'm sorry i thought with this being a news post i was free to greet devs and also inform anyone who doesnt know just what sort of person he is. that way when he starts contradicting math they know weather or not to trust him. if thats so wrong than sorry |
|
|
|
|
|
#408 |
|
Apprentice
Join Date: Nov 2011
Posts: 2
Likes: 0
Liked 20 Times in 2 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
|
Metldr and bootldr use the same exact console key and this has been the same since the start. If you can Get your per console key(this exploit) you can decrypt the metldr, if you can decrypt the metldr you can decrypt the bootldr(and the lv0 and every other ldr).
|
|
|
|
|
Likes: (3) |
|
|
#409 |
|
Member
![]() Join Date: Sep 2010
Location: In My World
Posts: 306
Likes: 954
Liked 136 Times in 74 Posts
Mentioned: 25 Post(s)
Tagged: 0 Thread(s)
|
j89 ,
youre sure ? |
|
|
|
|
|
#410 | ||
|
Apprentice
Join Date: Jun 2011
Posts: 5
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
|
This exploit does not enable you to find the hardware root key, merely a much weaker derivative which exists to prove the secure loader has been authorised by hardware. |
||
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|