|
|
#31 | |
|
Member
![]() Join Date: Jan 2012
Posts: 35
Likes: 1
Liked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
But as far as the PS3, Zaf posted a PS3 dump. (http://www.ps3hax.net/showthread.php?t=32837).( As I stated before, I don't know much about console modifying, so give me leniency . . ) Let's say theoretically speaking, this would be the dump necessary to decrypt and find the exploit ? I'm assuming this is a dump of the PS3's recovery ( I may be wrong ). Somewhere in there, is bound to be some kind of exploit, no ? |
|
|
|
|
|
|
#32 | |
|
Senior Member
![]() Join Date: Mar 2008
Posts: 1,163
Likes: 322
Liked 467 Times in 260 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() ...and the worlds shall reconnect. |
|
|
|
|
|
|
#33 | |
|
Member
![]() Join Date: Jan 2012
Posts: 35
Likes: 1
Liked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Chain of Trust . . . Does it apply only to the NOR/NAND ? Or is this a method used throughout the entire file system ? Last edited by монтре; 01-09-2012 at 10:21 PM. |
|
|
|
|
|
|
#34 |
|
Senior Member
![]() Join Date: Mar 2008
Posts: 1,163
Likes: 322
Liked 467 Times in 260 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() ...and the worlds shall reconnect. |
|
|
|
|
|
#35 | |
|
Member
![]() Join Date: Jan 2012
Posts: 35
Likes: 1
Liked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Code:
+ bootldr decrypts lv0 which runs on PPU -> loaders INIT |
|
|
|
|
|
|
#36 |
|
Senior Member
![]() Join Date: Mar 2008
Posts: 1,163
Likes: 322
Liked 467 Times in 260 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
|
That's the 3.60+ diagram, note that the dump that you will do will be already encrypted, so there's no point in doing so. You need to force your PS3 decrypt itself, inside the process of bootup which is not easily done without breaking the chain of trust plus you need to decrypt the bootldr at first which is not decrypted as of today.
__________________
![]() ...and the worlds shall reconnect. |
|
|
|
|
|
#37 | |
|
Member
![]() Join Date: Apr 2008
Posts: 104
Likes: 20
Liked 20 Times in 14 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
no we cannot "patch-in" 4.00 encrypted files into 3.55. 3.55 would not have the proper keys to decrypt what the 4.00 files and would therefore not load it. the only debugging that has a chance of possibly being leaked is the debug tools sony gives to developers to develop games, games which only run in lv2 or lower on the chain of trust. so if anything, we would only get a lv2 exploit if any debugging stuff were to appear. not only that though, we would need to use a TEST ps3 or a converted TEST retail ps3 to do this debugging, both of which are either expensive or not publically known. the stuff sony used to debug firmwares and flash firmwares and stuff will never be leaked, sony did that in house and we literally have no chance of getting to it. about as much of a chance of sony's entire firmware source code being leaked. |
|
|
|
|
|
|
#38 |
|
Member
![]() Join Date: Nov 2011
Posts: 72
Likes: 0
Liked 13 Times in 5 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
|
These development kits must be guarded pretty heavily... seems like everything is eventually leaked lol.
|
|
|
|
|
|
#39 |
|
Member
![]() Join Date: Jan 2012
Posts: 35
Likes: 1
Liked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Because companies fail to realize that no sworn admission is going to guarantee the safety of the company. On the other hand, could we not just hang the system (via some kind of bug that we would have to find) after lv0 has been decrypted, and dumped before re-encrypted ?
|
|
|
|
|
|
#40 | ||
|
Member
![]() Join Date: Nov 2011
Posts: 72
Likes: 0
Liked 13 Times in 5 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
|
|
||
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|