|
|
#101 | |
|
Member
![]() Join Date: Jan 2011
Posts: 164
Likes: 6
Liked 274 Times in 96 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
I have also looked into the possibility of bus mastering the PCI bus to read memory but that too, would require a rather large implementation. The most viable process for dumping RAM at the moment is via software, but as stated, just dumping LV0 - while it is progress and interesting, It is not enough for progression past the 3.60 firmware barrier. We need to dump the bootldr/lv0ldr to get the lv0 keys, Which in turn allow us to decrypt the entire firmware chain. |
|
|
|
|
|
|
#102 |
|
Apprentice
![]() Join Date: Jan 2012
Posts: 28
Likes: 0
Liked 6 Times in 4 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
I didn't say we need to decrypt the bootloader as is practicaly impossible. I said the PCK0 is the key that was used to encrypt the metldr and bootldr, so because of the security flaw of ps3, that gives us the decrypted metldr, there should be somewhere the PCK0 as only this key is able to decrypt the metldr. If this wasn't true, how come the metldr gets decrypted in the first place... when we know the key that has decrypted the metldr, we know practically everything we have to know...
|
|
|
|
|
|
#103 | |
|
Member
![]() Join Date: Mar 2012
Posts: 203
Likes: 12
Liked 80 Times in 50 Posts
Mentioned: 23 Post(s)
Tagged: 0 Thread(s)
|
|
|
|
|
|
|
|
#104 |
|
Apprentice
Join Date: Sep 2010
Posts: 1
Likes: 0
Liked 3 Times in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Hi, just wanted to leave this here, a short interview with naehrwert, also some talk about lv0. English Version starts somewhere in the middle of the page. http://monkeydesk.at/content/exklusi...aehrwert-1198/
|
|
|
|
|
Likes: (3) |
|
|
#105 | |
|
Member
![]() Join Date: Feb 2011
Location: Dublin
Posts: 165
Likes: 45
Liked 59 Times in 40 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
|
cheers, good read. |
|
|
|
|
|
|
#106 |
|
Member
![]() Join Date: Jun 2011
Posts: 203
Likes: 34
Liked 87 Times in 40 Posts
Mentioned: 6 Post(s)
Tagged: 0 Thread(s)
|
so this means lv0 is exploited through lv0ldr??
__________________
![]() |
|
|
|
|
|
#107 |
|
Member
![]() Join Date: Mar 2012
Posts: 203
Likes: 12
Liked 80 Times in 50 Posts
Mentioned: 23 Post(s)
Tagged: 0 Thread(s)
|
There's no such thing as lv0ldr. It's called bootldr, which you can't decrypt without the PCK_0.
|
|
|
|
|
|
#108 |
|
Member
![]() Join Date: Jun 2011
Posts: 203
Likes: 34
Liked 87 Times in 40 Posts
Mentioned: 6 Post(s)
Tagged: 0 Thread(s)
|
perconsole key 0
__________________
![]() |
|
|
|
|
|
#109 |
|
Apprentice
Join Date: Mar 2012
Posts: 4
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Exactly how many encryption levels are we talking here before reaching the bootldr key?
|
|
|
|
|
|
#110 | |
|
Member
![]() Join Date: Jun 2011
Location: The Frozen North.
Posts: 748
Likes: 503
Liked 707 Times in 312 Posts
Mentioned: 82 Post(s)
Tagged: 0 Thread(s)
|
__________________
|
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|