Go Back  
Reply
 
Thread Tools
Old 04-08-2012   #1
Xpenet
Apprentice
 
Xpenet's Avatar
 
Join Date: Feb 2012
Posts: 19
Likes: 16
Liked 2 Times in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Post More Info links And Pictures or [Tutor] Needed to Dump 4.11 keys via Oscilloskope

1)I have question what kind of oscilloskope maybe counter i need
2)I own old 20 Mhz Osc and 80 Mhz Counter....
3)We need some detailed info and pictures or pinout......RAM memory and flash memory with technical flow of Lv0, to dump keys....


Thanks For any Response....
__________________
Xpenet is offline   Reply With Quote
Likes: (2)
Old 04-08-2012   #2
EX-OD-US
Member
null
 
EX-OD-US's Avatar
 
Join Date: Feb 2012
Posts: 35
Likes: 115
Liked 9 Times in 8 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
More specifically;- what type of oscilloskope-/-counter are you using? You would need an oscillation device that would be able to simulate (or slow down) the cell's frequencies/computations. You are more than likely looking in the IBM "side of things"......
EX-OD-US is offline   Reply With Quote
Old 04-08-2012   #3
Xpenet
Apprentice
 
Xpenet's Avatar
 
Join Date: Feb 2012
Posts: 19
Likes: 16
Liked 2 Times in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Post Detect Computations of Cell`s processor to obtain Keys 4.11

Originally Posted by EX-OD-US View Post
More specifically;- what type of oscilloskope-/-counter are you using? You would need an oscillation device that would be able to simulate (or slow down) the cell's frequencies/computations. You are more than likely looking in the IBM "side of things"......


1) I am using old Two channel 20Mhz Analog Russian Oscilloskope C1-55 and Two channel 80Mhz universal counter Tesla BM 641...

2)To simulate freqencies or (slow down Cell 3,2Ghz) is impossible with my hardware<<<<20Mhz osc. and 80Mhz counter right?

So we need something better like a digital osc. with memory but this is so expensive...>>>solution is a detect minimal working frequencies of Cell pocessor...and simulate it ..right?

3)What/where is a minimal working Cell frequency or external,internal software slow downer ?

----->>>>The PPE is a general purpose CPU, while the eight SPE are geared towards processing data in parallel. One SPE is disabled to increase yield, so the PS3 can have at most 9 threads runnings at the same time (2 from PPE and 7 from SPE). Note that one SPE is reserved for the hypervisor, so PS3 programs can take advantage of 8 threads. Both the PPE and SPE of the Cell are 64 bit, and manipulate data in Big Endian. The Cell was introduced at 90nm. Later, PS3 model numbers starting with CECHG uses the 65nm version, while the PS3 Slim (CECH-20xx) used the 45nm version.
1 PPE (Power Processor Element)
3.2Ghz
64 bit, Big Endian
2 threads (can run at same time)
L1 cache: 32kB data + 32kB instruction
L2 cache: 512kB
Memory bus width: 64bit (serial)
VMX (Altivec) instruction set support
Full IEEE-754 compliant
8 SPE (Synergistic Processing Element)
3.2Ghz
64 bit, Big Endian
1 SPE disabled to improve chip yield
1 SPE dedicated for hypervisor security
256kB local store per SPE
128 registers per SPE
Dual Issue (Each SPE can execute 2 instructions per clock)
IEEE-754 compliant in double precision (single precision round-towards-zero instead of round-towards-even)

4) IBM Cell datasheet>>>>> https://www-01.ibm.com/chips/techlib...257060006E61BA
__________________
Xpenet is offline   Reply With Quote
Old 04-08-2012   #4
nevik
Member
 
Join Date: Sep 2011
Posts: 101
Likes: 18
Liked 71 Times in 31 Posts
Mentioned: 16 Post(s)
Tagged: 0 Thread(s)
some reading

hi
I hope you are successful with your endeavor.
I thought this was good reading.

http://ps3hvdoc.wikispaces.com/Hypervisor+RE

http://ps3hvdoc.wikispaces.com/Metldr+-+Decryption
nevik is offline   Reply With Quote
Old 04-08-2012   #5
Xpenet
Apprentice
 
Xpenet's Avatar
 
Join Date: Feb 2012
Posts: 19
Likes: 16
Liked 2 Times in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Post ::::

Originally Posted by nevik View Post
hi
I hope you are successful with your endeavor.
I thought this was good reading.

http://ps3hvdoc.wikispaces.com/Hypervisor+RE

http://ps3hvdoc.wikispaces.com/Metldr+-+Decryption
Ok thanks, very good reading^^^

1)But problem is with dumping the files becouse OtherOS options was dissabled during update in 4.11 and using The KeyFinder then to get the Keys out of the Dump

2)only secret what i found on net is this
>>More System Information

How to get this

Go to Settings > System > System Information
Press simultaneously R1 + L1 + DPad Left + Square for a few seconds
Release those buttons then immediately press the start button (and keep it hold)

Very usefull^^^ ...Thanks for discovering....

__________________
Xpenet is offline   Reply With Quote
Old 04-09-2012   #6
nevik
Member
 
Join Date: Sep 2011
Posts: 101
Likes: 18
Liked 71 Times in 31 Posts
Mentioned: 16 Post(s)
Tagged: 0 Thread(s)
more reading

if you can and you are that good with a soldering iron. i have heard you could stack nands or a nor on top for
http://www.ps3devwiki.com/wiki/Dual_Firmware

then you try
http://www.ps3devwiki.com/wiki/CELL_Reset_Exploit

but when you pull the cell reset you switch to the 3.55otherOS++ and then dump the ram.

I have only heard this works.?
nevik is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 07:58 PM.