Go Back  
Reply
 
Thread Tools
Old 04-18-2012   #71
DjKlown
Member
 
Join Date: Feb 2011
Posts: 176
Likes: 10
Liked 38 Times in 29 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Since I'm away.... Let me gwt this str8. Those aren't sonys. Those are tb. And if I'm not mistaken. Only way to change those is if u have lvl0 or bootloader access... And ill stop there til someone confirms that....
************* [ - Post Merged - ] *************
Nm just some troll **** from my limited resources at the moment... It's 4.11 stuff and not tb...
DjKlown is online now   Reply With Quote
Old 04-18-2012   #72
mcmrc1
Member
 
mcmrc1's Avatar
 
Join Date: Jan 2011
Location: Gliese 581g
Posts: 613
Likes: 531
Liked 346 Times in 176 Posts
Mentioned: 17 Post(s)
Tagged: 0 Thread(s)
Originally Posted by CrashSerious View Post
We looked at it briefly, and moved to Cobra because everything would be applicable to TB. And, also Cobra has at least some use other than warez. (No flames with "but I buy my games, please. I won't respond to them, we all know the major use of TB is piracy and it's ONLY feature is 3.55+ games.) someone could test the keys by (mostly) plugging them into key 3.55 files in their .ps3 directory and making unself fix the corrupted sections of the self.
ok i remember it was the cobra and not the tb you where working on and the idea with the key files was in my head too in an other thread i wrote that too but i don´t know how to make these files i opend the old 3.55 key files with notepad and i thought i can just change the keys somehow but there was just hieroglyphs letters

iam no dev or so it was just an idea it would be nice if a dev would explain how o make those key files or maybe make a program to test such leaked keys so we can respnse and check faster it is fake or not

and thx for your answer...
__________________

Last edited by mcmrc1; 04-18-2012 at 11:17 PM.
mcmrc1 is offline   Reply With Quote
Old 04-19-2012   #73
svenmullet
Member
 
svenmullet's Avatar
 
Join Date: Jun 2011
Location: The Frozen North.
Posts: 732
Likes: 479
Liked 678 Times in 304 Posts
Mentioned: 82 Post(s)
Tagged: 0 Thread(s)
Just C+P them into a hex editor and save.

[edit] here, let me do that for you. Not sure what to rename them before you drop them in your keys folder, but here you go.

Attachment 1234
__________________

Last edited by svenmullet; 07-30-2012 at 05:45 PM.
svenmullet is offline   Reply With Quote
Likes: (1)
Old 04-19-2012   #74
defyboy
Member
 
Join Date: Jan 2011
Posts: 161
Likes: 4
Liked 260 Times in 93 Posts
Mentioned: 52 Post(s)
Tagged: 0 Thread(s)
Great work Octopus, it is good to see someone making genuine progress rather than deliberately trolling.

Originally Posted by nookupeous View Post
Code:
1- Key: A7 0B 81 5A 47 AC 66 F9 7A A6 E7 CA 80 5B 22 19 08 C7 B3 5E 2A 8C F5 A7 23 78 1A 0E D0 84 11 F5
 
2- Key: A7 0B 81 5A 47 AC 66 F9 7A A6 E7 CA 80 5B 22 19 08 C7 B3 5E 2A 8C F5 A7 23 78 1A 0E F5 D0 84 11.
 
unknown00: C8 DB 12 00 03 00 00 00 34 93 8A BF 44 08 DD 00 80 7F 15 00 04 93 8A BD BF 18 25 00 00 00 00 00
 
Key: A7 0B 81 5A 47 AC 66 F9 7A A6 E7 CA 80 5B 22 19 08 C7 B3 5E 2A 8C F5 A7 23 78 1A 0E F5 D0 84 11
 
ivec: 5B E0 07 73 26 5E FD 18 FE AF A4 DA 88 2B F0 DF BC EA 0C 00 32 5B A2 AE EE 6B EE 8E BF 69 BF B9
 
Final Key 4.11: A7 0B 81 5A 47 AC 66 F9 7A A6 E7 CA 80 5B 22 19 08 C7 B3 5E 2A 8C F5 A7 23 78 1A 0E D0 84 11 F5
According to console crunch Icy and zadow28 have released they true blue eboot keys. Someone with the knowledge to encrypt/decrypt an eboot should test.
I bet those keys came from this book
defyboy is offline   Reply With Quote
Likes: (1)
Old 04-19-2012   #75
Deadman19
Member
 
Deadman19's Avatar
 
Join Date: Apr 2012
Posts: 82
Likes: 63
Liked 29 Times in 17 Posts
Mentioned: 6 Post(s)
Tagged: 0 Thread(s)
I bet we wouldn't find out until someone will test them... Actions before words, guys.

Last edited by Deadman19; 04-19-2012 at 03:48 AM.
Deadman19 is offline   Reply With Quote
Old 04-19-2012   #76
landon
Member
 
Join Date: Oct 2011
Posts: 207
Likes: 125
Liked 39 Times in 34 Posts
Mentioned: 14 Post(s)
Tagged: 0 Thread(s)
& the drama continue !
landon is offline   Reply With Quote
Old 04-19-2012   #77
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 8,971
Likes: 6,273
Liked 3,859 Times in 2,509 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
When Rebug made LV2 Loader what did they have in-mind to use it for?
DEFAULTDNB is online now   Reply With Quote
Likes: (2)
Old 04-19-2012   #78
Octopus
Member
 
Join Date: Oct 2011
Posts: 83
Likes: 31
Liked 50 Times in 9 Posts
Mentioned: 15 Post(s)
Tagged: 0 Thread(s)
Hello @CrashSerious , @defyboy
Thanks for good words!

Originally Posted by CrashSerious View Post
We looked at it briefly, and moved to Cobra because everything would be applicable to TB. And, also Cobra has at least some use other than warez. (No flames with "but I buy my games, please. I won't respond to them, we all know the major use of TB is piracy and it's ONLY feature is 3.55+ games.) someone could test the keys by (mostly) plugging them into key 3.55 files in their .ps3 directory and making unself fix the corrupted sections of the self.
If you have some free space in team I will be glad to help.

I heard some conspiracy theory about Cobra Team had made TB, but I am not sure in it. I dont have a look at Cobra payload, but I reversed TB updater and take a look at Cobra updater. If it made by the same people strange why code so different.

Originally Posted by landon View Post
Yes cause that dongle had the auto-destruction function ! it looks to be really impossible to crack those JailBreak 2 dongles !! it's a lost war guys ...
Its easy to avoid all checks

Originally Posted by svenmullet View Post
You forgot to post the "0x10 from 800000000035E104" part. Please do so
At adress 800000000035E100 you can see something what Graf_Chokolo called kthread. Im not 100% sure it gets overwritten or not, but I know what can be there, also I know some part of decrypted code, algo is TEA (64 rounds = 32 cycles), so I can made dictionary and bruteforce it.
Not really interested in it because with dongle its in few dozen easer.

Coming back to TB Updater, you can grab there section numbers and offsets.
For example in 2.4 update: 0 - 0x0; A - 0x21F00; C - 0x32F00; E - 0x47700; 10 - 0x58700; 6 - 0x6CF00; 0xF00 and 0x11F00 not written.

Dont set addresses in others updates, just copypast

2.1: 0.
2.2: 0, 4, 2, C, A, 6. 0xF00 0x11F00 0x21F00 0x32F00 0x44F00
2.3: 0, 4, 2, C, A, 6. 0xF00 0x11F00 0x21F00 0x32F00 0x45700
2.5: 10, E, 6. 0x12000 0x2D800
Octopus is offline   Reply With Quote
Likes: (7)
Old 04-19-2012   #79
Pockets69
Senior Member
 
Pockets69's Avatar
 
Join Date: Jan 2008
Location: Lisbon, Portugal
Posts: 6,681
Likes: 2,087
Liked 2,449 Times in 1,389 Posts
Mentioned: 138 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Octopus View Post
Hello @CrashSerious , @defyboy
Thanks for good words!


If you have some free space in team I will be glad to help.

I heard some conspiracy theory about Cobra Team had made TB, but I am not sure in it. I dont have a look at Cobra payload, but I reversed TB updater and take a look at Cobra updater. If it made by the same people strange why code so different.


Its easy to avoid all checks


At adress 800000000035E100 you can see something what Graf_Chokolo called kthread. Im not 100% sure it gets overwritten or not, but I know what can be there, also I know some part of decrypted code, algo is TEA (64 rounds = 32 cycles), so I can made dictionary and bruteforce it.
Not really interested in it because with dongle its in few dozen easer.

Coming back to TB Updater, you can grab there section numbers and offsets.
For example in 2.4 update: 0 - 0x0; A - 0x21F00; C - 0x32F00; E - 0x47700; 10 - 0x58700; 6 - 0x6CF00; 0xF00 and 0x11F00 not written.

Dont set addresses in others updates, just copypast

2.1: 0.
2.2: 0, 4, 2, C, A, 6. 0xF00 0x11F00 0x21F00 0x32F00 0x44F00
2.3: 0, 4, 2, C, A, 6. 0xF00 0x11F00 0x21F00 0x32F00 0x45700
2.5: 10, E, 6. 0x12000 0x2D800

a bruteforce on it? really? 64 rounds? but even being a dictionary attack if the word is not present you cant guess it, unless of course you have and idea about what to put in the dictionary.

none the less great work octopus.
__________________

<eussNL> judge: ´so why did you torrent 5 million AVI of women moaning´
<eussNL> <TizzyT> i dont judge if it sounds good i listen
Pockets69 is offline   Reply With Quote
Likes: (1)
Old 04-19-2012   #80
Octopus
Member
 
Join Date: Oct 2011
Posts: 83
Likes: 31
Liked 50 Times in 9 Posts
Mentioned: 15 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Pockets69 View Post
a bruteforce on it? really? 64 rounds? but even being a dictionary attack if the word is not present you cant guess it, unless of course you have and idea about what to put in the dictionary.

none the less great work octopus.
Yeah, thats what I meant. If you look at this adress you will understand there are not alot of values what can be there. Unless dongle write something directly to there, not sure about it.
Octopus is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 11:21 AM.