|
|
#21 |
|
Member
![]() Join Date: Jan 2008
Posts: 208
Likes: 1
Liked 35 Times in 25 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
I wonder who WOULD work on this...
Could the OP or someone possibly upload the decrypted bootldr? It would be interesting to actually view this... If we actually worked on this, it would go similar to this: 1. Alter bootldr to dump lv0 to a USB stick (you would require code execution at boot up could require a bit of work). 2. Sign bootldr using Mathieulh's metldr exploit (it works for the bootldr). 3. Replace bootldr in current PS3 with newly signed bootldr. 4. Plug in your USB and get your free copy of lv0. If those 4 steps were done we'd have the console pwn'd forever because Sony cannot update the bootldr. |
|
|
|
|
|
#22 | |
|
Senior Member
![]() Join Date: Sep 2011
Posts: 1,629
Likes: 432
Liked 853 Times in 459 Posts
Mentioned: 80 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() |
|
|
|
|
|
|
#23 |
|
Member
![]() Join Date: Jun 2011
Posts: 203
Likes: 34
Liked 87 Times in 40 Posts
Mentioned: 6 Post(s)
Tagged: 0 Thread(s)
|
bootldr never changes
__________________
![]() |
|
|
|
|
|
#24 |
|
Member
![]() Join Date: Jan 2011
Posts: 161
Likes: 4
Liked 260 Times in 93 Posts
Mentioned: 52 Post(s)
Tagged: 0 Thread(s)
|
Sorry people,
This script dumps the OtherOS bootloader binary image, Not the bootldr we need to get the lv0 keys. It was written by the 'real' Geoffery Levand. http://dev.man-online.org/man8/ps3-utils/ http://packages.debian.org/sid/admin/ps3-utils The real bootldr that we want to get will be less than 256kb and not contain a whole heap of kernel strings. Dumping the bootldr will not be this easy. Last edited by defyboy; 04-26-2012 at 12:38 AM. |
|
|
|
|
|
#25 |
|
Member
![]() Join Date: Jan 2008
Posts: 208
Likes: 1
Liked 35 Times in 25 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
@Cheesethief
bootldr is encrypted with the console key (how we get it decrypted would require knowing that except for this method which seems to bypass that). As such it's IMPOSSIBLE to EVER update the bootldr as then the console key for each console would be the same. If you write a bootldr that dumps lv0 (which is the only step required here) and sign it then we're done forever. No more updates can ever hide the keys.
We'd get access to lv0 by getting the bootldr to decrypt lv0 (which it already knows how to do as the bootldr is the FIRST link in the chain of trust) and simply telling it "Hey, rather than storing it memory and deleting it after it's done lets also dump it to say my internal hard drive or USB stick after decrypting it". Then we simply fetch the file later. Last edited by Elegant; 04-26-2012 at 12:39 AM. |
|
|
|
|
|
#26 | |
|
Senior Member
![]() Join Date: Sep 2011
Posts: 1,629
Likes: 432
Liked 853 Times in 459 Posts
Mentioned: 80 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() |
|
|
|
|
|
|
#27 |
|
Member
![]() Join Date: Jan 2008
Posts: 208
Likes: 1
Liked 35 Times in 25 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
@Cheesethief
Nah dude you're not quite getting it all, the "current bootldr" was the one you got from the factory when they made it. If you have a PS3 that originally had like FW 1.00 (lets pretend that was 5 years ago) you've had the same bootldr for 5 years regardless of how many times you upgraded from 1.00-1.50-3.41-3.55-4.11 or what have you. Even if you downgraded you're still using the same bootldr.
You simply CANNOT update the bootldr therefore when Sony changed lv0 it must be compatible with the "old bootldr" (they never change it's all the same bootldr). However that does not mean we can't alter the bootldr to do other things it simply means Sony can never update it as it's encrypted the per console key. So if we got the bootldr to dump a decrypted lv0 in 3.55. It would HAVE to work in 3.6x+ because the bootldr would never change. It doesn't matter what lv0 does because it's how the bootldr handles lv0! Last edited by Elegant; 04-26-2012 at 12:58 AM. |
|
|
|
|
|
#28 | ||
|
Homebrew Developer
![]() |
(twitter answered as many questions i could as well as being friendly as possible!)
|
||
|
|
|
|
|
#29 |
|
Member
![]() Join Date: Jan 2011
Posts: 161
Likes: 4
Liked 260 Times in 93 Posts
Mentioned: 52 Post(s)
Tagged: 0 Thread(s)
|
I can 100% confirm that this is nothing new. As I expected it dumps the OtherOS bootloader, which in this case is petitboot. The dump I have is identical to the current petitboot image found here: http://gitbrew.org/~glevand/ps3/peti...bImage.ps3.bin
Of course, feel free to replicate the test and compare it with the above file. |
|
|
|
|
Likes: (3) |
|
|
#30 | |
|
Member
![]() Join Date: Jun 2011
Location: The Frozen North.
Posts: 732
Likes: 478
Liked 677 Times in 303 Posts
Mentioned: 82 Post(s)
Tagged: 0 Thread(s)
|
__________________
|
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|