|
|
#141 | |
|
Senior Member
![]() Join Date: Jun 2010
Location: Heart of Palestine
Posts: 1,789
Likes: 1,058
Liked 328 Times in 256 Posts
Mentioned: 36 Post(s)
Tagged: 0 Thread(s)
|
Sent from my PC36100 using Tapatalk 2
__________________
By RobGee789 |
|
|
|
|
|
|
#142 | |
|
Member
![]() Join Date: Jun 2011
Location: The Frozen North.
Posts: 732
Likes: 479
Liked 678 Times in 304 Posts
Mentioned: 82 Post(s)
Tagged: 0 Thread(s)
|
__________________
|
|
|
|
|
|
|
#143 | |
|
Member
![]() |
of course as long its nothing like me ending up losing my hacked ps3...
Last edited by KentaZX; 05-02-2012 at 12:02 AM. |
|
|
|
|
|
|
#144 | |
![]() ![]() Join Date: Apr 2012
Posts: 121
Likes: 26
Liked 55 Times in 16 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
|
************* [ - Post Merged - ] ************* What if the True Blue Dongle merely loads a custom firmware from the USB the beginning? As anyone considered that possibility? ************* [ - Post Merged - ] ************* What am I thinking right now is what is the True Blue dongle simply loads a custem payload in the lv1/dev_flash and the eboots are simply redirected to it? By redirecting they are perhaps avoiding the whole security cycle?? Just an idea that I just got while cooking :-D |
|
|
|
|
|
Likes: (1) |
|
|
#145 |
|
Senior Member
![]() Join Date: Jan 2008
Location: Lisbon, Portugal
Posts: 6,681
Likes: 2,087
Liked 2,449 Times in 1,389 Posts
Mentioned: 138 Post(s)
Tagged: 0 Thread(s)
|
i like what i see here, people brainstorming
at least its better than what happens in most threads. good work
__________________
<eussNL> judge: ´so why did you torrent 5 million AVI of women moaning´ <eussNL> <TizzyT> i dont judge if it sounds good i listen |
|
|
|
|
|
#146 | |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
So mainly i dumping the RAM to get hands on the EBOOT's of games, Patch them cause some flags and some tables get replaced with files and make them run on lower fw with 3.55 npdrm keys or fself them and release a CFW that can boot debug self's and install debug pkg's. More like that. |
|
|
|
|
|
|
#148 |
|
Member
![]() Join Date: Feb 2011
Posts: 176
Likes: 10
Liked 38 Times in 29 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
|
@cfwprpht
i believe you are on the right track... i have said this same exact thing in recent posts and to certain people... you know who you are...
keep doing what your doing..."Patch them cause some flags and some tables get replaced with files and make them run on lower fw with 3.55 npdrm keys or fself them and release a CFW that can boot debug self's and install debug pkg's. More like that." regards |
|
|
|
|
|
#149 | |
![]() ![]() Join Date: Apr 2012
Posts: 121
Likes: 26
Liked 55 Times in 16 Posts
Mentioned: 28 Post(s)
Tagged: 0 Thread(s)
|
[QUOTE=Calliope;361228]Thank you! This is the sort of thing we were looking for! However, I believe you said in a earlier post that you were in the progress of getting your hands on debug eboots like True Blue?
************* [ - Post Merged - ] ************* What if the True Blue Dongle merely loads a custom firmware from the USB the beginning? As anyone considered that possibility? ************* [ - Post Merged - ] *************
Devkit --> NP-DRM –> Perhaps they are making the PS3 believe that it is a PSN game? If so then they are modifying the eboot.bin into a PSN eboot. Perhaps members of Team Duplex could help? - Patching of lvl1 to allow RW mapping of RAM via lvl1.self - File/memory - Offset(h) 00 01 02 03 - OFW: 000F5A44 39 20 00 00 li r9,0 - TB: 000F5A44 39 20 00 01 li r9,1 lv2_kernel.self --> only 1 function change, and a section added sub_28fe30 is replaced --> Determines whether to load as OFW or TB. So the actual exploit is executed before loading OFW code! dev_flash_010.tar.aa.2010_11_27_051337 \dev_flash\vsh\module\nas_plugin.sprx Offset(h) 00 01 02 03 OFW: 00003250 7C 60 1B 78 mr r0, r3 TB: 00003250 38 00 00 00 li r0, 0 Offset(h) 00 01 02 03 OFW: 00037350 41 9E 00 4C beq- cr7,4c TB: 00037350 60 00 00 00 nop I have reasons to believe that they perhaps are using the old USB exploit from PSJailbreak from a different angle. The Dongle modifies files on the dev_flash and I believe does some sort of Cex --> Dex conversion. I will look more into it tomorrow. Last edited by Calliope; 05-02-2012 at 06:58 PM. |
|
|
|
|
|
|
#150 |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
@svenmullet
No i don't have a DEX to time why you ask ?
![]() @DjKlown Thx for the Flowers @Calliope Im guess that the lv2 patches are peek&poke and a additional check to see if tb dongle is connected or not. The nas_plugin patches are for psydo-retail and debug pkg's. and no it's not a kind of cex2dex. Forget this thing. For a dex convertion you need to moddifie the EID segments. To be exact EID0,1,2. But first you need to decrypt them, patch data and set flags, encrypt back and flash it to the console. After that you need to start Service Mode and flash a debug fw to the console. Belive me when i say forget that true blue crap and the trie to reverse it. The step to get the new games running on lower fw have nothing to do with reversing tb.
|
|
|
|
|
Likes: (1) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|