Go Back  
Reply
 
Thread Tools
Old 05-17-2012   #1
Trivia618
Member
 
Trivia618's Avatar
 
Join Date: Feb 2012
Posts: 357
Likes: 163
Liked 90 Times in 66 Posts
Mentioned: 4 Post(s)
Tagged: 0 Thread(s)
Could an exploit be...

If we had the backup BIOS of the NOR Chip, do you think there could be an exploit somewhere in there (there is even a text file)?
OR
If someone was really good at programming and hardware, they could re-script the E3 flasher (any flasher) to look for/obtain certain files in the firmware?
Use the flasher to alter the firmware maybe...?
__________________
PS3 Slim 250GB - CECH-2004B 3.55 Rogero v3.1 (E3 Flasher)
Trivia618 is offline   Reply With Quote
Old 05-17-2012   #2
Pockets69
Senior Member
 
Pockets69's Avatar
 
Join Date: Jan 2008
Location: Lisbon, Portugal
Posts: 6,681
Likes: 2,087
Liked 2,449 Times in 1,389 Posts
Mentioned: 138 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Trivia618 View Post
If we had the backup BIOS of the NOR Chip, do you think there could be an exploit somewhere in there (there is even a text file)?
uuuhh??
OR
If someone was really good at programming and hardware, they could re-script the E3 flasher (any flasher) to look for/obtain certain files in the firmware?
the flasher dumps the whole nand/nor it obtains everything.
Use the flasher to alter the firmware maybe...?
talking about patching on the fly? that most likely does not work, files still to be signed and everything, it doesn't work...
__________________

<eussNL> judge: ´so why did you torrent 5 million AVI of women moaning´
<eussNL> <TizzyT> i dont judge if it sounds good i listen
Pockets69 is offline   Reply With Quote
Old 05-17-2012   #3
Caverna
Member
null
 
Caverna's Avatar
 
Join Date: Jan 2011
Posts: 30
Likes: 9
Liked 2 Times in 2 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
I'm not a "black belt" karate guy, but I know some thing about x86 assembly...
I think he is saying some thing about patching RAM content...
Does NOR=RAM? I really don't know.
But I think that RAm can be patched on the fly without need of any key...
Unless Sony's Nazis does a crc check in each function call...
$.02
__________________
PGP ID - 0x92E0B836
Caverna is offline   Reply With Quote
Old 05-17-2012   #4
Pockets69
Senior Member
 
Pockets69's Avatar
 
Join Date: Jan 2008
Location: Lisbon, Portugal
Posts: 6,681
Likes: 2,087
Liked 2,449 Times in 1,389 Posts
Mentioned: 138 Post(s)
Tagged: 0 Thread(s)
no NOR is not Ram

ram can be patched of course but not with e3 flasher lol
__________________

<eussNL> judge: ´so why did you torrent 5 million AVI of women moaning´
<eussNL> <TizzyT> i dont judge if it sounds good i listen
Pockets69 is offline   Reply With Quote
Old 05-17-2012   #5
TizzyT
Homebrew Developer
 
TizzyT's Avatar
 
Join Date: Jul 2011
Location: USA-Unfortunately Sucks A$$
Posts: 1,838
Likes: 1,007
Liked 810 Times in 476 Posts
Mentioned: 160 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to TizzyT
Dumping NOR/NAND will contain encrypted files etc iirc, and will only get us as far or less as to where we already are.
__________________
If you are going to promote TB at least do it right!!!, or better yet DON'T!!!
TizzyT is offline   Reply With Quote
Old 05-17-2012   #6
Trivia618
Member
 
Trivia618's Avatar
 
Join Date: Feb 2012
Posts: 357
Likes: 163
Liked 90 Times in 66 Posts
Mentioned: 4 Post(s)
Tagged: 0 Thread(s)
So everyone is stuck at the decrypting process?
************* [ - Post Merged - ] *************
Originally Posted by Pockets69 View Post
talking about patching on the fly? that most likely does not work, files still to be signed and everything, it doesn't work...
Ok someone on Firmware 3.55+<4.11 and has E3 Flasher installed starts up game>4.11
When Ps3 checks if the firmware is compatible (and it isn't) we could have a script that will trick it making it think that we are running >4.11 (this will be done via program modified to be executed by E3 Flasher operating on the NOR at said time)
If only someone could make a homebrew app that will allow the dumping of the RAM, i'm sure it can be done from the use of software

PS: I'm just brainstorming, i'm 15 years old and i've never read the ps3devwiki
************* [ - Post Merged - ] *************
Originally Posted by KaKaRoTo
Well Elliptic Curve cryptography is based on an equation of the form :

y^2 = (x^3 + a * x + b) mod p


The ECDSA is a type of graph just like a parabola, hyperbola, straight line
It has its laws and a specific formula
The private keys are "x" in this equation: y^2 = (x^3 + a * x + b) mod p
Which will generate said graph creating the ECDSA [“Elliptic Curve Digital Signature Algorithm”(digital curve signature)]

All info can be found Here
http://kakaroto.homelinux.net/2012/0...gorithm-works/

PS: I wish I was smarter and had the funds to experiment but I have neither so please forgive me on starting this thread...
__________________
PS3 Slim 250GB - CECH-2004B 3.55 Rogero v3.1 (E3 Flasher)

Last edited by Trivia618; 05-17-2012 at 03:43 PM.
Trivia618 is offline   Reply With Quote
Old 05-17-2012   #7
advocatusdiaboli
Senior Member
 
advocatusdiaboli's Avatar
 
Join Date: Sep 2010
Location: /dev/random
Posts: 1,686
Likes: 424
Liked 270 Times in 170 Posts
Mentioned: 14 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Trivia618 View Post
So everyone is stuck at the decrypting process?
There is a nice puzzle for you here: http://kakaroto.homelinux.net/2012/0...gorithm-works/
__________________
US 4USB ports OFW 3.15 PS Ubuntu
EU 4USB ports CFW 4.21.1 REX
There is only one OS; AmigaOS, the rest are just [l]imitations.
advocatusdiaboli is offline   Reply With Quote
Old 05-17-2012   #8
Pockets69
Senior Member
 
Pockets69's Avatar
 
Join Date: Jan 2008
Location: Lisbon, Portugal
Posts: 6,681
Likes: 2,087
Liked 2,449 Times in 1,389 Posts
Mentioned: 138 Post(s)
Tagged: 0 Thread(s)
i know all about the ecdsa i was studying it when kakaroto was studying it as well... it has nothing to do with this... or better it has but... i ll explain.
Ok someone on Firmware 3.55+<4.11 and has E3 Flasher installed starts up game>4.11
When Ps3 checks if the firmware is compatible (and it isn't) we could have a script that will trick it making it think that we are running >4.11 (this will be done via program modified to be executed by E3 Flasher operating on the NOR at said time)
If only someone could make a homebrew app that will allow the dumping of the RAM, i'm sure it can be done from the use of software
but making it think is not enough we need to have files (encrypted files) to get those games running so the ps3 can decrypt them, you cant just expect to run a game that requires a higher firmware if you don't have the required keys to do so, think of it as a door, you can't open it without the keys, there is no tricking the door no going around nothing, you need the keys, making the door thinking you have the key will not work, cause it does require the key!

PS: I'm just brainstorming, i'm 15 years old and i've never read the ps3devwiki
GO RREAD IT NOW!!! its important.
__________________

<eussNL> judge: ´so why did you torrent 5 million AVI of women moaning´
<eussNL> <TizzyT> i dont judge if it sounds good i listen
Pockets69 is offline   Reply With Quote
Likes: (1)
Old 05-17-2012   #9
playerkp420
Senior Member
 
Join Date: Dec 2011
Posts: 4,361
Likes: 932
Liked 1,506 Times in 1,089 Posts
Mentioned: 778 Post(s)
Tagged: 0 Thread(s)
Packages would have to signed also right? Can't sign the pkgs for the homebrew to play the games.
__________________
HOW TO DOWNGRADE W/E3 FLASHER TO ANY OFW/CFW
Nor model PS3 downgrade service in U.S.A. if you don't want to do it yourself
For downgrade help join irc at effnet-Just enter name and channel is #ps3downgrade
playerkp420 is online now   Reply With Quote
Old 05-17-2012   #10
TizzyT
Homebrew Developer
 
TizzyT's Avatar
 
Join Date: Jul 2011
Location: USA-Unfortunately Sucks A$$
Posts: 1,838
Likes: 1,007
Liked 810 Times in 476 Posts
Mentioned: 160 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to TizzyT
Originally Posted by Trivia618 View Post
So everyone is stuck at the decrypting process?
************* [ - Post Merged - ] *************


Ok someone on Firmware 3.55+<4.11 and has E3 Flasher installed starts up game>4.11
When Ps3 checks if the firmware is compatible (and it isn't) we could have a script that will trick it making it think that we are running >4.11 (this will be done via program modified to be executed by E3 Flasher operating on the NOR at said time)
If only someone could make a homebrew app that will allow the dumping of the RAM, i'm sure it can be done from the use of software

PS: I'm just brainstorming, i'm 15 years old and i've never read the ps3devwiki
************* [ - Post Merged - ] *************




The ECDSA is a type of graph just like a parabola, hyperbola, straight line
It has its laws and a specific formula
The private keys are "x" in this equation: y^2 = (x^3 + a * x + b) mod p
Which will generate said graph creating the ECDSA [“Elliptic Curve Digital Signature Algorithm”(digital curve signature)]

All info can be found Here
http://kakaroto.homelinux.net/2012/0...gorithm-works/

PS: I wish I was smarter and had the funds to experiment but I have neither so please forgive me on starting this thread...
Even if someone made the software (which already exists iirc), how would you run it?
__________________
If you are going to promote TB at least do it right!!!, or better yet DON'T!!!
TizzyT is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 09:35 AM.