Go Back  
Reply
 
Thread Tools
Old 06-27-2012   #21
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by DEFAULTDNB View Post
Without a vulnerability NOP slide is useless afaik.

I once spoke to comex about SSBB expliot on wii and he explained nop slide to me. You need to find a vuln that you can padd out and exploit.

I dont think hypervisor will allow this to happen. Kind of like how the tiff header exploits of psp fame used to work. Sony learned from this.
Also maybe that vunability could be used with a flasher to inject the eboot
__________________
JustThatDude is offline   Reply With Quote
Old 06-27-2012   #22
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,302
Likes: 427
Liked 611 Times in 452 Posts
Mentioned: 177 Post(s)
Tagged: 0 Thread(s)
The flasher cannot inject eboots, also It couldn't work on newer PS3s AKA 3xxx models, due to the new architecture and such.So not practical.
tjhooker73 is online now   Reply With Quote
Old 06-28-2012   #23
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by tjhooker73 View Post
The flasher cannot inject eboots, also It couldn't work on newer PS3s AKA 3xxx models, due to the new architecture and such.So not practical.
Okay but if we did find a way to inject a eboot then we would be able to have that hombrew on our system without having to inject the homebrew eboot everytime because the keys would then be signed to the app(if i'm right. once again just trowing out idea's) so if it worked that way we then could extract the signed homebrew with the newest keys verry easily and have signed homebrew for all.
__________________
JustThatDude is offline   Reply With Quote
Old 06-28-2012   #24
playerkp420
Senior Member
 
Join Date: Dec 2011
Posts: 4,684
Likes: 1,039
Liked 1,642 Times in 1,180 Posts
Mentioned: 847 Post(s)
Tagged: 0 Thread(s)
__________________
HOW TO DOWNGRADE W/E3 FLASHER TO ANY OFW/CFW
Nor model PS3 downgrade service in U.S.A. if you don't want to do it yourself
For downgrade help join irc at effnet-Just enter name and channel is #ps3downgrade
playerkp420 is offline   Reply With Quote
Old 06-30-2012   #25
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by playerkp420 View Post
Lol reverse that **** I know how to have a real good time with smoking some weed which is like 10x a day *braggin*
__________________
JustThatDude is offline   Reply With Quote
Likes: (1)
Old 07-03-2012   #26
sbmotoracer
Member
null
 
Join Date: Jul 2008
Posts: 45
Likes: 25
Liked 6 Times in 5 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Something like this will not work.

The ps3's executable files are all encrypted with the same key you are looking to find. You can't change something that is fully encrypted...
sbmotoracer is offline   Reply With Quote
Old 07-03-2012   #27
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 9,274
Likes: 6,498
Liked 4,038 Times in 2,627 Posts
Mentioned: 1002 Post(s)
Tagged: 0 Thread(s)
You say that but there is obviously a method for tb and e3 to crack and resign 3.56+ eboots without having any keys whatsoever....

I'm sure math said something ages ago about a eboot header fail.
__________________
DEFAULTDNB is online now   Reply With Quote
Old 07-03-2012   #28
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,302
Likes: 427
Liked 611 Times in 452 Posts
Mentioned: 177 Post(s)
Tagged: 0 Thread(s)
Wink

Originally Posted by DEFAULTDNB View Post
You say that but there is obviously a method for tb and e3 to crack and resign 3.56+ eboots without having any keys whatsoever....

I'm sure math said something ages ago about a eboot header fail.
They can easily Get the keys, Anyone can. All you need is money, Time, Knowledge, and Expensive hardware. Which is what they have a lot of, Obviously.
tjhooker73 is online now   Reply With Quote
Old 07-05-2012   #29
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by DEFAULTDNB View Post
You say that but there is obviously a method for tb and e3 to crack and resign 3.56+ eboots without having any keys whatsoever....

I'm sure math said something ages ago about a eboot header fail.
Yeah well I would like someone experienced to look into NOP Slide
__________________
JustThatDude is offline   Reply With Quote
Old 07-06-2012   #30
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 9,274
Likes: 6,498
Liked 4,038 Times in 2,627 Posts
Mentioned: 1002 Post(s)
Tagged: 0 Thread(s)
Originally Posted by JustThatDude View Post
Yeah well I would like someone experienced to look into NOP Slide
I think its simpler than this.

We have PC based tools to unself/lordself, we just need the TB/E3/anonymous chinese hacker method.

I would put my money on it being PC based tool that implements the fail on an eboot and cracks em wide open, and not PS3 based, so no need for NOP or finding an exploit with which to even initiate the NOP.

TBH I think on PS3-wise: the POC ram dump method could yield more than we think, I wonder how CFWProphet is coming along with that?

Project: POC of PS3 RAM Dump and Decrypting 3.6+ Games

It was a long run to get the right peoples involved and set up a new team but finally it's up and we already do some nice progress. This time i want to share a litle POC of a RAM dump of the PS3.

At this stage i don't want to say too much but we haven't used any hardware or software modifications and also already have done a dump on OFW 3.74. I used BlackBox a small app for the start to get a better understanding and to prove that i'm right.

The attached files are from a 3.55 dump and i also have included some parts of my write down. Especially the offset and bytes of the diff between the orig and the dumped elf.

I'll need to work more on the project to find a way to also dump and decrypt 3.6+ EBOOT's but it's only a matter of time.
__________________

Last edited by DEFAULTDNB; 07-06-2012 at 02:38 AM.
DEFAULTDNB is online now   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 05:10 AM.