Go Back  
Reply
 
Thread Tools
Old 07-14-2012   #1
ben.ss7
Apprentice
 
Join Date: Jul 2012
Posts: 12
Likes: 5
Liked 11 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
How to Dump Lv0 :D

This is quite old but it's for those who are whining asking about 3.60+ keys. Basically to gain these keys you need to dump lv0. Decrypting lv0 is possible but you will need the bootloader keys which at this stage is quite difficult,because the bootloader decrypts the lv0 so unless you get bootloader keys you can't decrypt lv0, you can only dump lv0. Hope Noobs understand now :D

When lv0 is dumped it will contain the encrypted loaders. What you do is you decrypt the encrypted loaders with the metldr key so in other words dumping is the target, after dumping the loaders can be decrypted with metldr key and when decrypted=Keys

So thats out the way,:P

Now there are quite a few methods on how to dump lv0:
Cell reset line method in which you need a dual nor and signed lv1 (Mathieulh's method)
Dumping the ram at time when the ram holds the encrypted loaders before given to metldr (PsDev's Method)

Basically there's alot of whining going on and less research because if you actually dump the ram at a certain time before the loaders are given to metldr to run, and are held in the ram like PsDev said you can actually dump out the encrypted loaders by just dumping the ram using hardware.

Now to dump the ram you need a kernel module which maps out the real memory(AKA ram).
Now the rest is up to you how you use this kernel module but using hardware you insert this module and it will read out the real memory and dumping is the next step:D

Once dumped you basically got keys because you will dump the ram which will contain the encrypted loaders(appldr,rvkldr,isoldr etc) and you can decrypt these loaders with the metldr key.

Now have a go at dumping it now, Whining wont get you anywhere:D

Thanks to PsDev for his ram dump method and KaKaRoToKS for his kernel module

P.S I dont want any credit for this i just posted this so people can actually explore this method instead of whining and abusing other devs which is common :D

Last edited by ben.ss7; 07-16-2012 at 05:55 AM. Reason: missed out words
ben.ss7 is offline   Reply With Quote
Old 07-14-2012   #2
nevik
Member
 
Join Date: Sep 2011
Posts: 101
Likes: 18
Liked 71 Times in 31 Posts
Mentioned: 16 Post(s)
Tagged: 0 Thread(s)
Originally Posted by ben.ss7 View Post
This is quite old but it's for those who are whining asking about 3.60+ keys. Basically to gain these keys you need to dump lv0. Decrypting lv0 is possible but you will need the bootloader keys which at this stage is quite difficult,because the bootloader decrypts the lv0 so unless you get bootloader keys you can't decrypt lv0, you can only dump lv0. Hope Noobs understand now :D

When lv0 is dumped it will contain the encrypted loaders. What you do is you decrypt the encrypted loaders with the metldr key so in other words dumping is the target, after dumping the loaders can be decrypted with metldr key and when decrypted=Keys

So thats out the way,:P

Now there are quite a few methods on how to dump lv0:
Cell reset line method in which you need a dual nor and signed lv1 (Mathieulh's method)
Dumping the ram at time when the ram holds the encrypted loaders before given to metldr (PsDev's Method)

Basically there's alot of whining going on and less research because if you actually dump the ram at a certain time before the loaders are given to metldr to run, and are held in the ram like PsDev said you can actually dump out the encrypted loaders by just dumping the ram using hardware.

Now to dump the ram you need a kernel module which maps out the real memory(AKA ram) so i have attached it. Thanks to KaKaRoToKS

Now the rest is up to you how you use this kernel module but using hardware you insert this module and it will read out the real memory and dumping is the next step:D

Once dumped you basically got keys because you will dump the ram which will contain the encrypted loaders(appldr,rvkldr,isoldr etc) and you can decrypt these loaders with the metldr key.

Now have a go at dumping it now, Whining wont get you anywhere:D

Thanks to PsDev for his ram dump method and KaKaRoToKS for his kernel module

P.S I dont want any credit for this i just posted this so people can actually explore this method instead of whining and abusing other devs which is common :D

Sounds like it will work. Did you accomplish this and or what hardware did you use?
nevik is offline   Reply With Quote
Old 07-14-2012   #3
rafa11
Member
Wall Jumper Champion
 
Join Date: May 2011
Location: Braga, Portugal
Posts: 302
Likes: 219
Liked 156 Times in 92 Posts
Mentioned: 15 Post(s)
Tagged: 0 Thread(s)
Sounds wicked
If it works, that is...
rafa11 is offline   Reply With Quote
Old 07-14-2012   #4
TheEvolution_PT
Member
 
TheEvolution_PT's Avatar
 
Join Date: Oct 2011
Posts: 400
Likes: 455
Liked 190 Times in 113 Posts
Mentioned: 19 Post(s)
Tagged: 0 Thread(s)
I smell a trolololol in this one...
__________________
PS3 Slim Black with 160gb+320 hardrive(2) PS2 slim silver with freemcboot, PSP 2000 RED with PRO-C.
Retro Consoles: Sega Mega Drive 2, Gameboy Color and the great Poly Station xD
TheEvolution_PT is offline   Reply With Quote
Old 07-14-2012   #5
oPolo
Member
 
oPolo's Avatar
 
Join Date: Feb 2011
Posts: 910
Likes: 303
Liked 452 Times in 298 Posts
Mentioned: 79 Post(s)
Tagged: 0 Thread(s)
Only thing I will whine about is that PsDev gets credit for that. Honestly, its obvious and the first thing that imo comes to mind, when you think about getting the keys. Atleast for anyone with the slightest computer knowledge.
Anyone (or almost anyone) that needs to move around, learns to walk if they are capable of it. It has been like that for thousands of years. If some in the present comes about and suggest that people should walk to get around, should they get the credit connected with having made the present man walking?


Edit: Had he had more details to how it should be done, some specifics, then I would, have understood that he received the credit. Had he mentioned timings or contributed with anything new to concrete the abstraction of the theory on the PS3. Such as Team-Xecutor with their RGH exploit at which they state at which ns the cpu should receive a pulse of x ns on the cpu_rst line, then it was new. What he has suggested isn't actually new <.< And sorry if he has in fact mentioned elements relevant to the implementation of this already well known technique, which you just haven't mentioned. But as it's presented there, it actually makes him shame instead of making him glory, if he has stated this as his technique, which he should have known was obvious. It is a bit like Zadow with his findings that are not in the wiki, which defyboy points out is not, because it is assumed that people should know it already... I'm on an iPad so I'll keep it short, but look at the twitter conversations between defyboy and zadow, if you do not know what I mean.

By the way, _no_ hate towards Zadow, I haven't looked at what he has done myself, and I have seen/heard too little from 3th party sources, so I have no opinions about it.

Last edited by oPolo; 07-14-2012 at 12:45 PM.
oPolo is offline   Reply With Quote
Likes: (2)
Old 07-14-2012   #6
calo
Member
 
calo's Avatar
 
Join Date: Feb 2011
Location: Dublin
Posts: 165
Likes: 44
Liked 59 Times in 40 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
Originally Posted by TheEvolution_PT View Post
I smell a trolololol in this one...
he's just refreshing everybody on the method's to get lv0. that is all.
calo is offline   Reply With Quote
Likes: (1)
Old 07-14-2012   #7
furtsiv
Member
 
furtsiv's Avatar
 
Join Date: Jan 2012
Location: my room
Posts: 454
Likes: 123
Liked 150 Times in 90 Posts
Mentioned: 50 Post(s)
Tagged: 0 Thread(s)
hope it is the way that dongles use

Last edited by furtsiv; 07-15-2012 at 03:28 AM.
furtsiv is offline   Reply With Quote
Old 07-14-2012   #8
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,117
Likes: 394
Liked 553 Times in 413 Posts
Mentioned: 158 Post(s)
Tagged: 0 Thread(s)
Old stuff is old. I didn't even have to read it and knew it was old.
tjhooker73 is offline   Reply With Quote
Old 07-14-2012   #9
oPolo
Member
 
oPolo's Avatar
 
Join Date: Feb 2011
Posts: 910
Likes: 303
Liked 452 Times in 298 Posts
Mentioned: 79 Post(s)
Tagged: 0 Thread(s)
Originally Posted by tjhooker73 View Post
Old stuff is old. I didn't even have to read it and knew it was old.
As calo said, he is just refreshing it for us, along with a tool to help facilitate it. The way he writes it, reflects that its known stuff and nothing new.
oPolo is offline   Reply With Quote
Likes: (1)
Old 07-14-2012   #10
playerkp420
Senior Member
 
Join Date: Dec 2011
Posts: 4,436
Likes: 965
Liked 1,544 Times in 1,111 Posts
Mentioned: 796 Post(s)
Tagged: 0 Thread(s)
Originally Posted by ben.ss7 View Post
This is quite old
The first 4 words clued me that it was old. LOL :D
__________________
HOW TO DOWNGRADE W/E3 FLASHER TO ANY OFW/CFW
Nor model PS3 downgrade service in U.S.A. if you don't want to do it yourself
For downgrade help join irc at effnet-Just enter name and channel is #ps3downgrade
playerkp420 is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 05:18 AM.