Go Back  
Reply
 
Thread Tools
Old 07-25-2012   #51
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by JonahUK View Post
metldrpwn requires isoldr to perform its 'hack' so it should be in the same folder as metldrpwn anyway.

Metldrpwn uses isoldr to retrieve the eid root key seed(s) in order to get the eid root key.
Already found isoldr file on the ps3devwiki
http://www.ps3devwiki.com/files/firmware/OFW-CEX/ has subdir with unpacked binaries.

But i'm not at home right now, so i can't test & see what the second exploit dumps. Someone should also try & see if the lspwn pkg from adrianc runs on dex 4.x and what that dumps.. We may be closer to keys than we think
Asure is offline   Reply With Quote
Likes: (1)
Old 07-25-2012   #52
Gonzakpo
Member
 
Join Date: Nov 2011
Posts: 199
Likes: 25
Liked 94 Times in 50 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Have you seend this?

- support for isolation mode if there is demand
It's written on the TODO list of the lspwn. According to my undestanding if you can dump an isolated SPE LS, then you can dump the bootloader decrypted (it is loaded and decrypted in isolation mode).

It would be nice to contact adrianc to see if he can give us a hint (maybe he regrets what he did :P). Anyway, I'm kind of guessing here or more like brainstorming haha.
Gonzakpo is offline   Reply With Quote
Old 07-25-2012   #53
ryant001
Member
 
Join Date: Oct 2011
Posts: 427
Likes: 115
Liked 218 Times in 140 Posts
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Gonzakpo View Post
Have you seend this?



It's written on the TODO list of the lspwn. According to my undestanding if you can dump an isolated SPE LS, then you can dump the bootloader decrypted (it is loaded and decrypted in isolation mode).

It would be nice to contact adrianc to see if he can give us a hint (maybe he regrets what he did :P). Anyway, I'm kind of guessing here or more like brainstorming haha.
So in the end he has just left out the most important function, just our usual luck!
ryant001 is offline   Reply With Quote
Old 07-25-2012   #54
hintgiver
Member
 
Join Date: Jul 2012
Posts: 112
Likes: 5
Liked 24 Times in 17 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
http://www.ps3devwiki.com/index.php?...r_Console_Keys

on that site they talk also about dumping isolated spe ls

i think it links to the source code posted earlier.
And here is another page
http://www.ps3devwiki.com/wiki/SPU_I...se_Engineering
hintgiver is offline   Reply With Quote
Old 07-25-2012   #55
Gonzakpo
Member
 
Join Date: Nov 2011
Posts: 199
Likes: 25
Liked 94 Times in 50 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Originally Posted by hintgiver View Post
http://www.ps3devwiki.com/index.php?...r_Console_Keys

on that site they talk also about dumping isolated spe ls

i think it links to the source code posted earlier.
And here is another page
http://www.ps3devwiki.com/wiki/SPU_I...se_Engineering
Do you know what happens to the bootloader after it decrypts the LV0? Is it cleared from the LS?

Do we have to reload it if we want to dump it?
Gonzakpo is offline   Reply With Quote
Old 07-25-2012   #56
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Once i get home i'll compile the other code from the pasties i saw before, and see what gets dumped.
Asure is offline   Reply With Quote
Old 07-25-2012   #57
hintgiver
Member
 
Join Date: Jul 2012
Posts: 112
Likes: 5
Liked 24 Times in 17 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
the code from the pastie is also on the dev wiki.
http://www.ps3devwiki.com/files/devt...erConsoleKeys/


about the bootloader thing, maybe we find some information here:
http://www.ps3devwiki.com/wiki/Boot_Order
hintgiver is offline   Reply With Quote
Old 07-25-2012   #58
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Progress:

Unknown pasties
I put together the code from the different pasties, and fixed a few includes Dump_rootkey's main.cpp is a good example of how the second exploit should look.

It now compiles and runs over RPC just like the original eid0 dumper.

However, by default, the actual dumping code is commented out. I uncommented it, but nothing happens, the program just sits there.

This might be because of two things

1. There are provisions for a 'isoldr.patched' in ./data/ folder, also commented.
Uncommenting and using the file from ps3devwiki didn't help.

2. I tried with an original 'isoldr' file from an unpacked 3.41 pup.
Could be we need an unencrypted copy? Not sure at this point.

I have attached the modified source to this post for others to peruse. This is not my work. I'm no C expert!

LSpwn
Runs like a charm on 3.41 CEX and dumps out the local storage (256kb)
Could someone on DEX 4.x confirm if the lspwn pkg runs on it?
Attached Files
File Type: zip unknown-exploit.zip (165.1 KB, 18 views)
Asure is offline   Reply With Quote
Likes: (1)
Old 07-25-2012   #59
doggie721
Apprentice
 
Join Date: Aug 2009
Posts: 24
Likes: 8
Liked 7 Times in 7 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Why not try to use the v0.01 memdump to dump the LV2? ; )
doggie721 is offline   Reply With Quote
Old 07-25-2012   #60
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Memdump needs peek/poke. We don't have peek/poke on the higher DEX/CEX firmwares.
Asure is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 03:29 AM.