Go Back  
Reply
 
Thread Tools
Old 08-07-2012   #191
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by deeptrap View Post
Im also trying your pastie bat to see what will happen.

I get the following error .

od does not recognised, it think this is a typo and must be do, but it will still not work.
Maybe something wrong with the quotes ?
You need to add the tools in from cygwin.
Or, use this pre-packaged set. It does not contain keys or scetool. You need to put scetool and data directory and eboot/self in the same folder.

Code:
http://www.sendspace.com/file/g9syfd
For time-reasons, it would be best to try with a small decrypted eboot.elf, and self/sprx.. as small as possible, then it takes a lot less time. I'm trying with Portal 2 now, but that's still 20 hours..
Asure is offline   Reply With Quote
Old 08-07-2012   #192
deeptrap
Apprentice
null
 
Join Date: Aug 2012
Posts: 26
Likes: 1
Liked 2 Times in 2 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Asure View Post
You need to add the tools in from cygwin.
Or, use this pre-packaged set. It does not contain keys or scetool. You need to put scetool and data directory and eboot/self in the same folder.

Code:
http://www.sendspace.com/file/g9syfd
For time-reasons, it would be best to try with a small decrypted eboot.elf, and self/sprx.. as small as possible, then it takes a lot less time. I'm trying with Portal 2 now, but that's still 20 hours..
I know
Tried now on XP machine (also win 7)
Same error



od is not recognized as an internal or external command ...
Hope you can fix it for me i have here lots of cpu power : )
deeptrap is offline   Reply With Quote
Old 08-07-2012   #193
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by deeptrap View Post
I know
Tried now on XP machine (also win 7)
Same error

od is not recognized as an internal or external command ...
Hope you can fix it for me i have here lots of cpu power : )
Well, od.exe is in the zipfile. So you're doing something wrong.

You need to put the content from the zipfile in the same folder as SCEtool, eboot.elf and somefile.sprx. Edit the bat file as needed if you want to try with another elf/sprx combination. Run from a dos-window. This is not some easy tool to use by double-clicking
Asure is offline   Reply With Quote
Old 08-07-2012   #194
longhornx
Member
 
Join Date: Oct 2008
Posts: 182
Likes: 16
Liked 15 Times in 10 Posts
Mentioned: 15 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Asure View Post
Well, i left it running overnight, and OD.exe crashed after ~19000 tries.

I started calculating how long things will take. Currently my pc does ~10 key/sec from eboot.elf, and there's ~700000KBytes in the file. I'm shifting one byte at a time, so that's roughly 20 hours we're looking at to try all the possible options. (It can do ~600keys / minute. For a 700KB file, shifting one byte at a time, that's 700.000/600=roughly 20 hours)

There must be better ways. Perhaps once we get a few decrypted samples.

I'm testing with a SPRX and ELF (portal2) now, since the eboot.elf is only ~700kb. You can do the math for the 33MB elf/self combination for Rage if you want
its what I'm aspecting..., certely the klicense is located under a sce header, or some reference hex, with 4self's with possible to have sure if is location is fixed
longhornx is offline   Reply With Quote
Old 08-07-2012   #195
deeptrap
Apprentice
null
 
Join Date: Aug 2012
Posts: 26
Likes: 1
Liked 2 Times in 2 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Asure View Post
Well, od.exe is in the zipfile. So you're doing something wrong.

You need to put the content from the zipfile in the same folder as SCEtool, eboot.elf and somefile.sprx. Edit the bat file as needed if you want to try with another elf/sprx combination. Run from a dos-window. This is not some easy tool to use by double-clicking
Got it working

not the good user rights on the od.exe .

The eboot.elf file which one doe i have to use to compare

decryption of this one :

scetool.exe --decrypt ..\EBOOT.BIN ..\workdir\DECRYPTED.ELF

or

this one second part of decryption from the eboot

scetool.exe --decrypt ..\workdir\MODDED_EBOOT.BIN ..\workdir\FIXED.ELF

(source from _d_S_ : update decryption npdrm bat)

btw here 180 keys / sec 1 min . almost 11000 keys a minute
deeptrap is offline   Reply With Quote
Old 08-07-2012   #196
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by deeptrap View Post
Got it working

not the good user rights on the od.exe .

The eboot.elf file which one doe i have to use to compare

decryption of this one :

scetool.exe --decrypt ..\EBOOT.BIN ..\workdir\DECRYPTED.ELF

or

this one second part of decryption from the eboot

scetool.exe --decrypt ..\workdir\MODDED_EBOOT.BIN ..\workdir\FIXED.ELF

(source from _d_S_ : update decryption npdrm bat)

btw here 180 keys / sec 1 min . almost 11000 keys a minute
You can use both fixed.elf, or decrypted.elf.
You must use a sprx/self which is related to the fixed.elf or decrypted.elf.
See the included batch file for an example (portal 2).
Asure is offline   Reply With Quote
Old 08-07-2012   #197
deeptrap
Apprentice
null
 
Join Date: Aug 2012
Posts: 26
Likes: 1
Liked 2 Times in 2 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Im trying the npdrm update from mw3 1.01 update to decrypt EP0002-BLES01433_00-MW3P000000000010-A0102-V0100-PE.

the update contains eboot.bin and default.self and default_mp.self..

im now trying to decrypt default.self with this bruteforce methode.

eboot.bin is 76 Kb default.self = 7 MB

btw i m only do 2000 keys / min . little calculation error...

im now at offset 68000..
************* [ - Post Merged - ] *************
btw im seeing a lot of 0000 something other mubers but the most are 000

Working with offset: 69527
Trying 00000000000000000000000000000000
Working with offset: 69528
Trying 00000000000000000000000000000000
Working with offset: 69529
Trying 00000000000000000000000000000000
Working with offset: 69530
Trying 00000000000000000000000000000000
Working with offset: 69531
************* [ - Post Merged - ] *************
Working with offset: 71495
od: cannot skip past end of combined input

Last edited by deeptrap; 08-07-2012 at 06:24 AM.
deeptrap is offline   Reply With Quote
Old 08-07-2012   #198
JonahUK
Senior Member
 
Join Date: Jul 2011
Location: Salford, UK
Posts: 1,264
Likes: 578
Liked 781 Times in 494 Posts
Mentioned: 166 Post(s)
Tagged: 0 Thread(s)
@Asure ,

Don't you get the k_license from the pkg rather than the elf or any other files within the pkg?

The k_license is only used when building a pkg (entered in package.conf) and (afaik), its the only time the k_license is introduced so I don't think it will be in the files but rather the package itself.

I may be wrong but its worth looking at.
JonahUK is offline   Reply With Quote
Old 08-07-2012   #199
Asure
Member
 
Join Date: Jan 2008
Posts: 245
Likes: 27
Liked 127 Times in 72 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by deeptrap View Post
Im trying the npdrm update from mw3 1.01 update to decrypt EP0002-BLES01433_00-MW3P000000000010-A0102-V0100-PE.
the update contains eboot.bin and default.self and default_mp.self..
This update is 3.7x and you cannot decrypt eboot.bin, so that's no use..

...
Just grabbed BLUS30838 and this is also 3.72 now.. i could swear it was 3.60 a day ago?!?
Asure is offline   Reply With Quote
Old 08-07-2012   #200
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 8,912
Likes: 6,259
Liked 3,818 Times in 2,482 Posts
Mentioned: 947 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Asure View Post
Just grabbed BLUS30838 and this is also 3.72 now.. i could swear it was 3.60 a day ago?!?

Strange!? wtf!?
__________________
DEFAULTDNB is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 10:41 PM.