Go Back  
Reply
 
Thread Tools
Old 08-22-2012   #141
derako
Member
 
Join Date: Feb 2012
Posts: 69
Likes: 25
Liked 19 Times in 12 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
What about making it crash while playing Skirim? That game had to be patched to solve those crashing problems

Cheers
derako is offline   Reply With Quote
Old 08-22-2012   #142
sguerrini97
Member
 
Join Date: Jun 2011
Posts: 96
Likes: 42
Liked 14 Times in 12 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Originally Posted by badhabit View Post
to trigger the core dump you could use
samples/sdk/dbg/exception_handler in the 4+ sdk for example
using liblv2dbg
Thanks for the info.
I've compiled the exception_handler sample
Then I've made an mself (samples\sdk\lv2\multi-self) that contains as first self the "exception_handler_main.ppu.self" and as second self the original EBOOT (renamed EBOOT.self) of COD MW3 (BLES01430).

Here is it: http://www.mediafire.com/?otqtt5lq97t58be

If I'm right this should cause a core dump of both selfs.
I can't test it until tomorrow evening.. If someone wants to test just update to DEX 4.20, put the files from the archive to the fileserving dir (app_home) and execute from the target manager "/app_home/mself-main.ppu.self" then wait..
sguerrini97 is online now   Reply With Quote
Likes: (1)
Old 08-22-2012   #143
IngPereira
Member
 
Join Date: Apr 2012
Posts: 51
Likes: 28
Liked 119 Times in 23 Posts
Mentioned: 27 Post(s)
Tagged: 0 Thread(s)
I recommend that the fastest way is to swap some sprx (which can be activated from the XMB, like the music player is activated by playing any music in the usb).

audioplayer_plugin.sprx

With the SDK 3.70 you can create one sprx (It will trigger a Core dump) with FSELF in 4.11 and you can use a homebrew to remount the dev_flash with writing allowed (You can do this obviously with the SC 837 and 838 not need poke) so you can swap the sprx of the music player with your own!.

Now swap your new sprx, rename it to audioplayer_plugin.sprx (Ready to make a trigger that will call a Core dump) then run a game in bd-emu or original disc, later go back to XMB (The eboot remain in memory) and trigger the Core dump by trying to play any mp3 stored on usb with the modified audioplayer_plugin.sprx.

The sprx don't use much memory because this they are great to something like this(Documented on the SDK)...

I will try to do this because i have the 3.70 SDK...

Edit:The better way to do this is swapping xmb_ingame.sprx because you can call INGAME and trigger a Core dump while you are in the game, this will work better...

Last edited by IngPereira; 08-22-2012 at 06:44 PM.
IngPereira is offline   Reply With Quote
Likes: (3)
Old 08-22-2012   #144
tweetymr
Apprentice
 
Join Date: Jan 2011
Posts: 16
Likes: 5
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Originally Posted by IngPereira View Post
I recommend that the fastest way is to swap some sprx (which can be activated from the XMB, like the music player is activated by playing any music in the usb).

audioplayer_plugin.sprx

With the SDK 3.70 you can create one sprx (It will trigger a Core dump) with FSELF in 4.11 and you can use a homebrew to remount the dev_flash with writing allowed (You can do this obviously with the SC 837 and 838 not need poke) so you can swap the sprx of the music player with your own!.

Now swap your new sprx, rename it to audioplayer_plugin.sprx (Ready to make a trigger that will call a Core dump) then run a game in bd-emu or original disc, later go back to XMB (The eboot remain in memory) and trigger the Core dump by trying to play any mp3 stored on usb with the modified audioplayer_plugin.sprx.

The sprx don't use much memory because this they are great to something like this(Documented on the SDK)...

I will try to do this because i have the 3.70 SDK...
Sounds like a nice work-around I think it's worth a try.
tweetymr is offline   Reply With Quote
Old 08-22-2012   #145
ps3hen
Member
 
ps3hen's Avatar
 
Join Date: Jan 2011
Posts: 149
Likes: 228
Liked 104 Times in 57 Posts
Mentioned: 39 Post(s)
Tagged: 0 Thread(s)
The full quote of the post by cfwprophet from 'that site':
Hmm.. ok.. so only fake self or NPDRM fake self well then take MultiMan 04.02 which is a Retail NPDRM >> enable core dump function >> start MultiMan >> exit to XMB and be surprised.

Just only one little present. And now start to use your brains.

There is always a way.
That was part of an argument, cfwprophet was having with another member about the functionality of core dump. One member was saying that core dump would only work with fselfs, cfwprophet disagreed, with the above post. But in saying that multiman was a retail NPDRM self, showed great ignorance on the matter and was pointed out by a few members. cfwprophet has stayed quite since. Now I've never used core dump before, so I don't know either way. But information from someone who thought multiman was a proper retail NPDRM self, should be taken with a pinch of salt.
__________________
Co-developer of XMB Manager Plus - One of the few and maybe even the only open collaboration project on the PS3 Scene without any drama.
ps3hen is offline   Reply With Quote
Old 08-23-2012   #146
harryoke
Senior Member
 
harryoke's Avatar
 
Join Date: Aug 2011
Location: Inside your mind
Posts: 1,950
Likes: 1,044
Liked 1,383 Times in 751 Posts
Mentioned: 209 Post(s)
Tagged: 0 Thread(s)
we need to make a RSX exception i think....mess with some game files....textures ingame maybe?
harryoke is offline   Reply With Quote
Old 08-23-2012   #147
KDSBest
Homebrew Developer
 
Join Date: Mar 2009
Location: Super Mario Land
Posts: 160
Likes: 32
Liked 299 Times in 87 Posts
Mentioned: 72 Post(s)
Tagged: 0 Thread(s)
TeaM_AC1D are doing alot research in that direction. If you know any way or got ideas tell me. Sibce we are waiting for some Hardware to get crafted for us, this is our time filler
KDSBest is offline   Reply With Quote
Likes: (1)
Old 08-23-2012   #148
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 8,861
Likes: 6,247
Liked 3,803 Times in 2,470 Posts
Mentioned: 946 Post(s)
Tagged: 0 Thread(s)
Originally Posted by KDSBest View Post
Since we are waiting for some Hardware to get crafted for us, this is our time filler
Hardware??
__________________
DEFAULTDNB is offline   Reply With Quote
Old 08-23-2012   #149
IM1990
 
Join Date: Nov 2008
Posts: 104
Likes: 81
Liked 34 Times in 14 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
I've heard that anons working on this method have been able to fix Lollipop Chainsaw too.I really think this is the way TB team was going for with their patches
IM1990 is offline   Reply With Quote
Old 08-23-2012   #150
kilom
Apprentice
 
Join Date: Jul 2012
Posts: 11
Likes: 1
Liked 3 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Originally Posted by mellss
Sorry to said that but if you see a black sheep in irish, you will say that all sheep are black?

Readself RELOAD.SELF (MULTIMAN):


Control info
control flags:
40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 --> flag DEBUG
file digest:
62 7c b1 80 8a b9 38 e3 2c 8c 09 17 08 72 6a 57 9e 25 86 e4
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Why i say that: because i investigate in it a long time ago. If you don't trust duplex and me, that they don't use coredump is when you decrypt DUPLEX EBOOT the last section is present (in coredump there are no the last section).

I think they got others keys (3.60+) or someone in their team have reversed drm eboot.
He is right, the last section (segment) isn't present in lv2coredump

- Comparison between decrypted reload.self and coredump reload.self with winhex doesn't match.
- I also tried to reencrypt my extracted coredump EBOOT.BIN and it said "read: elf error".

Moreover, liblv2coredump.sprx is user mode app, so it couldn't dump lv2 (kernel) or lv1 memory(hypervisor).
To hack full ram you need, to pwnage before hypervisor...

"People should attempt to hack hypervisor mode to get a debug cfw hen", like someone said me who have pwnage TB a long time ago.

Last edited by kilom; 08-23-2012 at 03:47 AM.
kilom is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 10:46 PM.