|
|
#141 |
|
Member
![]() Join Date: Feb 2012
Posts: 69
Likes: 25
Liked 19 Times in 12 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
|
What about making it crash while playing Skirim? That game had to be patched to solve those crashing problems
Cheers |
|
|
|
|
|
#142 | |
|
Member
![]() Join Date: Jun 2011
Posts: 96
Likes: 42
Liked 14 Times in 12 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
|
I've compiled the exception_handler sample Then I've made an mself (samples\sdk\lv2\multi-self) that contains as first self the "exception_handler_main.ppu.self" and as second self the original EBOOT (renamed EBOOT.self) of COD MW3 (BLES01430). Here is it: http://www.mediafire.com/?otqtt5lq97t58be If I'm right this should cause a core dump of both selfs. I can't test it until tomorrow evening.. If someone wants to test just update to DEX 4.20, put the files from the archive to the fileserving dir (app_home) and execute from the target manager "/app_home/mself-main.ppu.self" then wait.. |
|
|
|
|
|
Likes: (1) |
|
|
#143 |
|
Member
![]() Join Date: Apr 2012
Posts: 51
Likes: 28
Liked 119 Times in 23 Posts
Mentioned: 27 Post(s)
Tagged: 0 Thread(s)
|
I recommend that the fastest way is to swap some sprx (which can be activated from the XMB, like the music player is activated by playing any music in the usb).
audioplayer_plugin.sprx With the SDK 3.70 you can create one sprx (It will trigger a Core dump) with FSELF in 4.11 and you can use a homebrew to remount the dev_flash with writing allowed (You can do this obviously with the SC 837 and 838 not need poke) so you can swap the sprx of the music player with your own!. Now swap your new sprx, rename it to audioplayer_plugin.sprx (Ready to make a trigger that will call a Core dump) then run a game in bd-emu or original disc, later go back to XMB (The eboot remain in memory) and trigger the Core dump by trying to play any mp3 stored on usb with the modified audioplayer_plugin.sprx. The sprx don't use much memory because this they are great to something like this(Documented on the SDK)... I will try to do this because i have the 3.70 SDK... Edit:The better way to do this is swapping xmb_ingame.sprx because you can call INGAME and trigger a Core dump while you are in the game, this will work better... Last edited by IngPereira; 08-22-2012 at 06:44 PM. |
|
|
|
|
Likes: (3) |
|
|
#144 | |
|
Apprentice
![]() Join Date: Jan 2011
Posts: 16
Likes: 5
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
I think it's worth a try.
|
|
|
|
|
|
|
#145 | |
|
Member
![]() Join Date: Jan 2011
Posts: 149
Likes: 228
Liked 104 Times in 57 Posts
Mentioned: 39 Post(s)
Tagged: 0 Thread(s)
|
The full quote of the post by cfwprophet from 'that site':
__________________
Co-developer of XMB Manager Plus - One of the few and maybe even the only open collaboration project on the PS3 Scene without any drama.
|
|
|
|
|
|
|
#146 |
|
Senior Member
![]() Join Date: Aug 2011
Location: Inside your mind
Posts: 1,943
Likes: 1,040
Liked 1,381 Times in 750 Posts
Mentioned: 209 Post(s)
Tagged: 0 Thread(s)
|
we need to make a RSX exception i think....mess with some game files....textures ingame maybe?
|
|
|
|
|
|
#147 |
|
Homebrew Developer
![]() Join Date: Mar 2009
Location: Super Mario Land
Posts: 160
Likes: 32
Liked 299 Times in 87 Posts
Mentioned: 72 Post(s)
Tagged: 0 Thread(s)
|
TeaM_AC1D are doing alot research in that direction. If you know any way or got ideas tell me. Sibce we are waiting for some Hardware to get crafted for us, this is our time filler
|
|
|
|
|
Likes: (1) |
|
|
#148 |
![]() ![]() Join Date: Mar 2012
Posts: 8,854
Likes: 6,244
Liked 3,801 Times in 2,469 Posts
Mentioned: 939 Post(s)
Tagged: 0 Thread(s)
|
Hardware??
__________________
|
|
|
|
|
|
#149 |
![]() ![]() Join Date: Nov 2008
Posts: 104
Likes: 81
Liked 34 Times in 14 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
|
I've heard that anons working on this method have been able to fix Lollipop Chainsaw too.I really think this is the way TB team was going for with their patches
|
|
|
|
|
|
#150 | |
|
Apprentice
![]() Join Date: Jul 2012
Posts: 11
Likes: 1
Liked 3 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
|
- Comparison between decrypted reload.self and coredump reload.self with winhex doesn't match. - I also tried to reencrypt my extracted coredump EBOOT.BIN and it said "read: elf error". Moreover, liblv2coredump.sprx is user mode app, so it couldn't dump lv2 (kernel) or lv1 memory(hypervisor). To hack full ram you need, to pwnage before hypervisor... "People should attempt to hack hypervisor mode to get a debug cfw hen", like someone said me who have pwnage TB a long time ago. Last edited by kilom; 08-23-2012 at 03:47 AM. |
|
|
|
|
|
Likes: (1) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|