Go Back  
Reply
 
Thread Tools
Old 10-22-2012   #191
sbmotoracer
Member
null
 
Join Date: Jul 2008
Posts: 45
Likes: 25
Liked 6 Times in 5 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
How exactly would you inject the code? The first thing that loads on the ps3 other then the syscon code is the cell bootloader.

Although I doubt it, has anyone actually looked at the code that verifies the SPU's authenticity? IE the code the Hardware processor uses inside the Cell.

I briefly looked at decapping a space cell chip a while back but after talking to a few people on irc and looking at the cost of an electron microscope. I never went through with it.


Edit - if the syscon is the first thing that loads then has anyone dumped the full syscon epprom?

Originally Posted by JustThatDude View Post
OkAy can we get back on topic. So far all we need to do i to dump the local storage of the SPU? There is always a way to slow down the CPU and if we can do that while its either booting up or slowing down it would be plausible to make a code to inject in it kind of like a NOP Slide or a buffer overflow of some sort to then dump the local storage and obtain the keys.

Last edited by sbmotoracer; 10-22-2012 at 11:09 AM.
sbmotoracer is offline   Reply With Quote
Likes: (1)
Old 10-22-2012   #192
zecoxao
Member
 
zecoxao's Avatar
 
Join Date: Oct 2011
Posts: 719
Likes: 398
Liked 721 Times in 279 Posts
Mentioned: 116 Post(s)
Tagged: 0 Thread(s)
so, what's the right offset for the decrypted metadata WE want? if we're attempting this by tries, we'll take ages and precious minutes of bricking our consoles, since bootldr has to load the right offset out of lv0. because we can do the same with metldr on a safe environment (linux/gameOS) we don't brick when we get the eid_root_key. how about bootldr? it'll brick, no?
__________________
"Whoever has ears, let them hear."
zecoxao is offline   Reply With Quote
Old 10-22-2012   #193
cfwprpht
Homebrew Developer
 
Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
Guys im sry but im out now. You don't listen what some one trie to tell's you with a good aim. You miss so much aknowledge about the PS3 and think every one is betraying you. Good Luck with "Slowing Down" the Cell or with Dumping "LocalStorage" from HDD or the embended Flash -.-
cfwprpht is offline   Reply With Quote
Old 10-22-2012   #194
sbmotoracer
Member
null
 
Join Date: Jul 2008
Posts: 45
Likes: 25
Liked 6 Times in 5 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
The reason I mentioned Spu's verification code and the syscon is those are 2 avenues of attack that(at least from what I've seen) haven't been looked at.

Originally Posted by cfwprpht View Post
Guys im sry but im out now. You don't listen what some one trie to tell's you with a good aim. You miss so much aknowledge about the PS3 and think every one is betraying you. Good Luck with "Slowing Down" the Cell or with Dumping "LocalStorage" from HDD or the embended Flash -.-
sbmotoracer is offline   Reply With Quote
Old 10-22-2012   #195
master737373
Member
 
Join Date: Mar 2012
Posts: 193
Likes: 11
Liked 72 Times in 47 Posts
Mentioned: 22 Post(s)
Tagged: 0 Thread(s)
Originally Posted by JustThatDude View Post
I didn't say that I said per console key
Lol that wasn't meant towards you.
************* [ - Post Merged - ] *************
No, you can't just take syscon eeprom mainly because no one has a flasher for it. Plus it's encrypted per console. Sycon doesn't even pull bootldr, the cell does. Decapping would be expensive if you want pck0 that way.
master737373 is offline   Reply With Quote
Old 10-22-2012   #196
sbmotoracer
Member
null
 
Join Date: Jul 2008
Posts: 45
Likes: 25
Liked 6 Times in 5 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Not that it would surprise me if it was but what makes you think that the syscon is encrypted inside the eeprom?

As for not having a flasher/dumper (correct me if im wrong since I had trouble finding any information about decapping eeproms)I would imagine once the bond wires are exposed they can be traced back to the vias at the bottom of the chip.


As for attacking the bootloader I really don't see a way around either not having a properly signed lv0 or taping the bus lines from memory to the cell.



Originally Posted by master737373 View Post
Lol that wasn't meant towards you.
************* [ - Post Merged - ] *************
No, you can't just take syscon eeprom mainly because no one has a flasher for it. Plus it's encrypted per console. Sycon doesn't even pull bootldr, the cell does. Decapping would be expensive if you want pck0 that way.
sbmotoracer is offline   Reply With Quote
Old 10-22-2012   #197
master737373
Member
 
Join Date: Mar 2012
Posts: 193
Likes: 11
Liked 72 Times in 47 Posts
Mentioned: 22 Post(s)
Tagged: 0 Thread(s)
Syscon is encrypted per console. Without your syscon key, you can't do anything with it. lv0 isn't the only way to get bootldr.
master737373 is offline   Reply With Quote
Old 10-22-2012   #198
sbmotoracer
Member
null
 
Join Date: Jul 2008
Posts: 45
Likes: 25
Liked 6 Times in 5 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
To keep from derailing the topic with my questions, mind listing the source where you learned that the syscon is encrypted per console?

Not disagreeing with you I just would like to learn more about the syscon and how its stores its data beyond whats listed in the dev wiki.


- On topic - what other methods do you have in mind? Does the bootloader take any inputs after the console has loaded?



Originally Posted by master737373 View Post
Syscon is encrypted per console. Without your syscon key, you can't do anything with it. lv0 isn't the only way to get bootldr.
sbmotoracer is offline   Reply With Quote
Old 10-22-2012   #199
jarmster
Member
 
jarmster's Avatar
 
Join Date: Feb 2011
Posts: 381
Likes: 50
Liked 86 Times in 58 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Well master...its game over now. so why not stop with the hints and explain in some detail how it works....Not like it matters now anyway and to be honest,
i wanna know...
jarmster is online now   Reply With Quote
Old 10-22-2012   #200
master737373
Member
 
Join Date: Mar 2012
Posts: 193
Likes: 11
Liked 72 Times in 47 Posts
Mentioned: 22 Post(s)
Tagged: 0 Thread(s)
The wiki doesn't have much about syscon because the main people who add to the wiki son know about syscon. They think syscon is signed with the same keys as bootldr. But guess what? Now you don't need bootldr. The ps3 has been almost busted wide open software-wise. Though there's still a lot left to learn.
master737373 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 09:33 AM.