Go Back  
Reply
 
Thread Tools
Old 10-24-2012   #1
diesel701
Member
 
diesel701's Avatar
 
Join Date: Aug 2012
Posts: 116
Likes: 15
Liked 19 Times in 14 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Need help reversing appldr

Hi all!
After the lv0 keys in the wild, we can extract and decrypt loaders.
Now, we need to see in appldr or lv2_kernel for others keys.

I'm working to reverse the appldr and if someone with skill can help and share his work, I'm here.

For now, I've seen that there is only two functions that look at the key table.
And the key table is repeated twice in the appldr.

Someone that is doing the same here?
diesel701 is offline   Reply With Quote
Old 10-24-2012   #2
Raito
Apprentice
 
Join Date: Aug 2012
Posts: 20
Likes: 1
Liked 0 Times in 0 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Hi,

I have been debugging appldr via my anergistic on local linux box. But I can't find any trace of functions which use those keys table - Do you have any ( if so could u post please? ) I have been searching for some mailbox channel read ( readed that lv1 uses those to let appldr know to decrypt the game ) and been also looking for the 0x60 multiples ( that's the size of 1 key set in that table , thought maybe that way i could locate functions ) but no luck : /

Btw i wrote u pm read it please.
Raito is offline   Reply With Quote
Old 10-24-2012   #3
diesel701
Member
 
diesel701's Avatar
 
Join Date: Aug 2012
Posts: 116
Likes: 15
Liked 19 Times in 14 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Raito View Post
Hi,

I have been debugging appldr via my anergistic on local linux box. But I can't find any trace of functions which use those keys table - Do you have any ( if so could u post please? ) I have been searching for some mailbox channel read ( readed that lv1 uses those to let appldr know to decrypt the game ) and been also looking for the 0x60 multiples ( that's the size of 1 key set in that table , thought maybe that way i could locate functions ) but no luck : /

Btw i wrote u pm read it please.
I use IDA PRO, if you want I can send you or I can post some screeshots about these two functions...
diesel701 is offline   Reply With Quote
Old 10-24-2012   #4
spectlze
Member
 
Join Date: Oct 2011
Location: Puerto Rico
Posts: 133
Likes: 102
Liked 25 Times in 20 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
Wink

Anyone knows? Because the only key i could find in 4.self.elf was the NP_klic_key in ida pro. This is useful for game translation, game modding, patching games etc... so hopefully someone post a tutorial to get the decryption keys. I'm already on 4.21 cfw but i'm interested in getting the decryption keys.

Last edited by spectlze; 10-24-2012 at 02:00 PM.
spectlze is offline   Reply With Quote
Old 10-24-2012   #5
diesel701
Member
 
diesel701's Avatar
 
Join Date: Aug 2012
Posts: 116
Likes: 15
Liked 19 Times in 14 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
Originally Posted by spectlze View Post
Anyone knows? Because the only key i could find in 4.self.elf was the NP_klic_key in ida pro. This is useful for game translation, game modding, patching games etc... so hopefully someone post a tutorial to get the decryption keys. I'm already on 4.21 cfw but i'm interested in getting the decryption keys.
Keys are obfuscated in some way.. so you must see in appldr and reverse the code..
diesel701 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 08:58 AM.