|
|
#1 |
|
Member
![]() Join Date: Jun 2011
Posts: 81
Likes: 31
Liked 9 Times in 6 Posts
Mentioned: 4 Post(s)
Tagged: 0 Thread(s)
|
What are we missing ? chain of trust!!
3.60++
![]() ![]()
|
|
|
|
|
|
#2 |
![]() ![]() Join Date: Mar 2012
Posts: 8,856
Likes: 6,244
Liked 3,803 Times in 2,470 Posts
Mentioned: 940 Post(s)
Tagged: 0 Thread(s)
|
bootldr .2 (?)
lv0 .2 metldr .2 PCK0
__________________
|
|
|
|
|
Likes: (1) |
|
|
#3 |
|
Member
![]() Join Date: May 2011
Location: UK
Posts: 743
Likes: 114
Liked 173 Times in 108 Posts
Mentioned: 24 Post(s)
Tagged: 0 Thread(s)
|
not sure. but i found this: Posted by Wololo:
The problem is that we need a way to convince the PS3 to flash our modified firmware. With 3.55 and below that was easy enough to do because of the keys recovered, but 3.56 and later change that so that flashing is more complex than just using the recovered keys. This isn’t an insurmountable problem – hardware flashers will always work – but for easy software flashing we need to find new exploits in the PS3 software stack to convince OFW consoles to flash CFW
__________________
![]() Ps3 3.55WT, 1TB HDD, Find me on twitter@daveyp187 |
|
|
|
|
|
#4 |
|
Member
![]() Join Date: Jan 2011
Posts: 59
Likes: 50
Liked 2 Times in 2 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Pck0 is coming in some weeks from an group.What can we do with per console key0?
Edit: We need to decrypt 3.56 reverse and studi it and for the 3.70 fw the same. Shuld be easyer to look for changes in seciurety in lower fws. |
|
|
|
|
|
#5 |
![]() ![]() Join Date: Mar 2012
Posts: 8,856
Likes: 6,244
Liked 3,803 Times in 2,470 Posts
Mentioned: 940 Post(s)
Tagged: 0 Thread(s)
|
PCK0 = we can make any CFW we like forever.
HMAC key is used for installing update pup's.
__________________
|
|
|
|
|
Likes: (1) |
|
|
#6 |
|
Member
![]() Join Date: Jun 2012
Location: Right in the middle of ALL
Posts: 325
Likes: 113
Liked 113 Times in 80 Posts
Mentioned: 42 Post(s)
Tagged: 0 Thread(s)
|
the 3k consoles chain of trust is somewhat like this: bootldr--->lv0--->lv0.2 and to make use of the Lv0 keys we need to convince the bootldr to bypass the requirement of lv0.2 check as it is a pre-secure loader and not bound by any specific keyset..
in the 4k consoles the chain of trust is again changed and if an exploit is found for 3k consoles that won't work on these 4k consoles.. @DEFAULTDNB : Whoops, sorry... edited.. any idea of the 4k consoles?? trying to search for it and all I remember is that all ldrs are directly linked to the bootldr itself and since the bootldr is console specific hacking them is nearly impossible..
__________________
Last edited by poorguy; 11-02-2012 at 10:56 AM. Reason: Was wrong about the 3k chain of trust.. |
|
|
|
|
|
#7 |
|
Member
![]() Join Date: Feb 2011
Posts: 903
Likes: 303
Liked 447 Times in 296 Posts
Mentioned: 79 Post(s)
Tagged: 0 Thread(s)
|
But PCK0 is unique per console, and it will probably need an already exploited system, which by now can also always be updated forever, because of the compromised lv0, so I'd rephrase the question - what can we do with it that we cannot already?
Even if not that much, its ****ing interesting to see these things uncover anyway though. Must also be that way for the hackers
|
|
|
|
|
Likes: (1) |
|
|
#8 | |
![]() ![]() Join Date: Mar 2012
Posts: 8,856
Likes: 6,244
Liked 3,803 Times in 2,470 Posts
Mentioned: 940 Post(s)
Tagged: 0 Thread(s)
|
http://www.ps3devwiki.com/wiki/CoreOS
__________________
|
|
|
|
|
|
|
#9 | ||
|
Member
![]() Join Date: Jan 2011
Posts: 59
Likes: 50
Liked 2 Times in 2 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
************* [ - Post Merged - ] *************
|
||
|
|
|
|
|
#10 |
|
Member
![]() Join Date: Oct 2011
Posts: 708
Likes: 389
Liked 708 Times in 276 Posts
Mentioned: 115 Post(s)
Tagged: 0 Thread(s)
|
What we have:
loaders decrypt/metldr keys (geohot, as much as it pains me to say, he was the first to publicly announce the C0CEFE key) = possibilities of decrypting loaders (lv1ldr, lv2ldr, isoldr, appldr) lv0 decrypt/bootldr keys (Juan Nadie) = custom lv0, possibilities of decrypting X.XX firmware (lv0 goes first), possibilities of exploits in future firmwares, (printf on the goddamn screen of your TV showing up) , more keys, etc (eid/ps2 memory card/encdec/ata decrypt)/pck1 (Mathieulh ???) = custom eid0,1,2,3,4 (5 can't be decrypted so far, but if it's true and DEX firmware 4.30 really bricks, the keyseed might be hardcoded there) What we can have: (METHOD TO GET) -> (e)bootrom key/pck0 = custom bootldr, possibilities of decrypting X.XX firmware REGARDLESS of what Sony does (assuming we can execute that method on unhackable firmware, and that unhackable firmware exists, which is highly unlikely) .2 keys (present on higher firmwares, on later 2K and 3K consoles, and so on) -> assuming we used the hypothetical method to get (e)bootrom key/pck0, i think it's possible and safe to assume in a near future we might be able to get CFW over 3.56 and higher. These are my thoughts. Take them with consideration, as i don't deem them 100% correct by myself regarding future keys, i could be though
__________________
"Whoever has ears, let them hear."
Last edited by zecoxao; 11-02-2012 at 10:56 AM. |
|
|
|
|
Likes: (4) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|