Go Back  
Reply
 
Thread Tools
Old 11-04-2012   #1
CaptainCPS-X
Homebrew Developer
 
CaptainCPS-X's Avatar
 
Join Date: Sep 2010
Location: Puerto Rico, U.S.
Posts: 906
Likes: 1,066
Liked 2,021 Times in 512 Posts
Mentioned: 347 Post(s)
Tagged: 0 Thread(s)
Arrow [Idea] Modify OFW3.56+ HDD with resigned apps / exploits

Hey guys idk if this is possible but recently I been thinking about an idea of how could someone on OFW 3.56+ manage to install something that has been resigned now that we have many keys at our disposal.

I'm not gonna be very technical since I just wanted to share this idea so if anyone has the "skills" (lol) they could consider doing an exploit based on it.

The Idea is as follow:

- Remove the PS3 HDD running on OFW 3.56+
- Decrypt the PS3 HDD on a PC by using @Naehwert 's PS3HDD ( http://www.ps3hax.net/2012/08/naehrw...dd-encryption/ ) (some dev(s) was(were) experimenting with this some months ago, if I remember correctly)
- Modify the PS3 HDD contents and inject (if possible) a resigned application for that FW now that we have many keys (example: exploit app for OFW 4.21 / 4.30)
- Encrypt the PS3 HDD
- Place the PS3 HDD back in the PS3
- Exploit ? xD

If someone could confirm if this idea cannot be done, and knows why it cannot be done with facts, I will appreciate any information.

Maybe if this was possible, probably we could run some kind of application that allowed us to downgrade OFW or just install CFW, idk.

Maybe all this is just garbage xD and I'm just dreaming haha!

SeeYa!
__________________
gamePKG / FB Alpha RL - [ https://github.com/CaptainCPS ]
FB ALPHA DEV TEAM - [ http://neosource.1emu.net ] [ http://www.barryharris.me.uk/ ]
PS3 - [CECH-2501A][NOR][160GB HDD][REBUG CFW 4.41.2 LITE]

Last edited by CaptainCPS-X; 11-04-2012 at 03:39 PM.
CaptainCPS-X is offline   Reply With Quote
Old 11-04-2012   #2
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,061
Likes: 386
Liked 536 Times in 400 Posts
Mentioned: 150 Post(s)
Tagged: 0 Thread(s)
no.
We could use Kaka's Exploit to install the Apps, And The Appldr keys to get them to run I think, making a HEN is the Best idea.
tjhooker73 is online now   Reply With Quote
Old 11-04-2012   #3
Goldeneye
Member
 
Goldeneye's Avatar
 
Join Date: Nov 2011
Location: Under your bed
Posts: 218
Likes: 93
Liked 89 Times in 55 Posts
Mentioned: 26 Post(s)
Tagged: 0 Thread(s)
Send a message via MSN to Goldeneye Send a message via Skype™ to Goldeneye
Originally Posted by tjhooker73 View Post
no.
We could use Kaka's Exploit to install the Apps, And The Appldr keys to get them to run I think, making a HEN is the Best idea.
whatever happend to his HEN anyway?
he didn't start working on it after the keys got leaked, did he?
__________________
PlayStation 3 (CECH-3004A) - OFW 4.25 (160gb)
XBox 360 - Lite-On DG-16D5S - LT Ultimate 1.2
Fixes|MinFWChecker|Emulators

Last edited by Goldeneye; 11-04-2012 at 03:54 PM.
Goldeneye is offline   Reply With Quote
Old 11-04-2012   #4
zecoxao
Member
 
zecoxao's Avatar
 
Join Date: Oct 2011
Posts: 708
Likes: 390
Liked 708 Times in 276 Posts
Mentioned: 115 Post(s)
Tagged: 0 Thread(s)
ps3_hdd poc works like this:
you get your per_console_key
you get the dumped sectors (aka an hdd dump) swaped with bswap16
you compile the app
you run it
voilá decrypted sectors. stick some kpartx from linux with ps3 patches from glevand and you can browse the insides of your hdd from linux like it was nothing.

i don't see any problem here, since 4.21.1 REX can run otheros++. but, the problem would be to swap the hdd, since that when we put the hdd of another console into a different one. it'll ask for format. or am i wrong here?
__________________
"Whoever has ears, let them hear."
zecoxao is offline   Reply With Quote
Likes: (3)
Old 11-04-2012   #5
luqi
Member
 
luqi's Avatar
 
Join Date: Sep 2010
Location: In My World
Posts: 306
Likes: 954
Liked 136 Times in 74 Posts
Mentioned: 25 Post(s)
Tagged: 0 Thread(s)
Originally Posted by zecoxao View Post
i don't see any problem here, since 4.21.1 REX can run otheros++. but, the problem would be to swap the hdd, since that when we put the hdd of another console into a different one. it'll ask for format. or am i wrong here?
youre right , if you put the hdd out and in it ask for format.
luqi is offline   Reply With Quote
Old 11-04-2012   #6
carldenning
Senior Member
 
Join Date: Jun 2009
Posts: 5,125
Likes: 1,880
Liked 1,789 Times in 1,170 Posts
Mentioned: 220 Post(s)
Tagged: 0 Thread(s)
thought i let u know ive tried homebrew signed for 4.31 cfw before on ofw 4.31 and 4.21 and they didnt boot . came up error cant rememeber the error code but its the same code as if u try to run a fself eboot on cfw
__________________
carldenning is offline   Reply With Quote
Likes: (1)
Old 11-04-2012   #7
alexsius
Member
 
alexsius's Avatar
 
Join Date: Mar 2012
Posts: 178
Likes: 10
Liked 7 Times in 7 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
It s interesting the problem is how to add a homebrew in the hdd (it should be signed with 3.55 keys but i think this is not a problem) i don't know if ps3 can check what is installed in the console...
alexsius is online now   Reply With Quote
Old 11-04-2012   #8
CaptainCPS-X
Homebrew Developer
 
CaptainCPS-X's Avatar
 
Join Date: Sep 2010
Location: Puerto Rico, U.S.
Posts: 906
Likes: 1,066
Liked 2,021 Times in 512 Posts
Mentioned: 347 Post(s)
Tagged: 0 Thread(s)
Thumbs up

Thanks for your informative posts guys! I just wanted to know if this was possible, but I see there are still complications.

Thanks to @zecoxao for the technical details too

SeeYa!
__________________
gamePKG / FB Alpha RL - [ https://github.com/CaptainCPS ]
FB ALPHA DEV TEAM - [ http://neosource.1emu.net ] [ http://www.barryharris.me.uk/ ]
PS3 - [CECH-2501A][NOR][160GB HDD][REBUG CFW 4.41.2 LITE]
CaptainCPS-X is offline   Reply With Quote
Old 11-04-2012   #9
zecoxao
Member
 
zecoxao's Avatar
 
Join Date: Oct 2011
Posts: 708
Likes: 390
Liked 708 Times in 276 Posts
Mentioned: 115 Post(s)
Tagged: 0 Thread(s)
@carldenning they're bad-signed, it wouldn't work either ways because you'd need to know the private keys. since newer custom firmwares have the checks disabled , naturally they'd work on the cfw environment.
__________________
"Whoever has ears, let them hear."
zecoxao is offline   Reply With Quote
Likes: (1)
Old 11-04-2012   #10
pereb27
Member
 
pereb27's Avatar
 
Join Date: Sep 2011
Posts: 878
Likes: 152
Liked 277 Times in 189 Posts
Mentioned: 52 Post(s)
Tagged: 0 Thread(s)
Originally Posted by zecoxao View Post
ps3_hdd poc works like this:
you get your per_console_key
you get the dumped sectors (aka an hdd dump) swaped with bswap16
you compile the app
you run it
voilá decrypted sectors. stick some kpartx from linux with ps3 patches from glevand and you can browse the insides of your hdd from linux like it was nothing.

i don't see any problem here, since 4.21.1 REX can run otheros++. but, the problem would be to swap the hdd, since that when we put the hdd of another console into a different one. it'll ask for format. or am i wrong here?
I do see a problem. You can't get your per console key on OFW.
__________________
PS3 Slim CECH-3004A 160GB (500GB)
PS2 Slim SCPH-70004 - FMCB 1.8b
pereb27 is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 05:53 PM.