Go Back  
Reply
 
Thread Tools
Old 12-02-2012   #1
ben.ss7
Apprentice
 
Join Date: Jul 2012
Posts: 12
Likes: 5
Liked 11 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
how to extract encrypted loaders from lv0.elf

Hi,
I have been wondering and researching on this forum on how to extract the encrypted loaders such as (lv1ldr,lv2ldr,isoldr) from lv0.elf. I haven't been successful so I thought I would ask the experts. How can I extract the encrypted loaders from lv0.elf?

Last edited by ben.ss7; 12-02-2012 at 06:32 AM. Reason: add more info
ben.ss7 is offline   Reply With Quote
Old 12-02-2012   #2
xxmcvapourxx
Member
 
Join Date: May 2010
Posts: 89
Likes: 49
Liked 64 Times in 38 Posts
Mentioned: 15 Post(s)
Tagged: 0 Thread(s)
You need to split the lv0 into 6 parts and then use scetools find the gui version to find out what ones are the following appldr,isoldr,lv2ldr Hope that help's then you got to reverse engineer using IDA pro Look on ps3devwiki that will help you out more!!
xxmcvapourxx is online now   Reply With Quote
Likes: (1)
Old 12-02-2012   #3
ben.ss7
Apprentice
 
Join Date: Jul 2012
Posts: 12
Likes: 5
Liked 11 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Hi,

Thanks for the help, but i don't quite understand what you mean by 6 parts could you please care to explain in more detail?
ben.ss7 is offline   Reply With Quote
Old 12-02-2012   #4
enosrasun
Member
 
enosrasun's Avatar
 
Join Date: Nov 2009
Posts: 190
Likes: 27
Liked 88 Times in 57 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
Originally Posted by ben.ss7 View Post
Hi,

Thanks for the help, but i don't quite understand what you mean by 6 parts could you please care to explain in more detail?
in lvo there are loaders encrypted

with a hex editor find this SCE
and then search down one more until you will find again SCE ,before than your encrypted loader end,, save it and decrypt it with scetool
enosrasun is offline   Reply With Quote
Likes: (1)
Old 12-02-2012   #5
ben.ss7
Apprentice
 
Join Date: Jul 2012
Posts: 12
Likes: 5
Liked 11 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
thanks for your reply, what shall i save the output filename as and what file type shall i save it as?
ben.ss7 is offline   Reply With Quote
Old 12-02-2012   #6
enosrasun
Member
 
enosrasun's Avatar
 
Join Date: Nov 2009
Posts: 190
Likes: 27
Liked 88 Times in 57 Posts
Mentioned: 11 Post(s)
Tagged: 0 Thread(s)
Originally Posted by ben.ss7 View Post
thanks for your reply, what shall i save the output filename as and what file type shall i save it as?

filename ..... what you want
type ........ .self (secured elf )
enosrasun is offline   Reply With Quote
Likes: (1)
Old 12-02-2012   #7
ben.ss7
Apprentice
 
Join Date: Jul 2012
Posts: 12
Likes: 5
Liked 11 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
so that file will contain all the loaders or only one of them and then i will decrypt with scetool using metldr keys?

Last edited by ben.ss7; 12-02-2012 at 10:11 AM.
ben.ss7 is offline   Reply With Quote
Old 12-05-2012   #8
ben.ss7
Apprentice
 
Join Date: Jul 2012
Posts: 12
Likes: 5
Liked 11 Times in 2 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Hi,

I have been able to extract all the loaders lv2ldr isoldr appldr and the .2 loaders for them 3 but I cant extract lv1ldr. Could someone teach me how to extract lv1ldr. I used the SCE technique through hex edit but there isn't an lv1ldr???
ben.ss7 is offline   Reply With Quote
Old 12-05-2012   #9
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,060
Likes: 386
Liked 536 Times in 400 Posts
Mentioned: 150 Post(s)
Tagged: 0 Thread(s)
Originally Posted by ben.ss7 View Post
Hi,

I have been able to extract all the loaders lv2ldr isoldr appldr and the .2 loaders for them 3 but I cant extract lv1ldr. Could someone teach me how to extract lv1ldr. I used the SCE technique through hex edit but there isn't an lv1ldr???
You may need to add some keys to the tool
Here are the keys: http://www.ps3hax.net/showthread.php...989#post474989
tjhooker73 is online now   Reply With Quote
Old 12-06-2012   #10
r07f1
Member
 
Join Date: Jan 2011
Posts: 187
Likes: 51
Liked 62 Times in 39 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
@ben.ss7

hey...
Simple algo...

1 - parse unencrypted lv0 like with a step of 0x4 bytes
2 - If magic == SCE_MAGIC read header (to find ldr size)
3 - Extract it

Oh and btw the ldr name can be found by looking @ the auth id...

http://www.ps3devwiki.com/wiki/SELF_...and_Decryption

and have a look @ f0f ps3tools
r07f1 is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 01:52 PM.