|
|
#1 |
|
Apprentice
Join Date: Jan 2013
Posts: 1
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
The info has been going around that the new "lvl0" hack will allow signing and modding of any code.
I was wondering if that would make it possible to use it to take a 3.55 firmware and mod/sign it as say a 4.40 firmware so that it would trick the ps3 into thinking that it was upgrading to a new firmware. In theory that should get around the issue of the ps3 not allowing a downgrade because it would think that the firmware is newer than what is already on the system. I know that there will be a lot of people with an opinion on this - but what would be nice is if a known coder could answer this and tell me why it either can or cannot be done. Thanks |
|
|
|
|
|
#2 |
|
Member
![]() Join Date: Jan 2011
Posts: 213
Likes: 0
Liked 15 Times in 12 Posts
Mentioned: 21 Post(s)
Tagged: 0 Thread(s)
|
yes, that will work when you can sign that modified firmware with the right keys to make the PS3 accept it.
those keys will certainly never be caught (private keys). so you must have to find another way (exploit).
|
|
|
|
|
|
#3 |
|
Senior Member
![]() Join Date: Jan 2011
Location: Texas
Posts: 2,119
Likes: 394
Liked 553 Times in 413 Posts
Mentioned: 158 Post(s)
Tagged: 0 Thread(s)
|
No. Just no. You would need some special private key to Sign that firmware and a public key That we do not have/Cannot get.
I'm not a "Coder" But I'm telling you as of now/Ever its not gonna happen. Unless sony gets robbed and a new jig with all the Current/Future keys gets out then no it wont happen. Or we get a real Debugging unit and Decap a few things then no. ************* [ - Post Merged - ] ************* We would not need an exploit if we have the Bootldr Keys which we have (Not lv0) Cause we can get the public keys and unlock the firmwares. But no private to sign it. If we got the right private keys then it might be possible. But we would need a lot of keys.
__________________
Helpful Links: |MinVerCk|PS3DateCheck|SKU_Models|How to downgrade|My Image Host|
More: |PS3DEVWIKI|Kiosk Reverters|Jig|Progskeet|E3Flasher|EliteMossy| Index| ![]() Last edited by tjhooker73; 01-06-2013 at 02:24 AM. |
|
|
|
|
Likes: (2) |
|
|
#4 |
![]() ![]() Join Date: Mar 2012
Posts: 9,015
Likes: 6,284
Liked 3,883 Times in 2,531 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
|
As above, but you would also need HMAC keys for current ofw to allow the modded update to even think about installing on ofw iirc.
__________________
|
|
|
|
|
|
#5 |
|
Apprentice
![]() Join Date: Jun 2012
Posts: 26
Likes: 2
Liked 9 Times in 8 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Yes, private keys can't be calculated since 3.56+, HOWEVER, I strongly advice you to refresh your memory about:
-lv2 exploit (which was introduced to public as a DRM product by PSJAILBREAK). -the discovery of the bootldr's private/public keys (those who decrypt/encrypt lv0). -some juicy information regarding the bootldr exploit (especially JuanNadie's last message on this forum). Technically, LV2 exploit on latest ofw is probably more than enough. But If you can combine all of these things with an LV1 exploit together, you should have your answer to what can possibly be achieved for 3k and most (if not all) of the 4k models. |
|
|
|
|
Likes: (1) |
|
|
#6 | |
|
Member
![]() Join Date: Nov 2012
Location: Earth
Posts: 307
Likes: 32
Liked 38 Times in 32 Posts
Mentioned: 5 Post(s)
Tagged: 0 Thread(s)
|
__________________
Psp Dev, psp 3k semi unbrick solution
|
|
|
|
|
|
|
#7 | |
|
Homebrew Developer
![]() Join Date: Aug 2007
Posts: 112
Likes: 210
Liked 89 Times in 30 Posts
Mentioned: 25 Post(s)
Tagged: 0 Thread(s)
|
|
|
|
|
|
|
|
#8 | |
|
Apprentice
![]() Join Date: Jun 2012
Posts: 26
Likes: 2
Liked 9 Times in 8 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
like I said before, 3.56+ private keys can't be obtained or calculated through the console itself, all you can have are the public keys for every ofw revision thanks to the 3 musketeers.
Theoretically, if you can exploit a 3.6+ OFW, and you have enough privileges to exploit LV1 (which should allow you to install Linux), you can basically use the bootldr exploit that JuanNadie has published and obtain your CELL BE key, i.e you can write your own bootldr and basically do whatever you want (like installing your own cfw for 3k+ models). |
|
|
|
|
|
|
#9 |
|
Member
![]() Join Date: Jan 2013
Posts: 45
Likes: 1
Liked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Would it be possible that when ps3 update occurs. We will modify the packets and send our data instead official?
|
|
|
|
|
|
#10 |
|
Member
![]() Join Date: Oct 2011
Posts: 719
Likes: 398
Liked 721 Times in 279 Posts
Mentioned: 116 Post(s)
Tagged: 0 Thread(s)
|
the first thing needed would be not only one, but two things, a usermode and a kernel mode exploit. the usermode exploit would allow usermode execution, and the kernel mode exploit would allow kernel mode execution, the combination of both would be something user-kernel, that we can access within a game, for example(user) and which in turn gains us code execution for lv2(kernel). now, the possibilties would be to either a. start by a game or b. start by vsh. both are usermode land, and if you can enter usermode land, then it's possible to do some things. in games, you can control what's inside a game, while in vsh, you can control what's in the XMB. the next step would be to control lv2, which would require a lv2 exploit. we have two available right now, one requires a special flag in selfs to be executed, the other i have no idea how it works. as for usermode exploits, none are available at the moment for public viewing that i know of. and this is where we are standing at the moment. as for hardware exploits, i have no idea about them.
__________________
"Whoever has ears, let them hear."
|
|
|
|
|
Likes: (2) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|