Go Back  
Closed Thread
 
Thread Tools
Old 01-30-2012   #1
mcmrc1
Member
 
mcmrc1's Avatar
 
Join Date: Jan 2011
Location: Gliese 581g
Posts: 613
Likes: 531
Liked 346 Times in 176 Posts
Mentioned: 17 Post(s)
Tagged: 0 Thread(s)
Project: Cobra and True Blue PS3 Dongles - TB EBOOTs Examined

Just found this on an other (scene) site but link is censored with ***
I think links to other sites are allowed or not ? If not pls say it and i delete the link...

http://www.*******.com/ps3-hacks-jai...oots-examined/

As a follow-up on our previous article with the spirit of Operation: Mongoose in mind, we are continuing to examine both the Cobra and True Blue PS3 DRM-infected dongles and TB EBOOT files, and welcome any help with this project from other PlayStation 3 developers in the scene!

First let me tell you the following explanation is not a theory or any rumors, it's actually how the USB dongles work to allow different things.

We heard many rumors / theories about the process of the Cobra / True Blue but I didn't see anyone give any big answer about that (I'm not saying I would give you the big answer but the explanation how it works and how to make this possible)

Cobra / True Blue Part 1

Both dongle use syscall / payload (after a big investigation, both dongle also follow the work of graf_chokolo and the functionality of the dongle can be ported into a CFW (not a good idea from some devs I guess)

Cobra / True Blue use a lv1_wrapper (syscall implementation) that can allow to use subroutine function into kernel mode call. Following the dump of the Cobra / True Blue, every subroutine are indicated inside the dump (probably the reason of some clone like JB-King)

What all this mean ?

About the TB Eboot, i come back on what i said recently, the TB Eboot come from original Eboot (don't make any sense that they access to the dev server when have not Eboot on it) the PSN dev don't exist this way... but for related beta development games and testing beta multiplayer mode, interface beta test PSN for games etc... but nothing related to a Eboot.

TB use original Eboot and make their own sign (you can easily generate a new NPDRM sign with a Self/elf)

How can boot the games, the NPDRM Sign made in TB can't be run into a user mode, you would have a error of boot and every program that you resign etc... will not boot into a usermode... that's why we need to use a syscall that can let use into a kernel mode to execute a program that not recognized and authorized by the system. The dongle validates the actual eboot by syscall / subroutine.

For example, I want to have a execute something into the CoreOS but I'm not allowed because I can only execute this on a kernel mode, fine, I use my actual user mode to turn into a kernel mode by using a syscall.

A Syscall can allow you to execute, create, read, load, etc... The limitation of a dongle = the PS3 system, a dongle it's only here to prevent a error that by using redirection and syscall, the dongle give a correct answer that PS3 system execute.

If you check correctly the dump you can see 0x80 -> correspond to the C library, also when you call into kernel mode, the kernel fix the table permission that allow to give big access. You can recognized r1 stack register -> 0xA0 (debugger mode) -> R2 stack status...

Ok you probably gonna ask, what is that ? lol

It's actually a schema / plan from the dongle, the dongle is here to give a strong access to the system that you can execute what you want.

For example the PS2 Emu of Cobra = PS2 self (is not executed into a user mode but kernel mode / debugger mode that) reason why it can be execute under a PS3 Slim retail without following an error system.

How this can help ?

This mean many things, that you don't need any keys to execute under a kernel / debugger mode because anyway the syscall will give you a whole access to the cell execution.

I want to give a simply explanation that everybody can understand, the TB EBoot = Original Eboot from Original game, we not interested by the sce header, etc... we only want the elf header program represent and related to the game execution (like a exe, you patch the exe to be run without cd) here almost the same, we patch the elf with a fake sign can be run into a specific mode without asking anything.

What is weird, graf gave many oriented possibility and no one try to exploit them but only in a business way. Anyway like I said, the dongle is in relation with the PS3 system/Dev_Flash/Core_OS

I'm also working on it and try to do my best to release something strong and free... but my knowledge is limited and I can't do that alone.

Why I explain all that, it's because I want to see also some good dev can work on it with me, actually I want to thanks graf for all this awesome stuff, cfwprophet and all the PS3 scene that support us, I say also thanks to the people who insult me and said I'm a fake... more you said that and more I don't care and offer good stuff

Somebody said he want to be fame, no at all... I don't really care, my family and my gf give me already that by supporting me, it's enough

Anyway I would like this project to encourage PS3 homebrew developers to help out if they can, and also for the work that cfwprophet, me and others are doing on it will be updated here periodically.

PS: Probably go have more explanation and more stuff about it in the next week. Oh yes about the Debug PKG that is available on PSN Dev (it's not related to the TB Eboot)

You can make a Debug PKG yourself by only extracting the ELF, make a Self without NPDRM, leave him Eboot.self and make a PKG without NPDRM, this represent exactly what is a debug PKG (it's a standard Self inside a PKG without NPDRM)
__________________

Last edited by mcmrc1; 01-30-2012 at 09:39 AM.
mcmrc1 is offline  
Old 01-30-2012   #2
VIRGIN KLM
Senior Member
 
VIRGIN KLM's Avatar
 
Join Date: Mar 2008
Posts: 1,163
Likes: 322
Liked 468 Times in 260 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
Same people, same amount of posts, same grammar faults, same misspellings, same target = Misleading.
__________________

...and the worlds shall reconnect.
VIRGIN KLM is online now  
Old 01-30-2012   #3
OoZic
 
OoZic's Avatar
 
Join Date: Sep 2010
Location: Just ask Sony !!
Posts: 3,559
Likes: 1,186
Liked 1,757 Times in 1,028 Posts
Mentioned: 86 Post(s)
Tagged: 0 Thread(s)
Nab Nab, who is there?

Ah, it is nabnab

About the TB Eboot, i come back on what i said recently, the TB Eboot come from original Eboot (don't make any sense that they access to the dev server when have not Eboot on it) the PSN dev don't exist this way... but for related beta development games and testing beta multiplayer mode, interface beta test PSN for games etc... but nothing related to a Eboot.

Read more: http://www.*******.com/ps3-hacks-jai...#ixzz1kxS8MUjk
If they (TB) make their Eboots from original Eboots, why don't they have all new games like Batman Arkham city?
__________________
Sony just lost the PS3's chastity belt keys, secret fun spots are open to explore ...
OoZic is online now  
Old 01-30-2012   #4
VIRGIN KLM
Senior Member
 
VIRGIN KLM's Avatar
 
Join Date: Mar 2008
Posts: 1,163
Likes: 322
Liked 468 Times in 260 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
Originally Posted by OoZic View Post
Nab Nab, who is there?

Ah, it is nabnab



If they (TB) make their Eboots from original Eboots, why don't they have all new games like Batman Arkham city?
Just avoid him, can't you see what they are trying to do?
They are hiring people to mislead others, and since most people on PS3 scene are retarded it's really easy for them to attract alot of them in this trap.
Result?
More time for them to make money and less to no possibilities to crack the dongle.
__________________

...and the worlds shall reconnect.
VIRGIN KLM is online now  
Likes: (1)
Old 01-30-2012   #5
OoZic
 
OoZic's Avatar
 
Join Date: Sep 2010
Location: Just ask Sony !!
Posts: 3,559
Likes: 1,186
Liked 1,757 Times in 1,028 Posts
Mentioned: 86 Post(s)
Tagged: 0 Thread(s)
Originally Posted by VIRGIN KLM View Post
Just avoid him, can't you see what they are trying to do?
They are hiring people to mislead others, and since most people on PS3 scene are retarded it's really easy for them to attract alot of them in this trap.
Result?
More time for them to make money and less to no possibilities to crack the dongle.
I know, just wanted to point out that nabnab is the original author of this information on PS3n€ws
__________________
Sony just lost the PS3's chastity belt keys, secret fun spots are open to explore ...
OoZic is online now  
Old 01-30-2012   #6
TitaniumL
Member
 
TitaniumL's Avatar
 
Join Date: Aug 2011
Posts: 369
Likes: 207
Liked 146 Times in 88 Posts
Mentioned: 24 Post(s)
Tagged: 0 Thread(s)
Why do they do this? Why mislead people? What the hell is wrong with these people? Why are they so sick in the head? Leave us alone you money hungry scum!
TitaniumL is offline  
Old 01-30-2012   #7
Warning
 
Join Date: May 2011
Posts: 777
Likes: 324
Liked 516 Times in 269 Posts
Mentioned: 60 Post(s)
Tagged: 0 Thread(s)
******* is like youtube news. You don't even have to look at it to know it is fake. They even mention cfwprophet, which is like the BS stamp.
Warning is offline  
Old 01-30-2012   #8
mcmrc1
Member
 
mcmrc1's Avatar
 
Join Date: Jan 2011
Location: Gliese 581g
Posts: 613
Likes: 531
Liked 346 Times in 176 Posts
Mentioned: 17 Post(s)
Tagged: 0 Thread(s)
ok i donīt know.. i thought it was maybe good news
__________________
mcmrc1 is offline  
Old 01-30-2012   #9
VIRGIN KLM
Senior Member
 
VIRGIN KLM's Avatar
 
Join Date: Mar 2008
Posts: 1,163
Likes: 322
Liked 468 Times in 260 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
Originally Posted by Warning View Post
******* is like youtube news. You don't even have to look at it to know it is fake. They even mention cfwprophet, which is like the BS stamp.
Good example, Youtube vids saying "4.00CFW download" are equaly obvious fakes as these posts, I mean EQUAL.
If people don't believe these videos why do they believe those bad-english-making-zero-sense-at-all-filled posts?
Originally Posted by mcmrc1 View Post
ok i donīt know.. i thought it was maybe good news
Actually it's bad news, it means that we are bound to get bombardized on nearly a daily basis by those nolifers that don't have the word "shame" on their vocabulary.
__________________

...and the worlds shall reconnect.

Last edited by VIRGIN KLM; 01-30-2012 at 10:30 AM.
VIRGIN KLM is online now  
Old 01-30-2012   #10
mcmrc1
Member
 
mcmrc1's Avatar
 
Join Date: Jan 2011
Location: Gliese 581g
Posts: 613
Likes: 531
Liked 346 Times in 176 Posts
Mentioned: 17 Post(s)
Tagged: 0 Thread(s)
ok so can an admin pls delete this tread ? sry for that...
__________________
mcmrc1 is offline  
Closed Thread

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright Đ 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 03:03 AM.