|
|
#1 |
|
Senior Member
![]() Join Date: Aug 2011
Posts: 1,269
Likes: 178
Liked 838 Times in 391 Posts
Mentioned: 59 Post(s)
Tagged: 0 Thread(s)
|
[RUMOUR]dump bootldr - how to exploit
dump bootldr how to exploit
Must have a dex 3.55 real or made dex 3.55 ps3 also duel nand/nor installed chip base. In a 3.55 dex console, prepare a lv0.self with the metadata exploit. reboot. lv0 will hang since lv0.self will not run properly. bootldr will send info to lv0 before it hangs, after it decrypts it, running dex with certain switches set up like boot in dev mode Will allow this hang dump of bootldr to be saved to the local store. But, essentially you will have a bricked ps3 so recovery of the local store wont happen. This is where the duel nand/nor comes in handy and allows you to recover from this and replace your messed up lv0.self with the original to boot up and recover the local store dump and the decrypted bootldr. This will allow the keys to bootldr these keys cannot be changed with any update. We can then exploit lv0. The exploit of bootldr/lv0 will allow the ability to change the way private keys are made or give us the ability to reset up the private key fail and resign packages with any new firmwares. this although is just a "well tested Theory" of course SOURCE |
|
|
|
|
Likes: (19) |
|
|
#3 |
|
Member
![]() Join Date: Sep 2008
Posts: 161
Likes: 47
Liked 40 Times in 26 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
any volunteer to try that method?
|
|
|
|
|
|
#4 |
|
Senior Member
![]() Join Date: Jan 2011
Location: Texas
Posts: 2,061
Likes: 386
Liked 536 Times in 400 Posts
Mentioned: 150 Post(s)
Tagged: 0 Thread(s)
|
I Am stunned at how easy this is, This means we can make an exploit for bootldr and make a CFW For any Firmware :O This is pretty similar to the ?Metlr? Exploit that ?PSGrade (3.21 dongle)? ?Used?
__________________
Helpful Links: |MinVerCk|PS3DateCheck|SKU_Models|How to downgrade|My Image Host|
More: |PS3DEVWIKI|Kiosk Reverters|Jig|Progskeet|E3Flasher|EliteMossy| Index| ![]() Last edited by tjhooker73; 10-20-2012 at 06:49 PM. |
|
|
|
|
|
#5 |
|
Senior Member
![]() Join Date: Aug 2011
Posts: 1,269
Likes: 178
Liked 838 Times in 391 Posts
Mentioned: 59 Post(s)
Tagged: 0 Thread(s)
|
I would but I don't have a flasher in case this "well tested theory" goes, well, not as expected.
|
|
|
|
|
Likes: (1) |
|
|
#6 |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
Uhm.....you want to use a lv0 with a exploit in it without the abbility to resign this lv0 ??
And all this just to dump the lv0 static keys which you will need before to replace on your console ?? Uhm....sry but you can't replace your lv0 with a hacked/exploit able one unless you have the static keys to do so but the problem here is you do that to get the static keys. Or have i missunderstood something here ? |
|
|
|
|
Likes: (4) |
|
|
#7 |
|
Senior Member
![]() Join Date: Sep 2010
Posts: 1,171
Likes: 601
Liked 622 Times in 373 Posts
Mentioned: 137 Post(s)
Tagged: 0 Thread(s)
|
I notice the words "well tested Theory", that means this works guaranteed - That or the person who wrote it can't speak english properly, let's just hope
@hellsing9
didn't write it and it could actually be more than a collection of words.
Well tested theory...... Doesn't really make sense, a well "tested theory" is a working solution and no longer just a theory. Last edited by baargle; 10-20-2012 at 07:06 PM. |
|
|
|
|
|
#8 | ||
|
Senior Member
![]() Join Date: Jan 2011
Location: Texas
Posts: 2,061
Likes: 386
Liked 536 Times in 400 Posts
Mentioned: 150 Post(s)
Tagged: 0 Thread(s)
|
************* [ - Post Merged - ] ************* More Input on this would be Appreciated...
__________________
Helpful Links: |MinVerCk|PS3DateCheck|SKU_Models|How to downgrade|My Image Host|
More: |PS3DEVWIKI|Kiosk Reverters|Jig|Progskeet|E3Flasher|EliteMossy| Index| ![]() |
||
|
|
|
|
|
#9 | |
|
Member
![]() Join Date: Oct 2011
Posts: 427
Likes: 115
Liked 218 Times in 140 Posts
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
|
Maybe some good guy finally decided to share the exploit with us? |
|
|
|
|
|
Likes: (1) |
|
|
#10 |
|
Senior Member
![]() |
Random Pastie saves the scene.
|
|
|
|
|
Likes: (1) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|