Go Back  
Reply
 
Thread Tools
Old 10-20-2012   #1
H3avyRa1n
Senior Member
 
H3avyRa1n's Avatar
 
Join Date: Aug 2011
Posts: 1,269
Likes: 178
Liked 838 Times in 391 Posts
Mentioned: 59 Post(s)
Tagged: 0 Thread(s)
[RUMOUR]dump bootldr - how to exploit

dump bootldr how to exploit

Must have a dex 3.55 real or made dex 3.55 ps3 also duel nand/nor installed chip base. In a 3.55 dex console, prepare a lv0.self with the metadata exploit. reboot. lv0 will hang since lv0.self will not run properly. bootldr will send info to lv0 before it hangs, after it decrypts it, running dex with certain switches set up like boot in dev mode Will allow this hang dump of bootldr to be saved to the local store. But, essentially you will have a bricked ps3 so recovery of the local store wont happen. This is where the duel nand/nor comes in handy and allows you to recover from this and replace your messed up lv0.self with the original to boot up and recover the local store dump and the decrypted bootldr. This will allow the keys to bootldr these keys cannot be changed with any update. We can then exploit lv0. The exploit of bootldr/lv0 will allow the ability to change the way private keys are made or give us the ability to reset up the private key fail and resign packages with any new firmwares.

this although is just a "well tested Theory" of course


SOURCE
H3avyRa1n is offline   Reply With Quote
Old 10-20-2012   #2
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 8,860
Likes: 6,244
Liked 3,803 Times in 2,470 Posts
Mentioned: 943 Post(s)
Tagged: 0 Thread(s)
Very interesting! Thanks for the info @H3avyRa1n
__________________
DEFAULTDNB is offline   Reply With Quote
Old 10-20-2012   #3
budzio
Member
 
budzio's Avatar
 
Join Date: Sep 2008
Posts: 161
Likes: 47
Liked 40 Times in 26 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
any volunteer to try that method?
budzio is offline   Reply With Quote
Old 10-20-2012   #4
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,061
Likes: 386
Liked 536 Times in 400 Posts
Mentioned: 150 Post(s)
Tagged: 0 Thread(s)
I Am stunned at how easy this is, This means we can make an exploit for bootldr and make a CFW For any Firmware :O This is pretty similar to the ?Metlr? Exploit that ?PSGrade (3.21 dongle)? ?Used?

Last edited by tjhooker73; 10-20-2012 at 06:49 PM.
tjhooker73 is online now   Reply With Quote
Old 10-20-2012   #5
H3avyRa1n
Senior Member
 
H3avyRa1n's Avatar
 
Join Date: Aug 2011
Posts: 1,269
Likes: 178
Liked 838 Times in 391 Posts
Mentioned: 59 Post(s)
Tagged: 0 Thread(s)
Originally Posted by budzio View Post
any volunteer to try that method?
I would but I don't have a flasher in case this "well tested theory" goes, well, not as expected.
H3avyRa1n is offline   Reply With Quote
Likes: (1)
Old 10-20-2012   #6
cfwprpht
Homebrew Developer
 
Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
Uhm.....you want to use a lv0 with a exploit in it without the abbility to resign this lv0 ??

And all this just to dump the lv0 static keys which you will need before to replace on your console ??

Uhm....sry but you can't replace your lv0 with a hacked/exploit able one unless you have the static keys to do so but the problem here is you do that to get the static keys.

Or have i missunderstood something here ?
cfwprpht is offline   Reply With Quote
Likes: (4)
Old 10-20-2012   #7
baargle
Senior Member
 
Join Date: Sep 2010
Posts: 1,171
Likes: 601
Liked 622 Times in 373 Posts
Mentioned: 137 Post(s)
Tagged: 0 Thread(s)
I notice the words "well tested Theory", that means this works guaranteed - That or the person who wrote it can't speak english properly, let's just hope @hellsing9 didn't write it and it could actually be more than a collection of words.

Well tested theory......

Doesn't really make sense, a well "tested theory" is a working solution and no longer just a theory.

Last edited by baargle; 10-20-2012 at 07:06 PM.
baargle is offline   Reply With Quote
Old 10-20-2012   #8
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,061
Likes: 386
Liked 536 Times in 400 Posts
Mentioned: 150 Post(s)
Tagged: 0 Thread(s)
Originally Posted by cfwprpht View Post
Uhm.....you want to use a lv0 with a exploit in it without the abbility to resign this lv0 ??

And all this just to dump the lv0 static keys which you will need before to replace on your console ??

Uhm....sry but you can't replace your lv0 with a hacked/exploit able one unless you have the static keys to do so but the problem here is you do that to get the static keys.

Or have i missunderstood something here ?
lv0.self with the metadata exploit
I haven't heard of this one, But I assume You just need to change the metadata.
************* [ - Post Merged - ] *************
More Input on this would be Appreciated...
tjhooker73 is online now   Reply With Quote
Old 10-20-2012   #9
ryant001
Member
 
Join Date: Oct 2011
Posts: 427
Likes: 115
Liked 218 Times in 140 Posts
Mentioned: 18 Post(s)
Tagged: 0 Thread(s)
Originally Posted by tjhooker73 View Post
I Am stunned at how easy this is, This means we can make an exploit for bootldr and make a CFW For any Firmware :O This is pretty similar to the ?Metlr? Exploit that ?PSGrade (3.21 dongle)? ?Used?
Math did say that the bootldr suffered from fails similar to the metldr and we know that some devs already have a working exploit and managed to get the keys so i wouldn't completely dismiss this "well tested theory" as fake for now.
Maybe some good guy finally decided to share the exploit with us?
ryant001 is offline   Reply With Quote
Likes: (1)
Old 10-20-2012   #10
itskamel
Senior Member
 
itskamel's Avatar
 
Join Date: May 2011
Location: somewhere close
Posts: 3,981
Likes: 1,181
Liked 2,210 Times in 926 Posts
Mentioned: 329 Post(s)
Tagged: 0 Thread(s)
Send a message via Yahoo to itskamel
Random Pastie saves the scene.
itskamel is online now   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 12:01 PM.