Go Back  
Reply
 
Thread Tools
Old 10-23-2012   #1
RickDangerous
Member
 
RickDangerous's Avatar
 
Join Date: Nov 2011
Posts: 82
Likes: 118
Liked 22 Times in 15 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
Kakarotos jailbreak - LV0 update

Wiki updated today with this:

Since the LV0 keys have now been leaked, I believe I can now share this info with you, to help out those who are trying to build their own 4.x CFW :
The NPDRM ECDSA signature in the SELF footer is checked by lv2. It first asks appldr to tell it whether or not the signature is to be checked, and appldr will only set the flag if the SELF is a NPDRM with key revision from 3.56+ (the ones without private keys). This means that the SELF files signed with the new 3.56+ keys still don't have their ecdsa checked (probably to speed up file loading).
If appldr says the ecdsa signature must be checked, then lv2 will verify it itself, and return an error if it's not correct. There are many ways to patch this check out.
1 - Patch out the check for the key revision in appldr
2 - Patch out the "set flag to 1" in appldr if the key revision is < 0xB
3 - Patch out the code in lv2 that stores the result from appldr
4 - Patch out the actual sigcheck function from lv2.
5 - Ignore the result of the ecdsa from lv2.

Here is one of the patches (the 4th one, patching out the check function from lv2) :
In memory 0x800000000005A2A8, which corresponds to offset 0x6a2a8 in lv2_kernel.elf, replace :
e9 22 99 90 7c 08 02 a6
With :
38 60 00 00 4e 80 00 20

This is for the 4.21 kernel (that was the latest one when I investigated this), I will leave it as an exercise to the reader to find the right offsets for the 4.25 and upcoming 4.30 kernel files.
And here's another bit of info... in 4.21 lv2, at memory address 0x800000000005AA98 (you figure out the file offset yourself), that's where lv2 loads the 'check_signature_flag' result from appldr, so if you prefer implementing method 3 above, just replace the 'ld %r0, flag_result_from_appldr' by 'ld %r0, 0' and you got another method of patching it out. Either solutions should work just the same though.
Enjoy homebrew back on 4.x CFW....

p.s: Thanks to flatz and glu0n who helped reversing this bit of info.

Source: http://ps3devwiki.com/wiki/KaKaRoTo_...ailbreak%C2%B4
RickDangerous is offline   Reply With Quote
Old 10-23-2012   #2
hostile666
Member
 
hostile666's Avatar
 
Join Date: Dec 2011
Location: Rio de Janeiro, Brasil
Posts: 139
Likes: 129
Liked 93 Times in 60 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
I really hope this means HEN for ofw 4.21
__________________
Best console rpg EVER:
hostile666 is offline   Reply With Quote
Old 10-23-2012   #3
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 8,860
Likes: 6,244
Liked 3,803 Times in 2,470 Posts
Mentioned: 941 Post(s)
Tagged: 0 Thread(s)
This is big news
__________________
DEFAULTDNB is online now   Reply With Quote
Old 10-23-2012   #4
MajorDisaster
Member
 
MajorDisaster's Avatar
 
Join Date: Jul 2008
Posts: 824
Likes: 513
Liked 289 Times in 181 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
what a wonderful last couple days, the awesomeness isn't done yet after 4.30 ofw a new Rebug is going to be release
__________________
Lord, grant me the serenity to accept the things I cannot change, the courage to change the things I can, and the wisdom to hide the bodies.
MajorDisaster is offline   Reply With Quote
Old 10-23-2012   #5
miksu123
Member
 
miksu123's Avatar
 
Join Date: Sep 2011
Posts: 59
Likes: 4
Liked 8 Times in 4 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
miksu123 is offline   Reply With Quote
Old 10-23-2012   #6
RickDangerous
Member
 
RickDangerous's Avatar
 
Join Date: Nov 2011
Posts: 82
Likes: 118
Liked 22 Times in 15 Posts
Mentioned: 1 Post(s)
Tagged: 0 Thread(s)
I'm glad he decided to release it now that he lost his motivation for the ps3 scene, but I'm sad to see that he's leaving.
RickDangerous is offline   Reply With Quote
Likes: (1)
Old 10-23-2012   #7
alexsius
Member
 
alexsius's Avatar
 
Join Date: Mar 2012
Posts: 178
Likes: 10
Liked 7 Times in 7 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
I m wondering how to decrypt the coreos and the lv2_kernel.self for edit the elf without the 4.21 keys...
alexsius is offline   Reply With Quote
Old 10-23-2012   #8
depblkman
Member
 
depblkman's Avatar
 
Join Date: Jan 2011
Posts: 478
Likes: 286
Liked 175 Times in 112 Posts
Mentioned: 17 Post(s)
Tagged: 0 Thread(s)
Send a message via Yahoo to depblkman
Christmas has once again came early. Just wait a couple of days folks. 4.xx CFW will be much more stable and safe. I believe for the Noobs, there will be a safe way to implement all they have been either trolling or waiting patiently(yea, right) for.
__________________
Alucard: Bet your a skank!
Hellsing: Bet your an arsehole!
Alucard: B**CH I EAT PEOPLE!!!
depblkman is online now   Reply With Quote
Old 10-23-2012   #9
mirkie
Member
 
Join Date: Feb 2012
Posts: 337
Likes: 52
Liked 170 Times in 97 Posts
Mentioned: 20 Post(s)
Tagged: 0 Thread(s)
Oh its mr. Impossible cfw on 3,60+

haha!
************* [ - Post Merged - ] *************
Oh its mr. Impossible cfw on 3,60+

haha!
mirkie is offline   Reply With Quote
Old 10-23-2012   #10
fanboysarestupid
 
Join Date: Aug 2012
Posts: 816
Likes: 165
Liked 128 Times in 92 Posts
Mentioned: 43 Post(s)
Tagged: 0 Thread(s)
Exciting news hopefully someone will make a 4.21 CFW for 4.21 OFW.
fanboysarestupid is offline   Reply With Quote
Likes: (3)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 09:36 AM.