Go Back  
Reply
 
Thread Tools
Old 09-25-2008   #1
Pirate
 
Pirate's Avatar
 
Join Date: Feb 2007
Posts: 6,946
Likes: 370
Liked 8,007 Times in 1,240 Posts
Mentioned: 575 Post(s)
Tagged: 0 Thread(s)
PS3 Flash ECC Algorithm Reversed!

Hackers have managed to reverse the code on the ECC protection on the PS3. What is the ECC Protection? The ECC protection basically kept the PS3 from booting with a custom flashed rom, with the ECC now claimed to be reversed, we can now generate custom ones to allow the rom to boot! The hackers have also claimed that through the reversing of the ECC they have found where the encypted keys are stored for SELF's, PKG's etc.

They also report that they were able to recover a "bricked" PS3 through this (bad flash recovery).

Originally Posted by http://www.ps3scene.com/news/static/Playstation3FlashECCAlgorithmReversed-1222105885.php
First, a small technical explanation. We were not able to modify any data on the PS3's flash chips due to the ECC. The ECC is a checksum basically, that ensures whatever data is in the block is not changed or corrupted, and if it is it errors. So, the problem was since when we tried to alter data, the ECC would then in turn be invalid, causing errors, making the system not boot. We did develop a way around this, however, it was time consuming and quite slow. We used the PS3 to write data to the flash, then dump it, with its proper ECC, then rewrite to where we needed it. This would take hours on end! We were not able to regenerate the ECC since we did not know the proper algorithm. But now, we can!!

After multiple tests done by NDT to see what the ECC algorithm was when the block was filled with some magic data, our very own RPS was able to reverse the algorithm!

What does this mean? Simple, we are now able to in minutes properly edit a flash dump, regenerate the ECC and flash it onto the PS3 in order to experiment with flash changes. Using this, we have already found where the encrypted keys are stored for SELF's, PKG's, and BD Pairing among other things, more on that in the weeks to come.

Furthermore, NDT implemented RPS's ECC regeneration code into his newest FlowRebuilder, which will be posted next week!

Finally, this has already saved one PS3! Hacked2123's PS3, which bit the dust long ago due to a bad flash was recently fixed thanks to RPS's ECC Regeneration code which was built into NDT's newest FlowRebuilder!

His PS3 had bad data that did not match the ECC data, resulting in a plethora of issues. However, as described here, it is now fixed!
More research is currently still being done, we will keep you updated on their progress.

UPDATE: It is unconfirmed if this was done on a TEST PS3, or a Retail PS3 with INFECTUS chip installed.
__________________


Please do not PM me with help/questions (I will not reply). Use this for your questions.
PS3 Hacks
Pirate is offline   Reply With Quote
Old 09-25-2008   #2
Spiker
Senior Member
 
Join Date: Jun 2007
Location: Beloit, Wisconsin
Posts: 1,104
Likes: 12
Liked 19 Times in 16 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to Spiker
So this pretty much mean's PS3 Hacking is on its way, and soon that is, correct?
__________________
Spiker is offline   Reply With Quote
Old 09-25-2008   #3
Californian
Member
null
 
Join Date: May 2008
Location: Los Angeles, California
Posts: 39
Likes: 12
Liked 1 Time in 1 Post
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Yipeee!
Bye bye PS3 restrictions, hello homebrew!
Or should I say,
Hello World!
__________________
Californian
Californian is offline   Reply With Quote
Old 09-25-2008   #4
Spiker
Senior Member
 
Join Date: Jun 2007
Location: Beloit, Wisconsin
Posts: 1,104
Likes: 12
Liked 19 Times in 16 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to Spiker
There wont be much of a Hello World, as 'Hello World' is to show exploits that are, well, exploit..able. Anyways, this just lets us load stuff like a debug firmware if needed, which we can do a **** load on, lol.

We can now change stuff on the PS3 system, and throw it back on, but think about what it is going to take to recode the firmware...interesting...
__________________
Spiker is offline   Reply With Quote
Likes: (1)
Old 09-25-2008   #5
Ihatecompvir
Member
 
Ihatecompvir's Avatar
 
Join Date: Sep 2008
Posts: 177
Likes: 16
Liked 6 Times in 3 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
So what all we need to do is decrypt/write our own firmware and it will boot if we do it correctly?

Is downgrading now possible to anyone who does this?
Ihatecompvir is offline   Reply With Quote
Old 09-25-2008   #6
Spiker
Senior Member
 
Join Date: Jun 2007
Location: Beloit, Wisconsin
Posts: 1,104
Likes: 12
Liked 19 Times in 16 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to Spiker
possably, but we would need a source code to the file system, which the hack dev's have. So we are working on it, lol. But remember, nothing is really amazing at lower firmware's.
__________________
Spiker is offline   Reply With Quote
Old 09-25-2008   #7
Ihatecompvir
Member
 
Ihatecompvir's Avatar
 
Join Date: Sep 2008
Posts: 177
Likes: 16
Liked 6 Times in 3 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
I would ATLEAST like to see the game category in the XMB Renamed to "Ihatecompvir wuz here lol"

That would be so rad, but I don't think it would fit.
I believe the PS3 is about to be hacked

Scratch that, it IS hacked, I just want a hack to be released to the public.

Last edited by Ihatecompvir; 09-25-2008 at 08:26 PM.
Ihatecompvir is offline   Reply With Quote
Old 09-25-2008   #8
Spiker
Senior Member
 
Join Date: Jun 2007
Location: Beloit, Wisconsin
Posts: 1,104
Likes: 12
Liked 19 Times in 16 Posts
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to Spiker
I am going to take a wild guess, and bring your guy's hope's up for a moment.

I have a prediction that something major will happen in about 2 - 3 weeks. Major enough to be able to mod the firmware, or atleast some news of it. The progress we have no has made it all possible. "LET DO THIS! STREETSKATER FUUUUUUUUUUUUUU" ((Leroyyyy Jenkins)
__________________
Spiker is offline   Reply With Quote
Likes: (1)
Old 09-25-2008   #9
FreePlayPSP
Member
 
Join Date: Feb 2008
Location: New York, USA
Posts: 260
Likes: 20
Liked 35 Times in 18 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
I'm pretty sure this is done on a devkit system or with an Infectus... seeing how there's no way to use the PS3 to write to flash on a stock retail system.
FreePlayPSP is offline   Reply With Quote
Old 09-25-2008   #10
BobbyBlunt
Senior Member
 
BobbyBlunt's Avatar
 
Join Date: Aug 2007
Location: Virginia US
Posts: 3,030
Likes: 1,598
Liked 1,954 Times in 921 Posts
Mentioned: 194 Post(s)
Tagged: 0 Thread(s)
With access to the flash, custom firmware and downgraders are now possible. It will take some time but we now have an open window. A lot of progress has been made. I wonder who is going to be the first to write a custom firmware. I have experience with C++ and Visual Basic. If there is anything I can do to help please let me know. I understand that Basic will not help in this situation.
__________________
Follow me on Twitter @BobbyBlunt83 Contact me via our irc server irc.ps3sanctuary.com/6667 You can figure out how to do so here. Don't start sh!t, there wont be sh!t.
BobbyBlunt is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 11:59 PM.