170w ago - Today
GeoHot has posted a few pictures (below) with the title "Custom Themes?" on the latest PlayStation 3 blog entry, however, no other useful details are available of the PS3 hack demonstration.
To speculate, it appears to illustrate modifying the PS3 GameOS XMB memory areas, but this was already known over a month ago when word first spread of the PS3 Hypervisor lv2 being dumped and reversed.
It's an RCO file edit, just like RCO edits on the PSP (almost same format too). RCO files are resource files for VSH plugins, live in the dev_flash, and aren't signed. To edit them on your system, patch your hypervisor to allow encrypted access to the partition (flash on old systems, hd on new), and mod ps3pf_storage. dev_flash is just a FAT partition, mount it in Linux and change what you'd like.
Nevertheless, it looks like progress is indeed being made editing and replacing an RCO in /dev_flash/vsh/resource/, although it would be nice if the information was made public so that other PS3 Devs in the scene could join in the fun.
From NDT: Le foto sono vere al 100% Ha modificato gli RCO dal dump della ram ma dato che non sono signed questo significa proprio poco. Si vede che stava cercando anche lui qualcosa da postare.
Rough translation: The photos are real 100% Changed the RCO by dump ram but since they have not signed this means just a little. One can see that he was looking for something to post.
Mathieulh: It's real, it has nothing to do with custom backgrounds, what he did was replace a rco file in dev_flash with one he edited (with a custom text in it).
To do that he had to mount dev_flash as rw because it is normally read only. You can do that if you know how to using his exploit under otheros.
As always, more details to come as they are available!
I don't recall GeoHot stating he would never provide any details, but aside from what was shared with Mathieulh he simply hasn't done so yet. Sooner or later others are bound to figure it out and post details how publically, although it could be months or years versus weeks before that happens is all.
While this decision delays progress, GeoHot isn't in a rush so I imagine most are waiting until himself, Mathieulh's crew or even someone such as simone or xorloser releases more than pictures like the RCO Edit ones at which point the scene will move forward again.
Beyond that, the Devs are waiting for the missing details from GeoHot on how to dump lv2 using it. Once it's dumped, it can be shared with others who can begin documenting the calls, reversing it, etc and move forward.
Didn't he say that he won't share any details? That's the main reason I don't like him (the "why" he won't share) and I'd be more than happy to change my mind.
Let's hope a way is found to edit and/or replace more files, especially core flags and such ^^
The most known about METLDR to date is located here: http://www.ps3news.com/forums/ps3-hacks/how-load-metldr-spu-isolation-mode-playstation-3-a-110199.html
Beyond that, the Devs are waiting for the missing details from GeoHot on how to dump lv2 using it. Once it's dumped, it can be shared with others who can begin documenting the calls, reversing it, etc and move forward.
I know it's a little more complicated than that, surely one of the devs can say?