Page 2 of 12 FirstFirst 1234 ... LastLast
Results 11 to 20 of 114



  1. #11
    Junior Member hacked2123's Avatar
    Join Date
    Nov 2006
    Posts
    665
    Quote Originally Posted by Maniac2k View Post
    @hacked2123: Shouldn't it be enough to do the same the original PSJB does? I think, if the log is complete everythin it does should be there.
    This isn't the complete log. From what I gather from the description of it, its only the procedural part of the device. At the very least there will be a point that the PSJB sends "Install Package Files"'s hex of
    Code:
    49 6E 73 74 61 6C 6C 20 50 61 63 6B 61 67 65 20
    46 69 6C 65 73
    That is NOT included in the retail firmware, and therefore must be sent from the PSJB.

  2. #12
    Member tmaster's Avatar
    Join Date
    Mar 2006
    Posts
    58
    Disane came up withe this for the hex code, This is the shellcode.

    1st PART
    Code:
    JIG_1.bin:     file format binary
    
    Disassembly of section .data:
    
    0000000000000000 <.data>:
       0:	09 02 12 00 	tdgti   r2,4608
       4:	01 00 00 80 	.long 0x1000080
       8:	fa 09 04 00 	std     r16,1024(r9)
       c:	00 00 fe 01 	.long 0xfe01
      10:	02 00 00 00 	.long 0x2000000
      14:	00 00 00 00 	.long 0x0
      18:	fa ce b0 03 	.long 0xfaceb003
      1c:	aa bb cc dd 	lha     r21,-13091(r27)
      20:	38 63 f0 00 	addi    r3,r3,-4096
      24:	38 a0 10 00 	li      r5,4096
      28:	38 80 00 01 	li      r4,1
      2c:	78 84 f8 06 	rldicr  r4,r4,63,0
      30:	64 84 00 70 	oris    r4,r4,112
      34:	38 a5 ff f8 	addi    r5,r5,-8
      38:	7c c3 28 2a 	ldx     r6,r3,r5
      3c:	7c c4 29 2a 	stdx    r6,r4,r5
      40:	28 25 00 00 	cmpldi  r5,0
      44:	40 82 ff f0 	bne+    0x34
      48:	38 84 00 80 	addi    r4,r4,128
      4c:	7c 89 03 a6 	mtctr   r4
      50:	4e 80 04 20 	bctr
    	...
      80:	7c 08 02 a6 	mflr    r0
      84:	f8 21 ff 61 	stdu    r1,-160(r1)
      88:	fb 61 00 78 	std     r27,120(r1)
      8c:	fb 81 00 80 	std     r28,128(r1)
      90:	fb a1 00 88 	std     r29,136(r1)
      94:	fb c1 00 90 	std     r30,144(r1)
      98:	fb e1 00 98 	std     r31,152(r1)
      9c:	f8 01 00 b0 	std     r0,176(r1)
      a0:	3b e0 00 01 	li      r31,1
      a4:	7b ff f8 06 	rldicr  r31,r31,63,0
      a8:	7f e3 fb 78 	mr      r3,r31
      ac:	64 63 00 05 	oris    r3,r3,5
      b0:	60 63 0b 3c 	ori     r3,r3,2876
      b4:	7f e4 fb 78 	mr      r4,r31
      b8:	64 84 00 70 	oris    r4,r4,112
      bc:	60 84 01 ac 	ori     r4,r4,428
      c0:	38 a0 04 fa 	li      r5,1274
      c4:	4b 97 bf 59 	bl      0xffffffffff97c01c
      c8:	7f e3 fb 78 	mr      r3,r31
      cc:	64 63 00 05 	oris    r3,r3,5
      d0:	60 63 0b 3c 	ori     r3,r3,2876
      d4:	38 63 00 20 	addi    r3,r3,32
      d8:	4b 9d 22 01 	bl      0xffffffffff9d22d8
      dc:	7f e3 fb 78 	mr      r3,r31
      e0:	64 63 00 05 	oris    r3,r3,5
      e4:	60 63 0b 3c 	ori     r3,r3,2876
      e8:	7f e4 fb 78 	mr      r4,r31
      ec:	64 84 00 2e 	oris    r4,r4,46
      f0:	60 84 b1 28 	ori     r4,r4,45352
      f4:	38 63 00 10 	addi    r3,r3,16
      f8:	f8 64 01 20 	std     r3,288(r4)
      fc:	7f e5 fb 78 	mr      r5,r31
     100:	64 a5 00 70 	oris    r5,r5,112
     104:	60 a5 01 50 	ori     r5,r5,336
     108:	80 65 00 00 	lwz     r3,0(r5)
     10c:	28 03 00 00 	cmplwi  r3,0
     110:	41 82 00 18 	beq-    0x128
     114:	80 85 00 04 	lwz     r4,4(r5)
     118:	7c 63 fa 14 	add     r3,r3,r31
     11c:	90 83 00 00 	stw     r4,0(r3)
     120:	38 a5 00 08 	addi    r5,r5,8
     124:	4b ff ff e4 	b       0x108
     128:	48 00 05 88 	b       0x6b0
     12c:	f8 21 ff 51 	stdu    r1,-176(r1)
     130:	7c 08 02 a6 	mflr    r0
     134:	fb c1 00 a0 	std     r30,160(r1)
     138:	fb e1 00 a8 	std     r31,168(r1)
     13c:	fb a1 00 98 	std     r29,152(r1)
     140:	f8 01 00 c0 	std     r0,192(r1)
     144:	3b c0 07 d0 	li      r30,2000
     148:	3b e0 00 c8 	li      r31,200
     14c:	4b 90 a9 b8 	b       0xffffffffff90ab04
     150:	00 04 90 e0 	.long 0x490e0
     154:	e8 82 0f 08 	ld      r4,3848(r2)
     158:	00 04 90 e4 	.long 0x490e4
     15c:	e8 7c 00 20 	ld      r3,32(r28)
     160:	00 04 90 e8 	.long 0x490e8
     164:	f8 64 00 00 	std     r3,0(r4)
     168:	00 04 f0 a8 	.long 0x4f0a8
     16c:	48 00 1a 9d 	bl      0x1c08
     170:	00 2a af c8 	.long 0x2aafc8
     174:	4b da 5b 80 	b       0xffffffffffda5cf4
     178:	00 04 ed 18 	.long 0x4ed18
     17c:	38 80 00 00 	li      r4,0
     180:	00 04 ed 1c 	.long 0x4ed1c
     184:	90 83 00 00 	stw     r4,0(r3)
     188:	00 04 ed 20 	.long 0x4ed20
     18c:	4e 80 00 20 	blr
     190:	00 3b a8 90 	.long 0x3ba890
     194:	01 00 00 00 	.long 0x1000000
     198:	00 05 05 d0 	.long 0x505d0
     19c:	38 60 00 01 	li      r3,1
     1a0:	00 05 05 d4 	.long 0x505d4
     1a4:	4e 80 00 20 	blr
     1a8:	00 00 00 00 	.long 0x0
     1ac:	38 60 00 01 	li      r3,1
     1b0:	4e 80 00 20 	blr
     1b4:	48 00 02 78 	b       0x42c
     1b8:	48 00 01 ec 	b       0x3a4
     1bc:	80 00 00 00 	lwz     r0,0(0)
     1c0:	00 05 0c a8 	.long 0x50ca8
     1c4:	80 00 00 00 	lwz     r0,0(0)
     1c8:	00 33 e7 20 	.long 0x33e720
     1cc:	80 00 00 00 	lwz     r0,0(0)
     1d0:	00 05 10 32 	.long 0x51032
     1d4:	80 00 00 00 	lwz     r0,0(0)
     1d8:	00 05 0b 7c 	.long 0x50b7c
     1dc:	80 00 00 00 	lwz     r0,0(0)
     1e0:	00 05 0b 8c 	.long 0x50b8c
     1e4:	80 00 00 00 	lwz     r0,0(0)
     1e8:	00 05 0b 9c 	.long 0x50b9c
     1ec:	80 00 00 00 	lwz     r0,0(0)
     1f0:	00 05 0b d4 	.long 0x50bd4
     1f4:	80 00 00 00 	lwz     r0,0(0)
     1f8:	00 33 e7 20 	.long 0x33e720
     1fc:	80 00 00 00 	lwz     r0,0(0)
     200:	00 05 0c 1c 	.long 0x50c1c
     204:	80 00 00 00 	lwz     r0,0(0)
     208:	00 33 e7 20 	.long 0x33e720
     20c:	80 00 00 00 	lwz     r0,0(0)
     210:	00 05 0c 78 	.long 0x50c78
     214:	80 00 00 00 	lwz     r0,0(0)
     218:	00 33 e7 20 	.long 0x33e720
     21c:	80 00 00 00 	lwz     r0,0(0)
     220:	00 05 0c 84 	.long 0x50c84
     224:	80 00 00 00 	lwz     r0,0(0)
     228:	00 33 e7 20 	.long 0x33e720
    	...
     244:	f8 21 ff 81 	stdu    r1,-128(r1)
     248:	7c 08 02 a6 	mflr    r0
     24c:	f8 01 00 90 	std     r0,144(r1)
     250:	38 80 00 00 	li      r4,0
     254:	38 a0 00 01 	li      r5,1
     258:	48 08 1d b1 	bl      0x82008
     25c:	80 a3 00 08 	lwz     r5,8(r3)
     260:	38 60 00 00 	li      r3,0
     264:	3c 80 aa aa 	lis     r4,-21846
     268:	60 84 c0 de 	ori     r4,r4,49374
     26c:	7c 04 28 40 	cmplw   r4,r5
     270:	41 82 00 08 	beq-    0x278
     274:	38 60 ff ff 	li      r3,-1
     278:	7c 63 07 b4 	extsw   r3,r3
     27c:	e8 01 00 90 	ld      r0,144(r1)
     280:	7c 08 03 a6 	mtlr    r0
     284:	38 21 00 80 	addi    r1,r1,128
     288:	4e 80 00 20 	blr
     28c:	f8 21 ff 81 	stdu    r1,-128(r1)
     290:	7c 08 02 a6 	mflr    r0
     294:	f8 01 00 90 	std     r0,144(r1)
     298:	38 80 00 00 	li      r4,0
     29c:	48 08 1d 99 	bl      0x82034
     2a0:	38 81 00 70 	addi    r4,r1,112
     2a4:	38 a0 00 00 	li      r5,0
     2a8:	f8 a4 00 00 	std     r5,0(r4)
     2ac:	38 c0 21 aa 	li      r6,8618
     2b0:	b0 c4 00 00 	sth     r6,0(r4)
     2b4:	38 c0 00 00 	li      r6,0
     2b8:	b0 c4 00 06 	sth     r6,6(r4)
     2bc:	38 c0 00 01 	li      r6,1
     2c0:	78 c6 f8 06 	rldicr  r6,r6,63,0
     2c4:	64 c6 00 05 	oris    r6,r6,5
     2c8:	60 c6 0b ac 	ori     r6,r6,2988
     2cc:	38 e0 00 00 	li      r7,0
     2d0:	48 08 1c cd 	bl      0x81f9c
     2d4:	38 60 00 00 	li      r3,0
     2d8:	e8 01 00 90 	ld      r0,144(r1)
     2dc:	7c 08 03 a6 	mtlr    r0
     2e0:	38 21 00 80 	addi    r1,r1,128
     2e4:	4e 80 00 20 	blr
     2e8:	38 60 00 00 	li      r3,0
     2ec:	39 60 00 ff 	li      r11,255
     2f0:	44 00 00 22 	sc      1
     2f4:	2c 03 00 00 	cmpwi   r3,0
     2f8:	40 82 00 1c 	bne-    0x314
     2fc:	38 60 00 01 	li      r3,1
     300:	78 63 f8 06 	rldicr  r3,r3,63,0
     304:	64 63 00 05 	oris    r3,r3,5
     308:	60 63 0b bc 	ori     r3,r3,3004
     30c:	38 80 00 01 	li      r4,1
     310:	90 83 00 10 	stw     r4,16(r3)
     314:	4e 80 00 20 	blr
     318:	f8 21 ff 31 	stdu    r1,-208(r1)
     31c:	7c 08 02 a6 	mflr    r0
     320:	f8 01 00 e0 	std     r0,224(r1)
     324:	fb e1 00 c8 	std     r31,200(r1)
     328:	38 81 00 70 	addi    r4,r1,112
     32c:	48 16 2e 81 	bl      0x1631ac
     330:	3b e0 00 01 	li      r31,1
     334:	7b ff f8 06 	rldicr  r31,r31,63,0
     338:	67 ff 00 05 	oris    r31,r31,5
     33c:	63 ff 0b bc 	ori     r31,r31,3004
     340:	e8 7f 00 00 	ld      r3,0(r31)
     344:	2c 23 00 00 	cmpdi   r3,0
     348:	41 82 00 0c 	beq-    0x354
     34c:	38 80 00 27 	li      r4,39
     350:	48 01 17 e9 	bl      0x11b38
     354:	38 80 00 27 	li      r4,39
     358:	38 60 08 00 	li      r3,2048
     35c:	48 01 13 9d 	bl      0x116f8
     360:	f8 7f 00 00 	std     r3,0(r31)
     364:	e8 81 00 70 	ld      r4,112(r1)
     368:	4b ff c5 f9 	bl      0xffffffffffffc960
     36c:	e8 61 00 70 	ld      r3,112(r1)
     370:	38 80 00 27 	li      r4,39
     374:	48 01 17 c5 	bl      0x11b38
     378:	e8 7f 00 00 	ld      r3,0(r31)
     37c:	4b ff c6 0d 	bl      0xffffffffffffc988
     380:	e8 9f 00 00 	ld      r4,0(r31)
     384:	7c 64 1a 14 	add     r3,r4,r3
     388:	f8 7f 00 08 	std     r3,8(r31)
     38c:	38 60 00 00 	li      r3,0
     390:	eb e1 00 c8 	ld      r31,200(r1)
     394:	e8 01 00 e0 	ld      r0,224(r1)
     398:	38 21 00 d0 	addi    r1,r1,208
     39c:	7c 08 03 a6 	mtlr    r0
     3a0:	4e 80 00 20 	blr
     3a4:	f8 21 ff 61 	stdu    r1,-160(r1)
     3a8:	7c 08 02 a6 	mflr    r0
     3ac:	fb 81 00 80 	std     r28,128(r1)
     3b0:	fb a1 00 88 	std     r29,136(r1)
     3b4:	fb e1 00 98 	std     r31,152(r1)
     3b8:	fb 41 00 70 	std     r26,112(r1)
     3bc:	fb 61 00 78 	std     r27,120(r1)
     3c0:	f8 01 00 b0 	std     r0,176(r1)
     3c4:	7c 9c 23 78 	mr      r28,r4
     3c8:	7c 7d 1b 78 	mr      r29,r3
     3cc:	3b e0 00 01 	li      r31,1
     3d0:	7b ff f8 06 	rldicr  r31,r31,63,0
     3d4:	7f a3 eb 78 	mr      r3,r29
     3d8:	7f e4 fb 78 	mr      r4,r31
     3dc:	64 84 00 05 	oris    r4,r4,5
     3e0:	60 84 10 28 	ori     r4,r4,4136
     3e4:	38 a0 00 09 	li      r5,9
     3e8:	4b ff c5 cd 	bl      0xffffffffffffc9b4
     3ec:	28 23 00 00 	cmpldi  r3,0
     3f0:	40 82 00 34 	bne-    0x424
     3f4:	67 ff 00 05 	oris    r31,r31,5
     3f8:	63 ff 0b bc 	ori     r31,r31,3004
     3fc:	80 7f 00 10 	lwz     r3,16(r31)
     400:	28 03 00 00 	cmplwi  r3,0
     404:	41 82 00 20 	beq-    0x424
     408:	e8 7f 00 00 	ld      r3,0(r31)
     40c:	28 23 00 00 	cmpldi  r3,0
     410:	41 82 00 14 	beq-    0x424
     414:	e8 7f 00 08 	ld      r3,8(r31)
     418:	38 9d 00 09 	addi    r4,r29,9
     41c:	4b ff c5 45 	bl      0xffffffffffffc960
     420:	eb bf 00 00 	ld      r29,0(r31)
     424:	7f a3 eb 78 	mr      r3,r29
     428:	48 25 a2 38 	b       0x25a660
     42c:	7c 08 02 a6 	mflr    r0
     430:	f8 21 fe 61 	stdu    r1,-416(r1)
     434:	fb 61 00 78 	std     r27,120(r1)
     438:	fb 81 00 80 	std     r28,128(r1)
     43c:	fb a1 00 88 	std     r29,136(r1)
     440:	fb c1 00 90 	std     r30,144(r1)
     444:	fb e1 00 98 	std     r31,152(r1)
     448:	f8 01 01 b0 	std     r0,432(r1)
     44c:	7c 7d 1b 78 	mr      r29,r3
     450:	7c 9e 23 78 	mr      r30,r4
     454:	3b e0 00 01 	li      r31,1
     458:	7b ff f8 06 	rldicr  r31,r31,63,0
     45c:	eb 82 96 00 	ld      r28,-27136(r2)
     460:	eb 9c 00 68 	ld      r28,104(r28)
     464:	eb 9c 00 18 	ld      r28,24(r28)
     468:	eb 62 0f 08 	ld      r27,3848(r2)
     46c:	e9 3d 00 18 	ld      r9,24(r29)
     470:	81 29 00 30 	lwz     r9,48(r9)
     474:	79 29 84 02 	rldicl  r9,r9,48,16
     478:	2c 09 00 29 	cmpwi   r9,41
     47c:	40 82 00 58 	bne-    0x4d4
     480:	e8 9c 00 10 	ld      r4,16(r28)
     484:	78 85 c1 e4 	rldicr  r5,r4,24,39
     488:	78 a5 46 20 	rldicl  r5,r5,8,56
     48c:	2c 05 00 ff 	cmpwi   r5,255
     490:	41 82 00 18 	beq-    0x4a8
     494:	60 84 00 03 	ori     r4,r4,3
     498:	f8 9c 00 10 	std     r4,16(r28)
     49c:	38 60 00 06 	li      r3,6
     4a0:	90 7e 00 00 	stw     r3,0(r30)
     4a4:	48 00 00 14 	b       0x4b8
     4a8:	60 84 00 02 	ori     r4,r4,2
     4ac:	f8 9c 00 10 	std     r4,16(r28)
     4b0:	38 60 00 2c 	li      r3,44
     4b4:	90 7e 00 00 	stw     r3,0(r30)
     4b8:	80 bc 00 04 	lwz     r5,4(r28)
     4bc:	e8 9c 00 08 	ld      r4,8(r28)
     4c0:	e8 7b 00 00 	ld      r3,0(r27)
     4c4:	7d 23 2a 14 	add     r9,r3,r5
     4c8:	f9 3b 00 00 	std     r9,0(r27)
     4cc:	48 02 b1 c1 	bl      0x2b68c
     4d0:	48 00 00 c4 	b       0x594
     4d4:	7f a3 eb 78 	mr      r3,r29
     4d8:	7f c4 f3 78 	mr      r4,r30
     4dc:	4b ff d9 b1 	bl      0xffffffffffffde8c
     4e0:	7f fd fb 78 	mr      r29,r31
     4e4:	67 bd 00 05 	oris    r29,r29,5
     4e8:	63 bd 0b d0 	ori     r29,r29,3024
     4ec:	80 7d 00 00 	lwz     r3,0(r29)
     4f0:	80 bc 00 04 	lwz     r5,4(r28)
     4f4:	7c 63 2a 14 	add     r3,r3,r5
     4f8:	90 7d 00 00 	stw     r3,0(r29)
     4fc:	e8 9c 00 10 	ld      r4,16(r28)
     500:	78 85 c1 e4 	rldicr  r5,r4,24,39
     504:	78 a5 46 20 	rldicl  r5,r5,8,56
     508:	2c 05 00 ff 	cmpwi   r5,255
     50c:	40 82 00 88 	bne-    0x594
     510:	e8 7b 00 00 	ld      r3,0(r27)
     514:	38 80 00 00 	li      r4,0
     518:	38 c0 00 00 	li      r6,0
     51c:	7c e3 22 14 	add     r7,r3,r4
     520:	80 a7 00 00 	lwz     r5,0(r7)
     524:	7c c6 2a 78 	xor     r6,r6,r5
     528:	38 84 00 04 	addi    r4,r4,4
     52c:	28 24 04 00 	cmpldi  r4,1024
     530:	40 82 ff ec 	bne+    0x51c
     534:	80 7d 00 00 	lwz     r3,0(r29)
     538:	78 c6 07 c6 	rldicr  r6,r6,32,31
     53c:	7c c6 1b 78 	or      r6,r6,r3
     540:	38 60 00 00 	li      r3,0
     544:	90 7d 00 00 	stw     r3,0(r29)
     548:	7f e7 fb 78 	mr      r7,r31
     54c:	64 e7 00 05 	oris    r7,r7,5
     550:	60 e7 0f 70 	ori     r7,r7,3952
     554:	e8 67 00 00 	ld      r3,0(r7)
     558:	28 23 00 00 	cmpldi  r3,0
     55c:	41 82 00 38 	beq-    0x594
     560:	38 e7 00 10 	addi    r7,r7,16
     564:	7c 23 30 40 	cmpld   r3,r6
     568:	40 82 ff ec 	bne+    0x554
     56c:	e8 a7 ff f8 	ld      r5,-8(r7)
     570:	e8 fb 00 00 	ld      r7,0(r27)
     574:	80 65 00 00 	lwz     r3,0(r5)
     578:	28 03 00 00 	cmplwi  r3,0
     57c:	41 82 00 18 	beq-    0x594
     580:	80 85 00 04 	lwz     r4,4(r5)
     584:	7c 63 3a 14 	add     r3,r3,r7
     588:	90 83 00 00 	stw     r4,0(r3)
     58c:	38 a5 00 08 	addi    r5,r5,8
     590:	4b ff ff e4 	b       0x574
     594:	38 60 00 00 	li      r3,0
     598:	eb 61 00 78 	ld      r27,120(r1)
     59c:	eb 81 00 80 	ld      r28,128(r1)
     5a0:	eb a1 00 88 	ld      r29,136(r1)
     5a4:	eb c1 00 90 	ld      r30,144(r1)
     5a8:	eb e1 00 98 	ld      r31,152(r1)
     5ac:	e8 01 01 b0 	ld      r0,432(r1)
     5b0:	38 21 01 a0 	addi    r1,r1,416
     5b4:	7c 08 03 a6 	mtlr    r0
     5b8:	4e 80 00 20 	blr
     5bc:	f8 21 ff 51 	stdu    r1,-176(r1)
     5c0:	7c 08 02 a6 	mflr    r0
     5c4:	fb c1 00 a0 	std     r30,160(r1)
     5c8:	fb e1 00 a8 	std     r31,168(r1)
     5cc:	fb a1 00 98 	std     r29,152(r1)
     5d0:	f8 01 00 c0 	std     r0,192(r1)
     5d4:	3b c0 0f a0 	li      r30,4000
     5d8:	3b e0 00 c8 	li      r31,200
     5dc:	4b fb 9b 98 	b       0xfffffffffffba174
     5e0:	a0 55 6f 3d 	lhz     r2,28477(r21)
     5e4:	00 2c b8 fd 	.long 0x2cb8fd
     5e8:	80 00 00 00 	lwz     r0,0(0)
     5ec:	00 05 0f b8 	.long 0x50fb8
     5f0:	8c 0a 94 8c 	lbzu    r0,-27508(r10)
     5f4:	00 0d 99 b1 	.long 0xd99b1
     5f8:	80 00 00 00 	lwz     r0,0(0)
     5fc:	00 05 0f e0 	.long 0x50fe0
     600:	a2 bc 1a 56 	lhz     r21,6742(r28)
     604:	00 05 2a dc 	.long 0x52adc
     608:	80 00 00 00 	lwz     r0,0(0)
     60c:	00 05 10 04 	.long 0x51004
     610:	6b 70 28 02 	xori    r16,r27,10242
     614:	00 02 00 17 	.long 0x20017
     618:	80 00 00 00 	lwz     r0,0(0)
     61c:	00 05 0f d4 	.long 0x50fd4
    	...
     628:	00 30 53 54 	.long 0x305354
     62c:	38 60 00 82 	li      r3,130
     630:	00 5f 3f c0 	.long 0x5f3fc0
     634:	38 60 00 01 	li      r3,1
     638:	00 5f 3f c4 	.long 0x5f3fc4
     63c:	4e 80 00 20 	blr
     640:	00 00 00 00 	.long 0x0
     644:	00 02 ed 0c 	.long 0x2ed0c
     648:	3b a0 00 01 	li      r29,1
     64c:	00 00 00 00 	.long 0x0
     650:	00 22 b8 88 	.long 0x22b888
     654:	5f 74 6f 6f 	rlwnm.  r20,r27,r13,29,23
     658:	00 22 b8 8c 	.long 0x22b88c
     65c:	6c 32 2e 78 	xoris   r18,r1,11896
     660:	00 22 b8 90 	.long 0x22b890
     664:	6d 6c 23 72 	xoris   r12,r11,9074
     668:	00 22 b8 94 	.long 0x22b894
     66c:	6f 6f 74 00 	xoris   r15,r27,29696
     670:	00 00 00 00 	.long 0x0
     674:	00 0d 68 b8 	.long 0xd68b8
     678:	5f 74 6f 6f 	rlwnm.  r20,r27,r13,29,23
     67c:	00 0d 68 bc 	.long 0xd68bc
     680:	6c 32 2e 78 	xoris   r18,r1,11896
     684:	00 0d 68 c0 	.long 0xd68c0
     688:	6d 6c 23 72 	xoris   r12,r11,9074
     68c:	00 0d 68 c4 	.long 0xd68c4
     690:	6f 6f 74 00 	xoris   r15,r27,29696
     694:	00 00 00 00 	.long 0x0
     698:	2f 64 65 76 	cmpdi   cr6,r4,25974
     69c:	5f 62 64 76 	rlwnm   r2,r27,r12,17,27
     6a0:	64 00 6d 6f 	oris    r0,r0,28015
     6a4:	64 00 00 00 	oris    r0,r0,0
    	...
     6b0:	eb 61 00 78 	ld      r27,120(r1)
     6b4:	eb 81 00 80 	ld      r28,128(r1)
     6b8:	eb a1 00 88 	ld      r29,136(r1)
     6bc:	eb c1 00 90 	ld      r30,144(r1)
     6c0:	eb e1 00 98 	ld      r31,152(r1)
     6c4:	e8 01 00 b0 	ld      r0,176(r1)
     6c8:	38 21 00 a0 	addi    r1,r1,160
     6cc:	7c 08 03 a6 	mtlr    r0
     6d0:	38 60 00 01 	li      r3,1
     6d4:	78 63 f8 06 	rldicr  r3,r3,63,0
     6d8:	64 63 00 70 	oris    r3,r3,112
     6dc:	38 80 00 00 	li      r4,0
     6e0:	38 a0 06 e8 	li      r5,1768
     6e4:	4b 94 ca 60 	b       0xffffffffff94d144
     6e8:	60 00 00 00 	nop
     6ec:	60 00 00 00 	nop
     6f0:	eb 61 00 78 	ld      r27,120(r1)
     6f4:	eb 81 00 80 	ld      r28,128(r1)
     6f8:	eb a1 00 88 	ld      r29,136(r1)
     6fc:	eb c1 00 90 	ld      r30,144(r1)
     700:	eb e1 00 98 	ld      r31,152(r1)
     704:	e8 01 00 b0 	ld      r0,176(r1)
     708:	38 21 00 a0 	addi    r1,r1,160
     70c:	7c 08 03 a6 	mtlr    r0
     710:	38 60 00 01 	li      r3,1
     714:	78 63 f8 06 	rldicr  r3,r3,63,0
     718:	64 63 00 70 	oris    r3,r3,112
     71c:	38 80 00 00 	li      r4,0
     720:	38 a0 06 e8 	li      r5,1768
     724:	4b 94 ca 60 	b       0xffffffffff94d184
     728:	60 00 00 00 	nop
     72c:	60 00 00 00 	nop
     730:	eb 61 00 78 	ld      r27,120(r1)
     734:	eb 81 00 80 	ld      r28,128(r1)
     738:	eb a1 00 88 	ld      r29,136(r1)
     73c:	eb c1 00 90 	ld      r30,144(r1)
     740:	eb e1 00 98 	ld      r31,152(r1)
     744:	e8 01 00 b0 	ld      r0,176(r1)
     748:	38 21 00 a0 	addi    r1,r1,160
     74c:	7c 08 03 a6 	mtlr    r0
     750:	38 60 00 01 	li      r3,1
     754:	78 63 f8 06 	rldicr  r3,r3,63,0
     758:	64 63 00 70 	oris    r3,r3,112
     75c:	38 80 00 00 	li      r4,0
     760:	38 a0 06 e8 	li      r5,1768
     764:	4b 94 ca 60 	b       0xffffffffff94d1c4
     768:	60 00 00 00 	nop
     76c:	60 00 00 00 	nop
     770:	eb 61 00 78 	ld      r27,120(r1)
     774:	eb 81 00 80 	ld      r28,128(r1)
     778:	eb a1 00 88 	ld      r29,136(r1)
     77c:	eb c1 00 90 	ld      r30,144(r1)
     780:	eb e1 00 98 	ld      r31,152(r1)
     784:	e8 01 00 b0 	ld      r0,176(r1)
     788:	38 21 00 a0 	addi    r1,r1,160
     78c:	7c 08 03 a6 	mtlr    r0
     790:	38 60 00 01 	li      r3,1
     794:	78 63 f8 06 	rldicr  r3,r3,63,0
     798:	64 63 00 70 	oris    r3,r3,112
     79c:	38 80 00 00 	li      r4,0
     7a0:	38 a0 06 e8 	li      r5,1768
     7a4:	4b 94 ca 60 	b       0xffffffffff94d204
     7a8:	60 00 00 00 	nop
     7ac:	60 00 00 00 	nop
     7b0:	eb 61 00 78 	ld      r27,120(r1)
     7b4:	eb 81 00 80 	ld      r28,128(r1)
     7b8:	eb a1 00 88 	ld      r29,136(r1)
     7bc:	eb c1 00 90 	ld      r30,144(r1)
     7c0:	eb e1 00 98 	ld      r31,152(r1)
     7c4:	e8 01 00 b0 	ld      r0,176(r1)
     7c8:	38 21 00 a0 	addi    r1,r1,160
     7cc:	7c 08 03 a6 	mtlr    r0
     7d0:	38 60 00 01 	li      r3,1
     7d4:	78 63 f8 06 	rldicr  r3,r3,63,0
     7d8:	64 63 00 70 	oris    r3,r3,112
     7dc:	38 80 00 00 	li      r4,0
     7e0:	38 a0 06 e8 	li      r5,1768
     7e4:	4b 94 ca 60 	b       0xffffffffff94d244
     7e8:	60 00 00 00 	nop
     7ec:	60 00 00 00 	nop
     7f0:	eb 61 00 78 	ld      r27,120(r1)
     7f4:	eb 81 00 80 	ld      r28,128(r1)
     7f8:	eb a1 00 88 	ld      r29,136(r1)
     7fc:	eb c1 00 90 	ld      r30,144(r1)
     800:	eb e1 00 98 	ld      r31,152(r1)
     804:	e8 01 00 b0 	ld      r0,176(r1)
     808:	38 21 00 a0 	addi    r1,r1,160
     80c:	7c 08 03 a6 	mtlr    r0
     810:	38 60 00 01 	li      r3,1
     814:	78 63 f8 06 	rldicr  r3,r3,63,0
     818:	64 63 00 70 	oris    r3,r3,112
     81c:	38 80 00 00 	li      r4,0
     820:	38 a0 06 e8 	li      r5,1768
     824:	4b 94 ca 60 	b       0xffffffffff94d284
     828:	60 00 00 00 	nop
     82c:	60 00 00 00 	nop
     830:	eb 61 00 78 	ld      r27,120(r1)
     834:	eb 81 00 80 	ld      r28,128(r1)
     838:	eb a1 00 88 	ld      r29,136(r1)
     83c:	eb c1 00 90 	ld      r30,144(r1)
     840:	eb e1 00 98 	ld      r31,152(r1)
     844:	e8 01 00 b0 	ld      r0,176(r1)
     848:	38 21 00 a0 	addi    r1,r1,160
     84c:	7c 08 03 a6 	mtlr    r0
     850:	38 60 00 01 	li      r3,1
     854:	78 63 f8 06 	rldicr  r3,r3,63,0
     858:	64 63 00 70 	oris    r3,r3,112
     85c:	38 80 00 00 	li      r4,0
     860:	38 a0 06 e8 	li      r5,1768
     864:	4b 94 ca 60 	b       0xffffffffff94d2c4
     868:	60 00 00 00 	nop
     86c:	60 00 00 00 	nop
     870:	eb 61 00 78 	ld      r27,120(r1)
     874:	eb 81 00 80 	ld      r28,128(r1)
     878:	eb a1 00 88 	ld      r29,136(r1)
     87c:	eb c1 00 90 	ld      r30,144(r1)
     880:	eb e1 00 98 	ld      r31,152(r1)
     884:	e8 01 00 b0 	ld      r0,176(r1)
     888:	38 21 00 a0 	addi    r1,r1,160
     88c:	7c 08 03 a6 	mtlr    r0
     890:	38 60 00 01 	li      r3,1
     894:	78 63 f8 06 	rldicr  r3,r3,63,0
     898:	64 63 00 70 	oris    r3,r3,112
     89c:	38 80 00 00 	li      r4,0
     8a0:	38 a0 06 e8 	li      r5,1768
     8a4:	4b 94 ca 60 	b       0xffffffffff94d304
     8a8:	60 00 00 00 	nop
     8ac:	60 00 00 00 	nop
     8b0:	eb 61 00 78 	ld      r27,120(r1)
     8b4:	eb 81 00 80 	ld      r28,128(r1)
     8b8:	eb a1 00 88 	ld      r29,136(r1)
     8bc:	eb c1 00 90 	ld      r30,144(r1)
     8c0:	eb e1 00 98 	ld      r31,152(r1)
     8c4:	e8 01 00 b0 	ld      r0,176(r1)
     8c8:	38 21 00 a0 	addi    r1,r1,160
     8cc:	7c 08 03 a6 	mtlr    r0
     8d0:	38 60 00 01 	li      r3,1
     8d4:	78 63 f8 06 	rldicr  r3,r3,63,0
     8d8:	64 63 00 70 	oris    r3,r3,112
     8dc:	38 80 00 00 	li      r4,0
     8e0:	38 a0 06 e8 	li      r5,1768
     8e4:	4b 94 ca 60 	b       0xffffffffff94d344
     8e8:	60 00 00 00 	nop
     8ec:	60 00 00 00 	nop
     8f0:	eb 61 00 78 	ld      r27,120(r1)
     8f4:	eb 81 00 80 	ld      r28,128(r1)
     8f8:	eb a1 00 88 	ld      r29,136(r1)
     8fc:	eb c1 00 90 	ld      r30,144(r1)
     900:	eb e1 00 98 	ld      r31,152(r1)
     904:	e8 01 00 b0 	ld      r0,176(r1)
     908:	38 21 00 a0 	addi    r1,r1,160
     90c:	7c 08 03 a6 	mtlr    r0
     910:	38 60 00 01 	li      r3,1
     914:	78 63 f8 06 	rldicr  r3,r3,63,0
     918:	64 63 00 70 	oris    r3,r3,112
     91c:	38 80 00 00 	li      r4,0
     920:	38 a0 06 e8 	li      r5,1768
     924:	4b 94 ca 60 	b       0xffffffffff94d384
     928:	60 00 00 00 	nop
     92c:	60 00 00 00 	nop
     930:	eb 61 00 78 	ld      r27,120(r1)
     934:	eb 81 00 80 	ld      r28,128(r1)
     938:	eb a1 00 88 	ld      r29,136(r1)
     93c:	eb c1 00 90 	ld      r30,144(r1)
     940:	eb e1 00 98 	ld      r31,152(r1)
     944:	e8 01 00 b0 	ld      r0,176(r1)
     948:	38 21 00 a0 	addi    r1,r1,160
     94c:	7c 08 03 a6 	mtlr    r0
     950:	38 60 00 01 	li      r3,1
     954:	78 63 f8 06 	rldicr  r3,r3,63,0
     958:	64 63 00 70 	oris    r3,r3,112
     95c:	38 80 00 00 	li      r4,0
     960:	38 a0 06 e8 	li      r5,1768
     964:	4b 94 ca 60 	b       0xffffffffff94d3c4
     968:	60 00 00 00 	nop
     96c:	60 00 00 00 	nop
     970:	eb 61 00 78 	ld      r27,120(r1)
     974:	eb 81 00 80 	ld      r28,128(r1)
     978:	eb a1 00 88 	ld      r29,136(r1)
     97c:	eb c1 00 90 	ld      r30,144(r1)
     980:	eb e1 00 98 	ld      r31,152(r1)
     984:	e8 01 00 b0 	ld      r0,176(r1)
     988:	38 21 00 a0 	addi    r1,r1,160
     98c:	7c 08 03 a6 	mtlr    r0
     990:	38 60 00 01 	li      r3,1
     994:	78 63 f8 06 	rldicr  r3,r3,63,0
     998:	64 63 00 70 	oris    r3,r3,112
     99c:	38 80 00 00 	li      r4,0
     9a0:	38 a0 06 e8 	li      r5,1768
     9a4:	4b 94 ca 60 	b       0xffffffffff94d404
     9a8:	60 00 00 00 	nop
     9ac:	60 00 00 00 	nop
     9b0:	eb 61 00 78 	ld      r27,120(r1)
     9b4:	eb 81 00 80 	ld      r28,128(r1)
     9b8:	eb a1 00 88 	ld      r29,136(r1)
     9bc:	eb c1 00 90 	ld      r30,144(r1)
     9c0:	eb e1 00 98 	ld      r31,152(r1)
     9c4:	e8 01 00 b0 	ld      r0,176(r1)
     9c8:	38 21 00 a0 	addi    r1,r1,160
     9cc:	7c 08 03 a6 	mtlr    r0
     9d0:	38 60 00 01 	li      r3,1
     9d4:	78 63 f8 06 	rldicr  r3,r3,63,0
     9d8:	64 63 00 70 	oris    r3,r3,112
     9dc:	38 80 00 00 	li      r4,0
     9e0:	38 a0 06 e8 	li      r5,1768
     9e4:	4b 94 ca 60 	b       0xffffffffff94d444
     9e8:	60 00 00 00 	nop
     9ec:	60 00 00 00 	nop
     9f0:	eb 61 00 78 	ld      r27,120(r1)
     9f4:	eb 81 00 80 	ld      r28,128(r1)
     9f8:	eb a1 00 88 	ld      r29,136(r1)
     9fc:	eb c1 00 90 	ld      r30,144(r1)
     a00:	eb e1 00 98 	ld      r31,152(r1)
     a04:	e8 01 00 b0 	ld      r0,176(r1)
     a08:	38 21 00 a0 	addi    r1,r1,160
     a0c:	7c 08 03 a6 	mtlr    r0
     a10:	38 60 00 01 	li      r3,1
     a14:	78 63 f8 06 	rldicr  r3,r3,63,0
     a18:	64 63 00 70 	oris    r3,r3,112
     a1c:	38 80 00 00 	li      r4,0
     a20:	38 a0 06 e8 	li      r5,1768
     a24:	4b 94 ca 60 	b       0xffffffffff94d484
     a28:	60 00 00 00 	nop
     a2c:	60 00 00 00 	nop
     a30:	eb 61 00 78 	ld      r27,120(r1)
     a34:	eb 81 00 80 	ld      r28,128(r1)
     a38:	eb a1 00 88 	ld      r29,136(r1)
     a3c:	eb c1 00 90 	ld      r30,144(r1)
     a40:	eb e1 00 98 	ld      r31,152(r1)
     a44:	e8 01 00 b0 	ld      r0,176(r1)
     a48:	38 21 00 a0 	addi    r1,r1,160
     a4c:	7c 08 03 a6 	mtlr    r0
     a50:	38 60 00 01 	li      r3,1
     a54:	78 63 f8 06 	rldicr  r3,r3,63,0
     a58:	64 63 00 70 	oris    r3,r3,112
     a5c:	38 80 00 00 	li      r4,0
     a60:	38 a0 06 e8 	li      r5,1768
     a64:	4b 94 ca 60 	b       0xffffffffff94d4c4
     a68:	60 00 00 00 	nop
     a6c:	60 00 00 00 	nop
     a70:	eb 61 00 78 	ld      r27,120(r1)
     a74:	eb 81 00 80 	ld      r28,128(r1)
     a78:	eb a1 00 88 	ld      r29,136(r1)
     a7c:	eb c1 00 90 	ld      r30,144(r1)
     a80:	eb e1 00 98 	ld      r31,152(r1)
     a84:	e8 01 00 b0 	ld      r0,176(r1)
     a88:	38 21 00 a0 	addi    r1,r1,160
     a8c:	7c 08 03 a6 	mtlr    r0
     a90:	38 60 00 01 	li      r3,1
     a94:	78 63 f8 06 	rldicr  r3,r3,63,0
     a98:	64 63 00 70 	oris    r3,r3,112
     a9c:	38 80 00 00 	li      r4,0
     aa0:	38 a0 06 e8 	li      r5,1768
     aa4:	4b 94 ca 60 	b       0xffffffffff94d504
     aa8:	60 00 00 00 	nop
     aac:	60 00 00 00 	nop
     ab0:	eb 61 00 78 	ld      r27,120(r1)
     ab4:	eb 81 00 80 	ld      r28,128(r1)
     ab8:	eb a1 00 88 	ld      r29,136(r1)
     abc:	eb c1 00 90 	ld      r30,144(r1)
     ac0:	eb e1 00 98 	ld      r31,152(r1)
     ac4:	e8 01 00 b0 	ld      r0,176(r1)
     ac8:	38 21 00 a0 	addi    r1,r1,160
     acc:	7c 08 03 a6 	mtlr    r0
     ad0:	38 60 00 01 	li      r3,1
     ad4:	78 63 f8 06 	rldicr  r3,r3,63,0
     ad8:	64 63 00 70 	oris    r3,r3,112
     adc:	38 80 00 00 	li      r4,0
     ae0:	38 a0 06 e8 	li      r5,1768
     ae4:	4b 94 ca 60 	b       0xffffffffff94d544
     ae8:	60 00 00 00 	nop
     aec:	60 00 00 00 	nop
     af0:	eb 61 00 78 	ld      r27,120(r1)
     af4:	eb 81 00 80 	ld      r28,128(r1)
     af8:	eb a1 00 88 	ld      r29,136(r1)
     afc:	eb c1 00 90 	ld      r30,144(r1)
     b00:	eb e1 00 98 	ld      r31,152(r1)
     b04:	e8 01 00 b0 	ld      r0,176(r1)
     b08:	38 21 00 a0 	addi    r1,r1,160
     b0c:	7c 08 03 a6 	mtlr    r0
     b10:	38 60 00 01 	li      r3,1
     b14:	78 63 f8 06 	rldicr  r3,r3,63,0
     b18:	64 63 00 70 	oris    r3,r3,112
     b1c:	38 80 00 00 	li      r4,0
     b20:	38 a0 06 e8 	li      r5,1768
     b24:	4b 94 ca 60 	b       0xffffffffff94d584
     b28:	60 00 00 00 	nop
     b2c:	60 00 00 00 	nop
     b30:	eb 61 00 78 	ld      r27,120(r1)
     b34:	eb 81 00 80 	ld      r28,128(r1)
     b38:	eb a1 00 88 	ld      r29,136(r1)
     b3c:	eb c1 00 90 	ld      r30,144(r1)
     b40:	eb e1 00 98 	ld      r31,152(r1)
     b44:	e8 01 00 b0 	ld      r0,176(r1)
     b48:	38 21 00 a0 	addi    r1,r1,160
     b4c:	7c 08 03 a6 	mtlr    r0
     b50:	38 60 00 01 	li      r3,1
     b54:	78 63 f8 06 	rldicr  r3,r3,63,0
     b58:	64 63 00 70 	oris    r3,r3,112
     b5c:	38 80 00 00 	li      r4,0
     b60:	38 a0 06 e8 	li      r5,1768
     b64:	4b 94 ca 60 	b       0xffffffffff94d5c4
     b68:	60 00 00 00 	nop
     b6c:	60 00 00 00 	nop
     b70:	eb 61 00 78 	ld      r27,120(r1)
     b74:	eb 81 00 80 	ld      r28,128(r1)
     b78:	eb a1 00 88 	ld      r29,136(r1)
     b7c:	eb c1 00 90 	ld      r30,144(r1)
     b80:	eb e1 00 98 	ld      r31,152(r1)
     b84:	e8 01 00 b0 	ld      r0,176(r1)
     b88:	38 21 00 a0 	addi    r1,r1,160
     b8c:	7c 08 03 a6 	mtlr    r0
     b90:	38 60 00 01 	li      r3,1
     b94:	78 63 f8 06 	rldicr  r3,r3,63,0
     b98:	64 63 00 70 	oris    r3,r3,112
     b9c:	38 80 00 00 	li      r4,0
     ba0:	38 a0 06 e8 	li      r5,1768
     ba4:	4b 94 ca 60 	b       0xffffffffff94d604
     ba8:	60 00 00 00 	nop
     bac:	60 00 00 00 	nop
     bb0:	eb 61 00 78 	ld      r27,120(r1)
     bb4:	eb 81 00 80 	ld      r28,128(r1)
     bb8:	eb a1 00 88 	ld      r29,136(r1)
     bbc:	eb c1 00 90 	ld      r30,144(r1)
     bc0:	eb e1 00 98 	ld      r31,152(r1)
     bc4:	e8 01 00 b0 	ld      r0,176(r1)
     bc8:	38 21 00 a0 	addi    r1,r1,160
     bcc:	7c 08 03 a6 	mtlr    r0
     bd0:	38 60 00 01 	li      r3,1
     bd4:	78 63 f8 06 	rldicr  r3,r3,63,0
     bd8:	64 63 00 70 	oris    r3,r3,112
     bdc:	38 80 00 00 	li      r4,0
     be0:	38 a0 06 e8 	li      r5,1768
     be4:	4b 94 ca 60 	b       0xffffffffff94d644
     be8:	60 00 00 00 	nop
     bec:	60 00 00 00 	nop
     bf0:	eb 61 00 78 	ld      r27,120(r1)
     bf4:	eb 81 00 80 	ld      r28,128(r1)
     bf8:	eb a1 00 88 	ld      r29,136(r1)
     bfc:	eb c1 00 90 	ld      r30,144(r1)
     c00:	eb e1 00 98 	ld      r31,152(r1)
     c04:	e8 01 00 b0 	ld      r0,176(r1)
     c08:	38 21 00 a0 	addi    r1,r1,160
     c0c:	7c 08 03 a6 	mtlr    r0
     c10:	38 60 00 01 	li      r3,1
     c14:	78 63 f8 06 	rldicr  r3,r3,63,0
     c18:	64 63 00 70 	oris    r3,r3,112
     c1c:	38 80 00 00 	li      r4,0
     c20:	38 a0 06 e8 	li      r5,1768
     c24:	4b 94 ca 60 	b       0xffffffffff94d684
     c28:	60 00 00 00 	nop
     c2c:	60 00 00 00 	nop
     c30:	eb 61 00 78 	ld      r27,120(r1)
     c34:	eb 81 00 80 	ld      r28,128(r1)
     c38:	eb a1 00 88 	ld      r29,136(r1)
     c3c:	eb c1 00 90 	ld      r30,144(r1)
     c40:	eb e1 00 98 	ld      r31,152(r1)
     c44:	e8 01 00 b0 	ld      r0,176(r1)
     c48:	38 21 00 a0 	addi    r1,r1,160
     c4c:	7c 08 03 a6 	mtlr    r0
     c50:	38 60 00 01 	li      r3,1
     c54:	78 63 f8 06 	rldicr  r3,r3,63,0
     c58:	64 63 00 70 	oris    r3,r3,112
     c5c:	38 80 00 00 	li      r4,0
     c60:	38 a0 06 e8 	li      r5,1768
     c64:	4b 94 ca 60 	b       0xffffffffff94d6c4
     c68:	60 00 00 00 	nop
     c6c:	60 00 00 00 	nop
     c70:	eb 61 00 78 	ld      r27,120(r1)
     c74:	eb 81 00 80 	ld      r28,128(r1)
     c78:	eb a1 00 88 	ld      r29,136(r1)
     c7c:	eb c1 00 90 	ld      r30,144(r1)
     c80:	eb e1 00 98 	ld      r31,152(r1)
     c84:	e8 01 00 b0 	ld      r0,176(r1)
     c88:	38 21 00 a0 	addi    r1,r1,160
     c8c:	7c 08 03 a6 	mtlr    r0
     c90:	38 60 00 01 	li      r3,1
     c94:	78 63 f8 06 	rldicr  r3,r3,63,0
     c98:	64 63 00 70 	oris    r3,r3,112
     c9c:	38 80 00 00 	li      r4,0
     ca0:	38 a0 06 e8 	li      r5,1768
     ca4:	4b 94 ca 60 	b       0xffffffffff94d704
     ca8:	60 00 00 00 	nop
     cac:	60 00 00 00 	nop
     cb0:	eb 61 00 78 	ld      r27,120(r1)
     cb4:	eb 81 00 80 	ld      r28,128(r1)
     cb8:	eb a1 00 88 	ld      r29,136(r1)
     cbc:	eb c1 00 90 	ld      r30,144(r1)
     cc0:	eb e1 00 98 	ld      r31,152(r1)
     cc4:	e8 01 00 b0 	ld      r0,176(r1)
     cc8:	38 21 00 a0 	addi    r1,r1,160
     ccc:	7c 08 03 a6 	mtlr    r0
     cd0:	38 60 00 01 	li      r3,1
     cd4:	78 63 f8 06 	rldicr  r3,r3,63,0
     cd8:	64 63 00 70 	oris    r3,r3,112
     cdc:	38 80 00 00 	li      r4,0
     ce0:	38 a0 06 e8 	li      r5,1768
     ce4:	4b 94 ca 60 	b       0xffffffffff94d744
     ce8:	60 00 00 00 	nop
     cec:	60 00 00 00 	nop
     cf0:	eb 61 00 78 	ld      r27,120(r1)
     cf4:	eb 81 00 80 	ld      r28,128(r1)
     cf8:	eb a1 00 88 	ld      r29,136(r1)
     cfc:	eb c1 00 90 	ld      r30,144(r1)
     d00:	eb e1 00 98 	ld      r31,152(r1)
     d04:	e8 01 00 b0 	ld      r0,176(r1)
     d08:	38 21 00 a0 	addi    r1,r1,160
     d0c:	7c 08 03 a6 	mtlr    r0
     d10:	38 60 00 01 	li      r3,1
     d14:	78 63 f8 06 	rldicr  r3,r3,63,0
     d18:	64 63 00 70 	oris    r3,r3,112
     d1c:	38 80 00 00 	li      r4,0
     d20:	38 a0 06 e8 	li      r5,1768
     d24:	4b 94 ca 60 	b       0xffffffffff94d784
     d28:	60 00 00 00 	nop
     d2c:	60 00 00 00 	nop
     d30:	eb 61 00 78 	ld      r27,120(r1)
     d34:	eb 81 00 80 	ld      r28,128(r1)
     d38:	eb a1 00 88 	ld      r29,136(r1)
     d3c:	eb c1 00 90 	ld      r30,144(r1)
     d40:	eb e1 00 98 	ld      r31,152(r1)
     d44:	e8 01 00 b0 	ld      r0,176(r1)
     d48:	38 21 00 a0 	addi    r1,r1,160
     d4c:	7c 08 03 a6 	mtlr    r0
     d50:	38 60 00 01 	li      r3,1
     d54:	78 63 f8 06 	rldicr  r3,r3,63,0
     d58:	64 63 00 70 	oris    r3,r3,112
     d5c:	38 80 00 00 	li      r4,0
     d60:	38 a0 06 e8 	li      r5,1768
     d64:	4b 94 ca 60 	b       0xffffffffff94d7c4
     d68:	60 00 00 00 	nop
     d6c:	60 00 00 00 	nop
     d70:	eb 61 00 78 	ld      r27,120(r1)
     d74:	eb 81 00 80 	ld      r28,128(r1)
     d78:	eb a1 00 88 	ld      r29,136(r1)
     d7c:	eb c1 00 90 	ld      r30,144(r1)
     d80:	eb e1 00 98 	ld      r31,152(r1)
     d84:	e8 01 00 b0 	ld      r0,176(r1)
     d88:	38 21 00 a0 	addi    r1,r1,160
     d8c:	7c 08 03 a6 	mtlr    r0
     d90:	38 60 00 01 	li      r3,1
     d94:	78 63 f8 06 	rldicr  r3,r3,63,0
     d98:	64 63 00 70 	oris    r3,r3,112
     d9c:	38 80 00 00 	li      r4,0
     da0:	38 a0 06 e8 	li      r5,1768
     da4:	4b 94 ca 60 	b       0xffffffffff94d804
     da8:	60 00 00 00 	nop
     dac:	60 00 00 00 	nop
     db0:	eb 61 00 78 	ld      r27,120(r1)
     db4:	eb 81 00 80 	ld      r28,128(r1)
     db8:	eb a1 00 88 	ld      r29,136(r1)
     dbc:	eb c1 00 90 	ld      r30,144(r1)
     dc0:	eb e1 00 98 	ld      r31,152(r1)
     dc4:	e8 01 00 b0 	ld      r0,176(r1)
     dc8:	38 21 00 a0 	addi    r1,r1,160
     dcc:	7c 08 03 a6 	mtlr    r0
     dd0:	38 60 00 01 	li      r3,1
     dd4:	78 63 f8 06 	rldicr  r3,r3,63,0
     dd8:	64 63 00 70 	oris    r3,r3,112
     ddc:	38 80 00 00 	li      r4,0
     de0:	38 a0 06 e8 	li      r5,1768
     de4:	4b 94 ca 60 	b       0xffffffffff94d844
     de8:	60 00 00 00 	nop
     dec:	60 00 00 00 	nop
     df0:	eb 61 00 78 	ld      r27,120(r1)
     df4:	eb 81 00 80 	ld      r28,128(r1)
     df8:	eb a1 00 88 	ld      r29,136(r1)
     dfc:	eb c1 00 90 	ld      r30,144(r1)
     e00:	eb e1 00 98 	ld      r31,152(r1)
     e04:	e8 01 00 b0 	ld      r0,176(r1)
     e08:	38 21 00 a0 	addi    r1,r1,160
     e0c:	7c 08 03 a6 	mtlr    r0
     e10:	38 60 00 01 	li      r3,1
     e14:	78 63 f8 06 	rldicr  r3,r3,63,0
     e18:	64 63 00 70 	oris    r3,r3,112
     e1c:	38 80 00 00 	li      r4,0
     e20:	38 a0 06 e8 	li      r5,1768
     e24:	4b 94 ca 60 	b       0xffffffffff94d884
     e28:	60 00 00 00 	nop
     e2c:	60 00 00 00 	nop
     e30:	eb 61 00 78 	ld      r27,120(r1)
     e34:	eb 81 00 80 	ld      r28,128(r1)
     e38:	eb a1 00 88 	ld      r29,136(r1)
     e3c:	eb c1 00 90 	ld      r30,144(r1)
     e40:	eb e1 00 98 	ld      r31,152(r1)
     e44:	e8 01 00 b0 	ld      r0,176(r1)
     e48:	38 21 00 a0 	addi    r1,r1,160
     e4c:	7c 08 03 a6 	mtlr    r0
     e50:	38 60 00 01 	li      r3,1
     e54:	78 63 f8 06 	rldicr  r3,r3,63,0
     e58:	64 63 00 70 	oris    r3,r3,112
     e5c:	38 80 00 00 	li      r4,0
     e60:	38 a0 06 e8 	li      r5,1768
     e64:	4b 94 ca 60 	b       0xffffffffff94d8c4
     e68:	60 00 00 00 	nop
     e6c:	60 00 00 00 	nop
     e70:	eb 61 00 78 	ld      r27,120(r1)
     e74:	eb 81 00 80 	ld      r28,128(r1)
     e78:	eb a1 00 88 	ld      r29,136(r1)
     e7c:	eb c1 00 90 	ld      r30,144(r1)
     e80:	eb e1 00 98 	ld      r31,152(r1)
     e84:	e8 01 00 b0 	ld      r0,176(r1)
     e88:	38 21 00 a0 	addi    r1,r1,160
     e8c:	7c 08 03 a6 	mtlr    r0
     e90:	38 60 00 01 	li      r3,1
     e94:	78 63 f8 06 	rldicr  r3,r3,63,0
     e98:	64 63 00 70 	oris    r3,r3,112
     e9c:	38 80 00 00 	li      r4,0
     ea0:	38 a0 06 e8 	li      r5,1768
     ea4:	4b 94 ca 60 	b       0xffffffffff94d904
     ea8:	60 00 00 00 	nop
     eac:	60 00 00 00 	nop
     eb0:	eb 61 00 78 	ld      r27,120(r1)
     eb4:	eb 81 00 80 	ld      r28,128(r1)
     eb8:	eb a1 00 88 	ld      r29,136(r1)
     ebc:	eb c1 00 90 	ld      r30,144(r1)
     ec0:	eb e1 00 98 	ld      r31,152(r1)
     ec4:	e8 01 00 b0 	ld      r0,176(r1)
     ec8:	38 21 00 a0 	addi    r1,r1,160
     ecc:	7c 08 03 a6 	mtlr    r0
     ed0:	38 60 00 01 	li      r3,1
     ed4:	78 63 f8 06 	rldicr  r3,r3,63,0
     ed8:	64 63 00 70 	oris    r3,r3,112
     edc:	38 80 00 00 	li      r4,0
     ee0:	38 a0 06 e8 	li      r5,1768
     ee4:	4b 94 ca 60 	b       0xffffffffff94d944
     ee8:	60 00 00 00 	nop
     eec:	60 00 00 00 	nop
     ef0:	eb 61 00 78 	ld      r27,120(r1)
     ef4:	eb 81 00 80 	ld      r28,128(r1)
     ef8:	eb a1 00 88 	ld      r29,136(r1)
     efc:	eb c1 00 90 	ld      r30,144(r1)
    This is the actual shellcode it repeats 32 times and it patches the lv2 (this info is from Rich). It probably tries to make the PC jump to this code sequence, I'm not sure if the same shell code could work on other firmwares.

    This is the second part. Looks more like RAW data or Encrypted data to me...
    Code:
    JIG_2.bin:     file format binary
    
    Disassembly of section .data:
    
    0000000000000000 <.data>:
       0:	09 02 4d 0a 	tdgti   r2,19722
       4:	01 01 00 80 	.long 0x1010080
       8:	01 09 04 00 	.long 0x1090400
       c:	00 00 fe 01 	.long 0xfe01
      10:	02 00 09 04 	.long 0x2000904
      14:	00 00 00 fe 	.long 0xfe
      18:	01 02 00 09 	.long 0x1020009
      1c:	04 00 00 00 	.long 0x4000000
      20:	fe 01 02 00 	.long 0xfe010200
      24:	09 04 00 00 	tdgti   r4,0
      28:	00 fe 01 02 	.long 0xfe0102
      2c:	00 09 04 00 	.long 0x90400
      30:	00 00 fe 01 	.long 0xfe01
      34:	02 00 09 04 	.long 0x2000904
      38:	00 00 00 fe 	.long 0xfe
      3c:	01 02 00 09 	.long 0x1020009
      40:	00 09 04 00 	.long 0x90400
      44:	00 00 fe 01 	.long 0xfe01
      48:	02 00 09 04 	.long 0x2000904
      4c:	00 00 00 fe 	.long 0xfe
      50:	01 02 00 09 	.long 0x1020009
      54:	04 00 00 00 	.long 0x4000000
      58:	fe 01 02 00 	.long 0xfe010200
      5c:	09 04 00 00 	tdgti   r4,0
      60:	00 fe 01 02 	.long 0xfe0102
      64:	00 09 04 00 	.long 0x90400
      68:	00 00 fe 01 	.long 0xfe01
      6c:	02 00 09 04 	.long 0x2000904
      70:	00 00 00 fe 	.long 0xfe
      74:	01 02 00 09 	.long 0x1020009
      78:	04 00 00 00 	.long 0x4000000
      7c:	fe 01 02 00 	.long 0xfe010200
      80:	02 00 09 04 	.long 0x2000904
      84:	00 00 00 fe 	.long 0xfe
      88:	01 02 00 09 	.long 0x1020009
      8c:	04 00 00 00 	.long 0x4000000
      90:	fe 01 02 00 	.long 0xfe010200
      94:	09 04 00 00 	tdgti   r4,0
      98:	00 fe 01 02 	.long 0xfe0102
      9c:	00 09 04 00 	.long 0x90400
      a0:	00 00 fe 01 	.long 0xfe01
      a4:	02 00 09 04 	.long 0x2000904
      a8:	00 00 00 fe 	.long 0xfe
      ac:	01 02 00 09 	.long 0x1020009
      b0:	04 00 00 00 	.long 0x4000000
      b4:	fe 01 02 00 	.long 0xfe010200
      b8:	09 04 00 00 	tdgti   r4,0
      bc:	00 fe 01 02 	.long 0xfe0102
      c0:	01 02 00 09 	.long 0x1020009
      c4:	04 00 00 00 	.long 0x4000000
      c8:	fe 01 02 00 	.long 0xfe010200
      cc:	09 04 00 00 	tdgti   r4,0
      d0:	00 fe 01 02 	.long 0xfe0102
      d4:	00 09 04 00 	.long 0x90400
      d8:	00 00 fe 01 	.long 0xfe01
      dc:	02 00 09 04 	.long 0x2000904
      e0:	00 00 00 fe 	.long 0xfe
      e4:	01 02 00 09 	.long 0x1020009
      e8:	04 00 00 00 	.long 0x4000000
      ec:	fe 01 02 00 	.long 0xfe010200
      f0:	09 04 00 00 	tdgti   r4,0
      f4:	00 fe 01 02 	.long 0xfe0102
      f8:	00 09 04 00 	.long 0x90400
      fc:	00 00 fe 01 	.long 0xfe01
     100:	fe 01 02 00 	.long 0xfe010200
     104:	09 04 00 00 	tdgti   r4,0
     108:	00 fe 01 02 	.long 0xfe0102
     10c:	00 09 04 00 	.long 0x90400
     110:	00 00 fe 01 	.long 0xfe01
     114:	02 00 09 04 	.long 0x2000904
     118:	00 00 00 fe 	.long 0xfe
     11c:	01 02 00 09 	.long 0x1020009
     120:	04 00 00 00 	.long 0x4000000
     124:	fe 01 02 00 	.long 0xfe010200
     128:	09 04 00 00 	tdgti   r4,0
     12c:	00 fe 01 02 	.long 0xfe0102
     130:	00 09 04 00 	.long 0x90400
     134:	00 00 fe 01 	.long 0xfe01
     138:	02 00 09 04 	.long 0x2000904
     13c:	00 00 00 fe 	.long 0xfe
     140:	00 fe 01 02 	.long 0xfe0102
     144:	00 09 04 00 	.long 0x90400
     148:	00 00 fe 01 	.long 0xfe01
     14c:	02 00 09 04 	.long 0x2000904
     150:	00 00 00 fe 	.long 0xfe
     154:	01 02 00 09 	.long 0x1020009
     158:	04 00 00 00 	.long 0x4000000
     15c:	fe 01 02 00 	.long 0xfe010200
     160:	09 04 00 00 	tdgti   r4,0
     164:	00 fe 01 02 	.long 0xfe0102
     168:	00 09 04 00 	.long 0x90400
     16c:	00 00 fe 01 	.long 0xfe01
     170:	02 00 09 04 	.long 0x2000904
     174:	00 00 00 fe 	.long 0xfe
     178:	01 02 00 09 	.long 0x1020009
     17c:	04 00 00 00 	.long 0x4000000
     180:	00 00 fe 01 	.long 0xfe01
     184:	02 00 09 04 	.long 0x2000904
     188:	00 00 00 fe 	.long 0xfe
     18c:	01 02 00 09 	.long 0x1020009
     190:	04 00 00 00 	.long 0x4000000
     194:	fe 01 02 00 	.long 0xfe010200
     198:	09 04 00 00 	tdgti   r4,0
     19c:	00 fe 01 02 	.long 0xfe0102
     1a0:	00 09 04 00 	.long 0x90400
     1a4:	00 00 fe 01 	.long 0xfe01
     1a8:	02 00 09 04 	.long 0x2000904
     1ac:	00 00 00 fe 	.long 0xfe
     1b0:	01 02 00 09 	.long 0x1020009
     1b4:	04 00 00 00 	.long 0x4000000
     1b8:	fe 01 02 00 	.long 0xfe010200
     1bc:	09 04 00 00 	tdgti   r4,0
     1c0:	00 00 00 fe 	.long 0xfe
     1c4:	01 02 00 09 	.long 0x1020009
     1c8:	04 00 00 00 	.long 0x4000000
     1cc:	fe 01 02 00 	.long 0xfe010200
     1d0:	09 04 00 00 	tdgti   r4,0
     1d4:	00 fe 01 02 	.long 0xfe0102
     1d8:	00 09 04 00 	.long 0x90400
     1dc:	00 00 fe 01 	.long 0xfe01
     1e0:	02 00 09 04 	.long 0x2000904
     1e4:	00 00 00 fe 	.long 0xfe
     1e8:	01 02 00 09 	.long 0x1020009
     1ec:	04 00 00 00 	.long 0x4000000
     1f0:	fe 01 02 00 	.long 0xfe010200
     1f4:	09 04 00 00 	tdgti   r4,0
     1f8:	00 fe 01 02 	.long 0xfe0102
     1fc:	00 09 04 00 	.long 0x90400
     200:	04 00 00 00 	.long 0x4000000
     204:	fe 01 02 00 	.long 0xfe010200
     208:	09 04 00 00 	tdgti   r4,0
     20c:	00 fe 01 02 	.long 0xfe0102
     210:	00 09 04 00 	.long 0x90400
     214:	00 00 fe 01 	.long 0xfe01
     218:	02 00 09 04 	.long 0x2000904
     21c:	00 00 00 fe 	.long 0xfe
     220:	01 02 00 09 	.long 0x1020009
     224:	04 00 00 00 	.long 0x4000000
     228:	fe 01 02 00 	.long 0xfe010200
     22c:	09 04 00 00 	tdgti   r4,0
     230:	00 fe 01 02 	.long 0xfe0102
     234:	00 09 04 00 	.long 0x90400
     238:	00 00 fe 01 	.long 0xfe01
     23c:	02 00 09 04 	.long 0x2000904
     240:	09 04 00 00 	tdgti   r4,0
     244:	00 fe 01 02 	.long 0xfe0102
     248:	00 09 04 00 	.long 0x90400
     24c:	00 00 fe 01 	.long 0xfe01
     250:	02 00 09 04 	.long 0x2000904
     254:	00 00 00 fe 	.long 0xfe
     258:	01 02 00 09 	.long 0x1020009
     25c:	04 00 00 00 	.long 0x4000000
     260:	fe 01 02 00 	.long 0xfe010200
     264:	09 04 00 00 	tdgti   r4,0
     268:	00 fe 01 02 	.long 0xfe0102
     26c:	00 09 04 00 	.long 0x90400
     270:	00 00 fe 01 	.long 0xfe01
     274:	02 00 09 04 	.long 0x2000904
     278:	00 00 00 fe 	.long 0xfe
     27c:	01 02 00 09 	.long 0x1020009
     280:	00 09 04 00 	.long 0x90400
     284:	00 00 fe 01 	.long 0xfe01
     288:	02 00 09 04 	.long 0x2000904
     28c:	00 00 00 fe 	.long 0xfe
     290:	01 02 00 09 	.long 0x1020009
     294:	04 00 00 00 	.long 0x4000000
     298:	fe 01 02 00 	.long 0xfe010200
     29c:	09 04 00 00 	tdgti   r4,0
     2a0:	00 fe 01 02 	.long 0xfe0102
     2a4:	00 09 04 00 	.long 0x90400
     2a8:	00 00 fe 01 	.long 0xfe01
     2ac:	02 00 09 04 	.long 0x2000904
     2b0:	00 00 00 fe 	.long 0xfe
     2b4:	01 02 00 09 	.long 0x1020009
     2b8:	04 00 00 00 	.long 0x4000000
     2bc:	fe 01 02 00 	.long 0xfe010200
     2c0:	02 00 09 04 	.long 0x2000904
     2c4:	00 00 00 fe 	.long 0xfe
     2c8:	01 02 00 09 	.long 0x1020009
     2cc:	04 00 00 00 	.long 0x4000000
     2d0:	fe 01 02 00 	.long 0xfe010200
     2d4:	09 04 00 00 	tdgti   r4,0
     2d8:	00 fe 01 02 	.long 0xfe0102
     2dc:	00 09 04 00 	.long 0x90400
     2e0:	00 00 fe 01 	.long 0xfe01
     2e4:	02 00 09 04 	.long 0x2000904
     2e8:	00 00 00 fe 	.long 0xfe
     2ec:	01 02 00 09 	.long 0x1020009
     2f0:	04 00 00 00 	.long 0x4000000
     2f4:	fe 01 02 00 	.long 0xfe010200
     2f8:	09 04 00 00 	tdgti   r4,0
     2fc:	00 fe 01 02 	.long 0xfe0102
     300:	01 02 00 09 	.long 0x1020009
     304:	04 00 00 00 	.long 0x4000000
     308:	fe 01 02 00 	.long 0xfe010200
     30c:	09 04 00 00 	tdgti   r4,0
     310:	00 fe 01 02 	.long 0xfe0102
     314:	00 09 04 00 	.long 0x90400
     318:	00 00 fe 01 	.long 0xfe01
     31c:	02 00 09 04 	.long 0x2000904
     320:	00 00 00 fe 	.long 0xfe
     324:	01 02 00 09 	.long 0x1020009
     328:	04 00 00 00 	.long 0x4000000
     32c:	fe 01 02 00 	.long 0xfe010200
     330:	09 04 00 00 	tdgti   r4,0
     334:	00 fe 01 02 	.long 0xfe0102
     338:	00 09 04 00 	.long 0x90400
     33c:	00 00 fe 01 	.long 0xfe01
     340:	fe 01 02 00 	.long 0xfe010200
     344:	09 04 00 00 	tdgti   r4,0
     348:	00 fe 01 02 	.long 0xfe0102
     34c:	00 09 04 00 	.long 0x90400
     350:	00 00 fe 01 	.long 0xfe01
     354:	02 00 09 04 	.long 0x2000904
     358:	00 00 00 fe 	.long 0xfe
     35c:	01 02 00 09 	.long 0x1020009
     360:	04 00 00 00 	.long 0x4000000
     364:	fe 01 02 00 	.long 0xfe010200
     368:	09 04 00 00 	tdgti   r4,0
     36c:	00 fe 01 02 	.long 0xfe0102
     370:	00 09 04 00 	.long 0x90400
     374:	00 00 fe 01 	.long 0xfe01
     378:	02 00 09 04 	.long 0x2000904
     37c:	00 00 00 fe 	.long 0xfe
     380:	00 fe 01 02 	.long 0xfe0102
     384:	00 09 04 00 	.long 0x90400
     388:	00 00 fe 01 	.long 0xfe01
     38c:	02 00 09 04 	.long 0x2000904
     390:	00 00 00 fe 	.long 0xfe
     394:	01 02 00 09 	.long 0x1020009
     398:	04 00 00 00 	.long 0x4000000
     39c:	fe 01 02 00 	.long 0xfe010200
     3a0:	09 04 00 00 	tdgti   r4,0
     3a4:	00 fe 01 02 	.long 0xfe0102
     3a8:	00 09 04 00 	.long 0x90400
     3ac:	00 00 fe 01 	.long 0xfe01
     3b0:	02 00 09 04 	.long 0x2000904
     3b4:	00 00 00 fe 	.long 0xfe
     3b8:	01 02 00 09 	.long 0x1020009
     3bc:	04 00 00 00 	.long 0x4000000
     3c0:	00 00 fe 01 	.long 0xfe01
     3c4:	02 00 09 04 	.long 0x2000904
     3c8:	00 00 00 fe 	.long 0xfe
     3cc:	01 02 00 09 	.long 0x1020009
     3d0:	04 00 00 00 	.long 0x4000000
     3d4:	fe 01 02 00 	.long 0xfe010200
     3d8:	09 04 00 00 	tdgti   r4,0
     3dc:	00 fe 01 02 	.long 0xfe0102
     3e0:	00 09 04 00 	.long 0x90400
     3e4:	00 00 fe 01 	.long 0xfe01
     3e8:	02 00 09 04 	.long 0x2000904
     3ec:	00 00 00 fe 	.long 0xfe
     3f0:	01 02 00 09 	.long 0x1020009
     3f4:	04 00 00 00 	.long 0x4000000
     3f8:	fe 01 02 00 	.long 0xfe010200
     3fc:	09 04 00 00 	tdgti   r4,0
     400:	00 00 00 fe 	.long 0xfe
     404:	01 02 00 09 	.long 0x1020009
     408:	04 00 00 00 	.long 0x4000000
     40c:	fe 01 02 00 	.long 0xfe010200
     410:	09 04 00 00 	tdgti   r4,0
     414:	00 fe 01 02 	.long 0xfe0102
     418:	00 09 04 00 	.long 0x90400
     41c:	00 00 fe 01 	.long 0xfe01
     420:	02 00 09 04 	.long 0x2000904
     424:	00 00 00 fe 	.long 0xfe
     428:	01 02 00 09 	.long 0x1020009
     42c:	04 00 00 00 	.long 0x4000000
     430:	fe 01 02 00 	.long 0xfe010200
     434:	09 04 00 00 	tdgti   r4,0
     438:	00 fe 01 02 	.long 0xfe0102
     43c:	00 09 04 00 	.long 0x90400
     440:	04 00 00 00 	.long 0x4000000
     444:	fe 01 02 00 	.long 0xfe010200
     448:	09 04 00 00 	tdgti   r4,0
     44c:	00 fe 01 02 	.long 0xfe0102
     450:	00 09 04 00 	.long 0x90400
     454:	00 00 fe 01 	.long 0xfe01
     458:	02 00 09 04 	.long 0x2000904
     45c:	00 00 00 fe 	.long 0xfe
     460:	01 02 00 09 	.long 0x1020009
     464:	04 00 00 00 	.long 0x4000000
     468:	fe 01 02 00 	.long 0xfe010200
     46c:	09 04 00 00 	tdgti   r4,0
     470:	00 fe 01 02 	.long 0xfe0102
     474:	00 09 04 00 	.long 0x90400
     478:	00 00 fe 01 	.long 0xfe01
     47c:	02 00 09 04 	.long 0x2000904
     480:	09 04 00 00 	tdgti   r4,0
     484:	00 fe 01 02 	.long 0xfe0102
     488:	00 09 04 00 	.long 0x90400
     48c:	00 00 fe 01 	.long 0xfe01
     490:	02 00 09 04 	.long 0x2000904
     494:	00 00 00 fe 	.long 0xfe
     498:	01 02 00 09 	.long 0x1020009
     49c:	04 00 00 00 	.long 0x4000000
     4a0:	fe 01 02 00 	.long 0xfe010200
     4a4:	09 04 00 00 	tdgti   r4,0
     4a8:	00 fe 01 02 	.long 0xfe0102
     4ac:	00 09 04 00 	.long 0x90400
     4b0:	00 00 fe 01 	.long 0xfe01
     4b4:	02 00 09 04 	.long 0x2000904
     4b8:	00 00 00 fe 	.long 0xfe
     4bc:	01 02 00 09 	.long 0x1020009
     4c0:	00 09 04 00 	.long 0x90400
     4c4:	00 00 fe 01 	.long 0xfe01
     4c8:	02 00 09 04 	.long 0x2000904
     4cc:	00 00 00 fe 	.long 0xfe
     4d0:	01 02 00 09 	.long 0x1020009
     4d4:	04 00 00 00 	.long 0x4000000
     4d8:	fe 01 02 00 	.long 0xfe010200
     4dc:	09 04 00 00 	tdgti   r4,0
     4e0:	00 fe 01 02 	.long 0xfe0102
     4e4:	00 09 04 00 	.long 0x90400
     4e8:	00 00 fe 01 	.long 0xfe01
     4ec:	02 00 09 04 	.long 0x2000904
     4f0:	00 00 00 fe 	.long 0xfe
     4f4:	01 02 00 09 	.long 0x1020009
     4f8:	04 00 00 00 	.long 0x4000000
     4fc:	fe 01 02 00 	.long 0xfe010200
     500:	02 00 09 04 	.long 0x2000904
     504:	00 00 00 fe 	.long 0xfe
     508:	01 02 00 09 	.long 0x1020009
     50c:	04 00 00 00 	.long 0x4000000
     510:	fe 01 02 00 	.long 0xfe010200
     514:	09 04 00 00 	tdgti   r4,0
     518:	00 fe 01 02 	.long 0xfe0102
     51c:	00 09 04 00 	.long 0x90400
     520:	00 00 fe 01 	.long 0xfe01
     524:	02 00 09 04 	.long 0x2000904
     528:	00 00 00 fe 	.long 0xfe
     52c:	01 02 00 09 	.long 0x1020009
     530:	04 00 00 00 	.long 0x4000000
     534:	fe 01 02 00 	.long 0xfe010200
     538:	09 04 00 00 	tdgti   r4,0
     53c:	00 fe 01 02 	.long 0xfe0102
     540:	01 02 00 09 	.long 0x1020009
     544:	04 00 00 00 	.long 0x4000000
     548:	fe 01 02 00 	.long 0xfe010200
     54c:	09 04 00 00 	tdgti   r4,0
     550:	00 fe 01 02 	.long 0xfe0102
     554:	00 09 04 00 	.long 0x90400
     558:	00 00 fe 01 	.long 0xfe01
     55c:	02 00 09 04 	.long 0x2000904
     560:	00 00 00 fe 	.long 0xfe
     564:	01 02 00 09 	.long 0x1020009
     568:	04 00 00 00 	.long 0x4000000
     56c:	fe 01 02 00 	.long 0xfe010200
     570:	09 04 00 00 	tdgti   r4,0
     574:	00 fe 01 02 	.long 0xfe0102
     578:	00 09 04 00 	.long 0x90400
     57c:	00 00 fe 01 	.long 0xfe01
     580:	fe 01 02 00 	.long 0xfe010200
     584:	09 04 00 00 	tdgti   r4,0
     588:	00 fe 01 02 	.long 0xfe0102
     58c:	00 09 04 00 	.long 0x90400
     590:	00 00 fe 01 	.long 0xfe01
     594:	02 00 09 04 	.long 0x2000904
     598:	00 00 00 fe 	.long 0xfe
     59c:	01 02 00 09 	.long 0x1020009
     5a0:	04 00 00 00 	.long 0x4000000
     5a4:	fe 01 02 00 	.long 0xfe010200
     5a8:	09 04 00 00 	tdgti   r4,0
     5ac:	00 fe 01 02 	.long 0xfe0102
     5b0:	00 09 04 00 	.long 0x90400
     5b4:	00 00 fe 01 	.long 0xfe01
     5b8:	02 00 09 04 	.long 0x2000904
     5bc:	00 00 00 fe 	.long 0xfe
     5c0:	00 fe 01 02 	.long 0xfe0102
     5c4:	00 09 04 00 	.long 0x90400
     5c8:	00 00 fe 01 	.long 0xfe01
     5cc:	02 00 09 04 	.long 0x2000904
     5d0:	00 00 00 fe 	.long 0xfe
     5d4:	01 02 00 09 	.long 0x1020009
     5d8:	04 00 00 00 	.long 0x4000000
     5dc:	fe 01 02 00 	.long 0xfe010200
     5e0:	09 04 00 00 	tdgti   r4,0
     5e4:	00 fe 01 02 	.long 0xfe0102
     5e8:	00 09 04 00 	.long 0x90400
     5ec:	00 00 fe 01 	.long 0xfe01
     5f0:	02 00 09 04 	.long 0x2000904
     5f4:	00 00 00 fe 	.long 0xfe
     5f8:	01 02 00 09 	.long 0x1020009
     5fc:	04 00 00 00 	.long 0x4000000
     600:	00 00 fe 01 	.long 0xfe01
     604:	02 00 09 04 	.long 0x2000904
     608:	00 00 00 fe 	.long 0xfe
     60c:	01 02 00 09 	.long 0x1020009
     610:	04 00 00 00 	.long 0x4000000
     614:	fe 01 02 00 	.long 0xfe010200
     618:	09 04 00 00 	tdgti   r4,0
     61c:	00 fe 01 02 	.long 0xfe0102
     620:	00 09 04 00 	.long 0x90400
     624:	00 00 fe 01 	.long 0xfe01
     628:	02 00 09 04 	.long 0x2000904
     62c:	00 00 00 fe 	.long 0xfe
     630:	01 02 00 09 	.long 0x1020009
     634:	04 00 00 00 	.long 0x4000000
     638:	fe 01 02 00 	.long 0xfe010200
     63c:	09 04 00 00 	tdgti   r4,0
     640:	00 00 00 fe 	.long 0xfe
     644:	01 02 00 09 	.long 0x1020009
     648:	04 00 00 00 	.long 0x4000000
     64c:	fe 01 02 00 	.long 0xfe010200
     650:	09 04 00 00 	tdgti   r4,0
     654:	00 fe 01 02 	.long 0xfe0102
     658:	00 09 04 00 	.long 0x90400
     65c:	00 00 fe 01 	.long 0xfe01
     660:	02 00 09 04 	.long 0x2000904
     664:	00 00 00 fe 	.long 0xfe
     668:	01 02 00 09 	.long 0x1020009
     66c:	04 00 00 00 	.long 0x4000000
     670:	fe 01 02 00 	.long 0xfe010200
     674:	09 04 00 00 	tdgti   r4,0
     678:	00 fe 01 02 	.long 0xfe0102
     67c:	00 09 04 00 	.long 0x90400
     680:	04 00 00 00 	.long 0x4000000
     684:	fe 01 02 00 	.long 0xfe010200
     688:	09 04 00 00 	tdgti   r4,0
     68c:	00 fe 01 02 	.long 0xfe0102
     690:	00 09 04 00 	.long 0x90400
     694:	00 00 fe 01 	.long 0xfe01
     698:	02 00 09 04 	.long 0x2000904
     69c:	00 00 00 fe 	.long 0xfe
     6a0:	01 02 00 09 	.long 0x1020009
     6a4:	04 00 00 00 	.long 0x4000000
     6a8:	fe 01 02 00 	.long 0xfe010200
     6ac:	09 04 00 00 	tdgti   r4,0
     6b0:	00 fe 01 02 	.long 0xfe0102
     6b4:	00 09 04 00 	.long 0x90400
     6b8:	00 00 fe 01 	.long 0xfe01
     6bc:	02 00 09 04 	.long 0x2000904
     6c0:	09 04 00 00 	tdgti   r4,0
     6c4:	00 fe 01 02 	.long 0xfe0102
     6c8:	00 09 04 00 	.long 0x90400
     6cc:	00 00 fe 01 	.long 0xfe01
     6d0:	02 00 09 04 	.long 0x2000904
     6d4:	00 00 00 fe 	.long 0xfe
     6d8:	01 02 00 09 	.long 0x1020009
     6dc:	04 00 00 00 	.long 0x4000000
     6e0:	fe 01 02 00 	.long 0xfe010200
     6e4:	09 04 00 00 	tdgti   r4,0
     6e8:	00 fe 01 02 	.long 0xfe0102
     6ec:	00 09 04 00 	.long 0x90400
     6f0:	00 00 fe 01 	.long 0xfe01
     6f4:	02 00 09 04 	.long 0x2000904
     6f8:	00 00 00 fe 	.long 0xfe
     6fc:	01 02 00 09 	.long 0x1020009
     700:	00 09 04 00 	.long 0x90400
     704:	00 00 fe 01 	.long 0xfe01
     708:	02 00 09 04 	.long 0x2000904
     70c:	00 00 00 fe 	.long 0xfe
     710:	01 02 00 09 	.long 0x1020009
     714:	04 00 00 00 	.long 0x4000000
     718:	fe 01 02 00 	.long 0xfe010200
     71c:	09 04 00 00 	tdgti   r4,0
     720:	00 fe 01 02 	.long 0xfe0102
     724:	00 09 04 00 	.long 0x90400
     728:	00 00 fe 01 	.long 0xfe01
     72c:	02 00 09 04 	.long 0x2000904
     730:	00 00 00 fe 	.long 0xfe
     734:	01 02 00 09 	.long 0x1020009
     738:	04 00 00 00 	.long 0x4000000
     73c:	fe 01 02 00 	.long 0xfe010200
     740:	02 00 09 04 	.long 0x2000904
     744:	00 00 00 fe 	.long 0xfe
     748:	01 02 00 09 	.long 0x1020009
     74c:	04 00 00 00 	.long 0x4000000
     750:	fe 01 02 00 	.long 0xfe010200
     754:	09 04 00 00 	tdgti   r4,0
     758:	00 fe 01 02 	.long 0xfe0102
     75c:	00 09 04 00 	.long 0x90400
     760:	00 00 fe 01 	.long 0xfe01
     764:	02 00 09 04 	.long 0x2000904
     768:	00 00 00 fe 	.long 0xfe
     76c:	01 02 00 09 	.long 0x1020009
     770:	04 00 00 00 	.long 0x4000000
     774:	fe 01 02 00 	.long 0xfe010200
     778:	09 04 00 00 	tdgti   r4,0
     77c:	00 fe 01 02 	.long 0xfe0102
     780:	01 02 00 09 	.long 0x1020009
     784:	04 00 00 00 	.long 0x4000000
     788:	fe 01 02 00 	.long 0xfe010200
     78c:	09 04 00 00 	tdgti   r4,0
     790:	00 fe 01 02 	.long 0xfe0102
     794:	00 09 04 00 	.long 0x90400
     798:	00 00 fe 01 	.long 0xfe01
     79c:	02 00 09 04 	.long 0x2000904
     7a0:	00 00 00 fe 	.long 0xfe
     7a4:	01 02 00 09 	.long 0x1020009
     7a8:	04 00 00 00 	.long 0x4000000
     7ac:	fe 01 02 00 	.long 0xfe010200
     7b0:	09 04 00 00 	tdgti   r4,0
     7b4:	00 fe 01 02 	.long 0xfe0102
     7b8:	00 09 04 00 	.long 0x90400
     7bc:	00 00 fe 01 	.long 0xfe01
     7c0:	fe 01 02 00 	.long 0xfe010200
     7c4:	09 04 00 00 	tdgti   r4,0
     7c8:	00 fe 01 02 	.long 0xfe0102
     7cc:	00 09 04 00 	.long 0x90400
     7d0:	00 00 fe 01 	.long 0xfe01
     7d4:	02 00 09 04 	.long 0x2000904
     7d8:	00 00 00 fe 	.long 0xfe
     7dc:	01 02 00 09 	.long 0x1020009
     7e0:	04 00 00 00 	.long 0x4000000
     7e4:	fe 01 02 00 	.long 0xfe010200
     7e8:	09 04 00 00 	tdgti   r4,0
     7ec:	00 fe 01 02 	.long 0xfe0102
     7f0:	00 09 04 00 	.long 0x90400
     7f4:	00 00 fe 01 	.long 0xfe01
     7f8:	02 00 09 04 	.long 0x2000904
     7fc:	00 00 00 fe 	.long 0xfe
     800:	00 fe 01 02 	.long 0xfe0102
     804:	00 09 04 00 	.long 0x90400
     808:	00 00 fe 01 	.long 0xfe01
     80c:	02 00 09 04 	.long 0x2000904
     810:	00 00 00 fe 	.long 0xfe
     814:	01 02 00 09 	.long 0x1020009
     818:	04 00 00 00 	.long 0x4000000
     81c:	fe 01 02 00 	.long 0xfe010200
     820:	09 04 00 00 	tdgti   r4,0
     824:	00 fe 01 02 	.long 0xfe0102
     828:	00 09 04 00 	.long 0x90400
     82c:	00 00 fe 01 	.long 0xfe01
     830:	02 00 09 04 	.long 0x2000904
     834:	00 00 00 fe 	.long 0xfe
     838:	01 02 00 09 	.long 0x1020009
     83c:	04 00 00 00 	.long 0x4000000
     840:	00 00 fe 01 	.long 0xfe01
     844:	02 00 09 04 	.long 0x2000904
     848:	00 00 00 fe 	.long 0xfe
     84c:	01 02 00 09 	.long 0x1020009
     850:	04 00 00 00 	.long 0x4000000
     854:	fe 01 02 00 	.long 0xfe010200
     858:	09 04 00 00 	tdgti   r4,0
     85c:	00 fe 01 02 	.long 0xfe0102
     860:	00 09 04 00 	.long 0x90400
     864:	00 00 fe 01 	.long 0xfe01
     868:	02 00 09 04 	.long 0x2000904
     86c:	00 00 00 fe 	.long 0xfe
     870:	01 02 00 09 	.long 0x1020009
     874:	04 00 00 00 	.long 0x4000000
     878:	fe 01 02 00 	.long 0xfe010200
     87c:	09 04 00 00 	tdgti   r4,0
     880:	00 00 00 fe 	.long 0xfe
     884:	01 02 00 09 	.long 0x1020009
     888:	04 00 00 00 	.long 0x4000000
     88c:	fe 01 02 00 	.long 0xfe010200
     890:	09 04 00 00 	tdgti   r4,0
     894:	00 fe 01 02 	.long 0xfe0102
     898:	00 09 04 00 	.long 0x90400
     89c:	00 00 fe 01 	.long 0xfe01
     8a0:	02 00 09 04 	.long 0x2000904
     8a4:	00 00 00 fe 	.long 0xfe
     8a8:	01 02 00 09 	.long 0x1020009
     8ac:	04 00 00 00 	.long 0x4000000
     8b0:	fe 01 02 00 	.long 0xfe010200
     8b4:	09 04 00 00 	tdgti   r4,0
     8b8:	00 fe 01 02 	.long 0xfe0102
     8bc:	00 09 04 00 	.long 0x90400
     8c0:	04 00 00 00 	.long 0x4000000
     8c4:	fe 01 02 00 	.long 0xfe010200
     8c8:	09 04 00 00 	tdgti   r4,0
     8cc:	00 fe 01 02 	.long 0xfe0102
     8d0:	00 09 04 00 	.long 0x90400
     8d4:	00 00 fe 01 	.long 0xfe01
     8d8:	02 00 09 04 	.long 0x2000904
     8dc:	00 00 00 fe 	.long 0xfe
     8e0:	01 02 00 09 	.long 0x1020009
     8e4:	04 00 00 00 	.long 0x4000000
     8e8:	fe 01 02 00 	.long 0xfe010200
     8ec:	09 04 00 00 	tdgti   r4,0
     8f0:	00 fe 01 02 	.long 0xfe0102
     8f4:	00 09 04 00 	.long 0x90400
     8f8:	00 00 fe 01 	.long 0xfe01
     8fc:	02 00 09 04 	.long 0x2000904
     900:	09 04 00 00 	tdgti   r4,0
     904:	00 fe 01 02 	.long 0xfe0102
     908:	00 09 04 00 	.long 0x90400
     90c:	00 00 fe 01 	.long 0xfe01
     910:	02 00 09 04 	.long 0x2000904
     914:	00 00 00 fe 	.long 0xfe
     918:	01 02 00 09 	.long 0x1020009
     91c:	04 00 00 00 	.long 0x4000000
     920:	fe 01 02 00 	.long 0xfe010200
     924:	09 04 00 00 	tdgti   r4,0
     928:	00 fe 01 02 	.long 0xfe0102
     92c:	00 09 04 00 	.long 0x90400
     930:	00 00 fe 01 	.long 0xfe01
     934:	02 00 09 04 	.long 0x2000904
     938:	00 00 00 fe 	.long 0xfe
     93c:	01 02 00 09 	.long 0x1020009
     940:	00 09 04 00 	.long 0x90400
     944:	00 00 fe 01 	.long 0xfe01
     948:	02 00 09 04 	.long 0x2000904
     94c:	00 00 00 fe 	.long 0xfe
     950:	01 02 00 09 	.long 0x1020009
     954:	04 00 00 00 	.long 0x4000000
     958:	fe 01 02 00 	.long 0xfe010200
     95c:	09 04 00 00 	tdgti   r4,0
     960:	00 fe 01 02 	.long 0xfe0102
     964:	00 09 04 00 	.long 0x90400
     968:	00 00 fe 01 	.long 0xfe01
     96c:	02 00 09 04 	.long 0x2000904
     970:	00 00 00 fe 	.long 0xfe
     974:	01 02 00 09 	.long 0x1020009
     978:	04 00 00 00 	.long 0x4000000
     97c:	fe 01 02 00 	.long 0xfe010200
     980:	02 00 09 04 	.long 0x2000904
     984:	00 00 00 fe 	.long 0xfe
     988:	01 02 00 09 	.long 0x1020009
     98c:	04 00 00 00 	.long 0x4000000
     990:	fe 01 02 00 	.long 0xfe010200
     994:	09 04 00 00 	tdgti   r4,0
     998:	00 fe 01 02 	.long 0xfe0102
     99c:	00 09 04 00 	.long 0x90400
     9a0:	00 00 fe 01 	.long 0xfe01
     9a4:	02 00 09 04 	.long 0x2000904
     9a8:	00 00 00 fe 	.long 0xfe
     9ac:	01 02 00 09 	.long 0x1020009
     9b0:	04 00 00 00 	.long 0x4000000
     9b4:	fe 01 02 00 	.long 0xfe010200
     9b8:	09 04 00 00 	tdgti   r4,0
     9bc:	00 fe 01 02 	.long 0xfe0102
     9c0:	01 02 00 09 	.long 0x1020009
     9c4:	04 00 00 00 	.long 0x4000000
     9c8:	fe 01 02 00 	.long 0xfe010200
     9cc:	09 04 00 00 	tdgti   r4,0
     9d0:	00 fe 01 02 	.long 0xfe0102
     9d4:	00 09 04 00 	.long 0x90400
     9d8:	00 00 fe 01 	.long 0xfe01
     9dc:	02 00 09 04 	.long 0x2000904
     9e0:	00 00 00 fe 	.long 0xfe
     9e4:	01 02 00 09 	.long 0x1020009
     9e8:	04 00 00 00 	.long 0x4000000
     9ec:	fe 01 02 00 	.long 0xfe010200
     9f0:	09 04 00 00 	tdgti   r4,0
     9f4:	00 fe 01 02 	.long 0xfe0102
     9f8:	00 09 04 00 	.long 0x90400
     9fc:	00 00 fe 01 	.long 0xfe01
     a00:	fe 01 02 00 	.long 0xfe010200
     a04:	09 04 00 00 	tdgti   r4,0
     a08:	00 fe 01 02 	.long 0xfe0102
     a0c:	00 09 04 00 	.long 0x90400
     a10:	00 00 fe 01 	.long 0xfe01
     a14:	02 00 09 04 	.long 0x2000904
     a18:	00 00 00 fe 	.long 0xfe
     a1c:	01 02 00 09 	.long 0x1020009
     a20:	04 00 00 00 	.long 0x4000000
     a24:	fe 01 02 00 	.long 0xfe010200
     a28:	09 04 00 00 	tdgti   r4,0
     a2c:	00 fe 01 02 	.long 0xfe0102
     a30:	00 09 04 00 	.long 0x90400
     a34:	00 00 fe 01 	.long 0xfe01
     a38:	02 00 09 04 	.long 0x2000904
     a3c:	00 00 00 fe 	.long 0xfe
     a40:	00 fe 01 02 	.long 0xfe0102
     a44:	00 09 04 00 	.long 0x90400
     a48:	00 00 fe 01 	.long 0xfe01
     a4c:	Address 0x0000000000000a4c is out of bounds.

  3. #13
    Senior Member PSPSwampy's Avatar
    Join Date
    Jun 2005
    Posts
    795
    My though on this was to get a USB A-A cable, then plug one end into PC and the other to the PS3.

    Would need to code the PC specially to send the data through to the PS3 - I've been having a look around the net to see if there are any c# examples of using the PC's USB port as a "slave" device. I've not worked with the USB port much before in code, but I can't help thinking that this route would be possible.

    The final solution would be to have the byte stream from the PSJailbreak sent through from the PC, thus triggering the exploit.

    I'll continue to have a look, but if any of the other DEVs here have previous experience (& example source code) maybe this might be a FREE way forward (well the cost of an A-A cable!)

    It is late though so i may be talking complete BS - feedback welcome (especially from fellow PC devs)



    PSPSwampy.

  4. #14
    Junior Member hacked2123's Avatar
    Join Date
    Nov 2006
    Posts
    665
    Quote Originally Posted by PSPSwampy View Post
    maybe this might be a FREE way forward (well the cost of an A-A cable!)
    I don't believe PC USB ports are designed to be used as USB Host devices. There was a program back in the day that used USB to USB to transfer files, Laplink (http://www.laplink.com/cables/), but they had a controller in the middle, which leads me to believe it really can't be done for sure. :-/

    I know the PSP however has the ability to be host, as well as receive (camera for instance)... but that doesn't mean I know we can change the Device ID or Hardware ID. :-/

  5. #15
    Registered User Maniac2k's Avatar
    Join Date
    May 2007
    Posts
    39
    I think there are some duplicated bytes in the log. For example the beginning of the second block. First a configuration (09 02...) descriptor is send followed by a lot of interface descriptors (09 04...). Some of the bytes seems to be doubled.
    Code:
    09 02 4D 0A 01 01 00 80 01
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00 
    09 04 00 00 00 FE 01 02 00
    02 00 
    09 04 00 00 00 FE 01 02 00
    The lines with 09 00 and 02 00 shouldn't be there.

  6. #16
    Registered User OrionMTBR's Avatar
    Join Date
    Aug 2010
    Posts
    2
    I think we must sniff the PSJailbreak code in different PS3 systems, I think they do a kind of challenge/response, but some code pieces could be different on each PS3.

  7. #17
    Registered User Maniac2k's Avatar
    Join Date
    May 2007
    Posts
    39
    The only things the second block does is sending one configuration descriptor and after that the same interface descriptor repeated 292 times. I don't counted them but the length descriptor says it has an overall length of 2637 byte. Divided by 9 (as every descriptor is 9 byte in this block) you get 293. I'm looking forward to count this manually, if i get to the same number this will prove the log contains errors as described above.

  8. #18
    Senior Member BwE's Avatar
    Join Date
    Apr 2010
    Posts
    709
    Quote Originally Posted by hacked2123 View Post
    I don't believe PC USB ports are designed to be used as USB Host devices. There was a program back in the day that used USB to USB to transfer files, Laplink (http://www.laplink.com/cables/), but they had a controller in the middle, which leads me to believe it really can't be done for sure. :-/

    I know the PSP however has the ability to be host, as well as receive (camera for instance)... but that doesn't mean I know we can change the Device ID or Hardware ID. :-/
    why the hell not. i'm sure you can at least spoof it

  9. #19
    Contributor urbanracer34's Avatar
    Join Date
    Jun 2008
    Posts
    77
    I'd be welcome to test any implementations of the code on a CFW PSP or a JB'ed iOS device, via USB.

  10. #20
    Banned User kakarotoks's Avatar
    Join Date
    Jul 2008
    Posts
    119
    @Maniac2k:
    Very good observations, thanks for the help. Yes, it looks like we're missing a device descriptor.. also, in the first block, we get a configuration+interface descriptor, then a lot of data, probably the injected code. However, This dump isn't very helpful, it only seems to show raw sent data. Since USB is host-driven, then we would still need to know what request makes that device send that information..

    Anyways, you are right about those extra bytes in the second block, but there are no duplicated data in the log, simply because the wDataLength is correct, so this means that the device does this on purpose somehow.

    I see that the device sends 4 times the configuration 0 descriptor+payload, then two times the configuration 1 descriptor+292interface descriptors (the same descriptor for the same interface, but with some glitches). The guy also says there's a 'disconnect/connect' signal or something.. But I don't really see/understand how this works.

    The initial RE said something about a USB hub emulating 6 devices being plugged in/unplugged, and also a JIG device being plugged in. Without the proper device descriptors, there's not much we can do I think.

    By the way, from the Interface descriptor, it looks like the Class ID/SubClass ID/Protocol ID (defined by usb.org) are for a 'Device Firmware Update' device with protocol 0x02 : http://www.usb.org/developers/defined_class/#BaseClassFEh

    FE with subclass 0x01 means : "Device Firmware Upgrade. Device class definition provided on http://www.usb.org ." which is the infamous "DFU" mode.. I believe that's the actual JIG 'id'.

    You can read how it all works here : http://www.usb.org/developers/devclass_docs/usbdfu10.pdf

    So what I think happens is that the device id is not necessary, it can be anything, we don't care.. but what happens is that the device gives it two configurations, the first one is full of data to exploit the device, then it gives its second configuration with its interface being the DFU device... since it may not work, or maybe it needs to send it a lot of times to get it through? I don't know.. but anyways, just wanted to let you know that the 0xFE/0x01 class/subclass is for "DFU" devices!
    Last edited by kakarotoks; 08-28-2010 at 10:27 PM Reason: Automerged Doublepost

 


 
Page 2 of 12 FirstFirst 1234 ... LastLast