Generally, assuming that there is already a user mode exploit (think an exploit in a game), using this exploit will allow you to elevate permission to kernel level. The simplest way to think about it is the PSP exploits, and how multiple exploits were needed. Generally, of course!
basically a payload like the one used in the 3.41 jailbreak (hermes) is loaded into stack overflow when the ps3 tries to read this the payload is loaded into memory and you get unsigned code execution. but the problem is that ps3 is using the stack and it copies something to it instead of reading first.
so the payload which has been loaded there is being over written before it has been read and is deleted so if you could somehow make the ps3 read from stack or load the payload just before the stack gets read the payload would be loaded and you have a new jailbreak.
One you get a stable execution (hint ROP) you can glitch HTAB entries and do anything except persistent root because bootldr couldn't even be figured out by fa1loverflow team..
If you're looking for a lv1 exploit you'll never get anywhere unless you get a talented RE person with a lot of time, and since it's obvious Linux means less than piracy is PS3 scene that isn't likely to happen..
PS3 4.21 EBOOT Resigner SCETool Script is Released for 4.21 CFW
Following up on the previous update by Naehrwert and yesterday's PS3 LV0 Keys leak, today Chinese developer Rain fish (aka JjKkYu) has released a 4.21 EBOOT Resigner PS3 SCETool (aka TrueAncestor EBOOT Resigner) script which allows the resigning of 3.55 or decrypted EBOOT.BIN files for use with PlayStation 3 4.21 CFW.
To quote, roughly translated: Update: I renamed my resigner to TrueAncestor EBOOT Resigner and add DEX support. Enjoy.
This is a script of SCETool to resign the 3.55- or decrypted EBOOT.BIN for 4.21CFW use.
1. Extract the 4.21 EBOOT Resigner.zip.
2. Put EBOOT.BIN into the extracted folder.
3. Run resigner.bat to resign EBOOT, you may need to choose encrypt type.
4. If you chose NPDRM type, you need to enter Content-ID.
5. The original EBOOT.BIN will be renamed to EBOOT.BIN.BAK.
This script is tested on BD4.21 CFW, and it should work on Rogero 4.21. Some game also contains decrypted self or sprx file, you need to resign them manually.
Credit to badzbb.
Note: This script uses 3.60 keys to encrypt the EBOOT, no new keys.
TrueAncestor EBOOT Resigner Oldschool 3.55 Resign Added by haz367:
All credits to JjKkYu, badzbb, aldostools, Asure and everybody else... added 2 more options to it for 3.55 users:
[Register or Login to view links] / [Register or Login to view links] by lurkandlearn (0x300FD4: 4BFFCDE1 --> 38600000 and 0x300A34: 4831EE1D --> 38600000. Someone with a hardware flasher and knowledge how to properly reencrypt vsh.self needed to test this).
[Register or Login to view links] by snkysnake02 (this one requires the appropriate map files etc.. placed on your external if I remember right. Just search and obtain the map files for the game. this is just the installer for PS3, I have tested this and it works. If you already have this game installed then just delete from XMB and install this pkg and run game)
[Register or Login to view links] by snkysnake02 (allows you to switch back and forth between installing on the internal HDD and External drive. Just click icon and it will switch, to switch back click the icon again)
[Register or Login to view links] by snkysnake02 (this is the latest version)
[Register or Login to view links] (Standalone Signed by Simonbuck)
[Register or Login to view links] (put the EBOOT.BIN in the USRDIR) / [Register or Login to view links] by [C*] (I thought 3.55 .pkgs wouldn't install on 4.XX, the same way 3.41 .pkgs wouldn't install on 3.55, but that's not the case. So just download the .pkg, install it, and then copy the resigned EBOOT.BIN attatched here over to the dev_hdd0\game\Eskiss\USRDIR\ directory. (The one in the EBOOT.RAR in the other post is an Epic Mickey 2 EBOOT). The game ran for me, showed the menu, but I think it crashed because the home button on my controller wouldn't work. Unless it's because I don't have Move?)
[Register or Login to view links] by alienkid (Install Eskiss then, in multiMAN>File Manager>dev_hdd0>game>Eskiss_00>USRDIR.. Replace that eboot with the one included).
[Register or Login to view links] by haz367 (runs ok - exit = black screen - no HDD corruption!)
[Register or Login to view links] (To play, install the PKG and put your heretic.wad on the same folder where EBOOT.BIN is located (i.e. /dev_hdd0/game/HERETIC01/USRDIR) - signed by friend of LoboGuara)
[Register or Login to view links] (signed by ConsoleHackDev Team via consolehackdev.com/forum/area-51/release-zone/934-dosmount-re-signed-per-cfw-4-21-4-30-consolehackdev-team.html)
From Condorstrike also comes Solar 4.2 for CFW 3.55-4.XX and PS3LoadX_4.XX for 4.XX CFW with details on the latter below:
Here's an updated and repacked PS3LoadX for 4.xx CFW’s, did some minor code cleanup, and bug removal, also reduced application size and replaced the loading method. Also replaced ICON0 and PIC1 for better aesthetics. Enjoy...
Repacked for use with 4.xx CFWs.
Replaced loading method.
Fixed minor bug with Temporary Folder.
You can load SELF files using the net.
You can load applications from USB/ HDD devices
You can install applications to the USB or HDD devices from one .zip file
You can copy applications from USB devices to HDD
Also you can delete installed applications.
Installing and launching programs and .zip files:
You can load .ZIP files via tcp using the network, just like the SELFs.
An “install” folder will be built into your [USB/HDD root: Homebrew] Folder and contents shadow copied to PSL145310/homebrew/install.
The “install” folder can be added manually as-well, if no network loading is to be used.
Programs will be displayed in PS3LoadX and buttons commands will be available accordingly.
Finally, from samson: I ran windos eboot through all options in the resigner, if my guess works right you should be able to install windos final for 3.55 on 4.xx cfw's/dex and just replace the eboot. Also some should work for my other dos games/toys.
great news but wheres the 4.30 cfw. that be the one we want!
Please upload to mediafire or some thing that works without all the garbage that goes along. so sick of trying to download and need this livid crap etc, mediafire is best. should be the only one allowed i think!
Last edited by elser1; 10-23-2012 at 06:40 AMReason: Automerged Doublepost