We have the PSJailbreak dongle yet again brought out of retirement to put it more precisely Herbs to take a closer look. We tell you here in brief the main steps of the internal process of PSJailbreak.
We can confirm that it can not confirm that PSJailbreak a clone of Sony's "Jig" is module. PSJailbrak is an exploit honest self-developed. The chip is not but a PIC18F444 ATMega with software USB. This means the chip is internally capable of USB to emulate. PSJailbreak mainly be emulated 6Port a USB hub connected to a specific end USB devices and then disconnected. One of these devices has the ID of Sony's "Jig" module, which means that played in the development of PSJailbreaks the "Jig" module, a certain role.
But let's start at the front: When the PS3 is clamped in the USB emulation device, which has a much too big Configuration Descriptor. This Descriptor überschriebt the stack with a PowerPC contained code that is executed. Now, various USB devices are connected in the emulation. A device has a large 0xAD Descriptor, which is part of the exploit and contains static data.
A short time later (we are moving here in Milisekundenbereich) the jig module is connected, and encrypted data are transmitted to the module jig. A (in Milisekundenbereich) eternity later, the answers Jig 64Byte module with static data, all USB devices are disconnected, a new USB device is connected and the PS3 launches with a new look.
64Byte static data that is emulated by the PS3 64Byte Jig sent to the static data that is emulated by Jig sent to the PS3
Extract from the USB stream Extract from the USB stream
Incidentally PSJailbreak is NOT updateable. The Update feature can be mentioned, if realized at all, only with additional hardware.
Last edited by red8316; 08-26-2010 at 06:48 PMReason: grammar
so here is a rough translation. My english isn´t that good by the way
They say that they examined the jailbreak device again and explain in a few steps how it works. It shouldnt be a clone of the sony jig. Jailbreak is an selfinvented hack. Its an Atmega with software usb, not an PIC18F444 Chip. This means the chip can emulate USB internally.
PSJailbreak emulates mainly an 6 Port USB-Hub, where in a special order, different USB-Devices gets connected and disconnected (emulated!). One of these devices has the id from the sony jig.
This means, that the sony jig played a certain role in the creation of PSJailbreak.
When you turn on your PS3, it simulates that a device gets connected to the hub, which has an way to big Configuration Descriptor. This Descriptor overwrites the stack with an contained PowerPC Code, which gets executed.
Now more devices will get connected to the hub.
One device has an 0xAD discriptor which is part of the exploit and contains static data. After that the jig gets connected (this all happens within microseconds) and some encrypted data will be send to the jig (auth process). After that the jig answers with 64Byte of static data, all other usb-devices are getting disconnected and a new device gets started, so that your PS3 starts with hack and all o its advantages.
The Jailbreak is not updateable! The Update-Feature only works (if it works at all) with an extra piece of Hardware!
This kinda worries me "Incidentally PSJailbreak is NOT updateable. Das erwähnte Update-Feature lässt sich, wenn überhaupt, nur mit zusätzlicher Hardware realisieren. The Update feature can be mentioned, if realized at all, only with additional hardware."