Sponsored Links

Sponsored Links

Video: PS3 4.31 OFW to 4.30 Rogero v2.03 CFW with Flasher Guide


Sponsored Links
90w ago - Nearly two months after the previous update, today I have posted a guide and video on how to downgrade a PS3 4.31 OFW console (including CECH-300x slims) to 4.30 Rogero v2.03 CFW using a PS3 Hardware Flasher with no 3.55 needed.

Very easy tutorial. Follow the steps to downgrade a PS3, but when you get to the first step of the USB downgrading part after putting your PS3 into service mode, use Rogero 4.30 CFW v2.03 on the root of the USB with the lv2diag.self to downgrade instead of the 3.55.

So again, no 3.55 ever touches the PS3 during this whole setup! Doing this will also now allow CECH-300x models original slims to be downgraded to 4.30 CFW as long as it never touches 3.55

The whole reason for this was to find out if the E3 fits a CECH-400xx model super slim models, but all I needed was proof that you can downgrade from 4.31 to 4.30 CFW with a flasher.

So if any one out there has an E3 and a new super slim model please test this if it works! You can make back ups of the NOR incase it fails.

Here is proof you can but I still do not know if the CECH-400xx models are compatible since I do not have one.

Files needed for safety and to proceed:


PS3 USB links after NOR editing:


E3 back-up checks links:


Steps:

  • Step 1 - switch pup's with Rogero's 4.30 CFW v2.03 - my link has it set ready
  • Step 2 - lv2diag out of factory mode
  • PS3 nor dump patcher to fix bad back-ups
  • downgrade.bin - makes it rewrite the nor to allow factory mode access
  • update.bin - its the Samsung version of the flasher firmware, allows multi-console downgrades.. more than one console in other words
  • PS3 Flowrebuilder - decrypts the backups to look and make sure its good

Here is proof of me downgrading to 4.30 CFW no 3.55! My video is not cut but speeds up through the middle since it takes almost 2 hours to prove this. You see every time I drop the camera, fix the E3 and finish the downgrade straight to 4.30 CFW Rogero v2.03 which you will know it's spoofed to 4.31, you can see the install PKG / lastGAME icon after downgrading.








Hint: The E3 always has the ribbon starting under the NOR words (pictured below).

Always test your back ups and even use Flowrebuilder 4.2.2 to reverse decrypt to make sure your back up was good.








Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 139 Comments - Go to Forum Thread »

• Please Register at PS3News.com or Login to make comments on Site News articles. Thanks!

mistarz's Avatar
#14 - mistarz - 98w ago
Guys if i understand this right then we can install any 4.xx CFW on OFW above 3.55.We need to patch this files... can someone help me with that?

Check it out! > pastie.org/private/3np6uj6md1occbctdeir6a

Since the LV0 keys have now been leaked, I believe I can now share this info with you, to help out those who are trying to build their own 4.x CFW :

The NPDRM ECDSA signature in the SELF footer is checked by lv2. It first asks appldr to tell it whether or not the signature is to be checked, and appldr will only set the flag if the SELF is a NPDRM with key revision from 3.56+ (the ones without private keys). This means that the SELF files signed with the new 3.56+ keys still don't have their ecdsa checked (probably to speed up file loading).

If appldr says the ecdsa signature must be checked, then lv2 will verify it itself, and return an error if it's not correct. There are many ways to patch this check out.

1 - Patch out the check for the key revision in appldr
2 - Patch out the "set flag to 1" in appldr if the key revision is < 0xB
3 - Patch out the code in lv2 that stores the result from appldr
4 - Patch out the actual sigcheck function from lv2.
5 - Ignore the result of the ecdsa from lv2.

Here is one of the patches (the 4th one, patching out the check function from lv2) :
In memory 0x800000000005A2A8, which corresponds to offset 0x6a2a8 in lv2_kernel.elf, replace :

e9 22 99 90 7c 08 02 a6

With :

38 60 00 00 4e 80 00 20

This is for the 4.21 kernel (that was the latest one when I investigated this), I will leave it as an exercise to the reader to find the right offsets for the 4.25 and upcoming 4.30 kernel files.

And here's another bit of info... in 4.21 lv2, at memory address 0x800000000005AA98 (you figure out the file offset yourself), that's where lv2 loads the 'check_signature_flag' result from appldr, so if you prefer implementing method 3 above, just replace the 'ld %r0, flag_result_from_appldr' by 'ld %r0, 0' and you got another method of patching it out. Either solutions should work just the same though.
Enjoy homebrew back on 4.x CFW....

p.s: Thanks to flatz and glu0n who helped reversed this bit of info.

M

solokaz's Avatar
#13 - solokaz - 98w ago
thanks man i try on 4.11 and 4.21, but not from 4.30...

pollicin123's Avatar
#12 - pollicin123 - 98w ago
see this




sangimed's Avatar
#11 - sangimed - 98w ago
any news for minimum downgrade 3.60 ?

solokaz's Avatar
#10 - solokaz - 98w ago
If the factory firmware is lower then 3.55 and the ps3 have installed 4.25 or 4.30 ofw, e3 work.. any one tell us how to downgrade?

Sponsored Links

Sponsored Links
Sponsored Links

Sponsored Links







Advertising - Affiliates - Contact Us - PS3 Downloads - Privacy Statement - Site Rules - Top - © 2014 PlayStation 3 News