116w ago - Today PS3 hacker
Mathieulh reports finding a PlayStation 3 Firmware 3.56 exploit, although he states he has no plans to give any further details about it.
To quote from PSX-Scene (linked above): Well-known hacker Mathieu Hervais has reportedly found a bug that allows exploiting metldr, the bootloader and firmware version 3.56. Unfortunately, he refuses to release it.
Originally Posted by Mathieulh (via
Twitter):
I hesitated a lot before tweeting about it, but a bug allows exploiting metldr, the bootloader and 3.56+. I don't intent to ever unveil it.
So much for "unhackable" PS3s though... I am not giving any further details about it. Sorry.
Actually the revocation list exploit doesn't allow you to exploit isoldr, you could however sign a revoke list if you had the revocation list keys and knew the sign fail, and use that to dump isoldr. Metldr does not load revocation lists.
This has been tested, how do you think I could release the lv2ldr and appldr keys ? (about 24hrs before Geohot showed up with metldr keys) This has been tested, how do you think I could release the lv2ldr and appldr keys ? (about 24hrs before Geohot showed up with metldr keys)
You can also dump any loader using a signed metadata (including metldr) though that means you need to have the keys for it in the first place (kinda kills the purpose)
Your entire purpose is to get the isolated process (the code running inside the spu) to jump to your instructions
For exemple the following instructions will dump the isolated LS to the SPU mailbox:
loop:
rdch $3, ch29
lqd $3, 0($3)
wrch ch28, $3
rotqbyi $3, $3, 4
wrch ch28, $3
rotqbyi $3, $3, 4
wrch ch28, $3
rotqbyi $3, $3, 4
wrch ch28, $3
up_one:
br loop
br up_one
Of course you'll need a ppu payload to fetch the mailbox data. Metldr is trivial to dump now that you can sign your loader, but I wont say anything more on this.
Finally the problem with isoldr and the revoke list exploit isn't so much that the exploit doesn't work (it actually does) It's that the payload from the crafted revoke list overwrites isoldr keys (which kinda kills the whole purpose), You can however get the revoke list keys from lv2ldr or appldr using the revoke list exploit and then sign a revoke list metadata to exploit isoldr later on. (There are other ways to get isoldr though, including the 3.60+ exploit I have (but there is at least another I know of) Again, good luck in your endeavor.
There is more than one npdrm key. It's not been released because the ones who have the skills to do it do not remotely care about pirating PlayStation store games (obviously).
Finally, in related PS3 homebrew news today a
PS3 FW Downloader application has been released which includes Official PS3 Firmware 2.50 - 3.55 and has Geohot, Kmeaw, Wutangraz PS3 Custom Firmware and 3.55 Downgrader support.
Doesn't matter if your work will stop an abuse of some teams. For Sony's eyes, you're using THEIR product and THEIR software (every level of them) and for this reasons, if you release something, you will be sued and called to a particular tribunal, where a funny judge will take care of ruin your life worst than if you was a drug pusher. Sony don't say thanks, neither if you save the CEO's life. You touched THEIR product, you will pay.
It's the truth, bro. And you know i'm right.
We don't sell sonys games hacked and pressed on a debug disk with there debug key. We dono use and sell a dongle with sonys drm stuff to prevent our work. We're also not releated to any release of sonys keys or what ever. We using tools, code and stuff others have written and released and this also includes work of this dev's. So what they want to do with us ?
We're not against sony, we're not against the scene, we're not against other dev's. We're against team's and dev's using sonys sys to make money with it. We're against dev's preventing those teams.
So we're not the BAD guys which upset sony. On special case WE help sony to stop those guys making money with sonys work. If you ask me sony have more reasons to sue those both teams and every dev of the scene involved into it then to sue guys like me or others.
And also we have not found something new that we push now. The theory of our ongoing work is based on them. They put the con into debugger mode to be able to let you play new games and sell this for a lot of money.
If those teams never started to sell there dongles we wouldn't never started to do the work we now do. So if some one of thoes dev's want to sue some one they should start and sue themself.
A You're not a loser nerd who need youpo for take a look to a girl
B You lost somewhere your teenager brain, the same one who make you feel a god when you complete a game on HARD MODE (I felt to be a god when i finally got my Bachelor, big difference)
C As much you're a dev, willing to help, elite group will start to threat you, with something like : "well done, you found a great exploit" "Hehe thanks. I think i'll publish it on ps3news and other major forums" "No, you don't understand how things works. You will keep it for yourself, thanks for share" "I beg your pardon? I'll release it in an hour"
"You still don't understand. We will send an email with your name and location to Sony and your life will be gone, if you try. Beware, no joke. You will do like us. Enjoy your work, play online with every game. Share it with your faithful friends. But again, if something goes leaked, we will be the first to help Sony to sue ya".
This is the real story. Kinda crap, right?
Thanks cfwprophet and nabnab, to ignore them.