• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

Graf Chokolo Decrypts OtherOS.self, PS3 Service JIG Lv2diag.self

Category: PS3 Hacks & JailBreak  By: PS3 News - (xorloser.com)
Tags: graf chokolo graf_chokolo ps3 lv2diag.self ps3 jig decrypted ps3 otheros decrypted

129w ago - A few weeks back graf_chokolo announced that he decrypted PS3 Firmware 3.50 and work on a free public PS3 Downgrader was underway, followed by a PSGroove Payload update to decrypt PKGs from PlayStation 3 PUP Files with today's update including the OtherOS.self and Lv2diag.self from a PS3 Service JIG decrypted!

Download: Decrypted Lv2diag.self from PS3 Service JIG (Teaser)

To quote via xorloser's blog, linked above, on the PS3 appldr interface reversal progress:

graf_chokolo says: Guys, i know you are waiting for the USB Dongle Master Key from me I have got now 2 fat PS3 with HV 3.15 but unfortunately no SX28 development board yet to exploit it

But i was not idle and the last and this week i was working on reversing of self decryption. And now i'm able to decrypt SELFs and SPRXs on my exploited GameOS by using HV calls only and no GameOS functions at all I reversed the interface to appldr which decrypts SELFs on GameOS 3.41.

So you won't get bored until i get the USB Dongle Master Key, i will make my findings and my source code public very soon and you will be able to decrypt your favourite games and programs by yourself :-) Let the fun begin, guys

Here is a "small" teaser of decrypted Lv2diag.self from service JIG

http://pastie.org/1333833

You cannot decrypt isolated SPUs with appldr, i think, because they are decrypted by isoldr.

I'm able to decrypt hdd_copy.self from 3.42 but not from 3.50

otheros.self decrypted



Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 51 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
PS3 News's Avatar
#46 - PS3 News - 129w ago
Reply
More graf_chokolo updates: http://xorloser.com/?p=297&cpage=9#comment-1849
Quote
Here is what my descriptor looks like:


const uint8_t PROGMEM port1_config_descriptor[] = {
0×09, 0×02, 0×12, 0×00, 0×01, 0×00, 0×00, 0×80, 0xFA, 0×09, 0×04, 0×00,
0×00, 0×00, 0xFE, 0×01, 0×02, 0×00, 0×00, 0×00, 0×00, 0×00, 0×00, 0×00,
0xFA, 0xCE, 0xB0, 0×03, 0xAA, 0xBB, 0xCC, 0xDD, 0×60, 0×00, 0×00, 0×00,

#include

———— and here paste dummy bytes ——————-

};

vsh.self and sys_init_osd.self decrypted

ps1emu*.self decrypted

ps2 emu cannot be decrypted by appldr because it’s like GameOS, it’s decrypted by lv2ldr, ps2 emu is not an application that can be run on GameOS.

Pretty all SPRX file can be decrypted now
I will just polish a bit my source code and then upload it, guys

Reversing lv2ldr interface and decrypting lv2_kernel.self is next on my list, guys

psp_emulator.self decrypted

bdp_BDMV.self

http://pastie.org/1339258

vsh.self

http://pastie.org/1339271

psp_emulator.self decrypted !!!

http://pastie.org/1339276

ps1_emu.self decrypted !!!

http://pastie.org/1339284

I will release my code today

ESID 0xA is used for dynamic memory allocation and memory mapping, so it’s ok. Every page is 0×1000. You should have several 0xA segments.

ProtectionPage has a member variable log2_size at offset 0×18 (size 1 byte). 0xC means 2^12 = 4kb

And i was wrong about VA in my first post about ProtectionPage ProtectionPage doesn’t contain VA, it’s EA and not VA. EA is converted by page table to VA.

Sorry EA is converted not by page table but by SLB I need a vacation from reversing

bdp_BDMV.self: http://www.ps3news.com/forums/attachment.php?attachmentid=26042

vsh.self: http://www.ps3news.com/forums/attachment.php?attachmentid=26060

psp_emulator.self: http://www.ps3news.com/forums/attachment.php?attachmentid=26061

ps1_emu.self: http://www.ps3news.com/forums/attachment.php?attachmentid=26062

ESWAMP's Avatar
#45 - ESWAMP - 129w ago
Reply
Originally Posted by mushy409 View Post
Quote How would they patch this exactly? From what I understand the Jailbreak dongle emulates the JIG device used to boot the system into Factory mode.

I dont believe they would go down the route of changing JIG hardware, I think they would change the response challenge in the firmware itself, then update their JIG dongles.

Sony wouldn't lock themselves out of their own consoles (obviously)... unless this is a similar incident to when they removed OtherOS support.

LOADS of people whined, Sony metaphorically slapped everyone with the excuse "We did it to protect everyone's best interests..." more like "We did it to cash in on future hardware & to ditch the freeloaders from our system (Linux Users!)..."

Who exactly is the 'Everyone'? A small group of autistic aliens that sony keep locked up for game testing & feed them on crack & sushi?

As i recall sony did so non Licensed hardware such as usb and controller do not work on the 3.50.

PS3 News's Avatar
#44 - PS3 News - 129w ago
Reply
Some more comments from graf_chokolo: http://xorloser.com/?p=297&cpage=8#comments
Quote
I can see now every syscall used by Lv2diag.self Now we can look for exploits in SELFs

Lv2diag.self uses services provided by HV processes a lot, especially Update Manager

polly316's Avatar
#43 - polly316 - 129w ago
Reply
it doesn't matter if this leads to a 350 hack 3.51 will be faster with 3.52 faster still, this is way its always flied.

Darkzero51521's Avatar
#42 - Darkzero51521 - 129w ago
Reply
Well if they updated their firmware, then updated their hardware, all they'd have to do is use their old jig devices to update to the newest firmware? If anyone sent them a broken ps3, they'd update it before fixing. That locks out hackers from updating passed a certain point, and at the same time leaves them able to fix people's ps3s who have old firmware. It'd also fix ps3s with new firmware.

Page 2 of 11 «‹123456789›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• Guide to Install multiMAN PS3 Themes via USB from a PKG File
• Simple PS3Updates v1.6 Build 2 Final PS3 Homebrew App Updated
• Video: Super Pixel Jumper v1.2 PS3 Homebrew Game is Released
• Video: Pointman: The Akkadian Wars PS3 Homebrew Game Arrives
• PSPMinis / PS3Minis / Bite v1.5.1 Update for PS3 is Now Released
• PS3 Fan Control Utility v1.7 for PS3 CFW CEX 3.41 to 4.41 Arrives
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
The Yes/No question thread - 1h ago

windrider42's Avatar
Quote No Are you Depressed?...
By windrider42 with
 2051 Comments »
Final Fantasy XIV: A Realm Reborn on PS3 8/27, Collector's Edition - 2h ago

Brenza's Avatar
Quote and now square is dead to me! ...
By Brenza with
 1 Comment »
The Yes/No question thread - 5h ago

mm4dsc's Avatar
Quote No. Are you sad?...
By mm4dsc with
 2051 Comments »
Video: The Witness on PlayStation 4 / PS4: Creator Conversations - 8h ago

PS3 News's Avatar
Quote Thekla Incorporated President Jonathan Blow shared some video footage today which include conversations with the creators of upcoming title The...
By PS3 News with
 0 Comments »

Latest PlayStation 3 Trophies
Pool Nation: Mega Shot
Pool Nation: Mega Streak
Pool Nation: Super Zen
Pool Nation: Zen

Latest PlayStation Vita Trophies
Men's Room Mayhem: Toilet Trouble
Men's Room Mayhem: Mayhem Master
Men's Room Mayhem: Hygiene Award
Men's Room Mayhem: Sand in the Face

Latest PlayStation 3 Releases
Tom Clancys H A W X EUR PS3-Googlecus - 05-23-2013
Terraria JPN PS3-HR - 05-23-2013
Kamen Rider Battlide War JPN PS3-Caravan - 05-21-2013
Fast And Furious Showdown PS3-DUPLEX - 05-21-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-19-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News