33w ago - Following up on the
PS3 KLicense Brute-force Tool release, this weekend PlayStation 3 scene developer
Flat_z has made available a PS3 Disc Key Dumper, Klicensee Dumper and corresponding Data Dumper with details outlined below.
Download:
PS3 Disc Key Dumper /
PS3 Data Dumper 0 /
PS3 Klicensee Dumper /
PS3 Data Dumper
From Twitter:
Disc key dumper http://mir.cr/1YDDSN6T http://mir.cr/0R8C1JVN
Klicensee dumper http://mir.cr/AKODIFIA http://mir.cr/1BAUGCKJ
The klicensee_dumper should speed up the gathering of
klicensees. One of dumpers is an alternative to klicensee bruteforcer which released before because some klicensee keys cannot be bruteforced. Klicensee is used to resign/decrypt/encrypt self/sprx/edat.
As for the other dumper (for a disc key), I'm writing a tool to decrypt/encrypt saves and resign them for your console if you want to use a save from another console. I will release a tool soon when it will be completed.
From the included ReadMe Files:
Disc Key Dumper
Requirements:
- 3.55 CFW (e.g. Kmeaw)
- MultiMAN or original dev_blind application and FTP client
1. Install `Data Dumper` (data_dumper.pkg) if you didn't installed it before. It is a homebrew application to dump a data from some LV2 memory to a file: /dev_hdd0/tmp/dumps.bin. A data which stored there is written by dumper loaders, e.g. by Disc Key Dumper.
2. Install `Disc Key Dumper Loader` (disc_key_dumper_loader.pkg). It stores a disc key if your game is not a PSN/SEN game.
3. Reboot a console to clear a data storage in LV2 memory.
4. Now you need to start `Disc Key Dumper Loader`, then start your game.
5. After exiting from the game you need to run `Data Dumper`, you will hear some beeps.
6. Then run any FTP client (e.g. builtin in MultiMAN) and download a dumped disc key from /dev_hdd0/tmp/dumps.bin.
Klicensee Dumper
A klicensee is specified by developer of the game. Usually it is stored in EBOOT.ELF and you can find it in a disassembler or by brute forcing a key along with a NPD header. But in some cases this key is not stored in a plaintext format and can be annoying to analyze a game's executable. That's why I had created this dumper.
Requirements:
- 3.55 CFW (e.g. Kmeaw)
- MultiMAN or original dev_blind application and FTP client
1. Install `Data Dumper` (data_dumper.pkg) if you didn't installed it before. It is a homebrew application to dump a data from some LV2 memory to a file: /dev_hdd0/tmp/dumps.bin. A data which stored there is written by dumper loaders, e.g. by Klicensee Dumper.
2. Install `Klicensee Dumper Loader` (klicensee_dumper_loader.pkg). It stores a file path to self/sprx/edat and a klicensee key if it is specified.
3. Now you need to replace original `libsysutil_np.sprx`. I use a dev_blind feature from MultiMAN, you can use any other way. Don't forget to backup original file.
4. Reboot a console to clear a data storage in LV2 memory.
5. Now you need to start `Klicensee Dumper Loader`, then start your game.
6. After exiting from the game you need to run `Data Dumper`, you will hear some beeps.
7. Then run any FTP client (e.g. builtin in MultiMAN) and download dumped klicensee keys from /dev_hdd0/tmp/dumps.bin.
8. Restore an original `libsysutil_np.sprx` using the same method as at step 3.
Data Dumper
Requirements:
- 3.55 CFW (e.g. Kmeaw)
- MultiMAN or original dev_blind application and FTP client
1. Install `Data Dumper` (data_dumper.pkg) if you didn't installed it before. It is a homebrew application to dump a data from some LV2 memory to a file: /dev_hdd0/tmp/dumps.bin
2. Every time you're want to dump a data from my applications (e.g. Klicensee Dumper) you're need to reboot a console to clear a data storage in LV2 memory.
3. Run a dumper loader, then start your game.
4. After exiting from the game you need to run `Data Dumper`, you will hear some beeps.
5. Then run any FTP client (e.g. builtin in MultiMAN) and download a dumped data from /dev_hdd0/tmp/dumps.bin.
The Secure File ID Dumper dumps the Secure File ID key which is the main thing you need for save decrypt/encrypting. It doesn't seem to work with some games (dark souls is still being a pain)
Klicensee dumper, of course, dumps the klicensee. It's mostly only used for decrypting the EBOOT.BIN or SELFs or SPRXs.
Basically though if you don't already know those terms, you don't need to worry about it.
only use the libsys one when doing the klic one. And make sure to back up your originals or you wont be able to switch between what you want to use at all, as far as these dumpers go.
Download: https://rapidshare.com/#!download|789p4|2414359018|dumpers_421.7z|991|0|0 / http://uploadmirrors.com/download/1AS5FBIN/dumpers_421.7z (Mirror)
To quote: Finally I was able to find the time to port my dumpers on 4.21 CFW. There were some problems while porting from 3.55 to 4.xx and hopefully all of them were fixed.
These dumpers are not required to work with previous tool called Data Ddumper because they just write all data directly to the corresponding file on /dev_hdd0/tmp. All dumpers were tested on 4.21 REX and should works fine if you do the process correctly.
Example from KDSBest in REX 4.21:
[BLES01251]
;disc_hash_key=
secure_file_id:*=0A010B020C030D040E050F0607080909
I ported XB36Harzard's XBox 360 Dishonored Save Game Editor to PS3 and modified it. His was detected as virus and I know why. Mine shouldn't get detected.
Download: http://bitshare.com/files/zj6oxi0p/Dishonored-SaveGame-Editor-by-KDSBest.rar.html
You have to use pfdtool to decrypt PAYLOAD of your Dishonored Save.
Enter the Stuff the SaveGame wants to know.
Play till you got at least 1 rune to be save.
Backup the savegame it uses a heuristic method since the positions of coins and runes are not fixed. It will warn you if it came to trouble and it backups your old PAYLOAD file.
If no warning comes (even sometimes if one comes) you should have more coins, runes and 65000 of most of the bullet types.
At the end you have to encrypt the PAYLOAD file with pfdtool again.
To the SaveGame it uses some strange modified zip algorithm to zip and unzip the save.
XB36Harzard uses offzip and packzip to manage the zip algo for him. So do I! I just ported his stuff and modified it and wrote it in C#... VB really sucks. Have fun, KDSBest
PS: If autosaves save failing press circle to cancel and normal. That works for me!
From whitezombie:
Here is FFXIII-2. I resigned a save, successfully copied, and loaded it. I don't know if it works on the US version but someone can test it. Add the following to your games.conf. I used the 3.55 version and keam to dump it from memory. Loaded it on another console with the latest Rogero.
[BLES01269]
;disc_hash_key=
secure_file_id:*=58D0ABA00D127D50B925634DF50E63E9
I recommend to use the FTP client from multiMAN to patch sprx files.
Don't forget to make backups of sprx files before patching them.
Don't use two or more dumpers at once - this will definitely not work).
More PlayStation 3 News...