106w ago - This weekend Sony PlayStation 3 hacker naehrwert has released a PS3 SCETool based on the fail0verflow tools, an Isolated SPU binary POC dubbed Friday and some EIDTool work in progress updates for PlayStation 3 developers interested in remarrying Blu-ray drives, motherboard keys, QA tokens, etc via Twitter.
Friday (C) 2011 by naehrwert - This is a POC for a isolated spu binary. Generate a self encrypted+signed with the metldr keys out of friday.elf. Then use friday.h to write a PPU application that loads the self by utilizing metldr and DMAs your console's EID2 to the shared SPU LS. It will generate the P and S block from it, that is used to pair the BD drive to the specific console. Yon can then DMA the blocks out from the LS and send them to the drive to remarry it to the console.
Communication with the SPU is done over in_mbox and out_mbox. MSG_OUT_* is send from the SPU code to out_mbox. MSG_IN_* should be written from the PPU to in_mbox. When MSG_OUT_READY arrives the PPU should DMA the EID2 to EID2_START and send MSG_IN_READY. When MSG_OUT_GEN_DONE arrives the PPU should DMA the blocks out from BLOCKS_START and send MSG_IN_DIE.
Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!
Finally, in related PlayStation 3 hacking news pink1 has made available an R2R+Edat tool followed by a R2R+edat v1.0.1 update with details below, as follows:
Here is a tool I put together. It's pretty much rap2rif, rif2rap and an edat fix tool for C00 type demos. Put your act.dat & idps in the data folder and you're ready for rap2rif & rif2rap. To fix C00 type demos input a .pkg from a C00 demo or the PARAM.SFO and it will output the fixed .edat.
This is a small update to R2R+edat, it fixes edats being a byte short & should speed up pkg2edat a lot by only decrypting the first 5MB instead of the whole pkg. Put your act.dat & idps in the data folder and you're ready for rap2rif & rif2rap. To fix C00 type demos input a .pkg from a C00 demo or the PARAM.SFO and it will output the fixed .edat.
To quote: This tool is used to bruteforce devklic for edat files on pc. It supports bruteforcing from binary or text files. It only take minutes to bruteforce in an elf file, no more waiting for hours or days.
This tool is based on BuC's EDAT Devklic Validator, all credit to BuC.
Update to v1.1
Fix a bug while bruteforce in text file.
If you meet some issue, please feedback. Thx.
Update to v1.2
Add 2 Modes:
Short Mode: Run only 4 rounds for binary source file. This mode doesn't try all the contents from source file. But it is enough in most cases.
Line Mode: Run only 1 round for text source file. This mode reads first 32 bytes in each line as devklic. It runs extremely fast for formatted text source file.