Sponsored Links

Sponsored Links

PS3 SCETool, Friday Isolated SPU POC and EIDTool WIP Updates


Sponsored Links
138w ago - This weekend Sony PlayStation 3 hacker naehrwert has released a PS3 SCETool based on the fail0verflow tools, an Isolated SPU binary POC dubbed Friday and some EIDTool work in progress updates for PlayStation 3 developers interested in remarrying Blu-ray drives, motherboard keys, QA tokens, etc via [Register or Login to view links].

Download: [Register or Login to view links] / [Register or Login to view links] / PS3 SCETool v0.0.3 and VSH.Self Output / [Register or Login to view links]

Below are the details from the ReadMe files and Tweets, as follows:

SCETool (C) 2011 by naehrwert - This tool will see more features in the future.

Notice: THIS CAN DO NOTHING NEW, IT'S CURRENTLY JUST A REWRITE OF f0f TOOLS.

Keyfile format:

A sample keyfile is included.

Shout-outs: I think they know who I mean

Friday (C) 2011 by naehrwert - This is a POC for a isolated spu binary. Generate a self encrypted+signed with the metldr keys out of friday.elf. Then use friday.h to write a PPU application that loads the self by utilizing metldr and DMAs your console's EID2 to the shared SPU LS. It will generate the P and S block from it, that is used to pair the BD drive to the specific console. Yon can then DMA the blocks out from the LS and send them to the drive to remarry it to the console.

Communication with the SPU is done over in_mbox and out_mbox. MSG_OUT_* is send from the SPU code to out_mbox. MSG_IN_* should be written from the PPU to in_mbox. When MSG_OUT_READY arrives the PPU should DMA the EID2 to EID2_START and send MSG_IN_READY. When MSG_OUT_GEN_DONE arrives the PPU should DMA the blocks out from BLOCKS_START and send MSG_IN_DIE.

Note: this is UNTESTED but should just work

POC [Register or Login to view links]

note: self part is only for spu yet!

scetool [Register or Login to view links]

veeeery nice [Register or Login to view links]

[Register or Login to view links]


which I can generate and yes my eid4 passes the hash check

but one would need to get the aes_omac1 key to be able to check it

hmm eid4 digest is stored unencrypted

seems like there are some hardcoded eid4 fallback bytes - [Register or Login to view links]

scetool/eidtool progress is great




Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 234 Comments - Go to Forum Thread »

• Please Register at PS3News.com or Login to make comments on Site News articles. Thanks!

elser1's Avatar
#49 - elser1 - 91w ago
great news but wheres the 4.30 cfw. that be the one we want!

Please upload to mediafire or some thing that works without all the garbage that goes along. so sick of trying to download and need this livid crap etc, mediafire is best. should be the only one allowed i think!

PS3 News's Avatar
#48 - PS3 News - 91w ago
Following up on the previous update by Naehrwert and yesterday's PS3 LV0 Keys leak, today Chinese developer Rain fish (aka JjKkYu) has released a 4.21 EBOOT Resigner PS3 SCETool (aka TrueAncestor EBOOT Resigner) script which allows the resigning of 3.55 or decrypted EBOOT.BIN files for use with PlayStation 3 4.21 CFW.

Download: [Register or Login to view links] / [Register or Login to view links] (Mirror) / [Register or Login to view links] (Mirror #2) / [Register or Login to view links] (Mirror #3) / [Register or Login to view links] / [Register or Login to view links] by haz367

To quote, roughly translated: Update: I renamed my resigner to TrueAncestor EBOOT Resigner and add DEX support. Enjoy.

This is a script of SCETool to resign the 3.55- or decrypted EBOOT.BIN for 4.21CFW use.

Tutorial:

1. Extract the 4.21 EBOOT Resigner.zip.
2. Put EBOOT.BIN into the extracted folder.
3. Run resigner.bat to resign EBOOT, you may need to choose encrypt type.
4. If you chose NPDRM type, you need to enter Content-ID.
5. The original EBOOT.BIN will be renamed to EBOOT.BIN.BAK.

This script is tested on BD4.21 CFW, and it should work on Rogero 4.21. Some game also contains decrypted self or sprx file, you need to resign them manually.

Credit to badzbb.

Note: This script uses 3.60 keys to encrypt the EBOOT, no new keys.

TrueAncestor EBOOT Resigner Oldschool 3.55 Resign Added by haz367:

All credits to JjKkYu, badzbb, aldostools, Asure and everybody else... added 2 more options to it for 3.55 users:

5. Disc t/m 3.7X Backup EBOOT Auto-resign (Oldschool 3.55 CFW)
6. NPDRM Game/Update t/m 3.6X EBOOT Auto-resign (Oldshcool 3.55 CFW)

Only add the "keys" file to it.

From danixleet comes some PS3 homebrew ports as follows: 4.XX CFW Homebrew (In theory these should all work on OFW 3.6+)






From Condorstrike also comes Solar 4.2 for CFW 3.55-4.XX and PS3LoadX_4.XX for 4.XX CFW with details on the latter below:

Here's an updated and repacked PS3LoadX for 4.xx CFW’s, did some minor code cleanup, and bug removal, also reduced application size and replaced the loading method. Also replaced ICON0 and PIC1 for better aesthetics. Enjoy...

  • Repacked for use with 4.xx CFWs.
  • Replaced loading method.
  • Fixed minor bug with Temporary Folder.

Features:

  • You can load SELF files using the net.
  • You can load applications from USB/ HDD devices
  • You can install applications to the USB or HDD devices from one .zip file
  • You can copy applications from USB devices to HDD
  • Also you can delete installed applications.

Installing and launching programs and .zip files:

  • You can load .ZIP files via tcp using the network, just like the SELFs.
  • An “install” folder will be built into your [USB/HDD root: Homebrew] Folder and contents shadow copied to PSL145310/homebrew/install.
  • The “install” folder can be added manually as-well, if no network loading is to be used.
  • Programs will be displayed in PS3LoadX and buttons commands will be available accordingly.

Finally, from samson: I ran windos eboot through all options in the resigner, if my guess works right you should be able to install windos final for 3.55 on 4.xx cfw's/dex and just replace the eboot. Also some should work for my other dos games/toys.

More PlayStation 3 News...

dalmatianu's Avatar
#47 - dalmatianu - 96w ago
Great news

xrayglasses's Avatar
#46 - xrayglasses - 96w ago
again.. it can write HTAB entries..

One you get a stable execution (hint ROP) you can glitch HTAB entries and do anything except persistent root because bootldr couldn't even be figured out by fa1loverflow team..

If you're looking for a lv1 exploit you'll never get anywhere unless you get a talented RE person with a lot of time, and since it's obvious Linux means less than piracy is PS3 scene that isn't likely to happen..

Tidusnake666's Avatar
#45 - Tidusnake666 - 96w ago
stack overflow... so 199X-th.... but still works!! Haha!

I still prefer to use 0xFACEBOOC instead of 0xABADCAFE lol

Sponsored Links

Sponsored Links
Sponsored Links

Sponsored Links







Affiliates - Contact Us - PS3 Downloads - Privacy Statement - Site Rules - Top - © 2014 PlayStation 3 News