• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

PS3 SCETool v0.2.5 by Naehrwert Out, Uses Metadata for Decryption

Category: PS3 Hacks & JailBreak  By: PS3 News - (twitter.com)
Tags: ps3 scetool naehrwert ps3 metadata ps3 decryption ps3 hax ps3hax ps3 hacks

61w ago - Following up on his previous revision, today PlayStation 3 developer naehrwert has updated PS3 SCETool v0.2.5 which utilizes metadata information for decryption among the changes outlined below.

Download: PS3 SCETool v0.2.5 / ZLib1.dll File (Required)

scetool 0.2.5 public build (C) 2011-2012 by naehrwert

Setup:

  • /data/keys : Keyfile.
  • /data/ldr_curves : Loader curves (7744 bytes).
  • /data/vsh_curves : VSH curves (360 bytes).

Keyfile format:

 [keyname]
 type={SELF, RVK, PKG, SPP, OTHER}
 revision={00, ..., 18, 8000}
 version={..., 0001000000000000, ...}
 self_type={LV0, LV1, LV2, APP, ISO, LDR, UNK_7, NPDRM}
 key=...
 erk=...
 riv=...
 pub=...
 priv=...
 ctype=...
Keyset example:

 [metldr]
 type=SELF
 revision=00
 self_type=LDR
 erk=0000000000000000000000000000000000000000000000000000000000000000
 riv=00000000000000000000000000000000
 pub=00000000000000000000000000000000000000000000000000000000000000000000000000000000
 priv=000000000000000000000000000000000000000000
 ctype=00
NPDRM key(set) names:

  • [NP_tid]: Title ID OMAC1 key.
  • [NP_ci]: Control info OMAC1 key.
  • [NP_klic_free]: Free klicensee.
  • [NP_klic_key]: Klicensee key.
  • [NP_sig]: Footer signature ECDSA keyset.

Help text:

 USAGE: scetool [options] command
 COMMANDS           Parameters       Explanation
  -h, --help                         Print this help.
  -k, --print-keys                   List keys.
  -i, --print-infos file_in          Print SCE file info.
  -d, --decrypt     file_in file_out Decrypt/dump SCE file.
  -e, --encrypt     file_in file_out Encrypt/create SCE file.
 OPTIONS                Possible Values       Explanation
  -v, --verbose                               Enable verbose output.
  -r, --raw                                   Enable raw value output.
  -0, --sce-type        SELF/RVK/PKG/SPP      SCE File Type
  -1, --compress-data   TRUE/FALSE(default)   Whether to compress data or not.
  -2, --key-revision    e.g. 00,01,...,0A,... Key Revision
  -m, --meta-info                             Use provided meta info to decrypt.
  -3, --self-auth-id    e.g. 1010000001000003 Auth ID
  -4, --self-vendor-id  e.g. 01000002         Vendor ID
  -5, --self-type       LV0/LV1/LV2/APP/ISO/
                        LDR/NPDRM             SELF Type
  -6, --self-fw-version e.g. 0003004100000000 Firmware Version
  -7, --self-add-shdrs  TRUE(default)/FALSE   Whether to add ELF shdrs or not.
  -8, --self-ctrl-flags                       Override control flags.
  -9, --self-cap-flags                        Override capability flags.
  -b, --np-license-type FREE                  License Type
  -c, --np-app-type     SPRX/EXEC/UPDATE      App Type
  -f, --np-content-id                         Content ID
  -g, --np-real-fname   e.g. EBOOT.BIN        Real Filename
  -j, --np-add-sig      TRUE/FALSE(default)   Whether to add a NP sig. or not.
History:

Version 0.2.5:

  • Added option to use provided metadata info for decryption.
  • "PS3" path environment variable will now be searched for keys/ldr_curves/vsh_curves too.
    Version 0.2.4:
  • Added option to display raw values.
  • Moved factory Auth-IDs to (as they are on ps3devwiki now).

Version 0.2.2:

  • Added options to override control/capability flags (32 bytes each).
  • Fixed where a false keyset would crash scetool when decrypting a file.
  • Some source level changes and optimizations.

Version 0.2.1:

  • zlib is required to use scetool.
  • 'sdk_type' was changed to 'revision' in data/keys.

Greetings to: you know who you are!




Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 211 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
xrayglasses's Avatar
#46 - xrayglasses - 35w ago
Reply
again.. it can write HTAB entries..

One you get a stable execution (hint ROP) you can glitch HTAB entries and do anything except persistent root because bootldr couldn't even be figured out by fa1loverflow team..

If you're looking for a lv1 exploit you'll never get anywhere unless you get a talented RE person with a lot of time, and since it's obvious Linux means less than piracy is PS3 scene that isn't likely to happen..

Tidusnake666's Avatar
#45 - Tidusnake666 - 35w ago
Reply
stack overflow... so 199X-th.... but still works!! Haha!

I still prefer to use 0xFACEBOOC instead of 0xABADCAFE lol

technodon's Avatar
#44 - technodon - 35w ago
Reply
basically a payload like the one used in the 3.41 jailbreak (hermes) is loaded into stack overflow when the ps3 tries to read this the payload is loaded into memory and you get unsigned code execution. but the problem is that ps3 is using the stack and it copies something to it instead of reading first.

so the payload which has been loaded there is being over written before it has been read and is deleted so if you could somehow make the ps3 read from stack or load the payload just before the stack gets read the payload would be loaded and you have a new jailbreak.

JOshISPoser's Avatar
#43 - JOshISPoser - 35w ago
Reply
i'm understanding it a bit more. the higher the lvl, the more security breaches needed because it'll allow it to be more open?

CJPC's Avatar
#42 - CJPC - 35w ago
Reply
Generally, assuming that there is already a user mode exploit (think an exploit in a game), using this exploit will allow you to elevate permission to kernel level. The simplest way to think about it is the PSP exploits, and how multiple exploits were needed. Generally, of course!

Page 34 of 43 «‹3233343536›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• Guide to Install multiMAN PS3 Themes via USB from a PKG File
• Simple PS3Updates v1.6 Build 2 Final PS3 Homebrew App Updated
• Video: Super Pixel Jumper v1.2 PS3 Homebrew Game is Released
• Video: Pointman: The Akkadian Wars PS3 Homebrew Game Arrives
• PSPMinis / PS3Minis / Bite v1.5.1 Update for PS3 is Now Released
• PS3 Fan Control Utility v1.7 for PS3 CFW CEX 3.41 to 4.41 Arrives
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
Introductions: Hello Everyone, I'm New at PS3News.com! - 1h ago

xvir's Avatar
Quote hope to find something usefull here .. hello ...
By xvir with
 7038 Comments »
Call Of Duty: Black Ops 2 Game Spoofer for PS3 3.55 CFW Out - 1h ago

pakistanos's Avatar
Quote UPDATE I DOWN GRADE MY GAME TO 1.04 AND AGAIN BLACK SCREEN :/ I have rogero 4.41 REBUG and my game is BLES01717...
By pakistanos with
 20 Comments »
Introductions: Hello Everyone, I'm New at PS3News.com! - 1h ago

guy960915's Avatar
Quote thanjks...
By guy960915 with
 7038 Comments »
What Are You Most Looking Forward To? - 2h ago

noobtube's Avatar
Quote How quick it can be hacked ...
By noobtube with
 1 Comment »

Latest PlayStation 3 Trophies
Move Street Cricket II: Ace of all trades
Move Street Cricket II: Veteran
Move Street Cricket II: 5 Star
Move Street Cricket II: Velcro Hands

Latest PlayStation Vita Trophies
Men's Room Mayhem: Toilet Trouble
Men's Room Mayhem: Mayhem Master
Men's Room Mayhem: Hygiene Award
Men's Room Mayhem: Sand in the Face

Latest PlayStation 3 Releases
Kamen Rider Battride War Premium TV Sound Edition JPN PS3-HR - 05-24-2013
Tom Clancys H A W X EUR PS3-Googlecus - 05-23-2013
Terraria JPN PS3-HR - 05-23-2013
Kamen Rider Battlide War JPN PS3-Caravan - 05-21-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-19-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News