Sponsored Links

Sponsored Links

PSJailBreak Reverse Engineered, Requires Hardware to Update


Sponsored Links
205w ago - A few days ago PSJailBreak Reverse-Engineering work began, and today German site GamerFreax.de (linked above) has posted a breakdown of the PSJailBreak, how it was reverse engineered and notes that it requires additional hardware to update.

Below is the rough translation of the PS JailBreak reverse-engineering details, to quote:

"We have the PSJailbreak dongle yet again brought out of retirement to put it more precisely Herbs to take a closer look. We tell you here in brief the main steps of the internal process of PSJailbreak.

We can confirm that it can not confirm that PSJailbreak a clone of Sony's "Jig" is module. PSJailbrak is an exploit honest self-developed. The chip is not but a PIC18F444 ATMega with software USB.

This means the chip is internally capable of USB to emulate. PSJailbreak mainly be emulated 6Port a USB hub connected to a specific end USB devices and then disconnected. One of these devices has the ID of Sony's "Jig" module, which means that played in the development of PSJailbreaks the "Jig" module, a certain role.

But let's start at the front: When the PS3 is clamped in the USB emulation device, which has a much too big Configuration Descriptor. This Descriptor ├╝berschriebt the stack with a PowerPC contained code that is executed. Now, various USB devices are connected in the emulation. A device has a large 0xAD Descriptor, which is part of the exploit and contains static data.

A short time later (we are moving here in Milisekundenbereich) the jig module is connected, and encrypted data are transmitted to the module jig. A (in Milisekundenbereich) eternity later, the answers Jig 64Byte module with static data, all USB devices are disconnected, a new USB device is connected and the PS3 launches with a new look.

64Byte static data that is emulated by the PS3 64Byte Jig sent to the static data that is emulated by Jig sent to the PS3

Extract from the USB stream Extract from the USB stream (pictured below).

Incidentally PSJailbreak is NOT updateable. The Update feature can be mentioned, if realized at all, only with additional hardware."





Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 73 Comments - Go to Forum Thread »

• Please Register at PS3News.com or Login to make comments on Site News articles. Thanks!

xantra's Avatar
#58 - xantra - 205w ago
You need to add a pair of Zeners to protect the USB (the D+ / D- use 3,3V!) or run the uC from limited voltage.

Also, the D- should be pulled UP (Vcc) instead of down (GND). And never use capacitor on data lines!
All right, but what is the components 'E', 'F', 'G', 'H', 'I' and 'J'. 'I' can be the pull up. 'J' can be a capa.

The microcontroller really doesn't matter, all we need is the "how" it works and the "what" it does. *ANY* advanced enough device with a usb port can be used as a replacement to the microcontroller.. after all, the chip isn't anything special in hardware, and it doesn't have any USB/hack specific hardware components, it's all just a USB software emulation that does specific things... we can replicate this into a small linux kernel driver and use our phones (N900 or Android phones) or maybe even a PC/laptop and make it do the same thing.
Yes but with the ref of the Á you can try to dump the memory with the JTAG port for exemple.

kakarotoks's Avatar
#57 - kakarotoks - 205w ago
The microcontroller really doesn't matter, all we need is the "how" it works and the "what" it does. *ANY* advanced enough device with a usb port can be used as a replacement to the microcontroller.. after all, the chip isn't anything special in hardware, and it doesn't have any USB/hack specific hardware components, it's all just a USB software emulation that does specific things... we can replicate this into a small linux kernel driver and use our phones (N900 or Android phones) or maybe even a PC/laptop and make it do the same thing.

CodeKiller's Avatar
#56 - CodeKiller - 205w ago
The microcontrolleur can be a ATmega164PA. I have made a schematic and a typon.

Just confirm the connection of the D+ after the resistor, and the value of resistors and capasitors.
You need to add a pair of Zeners to protect the USB (the D+ / D- use 3,3V!) or run the uC from limited voltage.

Also, the D- should be pulled UP (Vcc) instead of down (GND). And never use capacitor on data lines!

xantra's Avatar
#55 - xantra - 205w ago
The microcontrolleur can be a ATmega164PA. I have made a schematic and a typon.

Just confirm the connection of the D+ after the resistor, and the value of resistors and capasitors.

xantra's Avatar
#54 - xantra - 205w ago
Before work on a snif of the usb, we can identify the Á, and try to get a dump of the memory.

Sponsored Links

Sponsored Links
Sponsored Links

Sponsored Links







Affiliates - Contact Us - PS3 Downloads - Privacy Statement - Site Rules - Top - © 2014 PlayStation 3 News