• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

SKFU on PS3 Registry Research and PS3 USB Custom Firmware

Category: PS3 Hacks & JailBreak  By: PS3 News - (streetskaterfu.blogspot.com)
Tags: skfu ps3 registry ps3 research ps3 usb ps3 custom firmware ps3 hacks ps3 mods

141w ago - Earlier today we reported on a preliminary PS3 flash and registry entry analysis from DemonHades and RichDevX, and now SKFU (linked above) has shared his input thus far.

To quote: Since PS3News released their PS3 FTP application I did some research on the PS3's registry.

The registry and it's backup are stored on dev_flash2 as xRegistry.sys.

The header

BC AD AD BC 00 00 00 90 00 00 00 02 BC AD AD BC

The entries

Every entry has a fronttag which is 5 bytes long. I'll describe:

56 41 00 11 01

This is an example value:

/setting/parental

Behind the value theres a 1 byte close mark:

00

The 5 bytes

The first 4 bytes are a unique but random number. Every value has it to be identified and found by the system as there is no special pattern. An sprx(?) finds every value by this 4 bytes.

56 41 00 11

The 5th byte can be 00, 01 or 02. 00 tagged values are actually activated/used by the VSH, 01 ones not. The 02 seems to mean "DO NEVER UNLOCK". For example the QA Mode is tagged with 02.

00 == unlocked/used/activated
01 == locked/unused/inactive
02 == never ment to be unlocked


Stop footer

The registry has a

AA BB CC DD EE

after the last value. Here the system stops to search for values.

Single values without tag

Some values are behind the stop tag spreaded randomly in the file it seems. I have no clue how the system finds those yet but here are some I found:

- your local username
- your language (f.e. eng for english)
- your PS3 system name
- URL to the information board online stored files
- HDD serial
- Board name
- your PSN username + password
- your WIFI network key
- your local IP
- your PSID
- path to local user pic

You can modify all those values as long as you don't change its size or adress. For example the local user pic is loaded from:

/dev_flash/vsh/resource/explore/user/000.png

But you can redirect it to load from USB for example:

/dev_usb/vsh/resource/explore/user/12345.png

The Cool Stuff

The retail PS3's registry contains all values to unlock the settings which are possible on a test/debug PS3 and even more like QA mode. We can enable those via the registry, but we won't see any effect in the XMB.

That is because we just UNLOCKED it, but different files on dev_flash handle what we can actually SEE in the XMB. So we need to modify them also to fully use debug options on a retail and more.

This can be done by mounting the dev_flash from USB. We need to do this as we can not write to the original dev_flash. So once we can load our customized dev_flash from USB and have modiified our registry, we have a nice way to load a our custom firmwares.

The Crash Report

The registry can contain an crash report which is seperatly splitted with another registry header as explained above. It contains system error messages, for example if you muck up your registry ;-)

PS3 Live USB CFW Theory

While the Jailbreak just changes mountpoints it should be possible to do the same for other places than the BDD, aswell.

For the JB, the drive is remounted @ HDD. So why not mount the dev_flash from USB?

Surely this is possible and I hope to see some action here soon!

So we would have a good solution to test and run custom firmwares as the brick risk is equal zero, because we can just unplug the USB device and the dev_flash is mounted as common - unchanged.



Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 82 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
EiKii's Avatar
#72 - EiKii - 140w ago
Reply
Originally Posted by ionbladez View Post
Quote that came to mind as well, we could in theory just unpack one of the debug pkgs, using the ps3 itself with an SDK and extract required files.

however that's just a concept yet to be tested. I wish I had the tools to do it but I'd need hours upon hours to learn all those api calls and such.


how about a semi debug, one where you do the hdd swap trick, and get the menus but not working, possible to make em work by adjusting reg maybe?

ionbladez's Avatar
#71 - ionbladez - 140w ago
Reply
that came to mind as well, we could in theory just unpack one of the debug pkgs, using the ps3 itself with an SDK and extract required files.

however that's just a concept yet to be tested. I wish I had the tools to do it but I'd need hours upon hours to learn all those api calls and such.

sammaz's Avatar
#70 - sammaz - 140w ago
Reply
Originally Posted by ionbladez View Post
Quote Thought it'd be highly possible since we have registry access now, maybe copying the file over to a retail would give us those debug options ;]

however I've never had a ps3 debug/tool in my hands to know, maybe it's padded differently.

Thoughts?

Whoa... great idea... just make sure all the supporting files exist on the retail hdd.

Doesn't seem logical that the files for debug would be same on retail hdd.

ionbladez's Avatar
#69 - ionbladez - 140w ago
Reply
Thought it'd be highly possible since we have registry access now, maybe copying the file over to a retail would give us those debug options ;]

however I've never had a ps3 debug/tool in my hands to know, maybe it's padded differently.

Thoughts?

coobot's Avatar
#68 - coobot - 141w ago
Reply
Originally Posted by vandalj View Post
Quote

So yeah just because they can doesn't mean they'll be able to find anything once proper patching measures have been taken.


But it is still something that people like CJPC can hang on to if they try and make a CFW.

Page 3 of 17 «‹123456789›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• Simple PS3Updates v1.6 Build 2 Final PS3 Homebrew App Updated
• Video: Super Pixel Jumper v1.2 PS3 Homebrew Game is Released
• Video: Pointman: The Akkadian Wars PS3 Homebrew Game Arrives
• PSPMinis / PS3Minis / Bite v1.5.1 Update for PS3 is Now Released
• PS3 Fan Control Utility v1.7 for PS3 CFW CEX 3.41 to 4.41 Arrives
• PSPMinis / PS3Minis / Bite v1.5 for PS3 with PSP Homebrew Support
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
Video: PlayStation 4 / PS4: See It First on June 10th at E3 2013 - 34s ago

kalberto's Avatar
Quote it's look like thin xbox360 ...
By kalberto with
 1 Comment »
Introductions: Hello Everyone, I'm New at PS3News.com! - 2m ago

Vpony's Avatar
Quote hi all, ive been reading into your forums and have a few questions. but i guess i have to make a few posts first....
By Vpony with
 7002 Comments »
Introductions: Hello Everyone, I'm New at PS3News.com! - 39m ago

thegame123's Avatar
Quote Hi New member here. P.S.: am an absolute noob, so please bear with me....
By thegame123 with
 7002 Comments »
Sony Announces Ultimate PS3 Deal with 10 New Ultimate Editions - 2h ago

playboyj305's Avatar
Quote Hmm I might buy the ac3 ultimate edition...
By playboyj305 with
 1 Comment »

Latest PlayStation 3 Trophies
Call of Juarez: Gunslinger: Keep At It
Call of Juarez: Gunslinger: True Story
Call of Juarez: Gunslinger: Grows In The Telling
Call of Juarez: Gunslinger: Turkey Shoot

Latest PlayStation Vita Trophies
Men's Room Mayhem: Toilet Trouble
Men's Room Mayhem: Mayhem Master
Men's Room Mayhem: Hygiene Award
Men's Room Mayhem: Sand in the Face

Latest PlayStation 3 Releases
Resident Evil Revelations PS3-ANTiDOTE - 05-19-2013
Muvluv Alternative Total Eclipse JPN PS3-HR - 05-17-2013
Skate 2 EUR PS3-Googlecus - 05-16-2013
The Walking Dead A Telltale Games Series PS3-COLLATERAL - 05-15-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-19-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News