• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

Video: OpenCobra Cobra USB Dongle PS3 Payload by Oct0xor Demo

Category: PS3 Hacks & JailBreak  By: PS3 News - (twitter.com)
Tags: video opencobra cobra usb dongle payload oct0xor cobra dongle cobra dongle hacked

22w ago - Following up on the PS3UserCheat and True Blue unnecessary DRM-infected dongles being hacked alongside zadow28's work, today PlayStation 3 developer oct0xor shared a video of his OpenCobra Payload which aims to render the current Cobra USB dongle from Max Louarn useless.

Below are the details from his blog, as follows: "First I am going to say that this is not going to be an article, just a first blog post and some info about my recent project.

Finally I got my hands on cobra it was quite a lot of time since I touched this last time. There was s good things happened since then eg. I reverse engineered usercheat and true blue, had done a lot ps3 and not ps3 related hacking. There was a bad things eg. BlueDiskCFW, lv0 leak, a lot of devs leave the scene...

Cobra was for me really "the last" thing I have to do.

The last time when I worked on this I didnt had a dongle, and all what I had was a dump by JaiCraB. I reverse engineered it as much as possible, figure out almost all tricks, encrypton and etc. And figuare out that it reads a lot of data from dongle, and I cant do much without dongle itself. Thats why I put this project to the back burner.

Well... I had never buyed anyone dongle, and I never was not going to. All my dongles was donated (thanks again ) but not that time.

it was hard for me to make this decision but a few days ago cobra finally shipped to me...

3 days and now its all over.

Security is good enough, but not without big security risks. But it still the best crypto/obfuscation what I had seen on ps3. Sony have something to learn from this guys, especially now.

Cobra / True Blue almost identical, have the same source code, if you ever hacked 1 thing, 2nd wouldnt be a problem. The main functionality, honestly, not changed since original jb. Thats a shame. Thats why I cracking them like nuts





On the fourth day I taked a decision to make my own "OpenCobra" payload. only clean code without drm and garbage, to be able to port it to any new firmware, and change/add features. It taked 2 days, 3000 lines of asm, and you had seen the result.

Atm it based on 4.1 payload, plans for future is check/add new features from 4.4/5.0. Port to a new firmware (if cobra will not do this for me), and realize all nice innovations from new version of psp emu, such as better emu accuracy, 3D and etc...

In video you had seen Payload Loader. Thats the all code it has:

install_payload("OpenCobra_41.bin", PAYLOAD_OFFSET); // no comments
 
// install hooks
...
 
void sc8_0x9001(const char *path, const char *id) {
 
lv2syscall8(8, 0x9001, (u64)path, (u64)id, 0, 0, 0, 0, 0);
 
}
 
void sc8_0x9002(u8 flag1, u8 flag2, u8 flag3, u8 flag4) {
 
lv2syscall8(8, 0x9002, flag1, flag2, flag3, flag4, 0, 0, 0); // flag1 - eboot.bin encrypted/decrypted, flag2, flag3, flag4 - not real flags, its a tag related patch.
 
}
 
const char *path = "/dev_usb000/PSPISO/CRISIS CORE -FINAL FANTASY VII-.iso";
 
const char *id = "ULUS-10336";
 
sc8_0x9001(path, id);
 
sc8_0x9002(0, 0, 0, 0);
This tag related patches handled by mngr. So far I want to move it in payload. First I have to check how it handled in 4.4 / 5.0

Not sure yet when it will be released, if it will be, but we will see.

Keys!

LV2:
7174e18ad8c87a31.... 3.0
2005d05b1ac8a331.... 4.0
3902a14001cd4836.... 4.4
fd905abf25cdc236.... 5.0

APP:
3CFE6288B199F90A.... 3.0
5824D034A3CEED3A.... 4.0
8FA23E557693D4FE.... 4.1
If this subject will be interested for people, maybe I will write a full article about True Blue / Cobra analysis and hacking.

btw: Me and ~ some psp mysterious dark figure ~ reverse engineered algo for generating valid psp isos back to jule. But saves and a lot of games dont work without patching. So cobra's patched emu much better there imho."

Below are some additional pics from his blog which simply states: Usercheat + Cobra = <3

From flat_z: Here is some explanations to make things more clearer. If you read my twit about ps2_netemu you can see that I reverse-engineered it. It includes almost all things which are required to make custom disc images of original PS2 discs and run them on the PS3 if everything will works fine. So it can lead us to the process of remastering PS2 discs which includes making of ISO.BIN.ENC (the encrypted version of original image which can be read by the PS3), creation and encryption of .VME files (virtual memory cards), ISO.BIN.EDAT (includes the title ID of disc).

The only thing which is not currently known is the format of decrypted CONFIG file (I can decrypt the file and encrypt it back but it have a complex format). It is optional and can be empty but I'm afraid that some games requires it to run on the PS3. My plan was the creation of PS2 remastering tool and I wanted to share it. Although I even not sure will it work or no but there are many chances that it will.

But something happened before I started to do it. My HDD on the laptop died and I have all information regarding PS3 on it. Although I was able to restore some important files but not all. So I need a time to buy components for a new computer and build it. For the same reason, I have a delay on my real job (I'm working as a free-lancer) so I will going to do my job before I start to do something new for PS3.

P.S. I see many questions about compatibility. You don't need a backward compatible PS3 console to run PS2 games through ps2_netemu because it is software emulator and doesn't require any PS2 hardware components. Also I think that ps2_netemu is more better and stable than ps2_softemu but this statement requires testing.

Finally, from naehrwert (via twitter.com/naehrwert) comes some related Cobra ODE EID0 information (ECDSA from pastie.org/6169158) , as follows:

/*
* Copyright (c) 2012-2013 by naehrwert
* This file is released under the GPLv2.
*/

#include <stdio.h>

#include "types.h"
#include "sha1.h"
#include "ecdsa.h"

/*! EID0 section entry. */
typedef struct _section
{
	u8 data[0x38];
	u8 R[0x14];
	u8 S[0x14];
	u8 pub[0x28];
	u8 unk[0x20];
	u8 omac[0x10];
	u8 padding[0x08];
} section_t;

/*! ECDSA curve. */
typedef struct _curve
{
	u8 p[20];
	u8 a[20];
	u8 b[20];
	u8 N[21];
	u8 Gx[20];
	u8 Gy[20];
} curve_t;

/*! EID0 Section 0 - 1. */
u8 section0_1[0xC0] = {
	//Paste a decrypted EID0 section 0 here.
};

/*! EID0 Section 0 - 2. */
u8 section0_2[0xC0] = {
	//Paste a different (!) decrypted EID0 section 0 here.
};

/*! One sexy curve. */
u8 curve0[0x79] = {
	//SHA1: https://twitter.com/naehrwert/status/286745714434899968
	//(9035B33F58DFAEF389FD49187F93C4FC2D2DD268)
};

/*!
* \brief Hexdump, dummy.
*/
void _hexdump(const char *name, u32 offset, u8 *buf, int len, int print_addr)
{
	int i, j, align = strlen(name) + 1;

	printf("%s ", name);
	if(print_addr)
		printf("%08X: ", offset);
	for(i = 0; i < len; i++)
	{
		if(i % 16 == 0 && i != 0)
		{
			printf("\n");
			for(j = 0; j < align; j++)
				putchar(' ');
			if(print_addr)
				printf("%08X: ", offset + i);
		}
		printf("%02X ", buf[i]);
	}
	printf("\n");
}

/*!
* \brief Dump section info.
* \param name Name.
* \param s Section.
*/
void dump_section(const char *name, section_t *s)
{
	printf("Section%s:\n", name);
	_hexdump(" DATA     ", 0x00, s->data, 0x38, 1);
	_hexdump(" ECDSA R  ", 0x38, s->R, 0x14, 1);
	_hexdump(" ECDSA S  ", 0x4C, s->S, 0x14, 1);
	_hexdump(" ECDSA PUB", 0x60, s->pub, 0x28, 1);
	_hexdump(" UNK      ", 0x88, s->unk, 0x20, 1);
	_hexdump(" OMAC     ", 0xA8, s->omac, 0x10, 1);
	_hexdump(" PADDING  ", 0xB8, s->padding, 0x08, 1);
	printf("\n");
}

/*!
* \brief Verify section.
* \param s Section.
* \param c Curve.
* \return Verify result.
*/
int verify_section(section_t *s, curve_t *c)
{
	u8 hash[0x14];
	u8 _R[21] = {0}, _S[21] = {0};

	memcpy(_R + 1, s->R, 20);
	memcpy(_S + 1, s->S, 20);

	sha1(s->data, 0x38, hash);
	ecdsa_set_curve(c->p, c->a, c->b, c->N, c->Gx, c->Gy);
	ecdsa_set_pub(s->pub);
	return ecdsa_verify(hash, _R, _S);
}

//Maybe you're lucky?!
int main()
{
	dump_section("0_1", (section_t *)section0_1);
	dump_section("0_2", (section_t *)section0_2);
	printf("sig. 1 verified: %s\n", verify_section((section_t *)section0_1, (curve_t *)curve0) ? "yay" : "nay");
	printf("sig. 2 verified: %s\n", verify_section((section_t *)section0_2, (curve_t *)curve0) ? "yay" : "nay");
	printf("R_1 == R_2: %s\n", memcmp(((section_t *)section0_1)->R, ((section_t *)section0_2)->R, 0x14) ? "nay " : "yay ");
	getchar();
	return 0;
}
While this is definitely interesting news, odds are it's just a ploy for the Cobra Team to release a new dongle that will be 'required' for their upcoming PS3 4.3x CFW unfortunately or the PS3 ODE in order to further line their pockets with PlayStation 3 sceners' hard-earned cash once again... as always, time will tell for sure.








Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 547 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
condorstrike's Avatar
#107 - condorstrike - 77w ago
Reply
Thanks Boss, this is nice update for Cobra users... and specially good for themers.

PS3 News's Avatar
#106 - PS3 News - 77w ago
Reply
Here are some mmCM (multiMAN Cobra Manager) updates Condorstrike let us know about for those who own the Cobra dongle. To quote from http://www.tortuga-cove.com/forums/viewtopic.php?f=77&t=668#p1852:

Download: http://www.multiupload.com/79ZRUJTQB1 / http://www.multiupload.com/U192JAC6OY / http://www.multiupload.com/79947BK81L

Changelogs:

mmCM v3.00.02 Changelog:

• Fixed loading of PSP ISO files when no disc is inserted
• Added option "Detect Game Title in ISO Images" to allow using ISO filenames and *not* scan for game names in local database
• Improved scanning for retro roms/iso and covers (populating the Retro column)
• Support for ICON0.PNG for PSP ISO in Retro column
• Support for cover art for PS2 ISO/CUE+BIN in Retro column
• Support for cover art for PSX CUE+BIN in Retro column and for PSX discs

mmCM 03.00.03 with Theme Packer Changelog:

• New THEME format (.thm). One theme - one file. Easy installation within mmCM without going to XMB to install theme pkg files.
• mmTM - Easy to use PC application to create thm files from folders (separate download).
• mmCM will try to read disc volume labels and display in VIDEO column (BD/DVD entry) and in other display modes.
• ISO images created from such discs (BD/DVD/AVCHD) will get the disc volume label as file name for the ISO.
• Fixed extracting ICON0.PNG from PSP ISO images saved on external USB drives
• Added indication (rotating refresh icon next to the column icon) when mmCM is loading/extracting title thumbnails (XMMB mode)
• Added support for PSX/PS2/PSP covers when browsing drives/folders in Retro column

Beginner's mmCM Theme Packer guide:

1) Modify/Create Images (refer to the images in the ORIGINAL MMCM THEME folder)

2) When you're done, drag & drop your theme folder to mmTM.exe (name the folder properly - the theme will get the same name in mmCM when installed)

3) You will get a ".thm" file - transfer it to your PS3 in /dev_hdd0/game/BLES80608/themes folder and test it (activate the theme in mmCM column -> Themes)

vacano's Avatar
#105 - vacano - 77w ago
Reply
he deserves it, and i think that's why we haven't really hear from him..

Hey dean how about MULTICOBRA USB.

quotejoss's Avatar
#104 - quotejoss - 77w ago
Reply
Well i hope cobra throws a little cash deans way.

PS3 News's Avatar
#103 - PS3 News - 77w ago
Reply
He used to be called deanrr here so some people still use that name... for the most part he's known as deank though. Also, he replied stating the following, so it appears condorstrike was correct and he's fine with Cobra using it, etc for those following:

Quote I'm actually glad that for the first time I see a clone/fork of multiMAN which has things and features ADDED. I've witnessed 4 or 5 releases of multiMAN, compiled by various users or sites, castrated and barely recognizable, renamed and published as 'original work' (there was no drama there, right?!), but this time some users get a better version, although limited to cobra dongle users. As I see it, the new stuff in mmCM is about cobra and it is nice that someone picked up on the 'garbage source-code' (as many qualified it numerous times few months ago), and managed to add useful features to it.

I don't care who uses mm's source, so just stop the drama. The license says 'you can do whatever you want with it' and it doesn't require that you include the modified source or anything. Check your English skills and re-read it. It requires that the redistributed package/version includes the license and it does - there is a ./usrdir/sys/LICENSE file in their distribution.

As I see it - cobra usb users got a new option and that's good - I like that now they can enjoy a multiMAN clone. Actually I feel kind of good that mm will reach more people. As for the mm 02.09.02 being the latest (not last) multiMAN version - well if I find something new to add - I'll add it. I spent a year adding stuff and features and it looks good to me as it is now. If I find time - I'll add more. If you find time to add something useful - add it - the source was there for 7 months and no one cared about that.

However, not all PS3 developers think he's on the level... some feel despite telling the public otherwise he's still on Cobra's payroll it appears: twitter.com/#!/CrashSerious/status/156446073739673600

CrashSerious: Huge thanks to deank for leaving the scene and selling out to Cobra

Page 89 of 110 «‹8788899091›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• Simple PS3Updates v1.6 Build 2 Final PS3 Homebrew App Updated
• Video: Super Pixel Jumper v1.2 PS3 Homebrew Game is Released
• Video: Pointman: The Akkadian Wars PS3 Homebrew Game Arrives
• PSPMinis / PS3Minis / Bite v1.5.1 Update for PS3 is Now Released
• PS3 Fan Control Utility v1.7 for PS3 CFW CEX 3.41 to 4.41 Arrives
• PSPMinis / PS3Minis / Bite v1.5 for PS3 with PSP Homebrew Support
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
Sony India Leaks Rumored PlayStation 4 / PS4 250 GB Retail Pricing - 35m ago

PS3 News's Avatar
Quote Today GamingBolt.com (linked above) reports that Sony India's Web site has apparently leaked the rumored PlayStation 4 / PS4 250 GB SKU retail pricing...
By PS3 News with
 0 Comments »
PSN Games Decrypted for PS3 Custom Firmware 3.55 by DUPLEX! - 49m ago

PS3 News's Avatar
Quote I have now fixed the link in his post here: http://www.ps3news.com/forums/ps3-cfw-mfw/psn-games-decrypted-ps3-custom-firmware-3-55-duplex-121017-816...
By PS3 News with
 8165 Comments »
Video: XBox One Next-Generation Console Unveiled by Microsoft - 2h ago

PS3 News's Avatar
Quote Here are a few XBox One internal pics as well (via wired.com/gadgetlab/2013/05/xbox-one-development-photos/#slideid-138509). I will add more below as ...
By PS3 News with
 1 Comment »
Video: Men's Room Mayhem Queues Up on PlayStation Vita Today - 2h ago

StanSmith's Avatar
Quote Doesn't sounds like the sort of game I would find fun. Who wants to clean piss for a game? People don't want to do it for a job so why would a game of...
By StanSmith with
 1 Comment »

Latest PlayStation 3 Trophies
Ratchet: Deadlocked HD: Gut Wrencher
Ratchet: Deadlocked HD: Landstalker Talkin'
Ratchet: Deadlocked HD: Death From Above
Ratchet: Deadlocked HD: Spotless

Latest PlayStation Vita Trophies
Men's Room Mayhem: Toilet Trouble
Men's Room Mayhem: Mayhem Master
Men's Room Mayhem: Hygiene Award
Men's Room Mayhem: Sand in the Face

Latest PlayStation 3 Releases
Kamen Rider Battlide War JPN PS3-Caravan - 05-21-2013
Resident Evil Revelations PS3-ANTiDOTE - 05-19-2013
Muvluv Alternative Total Eclipse JPN PS3-HR - 05-17-2013
Skate 2 EUR PS3-Googlecus - 05-16-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-19-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News