Close



Keep me logged in.

Forgot your password? | Register Now

Page 19 of 28 FirstFirst ... 9 17 18 19 20 21 ... LastLast
Results 181 to 190 of 273
  1. Original Post
    ILLUMINATUS
    *SCHAOS*'s Avatar

    Default 3.56 Firmware Encryption Keys Found! UPDATE: Possible 3.56 Downgrade!

    It seems as though PS3 Dev's KakaRoTo, Rms and Adrianc have already located the new encryption keys Sony implemented in an attempt to combat Homebrew.

    UPDATE 1 (1/26): The keys have been pushed to KaKaRoTo's git repository and are now available for download.

    Download here:

    UPDATE 2 (1/27): More Good News; It looks as though PS3 Dev Mathieulh has began work on the new FW and gives insight into downgrading back to 3.55!


    Here's a snippit of their IRC converstion:

    KaKaRoTo: nice... it's full of spkg files now .. probably a new crypted pkg format
    KaKaRoTo: possibly with a new signature that only ps3swu.self can read, but without the ecdsa fail
    KaKaRoTo: humm.. seems I was misled, there's no spkg files in 3.56
    KaKaRoTo: ok, so they added a new .self file in the PUP
    KaKaRoTo: and it seems it contains a key that we don't know about
    KaKaRoTo: yeah, probably a newer ps3swu.self that is more secure
    KaKaRoTo: but they kept the old one for people upgrading from older firmwares
    KaKaRoTo: the new ps3swu.self probably decrypts and uses the new self
    KaKaRoTo: ok, so we need new keys for everything now
    KaKaRoTo: I just pushed to ps3tools and ps3utils, fixes to allow pup/puppack/pupunpack to identify the new files in the pup
    rms: 000130e0 22 62 8a 9e c4 c4 14 d5 b3 2f 2b 4b a4 92 60 89 |"b......./+K..`.|
    rms: 000130f0 de 9a 46 1b 19 0f b3 e4 39 2d 05 7c 52 55 35 de |..F.....9-.|RU5.|
    rms: 00013100 d5 d4 b8 ed 62 b6 cc a0 24 9a 79 77 6e 13 69 75 |....b...$.ywn.iu|
    rms: 00013110 51 75 1b 9f 1d a5 86 38 d2 d9 9f 67 e2 0a 1d 4a |Qu.....8...g...J|
    rms: 00013120 45 4c 5b 04 2c d1 d0 a4 49 a2 98 98 08 00 2b a6 |EL[.,...I.....+.|
    rms: 00013130 8f b5 b7 f4 b5 b4 e6 3b 00 00 00 00 00 00 00 00 |.......;........|
    rms: try it.
    KaKaRoTo: rms, what's that blob you pasted ?
    adrianc: the new key
    KaKaRoTo: ha, cool
    KaKaRoTo: rms, if you know how and can extract all the new keys, please do and send them to me so I can upload to my ps3keys repo
    adrianc: the new keys are all in there
    rms: KaKaRoTo: i believe it's a lv2ldr key
    rms: erk/riv/pub its all in one block
    rms: i forgot the order its in though, it should be in that, its been a while
    KaKaRoTo: I don't even know how you did to find those keys
    adrianc: its in the data section of the elf usually
    rms: its really simple
    adrianc: after that look for references for blocks of data
    rms: really KaKaRoTo, i think even you could do it
    rms: adrianc: or something out of place
    adrianc: helps to compare to older versions where you already know the key position
    rms: and has a set of 8 00s
    adrianc: KaKaRoTo 3.56 key works?
    KaKaRoTo: adrianc, didn't try, not planning on trying atm
    KaKaRoTo: not until I have ~/.ps3/ files prepared for me by someone

    KaKaRoTo: lv2 3.56 decrypted
    rms: keyset?
    KaKaRoTo: pushing to github.com/kakaroto/ps3keys
    KaKaRoTo: pushed
    rms: ok
    rms lv1 is also new
    rms lv0 also
    rms and also the spu stuff apparently
    KaKaRoTo: humm.. I wonder who has the lv0 key
    adrianc: i dont think lv0 is available

    KaKaRoTo: iso keys are now pushed
    KaKaRoTo: also, now, if we want to repackage things (unless they screwed up the ecdsa *again*), we'd have to change the keys in all the loaders... which means repackaging all the *ldr and iso selfs...
    KaKaRoTo: so even more risk of bricking :tongue:
    KaKaRoTo: pushed spp keys
    KaKaRoTo: the missing keys are for 'app', 'ldr' and 'rvk'
    KaKaRoTo: btw.. where is that 'ldr' coming from ?
    KaKaRoTo: and I can't figure out who decrypts lv0
    KaKaRoTo: it can't be metldr since that one can't be changed
    KaKaRoTo: and there's no lv0ldr
    eussNL: bootldr decrypts lv0 afaik
    KaKaRoTo: there's no bootldr either
    adrianc: bootldr and lv0ldr arent in the pup
    Matt_P: not part of coreos
    Matt_P: and theres no such thing is lv0ldr
    adrianc: apparently sony removed recovery mode
    UPDATE:

    Mathieulh: Sorrowuk I suppose modchip manufacturers will start shipping nor/nand programmer soon..
    IceKiller: Mathieulh why? just get a at90 based thing
    IceKiller: i already told you about that Mathieulh :tongue:
    Mathieulh: SLC the bootchain is pwned, no matter what
    Mathieulh: you can always downgrade the coreos
    Mathieulh: 3.56 has nice new stuffs in there :P
    Mathieulh: like remote code execution upon login
    Mathieulh: I assume they probably added some syscalls for lv2 integrity checks
    Sorrowuk: Who wants to resign lv2diag.self for 3.56 so it works again ? I would do it but I dont know how to rebuild the signature after I change the authid . Some people are stuck in service mode in 3.56 :P lol
    Mathieulh: Sorrowuk you can't
    Sorrowuk: so people are stuck in service mode?
    Mathieulh: they force updaters and lv2diags to be signed with the new 3.56+ app key
    Mathieulh: and of course we don't have the private key for that
    Mathieulh: if they want to get out of service mode they have to downgrade first by reflashing the nor externally
    Sorrowuk: Sony should release a new lv2diag.self for everyone to get out of service mode. thats not very nice of them XD
    Mathieulh: btw interestingly enough
    Mathieulh: it seems the new signature check for the updater (and supposedly lv2diag) is skipped on DEX consoles
    Mathieulh: I assume that's to allow debugs to downgrade
    Sorrowuk: so if you used a nand flasher and flashed the nand of a retail with a debug nand, you would have a debug console
    IceKiller: Sorrowuk no
    IceKiller: won't work.
    Mathieulh:
    About 3.56 if the updater/lv2diag application keyset revision is lower than 0x0D, lv2 will refuse to run it.
    Mathieulh: the fail is the following anyway, decrypt your hdd cache partition /dev_hdd1 using the hdd decryption trick right after the 3.56+ updater starts (but before it updates) (just use the back switch), then replace the coreos package, with one you resigned which has 3.55 coreos but 3.56+ in info0 (or the value 0xA0 at offset 0x2C) then reencrypt the hdd partition and put the hdd back, because the
    Mathieulh: update status flag will be set, the updater will start and flash the resigned 3.55 coreos package (the fail works because they haven't changed the packages signatures, not like they can)
    Mathieulh: then you can use service mode again and flash whatever crap
    Mathieulh: doesn't work on slims cause the hdd decryption trick is fixed there
    Mathieulh: they btw can't fix it in the fat ones because it's hardware related
    Mathieulh: (encdec device)
    Mathieulh: also it's not the decryption that's the issue
    Mathieulh: appldr decrypts those selfs fine
    Mathieulh: the problem is lv2 wont run them
    Mathieulh: lv2 checks the app revision
    Mathieulh: if it's lower than 0x0D it wont run it
    Mathieulh: and of course you can't change an old one to 0x0D or higher
    Mathieulh: cause then appldr will check the signature with the new pub key
    Mathieulh: and you lack the private key
    Mathieulh: of course if anyone manages to pack a new PUP properly, then you don't need to do the hdd crypto shit to
    Mathieulh: but I haven't looked at the new pup format
    Mathieulh: rofl I am looking at the new appldr
    Mathieulh: and they hardcoded/revoked tons of new auth_ids in there
    Mathieulh: how much do you want to guess that those are the ones of the previously signed homebrews ? xD
    Mathieulh: oh ! wait
    Mathieulh: those aren't auth_id
    Mathieulh: those are hashes
    Mathieulh: 20 bytes each
    Mathieulh: sha1 considering the lenght
    Mathieulh: selfs
    Mathieulh: that has defintely something to do with why npdrm homebrews stopped working
    Mathieulh: in fact I am running the new appldr in
    Mathieulh: and it wont decrypt these demos
    Mathieulh: I mean homebrews
    Mathieulh: well you get the idea
    naehrwert: so new demos need new firmware version then, but what if they want to release a new demo and don't want to update fw?
    Mathieulh: naehrwert they just have to encrypt/sign it with new keys









    Looks like the Dev's win again. Ill try to keep this thread up to date as I find more news.
    Last edited by *SCHAOS*; 01-27-2011 at 06:18 PM.
    Register or log in to view signatures.

  2. The Following 178 Users Say Thank You to *SCHAOS* For This Useful Post:

    ---CERTIFIED--- (02-18-2011), -Skyline (01-28-2011), -Syed- (02-19-2011), 04jberry (02-26-2011), 3nduser (02-22-2011), Accurs0 (01-26-2011), adam9897 (01-28-2011), Adam™ (03-03-2011), Agent Wolf (02-18-2011), ahacker234 (02-18-2011), air6199 (02-18-2011), allant (01-28-2011), AlphaPoppy (02-13-2011), Alt (01-27-2011), Ander$on (01-27-2011), Andr3wM (01-27-2011), Asmel (02-26-2011), Axiom (01-27-2011), azhar101 (02-19-2011), Bad Luck Brian (01-28-2011), baitz4 (02-13-2011), bcb (01-27-2011), bigboybobby14 (01-28-2011), billionk (01-27-2011), Bloodstaind (01-27-2011), Bomber1614ModZ (01-27-2011), brad_ (02-26-2011), brookboy98 (01-28-2011), BuLlDoZeR_2014 (02-13-2011), Car Lover (01-27-2011), chat912 (01-30-2011), chef hou (01-27-2011), CHuRCHYx (01-27-2011), Clutch Hunterr (01-28-2011), CmDeR (01-28-2011), commander2000 (02-26-2011), Como's Hoe #1 (03-03-2011), Cooliohoolio (02-26-2011), courtjester51 (02-13-2011), cozmo195 (01-29-2011), Dan21392 (03-03-2011), DarkLiightz (02-13-2011), DaRKnEzZ- (01-28-2011), david9602 (02-18-2011), DemonPaladin (02-27-2011), DG-K95 (02-27-2011), divybc (01-28-2011), dkfallen (03-03-2011), edward20 (03-03-2011), eekndot (02-13-2011), Eggy551 (02-19-2011), egonadrian (01-26-2011), Elementt (01-27-2011), Eltrickster977 (02-28-2011), fatboyfry (01-26-2011), forumjunkie (01-28-2011), FourzerotwoFAILS (01-30-2011), frag06 (02-13-2011), Fuser's Hoe (02-19-2011), galanoth (02-14-2011), Geigers (03-03-2011), get_fukedup (02-18-2011), Grandad Trotter (01-27-2011), hacker103 (02-26-2011), Hakaan (01-28-2011), Hawkeslayer (01-27-2011), HeadHunterM7 (03-03-2011), hofpint (01-26-2011), Hx1 (02-19-2011), I Got Cookies (01-26-2011), ibombo (02-18-2011), ii-ownaged-iixx (01-27-2011), iiFaMoUzZ- (02-23-2011), iMAGEi (02-13-2011), ipodtouch44 (01-27-2011), iRobert (01-28-2011), ismael91 (04-08-2011), italianboss (01-28-2011), IX_BloodBath_XI (02-18-2011), J.V. (02-27-2011), j0ker666 (01-27-2011), j0nny (03-03-2011), jakenbake (02-27-2011), Jakob (01-26-2011), Janiboy (01-28-2011), JaponesHarD (01-27-2011), jeffers07 (02-26-2011), joejn27 (01-26-2011), kiddblaze18 (02-13-2011), Kohnt101 (02-19-2011), krazyfoolof2010 (02-18-2011), lawford (01-27-2011), Ledet (02-20-2011), lubu772 (02-13-2011), markinatorz (01-27-2011), Max21 (01-27-2011), maxrox (01-27-2011), mEdiivalXvirrus (02-13-2011), Mezzid (01-27-2011), microcell (02-26-2011), mj45dog (02-18-2011), MBO (01-28-2011), Mr.Kane (01-27-2011), multikillaz (02-19-2011), Ned Flanders (01-27-2011), Nero. (01-27-2011), nichols_ (01-27-2011), No1s Perfect (01-27-2011), nutta1234 (01-27-2011), OdoubleR (03-09-2011), Omniplasma (01-26-2011), OPTIMISM (03-03-2011), Out_Law_Gam3r (01-27-2011), P4NiSh3R (01-28-2011), Pass Word (02-13-2011), Pfk_eggroll (01-27-2011), PIINC (02-13-2011), pizzamon9 (01-29-2011), qmaster (02-13-2011), qwerew (02-18-2011), razor22 (02-26-2011), ronald809 (03-03-2011), RusterG (02-23-2011), s0ph0r (02-19-2011), S3gant (04-07-2011), SAM1994 (02-18-2011), samb222 (01-28-2011), Sambrears (02-19-2011), samybe122 (02-13-2011), Sasuke Uchiha (01-28-2011), SHAkA (01-27-2011), shinobi-of-zhit (02-13-2011), SiiANA--x (01-26-2011), Slay No More (01-27-2011), Slipperytesties (03-03-2011), smushpie (01-27-2011), Solid Snake (01-27-2011), spedy1 (01-28-2011), Starek (02-13-2011), Steve Jobs (02-18-2011), stronghead (02-13-2011), Swade (04-07-2011), Team Coco (02-13-2011), teeth08 (01-27-2011), TEXAS24_ReStEr (03-03-2011), thahsinul (03-03-2011), Thanitos (03-09-2011), TheSpoken (02-26-2011), theycallmeryan (01-26-2011), THE_JMAN (02-18-2011), toppdogg93 (01-26-2011), Top_Dog_Uk (02-23-2011), toxicflash (02-13-2011), TryCatchMe (01-27-2011), tsuma (03-03-2011), Tuhoaja (01-28-2011), UMD (01-28-2011), vipervimal (02-13-2011), w8t4it (02-18-2011), wyatt741 (03-03-2011), x Too GodLy x (02-27-2011), xDenley (01-27-2011), xEnhancer (02-27-2011), xGIBRALTERx (01-26-2011), xi-Callboii (02-19-2011), xpotato (02-19-2011), xQuaKz (01-27-2011), xRafiq- (01-27-2011), xShadow (04-09-2011), xT4sSin (03-09-2011), xTh3-J0k3R (02-26-2011), xzxero (02-18-2011), x_5 (01-27-2011), x_xPuNiiSh3Rx_x (01-27-2011), yoyo6-7 (02-19-2011), Zeroed_in (01-28-2011)

  3. #181

    Default





    0 Not allowed! Not allowed!
    Sony fails again haha.
    Register or log in to view signatures.

  4. #182
    Respect pl0x?
    xGIBRALTERx's Avatar

    Default


    0 Not allowed! Not allowed!
    Quote Originally Posted by The15thPrestige View Post
    Sony fails again haha.
    what did you do to get -100 rep
    Register or log in to view signatures.

  5. #183

    Default


    0 Not allowed! Not allowed!
    Quote Originally Posted by BlackOpsPost View Post
    what did you do to get -100 rep
    I posted really old stuff
    Register or log in to view signatures.

  6. #184
    Burrito

    Default


    0 Not allowed! Not allowed!
    I see that anyone tried the method that I posted here:
    Register or log in to view signatures.

  7. #185
    French Fries

    Talking Good Good


    0 Not allowed! Not allowed!
    When will it be released m8s LOL sony sucks :L
    Register or log in to view signatures.

  8. #186
    Ragdoll

    Default


    0 Not allowed! Not allowed!
    awaiting downgrade 3.56 or CFW 3.56 :derp:

    World need this!!
    Register or log in to view signatures.

  9. #187
    LAG? ;D
    david23's Avatar

    Default


    0 Not allowed! Not allowed!
    [QUOTE=*SCHAOS*;2401449]********It seems as though PS3 Dev's KakaRoTo, Rms and Adrianc have already located the new encryption keys Sony implemented in an attempt to combat Homebrew.[/LEFT]

    ********[SIZE=4][COLOR=red][B]UPDATE 1 (1/26):

    SOURCE?:smh:
    Register or log in to view signatures.

  10. #188
    Konichiwa Bitches
    Tory Lanez's Avatar

    Default


    0 Not allowed! Not allowed!
    [quote=david23;2604575]
    Quote Originally Posted by *SCHAOS* View Post
    ********It seems as though PS3 Dev's KakaRoTo, Rms and Adrianc have already located the new encryption keys Sony implemented in an attempt to combat Homebrew.[/LEFT]

    ********[SIZE=4][COLOR=red][B]UPDATE 1 (1/26):

    SOURCE?:smh:
    Fail quote quote is a fail
    Register or log in to view signatures.

  11. #189
    Junior Ranger
    Zeroed_in's Avatar

    Default


    0 Not allowed! Not allowed!
    This thread is almost 2 months old... where we going with this?
    Register or log in to view signatures.

  12. #190
    French Fries

    Default


    0 Not allowed! Not allowed!
    Quote Originally Posted by Zeroed_in View Post
    This thread is almost 2 months old... where we going with this?
    Not even a month old. 1/26/11 and now 2/19/11?

    Also give them time to do it not that's it is a 1sec job and they might got other things to do except for helping you downgrading.
    Register or log in to view signatures.

Page 19 of 28 FirstFirst ... 9 17 18 19 20 21 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •