PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Mathieu Explains 3.60 Exploit - Will Lead to Application Keys and Eventually 3.60 CFW

    The cats out of the bag, after many subtle hints, Mathieu explains his exploit and how it will lead to application keys. With the help of this loader exploit, devs can now obtain the Bootloader keys which will lead to the Application keys and eventually, a 3.60 CFW! With application keys, Portal 2 and future 3.60 encrypted games may soon be playable!
    Synopsis of Mathieu's explanation of the exploit:
    The function that copies the SCE header from the shared LS to the isolated Local Store doesn’t check the header’s size.

    [So] you craft a self with a HUGE header so [that] it overwrites ldr code as it gets copied to the isolated LS and you wait [for] the loader to jump to it.

    [Then] you can get lv0 decrypted, once you get lv0 decrypted, you get appldr, once you get appldr, you get 3.60 application keys, [and] once you get that, you [get] warez.


    Mathieu's full conversation regarding the exploit:

    X nah, not a single line of code, at least not for the implementation
    but finding the exploit itself
    is EASY
    except no one has gone looking
    I’ve seen lots of askings and whining, very little looking xD
    if someone who remotely knows spu reversing starts looking
    he’ll find it
    at the very worse in a matter of hours
    the bug is ******ly stupid to begin with
    LV0, EID0, anything with coreOS imo should not be done without a hardwareflasher. Atleast with that you can undo the mess.
    yeah
    I am a bit of a red head here xD
    you keep saying that, but I suck at SPU assembly
    you’d find it even if you fail at it
    you just need to know where to look
    just look at how selfs are processed by ldrs
    and you’ll find it
    hell, I’ll help you, it’s about overflowing a certain buffer
    yes, that is what defyboy and I tried to document in the ps3devwiki : bootprocess and loader locations etc.
    well if you know how selfs are processed by loaders, it’s easy
    another hint
    it happens before the ecdsa check
    my earlier guess btw was that it was a header overflow, which gave access to the local storage
    It’s a ******ed exploit
    if you want to know what it is, I’ll tell you
    the function that copies the SCE header from the shared LS to the isolated Local Store
    doesn’t check the header’s size
    \o/
    it’s just THAT ******ed
    implementing it isn’t easy though
    cause loaders have failsafes and ****
    header size fail
    lol
    ?
    but now that you know, you can try it on your own
    X1 yes
    you craft a self with a HUGE header
    so it overwrites ldr code as it gets copied to the isolated LS
    and you wait the loader to jump to it
    lolol must try heh
    X1 it’s a total ***** to implement
    but feel free xD
    if someone pwns the bl with this and gets the keys, he’ll have my kudos
    cause finding the exploit is the easy part
    Sony’ll fix it now, but it’s not like I care much
    their “unhackable” ps3s are probably already on the way
    Mathieu explains the impact the exploit/keys have on Sony:

    why would they care about bootldr keys?
    ps3devnews etc. host metldr keys, appldr keys etc.
    X1 cause you can get lv0 decrypted
    once you get lv0 decrypted
    you get appldr
    once you get appldr
    you get 3.60 application keys
    once you get that
    you warez
    also, with those keys you can sign your own lv0, no ps3 fw update can beat you then
    yah
    you can have your 3.60+ custom firmware then
    and warez even more
    and mess with the psn again
    and so on
    Source: PS3Church
    Comments 65 Comments
    1. NEO117-PSG's Avatar
      NEO117-PSG -
      Quote Originally Posted by rrrboy159 View Post
      First of all, Math, doesnt have to release anything. If he has the keys or doesnt have the keys. If he has the method or not. UNDER ANY CIRCUMSTANCE HE DOES NOT HAVE TO RELEASE ANYTHING.
      Second, there is no real point of 3.60 CFW. The only reason we would need it is psn. ONLY REASON. NOthin more nothing less. There are no more excuses.
      When SOny came out with 3.56 or 3.60, no body should have updated in the first place. Even if it was on "accident" or if my "brother" did it or if my "stupid dog got an erection and hit X on the controller" NO MORE EXCUSES
      For the people who bought their ps3 on 3.56 or 3.60, can't say anything about that.
      The keys would be helpful for Portal 2 and future games, but wats the point. If your not pirating you would buy the game. And when you do youll have the disk. So you could play it. There the end.
      If you buy Portal 2, you still have to update in order to play the game.
    1. Angel Diaz's Avatar
      Angel Diaz -
      @richguas1970 +1
      .................................................. ...............
    1. ihaxgames-PSG's Avatar
      ihaxgames-PSG -
      For those of you calling him selfish stfu, you guys can't do what he did. And if you say he "simply cloned the psjb" that's far from the truth, he and other devs improved the payloads. He's also risking prosecution for giving us HINTS on how to get this
    1. varaques-PSG's Avatar
      varaques-PSG -
      I hope they don't release anything until more games requiring updating to 3.60 firmware are released
    1. Hkas's Avatar
      Hkas -
      Quote Originally Posted by rrrboy159 View Post
      First of all, Math, doesnt have to release anything. If he has the keys or doesnt have the keys. If he has the method or not. UNDER ANY CIRCUMSTANCE HE DOES NOT HAVE TO RELEASE ANYTHING.
      Second, there is no real point of 3.60 CFW. The only reason we would need it is psn. ONLY REASON. NOthin more nothing less. There are no more excuses.
      When SOny came out with 3.56 or 3.60, no body should have updated in the first place. Even if it was on "accident" or if my "brother" did it or if my "stupid dog got an erection and hit X on the controller" NO MORE EXCUSES
      For the people who bought their ps3 on 3.56 or 3.60, can't say anything about that.
      The keys would be helpful for Portal 2 and future games, but wats the point. If your not pirating you would buy the game. And when you do youll have the disk. So you could play it. There the end.
      well your stupid i bought portal 2 but cant play it cause of the encryption i agree there shouldnt be a cfw but at least a way to play your legally purchased games on whatever firmware you want


      Sent from my iPod touch using Tapatalk
    1. blazie151's Avatar
      blazie151 -
      Quote Originally Posted by rrrboy159 View Post
      First of all, Math, doesnt have to release anything. If he has the keys or doesnt have the keys. If he has the method or not. UNDER ANY CIRCUMSTANCE HE DOES NOT HAVE TO RELEASE ANYTHING.
      Second, there is no real point of 3.60 CFW. The only reason we would need it is psn. ONLY REASON. NOthin more nothing less. There are no more excuses.
      When SOny came out with 3.56 or 3.60, no body should have updated in the first place. Even if it was on "accident" or if my "brother" did it or if my "stupid dog got an erection and hit X on the controller" NO MORE EXCUSES
      For the people who bought their ps3 on 3.56 or 3.60, can't say anything about that.
      The keys would be helpful for Portal 2 and future games, but wats the point. If your not pirating you would buy the game. And when you do youll have the disk. So you could play it. There the end.
      You right and I've been singing the same song for awhile. I'm pissed that this info is released. $ony can now patch it and WE HAVE NOTHING to show for it. Someone needed to do this exploit WITHOUT releasing it, release the appldr key and x-platform-passphrase, and NOT RELEASE THE EXPLOIT. Problem now is that the cat's outta the bag, which is f*cking stupid.
    1. happyface-PSG's Avatar
      happyface-PSG -
      I'm pissed that this info is released. $ony can now patch it and WE HAVE NOTHING to show for it
      well even if $ony fixes it with a new update we still have 3.60 CFW and will be able to play newer games right?
    1. merkinmaker's Avatar
      merkinmaker -
      Quote Originally Posted by blazie151 View Post
      You right and I've been singing the same song for awhile. I'm pissed that this info is released. $ony can now patch it and WE HAVE NOTHING to show for it. Someone needed to do this exploit WITHOUT releasing it, release the appldr key and x-platform-passphrase, and NOT RELEASE THE EXPLOIT. Problem now is that the cat's outta the bag, which is f*cking stupid.
      I agree, this work should be done underground until it is complete. It's kinda like saying to your neighbor "Hey man, thanks for leaving your car door unlocked. That makes it much easier for me to take your expensive CD player tonight." Your neighbor will then more than likely turn around and lock their door. Good thinking white-hats!
    1. tg3's Avatar
      tg3 -
      Quote Originally Posted by rrrboy159 View Post
      First of all, Math, doesnt have to release anything. If he has the keys or doesnt have the keys. If he has the method or not. UNDER ANY CIRCUMSTANCE HE DOES NOT HAVE TO RELEASE ANYTHING.
      Second, there is no real point of 3.60 CFW. The only reason we would need it is psn. ONLY REASON. NOthin more nothing less. There are no more excuses.
      When SOny came out with 3.56 or 3.60, no body should have updated in the first place. Even if it was on "accident" or if my "brother" did it or if my "stupid dog got an erection and hit X on the controller" NO MORE EXCUSES
      For the people who bought their ps3 on 3.56 or 3.60, can't say anything about that.
      The keys would be helpful for Portal 2 and future games, but wats the point. If your not pirating you would buy the game. And when you do youll have the disk. So you could play it. There the end.

      "stupid dog got an erection and hit X on the controller"

      LMAO
    1. nawzad40-PSG's Avatar
      nawzad40-PSG -
      i think Mathieu is the only person helping us out kind of..who else has talked about the 3.60 keys or 3.60cfw:o:o
    1. FlashDrive101's Avatar
      FlashDrive101 -
      This is great news. I'm so sorry for ever doubting it could happen. :o
    1. Rigg023's Avatar
      Rigg023 -
      Let's get it on like donkey kong!
    1. videogamerevie81's Avatar
      videogamerevie81 -
      cant wait for 3.60 cfw
    1. gixernaz's Avatar
      gixernaz -
      Mathieulh <- ALL BARK, NO BITE. A poser in this scene. Don't keep your hopes up.
    1. jigglesthefett-PSG's Avatar
      jigglesthefett-PSG -
      Quote Originally Posted by gixernaz View Post
      Mathieulh <- ALL BARK, NO BITE. A poser in this scene. Don't keep your hopes up.
      What have -you- done for this scene? Anything except make snide comments on a message board? Doubtful. Until you do more than math HAS (cause he -has- helped forward this scene), just quit *****ing about it. Seriously, and this goes for everyone that hates him because he 'hasn't done anything'.


      Seriously, let's NOT make this another DA situation, that was just embarrassing for -everyone-.
    1. Zero95's Avatar
      Zero95 -
      Quote Originally Posted by jigglesthefett View Post
      What have -you- done for this scene? Anything except make snide comments on a message board? Doubtful. Until you do more than math HAS (cause he -has- helped forward this scene), just quit *****ing about it. Seriously, and this goes for everyone that hates him because he 'hasn't done anything'.


      Seriously, let's NOT make this another DA situation, that was just embarrassing for -everyone-.
      With the exploit we became the bootldr keys.

      Bootldr keys can´t change. Obvously bootldr keys can change but only with a ne hardware revision.

      We can sign own lv0 with the bootldr so no update in the future can **** us because we can decrypt the new lv0 and change lv0 encrypt lv0 and sign lv0

      no chek is before bootldr.
    1. Dishank's Avatar
      Dishank -
      Cool, we are closer to 3.60 CFW YESSSS! But i prefer to stay on 3.55 CFW and have 3.60 OFW too, everyone is right, a dual boot would be awesome, with that we are unstoppable cuz sony can't do anything!
    1. Turkish-PSG's Avatar
      Turkish-PSG -
      Quote Originally Posted by MadnessImport View Post
      Ok I laughed till i barfed

      ANYTHING Turkish will say is only Gona make me laugh harder if he post's here because ill agree

      its becoming nothing but piracy these days

      Lol, by now its 3 months since they couldn't hack 3.56/3.60, how many months will it be when actually 3.60cfw comes? Don't they think Sony is gonna patch it up... again?
      They need to find a way so we can play our games/homebrew on 3.55 without having to update our fw. Just like on the psp, 5.00m33-6 can play the newest games. All the homebrew and emus needs to be signed again, we already have emus on 3.41 that don't work on 3.55 like Sega emu Yabause.
    1. toml's Avatar
      toml -
      Congrats to the devs! Keep up the good work!

      I also believe that the Primary Objective is to reach the following multiboot configuration:
      - CFW 3.60
      - OFW 3.60+
      - Linux

      ;-)
    1. Turkish-PSG's Avatar
      Turkish-PSG -
      And whats up with EVERYONE demanding a dual boot??? NOWHERE and NO ONE has EVER said that dual boot fw was coming LOL! Some people are really Lemmings, one guy is starting a rumor and everyone is barking the same thing.

      Let me get this straight:

      First: dual boot was nothing about having 2 firmwares: it was about booting 1 firmware and... 1 Linux(OtherOs)

      Second: Matieulh has NOTHING to do with that, it was graf_chokolo working on it

      Third: Stop getting your hopes up for nothing and stop telling the same thing over and over again: "i haz wantz dual boot pl0x, 1 cfw and 1 ofw" lmao, we all know u are desperatly trying to reach PSN, go get yourself a 2nd 2nd hand ps3.
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    lovewiibrew

    OPL development stalling?

    Thread Starter: lovewiibrew

    It's a fantastic program and I would hate to see it abandoned. One commit in 9 months and sometimes there's maybe one post a day in the OPl forum. Has

    Last Post By: RandQalan Today, 03:44 AM Go to last post
    w0mb

    SLIM - Firmware 3.50 120 GB - cech2001a - For Sale

    Thread Starter: w0mb

    Listing on ebay to buy but shoot me offers before I list it. Will do transaction threw ebay.
    Perfect condition.
    This is the Offical Sony

    Last Post By: w0mb Yesterday, 10:43 PM Go to last post
    inserttwo

    PS4 new Teaser! Console shown!

    Thread Starter: inserttwo

    New teaser folks with a few close ups of the PS4 Console:



    It seems they will show the complete console in June 10th.

    Last Post By: inserttwo Yesterday, 10:29 PM Go to last post
    Smoker1

    Vita Inquiries

    Thread Starter: Smoker1

    I am planning on purchasing a Vita at the end of the Month when I get paid. Now, I am just wondering if there is anything worth while to install yet?

    Last Post By: Smoker1 Yesterday, 10:26 PM Go to last post
    ANTZ7

    question about using bruteforce

    Thread Starter: ANTZ7

    yo all

    so my question is. i just used bruteforce to change some games saves over

    i did far cry 3 perfect and did tombraider

    Last Post By: ANTZ7 Yesterday, 09:29 PM Go to last post
    posimosh

    WTS G25 Racing Wheel $120 (US) Will Ship

    Thread Starter: posimosh

    Used for about a year. In good shape with minor wear and tear, minor signs of usage, but hardware wise, its perfect. I have pictures to share if yall

    Last Post By: posimosh Yesterday, 08:58 PM Go to last post
  • Recent Comments

    matt100

    New Multiman Themes by hcode123

    got to admit you make some fantastic themes...bootifull just bootifull Go to last post

    matt100 Today 05:11 AM
    alaska32

    [update #32] New EBOOT Patches/Fixes for 3.55/3.41

    Thanks bro Go to last post

    alaska32 Today 04:10 AM
    White Lord

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    i would love to see this running on ps3 surely. :)
    There is no reason for this not to work on PS3... Go to last post

    White Lord Today 03:50 AM
    gamecheater

    Latest in PSP Conversions Tools and News (PSPonPS3)

    Using Ez psp2ps3 1.3, tried making remaster on 3 different iso and can successfully convert into... Go to last post

    gamecheater Today 02:14 AM
    XPredator13

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    Yep. But, after booting MM or RT, it works flawless, but it has a major issue in rebug 4.30, the... Go to last post

    XPredator13 Today 01:46 AM
    bitsbubba

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    be sure to report back atreyu187 (like there's any doubt you won't :D ) Go to last post

    bitsbubba Today 12:57 AM
    atreyu187

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    Wonder how it handles in a PSP2PS3 conversion, time for testing and thank a lot!! No PSP anymore... Go to last post

    atreyu187 Today 12:51 AM
    bitsbubba

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    nice :) Go to last post

    bitsbubba Today 12:43 AM
    tthousand

    PSChannel receives some Eye Candy from Opium2k

    Just a bit opium2k, but we are trying to bring back that retro feeling here. Even if it is... Go to last post

    tthousand Today 12:42 AM
    White Lord

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    Next is an update for the mod for this game. Adding new moves, maybe new playable characters.
    It... Go to last post

    White Lord Today 12:39 AM