PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • CEX to DEX Method/Guide Leaked - Confirmed Real but be Cautious

    I just got word of a newly released method for converting your CEX (retail) PS3 consoles into DEX (dev/test) machines. To the best of my knowledge, the following has yet to be verified; but for those who know what to do with this information, perhaps this may come into handy for those individuals. For now, it is recommended that your average sceners leave this process alone, until someone can confirm it's validity. The following guide may result in a brick, so please use caution and read make sure to read and understand everything before proceeding.


    This is an anonymous release, so there is even more reason to take caution before attempting this process. Again, wait until there is some conformation before attempting it yourselves.
    Hi Scene Sorry for my bad English. I want to give you info you pls make public. I want be anonymous. I only can say I’m from Hong Kong. I have way to get a dex, it works and is complete nothing missing

    Manual to get a dex (here is everything you needed) and you have a full working dex

    EID0 Key Seed and EID0 Section Key Seed are hardcoded in the isoldr

    EID0 Key Seed
    AB CA AD 17 71 EF AB FC 2B 92 12 76 FA C2 13 0C
    37 A6 BE 3F EF 82 C7 9F 3B A5 73 3F C3 5A 69 0B
    08 B3 58 F9 70 FA 16 A3 D2 FF E2 29 9E 84 1E E4
    D3 DB 0E 0C 9B AE B5 1B C7 DF F1 04 67 47 2F 85

    EID0 Section Key Seed
    2E D7 CE 8D 1D 55 45 45 85 BF 6A 32 81 CD 03 AF

    If you dump they isoldr key (EID Root Key) with metldrpwn you got from 0x00 to 0x1F the EID Root Key and from 0x20 to 0x2F the EID Root IV

    use AES Encrypt to Encrypt EID0 Key Seed as data with EID Root Key as Key and EID Root IV as IV

    the result contains from 0x10 to 0x20 the EID0IV

    and contains from 0x20 to 0x40 the EID0Key

    use AES Encrypt to Encrypt the EID0 Section Key Seed as data with the EID0Key as Key and no IV

    the result will be the first 0x10 bytes of the EID0 First Section Key

    the second 0x10 bytes of the EID0 First Section Key are only 0x00 bytes

    EID0 is located in NAND at 0x80870 and in NOR at 0x2f070

    the first 0x20 bytes of EID0 are not encrypted

    at the fifth byte of EID0 (NOR example 0x2f075) your target ID is located change it to 0x82 (Debug Target ID)

    use AES Decrypt to decrypt the first EID0 Section (NOR example 0x2f090). The size of the first Section is 0xC0 bytes. Use the EID0 First Section Key as Key and the EID0 IV as IV

    Build the CMAC (OMAC1) hash of the decrypted EID0 Section from 0x00 to 0xA8 with EID0 First Section Key as Key. The calculated hash has to be the same as the bytes in the decrypted EID0 Section from 0xA8 to 0xB8.

    At 0x5 of the decrypted EID0 Section is your target id again change it to 0x82 again

    0xB8-0xC0 of the decrypted EID0 Section should be just 0x00 bytes

    after you changed the target ID of the decrypted EID0 Section, create the CMAC hash of the new decrypted EID0 Section and write the new hash to the decrypted EID0 Section

    use AES Encrypt to encrypt the EID0 Section and write it back to the NOR (NAND).

    Now install dex Firmware with the recovery menu.

    HINT: Got Petitboot on emer init go to boot gameos and do emer init again to get to the recovery menu.

    You can’t login to the PSN because IDPS is obviously not valid from now on.

    THIS CAN BRICK YOUR CONSOLE IF NOT DONE CORRECTLY.

    有志者,事竟成 “Where a will, there is way”
    一不做二不休 „You start something, you have to finish it”
    Source: PS3News

    UPDATE:

    PS3Hax's zecoxao has confirmed this method working, and has also stated the following about requirements.

    btw, you can use flasher, linux or jaicrab's preloader (basically anything that flashes the dump)

    jaicrab's preloader only works correctly on NOR's, you'll have problems with NAND's, or so i've tested (thanks to a friend of mine )
    But again, I am going to advise users to wait until other developers look into this method before jumping into it. Chances are there may be a user friendly option available one day soon.

    PSX-SCENE: The Best News for the Best Community!

    Hall of Fame - Latest News - Report News - Search Forums
    SkyNet, sketchdesigner and gDrive like this.
    Comments 92 Comments
    1. mad mike 96's Avatar
      mad mike 96 -
      Thats pretty awsome if this is legit.
    1. mossopinc's Avatar
      mossopinc -
      what is a use for this?
    1. tthousand's Avatar
      tthousand -
      I think this is what the scene was waiting for Not the devs, not the sites, but the scene.
    1. mad mike 96's Avatar
      mad mike 96 -
      ****ing Sweet!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!

      This converts a retail PS3 into a Debug machine able to run the debug firmwares and homebrew code. So I assume we can update to the latest debug release? anyone have a hash check for that release so I can verify my source before hand?
    1. tthousand's Avatar
      tthousand -
      Have you tried Berion's Custom Firmeware Validator?

      BTW, you might want to wait it out before you try it. You don't want to brick your system right when this thing is getting started, right?
    1. mad mike 96's Avatar
      mad mike 96 -
      Eh I have four PS3s at the moment not worried bout it m8. thanks for the concern though! Seems however I have lost my copy of the debug firmware.... going to play hell finding it again!

      It just occured to me Debug consoles can run backup managers cant they?
    1. garine's Avatar
      garine -
      yes they can.

      Dex can run unsigned code/Pkgs...
    1. Warning's Avatar
      Warning -
      I can see a couple things wrong with this.
      I would wait for better confirmation
    1. futuretime23's Avatar
      futuretime23 -
      iirc,debug ps3 can run backups(via discs),maybe we can get homebrew working on debug?
    1. mad mike 96's Avatar
      mad mike 96 -
      Indeed should easily be working. as for confirmation one never gets anywhere by sitting around with his thumb up his arse!
      Though at this rate I may as well be doing so. still hhavent tracked down a debug firmware higher than 3.66.
    1. Vegeta's Avatar
      Vegeta -
      Homebrew would work as debug fw allows unsigned code.
    1. DEREKTROTTER's Avatar
      DEREKTROTTER -
      yes, you could run EVERY backup with this regardless of what keys they are signed with. Shame about losing the PSN access tho.
    1. DEREKTROTTER's Avatar
      DEREKTROTTER -
      btw, if this is real someone make a pkg to do all this
    1. r1c0la's Avatar
      r1c0la -
      Quote Originally Posted by DEREKTROTTER View Post
      btw, if this is real someone make a pkg to do all this
      ^^^^^
    1. BahumatLord's Avatar
      BahumatLord -
      But again, I am going to advise users to wait until other developers look into this method before jumping into it. Chances are there may be a user friendly option available one day soon.
      I hope so. I don't have a flasher to even attempt this. Probably gonna sound like a noob, but with the latest debug firmware you could run whatever you wanted without the need of any dongles or patches right? Including game updates/PSN content?
    1. mad mike 96's Avatar
      mad mike 96 -
      Yeah who cares. if you dont have PSN..... any chance a tool like **** PSN could fake the IDPS? don't know how to make a package to do all that but I'm sure it's doable. after all the necessary tools exist..... as for if it's legit well only time will tell.


      Yes you can sir. as for a flasher it's not needed at all if you are jailbroken. just use one of the tools out there for writing to flash.
    1. gDrive's Avatar
      gDrive -
      Quote Originally Posted by DEREKTROTTER View Post
      yes, you could run EVERY backup with this regardless of what keys they are signed with. Shame about losing the PSN access tho.
      If this is legit, most of "teh warez mongrelz" will be jumping on this like a horny skank jumping and riding on a pimp with a 40-inch dick, and I don't think they'll give a damn about sacrificing PSN (via PS3 access) at all, not for a while at least.

      Update: Actually, it is legit, but be prepared to go down Brick Lane if sh*t hits the fan - missed that part

      Update #2: Looks like its usefulness has been questioned - blah!
    1. yes159's Avatar
      yes159 -
      I guess this means that the E3 dongle is dead before it hit the market.

      EDIT: That is IF this CEX to DEX method allows any PS3 debug firmware to be installed. If you still need custom firmware for debug too, then i'm not sure if this will change much in the scene.
    1. the-green's Avatar
      the-green -
      Hope it's not another fake, btw, are you sure you can install 3.6+ debug firmwares !!
      As i knew all the previews fakes taliking about CEX to DEX conversion said this will work only with 3.55 debug version !!! not higher !
      about homebrews story, may be it's possible on debug units but not the backups, for backups you'll need peek & poke payloads & many other things, so you need to decrypt the 3.6+ debug firmwares = you need the new public keys & no one will give us such keys !!!!
    1. BahumatLord's Avatar
      BahumatLord -
      If there is a problem running backups through multiMAN, couldn't you just do the PSN style conversion and boot them from the XMB? Might not work on all games, but most at least