PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • CEX to DEX Method/Guide Leaked - Confirmed Real but be Cautious

    I just got word of a newly released method for converting your CEX (retail) PS3 consoles into DEX (dev/test) machines. To the best of my knowledge, the following has yet to be verified; but for those who know what to do with this information, perhaps this may come into handy for those individuals. For now, it is recommended that your average sceners leave this process alone, until someone can confirm it's validity. The following guide may result in a brick, so please use caution and read make sure to read and understand everything before proceeding.


    This is an anonymous release, so there is even more reason to take caution before attempting this process. Again, wait until there is some conformation before attempting it yourselves.
    Hi Scene Sorry for my bad English. I want to give you info you pls make public. I want be anonymous. I only can say I’m from Hong Kong. I have way to get a dex, it works and is complete nothing missing

    Manual to get a dex (here is everything you needed) and you have a full working dex

    EID0 Key Seed and EID0 Section Key Seed are hardcoded in the isoldr

    EID0 Key Seed
    AB CA AD 17 71 EF AB FC 2B 92 12 76 FA C2 13 0C
    37 A6 BE 3F EF 82 C7 9F 3B A5 73 3F C3 5A 69 0B
    08 B3 58 F9 70 FA 16 A3 D2 FF E2 29 9E 84 1E E4
    D3 DB 0E 0C 9B AE B5 1B C7 DF F1 04 67 47 2F 85

    EID0 Section Key Seed
    2E D7 CE 8D 1D 55 45 45 85 BF 6A 32 81 CD 03 AF

    If you dump they isoldr key (EID Root Key) with metldrpwn you got from 0x00 to 0x1F the EID Root Key and from 0x20 to 0x2F the EID Root IV

    use AES Encrypt to Encrypt EID0 Key Seed as data with EID Root Key as Key and EID Root IV as IV

    the result contains from 0x10 to 0x20 the EID0IV

    and contains from 0x20 to 0x40 the EID0Key

    use AES Encrypt to Encrypt the EID0 Section Key Seed as data with the EID0Key as Key and no IV

    the result will be the first 0x10 bytes of the EID0 First Section Key

    the second 0x10 bytes of the EID0 First Section Key are only 0x00 bytes

    EID0 is located in NAND at 0x80870 and in NOR at 0x2f070

    the first 0x20 bytes of EID0 are not encrypted

    at the fifth byte of EID0 (NOR example 0x2f075) your target ID is located change it to 0x82 (Debug Target ID)

    use AES Decrypt to decrypt the first EID0 Section (NOR example 0x2f090). The size of the first Section is 0xC0 bytes. Use the EID0 First Section Key as Key and the EID0 IV as IV

    Build the CMAC (OMAC1) hash of the decrypted EID0 Section from 0x00 to 0xA8 with EID0 First Section Key as Key. The calculated hash has to be the same as the bytes in the decrypted EID0 Section from 0xA8 to 0xB8.

    At 0x5 of the decrypted EID0 Section is your target id again change it to 0x82 again

    0xB8-0xC0 of the decrypted EID0 Section should be just 0x00 bytes

    after you changed the target ID of the decrypted EID0 Section, create the CMAC hash of the new decrypted EID0 Section and write the new hash to the decrypted EID0 Section

    use AES Encrypt to encrypt the EID0 Section and write it back to the NOR (NAND).

    Now install dex Firmware with the recovery menu.

    HINT: Got Petitboot on emer init go to boot gameos and do emer init again to get to the recovery menu.

    You can’t login to the PSN because IDPS is obviously not valid from now on.

    THIS CAN BRICK YOUR CONSOLE IF NOT DONE CORRECTLY.

    有志者,事竟成 “Where a will, there is way”
    一不做二不休 „You start something, you have to finish it”
    Source: PS3News

    UPDATE:

    PS3Hax's zecoxao has confirmed this method working, and has also stated the following about requirements.

    btw, you can use flasher, linux or jaicrab's preloader (basically anything that flashes the dump)

    jaicrab's preloader only works correctly on NOR's, you'll have problems with NAND's, or so i've tested (thanks to a friend of mine )
    But again, I am going to advise users to wait until other developers look into this method before jumping into it. Chances are there may be a user friendly option available one day soon.

    PSX-SCENE: The Best News for the Best Community!

    Hall of Fame - Latest News - Report News - Search Forums
    SkyNet, sketchdesigner and gDrive like this.
    Comments 92 Comments
    1. Nemes's Avatar
      Nemes -
      Quote Originally Posted by Mitdog View Post
      I just tryed the pkgs and no luck , it still says no bd emu support and just loads back to the original game disc.
      Please forgive my ignorance, but isn't the problem in lv2? You're running an authentic Sony firmware, which means lvl2 hasn't been patched. If one were to patch lv2 in the same manner that CFWs patched it, would that work? Or even on debug firmware is lv0 still enforcing a chain of trust?
    1. mad mike 96's Avatar
      mad mike 96 -
      You PM from the top of the page under the PSXscene logo. you should see private messages.
    1. Mitdog's Avatar
      Mitdog -
      ok cool

      email me mitdog12345 at gmail com
    1. Mitdog's Avatar
      Mitdog -
      I'm going to the store i'll be back in 10 mins
    1. mad mike 96's Avatar
      mad mike 96 -
      ok sorry I missed the message. will send an email shortly.
    1. pip313's Avatar
      pip313 -
      Quote Originally Posted by Nemes View Post
      Please forgive my ignorance, but isn't the problem in lv2? You're running an authentic Sony firmware, which means lvl2 hasn't been patched. If one were to patch lv2 in the same manner that CFWs patched it, would that work? Or even on debug firmware is lv0 still enforcing a chain of trust?
      If you want to patch lv2 in dex then you need the same keys to sign as sony has and we don't have them above 3.55. Also if we did we would have cfw 4.xx not be trying to install debug software.

      All of this is dumb, if you really want new games get your per console key and dump 4.21, downgrade to 3.55, disassemble the 4.21 dump, find keys, decrypt yourself. (after brute forcing the curve type out of 64 possibilities) This allows psn games and updates debug won't.

      I've said it before and will say it again, people have the public keys above 3.55 because they got them themselves. Do not share unless you like being sued.
    1. maciek B's Avatar
      maciek B -
      I was waiting for dongle from E3, and here is the surprise. I can not wait to test it.
    1. mad mike 96's Avatar
      mad mike 96 -
      Quote Originally Posted by pip313 View Post
      If you want to patch lv2 in dex then you need the same keys to sign as sony has and we don't have them above 3.55. Also if we did we would have cfw 4.xx not be trying to install debug software.

      All of this is dumb, if you really want new games get your per console key and dump 4.21, downgrade to 3.55, disassemble the 4.21 dump, find keys, decrypt yourself. (after brute forcing the curve type out of 64 possibilities) This allows psn games and updates debug won't.

      I've said it before and will say it again, people have the public keys above 3.55 because they got them themselves. Do not share unless you like being sued.
      if you were able to obtain the 4.21 keys that easily do you truely believe the scene would be standing still? I mean honestly? the per console keys let you do some neat things but obtaining private keys is not one of them.
    1. thommy86's Avatar
      thommy86 -
      should it be possible to make a dual boot for CEX and DEX firmware with the e3 flasher..

      really like to read this.. (and all the comments ;P) hope to see something nice in the near future!
    1. mad mike 96's Avatar
      mad mike 96 -
      I doubt you will be able to make a dual boot setup with both CEX and DEX firmwares do to the way you have to patch flash to be able to install the debug software.


      Well at least I'm sure it would be a real B**** to do.
    1. futuretime23's Avatar
      futuretime23 -
      hey folks,at least look at the bright side,ps3 scene isnt dead as it was after all,now if we could get a user friendly way or a way without a flasher,it could at least allow us to play newer games without any issue,until sony comes along,i wonder how are they going to fix this?
      i know,newer debug fw,put a new security check,etc.
    1. Gradius's Avatar
      Gradius -
      Well, this is good news if confirmed true.

      The scene was almost totally *DEAD*, we all needs to thanks to Bruce Lee guy. hehehe
    1. ahou's Avatar
      ahou -
      We can still play retail disks on debug firmware, yes? And since we can downgrade from debug firmware, this is still pretty nice for those of us without flashers, even if there's never a way to run backups, since we can switch back and forth between cfw and debug ofw.

      There's a few games i would have bought a long time ago if i could play them without losing cfw.
    1. Berion's Avatar
      Berion -
      Quote Originally Posted by ahou View Post
      We can still play retail disks on debug firmware, yes? And since we can downgrade from debug firmware, this is still pretty nice for those of us without flashers, even if there's never a way to run backups, since we can switch back and forth between cfw and debug ofw.

      There's a few games i would have bought a long time ago if i could play them without losing cfw.
      I agree.

      Also I'm curious if multiMAN could be installed and launched. Of course I know backup will not work but I'm thinking about fully working file manager to access my data, especially saves with Copy Prohibited and Trophies.
    1. deank's Avatar
      deank -
      Not in its current shape, but it should be possible, just like any other homebrew like Showtime or emulators.
    1. wartutor's Avatar
      wartutor -
      my question is couldn't we just go back to installing them as packages (like psn games) instead
    1. cubano1401's Avatar
      cubano1401 -
      [QUOTE=wartutor;984115]my question is couldn't we just go back to installing them as packages (likepsn games) instead[/QUOTE ] yeah but if emulators can't run with out having to be tweaked then I doubt that'll work but I sure would like it to.
    1. zldr's Avatar
      zldr -
      let's see if i can write a noob friendly tutorial/and or make a video
    1. sangimed's Avatar
      sangimed -
      it's just for cfw ? or may be applied on any ofw?
    1. master737373's Avatar
      master737373 -
      Quote Originally Posted by mad mike 96 View Post
      I doubt you will be able to make a dual boot setup with both CEX and DEX firmwares do to the way you have to patch flash to be able to install the debug software.


      Well at least I'm sure it would be a real B**** to do.
      Yes you can. Once you have a flash/HDD with the Dex firmware, follow the same steps as dual firmware. Nothing hard about the setup.
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    kudabe

    Jail

    Thread Starter: kudabe

    Okay so i had a jailbroken ps3, and i accidentally updated it to OFW 4.41. The custom firmware that i had was CFW 4.30. Its a slim ps3 and the reason

    Last Post By: Princescyther Today, 02:35 AM Go to last post
    Priime

    NETFLIX 12 MONTH MEMBERSHIP!! -3 Available

    Thread Starter: Priime



    got 3 netflix 12 month member ship

    i just got the codes no cards

    currently used a card for myself!! (:

    Last Post By: Priime Today, 01:02 AM Go to last post
    Hankk

    Gta tbogt Crashing

    Thread Starter: Hankk

    I have my PS3 Jail Broken onto Rebug CFW (4.41)

    So first, I open Multi-MAN then copy the game to my hdd (internal)
    Then i do the

    Last Post By: H8ncars Today, 01:21 AM Go to last post
    DaBOSS54320

    3.55 Question

    Thread Starter: DaBOSS54320

    If I reset my PS3 entirely (format and everything) will it return to a version before/on 3.55 so I can put it on 3.55 and get a CFW? I am not 100% sure

    Last Post By: DaBOSS54320 Today, 01:37 AM Go to last post
    Hankk

    Gta tbogt Crashing

    Thread Starter: Hankk

    I have my PS3 Jail Broken onto Rebug CFW (4.41)

    So first, I open Multi-MAN then copy the game to my hdd (internal)
    Then i do the Permissions

    Last Post By: Hankk Yesterday, 11:55 PM Go to last post
    soules172

    Final Fantasy Tactics: The War of the Lions

    Thread Starter: soules172

    anyone get saves working for Final Fantasy Tactics: The War of the Lions ?

    Last Post By: atreyu187 Today, 12:47 AM Go to last post
  • Recent Comments

    nativesith

    May's PSX-Scene Contest Leaderboard.

    The other... taken OVER!
    Hell Yeah! Go to last post

    nativesith Yesterday 11:51 PM
    worrorfight

    May's PSX-Scene Contest Leaderboard.

    Lots of GTA-IV mods :D good write up STLcardsWS Go to last post

    worrorfight Yesterday 10:21 PM
    worrorfight

    Bite h&e v1.5.1 -- Addition of 3 PC emulators.

    Great work on the 3 emulators Francesco Lanzilotta. :) Go to last post

    worrorfight Yesterday 10:18 PM
    JOshISPoser

    April Contest Winner: RazorX Interview

    damn. thanks, but i don't have any 99 min cds, just 80 min. i remember looking for them, sort of,... Go to last post

    JOshISPoser Yesterday 09:49 PM
    atreyu187

    April Contest Winner: RazorX Interview

    I made a 99min rip of the game I could pass along. Go to last post

    atreyu187 Yesterday 09:08 PM
    JOshISPoser

    mMTools Updated for 4.41 CFW

    pretty sure that's showtime disc access. Go to last post

    JOshISPoser Yesterday 07:49 PM
    Ziken

    mMTools Updated for 4.41 CFW

    what does stDISC4.pkg do? Go to last post

    Ziken Yesterday 07:36 PM
    soules172

    PSPtoPS3 GUI Released with New PSP Remaster Method

    anyone get Final Fantasy Tactics: The War of the Lions saves to work ? Go to last post

    soules172 Yesterday 07:27 PM
    JOshISPoser

    April Contest Winner: RazorX Interview

    revivedc...you are a god.

    by any chance you have a working release of LoL? I can't get that... Go to last post

    JOshISPoser Yesterday 06:18 PM
    futuretime23

    Classic Resident Evil Modding -- Including a Resident Evil 1.5 Mod Update

    atreyu187
    the ps1 RE rebuilders were done by Wes67,not by me. Go to last post

    futuretime23 Yesterday 05:57 PM