PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Flukes1 LV1 LV2 Peek and Poke Tools Released

    Earlier this week, a developer by the name of flukes1 had successfully modified LV1/LV2 to allow full backup manager playback. However, due to legal reasons, he decided not to release his modifications. Today, he has decided to release the tools that led to his modifications, so other budding developers can give it a shot. Please note these are not for the average user, strictly for developers.

    Download: tools.zip

    As you may know if you’ve been following my progress, last week I took a short break from Wi-Fi Sync to look at the PS3 and how it works behind the scenes. The PS3 homebrew scene is currently at a point where you can install userland packages, such as FTPDs and SNES emulators, but you still don’t have any access to the hypervisor or GameOS kernel. It’s still very much a closed system.

    As an iPhone developer with an app on Cydia, I can see great potential within the PS3. It’s crying out for a decent package manager, but you need OS-level access to do that effectively. Unlocking the PS3 in this way has other benefits too; the system can effectively be modified in any way you wish.

    So today I’m releasing three tools which open the PS3’s hypervisor (lv1) and GameOS (lv2) to full read/write access from packaged userland applications. These tools can be used to create and test lv1/lv2 patches in RAM, which negates the risk of bricking your PS3 by flashing it with an incorrectly patched lv1 or lv2 binary. You can also use the tools to create a patched lv1 or lv2 binary, if you wish, although I suggest thoroughly testing your patches in-memory first.

    I will make a few things clear before continuing: I do not condone piracy and these tools DO NOT enable copied games to run on the PS3. Again: these tools will not allow backup managers to suddenly start working on firmware 3.55. The tools are packaged in source code form and do not include any Sony code or other Sony assets such as encryption keys. If you’re not a developer, these tools will be useless to you, so please do not try to use them. They are made available with no implied warranty of fitness for a particular purpose.

    Three tools are being made available today:

    * resign_self.py. This allows you to automatically replace any segment within a self and re-sign the self so the signatures and hashes are all valid again. Similar to makeself, but it is more suited towards patching lv1 and lv2 (and has been tested for this purpose).
    * insert_lv1_lv2.py. This is just a convenience script I made to take a modified, re-signed lv1.self and lv2_kernel.self, and automatically create a PUP which is identical to an original PUP except for those two files.
    * lv1dumper. This is an application which runs on the PS3 that you can compile and package using PSL1GHT and geohot’s tools. After running it, lv1 will be mapped at 0x8000000014000000 with read/write access, and you will be able to poke lv2 without the system shutting down. It disables the new lv2 memory hashing feature Sony added to 3.55 (probably to stop future USB jailbreaks).

    lv1dumper requires that some patches to lv1 and lv2 are already in place. I’ll describe how to add these patches. They have been tested but I cannot guarantee that they won’t brick your PS3. Do not do this unless you’re comfortable with that.

    Firstly, you need to extract the decrypted code segments from lv1.self and lv2_kernel.self (just use unself and copy them directly out of the ELF), and make the following changes to to them, assuming you’re using 3.55:

    * lv1_undocumented_function_114 in lv1 must be patched so that it can be used to map any area of real memory. graf_chokolo found this trick months ago, but it still applies here. Patch the byte at D5A47 from 00 to 01 (2D5A47 if you’re looking for it in IDA).
    * You then need to add peek and poke to lv2. Patch 1933C to E8 63 00 00 60 00 00 00 and 19348 to F8 83 00 00 60 00 00 00.

    You can then use resign_self.py to re-insert your patched code segment back into the self. You’ll firstly need to change a few bytes in some useless strings because of the way zlib deflate works; the script will tell you what to do. I found that changing strings was the easiest way to do this, it just takes a bit of trial and error.

    Finally, use insert_lv1_lv2.py to create your modified PUP. You’ll need to update to the PUP, then install geohot’s jailbreak PUP over the top of it. If you’ve done everything right, lv1dumper should just exit after you run it and you’ll have r/w access to lv1 and lv2 (peek and poke). The lv1_peek, lv1_poke, lv2_peek and lv2_poke functions in lv1dumper show how to use that access.

    I’m hoping that some interesting and innovative stuff can come out of this, and maybe we can start to see ‘unofficial’ apps enjoying the same success on the PS3 that they do on the iPhone.

    Source:
    Flukes1
    Comments 40 Comments
    1. rrrboy159's Avatar
      rrrboy159 -
      for noobs who do not read all of the post this WILL LEAD TO Backup managers by other devs the tools itself doesnt BTW first one to COMMENT
    1. Erikas Nu's Avatar
      Erikas Nu -
      thanks rrboy159 post more useful than that one above
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Considering on what could of happened to Geohot and Flowpoision

      NOOBS!!!

      I dont think there will ever be a backup manager for 3.55

      and we all know (Lord Sony) Will Update the ps3 to 4. whatever for the newer games...

      so think of it as a good run and better stick to 3.41
    1. johnpod1's Avatar
      johnpod1 -
      at the top it says"flukes1 had successfully modified LV2 to allow full backup manager playback earlier this week. However, due to legal reasons, he decided not to release his modifications."

      Read more: PSGroove.com - Flukes1 LV1 LV2 Peek and Poke Tools Released http://psgroove.com/content.php?650-...#ixzz1BEiV0g1i

      so they have made it happen just wont release it??
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Quote Originally Posted by johnpod1 View Post
      at the top it says"flukes1 had successfully modified LV2 to allow full backup manager playback earlier this week. However, due to legal reasons, he decided not to release his modifications."

      Read more: PSGroove.com - Flukes1 LV1 LV2 Peek and Poke Tools Released http://psgroove.com/content.php?650-...#ixzz1BEiV0g1i

      so they have made it happen just wont release it??

      yeah I read it but thats why i said that there will never be a backup manager... (for the public) he has his up and running but he isnt going to but his hide on the line for the public...

      Nobody wants to be sued bro

      Sony still and will always carry the big guns

      No dev is that crazy to release a backup manager and at the same time just happen go anonymous

      If i was a dev sure i will have a back up manager running but i will never release it for 2 reasons

      1. Sony will hunt me down and sue me to a pulp

      2. I would charge people for it and then sony will hunt me down and sue me to a pulp and add extortion :S
    1. xdslx's Avatar
      xdslx -
      not releasing back up manager just protects the dongle sellers , and this is fun , somebody protects the dongle sellers
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Workin on a firmware patch now =P

      Im paranoid so if I make it work no release
    1. bandito22's Avatar
      bandito22 -
      Backup Managers will be running by the end of the week.

      If they worked on 3.41 regardless of any comeback from Sony, they will be doing the same on 3.55. Creating or using a Backup Manager is not illegal in itself, anymore that making a DVD recorder is illegal. It's what you use it for that determines if you are breaking any laws.

      It should be pretty straightforward for Sony to block online play via PSN so that will moderate some of the piracy.
    1. ShadowG-PSG's Avatar
      ShadowG-PSG -
      there is always someone around ready to take the risky... sooner or later it will come out...
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Quote Originally Posted by ShadowG View Post
      there is always someone around ready to take the risky... sooner or later it will come out...
      Im workin on a patch now but Im sure as hell not releasing it. I cant afford a lawyer
    1. frosttool's Avatar
      frosttool -
      don't waste our time telling every one you've done it with out proof and if you so worried dont tell any one your suppose to release it anonymously on a warez site such as katz with and use an ip scrambler to protect your self and not getting our hopes up of false hope don't be a Pansie heck if you gave me the files i cold have some friends in chin and in the Philippines take a look at it and have him send the file out for you or i could i dont care if Sony knocks on my door they can go back to japan and bug someone else its bad enough they take all our money and we get nothing back besides downgrades
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Quote Originally Posted by frosttool View Post
      don't waste our time telling every one you've done it with out proof and if you so worried dont tell any one your suppose to release it anonymously on a warez site such as katz with and use an ip scrambler to protect your self and not getting our hopes up of false hope don't be a Pansie heck if you gave me the files i cold have some friends in chin and in the Philippines take a look at it and have him send the file out for you or i could i dont care if Sony knocks on my door they can go back to japan and bug someone else its bad enough they take all our money and we get nothing back besides downgrades

      Im a noob at this, by the time Im done, I guarentee there will be a million pnp lv1/2 patches out made by these tools. I doupt Ill even be sucessful >.>
    1. frosttool's Avatar
      frosttool -
      my skype is frosttool and my msn is frosttool i do not and will not use twiter let me know if your willing to share just make shure you did not leave any trace of you in the files you made wait till geo hot gets out of Cort to find out the out come even if its bad ill still release the files sony needs to know that they have already lost just like ww2
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Quote Originally Posted by frosttool View Post
      don't waste our time telling every one you've done it with out proof and if you so worried dont tell any one your suppose to release it anonymously on a warez site such as katz with and use an ip scrambler to protect your self and not getting our hopes up of false hope don't be a Pansie heck if you gave me the files i cold have some friends in chin and in the Philippines take a look at it and have him send the file out for you or i could i dont care if Sony knocks on my door they can go back to japan and bug someone else its bad enough they take all our money and we get nothing back besides downgrades
      true ... but do you know how much money is involved in something like this?

      why do you think the people who are selling the dongles are cashing in? and they are the ones with the backup managers running??

      hacking isnt free... and who doesnt want to cash in on the 3.55 jailbreak with backup manger but at the same time why even bother

      sony or i should say (lord sony) will just update and update... keys or not.. they will make the game harder to play on a backup.. and those pkg whatever files isnt doing any good...

      Sony always carry the bigger gun... and last time I check... reason Geohot and FailOverFlow isnt being sued is because of the backup managers

      If he released a fully functional backup manager do you really think he will be on g4?
    1. digidolcymru's Avatar
      digidolcymru -
      I would never trust flukes1 work anyway,not a very well know dev as far as i'm aware.Surly there will be a 3.55 BM which will proberly be released 2morro or the next day as there are thousands of devs who will post the working BM anon.The ps3 is totally wide open,so why would they stop now,just cause one person has decided not to release is working BM,
      Guarenteed soon as someone anon or someone who dont mess the public around releases a working 3.5BM flukes1 will want all the praise.I still dont understand why release a 3.55CFW if your not going to go through with releasing the working BM,seems like he tried to get everyone on his cfw3.55 to **** them around..........................................ST RANGE I THINK,sounds like the work of sony 2 me.luckily kakaroto came up with downgrader for peeps with fat console,but peeps with slims are still ****ed.anyone agree?
    1. frosttool's Avatar
      frosttool -
      don't let them scare us like this there are more of us then sony can handle and more computers they they can stop other wise they will win plz don't let them win
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Quote Originally Posted by digidolcymru View Post
      I would never trust flukes1 work anyway,not a very well know dev as far as i'm aware.Surly there will be a 3.55 BM which will proberly be released 2morro or the next day as there are thousands of devs who will post the working BM anon.The ps3 is totally wide open,so why would they stop now,just cause one person has decided not to release is working BM,
      Guarenteed soon as someone anon or someone who dont mess the public around releases a working 3.5BM flukes1 will want all the praise.I still dont understand why release a 3.55CFW if your not going to go through with releasing the working BM,seems like he tried to get everyone on his cfw3.55 to **** them around..........................................ST RANGE I THINK,sounds like the work of sony 2 me.luckily kakaroto came up with downgrader for peeps with fat console,but peeps with slims are still ****ed.anyone agree?
      flukes1's tools always work well. Not has big as GH or fail0verflow, there work is always top notch
    1. frosttool's Avatar
      frosttool -
      it does not take some one very well know its better not to be well know other wise you end up in cort like geohot your not suppose to give out you're code name with your real name if sony went thro my hose right now i wold be in trouble wit many different companies as wold another million others
    1. barrons-PSG's Avatar
      barrons-PSG -
      im going to say by friday someone who is a complete legend will have one they are willing to share!?!?!?
    1. frosttool's Avatar
      frosttool -
      i wold if i had working files
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    Foster182

    Updating to rogero 4.40 cfw, will i lose remarry drive?????

    Thread Starter: Foster182

    Simple question but haven't found any info on it, if i upgrade from 3.55cfw - 4.40 cfw, is there any chance i will lose my remarried drive?
    Its

    Last Post By: pinkfloydviste Today, 07:50 PM Go to last post
    chicagouno

    WTS: Call of Duty: Black Ops 2 PS3 Game

    Thread Starter: chicagouno

    Up for sale is my Call of Duty: Black Ops 2 PS3 Game. The game has been played only a hand full of times. My PS3 got the YLOD so I have no need for

    Last Post By: chicagouno Today, 07:24 PM Go to last post
    teepo

    PS3 Hard Drive Read?

    Thread Starter: teepo

    I was wondering if there are any ways to view an OFW ps3's hard drive from either linux/windows?

    I've read that the ps3 encrypts the drive

    Last Post By: BahumatLord Today, 03:32 PM Go to last post
    bhek

    Help me install HDD on Sony PlayStation 2 Slim NTSC-J SCPH-70xxx

    Thread Starter: bhek

    Hi I'm just new here and new in ps2 HDD installation, i bought a 2nd Sony PlayStation 2 Slim NTSC-J SCPH-70xxx and i wanted to install hdd. Can someone

    Last Post By: amp2006 Today, 01:28 PM Go to last post
    Rikrik

    Progskeet 1.2

    Thread Starter: Rikrik

    Hi,

    I'm having some trouble with my progskeet 1.2. I'm hoping anyone here has a solution because i can't find much on the internet.

    Last Post By: Rikrik Today, 04:25 PM Go to last post
    snowkid1995

    PS2 Slim problem.

    Thread Starter: snowkid1995

    Hello guys,

    i have replaced laser unit in my PS2 Slim... everything went fine until i wanted to play game (disk is little bit scratched but

    Last Post By: snowkid1995 Today, 06:27 AM Go to last post
  • Recent Comments

    lunacryed

    Super Pixel Jumper v1.2 by ThatOtherPerson

    cool game thanks ThatOtherPerson Go to last post

    lunacryed Today 06:33 PM
    aldostools

    {Update #1} Rogero's CFW 4.40 v1.02 Released

    exofreak please post a link of your "mod" or share it in the official thread at ps3crunch

    A... Go to last post

    aldostools Today 06:15 PM
    JOshISPoser

    Super Pixel Jumper v1.2 by ThatOtherPerson

    guess who won for may's contest :p

    looks like a great lil game, especially for drinking Go to last post

    JOshISPoser Today 03:32 PM
    worrorfight

    Super Pixel Jumper v1.2 by ThatOtherPerson

    This looks great ThatOtherPerson thanks for your hard work. :) Go to last post

    worrorfight Today 02:54 PM
    Mathematician

    Super Pixel Jumper v1.2 by ThatOtherPerson

    I've played this game for the wii port so many times. I remember getting a ridiculous high score.... Go to last post

    Mathematician Today 01:01 PM
    STLcardsWS

    Super Pixel Jumper v1.2 by ThatOtherPerson

    How to place a Vote



    http://img716.imageshack.us/img716/9273/psxscenecontesttute.gif Go to last post

    STLcardsWS Today 12:45 PM
    JOshISPoser

    CFW 4.40 MiralaTijera - Update 4: System Manager 1.1 & 3.2.0 Integrated Core + qaflag

    oh man, i hope that feature alone gets put in other firmwares. it took me a long ass time to figure... Go to last post

    JOshISPoser Today 11:20 AM
    exofreak

    {Update #1} Rogero's CFW 4.40 v1.02 Released

    hi all. i have been on this fourm for a while now so i am no guest.
    anyways, i wanted to ask some... Go to last post

    exofreak Today 09:41 AM
    Tranced

    CFW 4.40 MiralaTijera - Update 4: System Manager 1.1 & 3.2.0 Integrated Core + qaflag

    I'm really liking the no sleep implementation. Some games will not run on my 2TB external. Go to last post

    Tranced Today 09:04 AM
    ppr2012

    BwE NOR Validator 1.28 -- Final Version?

    pls can any1 help!! i used this app to validate my 2dumps when taken on k3.55 with mm before... Go to last post

    ppr2012 Today 08:54 AM