PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Flukes1 LV1 LV2 Peek and Poke Tools Released

    Earlier this week, a developer by the name of flukes1 had successfully modified LV1/LV2 to allow full backup manager playback. However, due to legal reasons, he decided not to release his modifications. Today, he has decided to release the tools that led to his modifications, so other budding developers can give it a shot. Please note these are not for the average user, strictly for developers.

    Download: tools.zip

    As you may know if you’ve been following my progress, last week I took a short break from Wi-Fi Sync to look at the PS3 and how it works behind the scenes. The PS3 homebrew scene is currently at a point where you can install userland packages, such as FTPDs and SNES emulators, but you still don’t have any access to the hypervisor or GameOS kernel. It’s still very much a closed system.

    As an iPhone developer with an app on Cydia, I can see great potential within the PS3. It’s crying out for a decent package manager, but you need OS-level access to do that effectively. Unlocking the PS3 in this way has other benefits too; the system can effectively be modified in any way you wish.

    So today I’m releasing three tools which open the PS3’s hypervisor (lv1) and GameOS (lv2) to full read/write access from packaged userland applications. These tools can be used to create and test lv1/lv2 patches in RAM, which negates the risk of bricking your PS3 by flashing it with an incorrectly patched lv1 or lv2 binary. You can also use the tools to create a patched lv1 or lv2 binary, if you wish, although I suggest thoroughly testing your patches in-memory first.

    I will make a few things clear before continuing: I do not condone piracy and these tools DO NOT enable copied games to run on the PS3. Again: these tools will not allow backup managers to suddenly start working on firmware 3.55. The tools are packaged in source code form and do not include any Sony code or other Sony assets such as encryption keys. If you’re not a developer, these tools will be useless to you, so please do not try to use them. They are made available with no implied warranty of fitness for a particular purpose.

    Three tools are being made available today:

    * resign_self.py. This allows you to automatically replace any segment within a self and re-sign the self so the signatures and hashes are all valid again. Similar to makeself, but it is more suited towards patching lv1 and lv2 (and has been tested for this purpose).
    * insert_lv1_lv2.py. This is just a convenience script I made to take a modified, re-signed lv1.self and lv2_kernel.self, and automatically create a PUP which is identical to an original PUP except for those two files.
    * lv1dumper. This is an application which runs on the PS3 that you can compile and package using PSL1GHT and geohot’s tools. After running it, lv1 will be mapped at 0x8000000014000000 with read/write access, and you will be able to poke lv2 without the system shutting down. It disables the new lv2 memory hashing feature Sony added to 3.55 (probably to stop future USB jailbreaks).

    lv1dumper requires that some patches to lv1 and lv2 are already in place. I’ll describe how to add these patches. They have been tested but I cannot guarantee that they won’t brick your PS3. Do not do this unless you’re comfortable with that.

    Firstly, you need to extract the decrypted code segments from lv1.self and lv2_kernel.self (just use unself and copy them directly out of the ELF), and make the following changes to to them, assuming you’re using 3.55:

    * lv1_undocumented_function_114 in lv1 must be patched so that it can be used to map any area of real memory. graf_chokolo found this trick months ago, but it still applies here. Patch the byte at D5A47 from 00 to 01 (2D5A47 if you’re looking for it in IDA).
    * You then need to add peek and poke to lv2. Patch 1933C to E8 63 00 00 60 00 00 00 and 19348 to F8 83 00 00 60 00 00 00.

    You can then use resign_self.py to re-insert your patched code segment back into the self. You’ll firstly need to change a few bytes in some useless strings because of the way zlib deflate works; the script will tell you what to do. I found that changing strings was the easiest way to do this, it just takes a bit of trial and error.

    Finally, use insert_lv1_lv2.py to create your modified PUP. You’ll need to update to the PUP, then install geohot’s jailbreak PUP over the top of it. If you’ve done everything right, lv1dumper should just exit after you run it and you’ll have r/w access to lv1 and lv2 (peek and poke). The lv1_peek, lv1_poke, lv2_peek and lv2_poke functions in lv1dumper show how to use that access.

    I’m hoping that some interesting and innovative stuff can come out of this, and maybe we can start to see ‘unofficial’ apps enjoying the same success on the PS3 that they do on the iPhone.

    Source:
    Flukes1
    Comments 40 Comments
    1. rrrboy159's Avatar
      rrrboy159 -
      for noobs who do not read all of the post this WILL LEAD TO Backup managers by other devs the tools itself doesnt BTW first one to COMMENT
    1. Erikas Nu's Avatar
      Erikas Nu -
      thanks rrboy159 post more useful than that one above
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Considering on what could of happened to Geohot and Flowpoision

      NOOBS!!!

      I dont think there will ever be a backup manager for 3.55

      and we all know (Lord Sony) Will Update the ps3 to 4. whatever for the newer games...

      so think of it as a good run and better stick to 3.41
    1. johnpod1's Avatar
      johnpod1 -
      at the top it says"flukes1 had successfully modified LV2 to allow full backup manager playback earlier this week. However, due to legal reasons, he decided not to release his modifications."

      Read more: PSGroove.com - Flukes1 LV1 LV2 Peek and Poke Tools Released http://psgroove.com/content.php?650-...#ixzz1BEiV0g1i

      so they have made it happen just wont release it??
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Quote Originally Posted by johnpod1 View Post
      at the top it says"flukes1 had successfully modified LV2 to allow full backup manager playback earlier this week. However, due to legal reasons, he decided not to release his modifications."

      Read more: PSGroove.com - Flukes1 LV1 LV2 Peek and Poke Tools Released http://psgroove.com/content.php?650-...#ixzz1BEiV0g1i

      so they have made it happen just wont release it??

      yeah I read it but thats why i said that there will never be a backup manager... (for the public) he has his up and running but he isnt going to but his hide on the line for the public...

      Nobody wants to be sued bro

      Sony still and will always carry the big guns

      No dev is that crazy to release a backup manager and at the same time just happen go anonymous

      If i was a dev sure i will have a back up manager running but i will never release it for 2 reasons

      1. Sony will hunt me down and sue me to a pulp

      2. I would charge people for it and then sony will hunt me down and sue me to a pulp and add extortion :S
    1. xdslx's Avatar
      xdslx -
      not releasing back up manager just protects the dongle sellers , and this is fun , somebody protects the dongle sellers
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Workin on a firmware patch now =P

      Im paranoid so if I make it work no release
    1. bandito22's Avatar
      bandito22 -
      Backup Managers will be running by the end of the week.

      If they worked on 3.41 regardless of any comeback from Sony, they will be doing the same on 3.55. Creating or using a Backup Manager is not illegal in itself, anymore that making a DVD recorder is illegal. It's what you use it for that determines if you are breaking any laws.

      It should be pretty straightforward for Sony to block online play via PSN so that will moderate some of the piracy.
    1. ShadowG-PSG's Avatar
      ShadowG-PSG -
      there is always someone around ready to take the risky... sooner or later it will come out...
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Quote Originally Posted by ShadowG View Post
      there is always someone around ready to take the risky... sooner or later it will come out...
      Im workin on a patch now but Im sure as hell not releasing it. I cant afford a lawyer
    1. frosttool's Avatar
      frosttool -
      don't waste our time telling every one you've done it with out proof and if you so worried dont tell any one your suppose to release it anonymously on a warez site such as katz with and use an ip scrambler to protect your self and not getting our hopes up of false hope don't be a Pansie heck if you gave me the files i cold have some friends in chin and in the Philippines take a look at it and have him send the file out for you or i could i dont care if Sony knocks on my door they can go back to japan and bug someone else its bad enough they take all our money and we get nothing back besides downgrades
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Quote Originally Posted by frosttool View Post
      don't waste our time telling every one you've done it with out proof and if you so worried dont tell any one your suppose to release it anonymously on a warez site such as katz with and use an ip scrambler to protect your self and not getting our hopes up of false hope don't be a Pansie heck if you gave me the files i cold have some friends in chin and in the Philippines take a look at it and have him send the file out for you or i could i dont care if Sony knocks on my door they can go back to japan and bug someone else its bad enough they take all our money and we get nothing back besides downgrades

      Im a noob at this, by the time Im done, I guarentee there will be a million pnp lv1/2 patches out made by these tools. I doupt Ill even be sucessful >.>
    1. frosttool's Avatar
      frosttool -
      my skype is frosttool and my msn is frosttool i do not and will not use twiter let me know if your willing to share just make shure you did not leave any trace of you in the files you made wait till geo hot gets out of Cort to find out the out come even if its bad ill still release the files sony needs to know that they have already lost just like ww2
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Quote Originally Posted by frosttool View Post
      don't waste our time telling every one you've done it with out proof and if you so worried dont tell any one your suppose to release it anonymously on a warez site such as katz with and use an ip scrambler to protect your self and not getting our hopes up of false hope don't be a Pansie heck if you gave me the files i cold have some friends in chin and in the Philippines take a look at it and have him send the file out for you or i could i dont care if Sony knocks on my door they can go back to japan and bug someone else its bad enough they take all our money and we get nothing back besides downgrades
      true ... but do you know how much money is involved in something like this?

      why do you think the people who are selling the dongles are cashing in? and they are the ones with the backup managers running??

      hacking isnt free... and who doesnt want to cash in on the 3.55 jailbreak with backup manger but at the same time why even bother

      sony or i should say (lord sony) will just update and update... keys or not.. they will make the game harder to play on a backup.. and those pkg whatever files isnt doing any good...

      Sony always carry the bigger gun... and last time I check... reason Geohot and FailOverFlow isnt being sued is because of the backup managers

      If he released a fully functional backup manager do you really think he will be on g4?
    1. digidolcymru's Avatar
      digidolcymru -
      I would never trust flukes1 work anyway,not a very well know dev as far as i'm aware.Surly there will be a 3.55 BM which will proberly be released 2morro or the next day as there are thousands of devs who will post the working BM anon.The ps3 is totally wide open,so why would they stop now,just cause one person has decided not to release is working BM,
      Guarenteed soon as someone anon or someone who dont mess the public around releases a working 3.5BM flukes1 will want all the praise.I still dont understand why release a 3.55CFW if your not going to go through with releasing the working BM,seems like he tried to get everyone on his cfw3.55 to **** them around..........................................ST RANGE I THINK,sounds like the work of sony 2 me.luckily kakaroto came up with downgrader for peeps with fat console,but peeps with slims are still ****ed.anyone agree?
    1. frosttool's Avatar
      frosttool -
      don't let them scare us like this there are more of us then sony can handle and more computers they they can stop other wise they will win plz don't let them win
    1. Alec von Kerritler's Avatar
      Alec von Kerritler -
      Quote Originally Posted by digidolcymru View Post
      I would never trust flukes1 work anyway,not a very well know dev as far as i'm aware.Surly there will be a 3.55 BM which will proberly be released 2morro or the next day as there are thousands of devs who will post the working BM anon.The ps3 is totally wide open,so why would they stop now,just cause one person has decided not to release is working BM,
      Guarenteed soon as someone anon or someone who dont mess the public around releases a working 3.5BM flukes1 will want all the praise.I still dont understand why release a 3.55CFW if your not going to go through with releasing the working BM,seems like he tried to get everyone on his cfw3.55 to **** them around..........................................ST RANGE I THINK,sounds like the work of sony 2 me.luckily kakaroto came up with downgrader for peeps with fat console,but peeps with slims are still ****ed.anyone agree?
      flukes1's tools always work well. Not has big as GH or fail0verflow, there work is always top notch
    1. frosttool's Avatar
      frosttool -
      it does not take some one very well know its better not to be well know other wise you end up in cort like geohot your not suppose to give out you're code name with your real name if sony went thro my hose right now i wold be in trouble wit many different companies as wold another million others
    1. barrons-PSG's Avatar
      barrons-PSG -
      im going to say by friday someone who is a complete legend will have one they are willing to share!?!?!?
    1. frosttool's Avatar
      frosttool -
      i wold if i had working files
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    opscript

    is there a jailbreak for 3.70 version?

    Thread Starter: opscript

    i dont have downgrade tools and i dont know if the "jailbreaks" that are online now are really make the work or there is still no any real support

    Last Post By: qwillis Today, 10:43 AM Go to last post
    Raeralus

    YLOD (Not what you think)

    Thread Starter: Raeralus

    About a month ago, my PS3 stopped working after I gave it quite a grilling by leaving it on for a full week while I was idling on the pause menu for Grand

    Last Post By: Raeralus Today, 10:08 AM Go to last post
    michellefland

    hello i am search code no random battle pal french code work please for suikoden 4 and 1 help my please thanks in advance

    Thread Starter: michellefland

    hello

    i am search code no random battle pal french code work please for suikoden 4 and 1 help my please thanks in advance

    Last Post By: michellefland Today, 07:27 AM Go to last post
    BahumatLord

    Showtime metadata is being read incorrectly

    Thread Starter: BahumatLord

    I use the movie db plugin for showtime that pulls up artwork and info on every movie. Most of the time it identifies movies correctly and will display

    Last Post By: BahumatLord Today, 06:49 AM Go to last post
    uaeboss616

    help me with turn off automatically:(

    Thread Starter: uaeboss616

    hello guys my problem is my ps3 turn off automatically after i downgrade my ps3 by e3 flasher and jailbroken my ps3 turn on 10 sec then turn off automatically

    Last Post By: fq360 Today, 07:17 AM Go to last post
    nova89

    Is it possible on ps3 add a radio station ?

    Thread Starter: nova89

    So I'm bored of the eflc sound track since massive b was removed I now only listen to electro choc and ever since gta iv was released I wanted msx fm

    Last Post By: ribonucleic Today, 10:06 AM Go to last post
  • Recent Comments

    brunolee

    {Guide} Install multiMAN Themes via a PKG File

    On PS3 THMs is a package for multiMAN themes, PKGs is a instalation package, put THMs in pkg only... Go to last post

    brunolee Today 11:02 AM
    Raeralus

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    Okay. I got it to stop exiting.

    I ran MultiMAN, from there I ran RT. Afterwards, I ran the... Go to last post

    Raeralus Today 10:43 AM
    Raeralus

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    I have a similar problem. When I set it at payload 2, with 0x70 (112), and press triangle, the... Go to last post

    Raeralus Today 10:36 AM
    krytonic

    Sony's Testing a Better, Faster Video Streaming Technology.

    Yeah testing a new service like this which is probably mainly being tested for the PS4 should have... Go to last post

    krytonic Today 09:39 AM
    atreyu187

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    I run OxCD due to me OCD disorder and it keeps my PS3 below 50 degrees Celsius. And when the light... Go to last post

    atreyu187 Today 08:48 AM
    jkoiou

    {Guide} How to make themes for multiMAN

    i don't have a lot of time to play around with this. can comeone try making a MM theme based on the... Go to last post

    jkoiou Today 07:50 AM
    bitsbubba

    {Guide} Install multiMAN Themes via a PKG File

    me neither really, isn't this a step backwards, I thought thm was a package file. why switch thm to... Go to last post

    bitsbubba Today 02:47 AM
    tnh531

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    Can anyone help, which setting is best for my phat ps3. i am a little confuse about the modes. Go to last post

    tnh531 Today 12:52 AM
    condorstrike

    {Guide} Install multiMAN Themes via a PKG File

    also, that was one of the tricks I used, to make Solar run by itself on a timer without user input... Go to last post

    condorstrike Yesterday 11:57 PM
    STLcardsWS

    {Guide} Install multiMAN Themes via a PKG File

    BahumatLord
    That what i usually use.

    Yea my bad its not the eboot, but there are requirements.... Go to last post

    STLcardsWS Yesterday 11:57 PM