PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Mathieu Explains 3.60 Exploit - Will Lead to Application Keys and Eventually 3.60 CFW

    The cats out of the bag, after many subtle hints, Mathieu explains his exploit and how it will lead to application keys. With the help of this loader exploit, devs can now obtain the Bootloader keys which will lead to the Application keys and eventually, a 3.60 CFW! With application keys, Portal 2 and future 3.60 encrypted games may soon be playable!
    Synopsis of Mathieu's explanation of the exploit:
    The function that copies the SCE header from the shared LS to the isolated Local Store doesn’t check the header’s size.

    [So] you craft a self with a HUGE header so [that] it overwrites ldr code as it gets copied to the isolated LS and you wait [for] the loader to jump to it.

    [Then] you can get lv0 decrypted, once you get lv0 decrypted, you get appldr, once you get appldr, you get 3.60 application keys, [and] once you get that, you [get] warez.


    Mathieu's full conversation regarding the exploit:

    X nah, not a single line of code, at least not for the implementation
    but finding the exploit itself
    is EASY
    except no one has gone looking
    I’ve seen lots of askings and whining, very little looking xD
    if someone who remotely knows spu reversing starts looking
    he’ll find it
    at the very worse in a matter of hours
    the bug is ******ly stupid to begin with
    LV0, EID0, anything with coreOS imo should not be done without a hardwareflasher. Atleast with that you can undo the mess.
    yeah
    I am a bit of a red head here xD
    you keep saying that, but I suck at SPU assembly
    you’d find it even if you fail at it
    you just need to know where to look
    just look at how selfs are processed by ldrs
    and you’ll find it
    hell, I’ll help you, it’s about overflowing a certain buffer
    yes, that is what defyboy and I tried to document in the ps3devwiki : bootprocess and loader locations etc.
    well if you know how selfs are processed by loaders, it’s easy
    another hint
    it happens before the ecdsa check
    my earlier guess btw was that it was a header overflow, which gave access to the local storage
    It’s a ******ed exploit
    if you want to know what it is, I’ll tell you
    the function that copies the SCE header from the shared LS to the isolated Local Store
    doesn’t check the header’s size
    \o/
    it’s just THAT ******ed
    implementing it isn’t easy though
    cause loaders have failsafes and ****
    header size fail
    lol
    ?
    but now that you know, you can try it on your own
    X1 yes
    you craft a self with a HUGE header
    so it overwrites ldr code as it gets copied to the isolated LS
    and you wait the loader to jump to it
    lolol must try heh
    X1 it’s a total ***** to implement
    but feel free xD
    if someone pwns the bl with this and gets the keys, he’ll have my kudos
    cause finding the exploit is the easy part
    Sony’ll fix it now, but it’s not like I care much
    their “unhackable” ps3s are probably already on the way
    Mathieu explains the impact the exploit/keys have on Sony:

    why would they care about bootldr keys?
    ps3devnews etc. host metldr keys, appldr keys etc.
    X1 cause you can get lv0 decrypted
    once you get lv0 decrypted
    you get appldr
    once you get appldr
    you get 3.60 application keys
    once you get that
    you warez
    also, with those keys you can sign your own lv0, no ps3 fw update can beat you then
    yah
    you can have your 3.60+ custom firmware then
    and warez even more
    and mess with the psn again
    and so on
    Source: PS3Church
    Comments 65 Comments
    1. MadnessImport's Avatar
      MadnessImport -
      "once you get appldr
      you get 3.60 application keys
      once you get that
      you warez
      also, with those keys you can sign your own lv0, no ps3 fw update can beat you then
      yah
      you can have your 3.60+ custom firmware then
      and warez even more"
      Ok I laughed till i barfed

      ANYTHING Turkish will say is only Gona make me laugh harder if he post's here because ill agree

      its becoming nothing but piracy these days
    1. DG_Legend-PSG's Avatar
      DG_Legend-PSG -
      Wasn't it also said that CFW 3.55 wasn't be able to be patched by a firmware update, cause we found the "keys", yet Sony patched it with 3.56 . I'm not trying to sound too demanding, but what guarantee do we have this time 'round?
    1. Arnaud Cohen Scali's Avatar
      Arnaud Cohen Scali -
      MatNooblh should stop talking and release something. this guy is boring
    1. happyface-PSG's Avatar
      happyface-PSG -
      AWESOME AWESOME! IVE BEEN REFREASHING SINCE THE RELEASE OF PORTAL 2 HOPING FOR THIS KIND OF GOOOOOD NEWS. YES! Mathieu YOU ARE THE FUKIN MAN!
    1. PHPMyPS3's Avatar
      PHPMyPS3 -
      Mathieu is not very intelligent. Basically he tells the PS3 developpers what to do to prevent the 3.60 security from being broken. Well I don't even think Mathieu found an exploit this guy is ALL TALK.
    1. Storm Respect's Avatar
      Storm Respect -
      Quote Originally Posted by PHPMyPS3 View Post
      Mathieu is not very intelligent. Basically he tells the PS3 developpers what to do to prevent the 3.60 security from being broken. Well I don't even think Mathieu found an exploit this guy is ALL TALK.
      At least he is trying
    1. One2thr456svn's Avatar
      One2thr456svn -
      Quote Originally Posted by Arnaud Cohen Scali View Post
      MatNooblh should stop talking and release something. this guy is boring
      Man the only thing that is boring is people coming on here stating that the scene is this or that, or asking someone else to release something, If Math didn't release anything I would not blame him, cause it seems that the majority of people do is whine and complain without any addition to the movement at all, and If and I use the word "If" anything 3.60 get released, it would be a plus, but not a necessarily a major need. It would be cool just to hack it because $ony is actin like a spoiled baby. As for me I am comfortable with the 3.55, and no PSN. I am thankful for the work the guys put in, but seeing how $ony is ******g with everybody if you do release it, just be safe about it.....
    1. Kingj13-PSG's Avatar
      Kingj13-PSG -
      Keep up the good work guys can't wait to give portal 2 a run.
    1. Cagutinho's Avatar
      Cagutinho -
      Its not just about piracy. But without a cfw 3.60, if you want homebrews you cannot play 3.60 games (like Portal 2), original game or not.

      So, if you people want more support at homebrews, will have to accept the 3.60cfw with open arms, because if it does not come to us, people will start to give up the homebrews in a choice to play new games, and so, consequently, the homebrew support will decrease.

      Lots of people want something more solid or stable, that can allow us to play all the titles of PS3, and also use homebrews (like emulators). PSN is not important... but I cant see advantages in give up tons of new games (like Portal 2, and so much more that will come from now) just to use some homebrews, so the scene starts do "die".
    1. STALKER's Avatar
      STALKER -
      GOOD WORK, Show sony What can we do !!!
    1. Lestat-PSG's Avatar
      Lestat-PSG -
      This is taking too long. By the time they release this Sony will have 3.61 and we will have to start all over again. With geohot down already, Seems to me that Sony has already won.
    1. NulVoid's Avatar
      NulVoid -
      For those of you complaining read this
      I’ve seen lots of askings and whining, very little looking xD
      if someone who remotely knows spu reversing starts looking
      he’ll find it
      if you want to help out go to this link:

      http://www.ps3news.com/forums/ps3-li...in-112032.html
    1. NulVoid's Avatar
      NulVoid -
      If anyone want to complain read this

      I’ve seen lots of askings and whining, very little looking xD
      if someone who remotely knows spu reversing starts looking
      if you don't know spu reversing look here:

      http://www.ps3news.com/forums/ps3-li...in-112032.html
    1. richguas1970's Avatar
      richguas1970 -
      Its funny how people can complain so much, even when bones are thrown at them.. rofl.. I guess its hard for some kiddies to be humble and thankful for what is freely given.. Lets be honest, piracy is an uncontrollable force SONY will never silence..
      I mean, did Microsoft.. lol

      CFW and homebrew is the PS3 scene..
      I still support idea of multi-booting the PS3, as it might solve most of our woes..
      A PS3 OFW/PS3 CFW/ LINUX.. wow, What a lustrous PS3 to have..
    1. houdrummer's Avatar
      houdrummer -
      Quote Originally Posted by richguas1970 View Post
      I still support idea of multi-booting the PS3..
      I do too. I would rather have 3.55 cfw and 3.60 ofw on the same machine than a 3.60 cfw.
    1. DGPRodiGY-PSG's Avatar
      DGPRodiGY-PSG -
      Quote Originally Posted by DG_Legend View Post
      Wasn't it also said that CFW 3.55 wasn't be able to be patched by a firmware update, cause we found the "keys", yet Sony patched it with 3.56 . I'm not trying to sound too demanding, but what guarantee do we have this time 'round?
      Shut up you ugly noob, no one likes you, cut (:
    1. rrrboy159's Avatar
      rrrboy159 -
      First of all, Math, doesnt have to release anything. If he has the keys or doesnt have the keys. If he has the method or not. UNDER ANY CIRCUMSTANCE HE DOES NOT HAVE TO RELEASE ANYTHING.
      Second, there is no real point of 3.60 CFW. The only reason we would need it is psn. ONLY REASON. NOthin more nothing less. There are no more excuses.
      When SOny came out with 3.56 or 3.60, no body should have updated in the first place. Even if it was on "accident" or if my "brother" did it or if my "stupid dog got an erection and hit X on the controller" NO MORE EXCUSES
      For the people who bought their ps3 on 3.56 or 3.60, can't say anything about that.
      The keys would be helpful for Portal 2 and future games, but wats the point. If your not pirating you would buy the game. And when you do youll have the disk. So you could play it. There the end.
    1. richguas1970's Avatar
      richguas1970 -
      Chop away the impossible, what is left exposed is the probable.. There is nothing that cannot be undone and rewritten.. For anyone to say that its HACKproof, lol, they are truly noobs..

      Multi booting the PS3 is the answer in my opinion.. GO on the PSN with PS3OFW, homebrew and Multiman with CFW, and finally LINUX for those who bought it for that particular reason.. This way its all legal..
    1. PHPMyPS3's Avatar
      PHPMyPS3 -
      Quote Originally Posted by Cagutinho View Post
      the scene starts do "die".
      I agree not only will the new games use 3.60 but on top of that Sony will start distributing new PS3s with 3.60 preinstalled (and possibly new hardware protection) and the scene will die a slow death. Geohot gave his arse to Sony by accepting to stop hacking the PS3, Mathieulh is all talk, Graf_Chokolo is in legal trouble.

      When ofw 3.60 came out, Mathieulh claimed that the new PSN protocol was "easy" to hack. Well we're still waiting for someone to do it.
    1. ki11m3please's Avatar
      ki11m3please -
      Quote Originally Posted by Lestat View Post
      This is taking too long. By the time they release this Sony will have 3.61 and we will have to start all over again. With geohot down already, Seems to me that Sony has already won.
      no one is winning anything...
      oh yay im a hacker i hacked ps3 ofw 3.60.. do i get millions of dollars??.. no not rly.. sry..
      and sony.. they are spending a ton on updates.. that ***** not free man.. and court battles tons of cash..
      no one is winning a damn thing!! lol

      If anything.. everyone is losing..
      but if i picked a team to go with it would be the hacker/crackers.. because!
      they put hard work in to this.. for thousands of people..
      and get yelled at for not getting somthing out on time or not at all...
      INFOINFO FOR EVERYONE!!!!!
      THEY ARE DOING THIS FOR NOTHING! DONT PUSH! AND DONT B'TCH.. THANK YOU..
      AND THANK THESE GUYS EVERYDAY FOR THIS.. BECAUSE WITH OUT THEM WE WOULD NOT
      HAVE GOTTEN THIS FAR BY ANY MEANS.. GOOD DAY TO YOU!

      as for everything.. im happy with 3.55 i run supernintendo and other emulators..
      i also would be happy to see a dual boot happen..
      i bought another ps3 just for portal 2 and future games.
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    HyoImowano

    Rebug 4.41 and PS Vita Content Manager Problem

    Thread Starter: HyoImowano

    My PS3 is on Rebug 4.41, Vita is on latest OFW. Every time I attempt to connect them the PS3 crashes forcing me to unplug it from the wall in order to

    Last Post By: HyoImowano Today, 12:23 AM Go to last post
    HyoImowano

    Rebug 4.41 and PS Vita Content Manager Problem

    Thread Starter: HyoImowano

    My PS3 is on Rebug 4.41, Vita is on latest OFW. Every time I attempt to connect them the PS3 crashes forcing me to unplug it from the wall in order to

    Last Post By: HyoImowano Today, 12:22 AM Go to last post
    atreyu187

    Help replacing PSID on 4.41 using software

    Thread Starter: atreyu187

    So I got a new PSID and I am trying to install using PS3ita v0.2 and it can't read the file and gives a error "Anything could have happened"

    Last Post By: atreyu187 Yesterday, 10:50 PM Go to last post
    daddyfredregill

    OPL frozen

    Thread Starter: daddyfredregill

    I successfully installed fmcb and all is running well, until now. I put in my internal hard drive and the network adapter, booted up HD loader, formatted

    Last Post By: RandQalan Yesterday, 10:52 PM Go to last post
    blahman179

    MArvel Vs Capcom 2 Music Hacking Guide?

    Thread Starter: blahman179

    LSS;

    Just got MVC2, and I'd like to rip it to an ISO and replace the crappy Muzak with my own music, then load it onto my HDD.

    Last Post By: blahman179 Yesterday, 10:12 PM Go to last post
    Cza102282

    reactPSN v2.26 booting back to XMB and not rebooting?

    Thread Starter: Cza102282

    I can verify these things...

    -using REBUG 4.30.2
    -using reactPSN v2.26
    -/dev_hdd0/home/0000xx/exdata has act.dat, act.key,

    Last Post By: Cza102282 Yesterday, 10:09 PM Go to last post
  • Recent Comments

    owen420

    PSIO Team Update To Project PlayStation Input Output - A PS1 SD Card Hack

    yeah it seems its only for the 1000's series..... the 2000-9000 did not have that port, so kinda... Go to last post

    owen420 Today 12:31 AM
    andre104623

    PSIO Team Update To Project PlayStation Input Output - A PS1 SD Card Hack

    Its 15 years to late for this if this came out in 98 i would have bought it. I still have my ps1... Go to last post

    andre104623 Today 12:12 AM
    STLcardsWS

    PSChannel receives some Eye Candy from Opium2k

    Well lets throw some easy some dre and add some ice


    ... Go to last post

    STLcardsWS Today 12:07 AM
    bitsbubba

    PSChannel receives some Eye Candy from Opium2k

    Dre's ok but he will never be Eazy Go to last post

    bitsbubba Yesterday 11:50 PM
    tthousand

    PSChannel receives some Eye Candy from Opium2k

    Well then, it looks like you and no one it is. I wonder what other themes no one has done, I have... Go to last post

    tthousand Yesterday 11:35 PM
    opium2k

    PSChannel receives some Eye Candy from Opium2k

    Good song.
    Unfortunately I don't think making guides/tutorials will help. I've made a couple in... Go to last post

    opium2k Yesterday 11:25 PM
    tthousand

    PSChannel receives some Eye Candy from Opium2k

    I think something sour went down with deroad and no one. And everybody acts like they forgot about... Go to last post

    tthousand Yesterday 10:52 PM
    tthousand

    Pointman: The Akkadian Wars - Homebrew Game by Condorstrike

    When can I buy the game? And does it come with a limited edition, with things such as behind the... Go to last post

    tthousand Yesterday 10:46 PM
    condorstrike

    Pointman: The Akkadian Wars - Homebrew Game by Condorstrike

    Here's a better video so people can have an idea of what it looks like, sorry video editing is not... Go to last post

    condorstrike Yesterday 10:29 PM
    atreyu187

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    Sorry not home yet but I promise I will post back. Go to last post

    atreyu187 Yesterday 10:18 PM