As always please use caution when installing a new CFW. Its always better to wait if you are afraid of a possible brick, or do not have the means to recover from one.. If Spanish is not your native language or a language you understand that is more reason to take a bit of caution as some facts can get lost in translation. However it looks like this Developer has done some interesting things with this new CFW. Check below at the translated quote for more info & details about this new CFW.
You may ask what this is all about?.
Well itís about my CFW 4.31 FULL 4.31, nothing about spoofís. Itís ported to 4.31. And..
I give you along with the Os also my (personal) multiTOOL called ďcoreĒ itís only a self that loads at console startup.
If itís available on right USb port of our PS3 ď/dev_usb000/Ē that among other things this will allow to dump console flash.
Also activates QA flags (on 4.31 = directly) and exits and start on factory mode.
Here some specs:
- lv1 CoreOS hash deactivated for downgraded consoles.
- lv1 183/182 undocumented ( lv1 peek / poke )
- lv1 Otheros ++
- VSH: nas_plugin ( all pkgs can get installed , explore_plugin y game_ext plugin to show the install package and erase that annoying warning
- message of *epilepsy* (though this is automatic while with QA flag)
and patches VSH for rif / rap with fakesign.)
- default.spp: added that memory extra on gameOS for otherOs.
- lv2 peek / poke , syscall 6 / 7 ,
- v2 lv1 peek / poke ( opcional syscall 8 / 9 via core)
- Payload Hermes with ported SC 36
- APPLDR: lv2 memory hash desactived from appldr ( no need to patch on lv1 ) , dev_flash whitelist deactivated ( loads any keyset from dev_flash ) and ECDSA deactivated.
- ISOLDR : ECDSA deactivated
- SPP_VERIFIER: ECDSA deactivated
- spu_utoken_processor : ECDSA deactivated ( qa flag )
Here you have the payload to include on C for our managers with fixes and hook.
Private Paste - Pastie ( payload with sc36 )
Private Paste - Pastie (lv2 lv1 calls)
Now letís talk about = Core.
Itís AIO (all in one) tool. This CFW at startup search on dev_usb000 if theres a files called cellftp.self and other called copy_script.txt. Also i activated *search function* you can deactivate if you want so just doing this:
You have to put an original 4.31 sys_init_osd.self inside dev_flash/sys/internal/HERE and that will stop it for search it.
So i developed a homebrew called core, that allows to end user have more options and tools.
Remember though that the self has to be on your pen-drive root along with copy_script.txt and flags folder with the flags ( functions ) that you want inside.
When your PS3 starts up will search for it and execute it. It will leave a log on root called core.log.
I will mention the more important ones and tomorrow i will explain a little more:
BD emu flag = Is for if you donít have blu-ray drive or just donít work npdrm if you activate this flag, the PS3 will behave as if it have the drive installed.
Enableqa = Activates those QA flag directly on 4.31 ..
Dump full ram
Changelog: core 2.6.5 changelog 2.6.5: Added toggle_recovery flag = Warning PHAT wipe. Fixed 6 flags. Erased that epilepsy warning. Core 2.6.0 Changelog 2.6.0: aŮadida flag para limpiar restos de flagís de otheros ( usar en casos de problemas al entrar recovery ) Added flag to clean otherOS flagís ( use in case that you have problem to enter into recovery). Changelog 2.5.0: Added otherOS. Fixed dumpnandflash flag, now dumps bootloader also to have a full vital backup of your PS3. ============================ OtherOS boot Tutorial: 1) Start core only with setup_flash_for_otheros flag, when you hear a double beep means thatís the process went well. If you donít listened nothing = check log. 2) Then put dtbImage.ps3.bin (the one who corresponds to your CONSOLE) If itís Nand = dtbImage.ps3.bin.nand If itís NOR = dtbImage.ps3.bin.nor You have to rename it to = dtbImage.ps3.bin and paste it on the your pendrive root in this case we will use install_otheros flag. 3) This will boot up and you will hear 2 beeps, if you donít listened. Again, check the log. Something failed. 4) Once we done this, shutdown your PS3 and use boot_otheros flag. On boot you will see petitboot on your screen.
Thanks hermes, i used your cosunpkg and cospkg to align of CoreOs AND payload with sc36.
Links about all i mentioned above :
Private Paste - Pastie
Mirror thanks to ďpalestinaĒ mod431.rar (67,68 MB) - uploaded.to
BD Emu function is integrated also on one CFW 3.55 that im currently uploading. This comes handy for example if you want to dump your root key.
To created our own CFW, just open delta patcher. On original file choose 4.31 OFW from here:
On xdelta patch, hit the patch and apply with check checksum option and keep original file tilted. This will create other file called *NEW.PUP being * name of the OFW you use.
PUP Hashes should be:
THIS IS NOT A CONSOLE BRICKER.
This method was in the shadows for some time and was tested and all systems that allow this.
I think on give core src once i polish it. Honestly im ashamed about some much comments on this code xD
I will keep you guys posted on this thread for next 3 days.
Source, Download, and Additional Info: Elotrolado.net (Spanish Site)