PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Possible PS3 4.00 Exploit - PsDev's Theory

    Developer PsDev is back again today with another article for everyone to read and enjoy. This time, the topic revolves around a possible PS3 4.0 exploit, and the theory around it. This is information that he would like to share with the scene, in hopes of change and overcoming the current barriers to jailbreaking the PS3 console. Feedback welcomed, as PsDev has put a lot of thought and time into this theory.


    OK so lets get right to it. This is a theory, nothing more.

    There has been information available for quite some time. and I took it, thought about it, researched and experimented and I come out with my theory below to exploit 4.00 part of the way. This is not a random theory to, this is logical stuff and true facts. I'm providing this info for other devs to look at and lets see if this can work. I don't keep my work to my self, I like to share in give other people chances in discovering stuff. It always makes me happy when someone finds something out using my work, it just tells me I did a good job in describing and helping and they did a good job in listening and learning the material in order to trigger the exploit or whatever it might be.



    So the lv2ldr verifys decrypts the lv2_kernal.self. we can get the address of this happening. inside Parameters Layout there are arguments, they are used as commands basically to load a function you want to use. they start in the lv2 @ 0x3E800(seems to be same for other ldrs) that address. There is a argument that is called lv2_in and lv2_out (we have know about these) basically we can use lv2_in to map out the address and lv2_out to map out the address for where the lv2ldr decryptes the self file. We can make a program like readself basically and get the offset, u8* means read one byte from the address. use that and we can actually be get the exact offset where it all happens at. once we have the location grabbing this decrypted self should be the easy task. Like I said some info we had and some we did not know about can be obtained like this and used to get keys.
    exploiting 4.00 with this method would work most likely because I doubt sony changed all the locations where the loaders do there thing, sure there encapsulated in the bootloader but they still pass over into the ram at one point before being fed over to the metldr which loads ldrs and if all that is still happening then Sony didn't change nothing
    Code:
    I removed the code because I know it was wrong. I t was just a general idea of what it may look like using arguments as the commands.
    So other devs I post this possible exploit I found here for you to experiment with and get some where with 4.00. You can follow me on twitter @ https://twitter.com/#!/RealPsDev
    Thanks bye.


    [Report Your Own PSX-Scene Related Topics, Member News Submissions!]

    Edited by tthousand
    Code2Free likes this.
    Comments 80 Comments
    1. mihaiolimpiu's Avatar
      mihaiolimpiu -
      This is the same guy who released PSwizard (that even himself said that may work or not), and that bat file that checks the directory structure on a USB stick ??? Oh yeah... Encrypt decrypt with 1000 lines of code.. I can do that with max 10 lines!?

      Why are you guys defending him?

      You know what?
      Here is a ideea for a exploit... Try altering a GIF to include a malicious piece of code that finally crashes the OS... Oh.. it's been done... not o problem...

      Let's find a game save that we can corrupt to include a malicious piece of code that would be executed... Oh ... this didn't work neither...

      Oh yeah... get a wire from a point on the mother board, and while putting a electrical impulse at an unknown or absurdly high rate, we pass it on an unknown point on the Mobo... it should work... Geohot did it no??

      DO YOU SEE THE IRONY? I'm curious when this will make front page! It already contains THREE ideas not one!

      P.S. (softener): The idea is, PSDEV, you got some skills, but this is not the way to make a name for yourself... Come with something useful, not CFW, I couldn't care less about that... USEFUL! Look at some of the homebrew for the PS3.. it's pure genius, MULTIMAN, even if you forget all about it being a backup manager is a USEFUL piece of software, Showtime, the ftp servers, the custom firmwares (3.55) that kept improving... the payloads that once were the salt and pepper of the scene... try to get this: USEFUL!
    1. cyto's Avatar
      cyto -
      Quote Originally Posted by dagrimmreepa View Post
      PSDev put a lot of thought and energy into this possible exploit, and instead of keeping it for himself in the hopes of developing an eventual CFW4 and then SELLING it to you (like others have), he chooses to release it for the betterment of the scene, and instead of saying "thank u," THIS is how you choose to respond?
      What a ****ing douche-nozzle you are, bro.
      Agreed. Adam Corolla fan, eh?
    1. defyboy's Avatar
      defyboy -
      I am having trouble understanding the post, but it sounds like you are suggesting grabbing the decrypted lv2_kernel.self file, But it appears your suggested method requires code execution which we do not currently have.

      From what I understand, Code execution at the level you require to perform this would also be sufficient to allow us to read the contents of the RAM, including the encrypted loaders. We have the keys to decrypt these, allowing us to further transverse the firmware chain all the way down, negating the need for any other obtrusive methods of grabbing decrypted files.
    1. krytonic's Avatar
      krytonic -
      Woh, someone posts something that is for developers but because people like DeadlyFoez can't understand it and do anything with it, they go on a rage because it is not an instant hack where they just download a file and run it... I am seriously surprised at how retarded and selfish DeadlyFoez is being.

      @DeadlyFoez, what have you done for the scene? What have you released which is better than this? Are you able to hack consoles? If not, this post is not for you, you're simply too stupid.

      I don't pretend to be able to do anything with this myself but I at least appreciate someone trying to come up with a theory and share it with other developers for the chance something can come from it, if developers never shared I doubt we would even have 3.55 CFW, so try actually using your brain before posting... I know, it hurts you when you use your brain.

      P.S. Why post here if you sold your PS3? Even if this news is useless, it does not apply to you since you don't have a PS3. Did you just find out you have a small penis and so you are raging on the internet or something?
    1. ketamine's Avatar
      ketamine -
      Quote Originally Posted by DeadlyFoez View Post
      Can you at least make one post without a spelling error? "you feel proud to show you name around here"
      Can you?
    1. CS67700's Avatar
      CS67700 -
      Possible exploit, CFW on the way, months go by and Sony keeps unleashing FW's after FW's. This entire scene is a joke, not only this post.

      It's mainly made of devs wannabe and kids, nothing to see here except all the lame drama and the math gayish incidents.
    1. krytonic's Avatar
      krytonic -
      Quote Originally Posted by CS67700 View Post
      Possible exploit, CFW on the way, months go by and Sony keeps unleashing FW's after FW's. This entire scene is a joke, not only this post.

      It's mainly made of devs wannabe and kids, nothing to see here except all the lame drama and the math gayish incidents.
      What exploit are you working on at the moment?
    1. ICT WP07's Avatar
      ICT WP07 -
      Agree, Im not a Developer so i willnt criticize he knows what he is doing so All the idiotic comments is unnecessary Give the Dev credit and lets hope there is a CFW 4.00 out soon.
    1. BahumatLord's Avatar
      BahumatLord -
      Quote Originally Posted by itzViolence View Post
      Are you talking about PsDev or DeadlyF(-whatever) cause I'm a bit confused right now (maybe because it is 6 in the morning)

      Edit: oh btw, were you actually talking to me?
      I was answering your question about DeadlyFoes. That's what's supposed to happen if someone has a question - simple answers. Not the nonsense

      Edit: and nobody is defending anyone. I see what he (PsDev) was trying to do by getting people talking and working together. He said in the post it's nothing more than a theory and that his code was wrong. If anybody bothered to read what was said before going on a rant, none of that would have gone on
    1. uZer's Avatar
      uZer -
      Deadlyfoez is the only reasonable person here... Every his word is sooo true.
    1. dualshock1992's Avatar
      dualshock1992 -
      I won't even comment on this, I'm not smart enough of saying anything about this.
    1. CS67700's Avatar
      CS67700 -
      Quote Originally Posted by dualshock1992 View Post
      I won't even comment on this, I'm not smart enough of saying anything about this.
      You don't need to be smart to see that this scene isn't worth a penny.
      We're seeing the same news and same shit for a year now, only wannabes.

      This is starting to be pretty ridiculous if you ask me.
      Sony engineers must be laughing their ass off reading the scene news, and i'm being polite here.

      I don't mean to be rude or attack others, but i'd like to give an advice : if you don't know what you're doing/talking about, move along, programming and security engineering isn't for 15 y.o searching for fame.

      It's the first time in my gaming life (and i'm over 30) i've seen such an immature scene.
      I'll be pointed at and attacked after this post, no doubt, but i don't care. The truth must be spoken, no one has the balls to do it.
    1. Lightangel's Avatar
      Lightangel -
      0.00000000000000000000000001 closer to CFW 4.0
    1. vatzcar's Avatar
      vatzcar -
      Quote Originally Posted by CS67700 View Post
      You don't need to be smart to see that this scene isn't worth a penny.
      We're seeing the same news and same shit for a year now, only wannabes.

      Blah... Blah... Blah...
      We know you're really pissed off with this scene. Now you have the right to come here and bash it, but you know..... You may want not to waste your time here and use OFW with legit rented/bought BDs. Or you may want to buy a (or couple of) other console and join their (a lot happening) scene. It's your choice but why would you like to give a single hit to a website of a dead scene?
    1. mihaiolimpiu's Avatar
      mihaiolimpiu -
      Actually, we're not close to anything...
      Sharing ideas (please note that I didn't said that it is good/bad) is not the way to go... Fallow it to see if it's practical, I already shared more than 3 ideas in this thread, does that make me a genius? Well no! I'm no genius still...
      As some users already pointed out it's useless, because we don't have a way to run anything atm (not even a piece of code), and the idea is based on that! In other words, how to hack a already hacked machine? Now you see the irony?

      I'm not against sharing ideas, I'm against nonsense, I'd rather read a well documented idea from a well documented guy instead of this... Share if you have something solid, put together 3 lines... usually that is all it takes, and test... if you can.

      People don't understand that game consoles have some of the most powerful security systems in place because it's a multi billlion dollar industry! If it were any less any high school kid could do it! remember the dreamcast?, the initial PS?

      In this day and age, a easily hacked console is death!, even the WII which is extremely easy to do now, can't be done by the average Joe... The Xbox that can be modded pretty easy actually, how many do you know that have managed to do it by themselves? well very few!

      The scene is lame? What more you could do? You have all this wonderful homebrew, actually we have a open system... A FULLY OPENED system... I don't complain, as the games just don't interest me so much nowadays... and If I really want to play a game I still have 3-4 sealed games... Yes it's Resistance 2... a old game now.. but I still didn't find the time to play it... Why? because I actually have a life, a job, a family...

      What games can't you play? they are so few, even FIFA 12 works now... so.. what is the problem?
    1. Shrek's Avatar
      Shrek -
      Quote Originally Posted by krytonic View Post
      What exploit are you working on at the moment?
      What does that have to do with anything ? I buy a car, I cant say its crap as I dont make one ? I buy a TV, I cant say its crap because I dont make them ? An exploit cant be called crap cause we dont make them ?
    1. itzViolence's Avatar
      itzViolence -
      Quote Originally Posted by BahumatLord View Post
      I was answering your question about DeadlyFoes. That's what's supposed to happen if someone has a question - simple answers. Not the nonsense

      Edit: and nobody is defending anyone. I see what he (PsDev) was trying to do by getting people talking and working together. He said in the post it's nothing more than a theory and that his code was wrong. If anybody bothered to read what was said before going on a rant, none of that would have gone on
      haha dude seems like you got me wrong
      I was asking if PsDev did the Windows 98 (?) on PS3 thing, not DeadlyFoes

      because I think I saw the name "PsDev" above one of those (news)posts
    1. indecks's Avatar
      indecks -
      So essentially:


      Step 1: Get PS3
      Step 2: Turn it on.
      Step 3: crack it somehow
      Step 4: 4.0 jailbreak

      AWESOME! This can be applied to ANYTHING!!!!!


      How in the hell is this news? Someone thinks there is a possibility of a chance of a possibility of a chance of a possibility of a hack?

      Come on. Stop starting and start.
    1. vodcas's Avatar
      vodcas -
      Quote Originally Posted by DeadlyFoez View Post
      Honestly, I sold my PS3 a few months back. Why? because first, the PS3 just sucks. Second, because the homebrew scene here is a joke. The wii is far more open. The Game Cube is far more open. Everyone here on this site only cares about pirating games, but one year later and you are all still suffering and waiting.
      Even though geohot is a d*ck, he still was the only one with everything to make all your ps3 wet dreams come true, and no one else is able to come close to it.
      Keep chasing the dragon...
      Let me guess you are in this site just for homebrew games?? and not piracy, wtf how old are you, go play with your wii or gamecupe kid. 99.9 % of people in this site is here for piracy, you and yes you, dont tell me you aint here for piracy, who the f*** plays homebrew games on a ps3, come one kid,

      i dont know wheather to laugh at you or feel sorry for u. U mention u have sold your ps3 few months back, so u actually dont have a ps3, but yet u dont have anything better to do, other than bash devs in the ps3 scene. pathetic, this clearly says what kind of person you are,

      better for you to just stay with the wii kid
    1. Metagondria's Avatar
      Metagondria -
      Quote Originally Posted by CS67700 View Post
      You don't need to be smart to see that this scene isn't worth a penny.
      We're seeing the same news and same shit for a year now, only wannabes.

      This is starting to be pretty ridiculous if you ask me.
      Sony engineers must be laughing their ass off reading the scene news, and i'm being polite here.

      EXACTLY, all i want to say is i knew this kind of (keep-ur-hopes-up-scenario's) wos about to happend like more then a year ago (ofw 3.5+) and decided to go back to OFW and sell that piece of useless crap as soon as possible .

      Now when i see this scene CRAwlling more like 20 steps backwards then forward iam glad i sold it.

      Iam just saying, with this new law now taking down file sharing domains and all that shit it's looking grim and the good old console hacking day's is pretty much gAmE OvEr if you ask me !

      Even some psp models (piece of old garbage) cant be permanently hacked these day's last time i checked !!

      Need to re-hack it everytime you power down that device !!!

      Go figure .. a handheld !!!
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    michellefland

    hello i am search code no random battle pal french code work please for suikoden 4 and 1 help my please thanks in advance

    Thread Starter: michellefland

    hello

    i am search code no random battle pal french code work please for suikoden 4 and 1 help my please thanks in advance

    Last Post By: michellefland Today, 07:27 AM Go to last post
    BahumatLord

    Showtime metadata is being read incorrectly

    Thread Starter: BahumatLord

    I use the movie db plugin for showtime that pulls up artwork and info on every movie. Most of the time it identifies movies correctly and will display

    Last Post By: BahumatLord Today, 06:49 AM Go to last post
    uaeboss616

    help me with turn off automatically:(

    Thread Starter: uaeboss616

    hello guys my problem is my ps3 turn off automatically after i downgrade my ps3 by e3 flasher and jailbroken my ps3 turn on 10 sec then turn off automatically

    Last Post By: fq360 Today, 07:17 AM Go to last post
    nova89

    Is it possible on ps3 add a radio station ?

    Thread Starter: nova89

    So I'm bored of the eflc sound track since massive b was removed I now only listen to electro choc and ever since gta iv was released I wanted msx fm

    Last Post By: ribonucleic Today, 07:34 AM Go to last post
    arsenal553

    CXD2973GB Heatspreader

    Thread Starter: arsenal553

    Hello everyone,

    I have a launch model PS3 i got for a bargain because the owner said it overheated every 3 min. He was right so i decided

    Last Post By: arsenal553 Today, 01:44 AM Go to last post
    pelvicthrustman

    PS2 Controller Remapper

    Thread Starter: pelvicthrustman


    PS2 Controller Remapper




    PS2 Controller Remapper is a tool designed to arbitrarily remap a PS2 game's controls

    Last Post By: pelvicthrustman Yesterday, 10:05 PM Go to last post
  • Recent Comments

    atreyu187

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    I run OxCD due to me OCD disorder and it keeps my PS3 below 50 degrees Celsius. And when the light... Go to last post

    atreyu187 Today 08:48 AM
    jkoiou

    {Guide} How to make themes for multiMAN

    i don't have a lot of time to play around with this. can comeone try making a MM theme based on the... Go to last post

    jkoiou Today 07:50 AM
    bitsbubba

    {Guide} Install multiMAN Themes via a PKG File

    me neither really, isn't this a step backwards, I thought thm was a package file. why switch thm to... Go to last post

    bitsbubba Today 02:47 AM
    tnh531

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    Can anyone help, which setting is best for my phat ps3. i am a little confuse about the modes. Go to last post

    tnh531 Today 12:52 AM
    condorstrike

    {Guide} Install multiMAN Themes via a PKG File

    also, that was one of the tricks I used, to make Solar run by itself on a timer without user input... Go to last post

    condorstrike Yesterday 11:57 PM
    STLcardsWS

    {Guide} Install multiMAN Themes via a PKG File

    BahumatLord
    That what i usually use.

    Yea my bad its not the eboot, but there are requirements.... Go to last post

    STLcardsWS Yesterday 11:57 PM
    condorstrike

    {Guide} Install multiMAN Themes via a PKG File

    I've been doing this for years, no... Eboots are not needed, I always did my stuff manually in... Go to last post

    condorstrike Yesterday 11:52 PM
    makaveli07

    PSChannel v1.10 Released - Added Language Support

    so i finally figured out that i had to get it signed for 4.40 rogero and after doing that it is... Go to last post

    makaveli07 Yesterday 11:48 PM
    BahumatLord

    {Guide} Install multiMAN Themes via a PKG File

    EBOOTs aren't needed to make a pkg. You should never include an eboot unless you need to replace... Go to last post

    BahumatLord Yesterday 11:47 PM
    makaveli07

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    hey guys my ps3 Phat LED changed yellow is that normal what does it indicate ? the CPU temp is... Go to last post

    makaveli07 Yesterday 11:44 PM