PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Possible PS3 4.00 Exploit - PsDev's Theory

    Developer PsDev is back again today with another article for everyone to read and enjoy. This time, the topic revolves around a possible PS3 4.0 exploit, and the theory around it. This is information that he would like to share with the scene, in hopes of change and overcoming the current barriers to jailbreaking the PS3 console. Feedback welcomed, as PsDev has put a lot of thought and time into this theory.


    OK so lets get right to it. This is a theory, nothing more.

    There has been information available for quite some time. and I took it, thought about it, researched and experimented and I come out with my theory below to exploit 4.00 part of the way. This is not a random theory to, this is logical stuff and true facts. I'm providing this info for other devs to look at and lets see if this can work. I don't keep my work to my self, I like to share in give other people chances in discovering stuff. It always makes me happy when someone finds something out using my work, it just tells me I did a good job in describing and helping and they did a good job in listening and learning the material in order to trigger the exploit or whatever it might be.



    So the lv2ldr verifys decrypts the lv2_kernal.self. we can get the address of this happening. inside Parameters Layout there are arguments, they are used as commands basically to load a function you want to use. they start in the lv2 @ 0x3E800(seems to be same for other ldrs) that address. There is a argument that is called lv2_in and lv2_out (we have know about these) basically we can use lv2_in to map out the address and lv2_out to map out the address for where the lv2ldr decryptes the self file. We can make a program like readself basically and get the offset, u8* means read one byte from the address. use that and we can actually be get the exact offset where it all happens at. once we have the location grabbing this decrypted self should be the easy task. Like I said some info we had and some we did not know about can be obtained like this and used to get keys.
    exploiting 4.00 with this method would work most likely because I doubt sony changed all the locations where the loaders do there thing, sure there encapsulated in the bootloader but they still pass over into the ram at one point before being fed over to the metldr which loads ldrs and if all that is still happening then Sony didn't change nothing
    Code:
    I removed the code because I know it was wrong. I t was just a general idea of what it may look like using arguments as the commands.
    So other devs I post this possible exploit I found here for you to experiment with and get some where with 4.00. You can follow me on twitter @ https://twitter.com/#!/RealPsDev
    Thanks bye.


    [Report Your Own PSX-Scene Related Topics, Member News Submissions!]

    Edited by tthousand
    Code2Free likes this.
    Comments 80 Comments
    1. mihaiolimpiu's Avatar
      mihaiolimpiu -
      This is the same guy who released PSwizard (that even himself said that may work or not), and that bat file that checks the directory structure on a USB stick ??? Oh yeah... Encrypt decrypt with 1000 lines of code.. I can do that with max 10 lines!?

      Why are you guys defending him?

      You know what?
      Here is a ideea for a exploit... Try altering a GIF to include a malicious piece of code that finally crashes the OS... Oh.. it's been done... not o problem...

      Let's find a game save that we can corrupt to include a malicious piece of code that would be executed... Oh ... this didn't work neither...

      Oh yeah... get a wire from a point on the mother board, and while putting a electrical impulse at an unknown or absurdly high rate, we pass it on an unknown point on the Mobo... it should work... Geohot did it no??

      DO YOU SEE THE IRONY? I'm curious when this will make front page! It already contains THREE ideas not one!

      P.S. (softener): The idea is, PSDEV, you got some skills, but this is not the way to make a name for yourself... Come with something useful, not CFW, I couldn't care less about that... USEFUL! Look at some of the homebrew for the PS3.. it's pure genius, MULTIMAN, even if you forget all about it being a backup manager is a USEFUL piece of software, Showtime, the ftp servers, the custom firmwares (3.55) that kept improving... the payloads that once were the salt and pepper of the scene... try to get this: USEFUL!
    1. cyto's Avatar
      cyto -
      Quote Originally Posted by dagrimmreepa View Post
      PSDev put a lot of thought and energy into this possible exploit, and instead of keeping it for himself in the hopes of developing an eventual CFW4 and then SELLING it to you (like others have), he chooses to release it for the betterment of the scene, and instead of saying "thank u," THIS is how you choose to respond?
      What a ****ing douche-nozzle you are, bro.
      Agreed. Adam Corolla fan, eh?
    1. defyboy's Avatar
      defyboy -
      I am having trouble understanding the post, but it sounds like you are suggesting grabbing the decrypted lv2_kernel.self file, But it appears your suggested method requires code execution which we do not currently have.

      From what I understand, Code execution at the level you require to perform this would also be sufficient to allow us to read the contents of the RAM, including the encrypted loaders. We have the keys to decrypt these, allowing us to further transverse the firmware chain all the way down, negating the need for any other obtrusive methods of grabbing decrypted files.
    1. krytonic's Avatar
      krytonic -
      Woh, someone posts something that is for developers but because people like DeadlyFoez can't understand it and do anything with it, they go on a rage because it is not an instant hack where they just download a file and run it... I am seriously surprised at how retarded and selfish DeadlyFoez is being.

      @DeadlyFoez, what have you done for the scene? What have you released which is better than this? Are you able to hack consoles? If not, this post is not for you, you're simply too stupid.

      I don't pretend to be able to do anything with this myself but I at least appreciate someone trying to come up with a theory and share it with other developers for the chance something can come from it, if developers never shared I doubt we would even have 3.55 CFW, so try actually using your brain before posting... I know, it hurts you when you use your brain.

      P.S. Why post here if you sold your PS3? Even if this news is useless, it does not apply to you since you don't have a PS3. Did you just find out you have a small penis and so you are raging on the internet or something?
    1. ketamine's Avatar
      ketamine -
      Quote Originally Posted by DeadlyFoez View Post
      Can you at least make one post without a spelling error? "you feel proud to show you name around here"
      Can you?
    1. CS67700's Avatar
      CS67700 -
      Possible exploit, CFW on the way, months go by and Sony keeps unleashing FW's after FW's. This entire scene is a joke, not only this post.

      It's mainly made of devs wannabe and kids, nothing to see here except all the lame drama and the math gayish incidents.
    1. krytonic's Avatar
      krytonic -
      Quote Originally Posted by CS67700 View Post
      Possible exploit, CFW on the way, months go by and Sony keeps unleashing FW's after FW's. This entire scene is a joke, not only this post.

      It's mainly made of devs wannabe and kids, nothing to see here except all the lame drama and the math gayish incidents.
      What exploit are you working on at the moment?
    1. ICT WP07's Avatar
      ICT WP07 -
      Agree, Im not a Developer so i willnt criticize he knows what he is doing so All the idiotic comments is unnecessary Give the Dev credit and lets hope there is a CFW 4.00 out soon.
    1. BahumatLord's Avatar
      BahumatLord -
      Quote Originally Posted by itzViolence View Post
      Are you talking about PsDev or DeadlyF(-whatever) cause I'm a bit confused right now (maybe because it is 6 in the morning)

      Edit: oh btw, were you actually talking to me?
      I was answering your question about DeadlyFoes. That's what's supposed to happen if someone has a question - simple answers. Not the nonsense

      Edit: and nobody is defending anyone. I see what he (PsDev) was trying to do by getting people talking and working together. He said in the post it's nothing more than a theory and that his code was wrong. If anybody bothered to read what was said before going on a rant, none of that would have gone on
    1. uZer's Avatar
      uZer -
      Deadlyfoez is the only reasonable person here... Every his word is sooo true.
    1. dualshock1992's Avatar
      dualshock1992 -
      I won't even comment on this, I'm not smart enough of saying anything about this.
    1. CS67700's Avatar
      CS67700 -
      Quote Originally Posted by dualshock1992 View Post
      I won't even comment on this, I'm not smart enough of saying anything about this.
      You don't need to be smart to see that this scene isn't worth a penny.
      We're seeing the same news and same shit for a year now, only wannabes.

      This is starting to be pretty ridiculous if you ask me.
      Sony engineers must be laughing their ass off reading the scene news, and i'm being polite here.

      I don't mean to be rude or attack others, but i'd like to give an advice : if you don't know what you're doing/talking about, move along, programming and security engineering isn't for 15 y.o searching for fame.

      It's the first time in my gaming life (and i'm over 30) i've seen such an immature scene.
      I'll be pointed at and attacked after this post, no doubt, but i don't care. The truth must be spoken, no one has the balls to do it.
    1. Lightangel's Avatar
      Lightangel -
      0.00000000000000000000000001 closer to CFW 4.0
    1. vatzcar's Avatar
      vatzcar -
      Quote Originally Posted by CS67700 View Post
      You don't need to be smart to see that this scene isn't worth a penny.
      We're seeing the same news and same shit for a year now, only wannabes.

      Blah... Blah... Blah...
      We know you're really pissed off with this scene. Now you have the right to come here and bash it, but you know..... You may want not to waste your time here and use OFW with legit rented/bought BDs. Or you may want to buy a (or couple of) other console and join their (a lot happening) scene. It's your choice but why would you like to give a single hit to a website of a dead scene?
    1. mihaiolimpiu's Avatar
      mihaiolimpiu -
      Actually, we're not close to anything...
      Sharing ideas (please note that I didn't said that it is good/bad) is not the way to go... Fallow it to see if it's practical, I already shared more than 3 ideas in this thread, does that make me a genius? Well no! I'm no genius still...
      As some users already pointed out it's useless, because we don't have a way to run anything atm (not even a piece of code), and the idea is based on that! In other words, how to hack a already hacked machine? Now you see the irony?

      I'm not against sharing ideas, I'm against nonsense, I'd rather read a well documented idea from a well documented guy instead of this... Share if you have something solid, put together 3 lines... usually that is all it takes, and test... if you can.

      People don't understand that game consoles have some of the most powerful security systems in place because it's a multi billlion dollar industry! If it were any less any high school kid could do it! remember the dreamcast?, the initial PS?

      In this day and age, a easily hacked console is death!, even the WII which is extremely easy to do now, can't be done by the average Joe... The Xbox that can be modded pretty easy actually, how many do you know that have managed to do it by themselves? well very few!

      The scene is lame? What more you could do? You have all this wonderful homebrew, actually we have a open system... A FULLY OPENED system... I don't complain, as the games just don't interest me so much nowadays... and If I really want to play a game I still have 3-4 sealed games... Yes it's Resistance 2... a old game now.. but I still didn't find the time to play it... Why? because I actually have a life, a job, a family...

      What games can't you play? they are so few, even FIFA 12 works now... so.. what is the problem?
    1. Shrek's Avatar
      Shrek -
      Quote Originally Posted by krytonic View Post
      What exploit are you working on at the moment?
      What does that have to do with anything ? I buy a car, I cant say its crap as I dont make one ? I buy a TV, I cant say its crap because I dont make them ? An exploit cant be called crap cause we dont make them ?
    1. itzViolence's Avatar
      itzViolence -
      Quote Originally Posted by BahumatLord View Post
      I was answering your question about DeadlyFoes. That's what's supposed to happen if someone has a question - simple answers. Not the nonsense

      Edit: and nobody is defending anyone. I see what he (PsDev) was trying to do by getting people talking and working together. He said in the post it's nothing more than a theory and that his code was wrong. If anybody bothered to read what was said before going on a rant, none of that would have gone on
      haha dude seems like you got me wrong
      I was asking if PsDev did the Windows 98 (?) on PS3 thing, not DeadlyFoes

      because I think I saw the name "PsDev" above one of those (news)posts
    1. indecks's Avatar
      indecks -
      So essentially:


      Step 1: Get PS3
      Step 2: Turn it on.
      Step 3: crack it somehow
      Step 4: 4.0 jailbreak

      AWESOME! This can be applied to ANYTHING!!!!!


      How in the hell is this news? Someone thinks there is a possibility of a chance of a possibility of a chance of a possibility of a hack?

      Come on. Stop starting and start.
    1. vodcas's Avatar
      vodcas -
      Quote Originally Posted by DeadlyFoez View Post
      Honestly, I sold my PS3 a few months back. Why? because first, the PS3 just sucks. Second, because the homebrew scene here is a joke. The wii is far more open. The Game Cube is far more open. Everyone here on this site only cares about pirating games, but one year later and you are all still suffering and waiting.
      Even though geohot is a d*ck, he still was the only one with everything to make all your ps3 wet dreams come true, and no one else is able to come close to it.
      Keep chasing the dragon...
      Let me guess you are in this site just for homebrew games?? and not piracy, wtf how old are you, go play with your wii or gamecupe kid. 99.9 % of people in this site is here for piracy, you and yes you, dont tell me you aint here for piracy, who the f*** plays homebrew games on a ps3, come one kid,

      i dont know wheather to laugh at you or feel sorry for u. U mention u have sold your ps3 few months back, so u actually dont have a ps3, but yet u dont have anything better to do, other than bash devs in the ps3 scene. pathetic, this clearly says what kind of person you are,

      better for you to just stay with the wii kid
    1. Metagondria's Avatar
      Metagondria -
      Quote Originally Posted by CS67700 View Post
      You don't need to be smart to see that this scene isn't worth a penny.
      We're seeing the same news and same shit for a year now, only wannabes.

      This is starting to be pretty ridiculous if you ask me.
      Sony engineers must be laughing their ass off reading the scene news, and i'm being polite here.

      EXACTLY, all i want to say is i knew this kind of (keep-ur-hopes-up-scenario's) wos about to happend like more then a year ago (ofw 3.5+) and decided to go back to OFW and sell that piece of useless crap as soon as possible .

      Now when i see this scene CRAwlling more like 20 steps backwards then forward iam glad i sold it.

      Iam just saying, with this new law now taking down file sharing domains and all that shit it's looking grim and the good old console hacking day's is pretty much gAmE OvEr if you ask me !

      Even some psp models (piece of old garbage) cant be permanently hacked these day's last time i checked !!

      Need to re-hack it everytime you power down that device !!!

      Go figure .. a handheld !!!
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    Squallcloud

    Is there a list of PAL game that GMS works on yet?

    Thread Starter: Squallcloud

    Hello, I want was just wondering if there was a list in which it has every PS2 game which has been confirmed to work on GMS yet and what resolution mode

    Last Post By: Squallcloud Today, 08:25 AM Go to last post
    Anno1404

    Upgrading to Rebug

    Thread Starter: Anno1404

    Hello,
    I finally chose to upgrade to Rebug 4.41.2 cause i've been going crazy with finding fixes , changing E-Boots , games not working.

    Last Post By: Anno1404 Today, 07:50 AM Go to last post
    gunas4

    Multiman cant mount game

    Thread Starter: gunas4

    hi,i have problem with my ps3,i had downgrade,have installed rogero 4.40 and multiman it was working fine but,one day my joystick was broked and i did

    Last Post By: gunas4 Today, 07:47 AM Go to last post
    Alderaan

    Help with PK2 file - Star Wars ROTS

    Thread Starter: Alderaan

    Can anyone help me with the exact location of the Jedi Mantra audio data (in the jedi temple you can hear a voice going through the sentences of the mantra)?

    Last Post By: Alderaan Today, 05:34 AM Go to last post
    InfernalFury

    Possible to transfer trophies to another profile user?

    Thread Starter: InfernalFury

    I've recently been banned a week ago due to using cfw. Created a new psn account using unban program and managed to resign my saves to match my newly

    Last Post By: bitsbubba Yesterday, 11:14 PM Go to last post
    nokiajavi

    USBUtil 2.1 Ultimate.REV.1.2[UPDATE]

    Thread Starter: nokiajavi

    USBUtil 2.1 (rev 1.2) May 2010

    Due to bugs reported these last weeks, USBUtil has been revised.



    Quote ISEKO

    Last Post By: RandQalan Today, 04:31 AM Go to last post
  • Recent Comments

    RandQalan

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    Remember the rules this can get you in trouble :mad: Go to last post

    RandQalan Today 08:02 AM
    Staylecrate

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    It is on my dropbox account, PM or email me your email and I will share the folder, it's 1.5 gigs. Go to last post

    Staylecrate Today 07:51 AM
    mad mike 96

    Comedy on Demand: Laugh Factory on PS3 Updated

    Anyone have a link to the .pkg for this one? Go to last post

    mad mike 96 Today 07:31 AM
    aldostools

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    75C in idle (reported by multiMAN) after a short session of play videos... but my ambient... Go to last post

    aldostools Today 07:30 AM
    suaveburn

    Sony's Testing a Better, Faster Video Streaming Technology.

    I agree i have dropped my cable provider and simply added an internet plan i pay 50 dollars a month... Go to last post

    suaveburn Today 06:50 AM
    qrange

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    thanks. could you please confirm, is that 75C in idle?
    my PS3 is slim, CECH-25xxB (iirc) ,... Go to last post

    qrange Today 06:25 AM
    Staylecrate

    English Patch version for Dynasty Warriors Strikeforce 2 PSP.

    Hey atreyu, I have the game. let me know if you want a copy to mess around with. Go to last post

    Staylecrate Today 05:51 AM
    eustolio

    SDAT Creator by oakhead69

    Under this method, you can create edat_decrypter_creator?
    Thanks for u work oakhead69! Go to last post

    eustolio Today 04:53 AM
    opium2k

    {Guide} Install multiMAN Themes via a PKG File

    Nice of them to mention me but I haven't my multiMAN themes in ages. Probably best stick with more... Go to last post

    opium2k Today 03:35 AM
    the-green

    IrisManager v2.45 -- Various Additions and Improvements

    thanks for this update !!! Go to last post

    the-green Today 03:27 AM