PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • Videos - Secret Quality Assurance Menu Unlocked + QA Downgrading

    Mathieulh, an underground hacker, has released two videos showcasing retail consoles which have been converted to special quality assurance consoles. He has managed to set a special QA flag in his console which unlocks a secret Quality Assurance menu. In the video he showcases some very unique options which typically are only available in Sony's QA Centers and their R&D Department. In one of the videos he also demonstrates how Sony officially downgrades their consoles using these QA options. Unfortunately, Mathieulh is infamous for not releasing his methods and has stayed true to form with this latest development.





    Update - rms elaborates on why QA Flagging is difficult:

    Ever since Mathieulh released his video, some people just want to QA flag their consoles. Now, let me tell you one thing, it’s so not easy.
    Besides, if you want to use the QA flag, you have to have a valid QA token, and you have to be on a specific firmware range. Now, what’s so special about the token is that it’s generated in a funny way, I am not going to disclose that here. But, remember, PS3 hypervisor can also make tokens. But these tokens.. don’t do /anything/ except just unlock the QA repository node.
    Besides, the fancy menu requires a very weird key combo on the Sixaxis, and it only works on retails. On debugs, it just removes all restrictions.
    Remember, the QA flag in Syscon also requires a valid token. (reiterated again.)
    So, in the end QA flagging = (Piracy*Warez)++;. Don’t do it.

    What is a QA flag?

    QA flag is the internal console flag used by Sony, it enables hidden options and removes restrictions for both retail and debug consoles alike. It is used for QA centers and the R&D Department, there are 2 levels of QA flags, Minimum and Advanced, this console has been set to the Advanced one.
    Attachment 1199

    Video Description:

    I just QA flagged my Metal Gear Solid 4 Limited Edition console and I thought I’d show you the hidden options for the sake of it. (and because I was bored)
    I am sorry for the unstable camera, I only have two hands and the options are hidden and require (along with the actual flag) a crazy button combo to pop up. (I kid you not)
    Sorry I am not telling you how to do this, please do not ask.
    Yes, this video is real
    Relevant tweets:

    Mathieulh:
    @dantezteam It’s an UNMODIFIED RETAIL FIRMWARE.
    @KaKaRoToKS For various reasons, one of them being that you can warez with this, and the flag stays even after updating.
    @KaKaRoToKS The QA flag happens to remove a bunch of restrictions that have the side effect of preventing you to warez.
    @dantezteam The console is QA flagged, The firmware checks for this flag and will enable special features when it finds it.
    @dantezteam Basically it’s what Sony themselves use to allow special debugging on their consoles and loosen restrictions.

    @KaKaRoToKS By the way, Advanced QA flag enables downgrading, just my 2 cents… xD
    Downgrading Video Description:

    This is what happens when downgrade gets enabled. This is the way Sony officially downgrade retails.

    Source: PS3Hax
    Comments 61 Comments
    1. badboyz80-PSG's Avatar
      badboyz80-PSG -
      great work as always but i really dont see the point in showing all your work if you aint going to realease any of it
    1. Zero95's Avatar
      Zero95 -
      One more thing that show us that Mathieulh is a arrogant ******* and will only fame.

      Why show he us that when he does not release it that is nonsense and nothing else than arrogant.
    1. grandy's Avatar
      grandy -
      At the very least, the videos show other devs/hackers whats possible. Granted, a release would be much more appreciated.
    1. ihaxgames-PSG's Avatar
      ihaxgames-PSG -
      Quote Originally Posted by grandy View Post
      At the very least, the videos show other devs/hackers whats possible. Granted, a release would be much more appreciated.
      I agree with you, however other Devs will likely look into this now. It's too bad though... If anyone would release this if they did it, it would've been Graf, hopefully he's doing alright
    1. Thorn's Avatar
      Thorn -
      well what a
      ****** ****tease
    1. reloaded231-PSG's Avatar
      reloaded231-PSG -
      im sorry but i have to say bull SNOT well all know that the xmb can be changed i am sure with a little tinkering i think all this can be faked i mean hell my xmb is not like others i have changed almost everything in text so this can very well be fake
    1. grandy's Avatar
      grandy -
      Quote Originally Posted by reloaded231 View Post
      im sorry but i have to say bull SNOT well all know that the xmb can be changed i am sure with a little tinkering i think all this can be faked i mean hell my xmb is not like others i have changed almost everything in text so this can very well be fake
      I can confirm this isn't fake.
    1. hackbard23's Avatar
      hackbard23 -
      looks like this "Controller Code" is something for my Logitech Harmony Remote :joystick1:
    1. reloaded231-PSG's Avatar
      reloaded231-PSG -
      and how is that you have been to this guys house and seen this yourself
    1. CrimsonSoul's Avatar
      CrimsonSoul -
      Sooooo basically there's always been a "simple-ish" way to downgrade with/without modified .PUP aka CFW??

      ....wait for it


      .........wait for it


      Ok, open the flood gates of people moaning, *****ing, complaining and asking so they can downgrade their 3.60 FW!

      Quote Originally Posted by VikasNarula View Post
      Its not fake Mathieulh is most popular console hacker. Also he is the first one who get his hand on 3.60 encryption keys but he didn't release in public for some reason.

      PS: You can google his name for proof.
      Read the below statement.

      Quote Originally Posted by reloaded231 View Post
      im sorry but i have to say bull SNOT well all know that the xmb can be changed i am sure with a little tinkering i think all this can be faked i mean hell my xmb is not like others i have changed almost everything in text so this can very well be fake
      It was for comments like this that I knew eventually would pop up.
    1. goblueguy11's Avatar
      goblueguy11 -
      It sucks that Mathieulh doesn't release anything!
    1. Zero95's Avatar
      Zero95 -
      Quote Originally Posted by grandy View Post
      At the very least, the videos show other devs/hackers whats possible. Granted, a release would be much more appreciated.
      Jeah and for this Mathieulh has must make a video and release it to the public and twitter about it?

      NO to show other Hackers what is possible he must not do this.
    1. badkiller2-PSG's Avatar
      badkiller2-PSG -
      Well, this is interesting news. Maybe we could finally go back and forth between Firmwares as we please, play online and use PSN for legit business, and CFW for our uhm "homebrew"... Only problem is, he doesn't give anything.

      Maybe he shows it to make other devs know the possibility. IDK really, .

      Also, I don't know if it's true, but someone posted on the videos a code that supposely unlocks the debug Mathieulh presented. Dunno if it's true, but figured I might as well repost it in case it is and Methieulh will delete the comment so no one would know:

      write QA flags3dm_um /dev/ps3dmproxy write_eprom 0x48C0A 0x00

      OR

      ps3dm_um /dev/ps3dmproxy write_eprom 0x48C0A 0xFF
    1. Captain Obvious's Avatar
      Captain Obvious -
      why can't these developers afford tripods?
    1. pito ho's Avatar
      pito ho -
      Hey Yo Mathieulh,
      You are useless and just shut the **** up. You don't need to show your **** to the public if it does not smell. Geohot is the best and always share to everyone.
    1. role2682-PSG's Avatar
      role2682-PSG -
      I know it sucks that he doesn't release his work but hopefully someone will be able to figure out how he did this from his hints.

      I've seen this on other sites thought it should be posted here as well, this is originally form Mathieulh's twitter:

      Here's 2 hints I'm gonna share with you guys;

      update_mgr_qa_flag.c - graf_payloads in graf_payloads - git-hacks.com

      Code: [Check Download Links]
      http://git-hacks.com/graf_payloads/g..._mgr_qa_flag.c


      update_mgr_set_token.c - graf_payloads in graf_payloads - git-hacks.com

      Code: [Check Download Links]
      http://git-hacks.com/graf_payloads/g...gr_set_token.c

      EEPROM Offset Table
      Here is the table of EEPROM offsets that can be accessed through Update Manager (3.15):

      0x48C06 1 FSELF Control Flag
      0x48C07 1 Product Mode (UM allows to read this offset, it can be also written but only when already in product mode)
      0x48C0A 1 QA Flag
      0x48C13 1 Device Type
      0x48C42 1 HDD Copy Mode
      0x48C50 0x10 Debug Support Flag
      0x48C60 1 Update Status
      0x48C61 1 Recover Mode Flag
      0x48D3E 0x50 QA Token (UM doesn't allow access to this offset but SC Manager can read/write it)
    1. VikasNarula-PSG's Avatar
      VikasNarula-PSG -
      Update from rms's crypt

      Why QA flagging is difficult

      Ever since Mathieulh released his video, some people just want to QA flag their consoles. Now, let me tell you one thing, it’s so not easy.

      Besides, if you want to use the QA flag, you have to have a valid QA token, and you have to be on a specific firmware range. Now, what’s so special about the token is that it’s generated in a funny way, I am not going to disclose that here. But, remember, PS3 hypervisor can also make tokens. But these tokens.. don’t do /anything/ except just unlock the QA repository node.

      Besides, the fancy menu requires a very weird key combo on the Sixaxis, and it only works on retails. On debugs, it just removes all restrictions.

      Remember, the QA flag in Syscon also requires a valid token. (reiterated again.)

      So, in the end QA flagging = (Piracy*Warez)++;. Don’t do it.
    1. daxgr-PSG's Avatar
      daxgr-PSG -
      Kinda sucks

      Sent from my X10mini using Tapatalk
    1. mytsoutsou-PSG's Avatar
      mytsoutsou-PSG -
      Having a PS3 dev kit and making videos showing the extra options it has,while trying to convince everyone of your imaginary accomplicements, is really sad, so s u c k my c o c k Mathieulh
    1. vSaAmTp-PSG's Avatar
      vSaAmTp-PSG -
      Pffffff... That Sucks. Mathieulh use this for his Ego.

      Same like: I can walk on the Water. With a Secret Finger Combo i do this.
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    pelvicthrustman

    PS2 Controller Remapper

    Thread Starter: pelvicthrustman


    PS2 Controller Remapper




    PS2 Controller Remapper is a tool designed to arbitrarily remap a PS2 game's controls

    Last Post By: pelvicthrustman Yesterday, 10:05 PM Go to last post
    lordsnipe

    Free MC Boot 1.8b - 75004 PAL - Black Screen

    Thread Starter: lordsnipe

    Hi all,

    I'm new to this Free MC Boot, but have come across an issue that hopefully someone can help out with.

    I have two PS2s

    Last Post By: lordsnipe Yesterday, 10:24 PM Go to last post
    DaBOSS54320

    Tutorial for using E3 flasher without limited edition.

    Thread Starter: DaBOSS54320

    I have necessary items to use the flasher, however tutorials i found used the limited edition, with the station thing you put your hard drive into. i

    Last Post By: DaBOSS54320 Yesterday, 08:09 PM Go to last post
    DSAPSX

    Backwards compatibility for Xbox One is a waste?

    Thread Starter: DSAPSX

    I don't understand the choice of words that Microsoft used regarding backwards compatibility. I understand what they are saying but doesn't it just seem

    Last Post By: tthousand Yesterday, 08:30 PM Go to last post
    ANTZ7

    my ps3 is sort of stuck on bluescreen

    Thread Starter: ANTZ7

    i bought a ps3 that when turned on just shows blue screen on both hdmi/scart

    so took it apart and installed e3 flasher did all the usual

    Last Post By: ANTZ7 Yesterday, 09:20 PM Go to last post
    Villsson

    Problems with multiman 4.40

    Thread Starter: Villsson

    Hello everybody.

    First of all SORRY MY BAD ENGLISH!

    And second: I don't know is this the right place for this.

    Last Post By: Villsson Yesterday, 06:19 PM Go to last post
  • Recent Comments

    condorstrike

    {Guide} Install multiMAN Themes via a PKG File

    also, that was one of the tricks I used, to make Solar run by itself on a timer without user input... Go to last post

    condorstrike Yesterday 11:57 PM
    STLcardsWS

    {Guide} Install multiMAN Themes via a PKG File

    BahumatLord
    That what i usually use.

    Yea my bad its not the eboot, but there are requirements.... Go to last post

    STLcardsWS Yesterday 11:57 PM
    condorstrike

    {Guide} Install multiMAN Themes via a PKG File

    I've been doing this for years, no... Eboots are not needed, I always did my stuff manually in... Go to last post

    condorstrike Yesterday 11:52 PM
    makaveli07

    PSChannel v1.10 Released - Added Language Support

    so i finally figured out that i had to get it signed for 4.40 rogero and after doing that it is... Go to last post

    makaveli07 Yesterday 11:48 PM
    BahumatLord

    {Guide} Install multiMAN Themes via a PKG File

    EBOOTs aren't needed to make a pkg. You should never include an eboot unless you need to replace... Go to last post

    BahumatLord Yesterday 11:47 PM
    makaveli07

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    hey guys my ps3 Phat LED changed yellow is that normal what does it indicate ? the CPU temp is... Go to last post

    makaveli07 Yesterday 11:44 PM
    STLcardsWS

    {Guide} Install multiMAN Themes via a PKG File

    condorstrike

    Wont the Package fail to make if no eboot is present? Or are there tools im over... Go to last post

    STLcardsWS Yesterday 11:43 PM
    condorstrike

    {Guide} Install multiMAN Themes via a PKG File

    ic :), also that's the reason I never used Eboots on these types of Pkgs, there's no need for it. ;) Go to last post

    condorstrike Yesterday 09:58 PM
    doctorwho05

    In Depth Review/Comparison Of OEM Cooling Fans

    That would be awesome, new custom case, new heatsink maybe trick out with LEDs Go to last post

    doctorwho05 Yesterday 09:17 PM
    STLcardsWS

    {Guide} Install multiMAN Themes via a PKG File

    condorstrike.

    There is nothing new about this. Sometime its good for a refresher or good for... Go to last post

    STLcardsWS Yesterday 08:13 PM