Forum: General Jailbreak Discussion - The General Jailbreak Discussion forum is your place to discuss everything related to the PS3 jailbreak. You can discuss QA Flags, CFW, kmeaw or find information about many general jailbreak methods.


The above video goes away if you are a member and logged in, so log in now!




 
Would you like to get all the new info from
PSX-Scene in your email each day?




Want to learn more about the team keeping you up to date with the latest scene news?

Read about them now!

Check out our Developer bios, too!

 


User Tag List

Like Tree1Likes
  • 1 Post By tthousand

Thread: TrueBlue & Cobra USB Payload Download
  

Results 1 to 3 of 3
  1. #1 TrueBlue & Cobra USB Payload Download 
    Secludedly is offline Member
    Join Date
    Jan 2011
    Posts
    128
    Downloads
    10
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    2
    Likes Received
    9
    http://www.brewology.com/?p=2559


    I (aka shadoxi) figured out where is locatedthepayload of Trueblueandcobradongle. You can find it at offset @360000 in lv2_kerneland 7f0000 in ps3 memory.

    First of all you need to edit the header of lv2_kernel.self (from cfw trueblue) at offset 0×1D, replace 36 1A 00 by 4C FC F0. And decrypt it with unself toolfrom fail0verFlow.Openlv2_kernel.elf with Ida pro (in binary file mode), go to offset 360000 and press “C” to convert to asm code.

    TrueBlue use some HVCALL: lv1_insert_htab_entry lv1_undocumented_function_114 lv1_undocumented_function_115 lv1_allocate_device_dma_region lv1_map_device_dma_region lv1_net_start_tx_dma lv1_net_control lv1_panic (shutdown ps3 when TB is unplugged)

    This payload do some hvcall: lv1_insert_htab_entry (maplv1) lv1_allocate_device_dma_region (?) lv1_map_device_dma_region(?) lv1_net_start_tx_dma (?) lv1_net_control(?) lv1_panic (shutdown ps3 when TrueBlue Dongle is unplugged) lv1_undocumented_function_114 (map lv1) lv1_undocumented_function_115 (unmaplv1)

    We need now to dump lv2 and lv1 memory when TrueBlue is plugged. So I create a modified TrueBlue Cfw with peek and poke syscall. It work fine!
    Reply With Quote  

  2. #2  
    hcode123's Avatar
    hcode123 is offline Developer
    Join Date
    Jan 2011
    Posts
    233
    Downloads
    6
    Uploads
    0
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    14
    Likes Received
    63
    This is big news. Why isn't this front page.
    PS3 slim cech2501 1tb internal ROGERO 4.30CFW V2.05 spoofed to fw 4.41
    PS3 slim cech2001 500gb internal ROGERO 4.30CFW V2.05 spoofed to fw 4.41
    PSP 3000 6.39 PRO-B10 32GB M2
    PSVITA OFW
    WII 4.3u usb configurable 8gb sd
    Reply With Quote  

  3. #3  
    tthousand's Avatar
    tthousand is offline Paradigm/Paragon/Prototype Robo Model #I
    Join Date
    Sep 2010
    Location
    The Future
    Posts
    6,598
    Downloads
    32
    Uploads
    143
    Mentioned
    139 Post(s)
    Tagged
    2 Thread(s)
    Likes Given
    2624
    Likes Received
    2496
    Quote Originally Posted by hcode123 View Post
    This is big news. Why isn't this front page.
    Have you looked on the front page?!?! It was there about 10 minutes before you posted
    Mathematician likes this.


    FacebookTwitterYouTubeCFW/JBDowngradingCheatPKGs
    PS3BrewPS3Brew v2PSVitaBrewWallOfFamePS3DevWikiRebugGitbrew
    Reply With Quote  

Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •