Forum: PS3 Technical Development - Topics relating to Playstation 3 Technical development ONLY! Read and discuss the latest Cobra USB updates, tutorials and explanations or find out about bluray drive bypass firmwares plus much more.


The above video goes away if you are a member and logged in, so log in now!




 
Would you like to get all the new info from
PSX-Scene in your email each day?




Want to learn more about the team keeping you up to date with the latest scene news?

Read about them now!

Check out our Developer bios, too!

 


User Tag List

Thread: HV reversing
  

Results 1 to 9 of 9
  1. #1 HV reversing 
    KDSBest's Avatar
    KDSBest is offline PS3 Payload Engineer
    Join Date
    Sep 2010
    Posts
    107
    Downloads
    1
    Uploads
    0
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    55
    Hi,

    alot of new infos about the HV hitted the scene.

    Hypervisor Reverse Engineering - PS3Wiki

    thanks to graf_chokolo.

    is there a way to use "0x10042 - decrypt_lv2_self(spe id, LPAR auth id, SELF file image ptr, LPAR memory address) "?

    Can we execute higher Syscalls?
    Think inside the box, everyone else is too busy trying to think outside the box.

    Follow me on Twitter: http://twitter.com/KDSBest
    Reply With Quote  

  2. #2  
    stoker25 is offline IJDGAF
    Join Date
    Sep 2010
    Posts
    151
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    3
    Likes Received
    2
    Quote Originally Posted by KDSBest View Post
    Hi,

    alot of new infos about the HV hitted the scene.

    Hypervisor Reverse Engineering - PS3Wiki

    thanks to graf_chokolo.

    is there a way to use "0x10042 - decrypt_lv2_self(spe id, LPAR auth id, SELF file image ptr, LPAR memory address) "?

    Can we execute higher Syscalls?
    graf's modded payload is able to use the HV services, so once hes released that we should be able to decrypt selfs, although it seems that function decrypts a SELF into an LPAR memory region, so we might still need a LV1 exploit to read that memory, i'm thinking of setting up asbestos and using geo's exploit, but i'm not sure what hardware is needed, if anybody knows i'm willing to go buy it, please drop me a PM
    PSIDPatch - http://bit.ly/psidpatch
    xRegistry Editor - http://bit.ly/xregistry
    Playstation 3 Update Repo - http://bit.ly/iR2iXh

    People, stop hating on Math & Co. If it wasn't for them we'd be nowhere, so what if they have their secrets? Remember, they could of just decided not to show anything
    Reply With Quote  

  3. #3  
    Jon Salat is offline Member
    Join Date
    Aug 2010
    Posts
    394
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    Atmega8 can be used;

    Dumping PS3 Hypervisor and Bootloader with Atmega8 at 16Mhz - PS3 NEWS - PlayStation 3 News - PS3 Hacks

    The actual internal hardware is pretty simple, just one wire soldered onto a resistor, with another wired to ground.

    PS3 Exploit: Hardware « xorloser’s blog
    PS3 Exploit: Software « xorloser’s blog
    Reply With Quote  

  4. #4  
    KDSBest's Avatar
    KDSBest is offline PS3 Payload Engineer
    Join Date
    Sep 2010
    Posts
    107
    Downloads
    1
    Uploads
    0
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    55
    that is not needed with the help of this syscall

    0x10002 - lpar_memory_addr_to_phys_addr(LPAR id, LPAR address, physical addr)

    or am i wrong?

    I really want to have that payload
    Think inside the box, everyone else is too busy trying to think outside the box.

    Follow me on Twitter: http://twitter.com/KDSBest
    Reply With Quote  

  5. #5  
    newzy32 is offline Registered User
    Join Date
    Nov 2010
    Posts
    9
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    Quote Originally Posted by KDSBest View Post
    that is not needed with the help of this syscall

    0x10002 - lpar_memory_addr_to_phys_addr(LPAR id, LPAR address, physical addr)

    or am i wrong?

    I really want to have that payload
    I was under the impression you just had to patch in a new lv2 syscall that just passes on a call to the lv1 syscall? (the same way peek and poke are patched into lv2)

    so you would just need to add new lv2 syscalls as proxies for any lv1 syscall you wanted. Or have i misunderstood the situation?
    Reply With Quote  

  6. #6  
    newzy32 is offline Registered User
    Join Date
    Nov 2010
    Posts
    9
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    his payload is here by the way

    https://github.com/grafchokolo/psgroove
    Reply With Quote  

  7. #7  
    Heden_DeLiGhT is offline Registered User
    Join Date
    Nov 2010
    Posts
    6
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    1
    Likes Received
    0
    Quote Originally Posted by newzy32 View Post
    I was under the impression you just had to patch in a new lv2 syscall that just passes on a call to the lv1 syscall? (the same way peek and poke are patched into lv2)

    so you would just need to add new lv2 syscalls as proxies for any lv1 syscall you wanted. Or have i misunderstood the situation?
    You are right !
    The Idea is to code a "bridge" LV2 -> LV1 syscall...
    For that, there are some syscalls in LV2 that can give help ;-)
    Reply With Quote  

  8. #8  
    KDSBest's Avatar
    KDSBest is offline PS3 Payload Engineer
    Join Date
    Sep 2010
    Posts
    107
    Downloads
    1
    Uploads
    0
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    55
    the "bridge" would be a nice to have. Why does everyone wants to make a payload what is against creating a kammy plugin?
    Think inside the box, everyone else is too busy trying to think outside the box.

    Follow me on Twitter: http://twitter.com/KDSBest
    Reply With Quote  

  9. #9  
    ceckin is offline Registered User
    Join Date
    Sep 2010
    Posts
    27
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    Quote Originally Posted by KDSBest View Post
    the "bridge" would be a nice to have. Why does everyone wants to make a payload what is against creating a kammy plugin?
    Kammy is lv2 user patches, while HV patches are for research purpose only, normal user would never need to have lv1/HV/SPU access by default. I believe graf_choko's payload should be the base for every other research payload.
    Reply With Quote  

Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •