Forum: Latest News - Get all of the latest legal dev and underground news as it relates to the Sony PlayStation right here on PSX-Scene.


The above video goes away if you are a member and logged in, so log in now!




 
Would you like to get all the new info from
PSX-Scene in your email each day?




Want to learn more about the team keeping you up to date with the latest scene news?

Read about them now!

Check out our Developer bios, too!

 


User Tag List

Thread: How to Hook into LV2 Memory!
  

Page 2 of 3 FirstFirst 1 2 3 LastLast
Results 11 to 20 of 30
  1. #11  
    Jon Salat is offline Member
    Join Date
    Aug 2010
    Posts
    394
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    Very interesting, maybe we can change region for PS1/PS2/DVD/BD with this method.
    Reply With Quote  

  2. #12  
    mеdi01 is offline Banned
    Join Date
    Sep 2010
    Posts
    389
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    Quote Originally Posted by Dark Scyth View Post
    Of course you may want to wait for someone else to try this, could be some bricking problems.
    Why on Earth? We are talking about on the fly modifications of the loaded memory, that do not touch flash.
    Reply With Quote  

  3. #13  
    DeadlyFoez's Avatar
    DeadlyFoez is offline Banned!
    Join Date
    Sep 2010
    Posts
    286
    Downloads
    2
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    4
    Quote Originally Posted by mеdi01 View Post
    Why on Earth? We are talking about on the fly modifications of the loaded memory, that do not touch flash.
    Technically, if someone adjusts code the wrong way then it could possibly lead to writing data to the flash memory. Is it likely? Probably not. Is it still possible? Yes.

    Luckily we have a bunch of very talented programmers here that know what they are doing.

    Trust me, it is very possible to brick a PS3 through software with only lv2 access. Remember the fake PSP Emulator?
    Reply With Quote  

  4. #14  
    vampirexx's Avatar
    vampirexx is offline Member
    Join Date
    Oct 2010
    Posts
    166
    Downloads
    1
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    5
    Likes Received
    9
    i would like someone to develop a live cheat system like comparison scan memory to find out cheats for offline games is it possible using this discover?
    Reply With Quote  

  5. #15  
    jebise is offline Member
    Join Date
    Sep 2010
    Posts
    34
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    how about we get whats more important here like retail to debug without a usb dongle linux etc before we start working on game cheats. Like come on dude WTF?
    Reply With Quote  

  6. #16  
    clik.MEK is offline Member
    Join Date
    Oct 2010
    Posts
    194
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    11
    Likes Received
    27
    Quote Originally Posted by garyopa View Post
    PS3mrengigma has updated his blog with a tutorial on how to hook into LV2.

    In this tutorial he utilizes, the undocumented, SYSCALL 867 for his hook.

    SYSCALL 867, which he explained previously, controls the PS3′s model information (retail, debug, reference tool etc).

    In his tutorial he walks us through the process of making his debug PS3, thinking its a Retail unit (there is no benefit to making it think its a retail, its simply a learning exercise).
    tbh this tutorial is way over my head, but it read like the guy does know what he is talking about. I would like to understand a little more of it, so if anybody with more knowledge than me has the patience to answer sth of the *probably* bs I am going to post, then: thanks!
    From what I got this is really huge, isn't it?

    Quote Originally Posted by garyopa View Post
    For this section we should bear in mind that we need to meet the following requirements:

    - Take a dump of the entire LV-2, possibly without being modified in any way by a payload.
    – Knowledge of assembler to understand the original SYSCALL to create our hooks.
    – Understand how the / s SYSCALL we will modify.
    So you dump lv2 memory over ethernet using some tools, right? But does this work without jailbreaking? As he says "not modified by a payload"?

    Quote Originally Posted by garyopa View Post
    For this post we will take the example of a LV-2 3.41 Debug (for it is that I work mostly), but can be applied just as in a LV-2 Retail.
    here again, is he talking about a jailbroken unit or not? Or is it like he can dump lv2 memory on his debug unit, but a retail would not be able to do it (without jailbreaking)?

    Quote Originally Posted by garyopa View Post
    Once copied, you need to install the hook so that when the modules call the SYSCALL call our code, in our case as we know where to start our code (0x54408), proceed to write this direction in the second memory address that points that indicate the SYSCALL_TABLE, ie 0x348FB4.

    Once done, any module, homebrew, etc to call that SYSCALL go through our hook, and if the command is 0x19004, we will refund a forced Retail Eur.
    ok he dumped lv2 and modified the syscall to be callable by any homebrew.
    So any hb could implement that syscall and it would return "I am a debug"?
    great! all debug functions would be enabled that way. That surely is why that syscall isn't documented in the sdk
    Futher questions: When is this patching happening, is it part of the jailbreaking payload, is the code part of a homebrew app, or is both possible? Once the hook is complete, you would write that in devflash, so this is permanent, right? No need for dongles any more? Can that be done without bricking the console? And what are other possible applications of the "hooking" of syscalls?
    Reply With Quote  

  7. #17  
    t_jay17 is offline Member
    Join Date
    Mar 2005
    Posts
    173
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    0
    I wonder if this can lead to a way to get onto psn?
    Reply With Quote  

  8. #18  
    talmagal is offline Member
    Join Date
    Aug 2010
    Posts
    712
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    0
    Likes Received
    3
    Quote Originally Posted by subcon959 View Post
    I need the syscall for increasing my bank balance.
    damn staright
    I'm Looking For An Alien Toilet To Park My Bricks, Who's First?

    -DNF
    Reply With Quote  

  9. #19  
    Join Date
    Sep 2010
    Posts
    61
    Downloads
    0
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    1
    Likes Received
    0
    I hope somebody can use this to find a way to make the PS3 return the latest FW version to PSN.
    Reply With Quote  

  10. #20  
    phlak is offline Member
    Join Date
    Sep 2010
    Posts
    86
    Downloads
    1
    Uploads
    0
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Likes Given
    2
    Likes Received
    0
    I just want something to lead to CFW with no more need for jailbreaking. Just a simple flash and to be on CFW for good. Someday I suppose, as for now way to go on the progress in the homebrew scene.
    Reply With Quote  

Page 2 of 3 FirstFirst 1 2 3 LastLast
Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •