Thread: PS3 CEX (Retail) to DEX (Debug) Conversion Method is Released!

    Weezum Guest


    i'm so confused..

    haze67 Guest

    works good

    thx to rikukh3, zecoxao he made my day.. thx guys, it's all clear here, easy once you know it

    recreated stuff/identical and bam cexdex not flashed yet

    ps: for entering servicemode after flashing dump, the files from E3 exit/enter SELF's can be used or do we need another/older FSM self?

    i'm asking cuse there are different ones

    sguerrini97 Guest
    The tutorial says to install DEX Firmware through recovery menu, not FSM

    haze67 Guest
    yup, should be ok

    Quote Originally Posted by rikukh3
    After you flash nor, you need to install dex firmware via service menu with lv2diag.self (like in old 3.41 downgrade methods).
    thats why i asked ... you've tested this/installing DEX in recovery after flashing back?

    if one is on cfw355 i've heard jaicrab preloader can be used to flash this back? or is a hardware flasher required, only for 3.60++ if the backup/restore function works from preloader on cfw355 and not only that 365cfw?

    EiKii Guest
    Well it should aslong as you don't have NAND, but i wouldn't recommend it, as if it brick and you don't have a hw flasher, you will need to get one. AND Jaicrab advance is pretty much beta or lower

    so proceed carefully as MANY things can go wrong afaik.

    rodq Guest
    The first 16 bytes of decrypted EID0 Section should match the first 16 bytes of the EID0. If not, STOP!

    Weezum Guest
    when i use open ssl and and i cp aes-256-cbc -e -in EID0_Key_Seed.txt -out EID0IV.txt -nosalt -K its says file not found.

    where do i save eid0 key?

    rodq Guest


    openssl enc -aes-256-cbc -e -K key -iv initialization_vector -p -nosalt -nopad -in file.bin -out file_crypted.bin
    -p flag will pop out the [key] and the [initialization vector]

    If you like PERL instead of OpenSSL... i made a nice script..

    haze67 Guest
    Quote Originally Posted by rodq View Post
    The first 16 bytes of decrypted EID0 Section should match the first 16 bytes of the EID0. If not, STOP!
    yes the IDPS/16 bytes, thats the one for total verify right if correct? my dump matches up idps

    check in original cex dump (with modified TargetID - 82) - offset 002f070/EID0 - first 16 bytes = IDPS
    must match up with decrypted eid0 (eid0_dec.txt - open/use with HxD) first 16 bytes (IDPS)
    original IDPS = cex targetID e.g 0085

    for NOR, preloader should work? nice, i have e3 flasher, if preloader can do the job why not .. all the e3 hassle, not to sure of preloader either haha or is it real buggy? thx

    Weezum Guest
    so what do i do with that, sorry not afraid to admit noobness. and I ain't scared on no brick sorry had to say that.

