09-20-2012 #41xrayglasses Guest
You don't need a lv1 exploit, it can glitch HTAB..
09-20-2012 #42JOshISPoser Guest
if that was to me, it doesn't make sense.
eh, whatever. i know it's not exactly for me, i was just wondering the possibilities but i'm guessing it's not something easily explained in a sentence or two in laymen terms.
09-20-2012 #43CJPC Guest
Generally, assuming that there is already a user mode exploit (think an exploit in a game), using this exploit will allow you to elevate permission to kernel level. The simplest way to think about it is the PSP exploits, and how multiple exploits were needed. Generally, of course!
09-20-2012 #44JOshISPoser Guest
i'm understanding it a bit more. the higher the lvl, the more security breaches needed because it'll allow it to be more open?
09-21-2012 #45technodon Guest
basically a payload like the one used in the 3.41 jailbreak (hermes) is loaded into stack overflow when the ps3 tries to read this the payload is loaded into memory and you get unsigned code execution. but the problem is that ps3 is using the stack and it copies something to it instead of reading first.
so the payload which has been loaded there is being over written before it has been read and is deleted so if you could somehow make the ps3 read from stack or load the payload just before the stack gets read the payload would be loaded and you have a new jailbreak.
09-21-2012 #46Tidusnake666 Guest
stack overflow... so 199X-th.... but still works!! Haha!
I still prefer to use 0xFACEBOOC instead of 0xABADCAFE lol
09-21-2012 #47xrayglasses Guest
again.. it can write HTAB entries..
One you get a stable execution (hint ROP) you can glitch HTAB entries and do anything except persistent root because bootldr couldn't even be figured out by fa1loverflow team..
If you're looking for a lv1 exploit you'll never get anywhere unless you get a talented RE person with a lot of time, and since it's obvious Linux means less than piracy is PS3 scene that isn't likely to happen..
09-21-2012 #48dalmatianu Guest
- Join Date
- Apr 2005
PS3 4.21 EBOOT Resigner SCETool Script is Released for 4.21 CFW
Following up on the previous update by Naehrwert and yesterday's PS3 LV0 Keys leak, today Chinese developer Rain fish (aka JjKkYu) has released a 4.21 EBOOT Resigner PS3 SCETool (aka TrueAncestor EBOOT Resigner) script which allows the resigning of 3.55 or decrypted EBOOT.BIN files for use with PlayStation 3 4.21 CFW.
Download: PS3 4.21 EBOOT Resigner SCETool Script / PS3 4.21 EBOOT Resigner SCETool Script (Mirror) / PS3 4.21 EBOOT Resigner SCETool Script (Mirror #2) / PS3 4.21 EBOOT Resigner SCETool Script (Mirror #3) / TrueAncestor EBOOT Resigner / TrueAncestor EBOOT Resigner Oldschool 3.55 Resign Added by haz367
To quote, roughly translated: Update: I renamed my resigner to TrueAncestor EBOOT Resigner and add DEX support. Enjoy.
This is a script of SCETool to resign the 3.55- or decrypted EBOOT.BIN for 4.21CFW use.
1. Extract the 4.21 EBOOT Resigner.zip.
2. Put EBOOT.BIN into the extracted folder.
3. Run resigner.bat to resign EBOOT, you may need to choose encrypt type.
4. If you chose NPDRM type, you need to enter Content-ID.
5. The original EBOOT.BIN will be renamed to EBOOT.BIN.BAK.
This script is tested on BD4.21 CFW, and it should work on Rogero 4.21. Some game also contains decrypted self or sprx file, you need to resign them manually.
Credit to badzbb.
Note: This script uses 3.60 keys to encrypt the EBOOT, no new keys.
TrueAncestor EBOOT Resigner Oldschool 3.55 Resign Added by haz367:
All credits to JjKkYu, badzbb, aldostools, Asure and everybody else... added 2 more options to it for 3.55 users:
5. Disc t/m 3.7X Backup EBOOT Auto-resign (Oldschool 3.55 CFW)
6. NPDRM Game/Update t/m 3.6X EBOOT Auto-resign (Oldshcool 3.55 CFW)
Only add the "keys" file to it.
From danixleet comes some PS3 homebrew ports as follows: 4.XX CFW Homebrew (In theory these should all work on OFW 3.6+)
- BlackB0x FTP V1.2 for 4.21 CFW / Blackb0x v1.2 for 4.21 CFW (by hawkeye#2360) / Blackb0x FTP 1.2 for 4.21 CFW (Mirror)
- ReActPSN Rogero Fix for 4.21 CFW / Rogero 4.21 VSH.elf by lurkandlearn (0x300FD4: 4BFFCDE1 --> 38600000 and 0x300A34: 4831EE1D --> 38600000. Someone with a hardware flasher and knowledge how to properly reencrypt vsh.self needed to test this).
- Several PS3 CFW 4.21 Homebrew Ports by pounou
- Several PS3 CFW 4.21 Homebrew Ports by Luis ngu
- Rogero Manager v8.5 Solar Edition by Luis ngu
- PSNinja v3 by Luis ngu
- Comgenie's Awesome Filemanager v0.06 for PS3 4.21 CFW / Comgenie File Manager for Rebug 4.21.1 by haz367 (75% working - installs and runs fine on REX, no access to all folder... home/theme so 75/100 % is working for the rest use MM's file manager cause it can access all folders, must be some code missing in Comgenie's Filemanager)
- dev_blind for 4.21.rar
- blackb0x FTP 1.2 for 4.21.rar
- reActPSN for 4.21.zip
- Open PS3 FTP for ROGERO CFW 4.21 by [email protected]€R$-
- JochenHippelTribute.pkg (Musical Demo) for CFW 4.21 by traube
- PSIDPatch 1.5 for PS3 4.21 CFW by itskamel
- Retroarch Multi Emulator / Game System / Mirror
- PCEEMU (PC Engine) by LoboGuara
- GenesisNEXT (Mega Drive/Genesis) by LoboGuara
- SNES9XNEXT (SNES) by LoboGuara
- VBA (Game Boy Advance) by LoboGuara
- MAME (Arcade) by LoboGuara
- Fuse (ZX Spectrum) by LoboGuara
- SCUMM by LoboGuara
- Gambatte (Game Boy Color) by LoboGuara
- SNES 9x 4.4.8 for 4.21 CFW by snkysnake02
- FCEU 1.05 for 4.21 CFW by snkysnake02
- Sega Genesis for 4.21 CFW by snkysnake02
- VBA 1.0 for 4.21 CFW by snkysnake02
- SNES9x v4.4.9 for 4.21 CFW by snkysnake02
- Super Mario War by snkysnake02 (this one requires the appropriate map files etc.. placed on your external if I remember right. Just search and obtain the map files for the game. this is just the installer for PS3, I have tested this and it works. If you already have this game installed then just delete from XMB and install this pkg and run game)
- GameDATA v3.0 for 4.21 CFW by snkysnake02 (allows you to switch back and forth between installing on the internal HDD and External drive. Just click icon and it will switch, to switch back click the icon again)
- Scummvm 1.5 for 4.21 CFW by snkysnake02 (this is the latest version)
- Showtime_4.0_4.21.rar (Standalone Signed by Simonbuck)
- Solar 4.2 for CFW 3.55-4.XX by Condorstrike
- PS3LoadX_4.XX for 4.XX CFW by Condorstrike
- WinDOS EBOOTs for 4.XX CFW / DEX by samson
- PS3UserCheat by Luis ngu
- PSNinja v4 for 4.XX CFW (Mirror) by itskamel
- PSNinja v4 for 4.XX CFW by smokin
- Mednafen (Multi-System Emulator)
- PS3VECX (Vectrex)
- RetroArch 0.9.7 (Multi System Emulator)
- RetroArch Unofficial Standalone Emulators
- PS3MAME 0.142 (Preview Edition)
- FUSE (ZX Spectrum)
- Stella (Atari 2600)
- ViceNEXT (Commodore 64)
- E-UAE (Amiga)
- SCUMM 1.5
- Showtime 4.0
- Showtime Disc Access
- Paintown 3.6.1 Mod Pack v2.pkg for CFW 4.21 1.01
- Scrogger HD
- Gambol by primetime43
- UFO Racer v3.4
- They Do Not Die 2 v0.8
- Winters End v1.0
- That Other Pong v2 by primetime43
- Hero City 2 v1.3
- Cylinder Dodge v1.1
- Cascade Beneath v1.1
- Don't Get Crushed v1.2
- Oregon Trail DOSBox
- Maniac Mansion DOSBox
- Sam And Max Hit The Road DOSBox
- Cool Spot DOSBox
- Lemmings Collection DOSBox
- Lemmings 2 DOSBox
- Day Of The Tenticle DOSBox
- SNES9x v4.4.9 mM 4.21 Signed by Luis ngu
- Clear History PSN Stealth version MoD update v0.1
- SEN Enabler Version Spoofer 4.20 for v4.21 CFW by itskamel
- PSIDPatch v1.5 Resigned for 4.30 by DANNY G
- EsKiss PS3 Homebrew for 4.30 (put the EBOOT.BIN in the USRDIR) / EsKiss PS3 Homebrew for 4.30 by [C*] (I thought 3.55 .pkgs wouldn't install on 4.XX, the same way 3.41 .pkgs wouldn't install on 3.55, but that's not the case. So just download the .pkg, install it, and then copy the resigned EBOOT.BIN attatched here over to the dev_hdd0\game\Eskiss\USRDIR\ directory. (The one in the EBOOT.RAR in the other post is an Epic Mickey 2 EBOOT). The game ran for me, showed the menu, but I think it crashed because the home button on my controller wouldn't work. Unless it's because I don't have Move?)
- EsKiss PS3 Homebrew for 4.30 by alienkid (Install Eskiss then, in multiMAN>File Manager>dev_hdd0>game>Eskiss_00>USRDIR.. Replace that eboot with the one included).
- Eleganz: The Elegant Homebrew Manager PS3 (Resigned 4.xx) PKG by haz367 (runs ok - exit = black screen - no HDD corruption!)
- Resigned SNES (SSNE88888) for ALL Firmware by haz367
RetroArch Package Signed for 4.30 by deank (delete your old one before installing)
- Doom v0.05 for PS3 CFW 4.21-4.30 (signed by ConsoleHackDev Team)
- ScummVM 1.6.0 PS3 Emulator (Compiled by pete_uk)
- PS3 Heretic CFW 4.21-4.30 (To play, install the PKG and put your heretic.wad on the same folder where EBOOT.BIN is located (i.e. /dev_hdd0/game/HERETIC01/USRDIR) - signed by friend of LoboGuara)
- DosMount DOS Package to Install DOSBox Games for CFW 4.21/4.30 (signed by ConsoleHackDev Team via consolehackdev.com/forum/area-51/release-zone/934-dosmount-re-signed-per-cfw-4-21-4-30-consolehackdev-team.html)
- Get IDPS.pkg (4.20+ Signed) by Anxietic
- IrisManager v1.25 for PS3 4.XX CFW by D_Skywalk and Estwald
- Showtime v3.99.425 Signed for 4.30 CFW by gLacK
- Resident Evil Paintown Final Alpha for PS3 4.XX CFW by Daveyshamble501 and Markus95
- Paintown v3.6.1 Mod Pack v2 PKG for PS3 3.55 or 4.XX CFW by Daveyshamble501 and Markus95
- PS3 Disc Key Dumper, Klicensee Dumper and Secure File ID Dumper for 4.21 CFW by Flat_z
- PSChannel RC1 PS3 Homebrew Store for 4.21 and 4.30 CFW by atreyu187 and STLcardsWS
- Modded PS_Unban Version for 4.XX CFW by Hells Guardian
- RetroArch v0.9.8 Beta 3 Unofficial Standalones (4.21-4.30 CFW) by STLcardsWS
- PS3 CFW 4.XX Resigner Script v0.3.3b
- Resigned ColdBoot Installer Rebug 4.21 by Nicolas19
- PSIDPatch 1.6 for PS3 (Resigned for 4.30 CFW) by willmav5000
- PSIDPatch 4.21 CEX & DEX (DEXPSIDPatch / CEXPSIDPatch) by arj1231
- Mednafan v0.9.16 Resigned for Rogero 4.30 PS3 CFW by sheaushyong
- PS3 eEID_Dumper.pkg / eEID_RKDumper.pkg Signed for 4.31 by jarmster
- DOSBOX 0.74 PS3 by Robo Hobo for 4.XX CFW Resigned by pete_uk
- ScummVM 1.6.0 git2625 gadc338c PKG for 4.XX CFW Resigned by pete_uk
- PRBOOM-PLUS-126.96.36.199-R3.pkg / PRBOOM-PLUS-188.8.131.52-R3_ULTFREEDOOM.pkg for 4.XX CFW Resigned by pete_uk
- PS3 EID Dumper Resigned for 4.31 CFW by OtaconSnake
- PS3VNC Viewer Resigned for PS3 4.30 CFW by troy1
- Dance Clone v0.6 and Avoidance v1.3 Resigned for PS3 CFW 4.XX
- DEX 4.30 XMB_Plugin.30.rar by DANNY G
- PSIDPatch for 4.40 CFW by solidspike
- How to ReSign (Port) and Sign PS3 Homebrew to 4.21 CFW Guide
From Condorstrike also comes Solar 4.2 for CFW 3.55-4.XX and PS3LoadX_4.XX for 4.XX CFW with details on the latter below:
Here's an updated and repacked PS3LoadX for 4.xx CFW’s, did some minor code cleanup, and bug removal, also reduced application size and replaced the loading method. Also replaced ICON0 and PIC1 for better aesthetics. Enjoy...
- Repacked for use with 4.xx CFWs.
- Replaced loading method.
- Fixed minor bug with Temporary Folder.
- You can load SELF files using the net.
- You can load applications from USB/ HDD devices
- You can install applications to the USB or HDD devices from one .zip file
- You can copy applications from USB devices to HDD
- Also you can delete installed applications.
Installing and launching programs and .zip files:
- You can load .ZIP files via tcp using the network, just like the SELFs.
- An “install” folder will be built into your [USB/HDD root: Homebrew] Folder and contents shadow copied to PSL145310/homebrew/install.
- The “install” folder can be added manually as-well, if no network loading is to be used.
- Programs will be displayed in PS3LoadX and buttons commands will be available accordingly.
Finally, from samson: I ran windos eboot through all options in the resigner, if my guess works right you should be able to install windos final for 3.55 on 4.xx cfw's/dex and just replace the eboot. Also some should work for my other dos games/toys.
More PlayStation 3 News...
10-23-2012 #50elser1 Guest
great news but wheres the 4.30 cfw. that be the one we want!
Please upload to mediafire or some thing that works without all the garbage that goes along. so sick of trying to download and need this livid crap etc, mediafire is best. should be the only one allowed i think!