PS4 News on Facebook! PS4 News on Twitter! PS4 News on YouTube! PS4 News RSS Feed!

Home PS4 News - Latest PlayStation 4 and PS3 News

January 16, 2011 // 9:50 pm - Update: PS3 hacker Graf_Chokolo has now shared news of a PlayStation 3 GameOS Hypervisor exploit (quoted below) and released a NPDRM Decryption Payload (GIT) for developers while JU57FL1P has decrypted an NCIS Eboot.

PlayStation 3 developers were previously unable to decrypt NPDRM EBOOT.BIN's (like those in PKG files) as the PS3's NPDRM encryption differed, but today Graf_Chokolo has figured out how to use appldr to decrypt NPDRM encrypted data from Sonic 4.

For those who haven't been following, prior to this PS3 hacking update Graf_Chokolo was working on porting the LV1 Exploit to GameOS mode.

Graf_Chokolo said the following, to quote: "Dumped appldr arguments for NPDRM decryption on 3.41. I'm able now to decrypt NPDRMs with appldr on 3.41. Thanks to Jack for his support.

Here is a snippet from Sonic 4 NPDRM decrypted on 3.41:

[Register or Login to view code]

Guys, if someone has NPDRMs to test please upload it. Thanks.

Uploaded my new stuff: NPDRM, SYSCON, HV exploit from GameOS and other thinsg.

With NPDRM payload you won't be able to decrypt all NPDRMs.

I 'm already able to decrypt dev_flash by using HV calls only.

HV uses ENCDEC device to do storage device encryption/decryption. I'm currently working on reversing of this peripheral. I have full HV access now and can control it So expect more nice stuff in the future

And thanks for all NPDRMs, guys. I will test them and will let you know which one decrypted.

Guys and be careful with store_file_on_flash.c and replace_lv2.c payloads. With store_file_on_flash.c i'm able to store a new file on FLASH memory where CORE OS files are stored from PUP. If you do not know what that means then don't play with this, it could brick your PS3, but it's safe to use when you know what you do.

With both of those payloads i'm able to boot a patched lv2_kernel.self from FLASH without flashing PUP, i just store a second lv2_lernel.self on FLASH, then patch System Manager in HV which is reponsible for booting GameOS and boot custom LV2 kernel from 3.41. You don't need NOR flasher if something goes wrong, just reboot HV and your original lv2_kernel.self will be booted again

The same way you could boot lv2_kernel.self from dev_flash. Just patch path to lv2_kernel.self in System Manager and point it to lv2_kernel.self stored on dev_flash

Theoretically, yeah, you could run what ever OS you want It has just to support Cell arch Today i will try to boot PS2 soft EMU instead of LV2 kernel. Linux would be nice of course and it would have all the rights of GameOS.

I'm reversing currently HDD, BD and FLASH encryption/decryption, trying to understand how HV does it. The key to understanding of it is the ENCDEC peripheral device which i'm currently working with. As soon as i have some good results which can be used by other developers i will make it public and let you know. Are you also reversing this part of HV currently ?

Booting PS2 EMU didn't work, i could boot ps2_emu.self but the screen was black. PS2 Soft EMU ps2_softemu.self didn't boot at all, HV shuts down. You have to patch also LAID in System Manager and not only file path or else lv2ldr wont't decrypt the PS2 kernel.

otheros.self is not a kernel like LV2 or Linux, it's gameOS application, you cannot boot it like a OS kernel on PS3. But i see no problems to boot Linux kernel instead of LV2. To boot Linux kernel image instead of LV2 kernel, you have to store Linux image on CORE OS flash, patch GameOD System Manager and point kernel path to Linux image, then patch System Manager so it won't use lv2ldr to load the Linux image, just memcpy Linux image to memory of GameOS.

HV procs cannot read USB devices because there is no USB device driver in HV. USB device driver is implemnted only in gameOS kernel and without some kind of USB device driver in HV there is no way to boot a LV2 kernel from USB. I can only boot LV2 kernel from CORE OS flash or dev_flash."

Graf Chokolo Decrypts PS3 NPDRM SELF Data from Sonic 4 Game

Follow us on Twitter, Facebook and drop by the PS3 Hacks and PS3 CFW forums for the latest PlayStation 3 scene and PS4 Hacks & JailBreak updates with PlayStation 4 homebrew.

#13 - ian2k6 - January 17, 2011 // 11:17 am
ian2k6's Avatar
all the games i bought legally from the psn have stopped working for some reason, it's saying i need to renew the license on all of them. i did go in and out of factory mode the other day though as a test, would that have something to do with it?

#12 - solrac1974 - January 17, 2011 // 9:33 am
solrac1974's Avatar
Great news, can't wait to see all games and DLCs decrypted and available to everyone! Thanks to Graf Chokolo.

#11 - moja - January 17, 2011 // 8:40 am
moja's Avatar
Hey Graf, congrats and good work! Here's a Venetica eboot (disc game), would you be able to test this one out? (BLES-00776)

#10 - jokr2k10 - January 17, 2011 // 8:23 am
jokr2k10's Avatar
Hopefully this will allow for 1.05 update for GT5 and others to be decrypted and patched... i am so tired of grinding LeMans 24 hour... plus the fact that 1.05 adds new races, and increases money per race.

#9 - clouduzz - January 17, 2011 // 7:05 am
clouduzz's Avatar
this is awesome! Hopefully it'll be just as easy to sign as it is now, I have two ps3's but only one has my psn games, now hopefully soon I'll be able to copy them to my other one

#8 - CJPC - January 17, 2011 // 5:12 am
CJPC's Avatar
Well, simply put - up until now the way to decrypt NPDRM selfs (like, EBOOT.BIN's inside PKG files) has not been known. So, any DLC only games that are for newer FW's (among other reasons) will eventually be able to be decrypted using this method, then perhaps resigned and played on a lower firmware - and that is just to start!

#7 - Brian10122 - January 17, 2011 // 5:09 am
Brian10122's Avatar
So, what does this help? I'm truly confused.

#6 - jokr2k10 - January 17, 2011 // 5:00 am
jokr2k10's Avatar
I *LOVE* Sonic 4. it's really the only thing I have missed on my Wii other than New Super Mario Bros. and the Guitar Hero games (yea, i know i can get the Guitar Hero games on PS3, but i already had the guitar for Wii ) LOL

#5 - serial2305 - January 17, 2011 // 4:59 am
serial2305's Avatar
good news, great work!

#4 - PS4 News - January 17, 2011 // 4:51 am
PS4 News's Avatar
Moved to the main page now, and +Rep maxdb1984 for the news!