PS4 News on Facebook! PS4 News on Twitter! PS4 News on YouTube! PS4 News RSS Feed!

Home PS4 News - Latest PlayStation 4 and PS3 News

September 29, 2010 // 12:54 am - Today KaKaRoTo has introduced a common repository of payloads that can be used by any PS3 JailBreak implementation called PL3, and also said he is making progress with PSFreedom ports for PS3 Firmware 3.01, 3.10 and 3.15.

Download: PL3 PS3 JailBreak Payloads

To quote: "I'll announce two things, first, let's talk about PL3.. PL3 is a new project I started in order to have a common repository of payloads that can be used by any 'jailbreak' implementation. I got tired of copying payloads from PSGroove, and I had some nice changes in mine that I thought the PSGroove project could benefit from, so I thought I'd create a single repository that both projects, PSFreedom and PSGroove (or any other similar projects) could use.

You can find it in github, so don't hesitate to submodule it and use it.

Second important news... I've bought a new PS3 just for homebrew. Thanks to all who donated money so I can buy it (I didn't get enough donations to pay for it, but enough to help me). I bought this PS3 used and it came with firmware 3.01! This is good and bad news : I can't use PSFreedom to jailbreak it, so i've put on hold any improvements for it, however, it will allow me to actually port PSFreedom to older firmwares! My plan is to get the jailbreak working on 3.01, then move on to 3.10 and 3.15 (depending on how hard it is, i might skip 3.10).

Another good news is that after 4 days of work, I was finally able to dump the LV2 memory from the 3.01 firmware, and now all that remains is to find the right offsets to patch, and port PSFreedom to 3.01, so all those who are still using this firmware version, you will soon be able to jailbreak it! Once I'm done with that, I'll try to do the same with the 3.10/3.15 firmware versions!

To dump LV2, I used a trick and algorithms found by marcan42, so big thanks goes to him, as well as many other people who helped me out, RichDevX and Aaron in particular. I used RichDevX's idea of ignoring the JIG and bruteforcing the address in which the port1 descriptor gets stored until I get a hit, then use that payload to dump lv2, then find the right JIG offset for that particular firmware from the dump. Marcan's trick was to send the data through the ethernet cable by using LV1 only hypercalls, and it worked!

Now the latest git version of PL3 has a new 'dump_lv2′ payload which you can use, it is firmware independent, and only uses LV1 hypercalls, so it should just work... It will dump all the lv2 memory through ethernet, so fire up wireshark, save the dump to a .pcap file, and use the tool in PL3/tools to extract the memory dump from the .pcap file.

In other news, I will soon upload to Ps3utils an .idc script that will search and find the syscall table, and correctly resolve all of its functions and name them properly.. maybe even have it automatically find all functions of a dump in order to save time creating procs in IDA. I'll let you know once I'm done with it."

KaKaRoTo Introduces PL3, 3.01, 3.10 and 3.15 PSFreedom Ports

PlayStation Follow us on Twitter, Facebook and join us at our new site WWW.PSXHAX.COM!

#40 - PS4 News - October 1, 2010 // 7:35 am
PS4 News's Avatar
Continue discussion in the new thread here guys:

#39 - spartan6199 - September 30, 2010 // 4:13 am
spartan6199's Avatar
sounds good, keep up the good work!

#38 - mestereo - September 30, 2010 // 2:22 am
mestereo's Avatar
Should try to go way back to like the very 1st firmwares like 1.0, 1.02 and up from there. Just a sugestion!!

#37 - syncmasters - September 29, 2010 // 11:42 pm
syncmasters's Avatar
I'll be answering those questions with my limited knowledge acquired from reading dev threads here...

1. Original JB was supposed to be updateable.

Yes. They are supposed to be upgradeable...

2. What is exactly different in this payload that makes it work on 3.15 and 3.42?

KaKaRoTo's payload only works on 3.01 as far as I could understand... If we are talking about the Jailbreak Payload.

The other hack payload is to use some lvl1 syscalls to make the PS3 dump all memory pages (lvl2 / Game OS) trough Ethernet.
This probably works on any firmware.

To actually make the Jailbreak Payload work on any firmware different then 3.41 you need to know the exactly ram page address on memory, so that you can patch those addresses tho known functions that we can easily call.

3. Do they have this up and running?

Jailbreak Upgrade? Probably not. The hardware lets us burn new Hex Codes but the actual payload is not upgradeable, partially because we have fixed memory page addresses that we need to know beforehand.

3.01 Jailbreak? Probably yes, but buggy. We need the right calls and addresses.

4. When will it be out and will the scene get to it faster before a paid version?

Who knows? The paid version probably has gone and hided itself from anyone since Sony is hunting them.

to 5, 6 and 7... I don't know... maybe?
Only time will tell.

#36 - junior2k9 - September 29, 2010 // 9:14 pm
junior2k9's Avatar
Great work!! Its good to see the scene moving forward! What would happen if you would try to brute force over ethernet the newest firmware as you did with the older one?

Maybe we could get a new payload for that or have they patched it all together?

#35 - PSPSwampy - September 29, 2010 // 9:09 pm
PSPSwampy's Avatar
Great news - just a little too late for me I went ahead and upgraded from 3.10 to 3.41 so i could have a play - wish i'd waited now.

Although on the other hand - my PS3 still has it's OtherOS partition intact, so it will be interesting to see what exactly happens when we to boot 3.15 with Jaicrab's loader and switch to OtherOS. I know it restarts the console, but wonder if it leaves a flag set to boot the other partition - will be interesting finding out.

Just need a 3.01-3.15 dev_flash dump to play with - here's hoping someone uploads one when this JB becomes available


#34 - izac01 - September 29, 2010 // 6:14 pm
izac01's Avatar
Amazingly huge step out o no where. GOOD WORK! NOW on to 3.5 lulz

#33 - v0ld - September 29, 2010 // 5:45 pm
v0ld's Avatar
great work - let's hope to jb 3.15 soon.

Not to forget the ppl who want to update their games but have no network ... i know some of them. Making it possible to download game-updates via PC and transferring it to an "unconnected" PS3 would also be great.

#32 - WeOutHere - September 29, 2010 // 5:34 pm
WeOutHere's Avatar
Good work K-Man! I love the developments that are going on these days. I can't wait to see what kind of tools we will have in only a month from now. Slightly off topic, but an easier way to get game updates would be great, like a Game Update Repo that we can connect to in the future, or something similar.

#31 - tryerps3 - September 29, 2010 // 5:12 pm
tryerps3's Avatar
Very good point. Also, they could possibly find exploits in previous versions that could be worked on to hack future FW's.

I've been on 3.15 since before April 1st for one reason only: I spent around 20-25 hours of my live configuring my YDL to work just the way I want on my PS3, and I'm not letting FONY flush it down the drain coz they were trying to patch something they didnt fully comprehend.

Now I cant wait for JB 3.15, so I can finally mod my Fallout 3 GOTY