PS4 News on Facebook! PS4 News on Twitter! PS4 News on YouTube! PS4 News RSS Feed!

Home PS4 News - Latest PlayStation 4 and PS3 News

March 19, 2012 // 11:23 pm - It's been awhile since the last IDPS update, and today I've created this PS3 IDPS Viewer homebrew application based on research I'm doing and had not planned to release the tool out yet, but if someone needs it here it is (Thanks to J-Martin for the logo).

Download: PS3 IDPS Viewer Homebrew Application / PS3 IDPS Viewer Homebrew Application (USB)

What does this tool?

  • Displays the IDPS
  • Shows Target ID
  • Displays Motherboard revision
  • Save your IDPS in IDPS.bin file

Note: THIS TOOL IS SAFE

When the program starts you will see the typical intro screen, if you choose "Yes" you will see the data from your PS3, if sounds three beeps indicates that it was not possible dump and show the error message, and if all went well sounds a beep and you are able to see the data.

Automatically saves the IDPS in dev_hdd0/IDPS.bin, you must open it with a hex editor and look hexadecimal values, for example (IDPS false, I will not reveal my IDPS):

e.g Notepad

[Register or Login to view code]

Hex Editor
[Register or Login to view code]

The IDPS in this case would be: 00 00 00 01 00 85 00 May 87 47 64 15 A4 F6 4D AA

It has been tested on PS3 FAT, SLIM should work perfectly in also.

Regards

Finally, in related news PlayStation 3 developer naehrwert has recently blogged (nwert.wordpress.com/2011/12/24/individual-infos/) about PS3 Individual Infos, to quote:

One of the PS3′s console specific cryptography works as follows:

At factory time there is a console specific key generated, probably from a private constant value and a console specific seed. Maybe that’s the key used for encrypting bootldr and metldr. Fact is, that metldr stores another console specific keyset (key/iv) to LS offset 0x00000.

That keyset is probably calculated from the first one. At factory time the isolated root keyset (how I call it) is used to encrypt the console’s “Individual Infos”, like eEID. But not the whole eEID is encrypted the same way, special seeds are used to calculate key/iv pairs for the different sections.

And not even that is true for every eEID section, because for e.g. EID0 another step is needed to generate the final section key(set). Each of the isolated modules using such an “Individual Info” has a special section that isoldr uses to generate the derived key(set)s.

But the generation works in a way, that the section data is encrypted with aes-cbc using the isolated root keyset, so it is not possible to calculate the isolated root keyset back from the derived key(set)s, because aes shouldn’t allow a known plaintext attack.

So far I can decrypt some of EID0′s sections, EID1, EID2 and EID4. EID5 encryption should be similar to EID0′s but I lack the generation keys for that one.


PS3 IDPS Viewer Tool Homebrew Application is Released

PS3 IDPS Viewer Tool Homebrew Application is Released

Follow us on Twitter, Facebook and drop by the PS3 Hacks and PS3 CFW forums for the latest PlayStation 3 scene and PS4 Hacks & JailBreak updates with PlayStation 4 homebrew.



#26 - PS4 News - October 15, 2012 // 8:04 pm
PS4 News's Avatar
Following up on the previous PS3 IDPS update, today PlayStation 3 homebrew developer Rnd (aka RndRandomizer) has released a Request IDPS Generator version 1.0.0.0 with details below.

Download: PS3 Request IDPS Generator v1.0.0.0

From the ReadMe file: REQUEST IDPS Generator - v1.0.0.0 - Rnd

v1.0.0.0:

  • Initial Release

Features:

  • Generate a request_idps file
  • Get PerConsole Data (board ID, cid, ecid, kiban ID, ckp2_data, ckp_management_id)

Usage:

Just get your NAND/NOR dump and drop it in this application.

No more need for re-flashing the whole dump in order to convert EID.

Simply it makes it easier to use it with ObjectiveSuites-SetIdps and you dont have to gether it from Sony's server.

Put request_idps.txt in Temp folder in ObjectiveSuites, to set your request_idps and you are done with flashing the new EID.

I'm not responsible for ANY DAMAGE it may cause! USE AT YOUR OWN RISK!

P.S. If somebody has a script to get the EID with ObjectiveSuites, I would be very kind if you could let me know, I will update the application.

Sincerely,
Rnd

Contact me at RndRandomizer

Finally, from zecoxao: Found it, now we can make our own request_idps files

request_idps.txt (hex) info by Scorpion2k7

name Start offset Size (byte)

per_console_serial 0 8
header 8 96

- Header structure

bytes description
4 number of file (5)
4 lenght of entire file (value-8)
8 unknown (00 03 00 04 00 00 00 00)
(file table)
4 file position 1 (value-8)
4 file lenght 1
8 file id 1
4 file position 2 (value-8)
4 file lenght 2
8 file id 2
...
...

- File info

File 1 - 16 bytes - 00 12 00 02 00 00 00 00 00 00 00 00 00 00 00 00
File 2 - 2144 bytes - EID0
File 3 - 128 bytes - EID2 PBLOCK
File 4 - 48 bytes - EID4
File 5 - 2560 - EID5

Finally, below is a brief guide from Abkarino as follows:

1 - Dump you NAND/NOR flash using a memDump tool or Hardware flasher if you have a higher firmware.
2 - Drag this dump into Request IDPS generator tool to generate the request_idps.txt file.
3 - Set your PC IP Address to: 192.168.0.100 and sub net mask to 255.255.255.0.
4 - Enter a FSM using any dongle/software method you like.
5 - Connect your PS3 to your PC directly using Ethernet cable.
6 - Find the old leaked CEX2DEX conversion tools that contains ObjectiveSuite-SetIDPS.
7 - copy all files from conversion folder into flash drive and put it in the right USB slot in your PS3.
8 - in your PC start copy the generated request_idps.txt into the TEMP folder inside the ObjectiveSuite-SetIDPS folder.
9 - Start ObjectiveSuite.exe then power up your PS3.
10 - Wait for about 1 min and you will see a "PASS" message in ObjectiveSuite.
11 - Now turn off your console.
12 - Flash any 3.55 CFW DEX.
13 - While in FSM remarry your BD Drive using 3.30 DEX PUP + 3.55 Remarry tools from Wiki.
14 - Exit from FSM and now you have a fully functional DEX machine.

From eussNL via IRC: patch SSL, use REQUEST IDPS Generator, lay back bored (since what happens with SetIDPS isn't really a true conversion, because you just write your own EID to the NOR/NAND).

More PlayStation 3 News...

#25 - cfwprophet - March 28, 2012 // 3:17 am
cfwprophet's Avatar
PCK is EID key. Let me explain: per_console_key_1 = eid_root_key / per_console_key_2 = eid0_key and so on.

You wont need to enter something into the app. Just put the files into the folder of the app and hit some buttons. To time it will be pck and a dump of your nand/nor or the eeid it self. The tool will guid you truth the whole process how to optain those two files and have everything you need inside like the cygwin installer or the dump_flash.pkg.

It will be automated and userfrindly as much as it can.

For sure i will release also the source code and all files i have used and i will post new infos and keys not puplic released yet.

#24 - 1one - March 26, 2012 // 3:48 pm
1one's Avatar
Cfwprophet,

Are we going to have to enter our console eid root key into your GUI tool to get the pck?

#23 - cfwprophet - March 26, 2012 // 1:08 pm
cfwprophet's Avatar
I will release when everything is done and user frindly. I dono see a reason to release ACID CFW when it in first was a Retail/Debug hybried and now im working on the convertion of Retail to Debug Consoles. So i will release ACID CFW together with the convertion tool for cex2dex tool and do a reall full functional Debug CFW.

To time im testing a lot of stuff and coding the idps-tool app together with end user gui version. the Tool will be able to guid you truth the whole process and have a lot of buttons so you mostly only need to do a click and get your pck calculated, eid decrypted - patched and re- encrypted and a request_idps.txt generated.

Im working alone cause it seems the most coders of the scene are not interested in to help and others who allready also know what to do wont tell and also wont help us.

But just be a bit patient and i will do my job as good as i can and at it the end a lot of users will be surprissed what a debug ps3 in conclution with target manager and a few tricks will be possible.

#22 - Blade86 - March 24, 2012 // 3:09 pm
Blade86's Avatar
Thank you so much for answering me. !!BIG THX!!

At all the peace-breakers: I cannot share the bad mood in here... Even if cfwprophet doesnt give you/us your/our wished tools there is no need to front him.

At least they (cfwprophet, nabnab) take their time 2 EXPLAIN the users, why a method is not what it looks like. With their knowledge, they acctually dont need to waste their time in helping us, especially when the most of the users cannot do anything with the infos.

BUT there are some users, for whom their effort is a BIG help, so plz let them "talk"

I just cannot see it, why 1 team (our scene) cannot hold together and just wanted to bring some peace in here..

Cheers
Blade

#21 - Portalcake - March 22, 2012 // 1:06 am
Portalcake's Avatar
Quote Originally Posted by cfwprophet View Post

Then also pls keep away with rebug. Even if you change the to time change able 2 idps's and run a dex kernel on rebug... you can't use the debugger mode, you cant use target manager, you can't use the special downgrader pup's and jump between FW's as you want, you can't use BD EMU,... should i go on ??

About the metldr exploit you mentoined: You even know that this exploit is an hardware exploit ? So you need first to find out the test points on the ps3's mainboard to inject the metldr to the SPU's Local Storage directly. Do you knowed that ? Im guess not otherwise you wouldn't talk like that.

So TRUST ME if i tell you that you would have more fun with a bootloader exploit, which is actually done and ready for release but not pulically, then with your mentoined metldr exploit.

Sorry, didn't know that Rebug CEX wasn't as full-featured as a real DEX, outside of the things pirates would drool over.
Also, PM.

#20 - ps3hen - March 22, 2012 // 12:42 am
ps3hen's Avatar
Quote Originally Posted by 1one View Post
Cfwprophet, would you mind sharing your tool or the source code

Do you have a irc channel?

He said it's not finished.

#19 - ashmodeo - March 22, 2012 // 12:23 am
ashmodeo's Avatar
Quote Originally Posted by cfwprophet View Post
Changing the target ID for what ?

As i have told in a other post: Simply changing the TargetID in the EID do not lead into a full debug console. The TargetID is spread in the segments of whole EID and they are in encrypted form. The both idps we can view without decrypting the EID segments do not lead into a full functional debug fw.

Yes you can run dex kernel and install debug fw but again it doesn't lead into a reall debug console.

Again no offence to you im just a bit frustrated of the scene. Im still working on the full convertion and make good steps. It wasn't that hard to figuer out what to do and how to do. I just don't understand the whole scene with releasing stuff that is nearly unnesessary for the end user.

No offense to you but what are your issues about having this release? this is not a competition or something like that. In the end what the end user choose to do with this tool is up to the end user choice so what is the point about always questioning the purpose of this tool when it's obviously clear what you can do with this and what you cannot?

#18 - 1one - March 21, 2012 // 11:49 pm
1one's Avatar
Cfwprophet, would you mind sharing your tool or the source code

Do you have a irc channel?

#17 - cfwprophet - March 21, 2012 // 11:32 pm
cfwprophet's Avatar
I will release when its time for.

About hot air:


Anything else you sayed is not worth to comment.