Sponsored Links

PS4 News on Facebook! PS4 News on Twitter! PS4 News on YouTube! PS4 News RSS Feed!
Sponsored Links

Home PS4 News - Latest PlayStation 4 and PS3 News

True Blue (TB) and Cobra PS3 JB2 DRM Dongle Payloads WIP


Sponsored Links
159w ago - Following up on the previous True Blue (TB) PS3 JailBreak 2 (JB2) DRM-infected dongle news comes a WIP update from Shadoxi on dumping and decrypting the TB and Cobra payloads below, as follows:

Download: TB / Cobra Payloads (2.84 MB) / TB / Cobra Payloads (2.84 MB - Mirror) / TB / Cobra Payloads (2.84 MB - Mirror) / PS3 True Blue MFW (172.19 MB)

I have figured out where the payload is located of the TB and Cobra dongles. You can find it at offset @360000 in lv2_kernel and 7f0000 in PS3 memory. According to the PS3 Developer Wiki (ps3devwiki.com/index.php/ReDRM_/_Piracy_dongles) the LV2 dump payload at 0x7f0000 has also been decrypted @ LV2 dump 0x7f0000 (pastebin.com/3VG76HQs)

Drag and drop payload in IDA and load it in Binary file mode, Processor type PPC.Press "C" to convert in ASM code.

First of all you need to edit the header of lv2_kernel.self (from CFW TrueBlue) at offset 0x1D, replace 36 1A 00 by 4C FC F0. And decrypt it with unself tool from fail0verflow. Open lv2_kernel.elf with IDA Pro (in binary file mode), go to offset 360000 and press "C" to convert to asm code.

TrueBlue use some HVCALL:

  • lv1_insert_htab_entry
  • lv1_undocumented_function_114
  • lv1_undocumented_function_115
  • lv1_allocate_device_dma_region
  • lv1_map_device_dma_region
  • lv1_net_start_tx_dma
  • lv1_net_control
  • lv1_panic (shutdown ps3 when TB is unplugged)

This payload do some HVCALL:

  • lv1_insert_htab_entry (map lv1)
  • lv1_allocate_device_dma_region (?)
  • lv1_map_device_dma_region (?)
  • lv1_net_start_tx_dma (?)
  • lv1_net_control (?)
  • lv1_panic (shutdown ps3 when TrueBlue dongle is unplugged)
  • lv1_undocumented_function_114 (map lv1)
  • lv1_undocumented_function_115 (unmap lv1)

We needed to dump lv2 and lv1 memory when the dongle is plugged in, so I created a modified TB CFW with peek and poke syscall. It works fine !

Finally, from the MFW_TrueBLue.zip ReadMe file: Warning this mfw can brick your dongle !!!

  • First install PS3PEEKTEST.pkg
  • Install MFW TrueBlue firmware in recovery mode
  • Start ps3peektest

If Peek Result is equal to 10 and true blue light is green -> work.


True Blue (TB) and Cobra PS3 JB2 DRM Dongle Payloads WIP

Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter, Facebook and drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene and PlayStation 4 scene updates and fresh homebrew PS3 Downloads. Enjoy!
Sponsored Links
Sponsored Links

Comments 862 Comments - Go to Forum Thread »

• Please Register at PS4News.com or Login to make comments on Site News articles.
 
#822 - ASTRAL2k1 - 133w ago
ASTRAL2k1's Avatar
That's awesome news!

#821 - ZerotakerZX - 133w ago
ZerotakerZX's Avatar
Hehe, right. Use DEX you lazy bum.

#820 - lolong - 133w ago
lolong's Avatar
well it is TRUE, DUPLEX CRACKS DRM True Blue, then DUPLEX should know how to make eboot.bin with DRM for CFW 3.55 True Blue.

So, I challenge DUPLEX to mod EBOOT.bin SLEEPING DOGS run and play on CFW 3.55 with dongle True Blue.

#819 - elser1 - 133w ago
elser1's Avatar
holy sig. thats great news for the scene. applause to duplex.

gotta say this has made me so happy. i hope these fools don't sell one more drm infected p.o.s dongle.

i hope its made public how to do it. great news everyone!

#818 - cfwprophet - 133w ago
cfwprophet's Avatar
Siggy12 Convert to a Dex and use the update to make the fresh new released game work. And if there is no update then we need to dump it out of ram with coredump function.

utar oO The Coredump function is a embended system of the debug FW and get handled of liblv2dbg. The send signal call aka send_signal_to_coredump_handler() and the trigger function are always running and CAN NOT be deactivated.

This have nothing to do with any custom syscall. Please download a SDK, Install it and read the documentation about the Core Dump function.

#817 - PS4 News - 133w ago
PS4 News's Avatar
Here is a list of the TB releases for those who need to remove the dongle patched games and overwrite them with the PS3 scene release (Duplex, NRP, etc) fixes as they become available: http://www.ps4news.com/subdomain.php?pagename=nfo&search=_TB_

[Register or Login to view code]


#816 - utar - 133w ago
utar's Avatar
In none technical language I assume you mean that you do a memory dump once the eboot has been decrypted. How does this work with post 3.55 firmware? Wouldn't you need to have level 1 or 2 peek and poke access to trigger the exception and core dump which we don't have?

#815 - Siggy12 - 133w ago
Siggy12's Avatar
All right !!! this is the problem they beat who know to patch the games for 3.55 the problem now is... what we are going to do for new games that don't have a TB PATCH ?

#814 - cfwprophet - 133w ago
cfwprophet's Avatar
Yea sure. Whooohoo super team duplex. Do you guys really think that duplex discovered this the last 2 weeks ? Is it not suspect that they release after TrueBlue was already killed with Cex2Dex release ?

I say it now for the last time: There is NO fself for new games !! TrueBlue use the CoreDump function and a RSX exception to dump the games like i told the scene for over a half year.

I also showed some guys how to use the coredump function and how to trigger a exception but it seems like the average user do not listen or don't understand how to use but still putting teams like trueblue or duplex into heaven.

I go back underground... have fun.

#813 - technodon - 133w ago
technodon's Avatar
Excellent Work, Top Dog! Duplex. i'm still interested to know how true blue actually got fself eboots to run on retail firmware.

 

Sponsored Links

Sponsored Links







Advertising - Affiliates - Contact Us - PS4 Downloads - PS4 Forums - Privacy Statement - Site Rules - Top - © 2015 PlayStation 4 News