Sponsored Links

PS4 News on Facebook! PS4 News on Twitter! PS4 News on YouTube! PS4 News RSS Feed!
Sponsored Links
Sponsored Links
Home PS4 News - Latest PlayStation 4 and PS3 News

True Blue USB Dongle PS3 ELF Dumper and Source Code Surfaces


Sponsored Links
135w ago - Following up on the previous update, today I am releasing my True Blue USB dongle PS3 ELF dumper which works with any PlayStation 3 Firmware greater than 3.56 to dump the encrypted TB EBOOT / ELF files once they are loaded.

Download: True Blue USB Dongle PS3 ELF Dumper / True Blue USB Dongle PS3 ELF Dumper (Mirror) / True Blue USB Dongle PS3 ELF Dumper (Mirror #2) / True Blue USB Dongle PS3 ELF Dumper (Mirror #3) / True Blue USB Dongle PS3 ELF Dumper (Mirror #4) / True Blue USB Dongle PS3 ELF Dumper (Mirror #5) / True Blue USB Dongle PS3 ELF Dumper (Mirror #6) / True Blue USB Dongle PS3 ELF Dumper Source Code / True Blue USB Dongle PS3 ELF Dumper Source Code (Mirror) / UTEBOOT (DUMPEDBOOT.bin and DUMPEDBOOT1.bin) by arnes_king / Mass Effect 3 BLUS30853 RAMDUMP by gibson25 / TB ELF Dumper v2 (np_trp_prx.rar) / TB ELF Dumper v2 (Mirror) / DUMPEDBOOT PoC by mellss

Tested on:

  • Original 355 -> ok
  • True Blue CFW v2 -> ok
  • ...

There are some bugs (size of dump ...) but it works. It's ELF dumper from memory and it work with True Blue cfw v2 and any 3.55 firmware because it doesn't use lv2 peek/poke.

Warning: It will not brick your ps3. But I am not responsible for any damage.

HOWTO:

  • Enable dev_blind with multiman
  • copy libsysutil_np_trophy.sprx from /dev_blind/sys/external/external to dev_hdd0/ and rename it "orignal_libsysutil_np_trophy.sprx"
  • copy my modified "libsysutil_np_trophy.sprx" to /dev_blind/sys/external/
  • load a True blue game from multiman
  • exit multiman
  • run your game
  • wait few minutes (if you get black screen after 3 minutes reboot ps3)
  • exit game
  • go to ftp
  • in dev_hdd0/ there are your decrypted DUMPEDBOOT.bin
  • copy and rename it with another name.

Howto uninstall patch - Two ways:

  • You could uninstall this patch by replacing modified libsysutil_np_trophy.sprx by orginal libsysutil_np_trophy.sprx
  • Or update in recovery mode

Thanks to: Ps3dev

Brief Guide:

1 - Install TB ELF Dumper first as stated in its readme file.
2 - Start Multiman, it will make a dump of multiman eboots, so you must delete it first by browsing to dev_hdd0 then delete all DUMPEDEBOOT.BIN files you found there.
3 - Back to multiman game selection then select any TB game then launch it.
4 - Start the game from XMB then wait for some times until game start.
5 - Exit game now then start multiman again then browse to dev_hdd0 and now you must found a decrypted game dump.

From PlayStation 3 developer deank (via pastebin.com/avcM5iuU) comes a revision as follows:

Download: TB ELF Dumper v2 (np_trp_prx.rar) / TB ELF Dumper v2 (Mirror)

[Register or Login to view code]

Changed:

  • Doesn't stop dumping when it reaches embedded ELF
  • Dumps 35MB of RAM in one write call (so it takes ~1 second)
  • Dumps are saved in /dev_hdd0/RAMDUMP-##.BIN where ## is from 00 to 99 for 100 sequential dumps
  • Doesn't really require the original sprx, since loading never succeeds anyway
  • Tested: dumps mM, Beyond Good&Evil HD PSN...
  • Rebuilding the original 'elf' takes few minutes if you know what you're doing

Finally, from mellss: I tested shadoxi patch, in ofw 3.55 dex and 3.55 cfw it work fine (but like he said some buggy with size of dump). And also let him time to dump all memory!!! (it take for me around ~10 - 20 min !!!)

Proof Of Concept:


I make a fself EBOOT.bin (4.11 dex) which load reencrypted (flself) shadoxi patch and YES his patch dump my eboot and also some 4.11 dex lib sprx !!! So if someone can run shadoxi or deank patch when a game is running we can get decrypted 4.xx EBOOT.

I think TB team load the decrypted eboot to another offset in memory, that's why some of people get ps3 crash when TB was plugged. But, We can get this new offset by editing shadoxi exploit and print the address of a variable (stack address) to get the new one.


True Blue USB Dongle PS3 ELF Dumper and Source Code Surfaces

True Blue USB Dongle PS3 ELF Dumper and Source Code Surfaces

Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter, Facebook and drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene and PlayStation 4 scene updates and fresh homebrew PS3 Downloads. Enjoy!

Comments 862

• Please Register at PS4News.com or Login to make comments on Site News articles.
 
#812 - lolong - 136w ago
lolong's Avatar
TB is TAKING TOO LONG, for releasing their NEW GAMES EBOOT and NEW PATCH for their dongle. This is a stupid method, WHY ?

Because DUPLEX get the first to CRACK new GAMES such as DARKSIDERS2 and SLEEPING DOGS.

Honesty, I hate with TB, they should work together to make new games with mod eboot so it can play it with their dongle.

NOW it's too late, DUPLEX beats DONGLE!

#811 - Neo Cyrus - 136w ago
Neo Cyrus's Avatar
I thought this would have happened a lot sooner... oh well, better late than never.

#810 - PS4 News - 136w ago
PS4 News's Avatar
Currently the ones that get re-released with the DRM removed, whether this will change only time will tell... at the moment there are 2 games released above and most likely a slew more incoming from various scene release groups.

#809 - tickford - 136w ago
tickford's Avatar
Does this mean if your ps3 is on kmeaw cfw 3.55 you can play ALL the TB cracked games, or only the ones that get cracked (eg max payne 3)?

#808 - stingray1059 - 136w ago
stingray1059's Avatar
i'm glad i sold my dongle.

i hope all unfixed trueblue games will be patched tomorrow. like ghost recon FS, dragons dogma, mass effect 3 and tales of graces f.

#807 - master32820 - 136w ago
master32820's Avatar
I have a TB but i'm happy that duplex fcked them up

I got a question though! can we go back from TB CFW 2 to normal kmeaw 3.55 just they way we went to tb cfw 2?

#806 - spark32 - 136w ago
spark32's Avatar
This is awesome! Now all I need to wait for is a fixed eboot for Jak and Daxter collection, Twisted Metal, and Mass Effect 3.

#805 - PS4 News - 137w ago
PS4 News's Avatar
Not long after the release of the PS3 3.60 Keys comes the first of several PlayStation 3 releases with the TrueBlue PS3 USB dongle DRM-infected protection now removed by scene group DUPLEX!

Download: DUPLEX PS3 Releases - Ongoing thread, add new game releases here guys!

Below is the release information, from their Max Payne 3 Eboot Patch READNFO PS3 DUPLEX PS3 NFO as follows:

Release Name: Max.Payne.3.Eboot.Patch.READNFO.PS3-DUPLEX
Date: August 2012
Languages: English
Platform: PS3 CFW 3.55
Genre: Action

[Register or Login to view code]

Max Payne 3 TB Eboot Patch *CRACKED*

Release Info:

When we first read about the TrueBlue USB Dongle we were excited about it. Finally having a way to play FW 3.60+ games on CFW 3.55 again. What a great asset to the scene everyone thought .. until people found out that this USB Dongle was solely made for cashing in! Its only purpose was to check on the DRM the TrueBlue Team added to their 3.55 Eboots. What a shame!

DUPLEX to the rescue! Finally bury your TB dongle because we removed their unnecessary DRM and their Patches will now work on Cfw 3.55 without any dongle or special TB CFW.

Notes:

Copy the files inside the rars into your games usrdir and replace existing ones Tested on Kmeaw CFW 3.55 with Max.Payne.3.PROPER.PS3-DUPLEX more to come ...

Enjoy This Fine DUPLEX Release

From anonymous also comes another Max Payne 3 Update v1.05 [FW 4.0] Patched for CFW 3.40+ workaround as follows:

Max Payne 3 BLES / BLUS Test EBOOT and Param.sfo:

Download: http://www.mirrorcreator.com/files/RQWCQLZ7/max_payne3_patched_eboots.rar_links

  • Max Payne 3 BLES / BLUS Test EBOOT and param.sfo
  • The rar has an embedded readme with the pkg links
  • Its probably best if they have the common.sdat from the duplex release, though I am not positive.
  • They need to backup files, preferable that person has spoofing
  • Game update sfo's, don’t replace the Game sfo!!!!

From CaptainCPS-X: Here you have the PKG files for easy install of this awesome “Anonymous” collaboration! (thanks to hellsing9 to for providing with the files) This is really cool since maybe more 4.0 FW games will be patched in the future by this Anonymous person! Thanks!

US Patch [BLUS-30557]

FIX_340_UP1004-BLUS30557_00-MP3PATCH00000003-A0104-V0100-PE.pkg (51 MB)

Europe Patch [ BLES-00942 ]

FIX_340_EP1004-BLES00942_00-MP3PATCH00000004-A0105-V0100-PE.pkg (51 MB)

Installation instructions:

1- Download your specific PKG (US / EU)
2- Install normally from XMB.
3- Replace the original “common.sdat” from your untouched backup with DUPLEX’s one (duplex-mp3ebootpatch.part1.rar / duplex-mp3ebootpatch.part2.rar).
4- Load with multiMAN normally.

Enjoy! SeeYa!

In related PS3 news today, pr0p0sitionJOE has released several new PlayStation 3 fixes both HERE and HERE for those interested.

Update: A second PlayStation 3 scene group named NRP has also followed suit and released Kidou Senshi Gundam Extreme VS EBOOT PATCH READNFO JPN PS3 NRP. Below are the details from the PS3 NFO to the release as well:

Release Name: Kidou_Senshi_Gundam_-_Extreme_VS_EBOOT_PATCH_READNFO_JPN_PS3-NRP

NoRePack Presents. It's NoT a repack !

FiLENaME ------ nrp-exvsp
PlaTForM ------ PS3 CFW 3.55
Region ------ Japan
Language ------ Japanese
Supplier ------ Team NoRePack
rlz.Date ------ 2o12-o8-15
Serial ------ BLJS10131

Finally, a hero comes to kick the fcking TB'sass, cheers! And now we want to support dear DUPLEX with this release. Gundam stands on the ground without any dongle or special TB CFW. Works with our release: Kidou_Senshi_Gundam_-_Extreme_VS_JPN_REPACK_JB_PS3-NRP

Let's be the witness of the ruin of TB dynasty. Love & Peace! Enjoy! iF u LOvE or HATe THiS GAmE, BuY iT ;]

Other related PS3 releases from today:

  • Neverdead.Eboot.Patch.DirFix.PS3-DUPLEX
  • Tiger.Woods.PGA.Tour.13.Eboot.Patch.PS3-DUPLEX
  • Dirt.Showdown.Eboot.Patch.PS3-DUPLEX
  • Devil.May.Cry.HD.Collection.Eboot.Patch.PS3-DUPLEX
  • Sniper.Elite.V2.Eboot.Patch.PS3-DUPLEX
  • Syndicate.Eboot.Patch.PS3-DUPLEX
  • Twisted.Metal.Eboot.Patch.PS3-DUPLEX
  • Snipers.Invisible.Silent.Deadly.Eboot.Patch.PS3-DUPLEX
  • Puss.in.Boots.Eboot.Patch.PS3-DUPLEX
  • Assassins.Creed.Revelations.Eboot.Patch.PS3-DUPLEX
  • Kidou_Senshi_Gundam_-_Extreme_VS_EBOOT_PATCH_READNFO_JPN_PS3-NRP
  • Max.Payne.3.Eboot.Patch.READNFO.PS3-DUPLEX
  • Kidou_Senshi_Gundam_UC_EBOOT_PATCH_JPN_PS3-NRP

Here is a list of the TB releases for those who need to remove the dongle patched games and overwrite them with the PS3 scene release (Duplex, NRP, etc) fixes as they become available.

In related PS3 hacking news SGuerrini97 made available a CoreDump BLES00025 NBA2K7 (Password: BySGuerrini97) stating: Here is the Core Dump + Original self of NBA 2K7 (BLES00025). I made the dump from the original disk, i think that i can dump ALL the originals games.

Also below harryoke has outlined how he did a PS3 full core dump, as follows:

Download: PS3 Core Dump / PS3 Core Dump (Mirror)

Hello there my friends... as you may or may not know i have been looking into the possibility to get a full core dump from my ps3... a few hours ago i was sent a pm from ANON ... here it is....

Hey mate, yeh cfwprophet told something about the ram dump too. you can make a core dump on a dex. here is a quote from him:

'I say it now for the last time: There is NO fself for new games !! TrueBlue use the CoreDump function and a RSX exception to dump the games like i told the scene for over a half year.'

'Take MultiMan 04.02 which is a Retail NPDRM >> enable core dump function >> start MultiMan >> exit to XMB and be surprised'

'The Coredump function is a embended system of the debug FW and get handled of liblv2dbg. The send signal call aka send_signal_to_coredump_handler() and the trigger function are always running and CAN NOT be deactivated.'

He also said that you will get one 250MB file. there you have to search the decrypted file(s). it would be pretty sure that they use this method, because newer games wouldnt have debug eboots or fselfs.

If you open a tb eboot with a hex editor, you will see near at the end , that they stand right after the codes some passages with 'liblv2'. if you open a original eboot , you cant find passages with 'liblv2'. like cfwprophet said, the core dump get handled of 'liblv2dbg' and you can find 'liblv2' passages in tb eboots. so they use coredump pretty sure.

But the problem is to trigger a crash or so. i really dont know. i'm not a dev and dont have an idea. i just wanted to tell you this infos because i saw your post about coredump.

Here you can read more infos: ps3devwiki.com/files/documents/-SONY%20PS3%20SDK%20Documentation/360.01/cell/en/pdf/debug_support/Core_Dump-Overview_e.pdf

And here about liblv2dbg: ps3devwiki.com/files/documents/-SONY%20PS3%20SDK%20Documentation/RTL2.3.0/debug_support/liblv2dbg-Overview_e.pdf

Well i now have a few core dumps ...some were 250mb and a 500mb dump which i have uploaded including the log file...it is in rar format & compressed to 45mb

Hopefully this will lead us to the magic decrypted eboots that we all want. i hope someone with a bit more knowledge than me can use this info.

Just done a quick search of dump for USRDIR found this at address 002530E0

[Register or Login to view code]


And at 05D87600
[code]
00 00 00 3C 00 00 03 86 2F 64 65 76 5F 62 64 76 64 2F 50 53 33 5F 47 41 4D 45 2F 55 53 52 44 49 52 2F 45 42 4F 4F 54 2E 42 49 4E 00 33 B0 37 60 33 B0 37 F0 33 B0 38 70 33 B0 38 F0 33 B0 39 80 33 B0 3A 10 33 B0 3A 90 33 B0 22 B0 33 B2 A5 80
...

#804 - Daveyshamble501 - 137w ago
Daveyshamble501's Avatar
The video explains how to open the dongle by grabbing the plastic lip behind the usb connector with pliers an pulling towards you, Thus exposing the plastic casing... Check out the video.

How to take apart your True Blue dongle to see if you have a real or a fake one. Real easy guide to make sure is worth it. Fake dongles have a green pcb with medium size LEDs at the bottom, we're as a Real TB has a blue pcb with tiny LEDs an a actel chip (like the one in the video, if yours resembles that then its real.)



#803 - Tidusnake666 - 138w ago
Tidusnake666's Avatar
I do not know, by what miracle guys have run Batman Arkham City on TB CFW, it gave me black screen all the time, and I tried with and without disc, with and without patch, with and without dlc... etc.

1) Then I tried to make a PSN-like package to run it with the TB unplugged (you remember good old times, eh?). After 2.5 hours of converting NPDRM-update-like-pkg signed with debug keys with hard-as-nutshell-to-decrypt eboot, I finally managed to create a pkg. It run, but at the install it hanged.

2) So, I made another (obvious) solution in half an hour - reencrypted eboot, so you can replace it directly over your game dump and play happily on any 3.55 CFW (included TB) without problems (haven't tried dlc's on TB CFW yet). Tested on TB CFW v2 with dongle plugged.

Instructions:

1. Replace ebbot in your game's dump directory with this: http://www.sendspace.com/file/3u2rb5 (THIS IS NOT AN OLD EBOOT, IT'S CONVERTER!)
2. Run the game, allow it to install data, start new game, when you'll regain control of Bruce, while moving the character, you should press PS button and chose "Exit game"
3. Start multiman, copy "PATCH" directory d/l from here: http://www.sendspace.com/file/8yp618 to your hdd0/game/BLUS30538/USRDIR (game install directory)
4. Start the game again, wait till another install finishes, enjoy!

No old semi-working patches were used, it's a real deal, patched to run in a way for TB users, who have troubles launching the usual style.

Come on guys, I sacrificed some precious hours of sleep (it's 4 AM here), I deserve some +reps

 

Sponsored Links

Sponsored Links

Advertising - Affiliates - Contact Us - PS4 Downloads - PS4 Forums - Privacy Statement - Site Rules - Top - © 2015 PlayStation 4 News