Post: Mathieu Explains 3.60 Exploit - Will Lead to Application Keys and Eventually 3.60 CFW
04-22-2011, 01:53 AM #1
CLM
[b]They say sorry Mr. West is..[/b]
(adsbygoogle = window.adsbygoogle || []).push({}); Mathieu Explains 3.60 Exploit - Will Lead to Application Keys and Eventually 3.60 CFW
Source: You must login or register to view this content. // By: ClutchLikeMelo // April 21, 2011

You must login or register to view this content.

Mathieu keeps throwing out more and more hints. This time he explains his exploit and how it will lead to application keys, and...... Drum roll please. 3.60 CFW! (Oh and in case you're wondering, application keys can make current and future 3.60 encrypted games playable!)

Synopsis of Mathieu's explanation of the exploit:

Originally posted by another user
The function that copies the SCE header from the shared LS to the isolated Local Store doesn’t check the header’s size.

[So] you craft a self with a HUGE header so [that] it overwrites ldr code as it gets copied to the isolated LS and you wait [for] the loader to jump to it.

[Then] you can get lv0 decrypted, once you get lv0 decrypted, you get appldr, once you get appldr, you get 3.60 application keys, [and] once you get that, you [get] warez.


Here's Mathieu's full conversation about the exploit:

Originally posted by another user
X nah, not a single line of code, at least not for the implementation
but finding the exploit itself
is EASY
except no one has gone looking
I’ve seen lots of askings and whining, very little looking xD
if someone who remotely knows spu reversing starts looking
he’ll find it
at the very worse in a matter of hours
the bug is ******ly stupid to begin with
LV0, EID0, anything with coreOS imo should not be done without a hardwareflasher. Atleast with that you can undo the mess.
yeah
I am a bit of a red head here xD
you keep saying that, but I suck at SPU assembly
you’d find it even if you fail at it
you just need to know where to look
just look at how selfs are processed by ldrs
and you’ll find it
hell, I’ll help you, it’s about overflowing a certain buffer
yes, that is what defyboy and I tried to document in the ps3devwiki : bootprocess and loader locations etc.
well if you know how selfs are processed by loaders, it’s easy
another hint
it happens before the ecdsa check
my earlier guess btw was that it was a header overflow, which gave access to the local storage
It’s a ******ed exploit
if you want to know what it is, I’ll tell you
the function that copies the SCE header from the shared LS to the isolated Local Store
doesn’t check the header’s size
\o/
it’s just THAT ******ed
implementing it isn’t easy though
cause loaders have failsafes and ****
header size fail
lol
?
but now that you know, you can try it on your own
X1 yes
you craft a self with a HUGE header
so it overwrites ldr code as it gets copied to the isolated LS
and you wait the loader to jump to it
lolol must try heh
X1 it’s a total ***** to implement
but feel free xD
if someone pwns the bl with this and gets the keys, he’ll have my kudos
cause finding the exploit is the easy part
Sony’ll fix it now, but it’s not like I care much
their “unhackable” ps3s are probably already on the way


He then explained the impact this exploit would have on Sony:

Originally posted by another user
why would they care about bootldr keys?
ps3devnews etc. host metldr keys, appldr keys etc.
X1 cause you can get lv0 decrypted
once you get lv0 decrypted
you get appldr
once you get appldr
you get 3.60 application keys
once you get that
you warez
also, with those keys you can sign your own lv0, no ps3 fw update can beat you then
yah
you can have your 3.60+ custom firmware then
and warez even more
and mess with the psn again
and so on


(adsbygoogle = window.adsbygoogle || []).push({});

The following 16 users say thank you to CLM for this useful post:

AMNE, Anal Treat, BooshMayne, Hoang, I Go Nom, RastaMajik, Reaper, CHAOZ, Sn0wb0arder245, TheMagicPancake, Top_Dog_Uk, toxic90384109284, UnrealReality, VHS, xRaR
04-22-2011, 01:55 AM #2
viralhysteria
74261700027
Is it not apparent that 3.60 CFW is a bad idea?

The following user groaned viralhysteria for this awful post:

forcer911
04-22-2011, 01:57 AM #3
Kylee.
Banned
inb4 3.60cfw release! shouldn't be long before its out

The following 2 users say thank you to Kylee. for this useful post:

toxic90384109284, xRaR
04-22-2011, 02:12 AM #4
noodles88
Bounty hunter
Originally posted by ClutchLikeCeltics View Post
Mathieu Explains 3.60 Exploit - Will Lead to Application Keys and Eventually 3.60 CFW
Source: You must login or register to view this content. // By: ClutchLikeMelo // April 21, 2011

You must login or register to view this content.

Mathieu keeps throwing out more and more hints. This time he explains his exploit and how it will lead to application keys, and...... Drum roll please. 3.60 CFW! (Oh and in case you're wondering, application keys can make current and future 3.60 encrypted games playable!)

Synopsis of Mathieu's explanation of the exploit:



Here's Mathieu's full conversation about the exploit:



He then explained the impact this exploit would have on Sony:





Eventually this might get closed 3rd or 4th time been posted and got moved to general for some reason

You must login or register to view this content.
04-22-2011, 02:35 AM #5
Reaper
The Grim Reaper
Thanks for posting this Clutch! Awesome face
04-22-2011, 02:39 AM #6
CLM
[b]They say sorry Mr. West is..[/b]
Originally posted by reaper View Post
thanks for posting this clutch! ;d


Now it's working Awesome face
04-22-2011, 03:16 AM #7
Nas.
I AM Keep-It-X-Rated
Welp NGU Better get ready for the 11 year olds that are going to RUIN mw2 again. -___-

The following 3 users say thank you to Nas. for this useful post:

mcstyle24, teeth08, xRaR
04-22-2011, 03:28 AM #8
Default Avatar
Cade
Guest
Originally posted by ClutchLikeCeltics View Post
Mathieu Explains 3.60 Exploit - Will Lead to Application Keys and Eventually 3.60 CFW
Source: You must login or register to view this content. // By: ClutchLikeMelo // April 21, 2011

You must login or register to view this content.

Mathieu keeps throwing out more and more hints. This time he explains his exploit and how it will lead to application keys, and...... Drum roll please. 3.60 CFW! (Oh and in case you're wondering, application keys can make current and future 3.60 encrypted games playable!)

Synopsis of Mathieu's explanation of the exploit:



Here's Mathieu's full conversation about the exploit:



He then explained the impact this exploit would have on Sony:





another great thread! thanks! Smile
04-22-2011, 03:48 AM #9
TheManDavid
Your mother!
Here come the newfags!!!!!

The following user thanked TheManDavid for this useful post:

will34
04-22-2011, 03:53 AM #10
I Go Nom
The cow... She go moo
inb4 12 year olds screaming Awesome face

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo