Post: The Banhammer May Be Coming
10-15-2010, 07:51 PM #1
ryan saa
At least I can fight
(adsbygoogle = window.adsbygoogle || []).push({});
You must login or register to view this content.



On boot the system contacts the server and uploads the play list etc. this list alone is enought to get anyone that goes online banned as it shows the bootmanger etc. has been running. Here is the list and what they do, I port sniffed this a while ago before I went online with a retail unit >.> because I am not stupid hehe.

All these need to be blocked, web access will still work, updates will still work, but psn and any system messages/ads/communication will be blocked completely. For other areas someone would have to sniff the addresses again to compare. North American Servers are listed.


Originally posted by another user
fus01.ps3.update.playstation.net > Update Server (sys updates)
mercury.dl.playstation.net > What's new ads
nsx.np.dl.playstation.net > playstation store preview
nsx-e.np.dl.playstation.net > ads
(main file exchange connections)
us.np.stun.playstation.net > on boot initiates connection
ena.net.playstation.net > SSLv3 connection after above connection
dus01.ps3.update.playstation.net > secondary update attempt (could force updates)
auth.np.ac.playstation.net > SSLv3 authentication server
(destination servers)
service.playstation.net (has multiple IPs if only the ip address is blocked)
(Error Reporting)
creepo.ww.hl.playstation.net (uploads crash reports etc.)



Almost all connections cannot just be port blocked, the port will continue to increment until it connects, you have to block the entire domains. Also a big point is that ALL computers on your network need to have these blocked not just the PS3's MAC because if you are running a proxy for example to get patches, the computer you proxy to will just allow the connections right out to the open unless all local IPs are blocked from these sites as well.








You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 2 users say thank you to ryan saa for this useful post:

Suxh4rd2bu, ZachFean
10-15-2010, 08:28 PM #2
Suxh4rd2bu
Extreme Anarchist
Originally posted by ryan
You must login or register to view this content.



On boot the system contacts the server and uploads the play list etc. this list alone is enought to get anyone that goes online banned as it shows the bootmanger etc. has been running. Here is the list and what they do, I port sniffed this a while ago before I went online with a retail unit >.> because I am not stupid hehe.

All these need to be blocked, web access will still work, updates will still work, but psn and any system messages/ads/communication will be blocked completely. For other areas someone would have to sniff the addresses again to compare. North American Servers are listed.





Almost all connections cannot just be port blocked, the port will continue to increment until it connects, you have to block the entire domains. Also a big point is that ALL computers on your network need to have these blocked not just the PS3's MAC because if you are running a proxy for example to get patches, the computer you proxy to will just allow the connections right out to the open unless all local IPs are blocked from these sites as well.








You must login or register to view this content.



Good find :y:
10-15-2010, 10:39 PM #3
Saul
¯\_(ツWinky Winky_/¯
I'm lucky enough to have a router that can do custom firewall rules, so it's as simple as:
1) set up a static IP on the ps3 to be locked down
2) drop this line in the outbound firewall rules:
    drop from addr 192.168.xxx.xxx >> done

Then nothing from that address gets out, period. FTP on the local side still works fine. With two ps3's there is no real need for the locked down system to connect to the net. If I need a game update or something I get the link using connection sharing, wireshark, and my updated ps3.

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo