Post: Mathieulh: QA Flagged Ps3 - Enable Hidden Firmware Option ( Means CFW On Steroids)
05-14-2011, 02:14 AM #1
Stack0verfl0w
Computer engineer
(adsbygoogle = window.adsbygoogle || []).push({}); member a few weeks ago Mathieulh released a video of the QA flagged PS3? To refresh your memories; the QA flag is the internal console flag used by Sony, it enables hidden options and removes restrictions for both retail and debug consoles alike. It is used for QA centers and the R&Awesome face Department (there are 2 levels of QA flags, Minimum and Advanced). In short it could lead to a complete open PS3…and yes all the CFW, homebrew and backup manager your little heart desires.

You must login or register to view this content.

Well the method of how to “QA flag” your PS3 was never posted/revealed but since then plenty of hints have been given in attempts for the “scene”, and one of the first steps was to figure out the secret button combo. Well after weeks of people trying and moaning, the man behind the emulators – squarepusher 2 has released/posted information on exactly what that button combo was. Noobs do not try this – the guide below is still a work in progress and QA flag button combo is the icing on the cake.
How to QA Flag your PS3, the button combo:

1. Be on 3.55 OFW (no rebug): You must login or register to view this content.
2.Move the PS3 cursor/select “Network Setting“
3.Punch the following button combo with your PS3 controller: L2 + L1 + R1 + R2 + L3 + D-pad Dow
4. Thats it, the “Edy Viewer”, “Debug Settings”, “Install Package” Menu will now appear.
Notes and disclaimers:

Install Package is useless and can’t install homebrew at the moment – only signed PKGs (and the first one in root of USB only).
This is not all that is needed to QA flag your PS3, but its a big start for the community – we still need all the pieces to fully QA flag the PS3 and its the scenes job to “figure out the rest”.

Thanks to munky875821417 for news tip.

enjoy source ps3hax.com
(adsbygoogle = window.adsbygoogle || []).push({});

The following 30 users say thank you to Stack0verfl0w for this useful post:

Alfa, AMNE, Arman M., b0snian, bryanakabid, Dante., DaveedDB, gamer89117, gunhead88, iDontExist, IRISH-SHAM1, jsonnerrr, Kallen, Karoolus, khalids19, killa skillz, kuruptaz, LIGHTDARKYIN, MateoGodlike, Monster-Energy, Norman, pooponme, PS3FFviewer, SavageRising, stuartlittle98, Swade, thabeast_32, UnTaMeD-KiD, vit., Wfloydboy16
05-30-2011, 05:11 PM #164
stuartlittle98
Do a barrel roll!
Originally posted by i
While the PS3 scene is slow now a days and some of you are dreading for the return of PSN, Mathieulh has posted some interesting discoveries on his Twitter. Mathieulh has managed to QA Flag his PS3 and show the hidden options available for it. Before I go on, most of you are probably wondering what in the world does QA Flagged mean?

You must login or register to view this content.
So alls we need is the combo now right?
To quote:

QA flag is the internal console flag used by Sony, it enables hidden options and removes restrictions for both retail and debug consoles alike. It is used for QA centers and the R&Awesome face Department, there are 2 levels of QA flags, Minimum and Advanced, this console has been set to the Advanced one.

Now Mathieulh has come out and said that he will not be telling us how he did this, but nonetheless very cool and it will be interesting to see where this will lead to.



This Makes you feel teased

To quote video description:

I just QA flagged my Metal Gear Solid 4 Limited Edition console and I thought I’d show you the hidden options for the sake of it. (and because I was bored)

I am sorry for the unstable camera, I only have two hands and the options are hidden and require (along with the actual flag) a crazy button combo to pop up. (I kid you not)

Sorry I am not telling you how to do this, please do not ask.

Yes, this video is real

Here are some interesting Tweets made regarding this:


Mathieulh Mathieulh:
@dantezteam It’s an UNMODIFIED RETAIL FIRMWARE.

@KaKaRoToKS For various reasons, one of them being that you can warez with this, and the flag stays even after updating.

@KaKaRoToKS The QA flag happens to remove a bunch of restrictions that have the side effect of preventing you to warez.

@dantezteam The console is QA flagged, The firmware checks for this flag and will enable special features when it finds it.

@dantezteam Basically it’s what Sony themselves use to allow special debugging on their consoles and loosen restrictions.

@KaKaRoToKS By the way, Advanced QA flag enables downgrading, just my 2 cents… xD

ps: if this is ever figured out it would mean a regular ps3 that if you push like up up left... x10 just saying not actual sequence you would be able to have a regular ps3 no cfw or dongle nothing just a regular ps3 retail on steroids it like a super cfw with out no mod just a button sequence to activate it one time only if it was release it would be the end of sony
of course, he won't share how to do it

but... its pretty easy
UPDATE1: this how to QA flag your ps3 do at your own risk source psx scene

requirements:
grafs kernel, ps3dm-utils and linux_hv_scripts

to patch your DM you have to run dmpatch.sh (skip if you're on gitbrew fw)

read QA flag:
Code:
ps3dm_um /dev/ps3dmproxy read_eprom 0x48C0A
it should return 0xFF on retail ps3.
just set it to 0x00

write QA flag: <- on your own risk!

Code:
ps3dm_um /dev/ps3dmproxy write_eprom 0x48C0A 0x00

OR

ps3dm_um /dev/ps3dmproxy write_eprom 0x48C0A 0xFF
its a very mighty tool. you can also enable product mode and other things.
more offsets @ps3devwiki


UPDATE 2 AS OF 5/50/2011 :
OVER AT PS3 SCENE THESE GUYS ARE WORKING ON IT NIGHT AND DAY WITH SOME HINTS FROM Mathiuleh him self they almost got it done and yes im contributing what i know as well ONCE IT READY AND I HAVE THE GO ILL RELEASE IT ON NGU THE PUBLIC well here what we got so far contribute by posting what you know and i will add it
Found the key to decrypt the token. It's a step. Still need to figure a few more things out. ^^

SUCCESS!
key: 34-18-12-37-62-91-37-1C-8B-C7-56-FF-FC-61-15-25-40-3F-95-A8-EF-9D-0C-99-64-82-EE-C2-16-B5-62-ED
iv: E8-66-3A-69-CD-1A-5C-45-4A-76-1E-72-8C-7C-25-4E

If your IDPS was
0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77,
0x88, 0x99, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF
Encrypted Token (Dummy)

0x96, 0x6D, 0x15, 0xCC, 0x15, 0x32, 0x8C, 0x6A,
0xC9, 0xED, 0xC4, 0xFA, 0x7E, 0xAB, 0x8E, 0xA7,
0xEF, 0x38, 0x12, 0x91, 0xE9, 0x57, 0x02, 0x29,
0xF2, 0x9D, 0x1C, 0x6B, 0x09, 0xDA, 0x4B, 0x36,
0xC1, 0x91, 0x7F, 0xB4, 0x52, 0x80, 0xB3, 0x72,
0xDC, 0x14, 0x03, 0x30, 0x4B, 0xB2, 0xA9, 0x5D,
0x51, 0x9B, 0x91, 0xE2, 0x54, 0xAC, 0x09, 0x5D,
0x08, 0xEE, 0x28, 0x66, 0x74, 0x0A, 0xF7, 0xDC,
0xB6, 0xD3, 0x89, 0x2C, 0x85, 0x2B, 0xC7, 0xCC,
0xAB, 0x82, 0xD8, 0xB5, 0xEA, 0xAC, 0xFB, 0xDA

Decrypted Token (Dummy)

0x00, 0x00, 0x00, 0x01, 0x00, 0x11, 0x22, 0x33,
0x44, 0x55, 0x66, 0x77, 0x88, 0x99, 0xAA, 0xBB,
0xCC, 0xDD, 0xEE, 0xFF, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x19, 0x4A, 0x4B, 0xBA,
0x15, 0x97, 0xAE, 0x71, 0x36, 0xCC, 0xB6, 0x65,
0x7F, 0xC3, 0xB5, 0x3F, 0x49, 0x22, 0x2F, 0xB1


This is highly useful if you figured this it out + rep for info


So all we need is the button combo now right?
More or less..
05-30-2011, 07:47 PM #165
qa ftw omg omg omg whats that qa qa qa Smile
05-30-2011, 08:06 PM #166
-O-Z-Z-A-8-8-
At least I can fight
Originally posted by BoobiesDD View Post
Banning was invented for people like you. He did answer your question. You can't, you need CFW in order to complete the steps to unlock QA flagging.

Now answer my question: Why would you update to 3.61?


some 1 will figuire how sony do it properly with a dongle or a jig of some sort like the original jailbreak

i dont think sony use cfw to qa there consoles when they get sent in for repair
05-31-2011, 11:47 AM #167
Qa flagging is cool

The following user thanked stoney2759 for this useful post:

crazyface
06-01-2011, 03:41 AM #168
cpt.jay
DOWN GUNTER DOWN
people need to realise this is going to take some time to get right. plus people also need to realise that this will NOT work on 3.60 and above unless you qa flag before 3.60 then update the firmware wich you would like, unless someone gets the keys for 3.60 and above. plus people sating that "all we need now is the button combo" expecting to get it like in the next few mins need to chill there beans, it will take ages untill someone finds the combo.
06-01-2011, 04:29 AM #169
XDev
Banned
Originally posted by cpt.jay View Post
people need to realise this is going to take some time to get right. plus people also need to realise that this will NOT work on 3.60 and above unless you qa flag before 3.60 then update the firmware wich you would like, unless someone gets the keys for 3.60 and above. plus people sating that "all we need now is the button combo" expecting to get it like in the next few mins need to chill there beans, it will take ages untill someone finds the combo.

Not Exacltly We just need to look for it in vsh? maybe, Im looking through it for my self, Aswell as in touch with others that are to.
We are that much closer to this.
But like you are saying, this wont be in minutes, or week. It could be forever.
but with a few more hints hopefully, And or we findout what the last hint was that meth gave us we will sure conquer this.
06-01-2011, 02:38 PM #170
This is really cool. Too bad nobody here knows how to do it.
06-01-2011, 05:14 PM #171
cpt.jay
DOWN GUNTER DOWN
Originally posted by XDev View Post
Not Exacltly We just need to look for it in vsh? maybe, Im looking through it for my self, Aswell as in touch with others that are to.
We are that much closer to this.
But like you are saying, this wont be in minutes, or week. It could be forever.
but with a few more hints hopefully, And or we findout what the last hint was that meth gave us we will sure conquer this.



what firmware did you get the vsh.self from? mathieulh siad in the chat that he got it from a 3.41 if you need a 4.41 vsh.self let me know an ill send you mine. i decrypted the .seft to .elf
06-01-2011, 05:17 PM #172
wowaka
Former Staff
I haven't really been paying attention to this QA flagging thing recently, explain to the dummy please :dumb:.

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo