Post: Mathieulh: QA Flagged Ps3 - Enable Hidden Firmware Option ( Means CFW On Steroids)
05-14-2011, 02:14 AM #1
Stack0verfl0w
Computer engineer
(adsbygoogle = window.adsbygoogle || []).push({}); member a few weeks ago Mathieulh released a video of the QA flagged PS3? To refresh your memories; the QA flag is the internal console flag used by Sony, it enables hidden options and removes restrictions for both retail and debug consoles alike. It is used for QA centers and the R&Awesome face Department (there are 2 levels of QA flags, Minimum and Advanced). In short it could lead to a complete open PS3…and yes all the CFW, homebrew and backup manager your little heart desires.

You must login or register to view this content.

Well the method of how to “QA flag” your PS3 was never posted/revealed but since then plenty of hints have been given in attempts for the “scene”, and one of the first steps was to figure out the secret button combo. Well after weeks of people trying and moaning, the man behind the emulators – squarepusher 2 has released/posted information on exactly what that button combo was. Noobs do not try this – the guide below is still a work in progress and QA flag button combo is the icing on the cake.
How to QA Flag your PS3, the button combo:

1. Be on 3.55 OFW (no rebug): You must login or register to view this content.
2.Move the PS3 cursor/select “Network Setting“
3.Punch the following button combo with your PS3 controller: L2 + L1 + R1 + R2 + L3 + D-pad Dow
4. Thats it, the “Edy Viewer”, “Debug Settings”, “Install Package” Menu will now appear.
Notes and disclaimers:

Install Package is useless and can’t install homebrew at the moment – only signed PKGs (and the first one in root of USB only).
This is not all that is needed to QA flag your PS3, but its a big start for the community – we still need all the pieces to fully QA flag the PS3 and its the scenes job to “figure out the rest”.

Thanks to munky875821417 for news tip.

enjoy source ps3hax.com
(adsbygoogle = window.adsbygoogle || []).push({});

The following 30 users say thank you to Stack0verfl0w for this useful post:

Alfa, AMNE, Arman M., b0snian, bryanakabid, Dante., DaveedDB, gamer89117, gunhead88, iDontExist, IRISH-SHAM1, jsonnerrr, Kallen, Karoolus, khalids19, killa skillz, kuruptaz, LIGHTDARKYIN, MateoGodlike, Monster-Energy, Norman, pooponme, PS3FFviewer, SavageRising, stuartlittle98, Swade, thabeast_32, UnTaMeD-KiD, vit., Wfloydboy16
06-05-2011, 02:09 AM #191
lilkid666
A.K.A Alez003
Originally posted by aiman119 View Post
Please excuse the noob question............what do you mean by IDA... =D ? I opened the file with HxD


he means ida pro You must login or register to view this content. its thier
06-05-2011, 02:10 AM #192
Originally posted by lilkid666 View Post
he means ida pro You must login or register to view this content. its thier


WOAH...tried to download the demo...neither IE or Norton Anti-Virus approve the program :\
06-05-2011, 02:24 AM #193
lilkid666
A.K.A Alez003
Originally posted by aiman119 View Post
WOAH...tried to download the demo...neither IE or Norton Anti-Virus approve the program :\


yea it does that idk y i shut my protector off thats the real site im not trying to give u a virus
06-05-2011, 02:41 AM #194
Originally posted by lilkid666 View Post
yea it does that idk y i shut my protector off thats the real site im not trying to give u a virus


Ok then. I think it's just because it's new and not downloaded very much. That's what Norton said anyway, I am assuming that's the same reason IE 9 blocked it. I'll turn off Norton's auto protection and download it then tell Norton to exclude the program. I'll have to mess with IE 9's settings too to download. Do I NEED this or can I just use HxD?
06-05-2011, 02:52 PM #195
lilkid666
A.K.A Alez003
Originally posted by aiman119 View Post
Ok then. I think it's just because it's new and not downloaded very much. That's what Norton said anyway, I am assuming that's the same reason IE 9 blocked it. I'll turn off Norton's auto protection and download it then tell Norton to exclude the program. I'll have to mess with IE 9's settings too to download. Do I NEED this or can I just use HxD?


need that..........

The following user thanked lilkid666 for this useful post:

aiman119
06-05-2011, 03:39 PM #196
Originally posted by lilkid666 View Post
need that..........


Got it, thanks! :y:
06-17-2011, 04:47 PM #197
Stack0verfl0w
Computer engineer
Originally posted by 9762
while the ps3 scene is slow now a days and some of you are dreading for the return of psn, mathieulh has posted some interesting discoveries on his twitter. Mathieulh has managed to qa flag his ps3 and show the hidden options available for it. Before i go on, most of you are probably wondering what in the world does qa flagged mean?

You must login or register to view this content.

to quote:

qa flag is the internal console flag used by sony, it enables hidden options and removes restrictions for both retail and debug consoles alike. It is used for qa centers and the r&d department, there are 2 levels of qa flags, minimum and advanced, this console has been set to the advanced one.

Now mathieulh has come out and said that he will not be telling us how he did this, but nonetheless very cool and it will be interesting to see where this will lead to.



this makes you feel teased

to quote video description:

i just qa flagged my metal gear solid 4 limited edition console and i thought i’d show you the hidden options for the sake of it. (and because i was bored)

i am sorry for the unstable camera, i only have two hands and the options are hidden and require (along with the actual flag) a crazy button combo to pop up. (i kid you not)

sorry i am not telling you how to do this, please do not ask.

Yes, this video is real

here are some interesting tweets made regarding this:


mathieulh mathieulh:
@dantezteam it’s an unmodified retail firmware.

@kakarotoks for various reasons, one of them being that you can warez with this, and the flag stays even after updating.

@kakarotoks the qa flag happens to remove a bunch of restrictions that have the side effect of preventing you to warez.

@dantezteam the console is qa flagged, the firmware checks for this flag and will enable special features when it finds it.

@dantezteam basically it’s what sony themselves use to allow special debugging on their consoles and loosen restrictions.

@kakarotoks by the way, advanced qa flag enables downgrading, just my 2 cents… xd

ps: If this is ever figured out it would mean a regular ps3 that if you push like up up left... X10 just saying not actual sequence you would be able to have a regular ps3 no cfw or dongle nothing just a regular ps3 retail on steroids it like a super cfw with out no mod just a button sequence to activate it one time only if it was release it would be the end of sony
of course, he won't share how to do it

but... Its pretty easy
update1: this how to qa flag your ps3 do at your own risk source psx scene

requirements:
Grafs kernel, ps3dm-utils and linux_hv_scripts

to patch your dm you have to run dmpatch.sh (skip if you're on gitbrew fw)

read qa flag:
Code:
Ps3dm_um /dev/ps3dmproxy read_eprom 0x48c0a
it should return 0xff on retail ps3.
Just set it to 0x00

write qa flag: <- on your own risk!

Code:
Ps3dm_um /dev/ps3dmproxy write_eprom 0x48c0a 0x00

or

ps3dm_um /dev/ps3dmproxy write_eprom 0x48c0a 0xff
its a very mighty tool. You can also enable product mode and other things.
More offsets @ps3devwiki


update 2 as of 5/30/2011 :
Over at ps3 scene these guys are working on it night and day with some hints from mathiuleh him self they almost got it done and yes im contributing what i know as well once it ready and i have the go ill release it on ngu the public well here what we got so far contribute by posting what you know and i will add it
found the key to decrypt the token. It's a step. Still need to figure a few more things out. ^^

success!
Key: 34-18-12-37-62-91-37-1c-8b-c7-56-ff-fc-61-15-25-40-3f-95-a8-ef-9d-0c-99-64-82-ee-c2-16-b5-62-ed
iv: E8-66-3a-69-cd-1a-5c-45-4a-76-1e-72-8c-7c-25-4e

if your idps was
0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77,
0x88, 0x99, 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff
encrypted token (dummy)

0x96, 0x6d, 0x15, 0xcc, 0x15, 0x32, 0x8c, 0x6a,
0xc9, 0xed, 0xc4, 0xfa, 0x7e, 0xab, 0x8e, 0xa7,
0xef, 0x38, 0x12, 0x91, 0xe9, 0x57, 0x02, 0x29,
0xf2, 0x9d, 0x1c, 0x6b, 0x09, 0xda, 0x4b, 0x36,
0xc1, 0x91, 0x7f, 0xb4, 0x52, 0x80, 0xb3, 0x72,
0xdc, 0x14, 0x03, 0x30, 0x4b, 0xb2, 0xa9, 0x5d,
0x51, 0x9b, 0x91, 0xe2, 0x54, 0xac, 0x09, 0x5d,
0x08, 0xee, 0x28, 0x66, 0x74, 0x0a, 0xf7, 0xdc,
0xb6, 0xd3, 0x89, 0x2c, 0x85, 0x2b, 0xc7, 0xcc,
0xab, 0x82, 0xd8, 0xb5, 0xea, 0xac, 0xfb, 0xda

decrypted token (dummy)

0x00, 0x00, 0x00, 0x01, 0x00, 0x11, 0x22, 0x33,
0x44, 0x55, 0x66, 0x77, 0x88, 0x99, 0xaa, 0xbb,
0xcc, 0xdd, 0xee, 0xff, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x19, 0x4a, 0x4b, 0xba,
0x15, 0x97, 0xae, 0x71, 0x36, 0xcc, 0xb6, 0x65,
0x7f, 0xc3, 0xb5, 0x3f, 0x49, 0x22, 0x2f, 0xb1


this is highly useful if you figured this it out + rep for info


update as 6/17/11
coming soon once secene back up i havent been following this but now i am for you guys
06-17-2011, 10:38 PM #198
thank you soo much for finding this! appreciate it
06-22-2011, 02:19 AM #199
Stack0verfl0w
Computer engineer
Originally posted by XxUSSoldierXx View Post
thank you soo much for finding this! appreciate it


updated enjoy redeem your self

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo