Post: Waninkoko explains how to develop a CFW 3.60/61
06-06-2011, 09:10 PM #1
223152
Keeper
(adsbygoogle = window.adsbygoogle || []).push({}); This is the translated version from Spanish to English. By waninkoko:

Originally posted by another user
1. Private keys can not be calculated for any firmware> = 3.56, and are NOT in any site, which for some are private (only the Sony has, and if we make a mistake it was thanks to them which they applied the algorithm So encryption of data and a few mathematical operations could calculate the private keys).

2. IF you can create a CFW 3.61, the only obstacle is to get the public keys, which can be drawn SI, with varying degrees of difficulty but you can. Each loader is encrypted with a private key and decrypted with the corresponding public key. But the lowest level loader in a FW is encrypted and decrypted with the root key, which is invariably because the root public key used to decrypt the loader is located in the metldr (obviously, the metldr will have to have the public key to decrypt the loader) and metldr NOT be updated in any way, so that the root key can not be changed from one version to another firmware because it is sad if any.

So if you want to create a CFW of 3.61, changing the LV2 to add new features, we have to go hacking the chain of loaders to get on. Example:

METLDR -> LV0LDR -> LV0 -> LV1LDR -> LV1 -> LV2LDR -> LV2

More or less this is the chain of loaders (do not know if there is some small variation in FW 3.61).

METLDR, as I said, NO you can update.

METLDR LV0LDR decode the root key (LV0LDR loader is the lowest level, if we do not have to METLDR) and executes it.

LV0LDR LV0 decode the LV0-key (this key if you can change between versions of firmware as LV0LDR SI is upgradeable and can therefore LV0 encrypt a private key and update LV0LDR to decode it with the new corresponding public key) and runs.

Decrypts LV0 LV1LDR ....

blablabla

LV2 LV2LDR decrypts the lv2-key and executes it.

Therefore, if you want a CFW, we need to decipher LV0LDR (with the root key, which geohot public and will never change), change LV0LDR change LV0 decryption key (the change of a key that is capable of decoding a LV0 encrypted with a private key that we DO know ... that private key? anyone, as if we generate a key), encrypt LV0LDR with the root key, and we can modify LV0 to our liking and is now LV0 deciphered with a different public key, which we know the private key. And so we change the whole chain to LV2, modify and recifrarlo with the new key we've chosen.

Well, that's the way broadly told (when I say encrypt / decrypt, I do not mean the contents of the loaders, because it works with AES encryption and symmetric and there is no question of public / private key, but I mean really at the head of such loaders, for signature, which uses RSA keys is where public / private partnerships, with the sole purpose of checking that these loaders have NOT been changed).

In the case of FW 3.61 the track is a bit more complex as there are RSA public key and AES keys that are easy to obtain, but hey, there are methods to obtain, there are people who have them, and therefore it is not impossible .

Now, we must take into account that a CFW can be installed only if the console is in a FW 3.55 or lower, because higher versions will make use of a new updater, which verifies the upgrade package (internal data the PUP, so I understand) by checking with new firms (which had not previously existed and are now mandatory) which we have neither the public nor the private key (the public can take, but privately we can forget and here no no chain so we can prevent this ... the updater is a separate application of FW and no longer has to do with the above explained).

Said this last, some will think that if the upgrade to a CFW 3.56/3.60/3.61 and thou mayest not reinstall any other CFW (that is, you stay forever in that CFW or FW actualizais an official). The answer is yes, but hey, is not inevitable and that, in creating this CFW, we can modify the VSH (or one) to use the old updater (which does not check new firms and therefore we have no obstacle to install new CFW), or modify the APPLDR to allow us to load the new updater but modified to not check signatures (the new updater can be changed, of course, but also need to modify our FW APPLDR currently installed to recifrar said updater with a private key known and APPLDR then be able to decrypt and run).

And that's all.


Source: You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 5 users say thank you to 223152 for this useful post:

Agentcell, ARVINLOCOx, Gandi, killa skillz, x i Su1c1d3 i x
06-06-2011, 09:23 PM #2
223152
Keeper
Originally posted by RANKSTA View Post
1stttt !!!!!!!!!!!!!!


-________________________- what a fagg

The following 3 users say thank you to 223152 for this useful post:

jfed, Slay No More, x i Su1c1d3 i x
06-06-2011, 09:27 PM #3
MagicMickey
I defeated!
My god I would be gladly be forever in 3.61cfw. I think.
Na want to play fifa2012.
06-06-2011, 09:32 PM #4
Originally posted by RANKSTA View Post
1stttt !!!!!!!!!!!!!!


soo fukin childish..
OP
this looks hard as hell
06-06-2011, 09:50 PM #5
223152
Keeper
god damn it -_____- just ban this fuking spammer
06-06-2011, 10:42 PM #6
waninkoko is a legend, the thing is who will be man enough to go against $ony & release a cfw...

i would release a cfw anonymously & spread it... and if they found me as the 1st source, i'll just say i found it from some website Happy

Simple, just spread a cfw anonymously
06-06-2011, 11:14 PM #7
UnrealReality
Sierra Leone
Originally posted by makaveli101 View Post
waninkoko is a legend, the thing is who will be man enough to go against $ony & release a cfw...

i would release a cfw anonymously & spread it... and if they found me as the 1st source, i'll just say i found it from some website Happy

Simple, just spread a cfw anonymously


why the **** would you release a cfw anonymously... people want the fame.... i would to and personally i dont blame him for not wanting to get ****ed by sony
06-06-2011, 11:23 PM #8
Originally posted by UnrealReality View Post
why the **** would you release a cfw anonymously... people want the fame.... i would to and personally i dont blame him for not wanting to get ****ed by sony


if you want to get butt f**ked by $ony then go ahead & give em ur phone number too so at least you can wear lipstick & look pretty b4 it happens,

release anonymously & if you want a bit of fame put ur code name/nickname in there... just like lulzsec, no one knows his ID but he is hurting $ony, it's harder if $ony don't know their enemies.
06-07-2011, 02:58 AM #9
sj_7
Keeper
Originally posted by UnrealReality View Post
why the **** would you release a cfw anonymously... people want the fame.... i would to and personally i dont blame him for not wanting to get ****ed by sony

Remember Jailbreaking a ps3 is legal in spain and waninikoko lives in spain so i think sony cant touch him if he releases CFW before talking to their government,or get any sort of warrant

The following user thanked sj_7 for this useful post:

UnTaMeD-KiD
06-07-2011, 03:15 AM #10
Frmunduh
Save Point
Seems more like trolling bait then anything else.. and unless someone steps up producing something other than talk, talk, talk or another addition to going no-where type videos its -

USELESS!!

The following user groaned Frmunduh for this awful post:

UnTaMeD-KiD

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo