Post: How to dump the lv0
12-05-2011, 04:23 AM #1
Xx--AIDAN--xX
One Man Army
(adsbygoogle = window.adsbygoogle || []).push({}); First i will be explaining this in a way anyone with basic PS3 knowledge will be able to understand, lets get started.(hehe)


the bootldr holds the lv0 yes, the lv0 encapsulate the other ldrs (lv1, lv2, appldr, rvkldr, isoldr, ect.); sense 3.56^. But usually the chain of trust would go like metldr>other ldrs, and the metldr would run the loaders. But after 3.55 the lv0 has been copy the ldrs to the Ram then they are given to the metldr to exucute with out ever being held by the metldr. Now if you use a kernal module you can map out the ps3 real memory Using hardware you can dump Ram. By dumping the ram your getting a decrypted version of lv0 with all the ldrs in it. And you got keys.

Concept in boot order.

Cell INIT-> get encrypted bootldr off NAND/NOR flash, then the Ram will Initialises. This is when it will load the bootldr into a isolated spu, secure boot will decrypt the bootldr and verifies and executes. Now this is where the magic happens. Now the bootldr will decrypt the lv0 and it will get copy to the Ram (With loaders) before the Ram will run the loaders to the metldr


The metldr will always have to boot the ldrs too cause it is per console encrypted sony cant go change that out of no where.


source You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following user thanked Xx--AIDAN--xX for this useful post:

slim355

The following 2 users groaned at Xx--AIDAN--xX for this awful post:

Implicit, SirBlazeAlot
12-05-2011, 04:41 AM #2
jr3277
Banned
lol duh you lost me, I am glad people like you know what there doing
12-05-2011, 04:45 AM #3
ichris26
The Muff Muncher
Originally posted by jr3277 View Post
lol duh you lost me, I am glad people like you know what there doing


He doesn't know what he is doing. :lol:

He straight copy/pasted that from Ps3Hax.

You also have to have some skills and some additional hardware to be able to dump the encrypted data.

The following 2 users say thank you to ichris26 for this useful post:

Glowing, SilentStorm1011
12-05-2011, 04:49 AM #4
Steeldude1
Do a barrel roll!
people with basic knowledge my a** lol
12-05-2011, 05:01 AM #5
jr3277
Banned
lol okay I know just about enough to hurt myself, simple file mods like make say a 1.07 game update say its a 1.13 or ad someone else mod file that they worked hard on in a game i did do that vsh spoof when it came out like 5 months ago but I keep it simple and let the pros handle the hard stuff. If you want to know how to build an 11s car I am you man lol
12-05-2011, 12:18 PM #6
SirBlazeAlot
I ROCK like a fossil
Originally posted by xX View Post
First i will be explaining this in a way anyone with basic PS3 knowledge will be able to understand, lets get started.(hehe)


the bootldr holds the lv0 yes, the lv0 encapsulate the other ldrs (lv1, lv2, appldr, rvkldr, isoldr, ect.); sense 3.56^. But usually the chain of trust would go like metldr>other ldrs, and the metldr would run the loaders. But after 3.55 the lv0 has been copy the ldrs to the Ram then they are given to the metldr to exucute with out ever being held by the metldr. Now if you use a kernal module you can map out the ps3 real memory Using hardware you can dump Ram. By dumping the ram your getting a decrypted version of lv0 with all the ldrs in it. And you got keys.

Concept in boot order.

Cell INIT-> get encrypted bootldr off NAND/NOR flash, then the Ram will Initialises. This is when it will load the bootldr into a isolated spu, secure boot will decrypt the bootldr and verifies and executes. Now this is where the magic happens. Now the bootldr will decrypt the lv0 and it will get copy to the Ram (With loaders) before the Ram will run the loaders to the metldr


The metldr will always have to boot the ldrs too cause it is per console encrypted sony cant go change that out of no where.


source You must login or register to view this content.


First of all: You have no idea whatsoever what the FUC.K your talking about. So next time, before posting something that has already been posted, just to try to get rep/thanks: Just do us ALL the favor and...
Stop:
Fill the bathtub
Get in
Drop radio in water while plugged in
we ALL PROFIT Happy

The following user thanked SirBlazeAlot for this useful post:

Jakeyy
12-05-2011, 03:02 PM #7
jr3277
Banned
Originally posted by SirBlazeAlot View Post
First of all: You have no idea whatsoever what the FUC.K your talking about. So next time, before posting something that has already been posted, just to try to get rep/thanks: Just do us ALL the favor and...
Stop:
Fill the bathtub
Get in
Drop radio in water while plugged in
we ALL PROFIT Happy[/QUOTE lol
12-05-2011, 08:58 PM #8
^^^^Dude above me fails at quoting.

The following 2 users say thank you to #Robert G. III for this useful post:

CodingNation, SirBlazeAlot
12-05-2011, 09:16 PM #9
SirBlazeAlot
I ROCK like a fossil
Originally posted by XxKonFUzeDxX View Post
^^^^Dude above me fails at quoting.


Indeed............
12-05-2011, 11:58 PM #10
Originally posted by xX View Post
First i will be explaining this in a way anyone with basic PS3 knowledge will be able to understand, lets get started.(hehe)


the bootldr holds the lv0 yes, the lv0 encapsulate the other ldrs (lv1, lv2, appldr, rvkldr, isoldr, ect.); sense 3.56^. But usually the chain of trust would go like metldr>other ldrs, and the metldr would run the loaders. But after 3.55 the lv0 has been copy the ldrs to the Ram then they are given to the metldr to exucute with out ever being held by the metldr. Now if you use a kernal module you can map out the ps3 real memory Using hardware you can dump Ram. By dumping the ram your getting a decrypted version of lv0 with all the ldrs in it. And you got keys.

Concept in boot order.

Cell INIT-> get encrypted bootldr off NAND/NOR flash, then the Ram will Initialises. This is when it will load the bootldr into a isolated spu, secure boot will decrypt the bootldr and verifies and executes. Now this is where the magic happens. Now the bootldr will decrypt the lv0 and it will get copy to the Ram (With loaders) before the Ram will run the loaders to the metldr


The metldr will always have to boot the ldrs too cause it is per console encrypted sony cant go change that out of no where.


source You must login or register to view this content.
wonder what member over there cp this from a dev site this has been released months ago just no one ever tried it cause it requires soldering

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo