Post: [How To] Dump the Bootldr
12-18-2012, 02:21 AM #1
(adsbygoogle = window.adsbygoogle || []).push({}); Requirements
    
OtherOS++ with SS Patches
Linux Kernel with glevand's/graf's patches (red ribbon rc6 will do the trick, since it has the embedded kernel)
https://dl.dropbox.com/u/35197530/bootldrexploit.7z the exploit and the lv1 peek poke from Juan (already corrected in this case)
NOR console with a NOR dump (the exploit isn't adapted to NAND consoles yet)


How to

Start a normal session from red ribbon (or any other distro you might have)
Extract the contents of bootldrexploit to your home folder
Open your terminal and type as root:
    
cd bootldrexploit/ps3peekpoke

Compile the lv1 peek poke kernel module:
    
make

Insert the lv1 peek poke kernel module:
    
insmod ps3peekpoke.ko

Change directory to the exploit dir
    
cd ../btldr8

Compile the exploit
    
make

Make a nor dump by typing
    
dd if=/dev/ps3nflasha of=nor.bin bs=1024

Execute the exploit
    
./lv0Decrypt 0 nor.bin buffer.bin

It should show the status as status A0082. This means you've succeeded. check your dump for the keys.
    
hexdump -C dump.bin > test

nano test
(adsbygoogle = window.adsbygoogle || []).push({});

The following 4 users say thank you to Dr. Mayham for this useful post:

DEREKTROTTER, jborgadog, Ps3-Dev-2456
12-18-2012, 02:36 AM #2
Dude, your are obsessed with finding a way to JB 4.30 OFW, it is not going to happen bro, it would be great though but no one is going to crack ECDSA

The following user thanked Machiavelli_23 for this useful post:

SC58
12-18-2012, 02:40 AM #3
Originally posted by 23 View Post
Dude, your are obsessed with finding a way to JB 4.30 OFW, it is not going to happen bro, it would be great though but no one is going to crack ECDSA


I know that... but nothing is impossible. We already found the Lv0 private and public keys. PLUS i'm a PS3 developer... it's my job to find out how to solve the ECDSA

The following user thanked Dr. Mayham for this useful post:

jborgadog
12-18-2012, 04:39 AM #4
method1278
OLD SCHOOL IS COOL
What have you developed 4 the ps3
12-18-2012, 12:58 PM #5
Originally posted by MODZ View Post
I know that... but nothing is impossible. We already found the Lv0 private and public keys. PLUS i'm a PS3 developer... it's my job to find out how to solve the ECDSA



Give you a hint where to start scekrit ;-) look at 3.55 lv0 compare it with 3.60 so on!! but you got to have two files exactly with the same keys!!! buy the way its not ecsda its HMAC-SHA1 look at that first yes sha1 is different to HMAC!!! then look at ecsda!!! look at geohot hmac reverse and failoverflow hmac reverse they are both algor but its not what we need its the maths on how to calculate the public key its impossible to calculate the private keys Brute forcing the private keys would take billion of years no hacker has achieved to break the hmac-sha1 the only way we could do it i would recommend looking at quantum computers how to build one trust me i have looked at this for the past month with the dev's on irc channel not even hashcat with 70gb of dictionary or john the ripper cant do it.so for now what we need to do is look for public/iv/key and a exploit on lv2 but it will only be a hen.oh the number you need to work out what is *K (uCool Man (aka Tustin) is so im affraid hope this clears it up.if you want to discuss it further you can always pm me!!!
12-18-2012, 11:31 PM #6
jborgadog
Save Point
He developed the GUI v2 PS3 Tools
12-19-2012, 01:52 AM #7
SC58
Former Staff
buy a 3.55Happy
12-19-2012, 06:56 AM #8
method1278
OLD SCHOOL IS COOL
Originally posted by jborgadog View Post
He developed the GUI v2 PS3 Tools

no he didnt ..................

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo