Post: 4.41 OFW CORE_OS Dump
06-19-2013, 07:15 AM #1
(adsbygoogle = window.adsbygoogle || []).push({}); Dumped CORE_OS_PACKAGE.pkg contents from the PS3UPDAT.PUP, decrypted some of the stuff and have a library of keys. Just wanted to help any developers out there (although you probably have this shit already)

CORE_OS_DUMP:
You must login or register to view this content.

lv0 decrypted (.elf) :
You must login or register to view this content.

4.40 - 4.41 Keys (for scetool and other purposes Winky Winky ) :
You must login or register to view this content.

Download: You must login or register to view this content.
Pass: ngudump

And to re-state really not taking credit for others work.. I just used all their tools and put it into 1 big "folder" for all of you to use. Hope this helps someone.


Edit #1: Edited license.txt and then I decrypted and encrypted lv0. without any changes (just testing the private keys) and it worked fine on my ps3.
You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 8 users say thank you to Jakes625 for this useful post:

|RichModder|, ArmoredLeader, BadChoicesZ, King Sosa, OmGRhys-x, Pseudo_Soldier, Wretch 32

The following 3 users groaned at Jakes625 for this awful post:

ErasedDev, SC58, SonyBlack
06-19-2013, 02:41 PM #47
Originally posted by Soldier View Post
I forget the actual name of the private keys we're referring to but it goes like this(if I remember right, tired as fuck Happy)...



...the only option is to somehow bypass the ECDSA Algo and have a 3.55 JB-like for 3.56+ firmwares, somehow guess the random key from Sony, or crack the ECDSA Algo and use advanced mathematics to interpret the key with the formula (Could take forever).

Again sadly, I don't see any of this happening. Current CFW is the best it will probably get, which is great nonetheless.


okay

sony encrypts using a async method. Which means.. it uses a private key (which no one has) to encrypt data and only people with the public key (we all have) can decrypt it. Idk what you guys are talking about with this other private key talk lol. I have the private keys and unless we are referring to two different private keys... my head hurts Sad Awesome
06-19-2013, 02:51 PM #48
Master0wn3r
I’m too L33T
Originally posted by Jake625 View Post
okay

sony encrypts using a async method. Which means.. it uses a private key (which no one has) to encrypt data and only people with the public key (we all have) can decrypt it. Idk what you guys are talking about with this other private key talk lol. I have the private keys and unless we are referring to two different private keys... my head hurts Sad Awesome


firmware 3.60+ has ECDSA, that means a private key will be generated through the ECDSA algo with your per console key, which is random for everybody and it is not console id, maybe that is what you think is the "second" key :P
06-19-2013, 03:36 PM #49
Originally posted by master0wn3r View Post
firmware 3.60+ has ECDSA, that means a private key will be generated through the ECDSA algo with your per console key, which is random for everybody and it is not console id, maybe that is what you think is the "second" key :P

It can't be different for everybody because then how would sony release OFW?
06-19-2013, 03:41 PM #50
Master0wn3r
I’m too L33T
Originally posted by Jake625 View Post
It can't be different for everybody because then how would sony release OFW?


I dong know exactly but the console key(i thought it was eid0 key) is in the hardware, and it gets encrypted with the ecdsa algo.
How does a console install it, through the bootldr, it decrypts the firmware (thats how 4.x cfws are possible) and after installing/decrypting the console reencrypts them with the ecdsa
06-19-2013, 04:13 PM #51
Originally posted by master0wn3r View Post
I dong know exactly but the console key(i thought it was eid0 key) is in the hardware, and it gets encrypted with the ecdsa algo.
How does a console install it, through the bootldr, it decrypts the firmware (thats how 4.x cfws are possible) and after installing/decrypting the console reencrypts them with the ecdsa


I think you guys are mixing up enc/dec keys for the actual file and for the console. like the actual .elf programming and their keys. or something.. idk lol because I can enc/dec lv0, lv1, lv2_kernal etc. fine and have it run on my ps3 without error/brick.
06-19-2013, 04:26 PM #52
Master0wn3r
I’m too L33T
Originally posted by Jake625 View Post
I think you guys are mixing up enc/dec keys for the actual file and for the console. like the actual .elf programming and their keys. or something.. idk lol because I can enc/dec lv0, lv1, lv2_kernal etc. fine and have it run on my ps3 without error/brick.


as i said i dont know it exactly :P
it might lead to something i just tried to answer your questions as i interpreted them, i dont know what we can archieve by modding lv0-2? maybe you can tell us?
06-19-2013, 05:00 PM #53
isnt it possible to get out of service mode witht he newly decrypted lvl2 file
06-19-2013, 05:09 PM #54
Originally posted by Jake625 View Post
I think you guys are mixing up enc/dec keys for the actual file and for the console. like the actual .elf programming and their keys. or something.. idk lol because I can enc/dec lv0, lv1, lv2_kernal etc. fine and have it run on my ps3 without error/brick.


please tell me how you got the EID0 keys and the curve have you found all sections 1-6? Let me explain this to you Your keys your using is from cfwprophet mfw it disables the ECDSA since how did you fix the no random fail as it as fixed from 3.56 and the private keys are not in ps3 or lv1 or lv2 you used 3.55 private keys which you can sign any file and install above Dont make me bring EUSSNL the admin of ps3devwiki in here!! trust me he would embarrassed you badly!! And he would tell you either way!! if you found the curve of ecdsa which i think you haven't and the sdk your bullshitting about if you thinking using libsecure or any ppc file which you think will help you good luck to you!! if you have 4.41 sdk and dev net access which must of cost you about £10k and have a real dex most of the sdk released on torrent's are missing hell lost of stuff!! so good luck with your boasting of oh ive made a cfw and ive edited a text file wow any one can do that!! One that note figure this out : */u8 curve0[] = {0xA3, trust me you wont find it anywhere on the net *credit's to the unicorn for help :-)

The following 4 users say thank you to ELITE xxmcvapourxx for this useful post:

DarkAngel312, Pseudo_Soldier, SonyBlack
06-19-2013, 05:23 PM #55
Originally posted by xxmcvapourxx View Post
please tell me how you got the EID0 keys and the curve have you found all sections 1-6? Let me explain this to you Your keys your using is from cfwprophet mfw it disables the ECDSA since how did you fix the no random fail as it as fixed from 3.56 and the private keys are not in ps3 or lv1 or lv2 you used 3.55 private keys which you can sign any file and install above Dont make me bring EUSSNL the admin of ps3devwiki in here!! trust me he would embarrassed you badly!! And he would tell you either way!! if you found the curve of ecdsa which i think you haven't and the sdk your bullshitting about if you thinking using libsecure or any ppc file which you think will help you good luck to you!! if you have 4.41 sdk and dev net access which must of cost you about £10k and have a real dex most of the sdk released on torrent's are missing hell lost of stuff!! so good luck with your boasting of oh ive made a cfw and ive edited a text file wow any one can do that!! One that note figure this out : */u8 curve0[] = {0xA3, trust me you wont find it anywhere on the net *credit's to the unicorn for help :-)


ha I got it from here: You must login or register to view this content.

lol

and why would sony still use 3.55 keys to sign apps above 3.56+ ?

idk man. and I don't even know how I got onto this topic I just decrypted some files Sad Awesome

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo