Post: Possible things we could do with the backup exploit
02-01-2015, 07:19 AM #1
(adsbygoogle = window.adsbygoogle || []).push({}); Things we have accomplished:
Replace some game files.
Install PSN games.


Things we could do:
Replace some files that could modify the actually Firmware.
Find some more exploits from this exploit.



If you have any ideas on what we could make out of this exploit, tell me!


EDIT: I just started to find my own exploit, turns out the registry has some interesting options in it that could lead to something groundbreaking.

Pics: You must login or register to view this content. (Toggle QA?)
You must login or register to view this content. (Debug Options)
You must login or register to view this content. (Actual Debug?)

I also have some unofficial checksums for each important option:

homeQAMode: 2B97
debugMenu: ED21
debug: E925
debug (edy): E3E5
coreDump: 8769
coreDumpOptionFileGen: 8B43
coreDumpOptionTrigger: 40DF
coreDumpOptionExeCtrl: 0AB9
fakeLimitSize: 0CE5
fakeFreeSpace: BF27
fakeSaveDataOwner: 6DA7
fakeHddSpeed: F9CF
debugGameType: A241
debugBootPath: BECB
appHomeBootPath: 4666
wolDex: F4AD
debugSystemUpdate: F196
fakePlus: E192
hdcp: 5E4E
autoDIDebug: 1152
autoDIFlag: 9883
autoDITime: A9E2
debugFlag: C431
env: DCA8
bootMode: 9DAD
(adsbygoogle = window.adsbygoogle || []).push({});

The following user thanked DeflatedFootball for this useful post:

Midnight.eGo
02-03-2015, 03:15 AM #38
Originally posted by Dog88Christian View Post
That's why I was curious.. like if it did exist back then well he got it to crack. Why not now?

In 3.56 Sony fixed the ECDSA algorithm and it properly works now. It would take 1000 years for a super computer to crack it now. ECDSA involves super-level mathematics that are very hard to comprehend. Here's an explanation behind it if you wanna see: You must login or register to view this content.
02-03-2015, 03:20 AM #39
Dog88Christian
Hail to the King, Baby!
Originally posted by MetroSeven View Post
In 3.56 Sony fixed the ECDSA algorithm and it properly works now. It would take 1000 years for a super computer to crack it now. ECDSA involves super-level mathematics that are very hard to comprehend. Here's an explanation behind it if you wanna see: You must login or register to view this content.


I've seen that thread already.. but what was it in 3.55< that let us crack it. Does that mean the person who designed ECDSA could crack it? Even thought that would ever happen.
02-03-2015, 03:31 AM #40
Originally posted by Dog88Christian View Post
I've seen that thread already.. but what was it in 3.55< that let us crack it. Does that mean the person who designed ECDSA could crack it? Even thought that would ever happen.

Sony screwed up somewhere in one of the equations, basically they wrote an incomplete math problem. Geohot noticed this and exploited it to dump the ps3's private keys. I have no clue who created the ECDSA, but I know lots of things in the modern world rely on it and it'd be pretty bad if it was cracked.
02-03-2015, 03:38 AM #41
Dog88Christian
Hail to the King, Baby!
Originally posted by MetroSeven View Post
Sony screwed up somewhere in one of the equations, basically they wrote an incomplete math problem. Geohot noticed this and exploited it to dump the ps3's private keys. I have no clue who created the ECDSA, but I know lots of things in the modern world rely on it and it'd be pretty bad if it was cracked.


Ah ha smart fucker.. I actually used to have his mom's number, seriously.. I called 411 and asked for him xD. So does that mean the creator could crack that? I mean it is their own method.
02-03-2015, 03:42 AM #42
Originally posted by Dog88Christian View Post
Ah ha smart fucker.. I actually used to have his mom's number, seriously.. I called 411 and asked for him xD. So does that mean the creator could crack that? I mean it is their own method.

I think a group of people created it, but I'd guess they could? It'd defeat the entire purpose of its existence if they did crack it though since it was made to be uncrackable from the beginning.
02-03-2015, 03:46 AM #43
Dog88Christian
Hail to the King, Baby!
Originally posted by MetroSeven View Post
I think a group of people created it, but I'd guess they could? It'd defeat the entire purpose of its existence if they did crack it though since it was made to be uncrackable from the beginning.


Haha yeah I know I was just curious. Some people are so smart they could be aliens o.O
02-03-2015, 03:51 AM #44
Originally posted by Dog88Christian View Post
Haha yeah I know I was just curious. Some people are so smart they could be aliens o.O

yup and put them in a room together and you get something that an average person will never fully understand. :p
02-03-2015, 03:54 AM #45
Dog88Christian
Hail to the King, Baby!
Originally posted by MetroSeven View Post
yup and put them in a room together and you get something that an average person will never fully understand. :p


That would be me haha
02-03-2015, 01:06 PM #46
Originally posted by Dog88Christian View Post
That would be me haha


yes ecdsa was in before 3.55 since 00.01 sony was stupid to use the non random private key generator it wasnt geohot who hacked it he only done it from stealing other peoples work and claiming to be famous hense why so many devs have left in the scene behind closed doors and now.

there was another dude called juan nand he the one who helped the ps3 with 3.56 keys upwards

3 musketeers: flatz,eussnl,naehrwert was the one who cracked the lv0 using juan theory.

now the only person who we have left but he also leaving the scene soon is flatz.

with Mathieulh and kakaroto them two wow behind closed doors Mathieulh was lieing with his skin about NPDRM algorithm which would of helped us with HEN CFW (so you know might as well tell you) all it is sex kiosk firmware with ofw but we cant install anything you still need a flasher hense the backup tool released.

i know about all this because i was in the scene since 2007 and ive seen convo's people going and coming....

hope this explains well for you...

if you find objective suite and the new two dongle factory service dongle files you be in luck of downgrading...

QA : well ecdsa would be a problem to be enabled there is no algorithm to man unless some super smart person manages to reverse it and releases it to the world it is out there if you want to know more look at BTC they use the same...

if the dude find's the combo in user_token not just registry but in the syscon not firmware by the way he will be a hero...

thats all i can say for now...

find someone with decr1000a dump syscon reverse it and we will have fully cfw over ofw

The following 2 users say thank you to ELITE xxmcvapourxx for this useful post:

DeflatedFootball, Dog88Christian

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo