Post: More Explanation On The “Exploit” By Mathieulh
03-22-2011, 09:01 PM #1
Kherod
Be Dope, Act Dope, Stay Dope.
(adsbygoogle = window.adsbygoogle || []).push({}); You must login or register to view this content.

Many people have been talking about the exploit found by Mathielh and some people got too excited about it. His exploit would let us hack all future firmwares which are soon to come.

Whether or not it can be compared with the exploit that geohot used to obtain metldr keys is still not clear, even from Mathieulh himself since geohot has been keeping his mouth shut about it although he did told everyone on IRC, the metldr exploit was done (or use) on a OtherOS enabled 3.15 console.

Now, Mathielh posts:
Originally posted by another user
Actually the revocation list exploit doesn’t allow you to exploit isoldr, you could however sign a revoke list if you had the revocation list keys and knew the sign fail, and use that to dump isoldr. Metldr does not load revocation lists.


Originally posted by another user
@jarmster
Ya well without a disassembly i guess its all speculation isn’t it math


Originally posted by another user
This has been tested, how do you think I could release the lv2ldr and appldr keys ? (about 24hrs before Geohot showed up with metldr keys) This has been tested, how do you think I could release the lv2ldr and appldr keys ? (about 24hrs before Geohot showed up with metldr keys)

You can also dump any loader using a signed metadata (including metldr) though that means you need to have the keys for it in the first place (kinda kills the purpose)

Your entire purpose is to get the isolated process (the code running inside the spu) to jump to your instructions

For exemple the following instructions will dump the isolated LS to the SPU mailbox:
loop:
rdch $3, ch29
lqd $3, 0($3)
wrch ch28, $3
rotqbyi $3, $3, 4
wrch ch28, $3
rotqbyi $3, $3, 4
wrch ch28, $3
rotqbyi $3, $3, 4
wrch ch28, $3
up_one:
br loop
br up_one
Of course you’ll need a ppu payload to fetch the mailbox data.
Metldr is trivial to dump now that you can sign your loader, but I wont say anything more on this.

Finally the problem with isoldr and the revoke list exploit isn’t so much that the exploit doesn’t work (it actually does) It’s that the payload from the crafted revoke list overwrites isoldr keys (which kinda kills the whole purpose), You can however get the revoke list keys from lv2ldr or appldr using the revoke list exploit and then sign a revoke list metadata to exploit isoldr later on. (There are other ways to get isoldr though, including the 3.60+ exploit I have (but there is at least another I know of) Again, good luck in your endeavor.


When he was asked about the NPDRM key in the equation. Here’s what he said:
Originally posted by another user
There is more than one npdrm key. It’s not been released because the ones who have the skills to do it do not remotely care about pirating playstation store games (obviously).


You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 5 users say thank you to Kherod for this useful post:

1337UNO, crazyface, hacker4life, Jakob, khalids19
03-22-2011, 09:57 PM #20
Norman
NORMAN
Originally posted by rosseh View Post
do u guys think this would bypass something possibly and let us play online ?
You must login or register to view this content.


a wireless bridge for ps3


This has nothing to do with cfw. But no, it couldn't spoof the passphrase.

The following user thanked Norman for this useful post:

rosseh
03-22-2011, 09:58 PM #21
TryCatchMe
Like A Boss
I support mathieu
But not releasing anything just shows he is scared of Sony
03-22-2011, 10:03 PM #22
not really he can pass the hack behind closed doors
he can pass hack to me i will take the blame
03-22-2011, 11:20 PM #23
Matthieu's ego will not allow him to release anonymously..

why is he trying to "mentor" the ps3scene... stay away or help out your not the goddamn riddler

The following 4 users say thank you to ddrrmm for this useful post:

crazyface, Koyasan, KyUsS--x420x, NeglectFate
03-22-2011, 11:55 PM #24
Kherod
Be Dope, Act Dope, Stay Dope.
Originally posted by rosseh View Post
not really he can pass the hack behind closed doors
he can pass hack to me i will take the blame


That would be nice of you, but I do not, under any circumstances, think that you would want to take the blame for it an get sued. You really want to pay billions of dollars? Not hating, but just saying...

The following user thanked Kherod for this useful post:

NeglectFate
03-23-2011, 05:06 PM #25
xK-ayne
Bounty hunter
Originally posted by khalids19 View Post
yeah sure anyway it seems a CFW is coming more closer than i expected! thumbs up if you agreeSmile


this isnt youtube buddy stop asking for stuff :mad:
03-23-2011, 05:09 PM #26
Originally posted by khalids19 View Post
yeah sure anyway it seems a CFW is coming more closer than i expected! thumbs up if you agreeSmile


dude you just copy and paste your post from youtube? "THUMBS if you agree" /facepalm
03-23-2011, 05:10 PM #27
superhighme
dude, wheres my car
Originally posted by ViiRuzZ View Post
You must login or register to view this content.

Many people have been talking about the exploit found by Mathielh and some people got too excited about it. His exploit would let us hack all future firmwares which are soon to come.

Whether or not it can be compared with the exploit that geohot used to obtain metldr keys is still not clear, even from Mathieulh himself since geohot has been keeping his mouth shut about it although he did told everyone on IRC, the metldr exploit was done (or use) on a OtherOS enabled 3.15 console.

Now, Mathielh posts:






When he was asked about the NPDRM key in the equation. Here’s what he said:


You must login or register to view this content.


im pretty sure this was copy and pasted
but nice post anyway
i think it was on ps3hax.com
03-23-2011, 05:20 PM #28
khalids19
Bounty hunter
Originally posted by ayne View Post
this isnt youtube buddy stop asking for stuff :mad:


ey no am just kidding anyway am kinda making a point to noobs

---------- Post added at 08:20 PM ---------- Previous post was at 08:19 PM ----------

Originally posted by vipervimal View Post
dude you just copy and paste your post from youtube? "THUMBS if you agree" /facepalm


you people think am a noob /facepalm i know that dis isnt youtube but am just jokin dont you get it thumbs up if you agree i got two thumbs by the way heheCool Man (aka Tustin)

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo