kakaroto introduces PL3 and 3.01 firmware news - 改機

Robert avatar
By Robert
at 2010-09-29T17:47

Table of Contents

如果你手上有 3.01, 3.10 或 3.15 韌體版本的 PS3,
而你又想要玩 PSJB 的話或許可以考慮暫時不要更新,
kakaroto 大大在眾多網友捐款贊助下買了一台 3.01 版本的 PS3,
他目前正努力將 PSJB 移植到這些版本上面,
據 Blog 上的描述似乎已經 dump 了 3.01 版的 LV2 memory,
目前正在試著找出正確的偏移位址好觸發漏洞,
同時作者也把 LV2 的 dump image 放到一個名叫 PL3 的專案 repository 中,
PL3 是作者新開的專案,
目的是希望建立一個各種 PSJB 方案的 payload 都能共用的 git repository
(如 PSFreedom 或 PSGroove)

====================================
原文連結 : http://0rz.tw/VSY0p
PL3 git repository: http://github.com/kakaroto/PL3

I'll announce two things, first, let's talk about PL3..
PL3 is a new project I started in order to have a common repository
of payloads that can be used by any 『jailbreak』 implementation.
I got tired of copying payloads from PSGroove, and I had some nice
changes in mine that I thought the PSGroove project could benefit from,
so I thought I'd create a single repository that both projects,
PSFreedom and PSGroove (or any other similar projects) could use.

You can find it in github, so don't hesitate to submodule it and use it.

Second important news… I've bought a new PS3 just for homebrew.
Thanks to all who donated money so I can buy it (I didn't get enough
donations to pay for it, but enough to help me).
I bought this PS3 used and it came with firmware 3.01! This is good and
bad news : I can't use PSFreedom to jailbreak it, so i've put on hold any
improvements for it, however, it will allow me to actually
port PSFreedom to older firmwares! My plan is to get the jailbreak working
on 3.01, then move on to 3.10 and 3.15
(depending on how hard it is, i might skip 3.10).

Another good news is that after 4 days of work, I was finally able
to dump the LV2 memory from the 3.01 firmware, and now all that remains
is to find the right offsets to patch, and port PSFreedom to 3.01,
so all those who are still using this firmware version, you will
soon be able to jailbreak it! Once I'm done with that,
I'll try to do the same with the 3.10/3.15 firmware versions!

To dump LV2, I used a trick and algorithms found by marcan42,
so big thanks goes to him, as well as many other people who helped
me out, RichDevX and Aaron in particular. I used RichDevX's idea
of ignoring the JIG and bruteforcing the address in which the port1
descriptor gets stored until I get a hit, then use that payload to
dump lv2, then find the right JIG offset for that particular
firmware from the dump. Marcan's trick was to send the data through
the ethernet cable by using LV1 only hypercalls, and it worked!

Now the latest git version of PL3 has a new 『dump_lv2』 payload which
you can use, it is firmware independent, and only uses LV1 hypercalls,
so it should just work… It will dump all the lv2 memory through ethernet,
so fire up wireshark, save the dump to a .pcap file,
and use the tool in PL3/tools to extract the memory dump from the .pcap file.

In other news, I will soon upload to Ps3utils an .idc script
that will search and find the syscall table,
and correctly resolve all of its functions and name them properly..
maybe even have it automatically find all functions of a dump in order
to save time creating procs in IDA. I'll let you know once I'm done with it.

--
Tags: 改機

All Comments

Daph Bay avatar
By Daph Bay
at 2010-10-01T10:26
看成LP3…
Gilbert avatar
By Gilbert
at 2010-10-05T09:16
3 (廣告?
Todd Johnson avatar
By Todd Johnson
at 2010-10-08T23:56
悟空的真名?

徵求幫忙刷機中壢中原

Lily avatar
By Lily
at 2010-09-29T01:36
我的PSP是2007的 現在版本是6.20 徵中壢或中原可幫忙刷機的朋友 酬勞一杯飲料或一餐都可以 謝謝 :) - ...

4.2J USB LOADER GX無法讀取

Michael avatar
By Michael
at 2010-09-29T00:00
小妹的主機是4.2J渡假同捆版, 照著K大的#1A_ZLQVe這篇順利安裝成功, 但在使用USB LOADER GX時, 可以看到遊戲的標題和封面, 點擊光盤後就跳回HBC的選單畫面。 不知道是什麼原因,可以請好心人指點一下嗎? 謝謝!~ - ...

用usb存檔來改紀錄

Eden avatar
By Eden
at 2010-09-28T19:51
不知道這邊能不能討論修改遊戲存檔的問題, 但我還是問一下好了,不行在自D.... 我在網路上找到用usb隨身碟存檔修改紀錄的教學, 用了以下三個軟體: 1.USB XTAF Xplorer (提存usb隨身碟記錄的工具) 2.Xbox Save Editor (修改ID的工具) 3.Xbox 360 Has ...

PSP 3007問題

Margaret avatar
By Margaret
at 2010-09-28T17:28
不好意思想請問一下  我的PSP 3007 原廠是 5。03版本 但是我不小心升級到 5。51 請問板上大大們 它可以降級嗎 謝謝大家 - ...

SCEA is hard at work to find you

Kama avatar
By Kama
at 2010-09-28T13:20
Sony 開始行動了!!! Sony 也注意到了有越來越多的 PS3 破解活動在網路上出現, 並且要求 ISP,Domain 註冊商, 網站提供業者提供相關的資料, 首先被抄的是 http://shoppsjailbreak.com 這個網站, 同時該網站擁有者所使用的 “vladgazouneatyahoo ...