User talk:Zecoxao
Jump to navigation
Jump to search
The Last Piece of the Puzzle
- http://www.psdevwiki.com/ps3/Syscon_Hardware (<SW-301)
- http://www.psdevwiki.com/ps3/Service_Connectors (Diag/Backup Mode, <3rd Generation)
- http://www.psdevwiki.com/ps3/Talk:Syscon_Hardware#Backup_Mode_.2F_Diag
- http://www.psdevwiki.com/ps3/Talk:Service_Connectors
- http://www.ps3devwiki.com/ps3/Cell_Configuration_Ring
- http://www.psdevwiki.com/ps3/SIG_File_Format
- http://i.imgur.com/xQizq0K.png
- http://www.psdevwiki.com/ps3/images/a/ac/TMU-520_1-871-645-11_A_Detail_3_%28SYSCON%29.jpg
- http://www.psdevwiki.com/ps3/File:PS3_Service_Connector_1st_Generation_COK-001.png
- http://en.wikipedia.org/wiki/ARM7#ARM7TDMI
- http://www.fpga4fun.com/images/JTAG_TAP.gif
- http://hsb.wikidot.com/arduino-jtag-finder-workshop
- https://www.youtube.com/watch?v=Up0697E5DGc
- http://urjtag.org/
- http://i.imgur.com/O10hqAK.png
- http://pastie.org/private/grd5u9izjlglkult64rta
- http://psx-scene.com/forums/f149/brick-recovery-research-74903/index37.html#post786487
- http://i.imgur.com/o9R0YjJ.jpg
- https://www.sendspace.com/file/qzq6a4 (Patent Explaining DECR SYSCON)
- https://imgur.com/a/pR0a4 (Messages from mullion indicating erasing of User Program Area before updating)
How
By enabling diagnostic mode on the ps3, we can enable the use of JTAG again (it's temporarily disabled when diag mode isn't set)falseIt is possible to dump the syscon firmware using this method (in unencrypted state)falseThe JTAG registers/TAP-controllers need to be bruteforced / reverse engineeredfalseThe leaked service manuals present information about the pins connected to the JigPinfalseThe ObjectiveSuite contains an object (DIAGSERVICE) used to diagnose the ps3 using JTAGfalseUsing a DIY JigPin would facilitate the task, but we still need more info about the hardware and software interface used by ObjectiveSuite to handle this.falseThis would probably work on ps4 too (provided that the diag pin and the JTAG pins still exist)false- f0f's method is a viable way to get the ROM from later syscons
- tx function can be produced and it's not required for bruteforcing
- ocd flag is located somewhere in the second SFR area (which covers 0x800 bytes, minus already documented flags)
- code base is located somewhere in the backup ram ( 0x800 bytes) or in the second SFR area (0x800 bytes)
- second SFR area ranges from 0xF0000 to 0xF0800
- backup ram ranges from 0xF0800 to 0xF1000
- ocd flag is likely 0xF07F5 since the other SFRs are the same from RL78 to 78K0R
- 486 registers from the 2nd SFR range are publically documented
- 1562 registers are not documented (0xF01E7 - 0xF07FF)
- minimum scan area would be 0xE1A bytes (covering code base only and assuming ocd flag is the known value of 0xF07F5)
- maximum scan area would be 0x55FC8A bytes (same as above and assuming ocd flag isn't known (times 0x619 bytes)
To wikify
- Wikify begin (please wait...)
- Roxanne, if you could also take care of these : http://pastebin.com/s75FzYxd , that would be awesome (i'm not sure what happened to eussNL so, i leave it on your hands.)
- When I get my left hand back, then we can check this out together. Roxanne
request_idps generated files binary xor
Note: files are padded 8 bytes at start, for convenience
Wii U Key/IV Goodness
Switch Key/IV Goodness
Type | Key | SHA1/SHA256 | Status | Description |
---|---|---|---|---|
AES-CTR | key:F4ECA1685C1E4DF77F19DB7B44A985CA | sha1:8C98FF409724784DDF3E3D39B60B25B7087FF537 | Valid | stage1_key_00 |
AES-128-ECB | key:C2CAAFF089B9AED55694876055271C7D | sha1:4A98D62FF6EC0A042B7592219200E37DD9603479 | Valid | package1_key_00 |
AES-128-ECB | key:54E1B8E999C2FD16CD07B66109ACAAA6 | sha1:8CEC47B1B3974EED32C03B11A9DE0133D9E0F00B | Valid | master_key_01 |
AES-128-ECB | key:4F6B10D33072AF2F250562BFF06B6DA3 | sha1:ADD1D37E4A5C540AEEEF4050A2AB98E8B0DC1D04 | Valid | master_key_02 |
AES-CTR | key:A35A19CB14404B2F4460D343D178638D | sha1:4D64731F7AFA031C7EEAE3EB2F462D55FF8FF5AE | Valid | package2_key_00 |
Kernel | - | sha1:124BEFB2895BBA4DB1726485DAF6684B33EF5F51 | Valid | 1.00 Encrypted Kernel |
System Modules | - | sha1:96BF598BD162D5D8C87F2B25741F758F47730C88 | Valid | 1.00 Encrypted System Modules |
Modulus |
B36554FB0AB01E85A7F6CF918EBA9699 0D8B91692AEE01204F345C2C4F4E37C7 F10BD4CDA17F93F13359CEB1E9DD26E6 F3BB7787467AD64E474AD141B7794A38 066ECF618FCDC1400BFA26DCC0345183 D93B11543B9627329A95BE1E681150A0 6B10A8838BF5FCBC90847A5A5C4352E6 C826E9FE06A08B530FAF1EC41C0BCF50 1AA4F35CFBF097E4DE320A9FE35AAAB7 447F5C3360B90F222D332AE969793142 8FE43A138BE726BD08876CA6F273F68E A7F2FEFB6C28660DBDD7EB42A878E6B8 6BAEC7A9E2406E892082258E3C6A60D7 F3568EEC8D518A633C0478230E900CB4 E7863B4F8E130947320E04B84D5BB046 71B05CF4AD634FC5E2AC1EC43396097B |
sha1:F847ED0465C0DFDCD2C28B3E1A6DA0C0F01FBBC5 | Valid | Public Debug |
Modulus |
8D13A7776AE5DCC03B25D058E4206959 554BAB7040082807A8A7FD0F312E11FE 47A0F99DDF80DB865A2789CD976C85C5 6C397F41F2FF2420C395A6F79D4A4574 8B5D288AC699356885A56432809FD348 39A21D246769DF75AC12B5BDC32990BE 37E4A0809ABE36BF1F2CAB2BADF59732 9A429D098B08F06347A3E91B36D82D8A D7E1541195E44588698A2B35CED0A50B D55DACDBAF114DCAB81EE7019EF446A3 8A946D76BD8AC83BD231580C79A826E9 D1799CCBD42B6A4FC6CCCF90A7B99847 FDFA4C6C6F81873BCAB850F63E395D4D 973F0F353953FBFACDABA87A629A3FF2 0927963F079A91F716BFC63A825A4BCF 4950958C55807E39B148051E21C7244F |
sha1:A809E09F8BD790446B86F28B84A6D0F36481A245 | Valid | Public Retail |
Regarding Jokes
- Sorry, but it's difficult to distinguish Contributors with Spam Users, especially when you aren't logged in and when you log in to your account with different IP Addresses (and especially with this current Spam situation). It won't happen for a second time. Roxanne 21th December 2015 (18:12 GMT+1)
- It's ok, i should've logged, but i keep formatting my pc, so i always forget :) In the end it was my fault. Thanks for the feedback though Zecoxao
- OK and to answer your question regarding the newest DEX Firmwares, I'm on CEX but I'm still on this Firmware. Is this Good or Bad? :) (Roxanne 22th December 2015 (22:56 GMT+1)
- it'd be nice to test some psgroove on it :)
- http://www.psdevwiki.com/ps3/User:Not_Zecoxao is still needed?
- nope
- http://www.psdevwiki.com/ps3/User:Not_Zecoxao is still needed?
- it'd be nice to test some psgroove on it :)
- OK and to answer your question regarding the newest DEX Firmwares, I'm on CEX but I'm still on this Firmware. Is this Good or Bad? :) (Roxanne 22th December 2015 (22:56 GMT+1)
- It's ok, i should've logged, but i keep formatting my pc, so i always forget :) In the end it was my fault. Thanks for the feedback though Zecoxao