PS3 Hacks

#1 Spot for PS3 Hacks

Home | PS3 News | PS3 Hacks | PS3 Downloads | PS3 Saves

Folding@home | PS3-Hacks Live Chat | PS3 Reviews | Contact Us


You are not logged in.

Announcement

RAMROD'S BR-D BURNER DRIVE FOR AN ADMIN FUND:
INFO

#1  2008-01-21 16:27:14

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Install Test Firmware on retail PS3??

(From Wikipedia) (about PSP downgrader) On 9 September 2006, an easier way of downgrading firmware 2.01 was released. It functioned in the exact same way as the 2.00 downgrade (swapping index.dat from flash0 to the index.dat from the 1.00 firmware, tricking the PSP into launching the 1.50 update EBOOT) however, it uses a later TIFF exploit (as the one used to downgrade firmware 2.00 was patched in 2.01)
Bottom line: Replace a file in the NAND chip so the PSP thinks the frimware is older than it is. (so you can start older firmware updates)

Theory

But, what if someone made a program that could change individual files on the NAND chips?
If you could replace a file that gives the PS3 it's firmware number with an older one wouldn't the PS3 launch the Sony updater that is older than the PS3's current firmware?

Unsigned Code!

If you used my theory and grabbed the PS3's index.dat from a 1.50 Test PS3 and used this file to replace your retail PS3's index.dat and then tried to start the leaked 1.80.pup test firmware, wouldn't the installer start because the PS3 thinks it is test FW 1.5? (please note index.dat is the name of the PSP's file that determines the FW #, but since the PSP and PS3's FW are similar the PS3 probably has a file like this) Dev'ers should be made aware of this!

Offline

 

#2  2008-01-21 19:02:35

nickb827
Prior Of The Ori
Registered: 2007-05-21
Posts: 654

Re: Install Test Firmware on retail PS3??

That's a great idea, but how would you switch out the "index.dat"?


http://i251.photobucket.com/albums/gg313/JoN-pics/nickb.png
THANK YOU JoN-
PSN is ThatGuy827 (Not sure if there is caps or not), but PM me before adding me or I won't accept.

Offline

 

#3  2008-01-21 20:17:09

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Re: Install Test Firmware on retail PS3??

With the use of a mod chip. (infectus) and a program that edits single files in the PS3. This program that changes single files in the NAND chip of the PS3 is the only thing stopping us from trying this.

Offline

 

#4  2008-01-22 04:04:33

Joss
Horus Guard
From: UK
Registered: 2008-01-01
Posts: 421

Re: Install Test Firmware on retail PS3??

mdog wrote:

but since the PSP and PS3's FW are similar

How?

If they were similar, we wouldnt be taking about how to hack the firmware would we?

Last edited by Joss (2008-01-22 04:05:32)


http://joss.plesk.freepgs.com/sig3.jpg
PS3: 60GB Firmware: 2.50
PSN ID: Josseh
Games: Battlefield: Bad Company, GTA IV, CoD 4, GT 5: Prologue, RFoM, Fifa 08, Ridge Racer 7, Fight Night Round 3

Offline

 

#5  2008-01-22 19:20:47

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Re: Install Test Firmware on retail PS3??

True, but the point I am trying to make is that there is probably a file in the NAND chips of the PS3, that holds the firmware number.

Offline

 

#6  2008-01-26 03:01:10

MaX_SLayeR
PS3 Hacks ESKRIMA
From: California
Registered: 2007-09-25
Posts: 112
Website

Re: Install Test Firmware on retail PS3??

Lets not get ahead of ourselves here.


http://i34.photobucket.com/albums/d130/unemplizoid/gap2.gif

PSN: MaX_SLayeR

Offline

 

#7  2008-01-26 21:18:24

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Re: Install Test Firmware on retail PS3??

I agree, but we should at least get to the point where we can try this with different files. To see if it is possible.

Offline

 

#8  2008-02-11 17:27:54

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Re: Install Test Firmware on retail PS3??

Update
I just read the "PS3 NAND Extractor Update & More!" story by CJPC and he explained that with some game modifying he was able to get games to run from the hard dive (external and internal)(on test PS3's only). This makes this theory more urgent for people like CJPC to look into.

Offline

 

#9  2008-02-11 17:36:45

MaX_SLayeR
PS3 Hacks ESKRIMA
From: California
Registered: 2007-09-25
Posts: 112
Website

Re: Install Test Firmware on retail PS3??

mdog wrote:

Update
I just read the "PS3 NAND Extractor Update & More!" story by CJPC and he explained that with some game modifying he was able to get games to run from the hard dive (external and internal)(on test PS3's only). This makes this theory more urgent for people like CJPC to look into.

Buts its just more crap from PS3news.


http://i34.photobucket.com/albums/d130/unemplizoid/gap2.gif

PSN: MaX_SLayeR

Offline

 

#10  2008-02-12 15:12:07

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Re: Install Test Firmware on retail PS3??

lol, true. I think video proof is in order.

Offline

 

#11  2008-02-12 15:38:10

snafupossum
Ori
From: Texas
Registered: 2007-02-03
Posts: 737
Website

Re: Install Test Firmware on retail PS3??

I dont get this... ps3 is nothing like psp... so why would you want to go to firmware 1.5? when there is no point going to there because it doesnt allow anything. also, even with the test firmware installed, i hope your talking about a dev firmware, the hardware isnt there. a dev box is different then a retail box.


http://i36.photobucket.com/albums/e30/snafupossum/photoshop/purpcopy.jpg
"Friggin Powerslave going friggin chuck norris on us and dropping the dictionary bomb on us." -nickb827
Soft Mod Depot - your source for the latest in console modding-http://smdepot.net

Offline

 

#12  2008-02-12 15:51:45

Powerslave
Ruler of All
From: Alpha Quadrant
Registered: 2007-01-15
Posts: 10934
Website

Re: Install Test Firmware on retail PS3??

In order to flash DevKIT firmware to the PS3, you would need to resign the package.  When the firmware is done, is it signed, and also done a MD5 hash, along with the public Key.  When or IF you change 1 bit, just ONE BIT in side the pak, the MD5 is no longer valid, and the Firmware won't install. 

So, say you unpak a normal firmware, and put in DevKIT firmware, it won't work.  Sony made sure this can't be done conventionally, as in using their system update to do it.

The only way would be to use a flash kit, to force the firmware to be flashed into the NAND chips. This is similar to how MOD CHIPS are done, like with XBOX1, when you flash the on-board TSOP. You still got to know what goes where, because each flash or EEPROM usually has four banks, hence the nickname of EEPROM being called an E-square.  Most EEPROMs with four banks will contain the same information, so you can switch banks as a backup.  However, new O/Ss have seperate code in each bank, that is trigger/switched by the mainbaord when needed.  The XB1 Version 1.0 - 1.2 had 1 MB flash, with four banks.  Versions there up to V1.5 had 256k flash, and V1.6 and up they REMOVED the flash, and put the bios in ROM.  The 1.3 to v1.5 are CAKE to flash, two wire jumpers, and that's it!!  The 1.0 to 1.2 are not as easy, you need more jumpers, and another chip MFG required one more jumper.  Then, you could install a switch to boot STOCK or MOD by using the switch to change banks before powering up...  This is where Infectus comes in, and is not unlike the Modchip types used for XB1 that were soldered to the LPC bus.  This will do the same thing, except does not take over the PS3 functions, just allows for access and writing.

Another example of what they could use BANK switching for; boot start-up code, switch banks, then from the Chip, switch banks, then load the O/S from the other bank.  Once that is done, you can switch banks again to load the GUI, and so on.  The default bank can either have non classified code, or nothing at all.  This makes it a little harder for people to hack, because you need to put things where they belong.  It is only a matter of a few more steps, and the use of jumpers to switch banks, because the primary boot code will not be in the default bank, it WILL need triggered.  Or, the flash hit will have to switch banks for you, and all that stuff.

What you need to do FIRST, is WIKI EEPROM and read how they work...  Flash is the same, except it is a specific type of EEPROM that is erased FIRST, then programmed in large blocks; in early flash the entire chip had to be erased at once.  NAND FLASH uses tunnel injection for writing and tunnel release for erasing. NAND flash memory forms the core of the removable USB interface storage devices known as USB flash drives, as well as most memory card formats available today.

http://en.wikipedia.org/wiki/EEPROM
http://en.wikipedia.org/wiki/Flash_memory

Offline

 

#13  2008-02-12 21:00:48

mdog
PS3 Just Gettin' Started
Registered: 2008-01-21
Posts: 16

Re: Install Test Firmware on retail PS3??

So basically this will not work because the entire nand (not individual files) is signed. The only other chances of getting test firmware to run is to find a hardware/software hack (which would be useless because you would already have hacked the PS3) or finding out how the PS3 signs the nand in detail and being able to manipulate test firmware dumps to run on a retail PS3.

Offline

 
Home | PS3 News | PS3 Hacks | PS3 Downloads | PS3 Saves

Folding@home | PS3-Hacks Live Chat | PS3 Reviews | Contact Us


Board footer

Powered by PunBB
© Copyright 2002–2008 PunBB