作者cassine (Savannah)
看板Modchip
标题[PS3 ] PSGrade 开放原始码的降级方式不远了?
时间Mon Nov 22 23:29:41 2010
http://ppt.cc/gJn_
zAxis, of PSX-Scene has been working diligently on an open source
version of psdowngrade known as "PSGRADE." Today he shares his work
with the public however it is not fully functional. As his code still
requires the dongle master key which is buried under the PS3 console.
The good news however s that zAxis can retrieve the key via 3.15
firmware
He is asking the community, anyone with a 3.15 console, to help
retrieve this key. Once retrieved, PSGrade should become fully
functional. Below, is his request to the public.
To anyone who wants to help, here is what you have to do:
1- run the PSGrade I posted (just like jb)
2- reboot into linux (no power cycling!!)
3- dump HV (and post it)
if you don't know how to dump HV in linux, then google it
(you will
need to open your ps3 and solder it DON'T DO IT IF YOU ARE NOT AN
EXPERT!!!)
once you get the key, post it in key.h and try it.
Please remember, this is a work in progress, nothing is working
yet (so dont ask for hexes), and nothing is for sure.
Good Luck!
Oh, and thanks to graf_chokolo for ... everything, Hansi for the
dump, and mathieulh for PSGroove (PSGrade is a derivative of PSGroove)
and everyone else.
Accorking to graf_chokolo, to get the ps3 to decrypte the master
key, then you have to call "Verify Response" and the master key will
saved in plain text. it is called when plugin a jig, and that is what
PSGrade is.
Once we have the key, we will have a working jig :-)
And no 3.41 is no good even if you have dump the HV
Download PSGrade (not yet fully functioning):
https://github.com/zAxis/PSGrade
******
这篇技术性的字眼很多,首先解释一下 JIG的工作原理: JIG是一个主动元件,
必须要有硬体运算的能力,当主机准备要进入Factory/Service 模式时,会侦测
USB连接埠是否有 JIG元件存在, JIG元件有特殊的USB ID,前四码是 0xAAAA
,符合後系统会随机产生一个乱数,然後利用上面文章中提到的金钥将:1.某个
乱数;2. JIG的USB ID两者加密起来,然後传给 JIG, JIG接到後利用同一个金
钥将加密的讯息解密,然後将解密的结果回传,主机比对相符後才允许进入F/S
模式。
偷转本文的家伙生儿子没屁眼
因此,PSDG之所以能让主机进入F/S 模式,有很大的可能是已经取得那个关键金
钥了。
偷转本文的家伙生儿子没屁眼
那个金钥平时是以加密的形式存在主机里面,只有当有 JIG元件连接并要求认证
时,才会暂时解密(因为要用来加密乱数跟USB ID,所以不解密还原不行),然
後存在主机记忆体的某个地方。
偷转本文的家伙生儿子没屁眼
zAxis@psx-scene提出的方法是这样的:首先将PSGrade 的程式码编译成
.hex(目前只有支援atmega32u4)後放到JB工具上,然後按照普通的JB流程操作
。JB开始後PSGrade 的程式会假冒成 JIG然後向主机提出认证要求,提出後主机
当然就把金钥解密,然後加密某个乱数传给PSGrade ,然而PSGrade 会尝试用
key.h 里的金钥解密後回传,但目前那个金钥还是错的。
主机因为没收到正确地乱数值,所以不会进去F/S 模式,接着在不重新开机的情
况下利用OtherOS 执行Linux ,以免金钥被重开机的过程洗去。
最後利用外部电路读出整个记忆体的内容,然後开始人肉搜索(256 MB而已)。
金钥长度有160 个 bit。
偷转本文的家伙生儿子没屁眼
或许有人会问说$QNY怎麽不让金钥用过即丢,反而还存在记忆体里面等着给人搜
索,这不能怪$QNY,因为绝大部分的程式语言如 C语言,里面把东西删掉只是把
该记忆位址标注释放而已,没有其他资料盖过去的话原本的内容不会被改写。
******
唉唉,写这麽多, 426大概又要偷偷转载了。..╮(﹋﹏﹌)╭..
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 59.126.61.141
1F:推 hipposman:长知识推… 11/22 23:47
2F:推 kid566:可以在重点的句子用注音文... XD 11/23 00:05
3F:推 givemeback:楼上Good Idea! XDD 11/23 00:27
4F:→ hpo14:记得用火星文编码器 XD 11/23 00:46
5F:→ SGBA:痾? 大陆人会过来看 还是什麽意思? 11/23 01:29
6F:→ hpo14:意思是有人无断转载不附出处,也拿掉作者 11/23 01:56
7F:推 richjf:转成图片档...加浮水印. 11/23 02:09
8F:推 Yaoxi:受教了...大概知道怎样的原因了 11/23 02:14