作者cassine (Savannah)
看板Modchip
标题[PS3 ] graf_chokolo: almost bring back OtherOS
时间Thu Feb 3 10:30:25 2011
http://xorloser.com/?p=297&cpage=22#comment-3270
graf_chokolo:
@ModIt
My approach will enable OtherOS to have the same access rigths as
GameOS, it means access to Dispatcher Manager, Update Manager, VFLASH,
HDD encryption/decryption, isolated SPUs and RSX of course.
GameOS is only good for games, for PS3 development and hacking is
Linux or FreeBSD with GameOS rights are a lot better. And i want a
clean approach for booting Linux, not like AsbestOS, it's not very
clean.
I have my loader for OtherOS bootloader ready now, will patch HV today
and try it out in the evening, after that will report back. Stay tuned.
GameOS在玩游戏上或许没什麽问题,但要破解主机或是开发程式的话,Linux 比
GameOS有用得多。
http://xorloser.com/?p=297&cpage=22#comment-3283
graf_chokolo:
I managed to boot an unencrpyted LV2 kernel from VFLASH. The decrypted
LV2 kernel from Service JIG just made some strange sounds for several
seconds and then did shutdown :-) Normal unencrypted LV2 kernels boot
normally.
We could kick out lv2ldr from HV completely and boot
enencrypted LV2 kernel always :-) Working now on Linux bootloader.
Stay tuned.
graf_chokolo成功用PS3 主机载入 Linux了,有了 Linux之後也就不用$QNY那限
制多多的lv2ldr。如果有NOR Flash 写入权限的话很可能可以改 MAC位址或是传
闻中的PSID来躲$QNY的水桶,虽然说 MAC位址跟PSID很可能都是烧死在 ROM里面
的。
以 MAC位址来说,有很多厂牌的网卡可以用工具程式修改,连螃蟹牌(realtek)
这种廉价卡都行。PSID这种东西因为不是标准规范,所以十之八九是读出来先存
在记忆体中然後才传到 PSN伺服器,因此找得到位址就有办法可以改。不过也要
注意,$QNY的维修手册里面有写到,一台主机的 MAC、PSID、BD光碟机序号等,
一定必须吻合资料库里面的档案,而且是唯一的一组,所以也许不是那麽容易。
http://xorloser.com/?p=297&cpage=22#comment-3289
Marcan:
graf_chokolo, I don't think you "get" AsbestOS. It's just a linux
bootloader, in fact it would work great as otheros.bld or any other
way of running it as an lv2 binary, and it's more robust than
petitboot (and smaller and easier to modify).
Marcan上来老王卖瓜了XD,之前graf_chokolo嫌弃说AsbestOS的开机方式太脏,
所以他自己弄了个乾净一点的petitboot ,但Marcan反驳说AsbestOS更好用,而
且档案大小比petitboot 更小。
OtherOS + extra rights isn't a replacement for AsbestOS, it's an
alternative to our original approach of replacing lv2 with AsbestOS.
There's already one released way to boot AsbestOS (USB exploit, which
isn't very clean/handy),
Hermes is working on a runtime lv2 bootstrap
for it (also not very clean but handy for people who like CFWs),
there's the lv2 replacement that we demoed but which isn't out yet (
which is clean, though can't dual-boot GameOS yet), and once you release
what you're working on you will be able to just boot AsbestOS with
it. Of course you could just run petitboot too, but where's the fun
in that? (we could've just used petitboot as a lv2 kernel for the
27c3 demo too, but AsbestOS is just much easier to make work and I
already have a working new boot ABI using the devtree to pass the
region1 allocation to Linux and patches that make it work regardless
of whether the bootmem split is 128/128 or 16/240).
This isn't a competition, I see no reason why AsbestOS can't work
great with whatever you're getting ready ;)
Btw, re: disk encryption, they use the same key and a NULL IV (can't
remember if all 00 or all ff) for every sector. It's a very
stupid/insecure block encryption scheme.
There are flags for the
sector read commands to toggle encryption on and off, that's what we
used to boot Linux off of a raw, totally DOS formatted disk with no
encryption or lv1 regions.
顺带一提,$QNY用了个非常蠢的方式来帮硬碟资料加密,全部都是同一个金钥而
且对应的IV也是空的,然後在每个磁区的开头都有某个旗标(flag)设定该磁区是
否被加密,所以我们才有办法在使用 DOS格式化过,而且完全没有加密的磁碟上
直接跑 Linux。
Also, we thought about booting an unencrypted lv2 kernel too (I assume
you're messing with default.spp?) but we were very short on time and
self was easier. Of course, you know a lot more about lv1 than we do ;)
当然我们也差不多快可以跑未加密的lv2 核心程式了,我猜你大概是漏了
default.spp ?总之我们时间也没多少,self对我们而言比较容易就是,当然说
到lv1 还是你最行。
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 122.117.54.160