作者cassine (Savannah)
看板Modchip
标题Re: [PS3 ] 二代电子狗
时间Mon Oct 24 10:39:46 2011
http://goo.gl/q5jaE
昨晚的新消息
UPDATE #3:
More updates from the last several hours as more people seem to be
getting their hands on the device.
几个小时前的最新消息,看来有越来越多人拿到了这东西呢!
First off for those interested, the MFW and JB2 dongle updater files
have been leaked on to the web, you can grab the downloads below:
在好奇之余,有些东西已经流出来了,就是传说中的电子狗更新档以及跟狗搭配
的自制韧体,有兴趣的人可以自己下载来研究。
[Download Jailbreak 2 CFW/MFW files]
http://www.multiupload.com/9YPQX47G7F
[Download Jailbreak 2 Dongle Updater]
http://www.multiupload.com/9YPQX47G7F
Second off the Jailbreak 2 is being reversed engineered, for those
interested you can read the full documentation via PS3DevWiki.
再来呢,就是这个二代电子狗的逆向工程已经开工了,有兴趣的人可以前往
PS3DevWiki网站。〔译注:该网站内容相当专业,新手读起来可能像是天书〕
So I believe its safe to say this device is probably real, and now we
should focus on how it actually works.
因此呢,我认为可以合理认定这东西能够动作,不是芭乐,接下来我们来看看这
东西是怎麽操作的。
In summary it seems that JB2 is nothing special at all. What they
seem to be doing is using something called a DEBUG EBOOT which is
burned onto a disc, and is playable on the PS3. So all we technically
need is the debug eboot's for each game which can be acquired via
dev network (and people can get this via debug PS3's). So until
Sony takes a stand against these debug eboots, the scene may have
found their access to newer games.
大致上看来,这东西的原理并不令人惊讶。它只是单纯让主机执行 Debug版的主
程式而已,把从开发者网路下载下来的 Debug版主程式盖过原版光碟里头的主程
式,再把光碟内容烧进烧录片里头就结束了。因此,技术上我们需要想执行游戏
的 Debug版主程式(有些人有管道可以拿到),所以,除非SONY对这些 Debug版
的主程式进行反制,不然社群这边一路都能够玩到最新的作品。
Mathieulh 对这东西做出评论了:
<Mathieulh> I kinda figured how it works already
我想我大概了了
<Mathieulh> they patched lv1 and lv2
他们 patch了 lv1与 lv2的程式
<Mathieulh> and they have lv2 to check if the self keyset is 0x10 or
higher
他们让 lv2检查self档案的金钥注记值是否大於0x10
<Mathieulh> if so it's sent to lv1 through a separate hypercall than
hvsc99
如果是的话〔代表游戏需求版本大於3.56〕,那就把档案利用一个
新的syscall 而非利用原本的syscall99 进行解密
<Mathieulh> which sends the self or part of it to the usb hw
他们很可能透过电子狗上的硬体电路去实做这个新的 syscall,
<Mathieulh> which performs some crypto
所以主机会把整个self程式或程式的是一部分送去解密
<Mathieulh> and returns a decrypted result to lv1
硬体电路解密完後,把解密的主程式回传给 lv1
<Mathieulh> at least that's what I got out of a few minutes of
debugging
这就是我花几分钟研究跟除错得到的结果
<Mathieulh> I am pretty sure the keys are on the dongle
我相信解密的金钥应该是藏在电子狗里头没错
<Hewman> as in debug eboots?
那 Debug版的主程式?
<Mathieulh> 3.60+ app keys
也有3.60+的app 金钥。
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.120.31.137
1F:→ strike519:gogogogo 10/24 10:45
2F:推 f1234518456:希望可以免狗跑NP-DRM 10/24 11:29
3F:→ cassine:NP-DRM目前得靠电脑程式协助解密 10/24 11:53
4F:→ fly9588:越来越透明了YO 10/24 12:07
5F:推 oread168:SONY表示:下次更新......(ry 因为我还没赚够 10/24 12:30
6F:推 belion:花几分钟的研究..这太强了@@ 10/24 17:29
7F:→ cassine:几分钟我觉得是Mathieulh这家伙在嘴炮啦,但有研究是真的 10/24 17:41
8F:推 chiyosuke:继续期待。 10/24 19:31