dump rootkey without linux thanks to naehrwert

Moderator: Rogero

dump rootkey without linux thanks to naehrwert

Postby aKoN » Mon Jul 23, 2012 2:28 am

UPDATE:
PSDev wrote:This is defiantly worth adding to main thread, no other site mention what I state below, so everyone tried the 3.41 .PKG on there 3.55

naehrwert pre-compiled the asbestos ldr for 3.41, not 3.55, so it won't work. But you cannot just convert the elf and sign for 3.55 (usually can but not here.) you have to change the source. I started to do it and only one offset to be changed it left. LV2 Syscall table = 0x8000000000346570ULL (3.55 CEX), LV2 MEMCPY = 0x800000000007C3A4ULL there's a start :)


-PSDev


Now you can dump rootkey without Linux, @willemse21 brought this news to the board. Nice to see more progress being made on this topic. Needless to say use it at your own RISK. Don’t ask about a n00b tutorial, as far as i know nobody is doing it, hence we are in *testing* stances. When something *foolproof* and noob friendly arises you will see it posted.

dump_rootkey – 2012 by naehrwert

=== How-to ===
[1] Install asbestos_ldr.g.pkg on your PS3 (a firmware with lv2 peek/poke is
required to run it).
[2] Compile the client (make sure PS3HOST in main.cpp points to your PS3).
[3] Make sure you got your metldr in ‘./data’ as ‘metldr’.
[4] A prebuilt ‘dumper’ is included in ‘./data’ (dumper.elf and build.bat is
included too if you want to change parameters).
[5] Start asbestos_ldr on your PS3.
[6] Start the client on your PC.
[7] Unicorns!

=== Asbestos License ===
Copyright (C) 2010-2011 Hector Martin “marcan” SPU mailbox threshold interrupt
[INFO] Interrupt status (2, application) = 0000000000000011
[INFO] -> SPU mailbox threshold interrupt
[INFO] -> mailbox interrupt
[INFO] Mailbox value = 1
[INFO] -> Dumper loaded.
[INFO] Transferring eid_root_key to buffer…finished.
[INFO] Dumping eid_root_key…done.
[INFO] SPU status = 0×00000081
[INFO] Destructing spe…done.
[INFO] Press any key to exit…

Download Link http://www.sendspace.com/file/dxdmat

Pastie: http://pastie.org/4301209


To quote:

Something interesting that wrote @JonahUK:

You will still need to do some manual editing for the conversion but this is still great news.

@PsDev response:

Nope, once root key is dumped you’re good, just run flash and root key my/gunner tool (Depending on flash) and then validation will be done, just re-flash to you’re now DEX flash and it will still boot into gameOS just now update to 4.11 DEX FW or any DEX FW





Twitter: naehrwert

Source: ps3hax.net
Random avatar
aKoN
Member
Member
 
Posts: 14
Joined: Tue Jul 10, 2012 7:53 pm
Has thanked: 0 time
Been thanked: 0 time
Reputation point: 15
Novice

Re: dump rootkey without linux thanks to naehrwert

Postby PSDev » Fri Jul 27, 2012 2:07 am

This is defiantly worth adding to main thread, no other site mention what I state below, so everyone tried the 3.41 .PKG on there 3.55

naehrwert pre-compiled the asbestos ldr for 3.41, not 3.55, so it won't work. But you cannot just convert the elf and sign for 3.55 (usually can but not here.) you have to change the source. I started to do it and only one offset to be changed it left. LV2 Syscall table = 0x8000000000346570ULL (3.55 CEX), LV2 MEMCPY = 0x800000000007C3A4ULL there's a start :)


-PSDev
User avatar
PSDev
Developer
 
Posts: 5
Joined: Sat Jul 14, 2012 1:46 am
Has thanked: 0 time
Been thanked: 4 times
Reputation point: 25
Novice


Return to PS3 Software Hacks

Who is online

Users browsing this forum: Bing [Bot] and 1 guest