[Fake or Not?] Cex2Dex leaked. [Rumor]

Moderator: Rogero

[Fake or Not?] Cex2Dex leaked. [Rumor]

Postby BobbyBlunt » Mon Jul 09, 2012 5:24 am

I have marked this as rumor because I personally can't vouch for the validity of it but here is the article from ps3hax. PS3News was the original source

Thanks to @zecoxao we have this tutorial to convert CEX to DEX. USE IT AT YOUR OWN RISK.
Here you are not messing with a SAVE from some game, your going deeper into the rabbit hole. SO BE CAREFUL

—————————————————————————————————————————————————

From PS3 News, comes the latest information that the method to convert your Retail PS3 to Debug has been officially leaked.

Here is a the quote from the original post (watchout folks, ****’s about to hit the fan):

Hi Scene Sorry for my bad English. I want to give you info you pls make public. I want be anonymous. I only can say Im from Hong Kong. I have way to get a dex, it works and is complete nothing missing

Manual to get a dex (here is everything you needed) and you have a full working dex

EID0 Key Seed and EID0 Section Key Seed are hardcoded in the isoldr

EID0 Key Seed
AB CA AD 17 71 EF AB FC 2B 92 12 76 FA C2 13 0C
37 A6 BE 3F EF 82 C7 9F 3B A5 73 3F C3 5A 69 0B
08 B3 58 F9 70 FA 16 A3 D2 FF E2 29 9E 84 1E E4
D3 DB 0E 0C 9B AE B5 1B C7 DF F1 04 67 47 2F 85

EID0 Section Key Seed
2E D7 CE 8D 1D 55 45 45 85 BF 6A 32 81 CD 03 AF

If you dump they isoldr key (EID Root Key) with metldrpwn you got from 0×00 to 0x1F the EID Root Key and from 0×20 to 0x2F the EID Root IV

use AES Encrypt to Encrypt EID0 Key Seed as data with EID Root Key as Key and EID Root IV as IV

the result contains from 0×10 to 0×20 the EID0IV

and contains from 0×20 to 0×40 the EID0Key

use AES Encrypt to Encrypt the EID0 Section Key Seed as data with the EID0Key as Key and no IV

the result will be the first 0×10 bytes of the EID0 First Section Key

the second 0×10 bytes of the EID0 First Section Key are only 0×00 bytes

EID0 is located in NAND at 0×80870 and in NOR at 0x2f070

the first 0×20 bytes of EID0 are not encrypted

at the fifth byte of EID0 (NOR example 0x2f075) your target ID is located change it to 0×82 (Debug Target ID)

use AES Decrypt to decrypt the first EID0 Section (NOR example 0x2f090). The size of the first Section is 0xC0 bytes. Use the EID0 First Section Key as Key and the EID0 IV as IV

Build the CMAC (OMAC1) hash of the decrypted EID0 Section from 0×00 to 0xA8 with EID0 First Section Key as Key. The calculated hash has to be the same as the bytes in the decrypted EID0 Section from 0xA8 to 0xB8.

At 0×5 of the decrypted EID0 Section is your target id again change it to 0×82 again

0xB8-0xC0 of the decrypted EID0 Section should be just 0×00 bytes

after you changed the target ID of the decrypted EID0 Section, create the CMAC hash of the new decrypted EID0 Section and write the new hash to the decrypted EID0 Section

use AES Encrypt to encrypt the EID0 Section and write it back to the NOR (NAND).

Now install dex Firmware with the recovery menu.

HINT: Got Petitboot on emer init go to boot gameos and do emer init again to get to the recovery menu.

You cant login to the PSN because IDPS is obviously not valid from now on.

THIS CAN BRICK YOUR CONSOLE IF NOT DONE CORRECTLY.

有志者,事竟成 Where a will, there is way
一不做二不休 You start something, you have to finish it
User avatar
BobbyBlunt
Moderator
Moderator
 
Posts: 112
Joined: Fri Apr 06, 2012 3:17 am
Has thanked: 26 times
Been thanked: 39 times
Reputation point: 25
Novice

Re: [Rumor] Cex2Dex leaked. [Rumor]

Postby windrider » Mon Jul 09, 2012 6:37 am

A little more on it


You can use flasher, linux or jaicrab's preloader (basically anything that flashes the dump)

Jaicrab's Preloader only works correctly on NOR's, you'll have problems with NAND's, or so I've tested (thanks to a friend of mine ) in case you need to compare:

https://dl.dropbox.com/u/35197530/flashCEX.7z
https://dl.dropbox.com/u/35197530/flashDEX.7z
https://dl.dropbox.com/u/35197530/eid_root_key.bin

PS: If I'm not dead by the next 24 hours, you know where to find me

Source - http://www.ps3news.com/forums/ps3-hacks ... 23592.html

Note: Don't flash this, this belongs to my console, so I advise you not to flash, this is just for verifying only.

From Squarepusher2: You'll have to go digging for debug eboots though if you intend on playing anything that is not a retail game on your debug PS3. And those are not easily found. I don't think end-users will get much use out of it - for devs it's a totally different story though.

Finally, it also appears as though the newer PS3 SDKs will contain the necessary development tools and login information to access Sony's developer network (NP / SP-INT) as well:

The NP communication passphrase and signature will be provided within the Server Management Tools.

Details: NP communication ID, passphrase, and signature, required for certain PSN communication services, had been provided on the DevNet thread upon the completion of the requested PlayStation Network service configurations.

From 2012/07/05 the NP Communication Passphrase and Signature will be provided within the Server Management Tools.

This change affects all the communication IDs issued after 2012/07/05. It will not be possible to access the NP communication passphrase or signature in the support issued after that date.

Only those users who have initially requested the NP communication services and was provided the files on DevNet thread will have access to the file on the request threads.

Note that the NP communication passphrase and signature are required with NP Matching 2 and Title Small Storage.
If we all are here to help others , then what exactly are others here for?

Image

Forum rules - http://www.tortuga-cove.com/forums/view ... p?f=19&t=5
User avatar
windrider
Moderator
Moderator
 
Posts: 2575
Joined: Mon Jul 18, 2011 12:11 am
Location: Alberta
Has thanked: 794 times
Been thanked: 462 times
Reputation point: 494
NoviceNoviceNoviceNoviceNovice

Re: [Rumor] Cex2Dex leaked. [Rumor]

Postby BobbyBlunt » Mon Jul 09, 2012 6:39 am

Thanks windrider for adding to it. I just pulled the article from ps3hax since I havent seen it here yet, and you added quite a bit to it. :)
User avatar
BobbyBlunt
Moderator
Moderator
 
Posts: 112
Joined: Fri Apr 06, 2012 3:17 am
Has thanked: 26 times
Been thanked: 39 times
Reputation point: 25
Novice

Re: [Rumor] Cex2Dex leaked. [Rumor]

Postby condorstrike » Mon Jul 09, 2012 2:15 pm

This is Deja-vu... I've seen this before, there must be a glitch in the Matrix. ;P
CAW!
User avatar
condorstrike
Site Admin
Site Admin
 
Posts: 463
Joined: Thu Jun 30, 2011 10:53 am
Has thanked: 18 times
Been thanked: 27 times
Reputation point: 175
NoviceNovice

Re: [Rumor] Cex2Dex leaked. [Rumor]

Postby S4BRE » Mon Jul 09, 2012 6:41 pm

its been proven fake. There's a surprise LOL
 ! S4BRE wrote:
For now we will say we still don't know.
Image
Tortuga Cove Administrator
User avatar
S4BRE
Site Admin
Site Admin
 
Posts: 1297
Joined: Thu Jun 30, 2011 8:27 am
Has thanked: 63 times
Been thanked: 87 times
Reputation point: 179
NoviceNovice

Re: [Fake] Cex2Dex leaked. [Rumor]

Postby pbanj » Tue Jul 10, 2012 5:06 am

who proved it's fake?

tbh i dont give a shit ether way, but if its real then let it out. i just know a lot of people dont want this shit out
User avatar
pbanj
Site Admin
Site Admin
 
Posts: 130
Joined: Fri Jan 06, 2012 7:51 am
Location: your cupboard
Has thanked: 3 times
Been thanked: 6 times
Reputation point: 26
Novice

Re: [Rumor] Cex2Dex leaked. [Rumor]

Postby BobbyBlunt » Tue Jul 10, 2012 5:37 am

S4BRE wrote:its been proven fake. There's a surprise LOL


I have missed where it was proven fake besides the people that didnt want it released. Care to share how you know it is fake?
User avatar
BobbyBlunt
Moderator
Moderator
 
Posts: 112
Joined: Fri Apr 06, 2012 3:17 am
Has thanked: 26 times
Been thanked: 39 times
Reputation point: 25
Novice

Re: [Fake] Cex2Dex leaked. [Rumor]

Postby windrider » Tue Jul 10, 2012 6:18 am

I have missed it as well. :?

Out with it S4BRE ;)
If we all are here to help others , then what exactly are others here for?

Image

Forum rules - http://www.tortuga-cove.com/forums/view ... p?f=19&t=5
User avatar
windrider
Moderator
Moderator
 
Posts: 2575
Joined: Mon Jul 18, 2011 12:11 am
Location: Alberta
Has thanked: 794 times
Been thanked: 462 times
Reputation point: 494
NoviceNoviceNoviceNoviceNovice

Re: [Fake] Cex2Dex leaked. [Rumor]

Postby S4BRE » Tue Jul 10, 2012 12:30 pm

well from what i was reading in other channels, everyone was screaming fake. If I am wrong no problem. :P
Image
Tortuga Cove Administrator
User avatar
S4BRE
Site Admin
Site Admin
 
Posts: 1297
Joined: Thu Jun 30, 2011 8:27 am
Has thanked: 63 times
Been thanked: 87 times
Reputation point: 179
NoviceNovice

Re: [Fake] Cex2Dex leaked. [Rumor]

Postby BobbyBlunt » Wed Jul 11, 2012 6:42 am

S4BRE wrote:well from what i was reading in other channels, everyone was screaming fake. If I am wrong no problem. :P


The people yelling fake are the ones that never wanted it leaked to begin with (I will not say any names)
I also spoke to a dev over this matter and he never denied it being real, and he actually sounded pissed it was leaked. Now if it were fake, and me knowing some of these guys as well as I do, they would have tried to play it off, but instead they all rage.

Like I said I have not tried it because a CEX machine is good enough for me, but there is a lot of fuss being made over something that is "fake."

PS3 scene is and will always be that way. Some make their own progress, while they could care less about others.

S4BRE I mean no disrespect, but "you heard it on other IRC channels?" You and I both that 90% of the internet is bullshit. I would like to throw a few crooked ass names out there that have known how to do this conversion for a long time, but I am not going to. Some of these people are probably the ones yelling fake to draw the attention away.

Another point..... zecoxao deserves no credit at all. He posted it on hax, he didnt leak it. He was never even worthy of possessing a DEX machine to start with (IMHO).

I will go as far as saying "what seems to good to be true, usually is" but I also know how the PS3 community is. I know how some of these devs are as well. I wouldn't use the word fake again until the people with either OtherOS and/or flashers get to tinkering with this idea this weekend. If we hear about a bunch of bricks then we knew it was fake, but if for the off chance we hear of successful conversions then those that labeled it as fake may have jumped the gun. I have yet to see anyone yell fake outside of that small group of shady PS3 devs. Remember that some ps3devs gave out RSX SDK samples in the past and called it an RSX driver to get donations. I dont think I have to say a name but this is also one of the people that yelled fake within 3 minutes of the news making itself around the internet ;)
User avatar
BobbyBlunt
Moderator
Moderator
 
Posts: 112
Joined: Fri Apr 06, 2012 3:17 am
Has thanked: 26 times
Been thanked: 39 times
Reputation point: 25
Novice

Next

Return to PS3 Software Hacks

Who is online

Users browsing this forum: No registered users and 0 guests