Condorstrike • Pointman: The Akkadian Wars
HI GUYS, IT’S BEEN HARD FINDING TIME FOR THE PS3 WITH SO MUCH GOING ON AT WORK AND HOME, THAT’S THE REASON I DECIDED TO RELEASE THE POINTMAN BETA AS A (POC). WISH I HAD MORE TIME TO COMPLETE IT ...
A Word From Rogero
Attention Please: some of you already know that a version of my CFW4.41 was leaked on IRC by accident from some days, that was not a big deal and it was not out yet because I wanted some ...
PS3 Homebrew List • PSChannel v1.10 Released
deroad has released PSChannel v1.10. Fixed tons of bugs Removed the “install theme feature” since no one makes themes for my homebrew Info section moved to main menu and can be seen by ...
Xbox/X360 Hardware Hacks • Offical Review of Talismoon Wolf Controller 'Macros Mod Board' for 360
Today I am reviewing Talismoons Wolf Controller 'Macros Mod Board' that also functions as a rapid fire mod. Wolf Controller Site (Please note: neither I nor any other staff support or condone ...
PS3 Software Hacks • TEAM SGK CFW 4.40.5.2 RELEASED with 100% fixes for NOR PS3s
We were alerted today of a new cfw from Team SGK here as follows are the details. translated through google: hi to all sorry for the problem of the cfw 4.40.5 and v5.1 on slim I raporte ...
PS3 Hardware hacks • Cobra ODE Hardware - Main Board pictures
Hello! We're pleased to present pictures of the final Cobra ODE hardware - Main PCB assembly. As you can see there are two switches which enable configuration of PATA (FAT consoles)/SATA (FAT ...
Rogero CEX-4.40 v1.03 with ToolBox/StealthMAN and ReactPSN offline Patch
Rebuilt the CFW with minimal patches needed for similar OFW Stability, also adding full compatibility with multiMAN Tools. All known issues from v1.02 are fixed now ...
Rogero Downgrader PUP for any CFW version back to 3.55
This CFW can be installed fine from XMB Update over any CFW version ( 3.55 --> 9.99 )RSOD screen bypass patch for RSOD machines (it won't fix the RSOD but allows the PS3 to boot fine into ...
PS3 Nor and Nand Auto Patcher v0.04 by Rogero
Wow Rogero comes out swinging from semi holiday, blasting out with a new release this is an improvement to his Ps3 and Nor Patcher....  
Rogero CEX-4.40 v1.02
Those of you needing your Rogero fix, wait no longer have to wait.... Tortuga Cove member Rogero has released an update to his awesome firmware. Bringing it up to 4.40. Make you pop over on the ...

Breadcrumbs

Latest Post

Main

We have 74 guests and 0 members online

Forums

We have 22 guests and 2 members online

Tortuga Cove - Your Source For Gaming and Hacking News

FeaturedMost Hit User Rating:  / 0
PoorBest 

image

When metldr is encrypted at factory, a special keyset is set in the binary before encryption. Later when an isolated loader is loaded by metldr, it will copy the keyset to LS offset 0×00000. It consists of eid_root_key and eid_root_iv. To not having to use the same key for all eEID parts, several subkeys are generated from special data called individual information seed. These seeds are stored in the metadata header of isolated modules loaded by isoldr.

 

When isoldr will load a module, it will call a subroutine that encrypts each seed chunk (0×40 bytes) using eid_root_key and eid_root_iv. Then the so-called individual infos are passed in registers r7 to r22 (= 0×100 bytes in total) to the loaded module where they are used further. Usually isolated modules have a seed section of 0×100 bytes but all of them (except sb_iso_spu_module) have all zeroes but the first 0×40 bytes chunk. You can, for example, find the recently published EID0 seed in the metadata section of aim_spu_module. Appliance info manager is used to get e.g. the target ID or the PSID from EID0. This explains why the seed can also be found in isoldr directly, since that one is checking EID0 too.

 

As you can probably think, a fair amount of reversing time and knowledge has gone into finding this, so stop calling us *swearwords* for not releasing information that could potentially lead to more piracy, because we think that this would do more harm to the scene than just keeping some information in private (for now). Also I can only encourage everyone that thinks about us this way or is greedy demanding for developers/reverse engineers to release their stuff, to fire up isoldr in IDA or disassemble it with objdump and try to reverse all this from start to end. Well see, who is able to pull this through on his own.

 

Thnaks aKoN for the news.

 

Source: wwww.ps3hax.net

 

Copyright © 2013. Tortuga Cove. Designed by Shape5.com Joomla Templates