So... today i start hacking the 2.0 firmware....

Discuss the development of new homebrew software, tools and libraries.

Moderators: cheriff, TyRaNiD

Locked
EMO NEGRO
Posts: 6
Joined: Thu Aug 25, 2005 2:07 am
Location: Riverside, CA

So... today i start hacking the 2.0 firmware....

Post by EMO NEGRO »

tools i will be using.

MS notepad, ctrl+c, ctrl+v, the delete button on my keyboard, a gamestop warranty (i can brick as many psp's as i want), v1.0 firmware in pbp, v. 1.50 firmware in pbp, and v2.0 USA firmware in pbp...


what i plan on doing.

i have 3 methods.

using notepad, i plan on finding out where the firmwares are different. yess it will be painstakingly long, because it'l look worse than the matrix, but that's a task im willing to take.

i plan on either
A) creating a "HACKED" downgrade capable 1.0
B) a "Hacked downgrade to 1.5"
C) an exploitable 2.0
D) a 1.50 with 2.0 features, and identifies itself as 2.0
E) CREATING MY OWN FIRMWARE a "frankenstein firmware with MAC OSX TYPE GUI"

tools i may end up using.
"pbp unpacker"
im setting a realistic goal of having something working by december 31st.
and so far, by crudely cutting and pasting things in wordpad, i have gotten my psp to recognise the update on the memstick, but it wont run because of an error.
maybe if i figure out how to digitally sign it... who knows.

but within the big garble that notepad gives me, im not able to figure out what part is signed.

maybe if i had a jatag, i could just wipe the whole firmware, and write my own drivers and everything, but then it would be useless because it wouldnt run umd's any more...


wish me luck.
is there anything else to help me.
Yours truly,
EMO NEGRO.
AnonymousTipster
Posts: 197
Joined: Fri Jul 01, 2005 2:50 am

Post by AnonymousTipster »

Erm....well...good luck. At least you seem confident.
This is just me talking, but I would use a hex editor, rather than notepad. Then again, I'm not trying to hack 2.0.
PspPet
Posts: 210
Joined: Wed Mar 30, 2005 2:13 am
Contact:

Post by PspPet »

This is not the place to talk about "exploits". I suspect this thread will be locked/deleted soon.
> using notepad, i plan on finding out where the firmwares are different. yess it will be painstakingly long
You can say that again. A very long time...
-----
For anyone with who wants to seriously attempt such a thing, at least start with "PSAR Dumper" and the PRX decrypter sample in the PSPSDK
http://forums.ps2dev.org/viewtopic.php?t=2883
Even with that leg-up, there are incredible hurdles to get over due to the encrypted/signed executables.
BTW: The 2.0 English update content is exactly the same as the 2.0 Japanese update - not surprising.

My advice - spend your time doing something more productive - like learning/using the PSPSDK and writing useful Homebrew PSP apps.
EMO NEGRO
Posts: 6
Joined: Thu Aug 25, 2005 2:07 am
Location: Riverside, CA

Post by EMO NEGRO »

i think i've got it!!!!!!
someone's prolly already tried it...
but what about unpacking a 1.50 pbp
and a 2.00 pbp
and swapping the data.psar

that's where the bulk of the update is, and i bet there are security files to be deleted there.

we just have to figure out where.


il keep you posted....

*open's word pad*
Yours truly,
EMO NEGRO.
EMO NEGRO
Posts: 6
Joined: Thu Aug 25, 2005 2:07 am
Location: Riverside, CA

Post by EMO NEGRO »

sorry, but where can i talk about exploits?
and could someone please move this thread there?


im going to compare the psar's and see if i can modify the 2.0's to be able to run unsigned code like the 1.0 can.


wish me luck.
Yours truly,
EMO NEGRO.
EMO NEGRO
Posts: 6
Joined: Thu Aug 25, 2005 2:07 am
Location: Riverside, CA

Post by EMO NEGRO »

i need something to allow me to view .psar

sort of like the pbp dump prog lets people view .sfo's
are there any ready made programs?
or is it back to good ole word pad?

also, does anyone have a link to the 1.50 JP firmware update?
Yours truly,
EMO NEGRO.
_Psycho
Posts: 28
Joined: Thu Apr 14, 2005 3:02 am
Location: Montréal, Canada

Post by _Psycho »

Sorry to disapoint you, but that's won't work, everything is encrypted and signed. mean if you change the data, that won't match, etc. I doubt you will ever get any update running that way.
EMO NEGRO
Posts: 6
Joined: Thu Aug 25, 2005 2:07 am
Location: Riverside, CA

Post by EMO NEGRO »

link me to a japaneese 1.50 update .pbp.

one of my methods is trying to get a 1.50 to identify itself as a 2.0.

once i do that, il see if i can get a flash 0 dump with certificates that i could possibly spoof.
Yours truly,
EMO NEGRO.
Krevnik
Posts: 71
Joined: Wed Mar 09, 2005 12:07 pm

Post by Krevnik »

Spoof certificates? :D

Lemme give you a piece of advice, take a class on crypto systems, then come back. Most of us gave up on researching it for two reasons:

1) Attacking the crypto system itself is pointless, the keys are either too large to crack (RSA/Certificates), and protect the real encryption scheme which currently is safe from brute-force as well. So bypassing the security is done instead (a la the current schemes).

2) There are better places to discuss cracking, and the mods here have just got fed up with people jumping in attempting to use this as a site for it. They would like to be able to stay close to the white side of homebrew as possible. Cracking discussions don't help that.
mrbrown
Site Admin
Posts: 1537
Joined: Sat Jan 17, 2004 11:24 am

Post by mrbrown »

Locked for obvious reasons. EMO NEGRO, this site doesn't discuss exploits or firmware cracking. If you somehow missed that in the site rules, consider this a fair warning.
User avatar
Agoln
Posts: 326
Joined: Wed Jun 08, 2005 3:14 am
Location: Fort Wayne, IN

Post by Agoln »

No discussing exploits on this forum. This is a development forum.

Locked for obvious reasons.
Lego of my Ago!
Locked