MyQJ | QJ.NET | Apple | Mobile | Science | MMORPG | Nintendo DS | Wii | World of Warcraft | PlayStation 3 | PSP | XBOX 360 | Gadgets | PC Gaming | Age of Conan | DL.QJ | QJ.NET Forums
Home :: XML Feed :: Files :: Forums :: Bookmark site :: Terms of use :: Privacy policy :: Submit News :: Advertise :: Contact us


Go Back   QJ.NET Forums > All QJ Forums > Gaming Forums > QJ.NET Sony PSP Forums > PSP Development, Hacks, and Homebrew > PSP Development Forum
Register FAQ+ Become Premium Members List Mark Forums Read Log Out

Reply
 
Thread Tools
Hey Guest!
Not Registered? Join today!

Registration allows you too:

Post on our Forums.

Take part in games and registered user benefits!

Get rid of this ad....
Old 11-21-2006, 10:43 AM   #1
jas0nuk
Developer


Join Date: Dec 2005
Location: Manchester, UK
Posts: 570
Exclamation [Release] psardumper mod to extract 3.00 (NOT decrypt)

Extract 3.00 (encrypted only, need new keys)
Press CIRCLE, the other options don't work. If you try SQUARE ("decrypt all") it extracts the data files which aren't encryped and skips the PRXs

3.00 DATA.PSAR goes into root of memory stick, use PBP Extractor to get it.
(Can read PSAR files up to 18mb [3.00 PSAR is 16.7mb])

Cheers to Dark_AleX for psardumpermod, and zshadow for the buffer fix

Stuff to note about the firmware:
- No more ./vsh/resource/1.bmp, 2.bmp, 3.bmp (etc.)
Instead, there's now just a 1-12.bmp which is grey. The firmware probably applies a colour overlay onto this.
- audiocodec_260.prx and mpegbase_260.prx
Audio/video codecs from 2.60..?
- Just 1 certificate in "./data/cert" folder

Discuss anything else you find.
Attached Files
File Type: rar psardump_300.rar (62.4 KB, 184 views)
__________________
// jas0nuk
// LAN.ST admin
jas0nuk no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:45 AM   #2
_twopoint
Banned


Join Date: Apr 2007
Posts: 3,651
Default

Can we use this to get an hybrid 3.0 devhook?
_twopoint no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:48 AM   #3
jas0nuk
Developer


Join Date: Dec 2005
Location: Manchester, UK
Posts: 570
Default

Nah, for that we need the decryption keys, which aren't available just yet.
__________________
// jas0nuk
// LAN.ST admin
jas0nuk no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:51 AM   #4
_twopoint
Banned


Join Date: Apr 2007
Posts: 3,651
Default

OOO.

So this is just proof that 3.0 can be cracked?
_twopoint no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:52 AM   #5
Skyline34
Sage
 
Skyline34's Avatar


Join Date: Mar 2006
Location: UK
Posts: 3,468
   
Default

sorry for being so noobish but how were we able to obtain the decryption keys for 2.0-2.71?
Skyline34 no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:54 AM   #6
AndyMosh
Pwn3r Lu1z
 


Join Date: Sep 2006
Location: England
Posts: 2,569
Default

Skyline34 they have there little elf's working for them putting any encryption key they can think into a secret program... do you believe me? If not, you should! If you do join me in my evil empire!

So this can dump the 3.00 firmware so we can analyse it?
AndyMosh no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:58 AM   #7
jas0nuk
Developer


Join Date: Dec 2005
Location: Manchester, UK
Posts: 570
Default

Quote:
Originally Posted by GLITCH410
So this is just proof that 3.0 can be cracked?
Well, at least they didn't change the PSAR revision, so all we need is the and then it can be fully extracted/disassembled and potentially emulated.

Quote:
Originally Posted by Skyline34
sorry for being so noobish but how were we able to obtain the decryption keys for 2.0-2.71?
I think they were obtained from a kernel RAM dump.

Quote:
Originally Posted by AndyMosh
So this can dump the 3.00 firmware so we can analyse it?
Well, for now we can analyse the layout until we have the keys. And this is proof that it can be extracted.
__________________
// jas0nuk
// LAN.ST admin
jas0nuk no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 10:58 AM   #8
pJ14
Journeyman


Join Date: Jun 2005
Location: Netherlands
Posts: 206
Default

Yes,

usbcam.prx is new and usbgps.prx is there again
pJ14 no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 11:05 AM   #9
tommydanger
Developer
 
tommydanger's Avatar


Join Date: Mar 2006
Posts: 158
Default

or if you want to do it yourself increase the buffer to this:
Quote:
u8 g_dataPSAR[17000000] __attribute__((aligned(64 )));
it dumps all files-prx-some files
It's like we're knocking on the door
tommydanger no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Old 11-21-2006, 01:37 PM   #10
minus5252
Neophyte


Join Date: Jan 2006
Posts: 18
Default Probably a worthless post, but..

So there are so many guys out there who really know what they are doing, and I am facinated by this. I would love to help, but I also would just like to learn how anyone is able to even *begin* to make headway on this. To find the key for stuff like this seems like it would take FOREVER, but what can we do to help, and is there somewhere I could look to learn more about this(i.e. the process' people used to decrypt the previous firmwares, etc.). Anyway, I continue to be astounded by the things you guys are able to accomplish out there. I hope you're all making big bucks in your real jobs.

Minus
__________________
Minus
minus5252 no ha iniciado sesión   Quote this post in a PM   Reply With Quote Text-Multi-Quote with this Post
Reply


Thread Tools

Posting Rules

Smilies are On
[IMG] code is On
HTML code is Off

Points Per Thread View:
Points Per Thread:
Points Per Reply: