0. Renommez le pkg avec l'idps à l'intérieur
1. Ressignez votre raps avec le nouvel idps
Faites votre propre PSUnban
A. Faites votre propre PSUnban stealh avec votre IDPS
B. Générez votre PSUnban stealh par un IDPS aléatoire
E. Générez aléatoirement un IDPS pour l' EBOOT.BIN (test rapide)
C. Credits
I. Instructions
X. Sortie
v1.12Corection bug that generated the EBOOT.BIN always the same 2nd part of the IDPS (bbbbbbbbbbbbbbbb)v1.11Updated from version 2.04 PARAM.SFO (more demand shift for the moment)v1.1Added missing ddl the package.Fixed bug with renamingCreate the pkg now stealth: the program is called VidZone and is in the TV menu on the XMB.v1.00Initial-release (beta)
Téléchargement PSUNBAN Tools v1.12 : http://www.mirrorcre...ntool.rar_linksHello every body!
This is me Abkarino (Console Admin from DVD4Arab forum), This is a quick and dirty release for 3K3Y Ripper application including the full recovered source code.
So you can build/modify your own version.
All you will need is:
.Net Runtime v4.0
Message for 3K3Y Team:
Do not stole glevand's work again
Also do not forget to protect you applications using a good .Net protector like .Net Reactor to prevent me or any body else from recovering your codes
Special Thanks To:
Glevand, Graf, Zadow28, Flatz, DVD4Arab Forum, PS3Hax Forum, PS3Crunsh Forum, And sure our lovely team 3K3Y for relesing this app
And any body else i may forget (Please forgive me)
Regards.
Abkarino (Mohammed Hassan)
Now the core... is an all-in-one, this cfw to start looking at the dev_usb000 if a and a file called cellftp.self and another called copy_script.txt, enable disable search whoever can do it simply by putting the original sys_init_osd.self 4.31 in dev_flash folder / sys / internal / here and no longer seek more...
Then developed a homebrew called core which makes everything a little, the self has to go along with pendrive root folder copy_script.txt and flags with flags (functions) as you want to within when starting the console will look and run, leave a log of what was done in the root called core.log are mention the most important and tomorrow I explain a little more.
BD emu flag is for if you have not and do not controller works if you activate this flag npdrm console will behave as if the reader enabled qa, enable you qa flag directly in 4.31:
nand dump
nor dump
lv2 dump
full ram dump
etc.
CoreOS lv1 hash downgradeadas deactivated for consoles
lv1 183/182 undocummented (LV1 peek / poke)
lv1 OtherOS++
VSH: nas_plugin (all pkgs installable game_ext explore_plugin and plugin to show install package and eliminate epilepsy warning message (though the latter with qa flag leaves only) and for patched vsh rif / rap fakesign) (This last with qa flag leaves only)
default.spp: added extra memory for otheros GameOS
lv2 peek / poke, syscall 6/7,
lv1 lv2 peek / poke (optional syscall 8/9 via core)
Hermes Payload with 36 ported sc
APPLDR: lv2 memory hashing disabled from appldr (no need to have it at lv1 parcheeis) dev_flash whitelist disabled (load any keyset from dev_flash) and ECDSA Off
ISOLDR: ECDSA Off
SPP_VERIFIER: ECDSA Off
spu_utoken_processor: ECDSA off (qa flag)
Core 2.6.5
2.6.5 changelog:
Added flag toggle_recovery MAKES A WIPE OF FAT darling!
Fixed 6 flags
Removed epilepsy warning
Core 2.6.0
2.6.0 changelog:
Added flag to clean debris from otheros's flag (used in cases of trouble entering recovery)
2.5.0 changelog:
Added otheros (minituto end)
dumpnandflash fixeado dumpea bootloader flag now also have a full backup of critical data from the console.
flags:
toggle_recovery = MAKES A WIPE OF FAT
clear_bootparam = clean debris flag's use of otheros
custom_boot_nor = boot at dev_usb consoles customboot.self from North
custom_boot_nand = boot at customboot.self from nand consoles dev_usb
boot_otheros = boot at otheros
install_otheros = dtbImage.ps3.bin installed in cell_os_ext_area
prepares setup_flash_for_otheros = nand / nor to be installed otheros
enterfactory = gets you into factory ...
load = payload from payloaderdev dev_usb000/payloads/431cex.bin
load = payload Payloader from core to use Multiman new
active = qa flags enableqa
removeqa = qa flags off
fullramdump = full ram dump
activated bdemu = bd emulator to use the console without controller
dumpdevflash = dumpea dev_flash partitions in the raw
dumplv2 = dumpea lv2
nordump = dumpea the NOR Flash
exitfactory leaves the factory mode =
dumpnandflash = nand flash dumpea fat consoles (including bootloader)
Spoiler
Tutorial OtherOS boot:
Start with only core setup_flash_for_otheros flag, to hear a double beep is that everything went well, if you do not hear looking log
Put this after the dtbImage.ps3.bin that corresponds to your console type dtbImage.ps3.bin.nand dtbImage.ps3.bin.nor is for nand and nor it is for renombrais to dtbImage.ps3.bin and you put it in root of pendrive as appropriate in your case and you put the flag install_otheros, same start and soon will hear 2 beeps sound if you look at the log to and that something is wrong
Once done turn off the console and put the flag boot_otheros, when you start your petitboot will see on the screen
Hermes thanks, I used your cosunpkg and cospkg for CoreOS and payload lined with SC36 and more...
Link all this: http://pastie.org/5913506 / mirror thanks to "Palestine" http://ul.to/0mp1pmbl
Function bd emu's I have also built in a 3.55 cfw I'm uploading it is always useful to dump your key root
Edit: Here is = hilo_cfw-3-55-otheros-cex-bdemu-no-controller-integrado_1862166 to make your cfw patcher Open delta, in original file to Appoint the OFW 4.31 here: PS3UPDAT.PUP
CFW 3.55 OtherOS++ CEX, BDemu Without Controller (Integrated)
Hi, as promised here's the integrated version for CEX BDEmulator that has all patches from glevand for OtherOS++ and has the sha1 hash check syscon disabled for consoles for downgrades.
With this CFW because anyone with broken controller (black screen or throwing npdrm update loop etc...) can use the console as controller, you can load is APP_HOME your games from, that's something I have the same function in the CFW 4.31 in this same subforum but got to 3.55 here too integrated for people to use and get their root key inter things... SS unpatched least trophies error
Download: v3modnobd.pup (170.5 MB) / v3modnobd.pup (Mirror) / http://pastie.org/5926345
In xdelta patch, the patch obviously apply and give the option to check and keep the original file checksum enabled, you will create another file called * NEW.pup being * the name that you do them to OFW, hashes the PUP should be good:
CRC32: 203E06EC
MD5: AD09B0CB3C09CFCCAB578E4E85969830
SHA-1: 7258E1BB84ED6E8AB0F6325A0199B65F82C7ADEF
Of course not bricked any console, hidden takes time and has been tested on all systems that can be installed
I give the core src polish it once, honestly I'm embarrassed both comment on the code you enjoy it, just as I will update the post in these 3 days with what I forget, that sure is a lot to this fw has had his job for.. Now comes Rogero and copy
Finally, some feedback on this PS3 4.31 CFW WIP from butnut: So I did a little testing... It installs fine on my slim 2101 and since I had left QA active the last time I was on 3.55 it is now automatically activated (still have to input button combo) The cold boot takes the same amount of time, only you don't see the epilepsy warning... It has normal install pkg files and app_home icons (just like Kmeaw 3.55)
Backup managers do not work yet because they do not have the new payloads implemented yet. I will go back to Rogero 2.04 for now. QA downgrade does not seem to work. Every firmware I try (CFW and OFW) the PS3 says it is corrupt. Luckily Rogero 4.25 to 3.55 DG pup still wo
- Added support for 4.31CFW
- Added support for creating ISO files from PS1 game discs
- Improved support for PS1 ISO/BIN/IMG/MDF
- Added support for LTU required files on "Extract files" function for use with JungleFlasher
Changelog JungleFlasher :
========================================
Support for new Key verification process
Vendor command support for DG-16D5S Drives
-xecuter X360USB Pro ***f/w update required***
-xecuter X360USB Pro 2 ***f/w update required***
Extra functions to utilise RGH extracts with LTU using T-X DG-16D5S replacement PCB
Support for LT Plus 3.0
-Hitachi 78, 79
Support for LTU 1.2, using T-X replacement PCB
-liteon DG-16D5S 1175, 1352
-liteon DG-16D4S 0225, 0401, 1071 - lost f/w replacement, replaced with a T-X DG-16D5S replacement
-hitachi DL10N 0500, 0502 - replaced with a DG-16D5S
Bug fix to SlimKey for bytes at 3f005, 3f006
IO port enumeration for Win 8 using old school PCI bus scan
-Using new portIO driver from schtrom with 32bit memory access
Official release of the iXtreme LT Ultimate for Team Xecuter LTU PCB
- Support for Liteon 0225, 0401, 1071, 1175, 1532, Hitachi 0500/0502
- No need for firmware dump of source drive. Requires dvdkey and J-Runner data
- Supports enhanced topology data if present for more accurate topology responses (Future ABGX support)
- Requires new JF to support LTU board flashing process. Use 0800 dual layer disc in drive to enable reflashing/vendor mode once LTU is written to board
This firware is uniquely written for the TX LTU board. It has all the features of LT 3.0 with the addition of the LTU features.
The 1332 chip has been the most secure chip used in the 360 to date. Cudos to MTK/Liteon for their attempt.
The movement of the dvdkey, AES routines and realtime firmware checks into the drive CPU was a nice touch.
I would like to dedicate this release to fellow countryman and Commodore hacker Julian Assange and Wikileaks. Keep the bastards honest.
Thanks go to Team Jungle and all testers for their hard work and efforts in the development process.
Thanks also go to Team Xecuter for their support to this project.
- Catalan
- Anglais
- Italien
- Portuguais
- Espagnol
- Added possibility to extract ISO PSX (Game Copy option, press Select on PSX disc) from multiple disks.
- Added possibility to use tricks disk: ISO hits the / PSXGAMES / CHEATS. The iso should be 2352 bytes per sector that can then be used to adapt to other sizes, creating replicas. For example, the Xploder 4 is not even 10 MB, so it's no big deal to have multiple versions. When asked if you want to start using it and mount it as a first album. See notes for details (the name is the same, I just need an extension and a sector size correct, internally, is list what is in that directory looking for a valid ISO)
- Changed BD Emu options: there are now separate options for internal or external disk: In internal: libfs always takes patched, can not mount or play as hard. In external: if you mount the disk, not taken libfs patched and is the recommended option. With libfs only recommend it for games that have cached data in the internal HDD.
- Enabled L2 to show games. At first, the first option to show only R2 PS3 games, while if you press L2 would PSX
Simple 360 NAND Flasher By Swizzy v1.3 (BETA)
*********************************************
** Please note that this is an open BETA, it have been tested by me and a few friends, but… i don’t take any
responsibility for possible bricks, make sure you understand this before you use this new version! **
****************
* Requirements *
****************
- A Hacked Xbox 360 (JTAG/RGH or similar)
- A nand dump to write or just enough space to save your nanddump on whatever device you use this app on
** For AutoMode: **
- A CRC32 hash of updflash.bin (in file updflash.crc32)
- A File named « simpleflasher.cmd » containing a command described in the secton « AutoMode » below
****************
* What it does *
****************
- It’ll flash your motherboards nand with the supplied image (updflash.bin) using rawflash v4 or rawflash4g v1
- It’ll dump your motherboards nand with to flashdmp.bin using rawdump v1 or rawdump4g v1
************
* AutoMode *
************
Below is a list of commands followed by an explanation of what it does:
read – Dumps nand to flashdmp.bin and generates a CRC32 hash in flashdmp.crc32
dump – ^ same as above
write – Writes updflash.bin to nand (if CRC32 hash matches)
flash – ^ same as above
safe – Safeflash (dump + write) requires CRC32 hash like write, but dumps to recovery.bin instead
exit – Just exit the app, mainly meant for just extracting CPUKey…
reboot – Reboots the whole console, mainly meant for FSD plugin updates
In order for these features to actually work you have to write any of the above keywords/commands in a file called « simpleflasher.cmd »
This file is read on launch and deleted once read (NOTE: It’ll ONLY read 1 line!)
*********************
* CPUKey Extraction *
*********************
It’s finally here, i could’ve had it working a long time ago, i just didn’t get the test app working… and decided to put it aside for a while…
This feature will not work on every dash, old ones will most likely not work, it uses a peek feature introduced by Dashlaunch a while back, i don’t know when, nor does cOz remember when…
Etheir way, if it doesn’t work it’ll post a message to you saying that you’ll have to use xell…
***********
* Credits *
***********
- cOz Thanks for all the help you constantly give me with just about everything, and thanks for rawflash!
- Thanks to xvistaman for helping me solve that one last error i had with corona4g writes! i owe you
- Thanks to blaKcat for listening to me about security stuff, CRC32 hashes etc. and not releasing the modified version before my official one
- Thanks to everyone that has helped me test it!: Jonblu @ Consoleopen, Sileandro and Razkar And others that i don’t know the name of…
- Thanks also goes to who ever it was that ported rawflash to SDK in the first place and making it open source!
- Thanks also to everyone that reports bugs and/or errors in ALL my apps
*******************
* Future features *
*******************
- Standalone Network controls (AutoMode was designed for AutoGG’s network updates and requires FTP access with App Execution)
*************
* Changelog *
*************
v1.3 (BETA)
- Added: Auto/Manual mode, it can now do things straight away rather then waiting for user input…
- Added: CPUKey Extraction this is done before it asks what to do, or even reads automode files…
- Added: It’ll display the currently running dashboard version for you (Useful when dumping/updating to see what’s running atm)
- Fixed: Output log will nolonger include anything that starts with « \r » meaning anything that reports status…
- Changed: Changed the text color to gold (0xFFFFD700)
- Changed: Font size is now smaller, and i’ve changed the font from Verdana to X360 by Redge
- Changed: The console will now hard-reset itself rather then power off (same way as a normal Xbox 360 update do)
- Changed: It’ll now clear the screen before it starts reading/writing, giving you a more clear picture of what’s going on