Tag archive for ‘payload’

True Blue dongle payload released (Update #2: Q&A posted: “dongles are bad and obsolete…don’t need any dongle at all”)

by Rith - on Nov 17th 2011 - 31 Comments

Great progress has been made to reverse engineer the True Blue dongle. With that said, the payload for the True Blue dongle has been released. But don’t get too excited just yet, it may still need to be decrypted before it is usable on other USB dongles (e.g. Teensy++, E3 Card Reader, PS3Key, etc.). Download available below.

In case you’ve been living under a rock, True Blue allows v3.6x games to boot on v3.55 PS3 consoles.

SHA1: 43402D6FE2ECE43EBE91531EFA07C366D46DD121 //
MD5: BA5AFAB174BF6003D41AC8951301B822 //
CRC32: 248284D2 //
CRC16: 8C78

Update (11/12/2011): That’s right; the True Blue payload that was previously dumped has been decrypted! I assume a tool to flash this payload onto other USB dongles will come next but that’s just an assumption. Check out the dump info here.

lv2 dump (click to show hidden content):

payload decrypted @ LV2 dump 0x7f0000

Start Offset

End Offset

Payload

Description

00000000 00000FFF first 3.41
00001000 00001FFF second 3.41
00002000 00002FFF third 3.41
00003000 00003FFF fourth 3.41
00004000 00007FFF fifth
00008000 00008FFF  ?
00009000 0000BFFF  ?
0000C000 0000CFFF  ?
0000D000 0000DFFF  ?
0000E000 0000FFFF  ?
00010000 00013FFF  ?
00014000 0001BFFF  ?
0001C000 0001C00F  ?
0001C010 0001C01F  ?
0001C020 0001C03F  ?
0001C040 0001C05F  ?
0001C060 0001C06F  ?
0001C070 0001C07F  ?
0001C080 0001C09F  ?
0001C0A0  ?
001FFFFF  ?

Cheers to VenomusX for this news tip!

Update #2 (11/17/2011): Once the TB reverse engineering is complete, dongles such as Teensy++, Black cat, PS3Key, etc., will not be required.

Q&A:
Q: Is this posible on other dongles from the FW3.41 days like Blackcat and Teensy?
A: Dongles are bad and obsolete, mkay :P (once you have the key/algo, you don’t need any dongle at all)

Q: Are they (TB team) just stealing the dev eboots?
A: You can only rumor which source they use to resign the content to lock-in their DRM. But of course those very same DRM-less files can be resigned for 3.55 too (as has been done numerous times in the past). Piracy is bad, but pirates using DRM to make sure they get the money and not genuine developers is even worse (especially when they lock you into a single firmware that has even less to offer than generic MFW and makes you loose OtherOS++ too).

Files to strip:

rootfolder, LICDIR + content, TROPDIR + content, USRDIR (EBOOT.BIN + other signed binaries like .SPRX, .sdat)

example (portal_2_BLUS30732):

|-- ICON0.PNG
|-- LICDIR
| `-- LIC.DAT
|-- PARAM.SFO
|-- PIC0.PNG
|-- PIC1.PNG
|-- PIC2.PNG
|-- PS3LOGO.DAT
|-- SND0.AT3
|-- TROPDIR
| `-- NPWR01719_00
| `-- TROPHY.TRP
`-- USRDIR
|-- EBOOT.BIN
|-- bin
| |-- datacache_ps3.sprx
| |-- engine_ps3.sprx
| |-- filesystem_stdio_ps3.sprx
| |-- inputsystem_ps3.sprx
| |-- launcher_ps3.sprx
| |-- localize_ps3.sprx
| |-- materialsystem_ps3.sprx
| |-- scenefilecache_ps3.sprx
| |-- soundemittersystem_ps3.sprx
| |-- steam_api_ps3.sprx
| |-- steam_config.sdat
| |-- steam_resources.sdat
| |-- steamclient_ps3.sprx
| |-- studiorender_ps3.sprx
| |-- tier0_ps3.sprx
| |-- vgui2_ps3.sprx
| |-- vguimatsurface_ps3.sprx
| |-- vjobs_ps3.sprx
| |-- vphysics_ps3.sprx
| |-- vscript_ps3.sprx
| `-- vstdlib_ps3.sprx
`-- portal2
`-- bin
|-- client_ps3.sprx
|-- matchmaking_ps3.sprx
`-- server_ps3.sprx

Download True Blue dongle payload »

source ps3devwiki

Hermes updates payload version for CFW 3.41

by KingX - on Feb 10th 2011 - No Comments

There has been a latest update to Hermes CFW 3.41.  The update is to change to the latest payload 4d.  The changelog to this lateset update states that there is an added menu XMG retail with PS3_SYSTEM_VER patch and other stuff related to loading eboot.  The update is basically the payload to version 1.04.

Download the latest payload for Hermes CFW 3.41 »

Kmeaw's LV2 patcher updated. Add your own payload

by Rith - on Jan 19th 2011 - 1 Comment

Developer Kmeaw has updated his LV2 patcher to include an option for adding your own payload to this patcher. Hermes’ payloads are currently not compatible, so you’ll have to stick with the PL3 payloads.

Feel free to post your comments below.

Read more & discuss in forum »

Spoof firmware v3.55 for all USB boards. Includes both PL3 and Hermes 4B payloads

by Rith - on Dec 16th 2010 - No Comments

After the release of the first firmware v3.55 spoof by PS3Yes!, it didn’t take long for Cyberskunk of psx-scene to port over the spoof for the majority of USB boards out there. As mentioned before, this spoof ONLY stops the PS3 from prompting for an update to firmware v3.55–nothing more. Therefore, you cannot use it to go on PSN or online or play games like Gran Turismo 5.

Compatible USB devices:

  • AT90USBKEY
  • ATAVRUSBRF01
  • AVRKEY
  • Bentio
  • Blackcat
  • JMDBU2
  • Maximus
  • Minimus 32
  • Minimus v1
  • Olimex
  • OpenKubus
  • PS2CHIPER
  • Teensy 1.0
  • Teensy 2.0
  • Teensy++ 1.0
  • Teensy++ 2.0
  • UDIP8
  • UDIP16
  • USBTINYMKII
  • XPLAIN

What it doesn’t do:

  • NO ONLINE PSN GAME PLAYING
  • NO GT5 (original or backup)
  • NO N4S:HP (same as above)
  • NO UNLOCKing YOUR PSN CONTENT

Direct Download (for firmware v3.41 & v3.15)

[Mirror]: DOWNLOAD HERE (for firmware v3.41 & v3.15)

Source psx-scene

PS3Yes releases v3.55 spoof payload

by Rith - on Dec 15th 2010 - No Comments

Team PS3Yes! is back with their second firmware spoof payload. This one is for firmware v3.55. But unlike the firmware v3.50 spoof, this one only does one thing. It stops the PS3 from prompting you to update to v3.55. Yeah, not that exciting!

What it doesn’t do:

  • NO ONLINE PSN GAME PLAYING
  • NO GT5 (original or backup)
  • NO N4S:HP (same as above)
  • NO UNLOCKing YOUR PSN CONTENT

CE-X Hybrid payload for PS3 v3.41 released

by Rith - on Nov 18th 2010 - 1 Comment

This payload is a port of xoeo custom PL3 payload that was release for firmware v3.15 and is design to work on firmware v3.41.

This payload is a port of Xoeo custom PL3 for 3.15.
We have converted it for use with 3.41, major cleaning up of the coding and added/removed some stuff. /the only reason we are releasing this is because we said we would. This is still experimental so don’t complain if something doesn’t work for you.

What makes this payload different is that it is a hybrid of PL3 and hermes. It is very stable with 0 lock ups, but there is a catch some backups will return a 800xxx error. This payload is very stable but also kind of a backwards step in our goals as it uses syscall36. Either way it is still a very good payload. 

*I might have left out a few features I cant recall right now due to lack of sleep*

I have tested this with Gaia 1.03.1 and I was able to load backups but as I stated above some games will give you a 8000xxxx error and is bing looked into. I have also tested BlackBox FTP, Comagen Filemanager, Snes9x and all run perfectly. If you want to use multiman make sure to set syscall36 in your options.ini.

Things I haven’t checked (permissions)


You can all check the git at https://github.com/evilsperm/CE-X-3.41

Thanx goes out to xeoe for his hard work, as well as the very long hours and sleepless nights of Cyberskunk!
I need to sleep myself :P

This hex pack has 20+ boards so I don’t want to see anyone begging for complies check the pack first!
Also I have included the .bin for those of you who need it.

Features:
PSN – not working at this time
3.50 Spoof
syscall 36 – hermes
syscall 8 – stealth – peek poke
modelset – 0×82 – debug
version – 120gb slim

[FileFactory]: DOWNLOAD HERE



Join FileFactory Today!

source

payload - Bitbag