[tin vui] trong 1 tuần 2 dongle bị hạ gục. Tiếp theo là true blue

  • Thread starter Thread starter ducmt1
  • Ngày gửi Ngày gửi
đang định mua TB mà nghe tin TB sắp chết :4cool_oh:
 
Hi Scene Sorry for my bad English. I want to give you info you pls make public. I want be anonymous. I only can say I’m from Hong Kong. I have way to get a dex, it works and is complete nothing missing

Manual to get a dex (here is everything you needed) and you have a full working dex

EID0 Key Seed and EID0 Section Key Seed are hardcoded in the isoldr

EID0 Key Seed
AB CA AD 17 71 EF AB FC 2B 92 12 76 FA C2 13 0C
37 A6 BE 3F EF 82 C7 9F 3B A5 73 3F C3 5A 69 0B
08 B3 58 F9 70 FA 16 A3 D2 FF E2 29 9E 84 1E E4
D3 DB 0E 0C 9B AE B5 1B C7 DF F1 04 67 47 2F 85

EID0 Section Key Seed
2E D7 CE 8D 1D 55 45 45 85 BF 6A 32 81 CD 03 AF


If you dump they isoldr key (EID Root Key) with metldrpwn you got from 0x00 to 0x1F the EID Root Key and from 0x20 to 0x2F the EID Root IV

use AES Encrypt to Encrypt EID0 Key Seed as data with EID Root Key as Key and EID Root IV as IV

the result contains from 0x10 to 0x20 the EID0IV

and contains from 0x20 to 0x40 the EID0Key

use AES Encrypt to Encrypt the EID0 Section Key Seed as data with the EID0Key as Key and no IV

the result will be the first 0x10 bytes of the EID0 First Section Key

the second 0x10 bytes of the EID0 First Section Key are only 0x00 bytes

EID0 is located in NAND at 0x80870 and in NOR at 0x2f070

the first 0x20 bytes of EID0 are not encrypted

at the fifth byte of EID0 (NOR example 0x2f075) your target ID is located change it to 0x82 (Debug Target ID)

use AES Decrypt to decrypt the first EID0 Section (NOR example 0x2f090). The size of the first Section is 0xC0 bytes. Use the EID0 First Section Key as Key and the EID0 IV as IV

Build the CMAC (OMAC1) hash of the decrypted EID0 Section from 0x00 to 0xA8 with EID0 First Section Key as Key. The calculated hash has to be the same as the bytes in the decrypted EID0 Section from 0xA8 to 0xB8.

At 0x5 of the decrypted EID0 Section is your target id again change it to 0x82 again

0xB8-0xC0 of the decrypted EID0 Section should be just 0x00 bytes

after you changed the target ID of the decrypted EID0 Section, create the CMAC hash of the new decrypted EID0 Section and write the new hash to the decrypted EID0 Section

use AES Encrypt to encrypt the EID0 Section and write it back to the NOR (NAND).

Now install dex Firmware with the recovery menu.

HINT: Got Petitboot on emer init go to boot gameos and do emer init again to get to the recovery menu.

You can’t login to the PSN because IDPS is obviously not valid from now on.

THIS CAN BRICK YOUR CONSOLE IF NOT DONE CORRECTLY.

有志者,事竟成 “Where a will, there is way”
一不做二不休 „You start something, you have to finish it”

xin chia buồn những người mới mua true blue vì key đã bị leak bởi 1 hacker hồng công:1cool_look_down:
 
trueblue bị cóp py hình như hoàn toàn rồi , thị trường giờ rất nhiều loại usb

- trueblue xịn 2.7 tốt , giá hơi cao
- trueblue nhái 2.7 tàm tạm, giá quá cao
- jbking 2.7 giá tàm tạm , hay hỏng
- jb2 2.3 giá rẻ , trâu bò
- pb 2.7 chưa test
- ifinity chưa rõ fw , chưa test
 
Chán nản k bỏ 1 xu nào mua nữa dù cho usb ifinity có chơi đc các game mới nhất giờ
 
Cứ mà chờ =)))))))))))))))))))))))))))))))))))))))))))))))).......
 
Bị leak code rồi.. hóng tiếp thôi các bác :5cool_still_dreamin
 
Để coi sao, chuyện còn dài kì mà, xui xui từ đây tới cuối năm chã cò gì để chơi :1cool_look_down:
 
Loạn thật !
 
chắc cũng vì có nhìu ng cố break cái code đó cho bằng đc mà TrueBlue làm usb mới vào ngày 20 tháng này chăng :))
 
Coi TB có ra game mới hay không nữa là hiểu liền à :7cool_feel_good:
 
Phải chi mấy cái clone TB đó bán chừng vài chục ngàn mua để chơi 1game rồi liệng cũng đáng tiền ;;)
 
mẹ bực mới mua TB chưa hết BH nữa là
 
bực thật >< số mình đel thế , trước mua usb hack đời đầu 3.41 được tuần thì ra Cfw 3.55 , giờ mới mua TB thì TB chuẩn bị die >< cái số ... :(
 
TB chưa die đâu, cái dongle 20/7 tới là của nó đấy :9cool_canny:
"Update: We have confirmed that the NEW dongle is still called True Blue (aka JB2/TB), but it was changed new packaging and add more function in it. What's the new technical support? I am sorry we don't know currently except compatible with the old TB eboots.
"
 
ax ax đang toán mua 1 em tb về chơi, kiểu này chắc nghỉ
 
tôi sợ đoạn code đó chính mấy thằng dev TN có tình lộ hàng rồi bán USB như thế là hợp lý và dân tình k có gì để trách móc nó cả
 
Hiya everyone
Recently as u may already now, the scene has been blessed with a way to convert our CEX ps3s to DEX units, which for those of you who are still wondering does pretty much open up the ps3 wide open.
thank you anonymous HK dude, we love ya ^^
Now before we delve deeper, allow me to clarify a few points:

1: this will allow to run all backups prior to 3.55 as well as 3.6+, but the method to do so is a bit different from loading backups on a CEX unit, but don’t worry I’ll explain that later when i release the tool that will allow us to create and mount the masterdisk files in order to run the said backups.

2: i used OFW 3.55 as a source for the conversion due to a big number of scene members are stuck on CFW 3.55, so the PUP i will provide here can only be installed from CEX units running CFW 3.55, u gotta install OFW 3.55 via recovery then the converted PUP also via recovery. That will convert your CEX unit into a DEX.

3: 4.xx OFW ppl, sorry i will not look into making a PUP for you solely because i rather be working on testing and packaging the tool which will allow us to create and mount masterdisk files for our backup, which i will release as soon as finished and properly tested.

4: this will not allow PSN nor any form of online gaming, i believe Sony did actually block all the IDs trying to get a communication passphrase into devnet after 7th

5: this will allow running unsigned code, so yay for homebrew and yay for emulator, also with DEX units true potential, i foresee some great homebrew alongside full speed emulators in the near future.
to give up PSN and online gaming for all this goodies, i for one think its worth it

How to install :
1: install OFW 3.55 via recovery menu
2: install the provided PUP via recovery menu

Link :
Mã:
http://www.filejungle.com/f/VbCz3Y/DEX pup.rar
Password: DexConverT

Source :
Mã:
http://www.ps3news.com/forums/ps3-hacks-jailbreak/how-cex2dex-work-123592.html#ixzz204F29nBN

quick Q/A:

Q1: will this be able to load backups from all FW that will be released later ( OFW 5.XX) or it may be patched by Sony ?
A1: basically yes, it will be able to load all backups regardless of the base FW for the game, and if Sony want to patch it, they should recode the way masterdisks are handled which is no simple task believe me lol, due to hardware limitation i'm not even going to dwelve in. point is it will be a lot of hassle for them to patch it and it is more unlikely due to PS3 being in its last years.

Q2: when will the tool to make master disk files (prior to launching backups) be released
A2 : as soon as finished and properly tested




đã có CFW cho phép chạy tất cả game 3.6+ \m/ hiện nay các tester đang tiến hành kiểm tra nên các bạn khoan hãy cài vào PS3:4cool_beauty:
 
Back
Top