안녕하세요. 다크아이리스 입니다.
지금은 많이 잊혀지고 있는 DemonHades 해커의 JFW DH 3.56 MA1 버젼이 릴리즈 되었습니다.
이것은 최초의 3.56 사용자 정의 펌웨어 입니다. (무슨말인지 아시겠죠? 사용자 정의 펌웨어란?)
이것의 제작 기간은 7~8개월이 소요됬다고 합니다.
그리고 최근에 공개한 metldr 파일과는 전혀 상관 없다고 하네요 ㅎㅎ
업데이트 내용과 FIX에 관련된 영문 내용이 많아 일일이 번역을 하지는 않았습니다.
우선 DemonHades 해커는 스페인 사람입니다.
근데 공개한 타이밍 시기가 아주 죽이네요 ㅋㅋ
아마도 Matheulh 해커의 3.73 디크립트 소식에 뻑이 갔나 봅니다 ㅎㅎ
영문으로 올라온 readme 파일을 대신하여 올립니다.
3.56 펌웨어 사용자 분들은 한번 시도해 보세요. ^^
저도 곧 테스트 해볼 생각입니다.
※ 경고 !
이것은 소니의 정식 펌웨어가 아니므로 해당 펌웨어 사용에 대한 책임은 본인에게 있습니다.
이것을 사용함에 있어 어떤 고장도 책임지지 않습니다.
<<다운로드>>
3.55 상태에서의 JFW DH 3.56 MA1 패치 파일 (51.8메가) - DemonHades 릴
JFW DH 3.56 MA1 (175.99메가) - 스페인 유저가 3.56 MA1을 직접 패치한 릴
<<3.55펌웨어에서 패치파일을 이용한 패치 과정>>
1. Download the CEX 3.56 VERSION 2 from somewhere. 2. Apply the patch with included xdelta to patch on the official PUP VERSION 3.56 2. 3. Install the product using PUP by lv2diag mode, or through the XMB.
In the future, take a version for people stuck in the 3.56 flasher.
356MA-1.xdelta MD5: d6ead544a81564331851b4e8b8d96c6d DeltaPatcherLite.exe MD5: 05f144ebff7043c09107352315278ada xdelta.exe MD5: 1c6b3a6e1e9df2c8313bcf98aabfc8e1 ProductModeXMB MD5: 6a4d8a189a202a988bc1f5425446b190 RepoMaster.exe MD5: 741e08ed4dd51d0cefa8faa1d043e766
3.56 CEX ORIGINAL VERSION 2 MD5 (reference): 2a52196399a4b96ea568aafa65d1a27e 패치가 완료된 3.56 MA-1 PUP MD5 (reference): efe066e4836393c8bf60a5cc6804ddc3
MD5란?
해당 파일의 핵쉬 값을 나타내는 것입니다.
핵쉬값이 틀리면 정상 작동을 안하기 때문에 제작자가 직접 패치한 값과 그리고 클론 파일이 돌아다닐수 있기에
MD5 값을 공개한것입니다.
MD5 유틸은 네이놈 이나 구굴링하면 받을수 있습니다.
위 쪽에 링크되어 있는 패치된 JFW DH 3.56 펌웨어를 직접 MD5로 체크해보았습니다.
공개된 핵쉬값과 동일하네요. ^^
<<JFW DH MA1에 대한 감사인사>>
- Graf_Chokolo, for their great work. - To Demonhades, for its testing, its great strength. - To JaiCrab, for their help. - To Lara, for making me laugh a day. - People who have tested this 3.56 MA-1, thank you very much. - To all that s @ s who donated for a flasher, no firmware this far along would not exist as such. - To Varicella by their selfless help. - To B, thanks - To M.E.M, I NOT forget and NOT forgive. - All I forget that by mistake, apologize.
<<JFW DH 3.56 MA1 업데이트 내용>>
- FUNCTIONS
* Support PEEK / POKE lv2, using the typical SYSCALL 6 and 7 for compatibility with existing homebrew. * Support PEEK / POKE lv1 native SYSCALL using 10 and 11 respectively. These are used as SYSCALL than the lv2, the devs just have to use them as you would those of lv1 lv2 but affecting. * Load unsigned applications, FSELF format natively. That is, a normal application or npdrm FSELF valid format worked directly. (No touch-memory copy in the lv2). * Load logically signed applications, both official and unofficial signature valid. * Support for applications up to version 3.56. * Use of all SYSCALL system, provided that the product no later verify mode, QA, etc. * No need to modify the PARAM.SFO in the event that hypothetically would use a application that requests a version higher than 3.56 in either npdrm / normal application / or application running from the bdemu. * Installation of Retail and Debug PKG since the PKG Install option. * System settings in the XMB QA hacked. Now you can open the options using the normal combo without QA flag is active or a valid token or existing on your machine. Any options changed is maintained in the system registry settings. This QA system hack allows any SPRX to call the XMB to check this information hacked receive information, such as the nas_plugin.sprx, which in the case of DEX would permit installed without any patch of PKG Retail. As always be careful you do with those options, this is the safest way to have the QA without be QA, and not have to modify the EEPROM in any recalculated appearance or tokens of any kind. Here I have to thank Sony for making the security of your token only be in one byte and not in those should be.
- LV2
* FIX: Patch to allow loading of applications for (avoids errors 0x80010009) * FIX: Patch to avoid checking the firmware version of the application against the version of firmware stored in the memory of lv2 (avoid the error 0x80010019) * FIX: Patch to avoid the error 0x8001003C (allows loading of applications that request more internally than the current version) * FIX: Patch to avoid the error 0x8001003D * FIX: Patch to avoid the error 0x8001003E (using hdd patch and have no disc inserted) * FIX: Enables the use of all SYSCALL, avoiding generic error 0x80010003.
- CHANGES IN THE LV2 356: * FIX: Patching a new security check that prevents updater mode, it could launch an application unsigned with the minimum key 0xD (3.56), avoiding the error 0x80010009. NOTE: See NOTE AT THE END OF THIS README
* FIX: otherwise is used to integrate the new SYSCALL 6, 7, 10, 11 at lv2.
- LV1
* Added support for PEEK / POKE NATIVE at lv1. The method used to integrate these new hypercalls not use hypercall existing one, but really any hypercall not used in the system is a peek or poke depending on the case. To interact with PEEK / POKE, lv2 use SYSCALL of 10 and 11 respectively.
* Changes in the hypercall mmap (114). In the 3.56 Sony made significant changes in this hypercall to avoid the use that was being given to the lv1 to lv2 mapping. Now this hypercall checks that the key argument has not been modified, are checked mapping ranges (Someone who understands this will realize how dangerous it is that you map the critical thing, and do not speak of lv1) the hypercall code is divided into sub-functions into chunks for rolling the analysis. 3.56 In this version of this hypercall MA has not been touched, but having the support of PEEK / POKE in lv1 mapping is no longer necessary. In a later version is not ruled out such a check hypercall it's not complicated really, just it was not necessary for this version.
* Changes in the hypercall unmap (115), similar to mmap, its code shared between subfunctions.
* FIX: Added some patches to avoid integrity checks lv1 / LV0. * FIX: Added patches in the SPM and the DM to enable the use of any service. The patch is different, smaller, the SS patch exists (this is no longer compatible with 3.56), in my testings my patch does not produce any kind of problem with trophies, or saved games, etc.. * TODO: Delete the problem of not being able to downgrade to a version lower than 3.56. Currently not possible down from 3.56 after upgrading to the.
- LV0 APPLDR
* FIX: Patch to override the check ECDSA digital signature. Now an application with an invalid signature signed will be considered valid. For example, "sign" an application without having the proper private key to generate a proper signature. * FIX: Patch that removes the hash check of the application segments. A hash will be considered invalid valid. * FIX: Patch to override that you can not use FSELF retail consoles. This patch is different from that in ps3devwiki, the patch is on that page about this subject brickea machines has a problem metadata to decrypt the encrypted executables retail. * FIX: Patch to override the protection added in 3.55 (in the case of applications npdrm / normal, previously only was in charge of the RVK) which prevents applications can be used above the indicated version in the firmware today. That is, in a hypothetical case, a game trying to throw in a 3.60 3.56. * FIX: Patch to override the protection auth check the applications (added in 3.56), this check detects programs created public tools as they always put the same auth, auth superior one. * FIX: Patch to remove the protection from the white list of authorized programs, added in 3.56. Now you can use all applications as 3.55 and below.
- 참고 사항
* The lv2 is protected by a hash in lv1, in case you want to play an offset that encompassed in the range of protection, this would produce a panic check off the system. To avoid this problem, use the tool that is attached to this package before using poke modify lv2. Why not to implement this patch directly is because not everyone is dev, and that can not be touched lv2 is safe for the user. Of course the source code of this program is included, so a dev can see how using the POKE lv1 patched the problem.
* You can now exit of service mode, and use the lv2diag as before, but this has a potential danger. The 3.56 now makes it impossible to make a downgrade to less than 3.56, meaning that if you are in the 3.56 in him are, if you have time you tried to cancel out a version that checks the update manager. The problem is a programming error that allows updating Lv2Diag.self, the failure is that No checks that the update is in the usb or to verify that this is valid, the program formats the flash 1.2 and 3. That is, if then fails, your system would not have died partially flashes, still work ROS can use a lv2diag active again, but who Forewarned is forearmed. Lv2diag Beware!
* Attached to this package is an updated application to extract the nodes of a dump of lv1 is an update of the application made by Graf Chokolo, now has support for versions 3.15, 3.41, 3.55 and 3.56 in one program. Useful to display the nodes extracted from your dump.
* The firmware finished graphic will be added when finished JFW 3.41 itself. * In the package adds an application, I do not think there publicly, to put the product model directly from the XMB, acts as a toggle, in the event that you can use the product as simply So I removed the product.
As a final note to remember that this is the first version of the firmware, so constructive criticism are welcome. As I suppose that due to this publication where patches are appldr, many variants will come out of it, just remember that the first publication was this. Not bite the hand that feeds you, today is a 3.56 higher perhaps tomorrow another, or maybe not.
<<참고 사항>> - 구글 번역
당신이 포함하고 해당 오프셋을 재생하려는 경우에는 * lv2는 lv1의 해시에 의해 보호되고
보호의 범위에서, 이것은 공포가 시스템의 선택을 해제하는 생산 것입니다.
이 문제를 피하려면, 찌른 수정 lv2을 사용하기 전에이 패키지에 첨부되어 도구를 사용하십시오.
모든 사람은 데브이며, lv2는 사용자에 대한 안전 만지지 않기 때문에이 패치를 구현하지 않는 이유는 직접 있습니다.
물론이 프로그램의 소스 코드가 포함되어 있습니다,이 문제를 패치 lv1의 구멍을 사용하여 어떻게 dev에가 볼 수 있도록.
* 이제 서비스 모드를 입력하고 이전처럼 lv2diag을 사용하지만 이것은 잠재적인 위험을 가지고 있습니다.
3.56 지금은 그것이 불가능한 당신이 그를에 3.56에있는 경우 시간이있다면, 당신이 업데이 트 관리자를 확인 버전을 취소하려 고하는 의미, 이하 3.56로 다운 그레이드를 할 수 있습니다.
문제가 Lv2Diag.self을 업데이 트 있도록하는 프로그래밍 오류이며, 버그가있는 업데이 트가 USB 또는이 플래시 1.2 세 유효 기간, 프로그램 포맷되었는지 확인하는 것입니다 NO 확인합니다.
다음 실패하면 그것은, 여러분의 시스템이 부분적으로 깜박 죽었을하지 않았을 여전히 활성 선생님이 다시 lv2diag를 사용할 수 있습니다 작동하지만 누가 Forewarned forearmed이다. 주의를 Lv2diag!
* lv1의 덤프의 노드를 추출 업데이트된 응용 프로그램 업데이 트가이 패키지에 첨부됩니다 그라프 Chokolo 의해 만들어진 응용 프로그램의 현재 버전 3.15, 3.41, 하나의 3.55 및 3.56을 지원한다 프로그램입니다. 귀하의 덤프에서 추출한 노드를 표시하는 데 유용.
* 마무리는 펌웨어의 그래프는? JFW 3.41 자체가 완료되면 말해. * 패키지에? 응용 프로그램을 마, 제품 모델을 넣어, 공개적으로 그런 생각은하지 마 직접 XMB에서, 당신은 단순히 제품을 사용할 수있는 경우에, 토글로 동작 그래서 제품을 제거했습니다.
이것은 펌웨어의 첫 번째 버전입니다 기억하는 마지막 참고로 그래서 건설적인 비판은 환영합니다. 그 패치 appldr있는이 간행물에 의해 가정으로 많은 변종은, 그것을 밖으로 올 것이다 단지 첫 번째 발행물이되었다는 사실을 기억하십시오. Mordais하지 피드 한편, 오늘 같은 3.56 m입니까? 나가 최고이다, 아니면하지 않습니다.
JFW DH 오픈 스토어 영상
JFW DH 구동 영상
참조 사이트 :
프랑스 유명 포럼
영국 유명 해외 포럼 (progskeet 모드칩 최초 포스팅)
전 미국쪽으로 알고 있는 해외 유명 포럼
스페인 유명 포럼 (DemonHades 해커 활동)
DemonHades 해커가 운영하는 포럼
|