Geohot releases the PS3 keys [Discussion]


Recommended Posts

Wow, I thought GeoHot had stopped hacking the PS3.

Hes a sellout. his release came with a job application to any of the 'big three' so he's NOT on the 'side' hes portrayed in his PS3 and iPhone hacks...

I believe he figured this out months ago though, cause 3.21oo wouldn't have been possible otherwise - but that never came to light either.

wonder what Sony is going to do next(probably nothing)... pirated PS3 games will soon show up in the internet.

I am not sure if i have understand correctly and what has changed with Geohot's released keys but on the "failoverflow" videos they clearly state that they don't have the keys to sign games.

Has this changed now?

I am not sure if i have understand correctly and what has changed with Geohot's released keys but on the "failoverflow" videos they clearly state that they don't have the keys to sign games.

Has this changed now?

The Root/Master Key has leaked from what i can gather, that means the PS3 is wide open now anything can be run or signed and any firmware past, present or future can be hacked and you will be able to play on PSN, you wont need a dongle either.

I'm far from knowledgeable about how serious this is. I understand what it allows a user to do, but couldn't Sony release another firmware update that changes the key and uses a different form of encryption? Or would that break anything created for the PS3 in the past?

The Root/Master Key has leaked from what i can gather, that means the PS3 is wide open now anything can be run or signed and any firmware past, present or future can be hacked and you will be able to play on PSN, you wont need a dongle either.

From what I've read, it was the method Sony used to make the keys that was cracked (i.e. the method used was weak, like a random number generator always returning the same value)

It has the possibility to do that. It's still a very new hack and applications are limited at the moment... but they are coming.

Primarily, homebrew is what benefits this as the custom packages can now be signed with the proper key - not needing the jailbreak/debug console.

From what I've read, it was the method Sony used to make the keys that was cracked (i.e. the method used was weak, like a random number generator always returning the same value)

It wasnt, that was a joke from XKCD comics.

I thought it was pretty much a variable that Sony kept constant? Thats what the hacking slides show.

If K is the private key, and m is a random number (they're divided in the algorithm), if m is kept the same, that means K is the same so it's possible to work it out.

It's quite a read if no-ones seen the slides/videos yet and are interested:

http://psx-scene.com/forums/f6/fail0verflow-27c3-ps3-epic-fail-now-live-demo-73986/

fail0verflow has now released some of their tools on their git: http://git.fail0verf...?p=ps3tools.git

Some of the tools are as follows:

sceverify: verify SCE binaries

pupunpack: check pup hmacs

puppack: create PUP files from scratch

norunpack: extract files from a NOR dump

unself: convert fselfs back to elfs

makeself: convert ELF files to self files

makepkg: build update.pkg files

readself: read and output info regarding a self file

unpkg: decrypt and unpack update .pkg files

appldr keys have been dumped. That's the keys used to encrypt games.

And some tools have been released.

decrypt-self.exe

Code:

decrypts self files

Usage: decrypt-self {self file} {elf file} {key file} {fix}

self file: file you want to decrypt

elf file: your output file

key file: use one of the included (e.g. "315.appkey")

all x**.appkey files are unknown fw numbers

find out on your own :)

fix: 0 (zero)

read-self.exe

Code:

shows self info

Usage: read-self {self file}

self file: file you want to decryptrebuild-self.exe

Code:

rebuild self?

Usage: rebuild-self {self file} {elf file}

pup_unpack.exe

Code:

unpack pup files (get core_os_package.pkg, etc.)

Usage: pup_unpack {filename} {directory}

filename: your pup

directory: destination for pup contents

fwpkg.exe

Code:

decrypt pkgs (you extracted with pup_unpack)

Usage: fwpkg {mode} {input file} {output file}

Mode: - e: Encrypt PKG

- d: Decrypt PKG

input file: your crypted pkg

output file: decrypted output

coreos_tool.exe

Code:

extracts/rebuilds the decrypted CORE_OS_PACKAGE

Pack CoreOS : coreos_tool p {output pkg} {files...}

Unpack CoreOS: coreos_tool u {decrypted CORE_OS_PACKAGE.pkg}

key files:

Code:

first 32 bytes: erk

last 16 bytes: riv

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • What? They aren't removing the disc drive and charging $800 for questionable performance upgrades that are better suited to a new generation console? How outrageous!
    • Bummer it's only 1TB instead of 2. I had one of those - the "Halo Special Edition" OG Xbox. This looks like a cool update.
    • KillerPDF 1.4.3 is out.
    • Google's NotebookLM gets some useful features you may have been waiting for by Aditya Tiwari It's been three years since Google introduced its AI-powered note-taking and research app, NotebookLM. Just when Apple is about to kick off WWDC 2026, the search giant has announced a platter of new NotebookLM features that add agentic capabilities in chat and more advanced reasoning. For starters, NotebookLM now draws its fuel from Gemini 3.5 and Antigravity to improve accuracy and reliability. One of the things people have been asking for a long time is more transparency into the thinking steps. NotebookLM now shows expanded thinking steps in chat, providing better visibility into the thinking process. Google compared the upgraded NotebookLM with prior versions and found that it "achieved an average win rate of over 65% — a 15% point margin above parity — across our top five core evaluation dimensions," including accuracy & quality, multilingual support, large document analysis, document creation, and advanced research. It showed substantial improvements in analyzing large documents, achieving a 69.9% win rate. The system also delivered "exceptional performance" in advanced web research and source discovery with a 78.2% win rate. The AI research tool now generates outputs in more formats. You can give instructions to guide the outputs and download the generated files from the studio panel. Here are the newly supported formats: PNG and SVG for data visualizations and charts PDFs, docx, markdown, and text files for documents PNG, JPG, and GIF for images JSON and CSV for structured data XLSX for Microsoft Excel PPTX for Microsoft PowerPoint You can make edits after the outputs are generated. The feature is available globally; therefore, you can provide directions in one language and create outputs in another. Google said that it's also making it easier to get started with a project in NotebookLM. Instead of having a list of sources beforehand, you can even start with loose ideas, and NotebookLM can help build the repository of sources through the chat. For instance, you can find primary sources in other languages to get new perspectives or explore related works of an author. All of these new features are rolling out globally for those who can loosen up their pockets. They are available to users with Google AI Ultra and all Workspace business customers with AI Ultra access. Google has plans to expand them to more users in the future.
  • Recent Achievements

    • Very Popular
      Captain_Eric earned a badge
      Very Popular
    • One Month Later
      amusc earned a badge
      One Month Later
    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      PsYcHoKiLLa
      238
    3. 3
      ATLien_0
      76
    4. 4
      Steven P.
      75
    5. 5
      +Edouard
      69
  • Tell a friend

    Love Neowin? Tell a friend!