Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.
Newskeen.com isTHE
FIRST EVERto bring you
LIVE Demo's of homebrew! Also a good possibility to
chat with the author(s) of the homebrew that is being demonstrated.
Xbox360/Xbox: "RxE" New! THE best Dash ever! (Xbox360)
Truly amazing! Words can't describe how awesome this new dash is for jtag xbox360's!!!! Click the link to view more about this with a list of all the features.. Like voice command and skeleton recognition (kinect) Click me and read about RxE!!
E3
FLASHER dual boot, can with v3.70 play PSN and with v3.55 play your HDD
games!
After we release dual boot video, most people love it but it also
raised some doubt. We understand, so today we release a new video, and
do some clarification:
1: E3 FLASHER not only a flasher, but with perfectly extension because
integrated lots of interface
* We will release more useful function later, all will be free just
like when we release Golden Finger function on our E3 card reader.
2: E3 FLASHER can be upgrade from PC USB or TF card, very simple to do.
3: E3 FLASHER dual boot you need TWO HDD's, one for 3.70 , another for
3.55. If you use only one HDD, it will be required to format everytime.
* We will release a kit that includes ESATA station for you switch
HDD's easier. (Supports 2.5" and 3.5" sizes)
4: At present, on NAND flash console, you need to solder plus wires
also. And no dual boot function because no 256M NAND FLASH ON E3
FLASHER.
* On NOR flash FAT console, you need to solder plus wires also, and
includes dual boot function.
* On Slim console, there is no wires, but you still need solder some
points. It is easy can be done in 3min.
5: We will release 2 new version E3 FLASHER at the end of this month.
* One is 256M NAND flash on board and with CLIP, to get dual boot and
no solder function.
* Another is same as present E3 FLASHER but with CLIP, so all NOR flash
console no need any solder at that time. (sure cost will higher)
6: If all goes well, we will release official pictures and retail
prices by this wednesday !
Posted by admin on Monday, September 05 @ 09:07:02 EDT (135 reads)
(Read More... | PS3/PS2 | Score: 0)
WII/GameCube: Wii missed you! LetterBomb 4.3 systems hacked!
Been a while since a nice neat new hack has been released for the wii console. It uses the letter board and other fun stuff.
Up until now the only way to liberate your Wii console and enable
the use of homebrew with System Menu 4.3 was to use a gamedisc based
exploit such as “BatHaxx”, “Return of the Jodi” and others.
Today we are announcing a project that changes this completely and
removes the requirement for an exploitable game.
In memory of BannerBomb, we present you with LetterBomb ,
a brand new System Menu exploit that will allow you to enable homebrew
with the push of an envelope (no
stamp licking involved)
This exploit reuses (and abuses) some of some Nintendo’s
Wii Messageboard functionality. You will need:
A Wii running System Menu 4.3 (E/U/J/K)
A SD(HC) card with some free space
Your Wii’s WiFi
MAC Address (available from your Wii’s system settings). This is
needed because the Wii will only accept messages addressed to its
specific MAC address.
A few minutes of your time
For this very special occasion we have created an easy-peasy webpage
that takes away some of the pain that is usually involved with getting
homebrew onto your system:
http://please.hackmii.com This webpage will ask you for some necessary information (such as
your System Menu region and MAC address), and will
then return a nicely packaged ZIP file that is ready for extraction to
the root of your SD card. Simple eh?
All that is missing from that point is a boot.elf/boot.dol file
(that you will need to place in the root of your card), and you should
be good to go. For your convenience we have an option to prepackage and
bundle the HackMii Installer boot.elf (this is enabled by default).
So, how do I do this? Simple…. once you’ve unzipped the file to your SD card (and inserted
it) just navigate to the “messageboard” on your Wii and in the default
view you should browse to “yesterday” (the place where you usually see
yesterday’s messages) – sometimes this may be “today” or “two
days ago” (this depends on the timezone you are in).
From this view you will be presented with a small envelope (that
should obviously stand out against the rest of your plain old boring
ones), click it, kick back, twiddle your thumbs (the Brits among you,
go and make a cup of tea) cross your fingers and hope it worked. DISCLAIMER: We are aware of a similar exploit by
giantpune (good work!), but as of today this has not been released. In
anticipation of its release we decided to reverse engineer, hack and
implement something ourselves.
Hello, today I decided to share my advanced our own CFW 3.55 PS3A.
This "Rev3" contains a lot of novelty in design of the XMB and corrects
an annoying bug with formatting, but above all I brought you your own
category "Homebrew" that works for all languages.
I've prepared a short demonstration video to get you the mouth water
Xbox360/Xbox: Gecko 1.17 Released, Winbond Unlock Support (Xbox360)
Crazy... This is one of THE craziest things iv'e seen to help in the aid of hax... You have to watch.
QUOTE Source
Gecko 1.17 Released, Winbond Unlock Support
Gecko 1.17 has been released along with Winbond Unlock Support A man
built it... a man cracked it... after months of trial and error and
several weird methods; a Huge and Impressive effort in the tests.
Geremia has made public the Kamikaze Winbond Unlock.
We will not lie, this is not for noobz! Many drives have died in
these tests which arrived at the method you will see in the video. But
with all that, it’s the easiest method we can provide now. We delayed
the (by now old) Macronix trick while we worked on this WINBOND trick
to make as easy as possible. Full notes and comments of Geremia can be
found here.
We released Gecko 1.17 which can handle The Winbond Unlock method,
you will appreciate the possibilities put into the unlock on your
Workbench with a small standalone device like Lizard powered from
usb-ac adapter instead of having to have a PC near for this particular
job. :)
Full tutorials are being written and will be posted with-in the next
24 hours, but meanwhile we have prepared a small video of how to unlock
the Winbond with the Kamikaze method using Lizard (Require Gecko 1.17)
Xbox360/Xbox: (xbox360)Great News from elitemodscene.com!! Wasabi X360/X360S/BoxZii
Hot product of 2011 imo will be "Optical Disc Drive Emulators" for Xbox360. I wouldn't get one right away until people actually start testing these out. Competition is always a good thing for the consumer so hopefully the more there are of these the better the price for us! :) QUOTE Source
Even though the X360Key has not been released yet we already have two
new products that have recently been announced fighting for the top
spot in the Optical Disc Drive Emulator market. The first new product
is the Wasabi 360 which has 2 different models, one for the phat 360
and one for the slim 360. Not very much is known about this product
just yet but the following quote has been taken directly from their
webpage :
Quote
Wasabi X360 and X360S - coming soon!
The ultimate ODDE (Optical Disc Drive Emulator), allows you to emulate
your 360's optical disc drive and run Xbox 360 or Xbox 1 ISO's from
HDD. No more hunting for game discs, simply execute your favourite
ISO's from any ESATA HDD. Easy, fast, safe and convenient.
Features include:
Solderless installation
Selection of your favourite ISO's via our intuitive user interface
Support for AP25 enabled ISO's
ESATA interface is used in place of USB providing superior performance,
since data is transferred directly between the ESATA HDD and Xbox 360
resulting in impressively high bandwidth, many times faster than
reading from a real DVD disc
Elegant and streamlined console inspired case design
Versions available for both fat and slim consoles
NTFS file system natively supported
Powerful embedded CPU running performance tuned Real Time Operating
System
Regular firmware updates available free for download
Fully updatable hardware (MCU and FPGA's) from ESATA HDD including a
failsafe recovery mode
No need to modify your original ODD
Hardware selectable pass through mode - providing access to the
original ODD
Features coming soon:
Xbox Live compatibility
Dumping of X360 ISO's from original discs
The second product is named BoxZii, the people behind BoxZii have put
out a lot more information on their product and have even included
installation pictures. This product also comes in two different models
but they are not differentiated by the model of Xbox 360 you have like
the Wasabi360, The BoxZii has 2 models for you to choose from depending
on how you intend to use the device.
Model 1: Internal Mainboard + USB PC Control Dongle
Xbox 360 XDG2/XGD3 Compatible
Supports Dash (2.13599) included
Supports FAT Consoles / AP25 Emulation
SLIM support by Simple USB software Upgrade
Plug and Play/Requires DVD Key
NO FLASHED DRIVE or JTAG EXPLOIT required
100% SOLDERLESS
USB 2.0 and ULTRAFAST LOADINGS
Avoid Overheating and >75% 3 Red lights of Death posibilites
Avoid tedious drive fw reflash
DVD/DL/Multigame compatible
Full upgradeable by USB/JTAG
Model 2: External OLED Control Panel for USB
HDD/Pendrive (No PC required)
OLED control panel
USB HDD/Pendrive supported
Supports ALL Motherboards
USB & Jtag upgrades
Easy Installation
As you can see model one uses a dongle to communicate with your PC
where you can control the device with a PC side app however, with this
model you can only read ISO's from your internal 360 harddrive.
Model 2 has a standalone OLED control panel so you do not require a PC
and it can also read ISO's from an external USB harddrive.
For more information on these two products please visit their official
websites. ** WARNING **
None of these devices have been proven to be real, order at your own
risk.
OpenPStore will soon be released. Currently 5 people have tested said OpenPStore. It reminds me of the hombrew browser for the wii which happens to be fantastic btw ;) . Keep up the hard work blipi!!
Hey people. I've just heard you posted this here, and I just said to
myself, let's post too.
Atm I'm working on OpenPStore, which is part of the JFW. I've been
working on it for many many hours, as all devs which are working on
JFW, and it is just disgusting to read people saying JFW is a fake.
I've seen pics of JFW running, not all of its features though, so it's
not fake. There is a whole team working hard every day to bring this to
you, and I've actually talked to all of them and I do know their work
is real.
Just for you to know, now it is 2 am where I live, I've been working
till now just to have it all ready for the beta test and not to delay
it anymore.
We want to verify everything is working without any problems before
realeasing it, to avoid things such as bricks or weird bugs. That's why
the beta and further release will take so long. So far it is all
progressing fine, and I do have proofs of, at least, my work.
Here I bring you 2 proofs of how hard we are working (OpenPStore).
1- We had a problem with a pre-made library to read .xml files (mxml),
which was solved by manually coding a new .xml parser.
xml_parser.h : http://pastebin.com/bqQr1YG5
xml_parser.c : http://pastebin.com/A7DsysUJ
(Don't expect to find any OpenPStore here, as it is only a .xml parser)
2- Final GUI design of OpenPStore (Not a pic of a ps3, but from a PC.
Though PS3 is exactly the same):
It will come in multiple colors, with an autochanger (to random color)
feature.
If you want to I can keep you updated.
JFW is real, and we are putting all our effort into it. Do not trust
any fake release/leak! I don't know if the brick thing is true, but
having seen all the work which has been done here, I would just trust
it and not mess around.
Nobody is going to brick nobody's console unless someone leaks the JFW.
And, even if it is leaked, if you don't use the leaked beta, you dont'
have to worry about anything. And ofcourse, the final release won't
have this anti-leak feature.
I also have to say thanks to everyone of you who do trust in us and
give us support, as support and opinions is our only pay back for the
work =)
Blipi
PS: If it was for me, I would translate JFW and it's homebrew to
English and more languages, but as I am not the only one who works in
this project, I don't know when English support will come or whether it
will come or not. Sorry.
PS2: For those claiming evidence... Beta will be here soon, just wait.
You cant trust us or not. I know what I'm doing, and I do know that it
is real.
I don't even have a ps3 to test OpenPStore too, and I have to keep
asking for testers. More than 5 people have already tried OpenPStore,
and every one of them could tell you that it is real.
Posted by admin on Monday, August 01 @ 02:06:35 EDT (131 reads)
(comments? | PS3/PS2 | Score: 0)
Not sure about master but the title did make me giggle a bit. What some are still calling "fake", it seems this firmware from the folks over at demonhades.org will soon prove to be real. Today, testers will begin a 2 week testing phase. If you think well hey, I'll find this firmware cause like everything else on the internet gets leaked. Think again, something is being done so the firmware won't work and might even brick the console. At least that's what is being "said". So sit tight and soon we can have a new firmware that could even be better than kmew's
* User-Spanish speaking (in Spanish beta)
* Internet Connection on the PS3 (not psn)
* Backward-Console PAL, NTSC FAT
* Game-Original 3.56 (not dispensable)
* Console with Firmware 3.41 or less
* Original game-PS2, PS1, PS3
* Backup of the above both PS3, PS2, PS1 (PS3 unpatched)
* Game store NPDRM 3.56 or 355 (not psone)
* Backup 341 / 355Kmeaw
* Linux live cd-USB Red Ribon
GROUP B - Later-Model PHAT's (no PS2 ability)
* User-Spanish speaking (in Spanish beta)
* Internet Connection on the PS3 (not psn)
* Console not backwards-PAL, NTSC FAT
* Game-Original 3.56 (not dispensable)
* Console with Firmware 3.41 or less
* Original game-PS2, PS1, PS3
* Backup of the above both PS3, PS2, PS1 (PS3 unpatched)
* Game store NPDRM 3.56 or 355 (not psone)
* Backup 341 / 355Kmeaw
* Linux live cd-USB Red Ribon
GROUP C - New PS3 Slim Owners
* User-Spanish speaking (in Spanish beta)
* Internet Connection on the PS3 (not psn)
* Console not backwards-PAL, NTSC Slim
* Game-Original 3.56 (not dispensable)
* Console with Firmware 3.41 or less
* Original game-PS2, PS1, PS3
* Backup of the above both PS3, PS2, PS1 (PS3 unpatched)
* Game store NPDRM 3.56 or 355 (not psone)
* Backup 341 / 355Kmeaw
* Linux live cd-USB Red Ribon
No word on their forums if they are going to start an ENGLISH BETA
release, but they do warn their BETA testers, that if anyone thinks of
LEAKING it, they have safeguards IN-PLACE to in-fact BRICK the LEAKER's
PS3 or ones that have INSTALL the LEAKed BETA, so be VERY CAREFUL if
you find any so-called LEAKED-BETAs out there, as we will most likely
being seeing soon some lame Youtube pages or other wannabe sites
suddenly appear and claim to have the release now that it is out to
selected few people.
Demonhades also announced on the forums the firmware developers
are aiming for a release date of October 1, 2011 once the 3
selected groups of 2 weeks of BETA testing is over and all the required
selected tests have been completed, and the final remaining bugs are
tracked down and removed by the teams of developers working on the JFW-DH
custom firmware release.
Posted by admin on Monday, August 01 @ 01:23:28 EDT (161 reads)
(comments? | PS3/PS2 | Score: 0)
To ProgSkeet or not to ProgSkeet, that is the question.. What is this you might ask? Lil-Jons' remix? Some tech porno? YES!! it's a chip to program(think infectus but on crack)! nand's & nor's galore :) You can even request a custom build. If you like to tinker with soldering and game consoles you must get one of these! Make some money, buy "bricked" wii's or PS3's off ebay. Downgrade firmware on a PS3 that someones brother updated and more!
ProgSkeet barebone PCB [Limited White
Edition]
ProgSkeet
is your one and only solution to your flashing needs. Whether it is
NAND, NOR or any other kind of non-volatile memory - just solder, plug
in and operate!
Blazing fast read/write speed!
Beside software-side updates, you can also expect hardware updates
powered by customer requests!
With a broad range of applications, such as EEPROM programming
(among others: Altera, Lattice FPGA/CPLD), Bad flash recovery, more
commonly known as "Unbricking" (Modems, video cards, cell phones, music
players) and plain serial programming (manufacture of your own device).
Supported devices include, but are not limited to: K9F1G08,
S29GL128, K8Q2815, HY27US08.
Industrial programmers often range in the EUR 1000+ range with
limited customer support. ProgSkeet can
compete with these programmers all the while maintaining low cost!
And always remember - for accuracy and speed, choose ProgSkeet!
RRP: EUR45.00 - 55.00
Posted by admin on Tuesday, July 26 @ 11:36:06 EDT (149 reads)
(comments? | PS3/PS2 | Score: 0)
OMG'z!!! It's, it's ummm well not much yet but happy times ahead (post vacation that is ; ) "QUOTE" Source
I’m going to be on vacations for 3 weeks. I just wanted to tell you
that PNM project will be stopped during this period. But, i’ve some
great news for you. I successfully dumped a 3.60 NOR flash using one of
the socket ! The second socket has been validated too. We are not far
from our main goal : “jailbreak again the PS3″ ! Here are some
snapshots : - host console with a new feature (NOR FLASH details…), -
PNM with a NOR Flash on Socket #1, - an extract of the 3.60 NOR dump as
a proof Cheers No_One
Posted by admin on Monday, July 25 @ 17:07:42 EDT (144 reads)
(comments? | PS3/PS2 | Score: 0)
For those of you that have purchased a USB Cobra(BUY ONE NOW! $35.30usd), a new cfw (to work with it) has been released! Looks like it is more compatible and can run games right from the disk icon and more "diskless" games.
Added compatibility with 3.55. Support for firmware 3.41 is
discontinued, since now all updates will be for 3.55.
In 3.55, Cobra keeps all the features of previous versions, adds the
ones listed below and also removes some of the annoyances of the
jailbreak exploit.
Please, follow the steps in the manual, you must install first Cobra
3.55 cfw.
- Added a new discless mode for PS3 backups in jailbreak format. This
mode will be activated automatically when you load a backup and there
is no disc inserted.
In this mode, games are loaded from disc icon, not app_home, although
app_home hack is still supported.
This mode has a higher compatibility than the app_home hack, and
smaller than discless PS3 isos.
- Added support for PS2 backups in iso format to the remaining
backwards compatible models (CECHA and CECHB).
- PS2 isos can now be played discless too.
- Fixed compatibility issue with GT5. If you still experience
problems, please delete installed game data from XMB and try again.
------DOWNLOAD NOW------
Posted by admin on Saturday, July 23 @ 20:46:55 EDT (145 reads)
(comments? | PS3/PS2 | Score: 0)
A new CFW is in the works! This one doesnt work on all PS3's so use the tool (check the source to download) to find out if it does. This has a list of all the "good stuff" and more. Can't wait till it's done!!!
Tutorial created by DeathHades.
This tutorial will teach you to how to know the base firmware
of your PS3 with a few steps and images.
The first thing you must need is:
- A PS3.
- MinVerChk
Here is the simple steps you need to follow:
1 – Copy the MinVerChk to your USB stick, the same way as if
it was an firmware upgrade.
2 – Insert the USB stick into the PS3.
3 – Start a firmware update like normal from XMB (Don’t worry, it will
not update!)
4 – It will shortly fail and display the Firmware Base Value
PERCENT OF VARIOUS SECTIONS
- Core central 100%
- Payload Cobra 60%
- Linux 95%
- Preloader 90%
- Categorias xmb 95%
- Manager TheGrid 25%
- TheGrid 100%
- Services Packs 0%
- OpenPStore 50%
-Return of the online (running)
-Update of keys (working)
-Spoof Version
-Disable devices
-Mounted units, several readers virtual
-Plugins level conbinacion buttons on the six
-Modification speedfun speed
-Multiloader (operating)
Dumper full-ram (running)
PSN-games license generator (operating)
-Hacked signature verification token QA (running)
-Reboot
-PSN access sysversion check “no spoof nor certs” (running)
Check-patching the original disks (operating)
-Activation of the 8th SPU
-Etc
Compatibility with games and applications using a DH-JFW 341v2
core, this does not mean not being able to play all over now without
patching.
The DH-JFW is compatible with games that include between 3.56 down,
including the current patched to 3.55
DH-JFW runs natively games until 3.56 (original disks) without having
to upgrade.
Psn-games that require npdrm 356, are also supported without upgrading
(the current cfw not give this support)
-No need for a valid signature on the executable (including loaders and
other files)
-Not going to make a port to 3.55 of this JFW DH, since it includes
much more than 3.55
-Support for peripherals is not licensed by sony in that medium 355 is
eliminated leaving them unused
-The only custom firmware can take the keys with a dual nand 3.6x
(programmer) such as PNM and that allows the custom appldr redirect to
another area of the ram and so does not remove the old
-Theme DHorg exclusive community that will change randomly each time
the console or ignite the user cambiéis
-More surprises:)
Posted by admin on Wednesday, July 20 @ 00:34:52 EDT (157 reads)
(comments? | PS3/PS2 | Score: 0)
Xbox360/Xbox: Xbox360 iXtreme LT+ v1.9 for ALL Drives
Wanna get the next features early for the beloved multiMAN? If so, do the following... "You can get the update via debug-update (L2+R2 at startup -> Update)." SIMPLE!!
* Added: Pulsing of selected entry/title in XMMB display mode
* Added: Display of embedded JPEG images in MP3 files for XMMB Music column News Source
Posted by admin on Monday, July 18 @ 14:12:37 EDT (110 reads)
(comments? | PS3/PS2 | Score: 0)
D-pad mapped to arrow keys , start=enter, select=backspace
new programs and games all launch-able from the start menu..
added games:-
another world
hitchhikers guide to the galaxy
ghouls and ghosts
metal gear
shinobi
and lots more also a few wolf 3d mods
emulators:-
Colecovision.. some launching problems , run as dos session
Fmsx (msx) (windows and dos versions)
x5200 (atari)
pc64 (com64)
I’ve set up dos based emus to launch from a run.bat so end user
can edit and add game to be run, if you have problems try running from
explorer, run, run as dos session.
also added:
ps3hax theme
usb support(no hot plugging)
a fake cd rom(folder) to copy file into (ps3 file manager or
ftp)
a windows based hex editor
so i think i am about done with it most 3d game lag.. but all 2d
and simple 3d work. running slow-Pentium fixed@4000 BUT you can bump
the cycles up as much as you want, but sound will suffer.
also i still cant get win32s to work on ps3 , works fine on pc ..
go figure.
DOWNLOAD----->
Posted by admin on Monday, July 18 @ 01:31:30 EDT (154 reads)
(comments? | PS3/PS2 | Score: 0)
Where did deank from multiMAN go?
No folks he isn't lost, just relocated to a "better" website. I'm not a fan of full page ad's but less drama over at http://www.ps3hax.net. Him and a bunch of other dev's have made a new home there.
Posted by admin on Sunday, July 17 @ 14:48:39 EDT (121 reads)
(comments? | Score: 0)
Introducing http://www.tortuga-cove.com
Id like to announce the opening of http://www.tortuga-cove.com . Yes it means turtles but that aside, this is turning out to be a great resource. One of these resources would be for Retro game covers for the PS3. The ones for the PS3 emulators that everyone has grown to love. In addition to this, http://www.tortuga-cove.com also does news for the scene with many ppl to keep the news updated. Show them some love, take a look ;)!! Tell them I say caw! :)
Posted by admin on Sunday, July 17 @ 12:49:44 EDT (134 reads)
(comments? | Score: 0)
While we're enjoying our summer and working on the next release of FSD
we have decided to release the source code for the latest public build
of FSD, RC 2.1. We know this is what the community has wanted for a
long time and decidded today is a good day to share. We want other devs
to feel free to build upon our work to make the Alternative Xbox
Dashboard even better. This is not the Complete source as some things
needed to be witheld for legal reasons but this is the bulk of it:
JPizzle over at elitemodscene made a post about a hack for the xbox360. You might be thinking omg haxx!! but this is more for us lazy folk that dont want to get up to change the game disk. This however has inspired a thought that one could make an external dvd drive to cut down on heat with the old phat 360's. Just add an x360key to that for added fun ;) . Check out the video, very hard core hardware hacking to follow, enjoy "The Ben Heck Show"
Posted by admin on Tuesday, July 12 @ 14:21:15 EDT (165 reads)
(comments? | Score: 0)
PS3/PS2: PS3 multiMAN ver 02.02.00 UPDATE (20110711-180500) (1.76 MB)
*Changed Font
properties/functions for all modes * Max number of
games+AVCHD in game modes 960 (was640) * Max number of entries
per XMMB column 2650 * Changed character limit
for XMMB Settings column[selected option] to 36 (was 32 - now
German/French fit) * Moved [selected option]
to the far right * Freed more than 20MB of
RAM (and reallocated 10MB of itto increase max number of games/xmmb
entries) * Included all languages
(with latest versions posted bytranslators until 2011-07-11 16:06EET) * Added back Dutch * Added back Portuguese BR * This update should fix
"Not enough memory for webbrowser" which some users experienced
Posted by admin on Monday, July 11 @ 10:32:57 EDT (370 reads)
(comments? | PS3/PS2 | Score: 0)
Thanks for a better translation wiisixtyfour!! by
wiisixtyfour on Sunday, July 10 @ 00:08:23 MDTHere's a better
translation: Flynn sent me this text explaining this protection that is used by
the Cobra, I hope it will open the eyes of those interested in
reversing the dumps.
COBRA RTOC TRICK EXPLAINED
The Cobra JIG has several protective measures to ensure that your code
cannot be used correctly even if your code could be dumped.
This trick in the RTOC register is first used for this purpose in
addition to hinder analysis. The RTOC registry is initially stored in
the battery to keep the RTOC of lv2 and power it back later:
At this point we have to explain what the DELTA OFFSET is. The DELTA
OFFSET is a method used in x86, in its original moments in the creation
of computer viruses, to be able to calculate the memory address in
which we are in the sea of bytes in RAM.
In the original moments a computer virus didn't know where it was
pulled into an executable, depending on the executable it could be an
initial site or another, the DELTA OFFSET was invented for it.
The DELTA OFFSET can be used in any system, the procedure is:
- Using the register that indicates the current execution address (or
the next depending on the system)
- Reducing the size of the previous code we use the value obtained from
the register.
Knowing this, and taking for example the x86 processor where the EIP
register can not be read directly, the trick was invented to make a
call to a "subfunction" which is simply the following line to the call:
call x
x:
pop eax
The instruction call in x86 saves the top of the stack the address of
the next instruction to itself. Thus using pop draw from the top of the
stack this value, and stored in eax for example, and having the memory
address where we only subtract the above would be missing and we have
the exact calculation.
On the PowerPC we can use this trick using the equivalent instruction
BL (BRANCH LINK), which jumps to a "subfunction" but before you save in
the LR register the following address to BL.
bl _delta_offset
_delta_offset:
At this point we see the trick used for the creation of the RTOC of
cobra at this time. If you look both r0 and RTOC are passed to 0:
li %r0, 0
li %rtoc, 0
Subsequently, given the value 0x11DE0 to RTOC:
oris %rtoc, %rtoc, 1
ori %rtoc, %rtoc, 0x1DE0
A r0 is given the value 0x920:
oris %r0, %r0, 0
ori %r0, %r0, 0x920
R0 is subtracted from the value of RTOC:
subf %r0, %r0, %rtoc
Unlike the x86 on PowerPC the LR register can be read directly with
mflr instruction, we put in RTOC the value obtained by the delta offset:
mflr %rtoc
To calculate the delta offset subtract final instructions executed
before the delta offset, which were 4, or 16 bytes:
addi %rtoc, %rtoc, -0x10
Finally we add the value of r0 at the end of the delta offset RTOC,
storing the result in the RTOC and this already takes RTOC suitable for
this hook, :) :
add %rtoc, %rtoc, %r0
The cobra has the RTOC stored in the 3 stack arguments that the hook
received:
You call the function of the charges where the first argument will
check for command 0x8202 (a special command to the usual, :)) :
bl cobra_syscall_sm_shutdown
After doing what you need on the cobra, the battery recovers the
original RTOC, like the arguments the hook received, it executes the
original instruction that was overwritten in the syscall entry 379 (in
this case) to have our hook, and call the original syscall lv2: