- 精华
- 0
- 帖子
- 495
- 威望
- 0 点
- 积分
- 531 点
- 种子
- 12 点
- 注册时间
- 2007-3-8
- 最后登录
- 2024-9-24
|
发表于 2010-11-17 10:05 · 广东
|
显示全部楼层
本帖最后由 khan.lau 于 2010-11-17 10:26 编辑
momo1st 发表于 2010-11-17 10:02
那个 是3.41伪装3.5吧?
还是贴一小段出来给你吧....
ps3狗开发(64796806)
6:39:52
hyper visor被逆向了
ps3狗开发(64796806)
6:40:19
零售版机器 EEPROM里的产品模式是0xFF
ps3狗开发(64796806)
6:40:28
EEPROM读写已经可以了
ps3狗开发(64796806)
6:41:05
把产品模式换掉0xFF后。。。不会检查flash1的文件完整性
ps3狗开发(64796806)
6:41:46
就是说,基本上,EEPROM改0xFF成别的,然后用解密的固件的文件写入flash即可实现降级升级
ps3狗开发(64796806)
6:42:05
当然3.50以后可能会有别的措施防止这个~
ps3狗开发(64796806)
6:45:13
0x18000 - DM (Dispatcher Manager)
ps3狗开发(64796806)
6:46:45
0x600B - Read EEPROM
I have got read access to EEPROM of Update Manager through DM and tested it with PSGroove
I read PRODUCT_MODE from it successfully, PRODUCT_MODE = 0x000000FF
The service expects one additional parameter: offset (4 bytes)
The service accepts only some predefined offsets
The service returns the specified offset and the value at this offset
0x600C - Write EEPROM
Writting to EEPROM of Update Manager is also possible through DM
Tested this service successfully with QA flag
0x6010 - Check Integrity
This service checks integrity of important files stored on /dev/rflash1, e.g. lv0 or lv1
The service is used e.g. by System Manager
When product mode is NOT 0xFF then check is skipped !!!
|
|