PS3 PPPwn?

  • Thread starter Thread starter Nakamichi
  • Start date Start date
  • Views Views 2,366
  • Replies Replies 3
  • Likes Likes 2

Nakamichi

Well-Known Member
Member
Joined
Dec 10, 2021
Messages
1,396
Reaction score
1,476
Trophies
3
Age
38
XP
5,037
Country
Germany
No there's only one way to beat Metldr2 and there is one guy who is gonna DPA a superslim eMMC retail unit
Everything is locked away inside Lv0 since 3.60+ so the chain of trust has not been defeated and so far we only got as far as getting a Superslim with a factory fault tested on hackable units.
 
No there's only one way to beat Metldr2 and there is one guy who is gonna DPA a superslim eMMC retail unit
Everything is locked away inside Lv0 since 3.60+ so the chain of trust has not been defeated and so far we only got as far as getting a Superslim with a factory fault tested on hackable units.
what is it DPA and factory fault in superslim?
 
what is it DPA and factory fault in superslim?
I'm a layman as well, but it sounds like they're using Differential Power Analysis (DPA) to physically "disassemble" the encryption procedure, and eventually decrypt part of Superslim's bootchain, Metldr2. Decrypting Metldr2 will allow breaking through the other security levels using a set of commands (bootstrap?) to gain Return-Oriented Programming (ROP) code execution (e.g., Fusée Gelée exploit on Switch), or maybe overwrite it, if it's stored in writeable memory.

https://www.psx-place.com/threads/meltdr2-decryption.31497/

https://www.psx-place.com/threads/wait-why-cant-we-jailbreak-3000-systems.18778/page-2
 
  • Like
Reactions: LPpiton

Site & Scene News

Popular threads in this forum