Hacking Question Is boot0/1 console specific?

  • Thread starter Thread starter Bst22322
  • Start date Start date
  • Views Views 7,834
  • Replies Replies 11

Bst22322

Active Member
Newcomer
Joined
Jul 24, 2018
Messages
38
Reaction score
9
Trophies
0
XP
638
Country
United States
I have my original rawnand backup back when I used hekate 2.3(?)
It did not have the option to dump boot0/boot1 at the time
I have saved my fuses using choidujournx and currently am at 6.0.1
Can I downgrade using my rawnand backup without boot0/1? I thought these were firmware specific.
If so, then how do I create boot0/1 files for firmware 4.1.0?
 
Yes boot0/1 are firmware and console specific
I believe you can download 2.3 firmware and use choidujournx to downgrade the same way you upgraded.
So I'd want to downgrade to fw 4.1.0, then backup boot0/1, then restore backup of 4.1.0 using the newly dumped boot0/1 files?
 
Let someone who knows for sure answer this to but it is my understanding that you can downgrade and that would downgrade your boot files allowing you to get the correct boot files
 
So I'd want to downgrade to fw 4.1.0, then backup boot0/1, then restore backup of 4.1.0 using the newly dumped boot0/1 files?
Downgrade in ChoiDujour. Backup boot0/1. If you want, you can then restore 4.1.0 via your backup, or just upgrade again using ChoiDujour. What is your end goal?
 
  • Like
Reactions: Bst22322
Only boot0 have some console specific data the boot1 is the same for all the consoles with the same firmware. You can recreate the 2.3 boot0 with a donor boot0 of this firmware and your actual boot0. In the offset 0x180000 are all of your console keyblobs and in the offset 0x450 the keyblob of the actual firmware.
 
  • Like
Reactions: hippy dave
Downgrade in ChoiDujour. Backup boot0/1. If you want, you can then restore 4.1.0 via your backup, or just upgrade again using ChoiDujour. What is your end goal?
I'm just trying to prepare for the eventual warm boot exploit. Restoring my backup or not is trivial, I just thought you could not downgrade using choidujournx without boot0/1
If I can downgrade without boot0/1 files I am all set
 
Raugo is correct, ChoiDujour doesn’t touch the console unique part of BOOT0 and downgrading to your original firmware and then backing up is a good idea but having any backup of BOOT0 is better than no backup!
 
  • Like
Reactions: Bst22322
The issue with boot 0/1 is when restoring a nand backup, but downgrading with a "system update" will create the boot 0/1s needed for that version if I understand it correct. Someone can correct me if I am wrong
 
  • Like
Reactions: Bst22322
From my experience as i did a restore two days ago.

Restoring the NAND without restoring Boot0/1 will cause your system to crash on boot.
 
  • Like
Reactions: Bst22322
The issue with boot 0/1 is when restoring a nand backup, but downgrading with a "system update" will create the boot 0/1s needed for that version if I understand it correct. Someone can correct me if I am wrong
Choi only replaces the pkg1 part of Boot0, the keyblobs are left alone
From my experience as i did a restore two days ago.

Restoring the NAND without restoring Boot0/1 will cause your system to crash on boot.
this is true if on a different firmware version, Boot0 contains the pkg1 firmware that's supposed to run during boot and that changes in many firmware updates, if those don't match the current installed firmware that's on the rest of the NAND, it absolutely will not boot.
 
  • Like
Reactions: Bst22322
How does one use another persons boot1/0 mine was curropted and used someone elses and doesnt boot, i have all my biskeys
 

Site & Scene News

Popular threads in this forum