modrobert writes: "Dospiedras1973 over at elotrolado.net (Google translated to English) has posted a method how to downgrade PS3 fat and slim models with original firmware v3.70 to kmeaw CFW v3.55 by changing the NOR flash contents. Here's a brief summary of the steps involved; dump the NOR flash using a hardware flasher (Eg. NORway on Teensy++ 2.0, Progskeet or Infectus), modify the dump to enable factory service mode, write the modified binary back to NOR flash, downgrade to CFW v3.55 kmeaw."[/p]
Code:
Hello everyone, i finally got it, we have a downgrader for slims consoles , this time a bit different that i did with fat models, i made it by the two flashers, progskeet and teensy ++,dope
ÂÂÂÂWe need:
ÂÂÂÂfat or slim console with nor updated to 3.70 “DO NOT TRY With ANOTHER VERSION”Solution to write and read the nor of the console ( flasher progskeet or teensy + +)
ÂÂÂÂhxd program (which I use to edit hex)
ÂÂÂÂFlowRebuilder v.4.1.3.2
ÂÂÂÂa cold beer (this is important)
ÂÂÂÂHttp://pastebin.com/yuvJ5Leh Downgrade.bin
ÂÂÂÂFirst we dump our NOR with a flasher, the file size must be “16,777,216 bytes” no byte more or a byte less, take several to be absolutely sure of what you do..get the dump “example jakemcallister.bin”and we have to get it in flowrebuilder to make it readable,the option is called bytereverse dump and extract
ÂÂÂÂwe do it and we will have a file but the extension will be bin.REV open it with the hxd and take out our personal data of the console EID, BOOTLOADER, CSID and METLDR
ÂÂÂÂno need to put more data
ÂÂÂÂWe get it with the following way:in this case we get our METLDR in our prepatched image for downgrade attached in this tutorial
ÂÂÂÂinside the folder where flowrebuilder had placed our.rev also has created another folder called “nameofthedump.EXT”in there are our personal files of our console and we need to get some to place em inside the pre-patched image that i attached
ÂÂÂÂOpen the hxd and open downgrade.bin and the metldr file that is inside the folder asecure_loader, we pick the tab on the hxd metldr and copy all the HEX content to get in inside the downgrade.bin
ÂÂÂÂpress control + g and write “820?thats the position of the metldr right click on the first line of the position 820
ÂÂÂÂAnd choose “paste writing” and in the same way we introduce the other ones
ÂÂÂÂthe files to get in are
ÂÂÂÂ:METLDR: offset“810? size “E960?
ÂÂÂÂBOOTLOADER_0 Offset“FC0000? size “40000?
ÂÂÂÂEID: Offset “2F000? size “10000?
ÂÂÂÂCISD: Offset“3F000? size “800?
ÂÂÂÂthen we take the downgrade.bin with the saved changes and we get in flowrebuilder with the option bytereverse dump and extract
ÂÂÂÂThis time the program will give us a error, but is a normal error, in fact is okay and will give us a file called downgrade.bin.REV
ÂÂÂÂAnd thats the file you have to get in in the “flash” console
ÂÂÂÂif all went well at writing ,turn on the console and you will see in the screen press the ps button or in English push ps button, DONT PRESS ANYTHING, turn off the console and put it in factory service mode, once done we need to put the correct file system for 3.55 lv2diag of jaicrab without reader and a special cfw
ÂÂÂÂlv2diag:http://www.logic-sunrise.com/telecharge … icrab.html
ÂÂÂÂcfw: http://pastebin.com/03MFDLGV turn onthe console with the usbstick with these two files in the right usb port (in the last) of the console and it will shut down for 10 / 15 minutes, turn on the console without any usb connected to verify that you did it correctly it will take you to xmb,
ÂÂÂÂIf all went well turn off the console and put your lv2diag
ÂÂÂÂFILE2 of this pack:http://pastebin.com/gGETcxMR
ÂÂÂÂthe console will turn on for 20 seconds will turn off itself and CONGRATULATIONS you have your console in functional 100% and kmeaw cfw 3.55 100%
ÂÂÂÂThanks to
ÂÂÂÂ:D iGiTaLAnGeL (Tester with progskeet)
ÂÂÂÂGlevand & mfw builder team (cfw)
ÂÂÂÂNDT (Assistant) is a very good person
ÂÂÂÂJaiCraB (lv2diag without reader)
ÂÂÂÂRobs1 (my guide with the nor flash)
ÂÂÂÂEussNL (his great support in the wiki that I use every day PS3DEVWIKI.COM)
ÂÂÂÂDefyboy (for creating ps3devwiki)
ÂÂÂÂTo the whole channel darkps3 from irc-hispano.org for their support and many hours of testing we have hit hard mother****ers!
ÂÂÂÂDemonHades (because if you had not post on your website with the lie you said about me, I had not met DigitalAngel or uf6667and these two helped me a lot)
ÂÂÂÂand finally to the people who asked me in private to place a donate paypal button
ÂÂÂÂgreetings and from now on i will resume my work with the dual nand and that dump 3.6x that gives me so many problems hehehe
ÂÂÂÂIve updated the position of METLDR that was misplaced offset 810 ” e960?size