1. KiiWii

    KiiWii Reporter
    Reviewer

    Joined:
    Nov 17, 2008
    Messages:
    12,331
    Country:
    United Kingdom
  2. arfgh

    arfgh GBAtemp Regular
    Member

    Joined:
    Oct 3, 2019
    Messages:
    279
    Country:
    Armenia
    hey there friends... just about retail and dex, and the others. Referring the little bin file with no notification we have for 7.55 i was able to make it works in all modes, dex, dev, kratos and retail just changing the Byte in the offset: 0000002F, you know the values. If you need the modified file to retail just tell me, but i dont think that you have problems on that.

    What i was unable to determine is the offset to compile it with our collective sdk, and it is a shame :( I have created kernel dump with dex, dev, and retail, and with a hex comparisson as @Leeful did suggest, i was not able to find it.... :( soooo a partial success for me, because i see retail without reboot, highly important.

    But the question is tha...t i am unable to determine if the stars options these modes show in the apps... if they throw some difference between them, do you know ? or all are basically same for us ?
     
    Last edited by arfgh, Apr 5, 2021
  3. Leeful

    OP Leeful GBAtemp Member
    Developer

    Joined:
    Sep 4, 2015
    Messages:
    1,560
    Country:
    United Kingdom
    Finally got a FULL (101MB) working kernel dump of 7.55 (thanks @KiiWii :)) and the method I mentioned earlier of finding an offset for a later FW works.:toot:

    Here is the method to find the correct offset for todex for FW 7.55:

    First open a copy of previous FW version dumps in a hex editor and go to the known GOOD offset you are trying to find for that FW.
    01-505.jpg 02-672.jpg 03-702.jpg
    (you will see that the offest value for each FW is 87)


    Then look for a common string of bytes before the offset you are trying to find. The longer the string the better!
    Search on each FW dump and make sure that there is only one instance of string. This is why it is better to have a long string because there is less chance of it appearing again further on in the file.
    04-505.jpg 05-672.jpg 06-702.jpg
    (the same string appears only once in FW 5.05, 6.72 and 7.02)


    Open the 7.55 kernel dump and search for the long string that is common in the previous FWs.
    07-755.jpg
    (Success! The string is found and it only appears once:toot:)

    Then highlight the 87 in the place it is an other FW versions after the string and the offset it shows in the bottom left of the screen is the one you are looking for.
    08-755.jpg

    The offset I found is 222898D and it is the same offset posted by zeco on twitter:
    https://gbatemp.net/threads/release...exploit-host-menu.579557/page-16#post-9428378

    This method may not work for all offsets but I have usually had good success in the past when looking for offsets on later FW versions.

    Hope some people will find this useful.:)
     
  4. arfgh

    arfgh GBAtemp Regular
    Member

    Joined:
    Oct 3, 2019
    Messages:
    279
    Country:
    Armenia
    ^^ wow well done !
    so the kernel dumper we had, was not working good ?
     
    Leeful likes this.
  5. Leeful

    OP Leeful GBAtemp Member
    Developer

    Joined:
    Sep 4, 2015
    Messages:
    1,560
    Country:
    United Kingdom
    No it wasnt good. The kernel dumper was only dumping 34MB when it should be 101MB.
    No wonder I couldn't find the offset I was looking for with an incomplete dump. LOL
     
    Last edited by Leeful, Apr 7, 2021
  6. Ghost_of_Tsushima

    Newcomer

    Joined:
    Mar 17, 2021
    Messages:
    34
    Country:
    Russia
    @Leeful

    Hello, Leeful! Thanks for your brilliant work and fantastic contribution to ps4 scene. Your hosts are the most popular ever, at least in Russia.

    Would you kindly add to your PS-Phive autoHEN function? Vast majority of people who updated to 6.72 are extremely nostalgic about its younger brother - PS-Phwoar and his fantastic unbeliavable autoHEN function. My buddies and I tried to add it into Phive examining how it was made in Phwoar but unfortunately we didn't manage to make it work properly.
     
    Last edited by Ghost_of_Tsushima, Apr 8, 2021
    Leeful likes this.
  7. Prb

    Prb GBAtemp Advanced Fan
    Member

    Joined:
    Nov 10, 2020
    Messages:
    570
    Country:
    United Kingdom
    Why not just use leeful's v10 ?
    It's not as pretty as ps-phive but you can use auto exploit only or auto exploit and hen
    Just a thought
     
    Leeful likes this.
  8. godreborn

    godreborn GBAtemp Legend
    Member

    Joined:
    Oct 10, 2009
    Messages:
    17,605
    Country:
    United States
    @Leeful that offset information reminds me of the game_ext_plugin.sprx of the ps3, which is for gameboot audio, its hex series is known, but it's not always at the same offset. it did change from 3.55 to 4.xx (the hex series, but that is also known), but you can easily patch the sprx by using the same series, then replacing it with something most likely found in IDA. the patched sprx I made on like 4.82 most likely still works on 4.87, because so little has changed between firmwares. though, I no longer use any modded files except for alphabetizing things, which is something I can't believe sony didn't know was the most used sorting mechanic in the world. I mean sort by creation date? wtf!? who's going to remember when they bought things and in which order?
     
    Leeful likes this.
  9. Ghost_of_Tsushima

    Newcomer

    Joined:
    Mar 17, 2021
    Messages:
    34
    Country:
    Russia
    Yes, I know that Leeful v10 is good. But Phive has more functions, better design and it appeared to have better success rate than v10. So our people like Phive way mooree than v10.
     
    Prb and Leeful like this.
  10. Prb

    Prb GBAtemp Advanced Fan
    Member

    Joined:
    Nov 10, 2020
    Messages:
    570
    Country:
    United Kingdom
    Couldn't agree more ps-phive is my goto menu for 6.72 leeful's master piece you just can't go wrong with it
     
  11. leonmagnus99

    leonmagnus99 GBAtemp Psycho!
    Member

    Joined:
    Apr 2, 2013
    Messages:
    3,678
    Country:
    Iraq
    just got the message "jailbreak failed" just by opening the browser (psphive).

    console shut itself off then, this is the 3rd time it happening.

    I'm on 6.72 , isn't this bad for the console and corruption?
     
  12. Danethos86

    Danethos86 Advanced Member
    Newcomer

    Joined:
    Jan 5, 2019
    Messages:
    62
    Country:
    United States
    I been using leeful an older version think its v6 not sure for long time on 6.72 and out 25+ boots maybe failed once or twice. I never tried newer ones is newer ones better or more stable then mira+hen 2.3b
     
  13. NoIdeaofAnything

    Newcomer

    Joined:
    Nov 13, 2018
    Messages:
    40
    Country:
    Austria
    Hi, two things.

    1.) Is it possible to automatically "click" the "system memory not enough" message when I open the site?

    2.) Is it possible to automatically load HEN when opening the site?
     
Draft saved Draft deleted
Loading...

Hide similar threads Similar threads with keywords - [Release], (ForPS4, Exploit