PS3 4.85 Flash Writer Released (CFW PS3 Models Only) - Now go from 4.85 OFW to 4.85 HFW to a 4.85 CFW

It looks like the 4.85 landscape is starting to take shape now as developer's around the scene have been updated the homebrew, utilities and tools that require updates (not all things require updates) and now the PS3Xploit Team released one of the missing pieces. The Flash Writer for 4.85 HFW has now arose and now you can make the jump from 4.85 OFW >> 4.85 HFW >> Execute Flash Writer >>> Install a 4.85 CFW. This release (utility) is ONLY for PlayStation 3 models that can install a Custom FirmWare, if your model can not install a CFW then look at PS3HEN as the next best alternative to cfw, which the team has an update around the corner as well (stay tuned for that soon), but back to the Flash Writer, If your are new to the tool that is executed from the PS3 Internet Browser, it simply provides those cfw capable models with the ability to install a Custom Firmware after the tool has done its magic to your console's internal flash. However, you must follow all instructions for a clean installation to avoid any issues during the process on the fully softmod exploit..

ps3xploit-logo.png

FLASH WRITER v2.0.2 - 4.85 HFW SUpport


  • Frequently Asked Questions


    Is my PlayStation 3 Model Compatible for Custom Firmware (cfw) Install & Which Flash Writer does my console need (NOR or NAND)?


    18530-18c0504e4fef01a250e320326a2b2cb1.jpg.png
    Flash Writer PS3 Model Compatibility (PHAT):
    • CECH A01 NAND
    • CECH B NAND
    • CECH C NAND
    • CECH E NAND
    • CECH G NAND
    • CECH H NOR
    • CECH J NOR
    • CECH K NOR
    • CECH L NOR
    • CECH M NOR
    • CECH P NOR
    • CECH Q NOR
    • Note this covers all FAT MODELS....
    18529-494151f41ac9a8423b8ef05fe718d583.jpg.png
    Flash Writer Model Compatibility (SLIM):
    • 20XX NOR
    • 21XX NOR
    • 25XX NOR (3.56 and Lower)
    • How do i know for sure if my PS3 Model is compatible ?
    • You must have a PS3 Console that has a Factory Firmware of 3.56 and below. To check, its easy with this simple tool for OFW, Download minverchk PUP Then place the .pup file on a FAT32 USB Flash Drive in a PS3/UPDATE folder (create path if needed) Now on the PS3 XMB goto Setting ->> System Update >>> Update via Media Storage Once shown on the list select the PUP and install, shortly after there will be a message showing the factory firmware the console was shipped,
      For this we want 3.56 and below. ANYTHING HIGHER THEN 3.56 IS NOT ABLE INSTALL A CFW,. Sorry this will not work for your console, but you can use PS3HEN (Homebrew Enabler) possible for running homebrew and other CFW like features for those nonCFW models.,

    PlayStation 3 Console's - NOT COMPATIBLE


    (SLIM Models not compatible for CFW installs):

    • 25XX NOR (3.60 and Higher Factory Firmware Installed, check w/ minverchck)
    • 3XXX NOR
    • THESE MODELS CAN USE PS3HEN

    424.jpg
    (SUPERSLIM Models not compatible for CFW installs):
    • 4XXXA EMMC
    • 4XXXB NOR
    • 4XXXC NOR
    • THESE MODELS CAN USE PS3HEN

    .
    Can I install a CFW before 4.85, such as Rebug 4.84 or an earlier CFW?

    • Yes, however you must Toggle QA Flag. Once the Token is activated you have the ability to then freely jump CFW versions. (see below for details)
      • How do I Toggle QA Flag?
      • When on a CFW download & install >>> QA TOGGLER (Standalone), (Note: Will just show a black screen then reboot the PS3 and returns to xmb. A Restart is Required. After toggling QA, cfw syscalls will be disabled (meaning your CFW patches will be disabled until the next boot, so a reboot is required after the Toggler exits back to the XMB.) Additional Info about Q/A flag can be seen here ( & also @ PS3Devwiki)

    Should i use the "999 Downgrader" vs "Toggle QA" to install a different CFW from an earlier firmware?
    • NO, installing the "999 downgrader" PUP can cause various issues like on a 3.56 minver console, it can brick the console, simply just Toggle the Q/A Flag (see above question) and play it safe and is so simple to move from CFW versions (up and down from version to version) once toggled (and you only have to do it your console ONE time with togging Q/A Flag and its set for lifespan of console)

    What is the basic purpose of the Flash Writer & Flash Dumper Tools Release?
    • The Flash Dumper is to get a backup of the NAND, NOR, and eMMC chip
      • Recommendation perform a dump of the internal flash before exploiting, in-case of problems or a bad install a clean backup will be helpful for reviving a console and for other means. Having a clean backup on file is good practice, more then likely will never need it but can be helpful if you in a spot. Warning never share your backups in public as they contains SENSITIVE information about you and your console.
    • The Flash Writer is to jailbreak your console. (Adding a patch to OFW to allow CFW installation)

    Do I have to setup my own web server or can (has) someone host this exploit?
    • You can use **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) unless the site is e experiencing slowdown issues on server, then you can download local files using dropdown menu on top on the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website.

    Where can i find the latest 4.85 CFW?

    Where can i find PS3 Homebrew?

    The console shut down and beeped when using the exploit, however I'm getting an error when trying to install cfw? (provided by @lord3490)

    • There are a couple of possible reasons for that:
      • 1. Did you make sure you flashed the correct file (nand/nor)? See q/a above
      • 2. Try different 4.85 CFWs and make sure the md5 is correct after copying to fat32 thumb drive.
      • 3. Try a different USB thumb drive or reformat it.
      • 4. Install HFW 4.85 two times in a row then apply the patch using the PS3Xploit flash writer & finally install a 4.85 CFW. That should always solve the issue.
      • 5. As a last resort, make a backup and format internal HDD (I just read that solved the problem for one user).

    Should I install Custom Firmware (CFW) or PS3HEN on my PS3 Console?

    • A: The answer depends on your console, if your a listed model above can install Custom Firmware, then go that route. As that is the best exploit on the PS3, however the nonCFW models listed above PS3HEN is a powerful homebrew enabler that will allow for many PS3 Homebrew to run and contains other CFW like features, but it has limitations not seen on CFW so the better option is CFW if your model can install. See listed models above

    Do i need to install 4.85 HFW or can i do this from 4.85 Official firmware (OFW)?
    • You must install 4.85 HFW first, In the past or to be more precise v4.82 OFW only we could use the PS3Xploit Flash Tools directly from OFW, since that time Sony pushed a patch (released in v4.83 OFW) to restrict the execution of the PS3Xploit Tools, but developer's ( @Joonie ) stumbled on a way to inject those file back into OFW and thus HFW (Hybrid Firmware) was born which could be installed on a unmodified PS3. This simply re-injected the hole used in 4.82 OFW. Now since we are on 4.85 currently, we have a 4.85 HFW ready to go and that is what is needed to execute the PS3Xploit Tools (so be sure to install that prior to using), as the Official firmware 4.83, 4.84, 4.85 and beyond will restrict PS3Xploit Tools from OFW directly. HFW is the bridge and could get patched in the future (we are not sure why it has not yet) but was not patch on the previous firmware update of 4.85. Stay tuned what will 4.86 bring?

    What should i do if we see a future firmware update?
    • DO NOT UPDATE until developer's have investigated the firmware for any changes or potential patches that have been made to restrict Homebrew/Exploits.


  • What does the Flash Writer do?
    The Flash Writer (once executed) will provide the ability to install a CFW afterwards. (model must be compatible)

    4.85 Flash Writer Help
    4.85 HFW Only Supported

    WE NO LONGER SUPPORT THE 4.84 WRITER, AND RECOMMEND UPDATING TO 4.85 HFW (Hybrid Firmware)!

    IMPORTANT WARNINGs
    • USE THE PROVIDED flash_485.hex/flash_485.jpg AS IS.
    • ***** DON'T PATCH IT OR MODIFY IT OR YOU WILL BRICK *****
    • DO NOT USE ON CFW (Custom Firmware) (Only Supports HFW)
    • DO NOT USE IF MINVER CHECK REPORTS 3.60 OR HIGHER
    • DO NOT USE ON PS3 Models 3xxx/4xxx (aka SuperSlims / Late Slim models) YOU WILL BRICK THOSE CONSOLES!
    • USE ONLY ON 4.85 HFW
    • Verify flash_485.hex file on a flash drive and in the selected usb/card port.
    • Make sure to use TRIANGLE and save flash.jpg to HDD first if using HDD option!
    • flash_485.hex/flash_485.jpg MD5: 2D74B066E7453E6B1336E36C410FB1EB


    INSTALLATION PROCESS - Please Read Carefully :
    .
    • For best results with the flash writer, here are the recommended steps.
      • Install 4.85 HFW twice on the console you wish to flash to avoid the potential corruption error during CFW installation.
      • Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
      • Open the browser. The exploit page will load automatically. Choose your path option or download the flash_485.jpg file if you use the hdd edition.
      • Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
      • Trigger the exploit.
      • On success, load the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) dumper, dump the flash memory & check it with py checker tool. Don't restart if ever the validation tool gives you errors/warnings in both ros0 & ros1 or risk a partial brick.
      • Restart your console & install a 4.85 CFW.


    Usage Tips:
    j
    • Try using a LAN connection or a solid WiFi connection during exploitation. A weak signal can cause problems.
    • If the exploit takes more than 5 minutes to work, reload page, browser, or restart console and try again.
    • If you are using a LAN connection and experience network issues, make sure all cables to router are in working order.


    Additional Warning:
    f
    • Due to the lack of proper checks after exiting the ROP chain, it is possible in some cases to obtain a success message despite an operation failure. For instance, if you choose a path where no device is plugged in, a dumper page will still display a success message despite the fact the dump save could not work. This limitation has already been addressed, the added operation checks will be part of an update to these PS3Xploit tools which will be released in the coming weeks, that update will be final, no more will come after it.

  • What does the Flash Dumper do?
    • The dumper provides a dump of your PS3 Flash, which is a good idea to do before you start exploiting to have a clean dump handy. They can be useful if an error would ever occur and can help revert bricks with right hardware/software.
    Flash Dumper Help
    4.10 - 4.85 Firmware Supported

    For best results with the flash dumper, here are the recommended steps.
    .
    • Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
    • Open the browser. The exploit page will load automatically. Choose your dump path option or download the dump.jpg file if you use the hdd edition.
    • Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
    • Trigger the exploit.
    • On success, check your dump with the py checker tool.

    Usage Tips using Flash Dumpers:
    .
    • Try using a LAN connection or a solid WiFi connection during exploitation. A weak signal can cause problems.
    • If the exploit takes more than 5 minutes to work, reload page, browser, or restart console and try again.
    • If you are using a LAN connection and experience network issues, make sure all cables to router are in working order.

    Additional Warning:
    Due to the lack of proper checks after exiting the ROP chain, it is possible in some cases to obtain a success message despite an operation failure. For instance, if you choose a path where no device is plugged in, a dumper page will still display a success message despite the fact the dump save could not work. This limitation has already been addressed, the added operation checks will be part of an update to these PS3Xploit tools which will be released in the coming weeks, that update will be final, no more will come after it.

Additional Resources / Downloads:

Exploit Site @
:
**ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new)
Official Support & Help @ Ps3Xploit Forum: via psx-place.com
 
Last edited:
It seems I have managed to do it.

Just had a bit of fear but once I took the first step I have managed to go all the way to installing QA and Rebug Toolbox.

Now just to learn how to use everything new!


I need some help please. I can't seem to find any straightforward instructions on how to go from OFW to HFW to CFW in 4.85. I need to try do this completely offline as my internet in not stable. I have done all my due diligence by running MinVerChck and physically checking the serial no. I know I have a CFW model that is a L (NOR).

So far what I have gathered is:
1. I install HFW_4.85.1_PS3UPDAT.PUP from a USB by renaming it to PS3UPDAT.PUP
2. I need to run a flash dumper, for which I downloaded from GitHub flash-dumper-master. I found this site that helps me understand which folders I need to place all the files: https://gbatemp.net/threads/guide-ps3-4-82-cfw-installation-for-dummies.491117/
3. a) Similar to 2. above, I run a flash writer, for which I downloaded from GitHub flash-writer-master.
b) I also have NOR_NAND_writer_release_2.0.2_PS3Xploit, so I will most likely use this writer
4. I now can run REBUG_4.85.1_LITE_55173e651a5aa10d9aab9127e6e79e25_PS3UPDAT.PUP from a USB by renaming it to PS3UPDAT.PUP.

I have no idea of how to run a .pkg so do not know how to set the QA Flag as I have Habib-QA_Toggle-4.21+(standalone).pkg.334.v1.0_brewology_com.pkg.

I also have REBUG_TOOLBOX_02.03.03.MULTI_.16.pkg and have no idea what it is for.

I have about 20+ tabs open in my browser and can't seem to get simple instructions on how to do this so any help would be greatly appreciated.
 
Hey guys, using a FAT CECHG04 (NAND) model and a few weird things are occuring after hours of trying: the NAND Flash Writer is 296MB and when exploit is complete and I write to flash it completes in a split second and no files were written. Tried it on USB000, USB001 and USB006 but I'd like to be sure which USB port is which on my model. I have two USB ports at the bottom of the console when standing vertically. See my pic, the USB is in the top one.
 

Attachments

  • 20200224_213339.jpg
    20200224_213339.jpg
    1.3 MB · Views: 114
Hey guys, using a FAT CECHG04 (NAND) model and a few weird things are occuring after hours of trying: the NAND Flash Writer is 296MB and when exploit is complete and I write to flash it completes in a split second and no files were written. Tried it on USB000, USB001 and USB006 but I'd like to be sure which USB port is which on my model. I have two USB ports at the bottom of the console when standing vertically. See my pic, the USB is in the top one.
You don't use that nand file to flash your ps3. Nand dump is just in case you brick your console,so you can unbrick it with flasher. You only need hex file to do the exploit.
 
I had a guy message me for help, his original issue was 8002f281. I directed him to some no-bd firmware, but somehow he ended up installing the 4.86OFW update. My question is would the flash writer work on 4.86? I'm going to tell him to wait until everything has been updated, but I was just curious.

Sent from my LM-Q720 using Tapatalk
 
E996E566-55BC-4CC9-B08A-4AAFF3723AF4.jpeg
I had a guy message me for help, his original issue was 8002f281. I directed him to some no-bd firmware, but somehow he ended up installing the 4.86OFW update. My question is would the flash writer work on 4.86? I'm going to tell him to wait until everything has been updated, but I was just curious.

Sent from my LM-Q720 using Tapatalk
There you go.
 
Let's point out the obvious. My question was since the kernel didn't change would the tool even really need to be updated? It's all good, though.

Sent from my LM-Q720 using Tapatalk
we are retiring the v2 writer, so all further flash writing will be directed to BG Toolset
** www.** ** www.ps3xploit.net > D... (NEW URL = http://ps3toolset.com)/bgtoolset/

4.86 patching support will be available soon, once we have a standard CEX CFW to use coreos patch from

Hey guys, using a FAT CECHG04 (NAND) model and a few weird things are occuring after hours of trying: the NAND Flash Writer is 296MB and when exploit is complete and I write to flash it completes in a split second and no files were written. Tried it on USB000, USB001 and USB006 but I'd like to be sure which USB port is which on my model. I have two USB ports at the bottom of the console when standing vertically. See my pic, the USB is in the top one.

i would also advise using new toolset mentioned above to dump your NAND, if you are on 4.86 or lower
 
we are retiring the v2 writer, so all further flash writing will be directed to BG Toolset
** www.** ** www.ps3xploit.net > D... (NEW URL = http://ps3toolset.com)/bgtoolset/

Where can I find instruction on how to install CFW with this awesome toolset?
Thank you.
 
I read this thread 3x times.
Can I download CFW from this tool directly?
I don't understand where can I choose which CFW I want to install with this tool.

Sorry, i'm new to ps3 jailbreak.
Thank you
To install a CFW is needed to write a file in a flash chip of your PS3
That file needs to be created by copying the data from the flash chip of another PS3 running a standard 4.86 CFW (not rebug CFW's)

The problem is... at the time im writing this doesnt exists any standard 4.86 CFW (unless someone released one in the last hours and i missed it)... so that file doesnt exists yet
Also, they wants that file to be the most generic posible, it should be the same file included in some tools like the "pyps3tools"

So in plain words... they are trying to organize it in the better way posible, the only way to do it right now is by rushing a bit, but thats not good... they are trying to avoid rushing ;)
 
just wanted to ask would it be possible to create a recovery update file or somekind of os stability checker that might be able to tell if the file system's still in good possition or database needs to be rebuild etc or even be able to perform these.
Just a thought.
 
just wanted to ask would it be possible to create a recovery update file or somekind of os stability checker that might be able to tell if the file system's still in good possition or database needs to be rebuild etc or even be able to perform these.
Just a thought.
Hmm i dont think, the PS3 firmwares triggers the warning about restoring filesystem usually (not always) inmediatly after a firmware crash
Is like in linux when you turn off the PC without "unmounting" the filesystem, at the next boot the operative system detects that it had an "inproper shutdown" and pushes you into a filesystem check sequence
Is just linux forces you to do it... but the PS3 allows you to bypass it
Bypassing it is bad, it really needs to be made to keep the filesystems without problems

So... in some way the PS3 is a bit stupid... and we need to help it by starting that "restore filesystem" manually from time to time, just incase
I use to do it inmediatly before installing a new firmware because i know there is an intermediate step in the firmware installations where the contents of the PUP (firmware installer) are extracted to the internal hdd
And you know.. if the hdd have some problem and you copy files "on top" of the problematic areas the thing cant go well :D
There are other steps of the firmware installation procedures where that extracted files are checked (to identify this kind of problems or file corruptions), but you know... is better to take our own prevention measures because we dont know how much smart (or stupid) are those procedures

--------
The rebuild database doesnt matters much though, is used as an intermediate "index" to display stuff in XMB
When the PS3 boots it reads the database files (instead of scanning the whole hdd contents because this would take lot of time and would delay the boot time)
When there are problems in the database you will have mistmatching info in between what you see in XMB and what you really have installed in hdd
You know... maybe you installed something but is not displayed in XMB ?... thats when you need to enter recovery and "rebuild database"

Personally, i use to do the "restore flesystem" and then (after a reboot) the "rebuild database", this way i know in step 1 im fixing the posible problems (and deleting or restoring the damaged files)... and in step 2 im indexing the valid files to the database
After that everything should work and look fine, incase it doesnt we are in problems (the damned hdd betrayed you again)
 
Last edited:
Hmm i dont think, the PS3 firmwares triggers the warning about restoring filesystem usually (not always) inmediatly after a firmware crash
Is like in linux when you turn off the PC without "unmounting" the filesystem, at the next boot the operative system detects that it had an "inproper shutdown" and pushes you into a filesystem check sequence
Is just linux forces you to do it... but the PS3 allows you to bypass it
Bypassing it is bad, it really needs to be made to keep the filesystems without problems

So... in some way the PS3 is a bit stupid... and we need to help it by starting that "restore filesystem" manually from time to time, just incase
I use to do it inmediatly before installing a new firmware because i know there is an intermediate step in the firmware installations where the contents of the PUP (firmware installer) are extracted to the internal hdd
And you know.. if the hdd have some problem and you copy files "on top" of the problematic areas the thing cant go well :D
There are other steps of the firmware installation procedures where that extracted files are checked (to identify this kind of problems or file corruptions), but you know... is better to take our own prevention measures because we dont know how much smart (or stupid) are those procedures

--------
The rebuild database doesnt matters much though, is used as an intermediate "index" to display stuff in XMB
When the PS3 boots it reads the database files (instead of scanning the whole hdd contents because this would take lot of time and would delay the boot time)
When there are problems in the database you will have mistmatching info in between what you see in XMB and what you really have installed in hdd
You know... maybe you installed something but is not displayed in XMB ?... thats when you need to enter recovery and "rebuild database"

Personally, i use to do the "restore flesystem" and then (after a reboot) the "rebuild database", this way i know in step 1 im fixing the posible problems (and deleting or restoring the damaged files)... and in step 2 im indexing the valid files to the database
After that everything should work and look fine, incase it doesnt we are in problems (the damned hdd betrayed you again)
Its just that many new users do not really go all that to restore filesystem and database rebuilding stuff.
Just like minver
it might be nice to have an os stability checker for damages and orphan files lying around.
And Label complusory for all users new/old for HEN or CFW
 

Featured content

Trending content

Back
Top