HELP PS3 downgrade with Teensy Pinging forever .

Hi guys i have hard time downgrading two PS3 motherboard model are DNY-001, JSD-001 both are with OFM 4.70. I solder Teensy++ 2.0

with 3.3v volt regulator programed with Downgrade Tool (PS3) i solder all wire triple checked and measure with multimeter all

connection are good. I used cable from old Parallel ATA cable 15cm long. I powered up console (green light) wait 10-20sec and then

hook up usb to teensy, next start NORway.py v.0.6 and Pinging... and noting happen. This is the case on both console. The JSD-001

console when i assembled show black screen i thin is bricked but why? Can some one help please.
 
Last edited:
Hi guys i have hard time downgrading two PS3 motherboard model are DNY-001, JSD-001 both are with OFM 4.70. I solder Teensy++ 2.0

with 3.3v volt regulator programed with Downgrade Tool (PS3) i solder all wire triple checked and measure with multimeter all

connection are good. I used cable from old Parallel ATA cable 15cm long. I powered up console (green light) wait 10-20sec and then

hook up usb to teensy, next start NANDway.py v.0.6 and Pinging... and noting happen. This is the case on both console. The JSD-001

console when i assembled show black screen i thin is bricked but why? Can some one help please.

And it is better to connect the teensy to your computer before to power up the console. This way tristate is setted to GND before console boot. You can also jump Tristate to GND directly using wire.
 
Thanks for fast respond. My mistake i use NORway.py. So if i understand correct i should solder one wire from tristate to GND right?
 
After 3min of Pinging... give this error

Traceback (most recent call last):
File "C:\Program Files (x86)\Downgrade Tool (PS3)\NORway.py", line 707, in <mo
dule>
n.ping()
File "C:\Program Files (x86)\Downgrade Tool (PS3)\NORway.py", line 86, in ping

val = self.readbyte()
File "C:\Program Files (x86)\Downgrade Tool (PS3)\NORway.py", line 53, in read
byte
return ord(self.read(1))
TypeError: ord() expected a character, but string of length 0 found
Press any key to continue . . .


I try with NORway v0.7 is the same.
 
Thanks for fast respond. My mistake i use NORway.py. So if i understand correct i should solder one wire from tristate to GND right?

First, update your Norway.py to the latest release v0.7 and reprog your teensy with the latest norway.hex as well. I'm seeing your are using v0.6.
Everything is there: https://github.com/hjudges/NORway.
Direct download : https://github.com/hjudges/NORway/archive/master.zip

Then, you can solder a wire between tristate to GND. This way you are sure the southbridge will not wake up and disturb your flash memory during dump/write process.

Edit: and ensure you installed prjc serial drivers and python correctly:
NORway_README.txt said:
Latest prjc drivers: https://www.pjrc.com/teensy/serial_install.exe
 
Last edited:
i try everything and nothing happen.

First i connect usb and start norway.py
Then connect power cable and press power button.

Tomorrow i will try to resolder all connection.
If nothing happen again i will reinstall my windows.
 
I patched dump isntall Lv2diag.self and Rogero_V3.7_PS3UPDAT.PUP in FSM.
And another problem when try to update to DARKNET CEX 4.70 V1.00 or OFW 3.55 it givs error (8002F) what can i do now?
 
I do everything that is described in this tut.
Then i patched dump with 3.55 from "NORway-master pacher.exe"
Write patched bump to console, enter in FSM with TEENSY++ put this file in USB FLASH "Lv2diag.self and Rogero_V3.7_PS3UPDAT.PUP".
And now i have 3.55 CFW Rogero.
I try to change "Rogero_V3.7_PS3UPDAT.PUP" with "OFW3.55_PS3UPDAT.PUP" but it won't install.


I try to update from FSM and from Recovery menu but give me an error.

Can you give me some tut or explain me what is new method.
How to patch dumb and upgrade to latest DARKNET?
 
You must exit FSM, then toggle qa, then install OFW3.55 via recovery.
And your blueray drive must be correctly connected to do any update.
 
If i'm understrand you good you are now on Rogero downgrader and in fsm. You need to get out of fsm.

here is solution from psx scene:
once in FSM:
1. put the rogero 3.7 pup file above and "file 1" on the thumb drive (not e3 card reader)
2. put the thumb drive with rogero 3.7 and file 1 (lv2diag.self (366 kb) into the right most usb slot.
3. power on ps3 and let it install the pup. will take 5-7 mins usually
4. once installed, take the thumb drive out and boot the ps3. it will take it prob 30 secs maybe to boot, this is normal. just verify it goes to the xmb.
5. just verify it boots. once you verify, turn the ps3 back off, and put "file 2" on the thumb drive by itself with nothing else on there.
6. put thumb drive with file 2 (lv2diag.self 202 kb)in the right most usb port on the ps3.
7. boot the ps3, and it will shut off by itself.
8. once it shuts off, take out the thumb drive and boot ps3 noirmally, you will have to go thru the welcome screen or w.e like as if it was brand new.
9. be sure bluray is hooked up.
10. install and run toggle-qa.pkg
11. do button combo while network setting is highlighted (L1 L2 L3 R1 R2 and down on the d-pad, and then go to debug settings and be sure to find and turn system update debug to ON.
12. once you got it toggle qa'ed and system update debug is ON, then install 3.55 OFW from recovery.
 
Thank you guys you are great everything went fine now i am on Darknet 4.70.

Now i try to dump my second console JSD-001.
When i check dumb it gives this errors. Can i fix this manually with Hexeditor or is totally bricked? When i try to start console it gives black screen and blue led on blu-ray is on.
sdk_version ✔
AuthID: N/A ✔
[DANGER]- C16ADBF51B3363738DF78D3ACEFB2802

spu_pkg_rvk_verifier.self ✔
AuthID: 1070000022000001 ✔
[DANGER]- D4C82AA2AED8BF0F3697F93823AB7E4B

spu_token_processor.self ✔
AuthID: 1070000023000001 ✔
[DANGER]- FD93EFD0E3AEBE59CD39AFB02682DD49

spu_utoken_processor.self ✔
AuthID: 107000004C000001 ✔
[DANGER]- EEBA7291AA021CB3DC5FAE84A6ECD1FF

sc_iso.self ✔
AuthID: 1070000020000001 ✔
[DANGER]- 70B725C067533068CA9D50ECCDDEE533

aim_spu_module.self ✔
AuthID: 1070000025000001 ✔
[DANGER]- 34B6FA8599F2515DA7579078E7F926E7

spp_verifier.self ✔
AuthID: 1070000021000001 ✔
[DANGER]- 70DAFD2BFC2402584586EDD13BCBEBC9

mc_iso_spu_module.self ✔
AuthID: 1070000037000001 ✔
[DANGER]- 01091C92D6CEFC83FD9C3389B36741EA

me_iso_spu_module.self ✔
AuthID: 1070000043000001 ✔
[DANGER]- 5A326CBF13D3B3442833AAA52FCCA518

sv_iso_spu_module.self ✔
AuthID: 1070000024000001 ✔
[DANGER]- 469360185538A8BB7B2D38570F584D7A

sb_iso_spu_module.self ✔
AuthID: 107000001F000001 ✔
[DANGER]- 7EDF2A6EE81148C66329073960D8EEA7

me_iso_for_ps2emu.self ✔
AuthID: 1070000058000001 ✔
[DANGER]- C2B1774CAAAE0E043AB76D3C67C3097E

sv_iso_for_ps2emu.self ✔
AuthID: 1070000059000001 ✔
[DANGER]- 4502F4222D8B2DE4981AEFE1F345A17E

default.spp ✔
AuthID: N/A ✔
[DANGER]- C91DB2EB1B6AD2D8BD920687C0EEFBA8

lv1.self ✔
AuthID: 1FF0000002000001 ✔
[DANGER]- 224BB011DB6B0FAD672C9BA6C043E69C

lv0 ✔
AuthID: 1FF0000001000001 ✔
[DANGER]- 9D86B23CFF6C1ED14218D829877B5208

lv0.2 ✔
AuthID: 1FF0000001000001 ✔
[DANGER]- A93A5086C018DE95A7228C5D5B499973

lv2_kernel.self ✔
AuthID: 1050000003000001 ✔
[DANGER]- 322D191C413EE9574BBC7D6AFB8C6441

eurus_fw.bin ✔
AuthID: N/A ✔
MD5: B5F54D9A11D1EAE71F35B5907C6B9D3A ✔

emer_init.self ✔
AuthID: 10700003FC000001 ✔
[DANGER]- BB4856221A61D14E6A43C3BF4B1EE043

hdd_copy.self ✔
AuthID: 1070000501000001 ✔
[DANGER]- 63F3759A3D00CC08B01A237821E2BC92


CELL_EXTNOR_AREA:
Header - [DANGER] - ����������������
SHA1 Header -[DANGER] - FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Unused Area -[WARNING] - Too long to display!
HD Model - ��������������������������������������������������� ✔
HD Serial - �������� ✔
Unused Area -[WARNING] - Too long to display!


00 / FF / Other Statistics:
18.60% ✔
11.23% [DANGER]
0.27%
[/WARNING][/WARNING]
[WARNING][WARNING][/warning][/warning]
 
Not sure, you need to check on ps3devwiki that some of this files are per console encrypted, if yes is 100% not fixable, if no then you have some small (really small) chance to fix this. You also need to find offsets for this files and change them with good ones in HxD. I know that Flowrebuilder can extract nor dumps, but i dont know that can merge extracted files back to dump.

If i understand good CELL_EXTNOR_AREA can be repaired but is also not easy..
 
if you see errors in the dump why did you flash it in the first place?!!!!!!
per console data is irreplaceable,
send it to trusted members here to have a look at it
 

Similar threads

Back
Top