UPDATE 04-02-2020
These tools have been superseded by the BG Toolset
** www.** ** www.ps3xploit.net > Domain no Longer owned by team** (NEW URL = http://ps3toolset.com) > Domain no Longer owned by team** (NEW URL = http://ps3toolset.com > Domain no Longer owned by team** (NEW URL = http://ps3toolset.com)/bgtoolset/











UPDATE (OCT. 11 2018) - With the release of OFW 4.83 portions of PS3Xploit have been patched, The team is looking at workarounds, STAY ON 4.82, DO NOT UPDATE TO 4.83 AT THIS TIME:
IMPORTANT UPDATE (MARCH-2019) v3.0.1 was released providing support for 4.84 HFW (a new hybrid firmware that restores PS3Xploit for 4.84 OFW user's (See Link to HFW)
dI will start this off with NO you can not jailbreak your PS3 SuperSlim Console's (seems to be a popular question), however that does not mean the Ps3Xploit Team, (bguerville, esc0rtd3w, habib & W), has not been hard at work, with this new release of Ps3Xploit v2.0.. In this release all the tools (IDPS Dumper, Flash Dumper & Flash Writer) have seen significant improvements and now performing the task such as installing a Custom Firmware on your 4.82 OFW PS3 (with flash writer) has been made even easier and very stable thanks to the team's new checks implemented and progression of the exploit. The Flash and IDPS dumper are also much improved. All the details are provided below please read all the spoiler and tabs before asking any questions.
-STLcardsWS​

PS3Xploit_Tools_v2.jpg


PS3Xploit 2.0 Tools Now LIVE!!

  • Included Tools
    • 4.XX IDPS DUMPER
    • 4.XX FLASH DUMPER (USB Edition)
    • 4.XX FLASH DUMPER (HDD Edition)
    • 4.82 NOR/NAND WRITER (USB Edition)
    • 4.82 NOR/NAND WRITER (HDD Edition)
    Ps3Xploit Tools Changelogs
    v2.0
    • Freeze issues - Fixed
    • Occasional bad dumps - Fixed
    • No beeps & shutdown. Replaced by a graceful ROP chain exit & return to browser. This gives the opportunity to the user to dump after patching & validate the dump with littlebalup's py checker. As long as the user does not shutdown/restart, it's still possible to recover from bad patching.
    • Support for usb port 0,1,6 + sd/cf/ms cards.
    • Multi firmware support on all dumpers (4.10+) & DEX support on 4.81.
    • HDD editions for all dumpers & flash writer where a picture file placeholder is used for read/write operations.
    • Javascript refactoring for performance & efficiency.
    • **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) will host the 2.0 update, no need for 3rd party sites.

    v1.0 (Thanksgiving 2017 Release)
    • Supports Direct OFW to CFW patching for All Phat and 2xxx Slim (minver 3.56 Dec 2010 and lower)
    • the NOR/NAND writer will just copy 3Mb of CoreOS data to both ros0 & ros1 in the flash memory.
    • There is only one version released for 4.82. The same hex patch file can be used on nor & nand.
    • It's as safe as possible, with a check for usb device & patch file making the exploit hang instead of corrupting flash if file is not found.
    • In case of corruption (extremely rare but could always happen), it's only a partial brick because no per console info ever gets erased so a hardware flasher could still be used if ever a recovery reboot was impossible



  • Frequency Asked Questions

    Will this jailbreak my SuperSlim?
    • NO,The Flasher Writer Tool is not Supported on the SuperSlim and a some very late Slim models, Howeever, PS3Xploit has a strong possiablity to eventually evolve into a HEN style exploit (that aspect will take some additional development.)

    Which PS3Xploits Tools are Compatible with my PS3 Console?



    • 9199-7853467153566ba1908c9b32aa331bb5.jpg.png
      Check this sticker on the back of your PS3 to view your PS3 Model.
      Flash Writer Model Compatibility (PHAT):
      • CECH-A01 (NAND)
      • B (NAND)
      • C (NAND)
      • E (NAND)
      • G (NAND)
      • H (NOR)
      • J (NOR)
      • K (NOR)
      • L (NOR)
      • M (NOR)
      • P (NOR)
      • Q (NOR)

      All DUMPER (FLASH/IDPS) & FLASH WRITER TOOLS are Supported for this model.


    • 9200-4361b3a6a7359ffe524f966d4eeca4bc.jpg.png
      Check this sticker on the back of your PS3 to view your PS3 Model.

      ***IMPORTANT***
      You must pay very close attention to your PS3 SLIM Models depending on when the PS3 SLIM was manufactured will determine if your console can install CFW (Flasher Writer Compatibility).

      For the 25XX series or even if your unsure about any of the models it is reccomnded you run the minverchk PUP >> (DOWNLOAD) & (How to use Minverchk) its a simply utility that show the factory installed firmware on your ps3 and for the CECH-25XX model if the utility shows 3.56 or lower you are compatible but if it shows 3.60 and higher that means your are NOT compatible to use the Flash Writer (CFW enabler for 4.82 CFW)

      • Flash Writer Model Compatibility (SLIM):
        • 20XX NOR
        • 21XX NOR
        • 25XX NOR (3.56 minver. and Lower)
      • NOT COMPATIBLE (SLIM):
        • 25XX NOR (3.60 and Higher)
        • 3XXX NOR


      All DUMPER (FLASH/IDPS) TOOLS are Supported for this model.



    • 9203-5ab5229a0530b0274c59419c8b4f8987.jpg
      Check this sticker on the back of your PS3 to view your PS3 Model.
      • FLASH WRITER NOT COMPATIBLE (SUPERSLIM):
        • 4XXXA EMMC
        • 4XXXB NOR
        • 4XXXC NOR
      All DUMPER (FLASH/IDPS) TOOLS are Supported for this model.


    Where can i find official info and details?
    • Official Website (Exploit Hosting / Info) @ ** http://www.**ps3xploit.com >Doma...no Longer owned by team** (ps3xploit.me =new)
    • Official Ps3Xploit Forum (Support/News/Info): @ http://www.psx-place.com/forums/PS3Xploit/
    Warning: Known Limitation
    • Due to the lack of proper checks after exiting the ROP chain, it is possible in some cases to obtain a success message despite an operation failure. For instance, if you choose a path where no device is plugged in, a dumper page will still display a success message despite the fact the dump save could not work. This limitation has already been addressed, the added operation checks will be part of an update to these PS3Xploit tools which will be released in the coming weeks, that update will be final, no more will come after it


  • FLASH Dumper's Help


    • PS3 4.xx NAND/NOR/EMMC FLASH DUMPER v2.0
      All PS3 models supported
      All 4.10+ CEX CFW/OFW supported
      4.81 DEX CFW/OFW supported


      IMPORTANT NOTES:
      • It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically....
      • So in short, never use the browser or use a homepage you cancel before running the exploit!
      • It is recommended to set your homepage temporarily to the exploit page you wish to use to ensure there is no memory flooding messing with the exploit initialization stage.
      Steps:
      1. Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
      2. Open the browser. The exploit page will load automatically. Choose your dump path option.
      3. Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
      4. Trigger the exploit by pressing the dump button.
      5. On success, validate your dump with the py checker tool.

    • PS3 4.xx NAND/NOR/EMMC FLASH DUMPER - HDD EDITION v2.0

      All PS3 models supported
      All 4.10+ CEX CFW/OFW supported
      4.81 DEX CFW/OFW supported


      IMPORTANT NOTES:
      • It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically....
      • So in short, never use the browser or use a homepage you cancel before running the exploit!
      • It is recommended to set your homepage temporarily to the exploit page you wish to use to ensure there is no memory flooding messing with the exploit initialization stage.
      Steps:
      1. Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
      2. Open the browser. The exploit page will load automatically. Download the dump.jpg placeholder file to your PS3 System Storage using the provided link as instructed on screen.
      3. Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
      4. Trigger the exploit by pressing the dump button.
      5. On success, retrieve the dump file from the PS3 XMB Photo section, rename it appropriately to dump.hex or whatever & validate your dump with the py checker tool.


    Usage Tips:
    • Try using a LAN connection or a solid WiFi connection during exploitation. A weak signal can cause problems.
    • If the exploit takes more than 5 minutes to work, reload page, browser, or restart console and try again.
    • ]If you are using a LAN connection and experience network issues, make sure all cables to router are in working order.




    • PS3 OFW 4.82 NAND/NOR FLASH WRITER v2.0
      ***** IMPORTANT DETAILS BELOW -- AVOIDING A BRICK *****
      WARNING: USE ONLY THE PROVIDED flash_482.hex AS IS. DON'T PATCH IT OR MODIFY IT OR YOU WILL BRICK *****
      • Verify flash_482.hex file on a flash drive and in the selected USB slot!
        • flash_482.hex MD5: d05be52f8d21700052fbd1fc0174acae
      • DO NOT USE ON CFW (Custom Firmware) (Only Supports OFW)
      • DO NOT USE ON PS3 Models 3xxx/4xxx (aka late Slim or Superslim models), you would brick those consoles.
      • ON SLIM 2xxx Consoles, always use MinVerChck PUP to ensure that the minimum installable firmware version is < 3.60, if ever the minimum version is >3.56, using the flash writer would partially brick your console!
      • USE ONLY ON 4.82 OFW

      IMPORTANT NOTES:
      • It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to ps3 javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded due to previous browsing then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically..
      • So in short, never use the browser or use a homepage you cancel before running the exploit!
      • It is recommended to set your homepage temporarily to the exploit page you wish to use to ensure there is no memory flooding messing with the exploit initialization stage.

      Steps:
      For best results with flash writer, here are the recommended steps.
      1. Install OFW 4.82 twice on the console you wish to flash to avoid the potential corruption error during CFW installation.
      2. Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
      3. Open the browser. The exploit page will load automatically. Choose your path option.
      4. Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
      5. Trigger the exploit by pressing the patch button.
      6. On success, load the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) flash dumper, dump the flash memory & validate it with py checker tool. Do NOT restart the console if ever the validation tool gives you errors/warnings on both ros0 & ros1 or you risk to partially brick your console. Report your problem instead.
      7. When you are satisfied with the dump validation, restart your console & install a 4.82 CFW.


    • PS3 OFW 4.82 NAND/NOR FLASH WRITER - HDD EDITION v2.0
      ***** IMPORTANT DETAILS BELOW -- AVOIDING A BRICK *****
      WARNING: USE ONLY THE PROVIDED flash_482.jpg AS IS. DON'T PATCH IT OR MODIFY IT OR WILL BRICK *****
      • YOU
      • Download flash_482.jpg file to PS3 System Storage!
        • flash_482.jpg MD5: d05be52f8d21700052fbd1fc0174acae
      • DO NOT USE ON CFW (Custom Firmware) (Only Supports OFW)
      • DO NOT USE ON PS3 Models 3xxx/4xxx (aka SuperSlims / Late Slim models), you would brick those consoles.
      • ON SLIM 2xxx Consoles, always use MinVerChck PUP to ensure that the minimum installable firmware version is < 3.60, if ever the minimum version is >3.56, using the flash writer would partially brick your console!
      • USE ONLY ON 4.82 OFW

      IMPORTANT NOTES:
      • It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to ps3 javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded due to previous browsing then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically..
      • So in short, never use the browser or use a homepage you cancel before running the exploit!
      • It is recommended to set your homepage temporarily to the exploit page you wish to use to ensure there is no memory flooding messing with the exploit initialization stage.
      Steps:
      For best results with flash writer, here are the recommended steps.
      1. Install OFW 4.82 twice on the console you wish to flash to avoid the potential corruption error during CFW installation.
      2. Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
      3. Open the browser. The exploit page will load automatically. Download the patch file flash_482.jpg to your PS3 System Storage using the provided link on screen.
      4. Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
      5. Trigger the exploit by pressing the patch button.
      6. On success, load the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) flash dumper, dump the flash memory & validate it with py checker tool. Do NOT restart the console if ever the validation tool gives you errors/warnings on both ros0 & ros1 or you risk to partially brick your console. Report your problem instead.
      7. When you are satisfied with the dump validation, restart your console & install a 4.82 CFW.

    Usage Tips:
    • Try using a LAN connection or a solid WiFi connection during exploitation. A weak signal can cause problems.
    • If the exploit takes more than 5 minutes to work, reload page, browser, or restart console and try again.
    • ]If you are using a LAN connection and experience network issues, make sure all cables to router are in working order.

  • PS3 4.xx IDPS DUMPER v2.0

    All PS3 models supported
    All 4.10+ CEX CFW/OFW supported
    4.81 DEX CFW/OFW supported

    IMPORTANT NOTES:
    • It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically....
    • So in short, never use the browser or use a homepage you cancel before running the exploit!
    • It is recommended to set your homepage temporarily to the exploit page you wish to use to ensure there is no memory flooding messing with the exploit initialization stage.
    Steps:
    1. Open the browser & browse to the **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new) website, go to the page of the exploit you need. Set the current page as browser homepage. Don't launch the exploit initialization. Close the browser.
    2. Open the browser. The exploit page will load automatically. Choose your dump path option.
    3. Press the exploit initialization button & wait until initialization succeeds. If it fails, follow the refresh/reload instructions on screen.
    4. Trigger the exploit by pressing the dump button.
    5. On success, check your idps dump with an hex editor.

Source Code & Downloads:
NOR/NAND/EMMC/IDPS 4.xx Dumpers v2.0 Update
NOR/NAND 4.82 Flash Writer v2.0 Update
flash_482.hex (already included in the Flash Writer 2.0 archive) MD5: d05be52f8d21700052fbd1fc0174acae
MinVerChck PUP


IMPORTANT UPDATE (MARCH-2019) v3.0.1 was released providing support for 4.84 HFW (a new hybrid firmware that restores PS3Xploit for 4.84 OFW user's (See Link to HFW)

Exploits now hosted @ **ps3xploit.com >Domain no Longer owned by team** (ps3xploit.me =new)
Official Support Forum: psx-place.com/forums/PS3Xploit/
 
Last edited:
Now that it's been reported what happens next
Nothing. What are you expecting us to do about it?
A hacking tool containing webkit exploits being detected as possible malware is not entirely surprising.

If you want to download the files you must add an exception in your AV protection rules OR use your phone to download the files & setup your http server OR use the hosted version instead of the local files.
 
@bguerville @esc0rtd3w @habib
I made an updated tutorial for Version 2.0, would there be any chance you could add this to the post somewhere?
Not to call MrMario's video bad but some info in there is a little bit outdated, like him saying the system will shut down by itself; which as per version 2 it doesn't.
Worked about 2 weeks on the video, hopefully I got everything right though :)

*I'll refrain my primal urge to post the link until I get a green light, feels stupid asking is it is okay but also just shamelessly posting the link at the same time*
 
@bguerville @esc0rtd3w @habib
I made an updated tutorial for Version 2.0, would there be any chance you could add this to the post somewhere?
Not to call MrMario's video bad but some info in there is a little bit outdated, like him saying the system will shut down by itself; which as per version 2 it doesn't.
Worked about 2 weeks on the video, hopefully I got everything right though :)

*I'll refrain my primal urge to post the link until I get a green light, feels stupid asking is it is okay but also just shamelessly posting the link at the same time*
You are right, the video wad made for 1.0 & some things are not correct anymore.
Why don't you just post yours here in this thread & we may add it to the OP later. ;)
Or you can create your own video tut thread, it's all up to you.
Thanks for asking our opinion & for taking the time to make a vid. ;)
 
I'll just leave it here.
If there are any errors that could brick a system tell me and I'll take the video down, I do not feel like I'd do anyone a favor leaving misinformation online ;)
If it is up to snuff you can add it the the OP if that'd benefit it, not to say I'll also scream in happiness :D
 
I'll just leave it here.
If there are any errors that could brick a system tell me and I'll take the video down, I do not feel like I'd do anyone a favor leaving misinformation online ;)
If it is up to snuff you can add it the the OP if that'd benefit it, not to say I'll also scream in happiness :D
No problem at all.
If the vid is found satisfactory, it will be added to OP with proper crediting. Give us just a little time to review it.. ;)
 
if understand it good it has only access to ram wich COULD be an
an opening for an metlrd2 exploit.
im not forcing anyone to do something like ps3xploit they already done an good job

but here is some early speculation : (dont cheer early pls)
some on the lines of somebody disables metlrd2 before disabling metlrd1

can an dev talk more about metlrd 2 and how it works
 
if understand it good it has only access to ram wich COULD be an
an opening for an metlrd2 exploit.
im not forcing anyone to do something like ps3xploit they already done an good job

but here is some early speculation : (dont cheer early pls)
some on the lines of somebody disables metlrd2 before disabling metlrd1

can an dev talk more about metlrd 2 and how it works
I really wish someone talks more about metldr 2 as we have little info about it
 
First of all, thanks to everyone for making this possible.

Question, what is the best way to install ofw twice? I already ended up with a ****** up NAND on a CECHG (ROS / COREOS issues) letting me believe it was a genuine YLOD whilest it wasnt...

And yes, i was too confident / arrogant to believe i didnt need a proper backup :-)
 
@habib , @bguerville and @esc0rtd3w check this thread replies specifically replies from page 4 to 7 read them carefully and read devs replies more carefully as they have some good hints that might help you guys on this project

Here is the link:
https://www.psxhax.com/threads/metldr-lv2-dumper-for-ps3-4-75-to-4-78-retail-consoles-by-cmx.179/

Nothing but bullshit... Its common there. take any information there very lightly......

These are the real -deal devs here, you can search their names and see all the projects and things they have been associated with, you start doing that with some of the guys who are "devs" there you will see a big difference.. psxhax will give those developer badges very loosely,,

2016 it was posted and nothing come from his "hints"...
 
I really wish someone talks more about metldr 2 as we have little info about it
Nobody talks about metldr2 because nobody has anything more to say about it than what has already been published on the subject 6 years ago by hackers like marcan, mathieulh among others.

But as you asked, I will give you my own understanding of the status, although the research is not mine & it's better to refer to what the hackers wrote at the time rather than my own assessment. Still here goes..

Nobody has found a way to break the new metldr2 chain of trust so far & bruteforcing ecdsa is out of the question using today's computers.

Since metldr2 the use of all loaders is encapsulated into lv0 which means that in theory only bootldr & lv0 could be used to break the chain of trust. (check the chain of trust diagrams on wiki).
The runtime secure boot system responsible to check the integrity of any executable to be loaded in isolated spu is hardware based, tamper resistant & non updateable. bootldr is also non updateable in metldr2 consoles hw revisions iirc because its integrity is checked by the runtime secure boot system before being loaded into isolated spe0. As far as I can make out, that would leave lv0 (responsible for setting up the hardware) as only possible attack vector to try loading a modded kernel. However remember that bootldr contains a per console key which is used for lv0 encryption purposes, that link is also a problem with metldr2 consoles.
Few have tried to defeat the new chain since this research, a couple of pieces of the puzzle were found but nobody managed to defeat it entirely, at least not officially.
FYI the team is not working on this at all but rather on exploiting the kernel at runtime then working our way down. That's why nobody should expect us to enable cfw installation on 3xxx/4xxx.
In fact nobody should expect any jailbreak at all from the team, if it happens great, if it doesn't it would avoid much disappointment on your end.

http://www.psdevwiki.com/ps3/Boot_Order
http://www.psdevwiki.com/ps3/Dumping_Metldr
 
Last edited:
@bguerville
that went pear-shaped fast.
BTW do you think that the ps3xploit tools will help one such if they have the knowledge of achiving an jailbreak?

and what does the exploits give access to?

Don't misunderstand me. We want to get the jailbreak done, the motivation is there BUT we will not claim that something or other will get done for sure.
We have always said as much from the start.

The ps3xploit tools will not really help. It's not their function.
However the 2 exploits the tools use give everyone a base to start attacking the kernel. That definitely helps a great deal.
 
REad the damn threads, lol, i get so sick and seeing the same damn questions over and over. If you guys can't take the time to read. Then these guys can't take the hours and days weeks and months to develop these exploits. Do the 5 minute task of reading its fundamental and might even learn something . Nothing wrong with asking questions but the same type of question over and over and over and over and over.

Read first then ask questions :) . (this goes to all)
 
@bguerville what kind of exploit(s) is needed to run unsigned codes on 3k and 4k consoles, will a userland exploit suffice on its own ?? Or will we still need a kernel exploit ??
If a userland exploit was sufficient we would already have unsigned code execution.
You would need a lv2 kernel exploit, a lv1 exploit & possibly a spu exploit too depending on the situation.
 
4.82 OFW - Never previously exploited
CECH-A1 Trying Exploit 2.0 (Nand Dump and Write)

*The Nand_hdd option fails to save the link.*
"An error occurred (80711008)"

I've scoured this thread and I can't seem to find any help with my particular model. I have only gotten "successful" dumps using Nand, Nand hdd doesn't even let me save the link for the photo and I can't find info on moving the pic another way or if just copying it over from usb is an option. I also don't get any system reboots like I see in so many Nor videos.

The 239 mb dump.hex it writes to the usb fails check every time using PS3DumpChecker. Python just closes the window right away and doesn't write a log.

"Error on 1 of 105 Checks" with R0S0 showing the error.
12:04:03 PM : Hash check Started!
12:04:03 PM : Hash check for 009.02 ROS0 Hash Started... Result: FAILED!
Actual data: MD5 Hash: 8ED20C654ACF584A71FBD8BB7038710D

I presume this means something went wrong and should not continue, but I have because why not brick a collectors item? xD

All the faq's and tutorials are focused at Nor and usually lead me into dead ends because they seemingly act differently. But if I'm wrong about the hex check and continue to write the flash using Nand, I have varying results:

- Flasher instantly shows "success" and am asked to dump again to verify only to basically get the same check result. Reboot and no ability to CFW update

- Flasher shows loading bar for about 40% before success and hex check shows the same result after another dump and reboot

- Flasher loads to 100% then fails asking to refresh. I now clear cache and reboot and get one of these 3 results.

If someone could point me in the right direction I would appreciate it.
 

Similar threads

Back
Top