PS3 Question about how to get eid_root_key from nor dump

Discussion in 'General PS3 Discussion' started by Luisile, Apr 19, 2019.

  1. 278
    104
    72
    Luisile

    Luisile Member

    Joined:
    Feb 21, 2019
    Messages:
    278
    Likes Received:
    104
    Trophy Points:
    72
    Gender:
    Male
    Hi, time for my question. i have cech-2504b the not jailbreakable console. i can homever instal the hfw and make nor dump from it. It is posible to extraxt the eid root key from dump in format that it will work with ps3 hdd reader? i will do it only for backup for savegames that i can not copy to usb from xmb due to copyright issues. it is somehow possible? thanks
     
  2. 5,815
    5,437
    622
    sandungas

    sandungas Moderator Developer

    Joined:
    Dec 31, 2014
    Messages:
    5,815
    Likes Received:
    5,437
    Trophy Points:
    622
    Location:
    Babylon 20xxE series
    To extract the key is needed to run a PKG with a homebrew program that triggers an exploit
    In HAN is not posible to run homebrew so is not posible to dump the key :/
     
    Algol and pink1 like this.
  3. 1,581
    1,702
    297
    pink1

    pink1 Moderator Developer

    Joined:
    Feb 25, 2015
    Messages:
    1,581
    Likes Received:
    1,702
    Trophy Points:
    297
    Gender:
    Male
    I’ve never seen a way to dump the per console keys without having the system do it for you.
    I think you should be able to use the han file copier to backup the param.sfo from the save and remove the copy protected attribute then copy it back. After that the save should let you copy it to the usb.
     
    Algol likes this.
  4. 5,815
    5,437
    622
    sandungas

    sandungas Moderator Developer

    Joined:
    Dec 31, 2014
    Messages:
    5,815
    Likes Received:
    5,437
    Trophy Points:
    622
    Location:
    Babylon 20xxE series
    Hmmm, this should not work, because the PARAM.SFO is supervised by the PARAM.PFD
    The PARAM.PFD contains the hashes of the PARAM.SFO so is working like an anti-tampering protection, if you change a single bit of the SFO the whole savedata becomes invalid

    The way to do it in CFW is by removing the "copy protected" flag in the PARAM.SFO (this is the easy part)
    And after that you need to use the pfd tool tool released by flatz to force an "update" of the PARAM.PFD
    By using the "update" command the new PARAM.PFD is rebuilt and the new hash of your new PARAM.SFO is added in it

    But the tool needs the EID key of your PS3 :/
     
    Algol, pink1 and DeViL303 like this.
  5. 278
    104
    72
    Luisile

    Luisile Member

    Joined:
    Feb 21, 2019
    Messages:
    278
    Likes Received:
    104
    Trophy Points:
    72
    Gender:
    Male
    Thats not what i expected but ok thanks for answer
     
  6. 278
    104
    72
    Luisile

    Luisile Member

    Joined:
    Feb 21, 2019
    Messages:
    278
    Likes Received:
    104
    Trophy Points:
    72
    Gender:
    Male
    So hen is out. It somehow possible to do this on hen?
     
    sandungas likes this.
  7. 278
    104
    72
    Luisile

    Luisile Member

    Joined:
    Feb 21, 2019
    Messages:
    278
    Likes Received:
    104
    Trophy Points:
    72
    Gender:
    Male
    same question again..
     
  8. 5,772
    2,846
    497
    atreyu187

    atreyu187 Retired Old Hunter Moderator

    Joined:
    Sep 29, 2014
    Messages:
    5,772
    Likes Received:
    2,846
    Trophy Points:
    497
    Gender:
    Male
    Occupation:
    Scholar of Byrgenwerth
    Location:
    Cainhurst Castle
    Home Page:

    The best I can suggest is trying Rebug Toolbox and see if it works. Not near a system to test myself. That's the only app that comes to mind that isn't firmware dependant. I recall someone saying they were able to get it in another thread.

    @Joonie @habib


    Edit

    Never mind just checked one needs lvl1 access which is still protected using HEN and I don't forsee this happening anytime soon if at all. If this was possible we would have access to Linux for HEN. So if you ever see Linux supported for HEN then you will have access to eID root key. Sorry no such luck yet bud.
     
    Last edited: Jun 13, 2019
    Algol likes this.
  9. 68
    16
    37
    Kinglol

    Kinglol Member

    Joined:
    Mar 15, 2018
    Messages:
    68
    Likes Received:
    16
    Trophy Points:
    37
    Gender:
    Male
    Hey, can you answer me what is "CEX-FLASH.EID0.NANDBIN" please?
     
  10. 5,772
    2,846
    497
    atreyu187

    atreyu187 Retired Old Hunter Moderator

    Joined:
    Sep 29, 2014
    Messages:
    5,772
    Likes Received:
    2,846
    Trophy Points:
    497
    Gender:
    Male
    Occupation:
    Scholar of Byrgenwerth
    Location:
    Cainhurst Castle
    Home Page:

    It is a dump of your NAND flash which is needed for CFW to swap from CEX to DEX kernel. It isn't the eID root key. With that and your eID root key using Rebug Toolbox you can swap from CEX to DEX mode with CFW. Trying with HEN would result in a bricked system. But you have a NAND based model so you can install CFW if you don't have it and do this. You can also use it to get your IDPS on the PC with tools. Never share this or try it on another system as they are specific for your system. The only thing anyone else would need it for is to get your IDPS and using on any other system will result in a brick.
     
  11. 68
    16
    37
    Kinglol

    Kinglol Member

    Joined:
    Mar 15, 2018
    Messages:
    68
    Likes Received:
    16
    Trophy Points:
    37
    Gender:
    Male
    Is it important for hen?
     
  12. 5,772
    2,846
    497
    atreyu187

    atreyu187 Retired Old Hunter Moderator

    Joined:
    Sep 29, 2014
    Messages:
    5,772
    Likes Received:
    2,846
    Trophy Points:
    497
    Gender:
    Male
    Occupation:
    Scholar of Byrgenwerth
    Location:
    Cainhurst Castle
    Home Page:

    Nope can't be used for HEN but why would you be using HEN? You can install CFW with that system which is VASTLY superior. Check my updated post for more info
     
  13. 68
    16
    37
    Kinglol

    Kinglol Member

    Joined:
    Mar 15, 2018
    Messages:
    68
    Likes Received:
    16
    Trophy Points:
    37
    Gender:
    Male
    My console don't support CFW unfortunately(it's 3000 series),I'm at hen, I tried dumping that file with IDPSet, and it gave me "CEX-FLASH.EID0.NANDBIN" and "DEX-FLASH.EID0.NANDBIN"
     
  14. 5,772
    2,846
    497
    atreyu187

    atreyu187 Retired Old Hunter Moderator

    Joined:
    Sep 29, 2014
    Messages:
    5,772
    Likes Received:
    2,846
    Trophy Points:
    497
    Gender:
    Male
    Occupation:
    Scholar of Byrgenwerth
    Location:
    Cainhurst Castle
    Home Page:

    Oh I thought you got that from Rebug Toolbox. IDPSet isn't supported for HEN that's why it was getting confused.


    CEX-FLASH.EID0.NORBIN

    Is what your system would dump if it was compatible. Why we're you attempting to use IDPSet?
     
  15. 68
    16
    37
    Kinglol

    Kinglol Member

    Joined:
    Mar 15, 2018
    Messages:
    68
    Likes Received:
    16
    Trophy Points:
    37
    Gender:
    Male
    I'm trying to help HEN progress, I wanted to donate, but I don't have money.
    What I could do to help?
     
  16. 5,772
    2,846
    497
    atreyu187

    atreyu187 Retired Old Hunter Moderator

    Joined:
    Sep 29, 2014
    Messages:
    5,772
    Likes Received:
    2,846
    Trophy Points:
    497
    Gender:
    Male
    Occupation:
    Scholar of Byrgenwerth
    Location:
    Cainhurst Castle
    Home Page:

    The guys don't do it for cash man. Simply testing and posting results helps aid the process and a simple thank you goes a long way. The guys put in countless hours for everyone. There is already a new build in the pipeline we are testing as we speak. @habib and @Joonie tirelessly work on this as well as other contributors. This is a hobby and passion for these guys.
     
    Kinglol likes this.
  17. 278
    104
    72
    Luisile

    Luisile Member

    Joined:
    Feb 21, 2019
    Messages:
    278
    Likes Received:
    104
    Trophy Points:
    72
    Gender:
    Male
    So tested the rebug toolbox on hen but it does not work. i select dump eid root key and the system just freeze with black screen. needed restart the system. so no go for now.
     
  18. 278
    104
    72
    Luisile

    Luisile Member

    Joined:
    Feb 21, 2019
    Messages:
    278
    Likes Received:
    104
    Trophy Points:
    72
    Gender:
    Male
    I just realized something. Its not my question from first post pointles if i can install hen some ftp homebrew and just ftp the Save files to pc? But what about ban? I use this console only with original disc and oficial PSN content. On other things i have another cfw Ps3. So now what? That is the question....
     
  19. 3,089
    3,092
    372
    Joonie

    Joonie Developer

    Joined:
    Oct 15, 2014
    Messages:
    3,089
    Likes Received:
    3,092
    Trophy Points:
    372
    Location:
    Southwest US
    Don't waste your time testing rebug toolbox on HEN, you can't dump your eid root key due to limited access in kernel and hypervisor.
     
    Berion likes this.
  20. 2,190
    2,077
    372
    Berion

    Berion Developer

    Joined:
    Feb 3, 2015
    Messages:
    2,190
    Likes Received:
    2,077
    Trophy Points:
    372
    Gender:
    Male
    Location:
    rom0:/
    It doesn't matter for what purpose You using it. For Sony hacked console == reason to ban. It's simple as that (and injustice but we can do nothing).
     

Share This Page