PS3 [UPDATE] IDPS Dumper (PS3 NAND / NOR ) - 4.81/4.82 OFW Compatible by Team PS3Xploit

{UPDATE v0.2.3 Released(See tab)}
Following the official announcement of the PS3Xploit news (4.81 OFW Exploit), the devs behind the project have fulfilled the promises of releasing the IDPS Dumper for OFW 4.81/4.82 as this release is ready for the public. Now there is many more things being worked surrounding the overall project but this IDPS Dumper works on all models of the PS3 (NOR and NAND, note 12 GB EMMC will be supported soon in an updated release) and no reason not to release this tool. Since PS3 firmware 4.70 Sony had blocked flatz IDPS extracting tool (IDPS Stealer) and there has not been a known way to obtain the IDPS on OFW (4.70 +) consoles , but now this tool can now obtain your PS3's ID, which can have various uses, the tool has been confirmed to work on SuperSlim models by the team. . If you have not read the previous details about the PS3Xploit project, then checkout this official thread to get the firsthand information about this ambitious PS3 project.


capture_0.2.3.jpg

(UPDATE v0.2.3)


  • UPDATE v0.2.3- IDPS Dumper for 4.82 OFW
    • Added 4.82 Support
    • Removed all extra requirements like JQuery..
    • Removed the need for string relocations to improve the initial memory search process & overall trigger times.

  • UPDATE v0.2.3- IDPS Dumper for 4.81 OFW

    • Removed all extra requirements like JQuery..
    • Removed the need for string relocations to improve the initial memory search process & overall trigger times.



  • UPDATE v0.2.1a- IDPS Dumper for 4.81 OFW

    we have some more exciting news to bring you!! :cheerful:

    We have been working very hard to bring eMMC support for the newest SuperSlims CECH-40xxA, CECH-42xxA , CECH-43xxA and that has happened. :D

    The team would like to present a nice little update to the 4.81 IDPS Dumper now supporting eMMC hardware revision consoles!!

    Please report any issues you have while using this new version on any of the flash types, NAND, NOR, and eMMC.

    Thank You to all :cool:

    v0.2.1a
    • Added eMMC SuperSlim Support (CECH-40xxA, CECH-42xxA , CECH-43xxA)
    • Misc Tweaks To Exploit
    • Small typo on index.html pointed out by @Turranius - Fixed

    How to use this:
    *** MAKE SURE TO RUN AS ADMINISTRATOR ***
    install python to use server.py or another HTTP server of your choosing on both Windows and Linux!​

    On windows - Install any of these optional HTTP servers:

    On linux:
    • install python for your distribution using apt-get, yum, and similar commands.
    • make script executable using "chmod a+x server.py" or "chmod 775 server.py" or "chmod 777 server.py"
    • execute python script using "/usr/bin/python $exploitFolder/server.py" or "./server.py"

    Update
    on Android: (
    instructions from @No0bZiLLa)
    • I can confirm this does work if using an http server on Android. what i did was downloaded the zip (on my phone) and extracted it and then download something like Simple HTTP Server and point the server to the folder that contains index.html. once you do that just reload the server and make a note of what the ip:port is. then just go to ps3, type in ip:port (eg 192.168.2.7:12345) as specified in simple http server and then select the appropriate button for your system.


    Then run (for python):

    • On windows - windows.bat
    • On linux - linux.sh


    Usage Tips:

    1) Try using a LAN connection or a solid WiFi connection during exploitation. A weak signal can cause problems.
    2) If the exploit takes more than 5 minutes to work, reload page, browser, or restart console and try again.
    3) If you are using a LAN connection and experience network issues, make sure all cables to router are in working order.​



  • IDPS Dumper Release (v0.2 - After Leak Release)
    ok....the moment all of you have been waiting for......i assume :cheerful:
    • File: ps3_481_idps_dumper-PS3XPloit.zip
    • MD5 Hash: FFDA70AB2D1677886083F99185C54FE3
    • SHA-256 Hash: 852BDB301753C4F4A7E946188E850D3D325EEAA259B61AE2B5AE31320B2F292B

    enjoy this release from our team :victorious: we will be working hard to add eMMC support as soon as possible!!


    The documentation will be updated as time goes on. There is a readme.txt file included with basic setup and usage instructions.

    Please stay tuned for future tools and releases :D

    and once again, THANK YOU to everyone involved bringing this all together, without all of you, none of this would have happened!!!

    Additional details from @bguerville
    "The idps dumper will create a file on usb000 then beep 3 times & shutdown in all cases, even if flash memory read fails. emmc should not make a difference to this. You will get garbage in idps.bin in that case.

    Js errors with a black page message on ps3 should not happen. If ever it did, just report & in the meantime keep relaunching the exploit. Nobody has had this issue in dozens of tests though.

    And clearing cache or cookies is totally unnecessary with the exploit & the wk js interpreter. Between runs garbage collection will take care of cleaning up what is needed, the job it does is always sufficient".


It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically....

So in short, never use the browser or set a homepage you cancel before running the exploit!
If you need to, set the homepage to 'blank', close the browser then reopen it to start the idps dumper.

Set-up Steps:
  1. Setup a small Web server on pc or smartphone. The Python http server is not required for most users, it was provided for developers. Since v0.2.3, all other extra requirements have been removed. Don't come to us for explanations about how to run a http server though. Google it.
  2. Extract the files in your http server root folder.
  3. Put a fat32 USB key in port closest to BD Drive (/dev_usb000).
  4. Open the ps3 browser & write the ip address of your server (and the port if not 80).
  5. Run until ps3 beeps & shutdown. The idps should be on your USB drive as idps.bin.
- Downloads -
  • MD5 Hash: 3c2e1582f52e1002a12ad280f426d0c6
  • SHA-256 Hash: 1c49eabd64275171a60c90f0f06f503b7055f4ff863f87e7960d41464d127443
  • MD5 Hash: 71dd906e585bf470f84f9d4fb10c1f37
  • SHA-256 Hash: d4bffe2b7d08c1dda275590229f86903f1db487e9a78364d6a025c3734cd8f68
 
Last edited:
So I checked the 3.55 compatibility page located here.

I have one of these (not sure which one as I'm not about to open the unit) ...

CECH-25xx (JSD-001) with 3.56 from factory - datecode 1B (common)
CECH-25xx (JTP-001) with 3.56 from factory - datecode 1B (common)


... and in the notes it states ...

"(3.56+ + spkg fix + signed 3.55 priv : should work)"

What does this exactly mean? Should work?
 
So I checked the 3.55 compatibility page located here.

I have one of these (not sure which one as I'm not about to open the unit) ...

CECH-25xx (JSD-001) with 3.56 from factory - datecode 1B (common)
CECH-25xx (JTP-001) with 3.56 from factory - datecode 1B (common)


... and in the notes it states ...

"(3.56+ + spkg fix + signed 3.55 priv : should work)"

What does this exactly mean? Should work?
If your minver is 3.56, not 3.60 (!!!) then it mean that your ps3 is hackable by installing cfw, but can't go to 3.55 firmware. So is cfw ready ps3, that can run custom firmware 3.56 or newer.

In case your minver is 3.60 then is 100% not hackable in any way for now.
 
I'am running server as administrator (windows.bat) & I'am using ethernet (Ping PS3 ok).
What about missing file pls ?
No missing files in the archive.
Ping is not good enough as a test for viable connection. We know that ping will work as the first files are loaded...

Some people reported they needed to copy the include folder in python root folder. It sounds like a configuration issue that nobody on the dev team has experienced. Maybe check that your python folder has been added to PATH (system environment variable)
You could try with another server than python... A simple Web server would do just fine with idps dumper 0.2.3.
 
Last edited:
If your minver is 3.56, not 3.60 (!!!) then it mean that your ps3 is hackable by installing cfw, but can't go to 3.55 firmware. So is cfw ready ps3, that can run custom firmware 3.56 or newer.

In case your minver is 3.60 then is 100% not hackable in any way for now.

How do I check the minver?
 
How do I check the minver?

straight from my tutorial on installing cfw:

Code:
http://www.mediafire.com/download/s31d69pphkcv7dp/MVC.rar

run that pup file. it will throw an error and tell you the lowest downgradable firmware.
 
Last edited:
straight from my tutorial on installing cfw:

Code:
http://www.mediafire.com/download/s31d69pphkcv7dp/MVC.rar

run that pup file. it will throw an error and tell you the lowest downgradable firmware.

So I tried to run the update from the recovery menu and got this message ...

The Data is corrupted (8002F2C5)

So I ran it from within the system menu (normal boot) and I got this ...

Update data of version 3.40 or later can be installed on this system (8002F967)

So I am assuming I can skip those special instructions on the compatibility page and downgrade right to 3.55 when the downgrader is released. Correct?
 
@cots that is normal...it is showing you the minimum version that your PS3 can have on that alert from XMB, which your minver is 3.40

it is not an installable file, just to check version :-p
 
@cots that is normal...it is showing you the minimum version that your PS3 can have on that alert from XMB, which your minver is 3.40

it is not an installable file, just to check version :-p

Yes, I am aware it just checks the version. I have one of these versions according to the serial number;

CECH-25xx (JSD-001) with 3.56 from factory - datecode 1B (common)
CECH-25xx (JTP-001) with 3.56 from factory - datecode 1B (common)


So on the website it has a note next to my model number that says;

"(3.56+ + spkg fix + signed 3.55 priv : should work)"

However, the version check PUP says 3.40 so I am wondering if they note applies to me or not and if it does what does it mean?
 
the version check PUP says 3.40 so I am wondering if they note applies to me or not and if it does what does it mean?

if the version check PUP says '3.40 or later' then you can safely downgrade that console to 3.40 or any version above 3.40, for example 3.55. in other words that console is 100% hackable.

EDIT: I see what you mean now lol... Go by what that PUP says, model numbers and date codes aren't always 100% accurate with things like this.
You are good to go :)
 
Last edited:
if the version check PUP says '3.40 or later' then you can safely downgrade that console to 3.40 or any version above 3.40, for example 3.55. in other words that console is 100% hackable.

EDIT: I see what you mean now lol... Go by what that PUP says, model numbers and date codes aren't always 100% accurate with things like this.
You are good to go :)

Cool. Let's hope that downgrader is released soon.
 
Hello,

Does some one know about this error and about "exp_rel.js" file pls?

CECH2004A
REBUG 4.81.2 REX/CEX

Message:
C:\Python27>python.exe server.py
Starting server on 192.168.2.1:8080
192.168.2.3 - - [18/Nov/2017 23:24:40] "GET /html/idps_nor.html HTTP/1.1" 200 -
192.168.2.3 - - [18/Nov/2017 23:24:40] "GET /html/include/utils.js HTTP/1.1" 200 -
192.168.2.3 - - [18/Nov/2017 23:24:40] code 404, message File not found
192.168.2.3 - - [18/Nov/2017 23:24:40] "GET /html/include/exp_rel.js HTTP/1.1" 404 -

hey @0_obeWAN did you fix the problem, i had it happen to me but i was able to fix it, if you still are having trouble let me know.
 
I've used python with the wii u's wupserver. to know what's going on, you can right click the python script and use "edit with IDLE."
 
ps3_idps_dumper-v0.2.3-PS3XPloit states it will take a few seconds to a few minutes, but it's been running for about an hour now and it looks like it repeats a continuous loop, A few lines of code come up on the bottom of the screen an I get an orange activity light blinking on the PS3 and it stops blinking until the lines of code shows up on the screen again and the blinking starts again. did I miss something? or should I just wait? I'm running python as a HTTP server, this is the command I used "python -m SimpleHTTPServer 8000".

UPDATE: Ok, so after more then an hour my PS3 beeped and shut down... Success :) I got my idps.bin file the file is 16bytes big, It dumped the file on the root of my flash drive and not in a folder as it indicates on the instructions. So now where do I go from here? how can I go about testing the file to see if it was a successful dump?
 
Last edited:
ps3_idps_dumper-v0.2.3-PS3XPloit states it will take a few seconds to a few minutes, but it's been running for about an hour now and it looks like it repeats a continuous loop, A few lines of code come up on the bottom of the screen an I get an orange activity light blinking on the PS3 and it stops blinking until the lines of code shows up on the screen again and the blinking starts again. did I miss something? or should I just wait? I'm running python as a HTTP server, this is the command I used "python -m SimpleHTTPServer 8000".

UPDATE: Ok, so after more then an hour my PS3 beeped and shut down... Success :) I got my idps.bin file the file is 16bytes big, It dumped the file on the root of my flash drive and not in a folder as it indicates on the instructions. So now where do I go from here? how can I go about testing the file to see if it was a successful dump?
If you had read the posts in this thread you would have realised that there was a problem with your setup. A few seconds to a few minutes is what it takes, not an hour.
You most likely had your homepage not set to blank or whatever other reasons mentioned previously...
 
If you had read the posts in this thread you would have realised that there was a problem with your setup. A few seconds to a few minutes is what it takes, not an hour.
You most likely had your homepage not set to blank or whatever other reasons mentioned previously...
You're right bguerville, I forgot to set the home page to blank, redid it with the home page set to blank and it finished under 2 minutes.
 
Last edited:
hey @0_obeWAN did you fix the problem, i had it happen to me but i was able to fix it, if you still are having trouble let me know.
@bguerville FYI
My problem is solv, the file was missed because Windows 10 see like trojan and delete it :(

But I have failed to dump all the weekend. No way I'm disapounted
I tried all I can with CFW rebug 4.81.1 but no result :(
 
@bguerville FYI
My problem is solv, the file was missed because Windows 10 see like trojan and delete it :(

But I have failed to dump all the weekend. No way I'm disapounted
I tried all I can with CFW rebug 4.81.1 but no result :(
You don't explain the issue you are having so it's hard to answer.
If ever the idps dumper freezes the console in Rebug, it usually means the current vsh is not the cex version? Switching to CEX mode is not sufficient to guarantee that you are using CEX vsh...
 
You don't explain the issue you are having so it's hard to answer.
If ever the idps dumper freezes the console in Rebug, it usually means the current vsh is not the cex version? Switching to CEX mode is not sufficient to guarantee that you are using CEX vsh...
So many issues you can't imagine (better to rape than to cry). I tryed many web servers, localhost, local network with NAS, hosted on différents places... But all failed every times.

Please let me know about how to guarente CEX vsh.
I'm on clean Rebug REX 4.81.2 (not moded)
Cobra activ
WebMAN activ
 

Featured content

Trending content

Back
Top