forums.ps2dev.org Forum Index forums.ps2dev.org
Homebrew PS2, PSP & PS3 Development Discussions
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

PSP Decryption

 
Post new topic   Reply to topic    forums.ps2dev.org Forum Index -> PSP Development
View previous topic :: View next topic  
Author Message
coolkehon



Joined: 20 Oct 2008
Posts: 355

PostPosted: Fri Jan 29, 2010 2:46 am    Post subject: PSP Decryption Reply with quote

I heard that the main boot ipl ( I have no idea what I'm talking about ) modules uses encryption during the booting of the psp. I'd like to try to break that encryption. Any ideas where I should start. I know it uses aes but I'd like to run a bruteforce attack on it. And maybe i'll get lucky :P. Help plz
Back to top
View user's profile Send private message MSN Messenger
SilverSpring



Joined: 27 Feb 2007
Posts: 115

PostPosted: Fri Jan 29, 2010 3:13 am    Post subject: Reply with quote

What do you want to do exactly?

The IPL can already be decrypted, unless you are talking about IPL's for PSP 3K's and PSP GO's which we cannot decrypt because we are unable to dump the pre-IPL for those models (which the IPL encryption uses as a seed).
_________________
PSP PRX LibDocs
Back to top
View user's profile Send private message Visit poster's website
coolkehon



Joined: 20 Oct 2008
Posts: 355

PostPosted: Fri Jan 29, 2010 10:27 am    Post subject: Reply with quote

there was something that we could not do because of aes encryption during boot of the psp so instead we had to hook it. I haven't check on it in quite some time so I don't even remember what it was. You guys may have even of fixed it by now
Back to top
View user's profile Send private message MSN Messenger
SilverSpring



Joined: 27 Feb 2007
Posts: 115

PostPosted: Sun Jan 31, 2010 5:50 am    Post subject: Reply with quote

You are going to have to be more specific, I still don't know what you are talking about. Do you have any more information than just a vague "something we could not do"?
_________________
PSP PRX LibDocs
Back to top
View user's profile Send private message Visit poster's website
coyotebean



Joined: 05 Dec 2009
Posts: 26

PostPosted: Sun Jan 31, 2010 11:05 pm    Post subject: Reply with quote

The main security of the PSP is in the "Kirk chip". Currently there is no public knowledge of the exact algorithm & keys used. The "main" & "payload" part of the IPL is not directly protected by AES. Your question seems to suggest you are questioning about the protection of the Kernel keys?
Back to top
View user's profile Send private message
coolkehon



Joined: 20 Oct 2008
Posts: 355

PostPosted: Mon Feb 01, 2010 3:37 am    Post subject: Reply with quote

yes that would be correct. I guess you guys have it figured out when it comes to booting the psp.

But Why is the 3000 not cracked?
Back to top
View user's profile Send private message MSN Messenger
Torch



Joined: 28 May 2008
Posts: 842

PostPosted: Mon Feb 01, 2010 4:11 am    Post subject: Reply with quote

Because prior to Pandora we relied on the weak security of 1.50OFW to boot CFW which doesn't work on the Slim onwards. The Pandora IPL block was used only in 3.52M33-something onwards.
Back to top
View user's profile Send private message
coolkehon



Joined: 20 Oct 2008
Posts: 355

PostPosted: Mon Feb 01, 2010 11:38 am    Post subject: Reply with quote

the what steps would be needed to crack the psp 3000
Back to top
View user's profile Send private message MSN Messenger
SilverSpring



Joined: 27 Feb 2007
Posts: 115

PostPosted: Mon Feb 01, 2010 1:30 pm    Post subject: Reply with quote

So basically you're question is how to get the kernel keys from the IPL? The IPL (on 1K and 2K) and can already be decrypted no problem (which ends up exposing the keys in the plain).

Regarding cracking the 3K, it depends what you mean by "cracking" it. The 3K can already run unsigned code via exploits. If you are asking what it takes to get Pandora to work on it:

Firstly the service mode trigger via the battery is now encrypted so that has to be figured out. That will enable the 3K to boot into service mode. The next step would be to figure out how to run unsigned code from the MS IPL. The exploit that Pandora relied on in the pre-IPL has now been patched on the 3K (and later model 2K's) so we cannot run custom IPL's.

It's unlikely there would exist another exploit in the pre-IPL that'll allow unsigned code to run however we are unable to dump the 3K pre-IPL to even search for one. That is also why the 3K IPL cannot be fully decrypted since it uses the contents of the pre-IPL as a seed to decrypt it.

So basically to 'crack' the 3K we need exploits or figure out how to sign code like Datel figured out.

EDIT: also could you be a little more specific when asking questions, your comments are a bit too vague to understand what exactly you are asking about.
_________________
PSP PRX LibDocs
Back to top
View user's profile Send private message Visit poster's website
Torch



Joined: 28 May 2008
Posts: 842

PostPosted: Mon Feb 01, 2010 11:38 pm    Post subject: Reply with quote

Do you think they simply added the IPL block hash as an easy fix for the exploit or that they have fixed the exploit and added the hash as an extra security measure?
Back to top
View user's profile Send private message
jimparis



Joined: 10 Jun 2005
Posts: 1179
Location: Boston

PostPosted: Tue Feb 02, 2010 3:09 am    Post subject: Reply with quote

An easy fix is still a fix
Back to top
View user's profile Send private message
Torch



Joined: 28 May 2008
Posts: 842

PostPosted: Tue Feb 02, 2010 3:32 am    Post subject: Reply with quote

jimparis wrote:
An easy fix is still a fix


That means it can be cracked if its dumped.
Back to top
View user's profile Send private message
Davee



Joined: 22 Jun 2009
Posts: 59

PostPosted: Fri Feb 05, 2010 7:20 pm    Post subject: Reply with quote

Torch wrote:
jimparis wrote:
An easy fix is still a fix


That means it can be cracked if its dumped.


No, it's still a fix.
Back to top
View user's profile Send private message
Torch



Joined: 28 May 2008
Posts: 842

PostPosted: Fri Feb 05, 2010 11:07 pm    Post subject: Reply with quote

Davee wrote:
No, it's still a fix.


If its only the hash then its probably software calculated in the pre-IPL like DAX said before, meaning the exploit if unpatched would still work if the hash is correct.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    forums.ps2dev.org Forum Index -> PSP Development All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group