Olygame


ModChipCentral

Page 19 of 55 FirstFirst ... 9171819202129 ... LastLast
Results 181 to 190 of 545
  1. #181
    Member
    Join Date
    Jul 2011
    Location
    Abilene, TX
    Posts
    80
    Total Thanks Given
    47
    Total Thanks Received
    166
    Total Thanked Posts
    58
    I honestly didn't expect at ALL to get anywhere near the kind of post you provided. I've done a ton of work on reversing loaders, reactivating third-party controllers on 3.55 (and higher..), but never really ventured into this kind of thing. I've been playing with the Brute force tool for maybe an hour now, and was curious how much of a strain do you see on your CPU from it? Bruteforce.exe is seeming to use about 1.8% of CPU resources at the moment.

    PS My first post quote will be changed to "Your a gentlemen and a scholar (...and a Psychiatrist), PatrickBatman.

    I'll be having some fun with this tools. Credits and gratitude to everyone involved for giving somebody sitting in a hospital bed for 20 hours a day something to do. I've had so many great conversations with Doctors who try to talk down to you, than ask if I'm playing some mindless game on my laptop or desktop while laying here. The look on their faces when they see the Bruteforce.exe running, decrypted eboots shown on my screen, and of course the mess of hexadecimal code they see as gibberish is priceless. About 10 minutes ago:

    DR: "Jeremy, stop wasting your time playing solitaire, we need to recheck the implants from your prostate surgery" Jeremy: "Does this look like solitaire? you know you can use your computer for more than facebook and solitaire" DR: "Oh I know, is Bruteforce there some kind of word and number challenge game? Do you need to fill it in like a crossword?" Jeremy: "Close enough."

    The doctor actually looked over my screen, and of course tried to act like he understood everything he saw. He said it looks like some stuff he did in high school. But congratulations to you Aldostools, as of now my Cancer Treatment doctor thinks you developed a program to solve crossword puzzles. He is interested in knowing if theres a similar program on IOS to help him with Words with Friends. You have a pretty kick ass crossword puzzle solver. By all means please provide instructions so my doctor will understand how you solve crossword puzzles. In the mean time I'll be delighted with another team of nurses cutting a radioactive seed out of my prostate. I've had more fingers and objects shoved in my ass than your average porn star. They could of at least romanced me before having a laser knife fuck me in the ass.

  2.          
  3. The Following 8 Users Say Thank You to stock2255 For This Useful Post:

    aldostools (08-14-2012), andreus (08-14-2012), gDrive (09-15-2012), PatrickBatman (08-14-2012), pete_uk (08-14-2012), tomi666 (08-21-2012), xPreatorianx (08-15-2012), Yuu (08-14-2012)

  4. #182
    multiMAN Developer
    Join Date
    Aug 2011
    Posts
    1,049
    Total Thanks Given
    697
    Total Thanks Received
    4,560
    Total Thanked Posts
    844
    Quote Originally Posted by andreus View Post
    I just found a ogrez.self in that update and that key does not work in this self
    http://www.ps3crunch.net/forum/threa...8135#post48135
    If you like multiMAN or multiAVCHD, support the development with a small donation. Click here.

  5. The Following 3 Users Say Thank You to deank For This Useful Post:

    andreus (08-14-2012), gDrive (09-15-2012), Yuu (08-14-2012)

  6. #183
    Senior Member
    Join Date
    Jul 2011
    Posts
    425
    Total Thanks Given
    386
    Total Thanks Received
    627
    Total Thanked Posts
    294
    @deank, did you confirm it's working?
    @Asure, can you confirm?
    Last edited by andreus; 10-23-2012 at 11:14 AM.
    XMB Manager Plus co-developer | Showtime translator | WEBmedia plugin for Showtime developer

  7. The Following 2 Users Say Thank You to andreus For This Useful Post:

    gDrive (09-15-2012), Yuu (08-14-2012)

  8. #184
    multiMAN Developer
    Join Date
    Aug 2011
    Posts
    1,049
    Total Thanks Given
    697
    Total Thanks Received
    4,560
    Total Thanked Posts
    844
    It should work - it is the same procedure like Rock Band 3 (1.05/1.06 updates). I don't have the game so I can't test, but I'm confident it is ok. If someone can confirm - it will be better. Someone should create a update package using this self and the eboot (which has to be re-selfed for 3.55).
    If you like multiMAN or multiAVCHD, support the development with a small donation. Click here.

  9. The Following 2 Users Say Thank You to deank For This Useful Post:

    gDrive (09-15-2012), Yuu (08-14-2012)

  10. #185
    Member
    Join Date
    Jul 2011
    Posts
    35
    Total Thanks Given
    25
    Total Thanks Received
    67
    Total Thanked Posts
    18
    Yes, once i get home from work
    I have obtained a JAP release copy of the game which should be on my doorstep by now, or perhaps tomorrow. My friend who sent it, said it's 3.56. hope i didn't waste Deank's time on it.. But, more interesting.. How does the encryption/decryption on ogrez.self work then ?..

  11. The Following 2 Users Say Thank You to Asure For This Useful Post:

    gDrive (09-15-2012), Yuu (08-14-2012)

  12. #186
    multiMAN Developer
    Join Date
    Aug 2011
    Posts
    1,049
    Total Thanks Given
    697
    Total Thanks Received
    4,560
    Total Thanked Posts
    844
    Quote Originally Posted by Asure View Post
    How does the encryption/decryption on ogrez.self work then ?..
    It is pretty simple once you figure it out

    You will notice that in some game updates you have:

    EBOOT.BIN
    blabla.self

    where both files are "the same". They are not 1:1 the same, because they're encrypted with different keys, but if you look at the prog/data sections and the offsets - you will see what I mean. Also the sizes are the same. I noticed this 'update' approach back in 2010 with "Prince of Persia TFS" and with some other games, so I decided to try that. Both in this game and Rock Band there are no references to the .self and no k_lic... either.

    What you have to do is:

    1) Decrypt the EBOOT.BIN to .elf
    2) Use scetool to create NPDRM NPTYPE=UPDATE with key 00, contentID=game-update-content-id, and np-original-name=name_of_the_self.
    3) You get the new blabla.self and use it

    npdrm.jpg

    For example for this yakuza game you'll notice that the info for the eboot.bin and the ogrez.self are the same:

    Code:
    [*] ELF64 Program Headers:
     Idx Type     Offset   VAddr    PAddr    FileSize MemSize  PPU SPU RSX Align
     000 LOAD     00000000 00010000 00010000 012FF068 012FF068 X-R --R --- 00010000
     001 LOAD     01300000 01310000 01310000 001E31F8 00405B08 -WR -WR --- 00010000
     002 LOAD     014E31F8 00000000 00000000 00000000 00000000 --R --- --- 00010000
     003 LOAD     014E31F8 00000000 00000000 00000000 00000000 -WR --- --- 00010000
     004 LOAD     014E31F8 00000000 00000000 00000000 00000000 -WR -WR -WR 00010000
     005 TLS      013401AC 013501AC 013501AC 00000008 000002A0 --R --- --- 00000008
     006 PARAMS   012FF000 0130F000 0130F000 00000028 00000028 --- --- --- 00000008
     007 PRX      012FF028 0130F028 0130F028 00000040 00000040 --- --- --- 00000004[*] ELF64 Section Headers:
     Idx Name Type          Flags Address    Offset   Size     ES   Align    LK
     000 0000 NULL          ---   00000000   00000000 00000000 0000 00000000 000
     001 000B PROGBITS      -AE   00010200   00000200 0000002C 0000 00000004 000
     002 001F PROGBITS      -AE   00010230   00000230 010E31E8 0000 00000010 000
     003 0011 PROGBITS      -AE   010F3418   010E3418 00000024 0000 00000004 000
     004 0017 PROGBITS      -AE   010F343C   010E343C 00002D20 0000 00000004 000
     005 0025 PROGBITS      -AE   010F6160   010E6160 00016A7C 0000 00000004 000
     006 002C PROGBITS      -A-   0110CBDC   010FCBDC 00002894 0000 00000004 000
     007 0040 PROGBITS      -A-   0110F470   010FF470 000005A4 0000 00000004 000
     008 0050 PROGBITS      -A-   0110FA14   010FFA14 00000004 0000 00000004 000
     009 005D PROGBITS      -A-   0110FA18   010FFA18 00000038 0000 00000004 000
     010 0066 PROGBITS      -A-   0110FA50   010FFA50 00000004 0000 00000004 000
     011 0073 PROGBITS      -A-   0110FA54   010FFA54 00000004 0000 00000004 000
     012 0081 PROGBITS      -A-   0110FA58   010FFA58 000003F4 0000 00000004 000
     013 008B PROGBITS      -A-   0110FE4C   010FFE4C 00000004 0000 00000004 000
     014 0099 PROGBITS      -A-   0110FE80   010FFE80 0012FE68 0000 00000080 000
     015 00A1 PROGBITS      WA-   0123FD00   0122FD00 000CF300 0000 00000080 000
     016 00AC PROGBITS      WA-   0130F000   012FF000 00000028 0000 00000008 000
     017 00BC PROGBITS      -A-   0130F028   012FF028 00000040 0000 00000004 000
     018 00D0 PROGBITS      WA-   01310000   01300000 000014DC 0000 00000004 000
     019 00D7 PROGBITS      WA-   013114DC   013014DC 000000E8 0000 00000004 000
     020 00DE PROGBITS      WA-   013115C4   013015C4 00000004 0000 00000004 000
     021 00E3 PROGBITS      WA-   013115C8   013015C8 0000328C 0000 00000008 000
     022 00F0 PROGBITS      WA-   01314854   01304854 000005A4 0000 00000004 000
     023 00FF PROGBITS      WA-   01314DF8   01304DF8 00034B20 0000 00000008 000
     024 0104 PROGBITS      WA-   01349918   01339918 00006894 0000 00000008 000
     025 0109 PROGBITS      WA-   013501AC   013401AC 00000008 0000 00000004 000
     026 0110 NOBITS        WA-   013501B8   013401B4 00000294 0000 00000008 000
     027 0116 PROGBITS      WA-   01350480   01340480 001A2D78 0000 00000080 000
     028 011C NOBITS        WA-   014F3200   014E31F8 00222908 0000 00000080 000
     029 0121 PROGBITS      ---   00000000   014E31F8 00000CA8 0000 00000004 000
     030 0130 PROGBITS      ---   00000000   014E3EA0 00004A52 0000 00000001 000
     031 0001 STRTAB        ---   00000000   014E88F2 0000013C 0000 00000001 000
    Last edited by deank; 08-14-2012 at 04:20 AM.
    If you like multiMAN or multiAVCHD, support the development with a small donation. Click here.

  13. The Following 8 Users Say Thank You to deank For This Useful Post:

    aldostools (08-14-2012), andreus (08-14-2012), Asure (08-14-2012), gDrive (09-15-2012), kgb (08-14-2012), opoisso893 (08-14-2012), Yuu (08-14-2012)

  14. #187
    Senior Member
    Join Date
    Jul 2011
    Posts
    425
    Total Thanks Given
    386
    Total Thanks Received
    627
    Total Thanked Posts
    294
    So if it works, another problem solved. Thanks a lot deank!
    Last edited by andreus; 10-23-2012 at 11:14 AM.
    XMB Manager Plus co-developer | Showtime translator | WEBmedia plugin for Showtime developer

  15. The Following 2 Users Say Thank You to andreus For This Useful Post:

    gDrive (09-15-2012), Yuu (08-14-2012)

  16. #188
    multiMAN Developer
    Join Date
    Aug 2011
    Posts
    1,049
    Total Thanks Given
    697
    Total Thanks Received
    4,560
    Total Thanked Posts
    844
    There is no universal approach. Sizes must be equal (not more or less) and to be sure that there is no k_license involved you can either check if the .self is referenced in the eboot.bin or you'll have to use IDA to make sure that NP functions use NULL k_lic... (or find the k_license location in IDA using the NP functions).
    If you like multiMAN or multiAVCHD, support the development with a small donation. Click here.

  17. The Following 4 Users Say Thank You to deank For This Useful Post:

    aldostools (08-14-2012), gDrive (09-15-2012), kgb (08-14-2012), Yuu (08-14-2012)

  18. #189
    Member
    Join Date
    Jul 2011
    Posts
    35
    Total Thanks Given
    25
    Total Thanks Received
    67
    Total Thanked Posts
    18
    Quote Originally Posted by deank View Post
    It is pretty simple once you figure it out

    You will notice that in some game updates you have:

    EBOOT.BIN
    blabla.self
    ..
    Both in this game and Rock Band there are no references to the .self and no k_lic... either.
    This reference from eboot.bin had me looking in the wrong direction, so i had assumed that ogrez.self would be like 'rage' which has a similar approach.

    Code:
    0116A2F8 6F 67 72 65 │ 7A 2E 73 65 │ 6C 66 00 00 │ 00 00 00 00  ogrez.self......
    Rage has the exact same 'thing' where EBOOT.BIN and patch.self appear to be the same files, signed differently, but we can find a klic in the eboot..
    (Edit: Compared the two eboot/patch decrypted files from rage, they are indeed identical.)

  19. The Following 2 Users Say Thank You to Asure For This Useful Post:

    gDrive (09-15-2012), Yuu (08-14-2012)

  20. #190
    multiMAN Developer
    Join Date
    Aug 2011
    Posts
    1,049
    Total Thanks Given
    697
    Total Thanks Received
    4,560
    Total Thanked Posts
    844
    Yes, you're right - rock band didn't have reference to the band_s.self. But in yakuza there was only one usage of the k_license and it was for a sprx (as I posted the other day). I guess you can apply this method to rage and compare the results to the working patch.self. Both methods should work.

    (Edit: Compared the two eboot/patch decrypted files from rage, they are indeed identical.)
    Nice.

    As I said - it is not a universal method, but since it takes 1 min to test anyone can check it before trying the brute force method.
    Last edited by deank; 08-14-2012 at 05:25 AM.
    If you like multiMAN or multiAVCHD, support the development with a small donation. Click here.

  21. The Following 5 Users Say Thank You to deank For This Useful Post:

    Asure (08-14-2012), gDrive (09-15-2012), kgb (08-14-2012), pete_uk (08-14-2012), Yuu (08-14-2012)


 
Page 19 of 55 FirstFirst ... 9171819202129 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
EachGame