Olygame

DigiTopZ #2


Page 1 of 6 123 ... LastLast
Results 1 to 10 of 54
  1. #1
    Member
    Join Date
    Aug 2012
    Posts
    37
    Total Thanks Given
    45
    Total Thanks Received
    169
    Total Thanked Posts
    35

    Debugging full games + sniffing

    i moved the thread here

    i just think there are other ways also to do it like full game debugging.

    I research this option myself , and i can see also there are ways to to optain the decrypted eboot several ways.

    I really played around today, and i manages to get full game debugging.

    And that havent been done as yet

    It always have frustrateted me that you couldent debugg retail eboots/games

    Normally when loading just fself in debugger, is just nothinh happends.

    So i played around.

    here is an small tut.

    First reset in debugger mode.

    locate the eboot.bin decrypt it, and resign with Fself one.

    then in target manager set app_home to the BLES or BLUS folder.

    reset target

    Then load executable then locate the eboot.bin

    load it

    then open Tuner from the SDK.

    then load executable there also .

    when you do this you get kicked to the ps3 debugger.

    then in debugger you press go under options ..

    concrats you are debugging full game .

    movie intro

    Attachment 3312

    gameplay

    Attachment 3313

    also on the ps3 you can play the game under debugger mode .

    since eboots stays in ram to the next is loaded the intire game can be debugged.

    so there for only the eboot have to be decrypted and not the sprx if the game os needed off that

    just since an monkey like me can figure it out so can you.

    PS when the debugging starts you can sniff with "software."

    even works on 4.11 games but prepare for huge files like 1 gb when sniffing, so hope for any good suggestions.

    really dont care about war on sites, just help eachother

    funny shit is that you can debugg both TB and cobra this way, all the updates an dongle updaters, just wised that dex was around before

    regards

  2.     
  3. The Following 14 Users Say Thank You to zadow28 For This Useful Post:

    Abkarino (09-18-2012), acab (09-27-2012), andreus (09-17-2012), el-Cid (09-17-2012), gDrive (09-17-2012), kgb (09-20-2012), kilkip (09-20-2012), Kvass (09-17-2012), nextbike (09-17-2012), STLcardsWS (09-17-2012), tupac4u (09-17-2012), xPreatorianx (09-19-2012), Yuu (09-17-2012)

  4. #2
    Member
    Join Date
    Aug 2012
    Posts
    37
    Total Thanks Given
    45
    Total Thanks Received
    169
    Total Thanked Posts
    35
    so offcouse you say why debugg the game.

    1 ) Well the debugged of the game is done by decrypting and fself the eboot. Not the other files sprx/self ones they can still be signed with higher keys.

    This method also allowed full coredump from ram.

    2) Othere way i found is simply sniff with wireshack on local network, the game can be either set up as emu or just app_home.

    just sniff then load game. then in the log of the sniffer, the binary is there.(HEX)

    still some testing

  5. The Following 6 Users Say Thank You to zadow28 For This Useful Post:

    andreus (09-17-2012), el-Cid (09-17-2012), gDrive (09-17-2012), STLcardsWS (09-17-2012), Yuu (09-17-2012)

  6. #3
    Member
    Join Date
    Aug 2012
    Posts
    37
    Total Thanks Given
    45
    Total Thanks Received
    169
    Total Thanked Posts
    35
    So basicly my theory is load 4.1 games with the update trick, load it in the debugger, when game is running make full dump with ram.
    This should work since eboots are stored in ram till the next is loaded.

    still you need some kind off debugg info in the eboot, for the debugger to load the eboot.
    Last edited by zadow28; 09-17-2012 at 02:29 PM.

  7. The Following 4 Users Say Thank You to zadow28 For This Useful Post:

    andreus (09-17-2012), el-Cid (09-17-2012), gDrive (09-17-2012), Yuu (09-18-2012)

  8. #4
    Banned
    Join Date
    Aug 2012
    Posts
    18
    Total Thanks Given
    0
    Total Thanks Received
    4
    Total Thanked Posts
    3
    first of all, I'll call zadow28's method is 'A Conspiracy Theory without a Proof'

    zadow28,
    if this method can make an eboot TB or Cobra,
    why not you try it with making an eboot TB for Sleeping Dogs and Darksiders2, also Transformer fall cybertron ?

    Note: Please don't tell to the F**king Gregory Rasputin and Hellsing9, because they have a F**king mind problems with sleepingdogs.

  9. #5
    Member
    Join Date
    Aug 2012
    Posts
    37
    Total Thanks Given
    45
    Total Thanks Received
    169
    Total Thanked Posts
    35
    all the cobra and TB updates all the way up to the last can be debugged.
    Its pretty easy to do, just decrypt the updates and fself them.Run them in the debugger easy peacy.
    Just remember to make an folder PS3_GAME and put the USR dir inside+ set app_home to the dir where PS3_folder is.

    regarding the games all games is possible to debug. only the eboot have to be an fself one, then it dosent matter if the other files are signed with greater keys.
    the challenge is to build an fself that launch the higher eboots 3.61+ ones, but still there are many ways.
    can be if then game have an 3.60 patch but the rest is 4.21, then it should be apple to get some info there.
    No exact answer here. thats why i posted this thread, the more testing the faster we get answer.

    havent tryed yet on the nodrm games since i dont have any off those. so if any have those try it out.

  10. The Following 2 Users Say Thank You to zadow28 For This Useful Post:

    Yuu (09-18-2012)

  11. #6
    Member
    Join Date
    Aug 2012
    Posts
    37
    Total Thanks Given
    45
    Total Thanks Received
    169
    Total Thanked Posts
    35
    ive made an small video that shows how to debugg the dongle updates i dont have any dongle attach.
    http://www.youtube.com/watch?v=FkjRK...ature=youtu.be

    all updates and apps made can be done this way.

  12. The Following 2 Users Say Thank You to zadow28 For This Useful Post:

    nextbike (09-18-2012), Yuu (09-18-2012)

  13. #7
    Member
    Join Date
    Aug 2012
    Posts
    37
    Total Thanks Given
    45
    Total Thanks Received
    169
    Total Thanked Posts
    35
    Also made this one about how to sniff the game, minus is that you get huge files, but you get the eboot decrypted.




    so offcause the next is to sniff emu/iso games

    Also im on dex 4.21(affraid to downgrade, since i broke one console)
    If any on 3.55 can try sniffing the 4.21 emu games there and give some feedback.
    Last edited by zadow28; 09-18-2012 at 02:53 AM.

  14. The Following User Says Thank You to zadow28 For This Useful Post:

    Yuu (09-18-2012)

  15. #8
    Member
    Join Date
    Apr 2012
    Posts
    96
    Total Thanks Given
    133
    Total Thanks Received
    82
    Total Thanked Posts
    44
    Quote Originally Posted by lolong View Post
    first of all, I'll call zadow28's method is 'A Conspiracy Theory without a Proof'

    zadow28,
    if this method can make an eboot TB or Cobra,
    why not you try it with making an eboot TB for Sleeping Dogs and Darksiders2, also Transformer fall cybertron ?

    Note: Please don't tell to the F**king Gregory Rasputin and Hellsing9, because they have a F**king mind problems with sleepingdogs.
    Please dont turn this into a HAX drama thread, Devs came here to get away from the children, and further their work
    keep up the good work zadow28

  16. #9
    Banned
    Join Date
    Aug 2012
    Posts
    18
    Total Thanks Given
    0
    Total Thanks Received
    4
    Total Thanked Posts
    3
    I watched your youtube, but sorry, I dont believe it, and I'm gonna to say it again,

    still a theory, no proof, also no one try it ? and no one's successfully with this or dump method to get a decrypt TB/Cobra eboot such as fw 4.11 games.

    I've a conspiracy theory too, i can proof it, if I get the debug (devkit) keys


    also I don't believe, Duplex found TB's DRM ?!?
    if Duplex was really removing TB's DRM, then I could not play MaxPayne's Duplex eboot with TB dongle, right ?

    a theory, I hope, I'm wrong and Sony changes his DRM, LOL

  17. The Following User Says Thank You to lolong For This Useful Post:

    Yuu (09-18-2012)

  18. #10
    Senior Member
    Join Date
    Jul 2011
    Location
    Giza - Egypt
    Posts
    226
    Total Thanks Given
    74
    Total Thanks Received
    373
    Total Thanked Posts
    142
    Quote Originally Posted by lolong View Post
    I watched your youtube, but sorry, I dont believe it, and I'm gonna to say it again,

    still a theory, no proof, also no one try it ? and no one's successfully with this or dump method to get a decrypt TB/Cobra eboot such as fw 4.11 games.

    I've a conspiracy theory too, i can proof it, if I get the debug (devkit) keys


    also I don't believe, Duplex found TB's DRM ?!?
    if Duplex was really removing TB's DRM, then I could not play MaxPayne's Duplex eboot with TB dongle, right ?

    a theory, I hope, I'm wrong and Sony changes his DRM, LOL
    Allow me to correct your info first,
    TrueBlue not using any kind of Debug keys since in Debug/DevKits there is no need for encryption at all the key revision 0x800 you talked about is just to let GameOS know that they will launch debug self and its not encrypted at all.
    you can do it your self by just unself any retail self then use make_fself.exe tool from official SDK then you will have a EBOOT.BIN or SELF file that looks like TrueBlue Eboots except that all its sections are not encrypted and it has no metadata embedded into it.
    This revision key value maybe used only by TB to trigger its payload to load and decrypt the DRMed eboots only and use normal payload or normal keys for non 0x800 flaged eboots.

  19. The Following 7 Users Say Thank You to Abkarino For This Useful Post:

    acab (09-27-2012), gDrive (09-18-2012), pete_uk (09-18-2012), xPreatorianx (09-19-2012), Yuu (09-18-2012), zadow28 (09-18-2012)


 
Page 1 of 6 123 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
EachGame