PSP-Hacks.com

Join the Dashhacks Fan Club on FacebookFollow Dashhacks on TwitterDashhacks YouTube ChannelPSP-Hacks RSS Feed

Hack your Sony PSP

Forums | Tutorials | Custom Firmwares | PSP Themes | Search


 

Why PSP TA88v3 cannot be Hacked, yet…

greg | October 6, 2008

Straight from the source — Dark_AleX verbatim…

When the PSP boots, the boot code (aka pre-ipl or ipl loader) loads the ipl from either the nand or memory stick. The IPL is splitted into pieces of 0×1000 bytes.

First 0xA0 bytes of each block is a header for the kirk hardware command 1. It contains keys, the size of the cipher data, and two hashes, one for part the header itself, and another one for the body. The 0xF60 remaining bytes are the ciphered body, which will decrypt to 0xF60 plain bytes… if the hashes, which are checked by kirk hardware itself, are OK. (Note: ciphered body can actually be less than 0xF60, in this case, remaining bytes are ignored… before TA88v3)

What has Sony added to fix this?

The answer can be found in 4.00+ slim ipl’s. They decreased the size of the ciphered body to 0xF40 to leave 0×20 bytes at the end of each block (at offset 0xFE0). In newest pre-ipl’s, these 0×20 bytes have a meaning.

Why PSP TA88v3 Motherboard Cannot Be Hacked Yet

This protection also destroys any possibility of downgrading below 4.00, as these new cpu’s won’t be able to boot previous firmwares ipl’s.

Summary: basically, all security of newest psp cpu’s rely on the secrecy of the calculation of those 0×20 bytes. If pre-ipl were dumped somehow, the security would go down TOTALLY.

And you know the real kicker? The yet-to-be released PSP-3000 will likely sport the new TA88v3 board.

- source / full article: dark-alex.org

Share This With...
  • Facebook
  • Digg
  • Twitter
  • RSS
  • Slashdot
  • Technorati
  • del.icio.us
  • Reddit
  • Blogosphere News
  • HackerNews
  • StumbleUpon
  • Google Bookmarks
  • email
Comments (83)

Tagged: :: ::

RSS feed | Trackback URI

83 Comments »

Comment by kebrus
2008-10-06 18:34:01

i don’t know if I should be happy to not have one of those or not, cause that means maybe this will help the industry and we will get to see more games coming to psp, but that also means there will be less and less hackable psps

i’m glad to have one hackable slim though

Comment by kebrus
2008-10-06 18:36:25

ops, i meant “i don’t know if I should be happy for those psps to be hackable or not”

 
Comment by CS
2008-10-10 18:43:58

*sigh*, if that were true, the DS would have far less games than it does. Seriously guys, stop perpetuating this myth…

 
Comment by Kevin
2008-10-14 09:59:06

The “hurtin the industry” talk is such a misnomer. Everything in gaming is hackable, everything in gaming is piratable. So then why doesn’t all the development and publishing houses just shut down? Not putting a game on the PSP has more to do with other factors then if a game can be downloaded illegaly.

 
 
Comment by Low
2008-10-06 18:43:39

Well Dax never seaces to amaze me so we’ll wait and see

Comment by Mike
2008-10-06 18:53:20

“Ceases”

There’s got to be another workaround.

 
 
Comment by Jaryth
2008-10-06 19:42:31

The ever skillful Dax…
The first step is always identifying the problem.

Well, Im glad to see Sony is still doing work to keep the PSP alive… but the people that they have working on Homebrew/hacking psp’s are amazing. The ideas they have come up with in the past has been spectacular. Im sure they can do it again.

Comment by Fishyfish
2008-10-06 21:26:33

Don’t you see? The constant struggle with Sony keeps the PSP hacking industry alive. Oh well, hail D_A!!!

 
 
Comment by mike501
2008-10-06 19:53:45

sounds tough, i had no idea wat you were talking about with the hex stuff and watnot, but i still have the old phat psp. its all banged up, scratched, pieces missing inside… hes still kickin. lol no need to buy a new one

Comment by Fishyfish
2008-10-06 21:29:34

I’ve dropped my Phat PSP in snow (up to 1 feet), and when I got it out, it was dripping wet. It worked. :O

My battery, a Made-In-China battery (one of the new ones), has scratches and cellophane tape around it from where I visciously stabbed it trying to get it open.

One of the corners of the PSP is badly chipped: the little bumps on the power button are all gone except the big triangle.

At least the UMD drive still works!

That is the joy of having a phat PSP :D

Comment by mike501
2008-10-07 21:41:06

‘Nuff Said

 
Comment by elecman_x
2008-10-09 14:45:14

I miss my 1000 Model PSP, with the MGSPO case attachment it felt invincible.

 
Comment by dctravis
2009-06-21 00:49:50

I hate the slim so much. I have a fat psp that still looks brand new. I baby the thing like nothing else, because I know that I will never be able to get one that is in such good condition again. I swear that the old psp feels like something that is quality and well made, but when you hold the slim it just feels cheap and crappy. Also whenever I dropped the slim the battery would go flying across the room.

 
 
 
Comment by mark
2008-10-06 20:06:43

hahahha only time will destroy sonys puny security and im glad i already have a hacked slim/fat

 
Comment by chrc
2008-10-06 20:20:46

ok boys… all that stands between us and all of sonys glory is ox20 bytes…. you know it only took fema 5 days to bring water to the dome.

 
Comment by dlevans
2008-10-06 20:23:58

dax is amazing so once he finds a way to dump the codes on the header files the new psps will be hacked again? go Dax :)

 
Comment by SinWarrior
2008-10-06 20:26:29

all u need to know is “Impossible Is Nothing” like what the Brand, Nike’s moto said.

its not impossible, its just hard.

 
Comment by weiojfkadmv,
2008-10-06 20:40:30

i think that is addidas’ moto, nike’s is “just do it”

Comment by DoctaMario
2008-10-07 12:30:26

owned!

I’m sure DAX’ll find a way around this. He always seems to.

 
 
Comment by ???
2008-10-06 20:47:42

Lets see what Sony has to say about what motherboard it has. I just emailed them… hahaha.

 
Comment by TheKrimzonGhost
2008-10-06 20:55:40

ok well this certainly could be looked at as a bad thing….but I believe that this will just force us to find other exploits In the new IPL structure…..If anyone can do it its DAX

-TKG

 
Comment by Shin
2008-10-06 21:52:31

I have two slim-2000, later i want to sell it and buy a 3000, hoping Dark Alex will find out something for the time i’ll buy…
I dunno who is this DAX guy, maybe an ex-sony programmer, but hell, who cares, go man, you can do it (as always)!

Comment by RockSteady
2008-11-30 04:22:34

DAX is Dark AleX hence title

 
 
Comment by lone tiger
2008-10-06 22:25:44

i was hoping the 3000 would b hacked by the time i get it but im willing to wait. my slim recently got its lcd cracked so im waiting if i should get the 3000 or just fix the lcd and wait until i see if i really need the 3000 i only want the anti glare screen but using the psp as a phone?? its really wierd.

 
Comment by Razor Fox
2008-10-06 22:31:48

Not impossible, improbable.

I have gone through 3 phat PSPs, One stolen (had a password, found it smashed a week later about where it was taken. Took to EB with my warranty. Got number two). The second was on my dresser and a roommate dropped laundry one it, cracked it (got new replacement from EB, Love that warranty plan by the way). The third I currently can’t find… I have one of the Darth Vader slim PSPs to preoccupy me for now. Worst part, I don’t have the 4 Gig stick that was in the lost phat one, So no FF7 or MGS for now. Bummer.

As for the new PSPs, they are not that trilling as of yet. Hell the slims weren’t that great an upgrade (Only bought one because I’m a Star Wars whore(Its Vader when he’s badass, not emo, how am I to resist the dark side?)

If they want to win me, internal memory. My ipod is half the size of a PSP and it holds 80 gigs! They can do that, I’ll personally bitchslap Steve Jobs myself. Imagine 40 Psx games, 100 SNES games, and all my music in one device.

Glorious.

Comment by Darkie
2008-10-06 23:49:23

Yeah and you too, theEvilOne, SHUT YER F**KIN grade school!

Comment by Razor Fox
2008-10-07 11:59:38

What in the ever loving F*** are you yammering about? I’m not theEvilOne, if thats what you think, and…

SHUT YER F**KIN grade school!

?

Not graduate much?

 
 
Comment by BIOS Hazard
2008-10-07 11:25:42

That would be magical (and battery sucking) but that’s why we make bigger batteries!

 
 
Comment by Darkie
2008-10-06 23:01:53

@Razor Fox
What the f**kin comment!
Did Darth Vader has invaded your mom’s hole and cut her G-spot with saber?
Think again Son of a B****!

Comment by theEvilOne
2008-10-06 23:11:52

Someone needs to go back to grade school. Learn proper grammer. This is AMERICA.

Comment by usunoro
2008-10-07 00:57:12

It’s spelled grammar.

 
Comment by VADER
2008-10-07 04:27:58

No Bitch, this is the Internet, it’s not America…….

Comment by Razor Fox
2008-10-07 12:03:09

Wow, you seemed cooler before you talked Darth.

*Grabs Star Wars psp, throws into wall. Then burn it*

 
Comment by Dirkovat se musi furt!
2008-10-10 10:44:46

There will be no internet without USA, show some RESPECT.

Comment by MasterMind33
2008-10-11 08:40:17

Yeah, and there would be no USA without Columbus. And there would be no Columbus without his grandfather f***ing his grandmother. So what? Columbus’ Grandfather created the Internet?

Chill out everyone! Showing respect to the creator is of course a good thing. Arguing if the Internet is America is stupid. If it was not for America there would be someone else…

(Comments wont nest below this level)
 
Comment by lol
2008-10-15 13:34:16

i’ve never heard something so stupid before.
Internet is USA’s propiety?
Omg, lol.
You guys never let me down with those stupid statements.

No really. How can someone be so stupid?
Ever heard of backbone?
Try searching a bit bout the story of the internet (Which is really serious busyness [Actually, this should be something to be studied in schools, instead of learing the fuking names of the rat's sexual organ, lol])

(Comments wont nest below this level)
 
Comment by LMAO@U
2008-10-17 05:47:19

The funniest thing I ever heard was term “American English” ha ha ha ha ha.

How can that be, surly it’s just English….Yeah how interesting that would be to learn about some spotty, nose picking nerds who invented the internet.

I would much rather cut the rat’s dick up, lots more fun! What an interesting internet we would have if no other country bothered to invest, develop and participate.

(Comments wont nest below this level)
 
 
 
Comment by YODA
2008-10-07 04:35:20

young padowan I’ll penertrate your mum, with my green saber of love I will…huheuheheuhe

Comment by DARTH MAUL
2008-10-07 11:40:58

Not before I horn her!

Comment by lol
2008-10-15 13:36:52

Jeez.
I feel like i’m in a nerd convntion.

No really….

Mom jokes huh? isn’t that sooo grown up?
lol, this is as worse as flaming the new generation videgame sites, just to make sure that you choosed the right vg. lol

(Comments wont nest below this level)
 
 
 
Comment by Razor Fox
2008-10-07 12:36:40

@ theEvilOne
I second that. Poor dumb bastard might find grade school a challenge though. I think he might be able to handle Dora the Explorer. I pray he wisens up, I fear the stupidity is spreading.

 
Comment by Acid_1
2008-10-08 03:01:24

Dur. Some of us are from Canada you yankee.

 
 
 
Comment by XIYL
2008-10-06 23:44:35

I think he will wait until the PSP 3000 is released to demonstrate any success.

 
Comment by Alex
2008-10-07 02:59:15

do you thing it is possible to change the screen from the psp 3000 to psp 2000 model?

Comment by Thinker
2008-10-07 03:23:25

I don’t think it’s possible because the PSP-3000 has a larger LED screen than the slim and I don’t know if changing the faceplate of the PSP would work.

 
 
Comment by demon007
2008-10-07 04:22:57

seems to me sony have added some extra do_routines in the ipl’s to check mobo version, some clever coding going on there, the flow chart dose make sense but a way round it hex edit the headers dont know, definatley a job for Dark alex/C&D team hope its a possiblity

 
Comment by Code Red
2008-10-07 08:03:01

if it is a possibility or not, they would be wise to allow sony to think they have a secure mobo till the 3000 is released world wide, then they can let out a work around. if such a thing is passable now and they let it out sony would be quick to patch it.

 
Comment by ov3rkill
2008-10-07 08:45:35

But what if some of the PSP-3000’s aren’t using that kind of security, instead they just the ones that can be pandorized. Wouldn’t that be awesome? I’d loved to think that way. If so, I’m gonna get one for a ‘brighter’ tomorrow… err…. i mean display… nothing more. Would love to see that newer LCD in action… on my hands. haha. :)

 
Comment by Tim S.
2008-10-07 11:34:13

hey you don’t need to change the lcd screen from a 3000 to 2000, because the psp 3000 will have a color selecting option, so you can make your graphics look like the 2000 lcd screen or the newer 3000,

also don’t any of you think that the coming of the 3000, as well as the release of the 5.0 beta, will cause further trouble; think about sony always releases a new motherboard with a fw that has been hacked yet, an example would be the fw 4.05 with the new motherboard, but what if they made the 3000 with a 5.0 ipl, then we can be in trouble right? well maybe not i’ve been checking over this data/info that DAX has been posting up and it might be very possible, it could be as easy as sony is baiting us away from something,

but i’ve been thinking would it be possible to downgrade to 4.01 or 4.00 then upgrade to cfw, maybe there’s a way to do this if we “trick” the system, i was thinking by trying to use a hacked psp to edit the update folder of a umd disc to do this, by somehow turning off the check (the check that it runs to see if you have a later or newest version of fw/cfw

what do you guys think? i have faith in DAX but he’s going to need all the support and info he can get, in fixing this manner

 
Comment by Dirkovat se musi furt!
2008-10-07 12:39:39

Long live to DAX, thank you for everything you did for us. Keep kicking sir.

 
Comment by IceSky22AIZ
2008-10-07 13:17:45

Personally hope there will be a way around this. I was hoping to get my hands on a PSP-3000.

 
Comment by JoblessPunk
2008-10-07 13:30:54

I’m glad I got my PSP when I did. I was kind of disappointed when I heard about the PSP 3000, but after seeing what “Upgrades” they made it wouldn’t be worth my money anyways.

Though, I hope that the PSP 3000 becomes hackable. I could see us becoming a dying breed if not…

 
Comment by edito
2008-10-07 14:51:13

For those who say that it can’t be hacked… everyhting that was made to use some sort of code can have its code altered in some way to allow manipulaton. Be it a security bypass or whatever, I’m sure Dax can take it. It’s just another riddle like the first psp was, and the fact that this time around its different, one can’t help but notice that the original psp WAS different. And Sony is on to the hacking that’s going on but maybe they don’t take serious action against it since as more people realize the freedom of the hack, more people buy the Poospe. On the other hand, though, Sony can’t afford to lose their professionalism.

 
Comment by demon007
2008-10-07 20:36:08

Most people don’t even know how to hack/tweak whatever you want to call it, I just want to take the time and thank the coders that know there shit kudos! <…..Much Respect as the command lists and what they do in a many program language’s takes time to learn and well its very hard to me imho, Going back to my basic days (lol)
10 print “hello”;
20 goto 10
RUN
<…fill screen (boring but fun).

when it comes to hex editing/or even trying to understand any of it i havn’t got a clue, i do know about integers/and varibles but that it boo!

 
Comment by demon007
2008-10-07 20:49:01

ATTN: microsoft please port pascal programing language to x64 vista thanks :)

 
Comment by Jakob777
2008-10-07 21:39:50

Well I hope D_A is doing the smart thing, showing up saying he cant hack it, just so sony dosent get anything smart up there sleave (hardware) for the 3000, and then when it drops D_A will let us know what chumps they were and we will have to wait for the 4000 till anything we have to worry about.

BTW I just hacked a 2001 in 3 min flat, the god of war ed and with all the improvments in the magic stick stuffs I didnt need a fat and had a tool battery already from the darth vader ed I got.

So keep it up D_A and I would gladly like to see you continue to show them they dont have the upper hand.

 
Comment by mike501
2008-10-07 21:52:51

Attention lusers:
Darth Vader/Darth Maul/Star Wars is NOT i repeat, NOT cool. Star wars is lame, you guys are nerds, get a life, get a gf and get LAID. for fuck sakes, its nerds like you guys that make stereotypes for regular gamers like us.

Comment by Darkie
2008-10-07 22:53:46

Yeah, I’m agree with you, mike.
Those sucker needs to learn how their momma doin blowJOB rather than to playin star wars in the toilet.

@ theEvilOne
@ Razor Fox

Why don’t you guys try to find a whore and try out your F**ckin Saber on her.

Comment by J-man
2008-10-07 23:38:49

xD

 
Comment by Razor Fox
2008-10-12 18:29:29

Those sucker needs to learn how their momma doin blowJOB rather than to playin star wars in the toilet.

????

You learned how your mother gives a blowjob and your making fun of me… They must love you over at the Jerry Springer show.

@ mike501, I was making a simple joke at the model of PSP I have. Darkie started some fucked up sword rape shit. The Convention people are the people that should piss you off. Also you should be pissed at those who support your views by saying getting blowjobs from your mom is cool… I’m sorry, but you really need to learn to composed a fuckin’ sentence. Either he’s an idiot of epic proportions, raped by mommy and daddy as a kid, or just posing.

 
 
 
Comment by cboushell
2008-10-07 23:02:11

I would have to side with those of you who think he(DA) has already figured out a way to hack the TA88v3, and is doing the smart thing for now and keeping quiet about it, and hoping that motherboard or one similar is in the 3000.

 
Comment by dermo
2008-10-07 23:54:15

You all CLEARLY no idea what you’re talking about. He’s pointing out the reserved x20 blocks are now in use and the “opening block sizes” (can’t think of English phrase) have changed.
In other words, Sony’s rebuilt their ipl system removing any free space that was available to implement a loader.
dax probably made this statement as a request for help.
Think before you post. I would help him but I can’t afford another one of those bloody units.

Also I am quite sure, if nothing else, devolution would work.

Comment by MasterMind33
2008-10-11 08:55:32

“removing any free space that was available to implement a loader”

From what I understand, he’s not saying this. He’s saying that it just doesn’t boot unless you put the right checksums in the remaining 32 bytes.

He never used this space, it was just useless.

 
 
Comment by dballer
2008-10-09 17:10:09

i just bought a TA88v3 psp (madden blue) and i got it hacked!
i used an old version of DC (i think it was 5) and it gave me 3.71m33. then i upgraded from there to 4.01m33.
it works fine for me…..

Comment by sd
2008-10-10 02:09:45

i think the psp you hacked is not a TA88v3 psp

 
Comment by han daehan
2008-11-08 03:15:00

are you sure that is TA-88 ver 3? im pretty sure that is TA-88 ver 2 because ver 2 can be hacked by using dc6 or dc7 pandora but the ver 3 cannot

 
 
Comment by Tommyb
2008-10-10 06:58:33

Dax: Try a flux capacitor… it worked for Marty and Doc :D

Seriously though thanks for all your hard work! Keep it up, it has to break sooner or later.

 
Comment by hellboy
2008-10-10 11:57:44

dax will show us how powerfull he is than SONY!

 
Comment by Sid
2008-10-10 21:09:40

Yo, does anyone know the amount of time it will take to over come this problem.

Comment by MasterMind33
2008-10-11 08:57:03

GET REAL!
We don’t now HOW to solve it. How could we know WHEN??? lol man!

Comment by DSpider
2008-10-29 04:26:23

Ignore him. He’s a dumbass. The PS3 has been around for a couple of years now and only recently they’ve made (little) progress…

It could take a month or it could take a year. Nobody knows ! Only God does. Until then, you’re stuck with a shiny paper weigh that can play mp3’s and videos and pictures and UMD’s. Get a refund or shut your mouth and keep waiting.

 
 
 
Comment by du.der.icio.us
2008-10-11 09:48:52

If you can get physical access to a system, it can be hacked.

 
Comment by billa
2008-10-11 10:42:44

ugh, that sucks, maybe someone could put some kinda mod chip in it or something? modify the cpu or something?

Comment by Acid_1
2008-10-14 02:58:15

Lo and behold, we get people who toss out random words hoping that they sound techy enough that they may sound legit.

 
 
Comment by drmoo
2008-10-18 13:51:41

@billa: I’m sure Devolution would work

Physical access? I have an idea now. Watch this. Anybody with a hacked PSP, load an ISO. Now go to Game Sharing. Even though the digital signature is broken from the game, it is still possible to send the game to another PSP.

I’m looking into that now. Modify the Game Sharing sectors of the game may allow physical access to the flash0 or flash1 drives. It’s an idea anyway…

Comment by han daehan
2008-11-08 03:20:26

so how can you do that? you can use game sharing in the Psp with TA-88 ver 3 but as long as it is not been hacked yet, you can’t save the ISO games in that psp

 
 
Comment by tim nice but dim
2008-11-30 13:19:23

I think, you aint got the foggiest, mate.

 
Comment by Sgt Sanders -U.S.M.C-
2008-12-07 15:38:37

LOL you guys are wild! I just hope that DAX can get the psp hit up. I got lots of Marines here trying to get the new one. Its the only thing next to the 360 that keeps up morale here along with care packs in the Iraq sandbox so. You got my support and by all means hit me up. I got a little time to get to the net I can. Most of these pages get filtered but, nevertheless.
Justine.Sanders@tq.mnf-wiraq.usmc.mil.
Im out!

 
Comment by Tim S.
2008-12-27 00:35:57

lol Game Sharing, that’s used only with certain games that are supported (ie: demos and single umd multiplayer), you can’t use it to transfer over full isos, and second what would be the use of that? it’s all temp data usually anyways, you wanna play downloaded games then spend some money and learn how to burn umds

 
<< Login :: Register >>
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)


Affiliates



Video Games






PSP Hacks Archives