PS3:PS3Xploit (NAND): Difference between revisions

From ConsoleMods Wiki
Jump to navigation Jump to search
mNo edit summary
mNo edit summary
Line 1: Line 1:
{{Warning|There is always a chance of bricking your console when flashing data to the NAND/NOR chip.}}
{{Warning|There is always a chance of bricking your console when flashing data to the NAND/NOR chip.}}
To minimize the chance of bricking, do NOT skip any of the following sections. This process will use a recently released software hack to to allow the installation of custom firmware. Check to make sure that your [[PS3:Updating Firmware|console is CFW compatible]].
This page describes the self-hosting method for PS3Xploit. It is recommended to use an internet-hosted website instead, as they are more simplified and carry less risk of error. For instructions on using an internet-hosted website, please visit the [[PS3:PS3Xploit|PS3Xploit page]].  
 
'''With any newly released exploit of this caliber, there is always a chance that you can brick your console. Follow all sections of this guide exactly as how they are written.'''


==NAND or NOR?==
==NAND or NOR?==


It is recommended to check the model number on the back of your console and compare it to the chart below to determine if your console is NAND-based or NOR-based. If your console is not NAND based, go back to the [[PS3:How to Hack your PS3|How to Hack your PS3]] page and choose a different guide.
It is recommended to check the model number on the back of your console and compare it to the chart below to determine if your console is NAND-based or NOR-based. If your console is not NAND based, use the [[PS3:PS3Xploit (NOR)|PS3Xploit (NOR)]] page instead.


{| class="wikitable"
{| class="wikitable"
Line 22: Line 20:
|-
|-
| CECH-3000+
| CECH-3000+
| Cannot downgrade
| Not compatible.
|}
|}
If you have a CECH-25XX console, you will have to use [[PS3:MinVerChk|MinVerChk]] to check if it's compatible.


==Materials Needed==
==Materials Needed==


* A USB storage device, '''formatted as FAT32 with 32kb allocation size'''
* A USB storage device, '''formatted as FAT32 with 32kb allocation size'''.
* [http://ps3xploit.com/hfw/release/NOR_NAND_writer_release_2.0.2_PS3Xploit.zip NOR/NAND Flash Writer zip file] (extracted on Desktop)
* [https://raw.githubusercontent.com/littlebalup/PyPS3tools/master/PyPS3checker-standalone-package_2021-22-08_135015.zip PyPS3Checker].
* ps3_dump_checker.exe from [https://github.com/Edythator/PS3DumpChecker/archive/master.zip Edythator's version of Swizzy's Dump Checker]
* [http://ps3xploit.com/hfw/release/NOR_NAND_writer_release_2.0.2_PS3Xploit.zip The NOR/NAND Flash Writer zip file] (extracted to Desktop)
* [https://mega.nz/#!SAYhnYYB!6CmxOz0H_pSuVRb4YZ7-lYvY66hP0LlohgVMWfFut4Q 4.85.1 HFW .PUP]


==(Method 1) Using an Exploit-Loading Site==
==Self-hosting the Exploit==
 
# Double check that [[PS3:PS3Xploit (NAND)#NAND or NOR?|your console is a NAND console, and not a NOR console]]. '''You will risk bricking your console if it is a NOR console!'''
# Ensure your USB drive is formatted as FAT32, and that it is recognized by your PS3 by checking that it shows up on the XMB under Photos, Music, or Videos column.
# Plug the USB drive into your computer, and copy over the "flash_485.hex" file to the root of the drive.
#* [[PS3:MD5 Hash|Verify the MD5 checksum]] of this file matches the checksum: `2D74B066E7453E6B1336E36C410FB1EB` before continuing. If they match, you may continue, otherwise you will need to redownload the NOR/NAND Flash Writer zip file and verify again.
# Update to 4.85.1 HFW using [[PS3:Updating Firmware|this guide]] and the .PUP linked in the "Materials Needed" section.
#* [[PS3:MD5 Hash|Verify the MD5 checksum]] of the PUP matches the checksum: `C6632994C04D0ED8C555091F3FDE9BBB` before continuing. If they match, you may continue, otherwise you will need to redownload the PUP and verify again.
# Plug the USB drive into the right-most USB port.
# Navigate to the Network column of the XMB and select "Internet Browser". Press Start and enter the URL for the PS3Xploit website: `http://ps3xploit.com/hfw/writer/index_nand.html`. You should receive a message indicating that your console is compatible. If you do not, reinstall 4.85.1 HFW. Press Cross to dismiss the compatibility message.
# Press Triangle, scroll down one option and select Tools → Home Page. Scroll down two options to "Use Current" and press Cross. Scroll down to OK and press Cross to exit this menu.
# Press Circle and choose Yes to exit the browser.
# Launch the Internet Browser again. Read the warnings on screen, and ensure that the `/dev_usb000/flash_485.hex` option is checked.
# Hover over the "Initialize exploitation" button and press Cross. A success message should almost instantly appear indicating "Exploit Initialization SUCCESS...!". If it fails, follow the on-screen instructions to refresh the page.
# Select "Patch NAND Flash Memory". A message should appear saying "Proceeding to patch NAND Flash Memory...". After a few minutes, it should change to "NAND Flash memory patch operation completed..!". If it takes longer than 5 minutes to complete, exit the browser and try again.
# On the PS3, navigate to `http://ps3xploit.com/hfw/dumper/index_nand.html`. Press Triangle, scroll down one option and select Tools → Home Page. Scroll down two options to "Use Current" and press Cross. Scroll down to OK and press Cross to exit this menu.
# Press Circle and choose Yes to exit the browser.
# Launch the Internet Browser again. Read the warnings on screen, and ensure `/dev_usb000/dump.hex` is selected, click the "Initialize exploitation" button, wait for a success message, and then choose "Dump 239MB NAND to USB/Card device" and wait until you receive a message saying "NAND Flash dump operation completed..!".
#* If it takes longer than 30 minutes, try another USB storage device.
# Unplug your USB storage device and plug it into your PC. Drag your dump.hex file over the file "ps3_dump_checker.exe". The program will open and validate your dump. If the dump comes up as "OK" it's okay to proceed. If it comes up as "BAD" and lists the only failures as the ROS0/ROS1 hash, you're okay to proceed.
#* If you receive a message saying that it is the wrong file size, you likely have a NOR console and not a NAND console. [[PS3:PS3Xploit (NAND)|Check again here]].
#* If you receive an error for only SKUIdenityData (and maybe also ROS0 or ROS1), your console is likely refurbished and it is okay to proceed.
#* '''BACKUP THE DUMP.HEX FILE IF IT IS "OK"... SHOULD YOU MANAGE TO BRICK YOUR PS3, THIS FILE WILL BE USED WITH A HARDWARE FLASHER TO RESTORE THE CONSOLE'''
# Restart your console and proceed to install a CFW of equal or higher version with the [[PS3:PS3Xploit (NAND)#Installing a CFW|"Installing a CFW"]] instructions found below.
 
==(Method 2) Self-hosting the Exploit==
 
These steps are an alternative to using an exploit-loading site.


# Double check that [[PS3:PS3Xploit (NAND)#NAND or NOR?|your console is a NAND console, and not a NOR console]]. '''You will risk bricking your console if it is a NOR console!'''
# Double check that [[PS3:PS3Xploit (NAND)#NAND or NOR?|your console is a NAND console, and not a NOR console]]. '''You will risk bricking your console if it is a NOR console!'''
Line 84: Line 56:
#* If you receive an error for only SKUIdenityData (and maybe also the ROS0 hash or ROS1 hash), your console is likely refurbished and it is okay to proceed.
#* If you receive an error for only SKUIdenityData (and maybe also the ROS0 hash or ROS1 hash), your console is likely refurbished and it is okay to proceed.
#* '''BACKUP THE DUMP.HEX FILE IF IT IS "OK"... SHOULD YOU MANAGE TO BRICK YOUR PS3, THIS FILE WILL BE USED WITH A HARDWARE FLASHER TO RESTORE THE CONSOLE'''
#* '''BACKUP THE DUMP.HEX FILE IF IT IS "OK"... SHOULD YOU MANAGE TO BRICK YOUR PS3, THIS FILE WILL BE USED WITH A HARDWARE FLASHER TO RESTORE THE CONSOLE'''
# Restart your console and proceed to install a CFW of equal or higher firmware version with the [[PS3:PS3Xploit (NAND)|"Installing a CFW"]] instructions found below.
# Restart your console and proceed to install a CFW of equal or higher firmware version with the [[PS3:PS3Xploit (NAND)|"Installing a CFW"]] instructions.
 
==Installing a CFW==
 
# Remove the USB Drive from your PS3 and plug it into your PC.
# Create a folder on the root of the drive titled "PS3", and inside of that folder, create a new folder called "UPDATE".
# Download your desired CFW of equal or higher version, or a CFW spoofed to the latest version. The most recent firmwares can be found [[PS3:Firmwares|on this page]]. Regardless of which firmware you choose, [[PS3:MD5 Hash|verify the MD5 hash]] of the .PUP file to ensure that the file is not corrupt.
#* In order to go to a lower version CFW, you must install a CFW of equal or higher version and then install the [http://www.mediafire.com/file/kdmyl2g967y15m7/toggleqa.pkg Habib QA Toggle PKG], run it, and reboot before you can install the desired CFW.
# Rename the CFW .PUP to `PS3UPDAT.PUP`.
# Move the PUP to the UPDATE folder on the USB drive.
# Remove the USB drive from your PC and plug it into a USB port on your PS3. '''Make sure to remove any disc inside your console'''.
# On your PS3, navigate to Settings → System Update, then Update from Removable Media.
# Go through all the necessary prompts to install the firmware onto your system. If all goes well, you should now be on CFW.
#* If you get a error saying "The data is corrupted" and you had verified the MD5 hash, then the PS3xploit patch most likely failed and you should try the exploit again.
#* If you receive error 8002F1F9, check that your disc drive and Bluetooth are working. If they are not, you need to use a No-BD firmware.
# (Optional) Visit [[PS3:Recommended Setup|this page of the wiki]] to learn about the basic things you can do with your newly hacked PS3, and explore [[PS3:PS3 Mods Wiki|the rest of the PS3 Mods Wiki]].
 
==Bad Flash Recovery==
 
In the event that something goes wrong while flashing your NAND, and your console is not working properly (or "bricked"), you may be able to recover it by updating the firmware normally through the XMB, ensuring you haven't shut down your console. Otherwise you can possibly boot into [[PS3:Recovery Mode|recovery mode]] and reinstall your current firmware from there. If this does not work, you will need to use a a hardware flasher to reflash. Please see Bad Flash Recovery section of the [[PS3: E3 Flasher#Bad Flash Recovery|E3 Flasher]], [[PS3:Teensy#Bad Flash Recovery|Teensy]] or [[PS3:ProgSkeet#Bad Flash Recovery|ProgSkeet]] guides.

Revision as of 18:45, 1 November 2021

Exclamation-triangle-fill.svgThere is always a chance of bricking your console when flashing data to the NAND/NOR chip.


This page describes the self-hosting method for PS3Xploit. It is recommended to use an internet-hosted website instead, as they are more simplified and carry less risk of error. For instructions on using an internet-hosted website, please visit the PS3Xploit page.

NAND or NOR?

It is recommended to check the model number on the back of your console and compare it to the chart below to determine if your console is NAND-based or NOR-based. If your console is not NAND based, use the PS3Xploit (NOR) page instead.

Model Flash
CECHA through CECHG NAND
CECHH through CECHQ NOR
CECH-2000 through CECH-25XX NOR
CECH-3000+ Not compatible.

If you have a CECH-25XX console, you will have to use MinVerChk to check if it's compatible.

Materials Needed

Self-hosting the Exploit

  1. Double check that your console is a NAND console, and not a NOR console. You will risk bricking your console if it is a NOR console!
  2. Update to 4.85.1 HFW using this guide and the .PUP linked in the "Materials Needed" section.
    • Verify the MD5 checksum of the PUP matches the checksum: C6632994C04D0ED8C555091F3FDE9BBB before continuing. If they match, you may continue, otherwise you will need to redownload the PUP and verify again.
  3. Extract the NOR/NAND Flash Writer zip file into a folder labeled "NANDFlasher".
  4. Inside of the NANDFlasher folder, create a folder called "htdocs".
  5. Move the "ps3xploit_writer_v201.js", and the "index_nand.html" files into htdocs, then rename "index_nand.html" to "index.html".
  6. Ensure your PS3 is connected to the same network as your PC, in order to be able to connect to the web server. This can either be through WiFi or network cables to your router.
  7. Move the "miniweb.exe" file into the NANDFlasher folder and run it. This will start the web server on your local network.
  8. Plug the USB drive into your computer, and copy over the "flash_484.hex" file to the root of the drive and then plug it in the right-most USB port on the PS3.
  9. Turn your PS3 off, then turn it back on again.
  10. Navigate to the Network column of the XMB and select "Internet Browser". Press Start and enter the IP address and port that the miniweb window displays (example: "192.168.11.010:1337"). You should receive a message indicating that your console is compatible. If you do not, reinstall 4.85.1 HFW. Press Cross to dismiss the compatibility message.
  11. Press Triangle, scroll down one option and select Tools → Home Page. Scroll down two options to "Use Current" and press Cross. Scroll down to OK and press Cross to exit this menu. Press Circle and choose Yes to exit the browser.
  12. Launch the Internet Browser again. Read the warnings on screen, and ensure that the /dev_usb000/flash_484.hex option is checked.
  13. Hover over the "Initialize exploitation" button and press Cross. A success message should almost instantly appear indicating "Exploit Initialization SUCCESS...!". If it fails, follow the on-screen instructions to refresh the page.
  14. Select "Patch NAND Flash Memory". A message should appear saying "Proceeding to patch NAND Flash Memory...". After a few minutes, it should change to "NAND Flash memory patch operation completed..!". If it takes longer than 5 minutes to complete, exit the browser and try again.
  15. On the PS3, navigate to "192.168.11.010:1337"/index_nand.html. Note the example IP we used from earlier. Press Triangle, scroll down one option and select Tools → Home Page. Scroll down two options to "Use Current" and press Cross. Scroll down to OK and press Cross to exit this menu.
  16. Press Circle and choose Yes to exit the browser.
  17. Launch the Internet Browser again. Read the warnings on screen, and ensure /dev_usb000/dump.hex is selected, click the "Initialize exploitation" button, wait for a success message, and then choose "Dump 239MB NAND to USB/Card device" and wait until you receive a message saying "NAND Flash dump operation completed..!".
    • If it takes longer than 30 minutes, try another USB storage device.
  18. Unplug your USB storage device and plug it into your PC. Drag your dump.hex file over the file "ps3_dump_checker.exe". The program will open and validate your dump. If the dump comes up as "OK" it's okay to proceed. If it comes up as "BAD" and lists the only failures as the ROS0/ROS1 hash, you're okay to proceed.
    • If you receive a message saying that it is the wrong file size, you likely have a NOR console and not a NAND console. Check again here.
    • If you receive an error for only SKUIdenityData (and maybe also the ROS0 hash or ROS1 hash), your console is likely refurbished and it is okay to proceed.
    • BACKUP THE DUMP.HEX FILE IF IT IS "OK"... SHOULD YOU MANAGE TO BRICK YOUR PS3, THIS FILE WILL BE USED WITH A HARDWARE FLASHER TO RESTORE THE CONSOLE
  19. Restart your console and proceed to install a CFW of equal or higher firmware version with the "Installing a CFW" instructions.