PS3 Exploiting 4.90 OFW (Installing CFW & Running PS3HEN) Flash Writer / PS3HEN now supporting 4.90 FW

(Update: PS3HEN 3.2.0 w/ 4.90 Support Released) Exploiting a PlayStation 3 console in firmware 4.89 was a bit of a mess to say the least and added alot of confusion that was compounded by bad advice's on various platforms and even the emergence of dangerous software. With incomplete version of the closed source PS3 Toolset by bguerville (of PS3Xploit Team) that were being distributed around the net, Causing random bricks to user's as they were not using the true Toolset as it was not the Original Code of the Toolset (just partial code and some bypasses/removal of check's, that are normally designed to make the toolset safe and brick-proof originally in the official. but the incomplete you have to hope everything goes smoothly) .

So, many great developer's that are active in the PS3 scene now and whom have return to the scene and a new name have come together with psx-place to bring you the proper exploration of 4.90 on your PS3 Console. So we do not have the same confusion in the scene that we seen in 4.89 and the unofficial brick-ware floating from unreliable and untrustworthy sources and software..

We want to set the stage for the safest methods from the names of developer's you trust that been in the scene for year's and the names who have been advancing the community for a long time.Not having to rely on the untrustworthy sources and services.


PlayStation 3 all models.jpg

UPDATE: The last missing piece in 4.90, PS3HEN 3.2.0 has been released with 4.90 Support.

Which Exploit can I run on my PS3 Model?
PS3 CFW - Not installable on some PS3 models
PlayStation 3 Custom Firmware has more capabilities and more access then the PS3HEN exploit
PS3HEN - Capable of running on all PS3 Models
The PS3HEN exploit is a very powerful Homebrew Enabler, but does not contain all the functionality as CFW.

See a comparison of the two PS3 exploit's > here <


  • How to find model number of PS3
    • Locating the sticker on back of the console will show the model number
      9252-18c0504e4fef01a250e320326a2b2cb1.png 9250-494151f41ac9a8423b8ef05fe718d583.png 9251-ffd94adb37e20dbb2bcbefe06d91bcd3.jpg

    Can your PS3 models install a CFW?
    • Original (Fat) Models - All original fat models are CFW compatible
    • Slim Models (Check Slim Model's Carefully as some models are not CFW compatible)
      • CECH - 20xx / 21xx Both models are CFW- compatible.
        • CECH - 25xx
          This is the only model that needs a closer look. Some can use CFW and some can not use it. Consoles with a minimum version (minver) of 3.56 or lower can install CFW. Consoles with a minver of 3.60 or higher must use HEN.

          An offline tool called MinVerChk (Minimum Version Checker) can also be used to find the minver. It is disguised as a firmware update. When you try to install it, the installation will fail and it will tell you the minver. It is available HERE.
    • SuperSlim Models CECH - 3xxx - This model must use PS3HEN (unable to install a CFW)
    (info by @Coro)

  • Compatible Models
    • ALL PS3 Models can run the PS3HEN exploit. but if your console has the ability to install CFW that is the preferred exploit, as its a full jailbreak and offer's more access..
    • However PS3HEN is a very powerful exploit and offer's many of the same features on CFW such as homebrew support, backups for your personal collection's and more. You can see a Comparison of the two PS3 exploits in this chart >here<



.
Checking Firmware & Preparing Exploit method
Checking your console's System Firmware version is normally a very important step, if current firmware is not exploited (or proper tools updated). Since we have updated methods on firmware 4.90 OFW we do not need to check the firmware version (if installing PS3HEN) as we can exploit from 4.90 and from (CFW) we do not have to worry about firmware version unless on 3.55 or below for cfw capable models as you can install CFW directly via USB without exploiting.


Next Step
: Installing HFW (hybrid firmware)

Now you will need to install 4.90 HFW, as either exploit on the PS3 that we are about to cover will require HFW to be installed. (CFW Flash Writer or PS3HEN) Here is a link to 4.90 HFW (released by @Joonie) , it serves as a webkit entry point for each respective exploit . 4.90 HFW (hybrid firmware) is a 4.90 Official Firmware with 4.82 webkit re-injected.


Next Step: Choosing your exploit path of CFW or PS3HEN
After the installation of HFW, you should now know which exploit your PS3 Models is capable of depending on its model number and information from above, Now here are details and information for getting either of the exploits running on your PS3 console after you have successfully installed 4.90 HFW (Official):

  • Ps3 Custom Firmware Exploiting FAQ for 4.90
    I am on CFW already, how do i update to a newer version?
    • No need to exploit your console again, You simply install the new (cfw) PUP via USB method (from System Update or Recovery Menu) - via Sony's official USB firmware update procedure (just with a CFW PUP file instead of a Official FIrmware PUP) Create Folder's struture and rename pup on USB Root as follow's below for PS3 to reconize the PUP (firmware) file on a usb device.
      • X:/PS3/UPDATE/PS3UPDAT.PUP

    Can any "mirror" or "clone" of bguerville's PS3 Toolset be trusted?

    • NO, no matter what they claim, the truth of the matter is they are using an incomplete version of the code of the toolset and have made dirty modification and replacements just to essentially fool and trick the toolset to perform actions it would otherwise reject (and save from a bad installation), That is why the bricks are random and occur in various situations, depending on system error's / user actions or corrupted files. That's also why it can work for some, as not everytime who use's it will have an error occur and some situations can be more prone to errors, its just not a good idea if you fear risking the console to a brick,.
    • The source code has never been made public, it's still a closed source project, it has never been leaked. The toolset was only partially dumped by Aigon and the code published on Github (sat vacant for almost a year) and then was taken by various other's and those people are not being honest about the risk, just showing some of the successes and act like it's new and improved dumps when they are using the same code and readme's of the original Aigon incomplete dump.

    Is the Unofficial CFW Flash Writer safer then using Incomplete (unofficial) PS3 Toolset's?
    • Yes, in 4.90 using the CFW Flash Writer is a much better option and provides SAFETY checks that the incomplete toolsets do not have and is approved by community developer's. That is something that the incomplete-unofficial bgtoolset's can't provide..
    How to exploit my PS3 (CFW capable model) so i can install a CFW?
    • PS3Xploit's (CFW) Flash Writer is back!! With an unofficial update from @imn7 for 4.90 Support.
    browser.png 0GpAkEg.png

    Background (About)

    • The CFW Flash Writer is back in firmware 4.90, it has been sometime since we have seen this tool (last seen in firmware 4.85). Originally developed by the PS3Xploit Team in firmware 4.82 and was officially supported up until 4.85, as it was later replaced with the official bguerville Toolset in firmware 4.86. Currently, with the official bgtoolset down and only incomplete variants with potential brick issue's. There was a need to bring back the Flash Writer.
    • Now in 4.90, developer @imn7 has made an unofficial update to the much needed Tool, we have seen the developer in the past make an unofficial update that added some additional checks and security that was improvements over the original, so lmn7 is more then capable of making a proper unofficial update and even adding to the project, with even more checks added to the 4.90 update

    Exploiting your PS3 using the Flash Writer:
    See Release Thread (4.90 CFW Flash Writer)

    Added Features from @Imn7
    • Minimum firmware version check
    • Current firmware version check
    • Custom firmware check
    • Hybrid firmware check
    • Patch file hash check
    • Multiple patch chain checks to prevent memory corruption
    • Ability to dump the onboard flash to a USB drive before patching
    • Much more reliable memory searching
    • Much faster flash dumping for NAND based consoles

    See Release Thread >>
    https://www.psx-place.com/threads/hfw-4-90-1-hybrid-firmware.39758/
    Tutorial's
    Now you have successfully ran the Flash Writer Tool and Patched the PS3 Flash,
    You are now ready install a 4.90 CFW
    (once on 4.90 CFW and you Q/A toggle your Ps3 you can go to lower firmware if you choose to.)


    Choosing a CFW will depend on your needs for a Custom Firmware user, If you are new we suggest using
    4.90 Evilnat CEX , It's a powerful-feature rich CFW that has COBRA v8.4 payload injected and provide a wide array of features.

    If you are more advanced user, you already know about the other builds that are available such as the OverClock (OC) version, that can gain some performance in some games, but can also be a risk if your console is prone to heat issue's, , PEX (hybrid of CEX and DEX Firmware) which was introduced in 4.89 (similar to Rebug REX) or the builds that are for damaged console (noBD / noBT). You can view more about the details of those Custom Firmware from Evilnat's Official release thread for 4.90 Evilnat's CFW.



    @Evilnat's 4.90 Custom Firmware Builds

    • OFW - Official Firmware
    • CFW - Custom Firmware
    • CEX - Refers to Retail Firmware (what is installed on all PS3 Sold to public)
    • DEX - Refers to Debug Firmware (the officiial debug test firmware for official developer's)
    • REX - Refers to a CFW type created by Team Rebug, that is a hybrid of CEX and DEX firmware which create's REX. ,
      • D-REX: Same as REX for installing on DEBUG console.
    • PEX - Refers to a CFW type created by Evilnat, that is like REX but use's an earlier 4.84 DEX (Ported to 4.89) which creates PEX
      • D-PEX Same as PEX for installing on DEBUG console.
    • noBD - A Special CFW (for broken hardware (Blu-Ray Drive in this case)), that patches out the drive so the console can be used without the drive think of it as the "The PS3 Digital Edition". Without this patch those damaged console's can not launch or leave the XMB, even things that are stored on the HDD, so if your console is not reading disc and not launching anything from the XMB, it might just need a noBD firmware.
    • noBT - Just like the noBD firmware, this is no BlueTooth.
    • Standard CFW: This is your normal base CEX custom firmware with no extra payloads (such as Cobra or Mamba) provides homebrew support and backup capabilities.
    • Cobra CFW: This is a standard cfw but also contains the Cobra payload with expanded features (background plugin support / ISO Support / NETISO support / ect..)
    • DB Firmware - This is a Dualboot firmware for CFW user's this is exactly like OFW, but with a small modification for CFW. It's OFW for CFW user's as it allows you to return to a CFW later on without the need to Jailbreak or exploit the system again. This can be very useful when playing your disc games online and want to be cautious of a PSN-ban for using a modded system .
    • OC: refers to the RSX/CPU overclocking of the CFW build.

    CFW Evilnat 4.90 Cobra 8.4 [PEX] [CEX]
    CFW Evilnat 4.90 Cobra 8.4 [PEX] [CEX] [noBD]
    CFW Evilnat 4.90 Cobra 8.4 [PEX] [CEX] [noBD+noBT]
    CFW Evilnat 4.90 Cobra 8.4 [PEX] [CEX] [noBT]
    CFW Evilnat 4.90 Cobra 8.4 [PEX] [CEX] [OC]


    CFW Evilnat 4.90 Cobra 8.4 [D-PEX] [DEX]
    CFW Evilnat 4.90 Cobra 8.4 [D-PEX] [DEX] [noBD]
    CFW Evilnat 4.90 Cobra 8.4 [D-PEX] [DEX] [noBD+noBT]
    CFW Evilnat 4.90 Cobra 8.4 [D-PEX] [DEX] [noBT]
    CFW Evilnat 4.90 Cobra 8.4 [D-PEX] [DEX] [OC]


    CFW Evilnat 4.90 Cobra 8.4 [CEX]
    CFW Evilnat 4.90 Cobra 8.4 [CEX] [noBD]
    CFW Evilnat 4.90 Cobra 8.4 [CEX] [noBD+noBT]
    CFW Evilnat 4.90 Cobra 8.4 [CEX] [noBT]
    CFW Evilnat 4.90 Cobra 8.4 [CEX] [OC]


    CFW Evilnat 4.90 Cobra 8.4 [DEX]
    CFW Evilnat 4.90 Cobra 8.4 [DEX] [noBD]
    CFW Evilnat 4.90 Cobra 8.4 [DEX] [noBD+noBT]
    CFW Evilnat 4.90 Cobra 8.4 [DEX] [noBT]
    CFW Evilnat 4.90 Cobra 8.4 [DEX] [OC]

    Update: Here are a couple video from a trusted YouTuber's covering this article and the processes @MrMario2011, & Modded Warefare video's can help you if your need a visual.
    (Information by these two are usually very sound, however not all YouTuber's should be trusted. If they are not leaving developer links and official download be wary)

  • Official website ps3xploit.me is currently down (update see latest details>> here), 4.90 PS3HEN update to be released soon..
    .PS3HEN 4.90 FAQ
    What is PS3HEN and how does it differ from CFW?
    PS3HEN is a homebrew enabler that must be enabled on every console boot, where as ps3 cfw is a full jailbreak that is active on boot. There are other difference's between the two exploits that can be found >here< in a comparison chart of the two exploits
    What has happen to PS3HEN official website's?
    The PS3Xploit .com .net & .org domains no longer belong to the team. They were taken and resold by GoDaddy (@esc0rtd3w explains here).
    The Ps3Xploit.me still belongs to the team (last we heard) but its currently down.It has been having the same faith of bgtoolset and being recently flagged by Spamhuas group, So status is limbo and we are just awaiting to hear something back, hopefully positive,
    Why are mirror's consider safe(r) on PS3HEN, but not unofficial bgtoolset?
    The short answer: One project is Open Source (Ps3HEN) and its full code is available, where as the other is closed source (bguerville's PS3 Toolset) and its full code is not available , there are only incomplete dumps of the toolset that provide no safety checks and are missing various parts of the toolset PS3 developer's around the scene and the creator of the toolset itself have expressed the danger's of random bricks that can occur and we have seen that with various reports. .So that the is the differences between the two. But don't let your guard down on PS3HEN mirror's as anyone can use the code and add malicious things when they compile it. So beware of those danger's as well, Only trust approved Unofficial Tools and Mirrors. We have been seeing people clone the PS3Xploit's main website (ps3xploit.me) and use other domain extensions with the ps3xploit name's see more on that here Also there is a discussion in this thread about mirror's and unofficial update's: https://www.psx-place.com/threads/is-this-another-scam.39853/
    Where is a trusted mirror for PS3HEN?
    PSX-Place moderator @Coro has been providing an approved ps3xploit team mirror for PS3HEN,. It's a 1:1 copy of the latest version. You can find that @ https://ps3addict.github.io/ (if every needed - UPDATE ps3xploit.me is back online see official status of website here)

    Who made the update to PS3HEN 4.90?
    Developer @Joonie made the update, This is kind of an unofficial / official update.. Many of us know Joonie from being a developer on Team Rebug and also one of the later developer to join the PS3Xploit Team, releasing and creating the HFW concept, that reversed a patched exploit that we still use in 4.90., Now in 4.90 the developer has stepped in when PS3HEN has needed an update and also making sure HFW was good to go, as HFW will play an important role for 4.90 exploits..​
    .
    PS3HEN (v3.2.0) with 4.90 Support: Update by @Joonie. & @esc0rtd3w


    upload_2023-3-5_23-42-19.png

    Coming Soon, details will be posted
    RELEASED >>HERE <<

    Update (March 13) PS3HEN 3.2.0 w/ 4.90 HFW Support has been Released!!!
    .

    See Details:


    Chanegelog (v3.2.0 w/ 4.90 HFW Support)

    Global Changes
    • - Added support for 4.90 firmware. Special thanks to lmn7 and Joonie for their work on porting offsets, HFW, and other code contributions
    • - Xai updated to support new HFW Tools options. Special thanks to Evilnat for his help and code contributions
    HEN Plugin Changes
    • - Automatic reboot after successful initial HEN installation from Network and USB
    • - Added Clear Browser Cache code, currently disabled. This will be moved into xai_plugin (thanks xfrcc)
    • - Changes to HEN plugin attempting to make it unload properly (thanks @aldostools, TheRouLetteBoi)
    • - Updated host domain name from ps3xploit.me to ps3xploit.me
    Payload Changes
    • - Added mutex functionality to map_path and open_path_hook (thanks bguerville)
    • - Updated, fixed, and optimized map_path and open_path_hook. Also kept support for legacy homebrew that uses map_path (thanks bguerville)
    • - Added stat to open_path_hook for DEBUG build only (thanks DeViL303 for the idea and bguerville for the code and implementation)
    • - Changed compatibility for modules patching. Firmware versions 4.84-4.88 share values, but 4.89 has its own values now for hashes and sprx patches
    • - Added support for custom subchannel data via LSD files (thanks @aldostools)
    • - PSX BIOS patched with product code 0x85 for PAL games (thanks @aldostools)
    • - Option to force PAL or NTSC including the word in the file name (thanks @aldostools)
    • - Added support for .sbi files and improve the performance seeking the custom subchannels (thanks @aldostools)
    • - Added toggle for libaudio BT patch (thanks in1975)
    • - Updated act.dat restore function (thanks bucanero)
    • - Support for rap and RAP extension (lowercase/uppercase) (thanks aldostools)
    • - Added button detection on launch. Currently will look for R2 held, to disable boot plugins
    Resource Changes
    • - HEN Enable and Package Manager have been separated from category_game.xml
    • - Package Manager hidden on boot and shows full on HEN launch (thanks LuanTeles, DeViL303)
    • - The HEN Enable egg menu item will be shown on boot and will be hidden after the XMB is refreshed. This will be updated later to refresh automatically. (thanks LuanTeles, DeViL303)
    • - Added Developer options under HFW Tools -> Developer
    • - Added the ability to switch HEN from Release and Debug modes via HFW Tools -> Developer (USB will be added next release)
    • - Added the option to remove hen_enable.png to allow install from browser via HFW Tools -> Developer
    • - Only supporting Stock and Rebug themes for now until custom colors can be fixed

4.90 Release Links:
Tools
PS3 Homebrew @
Useful Guide's / Info

.Huge Thanks to the original PS3Xploit Team (@bguerville @habib @esc0rtd3w @W & @Joonie) for the work in PS3HEN / CFW Flash Writer & HFW, but in 4.90 we need to thank developer's @lmn7 @Joonie @littlebalup @kostirez1 @aldostools, @Evilnat & @esc0rtd3w for the work they have done in 4.90, to set the stage and get things back on track
.
Update: THE OFFICIAL Bguerville PS3 Toolset is back online (with a new official URL) , Currently only supporting 4.89.
4.90 Support is in testing. See thread for more information >>> https://www.psx-place.com/threads/ps3-toolset-is-back.40009/

Update 2: OFFICIAL ps3toolset is live with 4.90 support (guide needs updated above, if you see this message it has not been updated yet).
https://www.psx-place.com/threads/t...th-a-new-official-url-and-4-90-support.40076/
 
Last edited:
I think I messed up... I had a PS3 CECHG02 that I bought broken and fixed, but it didn't come with its original BD drive. So I installed CFW and remarried it to a new drive, no probs. That was all fine, the problem started when I tried to put regular OFW back onto it.

I tried installing it from the recovery, and it gave me a 8002F14E error saying it was corrupted, and then it reinstalled CFW and went back there. So I tried going to HFW first, then installing OFW ontop of HFW. When I did that, no matter what I do, it throws the same error trying to downgrade to OFW. So I thought f*** it I'll just load CFW and sell the console like that. Trouble is the CFW PUP file fails, as if I need to do the flash. So I try the flash and it gives me the "your console has already been flashed" error. I have no idea what to do and I'm stuck on HFW now, which is useless to me. Any ideas?
 
Hi everyone,

I now bought a cech2004 model and its on 4.66.
I guess its now possible to update to OFW 4.90, as I want to connect to PSN and install games from my library and then install to HFW 4.90.1 and go to CFW right?

Kind regards,
m
 
Hi everyone,

I now bought a cech2004 model and its on 4.66.
I guess its now possible to update to OFW 4.90, as I want to connect to PSN and install games from my library and then install to HFW 4.90.1 and go to CFW right?

Kind regards,
m

You can go directly to the latest OFW and use bgtoolset to go to CFW

You don't need to go to HFW, only If you want to use the Flash Writer that also needs HEN, both solutions are good, it's up to you to choose one.

BTW It's nice to see you back, maybe you can go back to development? :quartet:
 
Last edited:
Hi everyone,

I now bought a cech2004 model and its on 4.66.
I guess its now possible to update to OFW 4.90, as I want to connect to PSN and install games from my library and then install to HFW 4.90.1 and go to CFW right?

Kind regards,
m
Welcome back. [emoji6]

Like Luan said, update to ofw 4.90.
Open www.ps3toolset.com, let the Toolset load, go to system manager, use the context menu to load patch file from http, then apply the patch once loaded, reboot and install evilnat 4.90 CFW.

HFW is basically a OFW pup repack with a 4.82 or older tar file that contains the old silk_webkit.sprx file. That file is still necessary to use HEN because it still relies on a userland exploit that was patched in ofw 4.83, but you shouldn't be needing any of this if you go CFW.
 
Last edited:
Developers, have any of you come to a point while working on updating or creating a new firmware or app/pkg and thought to ask chatgtp or something similar to brainstorm other possible solutions?

For example https://www.phoronix.com/news/MTE5MTg

Betts was trying to get OpenGL core profile working on the ps3 RSX.
Now this was a long time ago and a seeming tall task but would asking questions to find solutions to chatgtp be worthwhile or is it too simplistic to really have much value?

There seems to be a lot of sharing that goes on between the scene's developers as noted by all of the thank-you's posted in the notes of most completed projects and updates. Is it just easier to ask someone for help than ask AI? More productive?

As I'm sure is apparent, my knowledge is sparse and superficial but I do like trying to figure out challenges and was wondering about this one.
Thanks.
 
Developers, have any of you come to a point while working on updating or creating a new firmware or app/pkg and thought to ask chatgtp or something similar to brainstorm other possible solutions?
No, not really, the thought crossed my mind but I quickly rejected it, what I like in hacking is the learning experience, the looking, the getting it wrong and sometimes when the going is good, the finding and the doing, delegating any of those tasks in exchange for expediency, or even efficiency, would make no sense, it would take something away from me rather than provide real value.
That's how I view it but of course it depends whether you focus on the end result alone or, as I do, on the way that takes you there.

Chatgpt could not "brainstorm" anyway, it can only analyse data according to potentially complex user defined patterns and regurgitate the results in a form you understand and according to any spec you specify, that's all.
 
No, not really, the thought crossed my mind but I quickly rejected it, what I like in hacking is the learning experience, the looking, the getting it wrong and sometimes when the going is good, the finding and the doing, delegating any of those tasks in exchange for expediency, or even efficiency, would make no sense, it would take something away from me rather than provide real value.
That's how I view it but of course it depends whether you focus on the end result alone or, as I do, on the way that takes you there.
.

I get it. The enjoyment is in the work not the end result. Figuring it out and knowing what doesn't work can be as useful as figuring out what does. Thanks for the response, it is greatly appreciated.
 
Good afternoon guys, I'm trying to recover my data from a PS3 hard drive, summary of what happened.
I have a 320 GB disk, I upgraded from HEN to CFW about a month ago, but there was a rather strange error when removing the hard disk, because the console didn't start anymore, the disk works and the console works too, but you can't read the system data, I installed a 500 gb hard disk and it works perfectly, the problem is that I removed it several times to test if just removing the disk damaged the system and if it "damaged" so to speak, for which I reinstalled it several times (CFW charges 8.4 Evilnat CEX), trying to recover the data on my PC, I initialized the 320 gb disk, which they told me that it could cause data deletion, now, is there a solution, I have the EID root key (of the hard disk of 500gb) will it help me to recover that data or is there something else I can do?
Thank you very much in advance and I hope you can help me
 
Hey if I'm getting 008.02 trvk_prg0. Hash

what does it mean the modsaren't on my system yet it's a ps3 fat model and my ps3 firmware is 4.90
 
Last edited:
Hi guys,
I have a Fat PS3, running a CFW 3.55 with multiman. Console has been sleeping since 2012 and now I want to revive it. As I discovered hard/impossible to find games to run this CFW I would like to update it to the latest CFW.
Can anyone of you guide me how to make it, if you have a step by step tutorial, I did the jailbreak myself years ago, so I just need some guidance how to proceed now!
Thank you in advance!
 
Hi guys,
I have a Fat PS3, running a CFW 3.55 with multiman. Console has been sleeping since 2012 and now I want to revive it. As I discovered hard/impossible to find games to run this CFW I would like to update it to the latest CFW.
Can anyone of you guide me how to make it, if you have a step by step tutorial, I did the jailbreak myself years ago, so I just need some guidance how to proceed now!
Thank you in advance!
If you still have any of the old PS Home stuff installed on it you should consider donating the cached files to one of the revival projects. It would be of great help to them.
 
If you still have any of the old PS Home stuff installed on it you should consider donating the cached files to one of the revival projects. It would be of great help to them.
I have no clue, I did the jailbreak when first 3.55 CFW was available, nothing else since that time was installed, except the games.
I am available to help anyone who need anything from me. Let me know how to do it and I give you all you need. Ready to help the community!!
 
Back
Top