PS3 SYSCON Firmware key is now public (release by zecoxao) - What does it mean?

Developer @zecoxao has recently released something that the dev has been working on obtaining for 10 years now and that obstacle that has now been cleared is the SYSCON Firmware Key and zecoxao has now released it to the public. First off we must erase some misconceptions as this is not going to directly lead us to a CFW on nonCFW PS3's anytime soon. As the dev stated on twitter "needless and pointless to say that the confusion being created around these keys that they will be useful for cfw on ps3 3k and superslim is a very farfetched idea. unless we have access to the TSOP 78K0R models, we will not be able to obtain anything else" and then when @kozarovv provided a follow-up question about 3k models here the developer responded with "don't expect miracles, is all i'm saying ". Now the question (which was asked by @DeViL303) "So what can we do with this as of now, what is possible with just this key alone and current knowledge? Then @zecoxao provides an explanation seen in this post (and also seen below). So this is a great feat that has been made, but its still being investigated and something that will need to be explored in the weeks to come to fully understand what we can be uncovered,. .

1200px-SYSCON_GEN1.JPG

  • i got the syscon firmware key, a dream i've been pursuing for the past 10 years. now that i have it i feel like i've acomplished my goal. the rest will follow naturally.
    - https://twitter.com/notzecoxao/status/1168954036541935616

    What can developer's do with this key?
    So what can we do with this as of now, what is possible with just this key alone and current knowledge? Custom fan speed profiles? Multiple boot sequences depending on flags or something, or does everything need more work?

    via @zecoxao : With this key the following has happened:


    14 syscon firmwares for the BGA models (CXR) were decrypted.
    from them, keys for PATCHES and FULL FW signing and encryption, as well as decryption and validation were found. we can now sign our own patches and fws for the following models:

    • TMU-510
    • COK-001
    • COK-002
    • SEM-001
    • DIA-001
    • DIA-002 or DEB-001 (same soft id)

    Additionally we found the initialization key for eid1 as well as the process of initializing it from factory
    We also found 7 extra keys (we still don't know what they do)
    Finally, we found out there is a secret keyslot function that generates keys for
    • SNVS
    • AUTH1/AUTH2
    • Regions of EEPROM
    • PATCH keys xoring (to generate the final keys)
    • Relationship with the other 7 Keys

    What still has to be done:
    • Hack the 78K0R chips (the TSOP ones found in later models)
    • Dump the firmware of those chips
    • Get the DYN-001 patch keys
    • Find an exploit on arm firmware that works in 78k0r firmware

    Edit: and yes, you can do all that fun kinky shit of fan boosting at max speeds, led disco panic attack, and star wars theme ON A DECR-1000! THIS is a devkit, so THIS is the ONLY device that supports FULL FUCKING FIRMWARES! DO NOT CONFUSE IT with a DECR-1400, that is a HALF devkit!


Release Source: twitter.com/notzecoxao
Discussion: psx-place.com

Thanks to @NathanHale for the news alert
 
Last edited:
Too bad slims and super slims' syscon chips can't be patched due to the lack of external EEPROMs. I wonder what's going to be the first feature fat consoles will try with patched syscon
 
There is nothing to install, the fact that a key has been published doesnt means that we can make use of it, because doesnt exists any tool, program, or exploit taking advantage of it... yet


Yes, to simplify it i use to say syscon is the "boss" of the PS3 motherboard
The ON/OFF buttons of the PS3 are connected to syscon, when you press the button you are interacting with syscon, and is syscon who sends the signal to boot CELL processor... so it can be said CELL is a "slave" of syscon

A friend of me uses to say the PS3 is like a mediaval fortress, the external wall is the userland, the secondary internal wall is the kernel, CELL is the citadel with the hypervisor that is the king's personal guard
And syscon... is like the armoury (connected with the citadel by some dungeons)

In the PS3's with CFW all the securities are breached... except the citadel (CELL) and the armoury (SYSCON)

Technically... the only way to attack the citadel (made by IBM) is by hacking syscon and using it against the citadel :D
Basically... is needed to take control of syscon and add some exploit to it... so in this first communications in between syscon and CELL that happens at boot our hacked syscon needs to tell... "hi CELL, its me the syscon, your friend, please let me in"... and CELL will reply with... "ok access granted"
And after that is when syscon tells... "muahahahaha i cheated you im a traitor trololol lol" :D
This words its a kind of magic.tanks gods for write for us.
10 tnks
20 tnks
50 tnk
60 return to 10
 
Sorry guys...
I think I may have started the whole "CFW on 3k 4k" thing way back at the beginning of the thread...

My bad, I didn't realise this was syscon for phats...
 
My bad, I didn't realise this was syscon for phats...
I like to use funny examples to simplify things, this one is like is we are aliens and we find a australophitecus for first time
We study it, and since that point we can get a very good idea about how the humans works
After that the next step to understand "how the humans works" is to find a neandhertal (another hominid more evolved)
There are going to be differences, but most of the things are common :)

At this point the experiments are made with monkeys by using the "reference tool" PS3 model DECR-1000 or older prototypes/variants of it

Theoretically it can be applyed to the first humans (the CECHA and his brothers) but i doubt they have started this kind of experiments yet, is a bit soon... but is tempting XD
 
I like to use funny examples to simplify things, this one is like is we are aliens and we find a australophitecus for first time
We study it, and since that point we can get a very good idea about how the humans works
After that the next step to understand "how the humans works" is to find a neandhertal (another hominid more evolved)
There are going to be differences, but most of the things are common :)

At this point the experiments are made with monkeys by using the "reference tool" PS3 model DECR-1000 or older prototypes/variants of it

Theoretically it can be applyed to the first humans (the CECHA and his brothers) but i doubt they have started this kind of experiments yet, is a bit soon... but is tempting XD
In this way, the reissues, being more compact logically, have different pieces and other parts with a new structure on the motherboard, but in essence they should have similarities in their operation, I even remember that at different times I had 2 psx fat with different motherboards in the design also the playstation one, was a curious caveman of 12 years with a screwdriver in hand when I tried to repair my playstation although it damaged the first one I could learn to replace and calibrate the lazer of the CD player and solder and desolder capacitors there I met the differences, in an era where I didn't have access to the internet or electronic books, I was just a caveman with a few tools.
 
Sorry guys...
I think I may have started the whole "CFW on 3k 4k" thing way back at the beginning of the thread...

My bad, I didn't realise this was syscon for phats...
That speculation was fine man. We were all excited in the beginning bc we all wanted to see what this could do. It's the fact that after zeco said this is a far fetched idea people kept off topic posting about I want cfw for ss and when. That's when I got hostile about it. Your good man
 
That speculation was fine man. We were all excited in the beginning bc we all wanted to see what this could do. It's the fact that after zeco said this is a far fetched idea people kept off topic posting about I want cfw for ss and when. That's when I got hostile about it. Your good man
Is fine to speculate, to chill a bit, and even a bit of offtopic (eventually we will return to it), but after zecoxao explained it is clear at wich point they are, and which PS3 models could potentially take advantage of it first

Im going to try to explain it better to clarify it, at some point in psdevwiki we had to made a classification of PS3 syscon chip models in groups "by series", and we used 5 series, take a look at top in this template
https://www.psdevwiki.com/ps3/Motherboard_Components
CXR713 Series = CXR713120-201GB · CXR713120-202GB · CXR713120-203GB
CXR714 Series = CXR714120-301GB · CXR714120-302GB
SW Series = SW-301 · SW-302
SW2 Series = SW2-301 · SW2-302 · SW2-303
SW3 Series = SW3-301 · SW3-302 · SW3-304

Zecoxao made a classification of them in 2 groups though... the ones soldered by "BGA" (solder balls under them and no visible connections externally)... and the others (soldered with pins all around)
The BGA syscons are the ones that starts with CXR713 & CXR714. Used by PS3 retail models:
CECHAxx
CECHBxx
CECHCxx
CECHExx
CECHGxx
CECHHxx
CECHJxx
CECHKxx

In other words... all PS3 fat models except the CECHLxx, CECHMxx, CECHPxx, CECHQxx (this PS3 models have the same motherboard VER_001)
In VER_001 motherboard sony started using a new syscon... lets say is a PS3 fat with components of the PS3 slim
In this table at top of the page can be seen better
https://www.psdevwiki.com/ps3/Talk:SKU_Models
 
Back
Top