PS3 [UPDATE] IDPS Dumper (PS3 NAND / NOR ) - 4.81/4.82 OFW Compatible by Team PS3Xploit

{UPDATE v0.2.3 Released(See tab)}
Following the official announcement of the PS3Xploit news (4.81 OFW Exploit), the devs behind the project have fulfilled the promises of releasing the IDPS Dumper for OFW 4.81/4.82 as this release is ready for the public. Now there is many more things being worked surrounding the overall project but this IDPS Dumper works on all models of the PS3 (NOR and NAND, note 12 GB EMMC will be supported soon in an updated release) and no reason not to release this tool. Since PS3 firmware 4.70 Sony had blocked flatz IDPS extracting tool (IDPS Stealer) and there has not been a known way to obtain the IDPS on OFW (4.70 +) consoles , but now this tool can now obtain your PS3's ID, which can have various uses, the tool has been confirmed to work on SuperSlim models by the team. . If you have not read the previous details about the PS3Xploit project, then checkout this official thread to get the firsthand information about this ambitious PS3 project.


capture_0.2.3.jpg

(UPDATE v0.2.3)


  • UPDATE v0.2.3- IDPS Dumper for 4.82 OFW
    • Added 4.82 Support
    • Removed all extra requirements like JQuery..
    • Removed the need for string relocations to improve the initial memory search process & overall trigger times.

  • UPDATE v0.2.3- IDPS Dumper for 4.81 OFW

    • Removed all extra requirements like JQuery..
    • Removed the need for string relocations to improve the initial memory search process & overall trigger times.



  • UPDATE v0.2.1a- IDPS Dumper for 4.81 OFW

    we have some more exciting news to bring you!! :cheerful:

    We have been working very hard to bring eMMC support for the newest SuperSlims CECH-40xxA, CECH-42xxA , CECH-43xxA and that has happened. :D

    The team would like to present a nice little update to the 4.81 IDPS Dumper now supporting eMMC hardware revision consoles!!

    Please report any issues you have while using this new version on any of the flash types, NAND, NOR, and eMMC.

    Thank You to all :cool:

    v0.2.1a
    • Added eMMC SuperSlim Support (CECH-40xxA, CECH-42xxA , CECH-43xxA)
    • Misc Tweaks To Exploit
    • Small typo on index.html pointed out by @Turranius - Fixed

    How to use this:
    *** MAKE SURE TO RUN AS ADMINISTRATOR ***
    install python to use server.py or another HTTP server of your choosing on both Windows and Linux!​

    On windows - Install any of these optional HTTP servers:

    On linux:
    • install python for your distribution using apt-get, yum, and similar commands.
    • make script executable using "chmod a+x server.py" or "chmod 775 server.py" or "chmod 777 server.py"
    • execute python script using "/usr/bin/python $exploitFolder/server.py" or "./server.py"

    Update
    on Android: (
    instructions from @No0bZiLLa)
    • I can confirm this does work if using an http server on Android. what i did was downloaded the zip (on my phone) and extracted it and then download something like Simple HTTP Server and point the server to the folder that contains index.html. once you do that just reload the server and make a note of what the ip:port is. then just go to ps3, type in ip:port (eg 192.168.2.7:12345) as specified in simple http server and then select the appropriate button for your system.


    Then run (for python):

    • On windows - windows.bat
    • On linux - linux.sh


    Usage Tips:

    1) Try using a LAN connection or a solid WiFi connection during exploitation. A weak signal can cause problems.
    2) If the exploit takes more than 5 minutes to work, reload page, browser, or restart console and try again.
    3) If you are using a LAN connection and experience network issues, make sure all cables to router are in working order.​



  • IDPS Dumper Release (v0.2 - After Leak Release)
    ok....the moment all of you have been waiting for......i assume :cheerful:
    • File: ps3_481_idps_dumper-PS3XPloit.zip
    • MD5 Hash: FFDA70AB2D1677886083F99185C54FE3
    • SHA-256 Hash: 852BDB301753C4F4A7E946188E850D3D325EEAA259B61AE2B5AE31320B2F292B

    enjoy this release from our team :victorious: we will be working hard to add eMMC support as soon as possible!!


    The documentation will be updated as time goes on. There is a readme.txt file included with basic setup and usage instructions.

    Please stay tuned for future tools and releases :D

    and once again, THANK YOU to everyone involved bringing this all together, without all of you, none of this would have happened!!!

    Additional details from @bguerville
    "The idps dumper will create a file on usb000 then beep 3 times & shutdown in all cases, even if flash memory read fails. emmc should not make a difference to this. You will get garbage in idps.bin in that case.

    Js errors with a black page message on ps3 should not happen. If ever it did, just report & in the meantime keep relaunching the exploit. Nobody has had this issue in dozens of tests though.

    And clearing cache or cookies is totally unnecessary with the exploit & the wk js interpreter. Between runs garbage collection will take care of cleaning up what is needed, the job it does is always sufficient".


It's essential not to flood the browser memory with junk before running the exploit. The reason for this is that due to javascript core memory usage limitations we are scanning several times a small range of browser memory (a few Mb) to find some essential data in RAM, if the memory is flooded then the range to scan becomes much larger & the probabilities that our data is found in the smaller range decrease dramatically....

So in short, never use the browser or set a homepage you cancel before running the exploit!
If you need to, set the homepage to 'blank', close the browser then reopen it to start the idps dumper.

Set-up Steps:
  1. Setup a small Web server on pc or smartphone. The Python http server is not required for most users, it was provided for developers. Since v0.2.3, all other extra requirements have been removed. Don't come to us for explanations about how to run a http server though. Google it.
  2. Extract the files in your http server root folder.
  3. Put a fat32 USB key in port closest to BD Drive (/dev_usb000).
  4. Open the ps3 browser & write the ip address of your server (and the port if not 80).
  5. Run until ps3 beeps & shutdown. The idps should be on your USB drive as idps.bin.
- Downloads -
  • MD5 Hash: 3c2e1582f52e1002a12ad280f426d0c6
  • SHA-256 Hash: 1c49eabd64275171a60c90f0f06f503b7055f4ff863f87e7960d41464d127443
  • MD5 Hash: 71dd906e585bf470f84f9d4fb10c1f37
  • SHA-256 Hash: d4bffe2b7d08c1dda275590229f86903f1db487e9a78364d6a025c3734cd8f68
 
Last edited:
idk if this has been said but the htdocs folder needs created if using miniweb, and html and js files placed inside of that folder
 
What FW version are you on? does the USB show up in the video column? have you reformatted the USB to fat32? Do you have other USBs to try?
Ive tried my fat32 sandisk flashdrive & my kingston data travelor 2.0 & get the same result. Im on 4.82 OFW. The usb's show up fine its just that they're in port slot 1 cause 2 is dead. I wish mods could be installed in both ports. :( Ive been at this all day & this site is my only help with this issue. Should I just ignore the dump & try to write the files for the jailbreak? Could you make the same files for the nor writer to work in slot 1 as well?
 
Ive tried my fat32 sandisk flashdrive & my kingston data travelor 2.0 & get the same result. Im on 4.82 OFW. The usb's show up fine its just that they're in port slot 1 cause 2 is dead. I wish mods could be installed in both ports. :( Ive been at this all day & this site is my only help with this issue. Should I just ignore the dump & try to write the files for the jailbreak? Could you make the same files for the nor writer to work in slot 1 as well?
The dumps are not really necessary, if ever you bricked partially you could reconstruct the flash memory without a prior dump.

However, if the dumper does not work due to usb io, you will have the same issue with the writer most likely.
You are using a modded version for /dev_usb001, are you 100% sure that your usb device currently gets mounted as /dev_usb001 in the first place?
 
Ive tried my fat32 sandisk flashdrive & my kingston data travelor 2.0 & get the same result. Im on 4.82 OFW. The usb's show up fine its just that they're in port slot 1 cause 2 is dead. I wish mods could be installed in both ports. :( Ive been at this all day & this site is my only help with this issue. Should I just ignore the dump & try to write the files for the jailbreak? Could you make the same files for the nor writer to work in slot 1 as well?
yes try the writer, but we need to be sure it's the left port that is working. So what your calling pot slot 1 is the left port (dev_usb001)?
 
yes try the writer, but we need to be sure it's the left port that is working. So what your calling pot slot 1 is the left port (dev_usb001)?
yes there are 2 slots the left & right. the right slot is dead, so im using the left slot which I assume is dev_usb001.
 
The dumps are not really necessary, if ever you bricked partially you could reconstruct the flash memory without a prior dump.

However, if the dumper does not work due to usb io, you will have the same issue with the writer most likely.
You are using a modded version for /dev_usb001, are you 100% sure that your usb device currently gets mounted as /dev_usb001 in the first place?
Ive tried the regular index files, ones ive edited myself, & 1s that were made by bitsbubba, NOTHING WORKED!. I can only use slot 1 cause slot 2 is dead & it looks like so is my hopes of modding my OFW :(
 
yes there are 2 slots the left & right. the right slot is dead, so im using the left slot which I assume is dev_usb001.
yes I just installed OFW 4.82 on my PS3 and used the same files I just posted and it dumped dump.hex to that USB port, then I ran the Nor Writer files that I'll post next and now the PS3 shut down and is ready for me to install CFW, so let's maybe reinstall OFW 4.82 on your system again to start fresh and try this process again
 
idk if this has been said but the htdocs folder needs created if using miniweb, and html and js files placed inside of that folder
I've done this for him on the last files I posted
The dumps are not really necessary, if ever you bricked partially you could reconstruct the flash memory without a prior dump.

However, if the dumper does not work due to usb io, you will have the same issue with the writer most likely.
You are using a modded version for /dev_usb001, are you 100% sure that your usb device currently gets mounted as /dev_usb001 in the first place?
out of the 2 ports I assume that it is as they are working great on my system
 
Ive tried the regular index files, ones ive edited myself, & 1s that were made by bitsbubba, NOTHING WORKED!. I can only use slot 1 cause slot 2 is dead & it looks like so is my hopes of modding my OFW :(
That does not answer my question.
If you use files for /dev_usb000 or /dev_usb001 but that is not the port of your usb device, you can try as much as you want it will never work.

Your hopes are still intact, no need to be dramatic, you own a console which needs repaired so it's no wonder if it gets more complicated.

The idps dumper is the best tool you have for testing. If it immediately beeps 3 times & shutdown (no need to wait for 5 min, if it is frozen after 1mn reboot manually) then the process worked & the file should be on the USB device provided you are using the correct USB port.
What console model is this anyway?
 
That does not answer my question.
If you use files for /dev_usb000 or /dev_usb001 but that is not the port of your usb device, you can try as much as you want it will never work.

Your hopes are still intact, no need to be dramatic, you own a console which needs repaired so it's no wonder if it gets more complicated.

The idps dumper is the best tool you have for testing. If it immediately beeps 3 times & shutdown (no need to wait for 5 min, if it is frozen after 1mn reboot manually) then the process worked & the file should be on the USB device provided you are using the correct USB port.
What console model is this anyway?
CECHK
 
What would be the edit for that?
Replace the 30/31 byte by 36...
Bitsy, that js string holds the usb path in ANSI hex.
Code:
/dev_usb000
is 
2F 64 65 76 5F 75 73 62 30 30 30
So 0 in ANSI is 30 & 6 is 36, get it ?
Write the path in HxD text column if it helps...
 
Last edited:
That does not answer my question.
If you use files for /dev_usb000 or /dev_usb001 but that is not the port of your usb device, you can try as much as you want it will never work.

Your hopes are still intact, no need to be dramatic, you own a console which needs repaired so it's no wonder if it gets more complicated.

The idps dumper is the best tool you have for testing. If it immediately beeps 3 times & shutdown (no need to wait for 5 min, if it is frozen after 1mn reboot manually) then the process worked & the file should be on the USB device provided you are using the correct USB port.
What console model is this anyway?
Well all of my usb's should be named dev_usb000 if thats what you mean. I used them on my modded 3.55 ps3 & thats what showed up in the file managers & yes im on CECHK. I dont know what could be the issue. Do I need to use the regular files from the forum, or the modded files by bitsbubba? Im going to try this again with a fat32 pen drive
 
Could it use 006 as 2nd port? My old k used that iirc...
You should try...
And kiwon445, honestly a second hand replacement usb card for your model would cost between 5 & 10 bucks. It takes about 5mn altogether to change.
I remember my A01 had a dev_usb007 as one
 
Back
Top