Advertising (This ad goes away for registered users. You can Login or Register)

PS Vita index.dat decryption keys posted

Open discussions on programming specifically for the PS Vita.
Forum rules
Forum rule Nº 15 is strictly enforced in this subforum.
The Z
VIP
Posts: 5505
Joined: Thu Jan 27, 2011 4:26 pm
Location: Deutschland
Contact:

Re: PS Vita decryption keys posted

Post by The Z »

Hykem wrote:This information was shared by Proxima yesterday on #vitadev. Since he couldn't log on to the vitadevwiki, I've added the keys for him.
I've named them according to the standard PSP naming convention seen in JPCSP or PPSSPP, but in these keys' case the naming is quite misleading.

PSP2IndexKey and PSP2IndexIV are the original ones seen on the firmware versions that Proxima mentioned and PSP2IndexKey180 is the key introduced on firmware 1.80 and it's also the one in use up to the latest firmware version (3.51).

This decryption is also likely to take place when doing the secret combo on the settings application.
You mean the one that got patched as of 1.6x?
Advertising
White PSV TV - 32GB - 3.65 CFW
White PSV 1000 - 32GB - 3.65 CFW
2x PSV 2000 - 32/64GB - 3.65 CFW
PSP Fat 1000 - TA-081 - 6.61 ME-2.3
PSP Slim 2000 - TA-085¹ - 6.61 ME-2.3
4x PSPgo & 1x PSP 3kº⁴ᶢ - 6.61 LME-2.3∞
Hykem
Guru
Posts: 75
Joined: Sat Jan 15, 2011 8:11 pm

Re: PS Vita decryption keys posted

Post by Hykem »

The Z wrote:
Hykem wrote:This information was shared by Proxima yesterday on #vitadev. Since he couldn't log on to the vitadevwiki, I've added the keys for him.
I've named them according to the standard PSP naming convention seen in JPCSP or PPSSPP, but in these keys' case the naming is quite misleading.

PSP2IndexKey and PSP2IndexIV are the original ones seen on the firmware versions that Proxima mentioned and PSP2IndexKey180 is the key introduced on firmware 1.80 and it's also the one in use up to the latest firmware version (3.51).

This decryption is also likely to take place when doing the secret combo on the settings application.
You mean the one that got patched as of 1.6x?
Yes: http://vitadevwiki.com/index.php?title= ... On_PS_Vita

Obviously there are other places where this file gets decrypted.
Advertising
Shaggy
Posts: 16
Joined: Mon Dec 08, 2014 11:06 am

Re: PS Vita decryption keys posted

Post by Shaggy »

Let's say I had a 1.61 Vita. Would that be useful to devs?
Shaggy
Posts: 16
Joined: Mon Dec 08, 2014 11:06 am

Re: PS Vita index.dat decryption keys posted

Post by Shaggy »

So I'm guessing no?
Zecoxao
Posts: 280
Joined: Mon Sep 27, 2010 7:27 pm

Re: PS Vita index.dat decryption keys posted

Post by Zecoxao »

@Shaggy ANY vita in 1.691 or less is interesting. The older, the better. It would actually be very nice if Hykem had one below 1.80 :)
My sig is original :D
iCEQB
Posts: 57
Joined: Thu Jan 16, 2014 3:54 pm

Re: PS Vita index.dat decryption keys posted

Post by iCEQB »

I see that some say that the decryption of the file takes place at several points during runtime?
So how was the key gathered? Can you calculate the key once you have the file in plaintext?
Or was it snatched from the place where the vita stores them ?

What I'm trying to ask is, if there were more keys stored where you got this one from?

Or was the key exposed at a point where you had control of certain regions in RAM?
yifanlu
Guru
Posts: 760
Joined: Sun Mar 11, 2012 6:42 am
Contact:

Re: PS Vita index.dat decryption keys posted

Post by yifanlu »

iCEQB wrote:I see that some say that the decryption of the file takes place at several points during runtime?
So how was the key gathered? Can you calculate the key once you have the file in plaintext?
Or was it snatched from the place where the vita stores them ?

What I'm trying to ask is, if there were more keys stored where you got this one from?

Or was the key exposed at a point where you had control of certain regions in RAM?
Someone knows the right questions to ask. Unfortunately, these keys are the only ones we can decrypt with usermode. It's useless since we can't write in vs0: if we could this /may/ allow for a downgrade... But if you can write to vs0, you can pretty much downgrade anyways.
Hykem
Guru
Posts: 75
Joined: Sat Jan 15, 2011 8:11 pm

Re: PS Vita decryption keys posted

Post by Hykem »

Shaggy wrote:Let's say I had a 1.61 Vita. Would that be useful to devs?
Yes. If there are any good chances of finding a kernel vulnerability, it's in a pre-1.80 Vita.
The reasons for this have been mentioned several times by Yifan Lu (no KASLR and no NID poisoning).
Some developers already have a pre-1.80 Vita (Davee, Proxima, etc.).
iCEQB wrote:I see that some say that the decryption of the file takes place at several points during runtime?
So how was the key gathered? Can you calculate the key once you have the file in plaintext?
Or was it snatched from the place where the vita stores them ?

What I'm trying to ask is, if there were more keys stored where you got this one from?

Or was the key exposed at a point where you had control of certain regions in RAM?
The keys were grabbed from memory and, unfortunately, they are the only ones we currently have access to.
As I stated earlier, they were likely used on low firmware versions when doing the secret combo on the Settings application (the combo was patched later on, but they remained accessible to the application as it needs them to decrypt index.dat for other reasons). It's easy to conclude that they were obtained by exploiting this particular application and looking for the memory region were the keys were temporarily stored.

Anyway, as Yifan Lu just stated, they are pretty much useless since the only thing we could pull off from this would be index.dat spoofing. Regardless, it's an impressive achievement from Proxima considering we have so little data from the Vita.
psvitamario
Posts: 31
Joined: Mon Mar 19, 2012 8:18 am

Re: PS Vita index.dat decryption keys posted

Post by psvitamario »

Hello,
with e-mail trick recentely discovered, it's possible reactivate the secret combo on the settings application for firmware 3.18+?
And possible to go pstore on 3.18 in editing index.dat?

Thank for your answer.
Tikiko99
Posts: 155
Joined: Mon Feb 21, 2011 6:45 pm
Location: Somewhere in this planet called Earth

Re: PS Vita index.dat decryption keys posted

Post by Tikiko99 »

no

Edit: it can't be that simple, can it??
Last edited by Tikiko99 on Tue Sep 29, 2015 12:46 pm, edited 1 time in total.
My Systems:

PSP GO OFW 6.60
PS Vita PCH-1004 : 3.60
PS Vita PCH-1101 : 1.50

PS3 OFW 4.25(dead)
Locked

Return to “Programming and Security”