PDA

View Full Version : Epsion Bios Beats all Sony Protection With the Undiluted Platinum Modchip ?



wraggster
July 22nd, 2006, 23:24
The team behind the Epsilon bios have posted information that they say proves they have beaten Sonys Latest Firmware, you will need to have a Undiluted Platinum Modchip (http://affiliates.modchipstore.com/idevaffiliate.php?id=892)installed.

The full details can be found in the comments.

wraggster
July 22nd, 2006, 23:26
REMEMBER WE DO NOT ALLOW ISO DISCUSSION BUT IVE LEFT THE ARTICLE INTACT FOR NOW.

Introduction

Epsilon BIOS is a custom flash "replacement" for the Sony PSP which unleashes the full potential of your handheld, allowing you to both use homebrew software and run UMD ISO games from your Memory Stick on the latest firmware releases while also enjoying the impressive features built into the operating system such as RSS feeds, WMA support etc. Currently the 2.71 firmware release is supported.





It is important to note that Epsilon BIOS is not standalone firmware replacement but more like a bootloader. It works using the dual-firmware system provided by the Undiluted Platinum hardware modification by loading when the PSP is initially powered on, then once running executes and "piggybacks" the real firmware stored in your PSP flash memory. Due to the way this works it is NOT possible to use Epsilon BIOS unless your PSP has an U.P. hardware modification installed.

Features

- Runs alongside 2.71 firmware, so you get all the features of 2.71 such as RSS feeds, web browser etc combined with the advantages of homebrew software and ISO loading.
- Allows execution of homebrew software in kernel mode, removing all limits previously in place while running homebrew on firmware versions above 1.50.
- Ultra reliable, near transparent UMD emulation allowing users to run their games from a Memory Stick with ease, including games which require 2.0+ firmware without rebuilding the ISO or relying on nasty hacks.
- Support for compressed ISO files for UMD emulation, allowing you to fit more games onto your Memory stick at one time.
- Built-in recovery menu which can be used to to update your Epsilon BIOS installation or restore your PSP flash contents if it becomes "bricked".

Functional Description

As described above, Epsilon BIOS can be compared to a "bootloader". It is stored on the U.P. flash memory and executed when your PSP is powered on. Once Epsilon BIOS is running it loads and "piggybacks" the real firmware from the PSP flash. Currently only 2.71 firmware is supported, you must
upgrade your PSP onboard firmware to 2.71 in order to use Epsilon BIOS. If you attempt to boot Epsilon BIOS with an unsupported firmware version you will be taken to the recovery menu where you can upgrade the PSP firmware. The great thing about Epsilon BIOS is that since the "bootloader" always runs before the real firmware we can apply whatever patches are necessary to disable -
whatever protection Sony tries to add in the future, making a U.P. modified PSP using Epsilon BIOS very future proof.

With Epsilon BIOS you can run homebrew software (EBOOT files) directly from the OS main screen. Kernel mode applications are also supported meaning there are no limits when it comes to homebrew software. Both 1.00 and 1.50 style EBOOT's are supported.

UMD emulation is handled almost transparently. You do not need to launch a separate application in order to load your UMD games from the memory stick, all the ISO's you have stored on your Memory stick are listed alongside your homebrew applications in the "Game->Memory Stick" screen and executed from there. Copying new games to your Memory stick is easy, simply enable the USB connection and copy ISO's to the "ISOS" directory in the root of your memory stick. Please note that each time you change the contents of the ISOS directory a cache file containing the icons etc for each game must be updated, and this will cause a slight delay while viewing the "Game->Memory Stick"
screen.

Compressed ISO's are supported for UMD emulation using our own custom format, "Epsilon ZIP". Using the "Epsilon ZIP Tool" included in the archive you can convert UMD ISO files into EZIP files and vice versa. Simply copy the EZIP files into the same location as normal ISO files in order to play them.

Epsilon BIOS includes a recovery mode which can be used to update the PSP onboard firmware, restore a bricked PSP or upgrade your Epsilon BIOS installation. If there are any problems while booting then you will be presented with the recovery menu. To forcefully enter the recovery menu, hold SELECT+START when you power on the PSP.

Installation

Epsilon BIOS is broken into two distinct parts: the bootloader and the core. The bootloader is programmed to U.P. flash from the PC and is what actually takes control of the system when you first power on your PSP. The bootloader attempts to load the core installed in U.P. flash; if the core has not yet been installed or there is another problem you will be taken to the recovery menu. When you first program the Epsilon bootloader onto your U.P. you will need to install the core separately
since it is not bundled inside the bootloader flash image. However, whenever an Epsilon BIOS core update is released you simply copy the update file onto your Memory Stick then use the recovery menu to update the core. This system is much safer and more user friendly than having to reprogram the U.P. flash from the PC each time you update which would be required if the bootloader and core were integrated.

Installing the Bootloader

1. Turn on the PSP while holding LEFT to enable U.P. programming mode
2. AFTER the PSP has turned on, connect the USB cable to the U.P.
3. Program the bootloader flash image (epsilonBootloader*.flash) to U.P using the flashing tool
4. Cold restart the PSP by cycling power

Installing/Updating the Epsilon BIOS Core

Updates and the initial installation of the Epsilon BIOS core are handled through the Epsilon recovery menu. To enter the recovery menu hold SELECT+START while you power on the PSP. The procedure to install/upgrade the BIOS is as follows:

1. Copy EBUPDATE.BIN to the root directory of your memory stick. This can be done via the
recovery menu by selecting "Memory Stick USB" or with a card reader, PSP XMB etc
2. Select "Update Epsilon BIOS", then hit X to confirm
3. Once the installation/update is complete the PSP will power off.

Notes Regarding Homebrew

As the majority of homebrew software currently available is designed to run on the 1.50 kernel we decided that for compatibility reasons it would be best to have Epsilon BIOS load the 1.50 kernel instead of 2.x when running homebrew software. This is possible since the Epsilon BIOS bootloader is actually based on the 1.50 firmware so when running homebrew software the kernel is loaded from U.P. flash rather than PSP onboard flash. The only known issue with this method relates to wireless network configuration - since the 1.50 kernel does not support WPA encryption you will need to configure your PSP to use WEP if you wish to use WIFI enabled homebrew software.

Recovery Menu

To forcefully enter the recovery menu hold SELECT+START while you power on the PSP. The Epsilon BIOS recovery menu from the 1.0 bootloader has the following menu selections:

1. Memory Stick USB – Enables the USB connection between the PSP and PC for transferring files. This is the same as the USB connection in the PSP XMB.
2. Update Epsilon BIOS – Installs an Epsilon BIOS core update from the memory stick. The update file must be named EBUPDATE.BIN and placed in the root directory of the memory stick.
3. Launch Firmware Updater – Launches an official Sony firmware updater EBOOT stored on the memory stick at /PSP/GAME/UPDATE/EBOOT.BIN. You may use this feature to both upgrade and downgrade your PSP onboard firmware version. Please take note first of the following important facts:

a. Epsilon BIOS releases are only compatible with certain firmware versions. If you flash your PSP to an unsupported version you will be taken to the recovery menu by the bootloader until such time as a supported firmware version is installed.
b. In order to downgrade your firmware certain files must be modified in your PSP onboard firmware so the official Sony updater *thinks* you have a very early firmware version installed. There are always risks involved with modifying your onboard firmware and such an action can be potentially hazardous to your data. Please note that when upgrading the firmware version no files need to be edited so this warning does not apply.

4. Restore onboard NAND – Used to “un-brick” a PSP by programming a known good flash dump (such as a dump of 1.0 or 1.50 firmware) to your PSP onboard NAND flash. The flash image must be a file called “nandImage.flash” in the root of the memory stick, in the same format used by the UP flasher tool (512bytes user + 16bytes extra for each page, interleaved).
5. Shutdown PSP – self-explanatory :)

Version Information

Epsilon BIOS v1.0 - Bootloader v1.0, Core v1.0
Required onboard firmware: 2.71

FAQ

Q: Why do I get a 0x86660000 error when I try to launch a Sony firmware upgrade?
A: Epsilon BIOS blocks you from trying to install firmware versions that are not supported by the installed core. If you wish to upgrade to a new firmware, you might first need to upgrade Epsilon BIOS to a version which supports said firmware.
Q: From firmware 2.6 and up, PRX files are protected with a new encryption method. How did you figure out how to decrypt these files?
A: As most people will now be aware, the discovery of the 2.6 kmode exploit lead to decryption of modules using the new encryption method. However when we started working on this the kernel mode exploit was unknown so we took a different approach to reach our goal, one that doesn’t rely on exploits so should allow us to easily hack new firmware releases in the future once Sony changes the encryption method again. Here’s how we did it - warning: this is a bit technical, which unfortunately is required to give a proper answer. Since we couldn't get a dump of kernel memory from a PSP running the 2.6 firmware, the only way to figure out how to decrypt the 2.6 PRX files was to disassemble the IPL and see how this decrypted the files while the PSP is booting. Unfortunately, Sony used a clever trick in the 2.6 IPL to prevent hackers disassembling it. They read out some data from the reset vector and use it to decrypt the main portion of the IPL code. The problem here is that by the time we can run code on the PSP, any attempt to read out this data will be in vain as it gets scrambled inside the IPL. However, through some hardcore trickery we found a way to dump the data at the reset vector which enabled us to decrypt the main portion of the IPL code and then use this to figure out how the 2.6 PRX files were encrypted. The same encryption method and keys are used in 2.7 and 2.71, so when 2.7 came out we had this dumped and decrypted very quickly. There is nothing left now they can use to hide the IPL so when the 3.0 firmware eventually comes out its highly likely the encryption will have changed again but it
shouldn’t take too long to figure it out. Sorry to give you the bad news Sony.. the hackers win another round, you cannot hide your firmware from our eyes anymore ;)

REMEMBER WE DO NOT ALLOW ISO DISCUSSION BUT IVE LEFT THE ARTICLE INTACT FOR NOW.

kfish2oo2
July 22nd, 2006, 23:30
Errr...Why is this news? I thought the whole point of the UP chip was to run ALL firmwares alongside 1.5. This is silly.

langsalang
July 22nd, 2006, 23:44
so wat if ur psp is bricked but have the U.P chip?
if the psp's original flash is bricked u cant use this?
since u have to have the firmware version 2.71 on the origianl psp's flash? or does U.P let u flash the original psp's flash as well as its own built on one??
im asking coz my psp is bricked while downgrading and soon im getting the U.P chip. i kinda need the answer quick. thank u

Anger
July 22nd, 2006, 23:56
this is news because it combines the good of 1.5/1.0 and mixes it with 2.71 (for now) so with this you can launch homebrew in a 2.71 psp. and of course play all games that have been released with no need for emulators to run the latest firmware etc.

in answer to your question yes you can use u.p. to fix your bricked psp. the instructions are in that article that you just didnt read :P but yeah it is possible to fix a bricked psp using u.p. and this. if your in any doubt read the article above (second post) it should tell you what you want.

pkmaximum
July 23rd, 2006, 00:19
Hmmm only a matter of time before this is emulated with dev hook (legal UMD version)

popcornx
July 23rd, 2006, 00:30
warning: do not get the modchip until this is confirmed real~!

siulmagic
July 23rd, 2006, 00:31
well correct me if im rong but if devhook does get to emulate a nad flash we coult in theory unbrick psp cu the psp will think it has 2 nad flash or something that devhoo tells him

siulmagic
July 23rd, 2006, 00:32
well if they say its true it has to be or else it would be pleturisum and thas ilegal they are chargin 99 dollars for the modchip so they have to say the truth

The_Lead_Factor
July 23rd, 2006, 01:13
well correct me if im rong but if devhook does get to emulate a nad flash we coult in theory unbrick psp cu the psp will think it has 2 nad flash or something that devhoo tells him
Once your PSP is bricked, how are you gona load up devhook :p

mog
July 23rd, 2006, 02:31
Hmm, I saw the video demo of Epsilon bios and was very impressed by how functional it looked.
It's interesting to hear how they decrypted 2.71...
"some hardcore trickery", now why did no one else think of that?! :p
So now they they found out about the encryption method and how to obtain the encryption keys...
So couldn't they also find a way for us to sign our homebrew so it would just run on fw 2.71 anyway??? :confused:
Hmm, I guess there are still problems with doing that, but I still don't see why it is seen as impossible?



you must upgrade your PSP onboard firmware to 2.71 in order to use Epsilon BIOS.:(
I'm not sure I would be able to force myself to do that!
After all me and fw1.00 have gone through... I don't think I could just kill it and shove crappy 2.71 over it's grave! :p
Would it not be possible to put Epsilon + fw2.71 on the modchip and piggyback fw1.00 from onboard flash?



warning: do not get the modchip until this is confirmed real~!
The mod chip is definitely real...it has been available for a couple of weeks now.
You can watch people use it on YouTube (www.youtube.com) and watch people install in at TeknoConsolas (http://www.teknoconsolas.info) (spanish) and soon PSPHacking101 (http://www.psphacking101.com). ;)
I also have the modchip, but I haven't installed it yet...
I just don't have much reason to install it at the moment...(and maybe still a little scared... :o)

popcornx
July 23rd, 2006, 04:37
oh I ment the bios not the modchip. Sorry.

Kramer
July 23rd, 2006, 05:52
If anyone cares epsilon bios is available for download at psp-hacks

mog
July 23rd, 2006, 07:40
I only just noticed that... most PSP sites haven't posted about it yet!
MaxConsole aparently put it on their website about 10 hours ago - 9:30 PM UK.
Not even pspupdates have it yet... :p

Anger
July 23rd, 2006, 11:18
It's interesting to hear how they decrypted 2.71...
"some hardcore trickery", now why did no one else think of that?! :p
So now they they found out about the encryption method and how to obtain the encryption keys...
So couldn't they also find a way for us to sign our homebrew so it would just run on fw 2.71 anyway??? :confused:
Hmm, I guess there are still problems with doing that, but I still don't see why it is seen as impossible?

the answer to this is this - they didnt find the ENcryption keys but they found the DEcryption keys. the encryption keys are kept at sony and are not anywhere in the psp at all. also sony can change how they encrypt the data at any time and there are many different ways for them to do this so even if you had the keys you would need to know the methods as well.

donald7777
September 9th, 2006, 06:08
i just downgraded my brothers psp from 2.71 to 1.5 and it bricked with no mod chip. just making sure that there is no way to fix this before i return it to bestbuy.

pkmaximum
September 9th, 2006, 07:35
When you say it bricked, be a bit more specific for instance:

Did it brick while you were downgrading?

Did it brick while you were installing something like custom game boot, font, etc?

Do you have custom firmware installed on it?

donald7777
September 9th, 2006, 07:39
I bricked it whille downgradeing from 2.71 firmware to 1.50. everything was going fine till it froze after 5 hours and would not do anything after restarting it.