spc970_dump_news_info.md

Info relating to PS2 SPC970 MechaCon dumps

Related to https://x.com/DiscoStarslayer/status/2099132300390744320

I an involved in reverse enginnering the PlayStation 2's MechaCon. See https://www.psdevwiki.com/ps2/MechaCon

I see a lot of mis-information regarding the news regarding the dumping of the SPC970 MechaCon. Here are some notes:

  • It is already possible to run backup/copied discs entirely using software methods (from memory card, HDD, or DVD video player exploit), and in the case of the 50k series and newer (Dragon MechaCon), can use the "force unlock" patch that does not require any patches to copied discs.
  • The dumps, alone, does not give enough information to create an """hardware""" ODE (optical drive emulator). However, it is possible to make a modchip that replaces the MechaCon, relying on the DSP to continue to read discs.
  • The current method to dump the ROM used in the SPC970 requires lots of writing to NVRAM.
  • These dumps will eventually be useful for full-system low level emulation, as MagicGate and KELF/KIRX security goes through it.
  • These dumps are useful for vulnability searching, which can allow functionality to MechaPwn (code execution on MechaCon, unlocking security e.g. set disc type and max LBN) or TonyHax (unlocking PS1 mode to read any disc, on SPC970 based MechaCons and all PS1 MechaCons).
  • The contents of game discs (except those that use DNAS online authentication) are not encrypted. These dumps don't unlock anything additional there.

Etc.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论