A german shop whose name is Gamefreak has posted on his blog. I try to translate.
They affirm that the PS JAILBREAK is not a copy of the jig from Sony and a true exploit. By the way are they saying this to make it legal and sell it on their shop? They affirm that the chip is not a PIC18F444 and rather and ATMega chip with Software emulation of USB. They tell that the PSJailbreak emulate roughly a 6 port USB Hub.
In this chip several USB-devices must get connected and disconnected in a speciffic sequence. One of these devices has the ID of Sony´s “Jig” modue. Furthermore they discover that the “Configuration Descriptor” is too big when the SP3 is powered on.
They should have explained that (taken from this site ).
This discriptor overwrites the stack with contained PowerPC-code that is executed. Now various other devices get connected within the emulation. One device has a 0xAD large descriptor that is part of the exploit and contains static data. Short time later (we´re talking about milliseconds here) the “Jig” gets connected and encrypted data is sent to the “Jig”.
An eternity later (in milliseconds that is) the “Jig” answers with 64Bytes of static data, all USB-devices get disconnected, a new device is connected and the PS3 restarts in a new look.
They have a lot of affirmations but no technical proof. And again say that the firmware is not upgradable and publish too an image of what seems to look like a dump of logic analyzer but without any explanation or even the model of the analyzer. And as you may know or not, each ATMEL or other MUC brand can be updated either by the JTAG points available but stucked in the glue of via a simple way through a bootloader (binary executable). For this reason i don’t agree with them. They only need a driver to make it seen by the pc.





