| There is always a chance of bricking your console when flashing data to the NAND/NOR chip. |
To minimize the chance of bricking, do NOT skip any of the following sections. This process will use a recently released software hack to allow the installation of custom firmware. Check to make sure that your console is CFW compatible.
With any newly released exploit of this caliber, there is always a chance that you can brick your console. Follow all sections of this guide exactly as they are written.
Materials Needed
- A USB storage device, formatted as FAT32 with an MBR partition table.
- PyPS3Checker.
- Windows users can download the 'PyPS3checker-standalone-package' and utilize the .bat script; all other operating systems must install Python and run the .py script.
- A CFW-capable PS3.
Using ps3tool.com (4.80 to 4.93 OFW/HFW)
ps3tool.com is the newest PS3 website tool based on a reverse engineering of PS3 Toolset. As such, it is a different backend and not all features are implemented, but PS3 Toolset does not support 4.93.
Checking Current Firmware Version
If your CFW-compatible console is currently on OFW/HFW, you can check if the current firmware is compatible with a web browser exploit.
- Scroll to the Settings column in the XMB.
- Scroll down until you see "System Settings" and click it.
- Scroll down until you see "System Information" and click it.
- You will now see the current firmware version listed next to "System Software".
- If your console is currently on firmware 3.55 or lower, you can skip this tutorial and do a direct update to CEX CFW without exploiting the system.
- If your console is currently a firmware newer than 3.55 but older than 4.80, you will need to install an HFW or OFW update to make it compatible with the flash writer. Use one of these methods to update it.
- If your console is currently on firmware 4.80 to 4.93, you can use this method.
- If your console is currently on a firmware newer than what the methods listed in this section are, you will either need to wait until web browser patchers are updated or use a hardware flasher.
Dumping & Patching the Flash
| After applying the patch on NAND-based consoles with 4.93 firmware, you won’t be able to boot into the XMB and will always get into safe mode after every reboot until the firmware is reinstalled. This is normal, and you should continue as usual. |
Since this tool has its own official tutorial, you can refer to it for full instructions.
Once the flash patching process is complete, you can go to the end of this page that details installing the CFW.
Using ps3toolset.com (4.75 to 4.92 OFW/HFW)
See the PS3 Toolset page.
Using PS3Xploit Flash Writer (4.82 OFW & 4.84/4.85/4.90/4.91/4.93 HFW)
This video guide also details the instructions for using this method. It is recommended to use the PS3 Toolset instead of the flash writer method, but if the PS3 Toolset is inaccessible, then this method will also work.
Checking Current Firmware Version
If your CFW-compatible console is currently on OFW/HFW, you can check if the current firmware is compatible with a web browser exploit.
- Scroll to the Settings column in the XMB.
- Scroll down until you see "System Settings" and click it.
- Scroll down until you see "System Information" and click it.
- You will now see the current firmware version listed next to "System Software".
- If your console is currently on firmware 3.55 or lower, you can skip this tutorial and do a direct update to CEX CFW without exploiting the system.
- If your console is currently a firmware newer than 3.55 but older than 4.82, you will need to install an HFW or OFW update to make it compatible with the flash writer. Use one of these methods to update it.
- If your console is currently on firmware 4.82 to 4.93, you can use this method.
- If your console is currently on a firmware newer than what the methods listed in this section are, you will either need to wait until web browser patchers are updated or use a hardware flasher.
Installing HFW
| If you are already on on 4.82 OFW, or 4.84, 4.85, 4.90, 4.91, or 4.93 HFW, you can ignore this section. |
Download any HFW (you can use the latest if you're not sure) from one of the sources listed in Firmwares and go through the standard HFW update process.
This is an optional step, but if you are using the 4.82/4.84/4.85 versions of PS3Xploit Flash Writer and want the console to use the necessary patch file locally rather than over the website, you will need to have the corresponding flash patch file on a FAT32 USB drive. They already come inside the download link of the Flash Writer website, but direct links to them are also provided at this download link for convenience and/or if you're not self-hosting it. Place the hex files on the root of the USB drive.
Self-hosting the Exploit
Due to changes by GitHub, these steps will be required to use this exploit method until someone is able to self-host this website without using GitHub Hosts.
- Download the aldostools flashwriter & XAMPP
- Launch XAMPP, and click the
Explorerbutton. It will take you to XAMPP's installation folder. - Navigate to the folder named
htdocs. - Extract the files from the flash writer zip into a folder named
ps3xploitinside XAMPP'shtdocsfolder. - In XAMPP, start the Apache module. The computer will now be hosting the web page.
- Determine the IP address of the computer.
- On Windows, it can be done by opening the terminal, command prompt, or PowerShell by typing the
ipconfigcommand. The IP address will be shown on the current network adapter. It can also be seen through the Network & Internet options in the settings app. - On macOS, it can be seen by either viewing the current connection in the System Information application or by typing the
ifconfig -a | grep inetcommand in the terminal. - On Linux distributions, it can be seen by typing the
ip addr showcommand in the terminal. It may also be viewable in your desktop environment's network settings GUI.
- On Windows, it can be done by opening the terminal, command prompt, or PowerShell by typing the
- If you're using 4.82 OFW or 4.84/4.85 HFW and want the PS3 to get the patch file locally rather than from the website, you should also install the corresponding
flash_48x.hexfile that corresponds to your console on a FAT32 USB drive. They will be inside the482,484, and485paths in Flash Writer's root directory.- Since the 4.82/4.84/4.85 Flash Writer sites will only use hex files with a specific name, you can have all three flash hex files on the USB drive if you wish.
- Continue to the next section for your firmware version.
Using the Exploit-Loading Site (4.9x HFW)
Dumping NAND/NOR flash
- From the XMB, navigate to the Network column of the XMB and open the Internet Browser, press Triangle > select Tools > Homepage > Use Blank Page.
- Press
> select Tools > Delete Cookies. - Press
> select Tools > Delete Search History. - Press
> select Tools > Delete Cache. - Press
> select Tools > Delete Authentication Information. - Press
to close the browser, then open it again. - Press
and enter the computer's local IP address with /ps3xploitadded at the end of the address. - Read the information displayed, then press Cross on the "Click here to CONTINUE" text.
- Insert a FAT32 MBR-formatted USB into the rightmost USB port of the PS3 and select the flash memory type used in your PS3's model, either NOR or NAND.
- CECHA/B/C/E/G models use NAND flash, while all other CFW-compatible models (CECHH/J/K/L/M/P/Q "fat" models and CECH-20/21/25 "slim" models) use NOR flash.
- The page should change to display "Successfully found all variable offsets!" Select the "Run checks" button.
- A file named
flash49x.P3T(file name number will be your current firmware version) will be downloaded; once complete, press the Circle button to close the prompt. - Once the text changes from "Checking patch file..." to "All checks passed!" select the "Dump flash memory" button.
- The page should eventually update to display "Dump operation successful!" Unplug the USB from the PS3 and plug it into a PC. Do not make any other changes to the PS3.
Verifying NAND/NOR flash dump (Windows)
- Download PyPS3Checker with the provided link.
- Extract the contents of the .zip archive to a new folder, and open the newly created folder to find the
drag&drop_your_dump_here_py3.batfile. - Select the flash dump .bin file from the USB, dragging and dropping it on top of the
drag&drop_your_dump_here_py3.batfile, a new window should open. - Verify that the number of dangers and number of warnings are both 0.
- If either is encountered, reinstall the PS3's firmware and try again.
- If an error is shown only for SKUIdentityData, the PS3 is likely refurbished, and it is okay to proceed.
- If an error is shown only for the hash of either ROS0 or ROS1, it is okay to proceed, but reinstalling the current firmware and creating a new flash dump should fix this warning. This just means that the current firmware slot & backup firmware slot are mismatched.
- If either is encountered, reinstall the PS3's firmware and try again.
Patching the flash
- Return to the PS3 and select the "Patch flash memory" button.
- It is important that the PS3 does not lose power or is otherwise interrupted during the patching process; ensure not to accidentally bump the PS3 or close the internet browser.
- The page should update to display "Patch operation successful!" Press Circle to close out of the browser, restart the PS3, and then continue to the next section for installing a CFW.
Using the Exploit-Loading Site (4.82 OFW & 4.84/4.85 HFW)
Dumping NAND/NOR flash
- From the XMB, navigate to the Network column of the XMB and open the Internet Browser, press Triangle > select Tools > Homepage > Use Blank Page.
- Press
> select Tools > Delete Cookies. - Press
> select Tools > Delete Search History. - Press
> select Tools > Delete Cache. - Press
> select Tools > Delete Authentication Information. - Press
to close the browser, then open it again. - Press
and enter "aldostools.github.io/flashwriter".
- If you are self-hosting the site, use the computer's local IP address with
/ps3xploitadded at the end of the address.
- If you are self-hosting the site, use the computer's local IP address with
- Read the information displayed, then press Cross on the "Click here to CONTINUE" text.
- Insert a FAT32 MBR-formatted USB into the rightmost USB port of the PS3, and select the HDD version of the flash memory type used in your PS3's model, either NOR or NAND.
- CECHA/B/C/E models (all the models with PS2 backwards compatibility), in addition to the CECHG, use NAND flash, while all other CFW-compatible models (CECHH to the CECH25) use NOR flash.
- If you select the USB version, your USB drive will need to have the flash_48x.hex files on the root of the drive.
- Read the warnings on screen, and ensure that either
/dev_usb000/dump.hex(right USB port) or/dev_usb001/dump.hex(left USB port), or the one next to the rightmost USB port on CECHA/B/C/E) is selected. - Click the "Initialize exploitation" button, wait for a success message, and then choose "Dump (your flash type) to USB/Card device" and wait until you receive a message saying
(NAND/NOR) Flash dump operation completed..!.
Verifying NAND/NOR flash dump (Windows)
- Download PyPS3Checker by clicking on the "PyPS3checker-standalone-package..." text and then the "Download" button.
- Extract the contents of the .zip file, and open the newly created folder to find the
drag&drop_your_dump_here_py3.batfile. - Select the dump.hex file from the USB, dragging and dropping it on top of the
drag&drop_your_dump_here_py3.batfile, a new window should open. - Verify that the number of dangers and number of warnings are both 0.
- If either is encountered, reinstall the PS3's firmware and try again.
- If an error is shown only for SKUIdentityData, the PS3 is likely refurbished, and it is okay to proceed.
- If an error is shown only for the hash of either ROS0 or ROS1, it is okay to proceed, but reinstalling the current firmware and creating a new flash dump should fix this warning. This just means that the current firmware slot & backup firmware slot are mismatched.
- If either is encountered, reinstall the PS3's firmware and try again.
Patching the flash
- Return to the PS3 and select the
Patch (NOR/NAND) flash memorybutton. A message should appear sayingProceeding to patch (NOR/NAND) Flash Memory.... After a few minutes, it should change toNOR/NAND Flash memory patch operation completed..!.- It is important that the PS3 does not lose power or is otherwise interrupted during the patching process; ensure not to accidentally bump the PS3 or close the internet browser.
- If it takes longer than 5 minutes to complete, exit the browser and try again.
- The page should update to display "Patch operation successful!" Press Circle to close out of the browser, restart the PS3, and then continue with the following steps for installing a CFW.
Installing a CFW
Once the flash patching process is complete, you will now be ready to update your console with a CFW file.
| If your console's Bluetooth/Wi-Fi is non-functional, you will need to use No-BT custom firmware to avoid an update loop. It's advised to test Bluetooth/Wi-Fi by either trying to use a DualShock 3 controller wirelessly or trying to connect to a Wi-Fi network before updating. If your console's Blu-ray drive daughterboard or controller is non-functional, you will need to use no-BD firmware to avoid an update loop. It's advised to test the Blu-ray drive controller by attempting to insert a disc when the console is off and seeing if it activates the disc drive power switch. If the disc drive can also successfully feed and eject discs without weird, strange behaviors, then the daughterboard is perfectly functional. If you are stuck in an update loop, please see the Update Loop section on this section. |
Safe Mode (Recommended)
Make sure you have a FAT32-formatted USB drive that is at least 256 MB or larger and uses MBR partitioning, and a DualShock 3 controller. DualShock 3 clone controllers may work as well, but it isn't guaranteed. It is recommended to do this process twice to ensure both of the console's firmware slots (ROS0/ROS1) are both overwritten with the desired firmware.
- Download the latest Evilnat CFW (make sure to download the PEX file, not CEX or D-PEX), and verify its MD5 hash.
- Create a folder called "PS3" on the root of your USB storage device.
- Create a folder within the PS3 folder called "UPDATE".
- Place the desired firmware within the UPDATE folder and rename it "PS3UPDAT.PUP".
- If you are on Windows and have file extensions hidden, name it "PS3UPDAT" instead.
- Some firmware developers release their firmwares as ZIP files that set up the directories and rename the .PUP to "PS3UPDAT.PUP" for you. A firmware update should have the extension
.PUP.
- Remove any disc in the Blu-ray drive.
- Plug your controller and USB storage device into your PS3.
- Boot your console into safe mode by powering it on, holding the power button until it turns off, then holding it again until it does a quick double beep.
- Press the PS button, and scroll down and select the
System Updatebutton. It may appear to hang while it checks for an update; so long as the loading icon is spinning, it is searching, and it may take hours depending on your storage device.- If it reports the data as corrupt, double-check the file and folder names and its MD5 hash, and make sure you chose the correct update for your system (PEX).
- If you want to use a modern controller, such as a DualSense, in safe mode, you will need to use a USB controller adapter (such as a Mayflash Magic NS) in order for the HOME button to work like an authentic DualShock 3 in safe mode.
- Select the listed update, proceed through the prompts, and allow the update to install and reboot the console.
- (Optional) Visit this page of the wiki to learn about the basic things you can do with your newly hacked PS3 and explore the rest of the PS3 Mods Wiki.
XMB System Settings
Please note that the PS3 will not allow you to reinstall the same firmware version when using the update feature in the system settings, but updating to a newer version will always work. It is recommended to reinstall the firmware a second time through Safe Mode to keep both of the console's firmware slots up to date and to clear any old corruption.
- Download the latest Evilnat CFW (make sure to download the PEX file, not CEX or D-PEX), and verify its MD5 hash.
- Create a folder called "PS3" on the root of your USB storage device.
- Create a folder within the PS3 folder called "UPDATE".
- Place the desired firmware within the UPDATE folder and rename it "PS3UPDAT.PUP".
- If you are on Windows and have file extensions hidden, be sure to unhide them.
- Some custom firmware developers release their firmwares as ZIP files that set up the directories and rename the .PUP to "PS3UPDAT.PUP" for you. A firmware update should have the extension
.PUP.
- Remove any disc in the Blu-ray drive.
- Plug your USB storage device into your PS3.
- Navigate to Settings > System Update > Update via Storage Media
- It may appear to hang while it checks for an update; so long as the loading icon is spinning, it is searching, and it may take hours depending on your storage device.
- If it reports the data as corrupt, double-check the file/folder names, the PUP file's MD5 hash, and make sure you chose the correct update for your system (PEX).
- Select the listed update, proceed through the prompts, and allow the update to install and reboot the console.
- (Optional) Visit this page of the wiki to learn about the basic things you can do with your newly hacked PS3 and explore the rest of the PS3 Mods Wiki.
Update Loop
Regardless of the firmware you are updating from, installing a firmware update when the Bluetooth/Wi-Fi chip (error code 8002F1F0/8002F1F9) or Blu-ray drive controller (error code 8002F14E) is non-functional or improperly connected may result in an update loop where it fails to update, reboots, and then keeps trying. To get out of this, either repair the broken part—which is necessary if you are on OFW/HFW—or you can try the below process, which has been reported to work for some people.
Please note that this may carry a risk of bricking your console's NAND/NOR flash memory.
- Note the percentage that the update fails at.
- Allow it to start updating again, and when it reaches about 3-4% before the noted percentage, look at the HDD activity light on the front of the console. When it stops blinking, unplug the HDD for three seconds. With some luck, this will fail to update and exit the update loop.
- If your Blu-ray daughterboard/controller is broken/missing, update using a no-BD firmware.
- If your Bluetooth/Wi-Fi chip is broken/missing, update using a no-BT firmware.
- If both are broken, update with a no-BD + no-BT firmware.
If you have a disc drive-related update error and your PS3 model is one where the disc drive has its own daughterboard, you can simply swap in another working daughterboard for the update to complete. It can also be just caused by the data cable not being seated correctly, like if the console was taken apart improperly before. While games and PS Store apps won't launch when a daughterboard is working but not paired, it is enough to at least install updates.
Since all PS3 models with disc drive daughterboards are CFW compatible, you can remarry them later on with CFW.
Most fat models (excluding CECHL and CECHP) also have a removable Wi-Fi/Bluetooth board, so swapping a defective chip on these models is also straightforward.
Bad Flash Recovery
If something goes wrong while flashing your NAND and your console is not working properly (or "bricked"), you may be able to recover it by updating the firmware normally through the XMB, ensuring you haven't shut down your console. Otherwise, you can possibly boot into recovery mode and reinstall your current firmware from there. If this does not work, you will need to use a hardware flasher to reflash. Please see the Bad Flash Recovery section of the E3 Flasher, Teensy or ProgSkeet guides.
Troubleshooting
Unable to access PS3Xploit:
- Check PSX-Place for any news regarding service changes.
Flash drive not appearing to dump flash:
- Check that the flash drive is formatted as a FAT32 MBR drive.
- To check if the PS3 detects the drive, plug it into the PS3 and see if it appears under the 'Music' category of the XMB.