| This guide only applies to CFW or qCFW consoles; PS3HEN by itself cannot dump the required ERK file. |
If something happens to your PS3 that leaves you unable to access files on the system storage, you may still be able to recover important files if you have previously dumped your per-console hard-drive encryption key (eid_root_key).
If a PS3 hard drive has been reinitialized but not formatted, you may be able to flash a new boot sector onto it.
Please note that the tools for Windows only allow for read-only access; you cannot use them to write files to the PS3's system storage. However, there are tools on Linux that allow for such actions.
Dumping the eid_root_key (CFW)
Rebug Toolbox
- Open Rebug Toolbox under "Game" on the XMB.
- If you do not have Rebug Toolbox installed, the installer should already be on your console at
/dev_rebug/rebug/packages, where you can install it via "Package Manager > Install Package Files > PS3 System Storage". - If Rebug Toolbox is not downloaded, you can get the latest version from Brewology (mirror, source)
- If you do not have Rebug Toolbox installed, the installer should already be on your console at
- Navigate to the "Utilities" category, scroll down to and select "Dump eid root key".
- A popup will inform you that the eid_root_key will be created in
/dev_hdd0/game/RBGTLBOX2/USRDIR/, select "Yes". - The PS3 will reboot and beep.
- Navigate to the location Rebug Toolbox informed you of with either your choice of homebrew or FTP program, copying over the "eid_root_key" file to a flash drive or your computer.
Evilnat Firmwares
| This feature was added in Evilnat 4.88.2; it will not be available in 4.88.1 or lower. |
- From the top of the "Network" column on the XMB, select "Custom Firmware Tools".
- Navigate to and select the "Dump Tools" category.
- Navigate to and select "Dump ERK".
- Navigate to either
/dev_usbX/or/dev_hdd0/tmp/and copy the eid_root_key to a safe place such as your PC.
Dumping the HDD and ENCDEC Keys (qCFW)
- On qCFW, use option Custom Firmware Tools -> Dump Tools -> Dump HDD Key (qCFW). Your console will reboot.
- After you are back at the XMB, insert the USB drive into the RIGHTMOST slot.
- Use the
Save HDD Key to USB (qCFW)option.
PS3 HDD Reading Software
| Whenever you plug the PS3's system drive into a PC, be careful to never format or initialize the drive; doing so may permanently erase your data. |
UFSXplorer (Windows)
UFSXplorer is a modern tool (currently exclusive to Windows) developed by sagemono, and comes with many useful tools for working with the PS3 HDD, like a PKG installer.
The latest release can be found here.
PS3HDDTool
PS3HDDTool is a modern easy-to-use crossplatform tool developed by Mena.
The latest release can be found here, and a tutorial can be found in its README.md here.
PS3 HDD Reader (Windows)
- Plug the SATA and power cable from your PC into the PS3's HDD.
- Turn your PC on, and if prompted, select "No" to initializing or formatting the drive.
- Download PS3_HDD_Reader by 3141card from here, extract the folder once complete.
- Paste your eid_root_key into the "PS3_HDD_Reader_final_windows" folder
- The readme.txt in the download will have the same or similar instructions to the below.
- Navigate to the "PS3_HDD_Reader_final_windows" folder previously extracted, and where the directory is displayed (to the left of the search bar), right click and select "Copy address as text"
- Alternatively, selecting "Copy path" with the "PS3_HDD_Reader_final_windows" folder selected will achieve the same result.
- Press Start, search for "cmd", right click Command Prompt, and select Run as Administrator.
- Enter the command
cd ...(replacing ... with the copied path to the folder you extracted).- If you copied the "PS3_HDD_Reader_final_windows" folder to a drive other than C:\, you may have to enter the command "[drive letter]:" (e.g., "C:\WINDOWS\system32>D:").
- In the command prompt window, enter
ps3_hdd_reader.exe hdd. This will display all available partitions on the PS3's HDD and will indicate that everything is working okay.- Alternatively, if you have a dump of a PS3 HDD, name it backup.bin, place it in the extracted programs folder, and use the command
ps3_hdd_reader.exe file. Replace "hdd" with "file" as the first argument in the following commands (e.g.ps3_hdd_reader.exe file dev_hdd0 copy /PS3ISO).
- Alternatively, if you have a dump of a PS3 HDD, name it backup.bin, place it in the extracted programs folder, and use the command
- Again, in the command prompt window, you can begin copying and viewing the files you want through commands such as:
dirto view a specified directory's contents.ps3_hdd_reader.exe hdd dev_hdd0 dir /to view the dev_hdd0 partition file structure.
copyto copy a specified directory's contents to the PS3_HDD_Reader_final_Windows folder.ps3_hdd_reader.exe hdd dev_hdd0 copy /PS3ISOto copy all files inside the "PS3ISO" directory.
- It's not recommended to copy entire large directories such as "dev_hdd0" due to potential storage space issues on the PC; instead, copy individual large files such as ISO or folder games with commands:
ps3_hdd_reader.exe hdd dev_hdd0 copy /GAMES/[gameName](replacing [gameName] with the exact name of the folder/file).
- Once you have copied all your important data, unplug your PS3 hard drive.
Linux Terminal
HDD Decryption Helper Scripts (Recommended)
PSX-Place member Berion has developed a series of Linux scripts that allow for easy management of PlayStation 2, PlayStation 3, & PlayStation 4 hard drives on a PC. Of course, this section of the page will focus on his PS3 scripts.
His original forum post tutorial can be found here. This page on ConsoleMods will just act as a mirror for archival purposes.
Mounting The PS3 Internal Memory on Linux (2023-11-22).pdf
Montowanie pamięci wewnętrznej na Linuksie (2023-11-22).pdf (Polish guide)
bswap16-ecb.ko
Initial Setup
sudo su
losetup loop1 /home/mint/ps3/disk.img
insmod '/home/mint/ps3/bswap16-ecb.ko'
cryptsetup create -c bswap16-ecb -d /dev/zero ps3hdd-bs /dev/loop1
Setting up HDD from a Slim
cryptsetup create -c aes-xts-plain64 -d /home/mint/ps3/ata_key.bin -s 256 ps3hdd /dev/mapper/ps3hdd-bs
kpartx -a /dev/mapper/ps3hdd
Setting up HDD from a Fat
cryptsetup create -c aes-cbc-null -d /home/mint/ps3/ata_key.bin -s 192 ps3hdd /dev/mapper/ps3hdd-bs
kpartx -a /dev/mapper/ps3hdd
If you have a fat with NOR memory, you will also need to set up the vFlash key like a Slim. If you're unsure what your PS3 uses, you can check the buying guide.
cryptsetup create -c aes-xts-plain64 -d /home/mint/ps3/vflash_key.bin -s 256 -p 8 ps3vflash /dev/mapper/ps3hdd1
kpartx -a /dev/mapper/ps3vflash
Mounting/Unmounting
mount -t ufs -o ufstype=ufs2,ro /dev/mapper/ps3hdd2 /home/mint/ps3/dev_hdd0
mount -t vfat /dev/mapper/ps3hdd3 /home/mint/ps3/dev_hdd1
mount -t vfat /dev/mapper/ps3vflash2 /home/mint/ps3/dev_flash1
mount -t vfat /dev/mapper/ps3vflash3 /home/mint/ps3/dev_flash2
mount -t vfat /dev/mapper/ps3vflash4 /home/mint/ps3/dev_flash3
umount -l /home/mint/ps3/dev_hdd0
umount -l /home/mint/ps3/dev_hdd1
umount -l /home/mint/ps3/dev_flash1
umount -l /home/mint/ps3/dev_flash2
umount -l /home/mint/ps3/dev_flash3
kpartx -d /dev/mapper/ps3vflash && cryptsetup remove ps3vflash
kpartx -d /dev/mapper/ps3hdd && cryptsetup remove ps3hdd
cryptsetup remove ps3hdd-bs
losetup -d /dev/loop1
rmmod bswap16
exit
bswap-nbd + nbd-client (Deprecated)
This process was tested on Mint Cinnamon 18.2. YOU CANNOT DO THIS METHOD ON A LIVE CD/USB!
- Open up a new terminal window and run the following command:
- sudo apt-get install openssl nbd-client
- Download the tools and extract the "ps3" file to
/home/your_name. - Open up a new terminal window, or reuse your previous one and change directory to
/home/your_name/ps3. - Copy your eid_root_key into this directory and rename it to
eid_root_key.bin. - If you are using Cinnamon 18.2, rename the "bswap16 (Mint 18.2 64bit, 512).elf" file to "bswap16.elf" using the command
mv "bswap16 (Mint 18.2 64bit, 512).elf" "bswap16.elf"in Terminal. - Run the following command:
chmod +x makedev.sh bswap16.elf "PS3HDD Keygen v1.3.sh"./PS3HDD\ Keygen\ v1.3.sh
- Select what model PS3 you have. This script will create the decryption keys.
- Run the command
lsblkto determine what identifier the PS3 HDD has. (/dev/sda,/dev/sdband so on). - Switch to superuser mode by executing the command
sudo su. - Execute the following command using the
sdxidentifier from step 8. If it succeeds, you should not receive an error../makedev /home/your_name/ps3/bswap16.elf /dev/sdx
- If you're on a Fat console, run the following command:
cryptsetup create -c aes-cbc-null -d /home/your_username/ps3/hdd_key.bin -s 192 ps3hdd /dev/nbd0"
- If you're on a Slim console, run this one instead:
cryptsetup create -c aes-xts-plain64 -d /home/your_username/ps3/hdd_key.bin -s 256 ps3hdd /dev/nbd0
- Run the following command:
kpartx -a /dev/mapper/ps3hdd
- If everything went well so far, running the following command will yield multiple partitions starting with dm-X. If you're only getting one partition, you decrypted it wrongly.
ls -l /dev/mapper/
- On NOR consoles, dm-1 is the VFLASH, whereas on NAND, dm-1 is dev_hdd1. dm-2 is always dev_hdd0 and dm-4 is dev_hdd2 (dm-3 on NAND consoles.)
- To mount the VFLASH on NOR consoles, you need to execute the following commands:
cryptsetup create -c aes-xts-plain64 -d /home/your_username/ps3/vflash_key.bin -s 256 -p 8 ps3vflash /dev/dm-1kpartx -a /dev/mapper/ps3vflash
- To mount dev_hdd0, you need to execute the following command:
mount -t ufs -o ufstype=ufs2,ro /dev/dm-2 /home/mint/ps3/dev_hdd0
- Mounting of dev_hdd1 and the dev_flash regions (for NOR) requires you to execute the following. This also works for mounting dev_hdd1 on NAND.
mount -t vfat /dev/dm-3 /home/your_username/ps3/dev_hdd1mount -t vfat /dev/dm-6 /home/your_username/ps3/dev_flash1mount -t vfat /dev/dm-7 /home/your_username/ps3/dev_flash2mount -t vfat /dev/dm-8 /home/your_username/ps3/dev_flash3
- Keep in mind that you can only write to the vfat partitions and nothing else. For the other partitions, you can only read.
- When you're finished doing your work, you'll need to unmount the partitions as well as delete the mapper drives. You can do that by executing the following commands.
umount -l /home/mint/ps3/dev_hdd0umount -l /home/mint/ps3/dev_hdd1umount -l /home/mint/ps3/dev_flash1umount -l /home/mint/ps3/dev_flash2umount -l /home/mint/ps3/dev_flash3kpartx -d /dev/mapper/ps3vflash && cryptsetup remove ps3vflashkpartx -d /dev/mapper/ps3hdd && cryptsetup remove ps3hdd
User Data Backup Guide
Byrom has also created a general guide on the directories that are important to back up on PSX-Place. This section on ConsoleMods will just act as a mirror for archival purposes.