The GlitchMod knowledge base

Recovering Data

If something happens to your PS3 that leaves you unable to access files on the system storage, you may still be able to recover important files if you have previously dumped your per-console hard-drive encryption key (eid_root_key). If a P…

9 min readUpdated Oct 9, 2026
Exclamation-triangle-fill.svgThis guide only applies to CFW or qCFW consoles; PS3HEN by itself cannot dump the required ERK file.

If something happens to your PS3 that leaves you unable to access files on the system storage, you may still be able to recover important files if you have previously dumped your per-console hard-drive encryption key (eid_root_key).

If a PS3 hard drive has been reinitialized but not formatted, you may be able to flash a new boot sector onto it.

Please note that the tools for Windows only allow for read-only access; you cannot use them to write files to the PS3's system storage. However, there are tools on Linux that allow for such actions.

Dumping the eid_root_key (CFW)

Rebug Toolbox

  1. Open Rebug Toolbox under "Game" on the XMB.
    • If you do not have Rebug Toolbox installed, the installer should already be on your console at /dev_rebug/rebug/packages, where you can install it via "Package Manager > Install Package Files > PS3 System Storage".
    • If Rebug Toolbox is not downloaded, you can get the latest version from Brewology (mirror, source)
  2. Navigate to the "Utilities" category, scroll down to and select "Dump eid root key".
  3. A popup will inform you that the eid_root_key will be created in /dev_hdd0/game/RBGTLBOX2/USRDIR/, select "Yes".
  4. The PS3 will reboot and beep.
  5. Navigate to the location Rebug Toolbox informed you of with either your choice of homebrew or FTP program, copying over the "eid_root_key" file to a flash drive or your computer.

Evilnat Firmwares

Exclamation-circle-fill.svgThis feature was added in Evilnat 4.88.2; it will not be available in 4.88.1 or lower.
  1. From the top of the "Network" column on the XMB, select "Custom Firmware Tools".
  2. Navigate to and select the "Dump Tools" category.
  3. Navigate to and select "Dump ERK".
  4. Navigate to either /dev_usbX/ or /dev_hdd0/tmp/ and copy the eid_root_key to a safe place such as your PC.

Dumping the HDD and ENCDEC Keys (qCFW)

  1. On qCFW, use option Custom Firmware Tools -> Dump Tools -> Dump HDD Key (qCFW). Your console will reboot.
  2. After you are back at the XMB, insert the USB drive into the RIGHTMOST slot.
  3. Use the Save HDD Key to USB (qCFW) option.

PS3 HDD Reading Software

Exclamation-triangle-fill.svgWhenever you plug the PS3's system drive into a PC, be careful to never format or initialize the drive; doing so may permanently erase your data.

UFSXplorer (Windows)

UFSXplorer is a modern tool (currently exclusive to Windows) developed by sagemono, and comes with many useful tools for working with the PS3 HDD, like a PKG installer.

The latest release can be found here.

PS3HDDTool

PS3HDDTool is a modern easy-to-use crossplatform tool developed by Mena.

The latest release can be found here, and a tutorial can be found in its README.md here.

PS3 HDD Reader (Windows)

  1. Plug the SATA and power cable from your PC into the PS3's HDD.
  2. Turn your PC on, and if prompted, select "No" to initializing or formatting the drive.
  3. Download PS3_HDD_Reader by 3141card from here, extract the folder once complete.
  4. Paste your eid_root_key into the "PS3_HDD_Reader_final_windows" folder
    • The readme.txt in the download will have the same or similar instructions to the below.
  5. Navigate to the "PS3_HDD_Reader_final_windows" folder previously extracted, and where the directory is displayed (to the left of the search bar), right click and select "Copy address as text"
    • Alternatively, selecting "Copy path" with the "PS3_HDD_Reader_final_windows" folder selected will achieve the same result.
  6. Press Start, search for "cmd", right click Command Prompt, and select Run as Administrator.
  7. Enter the command cd ... (replacing ... with the copied path to the folder you extracted).
    • If you copied the "PS3_HDD_Reader_final_windows" folder to a drive other than C:\, you may have to enter the command "[drive letter]:" (e.g., "C:\WINDOWS\system32>D:").
  8. In the command prompt window, enter ps3_hdd_reader.exe hdd. This will display all available partitions on the PS3's HDD and will indicate that everything is working okay.
    • Alternatively, if you have a dump of a PS3 HDD, name it backup.bin, place it in the extracted programs folder, and use the command ps3_hdd_reader.exe file. Replace "hdd" with "file" as the first argument in the following commands (e.g. ps3_hdd_reader.exe file dev_hdd0 copy /PS3ISO).
  9. Again, in the command prompt window, you can begin copying and viewing the files you want through commands such as:
    • dir to view a specified directory's contents.
      • ps3_hdd_reader.exe hdd dev_hdd0 dir / to view the dev_hdd0 partition file structure.
    • copy to copy a specified directory's contents to the PS3_HDD_Reader_final_Windows folder.
      • ps3_hdd_reader.exe hdd dev_hdd0 copy /PS3ISO to copy all files inside the "PS3ISO" directory.
    • It's not recommended to copy entire large directories such as "dev_hdd0" due to potential storage space issues on the PC; instead, copy individual large files such as ISO or folder games with commands:
      • ps3_hdd_reader.exe hdd dev_hdd0 copy /GAMES/[gameName] (replacing [gameName] with the exact name of the folder/file).
  10. Once you have copied all your important data, unplug your PS3 hard drive.

Linux Terminal

PSX-Place member Berion has developed a series of Linux scripts that allow for easy management of PlayStation 2, PlayStation 3, & PlayStation 4 hard drives on a PC. Of course, this section of the page will focus on his PS3 scripts.

His original forum post tutorial can be found here. This page on ConsoleMods will just act as a mirror for archival purposes.

Mounting The PS3 Internal Memory on Linux (2023-11-22).pdf

Montowanie pamięci wewnętrznej na Linuksie (2023-11-22).pdf (Polish guide)

bswap16-ecb.ko

Initial Setup

sudo su

losetup loop1 /home/mint/ps3/disk.img

insmod '/home/mint/ps3/bswap16-ecb.ko'

cryptsetup create -c bswap16-ecb -d /dev/zero ps3hdd-bs /dev/loop1

Setting up HDD from a Slim

cryptsetup create -c aes-xts-plain64 -d /home/mint/ps3/ata_key.bin -s 256 ps3hdd /dev/mapper/ps3hdd-bs

kpartx -a /dev/mapper/ps3hdd

Setting up HDD from a Fat

cryptsetup create -c aes-cbc-null -d /home/mint/ps3/ata_key.bin -s 192 ps3hdd /dev/mapper/ps3hdd-bs

kpartx -a /dev/mapper/ps3hdd

If you have a fat with NOR memory, you will also need to set up the vFlash key like a Slim. If you're unsure what your PS3 uses, you can check the buying guide.

cryptsetup create -c aes-xts-plain64 -d /home/mint/ps3/vflash_key.bin -s 256 -p 8 ps3vflash /dev/mapper/ps3hdd1

kpartx -a /dev/mapper/ps3vflash

Mounting/Unmounting

mount -t ufs -o ufstype=ufs2,ro /dev/mapper/ps3hdd2 /home/mint/ps3/dev_hdd0

mount -t vfat /dev/mapper/ps3hdd3 /home/mint/ps3/dev_hdd1

mount -t vfat /dev/mapper/ps3vflash2 /home/mint/ps3/dev_flash1

mount -t vfat /dev/mapper/ps3vflash3 /home/mint/ps3/dev_flash2

mount -t vfat /dev/mapper/ps3vflash4 /home/mint/ps3/dev_flash3

umount -l /home/mint/ps3/dev_hdd0

umount -l /home/mint/ps3/dev_hdd1

umount -l /home/mint/ps3/dev_flash1

umount -l /home/mint/ps3/dev_flash2

umount -l /home/mint/ps3/dev_flash3

kpartx -d /dev/mapper/ps3vflash && cryptsetup remove ps3vflash

kpartx -d /dev/mapper/ps3hdd && cryptsetup remove ps3hdd

cryptsetup remove ps3hdd-bs

losetup -d /dev/loop1

rmmod bswap16

exit

bswap-nbd + nbd-client (Deprecated)

This process was tested on Mint Cinnamon 18.2. YOU CANNOT DO THIS METHOD ON A LIVE CD/USB!

  1. Open up a new terminal window and run the following command:
    sudo apt-get install openssl nbd-client
  2. Download the tools and extract the "ps3" file to /home/your_name.
  3. Open up a new terminal window, or reuse your previous one and change directory to /home/your_name/ps3.
  4. Copy your eid_root_key into this directory and rename it to eid_root_key.bin.
  5. If you are using Cinnamon 18.2, rename the "bswap16 (Mint 18.2 64bit, 512).elf" file to "bswap16.elf" using the command mv "bswap16 (Mint 18.2 64bit, 512).elf" "bswap16.elf" in Terminal.
  6. Run the following command:
    chmod +x makedev.sh bswap16.elf "PS3HDD Keygen v1.3.sh"
    ./PS3HDD\ Keygen\ v1.3.sh
  7. Select what model PS3 you have. This script will create the decryption keys.
  8. Run the command lsblk to determine what identifier the PS3 HDD has. (/dev/sda, /dev/sdb and so on).
  9. Switch to superuser mode by executing the command sudo su.
  10. Execute the following command using the sdx identifier from step 8. If it succeeds, you should not receive an error.
    ./makedev /home/your_name/ps3/bswap16.elf /dev/sdx
    • If you're on a Fat console, run the following command:
    cryptsetup create -c aes-cbc-null -d /home/your_username/ps3/hdd_key.bin -s 192 ps3hdd /dev/nbd0"
    • If you're on a Slim console, run this one instead:
    cryptsetup create -c aes-xts-plain64 -d /home/your_username/ps3/hdd_key.bin -s 256 ps3hdd /dev/nbd0
  11. Run the following command:
    kpartx -a /dev/mapper/ps3hdd
  12. If everything went well so far, running the following command will yield multiple partitions starting with dm-X. If you're only getting one partition, you decrypted it wrongly.
    ls -l /dev/mapper/
  13. On NOR consoles, dm-1 is the VFLASH, whereas on NAND, dm-1 is dev_hdd1. dm-2 is always dev_hdd0 and dm-4 is dev_hdd2 (dm-3 on NAND consoles.)
  14. To mount the VFLASH on NOR consoles, you need to execute the following commands:
    cryptsetup create -c aes-xts-plain64 -d /home/your_username/ps3/vflash_key.bin -s 256 -p 8 ps3vflash /dev/dm-1
    kpartx -a /dev/mapper/ps3vflash
  15. To mount dev_hdd0, you need to execute the following command:
    mount -t ufs -o ufstype=ufs2,ro /dev/dm-2 /home/mint/ps3/dev_hdd0
  16. Mounting of dev_hdd1 and the dev_flash regions (for NOR) requires you to execute the following. This also works for mounting dev_hdd1 on NAND.
    mount -t vfat /dev/dm-3 /home/your_username/ps3/dev_hdd1
    mount -t vfat /dev/dm-6 /home/your_username/ps3/dev_flash1
    mount -t vfat /dev/dm-7 /home/your_username/ps3/dev_flash2
    mount -t vfat /dev/dm-8 /home/your_username/ps3/dev_flash3
    • Keep in mind that you can only write to the vfat partitions and nothing else. For the other partitions, you can only read.
  17. When you're finished doing your work, you'll need to unmount the partitions as well as delete the mapper drives. You can do that by executing the following commands.
    umount -l /home/mint/ps3/dev_hdd0
    umount -l /home/mint/ps3/dev_hdd1
    umount -l /home/mint/ps3/dev_flash1
    umount -l /home/mint/ps3/dev_flash2
    umount -l /home/mint/ps3/dev_flash3
    kpartx -d /dev/mapper/ps3vflash && cryptsetup remove ps3vflash
    kpartx -d /dev/mapper/ps3hdd && cryptsetup remove ps3hdd

User Data Backup Guide

Byrom has also created a general guide on the directories that are important to back up on PSX-Place. This section on ConsoleMods will just act as a mirror for archival purposes.

PS3 Manual Backup (2020-04-19)-1.pdf (English Guide)

Ręczna kopia zapasowa (2020-04-19).pdf (Polish Guide)