The original PlayStation 2 security chip was reverse engineered

The original PlayStation 2 security chip was reverse engineered

The last unmapped part of the big PS2 has been gutted.

More than 25 years after the launch of the big PlayStation 2, a developer known as DiscoStarslayer has managed to extract firmware from the stubborn SPC970 MechaCon chip, responsible for authorizing discs and handling most of the console’s security.

In a Bluesky post, the developer credited Libby, the collaborator who found an exploit that made mining possible. According to the dump tool’s documentation, this exploit told the chip that an incoming batch of settings data would be empty and would send more data than it had room for. Before that, in an effort that lasted about four years, there had been difficulty with a slower method of disassembling the chip packaging and reading its contents, which produced only crude discharges.

Everything has been uploaded to GitHub alongside 22 firmware images covering the big PS2s, from 2000’s Japan-only SCPH-15000 to 2002’s 39000 series models. They also cover the Namco System 246 and 256 arcade cards which used the same chip. These early machines were among the last unplayed parts of the PS2 after 2003’s MechaCon “Dragon” dropped in 2021.

Extract chip firmware

The SPC970 chip keeps its code in mask ROM, which cannot be written or corrected, and only stores calibration and configuration data in a separate 1 KB EEPROM. To get around this problem, the enthusiast group “spc970-dumper-union” abused the way the chip writes to this EEPROM.

The group discovered that opening a configuration write session with a block count of zero would cause the chip’s internal counter to overflow. Pushing more data than the seven-block buffer may cause overflows in the RAM that contains the EEPROM write task. Overwriting the source address of this task points it to the chip’s ROM, which means the MechaCon copies 256 bytes of its firmware into the EEPROM. Once there, the PS2 can play it back with a standard command. Once repeated about 1,000 times, the full 256 KB image is on a USB stick.

Each of these 1,000 passes rewrites the EEPROM, but each backup shortens its lifespan because it has no wear level and a smaller write budget than flash memory. To guard against this, the tool backs up the EEPROM before booting, restores it word by word afterward, and checks the result against the checksum routine when the chip is powered on. There’s always a risk, though, and Libby’s original dumper warns that it may leave a PS2 “unable to function normally, or in need of hardware repair. Use it entirely at your own risk.”

Building on the work of MechaPwn

Dragon MechaCon firmware images were released in 2021. MechaPwn, the exploit that made later PS2s region-free and allowed them to play save discs, was released a month later. The README file for this exploit states that older consoles do not use Dragon-based MechaCon and are therefore not supported, and that no support is planned. This affects around 20 model numbers from the first three years of the PS2, between 2000 and 2003. These machines can still run saves via memory card and hard drive exploits, but could not be unlocked at the chip level until now because no one could see its code. These landfills make this research possible for the first time.

The images alone don’t contain enough information to create an optical drive emulator, but they could support a chip that replaces the MechaCon, while still retaining the drive’s DSP to read discs. Since the PS2 games weren’t encrypted, nothing new is unlocked here. But the firmware exposes the code behind Sony’s “MagicGate” encryption for memory cards and KELF executables allow the console to boot from disk and memory cards. This will ultimately power “low-level emulation of the full system,” says contributor Uyjulian. PCSX2 and other emulators, which can also emulate the weaker GameCube, do not execute the chip code at all: PCSX2 reimplements MechaCon’s commands in C++ and reads a 1 KB NVRAM file and four-byte version number from disk to replace the real part. DiscoStarslayer maintains a PCSX2 fork called Reliquary, intended for authenticated PS2 paths. They acknowledge in their README that the replacement data generated does not override the hardware values ​​when a security check inspects the console identity.

As for the SPC970, the first task of its dump is to find a bug that opens the first consoles. With MechaPwn, people could read the Dragon chip’s code and find a weakness in the way Sony let that chip update itself. Uyjulian says a MechaPwn or TonyHax style unlock for the SPC970 is one of the goals here, but it won’t come that quickly. It only took researchers a month to crack Dragon, because Sony built that chip to accept patches. This gave researchers something to crack. The SPC970 cannot be updated at all; its code was integrated into the chip in 2000 and has never changed.

Similar Posts