More than 25 years after the original PlayStation 2 launched, developer Disco Starslayer has successfully extracted firmware from the elusive SPC970 Mecha Con chip used in early fat PS2 models. The breakthrough was made possible with the help of collaborator Libby, who discovered an exploit that tricked the chip into accepting oversized settings data. The extraction required repeating the process roughly 1,000 times to capture the full 256KB firmware image. The dumped data covers models from the SCPH-15000 released in 2000 to the 39000-series from 2002, as well as Namco System 246 and 256 arcade boards. Prior attempts over four years relied on slower chip decapping methods that only yielded rough results.
The SPC970 chip uses mask ROM for code storage and a 1KB EEPROM for configuration data. The spc970-dumper-union group exploited the chip's EEPROM write mechanism by triggering a buffer overflow into RAM, redirecting the write task to copy firmware from ROM into EEPROM. While effective, this method risks damaging the chip due to limited EEPROM write cycles, though safeguards like pre-dump backups help mitigate the danger.
These firmware images represent the last unread component of the PS2 ecosystem, following the 2021 dump of the later Dragon Mecha Con. While the dumps don't enable new optical drive emulation, they expose the code behind Sony's Magic Gate encryption for memory cards and KELF executables, potentially advancing full-system low-level emulation efforts in projects like PCSX2.
Source: Engadget · Summarized by HeadlinesBriefing