Help the PSP 3D community grow! Vote for us below:


| | Homebrew/Hacking - Discuss the latest available homebrew applications and games. |
Welcome to PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums!
You are currently viewing our website as a guest, which gives you limited access to reply and interact to discussions and other members. By joining our free community, you will be able to post topics in the forums, communicate privately with other members, vote in polls, and access many other special features.
Registration is fast, simple, and absolutely free so join our community today!
| 
04-23-2006, 03:05 PM
| | Senior Member | | Join Date: Nov 2005
Posts: 391
Points: 40.20 Donate | | | people like freeplay are why i keep coming back to psp3d | 
04-23-2006, 03:14 PM
| | Jesus is in the building
My Mood: | | Join Date: Nov 2005 Location: Carle Place..yea its 1 sq mile but so what!!! Age: 19
Posts: 1,072
Points: 13.56 Donate | | Quote: |
Originally Posted by FreePlay Fanjita,
I sort of doubt that you'll read this thread again (since you're of the opinion that it's not going to help), but I've got a question for you. In the scePaf module, there are a number of functions related to PNG images:True, most of these seem just like libpng functions, and are of little use to us. However, the sce_png_read function could (as unlikely as it is) have something vulnerable in it. I've tried disassembling the paf.prx and pafmini.prx files using Skylark's disassembler, but the end result is about 80MB of HTML that makes my browser choke and die.
So I guess I'm thinking that the only way anything useful could come of this is if Sony is using a modified libpng source. Given that, they'd still have to goof up the code and make it vulnerable to a buffer overflow or similar exploit.
I'm still interested in hacking away at this; if nothing else, then for the satisfaction of knowing that I can. I'm not really sure what to look for, but I've been reading up on a few types of exploits to try to get a better understanding of them. Especially helpful was Aleph One's article "Smashing the Stack for Fun and Profit" from Phrack.
If you've any more input to give, great. If not, also OK. | If we put a bit of code in the PNG's IHDR tag, couldn't we then use the png_get_IHDR function to execute it? | 
04-23-2006, 03:36 PM
| | | | Ok, like fanjita said, it seems to be read, the problem everyone is ignoring is, how to load the PNG into ram to be read in the fist place. If there is a PNG that has a exploit in it, wouldn't the exploit work just in the picture viewer in the sony shell? Or if it was blocked how would you load it to the ram to begin with. If that is the case then this "glitch" is USELESS...
I haven't used the e-Loader yet, but does it let you return to the sony shell to exit (or do you have to shut off the PSP). I assume you can, so if that is the case, if there is a version taht was modified to not dump stuff from ram, maybe you could load a exploited PNG (that might be blocked in the picture viewer) into ram, then use this "glitch" to load the picture from ram and it should (theoretically) run the code. If that were the case it would still require GTA to run it, but if you can get code in the shell to work, then it should be full mode and would probablly have more of a chance of accessing FLASH0 than any other method I can think of...just some thoughts. | 
04-23-2006, 03:40 PM
| | Jesus is in the building
My Mood: | | Join Date: Nov 2005 Location: Carle Place..yea its 1 sq mile but so what!!! Age: 19
Posts: 1,072
Points: 13.56 Donate | | | Forget accessing Flash0 for now....what we want to the ability to execute any type of code through this.
And the backgrounds and icons in an EBOOT ARE loaded into the RAM after youve seen them once. | 
04-23-2006, 03:41 PM
| | Senior Member | | Join Date: Apr 2006 Location: Portugal
Posts: 558
Points: 2.12 Donate | | | i dk who you are... but u just made a pretty high assumption... if that works, u MAY have solved in one post what others haven't been able to solve for months :S:S
edit: but that's a thing for another topic...
__________________ THe Following signature is being brought to you in part by yur friends from D-Generation X, that would like to remind you that if you're not down with that, me at PSP3D only got TWO WORDS FOR YA:
S*CK IT!  | 
04-23-2006, 03:49 PM
| | Senior Member | | Join Date: Dec 2005 Location: Glendale,California Age: 18
Posts: 237
Points: 0.24 Donate | | | FreePlay why dont you guys work with SonyXTeam there workin on a DG as well if you all work together maybe something good will come from this. | 
04-23-2006, 03:55 PM
| | Senior Member
My Mood: | | Join Date: Jan 2006 Location: Detroit
Posts: 178
Points: 4.29 Donate | | | does anybody know exactly what is restricting us from access to flash0, i know its the security checks, but is anyone even working on this right now? | 
04-23-2006, 03:57 PM
| | Senior Member | | Join Date: Mar 2006 Location: in da flash0 (MEX.)
Posts: 135
Points: 0.11 Donate | | | But anyway, run code is easier than getting access to flash0. A full mode or kernel and all of that seems to be more difficult. Maybe only we could have an eLoader without GTA and in USER mode.
__________________ +METAL UP YOUR ASS+
MeXiCaN PRiDE! 
+EET FUK+
+GIBSON X-PLORER PROUD OWNER+
1.52 > 2.50 > 2.60 > 1.50 
PSPMex member  | 
04-23-2006, 03:58 PM
| | | Quote: |
Originally Posted by HighlyIntense does anybody know exactly what is restricting us from access to flash0, i know its the security checks, but is anyone even working on this right now? | Getting code working outside of "usermode". The reason we cannot yet is because the only method to run code on a 2.01+ PSP is with the GTA gamesave hack, and once you load a game the PSP goes into "usermode" meaning you can't writer to flash0, so that is mainly the issue right now, that it is blocked off COMPLETELY, as for getting code to workk with this, the idea I said was just to see if code would work, not saying it will access FLASH0 at all, but getting the png to ram so it has a CHANCE to run is a better lead than anything that is going on with this thread at the moment... | 
04-23-2006, 04:00 PM
| | Senior Member | | Join Date: Apr 2006 Location: Portugal
Posts: 558
Points: 2.12 Donate | | | outlaw, i started a thread with ur theory... maybe you would care to defend it... just thought u'd wanna know...
__________________ THe Following signature is being brought to you in part by yur friends from D-Generation X, that would like to remind you that if you're not down with that, me at PSP3D only got TWO WORDS FOR YA:
S*CK IT!  | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off Points Per Thread View: 0.00 Points Per Thread: 1.00 Points Per Reply: 0.10 | | | | |