PSP3D Left Header
PSP3D Header Right
PSP3D Logo CraveOnline Logo
Help the PSP 3D community grow!
Vote for us below:


Vote on the PSP Top 200
PSP Top 200 - Games, Videos, Wallpapers, Files, Hacks, Homebrew

Homebrew/Hacking - Discuss the latest available homebrew applications and games.

Welcome to PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums!

You are currently viewing our website as a guest, which gives you limited access to reply and interact to discussions and other members. By joining our free community, you will be able to post topics in the forums, communicate privately with other members, vote in polls, and access many other special features.

Registration is fast, simple, and absolutely free so join our community today!

Go Back PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums > PSP Forums > Homebrew/Hacking

Closed Thread
 
LinkBack Thread Tools Display Modes
  #21 (permalink)  
Old 04-24-2006, 04:43 PM
supa_sick's Avatar
supa_sick supa_sick is offline
Senior Member
 
Join Date: Nov 2005
Location: IN MY PSP
Age: 23
Posts: 487
Points: 1.20
Donate
theres an exploit in macromedia flash player 6
read about it here http://news.zdnet.com/2100-1009_22-898517.html
or just read it here

An exploit has been discovered in Macromedia's Flash player that could let hackers execute malicious code on a user's computer.

According to Macromedia, more than 436 million copies of the Flash player have been downloaded from its site, accounting for 98 percent of Web users.

The exploit appears to have been independently discovered by Macromedia, which has already issued a fixed version of the Flash player, and by security software firm eEye Digital Security, which was credited last year with discovering and naming the Code Red virus.

Marc Maiffret, chief hacking officer at eEye, attributed the Macromedia Flash flaw to a buffer overflow vulnerability connected to an ActiveX control called Flash.ocx. "This attack can be performed via some HTML email clients, as well as when visitors visit malicious Web sites," he said.

EEye said it had confirmed the vulnerability in Flash Version 6, revision 23 which, it said, would "include most installations on Windows". Older versions of Flash could be affected, said eEye, and while the company admitted it had not tested them, it said that people who have an older version of Flash that is not affected may be forced to "upgrade" to the affected version because the OCX is signed by Macromedia.

EEye said it alerted Macromedia on Wednesday, and was told that Macromedia had just released a new revision. "We tried the link they gave us and it did indeed fix the problem," said eEye.

Flash Version 6, revision 29 can be downloaded from here.

EEye said it decided to make the vulnerability public because the signed OCX control has been downloaded "by an untold number of people, and potentially could still be used in an exploit scenario against those without the latest OCX". Furthermore, said eEye, this issue was found in the wild, "and it is not safe to assume it could not be found by others with malicious intent. Nor do we believe it is safe to assume this has not been found by users with malicious intent."

Troy Evans, product manager for Flash player, said the vulnerability only exists in Flash 6, revision 23, and does not affect previous versions of Flash. Revision 23 of the player is the first publicly available version of Flash 6, and was posted for download on Macromedia's site a month ago amid a flurry of publicity.

"The latest studies show we have a 3.3 percent penetration with this player," said Evans. "We have updated the deployment, and people are being redirected to revision 29," he said.

Evans said he had not heard of any reports of the exploit affecting users. "We have been working with eEye, but we did discover this ourselves." Macromedia had no issue with eEye publicising the vulnerability, said Evans. "The general public should be aware of issues that could affect them."

This is not the first security scare with Macromedia Flash. In January, antivirus companies warned PC users that future Macromedia Flash movies could carry malicious viruses and worms after an unknown virus writer sent just such an infectious program to UK antivirus company Sophos. Dubbed SWF/LFM-926, the program did little but infect Flash files on a PC when the movie is played.



The vulnerable code exists in Flash.ocx, which embodies the code
responsible for playing back SWF files. One function maintains a large,
256-element table of function pointers on the stack, and uses a frame
type identifier read from the SWF file as an index into the array,
without enforcing the array boundaries. The following disassembly
depicts the affected code:

.text:1002714F mov eax, [esi+0CA4h] ; type number
.text:10027155 mov ecx, [esi+94h] ; base of table
.text:1002715B lea eax, [ecx+eax*8] ; get element address
.text:1002715E mov ecx, [eax] ;

Although the index is not validated, its value is elsewhere restricted
to be at most 0x8000, so the attacker can cause a function pointer to be
retrieved from memory up to roughly 64KB after the base of the table on
the stack. Typically this range will include heap memory, so by
planting specific data on the heap, the attacker can very easily control
the exact value of the function pointer. Reliable exploitation using
this technique within Internet Explorer has been demonstrated by eEye
Digital Security.

Protection:
Retina Network Security Scanner has been updated to identify this
vulnerability.
Blink - Endpoint Vulnerability Prevention - protects from this
vulnerability.


tools that may come in handy to make a hack for psp flashplayer 6

http://www.gold-software.com/DreamFl...-file5708.html
http://www.tomdownload.com/multimedi..._converter.htm


oh yeah be nice to MATTE
  #22 (permalink)  
Old 04-24-2006, 04:45 PM
Kyubi_Naruto's Avatar
Kyubi_Naruto Kyubi_Naruto is offline
Senior Member
 
Join Date: Apr 2006
Location: Portugal
Posts: 558
Points: 2.13
Donate
that's one heck of a post... good work supa...
__________________
THe Following signature is being brought to you in part by yur friends from D-Generation X, that would like to remind you that if you're not down with that, me at PSP3D only got TWO WORDS FOR YA:

S*CK IT!

  #23 (permalink)  
Old 04-24-2006, 04:48 PM
Pspman3 Pspman3 is offline
Senior Member
 
Join Date: Dec 2005
Location: Im so crazy, I live in a stright jacaket
Age: 14
Posts: 251
Points: 43.31
Donate
thanks suppa , o guess what my grandma's friend gave me a computer that she didnt want i thought it was gonna be a junker but i got home and oppened it up to my supprize it was a Gateway profile 5.5C with 2.8Ghz a 160 Gig HDD and a 17' LCD its gonna be my DEV Computer not bad for a freebie
__________________



PSP UPDATE HISTORY: 1.51-2.0-1.5-2.6-2.7-2.71-1.5-hargley's custom FW-2.71A-2.71B-2.71B'-2.71B"-2.71C-3.0 SE *BRICK*-1.5-2.71-HEND-HENC-2.71C-3.0SE-1.5
  #24 (permalink)  
Old 04-24-2006, 04:51 PM
korhalf's Avatar
korhalf korhalf is offline
Senior Member
 
Join Date: Jan 2006
Posts: 220
Points: 1.55
Donate
Send a message via AIM to korhalf
Hahahahah Pspman, and you're 11 years old...
__________________



  #25 (permalink)  
Old 04-24-2006, 04:52 PM
Pspman3 Pspman3 is offline
Senior Member
 
Join Date: Dec 2005
Location: Im so crazy, I live in a stright jacaket
Age: 14
Posts: 251
Points: 43.31
Donate
Quote:
Originally Posted by korhalf
Hahahahah Pspman, and you're 11 years old...
yup and i live in the most unkown state Delaware
__________________



PSP UPDATE HISTORY: 1.51-2.0-1.5-2.6-2.7-2.71-1.5-hargley's custom FW-2.71A-2.71B-2.71B'-2.71B"-2.71C-3.0 SE *BRICK*-1.5-2.71-HEND-HENC-2.71C-3.0SE-1.5
  #26 (permalink)  
Old 04-24-2006, 05:16 PM
theoutlaw55 theoutlaw55 is offline
Junior Member
 
Join Date: Apr 2006
Posts: 14
Points: 0.00
Donate
Sorry to bust you guy's bubble...but that exploit is listed as being discovered in 2002! I'm sure Sony didn't f*** up and use a old ass exploited flash player...
  #27 (permalink)  
Old 04-24-2006, 05:19 PM
chriscooke109's Avatar
chriscooke109 chriscooke109 is offline
Master-Bator
 
Join Date: Jan 2006
Location: England
Age: 18
Posts: 957
Points: 16.97
Donate
This is just speculation and just because that exploit might not be there it doesn't mean that others might not creep up in the new flash player.
__________________
  #28 (permalink)  
Old 04-24-2006, 05:19 PM
theoutlaw55 theoutlaw55 is offline
Junior Member
 
Join Date: Apr 2006
Posts: 14
Points: 0.00
Donate
This might prove to be more useful if you can figure out what the exploit is ;p!

http://www.macromedia.com/devnet/sec...apsb06-03.html
  #29 (permalink)  
Old 04-24-2006, 05:19 PM
Pspman3 Pspman3 is offline
Senior Member
 
Join Date: Dec 2005
Location: Im so crazy, I live in a stright jacaket
Age: 14
Posts: 251
Points: 43.31
Donate
well the newest flash version is 8.26 Sony says theyre gonna put 6.0 in the PSP
__________________



PSP UPDATE HISTORY: 1.51-2.0-1.5-2.6-2.7-2.71-1.5-hargley's custom FW-2.71A-2.71B-2.71B'-2.71B"-2.71C-3.0 SE *BRICK*-1.5-2.71-HEND-HENC-2.71C-3.0SE-1.5
  #30 (permalink)  
Old 04-24-2006, 05:22 PM
theoutlaw55 theoutlaw55 is offline
Junior Member
 
Join Date: Apr 2006
Posts: 14
Points: 0.00
Donate
Quote:
Originally Posted by Pspman3
well the newest flash version is 8.26 Sony says theyre gonna put 6.0 in the PSP
Just because they are using a older "version" of flash, doesn't mean it's exploited the same way. I'm sure there will be chances for a exploit with these new features (has anyone tried overflowing the RSS feed yet?), but i'm sure they have a PATCHED version of Flash 6 on it.
Closed Thread

« another stupid noob idea?? | msn exploit using png »



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Points Per Thread View: 0.00
Points Per Thread: 1.00
Points Per Reply: 0.10

Similar Threads
Thread Thread Starter Forum Replies Last Post
Brainstorm some overflow ideas vinny1684 Homebrew/Hacking 18 03-23-2006 12:38 AM
whats "LibTIFF TIFFOpen Buffer Overflow Vulnerability" HappySlapster Homebrew/Hacking 5 02-22-2006 08:09 AM
Thought on Tiff overflow on 2.01-2.5-2.6 shanemac Homebrew/Hacking 12 01-20-2006 10:32 AM
Supposed 2.50 TIF Overflow EBOOT hbarroso Homebrew/Hacking 16 01-06-2006 06:52 PM
Dont know but may help hackers lucas224 Homebrew/Hacking 6 12-19-2005 11:55 PM





Crave Partner Sites: CraveOnline.com | DVDFile.com | PSP3D.com | ComingSoon.net | SuperHeroHype.com | RedBalcony.com | ActionTrip.com | CraveLyrics.com
Soundtrack.net | CraveFix.com | SpikedHumor.com | RPGamer.com | TattooNow.com | ImpactWrestling.com | SeekLyrics.com | PedalBMX.com | WildKO.com
vidKing.com | StrategyInformer.com | HHdb.com | RapLeagues.com | HipHop-Lyrics.com | Cravecocktails.com | ThePhatPhree.com | RideJudge.com | HottieSpots.com

ShopTapNham Shop Online Powered by Custom vB Version 5.1.0 for Crave Online Media, LLC.
Copyright © 2000 - 2007, Jelsoft Enterprises Ltd. and PSP3D.com.
LinkBacks Enabled by vBSEO 3.0.0 RC8

All times are GMT -4. The time now is 06:30 PM.
ShopTapNham Footer Right