PSP3D Left Header
PSP3D Header Right
PSP3D Logo CraveOnline Logo
Help the PSP 3D community grow!
Vote for us below:


Vote on the PSP Top 200
PSP Top 200 - Games, Videos, Wallpapers, Files, Hacks, Homebrew

Homebrew/Hacking - Discuss the latest available homebrew applications and games.

Welcome to PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums!

You are currently viewing our website as a guest, which gives you limited access to reply and interact to discussions and other members. By joining our free community, you will be able to post topics in the forums, communicate privately with other members, vote in polls, and access many other special features.

Registration is fast, simple, and absolutely free so join our community today!

Go Back PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums > PSP Forums > Homebrew/Hacking

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-09-2005, 04:00 AM
lucas224 lucas224 is offline
Junior Member
 
Join Date: Nov 2005
Posts: 13
Points: 4.08
Donate
Dont know but may help hackers

http://www.psp-hacks.com/forums/viewtopic.php?t=12526

this was done by PSP250 frotm page thats on top

I tried to summerize what I gathered from various sites about the status on 2.0+ FW hacks.

Looking forward to CONSTRUCTIVE comments.

This info is listed here in order to possible make some progress and share what people know.


Latest Status:

FW 2.00 - TIFF Exploit / Downgrader
available / Limited homebrew
FW 2.01 - GTA Savegame exploit / No downgrader / No homebrew
FW 2.50 - GTA Savegame exploit / No downgrader / No homebrew
FW 2.60 - No exploit / No downgrader / No homebrew


Found Vulnerabilities:

- Browser historyv.dat Heap Overflow (2.0-2.5)
- libungif memory write access (2.0-2.5)
http://www.sukimashita.com/temp/bad-24.gif
(Immediate crash due to segfault)
http://www.sukimashita.com/temp/bad-17.gif
(Same technique but different memory location overwritten, watch thumb with corrupt pixels after reboot)

- GTA savegame buffer overflow (2.0-2.5)
- Wipeout savegame buffer overflow (2.0-?)


Approaches:

- Run code using buffer overflow
- Sign/encrypt homebrew app and make the psp run it
(- Alter 1.50 FW to be pseudo 2.51 update and run it; does not work, encryption problem and 2nd version check within psar)
DISCARDED - Find privat encryption key for signing homebrew (takes too long)


Buffer Overflow

Some flaw in the code enables injection of code in order to execute bytecode.

Possible Weakness List 2.5 FW:

SAFE = Not vulnerable/No known exploit
???? = Untested on 2.5 FW
VULN = Vulnerable

SAFE - Bookmark File, String lengths in Attributes / URIs
VULN - Browser History Files
???? - LIBMPEG PSMF, libmpeg/PMF exploits (custom sony lib)
???? - Video Play, use wrong picture/frame info/size in videos to cause an overflow
SAFE - zlib 1.2.3, http://www.zlib.org/
SAFE - libpng version 1.2.8, http://www.libpng.org/
SAFE - Netfront Browser uses libpng 1.2.6
SAFE - libtiff
???? - Abuse proc:// scheme
VULN - libungif
???? - Wipeout "Ghost" Savegame Exploit
VULN - GTA Savegame Buffer Overflow
???? - MP4 Video Overflow (Since now only reported to work on 2.0 FW max)

... your ideas?


Features to research for possible flaws:

- Pictures: Overflow in Image routines (TIFF, PNG, GIF, BMP, JPG, ...)
- Music: Overflow in Audio routines (MP3, AT3, WAV, ...)
- Movie: Overflow in Movie routines (MP4, ...)
- Game: Run unsigned code/modify signed code to cause overflow/modify updaters
- Game-Sharing Feature
- Netfront Browser: Find exploit within browser
- Savegames: Find exploit in savegame loading routines
- LocationFree System

Last edited by PSP250 on Wed Nov 30, 2005 2:37 pm; edited 13 times in total

Last edited by lucas224 : 12-09-2005 at 04:04 AM.
Reply With Quote
  #2 (permalink)  
Old 12-19-2005, 11:01 PM
psphack4life's Avatar
psphack4life psphack4life is offline
Senior Member
 
Join Date: Dec 2005
Location: LIVE &DIED IN LA
Posts: 442
Points: 1.19
Donate
one of those ideas may help but most are not going to due too the .tiff being patched on mst apps
__________________

Reply With Quote
  #3 (permalink)  
Old 12-19-2005, 11:02 PM
psphack4life's Avatar
psphack4life psphack4life is offline
Senior Member
 
Join Date: Dec 2005
Location: LIVE &DIED IN LA
Posts: 442
Points: 1.19
Donate
that browser one sounds reasonable in pictures it brickes the psp savedata has already bene done but you may be on to something
__________________

Reply With Quote
  #4 (permalink)  
Old 12-19-2005, 11:03 PM
psphack4life's Avatar
psphack4life psphack4life is offline
Senior Member
 
Join Date: Dec 2005
Location: LIVE &DIED IN LA
Posts: 442
Points: 1.19
Donate
im a member not a junior no more wooooohoooo
__________________

Reply With Quote
  #5 (permalink)  
Old 12-19-2005, 11:04 PM
psphack4life's Avatar
psphack4life psphack4life is offline
Senior Member
 
Join Date: Dec 2005
Location: LIVE &DIED IN LA
Posts: 442
Points: 1.19
Donate
i will try t o pull something out of one of your ideas and make us both be responsable for the great hack downgrade if i get it working thanx so much
__________________

Reply With Quote
  #6 (permalink)  
Old 12-19-2005, 11:30 PM
Birdman1's Avatar
Birdman1 Birdman1 is offline
Stankin'-Ass Vagina
My Mood:
 
Join Date: Dec 2005
Location: THE O.C.
Posts: 3,437
Points: 4,922.72
Donate
Send a message via AIM to Birdman1 Send a message via ShopTapNham to Birdman1
four posts in a row. I dont care but the Moderators might ban you for a while for spaming. use the edit button if you want to add another idea and there are no new posts.
Reply With Quote
  #7 (permalink)  
Old 12-19-2005, 11:55 PM
antonio_424's Avatar
antonio_424 antonio_424 is offline
Senior Member
 
Join Date: Dec 2005
Age: 20
Posts: 775
Points: 2.37
Donate
Isn't the savegame exploit also in version 2.6?
Reply With Quote
Reply

« Psp oss out on the 23th of dec :) | Humble newbee looking for advice »



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Points Per Thread View: 0.00
Points Per Thread: 1.00
Points Per Reply: 0.10





Crave Partner Sites: CraveOnline.com | DVDFile.com | PSP3D.com | ComingSoon.net | SuperHeroHype.com | RedBalcony.com | ActionTrip.com | CraveLyrics.com
Soundtrack.net | CraveFix.com | SpikedHumor.com | RPGamer.com | TattooNow.com | ImpactWrestling.com | SeekLyrics.com | PedalBMX.com | WildKO.com
vidKing.com | StrategyInformer.com | HHdb.com | RapLeagues.com | HipHop-Lyrics.com | Cravecocktails.com | ThePhatPhree.com | RideJudge.com | HottieSpots.com

ShopTapNham Shop Online Powered by Custom vB Version 5.1.0 for Crave Online Media, LLC.
Copyright © 2000 - 2007, Jelsoft Enterprises Ltd. and PSP3D.com.
LinkBacks Enabled by vBSEO 3.0.0 RC8

All times are GMT -4. The time now is 06:01 PM.
ShopTapNham Footer Right