PSP3D Left Header
PSP3D Header Right
PSP3D Logo CraveOnline Logo
Help the PSP 3D community grow!
Vote for us below:


Vote on the PSP Top 200
PSP Top 200 - Games, Videos, Wallpapers, Files, Hacks, Homebrew

Homebrew/Hacking - Discuss the latest available homebrew applications and games.

Welcome to PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums!

You are currently viewing our website as a guest, which gives you limited access to reply and interact to discussions and other members. By joining our free community, you will be able to post topics in the forums, communicate privately with other members, vote in polls, and access many other special features.

Registration is fast, simple, and absolutely free so join our community today!

Go Back PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums > PSP Forums > Homebrew/Hacking

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-01-2006, 08:39 AM
6nikola9 6nikola9 is offline
Member
 
Join Date: Apr 2006
Posts: 48
Points: 0.29
Donate
maybe another tiff overflow in the 2.01+ firmwares

have a look at this site http://www.frsirt.com/english/advisories/2006/1563 this exploit was released only some day ago!!!!!!


EDIT: here you can download all the tiff exploit i found and tested!!

Files in the rar archive are files that freezes psp or shows an image, those are 3 files. There are other 2 files wich appears as corrupted data.
NULL deref in PredictorVSetField() freeze
NULL deref in Fax3VSetField() freeze
NULL deref via TIFFError() by TIFFFetchAnyArray() ? doesn't freeze (corrupted data)
buffer overflow via TIFFFetchData() and memcpy() ? doesn't freeze (corrupted data)
double free() in setByteArray()? shows an image but doesn't freeze

i've updated the archive putting other 2 files that psp doesn't read...now in the archive there are all files that i discovered and downloaded by the exploits site
__________________________________________________ _____

other 2 files tiff that freeze psp
links and files attached
http://www.security-protocols.com/sp-x29-advisory.php
http://www.security-protocols.com/sp-x30-advisory.php

__________________________________________________ __

Maybe now a really strange gif....
http://www.security-protocols.com/sp-x28-advisory.php
"Overview:
A heap overflow vulnerability exists when processing .gif files which causes the application to crash, and or may allow for an attacker to execute arbitrary code on the targted host.
Technical Details:
When decompressing a specially crafted .gif file, the CFAllocatorAllocate () function incorrectly parses the malformed data and causes the application to segmentation fault."

The gif in my psp system show as a looping preview loading...when i open the file psp tells me this "showing image impossible (00000001)"
Attached Files
File Type: rar sp-x29.rar (31.0 KB, 30 views)
File Type: rar sp-x30.rar (31.1 KB, 25 views)
File Type: rar 2.01+ OVERFLOW FILES TIFF.rar (1.6 KB, 71 views)
File Type: rar sp-x28-GIF.rar (41.4 KB, 38 views)

Last edited by 6nikola9 : 05-02-2006 at 12:26 PM.
Reply With Quote
  #2 (permalink)  
Old 05-01-2006, 08:52 AM
BigMessFHS's Avatar
BigMessFHS BigMessFHS is offline
Senior Member
 
Join Date: Mar 2006
Location: Dirty D
Posts: 192
Points: 1.84
Donate
Intresting, but dosent this still require you put a tiff image on your psp. We all know that its been patched up for 2.01+.
__________________




1.5 Owner
Reply With Quote
  #3 (permalink)  
Old 05-01-2006, 08:53 AM
6nikola9 6nikola9 is offline
Member
 
Join Date: Apr 2006
Posts: 48
Points: 0.29
Donate
i tried the overflow tiff and this shout down the psp.....it's very very very interesting guys....i'll post the link!!!
Reply With Quote
  #4 (permalink)  
Old 05-01-2006, 08:54 AM
BigMessFHS's Avatar
BigMessFHS BigMessFHS is offline
Senior Member
 
Join Date: Mar 2006
Location: Dirty D
Posts: 192
Points: 1.84
Donate
Quote:
Originally Posted by 6nikola9
i tried the overflow tiff and this shout down the psp.....it's very very very interesting guys....i'll post the link!!!
What fw do you have?
__________________




1.5 Owner
Reply With Quote
  #5 (permalink)  
Old 05-01-2006, 08:56 AM
6nikola9 6nikola9 is offline
Member
 
Join Date: Apr 2006
Posts: 48
Points: 0.29
Donate
i've japanese psp with 2.01 firmware installed on it
Reply With Quote
  #6 (permalink)  
Old 05-01-2006, 08:58 AM
6nikola9 6nikola9 is offline
Member
 
Join Date: Apr 2006
Posts: 48
Points: 0.29
Donate
http://bugzilla.remotesensing.org/show_bug.cgi?id=1102 here you can download tiff bugs

i'm not a faker, it's the true....download that files

Wow, blackbird I think your comment is a little to short to have made a new thread.......
Reply With Quote
  #7 (permalink)  
Old 05-01-2006, 09:04 AM
6nikola9 6nikola9 is offline
Member
 
Join Date: Apr 2006
Posts: 48
Points: 0.29
Donate
at this point i could not stay so secure
Reply With Quote
  #8 (permalink)  
Old 05-01-2006, 09:06 AM
Homer's Avatar
Homer Homer is offline
Moderator...
 
Join Date: Dec 2005
Location: Sweden
Age: 19
Posts: 553
Points: 1.44
Donate
Send a message via ShopTapNham to Homer
Quote:
Originally Posted by BigMessFHS
I never said you were a faker but, like I said before no downgrade for 2.01+ will come in the form of a .tiff overflow. Sony has dug the hole, buried the coffin, and racked the dirt over the .tiff bugs for 2.01+.
Not true, a downgrader won't come from the 2.0 tiff exploit. But, if we find another exploit it's possible.
__________________
Reply With Quote
  #9 (permalink)  
Old 05-01-2006, 09:08 AM
bobsickal bobsickal is offline
Junior Member
 
Join Date: Jan 2006
Posts: 9
Points: 0.00
Donate
I tried putting one of the Tiffs from the bugzilla link on the previous page into the photo folder and it does crash n shut down the PSP but it doesn't allow u to scroll down to the photo or view it it crashes as soon as u go into photo menu
__________________

Black PSP Giga Pack 2.50 ... Happy but gutted
Reply With Quote
  #10 (permalink)  
Old 05-01-2006, 09:11 AM
6nikola9 6nikola9 is offline
Member
 
Join Date: Apr 2006
Posts: 48
Points: 0.29
Donate
it crashes the psp as the 2.00 does..the image.tiff in 2.00 doesn't showed
Reply With Quote
Reply

« flashmod iso | 2.71 eboot! »



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Points Per Thread View: 0.00
Points Per Thread: 1.00
Points Per Reply: 0.10

Similar Threads
Thread Thread Starter Forum Replies Last Post
Brainstorm some overflow ideas vinny1684 Homebrew/Hacking 18 03-23-2006 12:38 AM
Thought on Tiff overflow on 2.01-2.5-2.6 shanemac Homebrew/Hacking 12 01-20-2006 10:32 AM
Speculated TIFF Overflow for 2.01+ TomFromVienna Homebrew/Hacking 5 01-07-2006 10:02 AM
DOWNGRADE 2.xx 1.5 VIDEO INSIDE quetzal Homebrew/Hacking 296 01-05-2006 10:47 PM
FW 2.01 Downgrader, possible? Venix Homebrew/Hacking 30 12-29-2005 04:34 PM





Crave Partner Sites: CraveOnline.com | DVDFile.com | PSP3D.com | ComingSoon.net | SuperHeroHype.com | RedBalcony.com | ActionTrip.com | CraveLyrics.com
Soundtrack.net | CraveFix.com | SpikedHumor.com | RPGamer.com | TattooNow.com | ImpactWrestling.com | SeekLyrics.com | PedalBMX.com | WildKO.com
vidKing.com | StrategyInformer.com | HHdb.com | RapLeagues.com | HipHop-Lyrics.com | Cravecocktails.com | ThePhatPhree.com | RideJudge.com | HottieSpots.com

ShopTapNham Shop Online Powered by Custom vB Version 5.1.0 for Crave Online Media, LLC.
Copyright © 2000 - 2007, Jelsoft Enterprises Ltd. and PSP3D.com.
LinkBacks Enabled by vBSEO 3.0.0 RC8

All times are GMT -4. The time now is 07:07 PM.
ShopTapNham Footer Right