Welcome to PSP3D.com - Sony PlayStation Portable News, Homebrew, Hacks, Reviews, Videos, Mods, Forums!
You are currently viewing our website as a guest, which gives you limited access to reply and interact to discussions and other members. By joining our free community, you will be able to post topics in the forums, communicate privately with other members, vote in polls, and access many other special features.
We have big news for everyone, a new exploit has been found AND it works on the PSP-3000! Yes, you read correctly, it works on the PSP-3000. A coder by the name of MaTiAz, and with the help of FreePlay (our own Michael M.) found this exploit that is exicuted through the game GripShift. The exploit works very similarly to the GTA exploit(s) and the Lumines exploit.
MaTiAz had this to say about the exploit:
Quote:
GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite $ra. The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running). The return address is located at offset 0xA9 in the file. In this poc it points to 0×08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.
It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn’t [be bothered to] get Shine’s savegame tool working so it’s in plaintext form) is in the SDDATA.BIN form which Hellcat’s Savegame-Deemer produces (thanks to him, if the program didn’t exist I wouldn’t have bothered with this). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don’t forget to have Savegame-Deemer working, duh.
This is huge news so expect more updates to follow and of course homebrew on the PSP-3000 in the near future.
In modern musical parlance, a hemiola is a metrical pattern in which two bars in simple triple time (3/2 or 3/4 for example) are articulated as if they were three bars in simple duple time (2/2 or 2/4).