2.0 Exploited


pmb236
 Share

Messages recommandés

We just received a very convincing email claiming to have hacked the 2.0 firmware. We do not currently have a 2.0 PSP accessible right now. So we would like our members to try it out and let us know how it goes. We’ve been hearing rants for a while about no 2.0 news so here is a chance to not just complain but actually help out and let us know if it works.

    First Homebrew Code on 2.00

    —————————–

    1. Set wallpaper to frame_buffer.png (without overflow.tif present

    in the PHOTO directory, or it will crash).

    2. Add overflow.tif to the PHOTO directory, and open into the photo

    viewer. Custom code to paint the screen! Or to write a homebrew

    app! Not to run illegal games.

    How It Works?

    —————

    1. The PNG contains a small amount of code in a known, fixed place

    (the VRAM). If to look closely at the wallpaper, sees small

    coloured pixels in the right down. The pixels are Allegrex

    opcodes, with the highest byte all zero for the ALPHA. These

    pixels do:

    syscall 0×20C7 ; sceKernelDcacheWritebackInvalidateAll

    slt a0, zero, sp ; put 1 into a0

    sll a0, a0, 6 ; put 64 into a0

    addiu a0, sp, a0 ; get screen painter address over SP

    jr a0 ; jump to the screen painter

    nop ; branch delay slot

    2. The TIFF contains also some code and a buffer to trigger the

    known BitsPerSample overflow in libtiff in the photo viewer.

    The buffer makes a jump to the VRAM which has the PNG colours

    by overwriting the safed ra (return address) on the stack.

    The VRAM code uses SP and calculates the address of the buffer

    then runs it. Then it jumps there. The screen is yellow as

    the colour was 0×12345678 in Hex.

    PSP Users:

    We didn’t do this so you could steal from Sony and game companies.

    We believe in OSS. There are plenty of amazing programs that have

    been written for the PSP. Use this as a gift and not as an excuse

    to steal.

    Sony:

    If you wanted to find us i know you could. This release wasn’t

    intended as a way to run pirated software on the PSP. We believe

    that everyone should be able to compile their own code and run it.

    Nothing is kept secret forever and i’m sure you know this.

    In the end, if it wasn’t us. It would be some one else.

    Fighting it would be like skating up a hill. You did create the

    PSP and did an amazing job.

    Toc2rta:

    To the people of the Toc2rta development network. You’re our phone

    a friend. With out your friendship this would never of happened.

    I hope this brings you as much happiness as it brings us.

    Join us on irc.toc2rta.com.

    Most importantly… Have fun!

Download required files

Source: Psp-hack.com

MAJ:

Update: This proof of concept has now been confirmed as a working exploit for the 2.0 firmware. Now we have to wait until some more useful code using this exploit is released :) Remember who had it first PSP-Hacks.com
Modifié par pmb236
Lien vers le commentaire
Partager sur d'autres sites

  • Réponses 486
  • Created
  • Dernière réponse

Top Posters In This Topic

tu devrait quand meme attendre oliv28, met pas la charut avant les boeufs !

Oui mais pour le coup il a raison ... il n'y a plus gd chose qui devrait bloquer là ...

la console, plante ou rebbot chez moi blink.gif

Normal, pour le moment il montre juste qu'il y a une faille .... et te le prouve ... c tout

Lien vers le commentaire
Partager sur d'autres sites

mouais je ne suis pas convaincu par cette methode mais bon, les resultats a venirs sont a observer.

d un autre coté utiliser une image pour cracker le firmware ca sent le foutage de tronche a plein nez, mais bon ...

512493[/snapback]

Non non c'est une technique assez fréquente en hack (enfin du moins le peu que j'en connaise, les format images sont beaucoup utiliser)

Lien vers le commentaire
Partager sur d'autres sites

bon ba j ai mis ma console a jour...Je pense que c etais 1 ellan de curiosité....

:P

512510[/snapback]

Ta bien fait parce que la 1.52 sert vraiment à rien, moi en attendant que la v2 soit hacker je faisait mumuse avec le naviagateur :D

Normal la v1.52 ne gère pas autant de format que la v2 ;)

Lien vers le commentaire
Partager sur d'autres sites

Créer un compte ou se connecter pour commenter

Vous devez être membre afin de pouvoir déposer un commentaire

Créer un compte

Créez un compte sur notre communauté. C’est facile !

Créer un nouveau compte

Se connecter

Vous avez déjà un compte ? Connectez-vous ici.

Connectez-vous maintenant
 Share

Annonces