PDA

View Full Version : PSP 3.0 Brower Exploit?!



fpcreator2000
December 11th, 2006, 20:20
This is something I discovered with a psp equipped firmware 3.00 (I bought the camera to use it with the firmware) I had. I found out that when I visited a website such a en.wikipedia.org and did a search, my PSP would shut down on it's own (not sleep mode).

The PSP would try to load the "Search Results" page, and when the first chunk appeared, that's when the shutdown would occur.

This lead me to believe that there was a memory overflow with the browser, and yes it was corrected by firmware 3.01.

I think the PSP firmware is equipped with what you can call a memory overflow "breaker switch" that shuts the system down when an overflow occurs to prevents exploits from functioning.
The PSP has the TA-86 motherboard.

Unfortunately the PSP in question got wet, and the memory stick access light is stuck on ON. Luckly for insurance, I have a replacement.

I may be wrong, but I believe that this is the so called "security update" Sony had states during update.

splodger15
December 11th, 2006, 20:50
You maybe be correct but coding will have to be done in to this if its true

ExcruciationX
December 11th, 2006, 21:40
I hope this leads to a downgrader.

jonezybaby
December 11th, 2006, 21:43
nicely notice, hopefully sum guys will look in2 this and we get a downgrader or homebrew on higher firmwares!!

dagger89
December 11th, 2006, 22:08
Can you repeat the bug? I get no succcess with your methods... Without it being able to be replicated, its useless...

turtleguy101
December 11th, 2006, 22:53
u have 3.00 with the camara? When you attach the camara do you need any umd in the drive? Or can u just go to camara and take pics?

andrewgabriel77
December 12th, 2006, 04:50
with 3.0 you can take pics without using the Chotto Shot umd...that's one of it's features listed in the Update info...

turtleguy101
December 12th, 2006, 04:51
SWEET! so if i buy the jap camara, it will make no diffrence and it will be in english?

hawke213x
December 12th, 2006, 05:04
Works on 2.82 as well, just tried it.

andrewgabriel77
December 12th, 2006, 05:10
SWEET! so if i buy the jap camara, it will make no diffrence and it will be in english?

No...all of your pics are going to be in Japanese..:rofl:

TacticalBread
December 12th, 2006, 08:01
No...all of your pics are going to be in Japanese..:rofl:

Oh damnit. I might as well wait until the English camera comes out so I can read my pictures properly.

:rofl:

tuta
December 12th, 2006, 15:24
Lol yeah wait for english version but does camera work on devhook 3.01 if not the camera is pretty useless though

and on the topic even though there is an exploit in the browser but how are we going to code one?
html based firmware downgrader?
this thing seems pretty useless.Not putting anyones hope though coz this just dont seem feasible

If tiff exploit cant come up with a downgrader(if I'm not wrong) I dont think this will be the next revolution

potatoman
December 12th, 2006, 21:18
actuall, tiff did get dg, but 2.71 only cause 2.8 didnt have the required kernal access. it depend on the type of overflow, and the security in question.
damn! i dont think i knew what half that meant 3 months ago :eek: , 1 month b4 joining dc emu!

gamerremag
December 12th, 2006, 22:38
seriously wait for the english version, the chotto shot has video editing software (im pretty sure anyway,) but all of that will be in japanesse

turtleguy101
December 13th, 2006, 01:29
How will they be in japanese? I dont want to edit the pictures with language, i just want to take pictures and videos lol for like facebook and stuff... Ive seen the editing software and its gay... takes to long and is worthless...(at least the video editing stuff...) Anyways i just wanna take pics, plug in usb cord and upload them... why would they be in japanese? And the 3.00 firmware is in english, and the camara mode (according to the pictures on the online 3.00 manual) is in english, and ime sure they wern't using a english version camara when they made the pics! Anyways, it has been confirmed that you do NOT need a UMD in the tray when using the camara from 3.00 tho right...?

cha0ticbliss
December 13th, 2006, 03:29
Yeh... you can take pics in english. You just can't edit stuff unless you feel like stumbling through everything in japanese

andrewgabriel77
December 13th, 2006, 03:54
if i was going to be editing pics or vids taken on my psp i'd move them to my pc and use some real software for that job not that crappy chotto schlop

m0th
December 13th, 2006, 05:21
No...all of your pics are going to be in Japanese..:rofl:

So everyone will look japanese too?

::: singing ::: I think Im turning japanese, turning japanese, I really think sooo

fpcreator2000
December 13th, 2006, 08:44
The PSP in question is in a better place (getting refurbished at a factory) due to water damage.

The Jap camera works fine with the US psp, but I think there is a 15 sec limitation (i'm not sure, my mem stick has less that 20mb left out of 1Gig), but I think this was lifted with the new updates.

The overflow was weird. it only occured at the wikipedia site. In the lower versions of the firmware, there was no overload. When I did the upgrade to 3.00 on that psp, that's when it started to self-shutdown (not sleep-mode). The Screen would turn black, and shut down.

Unfortunate for IndianCheese, I understand what you are asking about the hex values of the memory addresses that the leaks might be coming from but
My specialty is web dev, and software dev, not hardware dev. I'm not a low-level programmer, so unfortunately I don't have an answer to your questions.

But so people don't think I'm here to start a rumor mill, I'm just reporting something that I experienced on my former PSP (I have a new one) so there is a possibility of Homebrew on the higher firmwares without the need for Devhook emulation.

(Good work guys, but the risk of bricking my psp is too high for me, this is my 5th PSP.

No.1 Fell and scratched the front facing
No.2 I fell sideways and cracked the LCD, successful replacement but discovered the hardway how flimsy the analog makes contact with the motherboard.

No.3 Water Damage, Extreme Humidity caused a short circuit.

No.4 Water Damage, Fell into a puddle.

For those who own a PSP, BUY THE LOGITECH CLAM SHELL CASE, IT WILL SAVE YOU A LOT OF HEADACHES, IF NOT FOR IT I WOULD BE ON PSP No. 20!).

NOTE: If you remove the rubber from the Logitech clamshell case, a PSP fitted with Metal Gear Solid Portable Ops Case that you receive with a pre order fits in the clamshell. Unfortunately the MGS PO case interferes with the camera.

One more to finish this comment. Tekken Dark Resurrection is a great game except for one thing.
You cannot share game saves, It specifically codes data specifically for your psp. I bought the game when I owned PSP #3, had to restart my game record twice. Sold it after the second time. I have little patience for stuff of that nature.

fpcreator2000
December 13th, 2006, 08:50
Is it me or is everyone going "Domo Arigato, Mr. Roto" on me?!

If you guys don't cut it out, I'm gonna have Gurr sing the Doom song.....

Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom!

(someone tries to interrupt, but Gurr gives him the hand and continues...)

Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom! Doom!

(okay, he's done).

hawke213x
December 13th, 2006, 09:01
In the lower versions of the firmware, there was no overload.

Actually, ftpcreator my PSP is a 2.82 and it did the same thing with wikipedia. If I had a cam Id post a vid just to prove Im telling the truth.

cha0ticbliss
December 13th, 2006, 20:07
Odd.. SE-C also shuts off, however it happens when I search, then press the back button to return to the previous page.

While booting up it flashes white possibly due to the fact that it is some type of breaker switch which turns it off immediately without clearing the pixels to black like it does while shutting down normally.

^I prolly have no clue what I am talking about considering I have no idea how lcd's work

turtleguy101
December 14th, 2006, 02:54
OK yeah not worried about editing pictures... choto shot edit is gay... ALL I DO IS PUT THE CAMARA ON THE TOP (NO NEED FOR UMD IN DRIVE?) AND RUN DEVHOOK FROM MY 1.5 AND EMULATE 3.01. THEN I GO TO PHOTO AND THEN CAMARA AND I CAN TAKE PICS? I dont need a umd and this thing works with devhook ??? ime a confused person....

andrewgabriel77
December 14th, 2006, 03:21
I haven't heard whether the camera function actually works via devhook or not...I do know that it will work on full 3.0+ without having a umd in and regardless of your psp's language

hawke213x
December 15th, 2006, 12:28
Ok back to what this thread is actually about. Ok Ive been dabbling with the assumed exploit and from what i looks like it is a memory overflow auto shut off I know because after a few times I got an error before it turned off telling me there was something wrong with the mem or whatever. I thought it had bricked, but no thankfully. So what could this possibly do?

gamerremag
December 15th, 2006, 22:37
OK yeah not worried about editing pictures... choto shot edit is gay... ALL I DO IS PUT THE CAMARA ON THE TOP (NO NEED FOR UMD IN DRIVE?) AND RUN DEVHOOK FROM MY 1.5 AND EMULATE 3.01. THEN I GO TO PHOTO AND THEN CAMARA AND I CAN TAKE PICS? I dont need a umd and this thing works with devhook ??? ime a confused person....

no you are totally wrong.....lol u right!!

the mgs:po case is the BEST!!!:thumbup:

joshisposer
December 15th, 2006, 23:03
Ok back to what this thread is actually about. Ok Ive been dabbling with the assumed exploit and from what i looks like it is a memory overflow auto shut off I know because after a few times I got an error before it turned off telling me there was something wrong with the mem or whatever. I thought it had bricked, but no thankfully. So what could this possibly do?

thx for bringing this back on topic. dev people can look into this and probably look at the source code of the site or something and figure out what it does. maybe we can figure out some *website* exploit instead of picture exploit. IDK, copy the source code of wikipedia and then change it up a bit. idk, this will probably seem usefull in the future.


also, gamerremag, your site is stupid. "i'm sending your mac address to the feds." yeah, get a life and stop wasting internet bandwith

gamerremag
December 16th, 2006, 03:03
lol its funny, why do people even go on sites that advertise .isos and stuff?

hmmm

turtleguy101
December 16th, 2006, 06:03
ummm when devhook .5 or wutever got released, it had a list of things that it could emulate in 3.xx and a list of things it couldnt... the camara was nowhere on the list... so i dont know...

Russoxley187
December 16th, 2006, 06:10
i could not replicate either, anyone have any luck?

splodger15
December 16th, 2006, 10:35
This is an interesting exploit but people think about how do you suppose we run a downgrader through the browser.

Coders need to replicate the exploit first

But if it does lead somewhere downgraders will just not magically appear they take time to code and lots of testing

joshisposer
December 16th, 2006, 21:12
It does work on 2.71 se-c also for me. Just want to let you know since it is easy to run se-c then 3.00

fpcreator2000
December 17th, 2006, 17:50
Thank you for all the responses. My point was to bring this little discovery into the light of day to get some coders to take a look. I do apologize for the lack of proof due to lack of camera and the psp in question. But, thank you for listening.

turtleguy101
December 18th, 2006, 22:23
ordered the camara from play asia last night... should be here in 5-10 days... from what i hear it works perfectly in 1.5 with devhook emulating 3.xx... ile post again to confirm it......