Results 1 to 2 of 2

Thread: PSJailbreak Reverse Engineered

                  
   
  1. #1
    Won Hung Lo wraggster's Avatar
    Join Date
    Apr 2003
    Location
    Nottingham, England
    Age
    52
    Posts
    139,549
    Blog Entries
    3209
    Rep Power
    50

    Default PSJailbreak Reverse Engineered

    German website GameFreax has claimed to have successfully reverse engineered PS Jailbreak. They bring out some important information that was previously unknown. First off, PSJailbreak was apparently NOT a clone of Sony’s JIG, instead its a legitimate exploit that was developed. Second, we can NOT upgrade PSJailbreak without the use of additional hardware - maybe the company planned to sell another component to upgrade the unit?

    Here is the full (roughly) translated post:

    We have taken a closer look at this PSJailbreak dongle
    We can confirm that the PSJailbreak is not a clone of Sony’s “Jig” module. PSJailbreak is a self-developed exploit. The chip is not a PIC18F444 but a ATMega is used with a software USB interface. This means the chip is internally capable of emulating any USB device. PSJailbreak emulates a 6 Port USB hub on which different devices will later be connected and then disconnected. One of these devices has the product:vendor ID of Sony’s “Jig” module, which means this had played a certain role during the development of PSJailbreak role.

    But lets start from beginning: When the PS3 is powered on … A USB emulation device will be connected, which has a too large of a Configuration Descriptor. This Descriptor overrides the stack with a PowerPC shellcode that gets executed. Now, various USB devices are connected to the emulation USB hub. One device has a large Descriptor with a size of 0xAD, which is part of the exploit and contains static data. A short time later (we are moving here in milliseconds) the jig module is connected, and encrypted data is transmitted to the jig module. A few milliseconds later, the Jig module answers with 64 byte static data, all USB devices are then disconnected, and a new USB device is connected and the PS3 launches with ‘a new feature’.

    PSJailbreak is NOT software update-able. The Update feature which is mentioned, can be done just with hardware modifications. So by ‘update’ they mean ‘buy more of our stuff’

    http://www.gamefreax.de/psjailbreak-...ngineered.html

  2. #2
    DCEmu Pro
    Join Date
    Jun 2005
    Location
    USA
    Posts
    597
    Rep Power
    71

    Default

    So the single-point-of-failure is a buffer overflow, huh?
    Unless the PS3 boot sequence is entirely in mask ROM, this is going to be inconsequential for Sony to patch away.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Yu-Gi-Oh! 5D's World Championship 2010: Reverse of Arcadia
    By wraggster in forum Nintendo News Forum
    Replies: 1
    Last Post: February 16th, 2010, 20:48
  2. iPod shuffle headphone remote reverse engineered
    By wraggster in forum The Apple iPhone, Android & Mobile Phone News Forum
    Replies: 0
    Last Post: February 14th, 2010, 13:01
  3. Flip Your DSi To Play Tecmo’s Reverse Shooting
    By wraggster in forum Nintendo News Forum
    Replies: 0
    Last Post: February 2nd, 2010, 19:11
  4. The History Of Video Game Art In Reverse [Art]
    By indiegames in forum Off Topic Forum
    Replies: 0
    Last Post: January 5th, 2010, 16:20
  5. PSN gets reverse 2D shooter
    By wraggster in forum Sony Consoles News Forum
    Replies: 0
    Last Post: July 21st, 2009, 16:16

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •