Page 1 of 4 1234 LastLast
Results 1 to 10 of 35

Thread: Libtiff Exploit Found in Firmware 4.20 for PSP3000 Owners ?

                  
   
  1. #1
    Won Hung Lo wraggster's Avatar
    Join Date
    Apr 2003
    Location
    Nottingham, England
    Age
    52
    Posts
    139,568
    Blog Entries
    3209
    Rep Power
    50

    psp Libtiff Exploit Found in Firmware 4.20 for PSP3000 Owners ?

    Check out this video and discuss if legit:


  2. #2

    Default

    This is true, just not that video.

    Quote Originally Posted by MaTiAz
    So, happy new year. I think presenting a new usermode exploit on the PSP is a good way to start 2009

    GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite $ra.
    The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running ).
    The return address is located at offset 0xA9 in the file. In this poc it points to 0x08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.

    It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn't [be bothered to] get Shine's savegame tool working so it's in plaintext form) is in the SDDATA.BIN form which Hellcat's Savegame-Deemer produces (thanks to him, if the program didn't exist I wouldn't have bothered with this. ). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don't forget to have Savegame-Deemer working, duh.
    Video POC on PSP 3000 via FreePlay.

    I'm keeping the source link out, because they wouldn't be happy with non dev's flooding the forums.



    So, go buy GripShift now, if this gets fully worked out. You never know

  3. #3
    DCEmu Rookie
    Join Date
    Jul 2005
    Posts
    167
    Rep Power
    69

    Default

    Dude!!! I resent that comment about Gripshift being one of the worst games. It has always been one of my favourite games for PSP!

    **** that dude, I hope is exploit never works!

  4. #4
    DCEmu Regular newb_fo_life's Avatar
    Join Date
    Aug 2007
    Location
    Dublin
    Posts
    271
    Rep Power
    0

    Default

    Wow this is great news for the psp 3000

  5. #5
    DCEmu Newbie
    Join Date
    Jan 2006
    Posts
    16
    Rep Power
    0

    Thumbs down Good and Bad this is..........

    Good for the homebrew scene, but not for Sony, if this leads to this machine being cracked open, then we will all lose out, because no developers will bother releasing any new AAA Titles, knowing that they are just going to be copied as .ISO's for Free, on Custom Firmware's

  6. #6
    DCEmu Newbie
    Join Date
    Apr 2007
    Posts
    21
    Rep Power
    0

    Default 2 different exploits

    @tinman : The libtiff vulnerability and the GripShift exploit are two different things

    I can say the libtiff thing is legit (since I'm the one who created the files), although not very useful. You can see my posts here : http://lan.st/showthread.php?t=1856

    I'm pretty sure the GripShift thing is real (the people who created/confirmed it are trusty sources), and definitely more promising than my libtiff finding

  7. #7

    Default

    Quote Originally Posted by tinman View Post
    This is true, just not that video.



    Video POC on PSP 3000 via FreePlay.

    I'm keeping the source link out, because they wouldn't be happy with non dev's flooding the forums.



    So, go buy GripShift now, if this gets fully worked out. You never know
    Yea i read that on the PSPUPDATES.com webpage this morning. I immediately sent a email to sony to tell them about it and they should keep an eye on this new exploit. Really dont want to see the psp 3000 hacked leading to more piracy.

  8. #8

    Default

    no offense guys (And I seriously don't want to start a flame war)

    I think an image just crashing won't prove anything but if it crashes and then something like a hello world pops up, that's a whole different story (And we have to put in account that, even if this works, you might only have user level access not kernel level access which you need for hacking or replacing the firmware).

    Again, don't want to start a flame war. but to me, this was useless.

    About gripshift... Never played it nor care (doesn't make a difference to me) but if by any chance there is an exploit found, it happens.

    Sooner or later pirates find their way to hack the console.

    Deal with it.
    DON'T CLICK HERE
    98% of teenage population has tried smoking pot. If you're one of the 2% who hasn't, copy & paste this into your signature

  9. #9
    DCEmu Legend mike_jmg's Avatar
    Join Date
    Jun 2006
    Location
    The Darkest depts of Hades
    Age
    40
    Posts
    2,099
    Rep Power
    0

    Default

    This is kind of exciting yet kind of sad

    Is good to see people still trying and working for the homebrew scene, but at the same time is very sad that this might kill the platform for good as it happened to the dreamcast. Only part-good thing is that there is a bunch of AAA titles already on their way.

    Either way I'll go hunting for a gripshift umd

  10. #10
    DCEmu Legend Buddy4point0's Avatar
    Join Date
    May 2006
    Location
    The Lounge Awesomeness: 1337
    Age
    32
    Posts
    4,026
    Rep Power
    135

    Default

    This looks extremely promising.
    There's also downloads on QJ for any developers that want to try and make a hello world or anything like that.

Page 1 of 4 1234 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •