Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: GripShift savegame exploit Hello World + Sparta SDK - Exploit Works on PSP 3000

                  
   
  1. #1
    Won Hung Lo wraggster's Avatar
    Join Date
    Apr 2003
    Location
    Nottingham, England
    Age
    52
    Posts
    139,544
    Blog Entries
    3209
    Rep Power
    50

    psp GripShift savegame exploit Hello World + Sparta SDK - Exploit Works on PSP 3000

    Matiaz: has today released the Hello World of his exploit for the PSP which opens up Homebrew for all Consoles and expecially for those Homebrew Starved on PSP3000 consoles.

    Heres a video of the exploit:



    Ok, binary loader, hello world and SDK finished, get it here. Read the readme for the imporant stuff.
    It's encrypted and works on the US version only.
    Get the SDK here.

    Old post for nostalgia:

    Quote:
    So, happy new year. I think presenting a new usermode exploit on the PSP is a good way to start 2009

    GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite .
    The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running ).
    The return address is located at offset 0xA9 in the file. In this poc it points to 0x08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.

    It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn't [be bothered to] get Shine's savegame tool working so it's in plaintext form) is in the SDDATA.BIN form which Hellcat's Savegame-Deemer produces (thanks to him, if the program didn't exist I wouldn't have bothered with this. ). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don't forget to have Savegame-Deemer working, duh.

    Credits go to those who deserve them.

    Hello World on PSP FW 1.52-5.02
    The Spartaaaaaaaaaaaaaaaaaaaa!!! Exploit

    by MaTiAz & FreePlay

    Instructions
    ------------
    1. Copy the contents of MS_ROOT into the root of your memory stick.
    (This will overwrite the first GripShift savegame slot).
    2. Launch the US version of GripShift.
    3. Load up the game (if it doesn't autoload).
    4. See your PSP run unsigned code.

    It'll autoexit after some time. You can use the home button to exit too if
    you've seen enough.

    FAQ
    ---
    Q: Will this allow downgrading?
    A: No, because this is an usermode exploit and functions required to downgrade are
    only available in kernel mode.

    Q: Why the name?
    A: Because the original exploit was found by overwriting the player name with
    "this is spartaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaa".

    Q: Can/Will Sony block this?
    A: Yes.

    Q: I wanna make homebrew using the exploit. How?
    A: Get FreePlay's GS SDK: http://f6y.ath.cx/pspdev/sparta_sdk.zip
    It has some constraints though, check the readme.
    The Hello World was written with it.

    Credits
    -------
    Exploit and binary loader: MaTiAz
    SDK: FreePlay
    Greets go to Dark_AleX, Mathieulh, jas0nuk, Hellcat, etc. etc. etc, you know.

    Download and Give Feedback Via Comments

  2. #2
    DCEmu Pro mikebeaver's Avatar
    Join Date
    Oct 2006
    Location
    Ipswich-England
    Age
    44
    Posts
    636
    Rep Power
    66

    Default

    Nice work, just need to get some kernal access now and all will be right with the world again

    Mike..

  3. #3
    DCEmu Legend
    Join Date
    Sep 2006
    Location
    USA
    Posts
    2,152
    Rep Power
    75

    Default

    Really REALLY cool stuff. Its refreshing just to see that there are still teams hard at work ensuring PSP homebrew survives every single hardware revision thrown at us by SONY.

    The day when every single PSP can be homebrew enabled will hopefully once again be upon us.

    Thanks to all who worked on this and I hope it encourages more work to try to get CFW on the new PSP's.

  4. #4
    DCEmu Legend Buddy4point0's Avatar
    Join Date
    May 2006
    Location
    The Lounge Awesomeness: 1337
    Age
    32
    Posts
    4,026
    Rep Power
    135

    Default

    Great!
    Has anyone tried using one of the old eboot loaders from the GTA exploit days?
    It should work with little or no modification as that too ran in user mode.

    I think that's the PSP 3000's best shot for homebrew right now.

  5. #5

    Default

    Quote Originally Posted by Buddy4point0 View Post
    Great!
    Has anyone tried using one of the old eboot loaders from the GTA exploit days?
    It should work with little or no modification as that too ran in user mode.

    I think that's the PSP 3000's best shot for homebrew right now.
    All the tiff brew needs to be recompiled to include the sparta_sdk.h take a look at it's list of functions. It's a very good start, but limited. Some tiff brew games do work after doing a few edits.

  6. #6
    DCEmu Legend dejkirkby's Avatar
    Join Date
    Feb 2006
    Age
    44
    Posts
    2,632
    Rep Power
    97

    Default

    I bow to you guys.
    Great work.

  7. #7
    DCEmu Regular titch.ryan's Avatar
    Join Date
    Nov 2005
    Location
    Gold Saucer
    Posts
    428
    Rep Power
    69

    Default

    great work.
    here come the firmware updates!!

  8. #8
    DCEmu Newbie
    Join Date
    Jun 2006
    Posts
    87
    Rep Power
    0

    Default

    Does this do anything for the PSP 2000s that cannot be hacked?

  9. #9
    DCEmu Newbie
    Join Date
    May 2006
    Posts
    38
    Rep Power
    0

    Default

    bad ass exploit name. gratz for gettin this




    SPARTAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA!!!

  10. #10
    DCEmu Legend mike_jmg's Avatar
    Join Date
    Jun 2006
    Location
    The Darkest depts of Hades
    Age
    40
    Posts
    2,099
    Rep Power
    0

    Default

    This is Spartaaaaaaaaaaaaaaaaaaa!!!!!!!
    LOL

    Sony closes the door, developers open a window
    I knew there should be more savegame exploits, good work guys

    Do you guys think DAX will release a HEN or something for this exploit?, or will he go straight to trying to improve pandora on an already hacked psp-3000?

    either way I think the 3000 will be hacked soon but I don't know if I should get a copy of Gripshift, just in case

    as the only copy I've seen is really overpriced and the dude doesn't even know there might be an exploit for it, imagine when he finds out
    Last edited by mike_jmg; January 6th, 2009 at 02:44.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •