User Tag List

Page 1 of 2 12 LastLast
Results 1 to 10 of 15

Thread: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

  1. #1
    â€* Keep It Real â€*

    User Info Menu

    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    New exploit, old game! Damn, it's so cool to actually see this beauty working - and on a PSP-3000 no less! The PSP scene was buzzing the other day when MaTiAz found an exploit (read: buffer overflow!) in the three year old game, GripShift.

    Now then, the details: MaTiAz says that they've yet to find any further use for this, but it's still a new exploit. It could lead to further hacks, and for now, it's merely a proof of concept. Be that as it may, this is a great start, and a rather sweet find! Here's MaTiAz explaining the exploit:

    GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite $ra. The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running ). The return address is located at offset 0xA9 in the file. In this poc it points to 0x08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.


    It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn't [be bothered to] get Shine's savegame tool working so it's in plaintext form) is in the SDDATA.BIN form which Hellcat's Savegame-Deemer produces (thanks to him, if the program didn't exist I wouldn't have bothered with this. ). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don't forget to have Savegame-Deemer working, duh.

    There are two versions of the exploit. The first which is the raw form from MaTiAz, the other one (v2), is a version encrypted by FreePlay. It's also been confirmed that it works all the way up to the recent CFW 5.02 GEN-A.
    if u look around im sure youll find somthing but ill update if i find a link but soon the 3000 will be fully hacked so i know what im buying im not sure if its good or bad
    Last edited by funkmaster; 01-25-2009 at 07:17 PM.
    If you fail to plan. Plan to fail.

  2. #2
    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    WTF???
    Ftb2 name: _-CHRONiC-420-_
    Clan: [M87ELR]
    SNiPE!!!!

  3. #3
    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    Lol Spammer But thats pretty cool cuz u can now hack and have a built in mic :D SWEET

  4. #4
    â€* Keep It Real â€*

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    its not spam WTF but its not hacked yet wait a week or 2 and it will b
    If you fail to plan. Plan to fail.

  5. #5
    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    omg i cant freaking wait to mess socom up some more with a built in mic

  6. #6
    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    dont update your 3000 or this will not work becuase sony fix it with the new update

    Jack Bauer makes Chuck Norris CRY!!!!

  7. #7
    SilentProductions

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    Can some please post the 5.02 GEN-A fw so i can put on my psp i have grip shift i need the GEN-A fw please ?

    ^^ IIiviIIaster Owns! ^^

  8. #8
    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    No CFW yet. Not even a HEN.


  9. #9
    !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    PSP-3k just blows man,unless your not a hacker then youd luv it.



  10. #10
    SilentProductions

    User Info Menu

    Re: !!!!!!!!!!!!!!!!!!psp300 exploit!!!!!!!!!!!!!!!!!

    sooner or later they are going to release the HEN-A files and ill be able to hack my psp.

    ^^ IIiviIIaster Owns! ^^

Page 1 of 2 12 LastLast

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •