|
|
#1 |
|
Member
![]() Join Date: Dec 2011
Posts: 75
Likes: 2
Liked 12 Times in 7 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
How about crashing a .PUP??
Ok, so i had another exploit idea as i'm sitting here without a job recently and have alot of time on my hands. Ok, so ur at home downloading the newest fw update (cause u have two ps3's
and u get through the checks and such at which the ps3 reboots into recovery and starts installing right after u hit the ps button on the controller. So....my question would be....at what point does the ps3 check the .PUP for control? Would there not be an exploit waiting at that particular moment if u could make the .PUP crash the ps3 then swap usb drives with a cfw on it?? It would have to be extremely well executed....but why wouldn't it work?
|
|
|
|
|
|
#2 |
|
Hired Gun
![]() Join Date: May 2011
Posts: 6,778
Likes: 2,569
Liked 3,307 Times in 1,838 Posts
Mentioned: 980 Post(s)
Tagged: 1 Thread(s)
|
Swap usb drives will do not good to the console in first place.
That's the problem.
__________________
Check Blacklist of FAKE devs
Check Whitelist of TRUSTED devs Tutorial : DEX conversion (TEST-DEBUG) One thread with all DEX information published so far. One thread with PS3 LV0 keys, CFW'S and many more. PS3devwiki your number 1 source. Check it. Console ID's Market Warning thread PS3 Ban, CFW, Unban. How to avoid it. |
|
|
|
|
|
#3 |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
In case of keys. How you want to do a cfw for higher versions without the key to sign ?
|
|
|
|
|
|
#4 |
|
Member
![]() Join Date: Dec 2011
Posts: 75
Likes: 2
Liked 12 Times in 7 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
My theory would not involve the use of keys...this would be a downgrade/ jb. What i mean is, u update to and ofw 4.10 or .11 that has been modified. This can obviously be done. Nodex and a member of here did it for fun. So with that being said, u modify the fw to crash at which u would swap the .PUP on the usb port with a cfw 3.55. In theory downgrading. My question is really, "what are all the points at which the ps3 checks the .PUP?". If that can be answered the rest could be feasible.
|
|
|
|
|
|
#5 |
|
Member
![]() Join Date: Jul 2011
Posts: 679
Likes: 275
Liked 249 Times in 146 Posts
Mentioned: 87 Post(s)
Tagged: 0 Thread(s)
|
The ps3 knows when you remove the usb drive, so your idea might work if you could some how over write the pup without removing the usbdrive.
Maybe with one of those dual usb/sd memory sticks? Edit: the syscon of a cex ps3 doesn't downgrade unless you are in service mode or have qa flag working and use recovery mode, so you would need to use a pup that has the checks patched out. Last edited by butnut; 04-15-2012 at 07:49 PM. |
|
|
|
|
|
#6 |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
Wont work. Have you ever be gaved a look on new pup's ?
They are diff to the old ones and have some new parts in it. So the ps3 would still check thoes parts and if there are not there it wouldn't work. But to answer your question. The ps3 reads the pup and first check the version. If the version is valid she would start to unpack all files from the pup to the temporary hdd partition. After that the updater self is startet and ps3 starts in updater mode. Then again a check is done if everything is ok. If not the con will give you a nice error message. So no way to go on that idea. |
|
|
|
|
|
#7 | |
|
Member
![]() Join Date: Dec 2011
Posts: 75
Likes: 2
Liked 12 Times in 7 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
But....(and i don't have my hex open) about three quarter down the page is a call to http://www.scei.co.jp/legal/us/ and an encryption. Of course we might not know what that is but (and i hate to keep giving scenerios cause i prob. sound like i'm reachin, though i swear i'm only tryin to help) what if we were to change that to meet a server requirement of our own through the .PUP? thus causing the crash while maintaining hold of the server? I know i'm reaching but i am kind of an old school hacker with tools like flycrypter, filestealer, snort, kain&able, so on....i just really wanna help u guys. Just don't have the extensive script making knowledge.
|
|
|
|
|
|
|
#8 |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
Well the hacking of EID segments and writting a app that can decrypt and re-encrypt EID'S would be more of help.
Even the most average user dont know what to do with a debug con we would have a new way of jailbreaking the ps3. Cause a full converted debug can make use of the special downgrader pup's and you can software wise jump between fw's ase the user want. Also the hombrew can be converted to fake self's and the user could let them run on higher fw's. Not all HB could run at first stage but it is a start. And a debug can even much more what i cant explain here. But if you really want to help then let me know and we talk on irc or msn, icq what ever. |
|
|
|
|
|
#9 | |
|
Member
![]() Join Date: Dec 2011
Posts: 75
Likes: 2
Liked 12 Times in 7 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
) One of the best pc devs i've seen. But anyway, let me read more about idps cause i have the recent dumps that were converted to hex and back downloaded on my hdd along with linux commands for eid dump and objective suites. Just need to do some investigating. I do recall three files were missing from the objective suites dump. But, thanks....least now i know what to shoot for.
|
|
|
|
|
|
|
#10 |
|
Homebrew Developer
![]() Join Date: Jan 2012
Posts: 105
Likes: 157
Liked 171 Times in 45 Posts
Mentioned: 57 Post(s)
Tagged: 0 Thread(s)
|
I and my team we are three to time and working on the EID part along with something other nice. I have everything you may need and we also well know the whole EID part.
We could need help to speed up the process and deliver the scene a so called idps-tool. I send you a pm for the irc information.
|
|
|
|
|
Likes: (1) |
![]() |
| Bookmarks |
| Thread Tools | |
|
|