|
|
#11 |
|
Member
![]() Join Date: Jun 2012
Location: Right in the middle of ALL
Posts: 325
Likes: 113
Liked 113 Times in 80 Posts
Mentioned: 42 Post(s)
Tagged: 0 Thread(s)
|
tjhooker73 is right. the method you are referring to used to work on the samsung bada 1.2 platform but even that was later patched by the 2.0 update and u need a proper cert to resign the packages. therefore the KEY factor is important.
|
|
|
|
|
|
#12 |
![]() ![]() Join Date: Mar 2012
Posts: 9,014
Likes: 6,283
Liked 3,881 Times in 2,529 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
|
__________________
|
|
|
|
|
|
#13 |
|
Senior Member
![]() Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
|
Thats basically what I'm talking about maybe we could split it then grab the keys because they are decrypted in the system correct? If we were successful at splitting, wouldn't the keys be decrypted once we run a pkg and all we would have to do is extract them while its running or is that impossible. Also whatever happend GitBrew decrypting the meldr and bootldr back in the good days
__________________
![]() |
|
|
|
|
|
#14 |
![]() ![]() Join Date: Mar 2012
Posts: 9,014
Likes: 6,283
Liked 3,881 Times in 2,529 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
|
Split is not the correct word here.
NOP slide principle would require a vulnerability, after which it redirects to a known area rather than crash. Your principle is to replace files called by an eboot? I'm unclear on "splitting" Do you mean (for example) swap a 3.60 eboot with a donor 3.55 one, and hex/edit the 3.55 one to point at known 3.60 files? Essentially using the 3.55 eboot as a signed shell? I doubt this would work.
__________________
|
|
|
|
|
|
#15 | |
|
Senior Member
![]() Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() |
|
|
|
|
|
Likes: (1) |
|
|
#16 | |
![]() ![]() Join Date: Mar 2012
Posts: 9,014
Likes: 6,283
Liked 3,881 Times in 2,529 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
|
Cool, I understand now.
I have looked on devwiki about how eboots/selfs work, and paths within eboots, but I continue to find nothing useful. @euss will know exactly where to look, he has encyclopedic knowledge of PS3 wiki. what is interesting is:
__________________
Last edited by DEFAULTDNB; 06-27-2012 at 09:26 AM. |
|
|
|
|
|
|
#17 | |
|
Senior Member
![]() Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() |
|
|
|
|
|
|
#18 | |
|
Senior Member
![]() Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() |
|
|
|
|
|
Likes: (1) |
|
|
#19 | |
![]() ![]() Join Date: Mar 2012
Posts: 9,014
Likes: 6,283
Liked 3,881 Times in 2,529 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
|
I once spoke to comex about SSBB expliot on wii and he explained nop slide to me. You need to find a vuln that you can padd out and exploit. I dont think hypervisor will allow this to happen. Kind of like how the tiff header exploits of psp fame used to work. Sony learned from this.
__________________
|
|
|
|
|
|
|
#20 | |
|
Senior Member
![]() Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
|
__________________
![]() |
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|