Go Back  
Reply
 
Thread Tools
Old 08-18-2012   #11
advocatusdiaboli
Senior Member
 
advocatusdiaboli's Avatar
 
Join Date: Sep 2010
Location: /dev/random
Posts: 1,687
Likes: 425
Liked 271 Times in 171 Posts
Mentioned: 14 Post(s)
Tagged: 0 Thread(s)
Originally Posted by badman1150 View Post
Did geohot did make any tutorial..???? About the hardware what will it be??? Wen I search on google they didn't mention about some hardware??...........I am good at soldering...!!!!!!!!!
Yes, but the page was removed, he used a glitch tool.
__________________
US 4USB ports OFW 3.15 PS Ubuntu
EU 4USB ports CFW 4.21.1 REX
There is only one OS; AmigaOS, the rest are just [l]imitations.
advocatusdiaboli is offline   Reply With Quote
Old 08-18-2012   #12
tjhooker73
Senior Member
 
tjhooker73's Avatar
 
Join Date: Jan 2011
Location: Texas
Posts: 2,116
Likes: 394
Liked 553 Times in 413 Posts
Mentioned: 158 Post(s)
Tagged: 0 Thread(s)
Originally Posted by advocatusdiaboli View Post
Yes, but the page was removed, he used a glitch tool.
no he never released it. He even said he did not. He told sony how he did it though.
tjhooker73 is online now   Reply With Quote
Old 08-18-2012   #13
TizzyT
Homebrew Developer
 
TizzyT's Avatar
 
Join Date: Jul 2011
Location: USA-Unfortunately Sucks A$$
Posts: 1,843
Likes: 1,011
Liked 813 Times in 478 Posts
Mentioned: 160 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to TizzyT
Originally Posted by JustThatDude View Post
Hey just wondering but did GeoHot ever release his method of doing it? And if not can't he tell us stuff. If i remember correctly he was never allowed to crack a Sony device but they never said he could give us information without cracking it
Geohot used a XDR memory glitch where he prevented a write what was supposed to happen using tiny pulses. It is somewhat explained in F0F ccc event video.

Geohot did other things as well but apparently that info was not public.
__________________
If you are going to promote TB at least do it right!!!, or better yet DON'T!!!
TizzyT is offline   Reply With Quote
Old 08-18-2012   #14
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by TizzyT View Post
Geohot used a XDR memory glitch where he prevented a write what was supposed to happen using tiny pulses. It is somewhat explained in F0F ccc event video.

Geohot did other things as well but apparently that info was not public.
Wonder if he can tell us the method without getting fined
__________________
JustThatDude is offline   Reply With Quote
Old 08-19-2012   #15
baargle
Senior Member
 
Join Date: Sep 2010
Posts: 1,175
Likes: 603
Liked 625 Times in 376 Posts
Mentioned: 138 Post(s)
Tagged: 0 Thread(s)
Troll feeding time at the zoo...chomp chomp.
baargle is offline   Reply With Quote
Old 08-19-2012   #16
donglehater
Senior Member
 
donglehater's Avatar
 
Join Date: Jun 2012
Posts: 1,151
Likes: 254
Liked 648 Times in 362 Posts
Mentioned: 62 Post(s)
Tagged: 0 Thread(s)
Originally Posted by baargle View Post
Troll feeding time at the zoo...chomp chomp.
Ya, I think I called it to begin with. Even if he isnt a troll he clearly does not possess the necessary skills,tools or mental acuity to accomplish the task.

No offense to the OP intended.......I too do not possess two of the aforementioned requirements.
donglehater is online now   Reply With Quote
Old 08-19-2012   #17
advocatusdiaboli
Senior Member
 
advocatusdiaboli's Avatar
 
Join Date: Sep 2010
Location: /dev/random
Posts: 1,687
Likes: 425
Liked 271 Times in 171 Posts
Mentioned: 14 Post(s)
Tagged: 0 Thread(s)
About the glitch:
http:/ /www.**** ***.com/PS3-Hacks/geohot-releases-ps3-hack-exploit-your-system-and-enjoy/

geohot: well actually it's pretty simple
geohot: i allocate a piece of memory
geohot: using map_htab and write_htab, you can figure out the real address of the memory
geohot: which is a big win, and something the hv shouldn't allow
geohot: i fill the htab with tons of entries pointing to that piece of memory
geohot: and since i allocated it, i can map it read/write
geohot: then, i deallocate the memory
geohot: all those entries are set to invalid
geohot: well while it's setting entries invalid, i glitch the memory control bus
geohot: the cache writeback misses the memory
geohot: and i have entries allowing r/w to a piece of memory the hypervisor thinks is deallocated
geohot: then i create a virtual segment with the htab overlapping that piece of memory i have
geohot: write an entry into the virtual segment htab allowing r/w to the main segment htab
geohot: switch to virtual segment
geohot: write to main segment htab a r/w mapping of itself
geohot: switch back
geohot: PWNED
geohot: and would work if memory were encrypted or had ECC
geohot: the way i actually glitch the memory bus is really funny
geohot: i have a button on my FPGA board
geohot: that pulses low for 40ns
geohot: i set up the htab with the tons of entries
geohot: and spam press the button
geohot: right after i send the deallocate call
On his personal blog, in which is now removed, he revealed how to do it.
Perhaps: http://archive.org/web/web.php or similar pages will still have it?
__________________
US 4USB ports OFW 3.15 PS Ubuntu
EU 4USB ports CFW 4.21.1 REX
There is only one OS; AmigaOS, the rest are just [l]imitations.

Last edited by advocatusdiaboli; 08-19-2012 at 02:51 AM.
advocatusdiaboli is offline   Reply With Quote
Old 08-19-2012   #18
Annelies
Annelies Marie Frank
Manala Champion
 
Annelies's Avatar
 
Join Date: Sep 2010
Location: San Francisco, CA
Posts: 4,572
Likes: 1,587
Liked 2,436 Times in 1,328 Posts
Mentioned: 449 Post(s)
Tagged: 1 Thread(s)
Originally Posted by tjhooker73 View Post
no he never released it. He even said he did not. He told sony how he did it though.
Whether you're really trolling or not, you are horribly misinformed. Geohot described his method and it was a glitch. He didn't tell Sony a damn thing. Well, until they settled in court.
Annelies is online now   Reply With Quote
Likes: (1)
Old 08-19-2012   #19
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 9,014
Likes: 6,283
Liked 3,881 Times in 2,529 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
My reversing skills are amazing... Shame they only apply in a car :-(
__________________
DEFAULTDNB is online now   Reply With Quote
Old 08-19-2012   #20
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Why not attack the memory with so many commands and create a buffer overflow basically and be able to implement our code/exploit. Or is that what GeoHot had done? Lets explore timing attacks like on xbox 360. Even if we found a way to time attack it. It would still be good for the end user if we would be able to on the latest firmware.
__________________
JustThatDude is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 03:21 PM.