Go Back  
Reply
 
Thread Tools
Old 09-22-2012   #41
Disane
Member
 
Join Date: Jul 2008
Location: Austria
Posts: 121
Likes: 18
Liked 85 Times in 29 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Originally Posted by KDSBest View Post
That's bull****. You can't dump it that's the point.
What you talk about is from the nand/nor, but not the memory. In memory Lv2 is not encrypted and can not be dumped from userland. If you can dump it from userland you got the power to really search an exploit. I need 2 bytes in lv2 on a syscall i can call and I can pwn the whole lv2.

First patch peek -> dump the real one (if you don't got it)
Then patch a poke -> poke real peek and poke syscalls -> restore overwritten lv2 stuff with the poke syscall -> done

Theory is always as simple as that.
There is no need for complicated payloads if you manage to write to a syscall that is callable from userland. The whole security breaks apart from that on.

Of course such things are patchable.

We should wait for ps4 and checkout what AMD came up with. In my opinion IBM > AMD, but we will see ^^.

The cell has a strong security system, just the implementation lacks.
Biggest mistake was that they said, metldr is not patchable . They just don't use it anymore.

I did enough, most people don't even know what I all did. It's time for a new generation . I am an oldie to the ps3 scene xD and still very underestimated ^^
So, if I'm not mistaken you are patching the syscall table at this point. Did it work?
Disane is offline   Reply With Quote
Old 09-22-2012   #42
TheEvolution_PT
Member
 
TheEvolution_PT's Avatar
 
Join Date: Oct 2011
Posts: 400
Likes: 455
Liked 190 Times in 113 Posts
Mentioned: 19 Post(s)
Tagged: 0 Thread(s)
Originally Posted by KDSBest View Post
That's bull****. You can't dump it that's the point.
What you talk about is from the nand/nor, but not the memory. In memory Lv2 is not encrypted and can not be dumped from userland. If you can dump it from userland you got the power to really search an exploit. I need 2 bytes in lv2 on a syscall i can call and I can pwn the whole lv2.

First patch peek -> dump the real one (if you don't got it)
Then patch a poke -> poke real peek and poke syscalls -> restore overwritten lv2 stuff with the poke syscall -> done

Theory is always as simple as that.
There is no need for complicated payloads if you manage to write to a syscall that is callable from userland. The whole security breaks apart from that on.

Of course such things are patchable.

We should wait for ps4 and checkout what AMD came up with. In my opinion IBM > AMD, but we will see ^^.

The cell has a strong security system, just the implementation lacks.
Biggest mistake was that they said, metldr is not patchable . They just don't use it anymore.

I did enough, most people don't even know what I all did. It's time for a new generation . I am an oldie to the ps3 scene xD and still very underestimated ^^
You are a nice guy
__________________
PS3 Slim Black with 160gb+320 hardrive(2) PS2 slim silver with freemcboot, PSP 2000 RED with PRO-C.
Retro Consoles: Sega Mega Drive 2, Gameboy Color and the great Poly Station xD
TheEvolution_PT is offline   Reply With Quote
Likes: (2)
Old 09-22-2012   #43
devil hunter
Member
 
Join Date: Aug 2008
Posts: 86
Likes: 22
Liked 10 Times in 6 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Originally Posted by KDSBest View Post
That's bull****. You can't dump it that's the point.
What you talk about is from the nand/nor, but not the memory. In memory Lv2 is not encrypted and can not be dumped from userland. If you can dump it from userland you got the power to really search an exploit. I need 2 bytes in lv2 on a syscall i can call and I can pwn the whole lv2.

First patch peek -> dump the real one (if you don't got it)
Then patch a poke -> poke real peek and poke syscalls -> restore overwritten lv2 stuff with the poke syscall -> done

Theory is always as simple as that.
There is no need for complicated payloads if you manage to write to a syscall that is callable from userland. The whole security breaks apart from that on.

Of course such things are patchable.

We should wait for ps4 and checkout what AMD came up with. In my opinion IBM > AMD, but we will see ^^.

The cell has a strong security system, just the implementation lacks.
Biggest mistake was that they said, metldr is not patchable . They just don't use it anymore.

I did enough, most people don't even know what I all did. It's time for a new generation . I am an oldie to the ps3 scene xD and still very underestimated ^^

Well, asuming they are using the same CPU type of home pcs (x86-64)

then we should experience another xbox era ^^. Also, I believe that ps successor and xbox successor can't can't get another PPC cpu, because IBM was sold and no one else develops/designs such cpus anymore .

Off topic, THANK YOU <3 for your work, best wishes.

Sorry for any grammar errors.

Last edited by devil hunter; 09-22-2012 at 06:10 PM.
devil hunter is offline   Reply With Quote
Old 09-22-2012   #44
oPolo
Member
 
oPolo's Avatar
 
Join Date: Feb 2011
Posts: 906
Likes: 303
Liked 450 Times in 297 Posts
Mentioned: 79 Post(s)
Tagged: 0 Thread(s)
For whatever guy/girl that says this will allow backups to play on FW 4.20... If I am not mistaken, this is a usermode exploit right, and as such, no memory peeking or poking is possible, and as such no ordinary backupmanagers is possible... However, all homebrew not playing with those two, should work out
oPolo is offline   Reply With Quote
Old 09-22-2012   #45
sonyisass
Apprentice
 
Join Date: Sep 2012
Posts: 5
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Hacker's community need our donations to buy a Tianhe - 2A (the most powerfull supercomputer) to crack sony firmware.
sonyisass is offline   Reply With Quote
Old 09-22-2012   #46
bigo93
Member
 
Join Date: Oct 2010
Posts: 921
Likes: 69
Liked 476 Times in 249 Posts
Mentioned: 51 Post(s)
Tagged: 0 Thread(s)
Originally Posted by sonyisass View Post
Hacker's community need our donations to buy a Tianhe - 2A (the most powerfull supercomputer) to crack sony firmware.
Or get hundreds of ps3's linked together with linux to produce a much cheaper supercomputer, the US Airforce did it.
__________________
bigo93 is offline   Reply With Quote
Likes: (1)
Old 09-23-2012   #47
sonyisass
Apprentice
 
Join Date: Sep 2012
Posts: 5
Likes: 0
Liked 0 Times in 0 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Originally Posted by bigo93 View Post
Or get hundreds of ps3's linked together with linux to produce a much cheaper supercomputer, the US Airforce did it.
What the.... ??, how can such a thing be used to
create a supercomputer.
even if it can be done sony would
soon hijack our system
sonyisass is offline   Reply With Quote
Old 09-23-2012   #48
stussy1
 
stussy1's Avatar
 
Join Date: Sep 2010
Posts: 1,032
Likes: 702
Liked 263 Times in 191 Posts
Mentioned: 31 Post(s)
Tagged: 0 Thread(s)
Originally Posted by sonyisass View Post
What the.... ??, how can such a thing be used to
create a supercomputer.
even if it can be done sony would
soon hijack our system
link

http://phys.org/news/2010-12-air-pla...rcomputer.html
stussy1 is online now   Reply With Quote
Old 09-23-2012   #49
JustThatDude
Senior Member
 
JustThatDude's Avatar
 
Join Date: Feb 2012
Posts: 1,280
Likes: 454
Liked 329 Times in 234 Posts
Mentioned: 69 Post(s)
Tagged: 0 Thread(s)
Originally Posted by bigo93 View Post
Or get hundreds of ps3's linked together with linux to produce a much cheaper supercomputer, the US Airforce did it.
I believe thats what fail0verfl0w did or another team as well. If im not mistaken if I am correct me and show me proff
__________________
JustThatDude is offline   Reply With Quote
Old 09-23-2012   #50
manster
 
manster's Avatar
 
Join Date: Dec 2010
Posts: 831
Likes: 1,006
Liked 1,096 Times in 342 Posts
Mentioned: 121 Post(s)
Tagged: 0 Thread(s)
Originally Posted by JustThatDude View Post
I believe thats what fail0verfl0w did or another team as well. If im not mistaken if I am correct me and show me proff
this is what fail0verflow did:


DCEmu Reviews - 27C3 - Chaos Communication Congress 2010 - fail0verflow - FULL VIDEO - YouTube


sorry for off topic.
__________________
manster is offline   Reply With Quote
Likes: (1)
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 12:02 AM.