|
|
#1 |
|
Homebrew Developer
![]() Join Date: Mar 2007
Posts: 502
Likes: 6
Liked 31 Times in 10 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Flv buffer overflow?
this is an example of a FLV video being able to crash the browser
This video may crash your browser. [youtube=425,350]ULzxwmV5QgI[/youtube] Make sure to read this! it will tell you how it works!: http://www.mindedsecurity.com/en/lab...es/MSA01110707 |
|
|
|
|
|
#2 |
![]() ![]() Join Date: Feb 2007
Posts: 6,989
Likes: 371
Liked 8,050 Times in 1,248 Posts
Mentioned: 585 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
Embedded video for you.
Code:
[youtube=425,350]ULzxwmV5QgI[/youtube] |
|
|
|
|
|
#3 |
|
Senior Member
![]() Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
I love this exploit, its really nice and not that difficult to exploit (not saying the running of remote code on the ps3 is going to be easy but the basic exploit code changing the header info on a flv is easy to write using a hexeditor)
__________________
************************************
Exploiting Ps3 = while(!(succeed=try())); |
|
|
|
|
|
#4 |
|
Homebrew Developer
![]() Join Date: Mar 2007
Posts: 502
Likes: 6
Liked 31 Times in 10 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
video of it in action
[youtube=425,350]seZYSor_7T8[/youtube] |
|
|
|
|
|
#5 |
|
Senior Member
![]() Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
Same thing that happens on the Wii also happens on the Netfront browser on Ps3
__________________
************************************
Exploiting Ps3 = while(!(succeed=try())); |
|
|
|
|
|
#6 |
|
Member
![]() Join Date: Jun 2007
Location: GO **** YOURSELF!!!
Posts: 76
Likes: 7
Liked 7 Times in 5 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
BoF exploitation on PPC architecture is a ****load different then on i386 architecture...
Besides, this is going on for SO long, and I have not seen a single PoC with a payload or what so ever :-\ |
|
|
|
|
|
#7 |
|
Homebrew Developer
![]() Join Date: Mar 2007
Posts: 502
Likes: 6
Liked 31 Times in 10 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
i was taking a break form writing my program so i decided to make this little video:
http://stage6.divx.com/user/h3r3t1c/...r-OverFlow-POC |
|
|
|
|
|
#8 | |
|
Senior Member
![]() Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
__________________
************************************
Exploiting Ps3 = while(!(succeed=try())); |
|
|
|
|
|
|
#9 |
|
Member
![]() Join Date: Jun 2007
Location: GO **** YOURSELF!!!
Posts: 76
Likes: 7
Liked 7 Times in 5 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
Then explain to me why it is crashing XMB browser, below version 1.90
|
|
|
|
|
|
#10 |
|
Senior Member
![]() Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
|
Re: Flv buffer overflow?
The eror is in the Adobe flash player built into the ps3 firmware. The flash player has never been updated since the release of the ps3 (at least not on Euro machines (firmware 1.50-1.90)
The error has existed for ages but only discovered about a week or two ago. So all ps3's on all firmwares will crash. But this doens't mean the exploit has been known about for ages.
__________________
************************************
Exploiting Ps3 = while(!(succeed=try())); |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| For what does PS3 App maker work? | dxc | PS3 | Jailbreak & Custom Firmware | 0 | 07-13-2008 12:02 AM |