Go Back  
Reply
 
Thread Tools
Old 07-23-2007   #1
H3R3T1C
Homebrew Developer
 
Join Date: Mar 2007
Posts: 502
Likes: 6
Liked 31 Times in 10 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Flv buffer overflow?

this is an example of a FLV video being able to crash the browser

This video may crash your browser.
[youtube=425,350]ULzxwmV5QgI[/youtube]

Make sure to read this! it will tell you how it works!: http://www.mindedsecurity.com/en/lab...es/MSA01110707
__________________
Team PS3HaX
Sony can make it hack proof but that doesn't mean we aint going to hack it!

H3R3T1C is offline   Reply With Quote
Old 07-23-2007   #2
Pirate
 
Pirate's Avatar
 
Join Date: Feb 2007
Posts: 6,989
Likes: 371
Liked 8,050 Times in 1,248 Posts
Mentioned: 585 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

Embedded video for you.

Code:
[youtube=425,350]ULzxwmV5QgI[/youtube]
__________________


Please do not PM me with help/questions (I will not reply). Use this for your questions.
PS3 Hacks
Pirate is offline   Reply With Quote
Old 07-24-2007   #3
Ps3Rips
Senior Member
 
Ps3Rips's Avatar
 
Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

I love this exploit, its really nice and not that difficult to exploit (not saying the running of remote code on the ps3 is going to be easy but the basic exploit code changing the header info on a flv is easy to write using a hexeditor)
__________________
************************************
Exploiting Ps3 = while(!(succeed=try()));
Ps3Rips is offline   Reply With Quote
Old 07-24-2007   #4
H3R3T1C
Homebrew Developer
 
Join Date: Mar 2007
Posts: 502
Likes: 6
Liked 31 Times in 10 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

video of it in action
[youtube=425,350]seZYSor_7T8[/youtube]
__________________
Team PS3HaX
Sony can make it hack proof but that doesn't mean we aint going to hack it!

H3R3T1C is offline   Reply With Quote
Old 07-24-2007   #5
Ps3Rips
Senior Member
 
Ps3Rips's Avatar
 
Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

Same thing that happens on the Wii also happens on the Netfront browser on Ps3
__________________
************************************
Exploiting Ps3 = while(!(succeed=try()));
Ps3Rips is offline   Reply With Quote
Old 07-24-2007   #6
Core-TX
Member
 
Join Date: Jun 2007
Location: GO **** YOURSELF!!!
Posts: 76
Likes: 7
Liked 7 Times in 5 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

BoF exploitation on PPC architecture is a ****load different then on i386 architecture...
Besides, this is going on for SO long, and I have not seen a single PoC with a payload or what so ever :-\
Core-TX is offline   Reply With Quote
Old 07-24-2007   #7
H3R3T1C
Homebrew Developer
 
Join Date: Mar 2007
Posts: 502
Likes: 6
Liked 31 Times in 10 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

i was taking a break form writing my program so i decided to make this little video:
http://stage6.divx.com/user/h3r3t1c/...r-OverFlow-POC
__________________
Team PS3HaX
Sony can make it hack proof but that doesn't mean we aint going to hack it!

H3R3T1C is offline   Reply With Quote
Old 07-24-2007   #8
Ps3Rips
Senior Member
 
Ps3Rips's Avatar
 
Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

Originally Posted by Core-TX
BoF exploitation on PPC architecture is a ****load different then on i386 architecture...
Besides, this is going on for SO long, and I have not seen a single PoC with a payload or what so ever :-\
Going on for so long?, I think you mean the other flash exploit that was for opera browser and the WIii integrated flash player. This exploit was only made public last week.

__________________
************************************
Exploiting Ps3 = while(!(succeed=try()));
Ps3Rips is offline   Reply With Quote
Old 07-27-2007   #9
Core-TX
Member
 
Join Date: Jun 2007
Location: GO **** YOURSELF!!!
Posts: 76
Likes: 7
Liked 7 Times in 5 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

Then explain to me why it is crashing XMB browser, below version 1.90
Core-TX is offline   Reply With Quote
Old 07-27-2007   #10
Ps3Rips
Senior Member
 
Ps3Rips's Avatar
 
Join Date: Mar 2007
Posts: 1,081
Likes: 8
Liked 88 Times in 52 Posts
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Flv buffer overflow?

The eror is in the Adobe flash player built into the ps3 firmware. The flash player has never been updated since the release of the ps3 (at least not on Euro machines (firmware 1.50-1.90)

The error has existed for ages but only discovered about a week or two ago. So all ps3's on all firmwares will crash. But this doens't mean the exploit has been known about for ages.
__________________
************************************
Exploiting Ps3 = while(!(succeed=try()));
Ps3Rips is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
For what does PS3 App maker work? dxc PS3 | Jailbreak & Custom Firmware 0 07-13-2008 12:02 AM



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 04:53 AM.