LAN.ST  

Go Back   LAN.ST > Forum > Console Hacking & Development > Sony PlayStation Portable

Sony PlayStation Portable Sony PlayStation Portable related development discussion.

Reply
 
Thread Tools Display Modes
  #21  
Old 01-03-2009, 06:20 AM
rebman rebman is offline
Junior Member
 
Join Date: Jan 2009
Posts: 10
Send a message via AIM to rebman Send a message via Skype™ to rebman
Default

This is a great find, good work guys.

let me know if I can do anything to help.
Reply With Quote
  #22  
Old 01-03-2009, 09:14 AM
wololo wololo is offline
Moderator
 
Join Date: Dec 2008
Posts: 202
Default

May I ask how people usually find this kind of vulnerability in a game ? Luck ? Or is there a "way" to look for those ?

Edit: I hope the game's good, because I ordered it on ebay. I'm not going to wait until the prices skyrocket like they did for GTA

Last edited by wololo; 01-03-2009 at 10:05 AM.
Reply With Quote
  #23  
Old 01-03-2009, 12:22 PM
MaTiAz MaTiAz is offline
Malloc Staff
 
Join Date: Jan 2007
Posts: 12
Default

Quote:
Originally Posted by wololo View Post
May I ask how people usually find this kind of vulnerability in a game ? Luck ? Or is there a "way" to look for those ?

Edit: I hope the game's good, because I ordered it on ebay. I'm not going to wait until the prices skyrocket like they did for GTA
I found this one through pure boredom. There is a way to look for buffer overflows, and the simplest on is just trying to put long strings in places where a static size buffer is expected. In this case, I overwrote the player name with "this is spartaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaa" and watched psplink show the exception where the return address is 0x61616161
Reply With Quote
  #24  
Old 01-03-2009, 12:26 PM
Hellcat Hellcat is offline
Supervisor
 
Join Date: Jan 2008
Posts: 178
Default

I really should get PSPLink working....

In the meantime I'm trying to figure out how to make syscalls from the injected code, so that I could try to make something usefull for it
Like "how do I get the address of a function (let's say sceIoOpen, for example) to then call it by jumping to it's address"....
__________________
irc.malloc.us #Hellcat
Reply With Quote
  #25  
Old 01-03-2009, 02:45 PM
jas0nuk jas0nuk is offline
Administrator
 
Join Date: Oct 2006
Posts: 423
Default

An excellent find. Well done.
Reply With Quote
  #26  
Old 01-03-2009, 03:02 PM
ne0h ne0h is offline
Junior Member
 
Join Date: Jun 2008
Posts: 9
Default

Hellcat, look at dax's sctrlHENFindFunction, maybe is what you are searching...
Reply With Quote
  #27  
Old 01-03-2009, 06:43 PM
FreePlay FreePlay is offline
Senior Member
 
Join Date: Dec 2006
Location: Schenectady, NY, USA
Posts: 108
Send a message via ICQ to FreePlay Send a message via AIM to FreePlay Send a message via Skype™ to FreePlay
Default

It isn't. He's trying to figure out how to find and use functions without already having access to any of the SCE functions.
__________________
boinggggg.
Reply With Quote
  #28  
Old 01-03-2009, 07:22 PM
Bubbletune Bubbletune is offline
Member
 
Join Date: Dec 2007
Posts: 68
Default

Quote:
Originally Posted by FreePlay View Post
It isn't. He's trying to figure out how to find and use functions without already having access to any of the SCE functions.
Just jump in to the stubs of the game, that's what the 3.50 HEN does.
Obviously this is limited, which is why it needs to be exploited further to get access to all SCE functions.

Last edited by Bubbletune; 01-03-2009 at 07:24 PM.
Reply With Quote
  #29  
Old 01-03-2009, 07:55 PM
Torch Torch is offline
Junior Member
 
Join Date: Oct 2007
Posts: 27
Default

Is it even possible to have a HEN core in newer firmware without a custom IPL?
Reply With Quote
  #30  
Old 01-03-2009, 08:12 PM
MaTiAz MaTiAz is offline
Malloc Staff
 
Join Date: Jan 2007
Posts: 12
Default

Quote:
Originally Posted by Torch View Post
Is it even possible to have a HEN core in newer firmware without a custom IPL?
Why not, if we have a kernel exploit? Pre-3.60M33 firmwares didn't have a custom IPL and they still had a HEN core.
Reply With Quote
Reply

  LAN.ST > Console Hacking & Development > Sony PlayStation Portable

Tags
exploit, psp3000

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Possible Exploit Kwastie Sony PlayStation Portable 10 06-14-2007 06:13 PM
3.10 Possible Exploit. Mentality Sony PlayStation Portable 1 02-03-2007 05:22 PM
new exploit found! SpectroPlasm Sony PlayStation Portable 4 12-22-2006 02:00 AM


All times are GMT +1. The time now is 04:14 AM.

Design Developed by CompleteGFX
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.