LAN.ST  

Go Back   LAN.ST > Forum > Console Hacking & Development > Sony PlayStation Portable

Sony PlayStation Portable Sony PlayStation Portable related development discussion.

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 02-02-2010, 03:21 AM
pspjoke's Avatar
pspjoke pspjoke is offline
Member
 
Join Date: Oct 2008
Posts: 45
Default Game save crash

if this looks exploitable i would like to speak to one of the pros via pm to further the development of the exploit and to learn more about exploits in general.




the overrun string was just a ton of A's

or 0x61 .. as you see i managed to overwrite ra so i think im on to something.


changed to 0xEE and it is for sure.


Last edited by pspjoke; 02-02-2010 at 03:33 AM.
  #2  
Old 02-02-2010, 04:32 AM
Abigail Abigail is offline
Member
 
Join Date: Jan 2010
Posts: 78
Default

Yes, this is exploitable.
  #3  
Old 02-02-2010, 05:07 AM
Getsuga_3000 Getsuga_3000 is offline
Junior Member
 
Join Date: Jan 2010
Posts: 25
Default

im not holding my breath until wololo, or someone approves of this, and send the files to him.
  #4  
Old 02-02-2010, 05:10 AM
coyotebean coyotebean is offline
Member
 
Join Date: Dec 2009
Posts: 57
Default

This is clearly a buffer overflow and the stack is overwritten which can most likely be exploited.
  #5  
Old 02-02-2010, 05:28 AM
SilverSpring SilverSpring is offline
Administrator
 
Join Date: Feb 2007
Posts: 248
Default

Doesn't even look like a savegame. Just looks like a homebrew app.

Did you just write a simple homebrew to test a buffer overflow?

But, if it really is from a savegame feel free to PM and I'll confirm it and make an exploit from it.
__________________
PSP PRX LibDoc's Lives On!
http://silverspring.lan.st/

My new home:
http://my.malloc.us/silverspring/
  #6  
Old 02-02-2010, 07:17 AM
MaxMouseDLL's Avatar
MaxMouseDLL MaxMouseDLL is offline
Moderator
 
Join Date: Aug 2008
Location: Northamptonshire, England
Posts: 449
Default

That's one hell of a lot of variables you've broken into there, is it even possible to overwrite that many vars from a gamesave?

I look forward to hearing the outcome of this, but... in keeping with recent events, i won't hold my breath.
__________________
PSP2003, TA-085v1, 5.00M33-6
XBOX Classic v1.6, Font-SoftMod

Last edited by MaxMouseDLL; 02-02-2010 at 07:24 AM.
  #7  
Old 02-02-2010, 09:55 AM
coyotebean coyotebean is offline
Member
 
Join Date: Dec 2009
Posts: 57
Default

Quote:
Originally Posted by MaxMouseDLL View Post
That's one hell of a lot of variables you've broken into there, is it even possible to overwrite that many vars from a gamesave?

I look forward to hearing the outcome of this, but... in keeping with recent events, i won't hold my breath.
In the beginning of a function, it saves registers used in the function to the stack. When it is about to return to the calling routine, it restores registers from the stack. When the stack is overwritten, it restored the overwritten value (including the register $ra, the return address of the calling routine) from the stack.
  #8  
Old 02-02-2010, 09:59 AM
MaxMouseDLL's Avatar
MaxMouseDLL MaxMouseDLL is offline
Moderator
 
Join Date: Aug 2008
Location: Northamptonshire, England
Posts: 449
Default

Quote:
Originally Posted by coyotebean View Post
Quote:
Originally Posted by MaxMouseDLL View Post
That's one hell of a lot of variables you've broken into there, is it even possible to overwrite that many vars from a gamesave?

I look forward to hearing the outcome of this, but... in keeping with recent events, i won't hold my breath.
In the beginning of a function, it saves registers used in the function to the stack. When it is about to return to the calling routine, it restores registers from the stack. When the stack is overwritten, it restored the overwritten value (including the register $ra, the return address of the calling routine) from the stack.
I get that, but it seems to have affected a whole bunch of registers (Yes i call them variables because i code PHP all day everyday.. force of habit when dealing with dollar signs).

Anyway, i hope it's legit and look forward to hearing about it (Even though it obviously doesn't apply to me)
__________________
PSP2003, TA-085v1, 5.00M33-6
XBOX Classic v1.6, Font-SoftMod
  #9  
Old 02-02-2010, 12:09 PM
pspjoke's Avatar
pspjoke pspjoke is offline
Member
 
Join Date: Oct 2008
Posts: 45
Default

judging from peoples responses, sounds like i hit gold..

awesome. ok silver, pming you now. well... in a bit actually.. im shivering to death right now and just want some fing coffee...
  #10  
Old 02-02-2010, 01:22 PM
FrEdDy FrEdDy is offline
Senior Member
 
Join Date: Jan 2010
Location: Italy
Posts: 170
Default

this looks like GripShift exploit ^^ I think....I hope you tested it on 6.20 too and on psp go maybe....
Closed Thread

  LAN.ST > Console Hacking & Development > Sony PlayStation Portable

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
PsP GO save game exploit millp Sony PlayStation Portable 13 02-17-2010 09:31 AM
Game Crash millp Sony PlayStation Portable 10 10-21-2009 08:17 PM
Game Crash found with "0x41414141" Draco Sony PlayStation Portable 15 04-24-2009 05:02 AM
Can I save my UMD and WLan?? Genkiqi Ultimate Hall of Shame 4 04-09-2009 11:16 PM
can't save themes? spiffy Sony PlayStation Portable 3 09-22-2008 08:22 AM


All times are GMT +1. The time now is 04:17 AM.

Design Developed by CompleteGFX
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.