Kernel mode under firmware 2.6 * The proof of concept *
bug in sceKernelLoadExec?
hitchhikr:
is this ':' at the end of filename crucial for this to work? Something like 48 bytes buffer for device(drive) name?
is this ':' at the end of filename crucial for this to work? Something like 48 bytes buffer for device(drive) name?
Re: bug in sceKernelLoadExec?
Yes it is, we need to break the loop at the right time._00_ wrote:hitchhikr:
is this ':' at the end of filename crucial for this to work? Something like 48 bytes buffer for device(drive) name?
Re: bug in sceKernelLoadExec?
Congratulations! You are making history...hitchhikr wrote:Yes it is, we need to break the loop at the right time._00_ wrote:hitchhikr:
is this ':' at the end of filename crucial for this to work? Something like 48 bytes buffer for device(drive) name?
If you read over at PSPU, the founder and Fanjita are working on somewhat of an 'eLoader' for this new exploit/hole. So Im assuming the first release of it will allow full access and all those '1.5' only apps will now be 2.5-2.6 apps as well.
But I for one do not have GTA so I guess Ill stick with 1.5 til this is actually turned into something.
But I for one do not have GTA so I guess Ill stick with 1.5 til this is actually turned into something.
-
- Posts: 8
- Joined: Wed Oct 26, 2005 10:08 pm
- Location: Shiga, Japan
- Contact:
Yes you did! But...
Great work!
But what I am worrying is... that we have full access to flash..
We can downgrade 2.60 to 1.50 (or 1.00) maybe,
but some harmful program will be created for 2.60 users.
# In Japan, the "trojan horse" hiding in programs, or illegal ISOs
# is threat for "normal users"....
I'm creating new PSP Antibrick and I'll add 2.60 method.
# PSP Antibrick is protection software from harmful programs.
# And new version uses "debug registers" :P
But what I am worrying is... that we have full access to flash..
We can downgrade 2.60 to 1.50 (or 1.00) maybe,
but some harmful program will be created for 2.60 users.
# In Japan, the "trojan horse" hiding in programs, or illegal ISOs
# is threat for "normal users"....
I'm creating new PSP Antibrick and I'll add 2.60 method.
# PSP Antibrick is protection software from harmful programs.
# And new version uses "debug registers" :P
Re: Kernel mode under firmware 2.6 * The proof of concept *
Thx very much at all , what a great news~!
But could you pls explain what's the secret inside? thx ~
But could you pls explain what's the secret inside? thx ~
just check out the source that is with the zip
the exploit is so simple ...its all there and as you
can see it require 48 byte length path and that
will create a buffer overflow quiet easily ...something
so small i do not think i or anyone really bent on finding
could have found but hitchhikr has very good eyes :)
this is truely an exploit and not speculation
the exploit is so simple ...its all there and as you
can see it require 48 byte length path and that
will create a buffer overflow quiet easily ...something
so small i do not think i or anyone really bent on finding
could have found but hitchhikr has very good eyes :)
this is truely an exploit and not speculation
10011011 00101010 11010111 10001001 10111010
Trurely awesome!
Respect. This really is something. I have almost lost hope for kernel access on 2.00+ - and there it is. I have a feeling that there will be a surge of programs to follow, including some that we do not talk about in these forums... ;)
Congratulations. Hitchhikr's guide to the PSP.
Congratulations. Hitchhikr's guide to the PSP.
Excellent work :)
Hmm... something I was wondering, how is kernel space protected on PSP, as there is no MMU?
Hmm... something I was wondering, how is kernel space protected on PSP, as there is no MMU?
Sorry for my bad english
Oldschool library for PSP - PC version released
Oldschool library for PSP - PC version released