201w ago - Today GeoHot has released sample PS3 Linux isolated SPU loader code for those with OtherOS to experiment with.
To quote: "Right now, I'm playing with the isolated SPEs, trying to get metldr to load from OtherOS. Interesting thing, I am not using the exploit. I always assumed the enable isolation mode register was hypervisor privileged.
It's not, it's kernel privileged, which means using hypervisor calls you can all get to it. So, get to hacking. Here is the code I am playing with.
I'm not that opposed to releasing the exploit, but I think the majority of you are going to be disappointed, even if you do get it working. Unless you have pushed the HV to it's limits, this exploit really isn't going to do much for you... yet.
So install OtherOS and start playing around. If people start coming up with convincing reasons why they need the exploit to go further, I'll release it. It's just a waste to release if people can't make use of it.
As far as the GPU goes, I have full access to the GPU memory space 0x2800... But without a driver, it's useless. 3D video card drivers are notoriously hard to write, look at the ATI and NVIDIA ones for linux. The best are still the closed source manufacturer ones.
I'm not even sure I believe that the HV restricts video card access, just that the OtherOS driver is 2D. If someone skilled in video card driver development comes forward, and they can explain in detail what the HV is restricting, I'll send them the exploit."
Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!
Your right - it is hard to understand the exploit, especially knowing so little about it. I know you want to keep your method private for now, which is understandable as it keeps you safe.
But, at least the fruits of your work would be helpful for others to take a look at, sure it does not need to be a public release, but it should really be seen beyond a handful of people, especially considering the fact that some of them are not the most skilled individuals around!
I mean - we have been working on the box for ages (from a different angle) with plenty of interesting results, although none as astonishing as yours. Most of our work has been on the development kits, which of course are not easy or cheap to come across. But they love to leave things live, like the System Controller's UART and JTAG lines - let alone other interesting tidbits.
In that, things of course get kept quiet, nobody can really use some of the stuff we found, like one of the PS3 TOOL's AES encrypt/decrypt keys, or commands to send the System Controller.
Nevertheless - awesome work, I know your not up to sharing your exploit, but, like myself, I know a few very talented people who would love to get a look at your LV0/LV1 dumps!