• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

GeoHot Resumes Sony PS3 Hacking, Opens PS3 Hacks Blog

Category: PS3 Hacks & JailBreak  By: semitope - (geohotps3.blogspot.com)
Tags: geohot ps3 hack resumes sony ps3 hacking opens ps3 hacks blog

177w ago - This weekend GeoHot, the hacker responsible for several Apple iPhone hacks, has returned to Sony PS3 hacking after his initial announcement a few months back and has opened a PS3 hacks blog (linked above).

He recently made this Tweet:

"I just pulled everything from the USB bus... http://pastie.org/757313 the Cell processor SPI bus, PS3 is going down :-)"

These are the latest posts on his new PS3 hacks blog:

Cell SPI

The Cell processor has an SPI port which is used to configure the chip on startup. Well documented here. It also allows hypervisor level MMIO registers to be accessed. In the PS3, the south bridge sets up the cell, and the traces connecting them are on the bottom layer of the board. Cut them and stick an FPGA between.

Quick theoretical attack. Set an SPU's user memory region to overlap with the current HTAB. Change the HTAB to allow read/write to the hypervisor! If that works it's full compromise of the PPU.


A Real Challenge

The PS3 has been on the market for over three years now, and it is yet to be hacked. It's time for that to change.

I spent three weeks in Boston working software only, but now I'm home and have hardware. My end goal is to enable unsigned code execution, making every unit into a test and opening up a third party development community, either through software or hardware (with a mod chip). The PS3 is a prime example of how security should be done, very open docs wise, and the thing even runs Linux. But it isn't unbreakable :-)



Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 152 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
PS3 News's Avatar
#142 - PS3 News - 174w ago
Reply
Originally Posted by aries2k6 View Post
Quote Just wondering what the devs here think about this?

One of them said the following on IRC about it today: "fuzzing lv1 calls could be interesting" but that is about it. CJPC is busy with his latest "toy" which arrived today and will be covered in this weekend's Site News update.

aries2k6's Avatar
#141 - aries2k6 - 174w ago
Reply
Now this looks interesting and from what another user on his blog commented, it's even got more my attention. Just wondering what the devs here think about this? Maybe a serious attack point or just another stone wall.

Alot of technical talk above me but i picked up things like glitching lvl 1 data before it hits the HV or something like that... I think, lol

shalina's Avatar
#140 - shalina - 174w ago
Reply
Update: No ECC
Quote Just cause I can't read the ram bus doesn't mean I can't mess with it.


greetings
Quote George Hotz said...
Really Dumbed Down Version: No, you still don't get an aimer hack for MW2.

Yea, the HV is in XDR, top 2MB. I'm trying now to glitch the page tables to allow R/W to the page tables themselves. Then I can map w/e I want, including the hypervisor R/W

PS3 News's Avatar
#139 - PS3 News - 174w ago
Reply
Another brief update from his Blog comments:
Quote George Hotz said...
@Rich Thanks a lot for the offer, but I imagine the hard part is wiring it up. The proper way to do this is to design a passthrough board. Not sure I'm willing to put that time in yet.

To people asking if it'll work on the slim, what are you asking if it'll work? This is exploration, not a final product you get. And it never will be, learned my lesson with blackra1n.

@Paunstefan Obvious troll is obvious.

I'm trying now to find a GPIOish thing I can use to tell the injector when to inject. Thinking flash reads, but for some reason they aren't working.

Mathieulh's Avatar
#138 - Mathieulh - 174w ago
Reply
Originally Posted by Haksam View Post
Quote They were angry idiots who wanted geohot to deal with the new iphone bootrom. They dont even know what NAND is god save their new iphones (for being cheap and waiting for the price to drop)

Blackrain app solely developed by geohot and appreciated by the devs as one of the last few exploitations found until Apple learned their lesson and improved the security.

If one area has been tried, there's no harm trying again. This is why you never be pessimistic about something, so what if there's official documents to brag about a security system, even stupid idiots like IBM can have flaws and they definitely wouldn't document that in a public PDF. If this thing ever got hacked, Sony is gonna be pissed with IBM rather than the public for cracking it.

I can see you never even read these docs to begin with. Perhaps you should and then make your statement.

These documentations are very detailed about the cell security architecture and quite accurate.
Originally Posted by modzila View Post
Quote Suppose in a way you could say that the peeps hacking the PS3 are actually doing $ony a favour; one could say that $ony might learn a lesson just before releasing the PS4. That is if George exhibits something before the PS4's development is finished.

The idea to use PS3s as a blade server does tickle my nerdy gland though in case heavy computational power is required, wouldn't it be impressive that 20 million CELLs are out there and could be linked by the Internet. (Sure there are already supercomputers out there, with the power of Petaflops, but only in hands of a few)

Back to the topic, I am glad to read this show is back on the road and I don't care, Hacking is useful for society (Micro$oft backfilling holes in IE after hackers used it to attack Google, anyone...?)

Sony already learned their lesson from various plateforms, namely the xbox360 (they actually made the drive quite hard to mess with), the psp, the playstation 2 etc etc

Of course hacking a console always teaches a lesson to someone, but that still defeats millions of dollars previously put into security researches and implementations.

Page 3 of 31 «‹123456789›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• PSPMinis / PS3Minis / Bite v1.5.1 Update for PS3 is Now Released
• PS3 Fan Control Utility v1.7 for PS3 CFW CEX 3.41 to 4.41 Arrives
• PSPMinis / PS3Minis / Bite v1.5 for PS3 with PSP Homebrew Support
• PS3 Fan Control Utility v1.6 for PS3 CFW CEX 3.41 to 4.40 Arrives
• OpenSCETool (OSCETool) v0.9.2 By SpacemanSpiff for PS3 is Released
• PUAD GUI v1.5 - PS3 PUP Unpacker, Repacker and Decrypter Out
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
The Yes/No question thread - 2h ago

Lurker's Avatar
Quote Yes. Do you need the eSATA station to downgrade a "phat" PS3?...
By Lurker with
 2048 Comments »
Introductions: Hello Everyone, I'm New at PS3News.com! - 3h ago

kamikasear's Avatar
Quote Hello brothers and sisters, slim 160gb rebug 3.55.1 working great....
By kamikasear with
 6991 Comments »
PS3 Fan Control Utility v0.3 for 4.31 and 4.40 CFW CEX is Released - 4h ago

Lurker's Avatar
Quote So...what are the actual benefits of using this utility other than maintaining the PS3 at a reasonable temperature? I ask since there are posts here s...
By Lurker with
 19 Comments »
GTA IV for Rogero 4.40 - 5h ago

Liongooder's Avatar
Quote Play from external HDD & play it on HDMI,cause i've been told GTA IV gives black screen if you play it from AV cable,i just tried the Complete Edi...
By Liongooder with
 7 Comments »

Latest PlayStation 3 Trophies
PixelJunk Monsters : Encore : Zero Carat
PixelJunk Monsters : Encore : Wishing Well
PixelJunk Monsters : Encore : Scrooge's Return
PixelJunk Monsters : Encore : Black Flag

Latest PlayStation Vita Trophies
Jacob Jones and the Bigfoot Mystery : Low Notes
Jacob Jones and the Bigfoot Mystery : Unjammed
Jacob Jones and the Bigfoot Mystery : Low Roller
Jacob Jones and the Bigfoot Mystery : Quick Packer

Latest PlayStation 3 Releases
Muvluv Alternative Total Eclipse JPN PS3-HR - 05-17-2013
Skate 2 EUR PS3-Googlecus - 05-16-2013
The Walking Dead A Telltale Games Series PS3-COLLATERAL - 05-15-2013
The Cube PS3-ANTiDOTE - 05-14-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-19-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News