Sponsored Links

Sponsored Links

PS3 Lv0ldr / Bootldr Exploit Reverse-Engineering Details by Naehrwert


Sponsored Links
115w ago - Following up on the previous PS3 Lv0ldr / Bootldr clarifications by marcan42 and wololo, today PlayStation 3 hacker naehrwert has shared some details based on reverse-engineering the exploit used to dump it.

To quote from his blog: The Exploit

As the exploit that was used to dump lv0ldr/bootldr/howeveryouliketocallit is public now, let's have a closer look at it to understand what's going on. Here is what I have reversed from lv0 (it shares the syscon portion of the code with its SPU counterpart):

[Register or Login to view code]

The syscon library implements some high level functions, e.g. to shutdown the console on panic or to read certain configuration values. Every of this functions internally uses another function to exchange packets with syscon and the exchange function uses the read_cmpl_msg one to get the answer packet. The top-level function will pass a fixed size buffer to the exchange function.

So if we are able to control syscon packets, e.g. by emulating MMIO (and thanks to IBM we are), we can change the packet size between the two packet readings and overwrite the caller stack. And if we first copy a little stub to shared LS and let the return address point to it, we can easily dump the whole 256 kB.

Nothing more left to say now, let's wait and see if this is going to be fixed in future firmware versions (we just have to check lv0 fortunately).




Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter, Facebook and drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene and PlayStation 4 scene updates and fresh homebrew PS3 Downloads. Enjoy!
Sponsored Links
Sponsored Links

Comments 252 Comments - Go to Forum Thread »

• Please Register at PS3News.com or Login to make comments on Site News articles.
 
#202 - Gaarasaiyan - 117w ago
Gaarasaiyan's Avatar
I'm just waiting for when I don't have to downgrade to 3.55 to install a CFW. I miss my CFW but I don't want to have to downgrade to install it I just want to be able to install a CFW over the current OFW. Maybe one day...

#201 - mistarz - 117w ago
mistarz's Avatar
Well.. to be proper and simple. NOTHING.

M

#200 - miki2o - 117w ago
miki2o's Avatar
What can we do with this PS3 Downgrade 3.60++ (Lv2diag.421.self) ? Thanks I haven't understood the IRC conversation...

#199 - fantopoulos - 117w ago
fantopoulos's Avatar
ya it is bananas everywhere people trying to be the grinch of xmas lol enjoy and wait for rebug, or a proper cfw fix cheers

#198 - mistarz - 117w ago
mistarz's Avatar
Thx Shinji.

M

#197 - shinji1982 - 117w ago
shinji1982's Avatar
What i have read that the Lv2diag.421.self is fake and this is confirmed by eussNL.

#196 - mistarz - 117w ago
mistarz's Avatar
Hi guys.

This lv2diag.421.self does nothing for me i tried it in several ways... So anyone got some results with it??

M

#195 - kalberto - 117w ago
kalberto's Avatar
all decrypts is surface, but we are still need Duplex, Unsane, Propjoe and others to fix the problems inside the fixed.

such as: the damn data save corrupted, no sound, etc

#194 - PS3 News - 117w ago
PS3 News's Avatar
This crapola? God I hate having to navigate away from PS3 News for stuff, maybe I'm just lazy

From FB: Since I won't be able to 'play' with the PS3 the way I want for a little while, here's some work to fittle with. (Bricks on 4.30) Installs on 3.55 and below with SEN Access. (And PUBLIC Keys for decrypt are there)

BS File: [Register or Login to view links]

#193 - d3adliner - 117w ago
d3adliner's Avatar
The file this PS3 Scener is talking about has a link posted on ModderExcess45's facebook page. I'd stay far away from it, the guys a known fake & I wouldn't doubt Ps3 Scener is a part of his little scam "dev team" along with the mini-me Jay Leno on crank kid in the YouTube video above.

 

Sponsored Links

Sponsored Links







Advertising - Affiliates - Contact Us - PS3 Downloads - PS3 Forums - Privacy Statement - Site Rules - Top - © 2015 PlayStation 3 News