PS3 Lv0ldr / Bootldr Exploit - 改機

Kelly avatar
By Kelly
at 2012-11-21T21:47

Table of Contents

http://goo.gl/21FLs

PS3 Lv0ldr / Bootldr Exploit Reverse-Engineering Details by Naehrwert
and wololo, today PlayStation 3 hacker naehrwert has shared some details
based on reverse-engineering the exploit used to dump it.

To quote from his blog: The Exploit

As the exploit that was used to dump lv0ldr/bootldr/howeveryouliketocallit is
public now, let's have a closer look at it to understand what's going on.
Here is what I have reversed from lv0 (it shares the syscon portion of the
code with its SPU counterpart):

The syscon library implements some high level functions, e.g. to shutdown the
console on panic or to read certain configuration values. Every of this
functions internally uses another function to exchange packets with syscon
and the exchange function uses the read_cmpl_msg one to get the answer
packet. The top-level function will pass a fixed size buffer to the exchange
function.

So if we are able to control syscon packets, e.g. by emulating MMIO (and
thanks to IBM we are), we can change the packet size between the two packet
readings and overwrite the caller stack. And if we first copy a little stub
to shared LS and let the return address point to it, we can easily dump the
whole 256 kB.

Nothing more left to say now, let's wait and see if this is going to be fixed
in future firmware versions (we just have to check lv0 fortunately).


--

____ _ _ _ _ ____ _ _ ____ _____ ____
(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
_)(_ ) ( \ / )__) ) ( )( )(_)( ) /
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_)


--
Tags: 改機

All Comments

Charlie avatar
By Charlie
at 2012-11-23T20:49
PS3已經真的被脫光光了... 連內褲都不剩了

請問N3DS XL台灣版與DSTWO的相容性

Hedy avatar
By Hedy
at 2012-11-17T21:48
目前手上沒有任何一台NDS系列的主機 最近想買一台來玩 爬了板上許多文章還是摸不著頭緒 我想請問一下N3DS XL的台灣版繁中主機 能不能用DSTWO來玩NDS的遊戲? 有沒有可能造成以後要玩3DS的遊戲時沒辦法玩? 或者沒辦法連網路之類的問題? (不打算買NDS因為考慮到之後遊戲都會出在3DS ...

PS3ITA with IDPS Change

Kristin avatar
By Kristin
at 2012-11-17T03:08
◆ From: 98.159.211.240 推 mybaby520:改區碼型號SONY不太在意吧 仍然鎖定執行過multiMAN主機 11/16 22:40 → mybaby520:的console ID 11/16 22:41 → cassine:http://www.ps3devwiki.com/wik ...

PS3ITA with IDPS Change

Isla avatar
By Isla
at 2012-11-16T22:17
http://goo.gl/4UlsO Italian PlayStation 3 developers PS3TTA have made available what they call PS3ITA CFW 4.21 DEX which includes Change IDPS All Region 4 ...

請問wii改硬碟!

Frederic avatar
By Frederic
at 2012-11-16T22:03
大家好~ 請問wii硬改了之後 搭配的硬碟可以使用不用外接電源的隨身硬碟玩嗎?? 如果搭配2.5吋硬碟(盒)加外接電源 會跑得比較穩嗎???? 實在不曉得差異在哪邊~~~~ 感謝大家~ - ...

PS3 JB後如何播放藍光或DVD?

Joe avatar
By Joe
at 2012-11-14T16:20
版上大大們好! 不好意思又遇到奇怪的問題來求救了~ 因緣際會下修好了死亡黃燈的胖60G 並用自行JB 3.55配Multi-man來硬碟安裝減少光碟讀取, 結果昨天突然想看影片, 將BD/DVD(兩個都試了)放進光碟機後, 在主畫面的影片ICON下, 根本沒有看到BD或DVD的圖示~ 然後MM ...