PSJB的program code dump(中文不知道怎麼翻) - 改機

By Mia
at 2010-08-29T10:20
at 2010-08-29T10:20
Table of Contents
http://www.ps3hax.net/2010/08/ps-jailbreak-code/
底下二進位碼貼了也沒用,我也不是compiler,有興趣的人可以自己去買IC燒燒
看。
So what does this mean? Disane has summed it up below:
This is the disassembled PPC code more like the shell code that is
being injected. The best way would be to use the lv2 dump and this to
figure out how the stack overflow exploit works in the USB buffer of
the PS3 after that it can be reproduced on any FW. On both slim and
fat PS3s.
The JIG ID is probably passed to trigger some code pathern which
the Configuration Descriptor overflows and injects the shell code
after that the code gets executed. The shell code patches lv2 to run
fselfs and all kinds of interesting flags which I haven't noticed yet
******
跟我之前猜得差不多,就是利用和緩衝區溢位非常類似的堆疊溢位攻擊方式將攻
擊程式碼注入目標位置然後蓋掉program pointer 的值,讓他指到自己要執行程
式的開頭,就成功了。
只能說這是 C++語言的原罪,然後$ONY被婊了,因為這套程式語言對於記憶體的
管理太糟糕,緩衝區溢位、堆疊溢位這種鳥事已經是見怪不怪了。任天堂是自己
笨寫那種兩光的數位簽名驗證被抓到漏洞,這是$ONY可以說是相當無辜的說。
按照上面的說法, USB buffer 這個東西到底是在硬體層還是軟體層將成為關鍵
,如果是在硬體層的話$ONY只能在新機種上修改硬體設計才能反制了,不然單靠
更新韌體可能力有未逮。
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
底下二進位碼貼了也沒用,我也不是compiler,有興趣的人可以自己去買IC燒燒
看。
So what does this mean? Disane has summed it up below:
This is the disassembled PPC code more like the shell code that is
being injected. The best way would be to use the lv2 dump and this to
figure out how the stack overflow exploit works in the USB buffer of
the PS3 after that it can be reproduced on any FW. On both slim and
fat PS3s.
The JIG ID is probably passed to trigger some code pathern which
the Configuration Descriptor overflows and injects the shell code
after that the code gets executed. The shell code patches lv2 to run
fselfs and all kinds of interesting flags which I haven't noticed yet
******
跟我之前猜得差不多,就是利用和緩衝區溢位非常類似的堆疊溢位攻擊方式將攻
擊程式碼注入目標位置然後蓋掉program pointer 的值,讓他指到自己要執行程
式的開頭,就成功了。
只能說這是 C++語言的原罪,然後$ONY被婊了,因為這套程式語言對於記憶體的
管理太糟糕,緩衝區溢位、堆疊溢位這種鳥事已經是見怪不怪了。任天堂是自己
笨寫那種兩光的數位簽名驗證被抓到漏洞,這是$ONY可以說是相當無辜的說。
按照上面的說法, USB buffer 這個東西到底是在硬體層還是軟體層將成為關鍵
,如果是在硬體層的話$ONY只能在新機種上修改硬體設計才能反制了,不然單靠
更新韌體可能力有未逮。
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
Tags:
改機
All Comments

By Susan
at 2010-08-29T20:33
at 2010-08-29T20:33

By Genevieve
at 2010-08-30T13:44
at 2010-08-30T13:44

By Christine
at 2010-08-31T18:15
at 2010-08-31T18:15

By Margaret
at 2010-09-03T18:01
at 2010-09-03T18:01

By Sarah
at 2010-09-07T09:59
at 2010-09-07T09:59

By Kyle
at 2010-09-08T23:06
at 2010-09-08T23:06

By Noah
at 2010-09-10T12:18
at 2010-09-10T12:18

By Anonymous
at 2010-09-12T19:33
at 2010-09-12T19:33

By Hedda
at 2010-09-14T20:19
at 2010-09-14T20:19

By Isabella
at 2010-09-16T17:12
at 2010-09-16T17:12

By Jessica
at 2010-09-19T07:52
at 2010-09-19T07:52

By Erin
at 2010-09-19T20:44
at 2010-09-19T20:44

By Regina
at 2010-09-20T07:27
at 2010-09-20T07:27

By Anonymous
at 2010-09-21T23:42
at 2010-09-21T23:42

By Erin
at 2010-09-23T05:18
at 2010-09-23T05:18

By Kyle
at 2010-09-27T03:53
at 2010-09-27T03:53

By Noah
at 2010-09-28T20:57
at 2010-09-28T20:57

By Frederica
at 2010-10-03T10:18
at 2010-10-03T10:18

By Eartha
at 2010-10-07T15:51
at 2010-10-07T15:51

By Eden
at 2010-10-07T21:07
at 2010-10-07T21:07

By Kyle
at 2010-10-12T01:14
at 2010-10-12T01:14

By Sarah
at 2010-10-15T01:22
at 2010-10-15T01:22

By Adele
at 2010-10-16T19:57
at 2010-10-16T19:57

By Puput
at 2010-10-20T21:24
at 2010-10-20T21:24

By Ida
at 2010-10-23T18:58
at 2010-10-23T18:58

By Lauren
at 2010-10-25T19:49
at 2010-10-25T19:49

By Odelette
at 2010-10-28T01:06
at 2010-10-28T01:06

By Madame
at 2010-10-31T21:16
at 2010-10-31T21:16
Related Posts
關於$ONY訴訟 PSJB發明人的回應

By Susan
at 2010-08-29T10:08
at 2010-08-29T10:08
無法開機

By Zenobia
at 2010-08-29T09:46
at 2010-08-29T09:46
主機板是缺到爆嗎?

By Kumar
at 2010-08-28T21:06
at 2010-08-28T21:06
請給我一些建議

By Joe
at 2010-08-28T16:42
at 2010-08-28T16:42
$ONY於澳洲提告 請求法院禁止販賣PSJB

By Damian
at 2010-08-28T14:32
at 2010-08-28T14:32