PS3 is 100% hacked


Оценить
Нет оценок
Поделиться
Удалён
VPwQORnM9DzgY1PL
13605
Забанен
13 февраля 2010 года в 11:25

http://twitter.com/geohot
We are happy to report that the PS3 Hypervisor LV1 and Bootloader LV0 are dumped from the PlayStation 3's RAM after getting our SX28 Hardware a few days ago, utilizing code for glitching and mashing buttons for hours - the exploit eventually will get triggered!

We tried a few different ways to dump out the real memory - the biggest "problem" was the fact that you can't just simply use File I/O code in a kernel module. Furthermore, you can't call the lv1_peek function from user mode either.

Luckily, resident DEV kakarotoks was up to the challenge. After some trial and error (and too many PS3 crashes!) he made a kernel module which maps the "real" PS3 memory to a device in /proc. The /proc area lets the kernel and userland interact some.

Basically, the device /proc/ps3_hv_mem is created when the kernel module is inserted. Once it is inserted, you can use dd to read the device. By doing this, the device gets passed arguments, which is passed along to lv1_peek - which in turns reads out the real memory.

Be advised, don't go beyond the PS3's upper memory limit. At around 260MB, the PS3 tends to crash - it does not like trying to read beyond RAM limits! So, for usage:

First, run the exploit, and get it triggered and working - that's the hard part!

Next, download the attached file, inside are three files, a Makefile, the ps3_hv_mem.c and a pre-compiled version. Stick these in a folder, and run make. It will then compile a kernel module for you (ps3_hv_mem.ko, or use the pre-compiled one). Then simply type: sudo insmod ps3_hv_mem.ko

Enter your password and check /proc for a ps3_hv_mem entry, or your dmesg. If it is there - let the dumping begin!

You can dump out the PS3 Hypervisor and Bootloader (and the rest of the real memory) via dd. You can use the command:

dd if=/proc/ps3_hv_mem of=PS3_Memory_Dump.bin bs=1024 count=10K

That command will dump out 10485760 bytes, or about 10MB - which nicely includes the goodies like LV0 and LV1. Finally, you can also increase the count, which will increase the amount dumped (multiply by blocksize).
http://www.ps3news.com/forums/ps3-ha...re-109794.html

из блога геохота
Today I verified my theories about running the isolated SPUs as crypto engines. I believe that defeats the last technical argument against the PS3 being hacked.

In OtherOS, all 7 SPUs are idle. You can command an SPU(which I'll leave as an exercise to the reader) to load metldr, from that load the loader of your choice, and from that decrypt what you choose, everything from pkgs to selfs. Including those from future versions.

The PPU is higher on the control chain then the SPUs. Even if checks were to be added to, for example, verify the hypervisor before decrypting the kernel, with clever memory mappings you can hide your modified hypervisor.

Ah, but you still didn't get the Cell root key. And I/we never will. But it doesn't matter. For example, we don't have either the iPhone or PSP "root key". But I don't think anyone doubts the hackedness of those systems.

I wonder if any systems out there are actually secure?
http://geohotps3.blogspot.com/2010/0...ated-spus.html

13 февраля 2010 года в 15:40

gvammer:

только это еще мало, ключи для игр они так и не получили.

Для тех кому лень переходить по ссылке и читать:

до Root Key вряд ли кто, когда докопается. Но он в принципе и не понадобится, так как например в iPhone, PSP его тоже никто не знает, но системы то хакнуты.
Благодаря умелому манипулированию памятью можно прятать свой модифицированный Hypervisor и полностью управлять всеми SPU(давать им команды загрузки или дешифровки pkg/self файлов) из под OtherOS. От себя

Про непрошиваемые PSP c определенными материнками, про новые приводы Lite-On для X360. Из той же оперы. Результат - хакнуто и то и то.

а также пс3 ньюс успешно сдампили гипервизор и бутлоадер http://www.ps3news.com/forums/ps3-hacks/playstation-3-hypervisor-bootloader-dumped-ram-more-109794.html

апд
PS3 is 100% hacked

+1 0   -1 0
Автор
Lord Gremlin
11951
13 февраля 2010 года в 15:42

Да что тут такого. В 10 раз взламывают. Новая прошивка - и все опять чисто-гладко. Не будет уже пиратства на этой консоли - пока не забъют на ее поддержку.

+1 0   -1 0
Удалён
VPwQORnM9DzgY1PL
13605
Забанен
13 февраля 2010 года в 15:42

Lord Gremlin:

Да что тут такого. В 10 раз взламывают. Новая прошивка - и все опять чисто-гладко. Не будет уже пиратства на этой консоли - пока не забъют на ее поддержку.

спасибо посмеялся

+1 0   -1 0
JoD
rossoneri
15682
13 февраля 2010 года в 15:44

VPwQORnM9DzgY1PL:

Lord Gremlin:

Да что тут такого. В 10 раз взламывают. Новая прошивка - и все опять чисто-гладко. Не будет уже пиратства на этой консоли - пока не забъют на ее поддержку.

спасибо посмеялся

Ну да,а все над тобой.

+1 0   -1 0
Автор
Lord Gremlin
11951
13 февраля 2010 года в 15:45

VPwQORnM9DzgY1PL:

Lord Gremlin:

Да что тут такого. В 10 раз взламывают. Новая прошивка - и все опять чисто-гладко. Не будет уже пиратства на этой консоли - пока не забъют на ее поддержку.

спасибо посмеялся

Да у вас что-то не то с головой, батенька.

+1 0   -1 0
Удалён
VPwQORnM9DzgY1PL
13605
Забанен
13 февраля 2010 года в 15:45

JoD:

VPwQORnM9DzgY1PL:

спасибо посмеялся

Ну да,а все над тобой.

над тобой посмеялись

+1 0   -1 0
JoD
rossoneri
15682
13 февраля 2010 года в 15:45

VPwQORnM9DzgY1PL:

JoD:

Ну да,а все над тобой.

над тобой посмеялись

А ты оригинальный

+1 0   -1 0
Удалён
VPwQORnM9DzgY1PL
13605
Забанен
13 февраля 2010 года в 15:47

Lord Gremlin:

VPwQORnM9DzgY1PL:

спасибо посмеялся

Да у вас что-то не то с головой, батенька.

этот хак не фейк до этого не было хака были фейки

JoD:

VPwQORnM9DzgY1PL:

над тобой посмеялись

А ты остроумный

ты тоже

Сони это выгодно. Продажи консоли будут Огого

+1 0   -1 0
Madrid83
Скаузер
2353
13 февраля 2010 года в 15:48

izzy_man:


а также пс3 ньюс успешно сдампили гипервизор и бутлоадер http://www.ps3news.com/forums/ps3-hacks/playstation-3-hypervisor-bootloader-dumped-ram-more-109794.html

апд
PS3 is 100% hacked

как ты можешь писать что она хакнута? веря на словам не известно кому?

+1 0   -1 0
Автор
Lord Gremlin
11951
13 февраля 2010 года в 15:49

Да не суть важно, фейк или не фейк. Особенность-то в том что Сони может прикрыть любой хак простым обновлением прошивки, ведь при желании можно обновить все ее части. А Слимки взломать вообще невозможно. Так что все это не более чем игры в среде хакеров - писькомерство, и не более.

+1 0   -1 0