Forum: Latest News - Get all of the latest legal dev and underground news as it relates to the Sony PlayStation right here on PSX-Scene.

The above video goes away if you are a member and logged in, so log in now!



 
Would you like to get all the new info from
PSX-Scene in your email each day?




Want to learn more about the team keeping you up to date with the latest scene news?

Read about them now!

Check out our Developer bios, too!

 


Thread: PS3 CPU Exploit Released by DarkHacker
  

Page 1 of 13 1 2 3 11 ... LastLast
Results 1 to 10 of 129
  1. #1 PS3 CPU Exploit Released by DarkHacker 
    The Central Scrutinizer's Avatar
    The Central Scrutinizer is offline PSX-SCENE Admin Bot
    Join Date
    Jul 2002
    Posts
    919
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    512
    One day after Mathieulh Tweeted about a new exploit he refuses to release, a previously unheard of person calling himself "Darkhacker" has released info on a new CPU exploit.

    UPDATE: Mathieulh was apparently the original source of this "exploit" (click the link below for chatlog) but he and other devs claim it's useless. He adds that it is not the new exploit he Tweeted about yesterday.
    http://pastie.org/private/cjcucrzayyijh5mcpqvmlg

    CPU Exploit - one step closer to METLDR
    this is a release of the hidden Cell Exploit found a while ago and one of the step taken to the metldr exploit im going to release the because i fell people should have the right to do as they wish and the information should be free to the public

    i know by releasing this exploit ill probably be taken to court or sued but **** sony they can go to hell all i care for what there doing to us hackers ill fight until the last min i got of my life if i have to for the right of the people

    for this exploit your going need a leaked service pdf which is below

    time to explain this now listen up

    i know you all remember the exploit with ram and so on back in 3.15
    well your going look for the 'CELL RESET LINE' and that going be where the exploit is
    you know how the small 60ms or ns i dont remember thing sent to ps3 for the read and write of the ram ?

    well use line send that and connect it to the cell reset line. ( FIND IT IN DOC )
    and ground on outside of case and the example of what can be done with this is a cold reset which still has acess to the memory from gameos - dont let this die out people im taking a big risk by giving you all this information


    - thanks to mitchy my personal hard drive Tongue - note i did not upload the documents and if requested ill remove the links


    Example of what can be done with this --
    untouched memory on cold boot full access to lv2 and all game os memory
    News Source: PS3SDK via PsGroove

    Thanks to EmersonS35, natedogg20050 and spade_ for the news submissions.

    PDF download mirrors (not hosted on PSX-SCENE)...

    RapidShare - http://www.multiupload.com/RS_LGGA1T5T90
    MegaUpload - MEGAUPLOAD - The leading online storage and file delivery service
    DepositFiles - Deposit Files
    Hotfile - Hotfile.com: One click file hosting: Ps3 Blue Prints.pdf
    Zshare - zSHARE - Ps3 Blue Prints.pdf
    Uploading - Download Ps3 Blue Prints.pdf for free on uploading.com

    UPDATE #2: Mathieulh has added some additional information on the exploit via his Twitter feed.

    Quote Originally Posted by Mathieulh
    muhahahahaha this is just the cell reset line trick, you can use this to dump lv2 from 1.10 to 3.15 but that's it.

    Oh! and it's been known for ages by about....err... everyone...

    The fact is you can't glitch the cell to even access the isolated LS because it's PHYSICALLY disconnected from the bus.

    As in the cell was especially designed for the purpose of preventing access to the isolated LS by anything but the isolated process. You can read details about this here: The Cell Broadband Engine processor security architecture

    Anyway I'll stop talking of ps3 stuff for now, I am still pissed.

    That so called "cpu exploit" allows no more than dumping lv2 from 1.10 to 3.15. That's it. It's just pointless.

    The trick only worked because the otheros setting was written upon selection rather than upon shutdown.

    Then you could coldboot to a small piece of code installed in the linux partition which would dump the lv2 ram space for you.

    No, the isolated LS gets physically disconnected from the bus when isolation kicks in. That's the way it's designed

    Only the isolated process itself can access the isolated Local Store.

    Isolation itself is designed in a very secure way, I have never seen IBM engineers messing around when it comes to security.

    The line itself is cut, so to speak.

    As in the bus can have no physical interaction whatsoever with the isolated Local Store.

    In fact, should you have access to the nexus/jtag port on the cell, you still couldn't access the isolated Local Store.

    This means that to effectively dump the isolated LS content, you need to exploit the isolated process itself.

    Yes there is obviously a logic gate being involved in the process.

    Sadly most details from IBM about isolation are under NDA, so we don't know what's going on for sure "underneath"

    The only way to access the isolated LS again by software is to destroy the SPU and Create it again but this would delete the data.

    of course I do not mean to physically destroy the spu xD.

    Mainly what happens is that so long as a SPU runs isolated, only the software on that SPU can access the isolated LS, nothing else

    Then how about the code that actually kickstarts the isolation ?

    Then what does decrypt the bootloader and metldr ? There has to be some rom doing the decryption and holding key

    Of course the spu isolation itself would be done by hardware, but only "trusted" software can run isolated

    Those are the public docs you know ? :P

    A lot of the cell docs are NDAed, You cannot expect the spu to just jump at encrypted instructions can you ?

  2. #2  
    Anony is offline Member
    Join Date
    Sep 2010
    Location
    Desert
    Posts
    222
    Downloads
    0
    Uploads
    0
    Likes Given
    7
    Likes Received
    11
    let me see
    Olimex AVR-USB-162 + AVR-USB-STK Flashing Guide W/ Hermes v3 Compiled Hex:
    http://tinyurl.com/olimexguide
    Enjoy

  3. #3  
    Dofu is offline Member
    Join Date
    Aug 2010
    Posts
    154
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    0
    Why is Members News Submission private? Also, cool beans.

    ~Dofu

  4. #4  
    Omnomnom's Avatar
    Omnomnom is offline PSJCL Forum Moderator
    Join Date
    Oct 2010
    Posts
    545
    Downloads
    0
    Uploads
    0
    Likes Given
    10
    Likes Received
    9
    Surprise surprise.
    Trust, encouragement, reward, loyalty... satisfaction. That's what I'm... you know. Trust people and they'll be true to you. Treat them greatly, and they will show themselves to be great.

  5. #5 Thumbs up Nice 
    cookiedood's Avatar
    cookiedood is offline Registered User
    Join Date
    Jan 2011
    Posts
    23
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    4
    I don't know how to use this lol

  6. #6  
    elk1007's Avatar
    elk1007 is offline Registered User
    Join Date
    Sep 2010
    Posts
    16
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    2
    Sorry to be the ignorant one, but what does this mean for the scene, exactly?

  7. #7  
    Join Date
    Jan 2011
    Posts
    98
    Downloads
    1
    Uploads
    0
    Likes Given
    0
    Likes Received
    1
    Quote Originally Posted by cookiedood View Post
    I don't know how to use this lol
    This is only useful for devs right now but with luck this may bring us some goodies in the future. Spread this like fire lol
    Puff Puff Pass!

  8. #8  
    jayjayusa is offline Member
    Join Date
    Oct 2010
    Posts
    256
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    1
    OHOH niceee, will I be sued If I see this page? lmao
    Nice job, one step closer.

  9. #9  
    Ro0tk3y is offline Registered User
    Join Date
    Feb 2011
    Posts
    2
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    0
    BOOOOOOOOOOOOOOOMMMMMMMMMMMBBBBBBBBBBBBBBB!


    Take this Sony!!! hahahahahahhahahahaahahahahahahaha

  10. #10  
    2legit2quit's Avatar
    2legit2quit is offline PS3 SCENE SUPPORTER
    Join Date
    Jan 2011
    Posts
    30
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    0
    Example of what can be done with this --
    untouched memory on cold boot full access to lv2 and all game os memory
    Nice
    80GB CECH-E01 PHAT BC $ony Refurb. FEB '11 with A.Silver 5 applied - OFW 3.61
    750GB CECH-2501B SLIM w Move Bundle - REBUG 3.55.1 CFW. ESATA HDD Dock



Page 1 of 13 1 2 3 11 ... LastLast
Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Popular Tags

3.41 3.42 3.50 3.55 3.55 cfw 3.56 3.60 3.61 3.66 3.72 3.73 80gb 90006 agent under fire armax assassins creed back-up back up backup backup games backup manager backups backwards compatible banned batch bdemu black blackbox black ops blackrhino blackscreen black screen blu-ray bluray blu ray bluray drive boot break brick bricked broken bug burn burned bypass card cfw cfw 3.55 cfw3.55 cheat cheating cheats cobra cod code codebreaker codename rebug compatibility control controller cover custom custom firmware dead deank debug demo development devs disc read error dlc dongle downgrade drive dvd dvd+r dvd9 e3 flasher easy eboot eboot.bin eboot bin elf emulator error esr ethernet exploit external external hd external hdd fail fan fat fat32 fifa firmware fix fmcb fmcb 1.8 format free freemcboot free mcboot free mc boot free mc on my ps2 freeze friv ftp gaia gaia manager game games gameshark geohot graf_chokolo gran gran turismo 5 gt5 gta iv guide hack hacking hard drive harddrive hdd hdd incompatibility hdl hdloader hdtv helpme hermes hex homebrew infectus install internal internal hdd iphone iso jac jailbreak jailbreak 3.55 jak 3 kakaroto kiosk kmeaw kmeaw 3.55 lan laser linux load loader logo mac manager matrix matrix infinity maximus mcboot memento memor32 memory memory card mfw mod modbo mod chip modchip modded modding mods motherboard move multiman music mw2 nand need for speed netflix network network games help newbie news noob not working ntfs ntsc ofw online open open manager open ps2 loader openps2loader opl otheros packages packer pal param.sfo patch payload pic pkg playstation playstation 2 playstation 3 power problem problems progskeet ps1 ps2 ps2 backups ps2 slim ps3 ps3 break ps3 fat ps3 game backup ps3 game modding ps3 hdd ps3 homebrew ps3 jailbreak ps3 slim ps3break ps3key ps3mfw psfreedom psgrade psgroove psjailbreak psn psn bypass psp psp 3000 psx psx-scene question questions rebug red red flashing light region restore retro rock band rogero rogero manager router save saved games saves scph-70004 screen sdk server showtime skyrim slim slim ps2 smb sms softmod sony speed spoof stuck swap swapmagic swap magic swap trick system theme ti-84 tos trick trophies true blue turismo tutorial ubuntu ulaunchelf ule update updates upgrade usb usb advance usbadvance video virtual vmc waninkoko wireless working wutangrza x3max xmb xploder ylod