作者cassine (Savannah)
看板Modchip
标题Re: [PS3 ] PS3 Exploit Talk Pushed Back to Wedn …
时间Tue Dec 28 15:41:03 2010
http://www.ps3hax.net/2010/12/graf_chokolo-exploits-hv-through-lv2-gameos/
http://psx-scene.com/forums/f6/graf_chokolo-hv-exploit-dump-gameos-73893/
Originally Posted by graf_chokolo
I have just exploited and dumped HV 3.15 from GameOS.
I used memory glitching like Geohot to get dangling HTAB entry but
2nd and 3rd stages are quite different. I used my knowledge about HV
internals and created a simpler exploit for stage2 and stage3.
I didn't use second VAS like Geohot. I used
lv1_undocumented_function_114 and
lv1_undocumented_function_115 to
exploit HV after I got a dangling HTAB entry
Now we don't need Linux to exploit and dump HV. Furthermore, HV dump
from GameOS is a lot better because when GameOS is running more
features are activated in HV
So, I can reverse now more C++ objects
and understand better how HV works.
I will make everything public very soon and i plan to dump HV 3.41
in the next days.
Happy New Year guys!
今天graf_chokolo宣称参考George Hotz(geohot) 的方法,利用漏洞在3.15版的
韧体的GameOS模式将整个 PS3 Lv2的HyperVisor读了出来。按照他的说法,就是
日後不再需要Linux 才能将记忆体读出,而且在GameOS底下比在OtherOS 底下读
记忆体好,原因是GameOS向HV要求的功能比较多,所以可以读到更多东西。
读出来之後就是利用逆向工程把C++ 物件还原成组合语言,然後开始找漏洞,然
後针对漏洞写程式攻破HV,最後就是最後一关Lv1 了。
明後两天他要尝试在3.41版韧体上再试一次。
******
graf_chokolo这边的研究成果应该对自制韧体会有贡献,他主要在研究 PS3韧体
程式的更新过程。要说有什麽突破性的进展,就是解开程式更新的方式,日後可
以同时兼顾 PSN连线、游戏执行跟执行自制程式。
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.120.31.133
1F:推 ilwu:可兼顾PSN的话就太棒了! 12/28 16:05
2F:→ lostkimo:能接触到lv1的话~~完全攻破的机率就大增啦!!! 12/28 16:28
3F:→ toro1144:期待阿~ 手指程式快放出吧QQ 12/28 23:37