作者cassine (Savannah)
看板Modchip
标题[PS3 ] Mathieu Explains 3.60 Exploit
时间Fri Apr 22 10:37:49 2011
http://goo.gl/MNjUv
看来Mathieulh 之前卖很大的关子销路惨淡,没人买帐结果害自己被边缘晾在一
旁,於是非常积极的想要重回大众焦点XD。来看看这个传说中SONY无法补救的漏
洞是怎麽一回事:
The cats out of the bag, after many subtle hints, Mathieu explains
his exploit and how it will lead to application keys. With the help
of this loader exploit,
devs can now obtain the Bootloader keys which
will lead to the Application keys and eventually, a 3.60 CFW! With
application keys, Portal 2 and future 3.60 encrypted games may soon
be playable!
Synopsis of Mathieu's explanation of the exploit:
The function that copies the SCE header from the shared LS to the
isolated Local Store doesn't check the header's size.
检查self档案标头(header)的函式不会查验标头的大小
[So] you craft a self with a HUGE header so [that] it overwrites
ldr code as it gets copied to the isolated LS and you wait [for] the
loader to jump to it.
所以说如果你搞了个超大标头的档案,就有可能发生溢位,让你设计的标头里的
东西盖到程式指标,把内容盖成指向自己的程式,然後主机就载入你设计的程式
了(噗哧XD)
[Then] you can get lv0 decrypted, once you get lv0 decrypted, you
get appldr, once you get appldr, you get 3.60 application keys, [and]
once you get that, you [get] warez.
在你的程式里面,你可以解密Lv 0,当Lv 0解密之後,就可以解出appldr,解出
appldr之後,就可以得到程式的解密金钥,解密金钥到手後,就可以解密用3.60
金钥加密的程式
******
SONY设计的程式载入方式是先读取档案标头,里面会记载程式加密方式跟版本,
之後在拿对应的金钥去解密,在读取档案标头(标准长度是 0x980)时候,没去
检查长度,会一直读到尾巴,於是就有可能就把人家设计好的片段一口气读进去
记忆体里面,总之非常类似3.41的 JIG漏洞,当时是SONY忘记检查 USB装置描述
子的长度,结果被人家设计一个超大描述子送进去,把整个数位签证的机制瓦解
掉。
好吧,这个洞虽然可以解密Lv 0,但也是补得起来的。我记得在这之前就有人用
其他方法解出Lv 0了。
那这个洞对SONY有什麽影响?
******
also, with those keys you can sign your own lv0, no ps3 fw update can
beat you then
yah
you can have your 3.60+ custom firmware then
and warez even more
and mess with the psn again
and so on
拿到Lv 0的金钥,就可以拿来签自己的Lv 0,所以日後所有的韧体更新都不用担
心了。
******
啧啧,看来这个洞比3.41的JIG 漏洞还大条=.=
不知道会不会有人把petitboot 签上Lv 0的金钥,这样就可以丢掉SONY那限制多
多的bootloader了。
--
○ ____ _ _ _ _ ____ _ _ ____ _____ ____
。 ★(_ _)( \( )( \/ )( ___)( \( )(_ _)( _ )( _ \
o _)(_ ) ( \ / )__) ) ( )( )(_)( ) / ● ‧
(____)(_)\_) \/ (____)(_)\_) (__) (_____)(_)\_) ★
o
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.120.31.137
1F:推 OochunoO:XD140.123.105.107 04/22 10:56
2F:推 givemeback:lv0的key是SPU里面那个key吗? 112.105.71.121 04/22 10:56
3F:推 satou20444:真大洞wwww 114.40.132.184 04/22 10:57
4F:推 f1234518456:XDDDDDDDDDDDDDDDDdd 163.29.253.237 04/22 11:01
※ 编辑: cassine 来自: 140.120.31.137 (04/22 11:43)
5F:推 hill99:3.6自制快出吧!!!! 219.84.253.213 04/22 14:46
6F:推 myriad:感谢 cassine 大人长久以来资讯的提供 111.243.13.178 04/22 14:59
7F:推 PHILOSOMA:感谢更新 114.32.4.101 04/22 18:11
8F:推 toro1144:C大 真用心!!! 60.248.18.124 04/22 18:59
9F:→ flypenguin:不过从底下的回文来看,math只是提出 220.135.24.180 04/22 19:26
10F:→ flypenguin:这个方法,可是还没实作成功? 220.135.24.180 04/22 19:26
11F:→ cassine:正常,Mathieulh有说点出漏洞很容易,但让 140.120.31.137 04/22 20:39
12F:→ cassine:自己的程式执行成功才是最大的困难点 140.120.31.137 04/22 20:39