Advertising
n00neimp0rtant wrote:thecobra, why not try playing with format strings? Even though you can't actually see the vita's console/syslog, that doesn't mean you can't try tossing in some %n or %hhn format specifiers to potentially jenk around with the instructions. The past 2 iOS jailbreak untethers (sigcheck patches applied at boot time) use format string vulnerabilities =P
I try that first but it seems that the system doesn't patch/convert those special string into anything. just read them like normal characters. but it does interprets the ASCII char for /n
