Advertising (This ad goes away for registered users. You can Login or Register)

Another VHBL Exploid With Demo !

VHBL (Vita Half Byte Loader) is an open source tool to load PSP homebrews on the Playstation Vita.
VHBL can be downloaded at http://wololo.net/vhbl
Skaty
Posts: 32
Joined: Sun Mar 04, 2012 1:49 am

Another VHBL Exploid With Demo !

Post by Skaty » Sun Mar 04, 2012 1:58 am

Ok it seems that no one answer me about my recently mail about other name game that is compatible.

Like i said i'm not going to loose my time when i know that the MIPS Wrapper is available for a temp using.

Anyway the another PSP Game that you can use with the PS Vita to exploit the MIPS wrapper.

Also it's a demo and free game available on every SEN Store (US/EU/JP) Enjoy

Copy past the hexa code on a hexa editor and rename to .png to know ;)

HEX code is here: http://pastebin.com/cggAwJbM

source: NABNAB
Advertising

User avatar
Disturbed0ne
Retired Mod
Posts: 3787
Joined: Sun Jan 16, 2011 5:44 am
Location: In a van, down by the river!
Contact:

Re: Another VHBL Exploid With Demo !

Post by Disturbed0ne » Sun Mar 04, 2012 2:39 am

The demo in question is Ape Quest and there's still no proof that it actually works... :shock:

Provide something other than a name (ie a video showing it actually works with this demo) otherwise no one is going to believe this claim.

(Also, listing your source as "NABNAB" is pretty silly as even he hasn't provided any proof in the threads that he's posted on other forums about this...)
Advertising
DO NOT MESSAGE ME ABOUT THE NAME OF ANY NINJA RELEASE GAME! I WILL NOT PROVIDE YOU WITH THE NAME OF THE GAME AND IF YOU PERSIST THEN I WILL REPORT YOU TO THE STAFF!
I AM A RETIRED MODERATOR!

staplerz
Posts: 2
Joined: Fri Mar 02, 2012 12:05 am

Re: Another VHBL Exploid With Demo !

Post by staplerz » Sun Mar 04, 2012 3:17 am

Also this is not a US demo..

wololo
Site Admin
Posts: 3619
Joined: Wed Oct 15, 2008 12:42 am
Location: Japan

Re: Another VHBL Exploid With Demo !

Post by wololo » Sun Mar 04, 2012 3:48 am

Here's my opinion on the subject:
- The claims that this demo is exploitable need to be verified, this might take time
- This is for now completely unrelated to VHBL
- Since it's a demo, just feel free to install it. At worst, it takes a few hundred MBs on your Memory stick, and at best, something like VHBL might eventually come out of it.
If you need US PSN Codes, this technique is what I recommend.

Looking for guest bloggers and news hunters here at wololo.net, PM me!

wth
HBL Developer
Posts: 834
Joined: Wed Aug 31, 2011 4:44 pm
Contact:

Re: Another VHBL Exploid With Demo !

Post by wth » Sun Mar 04, 2012 4:24 am

wololo wrote:- The claims that this demo is exploitable need to be verified, this might take time
I deeply doubt such a savefile can ever get exploited anyway, just have a look http://hexpaste.com/sV3LpYAU/1
The text storing method here is like UTF32, that means at least like no buffer overflow attack possible, so unless someone would wanna make some incredible complicated thing to try exploit it this is just Not exploitable

User avatar
m0skit0
Guru
Posts: 3817
Joined: Mon Sep 27, 2010 6:01 pm

Re: Another VHBL Exploid With Demo !

Post by m0skit0 » Sun Mar 04, 2012 6:17 am

Why if encoding is UTF32 you cannot have buffer overflows?
I wanna lots of mov al,0xb
Image
"just not into this RA stuffz"

wth
HBL Developer
Posts: 834
Joined: Wed Aug 31, 2011 4:44 pm
Contact:

Re: Another VHBL Exploid With Demo !

Post by wth » Sun Mar 04, 2012 11:56 am

m0skit0 wrote:Why if encoding is UTF32 you cannot have buffer overflows?
sure well actually there indeed may still be buffer overflows in there, but I mean, if we kept using this UTF32-like style for a bof, inserted data would stay XX 00 00 00 XX 00 00 00 XX 00 00 00 like, so it wouldn't be of any use if overwriting ra with some XX 00 00 00
indeed if there were a way to somehow inject data as a XX XX XX XX XX XX XX XX XX XX XX XX UTF32-like thing there may be a way, but I doubt it would be so easy as to just be able to insert data like this
I tried inserting such data with some BB BB BB BB BB BB BB BB BB BB BB BB [...] but it didn't overwrite any register with BB BB BB BB or anything, ok it crashed, but registers looked just totally random
so I doubt nabnab ever found anything, there ay be a way but it wouldn't be a really obvious one then I guess

Skaty
Posts: 32
Joined: Sun Mar 04, 2012 1:49 am

Re: Another VHBL Exploid With Demo !

Post by Skaty » Mon Mar 05, 2012 9:30 am

Exploit in a demo ! if that possible some day, it would be great

User avatar
m0skit0
Guru
Posts: 3817
Joined: Mon Sep 27, 2010 6:01 pm

Re: Another VHBL Exploid With Demo !

Post by m0skit0 » Mon Mar 05, 2012 11:53 am

wth wrote: if we kept using this UTF32-like style for a bof, inserted data would stay XX 00 00 00 XX 00 00 00 XX 00 00 00 like
No, why so? UTF-32 says each character is 31 bit-wide, so it goes from 0x00000000 to 0x7FFFFFFF, which means 0x7AAAAAAA is a valid UTF32 character (and indeed it is).
I wanna lots of mov al,0xb
Image
"just not into this RA stuffz"

wololo
Site Admin
Posts: 3619
Joined: Wed Oct 15, 2008 12:42 am
Location: Japan

Re: Another VHBL Exploid With Demo !

Post by wololo » Mon Mar 05, 2012 12:03 pm

Nabnab was kind enough to send me his 2 attempts, and I looked into it.
I'll just leave the psplink screenshots here, and let people draw the conclusions they want to draw. I won't give any more comments on the matter since they would be misinterpreted again, however I invite people who want to seriously look for exploits in psp save games to read this article.

First file (I tried twice to be sure)
Image

Second file (the overflow attempt is a series of AA AA AA AA... in hexa)
Image

(hint for those who can't read these screenshots: no exception = nothing to exploit, and a null pointer exception is not exploitable)
If you need US PSN Codes, this technique is what I recommend.

Looking for guest bloggers and news hunters here at wololo.net, PM me!

Post Reply

Return to “Vita Half Byte Loader”