Random Homebrew: Tuyo Kiss
Tuyo Kiss is an interactive graphic novel for the PSP
Friends: Coding 'n Cracking - Nymphaea - PS3 Forum - darkforestgroup - daxhordes.org - Tgames - coldbird - gopsp.it - pspstation.org - prometheus - hgoel.info - MakeSmartTV - ps vita

PSVita Buffer Overflow...?

Re: PSVita Buffer Overflow...?

Postby n00neimp0rtant » Tue Jun 26, 2012 6:41 pm

wth wrote:
n00neimp0rtant wrote:Does the Vita use ASLR? If so, I can't imagine ANY user-level buffer overflow being of significance without kernel access to disable it.

I have no idea, but Sony would be really dumb not to imho no


https://twitter.com/cmwdotme/status/189549632379035648
https://twitter.com/cmwdotme/status/189553518879834112

(that's the guy who found the original PSP TIFF vulnerability)
Yes, I'm the iOS dev/hacker of the same name.

Got Cydia? Add my beta repo http://n00neimp0rtant.dyndns.org/repo
n00neimp0rtant
 
Posts: 32
Joined: Mon Jun 11, 2012 12:52 am

Re: PSVita Buffer Overflow...?

Postby konit_oo » Tue Jun 26, 2012 7:14 pm

If that would help you see what I've found (it's PDF)

http://www.arm.com/files/pdf/armcortexa-9processors.pdf

http://en.wikipedia.org/wiki/ARM_Cortex-A9_MPCore (yeah wikipedia, they say that vita uses 4-core Cortex-A9 MPCore)
I had that picture (below) from maybe half year or somehthing like that and I just ca'n't remember which part of vita was it, I'm nearly 100% that it was something for vita but I just can't remember what exactly.
Image

I'm not sure how usefull is this information but as you can see I'm doing it to help you and my point isn't to spam here, so sorry if I'd post info that you already know. :oops: :D

I hope I helped you a bit... :mrgreen: :roll:

Does vita need hardware hackers for that or it could be done just with software somehow?

oh... and sorry for my English :D :lol:
konit_oo
 
Posts: 189
Joined: Tue Jun 21, 2011 12:42 pm

Re: PSVita Buffer Overflow...?

Postby wth » Tue Jun 26, 2012 7:34 pm

n00neimp0rtant wrote:https://twitter.com/cmwdotme/status/189549632379035648
https://twitter.com/cmwdotme/status/189553518879834112

(that's the guy who found the original PSP TIFF vulnerability)

ah looks like good news :mrgreen:
wth
HBL Developer
 
Posts: 587
Joined: Wed Aug 31, 2011 4:44 pm

Re: PSVita Buffer Overflow...?

Postby Davee » Tue Jun 26, 2012 7:53 pm

Yeah but then there is still XN bit and such, that'd be a pain.
Follow me on twitter: @DaveeFTW
Davee
Guru
 
Posts: 294
Joined: Mon Jan 10, 2011 1:24 am

Re: PSVita Buffer Overflow...?

Postby n00neimp0rtant » Tue Jun 26, 2012 8:23 pm

konit_oo wrote:Does vita need hardware hackers for that or it could be done just with software somehow?

I really we need a lead through hardware hacking. The PS3 hacker community has all but resorted to hardware flashing and dumping at this point, and it really seems like the Vita is heading in the same direction. (Which isn't a real problem as long as there are talented, risk-taking hardware hackers in the scene, and the rest of us aren't afraid to get our hands dirty.)

Look at the iPhone: almost every jailbreak released recently has been discovered using already-jailbroken devices. Obviously, vulnerabilities do exist in the system, but without the ability to do things like take a look at the memory layout, it's extremely difficult to exploit them "in the dark."

Sometimes I really wish I was a CoE major instead of CS.
Yes, I'm the iOS dev/hacker of the same name.

Got Cydia? Add my beta repo http://n00neimp0rtant.dyndns.org/repo
n00neimp0rtant
 
Posts: 32
Joined: Mon Jun 11, 2012 12:52 am

Re: PSVita Buffer Overflow...?

Postby Davee » Tue Jun 26, 2012 9:12 pm

n00neimp0rtant wrote:
konit_oo wrote:Does vita need hardware hackers for that or it could be done just with software somehow?

I really we need a lead through hardware hacking. The PS3 hacker community has all but resorted to hardware flashing and dumping at this point, and it really seems like the Vita is heading in the same direction. (Which isn't a real problem as long as there are talented, risk-taking hardware hackers in the scene, and the rest of us aren't afraid to get our hands dirty.)

Look at the iPhone: almost every jailbreak released recently has been discovered using already-jailbroken devices. Obviously, vulnerabilities do exist in the system, but without the ability to do things like take a look at the memory layout, it's extremely difficult to exploit them "in the dark."

Sometimes I really wish I was a CoE major instead of CS.


Not necessarily, you just need to think rationally and work slowly with software. It's predictable. Gotta love that EE ;)
Follow me on twitter: @DaveeFTW
Davee
Guru
 
Posts: 294
Joined: Mon Jan 10, 2011 1:24 am

Re: PSVita Buffer Overflow...?

Postby thecobra » Wed Jun 27, 2012 7:53 pm

Davee wrote:
n00neimp0rtant wrote:
konit_oo wrote:Does vita need hardware hackers for that or it could be done just with software somehow?

I really we need a lead through hardware hacking. The PS3 hacker community has all but resorted to hardware flashing and dumping at this point, and it really seems like the Vita is heading in the same direction. (Which isn't a real problem as long as there are talented, risk-taking hardware hackers in the scene, and the rest of us aren't afraid to get our hands dirty.)

Look at the iPhone: almost every jailbreak released recently has been discovered using already-jailbroken devices. Obviously, vulnerabilities do exist in the system, but without the ability to do things like take a look at the memory layout, it's extremely difficult to exploit them "in the dark."

Sometimes I really wish I was a CoE major instead of CS.


Not necessarily, you just need to think rationally and work slowly with software. It's predictable. Gotta love that EE ;)


Agreed, Gotta love that "NO ASLR" ;)

n00neimp0rtant@ Yeah just read it, i responded.

wth wrote:
n00neimp0rtant wrote:Does the Vita use ASLR? If so, I can't imagine ANY user-level buffer overflow being of significance without kernel access to disable it.

I have no idea, but Sony would be really dumb not to imho no


lol, i guess Sony is dumb or brilliant, depend on what view you look at it. Anyway, It good news that There no ASLR in it else i don't think my buffer overflow will be exactly the same every-time that i restart the PSVita and test it out. I think tonight i gonna try something to see if i can get data before this strings Because i think maybe Sony read all of these information into those string before showing it to the user since when i try to read this string from another file, it also take no time to load it. Maybe if this work, I could somehow read data in between and other stuff or have some fun and change something lol.
Image
Tools

PSP Hack Device
PSVita 1.80 eCFW <Thank to wololo Community>
PSVita 1.67 vHBL Dead :(
PSP FAT 6.60 - CFW pro
thecobra
HBL Collaborator
 
Posts: 167
Joined: Thu Feb 24, 2011 7:50 pm

Re: PSVita Buffer Overflow...?

Postby 4ich » Wed Jun 27, 2012 11:18 pm

hehe then good luck :mrgreen:
Check out "ConsoleHeaven.net.ms" its an empty hacking forum that is hungry for users / we build it up =)
4ich
 
Posts: 40
Joined: Fri May 25, 2012 11:43 am

Re: PSVita Buffer Overflow...?

Postby garrei » Wed Jun 27, 2012 11:55 pm

Well, if something is comes up but is risky to test, i never use my vita so I dont mind If you would like to test something dangerous on it. I got firmware 1.61 on it still and im keeping it there until there is some sort of breakthrough. :|
My PC: AMD FX 8-core 4.2Ghz, 16gb RAM, GTX 580, 60gb SSD, Blu-ray Burner, WiFi, 1.5TB HDD, 1000W PSU, 27" Full HD Monitor
My PSP Slim 2002 - TA-085
My PS3 Slim 160GB 4.25 OFW
My Vita: WiFi only :(
User avatar
garrei
 
Posts: 242
Joined: Fri Mar 16, 2012 3:35 am
Location: Australia

Re: PSVita Buffer Overflow...?

Postby n00neimp0rtant » Thu Jun 28, 2012 12:54 am

thecobra, why not try playing with format strings? Even though you can't actually see the vita's console/syslog, that doesn't mean you can't try tossing in some %n or %hhn format specifiers to potentially jenk around with the instructions. The past 2 iOS jailbreak untethers (sigcheck patches applied at boot time) use format string vulnerabilities =P
Yes, I'm the iOS dev/hacker of the same name.

Got Cydia? Add my beta repo http://n00neimp0rtant.dyndns.org/repo
n00neimp0rtant
 
Posts: 32
Joined: Mon Jun 11, 2012 12:52 am

PreviousNext

Return to Security/Homebrews

Who is online

Users browsing this forum: Bing [Bot], Google Adsense [Bot], Google Feedfetcher and 5 guests