It’s a good day for the PSP homebrew scene. MaTiAz, a well known developer on the brew scene has found an exploit that uses the gamesaves in Gripshift to run arbitrary code. Now while this is just a proof of concept, this is a huge door open towards being able to fully hack the latest 3000 models. Here are a few words quoted from MaTiAz himself…
“So, happy new year. I think presenting a new usermode exploit on the PSP is a good way to start 2009 GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite $ra. It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn’t [be bothered to] get Shine’s savegame tool working so it’s in plaintext form) is in the SDDATA.BIN form which Hellcat’s Savegame-Deemer produces (thanks to him, if the program didn’t exist I wouldn’t have bothered with this.). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don’t forget to have Savegame-Deemer working, duh.”
|
|
Posted in PSP | No Comments » |
There are no comments yet for this post. |
You must be logged in to post a comment. |