A9VG电玩部落论坛

 找回密码
 注册
搜索
查看: 1643|回复: 7

[分享] [分享]How to Hook into LV2 Memory

[复制链接]

落伍者

JAY的忠实FANS

精华
0
帖子
40020
威望
34 点
积分
40238 点
种子
0 点
注册时间
2003-11-28
最后登录
2018-2-21
 楼主| 发表于 2010-10-30 12:54  ·  广东 | 显示全部楼层 |阅读模式
This post is meant for the more advanced developers out there. PS3mrengigma has updated his blog with a tutorial on how to hook into LV2. In this tutorial he utilizes, the undocumented, SYSCALL 867 for his hook. SYSCALL 867, which he explained previously, controls the PS3′s model information (retail, debug, reference tool etc). In his tutorial he walks us through the process of making his debug PS3, thinking its a retail unit (there is no benefit to making it think its a retail, its simply a learning exercise). For those interested in the tutorial, check it out after the jump.

http://psgroove.com/wp-content/u ... ubmodel-300x164.png

Translated:


In this post we will see how to make hooks (hooks) in the LV-2 SYSCALL. The possibilities are endless da hook, only to be limited to our imagination
and what we want to achieve with the hook.

For this section we should bear in mind that we need to meet the following requirements:

- Take a dump of the entire LV-2, possibly without being modified in any way by a payload.
– Knowledge of assembler to understand the original SYSCALL to create our hooks.
– Understand how the / s SYSCALL we will modify.

For this post’ll take the example of a LV-2 3.41 Debug (for it is that I work mostly), but can be applied just as in a LV-2 Retail.

The first thing you need to know is the beginning of the SYSCALL_TABLE, and the number of SYSCALL we want to put a hook.
For example put a hook to the SYSCALL 0 × 363 (867) to alter the machine model that we will return.

The SYSCALL_TABLE is at position 0 × 303130 (at any position in the LV-2 assume that they add the base address 0 × 8000 …), knowing the number of the SYSCALL (867)
and taking into account that each table entry is 8 bytes in the address pointed to multiply 867 * 8 = 6936, so we add that to the SYSCALL_TABLE, 0 × 303130 + 0x1B18 = 0x304C48.

In this direction we find another memory address, 0x348FB0, we go to the second and we have another memory address, 0x27A368. In this direction starts the code of the SYSCALL.
Point out the direction where is the address where the SYSCALL would begin, in this case, 0x348FB4.



Enter the code in the SYSCALL, knowing that the SYSCALL has 2 parameters, the first command of the operation to be performed and the second a pointer to a buffer to store the result
of the call, we can try to see how the SYSCALL.

The SYSCALL 867 with the command 0 × 19004 returned in the output buffer at position 3 (starting from 0) the byte that indicates the machine model, knowing that we can make our hook
inject this value in the output buffer.

http://psgroove.com/wp-content/u ... ubmodel-300x164.png.

落伍者

JAY的忠实FANS

精华
0
帖子
40020
威望
34 点
积分
40238 点
种子
0 点
注册时间
2003-11-28
最后登录
2018-2-21
 楼主| 发表于 2010-10-30 12:56  ·  广东 | 显示全部楼层
详细的请看这里

http://psgroove.com/?p=2027

精华
0
帖子
596
威望
0 点
积分
623 点
种子
10 点
注册时间
2007-3-5
最后登录
2022-10-20
发表于 2010-10-30 13:37  ·  河南 | 显示全部楼层
这学术性的东西看不明白.就说有啥作用?高版本游戏支持?自制系统?完美免盘?随意升降固件?
该用户已被禁言

精华
0
帖子
666
威望
0 点
积分
720 点
种子
0 点
注册时间
2005-2-21
最后登录
2016-3-20
发表于 2010-10-30 13:48  ·  四川 | 显示全部楼层
一个教程,交你如何修改PS3的LV2内存。
基本原理和X86汇编一样,命令是PPC汇编。

落伍者

JAY的忠实FANS

精华
0
帖子
40020
威望
34 点
积分
40238 点
种子
0 点
注册时间
2003-11-28
最后登录
2018-2-21
 楼主| 发表于 2010-10-30 13:54  ·  广东 | 显示全部楼层
那这个可以说可以修改金手指,存档的东西吗?
该用户已被禁言

精华
0
帖子
666
威望
0 点
积分
720 点
种子
0 点
注册时间
2005-2-21
最后登录
2016-3-20
发表于 2010-10-30 14:31  ·  四川 | 显示全部楼层
早着呢,这只是对8M LV2的分析修改。

精华
0
帖子
1000
威望
0 点
积分
1012 点
种子
12 点
注册时间
2008-9-10
最后登录
2024-10-22
发表于 2010-10-30 14:40  ·  江苏 | 显示全部楼层
拿分走人,俺看不懂。

精华
0
帖子
849
威望
0 点
积分
1748 点
种子
0 点
注册时间
2005-1-17
最后登录
2018-9-28
发表于 2010-10-30 15:41  ·  浙江 | 显示全部楼层
唉金手指貌似浮云了……继续等待吧等哪天权限能够直接修改内存了就牛X了
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|A9VG电玩部落 川公网安备 51019002005286号

GMT+8, 2024-11-27 03:52 , Processed in 0.182571 second(s), 15 queries , Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2020, Tencent Cloud.

返回顶部