A9VG电玩部落论坛

 找回密码
 注册
搜索
查看: 1443|回复: 5

【醒目】psp fm 2.6 告破!!

 关闭 [复制链接]

精华
0
帖子
65
威望
0 点
积分
96 点
种子
7 点
注册时间
2005-8-19
最后登录
2021-6-28
 楼主| 发表于 2006-6-28 18:55  ·  英国 | 显示全部楼层 |阅读模式
转自 http://pspupdates.qj.net/

原文:
Break out your calendars folks, because this may be a day that you want to mark as a pivotal day in the history of PSP homebrew. A developer known as hitchhikr of "hitchhikr SoftWorks" and coder companion Neural have come out with a Proof of Concept of a 2.50/2.60 Firmware Exploit! Once implemented and fine tuned for "normal user" use, this will bring 2.50 and 2.60 Firmware up to the same homebrew capability that 1.50 PSP owners enjoy with FULL kernel mode access - although Grand Theft Auto: Liberty City Stories will still be required, just like with eLoader.

Speaking of eLoader, Fanjita is already working with hitchhikr on incorporating this new exploit into an easily executable means via eLoader. After a brief chat with Fanjita, he's told us that you can expect some generic application for developers to hopefully be released in the next 24 hours. It will take a bit longer before something useable for non-devs will be released.

The exploit takes advantage of an added security check in 2.50/2.60 Firmware for sceKernelLoadExec, which is responsible for loading EBOOTs, but Sony also accidentally added an overflow bug, which means this exploit will not work with 2.0 and 2.01 Firmware.

Below you will find a download of hitchhikr's & Neural's Proof of Concept - this is not intended for the casual user. It creates dump files containing kernel memory dumps in the root of the memstick (boot.bin, kmem.bin, klib.bin). It also creates writeaccess.bin which contains just the hex (12 34 56 78) to prove that kmem CAN be written to.

But don't start upgrading those PSP's yet until a viable means of implementation is released! Also, this breakthrough does not open up the possibility of a downgrader due to the protection in the IPL in 2.50+ firmware. Although speculation has already begun that this will open the door to the decrypting of 2.70+ Firmware, allowing it to be emulated a la Devhook.


UPDATE #1: Fanjita has released the "source" of his work so far today on this newly discovered exploit. If you would like to take a look at it and continue investigating where he left off for today, have a look!

   Only for v2.5 / v2.6.

   Based on Proof of Concept code by Hitchhikr / Neural.

   Function : Attempts to load ms0:/kernel.elf using sceLoadModule/sceStartModule when in kernel mode, after writing a NOP to 0x8801A5B4.

   Diags: Writes a log of operations to ms0:/GTALOG.TXT.
   If LoadModule fails, writes the error code to ms0:/failload.trc.
   If StartModule fails, writes the error code to ms0:/failstart.trc.

iso和homebrew或者降级程序应该不久就可以在 2。6的fm上使用了!.

精华
0
帖子
112
威望
0 点
积分
152 点
种子
0 点
注册时间
2006-1-16
最后登录
2020-4-19
发表于 2006-6-28 19:23  ·  上海 | 显示全部楼层
哪位高人能翻下,我英文烂的要死

精华
0
帖子
65
威望
0 点
积分
96 点
种子
7 点
注册时间
2005-8-19
最后登录
2021-6-28
 楼主| 发表于 2006-6-28 19:31  ·  英国 | 显示全部楼层
其实就是通过sony的一个内存益处的bug,把2。6的固件破解了,但可能还需要gta来引导,就像eloader一样。
该用户已被禁言

精华
0
帖子
3740
威望
0 点
积分
3874 点
种子
0 点
注册时间
2003-11-3
最后登录
2020-1-15
发表于 2006-6-28 19:32  ·  日本 | 显示全部楼层
大意是说利用GTA的漏洞导出了2.6的系统文件

个人估计离破解还有相当距离

精华
0
帖子
65
威望
0 点
积分
96 点
种子
7 点
注册时间
2005-8-19
最后登录
2021-6-28
 楼主| 发表于 2006-6-28 19:38  ·  英国 | 显示全部楼层
警告一下1。5的玩家先别心急,等真正可用的东西出来了再升级。
还有,最近想入手小p的朋友可以考虑一下2。6的机器,可能之后2。6的机器会被js提价,毕竟2。71没有破解。

求败者

社会的安全隐患

精华
9
帖子
23805
威望
18 点
积分
24465 点
种子
5 点
注册时间
2004-11-19
最后登录
2022-9-17
发表于 2006-6-28 19:43  ·  北京 | 显示全部楼层
只是找到漏洞,
离破解还有一段距离,
和另一帖重复而且标题有点夸张,
先锁了
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|A9VG电玩部落 川公网安备 51019002005286号

GMT+8, 2024-11-19 22:42 , Processed in 0.161485 second(s), 13 queries , Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2020, Tencent Cloud.

返回顶部