메뉴 www.fafan.kr
파판 >> PS정보
  • 로그인
  • PS3 LV2_Kernel Exploit Sample Implementation By Naehrwert
    작성자 : Mac2 | 조회수 : 19690 (2012-09-21 오후 2:19:41)
    - 첨부파일
      images.jpg


    Following up on his PS3 SCETool update and PS3 Dump_Rootkey code, today Sony PlayStation 3 hackerNaehrwert has posted some details on exploiting the PlayStation 3 lv2_kernel and has made available a sample 3.41 implementation below.

    To quote from his blog: Exploiting (?) lv2

    A long while ago KaKaRoTo pointed me to a stack overflow he found while reversing lv2_kernel. But there are two problems:

    1. The vulnerability is in a protected syscall (the SELF calling it got to have the 0x40... control flags set). So you’d first need to find a suitable usermode exploit (don’t ask us), that gives you code execution with the right privileges.

    2. The payload data is copied to lv2 heap first and the function will do a free call on it before the payload has any chance to get executed. This might not sound like a problem but it looks like lv2′s heap implementation will overwrite the free’ed space with 0xABADCAFE and thus destroy the payload.

    Here (pastie.org/4755699) is my sample implementation for 3.41 lv2_kernel (although the vulnerability should be present in all versions of lv2 up to the latest firmware), maybe someone of you will find a way to overcome problem (2.) and can get something nice out of it because right now it’s only good to crash lv2.

    기사 원문 : http://www.ps3news.com/ps3-hacks-jailbreak/ps3-lv2-kernel-exploit-sample-implementation-by-naehrwert/

    ==========================================================================================================
    기사 원문과 DASHHACKS의 기사를 짧은 지식으로나마 해석해보니 LV2 단계의 커널의 EXPLOIT이 구현되었다고 하고
    이걸 통해서 모든 현 시스템의 LV2 커널의 EXPLOIT이 가능할 수도 있다라고 하는거 같은데요.
    (According to the source, there seems to be the possibility of a kernel exploit that could effect all current systems!)

    ==========================================================================================================
    As of right now, the PS3 scene is somewhat limited to a very specific group that happen to have one of the few possible hacked firmwares. However, if the exploit discussed in this coder's blog post can happen to be capitalized on, it's quite possible that the homebrew community just might open up to a massive degree. According to the source, there seems to be the possibility of a kernel exploit that could effect all current systems! Essentially in technical terms the crash creates what is called a stack overflow, allowing the entire security mechanism to be crushed under the right kind of code.
     
    However, as of right now this discovery is not without its share of limitations. As Naehrwert himself puts it "you’d first need to find a suitable usermode exploit (don’t ask us), that gives you code execution with the right privileges" to work behind the protected syscall involved with the vulnerability. Additionally, the firmware itself also has a way of erasing the extra payload so that the true crash isn't allowed to take full effect. Still, as proof of his work, my my source link shows the 3.41 version kernel in the hopes that another group may be able to help him out. Oh what a wonderful world we would live in should this be fully realized.


    ==================================================================================

    제가 너무 확대 해석한건지 ㅋ
    어쨋든 LV2 커널 EXPLOIT로 인해 3005도 커펌이 되길 기다립니다.
    (자세한 해석은 밑에분께 ㅠ)






    글쓰기 | 수정 | 삭제 | 목록   

    Lv.4 한번믿어봐 (2012-09-21 14:27:01)
    으음 ㅋㅋ DEX넘어가는거 우선 보류 ㅋㅋㅋ
    Lv.3 Mac2 (2012-09-21 14:44:51)
    근데 저걸 우리가 바로 쓸수 있는건지 .. 아니면 3005에서는 또 안되는건지 자세한 내용을 모르겠네요...
    저걸로 뭘 할수 있을지 ㅋ
    Lv.13 kiva (2012-09-21 20:56:00)
    저도 이거 보고 맘이 설레더군요 ㅡㅡ;;
    부디 루머가 아니길
    포럼에서는 루머로 생각중;
    Lv.12 GTO_GTO (2012-09-21 23:48:30)
    DEX도 좋지만 제발 새로운 커펌만 나왔으면 좋겠네요...ㅜ.ㅜ
    Lv.7 마이언 (2012-09-22 00:03:16)
    제발 3005도 커펌 한 번 해보자....ㅠ.ㅠ
    Lv.7 롤빵 (2012-09-22 20:59:11)
    왜 다들 dex넘어가는거를 망설이는걸까요?? 지금 사용하다가 다른게 나오면
    다른걸로 넘어가면 되는건데.. 지금상태에서는 최고의 펌이라고 봅니다. 여러가지 장점들..
    Lv.4 한번믿어봐 (2012-09-22 23:40:48)
    한번믿어봐님이 (2012/09/22 23:45)에 삭제 하였습니다.
    Lv.2 엑술로즈 (2012-09-23 19:43:51)
    엑술로즈님이 (2012/09/26 12:22)에 삭제 하였습니다.
    Lv.2 BeForU (2012-09-24 01:27:30)
    스크린샷이 익숙하네요 ㅎㅎ....
    하지만 벽돌 한번 만들어보니 겁이 나서 못넘어가겠네요.
    OtherOS++도 안되는 것 같고 하니까요.
    Lv.2 악질이 (2012-09-24 23:03:53)
    흠 3005도 언제 ㅠㅠ
    Lv.2 zpdjsxpdlzj (2012-09-24 23:12:12)
    dex에서cex전환하다가 보드크리낮어요 참고하시길
    Lv.3 다시리 (2012-09-25 08:48:18)
    기대되는 그링군요. ㅜㅜ
    Lv.3 하빼 (2012-10-02 12:00:49)
    완전 기대되는... 제발...ㅋ
    Lv.7 네오그랑존 (2012-10-08 18:03:27)
    하위호환 정발 80기가 모델도...제발.....
    Lv.3 튜닝페인 (2012-11-10 23:39:44)
    기대 되는데요 ㅎ 좋은정보 감사합니다 ㅎ



    도배방지 : 0

    글쓰기 | 수정 | 삭제 | 목록   

     

    12345

    Copyright ⓒ FINALFANTASIA.COM All rights reserved.