Hacking Finding an exploit/crash in 2022

reha

Long Live the Machine
OP
Member
Joined
Jun 10, 2021
Messages
105
Trophies
0
Website
reha.zc.al
XP
809
Country
Turkey
Yeah, I decided to hunt for an exploit (if not an exploit, at least a crash). So I have a few questions!

1) Which version should I be on for finding exploits?
2) Would it be easier to find if I look for them on older versions?
3) Do savegame/tiff exploits still work on 6.60/6.61?

Please don't reply "OMG why don't you just use CFW on latest version instead it's easier aswell", I already know that it's easy I'm just doing this for fun!

Thanks in advance!
 

FAST6191

Techromancer
Editorial Team
Joined
Nov 21, 2005
Messages
36,798
Trophies
3
XP
28,375
Country
United Kingdom
Menu exploits or game exploits? Also do you have any self imposed limits for this one -- you could sign the resulting code if you wanted that might dodge the "was it a crash or was it an exploit" aspect or indeed remove some protections and work up to an exploit with an otherwise signed firmware (think the equivalent of full updated PC with anti virus and proper user vs old PC with adobe flash/pdf reader and no AV).

Generally you will want to look for either a developer mode/fix this thing mode or something that reads external data (save games, pictures, network maybe, audio streams in for code purposes...), preferably in a higher level mode (such as the menu) and work in from there, possibly with a stop to any changelogs if it is an external library responsible for things as was the case.

New vs old versions has many possibilities and considerations.
Older stuff is more likely to be thrown together and have since revealed issues with libraries and whatnot, as well as most protections being reactionary rather than thought out from the top (don't spend time, money and CPU cycles when you could be having flashy animations or getting it "working), though at the same time chances are whatever dev was tapped to do the last updates (don't know if the PSP got one for the EU privacy thing that saw several other previously dead consoles get updates) probably considered it a lost cause, might have been an intern and likely was not concerned with the full battery of tests that might be run.
I don't think there was much on the PSP as time went on other than eboot encryption -- it is usually left to later consoles entirely to change hardware access levels, security philosophies and add in new protections even if theoretically software could be used to boost things.
 
  • Like
Reactions: reha

reha

Long Live the Machine
OP
Member
Joined
Jun 10, 2021
Messages
105
Trophies
0
Website
reha.zc.al
XP
809
Country
Turkey
Menu exploits or game exploits? Also do you have any self imposed limits for this one -- you could sign the resulting code if you wanted that might dodge the "was it a crash or was it an exploit" aspect or indeed remove some protections and work up to an exploit with an otherwise signed firmware (think the equivalent of full updated PC with anti virus and proper user vs old PC with adobe flash/pdf reader and no AV).

Generally you will want to look for either a developer mode/fix this thing mode or something that reads external data (save games, pictures, network maybe, audio streams in for code purposes...), preferably in a higher level mode (such as the menu) and work in from there, possibly with a stop to any changelogs if it is an external library responsible for things as was the case.

New vs old versions has many possibilities and considerations.
Older stuff is more likely to be thrown together and have since revealed issues with libraries and whatnot, as well as most protections being reactionary rather than thought out from the top (don't spend time, money and CPU cycles when you could be having flashy animations or getting it "working), though at the same time chances are whatever dev was tapped to do the last updates (don't know if the PSP got one for the EU privacy thing that saw several other previously dead consoles get updates) probably considered it a lost cause, might have been an intern and likely was not concerned with the full battery of tests that might be run.
I don't think there was much on the PSP as time went on other than eboot encryption -- it is usually left to later consoles entirely to change hardware access levels, security philosophies and add in new protections even if theoretically software could be used to boost things.
I'm probably going with menu exploits since they're (kinda) more interesting for me. About the version thing, I think I'll go with the lowest possible version (which is 1.00/1.50 for PSP 1000s), try to find a vulnerability in there, after that I'll try to run the same exploit/crash on the newer version and see if it works. Thanks for the help!!
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nice. Which operating system are you installing?
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, windows 10 and some linux distro like linux mint
  • Xdqwerty @ Xdqwerty:
    dualbooth
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Yeah, I'd recommend having another OS just in-case you want to play games.
  • SylverReZ @ SylverReZ:
    At least Linux doesn't contain spyware than what Windows has.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, cuz of lag?
  • SylverReZ @ SylverReZ:
    @Xdqwerty, No. Whenever you use the internet on Windows, Microsoft collects personal data and installs bloatware that isn't necessarily needed, such as Edge.
  • SylverReZ @ SylverReZ:
    Speaking of which
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    I recall @impeeza mentioned some trick about not having bloatware when installing windows where you set up your country to "world" or smh like that
    +1
  • SylverReZ @ SylverReZ:
    Yes, you can debloat the operating system, but in some cases for me it just reinstalls them.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    I also recall my brother downloded a "non bloated" version of windows 11 on his pc
    +1
  • BigOnYa @ BigOnYa:
    "Why debloat? Why not embrace and enjoy my bloat?" - Gates
    +3
  • impeeza @ impeeza:
    @Xdqwerty yes, when you are installing Windows on the first steps you are asked for your current location, you MUST to select «international» so no bloatware is installed, because the bloatware is location based. if this night I have some time I will setup a VM and take screenshots.
    +2
  • BigOnYa @ BigOnYa:
    User Gates "Disliked" your answer.
    +3
  • Psionic Roshambo @ Psionic Roshambo:
    Damn cleaned up 348GB's of crap I wasn't using with that lol
    +2
  • BigOnYa @ BigOnYa:
    But can it completely remove RealPlayer? Lol jk
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I remember at one point it being pretty much labeled as malware lol
  • Psionic Roshambo @ Psionic Roshambo:
    I think my favorite one was that dancing purple gorilla... I uninstalled that thing from sooo many machine people would be like "Why is my computer so slow?" lol because this thing is using like 30% of your system resources.....
  • Psionic Roshambo @ Psionic Roshambo:
    This one lady... her son kept installing Kazaa... OK no problem the issue is he would download DBZ movies and they where amazing usually like 2-8KB in size lol can't remember how many times I had to format and reinstall windows over his stupidity. I even explained to him about file sizes multiple times...
    Xdqwerty @ Xdqwerty: @Psionic Roshambo, bonzibuddy?