Mathieu Explains 3.60 Exploit

Discussion in 'User Submitted News' started by mechadylan, Apr 22, 2011.

Apr 22, 2011
  1. mechadylan
    OP

    Member mechadylan GBAtemp Advanced Fan

    Joined:
    Aug 18, 2009
    Messages:
    776
    Country:
    United States
    [​IMG]

    The cats out of the bag, after many subtle hints, Mathieu explains his exploit and how it will lead to application keys. With the help of this loader exploit, devs can now obtain the Bootloader keys which will lead to the Application keys and eventually, a 3.60 CFW! With application keys, Portal 2 and future 3.60 encrypted games may soon be playable!

    Synopsis of Mathieu's explanation of the exploit:

    The function that copies the SCE header from the shared LS to the isolated Local Store doesn’t check the header’s size.

    [So] you craft a self with a HUGE header so [that] it overwrites ldr code as it gets copied to the isolated LS and you wait [for] the loader to jump to it.

    [Then] you can get lv0 decrypted, once you get lv0 decrypted, you get appldr, once you get appldr, you get 3.60 application keys, [and] once you get that, you [get] warez.



    Mathieu's full conversation regarding the exploit:

    X nah, not a single line of code, at least not for the implementation
    but finding the exploit itself
    is EASY
    except no one has gone looking
    I’ve seen lots of askings and whining, very little looking xD
    if someone who remotely knows spu reversing starts looking
    he’ll find it
    at the very worse in a matter of hours
    the bug is ******ly stupid to begin with
    LV0, EID0, anything with coreOS imo should not be done without a hardwareflasher. Atleast with that you can undo the mess.
    yeah
    I am a bit of a red head here xD
    you keep saying that, but I suck at SPU assembly
    you’d find it even if you fail at it
    you just need to know where to look
    just look at how selfs are processed by ldrs
    and you’ll find it
    hell, I’ll help you, it’s about overflowing a certain buffer
    yes, that is what defyboy and I tried to document in the ps3devwiki : bootprocess and loader locations etc.
    well if you know how selfs are processed by loaders, it’s easy
    another hint
    it happens before the ecdsa check
    my earlier guess btw was that it was a header overflow, which gave access to the local storage
    It’s a ******ed exploit
    if you want to know what it is, I’ll tell you
    the function that copies the SCE header from the shared LS to the isolated Local Store
    doesn’t check the header’s size
    \o/
    it’s just THAT ******ed
    implementing it isn’t easy though
    cause loaders have failsafes and ****
    header size fail
    lol
    ?
    but now that you know, you can try it on your own
    X1 yes
    you craft a self with a HUGE header
    so it overwrites ldr code as it gets copied to the isolated LS
    and you wait the loader to jump to it
    lolol must try heh
    X1 it’s a total ***** to implement
    but feel free xD
    if someone pwns the bl with this and gets the keys, he’ll have my kudos
    cause finding the exploit is the easy part
    Sony’ll fix it now, but it’s not like I care much
    their “unhackable” ps3s are probably already on the way

    Mathieu explains the impact the exploit/keys have on Sony:

    why would they care about bootldr keys?
    ps3devnews etc. host metldr keys, appldr keys etc.
    X1 cause you can get lv0 decrypted
    once you get lv0 decrypted
    you get appldr
    once you get appldr
    you get 3.60 application keys
    once you get that
    you warez
    also, with those keys you can sign your own lv0, no ps3 fw update can beat you then
    yah
    you can have your 3.60+ custom firmware then
    and warez even more
    and mess with the psn again
    and so on


    [​IMG] Source
     
  2. shakirmoledina

    Member shakirmoledina Legend

    Joined:
    Oct 23, 2004
    Messages:
    6,611
    Location:
    Dar es Salaam
    Country:
    Tanzania
    i doubt it will be that easy. They said after geting the private key that sony is gone and now look, they are working on 3.6. Pretty sure sony CAN do something to block even this but this is good news for hackers.
    turn ur attention to the 3ds please!
     
  3. Zorua

    Zorua Newbie

    This is good news.
    I can't wait to play Portal 2!

    NO. Let it live. I don't want hordes of shovelware like the DS.
     
  4. mercluke

    Member mercluke ‮҉

    Joined:
    Dec 2, 2007
    Messages:
    3,161
    Location:
    Perth
    Country:
    Australia
    if you can't wait...
    Warning: Spoilers inside!
     
  5. squall23

    Member squall23 GBAtemp Regular

    Joined:
    Nov 19, 2002
    Messages:
    240
    Country:
    Canada
    They're only shovelware because you choose them to be. I find DS's library to be awesome. So start working on that 3DS and break that region lock!
     
  6. Zorua

    Zorua Newbie

    O rly? Ever heard of the infamous 'Imagine' series? And 'Littlest pet shop'? [​IMG]
     
  7. squall23

    Member squall23 GBAtemp Regular

    Joined:
    Nov 19, 2002
    Messages:
    240
    Country:
    Canada
    Hey, nowhere did I say that all DS games were good, that's an impossibility. But to say that the DS is full of shovelware means that you're ignoring stuff like Ouendan, Trauma Centre, Tales of Innocence, etc etc, I can go on and on.

    In fact, now that I think about it, EBA wouldn't even exist if the import rate of Ouendan didn't get so surprisingly high. So yeah, hacking = no region locks. No region locks = better 3DS.
     
  8. Zorua

    Zorua Newbie

    Don't get me wrong here.
    I'm a ninty fanboy.
    The DS is full of shovelware.
    Go have a look at your favorite rom site and look at the latest releases.........

    Let's stop derailing the thread now.
     
  9. DrOctapu

    Member DrOctapu Magnificent Bastard

    Joined:
    Dec 23, 2008
    Messages:
    1,207
    Location:
    Hell.
    Country:
    United States
    His grammar makes me want to punch a baby.
    Anyway, cool. I've been missing my emulators.
     
  10. Zorua

    Zorua Newbie

    I think he's German....
    Not sure though.
     
  11. soulx

    Member soulx GBAtemp Legend

    Joined:
    Apr 4, 2009
    Messages:
    10,130
    Country:
    Canada
    I suggest this.
     
  12. Zorua

    Zorua Newbie

    Thanks but I'm buying the 360 version.
    I decided that the game deserves my money. [​IMG]
     
  13. mechadylan
    OP

    Member mechadylan GBAtemp Advanced Fan

    Joined:
    Aug 18, 2009
    Messages:
    776
    Country:
    United States
    I always thought Mathieulh was French. [​IMG]
     
  14. twiztidsinz

    Member twiztidsinz Taiju Yamada Fan

    Joined:
    Dec 23, 2008
    Messages:
    4,981
    Country:
    United States
    Ever heard of Pokemon? [​IMG]

    I can't believe I'm defending something like "Littlest Pet Shop" (add 'of Horrors' and it could be awesome), but just because you don't like it (and it isn't targeted at you) doesn't make it shovelware.


    Hell... I think Pokemon is THE definition of shovelware. Every "generation" has 3 if not more games.
     
  15. Eckin

    Member Eckin GBAtemp Regular

    Joined:
    Mar 14, 2009
    Messages:
    216
    Country:
    Brazil
    Now Sony must stop messing around and start working against this exploit. I wonder if they still have someone working on that area, or if they fired everyone [​IMG]?

    Pokémon series has quality, even tho each gen comes around with 3 games. Can you say the same about the infinite amount of crap inside the DS library, like the Imagine series? I really doubt that!

    Let's face it, the DS has a nice number of gems, but they are surrounded but an enourmous number of quick cash-in games made for little kids - because those are the ones buying games (via their moms), while "older gamers" have this tendency to pirate.
     
  16. Annieone23

    Member Annieone23 GBAtemp Regular

    Joined:
    Jun 23, 2010
    Messages:
    125
    Location:
    USA
    Country:
    United States
    Even if all this is true I have absolutely no respect for Mathileu.

    He has repeatedly given his "formal" goodbye to the PS3 scene, teases about exploits only he has but wont release, and then when an even sh**ier team like X3 releases an exploit he has the audacity to claim he had it first, with no proof at all. he isnt a complete dofus and has released some honest good code in the past, but really i think he is just an ego hungry hack.

    on the one hand I hope this exploit is true, but on the other, since its from him I kinda hope its not true >.>
     
  17. Thesolcity

    Member Thesolcity Wherever the light shines, it casts a shadow.

    Joined:
    Oct 2, 2010
    Messages:
    2,146
    Location:
    San Miguel
    Country:
    United States
    Wasn't this the case with 3.56 too? I believe this guy teased and released the exploit (sort of) and nothing happened? I hope this isn't a get-your-hopes-up-for-nothing case. [​IMG]
     
  18. coolness

    Banned coolness PSN: Dutch_DarkLord

    Joined:
    Jun 14, 2009
    Messages:
    2,016
    Location:
    Rotterdam Bitches!!
    Country:
    Netherlands
    shit another exploit for the ps3 [​IMG]
     

Share This Page