Post: fail0verflow! - Sony's ECDSA code
12-29-2010, 04:08 PM #1
manster
League Champion
(adsbygoogle = window.adsbygoogle || []).push({});
Hi!
Featured News from You must login or register to view this content.
You must login or register to view this content.

You must login or register to view this content.

JAILBREAK -> DOWNGRADE -> fail0verflow


You must login or register to view this content.

You must login or register to view this content.

You must login or register to view this content.

Well the big PS3 Exploit talk is now officially over at the annual 27C3 conference. All the big names in the developer scene world was there giving a one hour talk regarding Sony's EPIC FAIL


You must login or register to view this content.

But basically they talked about how the PS3 totally failed in security, by botching the pki implementation it became possible to calculate the keys needed to sign everything. PUBLIC PRIVATE KEYS, and replacing the "revoke-list" with super-large one (overflow) during the bootup NOR flash at startup, giving them full control of the PS3 system.


The 360 console is now more of secure system then the PS3 after all these years!




This site was announcend at the conference
You must login or register to view this content. - Coming Soon
You must login or register to view this content.
check this site too
You must login or register to view this content.

Originally posted by another user

"The recent advent of these new exploits means current firmware is vulnerable, v3.55 and possibly beyond. It will be very difficult for Sony to fix the described exploits."

"we can now run unsigned code on an non-exploited PS3."

@KushanTheCat our goal is to have linux running on all existing PS3 consoles, whatever their firmware versions.

Our current PS3 goal: AsbestOS.pup

Myth #1: It took us 3-4 years to do this. Negative, this exploit only took a few months after we started working. We weren't trying before.

Myth #2: Sony can change keys. No, they can't. These aren't encryption keys, they're signing keys. If they change them GAMES STOP WORKING.

Clarification #3: The private keys refer to keys that Sony HQ uses. PS3s don't have these keys (but we calculated them due to the fail).

Clarification #4: the random number isn't 4, it's more like 007eabbb79360e14df1457a4194b82f71a0dc39280 (example). But it's still constant.

Note: we won't be working long-term on CFW or similar. We'll release tools and a PoC, someone else can take over. The fun part is done Winky Winky

Myth: Geohot -> Sony pulls OtherOS -> JB -> Fail. Fact: Slim had no OtherOS -> Geohot -> ... . Geohot started his work due to the Slim.

@You must login or register to view this content. yes, we'll release all our tools as soon as we cleaned them up in january or so.
Great news for all PS3 User's Smile




Console Hacking 2010 - Chaos Communication Congress
Screenshots:

You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.

short videos from the conference:

[ame]https://www.youtube.com/watch?v=YbUVgxw1yWc&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=GPjd6gHY6A4[/ame]
[ame]https://www.youtube.com/watch?v=ClnvJe4_u0Q&feature=player_embedded[/ame]

Full Video
[ame]https://www.youtube.com/watch?v=hcbaeKA2moE[/ame]
Splitted in 3 parts:

[ame]https://www.youtube.com/watch?v=X6CA4fqAdsc&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=X8ohOy8_XO4&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=Eag0VyRTld8&feature=player_embedded[/ame]
Download full video here (right click -> save as):
You must login or register to view this content.


Marcan @ 27C3 Lightning Talk
[ame]https://www.youtube.com/watch?v=lGI0EnNQ5GE&feature=player_embedded[/ame]


Have fun watching


Sources:
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 29 users say thank you to manster for this useful post:

369lo, 8======D----, bcb, Cain, CHuRCHYx, CRACKbomber, Fallen152039, Geigers, GetDeleted -_-, Hells, ihaxgames, IRiSe_GodFather, iSergeant-Adam, KimKardashian, MarioDaKid, Mark00agent, Mr. Aimbot, Mr. Star, Nicky74me, ProjectPartial, Slashey, Solid Snake, Suxh4rd2bu, That Guy_, The InvadeR, The Overdose, Uk_ViiPeR, UMD, XxLuisMaxX
12-30-2010, 09:02 PM #47
Flex99923
The Messiah
Great Work! :P, Hardware exploits cant be patched, same with the iphones.
12-30-2010, 10:22 PM #48
Originally posted by Castiel View Post
In the case this really success here is my point of view.

Disadvantages for me:

-We will have a non competitive and destroyed online game community, imagine a COD match with lots of people using an aimbot, that really isn't fun at all. In general I'm talking about using hacks online.

-PSN will turn into a paid service, since mostly everyone will stop buying original discs, how will they keep the service?


Advantages for me:

-A possible drop in original dics.
-Be able to play every game without paying.


Giving a full control to the PS3 will be a terrible error. In what will this really end?. I don't think this will be a pure victory for the PS3 users.

Someone else wants to make another advantage and disadvantage list, or all will be just perfect?


IMO:

Disadvantages:

.N/A


Advantages:

.FULL control over the PS3

.If the aimbotters and wallhackers come online then where will all the pre-pubes go? Yep, I'm hoping they quit >.>

.and the most important advantage: Everyone at NGU can start having some haxorz fun :420:
12-30-2010, 10:33 PM #49
sounds good
12-30-2010, 11:22 PM #50
xFusion-Patriot
433 Subscribers!
So does this mean we will be able to get FTP server onto our Ps3's without jailbreaking it?
12-30-2010, 11:25 PM #51
manster
League Champion
Originally posted by kid1 View Post
So does this mean we will be able to get FTP server onto our Ps3's without jailbreaking it?

yes in the near future (~1-2 month)
12-30-2010, 11:27 PM #52
what if there is an system update within that time?
12-30-2010, 11:30 PM #53
Reaper
The Grim Reaper
If you try things and work at them you shall achieve. And here is something like that. Winky Winky My sig kind of says it all. Smile
12-30-2010, 11:53 PM #54
This is a ********. I hate this notice. In 2 or 3 months all mw2 players have hacks and modded lobbies. This gonna be madness!! /facepalm
12-31-2010, 01:04 AM #55
CHuRCHYx
Offering Free Sex
Going to be funn messing round with black ops, shocking game anyway...

The following user thanked CHuRCHYx for this useful post:

The InvadeR

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo