Post: fail0verflow! - Sony's ECDSA code
12-29-2010, 04:08 PM #1
manster
League Champion
(adsbygoogle = window.adsbygoogle || []).push({});
Hi!
Featured News from You must login or register to view this content.
You must login or register to view this content.

You must login or register to view this content.

JAILBREAK -> DOWNGRADE -> fail0verflow


You must login or register to view this content.

You must login or register to view this content.

You must login or register to view this content.

Well the big PS3 Exploit talk is now officially over at the annual 27C3 conference. All the big names in the developer scene world was there giving a one hour talk regarding Sony's EPIC FAIL


You must login or register to view this content.

But basically they talked about how the PS3 totally failed in security, by botching the pki implementation it became possible to calculate the keys needed to sign everything. PUBLIC PRIVATE KEYS, and replacing the "revoke-list" with super-large one (overflow) during the bootup NOR flash at startup, giving them full control of the PS3 system.


The 360 console is now more of secure system then the PS3 after all these years!




This site was announcend at the conference
You must login or register to view this content. - Coming Soon
You must login or register to view this content.
check this site too
You must login or register to view this content.

Originally posted by another user

"The recent advent of these new exploits means current firmware is vulnerable, v3.55 and possibly beyond. It will be very difficult for Sony to fix the described exploits."

"we can now run unsigned code on an non-exploited PS3."

@KushanTheCat our goal is to have linux running on all existing PS3 consoles, whatever their firmware versions.

Our current PS3 goal: AsbestOS.pup

Myth #1: It took us 3-4 years to do this. Negative, this exploit only took a few months after we started working. We weren't trying before.

Myth #2: Sony can change keys. No, they can't. These aren't encryption keys, they're signing keys. If they change them GAMES STOP WORKING.

Clarification #3: The private keys refer to keys that Sony HQ uses. PS3s don't have these keys (but we calculated them due to the fail).

Clarification #4: the random number isn't 4, it's more like 007eabbb79360e14df1457a4194b82f71a0dc39280 (example). But it's still constant.

Note: we won't be working long-term on CFW or similar. We'll release tools and a PoC, someone else can take over. The fun part is done Winky Winky

Myth: Geohot -> Sony pulls OtherOS -> JB -> Fail. Fact: Slim had no OtherOS -> Geohot -> ... . Geohot started his work due to the Slim.

@You must login or register to view this content. yes, we'll release all our tools as soon as we cleaned them up in january or so.
Great news for all PS3 User's Smile




Console Hacking 2010 - Chaos Communication Congress
Screenshots:

You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.

short videos from the conference:

[ame]https://www.youtube.com/watch?v=YbUVgxw1yWc&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=GPjd6gHY6A4[/ame]
[ame]https://www.youtube.com/watch?v=ClnvJe4_u0Q&feature=player_embedded[/ame]

Full Video
[ame]https://www.youtube.com/watch?v=hcbaeKA2moE[/ame]
Splitted in 3 parts:

[ame]https://www.youtube.com/watch?v=X6CA4fqAdsc&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=X8ohOy8_XO4&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=Eag0VyRTld8&feature=player_embedded[/ame]
Download full video here (right click -> save as):
You must login or register to view this content.


Marcan @ 27C3 Lightning Talk
[ame]https://www.youtube.com/watch?v=lGI0EnNQ5GE&feature=player_embedded[/ame]


Have fun watching


Sources:
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
Last edited by manster ; 12-31-2010 at 11:43 PM.

The following 29 users say thank you to manster for this useful post:

369lo, 8======D----, bcb, Cain, CHuRCHYx, CRACKbomber, Fallen152039, Geigers, GetDeleted -_-, Hells, ihaxgames, IRiSe_GodFather, iSergeant-Adam, KimKardashian, MarioDaKid, Mark00agent, Mr. Aimbot, Mr. Star, Nicky74me, ProjectPartial, Slashey, Solid Snake, Suxh4rd2bu, That Guy_, The InvadeR, The Overdose, Uk_ViiPeR, UMD, XxLuisMaxX
01-01-2011, 12:01 PM #65
what does the failoverflow do
01-01-2011, 12:18 PM #66
bonbonbon
dead babies in a tree
Originally posted by shooterman100 View Post
what does the failoverflow do


fail0verflow is the hackers group that cracked sonys pkg file encryption, narf
01-01-2011, 01:37 PM #67
Step76
Keeper
ive seen the whole 45 mins and i dont have any clue what theyre talking about...but one thing i am sure about: sony will be pissed like hell!
01-01-2011, 01:55 PM #68
Cyborg Ninja
PS3 Security FtW !
Originally posted by BNPunish View Post
it is possible cause the codes of games going to change with a single patch....

and the controler its going to "say connect the controller using a USB to use the controller" then the code is rewrited


Complete rubbish patches of games utilize only certain aspects of the game such as call of duty black ops online multiplayer.

All of the code is stored on the disk and if they changed the way the PS3 reads the code or changed the signiture the ps3 would throw back errors.

All new disks would have to re issued.
01-01-2011, 01:56 PM #69
vyselegend
Pokemon Trainer
Originally posted by Step76 View Post
ive seen the whole 45 mins and i dont have any clue what theyre talking about...but one thing i am sure about: sony will be pissed like hell!


Same. I just want to hack mw2.
01-02-2011, 04:49 AM #70
lives2game
Do a barrel roll!
hopefully this will come with a "how to" tutorial for those of us, who pretty much dont know what they are doing yet, but want to stick it to sony :P
01-02-2011, 03:57 PM #71
you act like it is so hard to sack ps3

The following user thanked iSergeant-Adam for this useful post:

Goone
01-02-2011, 04:08 PM #72
noobidude
Save Point
HAhahaha this makes me laugh Smile
01-02-2011, 06:42 PM #73
CHAOZ
Banned
Originally posted by Ihatecompvir View Post
Actually no bro, the CoD4 save isn't signed by Sony. It's patched because I'm pretty sure it has something to do with how the playlists check the save. Or maybe its something to do with how the executable checks the save. I'm pretty sure its the latter.

But, WaW and BO savegame hacking, anyone? Winky Winky

Maybe, amazingly, no savegame mods for either game are patched on PS3. I highly doubt it for both of them though.


DO you actually think that they didn't think about savegame mods in the development ? lol.

We are starting to under estimate treyarchs ability.

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo